Configuration scanning sees an EC2 instance with a sensible security group and calls it healthy.
It cannot see the unpatched OpenSSL inside the AMI, the root-owned SSH key baked into the image, the container running as privileged, or the Lambda with an outdated runtime. The workload is where the exploit actually lands, and it is the layer most posture tools never open.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Workload discovery inventories every VM, container, serverless function and managed host across all seven supported clouds via read-only APIs.
- 2
The agentless scanner takes point-in-time volume snapshots inside your own account and analyses them out-of-band, so no software runs on the workload itself.
- 3
Each workload is evaluated against the compute and workload rule set — 219 dedicated posture rules — plus operating-system CIS benchmarks for Ubuntu, RHEL, SUSE, Debian and CentOS.
- 4
Vulnerability, container image, and host signal data is joined onto the same workload record, so one view shows configuration, packages, and exposure together.
- 5
Workload health rolls up into a single CWPP pillar score that trends over time and feeds the unified CNAPP score.
Specific outputs, measurable outcomes
CWPP — Workload Protection in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see CWPP — Workload Protection in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.