Get a Demo
Under Attack?
A blue and orange graphic with the Upwind logo in the top left. In the center, an astronaut helmet with a small star is next to the text “gVisor” on a dark blue background with a large orange semi-circle on the left.

Unlock Runtime Visibility for gVisor Sandboxed Containers

Unlock Runtime Visibility for gVisor Sandboxed Containers

Upwind Sensor now brings runtime visibility to gVisor sandboxed containers, proactively identifying threats in environments built for maximum isolation. gVisor acts as a security layer between containerized apps and the host OS, improving security and isolation, which is especially important for containers running sensitive workloads. With our new support for gVisor, strong isolation no longer comes at the cost of reduced security telemetry, enabling effective threat detection and runtime analysis across all containerized workloads.

What is gVisor?

gVisor is an open source security-focused container runtime, originally developed by Google and written in Go, that provides isolation between applications and their host operating system. Unlike traditional container runtimes that rely on kernel namespaces and cgroups, gVisor implements a user-space kernel, effectively acting as a “sandbox” for your containers. 

Here’s how gVisor strengthens container security: 

  • Sandbox containers: gVisor acts as a security boundary between your container and its host OS. gVisor intercepts syscalls made by the container, reducing container attack surface.
  • Reduce kernel exposure: Since the host kernel isn’t directly exposed to the container while utilizing gVisor, the kernel is less susceptible to container escape vulnerabilities.
  • Mitigate kernel-level exploits: Even if the container is compromised, the attacker would still be restricted by gVisor’s user-space kernel.

Why are we enabling gVisor within the Upwind Sensor?

With gVisor operating as a sandboxed kernel, Upwind now supports tracing inside these secure environments, which delivers the deep runtime visibility teams expect, without sacrificing container isolation.

A comparison diagram showing two architectures: on the left, eBPF in the Kernel; on the right, gVisor tracing in Sentry Userspace Kernel. Both interact with sensors, applications, cluster managers, and the Upwind Backend.
By enabling gVisor tracing within the Upwind Sensor, we’ve extended observability into sandboxed container environments that were previously opaque.

Our integration taps into gVisor’s remote sink protocol and syscall trace points to deliver real-time visibility into container behavior. Even within a user-space kernel, you get the runtime insights needed for effective threat detection – ensuring comprehensive protection for isolated workloads.

AD_4nXd-r2PJD4NRud9Eak9DHBxZxESj4ZGM6cxEXzkjpbHniefw5jOf9LfYvf8EZW67ULsGh_kqGbGIxa7f5msQ73ao65w_wZLqFGbAb3x8N5T5KAriQm9jp9YhmLeGG2sPGmhcf3A3?key=cmyymCzar0UG8WcUcrXS372f
Container image vulnerability detection in the Upwind Platform

Running gVisor? Let us show you how to gain full runtime visibility without giving up the isolation your security depends on – schedule a demo or drop us a line at [email protected]

Contents

Further Reading

API-ASM Blog

Validate the Real-World Exposure of Your APIs with Upwind Attack Surface Management

Your APIs are probably the least-monitored component of your attack surface. They multiply faster than any team can document, and most scanners only ever pick up the ones you already know about. But that gap just got smaller. Upwind’s Attack Surface Management capabilities now provide a unified view of cloud and API exposure, helping security…
gemini-svg

Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Executive Summary Upwind recently observed multiple Advanced Persistent Threat (APT) groups actively exploiting CVE-2026-72898. This vulnerability - an unauthenticated SQL injection in the Metabase password reset endpoint carrying a critical CVSS score of 10.0, was actively exploited as a zero-day before a patch became available. An unauthenticated remote attacker can craft a malicious SQL injection…
Buyers Demos

Why Buyers Remember Solving a Demo, Not Watching One

Key Takeaways I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS