Lacework continued to expand its security services in the multicloud world as it extended its Polygraph platform to support more major public clouds and prioritize Log4j flaw remediation.

The vendor unveiled a new name for its core platform: Polygraph Data Platform, which comes on the heels of its record-breaking $1.3 billion funding round last November.

The new name better reflects its growth and represents its holistic approach to modern security, which finds “the truth across your cloud in order to address true threats and risks from build time through runtime,” Lacework founder and CTO Vikram Kapoor wrote in a blog post.

Lacework’s Polygraph platform collects machine, process, and user interactions to develop behavioral models at scale and update them over time. It then monitors infrastructure, looks for anomalous behavior, and generates alerts with severity scores. It also maps out events to make it easy to visualize the who, what, where, and how far a security event moved in the customer’s environment.

The company's previous CEO Dan Hubbard called Polygraph Lacework’s secret sauce and the key to its success against other cloud security vendors such as Palo Alto Networks.

The newly named Polygraph Data Platform focuses on multicloud support and comes as the vendor saw more customers shifting to multicloud environments, said James Brown, senior director of product management at Lacework.

However, the majority of organizations (around 80%) are still using the same security methodology in the cloud as their on-premise infrastructure, while 57% of them reported the number and complexity of their security tools is creating significant inefficiencies, according to Lacework’s recent report.  

This opens opportunities for Lacework to help secure customers’ multicloud environments. The Polygraph Data Platform is available across Amazon Web Services (AWS), Amazon Elastic Kubernetes Service (EKS), Google Cloud, and now Microsoft Azure environments. And its anomaly detection capabilities are now generally available on Google Cloud and in the early release stage for Azure.

Lacework Correlates Log4j Vulnerability With Exploit Activity 

To better detect attack activity stemming from known and unknown threats, Lacework adopted a combined agentless and agent-based approach. It offers agentless security for continual monitoring of runtime environments and agent-based services to “analyze the runtime information to spot malicious behavior,” Brown said.

This approach helped the vendor identify anomalous behavior in customer environments before disclosure of the Log4j vulnerability, he added.

Additionally, the Polygraph Data Platform is equipped with the latest Lacework agent (version 5.1), tying together vulnerability data and anomaly detection, according to Kapoor.

“Not only can customers better prioritize remediation efforts, they can actively watch for exploits targeting those Log4j vulnerable systems — including those stemming from commercial, off-the-shelf tools they don’t control,”  he wrote.