> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/runtime-security/runtime-security.md).

# Runtime Security

Welcome to the Runtime Security documentation. Use the following table to explore how Runtime Security can help secure your environment.

| What do you want to do?                                                                                                                       | Start here                                                                                                                                                                                             |
| --------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| See the system requirements needed to enable runtime security                                                                                 | [System requirements](/content-collections/runtime-security/install/system-requirements.md)                                                                                                            |
| Onboard your cloud accounts                                                                                                                   | [Connect Cloud Accounts](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/connect/connect-cloud-accounts/connect-cloud-accounts.md)                     |
| Inspect the risks and vulnerabilities of your cloud workloads without having to install an agent or affecting the execution of your workload. | [Agentless scanning](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/agentless-scanning/agentless-scanning.md)                        |
| Provide predictive protection for containers and threat based active protection for running containers, hosts and serverless functions        | [Runtime defense](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/runtime-defense/runtime-defense.md)                                 |
| Provide both predictive and threat-based active protection for running containers in clusters or individually                                 | [Runtime defense for containers](/content-collections/runtime-security/runtime-defense/runtime-defense-containers.md)                                                                                  |
| Detect malware, network, log inspection, file integrity, activities, and custom events in your hosts                                          | [Runtime defense for hosts](/content-collections/runtime-security/runtime-defense/runtime-defense-hosts.md)                                                                                            |
| Monitor process, network, and filesystem activity within your serverless functions and enforce policies to allow or deny these activities     | [Runtime defense for serverless functions](/content-collections/runtime-security/runtime-defense/runtime-defense-serverless.md)                                                                        |
| Monitor and protect your containers at runtime, ensuring they execute as designed, and securing them against suspicious activity              | [Runtime defense for app-Embedded](/content-collections/runtime-security/runtime-defense/runtime-defense-app-embedded.md)                                                                              |
| Determine the type of agent you should deploy                                                                                                 | [Defender types](/content-collections/runtime-security/install/deploy-defender/defender-types.md)                                                                                                      |
| Dynamically analyze the runtime behavior of images before running them in your development and production environments                        | [Image analysis sandbox](/content-collections/runtime-security/runtime-defense/image-analysis-sandbox.md)                                                                                              |
| Learn how to deploy Defenders                                                                                                                 | [Deploy Prisma Cloud Defenders](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/install/deploy-defender/deploy-defender.md)           |
| Deploy a single container Defender                                                                                                            | [Install a Single Container Defender](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/install/deploy-defender/container/container.md) |
| Deploy Defenders on Kubernetes clusters                                                                                                       | [Kubernetes](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/install/deploy-defender/kubernetes/kubernetes.md)                        |
| Deploy a host Defender                                                                                                                        | [Install a single Host Defender](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/install/deploy-defender/host/host.md)                |
| Deploy a serverless Defender                                                                                                                  | [Serverless Defender](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/install/deploy-defender/serverless/serverless.md)               |
| Deploy an app-embedded Defender                                                                                                               | [Deploy app-embedded Defender](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/install/deploy-defender/app-embedded/app-embedded.md)  |
| Review the permissions needed to enable runtime security                                                                                      | [Permissions by feature](/content-collections/runtime-security/configure/permissions.md)                                                                                                               |
| Monitor the containers and hosts in your environment                                                                                          | [Radar](/content-collections/runtime-security/runtime-security-components/radar.md)                                                                                                                    |
| Monitor the serverless functions in your environment                                                                                          | [Serverless Radar](/content-collections/runtime-security/runtime-security-components/serverless-radar.md)                                                                                              |
| Learn about the enterprise identity support                                                                                                   | [Authentication](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/authentication/authentication.md)                                    |
| Find all cloud-native services being used across cloud service providers                                                                      | [Cloud discovery](/content-collections/runtime-security/cloud-service-providers/cloud-discovery.md)                                                                                                    |
| Identify and prevent vulnerabilities across the entire application lifecycle while prioritizing risk for your cloud native environments.      | [Vulnerability management](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/vulnerabilty-management/vulnerability-management.md)       |
| Establish and monitor access control measures for cloud workloads and cloud native applications                                               | [Access control](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/access-control/access-control.md)                                    |
| Monitor and enforce compliance for Kubernetes clusters, hosts, containers, and serverless environments                                        | [Compliance](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/compliance/compliance.md)                                                |
| Integrate runtime security into your continuous integration workflows                                                                         | [Continuous integration (CI)](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/continuous-integration/continuous-integration.md)       |
| Secure web applications by inspecting and filtering layer 7 traffic to and from the application                                               | [Web-Application and API Security (WAAS)](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/waas/waas.md)                               |
| Ensure the safe distribution of secrets                                                                                                       | [Secrets](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/secrets/secrets.md)                                                         |
| Send alerts for critical policy breaches                                                                                                      | [Alerts](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/alerts/alerts.md)                                                            |
| Create and store audit event records for all major subsystems.                                                                                | [Audit](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/runtime-security/audit/audit.md)                                                               |
| Install a command-line configuration and control tool                                                                                         | [twistcli](/content-collections/runtime-security/tools/twistcli.md)                                                                                                                                    |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/runtime-security/runtime-security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
