Hey everyone! 👋 We've been using Lacework's core cloud security features for about a year now, and the platform's been solid for our AWS workloads. Just got the email about their new 'Code Security' module, which seems to bundle SAST, secret detection, and infrastructure-as-code scanning.
We already have a dedicated SCA tool (we use Snyk) that handles our dependency scanning pretty well. I'm trying to figure out if adding this Lacework module would be complementary, or if it would just create overlap and noise. The main appeal for us is having one fewer dashboard to check, and potentially tighter integration with the cloud alerts we already get from them.
Has anyone piloted this new module yet? I'm especially curious about:
* How the secret detection compares to something like GitGuardian or TruffleHog.
* Whether the IaC scanning (for Terraform, CloudFormation) catches misconfigurations earlier than their regular cloud resource alerts.
* If the pricing is additive or if they have bundles for existing customers.
I'm leaning towards setting up a trial, but would love to hear from the community before I go building another comparison spreadsheet! 😄
ā Dan
spreadsheet ninja
Interesting question. I haven't tried the new module yet, but I'm in a similar spot. We also use Snyk for SCA.
My main hesitation is exactly the overlap you mentioned. Adding another tool for secrets and IaC might just mean more noise, unless the integration is truly seamless. The dashboard consolidation is a big plus, though. Have you seen how the findings from Lacework would be prioritized alongside your cloud alerts? That could be the deciding factor for us.
If you do the trial, I'd be curious to hear how the secret detection compares in practice.
We're about three months into the pilot, and it's squarely in the "complementary" column for us, but with a major caveat.
The secret detection is on par, maybe even a bit noisier than GitGuardian, but the consolidation is where it wins for us. Having those IaC findings and secrets alerts roll up into the same policy engine as our cloud runtime violations means we can finally build unified suppression rules. We blocked a deployment last week because the pipeline IaC scan caught a security group rule their cloud scanner would have flagged two hours later. That's the integration payoff.
On pricing, push them hard. They offered us a 20% discount for adding it to our existing enterprise agreement, but it was still additive. Your comparison spreadsheet is still necessary. The real question is whether closing that loop between code and runtime is worth the premium over your already-working SCA tool. For our compliance requirements, it was.