Get a Demo
Under Attack?
A flowchart with interconnected blue circles containing icons. Arrows in green, yellow, and blue link the circles. A small blue circle with a power icon is at the top left. The upwind logo is in the top left corner.

Automatically View High-Privilege Identity Insights in the Upwind Topology Map

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Denise Ashur March 12, 2025

Automatically View High-Privilege Identity Insights in the Upwind Topology Map

We’re excited to introduce a powerful new capability in the Upwind Cloud Security Platform –  enhancing security by providing seamless visibility into highly privileged identities for every containerized resource in your cloud environment. Now available directly in the Upwind Topology Map, this feature helps detect and mitigate excessive permissions, reducing the risk of privilege escalation attacks and unauthorized access.

Screenshot of a software dashboard showing a map and an overview. The map on the left displays nodes and connections. The overview on the right contains details about Kubernetes deployment and resources, including error messages and resource names.

This enhancement makes it even easier to visualize Upwind’s runtime-driven approach, going beyond traditional CWPP solutions. It correlates real-time network topology, privileged identities, posture misconfigurations, threats, vulnerabilities, and API weaknesses – giving you deeper contextualized security insights to prioritize actual risks.

With this update, you can now easily view high-privilege source information, including:

  • Cloud IAM High-Privilege Roles
  • Kubernetes High-Privilege Roles
  • Kubernetes Security Context
  • Pivot to Cloud – K8s Resources with Cloud Permissions
A network map interface from Upwind shows various nodes and connections, including Kubernetes clusters and AWS resources. A legend details resource states with colored icons, and a sidebar features options like cloud accounts and assets.

This granular identity insight makes it even easier to rapidly assess resource risk context and proactively remediate unnecessary privileges, which ensures stronger protection for your most critical cloud assets. Among other benefits, it helps identify overly permissive Kubernetes service accounts that could allow unintended access to cloud resources, reducing the risk of lateral movement by attackers.

User interface displaying a network map with interconnected nodes and services labeled AWS, Azure, MongoDB, and DNS. A dropdown menu shows filters for resources, with options like AWS and DNS. Various system components and paths are highlighted.

By leveraging Upwind’s correlated container and identity security capabilities, security teams can connect identity risk with vulnerabilities, threats, posture findings, and APIs, achieving holistic protection across containerized environments. To learn how to start correlating identity context with risk findings, schedule a demo today.

Contents

Further Reading

KSPM-Agentless-Scanning

Complete KSPM: From Pull Request to Production Runtime

Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…
Upwind MCP Server

Revolutionizing Security Investigations with the Upwind MCP Server

Frontier AI models combined with a rampant rate of new critical vulnerabilities mean speed and context are everything. When a critical production service starts behaving suspiciously, every second spent jumping between different tools and dashboards is a second lost to a potential attacker. At Upwind, we are excited to introduce a game-changer for security teams:…
Security Feed - Threat

No npm Token Required: Inside the AsyncAPI Supply Chain Attack

Executive Summary Upwind identified a critical supply chain compromise across five npm packages in the @asyncapi scope, published on July 14, 2026 via two separate branch compromises in two GitHub repositories. The attacker never touched an npm token. They abused each project's own CI pipeline through GitHub Actions OIDC to publish the malicious packages. The…