Use Lacework with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Secure your cloud via Lacework. search security alerts, monitor vulnerabilities, and audit cloud asset inventory.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 10 capabilities
The complete Lacework capability set.
These are the exact actions your AI can choose when you ask it to work with Lacework.
01-04
4 capabilities in this set.
Part of 10 available through Lacework.
- 01
List host vulnerabilities
Identifies running processes strictly matched against Critical or High CVEs (e.g., Log4j, Polkit) directly active inside EC2 or GCE instances. List known vulnerabilities executing natively on Cloud Hosts/VMs
- 02
Search alerts
Fetches events mapping to anomalous Kubernetes executions, AWS IAM brute-forcing attempts, and massive container network exfiltrations spanning the specified time filter. Search Cloud Security alerts dynamically across Lacework
- 03
List lql queries
These extract precise cloud telemetry fields mapping user-defined compliance checks directly against the underlying dataset. List all Lacework Query Language (LQL) structures
- 04
List security policies
Confirms whether Lacework will alert directly if an engineer violates structural norms (e.g., exposing port 22 directly to 0.0.0.0/0). List all globalThis Cloud Security Policies enforced by Lacework
05-07
3 capabilities in this set.
Part of 10 available through Lacework.
- 05
Search cve exposure
Directly filters the entire cloud infrastructure footprint determining exactly which specific nodes (Machines) are currently vulnerable to the designated CVE (e.g. "CVE-2026-0001"). Search all integrated Machines/Instances for a specific CVE
- 06
Execute query
Produces bespoke output matrices tracking API keys bypassing IAM logic, anomalous login patterns, or Kubernetes process spawn trees. Execute an LQL Threat Hunting Query on-demand
- 07
List container vulnerabilities
Examines ECR/DockerHub registries or direct cluster deployments for images carrying critical inherited CVEs at the filesystem level before CI/CD promotion blocks. List static image vulnerabilities detected in Container Registries
08-10
3 capabilities in this set.
Part of 10 available through Lacework.
- 08
Get alert
Extracts precisely what baseline behavior was deviated from, providing deep contextual metadata such as explicit AWS Accounts involved, offending Container Image SHAs, and correlated external IP anomalies. Get exact behavioral payloads and telemetry for an Alert
- 09
List resource groups
Helps define what constitutes "Production" vs "Staging" in Policy evaluation engines. List logical Resource Groups managing Lacework architectures
- 10
Search cloud inventory
Used to dynamically enumerate running instances, active networking perimeters, or unrestricted S3 buckets discovered by cross-account role polling. Query the real-time Lacework Cloud Control-Plane Asset Inventory
Observed, not estimated
882ms average. Fast in production.
Lacework is checked daily against the live service.
- Fastest day
- 693ms
- Slowest day
- 1085ms
- 14-day trend
- Slowing+16%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 10 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of Lacework, so you can see the experience inside your AI.
It does not authenticate your account with Lacework. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
Lacework Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — Lacework capabilities are ready to use.
{
"mcpServers": {
"lacework-cloud-security-cnapp-mcp": {
"url": "https://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions Lacework owners ask.
- 01
Can I search for specific CVE exposure across my whole cloud environment?
Yes. Use the search_cve_exposure capability and provide the official CVE ID (e.g. CVE-2023-1234). Your agent will filter the entire cloud footprint to determine exactly which specific nodes or machines are currently vulnerable.
- 02
How do I investigate the behavioral telemetry of a specific security alert?
The get_alert capability extracts precisely what baseline behavior was deviated from for a specific Alert ID. Your agent will return detailed contextual metadata, including offending container SHAs and correlated IP anomalies.
- 03
Can my agent run custom threat hunting queries using LQL?
Absolutely. Use the execute_query capability to run specialized Lacework Query Language (LQL) blocks. This allows your agent to perform complex mathematical analysis on cloud telemetry to identify deep security patterns.
Explore
More in Fort Knox
Aikido Security AI Connector
Query security vulnerabilities via Aikido — list open issues, check repositories, monitor cloud assets, and tr
ViewDrata AI Connector
Automate compliance and security via Drata — monitor controls, track personnel onboarding, audit policies, and
ViewLevo.ai (API Security & Observability) AI Connector
Secure your APIs via Levo.ai — audit endpoints, monitor sensitive data (PII/PHI), and manage OWASP vulnerabili
ViewDatadog Cloud SIEM AI Connector
Manage cloud security via Datadog — search security signals, triage alerts, and audit detection rules directly
View
Suggestions
Prisma Cloud AI Connector
Connect Prisma Cloud to any AI agent via MCP.
ViewSecurity Audit Prover AI Connector
An AI agent committed a Stripe API key to git, built SQL queries with string concatenation, and deployed an ad
ViewPatchstack Security AI Connector
Monitor WordPress security via Patchstack — track vulnerabilities, manage site software, and receive alerts di
ViewSalt Security AI Connector
Integrate Salt Security directly with your AI for comprehensive API threat vector discovery, posture managemen
View
