Saltar al contenido principal

Key Features

Below is an overview of the core capabilities of Plexicus CNAPP that help you build, deploy, and operate applications with confidence.

1. Application Security Posture Management (ASPM)

Secure your applications from the earliest stages of development. Plexicus's ASPM capabilities integrate directly into your CI/CD pipeline to identify and remediate vulnerabilities in your code and open-source dependencies.

  • Static Application Security Testing (SAST)
    Detect vulnerabilities in your source code with tools like Checkmarx, Semgrep, and Fortify, ensuring compliance with standards like the OWASP Top 10.
  • Software Composition Analysis (SCA)
    Identify vulnerable dependencies and manage license compliance across all major package managers with the plexicus-sca and plexicus-license bundles, and generate full SBOMs with plexicus-sbom.
  • Secrets Scanning
    Prevent exposure of sensitive credentials like API keys and passwords with the plexicus-secrets bundle — including Git-history scanning and live verification against issuing services.
  • Infrastructure as Code (IaC) Security
    Scan Terraform, CloudFormation, Kubernetes, Helm, and other IaC definitions for policy violations with the plexicus-iac and plexicus-cicd bundles.

2. Cloud Security Posture Management (CSPM)

Gain full visibility into your cloud environments and ensure they remain secure and compliant. The plexicus-cloud bundle continuously monitors your AWS, Azure, and GCP infrastructure, identifies misconfigurations, and mitigates cloud-specific risks before they can be exploited — with Prowler available as an external compliance integration.

3. Container Security

Protect your containerized applications and Kubernetes environments. Plexicus offers robust scanning and configuration analysis to secure every layer of your container stack.

  • Vulnerability Scanning
    Identify known vulnerabilities in your container images with the plexicus-container and plexicus-registry bundles — from Dockerfile to published registry image.
  • Secure Configuration
    Ensure your Docker and Kubernetes environments are configured securely to prevent common attack vectors.

4. Cloud Workload Protection Platform (CWPP)

Safeguard your cloud workloads against modern threats. Plexicus's CWPP capabilities provide real-time threat detection and protection for your virtual machines, containers, and serverless functions running in the cloud.

  • Threat and Malware Detection
    Proactively scan for malicious code and supply-chain threats with signature- and pattern-based detection, and audit SLSA supply-chain compliance with the plexicus-scm bundle.
  • Workload Monitoring
    Gain deep visibility into running workloads to detect and respond to suspicious activity in real-time.

5. Cloud Infrastructure Entitlement Management (CIEM)

Manage and enforce least-privilege access across your cloud infrastructure. Plexicus's CIEM capabilities help you understand who has access to what, identify excessive permissions, and right-size entitlements to reduce the risk of credential misuse and insider threats.