ARMO Updates Kubescape
October 13, 2021

ARMO announced the release of a new, expanded version of its Kubescape tool.

Kubescape is the world’s first open-source testing tool for Kubernetes environments that is compliant with the standards set forth in the Kubernetes Hardening Guidance released by the NSA and CISA.

Kubescape is one of the fastest-growing Kubernetes security tools among developers due to its easy-to-use CLI interface and flexible output formats. Just weeks after launching, Kubescape has become an immensely popular tool in the Kubernetes community, with more than 4000 stars and tens of thousands of downloads on Github, and thousands of active developers embracing the solution. Kubescape scans K8s clusters, YAML files, and HELM charts, providing hyper accurate results and enabling the detection of misconfigurations and software vulnerabilities at early stages of the CI/CD pipeline. It also integrates natively with other DevOps tools, including Jenkins, CircleCI and Github workflows.

The expanded version of Kubescape has been updated with new Kubernetes configuration scanning, based on the MITRE ATT&CK® framework. Kubescape is an open- source Kubernetes product to leverage the MITRE framework for testing. Teams can test Kubernetes against multiple frameworks in one single tool.

The new registration-based SaaS Kubescape solution, which is free to use, offers additional benefits including:

- User-friendly UI for streamlined scans and test management, providing teams the ability to choose which framework to use according to their organization’s structure and specific vulnerabilities.

- An instantly calculated risk score based on the current scan, giving stakeholders the ability to make quick, smart decisions based on their organization’s real-time standing.

- Easy access to a history of past scans for quick review of total risk scores trends from one scan to the next. Stakeholders can track their organization’s progress with hyper-accuracy, determine whether their risk has changed for better or worse over time, and manage configuration drifts.

- Exceptions management, allowing Kubernetes admins to mark acceptable risk levels within specific resources and select which tests to perform in order to avoid alert fatigue. Users no longer have to contend with multiple alerts on failed tests which internal stakeholders have determined to be of low priority to the organization.

- Build and create customized compliance frameworks, empowering stakeholders with the ability to test according to their organization’s unique requirements. Users can test organization’s Kubernetes environments using their custom framework, ensuring that all workloads deployed within an organization's networks are compliant with the same standard.

“Developers look at security as a design and architectural problem that needs to be managed from the earliest stages of the development pipeline. Kubescape’s seamless integration with Kubernetes’ tech stack and practical, simple output make it a high-value, go-to solution that’s extremely appealing to developers,” said Shauli Rozen, CEO and Co-Founder of ARMO. “... Kubescape is resonating with developers all over the globe, and our vision is to build on that momentum to continue solidifying Kubescape as the tool of choice for Kubernetes users, as an integral part of their daily routines and organization-wide security strategies.”

“Kubescape detects highly dangerous security weaknesses before they reach production, and our updated version provides an even deeper level of visibility and protection for Kubernetes users,” said Leonid Sandler, CTO and Co-Founder of Armo. “With the new expanded version of Kubescape, they can continuously examine their security controls and deployments to ensure the highest level of protection possible for their companies...”

Share this

Industry News

May 19, 2022

Jellyfish announced the launch of Jellyfish Benchmarks, a way to add context around engineering metrics and performance by introducing a method for comparison.

May 19, 2022

Solo.io announced the addition and integration of Cilium networking into its Gloo Mesh platform, providing a complete application-networking solution for companies’ cloud-native digital transformation efforts.

May 19, 2022

Aqua Security announced multiple updates to Aqua Trivy, making it a unified scanner for cloud native security.

May 18, 2022

Red Hat unveiled updates across its portfolio of developer tools designed to help organizations build and deliver applications faster and more consistently across Kubernetes-based hybrid and multicloud environments.

May 18, 2022

Armory announced public early access to their new Continuous Deployment-as-a-Service product.

May 18, 2022

DataCore Software announced DataCore Bolt, enterprise-grade container-native storage software for DevOps.

May 17, 2022

DevOps Institute, a global professional association for advancing the human elements of DevOps, announced the release of the Upskilling IT 2022 report.

May 17, 2022

Replicated announced a host of new platform features and capabilities that enable their customers to accelerate enterprise adoption of their Kubernetes applications.

May 17, 2022

Codefresh announced that its flagship continuous delivery (CD) platform will be made accessible as a fully-hosted solution for DevOps teams seeking to quickly and easily achieve frictionless, GitOps-based continuous software delivery in the cloud.

May 16, 2022

Red Hat announced new capabilities and enhancements across its portfolio of open hybrid cloud solutions aimed at accelerating enterprise adoption of edge compute architectures through the Red Hat Edge initiative.

May 16, 2022

D2iQ announced a partnership with GitLab.

May 16, 2022

Kasten by Veeam announced the new Kasten by Veeam K10 V5.0 Kubernetes data management platform.

May 12, 2022

Red Hat introduced Red Hat Enterprise Linux 9, the Linux operating system designed to drive more consistent innovation across the open hybrid cloud, from bare metal servers to cloud providers and the farthest edge of enterprise networks.

May 12, 2022

Couchbase announced version 7.1 of Couchbase Server.

May 12, 2022

Copado added Copado Robotic Testing to Copado Essentials.