CWPP · scan → runtime → respond

Every workload
is a way in.

VMs, containers, serverless functions and AMIs all carry vulnerabilities, malware and secrets — and most scanners only check them once, offline. OnDuty CWPP scans every workload continuously and watches it live at runtime, with a single agentless sensor.

Six capabilities, one sensor

CWPP, grounded
in runtime truth.

Capability / 01

Agentless vulnerability scanning

Scan VMs, containers, serverless functions and AMIs for CVEs without installing an agent or slowing the pipeline.

  • 200k+ CVEs indexed
  • Package-version matching
  • Registry & runtime scanning
Capability / 02

Malware & secret detection

Catch embedded malware, cryptominers and hardcoded secrets before they ship — and flag the ones already running.

  • Signature & behavioral scans
  • Secrets in images & repos
  • Zero-day heuristics
Capability / 03

eBPF runtime sensor

A single kernel-level sensor observes process, network and file activity in real time — no sidecars, no code changes.

  • Zero-instrumentation
  • Process & syscall visibility
  • Live, not scheduled
Capability / 04

Runtime threat detection

Detect cryptominers, container escapes, privilege escalation and lateral movement, mapped to MITRE ATT&CK for cloud.

  • MITRE ATT&CK coverage
  • Anomaly & drift detection
  • Auto-correlated incidents
Capability / 05

Container & serverless coverage

Native support for Docker, containerd, Kubernetes and Lambda — wherever your workloads actually run.

  • Kubernetes-aware
  • Lambda & Fargate
  • Multi-registry support
Capability / 06

Reachability-based prioritization

A finding only matters if it's loaded and exposed. OnDuty deprioritizes what's dormant and escalates what's exploitable now.

  • Runtime reachability score
  • Exposure-aware ranking
  • Auto-deprioritization

How the platform works

From noisy scans
to a focused fix.

Unified sensor

One eBPF sensor, every workload.

Stop stitching together a VM scanner, a container tool and a separate serverless agent. OnDuty watches VMs, containers, serverless functions and AMIs through a single kernel-level sensor — no sidecars, no code changes, nothing to fall out of date.

Zero-instrumentationProcess, network & file visibilityNo sidecars, no code changes
VMs
Containers
Serverless
AMIs

Zero-instrumentation

One live sensor

Reachability analysis

Prioritize what's actually loaded and reachable.

Every CVE is scored against what's actually loaded in memory, exposed to the network and exploitable right now — not severity alone. OnDuty surfaces the handful of findings that are live and reachable, so your team stops triaging vulnerabilities that were never going to run.

Loaded at runtimeNetwork reachableExploit available

Ranked by runtime reachability

internet-facing · KEV listed
Loaded at runtime92
Network reachable81
Exploit available64
Present but dormant12

xz-utils backdoor loaded in sshd process

Top of 612 runtime-reachable CVEs

Incident grouping

One root cause, not a hundred alerts.

OnDuty automatically clusters related detections into a single incident with a clear owner and deadline. A cryptominer spun up from one base image can trigger hundreds of alerts across your fleet — OnDuty groups them so you fix the image once, not the symptom a hundred times.

Auto-grouped by root causeOwner & deadline built inKill, isolate or patch in one click
Incident · Cryptominer in base image38 workloads

Root cause: base image node:18-slim-legacy ships with a compromised build dependency that launches a miner on startup.

16 of 38 containedowner: platform-eng · due in 2 days

1 image

Fix once

38 workloads

Resolves

42%

Contained

Build to runtime

Trace every runtime finding back to its image.

OnDuty connects the dots between the image that was built, the registry it shipped through and the workload it's running in today. A live detection traces straight back to the Dockerfile or base image that introduced it, so engineering fixes the source, not just the symptom.

Build, registry & runtime linkedBlocked in CI before it shipsFindings traced to source image

Dockerfile

PR #217 · base image pinned

Image scan

Blocked in CI · critical CVE

prod-checkout

Deployed workload

Runtime finding

CVE loaded, internet-facing

OnDuty AI

AI that responds, not just detects.

OnDuty AI shortens the distance between a live detection and a contained workload. Ask a question and get back a query, not a support ticket. Let AI suggest the patch, isolate the workload or kill the process — so your team spends its time on judgment calls instead of manual response.

AI kill / isolate actionsAI patch suggestionsAutonomous AI agents

AI Patch Suggestions

Generated fixes for images & IaC

AI Discovery

Ask questions, get asset queries

AI Kill / Isolate

Contain a workload in one click

AI Agents

Investigate and act autonomously

The CWPP lifecycle

From discovery
to containment.

Phase / 01

Discover

Agentlessly find every VM, container, serverless function and AMI across your estate.

Phase / 02

Scan

Check every workload for CVEs, malware and secrets against 200k+ indexed vulnerabilities.

Phase / 03

Watch

The eBPF sensor observes process, network and file activity live, with zero instrumentation.

Phase / 04

Respond

Kill malicious processes, isolate workloads and route fixes to the owning team automatically.

FAQ

Frequently asked questions.

CWPP (Cloud Workload Protection Platform) is a security category focused on protecting the workloads that actually run your applications — VMs, containers, serverless functions and machine images (AMIs). It combines vulnerability, malware and secret scanning with live runtime detection, rather than relying on a point-in-time scan alone.

Replace four scanners with one sensor

See the exploitable 12,
not the 40,000 CVEs.

See your real workload risk, runtime detections and reachable CVEs in a 30-min guided demo with our team.

  • Agentless scanning across VMs, containers, serverless & AMIs
  • One eBPF sensor watching process, network and file activity live
  • Runtime threat detection mapped to MITRE ATT&CK for cloud
  • Reachability-based prioritization for every CVE and secret
  • Evidence for your SOC 2 · ISO 27001 · HIPAA · PCI audits