What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Product naming after the Fortinet acquisition: confirm current branding and whether the Lacework name is still used
- Integration list reflects the platform generally; confirm specifics against current vendor documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Lacework's distinguishing technique is behavioral baselining rather than rule matching. It ingests cloud provider control plane logs, workload telemetry from a host agent, and configuration state, then builds a model of what normal looks like for your environment: which processes talk to which endpoints, which identities call which APIs, how containers in a given deployment behave. Deviation from that learned baseline becomes an alert. The design intent is to catch activity nobody wrote a signature for, which requires a learning period first.
Around that core sits the rest of a cloud-native application protection platform: posture assessment of cloud accounts against compliance benchmarks, agentless and agent-based vulnerability scanning of hosts and container images, Kubernetes configuration review, identity and entitlement analysis, and infrastructure as code scanning in pull requests. Findings are correlated into composite alerts rather than presented as a flat list, which is what keeps volume manageable.
Where it fits
This is primarily a production and pre-production control, operated by a cloud security or security operations team. Cloud accounts are connected through provider roles, and workload telemetry requires deploying an agent or enabling agentless collection. The IaC scanning piece reaches earlier, running in CI on Terraform, but the platform's center of gravity is the running environment. You need a triage process: anomaly detection produces findings that require investigation, not fixes a developer can simply close.
Strengths
- Anomaly detection based on learned behavior surfaces activity that signature and configuration checks structurally cannot see.
- Correlation across control plane, workload and configuration data means related signals arrive as one investigation rather than several tickets.
- Broad coverage in one platform reduces the number of consoles a cloud security team has to work across.
- Compliance reporting against common benchmarks is built in, which handles a recurring audit obligation without a separate tool.
Limitations
- Behavioral models need time and stable workloads. Environments that change constantly produce more noise, and the first weeks after onboarding are typically heavy on tuning.
- Agent deployment is an operational commitment across hosts and clusters, and agentless-only coverage sees less.
- Platform consolidation means lock-in: data, policies and alert history live in the vendor's model, and moving off is a project.
- The Fortinet acquisition has changed product packaging and naming, so confirm the current shape of the offering before relying on older documentation.
Who it suits
Suited to organizations running substantial multi-account cloud estates with a dedicated cloud security function that can act on behavioral alerts. Not a fit for a small team whose real problem is misconfigured Terraform and unpatched images, which open-source scanners in CI address more directly and with far less operational weight.
Used Lacework? Recommend it under your own name and title.
Recommend this tool