Get a Demo
Under Attack?
An illustration featuring a crane lifting several server racks with Kubernetes and Keycloak logos. The background includes large digital storage units. Labels on the racks display data strings and the name Upwind.

Pinpoint Vulnerability Origins With Complete Visibility into Container Image Layers

Denise Ashur February 21, 2024

Pinpoint Vulnerability Origins With Complete Visibility into Container Image Layers

We are excited to release an important new capability – container image layer visibility.

A Docker build consists of a series of ordered build instructions. A layer, or image layer, is a change in an image, or an intermediate image. Every command specified (FROM, RUN, COPY, etc.) in a Dockerfile causes the previous image to change, thus creating a new layer.

This new capability provides a detailed breakdown of each container image by:

  • Highlighting specific image layers
  • Identifying image changes between layers
  • Pinpointing the introduction layer for every package

Understanding and tracking container image layers is crucial for identifying when and where vulnerabilities were first introduced and can also be used to discover package drifts related to packages installed outside the base image layer.

layers-details-1-1024x661

In addition to layer visibility and the ability to pinpoint vulnerabilities origins, you can also use this capability for:

1. Streamlined scans of large images, leveraging our ability to break the scan per layer

2. More efficient scans that only scan the last layer

3. Faster and easier scanning for your organization

Use this capability for increased transparency into your running container images, helping you rapidly identify and track how image layers introduce or resolve vulnerabilities and how this impacts your overall cloud security.

Contents

Further Reading

Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
AI-will-make-software-more-secure

AI Will Make Software More Secure. The Transition Won’t Be Pretty

I believe AI is going to make us much more secure. But probably not tomorrow. In fact, I think the next two years may be exactly the opposite: attackers will have the upper hand before defenders eventually turn the economics of cybersecurity in their favor. For decades, we have built software with vulnerabilities and then…
Vulnerability Management

Vulnerability Management Requires Real-Time Intelligence

Security teams aren't short on data. But they’re often short on context and time. The average vulnerability management program is buried in alerts, running on scan results that are hours or days old, and facing both savvy and unskilled attackers that can leverage AI to develop sophisticated exploits in minutes. That combination is why backlogs…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS