Danilo Michelucci

Upwind Blue Agent – Increasing the Scope and tooling to a new level of incident response
Cloud attacks do not stay within the boundaries of a single security tool. An intrusion can begin with an API request, execute a process inside a Kubernetes workload, modify a file, contact an external host, use a cloud identity, and change cluster state, all as part of the same incident. But the evidence needed to…

Upwind for Microsoft Sentinel – Available on Marketplace and Security Store
Security teams should not have to switch between tools to understand what is happening across their cloud environments. That’s why we’re excited to announce that the Upwind solution for Microsoft Sentinel is now available through the Microsoft Marketplace and the Microsoft Security Store. The integration brings Upwind security data directly into Microsoft Sentinel, helping security…

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC
We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…

Upwind Launches Malware Scanning for Cloud Storage Across AWS, Azure, and GCP
Cloud object storage plays a central role in modern applications. Buckets are used to store application assets, exchange files, manage backups, build data pipelines, and share information across services and teams. That flexibility also makes object storage an attractive attack vector. A malicious file uploaded to a bucket can introduce risk into downstream applications, workloads,…

Upwind brings Custom Detection Policies for APIs
Every API has a different risk profile. An internal billing endpoint and a public-facing authorization endpoint don't fail the same way. They don't get attacked the same way either. A generic ruleset can't account for that. Custom rules can, and now those rules can see sensitive data too. This new release brings two things together…

Complete KSPM: From Pull Request to Production Runtime
Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…

We Compiled the Top 10 MCP Use Cases for Upwind
A new vulnerability enters the backlog. A workload is exposed. A misconfiguration affects production. An identity behaves unexpectedly. A customer asks for evidence. An audit or pentest is coming up. Each moment requires the same understanding of what is real, what is urgent, what is connected, and what should happen next. The Upwind MCP Server…

Upwind AI Security: Securing your AI stack from the inside-out
AI is changing how we build, work, and operate. It is moving from experimentation into production applications, customer experiences, developer workflows, and cloud operations. As AI moves closer to the core of the business, it is gaining access to the systems that matter most: sensitive data, internal tools, cloud services, and non-human identities. AI changed…

The Revolution in Cloud Security Prioritization
In the modern cloud landscape, security teams are drowning in a deluge of vulnerabilities. Thousands of Common Vulnerabilities and Exposures (CVEs) lurk within base images, open-source libraries, and operating systems. While today’s security infrastructure is doing better at detection—scanning images, generating Software Bills of Materials (SBOMs), and identifying exposures at scale—the real battle has shifted.…

Upwind and Microsoft Partner to Bring Security at runtime speed to Azure
Cloud Security has changed Teams are moving faster, architectures are getting more dynamic, and the old way of securing cloud environments with disconnected tools and static findings is no longer enough. Security leaders need more than posture snapshots. They need real-time context, runtime intelligence, and the ability to focus on what is actually exploitable. That…