Upwind Cloud Scanners
Overview
Upwind Cloud Scanners operate seamlessly with our eBPF sensor-centric approach, giving organizations more flexibility to easily get deep context in areas where installing sensors can't simply happen or where it's very difficult to deploy.
This combination of real-time monitoring from the Upwind sensor, paired with comprehensive scanning from Upwind's Cloud Scanners, ensures that all aspects of your infrastructure are fully discovered and protected - and that you can be up and running in minutes, no matter the complexity of your environment.

Upwind Cloud Scanners provide comprehensive monitoring for the following cloud infrastructure categories:
- Serverless containers: AWS Fargate, Google Cloud Run, Azure Container Instances, Oracle Cloud Infrastructure (OCI) Container Instances

- Functions: AWS Lambda, Google Cloud Functions, Azure Functions, Oracle Cloud Infrastructure (OCI) Functions

- Virtual Machines: Amazon EC2 instances, Google Compute Engine instances and Azure virtual machines, including those running older OS versions
- Container images: images held in your container registries
- Kubernetes nodes: scanned as grouped workloads, where a representative node is scanned and the findings are attributed to the whole node group
- Auto Scaling Groups: scanned by sampling an instance that belongs to the group, so findings are counted once across an elastic fleet
- Object storage: Amazon S3 buckets, Google Cloud Storage buckets and Azure Blob Storage containers
- Block storage: Amazon EBS volumes
Object storage and block storage are scanned for sensitive data by Data Security, which shares the Cloud Scanner infrastructure.
Coverage differs per cloud provider, and each scan category can be enabled or disabled per region and per resource type. For the resource types and scan categories supported in AWS, Google Cloud and Azure, see Cloud scanner coverage.
Using Upwind's Cloud Scanners
Upwind's Cloud Scanners are designed to be quick to deploy, easy to operate and efficient to use. The scanners operate as autoscaling groups that scan virtual machines (VMs) in a region in which they are deployed, snapshotting every disk in a VM to scan it and find misconfigurations, malware, exposed secrets and vulnerabilities.

Agentless VM Scanning Coverage
Agentless VM scanning is available across all four supported cloud providers. In each one, the scanners run inside your own cloud environment and are deployed as part of onboarding that provider.
| Cloud Provider | Virtual Machine Service | Agentless VM Scanning | Onboarding Guide |
|---|---|---|---|
| Amazon Web Services (AWS) | Amazon EC2 | ✅ | Connect AWS |
| Microsoft Azure | Azure Virtual Machines | ✅ | Connect Azure |
| Google Cloud | Compute Engine | ✅ | Connect Google Cloud |
| Oracle Cloud (OCI) | OCI Compute | ✅ | Connect Oracle Cloud |
Setting Up Upwind's Cloud Scanners
Upwind Cloud Scanners are currently available for AWS, GCP, Azure, and OCI and have multiple deployment options, including AWS CloudFormation and Terraform. For the full deployment process, see Deployment and Configuration.
Once you have deployed Upwind Cloud Scanners, you will be able to view findings in existing modules of the Upwind Cloud Security Platform, including:
- Vulnerability Management: Scans for vulnerabilities are integrated into Upwind's vulnerability management capabilities, which display both vulnerabilities found by Upwind's Cloud Scanners and vulnerabilities found at runtime by the Upwind sensor.
- Threat Detection: Consistent malware scanning is performed by Upwind's Cloud Scanners to identify any malicious files, in addition to coverage provided by the Upwind sensor. Results from both are shown in the Threats module of the Upwind Platform.
- Cloud Security Posture: Upwind's Cloud Scanners scan for exposed secrets, exposing any findings in the Secrets tab.
- Data Security (DSPM): Upwind's Cloud Scanners statically scan your storage assets - Amazon S3 buckets, Google Cloud Storage buckets, Azure Blob Storage containers and Amazon EBS volumes - to discover and classify sensitive data such as PII, PHI, PCI data and cloud credentials. These findings are combined with runtime context, so you can see which sensitive data is publicly accessible, which workloads reach it and how it is being accessed, in the Data Security module.
- Inventory: Upwind's Cloud Scanners provide fast, comprehensive visibility into your cloud infrastructure and applications, which are viewable in the Inventory module of the Upwind Platform. You can also view and manage all of your currently deployed scanners in the Inventory module.