Skip to content
aicoolies logo
Kubescape logo

Kubescape

Open-source Kubernetes security platform for risk analysis and compliance

Kubescape is a CNCF-backed open-source Kubernetes security platform that scans clusters, manifests, and container images for vulnerabilities, misconfigurations, and compliance violations. It checks against NSA-CISA, MITRE ATT&CK, and CIS benchmarks, integrates into CI/CD pipelines, and provides runtime threat detection via eBPF. Supports SBOM generation and vulnerability scanning. Used by ARMO with growing enterprise adoption in cloud-native security.

About Kubescape

Kubescape provides comprehensive Kubernetes security coverage across the entire development lifecycle. In CI/CD, it scans Helm charts, Kubernetes manifests, and Dockerfiles against security frameworks including NSA-CISA hardening guidelines, MITRE ATT&CK for containers, and CIS Kubernetes Benchmarks. Each finding includes severity scoring and actionable remediation steps, enabling teams to catch misconfigurations before they reach production.

At runtime, Kubescape uses eBPF-based monitoring to detect anomalous behavior in running workloads — unexpected network connections, file system modifications, process executions, and privilege escalation attempts. The integrated vulnerability scanner assesses container images against known CVE databases and generates Software Bill of Materials (SBOM) for supply chain compliance. Results aggregate into a risk score per workload, namespace, and cluster.

Kubescape is Apache 2.0 licensed and maintained within the CNCF ecosystem alongside projects like Falco and OPA. It integrates with Prometheus for metrics, Slack for alerts, and popular CI systems including GitHub Actions, GitLab CI, and Jenkins. For teams needing a managed experience, ARMO Platform provides a SaaS dashboard with historical trends and multi-cluster visibility. The CLI can be installed via Homebrew, curl, or Krew kubectl plugin.

Pricing & Platform Specs

Pricing Summary

Kubescape is 100% free and open source under the Apache-2.0 license as a CNCF project, offering unlimited self-hosted scans across unlimited clusters and nodes via CLI and Helm. The commercial ARMO Platform SaaS provides a Free tier ($0/mo for up to 3 clusters and 10 nodes) with web dashboards and compliance tracking. Paid Pro/Team plans (starting around $10-$15/node/mo) add eBPF runtime anomaly detection, automated remediation PRs, and Jira/Slack integrations. Enterprise custom plans offer on-premise/private cloud deployments, SAML SSO, custom compliance frameworks, and 24/7 dedicated SLAs.

full pricing breakdown →

Supported Platforms

CLI, CI/CD plugins, Kubernetes operator, ARMO SaaS

Explore categories, tags & use cases

Automated AI security testing and red teaming platform

Mindgard is an automated AI security testing platform that provides continuous red teaming for machine learning models and LLM applications. It detects vulnerabilities including adversarial attacks, prompt injection, data poisoning, and model extraction through systematic probing. Offers end-to-end testing across the AI lifecycle with enterprise compliance reporting and integration into CI/CD pipelines.

paid

Run local code inside your Kubernetes cluster without deploying

mirrord lets developers run local processes as if they were inside their Kubernetes cluster — intercepting network traffic, environment variables, and file access at the OS level without any deployment or configuration changes. Backed by $12.5M in seed funding with investors including Sentry's co-founder, it claims up to 98% faster iteration cycles and 30% fewer production bugs by eliminating the gap between local and cluster environments.

freemiumOpen Source

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is Kubescape?

Kubescape is a CNCF-backed open-source Kubernetes security platform that scans clusters, manifests, and container images for vulnerabilities, misconfigurations, and compliance violations. It checks against NSA-CISA, MITRE ATT&CK, and CIS benchmarks, integrates into CI/CD pipelines, and provides runtime threat detection via eBPF. Supports SBOM generation and vulnerability scanning. Used by ARMO with growing enterprise adoption in cloud-native security.

Is Kubescape free?

Kubescape offers a free tier alongside paid plans. Kubescape is 100% free and open source under the Apache-2.0 license as a CNCF project, offering unlimited self-hosted scans across unlimited clusters and nodes via CLI and Helm. The commercial ARMO Platform SaaS provides a Free tier ($0/mo for up to 3 clusters and 10 nodes) with web dashboards and compliance tracking. Paid Pro/Team plans (starting around $10-$15/node/mo) add eBPF runtime anomaly detection, automated remediation PRs, and Jira/Slack integrations. Enterprise custom plans offer on-premise/private cloud deployments, SAML SSO, custom compliance frameworks, and 24/7 dedicated SLAs.

Is Kubescape open source?

Yes — Kubescape is open source.

Is Kubescape still maintained?

Yes — Kubescape is active. Its listing was last verified on September 6, 2026.

What are the best Kubescape alternatives?

The first editor-selected Kubescape alternatives are Mindgard, mirrord.

How does Kubescape score in our review?

The published editorial review lists Kubescape at 81/100 overall across speed, privacy, and developer experience. Check the review's evidence status and test metadata for its verification level.