Detect and Monitor

Workload Protection evaluates your workload activity against several kinds of rules. Together they detect threats, assess your runtime security posture, and provide granular audit capabilities. Agent rules select which activity reaches Datadog. Detection rules and finding rules analyze that activity. Threat intelligence enriches it with reputation context, and Content Packs bundle optional rules for specific software stacks and threat vectors.

For how these rules fit together in the detection pipeline, see How Workload Protection works.

Agent rules

Agent rules define which system activity is sent to the Datadog backend for further analysis:

Detection and finding rules

Detection and finding rules describe the backend logic used to analyze Agent events and generate signals or findings:

Threat intelligence

Workload Protection uses threat intelligence databases to enrich your Agent Events and detect malware and known malicious entities. The Threat Intelligence page helps you:

  • Explore the threat intelligence databases that are provided out-of-the-box (OOTB) with Workload Protection
  • Import your own threat intelligence database and configure it to work with Workload Protection

Content Packs

Workload Protection provides targeted, Datadog-crafted Content Packs built for specific software stacks, threat vectors, and emerging vulnerabilities. The Content Packs page helps you:

  • Explore and enable Content Packs for key workload security use cases
  • Deploy optional detections only to the workloads where they apply
  • Stay current with emerging threats through Datadog-managed rule updates