Kubernetes Security Security Tools
Compare the best Kubernetes Security tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.
Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.
The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities
Via their oneagent, Dynatrace provides highly competitive ADR capabilities with function level reachability, RASP style blocking, and the ability to query most logs. Their agent also extends into processes and hosts. Their CADR offering has the complete offering from a feature perspective, but the UX struggles to tie it together for security.
AccuKnox began with the open source project KubeArmor and has since built into a larger CNAPP platform. Their specialization is runtime protection policies for Kubernetes, which allows for granular rules on which processes can access which files.
Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.
Cyscale checks all the boxes for a CNAPP, but their tracking of user identities stands out in the space. They have great visualizations, and have an agent for K8s support. A strong entry in the CNAPP market.
Tigera built the Calico network plugin for K8s and has since expanded into a larger cloud security offering focusing primarily on Kubernetes protection and observability. They remain the most robust on network protection, offering deep insights into what's traversing your network.
Aqua Security built a lot of the open source projects that power modern cloud security, and can go feature for feature with most other CNAPP platforms. The downside of the CNAPP has been the UI/UX, and the focus has always been on container protection more than holistic cloud security features.
Cortex Cloud is a security operations platform that integrates cloud and application security capabilities into their larger security operations offerings. This provides a single hub for managing first and third party findings across vulnerabilities and runtime events.
Datadog offers a complete suite a security offerings that are a great fit for developer focused teams not looking for the most mature details in each area. They offer most scanning types, runtime detections, and a full SIEM, and you're probably already sending them your logs. It's a great runtime choice to meet developers where they work, but the UX is built primarily for developers.
ARMO has all of the features of a CNAPP, but with a special emphasis on runtime security and Kubernetes. Their open source Kubescape is a great tool for scanning Kubernetes clusters, and their paid offering provides true CADR runtime protection and compliance features.
Sysdig created the first runtime cloud protection tool with the open source project Falco, and has since built a trusted, enterprise ready, runtime oriented CNAPP platform. The tool is strongest at runtime protection, but offers the standard suite of CNAPP features, and is especially a good choice for regulated industries.
Plerion has built a competitive CNAPP offering for smaller teams who don't need all of the features, primarily on the posture side. Alongside CSPM, they provide attack maps, IaC scanning, Secret scanning, and vulnerability scanning. They link findings to assets in a clean and intuitive way. Currently there is no agent based runtime protection.
Nirmata is a platform built for enforcing policies in your cloud environnment (but mostly Kubernetes). It functions as an admission controller and policy engine, allowing you to enforce checks for all your Kubernetes changes.
Rad has deep roots in contributing to kubernetes security developments and provides dedicated services to help customers secure their cloud environments. They have in depth policy, audit log, RBAC, and runtime capabilities protection capabilities, now augmented with an AI first approach to accessing and using the data.