
Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across Terraform, Kubernetes, CloudFormation, and 20+ IaC platforms.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project.
Setting up and using KICS is super-easy.
Interested in more advanced stuff?
See KICS documentation for more details and topics.
What makes KICS really powerful and popular is its built-in extensibility. This extensibility is achieved by:
You're welcome to join our community, talk with us on GitHub discussions or contact KICS core team at [email protected].
See our individual contributors in the community page. You're welcome to join them by contributing to KICS.
We also like to thank the following organizations for their ongoing contribution:
KICS is used by various companies and organizations, some are listed below. If you would like to be included here please open a PR.
Keeping Infrastructure as Code Secure!
© 2026 Checkmarx Ltd. All Rights Reserved.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|