Set up Elastic Security
Deploy the Elastic Security protections that cover your hosts, cloud accounts, and Kubernetes clusters. You do these tasks once for each feature, when you first turn it on.
After setup, each feature sends its data to Elastic Security, where you can review alerts, findings, and risk scores. To tune policies, manage exceptions, and control access after deployment, refer to Manage.
Each protection covers a different part of your environment, so the features you set up depend on what you run:
- Elastic Defend: Protects Windows, macOS, and Linux hosts, including Linux VMs in the cloud. It runs on Elastic Agent, which you install on each host. It can detect or block malware, ransomware, and malicious behavior.
- Cloud security: Checks your cloud accounts and Kubernetes clusters against security best practices, lists your cloud assets, and scans your AWS EC2 Linux workloads for known vulnerabilities.
-
Defend for Containers: Detects, and can block, unexpected behavior inside running Kubernetes containers.
| Your goal | Start here |
|---|---|
| Protect hosts from malware, ransomware, and malicious behavior | Configure endpoint protection with Elastic Defend |
| Check your cloud accounts and Kubernetes clusters for misconfigurations and vulnerabilities | Set up cloud security |
|
|
Get started with Defend for Containers for Kubernetes |
| Check what you need for entity risk scoring, asset criticality, and the entity store | Entity analytics requirements |
| Check what you need to run machine learning jobs and rules | Machine learning job and rule requirements |
After you set up your protections, you can:
- Manage Elastic Security to tune policies, manage exceptions, and give users access to each feature.
- Ingest data from third-party security tools and threat intelligence sources.
- Detect and alert on threats with prebuilt and custom detection rules.
- Hunt and assess posture to review findings and risk scores from the features you set up.