An evaluation of commonly used Kubernetes security scanning tools

Ioanna Angeliki Kapetanidou, Alexandros Nizamis, Konstantinos Votis · 2025

With the advent of the edge-cloud continuum, Kubernetes (K8s) has emerged as the prominent solution for service orchestration. In this context, ensuring deployment security is essential. To identify vulnerabilities and misconfigurations in a timely and efficient manner, security scanning tools are employed. In this work, we evaluate six widely used security tools for workload and static code analysis. We consider several factors, including scan time, the number of detected threats, and resource usage. This evaluation seeks not only to demonstrate the performance trade-offs of these tools but also to contribute additional insights into their practical capabilities.

Read the paper · More papers on PaperTik