Manage cloud workload protection
Cloud workload protection detects threats on your Linux VMs and Kubernetes workloads while they run, and can block some of them. It also sends process, file, and network activity to Elastic Security, where Elastic's prebuilt detection rules and machine learning models can use it to find threats.
To deploy cloud workload protection first, refer to Set up. To review cloud configuration findings and benchmarks instead, refer to Cloud Security.
Cloud workload protection uses one integration for VMs and another for Kubernetes containers:
- Linux VMs: Use Elastic Defend, the same integration that protects your other hosts. It detects and prevents malicious behavior, memory threats, and malware. To collect session data by default, select one of the Cloud workloads presets when you configure the integration.
-
Kubernetes containers: Use the Defend for Containers (D4C) integration. Each D4C policy has selectors, which match file and process operations, and responses, which log, alert on, or block the operations that match. The default policy logs process activity for threat detection, and alerts on drift, which is a change to a container's executables.
| Your goal | Start here |
|---|---|
| Understand how Elastic Defend protects Linux VMs | Cloud workload protection for VMs |
| Add environment variables to the process data that Elastic Agent collects | Capture environment variables |
|
|
Cloud workload protection for Kubernetes |
|
|
Container workload protection policies |
|
|
Kubernetes dashboard |
After you configure cloud workload protection, you can:
- Manage Elastic Defend to tune policies and exceptions for your Linux VMs.
- Install prebuilt rules that detect threats in container and cloud workload data.
- Review a Linux process session in Session View to investigate suspicious activity.