---
title: Threat Protection
description: >-
  Detect, investigate, and block application and API attacks in real time with
  Threat Protection in App and API Protection.
breadcrumbs: Docs > Datadog Security > App and API Protection > Threat Protection
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Threat Protection

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

Use Threat Protection in [App and API Protection](https://docs.datadoghq.com/security/application_security.md) (AAP) to detect attacks against your applications and APIs, perform investigations, and block malicious traffic in real time.

To get started, [set up AAP](https://docs.datadoghq.com/security/application_security/setup.md) on your services so they report security traces. AAP then detects threats from your live application traffic and lets you respond to them.

## How Threat Protection works{% #how-threat-protection-works %}

Threat Protection brings together several capabilities, all built on live application traffic data. With Threat Protection, you can:

- Detect and investigate threats with [Security Signals](https://docs.datadoghq.com/security/application_security/threat_protection/security_signals.md). Datadog creates a security signal when it detects a threat from a detection rule, so you can triage, filter, and investigate attacks in the Signals Explorer.
- Block attacks and attackers with [Policies](https://docs.datadoghq.com/security/application_security/threat_protection/policies.md). Block malicious IP addresses and users in real time from the Datadog UI, manually or through automated rules.
- Stop exploit attempts in code with [Exploit Prevention](https://docs.datadoghq.com/security/application_security/threat_protection/exploit-prevention.md). Detect and block attempts to exploit vulnerabilities, including zero-day attacks, from within the running application.
- Extend protection to the perimeter with [WAF Integrations](https://docs.datadoghq.com/security/application_security/threat_protection/waf-integration.md). Combine in-app protection with edge defenses such as AWS WAF for a defense-in-depth approach.
- Defend user accounts with [Account Takeover Protection](https://docs.datadoghq.com/security/application_security/threat_protection/account_takeover_protection.md). Detect and mitigate account takeover attacks, such as credential stuffing, and disable compromised users.

## Further reading{% #further-reading %}

- [Protect your applications from zero-day attacks with Datadog Exploit Prevention](https://www.datadoghq.com/blog/datadog-exploit-prevention/)
