End-to-end cloud-native protection: Covers the full lifecycle from code to runtime, including image scanning, IaC, and runtime defense. Strong Kubernetes and container security: Best-in-class visibility and control over container environments. Runtime enforcement capabilities: Inline protection actively blocks malicious actions before execution, which many competitors struggle to do effectively. Wide integrations: Works well with CI/CD pipelines, registries, and multi-cloud environments (AWS, Azure, GCP). Accurate vulnerability detection: Generally low false positives with detailed findings, improving trust in alerts.
June 25, 2026
For static image scanning, once you dive into the details, the portal lacks precision. Images that still exist and which once were listed as a problem fall off the report, even though no remediation has been performed. This is likely due the container side of the server reporting that the image is no longer live in production, but it doesn't appear consistent. We appear to be using a very basic version of the image scanner as it times out in the middle of the repo scanning and has to start over again many times. It pulls the same images over and over again which corrupts the 'Last pulled date' metadata which AWS maintains. This destroys our ability to remove stale images based on the last pulled date, which is annoying in the extreme. I have heard from the admins that we upgrading to the 'sonic' version of the image scanner and these issues should go away, but it way did we get put into the wrong the version in the first place? The whole company was supposed to go 'live' with images/containers being a part of security policy in the summer, but due the enterprise limitations mentioned earlier we have yet to onboard the Aqua results into the security program. Being late 6 months just looks bad. I'm sure our security operations team doesn't appreciate the look and wishes they had chosen a different vendor.
October 31, 2024