Get a Demo
Under Attack?
Sensor Improvements

Upwind Enables Smarter, More Efficient, Security with Sensor Improvements

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Chris Lentricchia October 13, 2025

We are excited to share the latest improvements to our eBPF-powered sensor, the foundation of our runtime security platform. By continuously enhancing how the sensor observes and protects Kubernetes environments, we’re making security both more effective and more efficient for our customers.

As part of this advancement, we are introducing container image scan jobs, a capability that makes Kubernetes image security faster, more reliable, and significantly more resource-efficient. Unlike static scanning tools that only run during build or registry stages, these scan jobs operate directly in the cluster, providing adaptive coverage of every running image. Orchestrated intelligently by the cluster manager, they ensure customers gain complete visibility with lower costs and faster results.

Securing Cloud-Native Environments at Scale

Cloud-native infrastructure gives organizations the speed and flexibility they need, but it also creates constant change: containers appear and disappear in seconds, microservices communicate dynamically, and clusters scale up and down on demand. These dynamics make visibility and security especially challenging for traditional tools.

Upwind was built to address this reality. By operating directly in the Linux kernel with eBPF, our platform provides real-time insight and runtime protection that keeps pace with the speed of Kubernetes. And with the addition of on-demand scan jobs, organizations can now achieve complete image coverage across their environments, without wasted resources.

The Power of the Upwind Sensor

At the core of this capability is the Upwind eBPF sensor. Running inside the Linux kernel, it captures system calls, process activity, and network behavior at the source, then enriches that data with Kubernetes and cloud provider metadata. The result is security intelligence that is both highly efficient and deeply contextual, translating raw kernel events into actionable insights tied to specific workloads and services.

Because the sensor attaches directly to kernel-level activity, there is no need for sidecars or heavy agents. This design scales naturally across clusters of any size, delivering reliable protection with minimal overhead.

CleanShot-2025-09-18-at-15.26.34@2x
The Upwind Sensor leverages eBPF to directly capture behavioral data from the Linux kernel. This data is then integrated with logging data, traces, and other information within the Upwind Backend.

CleanShot-2025-09-18-at-15.41.40@2x
By embedding supporting programs directly into the linux kernel, the Upwind Sensor avoids the need for sidecars, drastically reducing overhead

Smarter Image Scans with Adaptive Jobs

Our new scan jobs are designed specifically for the dynamic nature of Kubernetes. Unlike static scanning, these jobs are runtime-aware and orchestrated directly within the cluster. Scan jobs run only when needed, consuming resources on-demand rather than continuously. Each job automatically requests the right amount of compute for the image it is scanning, retrying with higher allocations if necessary. The cluster manager orchestrates jobs at a steady, predictable pace, ensuring every image in the environment is covered quickly and reliably.

scan-job-resource-allocation-f
The Upwind Cluster Manager orchestrates scans according to open resources

If a scan encounters an issue, the job is rescheduled without manual intervention, maintaining seamless coverage. This adaptive approach ensures consistent performance, rapid results, and a security posture that aligns with the fluidity of Kubernetes environments.

scan-jobs-diagram


From Technology to Tangible Value

For our customers, the benefits to our sensor improvements are immediate:

  • Lower costs by avoiding idle resource consumption
  • Complete coverage with every running image scanned successfully
  • Faster detection of risks, reducing the window of exposure
  • Simpler operations through intelligent orchestration and automation

These improvements deliver stronger, more predictable security while aligning with the agility of cloud-native infrastructure.

Final Thoughts

With the latest improvements to our eBPF-powered sensor, Upwind continues to raise the standard for runtime security in Kubernetes. The introduction of adaptive scan jobs makes image scanning faster, more reliable, and more cost-efficient, ensuring complete coverage without wasted resources.

The result is a stronger security posture that combines deep kernel-level visibility with intelligent orchestration. Customers gain the clarity, speed, and efficiency they need to protect dynamic cloud-native environments at scale.

image-2
Upwind Sensors enable more efficient and smarter security by improving CPU consumption. A sensor monitoring a GKE cluster uses only 0.35% of the node’s CPU capacity.

See it in Action

The best way to understand these improvements is to see them for yourself. Upwind’s eBPF-powered sensor and adaptive scan jobs deliver real-time visibility, reliable image scanning, and cost efficiency that scales with Kubernetes.Schedule a demo with our team to see how Upwind can strengthen your security posture and simplify runtime protection.

Contents

Further Reading

KSPM-Agentless-Scanning

Complete KSPM: From Pull Request to Production Runtime

Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…
Upwind MCP Server

Revolutionizing Security Investigations with the Upwind MCP Server

Frontier AI models combined with a rampant rate of new critical vulnerabilities mean speed and context are everything. When a critical production service starts behaving suspiciously, every second spent jumping between different tools and dashboards is a second lost to a potential attacker. At Upwind, we are excited to introduce a game-changer for security teams:…
Security Feed - Threat

No npm Token Required: Inside the AsyncAPI Supply Chain Attack

Executive Summary Upwind identified a critical supply chain compromise across five npm packages in the @asyncapi scope, published on July 14, 2026 via two separate branch compromises in two GitHub repositories. The attacker never touched an npm token. They abused each project's own CI pipeline through GitHub Actions OIDC to publish the malicious packages. The…