Get a Demo
Under Attack?
A pattern of shields with check marks, mostly in light purple, fills the background. One shield in the center stands out in a darker purple. The word upwind is in the top left corner in black and pink.

Enhance Your Threat Detection Capabilities with Custom Policy Scope 

Denise Ashur August 01, 2024

Enhance Your Threat Detection Capabilities with Custom Policy Scope 

We are excited to announce a significant new capability, giving you the ability to customize threat detection policy scope in the Upwind platform.

Upwind has always provided powerful out-of-the-box threat detection policies based on predefined attack vectors, ensuring real-time threat detection. With this new capability, Upwind provides even more customization to fit your unique infrastructure and operational needs, by giving you greater control over how existing policies operate.

Screen-Shot-2024-05-03-at-12.15.39-PM-1-1024x739

You can now modify existing policy attributes, including setting custom parameters for scope to meet your specific security needs.

With these new customization abilities, you can take greater control of your security, ensure maximum effectiveness and flexibility in defending against evolving threats, and prevent false positive events.

Use these new capabilities to modify policies to match your organization’s unique requirements, giving you the ability to ensure alignment with your specific security standards, compliance needs and operational workflows.

Contents

Further Reading

Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Custom-Reporting-Hero

Security Reporting Built Around Your Program

We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…
Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS