Transcript
day, we're all aiming for the same thing. To protect our teams and avoid the financial, brand and operational impact of malicious actors in our systems. To build higher walls against intruders and limit the effect of anyone who does make it through the defenses. At Lacework, our approach is to both prevent security incidents from occurring and also prepare you to react to those that do arise. Our cloud security platform does this uniquely by analyzing massive amounts of data to give teams the context necessary to take faster and more decisive action. Let's take a look at how it works. When dealing with a security incident, the first thing a security team should assess is whether or not an attack is still in progress. In this case, let's use the alert category filter to show us composite alerts, which identify critical security incidents that present an immediate threat to your cloud environment. This feature is unique because it detects hard-to-uncover malicious activity by combining specific indicators of compromise into highly accurate, detailed alerts. Composite alerts answer the two main questions a security team has after a security breach. What did the attacker do and what does this mean? We see through these series of alerts that the incident was a cloud-native ransomware attack. This alert provides access to key details like the exact cloud identity the attackers were able to compromise. And we can quickly investigate to see that the identity unfortunately had full admin privileges. Now we have all the details we'll need to immediately neutralize the threat, finding attackers during or after an attack is far from ideal. Thankfully, the Lacework platform also has capabilities to help you prevent attackers from even getting in the door. Let's see how Lacework would have helped prevent the earlier worst-case scenario from occurring. When we start our research and click on the Compliance tab, we see a list of known bad things for which your cloud environment could be configured. We can see it's auditing all of our access keys, and out of our seven keys, there are four that have not been rotated in the last 90 days. Next we'll look at Vulnerabilities. Here we can see our vulnerable hosts. Click on the specific host you want to learn more about. Then you can look at which CVEs, or Critical Vulnerabilities, are running on which packages. Under the Fixed Version column, we can see which version we need to update the system to in order to get it to a safe state. One key Lacework feature, Active Package Detection, lets us know whether a vulnerable package is actively running and being used by an application on your host, so we can prioritize fixing those packages first. We can easily see these by filtering the Package Status column. Next we'll look at Identities. If you click on Explore Identities at the top, we can see a list of all the identities we have in our accounts. We see that several of these are high severity risks, and we can also see why they are so risky. To help you understand the relationships among all of the resources and services in your cloud, we have the Lacework Explorer. With interactive visuals, this feature makes it easy to see and prioritize the potential risks associated with each resource. A host with a vulnerability may matter less if it's not misconfigured to be exposed to the public internet. But if that same host has an admin identity behind it, it becomes much more important to address that vulnerability right away. So let's click on Attack Paths on the left-hand side and investigate the path that attackers could take. Now we'll drill down into the top risky paths with the Admin Privilege role. We can see that from the public internet, there is a path an attacker could take through the internet gateway, through the security group. We see that this security group has two compliance, or configuration errors, which could give the attacker access to this host. It shows us that if the host did not have a certain identity associated with it with very broad access privileges, it wouldn't be as risky. So now we have a simple action to take to make our cloud safer. What sets Lacework apart isn't just the vast amount of data we handle. It's how we transform that data into actionable information through our advanced analytics.