
Kubescape
Kubescape is a free open-source Kubernetes security platform used to scan clusters, manifests, and Helm charts for risky settings for DevOps and security teams.
0 upvotes · 0 downvotes
No ratings yet
- Categories
- Cloud SecurityVulnerability Management
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
What it is
A command-line scanner and in-cluster operator that checks Kubernetes workloads against hardening frameworks and known vulnerabilities, then adds runtime threat detection through a node agent.
What it helps with
- Checking clusters against NSA-CISA, MITRE ATT&CK, and CIS Benchmark controls
- Finding known vulnerabilities in workload images
- Generating Kubernetes network policies
- Scanning manifests in CI pipelines before deployment
Who it's for
DevOps, platform, and security engineers hardening Kubernetes clusters they run.
Worth knowing
It is a Cloud Native Computing Foundation incubating project. Results can also be viewed in a web UI and inside code editors through plugins.
Can I accept a known risk so it stops failing scans?
Yes, findings can be marked as accepted risk.
Does it work with AI assistants?
Yes, it ships an MCP server so assistants can query scan results.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.