AppSecNews

IaC Security

Infrastructure as Code Security

Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.

17 tools profiled

How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

13 tools match

  • Falco

    The Falco Project (CNCF)

    IaC Security

    A CNCF runtime security engine that taps Linux kernel syscalls with eBPF and raises alerts when activity matches a rule.

    Open source
    Established
  • KubeArmor

    AccuKnox (CNCF project)

    IaC Security

    A CNCF runtime security engine that uses Linux security modules and eBPF to block, not just alert on, disallowed behavior inside workloads.

    Open source
    Growing
  • Kubescape

    ARMO (CNCF project)

    IaC Security

    A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.

    Open source
    Growing Verified
  • Kyverno

    The Kyverno Project (CNCF)

    IaC Security

    A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.

    Open source
    Established Verified
  • Lacework

    Fortinet

    IaC Security

    A cloud-native application protection platform that baselines normal cloud and workload behavior and flags deviation, now part of Fortinet's FortiCNAPP.

    Commercial
    Established
  • Mondoo

    Mondoo

    IaC Security

    A security and compliance platform built on cnquery, a query language that treats cloud accounts, hosts, containers and IaC as queryable resources.

    Open source and commercial
    Growing
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    IaC Security

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source
    Established Verified
  • Falco

    The Falco Project (CNCF)

    A CNCF runtime security engine that taps Linux kernel syscalls with eBPF and raises alerts when activity matches a rule.

    Open source Established
    IaC Security
  • KubeArmor

    AccuKnox (CNCF project)

    A CNCF runtime security engine that uses Linux security modules and eBPF to block, not just alert on, disallowed behavior inside workloads.

    Open source Growing
    IaC Security
  • Kubescape

    ARMO (CNCF project)

    A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.

    Open source Growing
    IaC Security
  • Kyverno

    The Kyverno Project (CNCF)

    A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.

    Open source Established
    IaC Security
  • Lacework

    Fortinet

    A cloud-native application protection platform that baselines normal cloud and workload behavior and flags deviation, now part of Fortinet's FortiCNAPP.

    Commercial Established
    IaC Security
  • Mondoo

    Mondoo

    A security and compliance platform built on cnquery, a query language that treats cloud accounts, hosts, containers and IaC as queryable resources.

    Open source and commercial Growing
    IaC Security
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source Established
    IaC Security
  • Orca Security

    Orca Security

    IaC Security

    An agentless cloud security platform that reads workload storage snapshots through the cloud provider API to assess vulnerabilities, secrets and posture.

    Commercial
    Established
  • Prisma Cloud

    Palo Alto Networks

    IaC Security

    Palo Alto Networks' cloud-native application protection platform, spanning posture management, workload defense, IaC scanning and code-to-cloud tracing.

    Commercial
    Established
  • Sysdig Secure

    Sysdig

    IaC Security

    A commercial cloud and container security platform built on Falco, combining runtime detection with posture, vulnerability management and capture-based forensics.

    Commercial
    Established
  • Terrascan

    Tenable

    IaC Security

    A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.

    Open source
    Established
  • Trivy

    Aqua Security

    IaC Security

    An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.

    Open source
    Established Verified
  • Wiz

    Wiz

    IaC Security

    An agentless cloud-native application protection platform that builds a graph of cloud resources, identities and workloads to surface real attack paths.

    Commercial
    Established
  • Orca Security

    Orca Security

    An agentless cloud security platform that reads workload storage snapshots through the cloud provider API to assess vulnerabilities, secrets and posture.

    Commercial Established
    IaC Security
  • Prisma Cloud

    Palo Alto Networks

    Palo Alto Networks' cloud-native application protection platform, spanning posture management, workload defense, IaC scanning and code-to-cloud tracing.

    Commercial Established
    IaC Security
  • Sysdig Secure

    Sysdig

    A commercial cloud and container security platform built on Falco, combining runtime detection with posture, vulnerability management and capture-based forensics.

    Commercial Established
    IaC Security
  • Terrascan

    Tenable

    A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.

    Open source Established
    IaC Security
  • Trivy

    Aqua Security

    An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.

    Open source Established
    IaC Security
  • Wiz

    Wiz

    An agentless cloud-native application protection platform that builds a graph of cloud resources, identities and workloads to surface real attack paths.

    Commercial Established
    IaC Security
Tick up to 4 tools above.