What problem does it solve? Managing runtime security detection rules and tracking Cloud Workload Security agent coverage across a large fleet requires navigating complex Datadog APIs and SECL expression syntax, which is slow and error-prone when done manually. ## Core Features & Use Cases - Agent Rules Management: Create, list, update, and delete Workload Protection detection rules written in SECL (Security Event Language), with support for MITRE ATT&CK product tags and rule actions like kill, set, and hash. - Policy Management: Group rules into policies targeted at hosts via host tags or AND/OR host tag lists, and download policies for manual or air-gapped deployment. - Deployment Monitoring: List CSM agents and serverless agents (Fargate, Lambda) with filters on CWS enablement, CSPM status, and Remote Configuration to identify coverage gaps. - Use Case: Ask which production hosts lack CWS coverage, then create a privilege-escalation detection rule and assign it to a Kubernetes production policy in one workflow. ## Quick Start Ask the agent to list all Workload Protection rules and show which hosts have CWS enabled.