Skip to main content
Sweet Security
Runtime Detection and Response

Cloud Detection & Response (CDR)

Real-time detection and blocking of cloud attacks

Cloud Detection & Response combines eBPF sensor telemetry with cloud provider logs (including AWS CloudTrail) and builds a behavioral baseline for every machine, identity and service. Deviations such as unusual API calls, role takeover or a suspicious process in a container reach one correlation engine that groups related events into a single incident with an impact and severity assessment. The team sees context from the cloud, workload and application layers in one place, and the response, for example terminating a malicious process, can be manual or automatic. According to Sweet Security, customers cut MTTR to 5 minutes and reduce cloud incident resolution time by 90%.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • One detection engine correlating the eBPF sensor with AWS, Azure and Google Cloud logs; incidents of type logs, sensor and unified
  • A behavioral baseline for every machine, identity and service, built during a learning period
  • Incidents with impact and severity scores, a timeline, top events and a graph of related identities and processes
  • Custom rules from templates plus exclusions tailored to the environment (e.g. dev and test namespaces)
  • Manual or automatic response: process termination, playbooks, alerts to Slack, Jira, ServiceNow, webhooks and SOAR (Torq)

Business benefits

  • MTTR cut to 5 minutes (Sweet Security data)
  • Cloud incident resolution time reduced by 90% (Sweet Security data)
  • Fewer false positives: deviations from the baseline are reported, not every event
  • One incident instead of dozens of scattered alerts from different layers
  • Attacks stopped without production downtime: malicious processes terminated without restarting the environment
Sweet Security

Why Sweet Security?

Sweet Security is a Runtime CNAPP that detects and blocks attacks on cloud infrastructure, workloads, applications and AI agents while the attack is still under way. A lightweight eBPF sensor and cloud logs build a behavioral baseline of the environment, and a single detection engine correlates events across every layer to cut MTTR to minutes, according to Sweet Security data.

All products

Need Cloud Detection & Response (CDR) in your organization?

As a certified Sweet Security partner, we'll help you deploy and configure the solution.

Book a free consultation