Cloud Application Detection and Response

See the attack.
Understand
what happened.

Primod helps security teams detect suspicious runtime behavior, understand the attack with workload context, and prioritize vulnerabilities using evidence from production.

  • eBPF sensor
  • Process activity
  • Workload identity
  • Request context where available
One attack, one investigation

An alert is the start
of the investigation.

See the process chain, the workload involved, and the activity that followed. When request context is available, connect the alert to the request under investigation.

Explore runtime threat detection
app.primod.io / runtime / alerts / checkout-service

Observed sequence

  1. +0 ms

    POST /api/upload

    Observed
  2. +18 ms

    Web process launches /bin/sh

    Succeeded
  3. +43 ms

    Process opens service-account token file

    Succeeded
  4. +91 ms

    Connection to 203.0.113.10:443

    Failed
Runtime alert HighIllustrative scenario · Product UI preview

Web process launched a shell

Workload
checkout-service · Deployment
Namespace
production
Process chain
web worker → /bin/sh
Observed activity
Shell launch followed by a token read and an outbound connection attempt
Interpretation
Consistent with suspicious command execution and credential access
Response
Observe — no action blocked

Illustrative attack scenario · Product UI preview

Two paths, one evidence-led platform

Investigate the threat.
Prioritize the fix.

Give the next responder context.

Bring process activity and workload identity into the same investigation, so security and engineering can work from the evidence.

See investigation workflows
app.primod.io / runtime / alerts / context
Alert contextWeb process launched a shell
Podcheckout-service-7d9f6c-x2k4p
Nodenode-pool-b-03
Containercheckout
Image digestsha256:9f2c…a1e0

Method · route: POST /api/upload

Trace · span: supplied by instrumentation

Rule: rce-shell-web-ancestor · rev 3

Illustrative scenario · Product UI preview

Bring runtime evidence to your vulnerability queue.

Review observed execution alongside affected workloads and available fixes to decide what needs attention first.

Explore vulnerability prioritization
app.primod.io / vulnerabilities / CVE-2024-21907
CRITICAL CVSS 7.5CVE-2024-219078/10/2026, 9:55:09 PM

Vulnerable Newtonsoft.Json code executed

Upgrade Newtonsoft.Json to 13.0.1 or later to remediate CVE-2024-21907

Present

Executed

Exploited

Impacted

Contained

Nodelima-default
Poddotnet-vuln-api-6bb7d4b879-drh5x
Containerdotnet-vuln-api
Namespacedotnet-vuln-ns

Call stack · Newtonsoft.Json.JsonConvert.DeserializeObject

6Newtonsoft.Json.Serialization.JsonSerializerInternalReader.DeserializeNewtonsoft.Json.dll:0
7Newtonsoft.Json.JsonSerializer.DeserializeInternalNewtonsoft.Json.dll:0
8Newtonsoft.Json.JsonConvert.DeserializeObjectTRIGGER
9Program/<>c.<<Main>$>b__0_3DotnetVulnApp.dll:0

Example finding · Illustrative vulnerability workflow

Your production environment

Bring runtime evidence
into your workflow.

Collect activity from supported Linux workloads and export security alerts through OpenTelemetry. Explore deployment and data-flow requirements for your environment.

Deployment
Cloudflare, Rancher, AWS, Azure, GCP, Kubernetes, OpenShift, Docker, Helm, Linux where the sensor runs, subject to release support review
Workloads
Go, Java, Python, Node.js, Rust, .NET, NGINX, Redis, PostgreSQL, Kafka observed workload technologies, not function-level coverage
Telemetry
OpenTelemetry, Grafana, Prometheus, Datadog, Splunk, Elastic OTLP-compatible destinations; receiver setup and field mapping required
Request a demo

See the evidence
behind the alert.

Walk through an investigation, explore vulnerability prioritization, and discuss your production environment with the Primod team.

Request a demo