IaC Security
Compare 184 iac security tools to find the right one for your needs
π Subcategories
π§ Tools
Compare and find the best iac security for your needs
Spacelift
A specialized CI/CD platform for IaC that provides automation, collaboration, and governance, with built-in security scanning.
Kubescape
An open-source Kubernetes security posture management tool that scans YAML files, Helm charts, and live clusters.
Wiz
A leading CNAPP that provides full stack visibility and security for your cloud.
CrowdStrike Falcon Cloud Security
Extends CrowdStrike's EDR leadership to cloud security.
Snyk IaC
Finds and fixes misconfigurations in Terraform, CloudFormation, Kubernetes, and ARM templates within developer workflows.
Spacelift
A CI/CD platform for IaC with built-in policy and compliance features.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that can be used for scanning IaC.
Wiz
An agentless CNAPP that provides full-stack visibility of cloud risks, connecting IaC issues to runtime context.
Wiz
A CNAPP that provides full stack visibility and security.
Terrascan
An open-source static code analysis tool for IaC that helps detect security and compliance violations.
GitGuardian
A platform for automated secrets detection and remediation.
GitGuardian IaC Security
Scans infrastructure-as-code files for misconfigurations and security issues within the software development lifecycle.
Orca Security
Provides comprehensive, agentless security and compliance for the cloud.
CrowdStrike Falcon Cloud Security
A comprehensive cloud security platform that provides breach protection for the entire cloud estate, from workloads to infrastructure.
Checkov
An open-source static analysis tool for scanning IaC to find misconfigurations before they're deployed.
Orca Security
An agentless cloud security platform with IaC scanning.
tfsec
A fast, open-source static analysis scanner for Terraform code to find security misconfigurations.
Orca Security
A comprehensive, agentless CNAPP that provides full-stack visibility into cloud environments, including IaC security.
Lacework
Automates cloud security and compliance for multicloud environments.
tfsec
An open-source tool that performs static analysis of Terraform code to spot misconfigurations and security issues.
Fugue by Snyk
A cloud security posture management (CSPM) tool with IaC capabilities.
Snyk IaC
Finds and fixes security issues in Terraform, CloudFormation, Kubernetes, and ARM templates.
Trivy
Versatile open-source security scanner from Aqua Security that finds vulnerabilities, IaC misconfigurations, and secrets.
Snyk
Finds and fixes vulnerabilities in code, open source, containers, and IaC.
KICS
An open-source static analysis tool from Checkmarx that finds security vulnerabilities and misconfigurations in IaC.
Open Policy Agent
An open-source, general-purpose policy engine.
Prisma Cloud (Checkov)
Secures applications from code to cloud, including IaC scanning with the open-source engine Checkov.
Checkov
Open-source IaC scanner that finds misconfigurations in Terraform, CloudFormation, Kubernetes, and more.
Prisma Cloud by Palo Alto Networks
Secures applications from code to cloud across multicloud environments.
SpectralOps
A developer-first platform for finding and fixing security issues in code.
Prisma Cloud
A comprehensive Cloud Native Application Protection Platform (CNAPP).
Datadog Cloud Security Management
Integrates security into the Datadog observability platform, providing IaC scanning, CSPM, and threat detection.
Datadog Cloud Security Management
A cloud security solution from Datadog that includes CSPM, CWP, and IaC scanning.
Terrascan
Open-source static code analyzer for IaC that helps detect security issues and compliance violations.
Lacework
A data-driven CNAPP that uses machine learning to automate cloud security, from IaC scanning to threat detection.
Snyk IaC
A tool that helps developers find and fix security issues in IaC files like Terraform, CloudFormation, and Kubernetes.
KICS
Open-source IaC scanner from Checkmarx that supports a wide range of platforms and offers extensive queries.
Tenable Cloud Security (Terrascan)
A CNAPP solution that includes IaC scanning, CSPM, and workload protection, utilizing the open-source Terrascan engine.
Sysdig Secure
A cloud security platform with deep runtime insights.
Aqua Security (tfsec, Trivy)
A full-lifecycle CNAPP that secures applications from development to production, featuring IaC scanning via tfsec and Trivy.
TFLint
A linter for Terraform that focuses on best practices, style conventions, and detecting potential errors.
Steampipe
An open-source tool that instantly queries cloud APIs using SQL, without needing to ETL data into a database.
Jit
A DevSecOps platform that simplifies and automates security.
Deepfactor
A runtime application security platform that includes IaC scanning.
Steampipe
Open-source tool that maps cloud APIs to PostgreSQL tables, enabling SQL-based querying for security and compliance.
CloudQuery
An open-source tool for building a cloud asset inventory that can be used for policy-as-code checks.
CloudQuery
An open-source tool that extracts, transforms, and loads your cloud infrastructure data into a PostgreSQL database, allowing you to query it with SQL.
Steampipe
An open-source tool that instantly translates APIs into a PostgreSQL database, allowing you to query your cloud infrastructure with SQL.
Cloudanix
A unified platform for code, cloud, identity, and workload security.
Lightspin
A CNAPP that provides a contextual view of cloud security risks.
oak9
Dynamically secure Infrastructure as Code (IaC) and deployed cloud-native workloads.
Prowler
An open-source security tool for AWS, Azure, and GCP that performs security assessments, audits, and incident response.
oak9
An Infrastructure as Code security platform that is designed for developers.
ggshield
A CLI tool for secrets detection that also includes IaC scanning capabilities to find misconfigurations.
Prowler
An open-source security tool for AWS, Azure, and GCP that performs security assessments, audits, and hardening.
tfsec
Open-source static analysis for Terraform.
Trivy
Finds vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more.
Runecast
Proactive security and compliance analysis for hybrid clouds.
Trivy
A comprehensive, open-source security scanner for vulnerabilities, misconfigurations, secrets, and SBOMs in IaC, containers, and more.
Open Policy Agent (OPA)
Open-source, general-purpose policy engine.
oak9
An IaC security platform that helps developers build secure and compliant cloud native applications.
Lightspin by Cisco
A CNAPP that prioritizes risks using attack path analysis.
Checkov
An open-source static analysis tool for scanning Infrastructure as Code for misconfigurations and security vulnerabilities.
env0
An automation platform for managing Terraform, Terragrunt, and other IaC workflows with governance and cost control.
Spacelift
A specialized CI/CD platform for Infrastructure as Code that provides automation, collaboration, and policy enforcement.
Styra Declarative Authorization Service (DAS)
An enterprise management plane for Open Policy Agent (OPA) to operationalize authorization and policy.
Styra DAS
A management plane for Open Policy Agent (OPA) that provides centralized policy authoring, distribution, and monitoring.
GitGuardian
A platform that helps you detect and remediate secrets in your code and monitor your software supply chain.
Wiz
A CNAPP that provides full stack visibility, risk prioritization, and security for cloud environments.
CrowdStrike Falcon Cloud Security
A CNAPP that extends CrowdStrike's leading endpoint security to protect the entire cloud estate.
Orca Security
An agentless CNAPP that provides comprehensive visibility and security for cloud environments without the need for per-asset agents.
Firefly
A platform for managing cloud assets, discovering resources, and codifying infrastructure to manage drift and ensure governance.
SpectralOps
A developer-first security platform that scans code, configuration, and other assets for security issues.
Checkov
An open-source static code analysis tool for scanning infrastructure as code (IaC) files for misconfigurations and security vulnerabilities.
GitHub Advanced Security
A suite of security tools for GitHub repositories.
Orca Security
A comprehensive, agentless CNAPP that provides shift-left security, including pre-commit IaC scanning.
SentinelOne Singularity Cloud
A cloud security platform that provides autonomous threat protection for cloud workloads and environments.
CrowdStrike Falcon Cloud Security
A CNAPP from a leader in endpoint security, offering both agentless and agent-based protection, including IaC scanning.
Trivy
A scanner for vulnerabilities in container images, filesystems, and Git repositories, as well as for configuration issues.
Fugue
A cloud security platform focused on IaC and CSPM.
Wiz
A comprehensive CNAPP that includes IaC scanning as part of its full lifecycle cloud security solution.
Kyverno
A policy engine designed for Kubernetes that can validate, mutate, and generate configurations using policies.
JupiterOne
A platform that creates a graph-based model of your cyber assets and their relationships, allowing you to understand and manage your attack surface.
SonarCloud
A cloud-based code quality and security service.
Lacework
A CNAPP that uses a Polygraph Data Platform to automate cloud security, including IaC security.
Datadog Cloud Security
A cloud security platform that includes IaC scanning, CSPM, and CWPP, leveraging observability data for context.
Datadog Cloud Security Management
A security and observability platform that includes IaC scanning as part of its cloud security offering.
Sysdig Secure
A CNAPP that uses deep runtime insights from Falco to secure the entire cloud-native lifecycle, including IaC scanning.
Pulumi CrossGuard
A policy as code solution for the Pulumi platform.
Datadog Cloud Security Posture Management
A CSPM solution that scans your cloud environments for misconfigurations and compliance risks, and provides remediation guidance.
Snyk Infrastructure as Code
A developer-first IaC security tool to find and fix misconfigurations.
Sentinel
A policy as code framework from HashiCorp.
Snyk IaC
A developer-focused IaC security tool that scans for misconfigurations and provides context and remediation advice.
Fugue
A CNAPP that provides end-to-end security for cloud environments, from IaC to runtime.
Accurics by Tenable
Provides security and governance from code to cloud.
Snyk IaC
Developer-first IaC security tool that finds and fixes misconfigurations in Terraform, CloudFormation, Kubernetes, and more.
KICS by Checkmarx
An open-source static analysis tool for finding security vulnerabilities, compliance issues, and infrastructure misconfigurations in IaC.
Datadog Cloud Security Management
A security and compliance solution that provides threat detection, posture management, and IaC scanning within the Datadog platform.
Snyk Infrastructure as Code
Find and fix security issues in your Terraform, CloudFormation, Kubernetes, and ARM configurations.
Pulumi
An IaC platform that allows you to use general-purpose programming languages to provision and manage cloud infrastructure.
tfsec
A static analysis tool for Terraform code.
Pulumi CrossGuard
Define and enforce policies on your cloud infrastructure using familiar programming languages.
Lacework
A CNAPP that uses data and machine learning to provide automated threat detection, configuration compliance, and vulnerability management.
HashiCorp Sentinel
An embedded policy-as-code framework that integrates with the HashiCorp Enterprise platform.
Lacework
A CNAPP that uses data and machine learning to secure cloud environments.
Datadog Cloud Security Management
Detects threats and misconfigurations across the full cloud stack.
Snyk IaC
A tool that helps developers find and fix security issues in IaC configurations like Terraform, CloudFormation, Kubernetes, and ARM templates.
Bridgecrew by Prisma Cloud
A developer-first cloud security platform with a focus on IaC.
CloudSploit by Aqua
Open-source and commercial tool for cloud security posture monitoring.
Checkov
An open-source static analysis tool for infrastructure as code.
Prisma Cloud (by Palo Alto Networks)
Secures applications from code to cloud across multicloud environments.
Sysdig Secure
A CNAPP built on a foundation of deep runtime visibility, powered by Falco.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform with IaC scanning capabilities.
Pulumi Policy as Code
An integrated policy as code solution for the Pulumi IaC platform.
Aqua Security Platform
The industry's most integrated Cloud Native Application Protection Platform (CNAPP).
Aqua Security
Secures applications from code to cloud and back.
Aqua Security
A comprehensive security platform for cloud native applications.
Prisma Cloud
A unified security platform that protects applications from code to cloud, including IaC scanning, CSPM, and CWPP.
Sysdig
A cloud security platform that provides deep visibility for securing and monitoring containers, Kubernetes, and cloud services.
Rapid7 InsightCloudSec
A CNAPP from Rapid7 for cloud security and compliance.
Terrascan
An open-source static code analysis tool that helps you detect security and compliance violations in your IaC.
Zscaler Posture Control
A cloud-native application protection platform (CNAPP) for unified cloud security.
Sysdig Secure
A CNAPP built on runtime insights from Falco.
Zscaler Posture Control
Provides unified CNAPP to secure cloud applications.
HashiCorp Sentinel
An embedded policy-as-code framework within the HashiCorp Enterprise platform, used to enforce policies on Terraform runs.
Veracode
A comprehensive application security platform.
SpectralOps
A security tool that scans code, configuration, and IaC for hardcoded secrets and misconfigurations.
GitLab Ultimate
A complete DevOps platform with built-in IaC security.
Sysdig
A cloud-native security and monitoring platform that provides a unified view of risk, health, and performance for cloud and container environments.
TFLint
An open-source linter for Terraform that checks for errors, best practice improvements, and potential bugs.
SonarQube
A platform for continuous inspection of code quality and security.
HashiCorp Sentinel
A policy as code framework for HashiCorp products.
Rapid7 InsightCloudSec
Comprehensive cloud security posture management (CSPM) and workload protection (CWPP).
Prisma Cloud (by Palo Alto Networks)
A comprehensive CNAPP that includes IaC scanning, CSPM, CWPP, and more, building on the open-source Checkov engine.
GitLab IaC Scanning
A built-in security scanning feature within the GitLab CI/CD platform for analyzing IaC files.
Zscaler Posture Control
A CNAPP that integrates CSPM, CIEM, and IaC scanning to provide a unified view of cloud risk.
Microsoft Defender for Cloud
A comprehensive CNAPP and CSPM solution that provides security for Azure, AWS, and GCP, including IaC scanning.
Veracode IaC Security
An IaC scanning solution integrated into Veracode's comprehensive application security platform.
Tenable Cloud Security
A cloud security platform that provides visibility and control over cloud environments, including IaC security.
Checkmarx IaC Security
The enterprise offering built upon the open-source KICS engine, integrated into the Checkmarx One platform.
Checkmarx IaC Security
An enterprise-grade IaC security solution from Checkmarx.
Tenable.cs
A CNAPP from Tenable that provides security from code to cloud, built on the open-source Terrascan engine.
Checkmarx One
A comprehensive application security platform that includes IaC scanning with KICS.
KICS
An open-source static analysis tool for IaC security.
Tenable.cs
A cloud-native application protection platform (CNAPP) from Tenable.
KICS
An open-source static analysis tool that scans IaC for security vulnerabilities, compliance issues, and misconfigurations.
Terrascan
An open-source static code analyzer for IaC.
Tenable Cloud Security (incorporating Terrascan)
Provides unified visibility and security for the entire cloud attack surface.
Aqua Security
A comprehensive CNAPP that secures the entire lifecycle of cloud native applications, including IaC scanning and runtime protection.
Tenable.cs
A cloud native security platform from Tenable.
Qualys Cloud Platform
A cloud-based platform for IT, security, and compliance.
KICS by Checkmarx
An open-source solution for static analysis of IaC.
Bridgecrew
A cloud security platform that helps developers secure their infrastructure from code to cloud.
Bridgecrew
Automate cloud security from code to cloud.
Qualys Cloud Platform
A comprehensive security and compliance platform that includes IaC scanning as part of its cloud security module.
Checkmarx KICS
Open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
Prowler
An open-source tool for AWS security assessment, auditing, hardening, and incident response, with some IaC capabilities.
Turbot Pipes
An open-source tool for querying and managing your cloud environment.
cfn-nag
An open-source tool that scans CloudFormation templates for patterns that may indicate insecure infrastructure.
Accurics
A cloud security platform that enables cyber resilience through policy as code.
pre-commit-terraform
A framework and collection of git hooks for automating checks on Terraform code before commit.
Yor
An open-source tool that automatically adds tags to IaC files, linking them to code owners and repositories.
Terratest
A Go library for writing automated tests for IaC, including security and compliance tests.
Driftctl
An open-source tool to detect differences between your IaC state and your live cloud environment (drift).
Check-jsonschema
A general-purpose CLI tool for validating JSON/YAML files against a schema, useful for custom IaC validation.
Regula
An open-source tool that checks Terraform, CloudFormation, and Kubernetes configs for misconfigurations using Rego.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine.
CloudSploit
An open-source tool for scanning cloud accounts for security risks and misconfigurations.
cfn-lint
An AWS-maintained linter for CloudFormation templates that checks for errors and best practices.
KubeLinter
A static analysis tool from StackRox/Red Hat that checks Kubernetes YAML files for security and best practices.
Terrascan
An open-source static code analyzer for IaC that helps developers build secure infrastructure from the start.
Horusec
Orchestration tool for SAST, SCA, and IaC scanning.
Driftctl
Open-source tool to manage IaC drift.
Regula
An open-source tool that evaluates IaC against policies.
Open Policy Agent (OPA)
An open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
Cloud Custodian
A YAML-based DSL to define policies for managing cloud resources.
Kyverno
A policy engine designed for Kubernetes.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform code.
Checkmarx KICS
An open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
Regula
An open-source tool that checks Terraform, CloudFormation, and Kubernetes configurations for security and compliance issues using Rego.
CloudQuery
An open-source tool that extracts, transforms, and loads cloud asset configuration into SQL databases for analysis.
Mondoo
Policy-as-code platform for security and compliance.
Regula
An open-source policy engine for checking IaC against security and compliance rules.
Cloud Custodian
An open-source tool for cloud security and governance.