Illustration of interconnected blue and purple servers with Kubernetes logos, creating a grid pattern. The background has a gradient from darker blue to purple. The word Upwind is visible in the top right corner.

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Denise Ashur October 16, 2024

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Upwind’s eBPF sensor is lightweight and high performance, which was recently shown in a record-breaking image scan with customer H2O.ai.

When scanning H2O.ai’s 30GB container image with multiple dependencies, the Upwind sensor consumed less than 1GB of RAM, about 3% of the image size, demonstrating how Upwind ensures comprehensive runtime security coverage with a lightweight footprint.

“The Upwind sensor’s ability to scan very large container images without hindering performance has allowed our team to effortlessly implement cloud security at runtime. Its efficiency, combined with its minimal impact on our environment, is truly groundbreaking.”

-Ophir Zahavi, Cloud Engineering Manager, H20.ai

The Upwind sensor is able to scan large container images as well as monitor real-time traffic on Layers 3, 4 and 7 while maintaining a lightweight footprint and using less than .01%-1% CPU.

To learn more about Upwind’s high-performance eBPF demo, visit the Upwind Documentation Center (login required) or schedule a demo.

Contents

Further Reading

Let Me Speak to Your Manager (Account)

Let Me Speak to Your Manager (Account)

The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…
Configuration-Focus

Introducing the new Configurations experience in Upwind

Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…
What You Could Build If IAM Let You

What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys

In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS