Terminology Index
Glossary
2953 terms
VM Detection Patterns
The patterns that detect threats and misconfigurations on cloud VMs, suspicious processes, lateral-movement signs, configuration drift, runtime anomalies, that cloud-workload-protection programs operationalize.
Detecting threats on cloud VMs combines familiar endpoint detection (suspicious processes, command-line patterns) with cloud-specific signals (unusual metadata-service queries, anomalous IAM role usage, unexpected outbound destinations). VM detection patterns codify these into rules, alerts, and dashboards. As a cloud-workload-protection topic, knowing which patterns matter on VMs is foundational to running effective workload detection at cloud scale rather than just porting on-prem endpoint detection straight in.
Introduced in: Cloud Workload Protection
Examples
- Detecting unusual metadata-service queries from a VM workload.
- Alerting on anomalous outbound destinations from a workload VM.
- Spotting suspicious process and command-line patterns at runtime.
Related
