
Cloud SecurityContainer Security
Uptycs CNAPP
Unified CNAPP combining agentless scanning, eBPF runtime protection, and a security data lake.
Uptycs CNAPP Overview
What it does
Uptycs CNAPP is a Cloud-Native Application Protection Platform (CNAPP) that secures hybrid cloud environments from development through runtime. The platform combines agentless scanning with eBPF-based runtime protection and consolidates telemetry from cloud accounts, workloads, containers, and Kubernetes clusters into a unified security data lake with a single console and policy framework. Attack path mapping correlates vulnerabilities, misconfigurations, and identity exposure to show routes to critical assets and trace runtime threats back to committed code.
How it works
Agentless cloud connections assess posture across AWS, Azure, Google Cloud, and IBM Cloud, while an optional lightweight sensor instruments workloads at the kernel level with eBPF, monitoring file, process, and network activity in real time. Osquery-based fleet management gives analysts structured queries across the estate, and build-to-runtime context links container images, code repositories, and CI/CD pipelines to what runs in production. Gatekeeper admission policies control Kubernetes deployments, the Juno AI Analyst assistant produces evidence-backed investigations, and out-of-the-box reports cover SOC 2, CIS Benchmarks, PCI DSS, NIST, FedRAMP, and HITRUST.
Credentials and traction
Uptycs maintains SOC 2 Type II compliance and was named a Representative Vendor in the 2025 Gartner Market Guide for Cloud-Native Application Protection Platforms. Customers include Comcast, Lookout, and Greenlight Financial, with Comcast deploying the platform at large scale as a component of its security posture. Uptycs targets enterprises operating large hybrid cloud, container, and Kubernetes estates.
Key Capabilities
mapped to solution categoriesDiscovers and classifies sensitive data in IaaS and PaaS stores such as object storage, databases, and data warehouses, surfacing data exposure risk alongside infrastructure findings.
Instruments workload behavior at the kernel level via eBPF without a traditional user-space agent. Provides syscall-level visibility into process execution, network connections, and file access in running containers and VMs.
Exports compliance evidence pre-mapped to framework control requirements (SOC 2, ISO 27001, PCI DSS), in formats auditors can consume directly: not raw CSV exports requiring manual assembly.
Monitors running pod and container behavior against policy, detecting unexpected process execution, network connections, and privilege escalation at runtime rather than at image scan time.
Assesses the configuration of Kubernetes clusters and managed orchestrators (EKS, AKS, GKE, ECS, Fargate, OpenShift) against best-practice templates, surfacing cluster misconfigurations, weak RBAC, exposed control planes and configuration drift, and driving their remediation. Distinct from runtime workload monitoring: this is the posture of the orchestrator itself.
Maps the effective access of human and machine identities to compute, storage and data resources across AWS, Azure and GCP as an access relationship graph, surfacing over-permissioned roles, unused permissions, cross-account trust and toxic combinations of administrator permissions, and remediating them toward least privilege, including automatic revocation of excessive roles.
Enforces a single policy definition across AWS, Azure, and GCP resource types, translating to provider-native configurations rather than requiring separate policy sets per cloud.
Scans infrastructure-as-code templates (Terraform, CloudFormation, Kubernetes manifests and Helm charts) for misconfigurations, policy violations and embedded secrets before deployment, gates CI/CD pipelines on the resulting risk, and detects drift between the IaC definition and the deployed resource. Depth of productized pipeline integration and drift remediation varies across products.
Continuously audits cloud and Kubernetes configuration across AWS, Azure, and GCP against security benchmarks, flagging misconfigurations and identity-permission gaps that create exploitable exposures.
Correlates individual misconfigurations, CVEs and excessive entitlements into chained attack scenarios showing lateral movement paths from an exposed entry point to a target asset, visualized on the resource graph. Produces a prioritized list of attack paths rather than a flat CVE inventory. Products differ in whether they show only possible paths derived from posture data or also actual paths confirmed from runtime and log telemetry.
Delivers scan results inside developer IDEs and pipeline stages so developers receive findings before code merges, reducing the cost and cycle time of remediation.
Reads cloud volume snapshots out-of-band to assess workloads for vulnerabilities, malware, exposed secrets and misconfigurations without installing agents or touching running instances, on a configurable scan schedule. Coverage of Windows threat detection and file integrity checks in agentless mode varies across products.
Analyzes container images and dependencies for CVEs, malicious or compromised packages, and SBOM generation across the build pipeline.
Provides AI copilots or agents inside the platform that search product documentation, triage and investigate alerts with plain-language explanations, discover threats and indicators of attack from telemetry, and generate remediation steps, policies and playbooks. Products differ in which of these tasks the copilot performs and how much of the investigation it completes on its own.
Aggregates posture findings and policy enforcement across multiple cloud accounts, subscriptions, and projects from a single control plane, critical for organizations with 10+ cloud accounts.
Applies the same posture policies and compliance benchmarks used against live cloud accounts to Terraform, CloudFormation, ARM templates and Pulumi configurations at pull-request or pipeline time, so a misconfiguration is caught before it appears in the deployed posture. Pipeline gating, secrets detection and drift remediation in IaC scripts are separate IaC security capabilities.
Maps detected misconfigurations to specific control requirements across CIS Benchmarks, NIST 800-53, SOC 2, PCI DSS, HIPAA, and ISO 27001 in a single assessment pass.
Automatically corrects specific misconfiguration types (enabling or enforcing S3 bucket encryption, correcting overly permissive security group rules), with or without approval workflow based on risk tier.
Records approved exceptions and risk acceptances for specific findings, resources or policies, with owner, justification and expiry, so accepted risk is excluded from posture scores and reports without deleting the underlying evidence, and expired exceptions resurface automatically.
Audits configuration, compliance and entitlements on cloud platforms beyond AWS, Azure and Google Cloud, including Alibaba Cloud, Oracle Cloud Infrastructure, Tencent Cloud, IBM Cloud and OpenStack, using the same policy set applied to the hyperscalers. Which secondary platforms are supported, and at what check depth, varies significantly across products.
Audits cloud service configurations across AWS, Azure, and GCP against security best practices and benchmarks, flagging misconfigurations such as public storage, permissive network rules, and disabled logging. Coverage breadth and per-service depth vary significantly across products.
Continuously discovers and inventories cloud resources across accounts, subscriptions and projects so posture assessment runs against a current, complete picture of the environment rather than a stale or partial asset list, and groups resources into collections by custom tags and account scope for targeted policies and reports. Coverage of newer and less common resource types varies across products.
Chains misconfigurations, exposed network paths, vulnerable assets and excessive entitlements into possible attack paths from internet-facing entry points to sensitive resources, visualized on the cloud resource graph, so posture findings are prioritized by exploitability rather than severity alone. Built from configuration and identity posture data rather than runtime telemetry.
Monitors critical operating system, application and configuration files on workloads for unauthorized changes, alerting on modifications that indicate tampering, persistence or compliance drift. Delivered through an agent on Windows and Linux hosts and, in some products, agentlessly; agentless and Windows coverage vary across products.
Enforces pod security standards, network policies and RBAC controls across Kubernetes clusters, blocks non-compliant or unscanned images at admission control, and detects policy drift on managed orchestrators (EKS, AKS, GKE, ECS, Fargate) using best-practice configuration templates.
Detects and remediates malware and ransomware on running virtual machines and container hosts across Windows and Linux, combining file scanning with behavioral indicators such as mass encryption, with the option of automated quarantine or process termination. Distinct from memory protection: this covers malicious files and payloads rather than in-memory exploitation techniques.
Scans container image layers for OS package CVEs and application dependency vulnerabilities at build time, registry push, or pre-deployment, before execution.
Captures a continuous record of workload events (process, network, file, syscall) for forensic investigation of incidents in running workloads.
Detects hardcoded credentials, API keys, and tokens left in running workloads and their file systems, so exposed secrets can be rotated before an attacker uses them for lateral movement.
Assesses virtual machines, containers and serverless functions for vulnerabilities, malware, exposed secrets and misconfigurations by reading disk snapshots and cloud provider APIs, without deploying an agent, on a configurable scan frequency. Covers workloads where an agent cannot be installed, at the cost of point-in-time rather than real-time visibility. Malware detection, file integrity monitoring and Windows threat coverage in agentless mode vary across products.
Monitors process execution, network connections and file system activity in running workloads through a kernel agent, eBPF sensor or sidecar container to detect behavioral anomalies and known attack patterns, including runtime privilege escalation, container escape attempts and unusual outbound network activity. This is the agent-based workload protection archetype; kernel-based versus non-kernel detection methods and Windows versus Linux coverage vary across products.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
See how Uptycs CNAPP fits your stack
Add Uptycs CNAPP to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.