TrustRadius: an HG Insights company

Lacework

Score7.1 out of 10

7 Reviews and Ratings

What is Lacework?

Lacework is a cloud-native application protection platform offered as-a-Service; delivering build-time to run-time threat detection, behavioral anomaly detection, and cloud compliance across multicloud environments, workloads, containers, and Kubernetes.

Lacework - good for the Enterprise

Use Cases and Deployment Scope

We used Lacework as a service that performed behavioral analysis of the AWS Infrastructure layer (Cloudtrail, AWS Config), the server host processes, and user activities within AWS and the server itself. We also used Lacework Container Security to deliver end-to-end visibility of Docker container images by providing vulnerability assessments and malware detection. Vulnerability scanning for production instances with centralized logging and event analysis is a ‘must-have’ for customers from any product in the Commercial/GxP state.

Pros

  • Easy to implement in our environments
  • Good with alert handling
  • Good with compliance
  • Assurance of protection against the latest vulnerabilities and threats

Cons

  • Improve product support
  • Improve alert handling

Most Important Features

  • ease of implementation
  • alert handling and integration with Slack
  • consistent way to setup across different AWS accounts

Return on Investment

  • Has helped give us coverage on different usage patterns
  • Good with compliance - helped with credibility with auditors
  • At times (a negative), Lacework has impacted our product teams by causing product issues on our production infrastructure

Alternatives Considered

F5 Distributed Cloud Application Infrastructure Protection (AIP)

Other Software Used

Checkmarx, CrowdStrike Falcon, VMware Carbon Black EDR

Lacework - The Road to Security Risk Reduction and Partners that we all have been looking for

Use Cases and Deployment Scope

We utilize Lacework to monitor and alert on Security Risk and Compliance issues within our Cloud Infrastructure environments. Similar to a SIEM in functionality without the overhead in resources of a traditional solution, Lacework provides the function that our team needs to protect the systems and data our company depends on daily.

Pros

  • Ease of deployment
  • Log and event correlation and alerting
  • Vulnerability & Compliance scanning

Cons

  • Addition of scanning of on-prem[ise] assets
  • Addition of SaaS resource scanning

Most Important Features

  • Ease of deployment
  • Ease of operation
  • Relevance of reported information
  • Dependability

Return on Investment

  • Being a FinTech company, financial institutions who partner with us want to know that we are appropriately maintaining a Security, Risk and Compliance program that maintains a level of comfort for their vendor management. Lacework gives us the ability to monitor and maintain a level of security for our infrastructure that puts our partners at ease, reduces the revenue cycle for new partners and opens doors to the future.

Alternatives Considered

LogRhythm NextGen SIEM Platform, Sumo Logic and Splunk Enterprise Security (SIEM)

Lacework - Coud native UEBA platform

Use Cases and Deployment Scope

We mainly use Lacework for User and Entity Behavior Analytics. It allows us to be aware of any anomalies in our systems, be it a process, a user or a connection coming from an unusual location etc. The beauty of it is that the platform takes care of establishing a baseline of what is usual behavior in the systems, and once that is done, it becomes humanly possible to sift through the incoming alerts of what is considered out of the norm.

Pros

  • installation at the OS level and containers.
  • Queries for the latest vulns (e.g log4j, ksmbd...) to scan the systems.
  • Alerts and notifications

Cons

  • The Web GUI could be more user friendly
  • The information fetched from AWS services (like CloudTrail specifically) could be more verbose.

Most Important Features

  • Alerting and Notifications.
  • Queries for the latest vulnerabilities (log4j, ksmbd...)
  • UEBA

Return on Investment

  • Better security
  • More visibility from a security/compliance perspective

Best security solution to protect your cloud environment easily

Use Cases and Deployment Scope

Lacework solutions help our company improve significantly our security posture in our cloud environment. We were looking for an easy-to-use solution and covered all our cloud assets. The tool is used on a daily basis to monitor vulnerabilities, threats in our environment, our posture against CIS benchmark... Security and DevOps teams are using the solution every week.

Pros

  • Detection of threats and Machine learning model
  • Ease of use
  • Support and contact with vendor

Cons

  • Alerting capabilities
  • Roles and permissions for Lacework users

Most Important Features

  • Cloud Compliance
  • Vulnerability management
  • Behavior detection

Return on Investment

  • Less operations task to maintain and deploy a vulnerability management solution
  • Detection of threats in our cloud without the need to check millions of lines of logs

Lacework makes it easy to monitor malicious behaviour within our multi-cluster cloud environment!

Use Cases and Deployment Scope

We are using Lacework's Intrusion Detection capabilities to monitor our cloud workloads (mostly k8s clusters) for malicious behaviour. Lacework is integrated with our ticketing system and automatically creates tickets when anomalous behaviour is detected. Because alerting is based on anomaly detection, we are able to focus our efforts on alerts that have a higher probability of being malicious, compared to other IDS solutions we used before.

Pros

  • Easy to set-up the agent in cloud workloads.
  • Easy integration with ticketing and messaging tools.
  • Detailed visibility of all our container workloads across multiple accounts.

Cons

  • Not all runtime behaviour alerts offer enough data to decide whether or not something is malicious. Having even more data (e.g., what process is doing a specific action) would help.

Most Important Features

  • Intrusion Detection System.
  • Integrations.
  • Actionable alerts.

Return on Investment

  • Our previous open-source IDS resulted in thousands of alerts that weren't actionable. As Lacework only alerts when it detects anomalous behavior, the amount of alerts is lower, and the probability is higher that something malicious is happening.

Alternatives Considered

Sysdig Secure DevOps Platform