Trivy
Scanner for container images, filesystems, git repositories, Kubernetes clusters and IaC templates.
Primary use Vulnerability and misconfiguration scanning
- PL
- CO
- BU
- TE
- RE
- DE
- OP
- MO
29 security tools mapped to lifecycle stages, categories and supported technologies.
Scanner for container images, filesystems, git repositories, Kubernetes clusters and IaC templates.
Primary use Vulnerability and misconfiguration scanning
Fast static analysis with pattern-based rules that resemble the source language being scanned.
Primary use Static application security testing
Code quality and security platform with language analysers, quality gates and historical trend tracking.
Primary use Code quality and security analysis
Semantic code analysis engine that queries code as data, with strong dataflow and taint tracking.
Primary use Deep static analysis and variant hunting
Open-source web application scanner and intercepting proxy with baseline and full active scan modes.
Primary use Dynamic application security testing
Secret scanner for git history, working trees and diffs, with configurable detection rules.
Primary use Secret detection
Secret scanner that can verify detected credentials against the issuing provider to reduce false positives.
Primary use Verified secret detection
Policy-as-code scanner for Terraform, CloudFormation, Kubernetes, Helm, ARM and Dockerfiles.
Primary use Infrastructure as code scanning
Terraform-focused static analysis with fast local feedback and custom checks.
Primary use Terraform security scanning
Scanner for infrastructure code across Terraform, Kubernetes, Docker, Ansible and CI configuration.
Primary use Multi-format IaC scanning
General-purpose policy engine using Rego, usable for admission control, CI checks and application authorisation.
Primary use Policy as code
Kubernetes-native policy engine that uses YAML policies for validation, mutation, generation and image verification.
Primary use Kubernetes admission policy
Runtime threat detection for containers and hosts, using kernel event streams and a rules engine.
Primary use Runtime security monitoring
SBOM generator for container images and filesystems, supporting SPDX and CycloneDX output.
Primary use SBOM generation
Vulnerability scanner for container images and filesystems, pairing with Syft SBOMs.
Primary use Vulnerability scanning from SBOMs
Signs and verifies container images and artefacts, including keyless signing and attestations.
Primary use Artifact signing and verification
Secrets management platform with dynamic credentials, encryption as a service and detailed audit logging.
Primary use Secrets management
Synchronises secrets from external managers into Kubernetes Secrets with scheduled refresh.
Primary use Secret synchronisation for Kubernetes
Linter for Ansible content with a production profile covering risky modules, idempotence and naming.
Primary use Ansible content quality and safety checks
Enterprise automation platform with RBAC, credential injection, execution environments and job auditing.
Primary use Governed infrastructure automation
Multi-cloud security assessment tool with benchmark-aligned checks for AWS, Azure, GCP and Kubernetes.
Primary use Cloud posture assessment
Rules engine for cloud resource governance with filters and remediation actions expressed in YAML.
Primary use Cloud policy enforcement and remediation
Container registry with vulnerability scanning, signing, replication, quotas and RBAC per project.
Primary use Secure artefact registry
Vulnerability management platform that aggregates and deduplicates findings from many scanners.
Primary use Vulnerability aggregation and tracking
Automated dependency update bot with grouping, scheduling and digest pinning across ecosystems.
Primary use Dependency updates
Compliance scanning and remediation against SCAP content such as CIS and STIG benchmarks.
Primary use Host compliance scanning
Open-source security platform combining host intrusion detection, log analysis and compliance monitoring.
Primary use SIEM and host monitoring
Web security testing suite with an intercepting proxy, scanner and extensive manual testing tooling.
Primary use Manual and automated web testing
Developer-oriented platform covering dependency, container, IaC and code scanning with fix advice.
Primary use Developer security platform