logo

Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

ID: bd89fdda-aef7-53d8-8e06-1c4f9bacaab2

STIX ID: report--bd89fdda-aef7-53d8-8e06-1c4f9bacaab2

Feed Name: Elastic Security Labs

Date Published: 2026-03-19

Date Updated: 2026-04-27

...
...

**Executive Summary:** This post documents Elastic Stack 9.3.0's Defend for Containers integration, explaining how to deploy the Elastic Agent integration in Kubernetes, author and tune policy selectors and responses, and use the runtime process and file telemetry (with container and orchestration context) to build behavior-driven detections for containerized workloads; it also outlines current Beta limitations (no network events, limited AKS support, file-open semantics) and recommends validation workflows before enabling blocking actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.