Illustration of interconnected blue and purple servers with Kubernetes logos, creating a grid pattern. The background has a gradient from darker blue to purple. The word Upwind is visible in the top right corner.

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Denise Ashur October 16, 2024

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Upwind’s eBPF sensor is lightweight and high performance, which was recently shown in a record-breaking image scan with customer H2O.ai.

When scanning H2O.ai’s 30GB container image with multiple dependencies, the Upwind sensor consumed less than 1GB of RAM, about 3% of the image size, demonstrating how Upwind ensures comprehensive runtime security coverage with a lightweight footprint.

“The Upwind sensor’s ability to scan very large container images without hindering performance has allowed our team to effortlessly implement cloud security at runtime. Its efficiency, combined with its minimal impact on our environment, is truly groundbreaking.”

-Ophir Zahavi, Cloud Engineering Manager, H20.ai

The Upwind sensor is able to scan large container images as well as monitor real-time traffic on Layers 3, 4 and 7 while maintaining a lightweight footprint and using less than .01%-1% CPU.

To learn more about Upwind’s high-performance eBPF demo, visit the Upwind Documentation Center (login required) or schedule a demo.

Contents

Further Reading

Upwind-Sentinel

Upwind for Microsoft Sentinel – Available on Marketplace and Security Store

Security teams should not have to switch between tools to understand what is happening across their cloud environments. That’s why we’re excited to announce that the Upwind solution for Microsoft Sentinel is now available through the Microsoft Marketplace and the Microsoft Security Store. The integration brings Upwind security data directly into Microsoft Sentinel, helping security…
You Can't Crowdsource Your Way to a Live Adversary

You Can’t Crowdsource Your Way to a Live Adversary

Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…
arrayref Supply Chain Attack

arrayref Supply Chain Attack: A One-Line Build Dependency Ran a Backdoor During cargo build

Key Takeaways Executive Summary arrayref 0.3.10 is a hijacked release of a widely used Rust utility crate that added one dependency, proc-macro1, whose build script downloaded and executed a remote binary at compile time. The release was live on crates.io for 86 minutes on August 20, 2026, alongside [email protected] and [email protected] published from the same…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS