CWPP
A Cloud Workload Protection Platform (CWPP) protects the workloads running within a cloud environment.
A Cloud Workload Protection Platform (CWPP) protects the workloads within the cloud itself. This includes virtual machines, containers, and serverless functions.
How it works
A CWPP monitors what is running on the workloads. It detects suspicious processes, malware, and unusual network connections. Many solutions also scan images for vulnerabilities before they are deployed. Depending on the product, it works with an agent on the system. Alternatively, it can be agentless, using snapshots of the hard disks.
A practical example
A web server in the cloud has an unpatched vulnerability. An attacker exploits it and launches a crypto-miner. The CWPP detects the unknown process with high CPU usage. It also spots connections to a mining pool. The SOC isolates the instance and secures it for investigation.
What to look out for
- Check if all workload types are covered: VMs, containers, and functions.
- Vulnerability scans before deployment are cheaper than fixes during operation.
- Short-lived containers disappear quickly. Telemetry must be stored externally.
- Integrate alerts into the SOC to link them with cloud logs and identities.
How it differs
A CWPP is comparable to an EDR for cloud workloads. Many EDR vendors now also cover cloud servers. In contrast, CSPM checks the cloud's configuration, not the operations on the systems. Together with CIEM, these functions form a CNAPP.
Typical mistakes
Often, only production environments are protected. Test and development environments, however, often have connections to production and weaker controls. A second mistake is having workloads without a clear owner. When an alert fires, nobody knows who operates the system or whether isolation is permitted.
How we implement it
We integrate alerts from your CWPP or EDR for cloud servers into our SOC. Containment is carried out within the mandate that you define.