Skip to main content10ETLabsRequest demo

CWPP

Cloud Workload Protection

Know every compute workload before you talk about runtime agents.

10ETLabs workload protection starts with an inventory of VMs, functions, and hosts from the cloud APIs you already trust — read-only, no agents. Opt in to DeepScan and 10ETLabs also snapshots VM disks and scans them in your own account for vulnerable packages, secrets, malware and AI model files; only findings metadata comes back.

Server racks in a data hall

CWPP

VMs, Lambda functions, and hosts from the APIs you already run. No guest-OS agent required.

See it work

Every cloud’s findings, one ranked queue

Findings from each provider share one shape, then 10ET Score orders them by exposure and blast radius.

Many clouds · one ranked queue

01Scan each cloud

Posture jobs list each connected provider’s control plane with its reader role or token — AWS deepest, then Azure, GCP, and Kubernetes.

Sample findings using real rule titles. Scores follow the 10ET Score formula.

What you get

Estate-wide compute map

EC2 instances, Lambda functions, Azure VMs, GCE instances, and other VPS hosts appear as assets with region, account, and 10ET Score from open findings. Azure Functions and Google Cloud Functions are not collected as workloads in this release.

No agents required

Read-only roles by default. Nothing needs to sit in the guest OS, so there is no performance tax and no change window to “install security.” DeepScan and the host and Kubernetes sensors are opt-in when you want more depth.

Tied to identity and data

On AWS, a Lambda function URL with no auth that runs as an admin or read-all-S3 role becomes an attack path. Other workload findings are scored alongside CSPM and CIEM in one queue.

DeepScan runs in your account

Opt-in and agentless: a separate, tag-scoped permission set snapshots a disk, a short-lived scanner VM in your account reads it, and snapshots and scanner VMs are deleted afterwards. Disks it cannot read (encrypted without key access, unsupported filesystem, too large) are listed as coverage gaps.

In this module

  1. Step 1

    Inventory compute

    Instances, functions, and hosts upsert by native ID with region, account, and last-seen.

  2. Step 2

    Inherit related posture

    Public IPs, weak IAM, and unencrypted disks score the workload — not a separate CVE feed.

  3. Step 3

    Opt in to DeepScan

    Per account: deploy the DeepScan template, check access, choose a schedule and cost cap. CVE, secret and AI-artefact findings land on the VM.

In this release

  • Control-plane inventory of EC2, Lambda, Azure VMs, GCE, and VPS hosts
  • Opt-in agentless DeepScan of EC2, Azure VM and GCE disks (Linux packages, secrets, malware, AI model files)
  • Scores from related posture findings
  • Unit filter by AWS, Azure, GCP, Kubernetes, VPS
Request a demo

On the roadmap

  • Windows installed-program and patch inventory in DeepScan

Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.

More of the platform

Other modules — not a reprint of this page.

AI security

AI workload security

Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.

Code security

Agentless code-to-cloud security

Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.

CSPM

Cloud Security Posture Management

Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.

CIEM

Cloud Identity & Access

AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.

Containers

Container & Kubernetes Security

EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.

Compliance

Cloud Compliance Monitoring

CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.

Vulnerabilities

Cloud Vulnerability Management

ECR scan-on-push gaps from the control plane, plus package CVEs from opt-in DeepScan or the optional host sensor, prioritized by blast radius.