🗂️ Navigation

KICS by Checkmarx

Keeping Infrastructure as Code Secure

Visit Website →

Overview

KICS (Keeping Infrastructure as Code Secure) is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code. It supports a wide variety of IaC platforms and has a large and growing library of queries.

✨ Key Features

  • Scans Terraform, Kubernetes, Docker, Ansible, and more
  • Over 2000 ready-to-use queries
  • Extensible and customizable with new queries
  • Integration with CI/CD pipelines
  • Multiple output formats (JSON, SARIF, etc.)
  • Open-source and community-supported

🎯 Key Differentiators

  • Large number of built-in queries
  • Broad support for different IaC platforms
  • Extensibility and customization

Unique Value: Offers a comprehensive and extensible open-source solution for securing a wide range of IaC.

🎯 Use Cases (4)

IaC vulnerability scanning Compliance checking Security auditing of infrastructure code Automated security checks in CI/CD

✅ Best For

  • Finding hardcoded secrets in Dockerfiles
  • Ensuring Terraform configurations adhere to security best practices

💡 Check With Vendor

Verify these considerations match your specific requirements:

  • Runtime security analysis
  • Intrusion detection

🏆 Alternatives

Checkov Terrascan Snyk IaC

Its extensive query library covers a wide array of potential security issues out of the box.

💻 Platforms

CLI API

✅ Offline Mode Available

🔌 Integrations

Jenkins GitLab CI GitHub Actions Azure DevOps CircleCI

💰 Pricing

Contact for pricing
Free Tier Available

Free tier: Full open-source version is free.

Visit KICS by Checkmarx Website →