What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Current platform module names and edition boundaries: confirm with vendor
- Supported managed Kubernetes and serverless runtime targets: verify against vendor documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Aqua works on both sides of the deploy boundary. Before deployment it scans container images, VM images, functions and infrastructure as code definitions, unpacking layers to inventory operating system packages and language dependencies, matching those against vulnerability feeds, and separately looking for embedded secrets, malware signatures and misconfigured Dockerfile directives. The open source Trivy scanner, which Aqua maintains, is the visible face of this engine, and the commercial platform adds an assurance policy layer that decides whether a given image is allowed to run at all.
After deployment the model changes from analysis to enforcement. Aqua places an agent, the Enforcer, on each node or as a sidecar, and uses kernel level telemetry including eBPF probes to observe process execution, file access, network connections and container escape attempts. A profile describes what a workload is expected to do, derived from image contents and observed behavior, and anything outside it can be alerted on or blocked. Drift prevention is the sharpest version: a container that starts executing a binary that was not in its image gets stopped, which cuts off a large family of post-exploitation techniques without needing a signature for the attack.
Where it fits
This is platform and security team tooling, not something an individual developer installs. Scanning hooks into CI and into registries, admission control sits in front of the cluster, and runtime enforcement runs as a DaemonSet with privileged access to each node. You need immutable images from a pipeline you control, and agreement on what an assurance failure means in practice. Moving enforcement from audit to blocking is an operational decision, not a technical one.
Strengths
- Drift prevention blocks unknown binaries in running containers without depending on threat signatures.
- The same policy object can gate a build, an admission request and a running workload, so one rule is not restated in three tools.
- Trivy gives you a genuinely capable free scanner to standardize on before committing to the commercial layer.
Limitations
- Node level agents with kernel visibility are a real blast radius consideration, and need ongoing compatibility attention as kernels move.
- The platform is broad, and teams routinely deploy a fraction of it while paying the complexity cost of the whole.
- Findings are version matched, so triage volume on large base images stays high without additional prioritization work.
Who it suits
A strong fit for organizations running containers at scale across multiple clusters and clouds, with a security team that will actually operate runtime policy rather than only read reports. Less appropriate for a small team needing image scanning and nothing else, where Trivy alone does the job, and awkward where you cannot run privileged agents.
Used Aqua Security? Recommend it under your own name and title.
Recommend this tool