AppSecNews

IaC Security

Infrastructure as Code Security

Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.

17 tools profiled

How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

3 tools match

  • Checkov

    Prisma Cloud (Palo Alto Networks), originally Bridgecrew

    IaC Security

    A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.

    Open source
    Established Verified
  • Prisma Cloud

    Palo Alto Networks

    IaC Security

    Palo Alto Networks' cloud-native application protection platform, spanning posture management, workload defense, IaC scanning and code-to-cloud tracing.

    Commercial
    Established
  • Trivy

    Aqua Security

    IaC Security

    An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.

    Open source
    Established Verified
  • Checkov

    Prisma Cloud (Palo Alto Networks), originally Bridgecrew

    A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.

    Open source Established
    IaC Security
  • Prisma Cloud

    Palo Alto Networks

    Palo Alto Networks' cloud-native application protection platform, spanning posture management, workload defense, IaC scanning and code-to-cloud tracing.

    Commercial Established
    IaC Security
  • Trivy

    Aqua Security

    An open-source scanner that finds vulnerabilities, misconfigurations, secrets and license issues across container images, filesystems, repositories and IaC.

    Open source Established
    IaC Security
Tick up to 4 tools above.