Screenshot of a software interface showing a network map with connected nodes labeled as various systems like microservice_demo and Cartservice. The interface displays details of a node, including service issues and resource usage, against a gradient background.

Identify Threats and Risks in an Istio-based Kubernetes Environment

Denise Ashur October 18, 2023

Identify Threats and Risks in an Istio-based Kubernetes Environment

We are excited to announce a new capability – Istio awareness. 

Istio allows organizations to secure, connect and monitor traffic to your microservices. Starting today, Upwind will identify Istio sidecars and proxies and use this information as context for our threat detection and risk prioritization engine. Upwind can now understand entire network flows, all the way from the endpoint (source) through virtual network devices such as Load Balancers, Istio Proxies and more. 

Understanding what resources do and how they behave helps to secure them and spot threats early, providing pivotal insights for forensic analysis to trace network flows and pinpoint vulnerabilities.

Contents

Further Reading

What IAM Sees That You Don't

What IAM Sees That You Don’t

Every IAM policy you write depends on condition keys - they're the precision layer that turns "can call S3" into "can call S3 only from our VPC, using our identity, on resources we own." They're the backbone of least-privilege, data perimeters, and SCP guardrails. But here's the thing: for every request, the IAM engine assembles…
Let Me Speak to Your Manager (Account)

Let Me Speak to Your Manager (Account)

The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…
Configuration-Focus

Introducing the new Configurations experience in Upwind

Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS