AccuKnoxCWPP by AccuKnox is a comprehensive Cloud Workload Protection Platform designed to provide continuous enforcement on Openshift environments. It offers detailed forensics, logs, alerts, and telemetry of attack violations in real-time with a Zero Trust Policy. AccuKnoxCWPP addresses advanced Zero Day attacks with inline mitigation, focusing on runtime container image scanning, audit/forensics, runtime application behavior, runtime application hardening, network micro-segmentation, and securing the secrets manager. It profiles and creates a baseline of policies by observing the application and network graph, delivering ongoing observability as the workload interacts with the host operating system and other workloads. AccuKnoxCWPP enforces security policies using Kernel Primitives and provides detailed forensics and inline remediation. It is based on KubeArmor, leveraging eBPF for observability of application behavior and LSMs for enforcement against unknown Zero Day attacks. The platform includes automated Zero Trust policy generation, vulnerability prioritization, SIEM/SOAR integration, continuous compliance, and anomaly detection. It supports SaaS, PaaS, IaaS AWS, GCP, Azure Kubernetes, and Serverless (Fargate and ECS). AccuKnoxCWPP also includes a Discovery Engine agent that assesses the security posture of workloads and auto-discovers the necessary policy-set for least-permissive mode. The Shared Informer Agent collects information about clusters like pods, nodes, namespaces, etc., and the Policy Discovery Engine discovers policies using the workload and cluster information relayed by the Shared Informer Agent. It provides micro-segmentation at the lowest granularity level, identifying process execution requests from pods, network connections, and systems accessed, developing a least permissive security posture through whitelisting policies and auditing/denying everything else.