TL;DR
- Upwind's view of your cloud risk now lives inside Vega. When a cloud alert fires, you already know how exposed the asset is and what an attacker could reach from it.
- Vega adds five Upwind sources you can query and join like any other: assets that are internet-exposed, critically vulnerable, holding sensitive data, highly privileged, or already under an active Upwind detection.
- Vega's agents triage and investigate every cloud alert with that context already in hand, and the analyst gets a verdict without opening Upwind.
An Alert Fires at 2:47 AM
An alert fires: an EC2 instance's role just created a new IAM user. The detection is solid. Instances almost never create users, and when one does, it usually means an attacker is setting up a backdoor account. But the analyst on call can't act on it until a few questions are answered:
- Can the internet reach this instance?
- Does it have a vulnerability someone could exploit?
- Does it hold sensitive data?
- What can its role touch?
- Has anything else fired on it?
Every one of those answers already exists in Upwind. Getting them used to mean leaving the alert, opening another console, searching for the asset, and piecing it together by hand, while the attacker kept working.
With Vega and Upwind, the answers come with the alert.
Know What's at Stake Before You Investigate
Once Upwind is connected, Vega pulls your at-risk cloud assets and the reason each one is at risk, and keeps them alongside your event data as five sources you can query:
- @Upwind-Internet-Exposed-Resources: cloud assets reachable from the internet
- @Upwind-Critical-Vulnerability-Resources: cloud assets with at least one critical vulnerability
- @Upwind-Sensitive-Data-Resources: cloud assets where Upwind found PII at rest
- @Upwind-High-Privilege-Resources: cloud assets whose identity holds elevated privileges
- @Upwind-Active-Detections-Resources: cloud assets with at least one active detection
Vega's agents use this context the moment a cloud alert fires. Triage ranks the alert by the real risk on the asset, and investigation uses the same facts to work out how the attacker got in and what else they could reach.
Back to 2:47 AM
This is what the analyst sees once Vega's Investigation Agent brings in Upwind's context:
Alert: EC2 instance i-0a1b2c3d4e5f67890 created IAM user backup-admin
- Exposed: reachable from the internet
- Vulnerable: 3 critical vulnerabilities
- Sensitive: PII found at rest
- Privileged: its identity holds elevated privileges
- Already flagged: 2 active Upwind detections
Verdict: Malicious. Compromised workload setting up persistence.
Recommended action: Contain the instance and disable backup-admin.
Illustrative example
Nobody opened Upwind or built a timeline by hand. The agent queried Upwind's context, put it together with what it saw in CloudTrail, and came back with a verdict and next steps.
Now picture the same alert on an isolated dev box: nothing reaches it from the internet, it holds no sensitive data, and its role can't touch much. Same detection, far less risk, so that alert still gets worked, just not at 2:47 AM, and the team stays on the one that matters.
This Covers Every Cloud Alert
Vega reads your cloud event data in place and pulls Upwind's context through a read-only API, so there is no second pipeline to build and nothing to re-ingest. That is why every cloud alert gets the full context, not only the ones a team could afford to send to a legacy SIEM, where this kind of context rarely arrives at all.
FAQ
How do I connect Upwind to Vega?
You need an Upwind role that can create API credentials, and your Upwind organization ID. Create an API credential with the read-only list:inventory-assets permission, then in Vega enter your regional API Base URL, the Client ID, the Secret, and your Organization ID and connect. It takes a few minutes.
Where does my Upwind data live?
In Upwind. Vega keeps a small read-only copy of just the at-risk asset records it needs, refreshed every 12 hours and kept for 30 hours, and Upwind stays the source of truth.
Can I change which assets each data source returns?
Not the risk condition itself. Each context data source is a fixed view of your Upwind asset inventory, defined by a single risk condition. You can combine them in Vega KQL, for example filtering sensitive-data assets down to the internet-exposed ones, to narrow them to the assets you care about.
See It on a Real Alert
The Upwind integration is available today. Book a demo and we'll run a cloud alert through Vega with Upwind context attached, so you can see the verdict it reaches and how it got there.