ESET PROTECT – Table of Contents

Amazon Web Services

ESET Cloud Workload Protection—Microsoft Azure, Amazon Web Services, Google Cloud Platform main features

Enables visibility and protection of cloud workloads by synchronizing virtual machines organized in resource groups.

Enables deployment of security protection to workloads, either manually or automatically, for newly created instances.

Provides endpoint-level security indicators from protected workloads, expanding visibility into threats across cloud environments.

Provides extended asset context in Incidents and supports response actions on protected machines.

Ingests more cloud indicators and telemetry, expanding visibility into cloud environment activity.

How to enable the integration

Prerequisites

Review and complete all prerequisites that apply to your chosen path before starting the CloudFormation template deployment.

arrow_down_businessAll deployments
arrow_down_businessOrganization-wide deployments
arrow_down_businessOrganization-wide deployment with DHMC setup
arrow_down_businessPrerequisite for VM Protection Deployment

Integration setup in ESET PROTECT Web Console


Important

See required permissions for CWP role in the AWS account.

Click Connect to go through the Connect Integration process:

1.General Setup—type Name, select a method: AWS Organizations (with Root Organization Unit ID) or AWS single account (with Account ID), type Client description and click Continue.

2.Host Management—select if the Default Host Management Configuration is enabled in your AWS account.

3.CloudFormation—create a stack in AWS (click the Launch in AWS button to check the stack status or complete the setup) and then select Confirm Status.

4.Integration Summary—review Integration Summary with your settings (Name, Method, Account ID, ESET CWP S3 Bucket, Client description) and click Finish.


Important

When an integration is finished (Status: Active), you can the see virtual machines synchronized in the Integration in Computers > Companies tree > selected organization (static group).

Deployment

System requirements and supported operating systems

You can deploy the ESET protection to virtual machines that meet the system requirements for the installation of the ESET security application:

ESET Server Security for Windows (Windows VMs)

ESET Server Security for Linux (Linux VMs)

Auto deployment

By default, auto-deployment is turned off. You can define how ESET Cloud Workload Protection behaves on virtual machines integrated from your connected cloud environments in the Configuration section.

If configured, every 15 minutes it is checked if there is an eligible virtual machine in the given group (target) to start deployment. If yes, the ESET Management Agent and then a security product will be installed on the virtual machine in a few minutes.

Audit log contains information about starting deployment.

Manual deployment

Select the computers on which you want to enable ESET security product. A subscription will be assigned automatically.

1.Go to Computers > select Company (static group) > list virtual machines.

2.Select the virtual machine > click the three dots icon_more_vertical button > select Platform modules > click Enable ESET security application for cloud.

3.Select Targets.

4.Select to agree to Legal documents and click Enable.

Reverting cloud-side changes

When the integration has been successfully removed from the portal, perform the following steps to fully revert all changes made on the cloud side:

1. Delete the CloudFormation Stack

arrow_down_businessIn the AWS Console (the easiest way):

2. Verify S3 Bucket Cleanup

During the deletion process, the CloudTrail S3 bucket should be emptied and removed automatically. Errors can occur, for example, if CloudTrail is still writing logs to the bucket during deletion, or if a custom Service Control Policy (SCP) prevents the operation. Therefore, we recommended to verify that the bucket has been successfully deleted.

arrow_down_businessFind CWP S3 Buckets:

Note

Only the root account user of your AWS account can delete the CWP S3 bucket. Regular Identity and Access Management (IAM) users are unable to perform this action.

3. Organization deployments only

Disable trusted access between AWS CloudFormation and AWS Organizations, and remove the service-linked role AWSServiceRoleForCloudFormationStackSetsOrgAdmin if it is no longer required.

arrow_down_businessSteps in the AWS Console:

Note

Trusted access between AWS CloudFormation and AWS Organizations may be used by multiple CloudFormation StackSets deployments. Do not disable trusted access unless you have confirmed that it is no longer required. Trusted access might have already been enabled before deploying the CWP CloudFormation stack.

4. Organization deployments with DHMC setup only

arrow_down_businessDisable Systems Manager integration with Organizations

Important

Disabling Systems Manager trusted access affects all Systems Manager deployments across your organization. Disable it only if you do not use other SSM configurations.

arrow_down_businessDisable SSM QuickSetup Integration with Organizations

Important

This step disables centralized configuration management for SSM Quick Setup across your organization. Only perform this step if you are completely removing all SSM Quick Setup deployments.

arrow_down_businessDelete SSM QuickSetup Explorer Role

Important

Deleting the role may impact SSM Explorer-related capabilities. Ensure that SSM Explorer features are no longer required before deleting the role.

arrow_down_businessDelete SSM Service-Linked Roles

Important

Delete service-linked roles if no services use them.

5. Deployments with DHMC setup only

If you do not require Default Host Management Configuration (DHMC), disable it in all AWS Regions. In an organization-wide deployment, disable this setting only in the AWS Organizations management account. If you need to continue using Default Host Management Configuration (for example, to use AWS Systems Manager), replace the IAM role created by the CWP deployment (SSMDefaultEC2InstanceManagementRole) with another valid IAM role. The SSMDefaultEC2InstanceManagementRole is removed during stack deletion, and leaving it configured will cause Default Host Management Configuration to reference a non-existent role.

arrow_down_businessSteps in the AWS Management Console: