About Kubescape
Kubescape is an open-source Kubernetes security platform that covers the lifecycle from development to runtime. It was created by ARMO and is a Cloud Native Computing Foundation incubating project. It works in an IDE, in CI/CD pipelines and against running clusters, with the aim of saving administrators time on risk analysis and compliance work.
Misconfiguration scanning checks clusters, YAML files and Helm charts against NSA-CISA guidance, MITRE ATT&CK and CIS Benchmarks. Image vulnerability scanning detects CVEs using Grype, image patching uses Copacetic, and auto-remediation can fix manifest issues. Admission control uses Validating Admission Policies, runtime monitoring is eBPF-based through Inspektor Gadget, and an MCP server connects AI assistants.
Kubescape is written in Go and released under the Apache-2.0 license. It installs through options such as Homebrew and Krew, and an in-cluster operator is available for continuous scanning. Results include an overview of control plane status, access control risks, workload misconfigurations, network policy gaps and compliance scores.
Key features
- Misconfiguration scanning against NSA-CISA, MITRE, CIS
- Image vulnerability scanning with Grype
- Automatic image patching with Copacetic
- Auto-remediation for Kubernetes manifests
- eBPF-based runtime security monitoring
- In-cluster operator and MCP server
Good fit for
- →Scanning Helm charts in CI pipelines
- →Tracking Kubernetes compliance scores
- Tags
- kubernetes
- security
- compliance
- devsecops
- ebpf
- cncf
- vulnerability-scanning
- go
Kubescape: questions and answers
- What is Kubescape used for?
- Kubescape is an open-source Kubernetes security platform covering misconfiguration scanning, image vulnerabilities, compliance checks and runtime monitoring. It is a good fit for scanning Helm charts in CI pipelines and tracking Kubernetes compliance scores.
- Is Kubescape open source?
- Yes. Kubescape is open source under the Apache-2.0 licence. Its source code is on GitHub at kubescape/kubescape and is written mainly in Go.
- Is Kubescape free?
- Yes. Kubescape is open source, so the software itself is free to use.
- What is Kubescape an alternative to?
- Kubescape is an open-source alternative to Wiz, Palo Alto Networks, Aikido Security and Orca Security. Other open-source alternatives to Wiz include Trivy, Falco and Grype.
- Is Kubescape actively maintained?
- Yes. The most recent commit to Kubescape was on 2 October 2026, and the latest release is v4.0.15, published on 29 September 2026. The project has 12k stars on GitHub.
Open-source alternatives to Kubescape
See all
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Falco
Security
Cloud Native Runtime Security
Apache-2.0vs Wiz★ 9.4k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
tfsec
Security
Tfsec is now part of Trivy
MITvs Aikido Security★ 7k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Gitleaks
Security
Find secrets with Gitleaks 🔑
MITvs GitGuardian★ 30k
SaaS alternatives to Kubescape
See allWiz
Security
Agentless cloud security platform mapping risk across code, cloud and runtime
SaaS
Palo Alto Networks
Security
Network, cloud and endpoint security vendor selling firewalls, SASE and SOC tools
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Orca Security
Security
Agentless cloud security platform for workloads and configurations
SaaS
Aqua Security
Security
Cloud native security platform for containers, Kubernetes and serverless
SaaS
Sysdig
Security
Cloud and container security platform with runtime threat detection
SaaS

