Catalog comparison
Side-by-side facts from the TestGuild Tool Matcher catalog. Empty cells mean the catalog does not list that attribute — not that the product lacks it.
Open-source Application Security Orchestration and Correlation (ASOC) and vulnerability management platform that integrates 80+ commercial and open-source scanners. Consolidates web (DAST), static (SAST), infrastructure, and cloud scan results, correlates findings, reduces false positives, and supports shift-left DevSecOps via archerysec-cli, REST APIs, and Jira ticketing.
Cloud Native Runtime Security - An open source security tool for detecting threats in cloud-native environments. Falco monitors system calls, container events, and Kubernetes audit logs to detect suspicious behavior and security threats in real-time.
Primary testing surface
ArcherySec
Security
Falco
Security
Primary capability
ArcherySec
Security
Falco
Security
License and pricing
ArcherySec
free · open source
Falco
free · open source
Free trial
ArcherySec
No
Falco
No
Complexity
ArcherySec
intermediate
Falco
intermediate
Team fit
ArcherySec
large, medium, small
Falco
enterprise, large, medium, small
Test authoring languages
ArcherySec
CLI, Python, REST API
Falco
C++, Go, JSON, Shell Scripts, YAML
Supported platforms
ArcherySec
api, ci/cd, cloud, docker, linux, network, on-premises, self-managed, web
Falco
aws eks, azure aks, cloud native environments, container orchestration platforms, containerd, cri-o, docker, google gke, kubernetes, linux, openshift, rancher
MCP server
ArcherySec
No
Falco
No
Key features (catalog)
ArcherySec
Application Security Orchestration and Correlation (ASOC), archerysec-cli for CI/CD shift-left scanning, Authenticated web scanning and Selenium-based application coverage, Consolidated vulnerability management for web, network, and cloud scans, Dynamic (DAST) and static (SAST) scan dashboards, Finding correlation and false-positive reduction, Infrastructure and network scan result consolidation, Integration with 80+ commercial and open-source security tools, Jira ticketing system integration, Open-source community-driven project +4 more
Falco
Alert management, Anomaly detection, Cloud-native integration, CNCF graduated project, Compliance monitoring, Container escape detection, Container runtime security, Cross-platform support, Custom rule creation with Falco rules, eBPF-based monitoring +22 more
Limitations (catalog)
ArcherySec
Feature depth depends on which scanner connectors you configure, Learning curve for orchestration, correlation, and project workflows, Requires connecting and operating upstream scanners for full value, Self-hosted deployment needs infrastructure and maintenance, Website and documentation can feel less polished than commercial ASOC suites
Falco
Learning curve for custom rule creation, Limited to runtime security (no static analysis), Linux-only (requires Linux kernel), May generate false positives requiring tuning, No built-in remediation capabilities, Requires external alerting and response systems, Requires kernel module or eBPF probe installation, Requires root/privileged access for installation +2 more
| Attribute | ArcherySec | Falco |
|---|---|---|
| Primary testing surface | Security | Security |
| Primary capability | Security | Security |
| License and pricing | free · open source | free · open source |
| Free trial | No | No |
| Complexity | intermediate | intermediate |
| Team fit | large, medium, small | enterprise, large, medium, small |
| Test authoring languages | CLI, Python, REST API | C++, Go, JSON, Shell Scripts, YAML |
| Supported platforms | api, ci/cd, cloud, docker, linux, network, on-premises, self-managed, web | aws eks, azure aks, cloud native environments, container orchestration platforms, containerd, cri-o, docker, google gke, kubernetes, linux, openshift, rancher |
| MCP server | No | No |
| Key features (catalog) | Application Security Orchestration and Correlation (ASOC), archerysec-cli for CI/CD shift-left scanning, Authenticated web scanning and Selenium-based application coverage, Consolidated vulnerability management for web, network, and cloud scans, Dynamic (DAST) and static (SAST) scan dashboards, Finding correlation and false-positive reduction, Infrastructure and network scan result consolidation, Integration with 80+ commercial and open-source security tools, Jira ticketing system integration, Open-source community-driven project +4 more | Alert management, Anomaly detection, Cloud-native integration, CNCF graduated project, Compliance monitoring, Container escape detection, Container runtime security, Cross-platform support, Custom rule creation with Falco rules, eBPF-based monitoring +22 more |
| Limitations (catalog) | Feature depth depends on which scanner connectors you configure, Learning curve for orchestration, correlation, and project workflows, Requires connecting and operating upstream scanners for full value, Self-hosted deployment needs infrastructure and maintenance, Website and documentation can feel less polished than commercial ASOC suites | Learning curve for custom rule creation, Limited to runtime security (no static analysis), Linux-only (requires Linux kernel), May generate false positives requiring tuning, No built-in remediation capabilities, Requires external alerting and response systems, Requires kernel module or eBPF probe installation, Requires root/privileged access for installation +2 more |
Guidance below is inferred only from catalog differences. It is not a winner pick.