Lacework Releases High-Fidelity, Composite Alerts for Polygraph Data Platform
February 27, 2023

Lacework announced the release of high-fidelity composite alerts on the Lacework Polygraph® Data Platform, to help customers detect compromised credentials, cloud ransomware, and cryptomining that would otherwise go unnoticed.

By combining human intelligence with the automatic correlation of disparate alerts, Lacework generates a single, evidence-based composite alert with full context and actionable data that makes it easy for SOC teams to quickly respond to specific cloud threats across data sources.

"I'm excited to see Lacework continuing to bring new features to market that will help give our security team better context to make decisions," said Alberto Silveira, Head of Engineering at LawnStarter. "We value Lacework as a partner because they're continually innovating the Polygraph Data Platform to bring us more value and help keep our business safe."

Enterprises are inundated with alerts, leading to slower response times and a lack of understanding about the nuances of potential risks or attack scopes. Security teams must spend countless hours manually correlating weak signals that appear insignificant when presented in isolation, but can indicate a dangerous, genuine threat when associated with other events. Lacework does this investigative work for customers. Composite alerts combine human intelligence from Lacework Labs about prevalent attack sequences and tactics with automatic correlation of numerous events, including low criticality data from disparate sources. In a single, opinionated composite alert, Lacework describes a suspected exploit so security teams can perform faster, more effective investigations and remediations —without excessive querying and significant expertise.

"Production environments can be very noisy and delivering actionable and highly precise alerts in quickly changing, complex environments is often a challenge," said Niels Provos, Head of Security Efficacy at Lacework. "With composite alerts, we combine many potentially noisy data points into highly actionable and opinionated alerts. We tell customers precisely about the specific security threat they face and provide all the evidence needed to underpin how we reached our verdict. This enables our customers to quickly and with confidence remediate the problem before it grows out of control."

The benefits for the enterprise are saved time and costs, as there's no need for SOC teams to manually link events and spend hours trying to determine what is happening. Customers also see improved security efficacy, as the technology automatically ties together seemingly disparate and often lower severity events that were previously not being investigated, recognizes important patterns, and adds context about the type of attack happening.

Share this

Industry News

May 07, 2024

Oracle announced plans for Oracle Code Assist, an AI code companion, to help developers boost velocity and enhance code consistency.

May 07, 2024

New Relic launched Secure Developer Alliance.

May 07, 2024

Dynatrace is enhancing its platform with new Kubernetes Security Posture Management (KSPM) capabilities for observability-driven security, configuration, and compliance monitoring.

May 07, 2024

Red Hat announced advances in Red Hat OpenShift AI, an open hybrid artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across hybrid clouds.

May 07, 2024

ServiceNow is introducing new capabilities to help teams create apps and scale workflows faster on the Now Platform and to boost developer and admin productivity.

May 06, 2024

Red Hat and Oracle announced the general availability of Red Hat OpenShift on Oracle Cloud Infrastructure (OCI) Compute Virtual Machines (VMs).

May 06, 2024

The Software Engineering Institute at Carnegie Mellon University announced the release of a tool to give a comprehensive visualization of the complete DevSecOps pipeline.

May 06, 2024

Synopsys has entered into a definitive agreement with Clearlake Capital Group, L.P. and Francisco Partners.

May 02, 2024

Parasoft announces the opening of its new office in Northeast Ohio.

May 02, 2024

Postman released v11, a significant update that speeds up development by reducing collaboration friction on APIs.

May 02, 2024

Sysdig announced the launch of the company’s Runtime Insights Partner Ecosystem, recognizing the leading security solutions that combine with Sysdig to help customers prioritize and respond to critical security risks.

May 02, 2024

Nokod Security announced the general availability of the Nokod Security Platform.

May 02, 2024

Drata has acquired oak9, a cloud native security platform, and released a new capability in beta to seamlessly bring continuous compliance into the software development lifecycle.

May 01, 2024

Amazon Web Services (AWS) announced the general availability of Amazon Q, a generative artificial intelligence (AI)-powered assistant for accelerating software development and leveraging companies’ internal data.

May 01, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux 9.4, the latest version of the enterprise Linux platform.