awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
checkmarx avatar

checkmarx/kics

0
View on GitHub↗
2,649 stars·374 forks·Open Policy Agent·Apache-2.0·16 viewskics.io↗

Kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Features

  • IaC Security - Security testing for infrastructure-as-code.
  • Infrastructure as Code Analysis - Detects security and compliance issues in infrastructure code.
  • Workflow Automation - Scan IaC for security and compliance issues.
  • Workflow Utilities - Security and compliance scanner for IaC.
  • Defending - Listed in the “Defending” section of the Awesome K8s Security awesome list.
  • Application Security - Finds security and compliance issues in infrastructure-as-code.
  • Application Security Testing - Scans infrastructure as code for vulnerabilities and compliance issues.
  • Infrastructure Security - Finds vulnerabilities and misconfigurations in infrastructure-as-code.
  • Security And Hardening - Infrastructure-as-code scanning for security vulnerabilities.

Star history

Star history chart for checkmarx/kicsStar history chart for checkmarx/kics

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Kics

These projects share indexed features with Kics. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • bridgecrewio/checkovbridgecrewio avatar

    bridgecrewio/checkov

    8,798View on GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Python
    View on GitHub↗8,798
  • fugue/regulafugue avatar

    fugue/regula

    964View on GitHub↗

    Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes security and compliance using Open Policy Agent/Rego

    Open Policy Agent
    View on GitHub↗964
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    View on GitHub↗36,462
  • bridgecrewio/yorbridgecrewio avatar

    bridgecrewio/yor

    927View on GitHub↗

    Extensible auto-tagger for your IaC files. The ultimate way to link entities in the cloud back to the codified resource which created it.

    Go
    View on GitHub↗927
Compare all 30 related projects→

Frequently asked questions

What does checkmarx/kics do?

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

What are the main features of checkmarx/kics?

The main features of checkmarx/kics are: IaC Security, Infrastructure as Code Analysis, Workflow Automation, Workflow Utilities, Defending, Application Security, Application Security Testing, Infrastructure Security.

Which projects share features with checkmarx/kics?

Projects with overlapping indexed features include: bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… fugue/regula — Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… deepfence/threatmapper — ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a… bridgecrewio/yor — Extensible auto-tagger for your IaC files. The ultimate way to link entities in the cloud back to the codified… snyk/cli — The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies,…