Get a Demo
Under Attack?
Screenshot of the Upwind platform showing response details in a table against a gradient background. The table includes timestamps, response statuses, and various metrics. Success status is highlighted in green.

Automate Threat Detection & Response for Kubernetes Workloads

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Jonathan Cohen November 09, 2023

Upwind’s real-time threat detection capabilities have helped our customers identify threats and bad actors the moment they enter their cloud environment. This real-time, runtime-powered capability is the definition of shift-right security, and we have now taken it one step further by providing the ability to respond to threats as soon as they are detected.

With this new capability, Upwind users will now be able to methodically kill threats at the process level, giving you the ability to selectively target and stop threats without interrupting your cloud operations.

Proactive Threat Response 

In order to understand how Upwind’s response capabilities work, you first need to understand the logic behind our threat detection machine. Upwind constantly monitors cloud workload behavior, deploying a lightweight eBPF agent to inspect packets at the kernel level. This allows the Upwind agent to read every system call and identify any abnormal behaviors or threats in real time. Using machine learning, Upwind also recognizes known security patterns, malware signatures and new or unusual behaviors that signify a threat is present.

As soon as a threat detection is made, you are given the relevant detection information including severity, root cause and whether or not it is an active threat. 

detection-details-1024x580

For active threats of every severity, you have the option to respond to the threat. By choosing the response option, you can kill the malicious process and quickly stop it from causing damage within your environment. 

Upwind Response: Automatically Kill the Process at the Source

Using Upwind’s threat detection machine, you are also able to view the detection process tree and relevant context to give you absolute certainty about the need to remediate it and any child processes that stem from the original process tree.

This is significant because it gives you the ability to not only kill a single malicious process, but to also kill processes running on multiple different containers at the same time. By killing the malicious process itself and not the container, you are able to rapidly secure your workloads without disrupting your cloud operations.

Side_panel-1024x395

Upwind’s Threat Prevention

Perhaps most importantly, Upwind now also provides you with the ability to create a prevention strategy over time that will repeatedly kill a malicious process when it tries to run. This goes beyond the response capability to provide security teams with the tools needed to not only stop threats but also prevent them from occurring in the future.

Upwind also keeps a response audit log, giving you the ability to identify who within your organization chose to use the response feature, when it was used and if it was successful.

Automated Response with eBPF

Upwind is able to provide this cutting-edge detection and response capability through our eBPF agent, which brings a host of advantages that revolutionize the way we approach runtime security:

  • Lightweight: eBPF’s minimalistic footprint ensures that the Upwind agent operates seamlessly without imposing unnecessary overhead on your applications or infrastructure. This means you can secure your workloads without sacrificing performance.
  • Kernel-Level Precision: One of the most powerful capabilities of eBPF is its ability to operate at the kernel level. This grants us unparalleled visibility and control, allowing us to track and respond to threats with precision, even in the deepest layers of your runtime environment.
  • Real-time Visibility into Process & Network Activity: eBPF allows for efficient real-time monitoring of processes & network activity, which translates to valuable insights into process executions, traffic patterns, connections and potential security anomalies. This level of visibility is crucial for proactive threat detection.

Learn More 

To learn more about Upwind’s Intelligent Threat Detection and Response capabilities, refer to the Upwind Documentation Center (login needed). 

To see a live demo of Upwind in action, please email us at [email protected].

Up & Upwind! 🏄‍♂️

Contents

Further Reading

gemini-svg

Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Executive Summary Upwind recently observed multiple Advanced Persistent Threat (APT) groups actively exploiting CVE-2026-72898. This vulnerability - an unauthenticated SQL injection in the Metabase password reset endpoint carrying a critical CVSS score of 10.0, was actively exploited as a zero-day before a patch became available. An unauthenticated remote attacker can craft a malicious SQL injection…
Buyers Demos

Why Buyers Remember Solving a Demo, Not Watching One

Key Takeaways I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive…
PagerDuty-Hero

Upwind Integrates with PagerDuty for Instant Incident Response

Upwind now integrates with PagerDuty, enabling security teams to create workflows that automatically route Upwind findings and detections to the appropriate on-call team based on existing incident management workflows. This integration expands Upwind's growing library of native workflow integrations, giving security and platform teams even more ways to turn real-time detections into immediate action. What's…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS