awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Kubernetes Cluster Security Scanners

Ranking updated Jun 30, 2026

For a security scanner for Kubernetes clusters, the strongest matches are bridgecrewio/checkov (Checkov is a static analysis tool that scans Kubernetes), aquasecurity/trivy (Trivy is a comprehensive security scanner that directly targets) and armosec/kubescape (Kubescape is a comprehensive Kubernetes security platform that scans). deepfence/threatmapper and kubescape/kubescape round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Automated tools that identify vulnerabilities, misconfigurations, and security policy violations within your Kubernetes cluster environments.

Kubernetes Cluster Security Scanners

Find the best repos with AI.We'll search the best matching repositories with AI.
  • bridgecrewio/checkovbridgecrewio avatar

    bridgecrewio/checkov

    8,798View on GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Checkov is a static analysis tool that scans Kubernetes manifests, container images, and infrastructure as code for misconfigurations, vulnerabilities, and secrets, covering CIS benchmarks, compliance reporting, and policy enforcement — a comprehensive fit for Kubernetes security scanning.

    PythonSecret DetectionSecrets ScanningSensitive Data Scanners
    View on GitHub↗8,798
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy is a comprehensive security scanner that directly targets Kubernetes clusters for vulnerabilities, misconfigurations, and CIS benchmark compliance, covering the major requested features like container image scanning, RBAC analysis, and policy reporting.

    GoContainer Security Scanners
    View on GitHub↗36,462
  • armosec/kubescapearmosec avatar

    armosec/kubescape

    11,482View on GitHub↗

    Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of

    Kubescape is a comprehensive Kubernetes security platform that scans clusters, configurations, and container images for CIS benchmarks, vulnerabilities, and compliance violations, with additional coverage of network policies and RBAC through its security assessments and audit utilities.

    GoVulnerability Scanning
    View on GitHub↗11,482
  • deepfence/threatmapperdeepfence avatar

    deepfence/ThreatMapper

    5,282View on GitHub↗

    ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

    ThreatMapper is a full-featured cloud-native application protection platform that scans Kubernetes clusters for vulnerabilities, misconfigurations, and compliance issues, covering the required capabilities like container image scanning, CIS compliance, and network traffic analysis.

    TypeScriptSecret Scanning
    View on GitHub↗5,282
  • kubescape/kubescapekubescape avatar

    kubescape/kubescape

    11,489View on GitHub↗

    Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo

    Kubescape is a full-featured Kubernetes security posture management platform that directly addresses the request: it scans clusters, manifests, and container images for misconfigurations, vulnerabilities, and compliance risks (including CIS benchmarks), and performs RBAC analysis, network policy evaluation, and secrets detection — making it an excellent match for a cluster security scanner.

    GoCustom Detection Rules
    View on GitHub↗11,489
  • aquasecurity/trivy-operatoraquasecurity avatar

    aquasecurity/trivy-operator

    1,890View on GitHub↗

    Kubernetes-native security toolkit

    Trivy-Operator is a Kubernetes-native operator that automates the Trivy scanner, providing comprehensive vulnerability, misconfiguration, secret, and CIS benchmark compliance scanning for your cluster, directly matching this search.

    GoKubernetes SecurityVulnerability Scanning
    View on GitHub↗1,890
  • aquasecurity/kube-hunteraquasecurity avatar

    aquasecurity/kube-hunter

    5,064View on GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Kube-hunter is a Kubernetes security scanner that identifies vulnerabilities and misconfigurations by simulating attacker techniques, but it lacks explicit CIS benchmark checks, container image scanning, and detailed compliance reporting that your search includes.

    PythonSecret ScanningVulnerability Scanning
    View on GitHub↗5,064
  • aquasecurity/kube-benchaquasecurity avatar

    aquasecurity/kube-bench

    8,078View on GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    kube-bench is a Kubernetes security benchmark scanner that checks CIS compliance and configuration hardening, which directly addresses the misconfiguration and compliance part of your search, but it does not cover container image vulnerabilities, RBAC analysis, network policy evaluation, or secrets detection that you also need.

    GoBenchmark ScanningSecurity ScanningCloud Compliance Auditors
    View on GitHub↗8,078
  • bad-antics/nullsec-k8sscanbad-antics avatar

    bad-antics/nullsec-k8sscan

    1View on GitHub↗

    Kubernetes Security Scanner - Part of NullSec Linux

    This repository is explicitly a Kubernetes security scanner, which directly matches the core category, but the sparse description and lack of topics provide no evidence of the specific features like CIS benchmarks, image scanning, or compliance reporting that the visitor wants.

    PythonKubernetes Security
    View on GitHub↗1
  • cyberark/kubiscancyberark avatar

    cyberark/KubiScan

    1,428View on GitHub↗

    A tool to scan Kubernetes cluster for risky permissions

    Kubiscan scans Kubernetes clusters for risky permissions, making it a legitimate security scanner, but it focuses narrowly on RBAC analysis and lacks the broader vulnerability, CIS benchmark, network policy, and secrets detection capabilities you listed.

    PythonContainer and Cluster SecurityDefendingKubernetes Security
    View on GitHub↗1,428
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
bridgecrewio/checkov8.8KPythonApache-2.0Jun 15, 2026
aquasecurity/trivy36.5KGoApache-2.0Jun 16, 2026
armosec/kubescape11.5KGoApache-2.0Jun 17, 2026
deepfence/threatmapper5.3KTypeScriptApache-2.0Jun 1, 2026
kubescape/kubescape11.5KGoApache-2.0Jun 22, 2026
aquasecurity/trivy-operator1.9KGoApache-2.0Jun 16, 2026
aquasecurity/kube-hunter5.1KPythonApache-2.0Mar 19, 2024
aquasecurity/kube-bench8.1KGoApache-2.0Jun 15, 2026
bad-antics/nullsec-k8sscan1PythonNOASSERTIONFeb 10, 2026
cyberark/kubiscan1.4KPythonGPL-3.0May 25, 2025

Related searches

  • a Kubernetes config auditing tool
  • a container orchestration platform for clusters
  • a command line tool for managing Kubernetes
  • a policy-as-code engine for Kubernetes
  • a tool for finding stale Kubernetes objects
  • a desktop UI for managing Kubernetes clusters
  • a container vulnerability scanner
  • a container hardening tool