Terrascan is a static code analyzer for Infrastructure as Code. Terrascan allows you to:
- Seamlessly scan infrastructure as code for misconfigurations.
- Monitor provisioned cloud infrastructure for configuration changes that introduce posture drift, and enables reverting to a secure posture.
- Detect security vulnerabilities and compliance violations.
- Mitigate risks before provisioning cloud native infrastructure.
- Offers flexibility to run locally or integrate with your CI/CD.
Resources
To learn more about Terrascan's features and capabilities, see the documentation portal: https://runterrascan.io
Join The Terrascan Community on Discord : https://discord.gg/DFwXEfbjzt
Key features
- 500+ Policies for security best practices
- Scanning of Terraform (HCL2)
- Scanning of Kubernetes (JSON/YAML), Helm v3, and Kustomize
- Scanning of Dockerfiles
- Support for AWS, Azure, GCP, Kubernetes, Dockerfile, and GitHub
- Integrates with docker image vulnerability scanning for AWS, Azure, GCP container registries.
Pinned Comments
enmanuelmoreira commented on 2021-08-27 02:42 (UTC) (edited on 2021-08-27 20:37 (UTC) by enmanuelmoreira)
Terrascan is a static code analyzer for Infrastructure as Code. Terrascan allows you to:
Resources
To learn more about Terrascan's features and capabilities, see the documentation portal: https://runterrascan.io
Join The Terrascan Community on Discord : https://discord.gg/DFwXEfbjzt
Key features