📋 IaC SAST
11 tools compared
🔧 Tools in IaC SAST
Spacelift
A specialized CI/CD platform for IaC that provides automation, collaboration, and governance, with built-in security scanning.
Wiz
An agentless CNAPP that provides full-stack visibility of cloud risks, connecting IaC issues to runtime context.
GitGuardian IaC Security
Scans infrastructure-as-code files for misconfigurations and security issues within the software development lifecycle.
Orca Security
A comprehensive, agentless CNAPP that provides full-stack visibility into cloud environments, including IaC security.
Snyk IaC
Finds and fixes security issues in Terraform, CloudFormation, Kubernetes, and ARM templates.
Prisma Cloud (Checkov)
Secures applications from code to cloud, including IaC scanning with the open-source engine Checkov.
Datadog Cloud Security Management
Integrates security into the Datadog observability platform, providing IaC scanning, CSPM, and threat detection.
Lacework
A data-driven CNAPP that uses machine learning to automate cloud security, from IaC scanning to threat detection.
Tenable Cloud Security (Terrascan)
A CNAPP solution that includes IaC scanning, CSPM, and workload protection, utilizing the open-source Terrascan engine.
Aqua Security (tfsec, Trivy)
A full-lifecycle CNAPP that secures applications from development to production, featuring IaC scanning via tfsec and Trivy.
Checkmarx KICS
Open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.