Skip to content
Notifications
Clear all

Is Lacework actually useful for serverless workloads?

2 Posts
2 Users
0 Reactions
24 Views
(@emmal)
Reputable Member
Joined: 3 months ago
Posts: 320
Topic starter   [#5750]

I’ve been reading through a lot of the discussions here on cloud security tools, and I’m trying to get a clear picture of where Lacework fits. We’re moving more of our architecture to serverless (mostly AWS Lambda, with some Step Functions and EventBridge) and the classic agent-based security tools seem to hit a wall there.

The marketing says Lacework covers serverless, but I’m having a hard time finding concrete details on what that actually means in practice. Does it effectively monitor function invocations, layer dependencies, and data flows between services? Or is it more about scanning the stored function code and cloud configs?

I’m particularly curious about a few specific points:
How does it handle the ephemeral, event-driven nature? Is there meaningful runtime insight, or is it mostly a compliance and posture check?
If you’re using it, what kind of alerts or findings have been most valuable for your serverless workloads?
Does it integrate with the deployment pipeline to catch issues before they go live, similar to how it works with containers?

We use a mix of Google Workspace and Zoom for internal ops, so I’m used to tools that need clear, tangible workflows. I’d appreciate any real-world experiences, especially if you’ve compared it to other approaches for securing serverless.



   
Quote
(@dianaf)
Reputable Member
Joined: 3 months ago
Posts: 260
 

Yeah, that marketing-to-reality gap is real. From our trial, the runtime insight for serverless felt thin compared to containers. It's good on the static side - scanning your code and configs in the repository or S3 for known vulns and misconfigurations. But for the actual ephemeral stuff, like monitoring a specific Lambda invocation chain during an event? It seemed more inferred from CloudTrail logs than having actual instrumentation in the runtime.

The most useful alerts we got were about over-permissive IAM roles on functions or a vulnerable package in a layer. Nothing about weird data flows or anomalous invocation patterns, which is what I really wanted.

Does it at least flag when a function starts hitting an unexpected external endpoint, or is that still in the "future roadmap" zone?



   
ReplyQuote