Collecting events using Cloud Security Management will affect your billing. For more information, see Datadog Pricing.

The following table summarizes the Cloud Security features available relative to each deployment type.

Deployment typeAgent Required (7.46+)MisconfigurationsWorkload ProtectionVulnerabilitiesIdentity RisksAgentless Scanning
AWS Account
Azure AccountAgentless Scanning (Preview)
GCP Account
Terraform
Docker
Kubernetes
Linux
Amazon ECS/EKS
Windows
AWS Fargate ECS/EKS

The following table summarizes the scope of coverage available relative to each Cloud Security feature.

Resources monitoredMisconfigurationsWorkload ProtectionVulnerabilitiesIdentity RisksAgentless scanning
Resources in AWS Account
Resources in Azure Subscription
Resources in GCP Project
Kubernetes Cluster
Docker Host
Linux Host
Windows Host
Docker Container
Container Image
IAM in AWS Account

Note: Cloud Security Misconfigurations additionally monitors common resources used in your cloud accounts that are running Windows and AWS Fargate, such as EC2 instances, RDS, S3, and ELB.