Checkov
Prisma Cloud (Palo Alto Networks), originally Bridgecrew
A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.
IaC Security
Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.
17 tools profiled
How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.
Prisma Cloud (Palo Alto Networks), originally Bridgecrew
A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.
Open Policy Agent
A CLI that parses configuration files into structured data and tests them against policies you write in Rego, the Open Policy Agent language.
Checkmarx
An open-source scanner from Checkmarx that parses many infrastructure formats into a common model and evaluates Rego queries against it.
ARMO (CNCF project)
A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.
The Kyverno Project (CNCF)
A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.
Prisma Cloud (Palo Alto Networks), originally Bridgecrew
A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.
Open Policy Agent
A CLI that parses configuration files into structured data and tests them against policies you write in Rego, the Open Policy Agent language.
Checkmarx
An open-source scanner from Checkmarx that parses many infrastructure formats into a common model and evaluates Rego queries against it.
ARMO (CNCF project)
A CNCF tool that scans Kubernetes clusters and manifests against control frameworks such as NSA-CISA hardening guidance and CIS benchmarks.
The Kyverno Project (CNCF)
A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.
Mondoo
A security and compliance platform built on cnquery, a query language that treats cloud accounts, hosts, containers and IaC as queryable resources.
Open Policy Agent (CNCF)
The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.
Tenable
A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.
Aqua Security
A Terraform-specific static analyzer that evaluates HCL against cloud misconfiguration checks, now consolidated into Aqua's Trivy.
Aqua Security
An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.
Mondoo
A security and compliance platform built on cnquery, a query language that treats cloud accounts, hosts, containers and IaC as queryable resources.
Open Policy Agent (CNCF)
The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.
Tenable
A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.
Aqua Security
A Terraform-specific static analyzer that evaluates HCL against cloud misconfiguration checks, now consolidated into Aqua's Trivy.
Aqua Security
An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.