Agentless vulnerability scanning
Scan VMs, containers, serverless functions and AMIs for CVEs without installing an agent or slowing the pipeline.
- 200k+ CVEs indexed
- Package-version matching
- Registry & runtime scanning
VMs, containers, serverless functions and AMIs all carry vulnerabilities, malware and secrets — and most scanners only check them once, offline. OnDuty CWPP scans every workload continuously and watches it live at runtime, with a single agentless sensor.
Six capabilities, one sensor
Scan VMs, containers, serverless functions and AMIs for CVEs without installing an agent or slowing the pipeline.
Catch embedded malware, cryptominers and hardcoded secrets before they ship — and flag the ones already running.
A single kernel-level sensor observes process, network and file activity in real time — no sidecars, no code changes.
Detect cryptominers, container escapes, privilege escalation and lateral movement, mapped to MITRE ATT&CK for cloud.
Native support for Docker, containerd, Kubernetes and Lambda — wherever your workloads actually run.
A finding only matters if it's loaded and exposed. OnDuty deprioritizes what's dormant and escalates what's exploitable now.
How the platform works
Stop stitching together a VM scanner, a container tool and a separate serverless agent. OnDuty watches VMs, containers, serverless functions and AMIs through a single kernel-level sensor — no sidecars, no code changes, nothing to fall out of date.
Zero-instrumentation
One live sensor
Every CVE is scored against what's actually loaded in memory, exposed to the network and exploitable right now — not severity alone. OnDuty surfaces the handful of findings that are live and reachable, so your team stops triaging vulnerabilities that were never going to run.
Ranked by runtime reachability
internet-facing · KEV listedxz-utils backdoor loaded in sshd process
Top of 612 runtime-reachable CVEs
OnDuty automatically clusters related detections into a single incident with a clear owner and deadline. A cryptominer spun up from one base image can trigger hundreds of alerts across your fleet — OnDuty groups them so you fix the image once, not the symptom a hundred times.
Root cause: base image node:18-slim-legacy ships with a compromised build dependency that launches a miner on startup.
1 image
Fix once
38 workloads
Resolves
42%
Contained
OnDuty connects the dots between the image that was built, the registry it shipped through and the workload it's running in today. A live detection traces straight back to the Dockerfile or base image that introduced it, so engineering fixes the source, not just the symptom.
Dockerfile
PR #217 · base image pinned
Image scan
Blocked in CI · critical CVE
prod-checkout
Deployed workload
Runtime finding
CVE loaded, internet-facing
OnDuty AI shortens the distance between a live detection and a contained workload. Ask a question and get back a query, not a support ticket. Let AI suggest the patch, isolate the workload or kill the process — so your team spends its time on judgment calls instead of manual response.
AI Patch Suggestions
Generated fixes for images & IaC
AI Discovery
Ask questions, get asset queries
AI Kill / Isolate
Contain a workload in one click
AI Agents
Investigate and act autonomously
The CWPP lifecycle
Agentlessly find every VM, container, serverless function and AMI across your estate.
Check every workload for CVEs, malware and secrets against 200k+ indexed vulnerabilities.
The eBPF sensor observes process, network and file activity live, with zero instrumentation.
Kill malicious processes, isolate workloads and route fixes to the owning team automatically.
FAQ
CWPP (Cloud Workload Protection Platform) is a security category focused on protecting the workloads that actually run your applications — VMs, containers, serverless functions and machine images (AMIs). It combines vulnerability, malware and secret scanning with live runtime detection, rather than relying on a point-in-time scan alone.
Related solutions
OnDuty is one platform on a single graph. Here's where the rest of it connects.
Replace four scanners with one sensor
See your real workload risk, runtime detections and reachable CVEs in a 30-min guided demo with our team.