The content of this page has been automatically translated by AI. If you encounter any problems while reading, you can view the corresponding content in Chinese.

Quick Start

Last updated: 2025-09-09 16:17:53

Step 1: Install Host Security

Log on to the CWPP Console and go to the Security Overview page to check if the Cloud Virtual Machine has Host Security installed.
Description
When purchasing a Tencent CVM or Blackstone Physical Server 1.0 (CPM), you can select "Security Reinforcement" to automatically install the CWPP client.

① Cloud Virtual Machines with CWPP installed and professional or flagship protection enabled enjoy comprehensive and multi-dimensional system security provided by CWPP.
② Cloud Virtual Machines with the basic version of Host Security installed can click Upgrade on the right to upgrade to professional protection or flagship protection.
③ Cloud Virtual Machines without the host security client installed can click Install on the right and follow the instructions to install it:

Windows CVM Environment

Supported versions

Currently supported versions:
Windows Server 2008, 2012, 2016, 2019, 2022 (32-bit or 64-bit).
Windows 10, 11 (64bit).

Host security client installation

Server Type
Server Product
Server Architecture
Network Location
Client Download and Installation
Tencent Cloud
CVMs, Lighthouse servers, blackstone servers, ECMs
x86
<VPC Network>
Open the cmd command line window, paste and run the following install command:
powershell -executionpolicy bypass -c "(New-Object Net.WebClient).DownloadFile('http://u.yd.tencentyun.com/ydeyes_win32.exe', $ExecutionContext.SessionState.Path.GetUnresolvedProviderPathFromPSPath('.\ydeyes_win32.exe'))"; "./ydeyes_win32.exe"
Tencent Cloud
Cloud Virtual Machine
x86
Basic Network
Open the cmd command line window, paste and run the following install command.
powershell -executionpolicy bypass -c "(New-Object Net.WebClient).DownloadFile('http://u.yd.qcloud.com/ydeyes_win32.exe', $ExecutionContext.SessionState.Path.GetUnresolvedProviderPathFromPSPath('.\ydeyes_win32.exe'))"; "./ydeyes_win32.exe"
Non-Tencent Cloud
/
x86
Public network, dedicated line
Due to the validity period limit of the command, please go to the Host list to view the installation instruction and download and install the client.

Installation instructions

Windows installation status verification: Open the task manager and check whether the YDService and YDLive processes are called. If they are called, the installation is successful.


Linux CVM Environment

Supported versions

Currently supported versions (64bit):
TencentOS Server
Tencent tlinux
CentOS 6 or later versions
Ubuntu 9.10 and above
Debian 6 or later versions
RHEL 6 or later versions
OpenCloudOS
AlmaLinux
openSUSE
Rocky Linux
Red Hat 6 or above
Alibaba Cloud Linux
Amazon Linux

Host security client installation

Server Type
Server Product
Server Architecture
Network Location
Client Download and Installation
Tencent Cloud
CVMs, Lighthouse servers, blackstone servers, ECMs
x86
VPC Network
wget http://u.yd.tencentyun.com/ydeyes_linux64.tar.gz -O ydeyes_linux64.tar.gz && tar -zxvf ydeyes_linux64.tar.gz && ./self_cloud_install_linux64.sh
Tencent Cloud
Cloud Virtual Machine
x86
Basic Network
wget http://u.yd.qcloud.com/ydeyes_linux64.tar.gz -O ydeyes_linux64.tar.gz && tar -zxvf ydeyes_linux64.tar.gz && ./self_cloud_install_linux64.sh
Tencent Cloud
CVMs, Lighthouse servers, blackstone servers, ECMs
arm
VPC Network
wget http://u.yd.tencentyun.com/ydeyes_linux64_aarch64.tar.gz -O ydeyes_linux64_aarch64.tar.gz && tar -zxvf ydeyes_linux64_aarch64.tar.gz && ./self_cloud_install_linux64.sh
Tencent Cloud
Cloud Virtual Machine
arm
Basic Network
wget http://u.yd.qcloud.com/ydeyes_linux64_aarch64.tar.gz -O ydeyes_linux64_aarch64.tar.gz && tar -zxvf ydeyes_linux64_aarch64.tar.gz && ./self_cloud_install_linux64.sh
Non-Tencent Cloud
/
x86, arm
Public network, dedicated line
Due to the command valid period limitation, please go to the host list to view the installation guide and download and install the client.

Installation instructions

Execute the command and check whether the YDService and YDLive processes are running. If they are running, the installation is successful.
ps -ef | grep YD

Note: If the processes are not running, you can manually execute the command as the root user to start the programs. The command is:
/usr/local/qcloud/YunJing/startYD.sh

Step 2: Operate Host Security

CWPP can process and display the server security information in real time. With the CWPP agent installed, you can configure it to detect and isolate Trojan files, detect vulnerabilities and suspicious logins, create allowlists, prevent password cracking and set alarms. For details, see Operation Guide.

Step 3: Troubleshooting

If your server is intruded, you can perform troubleshooting by referring to the troubleshooting guide to restore the website or system to normal operation. For details, see Intrusions on Linux or Intrusions on Windows.

Step 4: Uninstall Host Security

If you no longer need Host Security protection, you can uninstall it. There are two ways to uninstall Host Security: from the console or from the system. The detailed steps are as follows:

Uninstalling in the console

1. Log in to the CWPP Console, select Asset Management > Host list in the left navigation bar to check if your CVM has CWPP installed.
2. In the server list, select the server from which you want to uninstall the host security, and click Uninstall in the action bar on the right.


Uninstalling in the system

Windows system: Follow the path C:\Program Files\QCloud\YunJing\uninst.exe, find the uninst.exe file, and double-click to uninstall.
Linux system: Enter the command if [ -w '/usr' ]; then /usr/local/qcloud/YunJing/uninst.sh ; else /var/lib/qcloud/YunJing/uninst.sh ; fi to uninstall.

FAQs

How To Handle Firewall Interception During Installation?

It is recommended to allow the host security backend server access address in the firewall policy:
VPC network domain name: s.yd.tencentyun.com, l.yd.tencentyun.com, u.yd.tencentyun.com
VPC network IP: 169.254.0.55
Basic network domain name: s.yd.qcloud.com, u.yd.qcloud.com, l.yd.qcloud.com
Basic network IP: 10.148.188.202, 10.148.188.201, 11.177.125.116, 11.177.124.86, 11.149.252.57, 11.149.252.62, 11.149.252.51
Non-Tencent Cloud public network domain: sp.yd.qcloud.com, up.yd.qcloud.com, lp.yd.qcloud.com
Non-Tencent Cloud public network IP: 120.232.65.223, 157.148.45.20, 183.2.143.163
Port: 5574, 8080, 80, 9080 (port 443 also needs to be open for public network)

How To Set Up If Not Using the Default DNS?

If you do not use the default DNS, you need to forward all resolutions of the root domains tencentyun.com and yd.qcloud.com to the default DNS.