I
Ishan Pandey
Guest
Endpoint detection and response tools were built to watch a host that stays put. Today’s cloud workloads are too dynamic for that.
Existing runtime protection was built for persistent infrastructure, but today’s workloads run on hosts that are ephemeral by design, spun up and torn down automatically, often within minutes. It’s not fair to expect traditional tools to hold up under these circumstances. Some of these cloud instances are gone before a runtime tool even registers that they existed in the first place.
The security industry has been gradually shifting its approach to runtime protection to account for this reality, and Wiz is one of the companies leading that shift.
Traditional runtime protection is based on a crucial assumption that no longer holds true. EDR (endpoint detection and response) and TDR (threat detection and response) tools were built for security teams that know where workloads are hosted and which locations need ongoing monitoring.
While this was true well into the cloud computing era, when cloud infrastructure was relatively stable and long-lasting, today’s cloud environments are radically different. Infrastructure is created and managed through APIs, with workloads that spin up and shut down on their own, no server to walk up to, no fixed address to keep watching. Meanwhile, identities can move across services, leaving little to no trace.
“The attack surface has expanded beyond endpoints. Traditional TDR was built for persistent servers and known network boundaries. Modern environments introduce ephemeral workloads, identity-based access, and API-driven infrastructure that legacy tools were never designed to monitor,” warns Wiz’s Tal Moriah. “An attacker using a stolen credential to exfiltrate data through a legitimate API call generates zero endpoint alerts. Without detection across identity, network, and API layers, these attacks are invisible.”
The problem goes deeper than invisible workloads. Protecting cloud environments demands not just awareness of short-lived, cloud-hosted workloads. It requires a clear view of all the relationships between workloads, identities, networks, and APIs, something static, config-only analysis structurally can't provide, even when it's watching the right infrastructure.
Wiz’s cloud-native application protection platform (CNAPP), was built to secure the cloud environment as a whole, rather than expanding outward from any single endpoint. That’s the core difference from EDR, as Wiz starts from the cloud itself and looks beyond endpoints from day one, rather than treating them as the starting point.
The platform began life as an agentless cloud security solution that inspects and assesses all cloud workloads to map their vulnerabilities, configurations, permissions, exposure, sensitive data, and relationships, no matter how long-lived they are.
This agentless approach doesn’t need software installed on a server or host to assess risk across the environment. Real-time behavioral monitoring comes from a separate, opt-in layer, the Wiz Sensor, an agent that Wiz Defend uses to watch workload activity and take response or containment action when something confirmed goes wrong.
Moreover, Wiz goes beyond static analysis with dynamic runtime protection. Wiz Defend builds onto the Wiz Security Graph, correlating runtime signals with broader context around cloud workload activity. Putting agentless visibility and runtime protection onto a single graph places suspicious activity in the context of possible attack paths and risks, in contrast to traditional solutions which consider each workload in isolation.
The stakes are real. For one out of every six cloud environments that Wiz monitors at runtime, adding runtime context surfaces a high or critical severity attack path that had been overlooked by configuration-only analysis.
This is not to say that Wiz is the only tool addressing the new reality. Existing EDR solutions like CrowdStrike and Microsoft’s Defender or Sentinel platforms have not become obsolete. They all provide strong host-level detection and response for persistent infrastructure, which is still a much-needed offering.
What’s more, these vendors likewise recognize the need to adapt to the new transient cloud infrastructure. Microsoft, CrowdStrike, and other EDR vendors have begun to develop cloud-native detection capabilities.
CrowdStrike expanded its real-time cloud detection and response (CDR) functionality, while Microsoft extended Defender for Cloud with cloud-native integrations that push detection beyond traditional endpoints.
All the signs point to a market that recognizes the need for both broad cloud visibility and deep, correlated context on real-time workload activity. Instead of diverging, EDR and CNAPP are converging from opposite directions. EDR-native vendors are adding cloud context on top of their endpoint foundations, as CNAPP platforms like Wiz add deeper runtime protection on top of a cloud-first, endpoint-agnostic approach.
Cloud infrastructure has changed faster than the security models built to protect it. Security solutions built around the expectation that servers and containers will run for years aren’t suitable for hosts that last only minutes or seconds and infrastructure that’s dynamically created by APIs.
The industry is shifting in response. It’s becoming more widely acknowledged that short-lived, transient cloud infrastructure needs a security model built for its reality, not one that starts from the endpoint and works outward. As attack paths keep evolving, CNAPP platforms that look beyond endpoints from the start are better positioned to keep up than EDR tools extended into the cloud after the fact.
Don’t forget to like and share the story!
Vested Interest Disclosure: HackerNoon has reviewed the report for quality, but the claims herein belong to the author. #DYOR.
Existing runtime protection was built for persistent infrastructure, but today’s workloads run on hosts that are ephemeral by design, spun up and torn down automatically, often within minutes. It’s not fair to expect traditional tools to hold up under these circumstances. Some of these cloud instances are gone before a runtime tool even registers that they existed in the first place.
The security industry has been gradually shifting its approach to runtime protection to account for this reality, and Wiz is one of the companies leading that shift.
Cloud infrastructure broke the EDR model
Traditional runtime protection is based on a crucial assumption that no longer holds true. EDR (endpoint detection and response) and TDR (threat detection and response) tools were built for security teams that know where workloads are hosted and which locations need ongoing monitoring.
While this was true well into the cloud computing era, when cloud infrastructure was relatively stable and long-lasting, today’s cloud environments are radically different. Infrastructure is created and managed through APIs, with workloads that spin up and shut down on their own, no server to walk up to, no fixed address to keep watching. Meanwhile, identities can move across services, leaving little to no trace.
“The attack surface has expanded beyond endpoints. Traditional TDR was built for persistent servers and known network boundaries. Modern environments introduce ephemeral workloads, identity-based access, and API-driven infrastructure that legacy tools were never designed to monitor,” warns Wiz’s Tal Moriah. “An attacker using a stolen credential to exfiltrate data through a legitimate API call generates zero endpoint alerts. Without detection across identity, network, and API layers, these attacks are invisible.”
The problem goes deeper than invisible workloads. Protecting cloud environments demands not just awareness of short-lived, cloud-hosted workloads. It requires a clear view of all the relationships between workloads, identities, networks, and APIs, something static, config-only analysis structurally can't provide, even when it's watching the right infrastructure.
What Wiz is building instead
Wiz’s cloud-native application protection platform (CNAPP), was built to secure the cloud environment as a whole, rather than expanding outward from any single endpoint. That’s the core difference from EDR, as Wiz starts from the cloud itself and looks beyond endpoints from day one, rather than treating them as the starting point.
The platform began life as an agentless cloud security solution that inspects and assesses all cloud workloads to map their vulnerabilities, configurations, permissions, exposure, sensitive data, and relationships, no matter how long-lived they are.
This agentless approach doesn’t need software installed on a server or host to assess risk across the environment. Real-time behavioral monitoring comes from a separate, opt-in layer, the Wiz Sensor, an agent that Wiz Defend uses to watch workload activity and take response or containment action when something confirmed goes wrong.
Moreover, Wiz goes beyond static analysis with dynamic runtime protection. Wiz Defend builds onto the Wiz Security Graph, correlating runtime signals with broader context around cloud workload activity. Putting agentless visibility and runtime protection onto a single graph places suspicious activity in the context of possible attack paths and risks, in contrast to traditional solutions which consider each workload in isolation.
The stakes are real. For one out of every six cloud environments that Wiz monitors at runtime, adding runtime context surfaces a high or critical severity attack path that had been overlooked by configuration-only analysis.
Different playbooks for a changed battlefield
This is not to say that Wiz is the only tool addressing the new reality. Existing EDR solutions like CrowdStrike and Microsoft’s Defender or Sentinel platforms have not become obsolete. They all provide strong host-level detection and response for persistent infrastructure, which is still a much-needed offering.
What’s more, these vendors likewise recognize the need to adapt to the new transient cloud infrastructure. Microsoft, CrowdStrike, and other EDR vendors have begun to develop cloud-native detection capabilities.
CrowdStrike expanded its real-time cloud detection and response (CDR) functionality, while Microsoft extended Defender for Cloud with cloud-native integrations that push detection beyond traditional endpoints.
All the signs point to a market that recognizes the need for both broad cloud visibility and deep, correlated context on real-time workload activity. Instead of diverging, EDR and CNAPP are converging from opposite directions. EDR-native vendors are adding cloud context on top of their endpoint foundations, as CNAPP platforms like Wiz add deeper runtime protection on top of a cloud-first, endpoint-agnostic approach.
Final thoughts
Cloud infrastructure has changed faster than the security models built to protect it. Security solutions built around the expectation that servers and containers will run for years aren’t suitable for hosts that last only minutes or seconds and infrastructure that’s dynamically created by APIs.
The industry is shifting in response. It’s becoming more widely acknowledged that short-lived, transient cloud infrastructure needs a security model built for its reality, not one that starts from the endpoint and works outward. As attack paths keep evolving, CNAPP platforms that look beyond endpoints from the start are better positioned to keep up than EDR tools extended into the cloud after the fact.
Don’t forget to like and share the story!
Vested Interest Disclosure: HackerNoon has reviewed the report for quality, but the claims herein belong to the author. #DYOR.