Security Cipher
Home Blog About Us
Resources ▼
🗺️ Penetration Testing Roadmap 🌐 Web Application Security Checklist 🤖 OWASP Top 10 for LLM Applications 🧠 LLM AI Security Checklist 🛠️ Security Tools 🎯 Penetration Testing Tricks 📄 Secure Code Explain 📖 Vulnerability Explain ☁️ AWS Cloud Security Checklist
My Resume
Contact UsContact
← Security Tools View on GitHub

KICS

Finds security vulnerabilities and misconfigurations in IaC (Terraform, K8s, Docker, and more).

Latest Release License Queries Docker Pulls GitHub contributors Documentation GitHub Discussions

checkmarx Codacy Badge Quality Gate Status Go Report Card Go Coverage

KICS - Keep Infrastructure as Code Secure KICS - Keep Infrastructure as Code Secure


Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project.

Supported Platforms


Terraform Kubernetes Docker
CloudFormation Ansible Helm
OpenAPI gRPC Azure Resource Manager Google Deployment Manager
Cloud Development Kit SAM Docker Compose Knative
Crossplane Pulumi ServerlessFW
Azure BluePrints GitHub Workflows OpenTofu Bicep NIFCloud
Databricks TencentCloud

Getting Started

Setting up and using KICS is super-easy.

  • First, see how to install and get KICS running.
  • Then explore KICS output results format and quickly fix the issues detected.

Interested in more advanced stuff?

  • Deep dive into KICS queries.
  • Understand how to integrate KICS in your favourite CI/CD pipelines.

See KICS documentation for more details and topics.

How it Works

What makes KICS really powerful and popular is its built-in extensibility. This extensibility is achieved by:

  • Fully customizable and adjustable heuristics rules, called queries. These can be easily edited, extended and added.
  • Robust but yet simple architecture, which allows quick addition of support for new Infrastructure as Code solutions.

Community

You're welcome to join our community, talk with us on GitHub discussions or contact KICS core team at kics@checkmarx.com.

KICS Contributors

See our individual contributors in the community page. You're welcome to join them by contributing to KICS.

We also like to thank the following organizations for their ongoing contribution:

  • Checkmarx
  • Bedrock Streaming (since v1.4.8)
  • Dynatrace (since v1.5.1)
  • Orca Security (since v1.5.10)

KICS Users

KICS is used by various companies and organizations, some are listed below. If you would like to be included here please open a PR.

  • Checkmarx (IaC Security)
  • GitLab (Infrastructure as Code scanning)
  • Bedrock Streaming
  • Cisco (CI/CD Securitry)
  • Orca Security
  • JIT (SAST for IaC)
  • Firefly (Firefly Integrates With Checkmarx's KICS)
  • Redpanda
  • Keptn / Keptn Lifecycle Toolkit

Keeping Infrastructure as Code Secure!


© 2026 Checkmarx Ltd. All Rights Reserved.

Press Escape to close the search panel.

Donate

Buy me a Coffee

Penetration Testing Services - Fiverr

Buy me a Coffee

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Application Security Engineer

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • I Ran Codex Security on a Shop API Lab: 14 Bugs, $1.64, Full Playbook
    I Ran Codex Security on a Shop API Lab: 14 Bugs, $1.64, Full Playbook
    August 3, 2026/
    0 Comments
  • How I Would Hack Your Startup in 24 Hours (Real-World Pentest Guide)
    How I Would Hack Your Startup in 24 Hours (Real-World Pentest Guide)
    July 27, 2026/
    0 Comments
  • Web Cache Poisoning in 2026: A Practical Playbook (One Request, Every Victim)
    Web Cache Poisoning in 2026: A Practical Playbook (One Request, Every Victim)
    July 19, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Start Here
  • Cybersecurity Jobs
  • CVE Lookup
  • Bug Bounty Programs
  • Security Conferences
  • Payload Cheatsheets
  • Interview Prep
  • Report Templates
  • Blogs
  • About
  • Contact
  • RSS Feed

Recent Post

  • I Ran Codex Security on a Shop API Lab: 14 Bugs, $1.64, Full Playbook
  • How I Would Hack Your Startup in 24 Hours (Real-World Pentest Guide)
  • Web Cache Poisoning in 2026: A Practical Playbook (One Request, Every Victim)
© 2026 SecurityCipher. All rights reserved. Privacy Policies · Terms & Conditions