Kubescape
by ARMO
Open-source CNCF Kubernetes security platform covering IDE, CI/CD, and cluster scanning for vulnerabilities, misconfigurations, and runtime threat...
Last verified: June 2026
Kubescape: Open-Source Kubernetes Security Platform
Kubescape is a CNCF Incubating open-source project that provides comprehensive Kubernetes security scanning across the entire development and deployment lifecycle — from IDE to CI/CD pipeline to live cluster.
End-to-End Kubernetes Security
Kubescape scans Kubernetes manifests, Helm charts, and running clusters for vulnerabilities, misconfigurations, and compliance violations. It maps findings to industry frameworks including NSA-CISA Kubernetes Hardening Guidelines, MITRE ATT&CK, and CIS Benchmarks, giving security teams actionable, context-rich results.
Key Features
- Multi-stage scanning: IDE plugin, CI/CD integration, and live cluster scanning
- Compliance frameworks: NSA-CISA, MITRE ATT&CK, CIS Kubernetes Benchmark
- Runtime threat detection: eBPF-based runtime security with Kubescape 3.0+
- Vulnerability scanning: Container image CVE detection with EPSS scoring
- RBAC analysis: Identifies overly permissive Kubernetes role bindings
- AI integration: KAgent plugin for AI assistants to query security posture
- ARMO Platform: Commercial SaaS dashboard for team collaboration
Who Uses Kubescape?
Kubescape is used by DevSecOps teams and security engineers who need open-source Kubernetes security scanning without vendor lock-in. The ARMO Platform adds team management, historical trending, and enterprise features on top of the open-source core.
Pricing
Kubescape is free and open source. ARMO Platform has a free tier and paid plans for teams.
Pros
- + Free and open source (CNCF Incubating)
- + Covers full K8s security lifecycle
- + NSA-CISA and MITRE ATT&CK compliance
- + Runtime threat detection via eBPF
- + IDE and CI/CD integration
Cons
- - Kubernetes-only
- - Commercial features require ARMO platform
- - Steep learning curve for compliance frameworks
What Users Actually Complain About
Kubernetes-only. Security findings can be numerous and require prioritization — initial scan of a cluster often produces many findings.
Skip it if:
You don't run Kubernetes — Kubescape is specifically a Kubernetes security posture tool.
Based on community feedback from Reddit, HN, and G2 reviews.
Frequently Asked Questions
What is Kubescape?
Open-source CNCF Kubernetes security platform covering IDE, CI/CD, and cluster scanning for vulnerabilities, misconfigurations, and runtime threat...
How much does Kubescape cost?
Kubescape uses a open source pricing model with plans starting at Free (open source).
What are the main advantages of Kubescape?
The key advantages of Kubescape include: Free and open source (CNCF Incubating); Covers full K8s security lifecycle; NSA-CISA and MITRE ATT&CK compliance; Runtime threat detection via eBPF; IDE and CI/CD integration.
What are the drawbacks of Kubescape?
Some limitations to consider: Kubernetes-only; Commercial features require ARMO platform; Steep learning curve for compliance frameworks.
What category does Kubescape belong to?
Kubescape is a Security tool developed by ARMO.
Security Guides
Best DevSecOps Security Tools 2026
Best ToolsCompare the best DevSecOps security tools for 2026. Expert analysis of AI-powered platforms like Snyk, Wiz, Aqua Security & more to secure your CI/CD pipeline.
How to Choose a Security Scanning Tool
How to ChooseComplete guide to choosing security scanning tools for DevOps teams. Compare SAST, DAST, SCA tools and find the perfect fit for your security needs.
Snyk Review 2026: Features, Pricing & Is It the Best DevSecOps Tool?
How to ChooseIn-depth Snyk review for 2026 — what it does, how pricing works, free tier vs paid, and whether it's the right developer security platform for your team.
Best Snyk Alternatives in 2026: Free & Paid Developer Security Tools
Best ToolsThe best alternatives to Snyk in 2026 — Semgrep, Socket.dev, Aikido Security, Jit.io, and SonarQube compared on features, pricing, and use case fit.
Other Security Tools
View all 45 tools →Aikido Security
Aikido Security
Aikido Security is a comprehensive DevSecOps platform that provides real-time security monitoring, vulnerability management, and threat detection for...
Allstar by OpenSSF
Open Source Security Foundation (OpenSSF)
Allstar is a GitHub App that continuously monitors GitHub organizations and repositories for adherence to security best practices and policies.
Apiiro
Apiiro
Application Security Posture Management (ASPM) platform using a risk graph to prioritize code-level security risks based on developer behavior and asset...
Aqua Security AI
Aqua Security
AI-powered cloud native security platform for containers and serverless