AppSecNews

Container Security

Container and Kubernetes Security

Scan images, enforce policy and watch runtime behavior in containerized workloads.

8 tools profiled

How it differs Scans container images and enforces policy on running containers and Kubernetes workloads. Checking the manifests before deploy is IaC security.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

5 tools match

  • Aqua Security

    Aqua Security

    Container Security

    A cloud native security platform that scans images and infrastructure as code, then enforces workload policy at admission and at runtime with in-cluster agents.

    Commercial +1
    Established
  • Clair

    Quay (Red Hat)

    Container Security

    An open source container image scanner that indexes layer contents into a database and matches the resulting package inventory against distribution and language vulnerability feeds.

    Open source
    Established
  • Docker Scout

    Docker

    Container Security

    Docker's own image analysis service, which builds an SBOM from image layers, matches it against advisory sources, and recommends base image changes that remove the most findings.

    Freemium
    Growing
  • kube-bench

    Aqua Security

    Container Security

    A single binary that checks whether a Kubernetes node's configuration matches the CIS Kubernetes Benchmark, reporting each control as pass, fail or manual with remediation text.

    Open source
    Established
  • A Kubernetes-native security platform that scores deployment risk from cluster configuration, enforces policy at admission, and detects runtime behavior from kernel level telemetry.

    Open source and commercial
    Established
  • Aqua Security

    Aqua Security

    A cloud native security platform that scans images and infrastructure as code, then enforces workload policy at admission and at runtime with in-cluster agents.

    Commercial +1 Established
    Container Security
  • Clair

    Quay (Red Hat)

    An open source container image scanner that indexes layer contents into a database and matches the resulting package inventory against distribution and language vulnerability feeds.

    Open source Established
    Container Security
  • Docker Scout

    Docker

    Docker's own image analysis service, which builds an SBOM from image layers, matches it against advisory sources, and recommends base image changes that remove the most findings.

    Freemium Growing
    Container Security
  • kube-bench

    Aqua Security

    A single binary that checks whether a Kubernetes node's configuration matches the CIS Kubernetes Benchmark, reporting each control as pass, fail or manual with remediation text.

    Open source Established
    Container Security
  • A Kubernetes-native security platform that scores deployment risk from cluster configuration, enforces policy at admission, and detects runtime behavior from kernel level telemetry.

    Open source and commercial Established
    Container Security
Tick up to 4 tools above.