Deploy Prisma Cloud Defenders

To take advantage of the agent-based security features of Prisma Cloud, you must deploy the Defender agent.
You can deploy single Defenders for containers, hosts, and serverless functions or deploy Defenders on entire clusters using an orchestrator. There are several Defender types based on the assets they protect and how you wish to deploy them.

Defender capabilities

The following table summarizes the key functional differences between Defender types.
Capabilities
Defender type
Container
1
Host
Serverless
App-Embedded
Deployment methods
Console UI
Y
Y
Y
Y
API
Y
Y
Y
Y
twistcli
Y
Y
Vulnerability management
Y
Y
Y
2
Y
3
Compliance
Y
Y
Y
2
Y
4
Runtime defense
Behavioral modeling
Y
Process
Y
Y
Y
Y
Networking
Y
Y
Y
Y
File system
Y
Y
Y
Y
Forensics
Y
Y
Y
Access control
Kubernetes auditing
Y
5
Y
5
Admission control
Y
Firewalls
WAAS
Y
Y
Y
Y
CNNS
Y
Y
Radar (visualization)
Radar
Y
Y
Y
1
Container Defender supports all Host Defender capabilities. You can deploy single container and host Defenders or deploy container and host Defenders using an orchestrator.
2
Normally Defender scans workloads for vulnera