Skip to main content

Upwind Cloud Scanners

Overview

Upwind Cloud Scanners operate seamlessly with our eBPF sensor-centric approach, giving organizations more flexibility to easily get deep context in areas where installing sensors can't simply happen or where it's very difficult to deploy.

This combination of real-time monitoring from the Upwind sensor, paired with comprehensive scanning from Upwind's Cloud Scanners, ensures that all aspects of your infrastructure are fully discovered and protected - and that you can be up and running in minutes, no matter the complexity of your environment.

scanner-architecture.png

Upwind Cloud Scanners provide comprehensive monitoring for the following cloud infrastructure categories:

  • Serverless containers: AWS Fargate, Google Cloud Run, Azure Container Instances, Oracle Cloud Infrastructure (OCI) Container Instances

serverless.png

  • Functions: AWS Lambda, Google Cloud Functions, Azure Functions, Oracle Cloud Infrastructure (OCI) Functions

functions.png

  • Virtual Machines: Amazon EC2 instances, Google Compute Engine instances and Azure virtual machines, including those running older OS versions
  • Container images: images held in your container registries
  • Kubernetes nodes: scanned as grouped workloads, where a representative node is scanned and the findings are attributed to the whole node group
  • Auto Scaling Groups: scanned by sampling an instance that belongs to the group, so findings are counted once across an elastic fleet
  • Object storage: Amazon S3 buckets, Google Cloud Storage buckets and Azure Blob Storage containers
  • Block storage: Amazon EBS volumes

Object storage and block storage are scanned for sensitive data by Data Security, which shares the Cloud Scanner infrastructure.

note

Coverage differs per cloud provider, and each scan category can be enabled or disabled per region and per resource type. For the resource types and scan categories supported in AWS, Google Cloud and Azure, see Cloud scanner coverage.

Using Upwind's Cloud Scanners

Upwind's Cloud Scanners are designed to be quick to deploy, easy to operate and efficient to use. The scanners operate as autoscaling groups that scan virtual machines (VMs) in a region in which they are deployed, snapshotting every disk in a VM to scan it and find misconfigurations, malware, exposed secrets and vulnerabilities.

customer-cloud-accounts.png

Agentless VM Scanning Coverage

Agentless VM scanning is available across all four supported cloud providers. In each one, the scanners run inside your own cloud environment and are deployed as part of onboarding that provider.

Cloud ProviderVirtual Machine ServiceAgentless VM ScanningOnboarding Guide
Amazon Web Services (AWS)Amazon EC2Connect AWS
Microsoft AzureAzure Virtual MachinesConnect Azure
Google CloudCompute EngineConnect Google Cloud
Oracle Cloud (OCI)OCI ComputeConnect Oracle Cloud

Setting Up Upwind's Cloud Scanners

Upwind Cloud Scanners are currently available for AWS, GCP, Azure, and OCI and have multiple deployment options, including AWS CloudFormation and Terraform. For the full deployment process, see Deployment and Configuration.

Once you have deployed Upwind Cloud Scanners, you will be able to view findings in existing modules of the Upwind Cloud Security Platform, including:

  • Vulnerability Management: Scans for vulnerabilities are integrated into Upwind's vulnerability management capabilities, which display both vulnerabilities found by Upwind's Cloud Scanners and vulnerabilities found at runtime by the Upwind sensor.
  • Threat Detection: Consistent malware scanning is performed by Upwind's Cloud Scanners to identify any malicious files, in addition to coverage provided by the Upwind sensor. Results from both are shown in the Threats module of the Upwind Platform.
  • Cloud Security Posture: Upwind's Cloud Scanners scan for exposed secrets, exposing any findings in the Secrets tab.
  • Data Security (DSPM): Upwind's Cloud Scanners statically scan your storage assets - Amazon S3 buckets, Google Cloud Storage buckets, Azure Blob Storage containers and Amazon EBS volumes - to discover and classify sensitive data such as PII, PHI, PCI data and cloud credentials. These findings are combined with runtime context, so you can see which sensitive data is publicly accessible, which workloads reach it and how it is being accessed, in the Data Security module.
  • Inventory: Upwind's Cloud Scanners provide fast, comprehensive visibility into your cloud infrastructure and applications, which are viewable in the Inventory module of the Upwind Platform. You can also view and manage all of your currently deployed scanners in the Inventory module.