KubeArmor
AccuKnox (CNCF project)
A CNCF runtime security engine that uses Linux security modules and eBPF to block, not just alert on, disallowed behavior inside workloads.
IaC Security
Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.
17 tools profiled
How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.
AccuKnox (CNCF project)
A CNCF runtime security engine that uses Linux security modules and eBPF to block, not just alert on, disallowed behavior inside workloads.
The Falco Project (CNCF)
A CNCF runtime security engine that taps Linux kernel syscalls with eBPF and raises alerts when activity matches a rule.
Prisma Cloud (Palo Alto Networks), originally Bridgecrew
A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.
Tenable
A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.
ARMO (CNCF project)
A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.
AccuKnox (CNCF project)
A CNCF runtime security engine that uses Linux security modules and eBPF to block, not just alert on, disallowed behavior inside workloads.
The Falco Project (CNCF)
A CNCF runtime security engine that taps Linux kernel syscalls with eBPF and raises alerts when activity matches a rule.
Prisma Cloud (Palo Alto Networks), originally Bridgecrew
A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.
Tenable
A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.
ARMO (CNCF project)
A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.
Checkmarx
An open-source scanner from Checkmarx that parses many infrastructure formats into a common model and evaluates Rego queries against it.
Aqua Security
An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.
Sysdig
A commercial cloud and container security platform built on Falco, combining runtime detection with posture, vulnerability management and capture-based forensics.
Palo Alto Networks
Palo Alto Networks' cloud-native application protection platform, spanning posture management, workload defense, IaC scanning and code-to-cloud tracing.
Aqua Security
A Terraform-specific static analyzer that evaluates HCL against cloud misconfiguration checks, now consolidated into Aqua's Trivy.
Checkmarx
An open-source scanner from Checkmarx that parses many infrastructure formats into a common model and evaluates Rego queries against it.
Aqua Security
An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.
Sysdig
A commercial cloud and container security platform built on Falco, combining runtime detection with posture, vulnerability management and capture-based forensics.
Palo Alto Networks
Palo Alto Networks' cloud-native application protection platform, spanning posture management, workload defense, IaC scanning and code-to-cloud tracing.
Aqua Security
A Terraform-specific static analyzer that evaluates HCL against cloud misconfiguration checks, now consolidated into Aqua's Trivy.