Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Validate modifications across numerous supported resource types in all leading cloud service providers. Conduct scans of cloud resources during the build phase to identify misconfigured settings using a straightforward Python policy-as-code framework. Examine the connections between cloud resources through Checkov’s graph-oriented YAML policies. Run, test, and adjust runner parameters within the context of a specific repository's CI/CD processes and version control systems. Customize Checkov to create your own unique policies, providers, and suppression terms. Avoid the deployment of misconfigurations by integrating this process into the current workflows of developers. Facilitate automated annotations on pull or merge requests in your repositories, eliminating the need to establish a CI pipeline or perform routine checks. The Bridgecrew platform will automatically review new pull requests and provide comments highlighting any policy violations it uncovers, ensuring continuous compliance and security improvements in your cloud infrastructure. This proactive approach helps maintain best practices and enhances the overall security posture of your cloud environment.
Description
Our innovative, patent-pending graph-based technology facilitates the proactive identification and resolution of both recognized and unidentified threats in your systems. This includes handling misconfigurations, inadequate configurations, overly permissive policies, and Common Vulnerabilities and Exposures (CVEs), allowing your teams to effectively tackle and eradicate all potential risks to your cloud infrastructure. By prioritizing the most urgent concerns, your team can concentrate on the most critical tasks at hand. Furthermore, our root cause analysis significantly minimizes the volume of alerts and overall findings, ensuring that teams can focus on the most essential issues. Safeguard your cloud ecosystem while progressing in your digital transformation journey. The solution provides a correlation between the Kubernetes and cloud layers, integrating effortlessly with your current workflows. Additionally, you can obtain a quick visual evaluation of your cloud environment utilizing established cloud vendor APIs, tracing from the infrastructure level all the way down to individual microservices, thereby enhancing your operational efficiency. This comprehensive approach not only protects your assets but also streamlines your response efforts.
API Access
Has API
No
API Access
Has API
No
Integrations
Amazon Web Services (AWS)
Yes
Google Cloud Platform
Yes
Kubernetes
Yes
Microsoft Azure
Yes
AWS CloudFormation
Yes
Archipelo
Yes
Bitbucket
Yes
Brainboard
Yes
Cider
Yes
CycloneDX
Yes
Integrations
Amazon Web Services (AWS)
Yes
Google Cloud Platform
Yes
Kubernetes
Yes
Microsoft Azure
Yes
AWS CloudFormation
No
Archipelo
No
Bitbucket
No
Brainboard
No
Cider
No
CycloneDX
No
Pricing Details
Free
Open source
Free Trial
No
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
Yes
In Person
No
Vendor Details
Company Name
Prisma Cloud
Founded
2019
Country
United States
Website
www.checkov.io
Vendor Details
Company Name
Lightspin
Founded
2020
Country
Israel
Website
www.lightspin.io
Product Features
Static Code Analysis
Analytics / Reporting
No
Code Standardization / Validation
No
Multiple Programming Language Support
No
Provides Recommendations
No
Standard Security/Industry Libraries
No
Vulnerability Management
No
Product Features
Cloud Security
Antivirus
Yes
Application Security
No
Behavioral Analytics
Yes
Encryption
No
Endpoint Management
No
Incident Management
Yes
Intrusion Detection System
No
Threat Intelligence
Yes
Two-Factor Authentication
No
Vulnerability Management
No
Cybersecurity
AI / Machine Learning
No
Behavioral Analytics
Yes
Endpoint Management
No
IOC Verification
Yes
Incident Management
Yes
Tokenization
No
Vulnerability Scanning
Yes
Whitelisting / Blacklisting
No
Vulnerability Management
Asset Discovery
Yes
Asset Tagging
No
Network Scanning
No
Patch Management
Yes
Policy Management
Yes
Prioritization
Yes
Risk Management
Yes
Vulnerability Assessment
No
Web Scanning
No