AquilaX Container Scanner inspects Docker images layer by layer for CVEs, misconfigurations, privilege escalation paths, and exposed secrets. Full Kubernetes RBAC and runtime security analysis — aligned to CIS and NSA benchmarks.
From the base image to the Kubernetes RBAC policy — AquilaX Container Scanner covers the full container security stack.
Layer-by-layer scanning of OS packages (apt, apk, yum) and application packages inside container images. Real-time CVE lookup against NVD, GHSA, and Red Hat Security Advisory.
Root user, privileged mode, unnecessary capabilities, missing health checks, secrets in ENV/ARG, exposed dangerous ports, and ADD vs COPY best practice violations.
ClusterAdmin bindings, wildcard resource permissions, service account token auto-mounting, missing namespaces, and insecure inter-pod communication policies.
Privileged containers, host network/PID/IPC sharing, missing seccomp and AppArmor profiles, writable root filesystems, and missing resource limits and requests.
API keys, database passwords, and certificate private keys baked into image layers — including secrets added in intermediate build stages that persist in the final image.
Missing Kubernetes NetworkPolicy resources, overly permissive pod-to-pod communication, exposed service ports, and LoadBalancer services without IP allowlisting.
Container security is a non-negotiable for any team running workloads on Docker or Kubernetes.
Block container image builds that introduce new critical CVEs. Integrate with your registry pipeline — Docker Hub, ECR, GCR, or Harbor — and enforce security before push.
Continuously audit running cluster configurations against CIS Kubernetes benchmarks. Get actionable findings mapped to pod specs and RBAC policies with one-click remediation.
Generate CIS Kubernetes and NSA CNSA compliance reports automatically. Meet DoD STIG, FedRAMP, and SOC 2 container security requirements with continuous audit evidence.
Connect your container registry and AquilaX scans every image automatically. No agents inside the container.