> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rad.security/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloud Security Integrations

> Connect your cloud security platforms to RAD Security for unified cloud threat and runtime activity visibility.

# Cloud Security Integrations

Integrate your cloud security platforms with RAD Security to bring CNAPP signals — cloud threat detections and cloud runtime activity events — into a single, correlated view alongside your runtime and Kubernetes security data.

These integrations are **read-only**. RAD Security pulls cloud threats and runtime activity events from your provider on a scheduled basis to power unified threat detection and investigation. RAD never writes to or modifies your cloud security platform.

## Benefits

<CardGroup cols={2}>
  <Card title="Cloud Threat Visibility" icon="radar">
    Surface cloud threats and detections alongside runtime and Kubernetes signals for end-to-end coverage.
  </Card>

  <Card title="Runtime Activity" icon="wave-pulse">
    Ingest cloud runtime activity — process, network, DNS, and cloud events — to see what is actually happening across your workloads.
  </Card>

  <Card title="Correlated Analysis" icon="diagram-venn">
    Correlate cloud threats and activity with runtime detections to prioritize what matters.
  </Card>

  <Card title="RADBot Prioritization" icon="robot">
    Let RADBot triage cloud threats and activity by real-world impact.
  </Card>
</CardGroup>

## Supported Integrations

<AccordionGroup>
  <Accordion title="Upwind" icon="cloud">
    **Status:** Available

    [View Setup Guide →](/rad-security/integrations/cloud-security/upwind-setup)

    Connect Upwind to RAD Security to ingest cloud threats and cloud runtime activity events.

    **Key Features:**

    * Cloud threats and detections
    * Cloud runtime activity events (process, network, DNS, cloud)
    * OAuth 2.0 client-credentials authentication
    * Scheduled, read-only data ingestion
  </Accordion>
</AccordionGroup>

## What Data is Collected

<AccordionGroup>
  <Accordion title="Cloud Threats" icon="radar">
    * Cloud threat detections and alerts
    * Suspicious activity in cloud workloads (OCSF Detection Findings)
  </Accordion>

  <Accordion title="Runtime Activity Events" icon="wave-pulse">
    * Cloud runtime activity — process, network, DNS, and cloud events
    * Mapped to OCSF Activity events and stored alongside RAD's other activity feeds
  </Accordion>
</AccordionGroup>

## Use Cases

<CardGroup cols={2}>
  <Card title="Threat Investigation" icon="magnifying-glass">
    Investigate cloud threats with context from runtime and Kubernetes detections.
  </Card>

  <Card title="Runtime Activity Monitoring" icon="wave-pulse">
    Track cloud runtime activity — process, network, and DNS events — to understand workload behavior.
  </Card>

  <Card title="Correlated Detection" icon="diagram-project">
    Correlate cloud threats and activity with RAD runtime signals to cut through the noise.
  </Card>

  <Card title="RADBot Prioritization" icon="robot">
    Leverage RADBot to prioritize cloud threats based on real-world impact.
  </Card>
</CardGroup>

## Getting Started

<Steps>
  <Step title="Choose Your Platform">
    Select your cloud security platform from the supported integrations above.
  </Step>

  <Step title="Generate API Credentials">
    Create API credentials with read access in your cloud security platform.
  </Step>

  <Step title="Configure in RAD Security">
    Add the integration in your RAD Security workspace with the generated credentials.
  </Step>

  <Step title="Verify Connection">
    Confirm the integration is active and data is being synced.
  </Step>
</Steps>

## Next Steps

<CardGroup cols={2}>
  <Card title="Upwind Setup" icon="cloud" href="/rad-security/integrations/cloud-security/upwind-setup">
    Connect Upwind for cloud threats and runtime events
  </Card>

  <Card title="Data Sources Overview" icon="database" href="/rad-security/integrations/data-sources">
    Explore all available data sources
  </Card>

  <Card title="RADBot" icon="robot" href="/rad-security/getting-started/radbot">
    Learn how RADBot helps prioritize findings
  </Card>
</CardGroup>
