Lacework integrated its cloud-native application protection platform (CNAPP) capabilities with Google Cloud’s recently-announced Chronicle Security Operations to help joint customers gain better security insights across their multicloud environment.
Google introduced its Chronicle Security Operations during this year’s Next event. The security service unifies Chronicle’s security information and event management (SIEM) technology with the security orchestration, automation, and response (SOAR) solutions from Google’s Siemplify acquisition, and threat intelligence from Google Cloud, while aligning with Mandiant’s threat intelligence and incident response capabilities.
With the Lacework CNAPP integration, users can get runtime alerts and anomalous activity detection generated by the cloud security provider’s Polygraph Data platform for multicloud environments.
The vendor introduced the platform earlier this year to focus on multicloud support. It is built on Lacework’s Polygraph platform that collects machine, process, and user interactions to develop behavioral models at scale, monitors infrastructure, looks for anomalous behavior, and generates alerts with severity scores.
“Enterprises transforming their security strategies for the cloud require technologies that easily deliver comprehensive visibility across their multicloud environments,” Sunil Potti, VP and GM of security at Google Cloud, said in a statement. “Lacework's integration with Chronicle Security Operations enables organizations to detect and address the right threats via contextual insights that matter the most across their diverse environments.”
Google Cloud Chronicle Security Operations Plus Lacework Polygraph Data PlatformLacework’s Polygraph Data platform brings multicloud runtime telemetry and high-context alerts into Google Cloud Chronicle Security Operations that help security operation center (SOC) teams to accelerate threat investigation and remediation.
The Anomaly detection capability from the Polygraph Data platform including the cloud control plane, audit logs, cloud, and container instances for Google Cloud, Microsoft Azure, and Amazon Web Services (AWS) now will be shared with Chronicle Security Operations.
Additionally, customers can use Google Cloud Chronicle SOAR to create automation, orchestration, and response playbooks for faster threat reactions.
This is not Chronicle Security Operations’ first enhancement. Following the completion of the Google-Mandiant acquisition, Mandiant introduced Breach Analytics for Google Cloud’s Chronicle. It is designed to reduce attacker dwell time with advanced automation and inform customers about the presence of indicators of compromise (IOC) identified by Mandiant threat intelligence analysts.
Comments