Sysdig | Top 20 DevOps Solution Company - 2016
Sysdig: Bringing Visibility into Containerized Environments
CIOReview
  • About Us
About UsConferencePartner With Us
  • Technology
      1. ARTIFICIAL INTELLIGENCE
      2. AUDIOVISUAL
      3. BLOCKCHAIN
      4. BUSINESS INTELLIGENCE
      5. CLOUD
      6. DATA ANALYTICS
      7. DEVOPS
      8. DIGITAL TRANSFORMATION
      9. DIGITAL TWIN
      10. LOW CODE NO CODE PLATFORM
      11. NETWORKING
      12. ROBOTIC PROCESS AUTOMATION
      13. SECURITY
  • Industry
      1. CONTACT CENTER
      2. EDUCATION
      3. HEALTHCARE
      4. LEGAL
      5. MANUFACTURING
      6. PUBLIC SECTOR
      7. RETAIL
      8. TELECOM
      9. TRAVEL & HOSPITALITY
  • Solutions
      1. ASSET MANAGEMENT
      2. CUSTOMER EXPERIENCE MANAGEMENT
      3. CYBER SECURITY
      4. DATA CENTER
      5. DOCUMENT MANAGEMENT
      6. ELECTRONIC DATA INTERCHANGE
      7. ENTERPRISE DATA MANAGEMENT
      8. ENTERPRISE RESOURCE PLANNING
      9. ENTERPRISE RISK MANAGEMENT
      10. ENTERPRISE-GRADE WEB DATA SOLUTIONS
      11. FACILITY MANAGEMENT
      12. FIELD SERVICE
      13. IDENTITY AND ACCESS MANAGEMENT
      14. INFRASTRUCTURE
      15. IT SERVICE MANAGEMENT
      16. MANAGED IT SERVICES
      17. PAYMENT AND CARD
      18. PROJECT MANAGEMENT
      19. SOFTWARE TESTING
      20. STORAGE
      21. VIDEO SOLUTIONS
      22. WORKFLOW
  • Platforms
      1. ACUMATICA
      2. AMAZON
      3. IBM
      4. MICROSOFT
      5. ODOO
      6. ORACLE
      7. SAGE
      8. SAP
      9. SERVICENOW
      10. WORKDAY
  • Functions
      1. COMPLIANCE
      2. CONTRACT MANAGEMENT
      3. LOGISTICS
      4. PROCUREMENT
      5. SALES AND MARKETING
      6. SUPPLY CHAIN
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • Magazines
  • News
  • CXO Awards
Menu
  • US
    • US
    • APAC
    • LATAM
    • CANADA
    • EUROPE
CIOREVIEW >> DevOps >> Sysdig

Sysdig has been recognized by CIOReview Magazine as the recipient of “Top 20 DevOps Solution Companies - 2016,” based on our proprietary methodology, reflecting its position in the industry. This profile has been developed by the CIOReview research and editorial team based on insights from an interview with Loris Degioanni, Founder & CEO.

Sysdig
Bringing Visibility into Containerized Environments

Sysdig

Loris Degioanni, Founder & CEO
For Sysdig’s Founder and CEO, Loris Degioanni, the key to successfully deploying the next generation of applications directly intersects with the move to container-based infrastructure. By developing a container-native monitoring platform, Sysdig positioned itself at the intersection of three major trends—containerization of applications, the infrastructural shift to public and private clouds, and microservices based re-architecture of software.

Containers hold huge potential in fostering agility in software development processes, but fall short when it comes to operating, monitoring, and troubleshooting services. “From a DevOps perspective, you need deep visibility across containers rather than just being aware that they exist in your environment,” highlights Degioanni.

Sysdig’s core technology, ContainerVision, gives developers visibility into what is happening inside containers without invasive instrumentation or manual tuning. “ContainerVision matches the technical design of containers to give DevOps teams complete visibility into their containerized applications and infrastructure,” says Degioanni. The platform integrates with orchestrators like Kubernetes, Mesos, and Swarm to interpret infrastructure data through the lens of the organizations’ microservices. “This approach excels at container monitoring where legacy platforms fail, and at the same time, makes monitoring applications and microservices simpler and more robust,” adds Degioanni. By instrumenting the system calls of hosts, DevOps can monitor not only containers, but also the software behavior from inside the containers as well. Sysdig’s container-native technology also provides deep insight into underlying infrastructure: hosts, filesystems, networks, and clouds all can be monitored with just a single point of instrumentation.

Sysdig’s technology resonates with customers in the public cloud as well as those who operate their own data centers. “We offer Sysdig monitoring as a cloud service and as software for clients’ private cloud,” explains Degioanni. “In both cases, we provide a robust set of analytics, dashboarding, and alerting features that save time and money by ensuring high software performance of your own software.”

Sysdig matches the technical design of containers to give DevOps teams complete visibility into containerized applications and microservices


The monitoring service can automatically create topologies of an entire environment, enabling organizations to understand communication patterns at a glance; automatically collect the correct metrics via application auto-discovery; and detect and alert on anomalies.

Monitoring systems should be flexible enough to adapt to different environments. “Our system can automatically detect when new applications are run, or existing microservices are scaled. This automates the complex process of deploying integrations in dynamic, constantly changing containerized environments,” says Degioanni.

“We work with customers closely to deploy Sysdig, tuning it to their needs, and even training users on container best practices,” adds Degioanni. “In all, we’re focused on end-to-end simplicity and productivity for our customers, and are willing to go to great lengths to ensure their happiness.” For example, Degioanni highlights a case study which involves a major telecommunications company that was building its newest service offerings using Docker and Kubernetes as key infrastructure components. Initially, the client tried to build an in-house monitoring system, but the technical challenges associated with Docker containers made this approach untenable. In response, Sysdig quickly enabled the client to build a robust monitoring plan around its microservices, with deep actionable data for the applications running inside their containers.

For the future, Sysdig is gearing to expand its footprint across the globe to better support its customer base. The company is also adding new features to assist organizations in seamlessly managing large enterprise and microservices environments.

Sysdig

News

Is Traditional EDR a Risk to Your Cloud Estate?

Monday, December 11, 2023

Cloud attacks are different

Organizations are transitioning into the cloud at warp speed, but cloud security tooling and training is lagging behind for the already stretched security teams. In an effort to bridge the gap from endpoint to cloud, teams are sometimes repurposing their traditional endpoint detection and response (EDR) and extended detection and response (“XDR) on their servers in a “good enough” approach.

Server or host security has historically been an ownership gray zone, where the protection approach varies based on organizational preferences. Security teams have typically focused protection on the host itself, while DevSecOps teams have prioritized protection of their crown jewels such as containers, Kubernetes, VMs, and workloads. Both approaches are half measures that don’t provide adequate outcomes. A more pragmatic approach is to both protect the server and mission-critical applications.

Traditional EDR is too slow for cloud

Security teams and leaders are under increased pressure to protect business interests, in part because the operational impacts of a breach can affect revenue, reputation, and even share prices. Unfortunately, the average dwell time for an attacker before being detected is 16 days, according the Mandiant M-Trends 2023 report, yet it only takes 10 minutes on average for attackers to breach a cloud environment, as reported in
Sysdig’s 2023 Global Cloud Threat Report.

Enter the Sysdig 5/5/5 framework. 5 seconds to detect, 5 minutes to correlate, and 5 minutes to initiate a response. The traditional EDR approach to detecting attacks just doesn’t work in the cloud, where attacks are faster and environments are more complex. For instance, the average lifespan of a container is just 5 minutes. In an attack scenario, if the analyst does not see the detection within those 5 minutes, they will be unable to understand the scope of the event beyond just the alert. Security teams need the inherent advantages of cloud-native tooling for rapid and high-fidelity detections, followed by automatic contextualization and correlation of complex feeds. Accelerating detection and correlation across cloud-native services buys teams critical time as they initiate a response, a luxury not afforded with traditional EDR.



Advanced attacks, such as SCARLETEEL and ZERO TO ADMIN shown above, have the ability to move laterally between server and cloud. Traditional EDRs typically lack the visibility to see beyond the host, limiting context and correlation. This myopic view prevents security teams from being able to understand the incident context needed to respond within the 5/5/5 framework.

Sysdig’s end-to-end detection, investigation, and response capabilities accelerate teams, enabling the SOC to respond to threats at cloud speed. Traditional EDR just can’t deliver the speed, context, and response capabilities needed to stay ahead of attackers in the cloud.

Stepping back to move forward

To better understand why EDR’s “good enough” approach fails, we need to step back and look at the origins of traditional EDR: Windows workstations. Being purpose built for workstations and later being stretched into data centers, bare metal servers, and eventually the cloud results in critical shortcomings that security teams need to account for. Time-intensive tasks, such as attempting to correlate and contextualize events in container, Kubernetes, and serverless environments, slow teams to a crawl as they attempt to understand events. These core shortcomings set security teams up to fail.

Despite trying to change their spots to stripes, these traditional approaches are still unable to efficiently deliver adequate protection because of their foundational endpoint roots and immature Linux capabilities. The crux of this limitation is that EDR is purpose-built for endpoints, and as teams move into cloud-native services, those same value-drivers don’t exist.

For example, incidents in the cloud are multidimensional, so traditional EDR has trouble connecting and contextualizing the events that, although detected, are happening in separate dimensions. They simply can’t stitch them together. The only way for security teams to truly secure the cloud is with tools and platforms that are purpose-built for the cloud.

The future of cloud security – Bringing security and Dev together

Sysdig started deep in the cloud with containers and Kubernetes. These deep cloud roots are at the core of Sysdig’s cloud-native application protection platform (CNAPP), empowering Dev and security teams to protect cloud-based applications and infrastructure. Sysdig’s unified CNAPP capabilities, pictured below, create a bridge, connecting Dev, engineering, and security teams across their cloud estate. Detection and response capabilities within Sysdig CNAPP are part of Cloud Detection and Response (CDR). These capabilities, such as centralized controls, threat detection, and incident response, are built for maximal efficacy in the cloud. CDR supports the security center’s growing ownership of not only the server, but its contents and larger cloud relationships.

Upgrade to cloud-centric detection

Being rooted in the endpoint means EDR tools are primarily Windows workstation/endpoint centric. This relational misalignment limits visibility to cloud attacks where the focus should instead be centered on Windows and Linux services and applications. Further, EDR identification of lateral movement can be heavily dependent on network visibility, while cloud security tools achieve better visibility of lateral movement through identity and entitlements. Essentially, cloud logs and recording API calls provide better visibility and correlation by default (compared to traditional on-prem workloads), where lateral movement can only be inferred. These misalignments have major implications across critical instrumentation for collection, enrichment, correlation, and response in Linux environments.

Ditch the confines of traditional EDR black boxes

While traditional EDR operates from an opaque black box model, Sysdig’s Linux detections stand apart. Based on Falco, Sysdig has over 100 transparent rules for Linux servers across attack types, extending beyond traditional EDR capabilities in the cloud. Behavioral-based, fileless, and machine learning (ML) attack detections add additional layers of protection to the customizable logic teams can leverage to protect their organization. Real-time intrusion detection and response for kernel-level attacks uncover the subtlest of deviations from normal behavior, detecting stealthy techniques, such as BPF backdoor injection, even with obfuscation attempts. Malware-specific detections leverage behavioral, ML, and artificial intelligence (AI) approaches to protect cloud estates from a broad spectrum of cloud-relevant malware, including cryptominers and fileless attacks. Windows support also offers Sysdig’s superior transparency and support of custom logic to fit unique customer environments.

Graduate to cloud speed for correlated and contextualized investigations

Security teams with traditional EDR must manually stitch isolated events together, slowing their ability to effectively respond. Sysdig provides easy access to relevant, rich context so security teams can trace and build on an event across containers, hosts, and cloud activity. Activity Audit captures all interactive command executions, including every network connection, file access, and process creation. System call captures are able to recreate every syscall, even when the container goes away. Event Details are enhanced with Sysdig’s process tree (Shown below) visualizations for workload-related events such as ancestral lineage to the root process. Simplified forensic context and correlation across domains into a single view accelerates triage and investigation.

Bring the entire toolbox with cloud response capabilities

In addition to limited visibility and needing to manually stitch events together, traditional EDR responses are still stuck on an endpoint approach. Security teams have limited capabilities when responding to threats beyond the host and into containers. For instance, if a server with a compromised image containing malware (e.g., from software supply chain tampering) were deployed into a production environment. If the EDR is able to detect the malware, it may be able to kill or isolate the rogue process or whole container. Unfortunately, traditional EDR tooling lacks the capabilities to prevent that compromised image from reaching deployment in production.

While the kill or isolate actions may be appropriate for a laptop, they are fundamentally flawed in the cloud. This is because units of computing in the cloud are backed by auto-scalers to ensure infrastructure can scale to the limits of the internet. In this scenario, those very autoscalers would recreate the workload or host virtual infrastructure to ensure limited downtime, as the number of instances/containers has to equal the threshold specified in the autoscaling group resource. In this instance, traditional EDR and its limited capabilities in cloud infrastructure only function as a speed bump in delaying the pain.

Sysdig has a radically different approach to cloud response. Sysdig integrates with existing cloud Infrastructure-as-Code (IaC) resources that can make changes at the cloud resource level. We cannot treat a cloud VM or container the way we would with traditional endpoints/workstations, since they are fundamentally different.

Further, Sysdig’s actionable, runtime-aware attack path (shown below) enables teams to proactively mitigate threats and risks with extensive response capabilities across their cloud estate. Malware processes are prevented automatically, while container-centric actions are more robust with pause, stop, and kill options. Post detection, Sysdig automatically creates forensic captures for rapid triage and root-cause analysis. If needed, security teams can jump directly into the impacted host with Sysdig’s Rapid response for surgical remediation actions.

A Path Forward

As organizations continue on their cloud journey from lift and shift to fully cloud native, security and Dev teams need to evolve in parallel. Sysdig’s deep cloud roots and best-of-breed CNAPP unifies development and security as the optimal partner to drive innovation at cloud speed.


Top 20 DevOps Solution Companies - 2016

Company
Sysdig

Headquarters
San Francisco, CA

Management
Loris Degioanni, Founder & CEO

Description
A container visibility company dedicated to making containers viable and mainstream by offering production-quality monitoring for containerized applications and microservices.

Top 20 DevOps Solution Companies - 2016

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

CIOReview
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioreview.com
  • sales@cioreview.com
  • marketing@cioreview.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIOReview. All rights reserved.

 

companies_description
This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://www.cioreview.com/sysdig-2016