Lacework releases high-fidelity alerts for its Polygraph Data Platform

Niels Provos, Head of Security Efficacy at Lacework

Lacework®, the data-driven cloud security company, announced its high-fidelity composite alerts on the Lacework Polygraph® Data Platform, to help clients detect compromised credentials, cloud ransomware, and cryptomining that would otherwise go unnoticed.

Why are the Lacework alerts a gamechanger?

“I’m excited to see Lacework continuing to bring new features to market that will help give our security team better context to make decisions. We value Lacework as a partner because they’re continually innovating the Polygraph Data Platform to bring us more value and help keep our business safe,” said Alberto Silveira, Head of Engineering at LawnStarter.

“Production environments can be very noisy and delivering actionable and highly precise alerts in quickly changing, complex environments is often a challenge. With composite alerts, we combine many potentially noisy data points into highly actionable and opinionated alerts,” said Niels Provos, Head of Security Efficacy at Lacework.

“We tell customers precisely about the specific security threat they face and provide all the evidence needed to underpin how we reached our verdict. This enables our customers to quickly and with confidence remediate the problem before it grows out of control.”

What is the product offering of high-fidelity alerts?

By combining human intelligence with the automatic correlation of disparate alerts, Lacework generates a single, evidence-based composite alert with full context and actionable data that makes it easy for SOC teams to quickly respond to cloud threats.

Composite alerts combine human intelligence from Lacework Labs about prevalent attack sequences and tactics with automatic correlation of numerous events, including low criticality data from disparate sources. In a single, opinionated composite alert, Lacework describes a suspected exploit so security teams can perform faster, more effective investigations and remediations —without excessive querying and significant expertise.

Enterprises are inundated with alerts, leading to slower response times and a lack of understanding about the nuances of potential risks or attack scopes. In addition, security teams must spend countless hours manually correlating weak signals that appear insignificant when presented in isolation, but can indicate a dangerous, genuine threat when associated with other events. Lacework does this investigative work for customers.

The benefits for the enterprise are saved time and costs, as there’s no need for SOC teams to manually link events and spend hours trying to determine what is happening. Clients also see improved security efficacy, as the tech automatically ties together seemingly disparate and often lower severity events that were previously not being investigated, recognises important patterns, and adds context about the type of attack happening.