AppSecNews

IaC Security

Infrastructure as Code Security

Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.

17 tools profiled

How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

10 tools match

  • Checkov

    Prisma Cloud (Palo Alto Networks), originally Bridgecrew

    IaC Security

    A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.

    Open source
    Established Verified
  • Conftest

    Open Policy Agent

    IaC Security

    A CLI that parses configuration files into structured data and tests them against policies you write in Rego, the Open Policy Agent language.

    Open source
    Established Verified
  • KICS

    Checkmarx

    IaC Security

    An open-source scanner from Checkmarx that parses many infrastructure formats into a common model and evaluates Rego queries against it.

    Open source
    Established Verified
  • Kubescape

    ARMO (CNCF project)

    IaC Security

    A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.

    Open source
    Growing Verified
  • Kyverno

    The Kyverno Project (CNCF)

    IaC Security

    A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.

    Open source
    Established Verified
  • Checkov

    Prisma Cloud (Palo Alto Networks), originally Bridgecrew

    A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.

    Open source Established
    IaC Security
  • Conftest

    Open Policy Agent

    A CLI that parses configuration files into structured data and tests them against policies you write in Rego, the Open Policy Agent language.

    Open source Established
    IaC Security
  • KICS

    Checkmarx

    An open-source scanner from Checkmarx that parses many infrastructure formats into a common model and evaluates Rego queries against it.

    Open source Established
    IaC Security
  • Kubescape

    ARMO (CNCF project)

    A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.

    Open source Growing
    IaC Security
  • Kyverno

    The Kyverno Project (CNCF)

    A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.

    Open source Established
    IaC Security
  • Mondoo

    Mondoo

    IaC Security

    A security and compliance platform built on cnquery, a query language that treats cloud accounts, hosts, containers and IaC as queryable resources.

    Open source and commercial
    Growing
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    IaC Security

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source
    Established Verified
  • Terrascan

    Tenable

    IaC Security

    A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.

    Open source
    Established
  • tfsec

    Aqua Security

    IaC Security

    A Terraform-specific static analyzer that evaluates HCL against cloud misconfiguration checks, now consolidated into Aqua's Trivy.

    Open source
    Established
  • Trivy

    Aqua Security

    IaC Security

    An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.

    Open source
    Established Verified
  • Mondoo

    Mondoo

    A security and compliance platform built on cnquery, a query language that treats cloud accounts, hosts, containers and IaC as queryable resources.

    Open source and commercial Growing
    IaC Security
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source Established
    IaC Security
  • Terrascan

    Tenable

    A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.

    Open source Established
    IaC Security
  • tfsec

    Aqua Security

    A Terraform-specific static analyzer that evaluates HCL against cloud misconfiguration checks, now consolidated into Aqua's Trivy.

    Open source Established
    IaC Security
  • Trivy

    Aqua Security

    An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.

    Open source Established
    IaC Security
Tick up to 4 tools above.