Container Vulnerability Security Tools

Compare the best Container Vulnerability tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.

Wiz

Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.

CNAPPASPM
Trending Hands-on
Oligo Security

Oligo Security offers application layer insights as part of a CADR platform. They baseline application library activities at a function level, and can detect either malicious deviation, or the execution of known vulnerable functions. This extends into AI, allowing them to see, detect, and respond to AI applications.

CADRADR
Trending Hands-on
Upwind

Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.

CNAPPCADR
Trending Open Source
Sweet Security

The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities

CNAPPCADR
Hands-on Nerdy
Raven

Raven has built a comprehensive runtime oriented ADR solution that can detect function executions from packages being exploited. This empowers them to detect application layer attacks, create prioritization based on what functions are being used, as well as virtual patching to prevent vulnerability exploitation.

ADRSCA
Trending Hands-on
Kodem

Kodem offers runtime first code security solutions - from runtime function execution SCA to runtime detection for prioritizing SAST findings. They're also one of the few to offer ADR solutions.

ADRSAST
Trending Hands-on
Dynatrace

Via their oneagent, Dynatrace provides highly competitive ADR capabilities with function level reachability, RASP style blocking, and the ability to query most logs. Their agent also extends into processes and hosts. Their CADR offering has the complete offering from a feature perspective, but the UX struggles to tie it together for security.

CADRADR
Best for Enterprise
Stream Security

Stream Security provides real time cloud context for enterprise security operations teams. The solution fills in the missing configuration gaps with most existing EDR and SIEM approaches to cloud security by providing real time information about how the cloud environment is changing to detect and respond to threats faster.

CNAPPCSPM
Best for MidMarket
AccuKnox

AccuKnox began with the open source project KubeArmor and has since built into a larger CNAPP platform. Their specialization is runtime protection policies for Kubernetes, which allows for granular rules on which processes can access which files.

CNAPPASPM
Hands-on Nerdy Best for Enterprise
Snyk

Snyk was the first to really do DevSecOps - fast, actionable, developer focused CI/CD security scanning. They also were early to consolidate scanners into a single place - IaC, Code, SCA, and Container. There are many platforms with small improvements over them - better reachability, workflows, etc. - but they remain a strong player in the space for having scaled so meaningfully across enterprises.

ASPMSAST
Trending Open Source
Aqua Security

Aqua Security built a lot of the open source projects that power modern cloud security, and can go feature for feature with most other CNAPP platforms. The downside of the CNAPP has been the UI/UX, and the focus has always been on container protection more than holistic cloud security features.

CNAPPCSPM
Trending Open Source
Mend

Mend was Snyk's main competitor early for quick open source scanning in pipeline, but did not expand as quickly as Snyk into other areas. Their open source Renovate tool is great for keeping your in-house dependencies up to date, but their UI and scanning engine were more difficult to deploy, maintain, and navigate. However, due to Renovate they have unique visibility into the expected challenge of a version upgrade. They've recently expanded most heavily into MLBOM capabilities.

SASTSCAContainer Vulnerability
Hands-on Nerdy Best for Enterprise
DataDog

Datadog offers a complete suite a security offerings that are a great fit for developer focused teams not looking for the most mature details in each area. They offer most scanning types, runtime detections, and a full SIEM, and you're probably already sending them your logs. It's a great runtime choice to meet developers where they work, but the UX is built primarily for developers.

CNAPPASPM
Hands-on Nerdy
ARMO

ARMO has all of the features of a CNAPP, but with a special emphasis on runtime security and Kubernetes. Their open source Kubescape is a great tool for scanning Kubernetes clusters, and their paid offering provides true CADR runtime protection and compliance features.

CNAPPCADR
Trending Open Source
Sysdig

Sysdig created the first runtime cloud protection tool with the open source project Falco, and has since built a trusted, enterprise ready, runtime oriented CNAPP platform. The tool is strongest at runtime protection, but offers the standard suite of CNAPP features, and is especially a good choice for regulated industries.

CNAPPCADR
Trending Open Source
Deepfence

Deepfence is a great no-frills CNAPP with a ton of optionality. Their Open Source ThreatMapper scans for malware, vulnerabilities, misconfigurations, and secrets. Their paid offering, ThreatStryker, adds eBPF runtime protection - including network and quarantine responses. Their open source is an unbelievable value for a free offering.

CNAPPCSPM
Open Source Hands-on
Uptycs

Uptycs biggest strength is its biggest weakness - it undoubtedly has the most features of any CNAPP platform, from ASPM to container runtime. However, that creates a corresponding UI bloat that's as bad as it gets for these platforms. As a certified Kubernetes enjoyer though, their cluster visibility with Kubequery is quite good.

CNAPPASPM
Best for Enterprise
RAD Security

Rad has deep roots in contributing to kubernetes security developments and provides dedicated services to help customers secure their cloud environments. They have in depth policy, audit log, RBAC, and runtime capabilities protection capabilities, now augmented with an AI first approach to accessing and using the data.

CADRCSPM
Hands-on Best for Enterprise Best for MidMarket