π IaC Security
83 tools compared
π Subcategories
π§ Tools in IaC Security
Wiz
A comprehensive cloud security platform with IaC scanning.
Kubescape
A tool for risk analysis, security, compliance, and misconfiguration scanning in Kubernetes.
Spacelift
A specialized CI/CD platform for IaC that provides automation, collaboration, and governance, with built-in security scanning.
CrowdStrike Falcon Cloud Security
A comprehensive CNAPP that extends CrowdStrike's leading endpoint protection to secure the entire cloud estate.
Snyk IaC
Finds and fixes misconfigurations in Terraform, CloudFormation, Kubernetes, and ARM templates within developer workflows.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine.
Spacelift
A CI/CD platform for IaC with built-in policy and compliance features.
Wiz
Agentless CNAPP that provides full-stack visibility to rapidly identify and remove critical risks in cloud environments.
Wiz
An agentless CNAPP that provides full-stack visibility of cloud risks, connecting IaC issues to runtime context.
Terrascan
An open-source static code analysis tool for IaC that helps detect security and compliance violations.
GitGuardian
A platform for automated secrets detection and remediation.
CrowdStrike Falcon Cloud Security
A unified cloud-native application protection platform (CNAPP).
Orca Security
A comprehensive CNAPP that provides 100% visibility into cloud risks using a patented SideScanningβ’ technology.
GitGuardian IaC Security
Scans infrastructure-as-code files for misconfigurations and security issues within the software development lifecycle.
Checkov
An open-source static analysis tool for scanning IaC to find misconfigurations before they're deployed.
Orca Security
A comprehensive cloud security platform with IaC scanning.
tfsec
An open-source static analysis tool for Terraform.
Lacework
A CNAPP that uses a patented Polygraph Data Platform to provide automated threat detection and response.
Orca Security
A comprehensive, agentless CNAPP that provides full-stack visibility into cloud environments, including IaC security.
tfsec
An open-source tool that performs static analysis of Terraform code to spot misconfigurations and security issues.
Fugue by Snyk
A cloud security posture management (CSPM) tool with IaC capabilities.
Snyk IaC
Finds and fixes security issues in Terraform, CloudFormation, Kubernetes, and ARM templates.
Trivy
An open-source scanner for vulnerabilities, misconfigurations, secrets, and SBOM.
Snyk
Finds and fixes vulnerabilities in code, open source, containers, and IaC.
KICS
An open-source static analysis tool from Checkmarx that finds security vulnerabilities and misconfigurations in IaC.
Open Policy Agent
An open-source, general-purpose policy engine.
Prisma Cloud (Checkov)
Secures applications from code to cloud, including IaC scanning with the open-source engine Checkov.
Checkov
An open-source static analysis tool for Infrastructure-as-Code.
Prisma Cloud by Palo Alto Networks
Provides comprehensive security and compliance coverage for applications, data, and the entire cloud-native technology stack.
SpectralOps
A developer-first platform for finding and fixing security issues in code.
Prisma Cloud
A comprehensive Cloud Native Application Protection Platform (CNAPP).
Datadog Cloud Security Management
Integrates security into the Datadog observability platform, providing IaC scanning, CSPM, and threat detection.
Datadog Cloud Security Management
A cloud security solution that's part of the Datadog observability platform.
Lacework
A data-driven CNAPP that uses machine learning to automate cloud security, from IaC scanning to threat detection.
Terrascan
An open-source static code analysis tool for IaC.
Snyk IaC
Find and fix security issues in Terraform, CloudFormation, Kubernetes, and ARM templates.
KICS
An open-source IaC static analysis tool by Checkmarx.
Tenable Cloud Security (Terrascan)
A CNAPP solution that includes IaC scanning, CSPM, and workload protection, utilizing the open-source Terrascan engine.
Sysdig Secure
A cloud-native security platform with a focus on runtime security.
Aqua Security (tfsec, Trivy)
A full-lifecycle CNAPP that secures applications from development to production, featuring IaC scanning via tfsec and Trivy.
TFLint
A static analysis tool focused on linting Terraform code.
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) for misconfigurations.
Trivy
A comprehensive, easy-to-use open-source security scanner.
Styra Declarative Authorization Service (DAS)
An enterprise management plane for Open Policy Agent (OPA) to operationalize authorization and policy.
GitGuardian
A platform focused on detecting and remediating secrets in code, with IaC misconfiguration scanning.
Spacelift
A specialized CI/CD platform for IaC that includes integrated policy as code enforcement.
env0
An automation platform for IaC that provides governance, cost management, and policy enforcement.
Wiz
A CNAPP platform that provides full-stack visibility and security risk context, from code to cloud.
Orca Security
An agentless CNAPP that provides comprehensive visibility into cloud risks without per-asset integration.
CrowdStrike Falcon Cloud Security
A CNAPP that extends CrowdStrike's leading endpoint security to protect the entire cloud estate.
Snyk IaC
Scans IaC files for misconfigurations and security vulnerabilities, integrating into developer workflows.
Pulumi CrossGuard
A policy as code solution for the Pulumi platform.
HashiCorp Sentinel
An embedded policy-as-code framework integrated with the HashiCorp Enterprise products.
Lacework
A cloud security platform that uses data and automation to drive security outcomes.
Lacework
A CNAPP that uses anomaly detection to provide visibility and threat detection across cloud environments.
Datadog Cloud Security Management
Integrates security into the Datadog observability platform, providing posture management and threat detection.
tfsec
A static analysis security scanner for Terraform code.
Bridgecrew by Prisma Cloud
A developer-first cloud security platform with a focus on IaC.
Prisma Cloud (by Palo Alto Networks)
A comprehensive CNAPP that secures applications from code to cloud, including robust IaC security.
Sysdig Secure
A CNAPP built on a foundation of deep runtime visibility, powered by Falco.
HashiCorp Sentinel
A policy as code framework for HashiCorp products.
Rapid7 InsightCloudSec
A cloud-native security platform for unified visibility and control.
Zscaler Posture Control
A cloud-native application protection platform (CNAPP) for unified cloud security.
Checkov
An open-source static analysis tool for infrastructure as code.
Pulumi Policy as Code
An integrated policy as code solution for the Pulumi IaC platform.
Aqua Security
A comprehensive security platform for cloud-native applications.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform with IaC scanning capabilities.
Qualys Cloud Platform
A comprehensive security and compliance platform with IaC scanning.
Tenable.cs
A cloud-native security platform with IaC scanning.
Terrascan
An open-source static code analyzer for Infrastructure as Code.
Aqua Security
A CNAPP focused on securing the entire lifecycle of container-based and cloud-native applications.
KICS by Checkmarx
An open-source solution for static analysis of IaC.
Checkmarx KICS
Open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
CloudQuery
An open-source tool that extracts, transforms, and loads cloud configuration into a database for analysis.
Cloud Custodian
An open-source rules engine for managing public cloud accounts.
Prowler
An open-source tool for AWS security assessment, auditing, hardening, and incident response.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that enables unified, context-aware policy enforcement.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform code.
Checkmarx KICS
An open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
Turbot Pipes
An open-source tool for querying and managing your cloud environment.
Regula
An open-source tool for checking IaC against security and compliance policies.
Terrascan
An open-source static code analyzer for IaC that helps detect security issues and enforce policies.
Regula
An open-source tool that evaluates Terraform and CloudFormation for misconfigurations using Rego.