Upwind has introduced the AI Agentic Pack, a collection of AI agents integrated into its Cloud and AI Security Platform, designed to help security teams better manage the flood of alerts and findings generated in cloud environments. As organizations increasingly rely on cloud infrastructure, security teams find it difficult to distinguish which threats require immediate attention amidst the numerous alerts.
The AI Agentic Pack seeks to ease this burden by providing runtime context. Upwind's strategy emphasizes what is actively operating within the environment, identifying exposure levels, and understanding how various components interconnect. Moshe Hassan, VP of Product & Research at Upwind, highlighted that the defining feature of their solution is context. "In AI, context is the product," he stated. Many existing security solutions simply layer AI on top of static data, which limits their effectiveness. Upwind’s agents gather real-time data on active workloads, running processes, and service interactions, offering a more nuanced understanding of risk.
This suite consists of four distinct agents, each aimed at enhancing specific aspects of the security workflow. 'Choppy' maps services and dependencies across environments; 'Blue' analyzes alerts and suspicious activity; 'Red' identifies entry points and assesses potential vulnerabilities; while 'Green' translates findings into actionable insights and remediation strategies. This division enables security teams to engage more effectively with the complexity of their environments.
Addressing the Challenges of Cloud Security
Cloud security teams encounter unique challenges due to the dynamic nature of cloud environments. The same vulnerability can present varying levels of threat based on its context within a production setting. As Hassan noted, the importance of context becomes clear when considering how different factors—such as whether an asset is exposed to the internet or connected to sensitive information—can significantly alter the risk landscape. Upwind’s agents are designed to make these distinctions automatically, enhancing the team's ability to prioritize threats.
For managed security service providers (MSSPs), the implications are substantial. The AI Agentic Pack is especially beneficial in multi-tenant environments, where each tenant's infrastructure and risk profile can vary significantly. The agents utilize runtime data to provide insights tailored to each tenant's unique configuration. This capability allows MSSPs to move beyond merely reviewing alerts to delivering actionable decision support. Consequently, analysts can quickly assess risks and determine appropriate responses without the lengthy process of gathering evidence.

Improving Operational Efficiency
Early deployments of the AI Agentic Pack have already shown promising operational improvements. Upwind reports that integrating the 'Blue' and 'Green' agents has helped teams reduce investigation times by up to 75%. The 'Red' agent has decreased alert volumes by over 90%, enabling security teams to focus on the most critical threats. This efficiency is vital as security teams increasingly seek tools that streamline workflows and accelerate remediation efforts.
The evolution of security work is clear as teams look for solutions that not only provide visibility but also drive actions closer to resolution. Upwind envisions a dual approach, enhancing both AI-driven platforms for governance and decision-making while integrating security processes into existing operational tools. This flexibility ensures that teams can utilize advanced security intelligence in familiar environments.
In a rapidly changing landscape of cloud security needs, Upwind's AI Agentic Pack represents a strategic response to the challenges faced by security teams today. By prioritizing context and operational efficiency, Upwind aims to empower organizations to better manage their cloud security risks, ultimately fostering a more resilient digital infrastructure.
Quick answers
What is the AI Agentic Pack?
The AI Agentic Pack is a suite of AI agents launched by Upwind to enhance cloud security operations by providing real-time context and streamlining workflows.
How does the AI Agentic Pack improve security workflows?
It reduces alert fatigue by prioritizing threats based on runtime context, allowing security teams to focus on the most critical issues.
What are the main components of the AI Agentic Pack?
The pack includes four agents: 'Choppy' for mapping services, 'Blue' for alert analysis, 'Red' for exposure validation, and 'Green' for remediation guidance.
What benefits have early deployments shown?
Early deployments have reported a 75% reduction in investigation time and a 90% decrease in alert volume, significantly improving operational efficiency.
The stories that move AI & crypto markets — before the market reacts.
Free. 7am ET. Five stories. 62,400 readers.


