Workload Protection enriches Agent events with Threat Intelligence curated by Datadog. This enrichment adds reputation context to entities observed on your hosts and containers, such as IP addresses and file hashes, to help you assess whether an event is part of a known malicious campaign.

For general concepts, sources, categories, intents, and life cycle information that apply across all Datadog security products, see Threat Intelligence. This page covers the details specific to Workload Protection.

Entity types for Workload Protection

Workload Protection supports the following entity types:

  • IP addresses
  • Domains
  • File hashes: SHA1, SHA256, and ssdeep

ssdeep hashes support fuzzy matching, which helps identify files that are similar, but not identical, to a known malicious file.

Supported categories for Workload Protection

Workload Protection supports the following threat intelligence categories:

  • malware
  • exploitation
  • cryptomining
  • supply_chain_attack_infrastructure
  • custom

For category definitions and intents that apply across Datadog security products, see Threat intelligence categories.

Using threat intelligence in detection rules

Detection rules in Workload Protection can reference threat intelligence keys such as category (@threat_intel.results.category) and intent (@threat_intel.results.intention) in the search query or rule conditions. For example, a rule can trigger when a file executed on a workload matches the hash of a known malware sample, categorized as malware with intent malicious.

Threat intelligence sources and categories are not configurable.

Threat intelligence facets

Threat intelligence sources, categories, and intents are available as facets and filters. You can see threat intelligence enrichments on matching events in the Agent Events Explorer and on the resulting security signals.

Threat intelligence on security signals

When an Agent event matches a threat intelligence indicator, Workload Protection generates a security signal that displays the matched entity along with its source, category, and intent.

A Workload Protection security signal displaying threat intelligence enrichment details

Further reading

Additional helpful documentation, links, and articles: