Cloud Security Posture Management (CSPM) Tools
Compare the best CSPM tools for cloud security posture management. Detect misconfigurations, enforce compliance, and secure your cloud infrastructure.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.
Aikido provides everything the average startup to mid-market company needs for security in a box - every code and cloud security scanner under the sun without much feature compromise, alongside a surprisingly robust runtime application solution for things like bot prevention. A no-nonsense replacement for a lot of more "specialized" solutions that tend to slow developers down.
Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.
Cycode offers a holistic all-in-one ASPM tool with their in house scanners alongside the ability to import third party findings. They offer about every scanner and feature you could need out of an AppSec tool.
The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities
CloudQuery is a great open source tool to check your cloud environment for compliance issues. You can also use it to build compliance automation in house.
Ox provides an all-in-one application security solution that provides their own scanners combined with the ability to import third party findings. They also have a robust API for managing the data in the tool.
Orca offers the standard suite of CNAPP features with a focus on agentless scanning. They're a good all around CNAPP offering mostly focused on the posture side.
Qualys offers just about every vulnerability scanner you could want from a single vendor - from cloud to on premise to code. They have great vulnerability insights and scanning capabilities in a holistic place, but the platform UX can be difficult compared to more specialized vendors.
Prowler is built on top of the most robust open source cloud scanner there is. It's a great option for organizations that want to get started with CSPM scanning, but aren't sure where to start. I'd recommend anyone use it at least once to get an idea of what's in your environment.
Stream Security provides real time cloud context for enterprise security operations teams. The solution fills in the missing configuration gaps with most existing EDR and SIEM approaches to cloud security by providing real time information about how the cloud environment is changing to detect and respond to threats faster.
AccuKnox began with the open source project KubeArmor and has since built into a larger CNAPP platform. Their specialization is runtime protection policies for Kubernetes, which allows for granular rules on which processes can access which files.
Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.
Intruder offers holistic network vulnerability scanner, DAST, and CSPM scanning solutions, a great option for mid size businesses looking for a flexible scanner
Cyscale checks all the boxes for a CNAPP, but their tracking of user identities stands out in the space. They have great visualizations, and have an agent for K8s support. A strong entry in the CNAPP market.
Aqua Security built a lot of the open source projects that power modern cloud security, and can go feature for feature with most other CNAPP platforms. The downside of the CNAPP has been the UI/UX, and the focus has always been on container protection more than holistic cloud security features.
Cortex Cloud is a security operations platform that integrates cloud and application security capabilities into their larger security operations offerings. This provides a single hub for managing first and third party findings across vulnerabilities and runtime events.
Datadog offers a complete suite a security offerings that are a great fit for developer focused teams not looking for the most mature details in each area. They offer most scanning types, runtime detections, and a full SIEM, and you're probably already sending them your logs. It's a great runtime choice to meet developers where they work, but the UX is built primarily for developers.
Turbot's Guardrails allow enforcement of cloud security controls, while Pipes enables querying across your cloud data.
JIT built a holistic ASPM scanning solution, and has sense heavily invested in AI workflows. They consolidate scanners and create workflows and prioritization for developers. The JIT scanner is unique in that it's a wrapper for other scanners that you run in your own pipelines - an approach with pros and cons.
Cloudfence has focused on creating a more actionable CSPM for specifically managing network and identity security in the cloud. Their network visibility allows them to do some cool things like limiting security groups based on observed traffic.
CrowdStrike's container runtime technically works, but deployment, maintenance, and usefulness do not compare to other tools at the time of testing. CrowdStrike's Windows offerings remain dominant in the space, but their CNAPP and container security solutions are difficult to recommend.
Sysdig created the first runtime cloud protection tool with the open source project Falco, and has since built a trusted, enterprise ready, runtime oriented CNAPP platform. The tool is strongest at runtime protection, but offers the standard suite of CNAPP features, and is especially a good choice for regulated industries.
Argos offers a simple platform built for MSSP's to run cloud security tests on custom environments. They provide a combination of CSPM and Asset Mapping technologies to provide exactly the information a provider needs to generate a point in time report.
Acquired by Cloudflare. Kivera is not strictly speaking a CSPM, but provides granular controls over what cloud API calls are permissible within your environment. This allows instant enforcement of custom rules and policies, giving the same outcomes as CSPMs without the alert explosion. The downside of using them as a sole CSPM would be missing out on more holistic CNAPP features and visibility, but they run well alongside other providers.
Deepfence is a great no-frills CNAPP with a ton of optionality. Their Open Source ThreatMapper scans for malware, vulnerabilities, misconfigurations, and secrets. Their paid offering, ThreatStryker, adds eBPF runtime protection - including network and quarantine responses. Their open source is an unbelievable value for a free offering.
Plerion has built a competitive CNAPP offering for smaller teams who don't need all of the features, primarily on the posture side. Alongside CSPM, they provide attack maps, IaC scanning, Secret scanning, and vulnerability scanning. They link findings to assets in a clean and intuitive way. Currently there is no agent based runtime protection.
Uptycs biggest strength is its biggest weakness - it undoubtedly has the most features of any CNAPP platform, from ASPM to container runtime. However, that creates a corresponding UI bloat that's as bad as it gets for these platforms. As a certified Kubernetes enjoyer though, their cluster visibility with Kubequery is quite good.
Secberus creates a data lake of your cloud configuration similar to CloudQuery and then allows you to easily save and enforce custom policies against that infrastructure.
Blast provides preventative security controls to protect cloud environments based helping organizations deploy and manage different guardrails like SCP and IaC.
Rad has deep roots in contributing to kubernetes security developments and provides dedicated services to help customers secure their cloud environments. They have in depth policy, audit log, RBAC, and runtime capabilities protection capabilities, now augmented with an AI first approach to accessing and using the data.
Kloudle provides a simple credit based scanner that's a good alternative for companies looking for quick and easy on demand scan, they're also differentiated by supporting Digital Ocean.
ScoutSuite is another useful tool to run a quick scan of your cloud environment to check for any issues.
Elastio offers rich snapshot scanning for cloud environments, looking in depth for ransomware indicators of compromise. Their focus on ransomware and support for S3 scanning differentiate them from Wiz and other snapshot scanning solutions.
Lacework built on top of an alert based approach rather than more traditional scanning models. That has the benefit of reduced noise and a faster reactive approach, but at the cost of surfacing a lot of alerts to security that they don't have the ability to fix.
Defender for Cloud has a lot of comparative features to dedicated CNAPPs, but it's a beast to setup and maintain. It's a good starting point for larger companies who don't have an appetite for a more focused solution, and are addicted to collecting the highest E license as possible.
Security Hub does a decent job aggregating AWS' security tooling reports into a single dashboard. They also offer a lot of integrations into other tools. That being said, they're not a great CSPM solution on their own and their dashboards have limited usefulness.
CheckRed has created a CSPM with vulnerability scanning for containers. They are focused on an offering for MSSPs as a value add, but have a differentiator with some smart SaaS configuration rules as part of the platform.
Firemon has assembled a unique collection of cloud security features - CSPM, JIT AWS access, and alerting off cloudtrail events. While they don't have the full feature set of larger CNAPPs, they provide smart features at an aggressive price. They offer CSPM scanning for free.