You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OpenClarity is an open source tool for agentless detection and management of Virtual Machine
Software Bill Of Materials (SBOM) and security threats such as vulnerabilities, exploits, malware, rootkits, misconfigurations and leaked secrets.
Join OpenClarity's Slack channel to hear about the latest announcements and upcoming activities. We would love to get your feedback!
Virtual machines (VMs) are the most used service across all hyperscalers. AWS,
Azure, GCP, and others have virtual computing services that are used not only
as standalone VM services but also as the most popular method for hosting
containers (e.g., Docker, Kubernetes).
VMs are vulnerable to multiple threats:
Software vulnerabilities
Leaked Secrets/Passwords
Malware
System Misconfiguration
Rootkits
There are many very good open source and commercial-based solutions for
providing threat detection for VMs, manifesting the different threat categories above.
However, there are challenges with assembling and managing these tools yourself:
Complex installation, configuration, and reporting
Integration with deployment automation
Siloed reporting and visualization
The OpenClarity project is focused on unifying detection and management of VM security threats in an agentless manner.
Getting started
For step-by-step guidance on how to deploy OpenClarity across different environments, including AWS, Azure, GCP, and Docker, click on this link and choose your preferred provider for detailed deployment instructions.
Overview
OpenClarity uses a pluggable scanning infrastructure to provide:
SBOM analysis
Package and OS vulnerability detection
Exploit detection
Leaked secret detection
Malware detection
Misconfiguration detection
Rootkit detection
The pluggable scanning infrastructure uses several tools that can be
enabled/disabled on an individual basis. OpenClarity normalizes, merges and
provides a robust visualization of the results from these various tools.
If you are ready to jump in and test, add code, or help with documentation,
please follow the instructions on our contributing guide
for details on how to open issues, setup OpenClarity for development and test.