AppSecNews

Articles

Guides and comparisons for choosing tools, written to the same editorial standard as the profiles.

IaC Security comparison

Checkov vs KICS: Graph Checks or Rego Queries

Checkov and KICS both gate IaC in pull requests. The choice turns on how you write policy: Python and graph checks, or Rego queries.

7 min read

Secret Scanning roundup

The 10 Best Secret Scanning Tools

Ten secret scanning tools compared by where they sit in the lifecycle, whether they verify credentials, and whether they carry a leak through to rotation.

12 min read

SCA roundup

The 10 Best Software Composition Analysis Tools

Ten software composition analysis tools picked for distinct jobs: reachability triage, license compliance, SBOM monitoring, malicious package detection and patching.

12 min read

SAST roundup

The 10 Best SAST Tools

A practitioner's guide to ten static analysis tools, chosen for distinct scenarios rather than ranked, with the trade-offs each one brings.

12 min read

RASP roundup

The 10 Best RASP Tools

A practitioner's guide to runtime application self-protection: true in-process agents, mobile hardening libraries, and the WAF-adjacent tools often filed alongside them.

12 min read

Mobile Security roundup

The 10 Best Mobile Application Security Tools

Ten mobile application security tools chosen for distinct scenarios, from automated binary scanning to runtime instrumentation, with honest caveats.

12 min read

IAST roundup

The 6 Best IAST Tools

A practitioner's guide to interactive application security testing tools, picked for distinct scenarios rather than ranked, with an honest caveat on each.

12 min read