Elevate your cloud security beyond Kubescape with ARMO Platform
{in just two clicks}

  • Fully CNCF Sandbox project
  • > 10K Github stars
  • > 100K users

Kubescape is a Kubernetes security and compliance platform that scans Kubernetes clusters, manifests, code repositories, container registries, and images. Utilizing eBPF it sets up threat detection rules for alerting on potential malicious activities.

  • Developed by the creators  of Kubescape.
  • Provides enhanced functionality beyond the open-source version.

Kubescape is a Kubernetes security and compliance platform that scans Kubernetes clusters, manifests, code repositories, container registries, and images. Utilizing eBPF it sets up threat detection rules for alerting on potential malicious activities.

Watch a Demo

The differences between Kubescape and ARMO Platform

Runtime Sensor Capabilities
Technical Support
Data Aggregation with Control & Management Capabilities
User Experience
Non- Kubernetes Capabilities
table_armo
Kubescape
Kubernetes compliance and misconfiguration scanning
armo
armo
Vulnerability scanning
armo
armo
Runtime data analysis - File access
armo
armo
Runtime data analysis - Process Execution, syscalls, Linux capabilities
armo
armo
Runtime data analysis - L4 network
armo
armo
Runtime data analysis - DNS
armo
armo
Runtime data analysis - L7 network
armo
armo
Runtime data analysis - Function level
armo
armo
Network policy creation - k8s native policies 
armo
armo
Network policy creation - Calico and Cilium policies 
armo
armo
Seccomp profile creation
armo
armo
Application profile creation
armo
armo
Fixed detection rules
armo
armo
Anomaly and behavioral detection based rules
armo
armo
Access to ARMO cross customers package profiling and analysis
armo
armo
Network anomaly detection and API Security
armo
armo
Support for adding custom Rules requested by Customer, and self creation of custom detection rules
armo
armo
Threat Response / Prevention / Quarantine - policy and automation
armo
armo
Enterprise Level Testing
armo
armo
Scale assurance SLA
armo
armo
Bug fixes SLA
armo
armo
Roadmap influence & feature prioritization
armo
armo
Enterprise Support
armo
armo
Posture risk acceptance and policy creation
armo
armo
Advanced integrations, Jira, Slack, ServiceNow, SIEM, SOC etc
armo
armo
Integration w. Gitops (PR generation)
armo
armo
Issue prioritization with runtime and kubernetes context
armo
armo
Vulnerability management views - CVE, Image, SBOM, Workload
armo
armo
Image layers CVEs analysis
armo
armo
Prioritization of vulnerabilities based on aggregated external exploitability data (CISA-KEV, EPSS)
armo
armo
RBAC visualizer and investigator
armo
armo
Smart remediation and hardening
armo
armo
Incident aggregation - group alerts into incidents for analysis
armo
armo
Threat Incident exception and risk acceptance management
armo
armo
Editing of Application Baselines in UI
armo
armo
Dashboards and reports - Compliance. Posture and Threat Detection
armo
armo
Graph visualization - Attack Path,Incident Threat Graph and RBAC
armo
armo
Multi cluster management
armo
armo
Automation and workflows
armo
armo
VM based eBPF sensor for non-kubernetes environments (EC2 etc.)
armo
armo
CDR - Detection and response based on cloud logs, and connecting it to eBPF based incidents
armo
armo
CSPM - compliance and posture management for cloud accounts
armo
armo

Frequently Asked Questions

Going beyond Kubescape results saved in CRDs, ARMO Platform aggregates data in a database, making it available for cross data analysis and insights.

Kubescape works via an API with no graphical user interface. All additional analysis and dashboarding must be built outside of Kubescape.
ARMO Platform comes with a graphical user interface, which enables dashboards and graphic visualizations of Attack Paths, Runtime Incidents and RBAC.

ARMO Platform customers are entitled to the ARMO enterprise-grade premium support which is based on strict SLA for performance and bug fixes. Each customer is managed by a technical customer support account manager. They also have influence on the ARMO platform roadmap and have early access to advanced features.

ARMO Platform can be deployed as SaaS, on-premises and even air-gapped. All these options are deployed and secured by ARMO. All of these options are as secure as self-hosting Kubernetes.

Kubescape’s runtime sensor is considered to be one of the most advanced among CNCF security projects and is constantly evolving. It currently provides runtime context for vulnerability and compliance scanning, as well as runtime threat detection related to file access, process execution, and a certain level of networking. Additionally, it automates the generation of Kubernetes-native network policies.

ARMO Platform builds on the capabilities of Kubescape’s runtime sensor by adding L7 network data, application function level data, network anomaly detection, and runtime threat response. It also supports auto-creation of proprietary network policies and seccomp profiles, further lending itself to posture management.

No, While ARMO Platform utilizes Kubescape in its backend, it has moved beyond Kubernetes-native security and provides holistic analysis of security from cloud risks, through host and container risks to API, network and application function level risks including eBPF sensor for non kubernetes workloads (VMs) and cloud infrastructure capabilities such as Cloud Detection (CDR) and CSPM.

slack_logos Continue to Slack

Get the information you need directly from our experts!

new-messageContinue as a guest