AppSecNews
IaC Security Open source Growing Verified profile

Kubescape

by ARMO (CNCF project)

A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.

Visit kubescape.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Kubescape in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What it does

Kubescape evaluates Kubernetes configuration against named control frameworks. It can read manifests, Helm charts and Kustomize output from disk, or connect to a live cluster and pull the actual API objects, then run each control against them. Controls are grouped into frameworks: NSA and CISA hardening guidance, the CIS Kubernetes Benchmark, MITRE ATT&CK mappings, and organization-defined sets. The output is a per-control pass or fail with the offending resources named, plus a compliance score.

Beyond posture scanning, the in-cluster deployment adds image vulnerability scanning and a runtime component that observes workload behavior to identify which packages and capabilities are actually used. That last piece is the more interesting part: relevancy filtering lets you deprioritize vulnerabilities in code paths a workload never loads, which cuts the reported finding count substantially when it works.

Where it fits

Kubescape runs in two places. As a CLI it belongs in CI, scanning manifests on a pull request before they reach a cluster, and on a developer laptop for a quick check. As an in-cluster operator it runs continuously, producing posture and vulnerability data for the running state. Platform engineering usually owns it, with compliance or security consuming the framework scores. The cluster-side features need permission to install an operator and the appetite to run another set of components.

Strengths

  • Framework alignment is the core value: an NSA-CISA or CIS score is a language auditors and leadership already understand.
  • Scans both declared manifests and live cluster state, so you can see drift between what you committed and what is running.
  • Relevancy filtering based on observed runtime behavior meaningfully reduces vulnerability noise compared to scanning an image in isolation.
  • Straightforward CLI with SARIF and JSON output, so CI adoption is quick.

Limitations

  • The compliance score is a blunt instrument. It weights controls in ways that may not match your risk model, and chasing the number can pull effort toward low-impact fixes.
  • The in-cluster stack is considerably heavier than the CLI, and the runtime relevancy features require an observation window before they produce useful results.
  • Coverage is Kubernetes-specific. It says nothing about the cloud account, the network, or the Terraform that created the cluster, so it is one component of posture management rather than all of it.

Who it suits

Well matched to platform teams that need to demonstrate Kubernetes hardening against a recognized benchmark and want the same tool in CI and in the cluster. Less suitable if your primary concern is cloud account posture across many services, or if you already run a broader CNAPP that covers Kubernetes controls and you do not want a second scoring system to reconcile.

Used Kubescape? Recommend it under your own name and title.

Recommend this tool