KICS - Checkmarx
Free Virtual Summit Agentic AppSec Unleashed '26 is June 16th Register Now
Outlook Report The Future of Application Security in the Era of AI Download Now
Checkmarx for Developers
Partners
Blog
Research
By Checkmarx

Open-Source IaC:
Free, Fast, Scalable

KICS (Keeping Infrastructure as Code Secure) is a free, open-source solution for static code analysis of IaC.

Exposed secrets are a major AppSec attack vector

Enterprises are unintentionally exposing thousands of secret credentials every day, leading to cyberattacks, financial loss, and reputational damage. 2MS finds exposed secrets so that you can better protect your organization from attack.

5.5M+
Docker Pulls (Downloads)
2,400+
Fully Customizable Rules and Queries
18+
IaC Platforms Supported
75+
Languages and Formats Supported

Find Out More

Download KICS and protect your entire organization from flaws and misconfigurations.

Platform

KICS identifies security vulnerabilities, compliance issues, and misconfigurations in IaC solutions like Terraform, Kubernetes, Docker, AWS CloudFormation, Ansible, and Helm. It also supports OpenAPI 3.0 with over 2,400 editable queries.

platform-1
platform-2
platform-3
platform-4
platform-5
platform-6
platform-7
Platform Capabilities

Application Security That Prioritizes What Matters

Checkmarx One ASPM closes visibility gaps, eliminates redundant triage, and enables smarter prioritization with risk orchestration for faster, more efficient remediation.

Risk Coverage

End-To-End Risk Coverage

Connect vulnerabilities from source to runtime by integrating findings from Checkmarx, third-party tools, and CNAPPs into one unified view of risk.

placeholder
Integrations

Connect to Your Dev Ecosystem

Integrate with cloud tools, ticketing systems, and any IDE — bringing full ASPM context and best-fix-location guidance into existing workflows.

placeholder
Checkmarx Zero

Context-Enriched Risk Scoring

Powered by Checkmarx Zero, blend exploitability, reachability, fixability, and runtime exposure into one aggregated risk score so you can prioritize and act based on real business risk.

placeholder

Ready to secure what comes next?

See Checkmarx One in action with a personalized demo from our security experts.

Additional Resources

KICS is powered by Checkmarx—the leader in application security — in partnership with the open-source community.

Documentation

Read Now →

Contribute

Read Now →

Solution Brief

Learn More →

KICS Roadmap

Learn More →

GitHub Source

Download KICS →

Find Out More

Download KICS and protect your IaC, your APIs, and your entire organization from flaws and misconfigurations.