Skip to main content

Cloud Security Integrations

Integrate your cloud security platforms with RAD Security to bring CNAPP signals — cloud threat detections and cloud runtime activity events — into a single, correlated view alongside your runtime and Kubernetes security data. These integrations are read-only. RAD Security pulls cloud threats and runtime activity events from your provider on a scheduled basis to power unified threat detection and investigation. RAD never writes to or modifies your cloud security platform.

Benefits

Cloud Threat Visibility

Surface cloud threats and detections alongside runtime and Kubernetes signals for end-to-end coverage.

Runtime Activity

Ingest cloud runtime activity — process, network, DNS, and cloud events — to see what is actually happening across your workloads.

Correlated Analysis

Correlate cloud threats and activity with runtime detections to prioritize what matters.

RADBot Prioritization

Let RADBot triage cloud threats and activity by real-world impact.

Supported Integrations

Status: AvailableView Setup Guide →Connect Upwind to RAD Security to ingest cloud threats and cloud runtime activity events.Key Features:
  • Cloud threats and detections
  • Cloud runtime activity events (process, network, DNS, cloud)
  • OAuth 2.0 client-credentials authentication
  • Scheduled, read-only data ingestion

What Data is Collected

  • Cloud threat detections and alerts
  • Suspicious activity in cloud workloads (OCSF Detection Findings)
  • Cloud runtime activity — process, network, DNS, and cloud events
  • Mapped to OCSF Activity events and stored alongside RAD’s other activity feeds

Use Cases

Threat Investigation

Investigate cloud threats with context from runtime and Kubernetes detections.

Runtime Activity Monitoring

Track cloud runtime activity — process, network, and DNS events — to understand workload behavior.

Correlated Detection

Correlate cloud threats and activity with RAD runtime signals to cut through the noise.

RADBot Prioritization

Leverage RADBot to prioritize cloud threats based on real-world impact.

Getting Started

1

Choose Your Platform

Select your cloud security platform from the supported integrations above.
2

Generate API Credentials

Create API credentials with read access in your cloud security platform.
3

Configure in RAD Security

Add the integration in your RAD Security workspace with the generated credentials.
4

Verify Connection

Confirm the integration is active and data is being synced.

Next Steps

Upwind Setup

Connect Upwind for cloud threats and runtime events

Data Sources Overview

Explore all available data sources

RADBot

Learn how RADBot helps prioritize findings