Lacework is a cloud-native application protection platform offered as-a-Service; delivering build-time to run-time threat detection, behavioral anomaly detection, and cloud compliance across multicloud environments, workloads, containers, and Kubernetes.
N/A
Trellix Cloud Workload Security
Score 6.8 out of 10
N/A
Trellix Cloud Workload Security (formerly from McAfee) to give users a real-time view of running workloads through detecting workloads and pods. This product can integrate with both public and private cloud infrastructures.
Lacework is well suited for behavioral analysis. One thing to consider thought is in the early stages there will be quite a bit of noise generated by Lacework. There will be a higher volume alerts generated initially - until a good baseline is generated. Overall Lacework is good with alert handling - integration with Slack is good.
Suitable scenario: The McAfee Cloud Workload Security console has helped me a lot in saving physical resources. We no longer have to have a server and spend resources to maintain the console, everything is in the cloud. Unsuitable scenario: After the change to the cloud the McAfee Cloud Workload Security reduced many things that were made very easy when it was on a physical server. Active directory server integration with the console is a bit tricky. That should be improved and be somewhat more friendly when connecting to be able to migrate user machines.
Not all runtime behaviour alerts offer enough data to decide whether or not something is malicious. Having even more data (e.g., what process is doing a specific action) would help.
Compared to Sysdig Falco (the free open-source IDS), Lacework helps security teams by providing actionable alerts and a user-friendly interface that gives you an overview of all workloads being monitored, and detailed insights into these workloads if needed. Falco requires you to build your own integration and interface around it, including a mechanism to whitelist certain alerts. This made it harder for the security team to focus their time on potential intrusions.
We use McAfee Endpoint Security on user PCs and I must say that it is an excellent antivirus. The alerts we have had have been resolved without any problem. I totally recommend it.
Being a FinTech company, financial institutions who partner with us want to know that we are appropriately maintaining a Security, Risk and Compliance program that maintains a level of comfort for their vendor management. Lacework gives us the ability to monitor and maintain a level of security for our infrastructure that puts our partners at ease, reduces the revenue cycle for new partners and opens doors to the future.