Lacework vs. Sonatype Vulnerability Scanner

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Lacework
Score 6.0 out of 10
N/A
Lacework is a cloud-native application protection platform offered as-a-Service; delivering build-time to run-time threat detection, behavioral anomaly detection, and cloud compliance across multicloud environments, workloads, containers, and Kubernetes.N/A
Sonatype Vulnerability Scanner
Score 9.1 out of 10
N/A
Sonatype Vulnerability Scanner (formerly DepShield) discovers vulnerability among open source components and code in an application. It is available free and open source.
$0
Pricing
LaceworkSonatype Vulnerability Scanner
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
LaceworkSonatype Vulnerability Scanner
Free Trial
NoYes
Free/Freemium Version
NoYes
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
LaceworkSonatype Vulnerability Scanner
Best Alternatives
LaceworkSonatype Vulnerability Scanner
Small Businesses

No answers on this topic

No answers on this topic

Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
Veracode
Veracode
Score 9.2 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
Veracode
Veracode
Score 9.2 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
LaceworkSonatype Vulnerability Scanner
Likelihood to Recommend
7.1
(7 ratings)
9.1
(1 ratings)
User Testimonials
LaceworkSonatype Vulnerability Scanner
Likelihood to Recommend
Lacework
Lacework is well suited for behavioral analysis. One thing to consider thought is in the early stages there will be quite a bit of noise generated by Lacework. There will be a higher volume alerts generated initially - until a good baseline is generated. Overall Lacework is good with alert handling - integration with Slack is good.
Read full review
Sonatype
Well suited for organizations with small application security team as the solution scales and is easy for devs to use. The only choice if you develop in Java as their data is the most accurate.
Read full review
Pros
Lacework
  • Easy to set-up the agent in cloud workloads.
  • Easy integration with ticketing and messaging tools.
  • Detailed visibility of all our container workloads across multiple accounts.
Read full review
Sonatype
No answers on this topic
Cons
Lacework
  • UI can be complicated and hard to know where to click to find information.
  • Ability to create and manage cases or tickets from events that trigger.
Read full review
Sonatype
No answers on this topic
Alternatives Considered
Lacework
Compared to Sysdig Falco (the free open-source IDS), Lacework helps security teams by providing actionable alerts and a user-friendly interface that gives you an overview of all workloads being monitored, and detailed insights into these workloads if needed. Falco requires you to build your own integration and interface around it, including a mechanism to whitelist certain alerts. This made it harder for the security team to focus their time on potential intrusions.
Read full review
Sonatype
No answers on this topic
Return on Investment
Lacework
  • Being a FinTech company, financial institutions who partner with us want to know that we are appropriately maintaining a Security, Risk and Compliance program that maintains a level of comfort for their vendor management. Lacework gives us the ability to monitor and maintain a level of security for our infrastructure that puts our partners at ease, reduces the revenue cycle for new partners and opens doors to the future.
Read full review
Sonatype
No answers on this topic
ScreenShots