A screenshot of a dashboard displaying vulnerability analysis. The screen shows sections for threat detection, data exposure, and network information. A circular graph and various tags are present, with a purple and pink gradient background.

Labels & Tags Are the New Identities in the Cloud 

Denise Ashur November 27, 2023

Labels & Tags Are the New Identities in the Cloud 

Upwind is excited to announce a new capability – enhanced visibility of Labels & Tags Cardinality.

What is Labels & Tags Cardinality?
Cardinality gives you the ability to better understand how often and at what scale tags and labels are being used and what their values are across your resources. This helps you have a much more accurate picture of your identities at scale. The Upwind platform will now give you at-a-glance information about your cloud assets and their tags, labels and annotations in order to quickly identify the application owners and its identities. 

Starting today, you can view your resources’ tag cardinality everywhere in the Upwind console, when investigating a threat or exploring a vulnerability finding. Streamline your cloud security experience, ensure compliance and elevate your posture by increasing tag hygiene, giving you additional context about which resources and tags are most utilized across your cloud environment.

Contents

Further Reading

Let Me Speak to Your Manager (Account)

Let Me Speak to Your Manager (Account)

The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…
Configuration-Focus

Introducing the new Configurations experience in Upwind

Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…
What You Could Build If IAM Let You

What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys

In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS