Get a Demo
Under Attack?
Azure Container Service Tracer

Upwind Runtime Protection Now Supports Azure

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Danilo Michelucci March 04, 2026

Cloud teams are moving fast on Azure PaaS to reduce operational overhead—serverless containers with Azure Container Apps and managed web apps with Azure App Services. But that speed often comes with a tradeoff: security visibility and detection can lag behind because you don’t have the same host access or deployment patterns you’d expect in Kubernetes or traditional VM-based workloads.

Upwind now extends runtime protection to both Azure Container Apps and Azure App Services, bringing the same real-time visibility, detections, and risk prioritization you rely on for containers and Kubernetes—now tailored for Azure’s PaaS application layers.

What you get with Upwind runtime protection for Azure

azure-services-d-1024x556

1) Discover assets automatically

Once connected, Upwind can discover Azure Container Apps and Azure App Services assets and surface them directly in the platform—so these workloads are no longer “outside” your runtime coverage.

2) Visualize apps and connections in the Map

Azure PaaS environments can feel abstract: apps talk to services, services talk to APIs, and dependencies spread quickly.

Upwind makes it concrete by showing:

  • Applications and their connections
  • Communication paths across your environment
  • A clearer picture of blast radius when something suspicious happens
azure-services-a-1024x556

3) Deep runtime visibility: process + network activity

Upwind continuously collects runtime activity so you can see:

  • Process behavior (what’s running, how it’s behaving)
  • Network activity (who is talking to whom, when, and how)
azure-services-b-1024x557

This is critical for PaaS workloads where static configuration checks or pre-deploy scanning alone can’t capture what’s actually happening in production.

4) Real-time detections and risk prioritization

Runtime activity feeds Upwind’s detections so you can:

  • Identify threats as they happen
  • Prioritize issues with runtime evidence
  • Move from “possible exposure” to actionable risk

Why this matters for serverless container and PaaS application security

Azure Container Apps and App Services are designed to abstract infrastructure complexity—great for developers, challenging for security.

By extending runtime coverage to these platforms, Upwind helps you:

  • Maintain consistent runtime security across Kubernetes, containers, and Azure PaaS
  • Reduce blind spots introduced by “managed” execution environments
  • Detect suspicious behavior based on real execution, not assumptions

Flexible deployment options for Azure Container Apps

To support different environment sizes and onboarding preferences, Upwind provides two ways to connect Azure Container Apps:

Option 1: Cluster Manager + Tracer (recommended)

Best for: larger environments or teams that want centralized operations

This model enables:

  • Centralized management
  • Full runtime visibility across all applications
  • Aggregation and standardization of runtime signals

Option 2: Tracer Only

Best for: smaller environments, fast onboarding, or direct setup

This model allows:

  • Direct reporting to the backend
  • A lighter operational footprint for getting coverage quickly

Azure App Services runtime monitoring with the Upwind Tracer

For Azure App Services, Upwind supports runtime monitoring through Tracer deployment, enabling you to:

  • Discover protected App Services automatically
  • Visualize them in the Map
  • Turn on detections with deep process and network visibility
  • Deploy protection for a single application or in bulk across the environment

What teams can do immediately with this feature

  • Spot suspicious runtime behavior in App Services and serverless containers
  • Trace unexpected outbound connections from a single app to external endpoints
  • Validate whether a workload is performing actions it shouldn’t (process execution, unusual network patterns)
  • Prioritize risk based on runtime context, not just inventory

See It It In Action

If you’d like to see how this feature fits into your environment – or to explore how Upwind can help you prioritize and remediate risk more effectively – schedule a customized demo with us. We’ll walk through your use cases, integrations, and security goals to show how Upwind delivers actionable cloud security at scale.

Contents

Further Reading

ArgoCD repoURL XSS

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover (CVE-2026-62341)

Executive Summary  CVE-2026-62341 is a stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.6] that lets an attacker who can create or modify an Application persist a malicious repoURL, which then executes in an administrator's browser inside the ArgoCD origin. Because the payload rides the admin's authenticated session, and because ArgoCD's controller typically runs…
The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS