Kubescape logo
Security Open Source

Kubescape

by ARMO

Starting at

Free (open source)

Open-source CNCF Kubernetes security platform covering IDE, CI/CD, and cluster scanning for vulnerabilities, misconfigurations, and runtime threat...

Last verified: June 2026

Kubescape: Open-Source Kubernetes Security Platform

Kubescape is a CNCF Incubating open-source project that provides comprehensive Kubernetes security scanning across the entire development and deployment lifecycle — from IDE to CI/CD pipeline to live cluster.

End-to-End Kubernetes Security

Kubescape scans Kubernetes manifests, Helm charts, and running clusters for vulnerabilities, misconfigurations, and compliance violations. It maps findings to industry frameworks including NSA-CISA Kubernetes Hardening Guidelines, MITRE ATT&CK, and CIS Benchmarks, giving security teams actionable, context-rich results.

Key Features

  • Multi-stage scanning: IDE plugin, CI/CD integration, and live cluster scanning
  • Compliance frameworks: NSA-CISA, MITRE ATT&CK, CIS Kubernetes Benchmark
  • Runtime threat detection: eBPF-based runtime security with Kubescape 3.0+
  • Vulnerability scanning: Container image CVE detection with EPSS scoring
  • RBAC analysis: Identifies overly permissive Kubernetes role bindings
  • AI integration: KAgent plugin for AI assistants to query security posture
  • ARMO Platform: Commercial SaaS dashboard for team collaboration

Who Uses Kubescape?

Kubescape is used by DevSecOps teams and security engineers who need open-source Kubernetes security scanning without vendor lock-in. The ARMO Platform adds team management, historical trending, and enterprise features on top of the open-source core.

Pricing

Kubescape is free and open source. ARMO Platform has a free tier and paid plans for teams.

Pros

  • + Free and open source (CNCF Incubating)
  • + Covers full K8s security lifecycle
  • + NSA-CISA and MITRE ATT&CK compliance
  • + Runtime threat detection via eBPF
  • + IDE and CI/CD integration

Cons

  • - Kubernetes-only
  • - Commercial features require ARMO platform
  • - Steep learning curve for compliance frameworks

What Users Actually Complain About

Kubernetes-only. Security findings can be numerous and require prioritization — initial scan of a cluster often produces many findings.

Skip it if:

You don't run Kubernetes — Kubescape is specifically a Kubernetes security posture tool.

Based on community feedback from Reddit, HN, and G2 reviews.

Frequently Asked Questions

What is Kubescape?

Open-source CNCF Kubernetes security platform covering IDE, CI/CD, and cluster scanning for vulnerabilities, misconfigurations, and runtime threat...

How much does Kubescape cost?

Kubescape uses a open source pricing model with plans starting at Free (open source).

What are the main advantages of Kubescape?

The key advantages of Kubescape include: Free and open source (CNCF Incubating); Covers full K8s security lifecycle; NSA-CISA and MITRE ATT&CK compliance; Runtime threat detection via eBPF; IDE and CI/CD integration.

What are the drawbacks of Kubescape?

Some limitations to consider: Kubernetes-only; Commercial features require ARMO platform; Steep learning curve for compliance frameworks.

What category does Kubescape belong to?

Kubescape is a Security tool developed by ARMO.

Security Guides

Try Kubescape

Starting at Free (open source)

Other Security Tools

View all 45 tools →