Pre-Commit IaC Scanning

Compare 46 pre-commit iac scanning tools to find the right one for your needs

πŸ”§ Tools

Compare and find the best pre-commit iac scanning for your needs

Kubescape

An open-source Kubernetes security platform.

An open-source Kubernetes security posture management tool that scans YAML files, Helm charts, and live clusters.

View tool details β†’

Open Policy Agent (OPA)

Policy-based control for cloud native environments.

An open-source, general-purpose policy engine that can be used for scanning IaC.

View tool details β†’

GitGuardian

The code security platform for the DevOps generation.

A platform for automated secrets detection and remediation.

View tool details β†’

tfsec

Security scanner for your Terraform code.

A fast, open-source static analysis scanner for Terraform code to find security misconfigurations.

View tool details β†’

Trivy

A comprehensive and versatile security scanner.

Versatile open-source security scanner from Aqua Security that finds vulnerabilities, IaC misconfigurations, and secrets.

View tool details β†’

Checkov

Policy-as-code for everyone. Scan cloud infrastructure configurations to find misconfigurations before they're deployed.

Open-source IaC scanner that finds misconfigurations in Terraform, CloudFormation, Kubernetes, and more.

View tool details β†’

Prisma Cloud

The Code-to-Cloudβ„’ platform that secures apps from design to runtime.

A comprehensive Cloud Native Application Protection Platform (CNAPP).

View tool details β†’

Terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Open-source static code analyzer for IaC that helps detect security issues and compliance violations.

View tool details β†’

KICS

Keeping Infrastructure as Code Secure.

Open-source IaC scanner from Checkmarx that supports a wide range of platforms and offers extensive queries.

View tool details β†’

TFLint

A Pluggable Terraform Linter.

A linter for Terraform that focuses on best practices, style conventions, and detecting potential errors.

View tool details β†’

Steampipe

Query your cloud, APIs, and more with SQL.

Open-source tool that maps cloud APIs to PostgreSQL tables, enabling SQL-based querying for security and compliance.

View tool details β†’

CloudQuery

The open-source cloud asset inventory powered by SQL.

An open-source tool for building a cloud asset inventory that can be used for policy-as-code checks.

View tool details β†’

Cloudanix

Code to Cloud Security Platform.

A unified platform for code, cloud, identity, and workload security.

View tool details β†’

ggshield

Find and fix secrets in your source code.

A CLI tool for secrets detection that also includes IaC scanning capabilities to find misconfigurations.

View tool details β†’

oak9

Security as Code for Cloud Native.

Dynamically secure Infrastructure as Code (IaC) and deployed cloud-native workloads.

View tool details β†’

Orca Security

The Agentless Cloud Security Platform.

A comprehensive, agentless CNAPP that provides shift-left security, including pre-commit IaC scanning.

View tool details β†’

Wiz

The Cloud Security Platform.

A comprehensive CNAPP that includes IaC scanning as part of its full lifecycle cloud security solution.

View tool details β†’

CrowdStrike Falcon Cloud Security

Stop cloud breaches.

A CNAPP from a leader in endpoint security, offering both agentless and agent-based protection, including IaC scanning.

View tool details β†’

Snyk IaC

Developer-first infrastructure as code security.

A developer-focused IaC security tool that scans for misconfigurations and provides context and remediation advice.

View tool details β†’

Lacework

The data-driven cloud security platform.

A CNAPP that uses a Polygraph Data Platform to automate cloud security, including IaC security.

View tool details β†’

Sysdig Secure

Cloud security powered by runtime insights.

A CNAPP that uses deep runtime insights from Falco to secure the entire cloud-native lifecycle, including IaC scanning.

View tool details β†’

Datadog Cloud Security Management

Detect threats in real time. Investigate security alerts. Secure your production environment.

A security and observability platform that includes IaC scanning as part of its cloud security offering.

View tool details β†’

Datadog Cloud Security

Unified security and observability.

A cloud security platform that includes IaC scanning, CSPM, and CWPP, leveraging observability data for context.

View tool details β†’

Rapid7 InsightCloudSec

Unified Cloud Native Security.

Comprehensive cloud security posture management (CSPM) and workload protection (CWPP).

View tool details β†’

Prisma Cloud (by Palo Alto Networks)

The industry’s most complete Cloud-Native Application Protection Platform (CNAPP).

A comprehensive CNAPP that includes IaC scanning, CSPM, CWPP, and more, building on the open-source Checkov engine.

View tool details β†’

GitLab IaC Scanning

Scan your Infrastructure as Code (IaC) configuration files for known vulnerabilities.

A built-in security scanning feature within the GitLab CI/CD platform for analyzing IaC files.

View tool details β†’

Zscaler Posture Control

Secure your cloud with a unified, 100% agentless platform.

A CNAPP that integrates CSPM, CIEM, and IaC scanning to provide a unified view of cloud risk.

View tool details β†’

Microsoft Defender for Cloud

Protect multi-cloud and hybrid environments with Microsoft Defender for Cloud.

A comprehensive CNAPP and CSPM solution that provides security for Azure, AWS, and GCP, including IaC scanning.

View tool details β†’

Veracode IaC Security

Secure your cloud-native applications with a unified platform.

An IaC scanning solution integrated into Veracode's comprehensive application security platform.

View tool details β†’

HashiCorp Sentinel

Policy as Code for Security, Compliance, and Operational Governance.

An embedded policy-as-code framework within the HashiCorp Enterprise platform, used to enforce policies on Terraform runs.

View tool details β†’

SpectralOps

Automated code security for developers.

A security tool that scans code, configuration, and IaC for hardcoded secrets and misconfigurations.

View tool details β†’

Checkmarx IaC Security

Secure your infrastructure and applications from code to cloud.

The enterprise offering built upon the open-source KICS engine, integrated into the Checkmarx One platform.

View tool details β†’

Tenable.cs

Secure the entire cloud-native stack.

A CNAPP from Tenable that provides security from code to cloud, built on the open-source Terrascan engine.

View tool details β†’

Bridgecrew

The #1 developer-first cloud security platform.

Automate cloud security from code to cloud.

View tool details β†’

Qualys Cloud Platform

The only end-to-end solution for all aspects of cybersecurity.

A comprehensive security and compliance platform that includes IaC scanning as part of its cloud security module.

View tool details β†’

Prowler

The most comprehensive, free tool for AWS security.

An open-source tool for AWS security assessment, auditing, hardening, and incident response, with some IaC capabilities.

View tool details β†’

CloudSploit

Cloud security posture assessment.

An open-source tool for scanning cloud accounts for security risks and misconfigurations.

View tool details β†’

cfn-lint

Validate CloudFormation templates against the AWS CloudFormation Resource Specification.

An AWS-maintained linter for CloudFormation templates that checks for errors and best practices.

View tool details β†’

Regula

A tool that evaluates infrastructure as code for security misconfigurations and compliance violations.

An open-source tool that checks Terraform, CloudFormation, and Kubernetes configs for misconfigurations using Rego.

View tool details β†’

pre-commit-terraform

A collection of pre-commit hooks for Terraform.

A framework and collection of git hooks for automating checks on Terraform code before commit.

View tool details β†’

cfn-nag

A linter for AWS CloudFormation templates.

An open-source tool that scans CloudFormation templates for patterns that may indicate insecure infrastructure.

View tool details β†’

Yor

Automated IaC tagging and tracing.

An open-source tool that automatically adds tags to IaC files, linking them to code owners and repositories.

View tool details β†’

Terratest

A Go library that makes it easier to write automated tests for your infrastructure code.

A Go library for writing automated tests for IaC, including security and compliance tests.

View tool details β†’

Driftctl

Detect, track and alert on infrastructure drift.

An open-source tool to detect differences between your IaC state and your live cloud environment (drift).

View tool details β†’

Check-jsonschema

A CLI for checking JSON and YAML files against a JSON Schema.

A general-purpose CLI tool for validating JSON/YAML files against a schema, useful for custom IaC validation.

View tool details β†’

KubeLinter

A static analysis tool for Kubernetes YAML files and Helm charts.

A static analysis tool from StackRox/Red Hat that checks Kubernetes YAML files for security and best practices.

View tool details β†’