Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.kics-ubuntu-24-04-9cc32c30-a670-4cd7-adde-55605bf4808a/image5_logolarge.png

KICS on Ubuntu 24.04 LTS

by cloudimg

KICS on Ubuntu 24.04: scan Terraform, Kubernetes and CloudFormation for security issues

KICS (Keeping Infrastructure as Code Secure) is the open source static analysis scanner from Checkmarx that finds security misconfigurations and compliance issues in Infrastructure as Code before it is applied to a cloud account. It parses Terraform, CloudFormation, Kubernetes manifests, Ansible, Dockerfile and Docker Compose, Helm charts, ARM and Bicep, OpenAPI, gRPC, Pulumi and Crossplane, and evaluates each against an embedded library of more than two thousand queries covering the security guidance of the major cloud and platform providers. This cloudimg image runs KICS 2.1.20 on Ubuntu 24.04 LTS.

Every finding names the query, the platform, the file, the line, a severity from CRITICAL down to INFO and the CWE it maps to, and results can be written as JSON or SARIF, the format that GitHub code scanning, Azure DevOps and most IDEs consume directly, so a scan drops straight into a code review, a dashboard or a pipeline gate. Because the query library ships with the scanner and is evaluated locally, scanning needs no outbound internet at all and this VM runs happily in an isolated subnet with no egress.

The scanner and its query library are both pinned and verified against their published checksums, a simple wrapper makes a full scan a single command, a daily timer scans a directory you choose and writes JSON and SARIF reports with stable latest symlinks for CI pickup, and read only self test fixtures (an insecure Terraform sample and a locked down clean sample) let you prove detection works on your own VM. This is a headless command line product: no web UI, no listening service, no admin account and no password, so SSH on port 22 is the only open port.

KICS is distributed under the Apache License 2.0, free and open source with no per CPU or per deployment fee. cloudimg is not affiliated with or endorsed by Checkmarx or the KICS project. cloudimg provides packaging, secure by default hardening, security patching, and 24/7 support with a guaranteed 24 hour response SLA.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.kics-ubuntu-24-04-9cc32c30-a670-4cd7-adde-55605bf4808a/image1_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.kics-ubuntu-24-04-9cc32c30-a670-4cd7-adde-55605bf4808a/image4_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.kics-ubuntu-24-04-9cc32c30-a670-4cd7-adde-55605bf4808a/image2_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.kics-ubuntu-24-04-9cc32c30-a670-4cd7-adde-55605bf4808a/image6_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies