Cloud Security
Elastic Security for Cloud helps you improve your cloud security posture by comparing your cloud configuration to best practices, and scanning for vulnerabilities.
To set up these features, refer to Set up cloud security.
Discovers and evaluates the services in your cloud environment — like storage, compute, IAM, and more — against configuration security guidelines defined by the Center for Internet Security (CIS) to help you identify and remediate risks that could undermine the confidentiality, integrity, and availability of your cloud data.
Allows you to identify configuration risks in the various components that make up your Kubernetes cluster. It does this by evaluating your Kubernetes clusters against secure configuration guidelines defined by the Center for Internet Security (CIS) and generating findings with step-by-step instructions for remediating potential security risks.
Creates an up-to-date, unified inventory of your cloud resources from AWS, GCP, and Azure. Once you connect your cloud accounts, this integration automatically finds and lists your cloud services and assets, such as:
- AWS: S3 buckets, EC2 instances, EKS clusters, and more.
- GCP: Cloud Storage buckets, Compute Engine instances, Kubernetes clusters, and more.
- Azure: Virtual Machines, Blob Storage, Azure Kubernetes Service (AKS), and more.
Read the Cloud Asset Discovery docs.
Scans your cloud workloads for known vulnerabilities. When it finds a vulnerability, it supports your risk assessment by quickly providing information such as the vulnerability’s CVSS and severity, which software versions it affects, and whether a fix is available.
Runtime protection for Linux VMs and Kubernetes workloads detects and blocks threats while they happen, rather than assessing configuration. For details, refer to Manage cloud workload protection.