Lacework (Cloud Security & CNAPP) Connector for AI agents.
10 live capabilities
Manage cloud security posture and hunt for threats across your infrastructure.
Waiting for input…
Why people use Lacework (Cloud Security & CNAPP)
Lacework Cloud Security & CNAPP Vulnerability Management
With this Connector, you can just ask your AI client to find the problems. You can query for specific CVEs, list all unrestricted S3 buckets, and pull the behavioral telemetry for a Kubernetes alert in one go. It turns your security data into a searchable conversation.
What Vinkius changes
You get a conversational interface for your cloud security operations.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 5,900+ Connectors
- Real-world use case 01
Zero-day response
A security lead needs to know if Log4j is a threat.
- Real-world use case 02
IAM Audit
An admin suspects API key abuse.
- Real-world use case 03
S3 Leak Check
A compliance officer wants to find public buckets.
Complete set · 10capabilities
The complete Lacework (Cloud Security & CNAPP) capability set.
These are the exact actions your AI can choose when you ask it to work with Lacework (Cloud Security & CNAPP).
01—04
4 capabilities in this set.
Part of 10 available through Lacework (Cloud Security & CNAPP).
- 01 Capability
Get alert
Get behavioral payloads and telemetry for a specific alert, including AWS accounts and container SHAs.
- 02 Capability
List host vulnerabilities
See which running processes on EC2 or GCE instances are currently active with high-risk CVEs.
- 03 Capability
Search alerts
Fetch events for Kubernetes anomalies, IAM brute-forcing, and container network exfiltration.
- 04 Capability
Search cve exposure
Filter your entire infrastructure to find specific machines vulnerable to a designated CVE.
05—07
3 capabilities in this set.
Part of 10 available through Lacework (Cloud Security & CNAPP).
- 05 Capability
List security policies
View all global cloud security policies to confirm if structural norms are being enforced.
- 06 Capability
List lql queries
Extract telemetry fields that map your user-defined compliance checks against the dataset.
- 07 Capability
List resource groups
See how your architecture is organized into logical groups like Production or Staging.
08—10
3 capabilities in this set.
Part of 10 available through Lacework (Cloud Security & CNAPP).
- 08 Capability
Execute query
Run a custom LQL threat hunting query to track API key abuse or process spawn trees.
- 09 Capability
List container vulnerabilities
Check ECR or DockerHub registries for images with critical inherited CVEs.
- 10 Capability
Search cloud inventory
Query the real-time cloud control-plane to find running instances and unrestricted S3 buckets.
Set up in minutes
One URL. Then ask Lacework (Cloud Security & CNAPP) to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use Lacework (Cloud Security & CNAPP) from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it Lacework (Cloud Security & CNAPP), and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable Lacework (Cloud Security & CNAPP) for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the Lacework (Cloud Security & CNAPP) URL.
- Step 03
Save and start
Save the connection and enable Lacework (Cloud Security & CNAPP) in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"lacework-cloud-security-cnapp": {
"url": "https://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using Lacework (Cloud Security & CNAPP)
Open Agent mode in chat and ask: "Using Lacework (Cloud Security & CNAPP), help me...". 10 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"lacework-cloud-security-cnapp": {
"url": "https://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using Lacework (Cloud Security & CNAPP)
Ask Copilot: "Using Lacework (Cloud Security & CNAPP), help me...". 10 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"lacework-cloud-security-cnapp": {
"url": "https://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using Lacework (Cloud Security & CNAPP)
Open Cascade and ask: "Using Lacework (Cloud Security & CNAPP), help me...". 10 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"lacework-cloud-security-cnapp": {
"url": "https://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using Lacework (Cloud Security & CNAPP)
Ask Cline: "Using Lacework (Cloud Security & CNAPP), help me...". 10 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add lacework-cloud-security-cnapp --transport http "https://edge.vinkius.com/vk_preview_xT38bIhhFhzvvpfxyO01Dv9Iop7sXt66wD8neHzv/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using Lacework (Cloud Security & CNAPP)
Ask Claude: "Using Lacework (Cloud Security & CNAPP), show me...". 10 tools are ready
Where the request belongs
Work Lacework can move forward.
This is for the security pro who's tired of tab-switching and the DevOps engineer who needs to ensure every image is clean before it goes live.
Security Analyst
Investigates polygraph alerts and hunts for threats without manual filtering.
DevOps Engineer
Monitors container vulnerabilities to block insecure images in the CI/CD pipeline.
Compliance Officer
Audits global security policies to ensure the company stays within regulatory bounds.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsDatadog Cloud SIEM
Manage cloud security via Datadog. search security signals, triage alerts, and audit detection rules directly from any AI agent.
Tenable
Manage Tenable Vulnerability Management scans, inspect cloud assets, and triage CVEs natively via your AI agent.
Vanta
Manage your automated compliance and security posture. Audit users, devices, vendors, and vulnerabilities directly from your AI agent.
42Crunch
Automate API security testing via 42Crunch. manage collections, trigger audits, run conformance scans, and retrieve security reports directly from any AI agent.
Flystack
Manage cloud infrastructure. audit deployments, clusters, and metrics via AI.
Better Stack
Automate incident management via Better Stack. monitor uptime, manage incidents, and control on-call schedules securely from your AI agent.
Bring your own AI
Change the model, client or framework. Keep Lacework connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about Lacework.
The practical details behind the request, access and result.
Can Lacework MCP help me find zero-day vulnerabilities?
Yes, it allows your AI agent to scan your entire infrastructure for specific CVEs, helping you identify exposed nodes during zero-day events.
How does Lacework MCP handle container security?
It can scan your ECR and DockerHub registries for images with critical vulnerabilities before they are promoted to production.
Can I use Lacework MCP for compliance audits?
Yes, you can use it to list and audit all global cloud security policies to ensure your infrastructure meets regulatory requirements.
Does Lacework MCP support LQL queries?
Yes, it can execute custom Lacework Query Language (LQL) requests to hunt for API key abuse or anomalous login patterns.
How do I connect Lacework to my AI agent?
You can subscribe to this Connector through Vinkius, provide your Lacework account credentials, and then start asking questions in your preferred AI client.
Can it find public S3 buckets?
Yes, the Connector can query your cloud control-plane inventory to find unrestricted S3 buckets across your accounts.
Can I search for specific CVE exposure across my whole cloud environment?
Yes. Use the search_cve_exposure capability and provide the official CVE ID (e.g. CVE-2023-1234). Your agent will filter the entire cloud footprint to determine exactly which specific nodes or machines are currently vulnerable.
How do I investigate the behavioral telemetry of a specific security alert?
The get_alert capability extracts precisely what baseline behavior was deviated from for a specific Alert ID. Your agent will return detailed contextual metadata, including offending container SHAs and correlated IP anomalies.
Can my agent run custom threat hunting queries using LQL?
Absolutely. Use the execute_query capability to run specialized Lacework Query Language (LQL) blocks. This allows your agent to perform complex mathematical analysis on cloud telemetry to identify deep security patterns.
One connection away
Give your agent a direct line to Lacework.
Connect Lacework once. Keep it beside 5,900+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available