﻿---
title: Manage cloud workload protection
description: Configure Elastic Security runtime protection for Linux VMs and Kubernetes workloads after you deploy it.
url: https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage/manage-cloud-workload-protection
products:
  - Elastic Cloud Serverless
  - Elastic Documentation
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Manage cloud workload protection
Cloud workload protection detects threats on your Linux VMs and Kubernetes workloads while they run, and can block some of them. It also sends process, file, and network activity to Elastic Security, where Elastic's prebuilt detection rules and machine learning models can use it to find threats.
To deploy cloud workload protection first, refer to [Set up](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/set-up). To review cloud configuration findings and benchmarks instead, refer to [Cloud Security](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/cloud).

## How protection works on VMs and Kubernetes

Cloud workload protection uses one integration for VMs and another for Kubernetes containers:
- **Linux VMs**: Use Elastic Defend, the same integration that protects your other hosts. It detects and prevents malicious behavior, memory threats, and malware. To collect session data by default, select one of the **Cloud workloads** presets when you configure the integration.
- <applies-to>Elastic Cloud Serverless: Beta</applies-to> <applies-to>Elastic Stack: Beta since 9.3</applies-to> **Kubernetes containers**: Use the Defend for Containers (D4C) integration. Each D4C policy has selectors, which match file and process operations, and responses, which log, alert on, or block the operations that match. The default policy logs process activity for threat detection, and alerts on drift, which is a change to a container's executables.


## Where to start


| Your goal                                                                                                                                                                                    | Start here                                                                                                                                            |
|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------|
| Understand how Elastic Defend protects Linux VMs                                                                                                                                             | [Cloud workload protection for VMs](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/cloud/cloud-workload-protection-for-vms) |
| Add environment variables to the process data that Elastic Agent collects                                                                                                                    | [Capture environment variables](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/cloud/capture-environment-variables)         |
| <applies-to>Elastic Cloud Serverless: Beta</applies-to> <applies-to>Elastic Stack: Beta since 9.3</applies-to> Learn how D4C protects Kubernetes containers, and which platforms it supports | [Cloud workload protection for Kubernetes](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/cloud/d4c/d4c-overview)           |
| <applies-to>Elastic Cloud Serverless: Beta</applies-to> <applies-to>Elastic Stack: Beta since 9.3</applies-to> Allow expected container behavior and block drift                             | [Container workload protection policies](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/cloud/d4c/d4c-policies)             |
| <applies-to>Elastic Cloud Serverless: Beta</applies-to> <applies-to>Elastic Stack: Beta since 9.3</applies-to> Monitor your Kubernetes clusters and workloads                                | [Kubernetes dashboard](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/dashboards/kubernetes-dashboard)                      |


## Next steps

After you configure cloud workload protection, you can:
- [Manage Elastic Defend](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage-elastic-defend) to tune policies and exceptions for your Linux VMs.
- [Install prebuilt rules](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/detect-and-alert/install-prebuilt-rules) that detect threats in container and cloud workload data.
- Review a Linux process session in [Session View](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/investigate/session-view) to investigate suspicious activity.