Deepfence ThreatMapper
Open-source security observability for cloud-native production workloads.
At a glance
- Editor scoreNot yet scored
- PricingFree plan
- Best forOpen-source teams needing runtime risk visualization
- Free planYes
- Paid fromNone
- Image scanningYes
- Facts checked15 Sep 2026
Where it wins
- Discovers production workloads and infrastructure across diverse environments
- Combines runtime, registry, CI/CD, SBOM, secret, and compliance scanning
- ThreatGraph ranks exploit risk and connects notifications, SIEM, and ticketing tools
Where it doesn't
- Self-hosted deployment requires Docker or Kubernetes management
- Sensor agents and cloud-scanner tasks are part of the collection architecture
- Teams requiring admission control should consider an alternative
Our verdict on Deepfence ThreatMapper
Deepfence ThreatMapper is an open-source cloud-native application protection platform for security and DevOps teams. It discovers production workloads and infrastructure across containers, Kubernetes, cloud, serverless, and on-premises environments. The platform scans running workloads, container registries, and CI/CD image builds; generates runtime SBOMs; detects exposed secrets; checks cloud, host, and Kubernetes compliance; and ranks findings by risk of exploit. Its web management console is supported on Linux and provides API access, while the deployment model is self-hosted.
ThreatMapper’s strongest differentiator is the breadth of its security observability workflow. Teams can connect discovery with runtime vulnerability scanning, registry scanning, image-build scanning, SBOM generation, compliance checks, and ThreatGraph visualization. Risk-of-exploit ranking helps organize findings around potential impact rather than presenting vulnerabilities as an undifferentiated list. Integrations with CircleCI, Jenkins, GitLab, Slack, PagerDuty, Jira, Splunk, ELK, Sumo Logic, AWS S3, and Terraform extend the platform into development, notification, SIEM, ticketing, cloud, and infrastructure workflows. This makes it a fit for open-source teams that need visibility across both production and delivery environments.
The main operational consideration is deployment responsibility. The management console runs as containers on Docker or Kubernetes, while sensor agents and cloud-scanner tasks collect workload and infrastructure data. That architecture suits teams prepared to operate a self-hosted security platform, but it is less suitable for buyers seeking a managed service with minimal platform administration. ThreatMapper should be considered by organizations prioritizing open-source access, runtime risk visualization, and broad scanning coverage. Teams that specifically require admission control should choose a product designed for that requirement instead.
Deepfence ThreatMapper pricing
Deepfence ThreatMapper fact sheet
| Free plan | Yes |
|---|---|
| Paid from | None |
| Image scanning | Yes |
| Runtime protection | Yes |
| Kubernetes security | Yes |
| Registry scanning | Yes |
| Admission control | Not verified |
| SBOM generation | Yes |
| Deployment model | Self_hosted |
| Deployment | Cloud, Desktop |
| Platforms | Web, Linux |
| Integrations | 11 integrations: CircleCI, Jenkins, GitLab, Slack, PagerDuty, Jira … |
| Pricing | Free plan |
| Website | threatmapper.org |
| Facts checked | 15 Sep 2026 |
Deepfence ThreatMapper integrations
Deepfence ThreatMapper lists 11 integrations on its own site.
- CircleCI
- Jenkins
- GitLab
- Slack
- PagerDuty
- Jira
- Splunk
- ELK
- Sumo Logic
- AWS S3
- Terraform
Alternatives to Deepfence ThreatMapper
- Trend Vision One Container SecurityBroad container security coverage with transparent usage-based pricing.—
- Qualys Container SecurityBroad container coverage with a free visibility tier and sales-led paid access.—
- Wiz Container and Kubernetes SecurityA broad cloud security platform for prioritizing container and Kubernetes risks.—
See all Deepfence ThreatMapper alternatives →
Used Deepfence ThreatMapper? Be the first to review it
The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used Deepfence ThreatMapper for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.
Write a reviewTwo minutes · verified accounts only · read by an editor before it appears
Featured on iTechGuides
Deepfence ThreatMapper is listed in our Container Security Software directory. Add the badge to your site — it links back to this page.
<a href="https://www.itechguides.com/products/deepfence-threatmapper/"><img src="https://www.itechguides.com/best/badge/deepfence-threatmapper.svg" alt="Featured on iTechGuides" width="230" height="46"></a>
Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes a score or a verdict. How we rank.



