AppSecNews
IaC Security Open source Established Verified profile

KICS

by Checkmarx

An open-source scanner from Checkmarx that parses many infrastructure formats into a common model and evaluates Rego queries against it.

Visit kics.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run KICS in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What it does

KICS, short for Keeping Infrastructure as Code Secure, normalizes many configuration formats into a single internal JSON representation and then runs queries against that representation. The queries are written in Rego, the Open Policy Agent language, and each one ships alongside metadata and test fixtures: a sample that should fail and a sample that should pass. That structure makes the ruleset unusually easy to read and extend, since every check is a self-contained directory you can inspect.

Format coverage is the headline. KICS parses Terraform, CloudFormation, Kubernetes manifests, Helm, Ansible playbooks, Docker Compose and Dockerfiles, OpenAPI definitions, Google Deployment Manager, Azure Resource Manager templates, Pulumi, CDK output, Knative, SAM and gRPC configurations. It also does secret detection over scanned files. Results carry severity, a query identifier, file and line location, and the expected versus actual value.

Where it fits

KICS runs as a CLI or container image on a developer machine and in CI, gating pull requests before infrastructure changes are merged. It is usually owned by a platform or security engineering team who curate which query categories are enabled and which severities break the build. Nothing needs to be running for it to work: it reads files on disk, which makes it easy to adopt but also means it only sees what is statically declared.

Strengths

  • The widest format coverage of the common open-source IaC scanners, which matters if your estate spans Terraform, Ansible and Kubernetes rather than one of them.
  • Every query ships with positive and negative test samples, so you can see exactly what a rule catches before enabling it.
  • Rego queries mean you can add organization-specific checks using a language many platform teams already run elsewhere.
  • SARIF output drops straight into GitHub code scanning and similar review surfaces.

Limitations

  • Query depth varies by format. Terraform and Kubernetes coverage is strong, while some of the longer-tail formats have thin rulesets, so breadth is not uniform quality.
  • Like all static IaC scanners it cannot resolve computed values, remote module contents or anything determined at apply time, which produces both blind spots and false positives.
  • Writing custom Rego queries requires understanding the normalized document model as well as Rego itself, which is a steeper on-ramp than a YAML rule format.

Who it suits

A good fit for organizations with heterogeneous infrastructure definitions that want one scanner rather than several, and for teams already comfortable with Rego. Less compelling for a shop that is purely Terraform and wants the deepest possible Terraform analysis, where a more specialized tool or a plan-aware scanner will find more.

Used KICS? Recommend it under your own name and title.

Recommend this tool