---
title: Content Packs
description: >-
  Enable Datadog-curated Content Packs to deploy optional detections for
  specific software stacks and threat vectors.
breadcrumbs: >-
  Docs > Datadog Security > Workload Protection > Detect and Monitor > Content
  Packs
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Content Packs

Not every detection rule is relevant to every workload. Some detections can be too noisy for environments with specific constraints, or may not apply to particular software stacks. At the same time, new threats emerge regularly, and Datadog security research team continuously develops rules to detect novel attacks and vulnerabilities.

Workload Protection [Content Packs](https://app.datadoghq.com/security/workload-protection/overview#content-packs) address both challenges. Each Content Pack is a Datadog-crafted bundle of optional [Agent rules](https://docs.datadoghq.com/security/workload_protection/detect_and_monitor/agent_rules.md), [detection rules](https://docs.datadoghq.com/security/workload_protection/detect_and_monitor/detection_and_finding_rules/detection_rules.md), and supporting content built for a specific software stack, threat vector, or emerging vulnerability. You opt in to the Content Packs you need and deploy them only to the workloads where they apply.

## Benefits{% #benefits %}

- **Deploy targeted detections to relevant workloads:** Opt into policies built for specific workloads or environments, and deploy them only where they apply. This avoids unnecessary noise and performance impact on workloads where those detections do not apply.
- **Stay ahead of emerging threats:** Get access to new rules as Datadog security research team identifies novel threats and vulnerabilities, complementing the coverage provided by default policies.

## Included content{% #included-content %}

Depending on the Content Pack, a bundle can include:

- **Agent rules** packaged in a [policy](https://docs.datadoghq.com/security/workload_protection/detect_and_monitor/agent_rules/policy_management.md) scoped to the workloads the Content Pack targets
- **Detection rules** that raise [security signals](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals.md) when matching activity is detected
- **Finding rules** that evaluate runtime security posture for the covered use case
- Configuration guidance for deploying the Content Pack in your environment

## Enable a Content Pack{% #enable-a-content-pack %}

1. Go to [Content Packs](https://app.datadoghq.com/security/workload-protection/overview#content-packs).
1. Browse the available Content Packs and select one.
1. Review the included Agent rules, detection rules, and deployment requirements.
1. Click Enable to activate the Content Pack and go to the associated policy page.

Enabling a Content Pack adds its associated policy and rules to your organization. To start detecting threats, deploy the associated policy to your infrastructure.

## Deploy a Content Pack{% #deploy-a-content-pack %}

Content Packs deploy through [policies](https://docs.datadoghq.com/security/workload_protection/detect_and_monitor/agent_rules/policy_management.md). After you enable a Content Pack, scope its policy to the workloads where the detections apply:

1. Go to [Policies](https://app.datadoghq.com/security/workload-protection/policies).
1. Open the policy associated with the Content Pack you enabled.
1. Click Edit next to the deployment scope.
1. Add [tags](https://docs.datadoghq.com/getting_started/tagging.md) to target specific hosts, clusters, or environments.
1. Toggle the policy to enabled and confirm deployment.

For more information about policy deployment, see [Policy management](https://docs.datadoghq.com/security/workload_protection/detect_and_monitor/agent_rules/policy_management.md).

## Deactivate a Content Pack{% #deactivate-a-content-pack %}

1. Go to [Content Packs](https://app.datadoghq.com/security/workload-protection/overview#content-packs).
1. Browse the available Content Packs and select one that is activated.
1. Click Deactivate to remove the associated policy from the policy page.
