Get a Demo
Under Attack?
Illustration of interconnected blue and purple servers with Kubernetes logos, creating a grid pattern. The background has a gradient from darker blue to purple. The word Upwind is visible in the top right corner.

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur October 16, 2024

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Upwind’s eBPF sensor is lightweight and high performance, which was recently shown in a record-breaking image scan with customer H2O.ai.

When scanning H2O.ai’s 30GB container image with multiple dependencies, the Upwind sensor consumed less than 1GB of RAM, about 3% of the image size, demonstrating how Upwind ensures comprehensive runtime security coverage with a lightweight footprint.

“The Upwind sensor’s ability to scan very large container images without hindering performance has allowed our team to effortlessly implement cloud security at runtime. Its efficiency, combined with its minimal impact on our environment, is truly groundbreaking.”

-Ophir Zahavi, Cloud Engineering Manager, H20.ai

The Upwind sensor is able to scan large container images as well as monitor real-time traffic on Layers 3, 4 and 7 while maintaining a lightweight footprint and using less than .01%-1% CPU.

To learn more about Upwind’s high-performance eBPF demo, visit the Upwind Documentation Center (login required) or schedule a demo.

Contents

Further Reading

API-ASM Blog

Validate the Real-World Exposure of Your APIs with Upwind Attack Surface Management

Your APIs are probably the least-monitored component of your attack surface. They multiply faster than any team can document, and most scanners only ever pick up the ones you already know about. But that gap just got smaller. Upwind’s Attack Surface Management capabilities now provide a unified view of cloud and API exposure, helping security…
gemini-svg

Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Executive Summary Upwind recently observed multiple Advanced Persistent Threat (APT) groups actively exploiting CVE-2026-72898. This vulnerability - an unauthenticated SQL injection in the Metabase password reset endpoint carrying a critical CVSS score of 10.0, was actively exploited as a zero-day before a patch became available. An unauthenticated remote attacker can craft a malicious SQL injection…
Buyers Demos

Why Buyers Remember Solving a Demo, Not Watching One

Key Takeaways I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS