CNAPP / CSPM / Upwind

Upwind

Upwind combines runtime sensing with agentless cloud assessment to provide context about running applications and exposure. Live inventory and process evidence can help a team understand how a workload behaves. They also depend on sensor placement, supported environments and the quality of the signals actually collected.

Runtime-focused CNAPPResearch reviewed

What you are evaluating

This profile covers the documented CNAPP approach, including agentless assessment and separately deployed runtime sensors. Verify platform and workload support in a lab; marketing claims about detection speed or reduced noise are not independent performance evidence.

A useful evaluation context

A team that needs runtime context can evaluate whether the collected signals justify the sensor deployment and ongoing operating work.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Agentless scanning contributes cloud configuration and workload assessment information where supported.
  • Runtime sensors and eBPF-related detection provide live behavior and workload context on supported deployments.
  • The platform describes combined posture, workload and AI-related inventory capabilities, with scope dependent on the selected integration and sensor.

Where it fits in the work

  1. Inventory a small cloud lab and choose the workloads where runtime evidence is necessary to answer a specific security question.
  2. Deploy the supported sensor and compare its live inventory with the known applications, processes and network relationships.
  3. Correlate one benign runtime event with an agentless finding, recording which source supports each conclusion and which assets remain uninstrumented.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Run a documented harmless process or network event on an isolated, instrumented workload while maintaining a known inventory of uninstrumented controls.

Evidence to look for

The event is attributed to the correct workload, sensor health is visible, and the report clearly distinguishes observed assets from coverage gaps.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which kernels, workload types and managed services support the required runtime behavior?
  2. How is an absent or unhealthy sensor distinguished from an application with no detected activity?
  3. Which AI inventory or posture functions are actually available, and do they inspect behavior or only describe deployed resources?

Find your next idea.

Tip: press / to open search. Escape closes this window.