-

Sysdig Delivers Industry's First CNAPP with End-to-End Detection and Response

Introduces agentless cloud detection based on open source Falco, extending CDR beyond workload agents to Cloud, GitHub, and Okta logs

SAN FRANCISCO & WASHINGTON--(BUSINESS WIRE)--Gartner Security and Risk Summit Sysdig, the leader in cloud security powered by runtime insights, today announced end-to-end detection and response embedded in its CNAPP. The company is the first vendor to deliver the consolidation of cloud detection and response (CDR) and Cloud-Native Application Protection Platforms (CNAPP), leveraging the power of open source Falco in both agent and agentless deployment models. This approach enables Sysdig to be the only CNAPP platform that can detect threats instantly anywhere in the cloud with 360-degree visibility and correlation across workloads, identities, cloud services, and third-party applications.

As organizations build out their cloud environments, they face sprawl, with hundreds of unchecked and potentially vulnerable applications, services, and identities. Most cloud security tools are slow to identify suspicious behavior, and once alerted organizations can spend hours, if not days, combing through snapshots trying to piecemeal together what happened. It is a best-case scenario for bad actors, gifting them hours or even days to inflict maximum damage – and the organization might never know what happened.

Embedding CDR in CNAPP

Teams need a CNAPP that instantly and continuously understands the full context of the entire environment. With today's announcement, Sysdig is consolidating CDR and CNAPP, giving teams a single platform that understands the entire application life cycle, puts the application at the center, and consolidates security tools around it. Using its runtime insights – knowledge of what is in use at production – Sysdig makes better-informed decisions across the software life cycle.

Stop Breaches Instantly with End-to-End Threat Detection

  • Agentless cloud detection based on Falco: Created by Sysdig, Falco is a widely adopted open source solution for cloud threat detection, now under the stewardship of the Cloud Native Computing Foundation. Previously, to leverage the power of Falco within Sysdig, organizations had to deploy Falco on their infrastructure. With the release today, customers can access an agentless deployment of Falco when processing cloud logs, which are used to detect threats across cloud, identity, and the software supply chain, along with other sources.
  • Identity threat detection: With new Sysdig Okta detections, security teams can protect against identity attacks, such as multifactor authentication fatigue caused by spamming and account takeover. Sysdig details the entire attack from user to impact by stitching Okta events with real-time cloud and container activity.
  • Software supply chain detection: Extend threat detection into the software supply chain with new Sysdig GitHub detections. Developers and security teams can be alerted in real time of critical events, such as when a secret is pushed into a repository.
  • Enhanced Drift Control: Prevent common runtime attacks by dynamically blocking executables that were not in the original container.

Accelerate Cloud Investigations and Incident Response in Real Time

  • Live mapping: Sysdig brings an endpoint detection and response (EDR)-like approach of assembling all relevant real-time events into one view when a breach occurs. With Kubernetes Live, teams can dynamically see their live infrastructure and workloads, as well as the relationships between them, to speed incident response.
  • Attack lineage with context: Sysdig Process Tree enables the rapid identification and eradication of threats by unveiling the attack journey from user to process, including process lineage, container and host information, malicious user details, and impact.
  • Curated threat dashboards: Dashboards provide a centralized view of critical security issues, spotlighting events across clouds, containers, Kubernetes, and hosts to enable threat prioritization in real time. Sysdig also provides dynamic mapping against the MITRE framework for cloud-native environments, so security teams know exactly what is happening at any given moment.

What Customers are Saying

"Due to the nature of our product, Noteable is a target for cryptojacking attacks. Sysdig is the best at cloud detection and response. They are the only vendor that provides a complete platform with multiple defense layers to detect abnormal activity in real time and surface appropriate context so that we understand the possible impact and can respond quickly,” said Pierre Brunelle, CEO at Noteable.

“In the cloud, everything happens fast. Time is of the essence when stopping attacks. Breaches can be very costly. Sysdig enables us to quickly detect and respond to cloud attacks at cloud speed by knowing what is happening, the exact container or location in the cloud, and what is causing it, versus hours to detect and understand what needs to be done,” said Karl Maire, Platform Tech Team Lead at Fuel50.

Resources

About Sysdig

Sysdig helps companies secure and accelerate innovation in the cloud. Powered by runtime insights, the cloud security platform stops threats in real time and reduces vulnerabilities by up to 95%. Rooted in runtime, the company created Falco, the open source solution for cloud threat detection. By knowing what is running in production, dev and security teams can focus on the risks that matter most. From shift left to shield right, the most innovative companies around the world rely on Sysdig to prevent, detect, and respond at cloud speed.

Contacts

Sysdig Press
press@sysdig.com
703-473-4051

Sysdig


Release Summary
Sysdig is the only CNAPP to detect threats instantly with 360-degree visibility and correlation across the cloud fabric.
Release Versions

Contacts

Sysdig Press
press@sysdig.com
703-473-4051

Social Media Profiles
More News From Sysdig

Amid Global Expansion and >330% Growth of Sysdig Sage™ AI, Sysdig Appoints Gary Olson CRO and Crendal Kear CBO

SAN FRANCISCO--(BUSINESS WIRE)--Sysdig, the leader in real-time cloud security, today announced the appointment of Gary Olson as Chief Revenue Officer (CRO) and Crendal Kear as Chief Business Officer (CBO) following a remarkable 337% growth in Sysdig Sage™ user adoption over the last eight months. Sysdig Sage, the industry’s first agentic artificial intelligence (AI) cloud security analyst, uses multi-step reasoning and contextual awareness to help security teams find, understand, and fix issue...

Sysdig Usage Report Reveals that Machine Identities Outnumber Humans 40,000 to 1, Presenting a Major Challenge to Enterprise Security

SAN FRANCISCO--(BUSINESS WIRE)--Sysdig, the leader in real-time cloud security, today released its “2025 Cloud-Native Security and Usage Report.” The company’s annual user analysis provides in-depth insights into real-world cloud security and usage trends, highlighting significant enterprise security progress while identifying key areas that demand urgent attention. The report reveals that organizations of every size and industry across North America; Europe, the Middle East, and Africa; and th...

Sysdig Unveils Stratoshark, Enabling Millions of Network Professionals to Bring Their Security Experience to the Cloud

BRUSSELS--(BUSINESS WIRE)--FOSDEM 2025 – Sysdig, the leader in real-time cloud security, today announced the release of Stratoshark, an open source tool that extends Wireshark’s granular network visibility into the cloud and empowers users with a standardized approach to cloud observability. For 27 years, Wireshark – with over 5 million daily users and more than 160 million downloads in the last decade alone – has helped users analyze network traffic and troubleshoot issues. As companies have t...
Back to Newsroom