Container Vulnerability Security Tools
Compare the best Container Vulnerability tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.
Oligo Security offers application layer insights as part of a CADR platform. They baseline application library activities at a function level, and can detect either malicious deviation, or the execution of known vulnerable functions. This extends into AI, allowing them to see, detect, and respond to AI applications.
Aikido provides everything the average startup to mid-market company needs for security in a box - every code and cloud security scanner under the sun without much feature compromise, alongside a surprisingly robust runtime application solution for things like bot prevention. A no-nonsense replacement for a lot of more "specialized" solutions that tend to slow developers down.
Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.
Cycode offers a holistic all-in-one ASPM tool with their in house scanners alongside the ability to import third party findings. They offer about every scanner and feature you could need out of an AppSec tool.
The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities
Raven has built a comprehensive runtime oriented ADR solution that can detect function executions from packages being exploited. This empowers them to detect application layer attacks, create prioritization based on what functions are being used, as well as virtual patching to prevent vulnerability exploitation.
Kodem offers runtime first code security solutions - from runtime function execution SCA to runtime detection for prioritizing SAST findings. They're also one of the few to offer ADR solutions.
Apiiro has built an all-in-one application security management solution that is especially strong at managing application security results at enterprise scale. They focus on building robust relationships between code assets to manage application security programs at scale.
Corgea provides a robust bundling of AI first scanning tools - from AI SAST to SCA and Secrets scanning. Corgea's especially strong at discovering vulnerabilities via AI scanning, and AI based prioritization for false positive analysis.
Endor Labs stands out in their granularity and reachability analysis for open source packages. They've also added back ported patches and automatic fix suggestions based on function changes between patch versions. They offer basic SAST capabilities via opengrep for companies that need it.
Ox provides an all-in-one application security solution that provides their own scanners combined with the ability to import third party findings. They also have a robust API for managing the data in the tool.
Checkmarx has adapted well to the DevSecOps model, offering a lighter weight scanner in the Checkmarx One platform, that integrates well into the larger stack. They don't have all the latest features of some newer companies, but they certainly get the job done for diverse enterprises. I would not suggest venturing off Checkmarx One though.
Legit Security offers a holistic ASPM platform that focuses more on pipeline discovery, security, and third party data ingestion than native scanning solutions.
Via their oneagent, Dynatrace provides highly competitive ADR capabilities with function level reachability, RASP style blocking, and the ability to query most logs. Their agent also extends into processes and hosts. Their CADR offering has the complete offering from a feature perspective, but the UX struggles to tie it together for security.
Stream Security provides real time cloud context for enterprise security operations teams. The solution fills in the missing configuration gaps with most existing EDR and SIEM approaches to cloud security by providing real time information about how the cloud environment is changing to detect and respond to threats faster.
Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.
Snyk was the first to really do DevSecOps - fast, actionable, developer focused CI/CD security scanning. They also were early to consolidate scanners into a single place - IaC, Code, SCA, and Container. There are many platforms with small improvements over them - better reachability, workflows, etc. - but they remain a strong player in the space for having scaled so meaningfully across enterprises.
Soos offers holistic ASPM scanners and ingestion, with a special focus on in depth SCA scanning and SBOM generation
Aqua Security built a lot of the open source projects that power modern cloud security, and can go feature for feature with most other CNAPP platforms. The downside of the CNAPP has been the UI/UX, and the focus has always been on container protection more than holistic cloud security features.
Mend was Snyk's main competitor early for quick open source scanning in pipeline, but did not expand as quickly as Snyk into other areas. Their open source Renovate tool is great for keeping your in-house dependencies up to date, but their UI and scanning engine were more difficult to deploy, maintain, and navigate. However, due to Renovate they have unique visibility into the expected challenge of a version upgrade. They've recently expanded most heavily into MLBOM capabilities.
Boost Security has a shared vision for all in one configuration scanning out to runtime. They have smart kubernetes & Istio integrations for runtime context, alongside the standard suite of SCA, SDLC, SAST, IaC, Secrets, and Containers based on a combination of open source and in house built tools. I appreciate the openness of their rule set in their documentation.
Datadog offers a complete suite a security offerings that are a great fit for developer focused teams not looking for the most mature details in each area. They offer most scanning types, runtime detections, and a full SIEM, and you're probably already sending them your logs. It's a great runtime choice to meet developers where they work, but the UX is built primarily for developers.
ARMO has all of the features of a CNAPP, but with a special emphasis on runtime security and Kubernetes. Their open source Kubescape is a great tool for scanning Kubernetes clusters, and their paid offering provides true CADR runtime protection and compliance features.
Of the cloud providers, GCP offers the best native tooling to scan and remediate container vulnerabilities. Combined with Google Distroless images, Google offers robust out of the box image protection capabilities for containerized environments.
CrowdStrike's container runtime technically works, but deployment, maintenance, and usefulness do not compare to other tools at the time of testing. CrowdStrike's Windows offerings remain dominant in the space, but their CNAPP and container security solutions are difficult to recommend.
Sysdig created the first runtime cloud protection tool with the open source project Falco, and has since built a trusted, enterprise ready, runtime oriented CNAPP platform. The tool is strongest at runtime protection, but offers the standard suite of CNAPP features, and is especially a good choice for regulated industries.
Hopper provides SCA and container scanning with the full suite of features you'd expect from a modern SCA tool - function level reachability, legal compliance, prioritization, and more. Their function level reachability uses a unique methodology to reduce false positives.
Uptycs biggest strength is its biggest weakness - it undoubtedly has the most features of any CNAPP platform, from ASPM to container runtime. However, that creates a corresponding UI bloat that's as bad as it gets for these platforms. As a certified Kubernetes enjoyer though, their cluster visibility with Kubequery is quite good.
Start Left brings SAST, SCA, Container, and IaC scanning in a single platform. They also have AI code remediation recommendations, and provide a docker image for running local scans.
RapidFort focuses on removing vulnerabilities by creating slimmed down container images for your applications, and scans for vulnerabilities as well.
Rad has deep roots in contributing to kubernetes security developments and provides dedicated services to help customers secure their cloud environments. They have in depth policy, audit log, RBAC, and runtime capabilities protection capabilities, now augmented with an AI first approach to accessing and using the data.
Rezlion combines their own scanning at runtime with ingesting from other platforms to provide an exploitability prioritization view of container and SCA vulnerabilities. They focus on simple deployment into your environment to prioritize what packages and libraries are running.
AWS ECR has vulnerability scanning that works, but much like other tools has "CVE dump" problems. They also don't provide clear guidance on how to remediate issues, but can be a good extension of an AWS native security approach.
Defender for Cloud has a lot of comparative features to dedicated CNAPPs, but it's a beast to setup and maintain. It's a good starting point for larger companies who don't have an appetite for a more focused solution, and are addicted to collecting the highest E license as possible.
Qwiet takes a unique approach to scanning that starts with a map of your application, and scans within that context. They have smart prioritization filters combined with the standard suite of SCA, container, SAST, Secrets, and IaC scanning. They don't offer "pipeline-less" scanning via webhooks if that's a requirement for you.
Veracode is a legacy SAST vendor that has done a good job expanding into other categories. They are a great choice for organizations using more legacy or waterfall type development methods, but still don't have an intuitive interface or workflows for modern dev teams.
Rainforest combines all in one code vulnerable scanning with brand protection capabilities. They instrument via an on premise VM allowing you to scan everything in your own environment.
Docker has quietly built out their container vulnerability scanning to be comparable to other tools in the area. While, at the moment, they lack a full enterprise platform for full tracking across container lifecycles, their scanning built into the Docker Desktop app and CLI options provide much needed visibility into where vulnerabilities are coming from. They've also recently launched their own hardened images.
Trivy is an amazing open source container, SCA, and IaC scanner provided by the team at Aqua Security. This awesome scanner powers a lot of tools under the hoods and is a great resource for the community.