- Processes and execution chains
- Containers, workloads, and host state
- Image, release, and configuration lineage
- Service calls, data access, and network behavior
WORKLOAD AND RUNTIME SECURITY · OLLANDI DIP
Monitor live workload execution and connect process behavior to images, deployments, identities, network paths, and services.
Specialized workload and runtime security that contributes live evidence and domain actions to Ollandi’s cross-domain defense loop.
WHAT THE RUNTIME DIP DOES
From domain telemetry to a decision operators can use.
- Unexpected execution and persistence
- Workload identity misuse
- Runtime drift after deployment
- Suspicious service-to-service activity
- Which image, release, or change produced the behavior
- The workload identity and reachable dependencies
- Whether execution matches intended service behavior
- The operational impact of isolation or rollback
- Capture evidence and increase observation
- Restrict workload communication
- Quarantine a workload within policy
- Prepare rollback or credential rotation for approval
COVERAGE
The context this DIP brings into Ollandi.
The DIP normalizes domain evidence with source and time preserved. Ollandi then relates it to other DIPs, service dependencies, policy, authority, and historical state.
- Runtime and process telemetry
- Container and orchestrator metadata
- Image and deployment records
- Workload identity
- Network flows and service maps
- Policy and change history
Image 7F2A
Workload
Process tree
Service call
ONE INCIDENT · COMPLETE LOOP
See how the Runtime DIP moves from signal to verified outcome.
A production workload begins an unfamiliar execution sequence.
Ollandi relates the process to image lineage, deployment, identity, network destination, and service dependency.
A bounded communication restriction or quarantine is validated against availability and authority.
Execution and service health are checked before the incident is closed.
PART OF OLLANDI - NOT ANOTHER SILO
The DIP supplies depth. Ollandi supplies the shared state, threat reasoning, action validation, and evidence.
Domain state→Cross-domain hypothesis→Policy-checked action→Verified evidence
See the complete Ollandi lifecycle