Cloud Security Integrations
Integrate your cloud security platforms with RAD Security to bring CNAPP signals — cloud threat detections and cloud runtime activity events — into a single, correlated view alongside your runtime and Kubernetes security data. These integrations are read-only. RAD Security pulls cloud threats and runtime activity events from your provider on a scheduled basis to power unified threat detection and investigation. RAD never writes to or modifies your cloud security platform.Benefits
Cloud Threat Visibility
Surface cloud threats and detections alongside runtime and Kubernetes signals for end-to-end coverage.
Runtime Activity
Ingest cloud runtime activity — process, network, DNS, and cloud events — to see what is actually happening across your workloads.
Correlated Analysis
Correlate cloud threats and activity with runtime detections to prioritize what matters.
RADBot Prioritization
Let RADBot triage cloud threats and activity by real-world impact.
Supported Integrations
Upwind
Upwind
Status: AvailableView Setup Guide →Connect Upwind to RAD Security to ingest cloud threats and cloud runtime activity events.Key Features:
- Cloud threats and detections
- Cloud runtime activity events (process, network, DNS, cloud)
- OAuth 2.0 client-credentials authentication
- Scheduled, read-only data ingestion
What Data is Collected
Cloud Threats
Cloud Threats
- Cloud threat detections and alerts
- Suspicious activity in cloud workloads (OCSF Detection Findings)
Runtime Activity Events
Runtime Activity Events
- Cloud runtime activity — process, network, DNS, and cloud events
- Mapped to OCSF Activity events and stored alongside RAD’s other activity feeds
Use Cases
Threat Investigation
Investigate cloud threats with context from runtime and Kubernetes detections.
Runtime Activity Monitoring
Track cloud runtime activity — process, network, and DNS events — to understand workload behavior.
Correlated Detection
Correlate cloud threats and activity with RAD runtime signals to cut through the noise.
RADBot Prioritization
Leverage RADBot to prioritize cloud threats based on real-world impact.
Getting Started
1
Choose Your Platform
Select your cloud security platform from the supported integrations above.
2
Generate API Credentials
Create API credentials with read access in your cloud security platform.
3
Configure in RAD Security
Add the integration in your RAD Security workspace with the generated credentials.
4
Verify Connection
Confirm the integration is active and data is being synced.
Next Steps
Upwind Setup
Connect Upwind for cloud threats and runtime events
Data Sources Overview
Explore all available data sources
RADBot
Learn how RADBot helps prioritize findings