Lacework - good for the Enterprise
Use Cases and Deployment Scope
We used Lacework as a service that performed behavioral analysis of the AWS Infrastructure layer (Cloudtrail, AWS Config), the server host processes, and user activities within AWS and the server itself. We also used Lacework Container Security to deliver end-to-end visibility of Docker container images by providing vulnerability assessments and malware detection. Vulnerability scanning for production instances with centralized logging and event analysis is a ‘must-have’ for customers from any product in the Commercial/GxP state.
Pros
- Easy to implement in our environments
- Good with alert handling
- Good with compliance
- Assurance of protection against the latest vulnerabilities and threats
Cons
- Improve product support
- Improve alert handling
Most Important Features
- ease of implementation
- alert handling and integration with Slack
- consistent way to setup across different AWS accounts
Return on Investment
- Has helped give us coverage on different usage patterns
- Good with compliance - helped with credibility with auditors
- At times (a negative), Lacework has impacted our product teams by causing product issues on our production infrastructure
Alternatives Considered
F5 Distributed Cloud Application Infrastructure Protection (AIP)
Other Software Used
Checkmarx, CrowdStrike Falcon, VMware Carbon Black EDR

