Manage cloud workload protection

Cloud workload protection detects threats on your Linux VMs and Kubernetes workloads while they run, and can block some of them. It also sends process, file, and network activity to Elastic Security, where Elastic's prebuilt detection rules and machine learning models can use it to find threats.

To deploy cloud workload protection first, refer to Set up. To review cloud configuration findings and benchmarks instead, refer to Cloud Security.

Cloud workload protection uses one integration for VMs and another for Kubernetes containers:

  • Linux VMs: Use Elastic Defend, the same integration that protects your other hosts. It detects and prevents malicious behavior, memory threats, and malware. To collect session data by default, select one of the Cloud workloads presets when you configure the integration.
  • Kubernetes containers: Use the Defend for Containers (D4C) integration. Each D4C policy has selectors, which match file and process operations, and responses, which log, alert on, or block the operations that match. The default policy logs process activity for threat detection, and alerts on drift, which is a change to a container's executables.
Your goal Start here
Understand how Elastic Defend protects Linux VMs Cloud workload protection for VMs
Add environment variables to the process data that Elastic Agent collects Capture environment variables
Learn how D4C protects Kubernetes containers, and which platforms it supports Cloud workload protection for Kubernetes
Allow expected container behavior and block drift Container workload protection policies
Monitor your Kubernetes clusters and workloads Kubernetes dashboard

After you configure cloud workload protection, you can: