Get a Demo
Under Attack?
Illustration of interconnected blue and purple servers with Kubernetes logos, creating a grid pattern. The background has a gradient from darker blue to purple. The word Upwind is visible in the top right corner.

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Denise Ashur October 16, 2024

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Upwind’s eBPF sensor is lightweight and high performance, which was recently shown in a record-breaking image scan with customer H2O.ai.

When scanning H2O.ai’s 30GB container image with multiple dependencies, the Upwind sensor consumed less than 1GB of RAM, about 3% of the image size, demonstrating how Upwind ensures comprehensive runtime security coverage with a lightweight footprint.

“The Upwind sensor’s ability to scan very large container images without hindering performance has allowed our team to effortlessly implement cloud security at runtime. Its efficiency, combined with its minimal impact on our environment, is truly groundbreaking.”

-Ophir Zahavi, Cloud Engineering Manager, H20.ai

The Upwind sensor is able to scan large container images as well as monitor real-time traffic on Layers 3, 4 and 7 while maintaining a lightweight footprint and using less than .01%-1% CPU.

To learn more about Upwind’s high-performance eBPF demo, visit the Upwind Documentation Center (login required) or schedule a demo.

Contents

Further Reading

Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Custom-Reporting-Hero

Security Reporting Built Around Your Program

We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…
Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS