Autonomous cloud Defense goes Kubernetes
.png)

Stream Security now extends CloudTwin beyond public cloud to VMware, NSX, and on-prem network devices. You get full attack path analysis, runtime threat detection, and real-time topology modeling across your entire hybrid environment - not just the cloud or on-prem part of it.
CloudTwin, Stream's real-time digital twin of your infrastructure, now models VMware environments, NSX network policies, and on-prem networking devices alongside your cloud resources. This means Stream can trace complete attack paths that cross environment boundaries such as a compromised VM instance that can reach an RDS in AWS through a misconfigured network segmentation

Stream ingests and correlates native VMware audit logs, vCenter events, and ESXi system logs in real time. Combined with NSX network flow data, we detect threats that VMware-only and cloud-only tools miss:
For workloads that need deeper inspection, Stream's eBPF-based runtime sensor extends into hybrid environments, delivering:
This gives security teams the ability to detect threats at every layer — from network routing to API payloads to process execution — regardless of where the workload runs.
Detect and secure AI agents and workloads across your entire infrastructure, including both third-party services and self-hosted components.
Routers, switches, and firewall appliances are now first-class citizens in CloudTwin. Stream ingests device configurations, routing tables, and ACLs to:
Adding VMware and on-prem support isn't about checkbox compliance. It's about building the only security model that reflects how hybrid infrastructure actually works, and how attackers actually exploit it.
CloudTwin continuously maintains a living model of your entire environment: cloud resources, IAM relationships, network topology, VMware clusters, NSX policies, and on-prem routing. When something changes — a new firewall rule, a modified router ACL, a shifted NSX policy — Stream updates the model in real time and re-evaluates every attack path.
This is what allows Stream to go from alert to response in under 5 minutes — even when the attack spans three environments and six network boundaries.
VMware and on-prem networking are the beginning. We're building toward a unified security model that covers every environment where enterprise workloads run, because attackers don't respect infrastructure boundaries, and your detection shouldn't either.
If your security team is struggling with visibility gaps between cloud and on-prem environments, we'd love to show you how we can help - Book a demo
Stream is the AI-native platform built to fight AI-enabled attacks. It autonomously prevents, detects, hunts, and remediates exposures and threats across production at machine speed - driving risk toward zero. It replaces the fragmented stack of scanners, runtime agents, exposure tools and playbooks with one live model of production.Defending Production needs a new approach: Stream is the only Autonomous Production Defense Platform that works across your entire production estate. It runs on a patented CloudTwin®, a high-fidelity security data harmonization layer that models Cloud, SaaS, identity, runtime, AI, network, perimeter, on-prem, security controls, and the behavior running on top of them into one live model of production: real-time, fully correlated, continuously updating. Not a snapshot. And it does not stop at boundaries - the boundaries that fragment every other tool are the same boundaries an attacker moves across. Inside CloudTwin they are one system.

.png)

.png)