Lacework - Coud native UEBA platform
Use Cases and Deployment Scope
We mainly use Lacework for User and Entity Behavior Analytics. It allows us to be aware of any anomalies in our systems, be it a process, a user or a connection coming from an unusual location etc. The beauty of it is that the platform takes care of establishing a baseline of what is usual behavior in the systems, and once that is done, it becomes humanly possible to sift through the incoming alerts of what is considered out of the norm.
Pros
- installation at the OS level and containers.
- Queries for the latest vulns (e.g log4j, ksmbd...) to scan the systems.
- Alerts and notifications
Cons
- The Web GUI could be more user friendly
- The information fetched from AWS services (like CloudTrail specifically) could be more verbose.
Likelihood to Recommend
<div>Lacework is cloud native. If you have workloads running in any of the major cloud providers, I think it would make security management and compliance easier.</div><div>For on-prem environments, it would definitely work. But I think it would be an overkill, as you would not be using all it has to offer.
</div>
