Get a Demo
Under Attack?
K8S Sensor install Update

Runtime Security in Minutes: Upwind’s New Sensor Installation Experience 

Chris Lentricchia August 18, 2025

One of Upwind’s core advantages begins the moment runtime data is collected. That’s the moment teams stop guessing and start securing based on what’s actually happening in their clusters. From there, they gain meaningful visibility into workload behavior, identify real risks, and apply security policies based on observed activity rather than assumptions. To help teams realize that value faster, Upwind has introduced a redesigned Kubernetes sensor installation experience that eliminates friction and accelerates time-to-insight.

The Cluster Survey 

Our new sensor installation process for Kubernetes enables teams to activate runtime security capabilities within minutes. Whether using CLI, Helm, or Terraform, our new guided flow simplifies setup by adapting to each environment and providing install-ready commands. 

AD_4nXeVxT2Iv7PKsu_SFpigqm5jKrDblOg-HhmavKWs7XHeMOE46zkxiQmUbBj8JQX8cBCeHWqxkrFBl46DsGQrRo64Ui1aF2iuYtmJYhnqNr8HmOTig4T_z7KW3ZIDTIILymh20HgQ?key=cATRJXuvC6j_yHiPoY9Esw
On screen instructions walk you through the Upwind sensor deployment process

The Cluster Survey is central to this new process. It  automatically scans your Kubernetes environment to detect key characteristics and optimize installation parameters. The survey identifies resource requirements such as CPU and memory, recommends the appropriate number of replicas, and proactively flags issues like proxy limitations or metadata access restrictions before they impact deployment.

Upwind-Survey-Tool

For users who prefer not to run the automatic scan, a manual input option is available. By entering a few cluster details, teams receive a customized install command with intelligent defaults. This ensures the same speed and accuracy without requiring automation.


“At the scale of our infrastructure, we know we can only trust a few agent-based security products. Upwind’s eBPF sensor is the only one that met our standards.”

-Gal Aviv, CTO & GM, Digital Turbine

Deployment Options That Match Your Workflow

Recognizing that organizations manage infrastructure in different ways, Upwind supports multiple installation methods, each designed to accommodate various preferences and operational models:

  • Upwind CLI: Ideal for teams seeking automation, the CLI runs the Cluster Survey, configures system requirements, and installs the sensor with a single command. It’s the fastest route to runtime visibility, with data streaming into the platform within minutes.
  • Helm and Terraform: For teams managing infrastructure as code, Helm and Terraform workflows integrate seamlessly with the new installation process. The Cluster Survey generates configuration recommendations tailored to the cluster, enabling quick deployment without modifying existing practices.
  • Manual Setup: Whether CLI usage is restricted or teams need more granular control, the manual path provides a guided experience tailored to those needs. Users can input basic configuration details and receive a pre-filled installation command – removing uncertainty while preserving control.

Regardless of the method, the outcome remains consistent: Upwind sensors deployed quickly, real-time insights activated, and meaningful protection established – all in a fraction of the time traditional solutions require.

Immediate Value Through Runtime Awareness

This initiative is not solely about simplifying installation – it’s about accelerating access to Upwind’s core value: real-time, runtime-driven security.

Once Upwind’s sensors are installed, teams immediately begin receiving actionable data on workload activity. This includes detailed visibility into service communications, data flows, and behavioral anomalies that could indicate risk. Unlike static security approaches, Upwind enables continuous monitoring based on live production behavior.

“Upwind’s risk prioritization has completely changed the way we approach security. Understanding our greatest risks and what caused them has greatly improved our workflows, cut down on unnecessary labor, and given us the ability to ensure our security practice is proactive rather than reactive.”

-Matan Koresh I SecOps, Anzu

This visibility allows security and platform teams to:

  • Detect threats with greater speed and accuracy
  • Eliminate blind spots across workloads and services
  • Administer security policies grounded in real-world usage patterns

The result is a more adaptive, resilient security posture, achieved in a fraction of the time.

AD_4nXcwJeiAojvoqkqTIGVslELVpPxuuGTVBYX43pI05WVz6sJjpLfQh7J_dvPUmJ_h_mTcjwdQYl1Z4tdQRDKItFTNHCtNvCK2ODW97YhY6hYf3buoY-Fv1PVR0jvTPqDfnJ0NNpjcyg?key=cATRJXuvC6j_yHiPoY9Esw
Runtime data is key to Upwind’s vulnerability prioritization, enabling you to proactively focus on the most critical risks to your business. Focus on the highest-impact risks. Save hours of effort. 

Now Available in the Upwind Platform

Upwind’s new Kubernetes sensor installation experience is available today. Designed to reduce setup complexity and help teams operationalize runtime security faster, it supports organizations of all sizes in achieving immediate, meaningful outcomes through runtime data.

See It in Action

If you’re running Kubernetes and looking to accelerate your time to value, we invite you to experience the new installation flow firsthand. Schedule a demo to see how Upwind turns runtime signals into real protection, fast.

Contents

Further Reading

Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Custom-Reporting-Hero

Security Reporting Built Around Your Program

We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…
Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS