Catalog comparison
Side-by-side facts from the TestGuild Tool Matcher catalog. Empty cells mean the catalog does not list that attribute — not that the product lacks it.
Cloud Native Runtime Security - An open source security tool for detecting threats in cloud-native environments. Falco monitors system calls, container events, and Kubernetes audit logs to detect suspicious behavior and security threats in real-time.
Open-source Application Security Orchestration and Correlation (ASOC) and vulnerability management platform that integrates 80+ commercial and open-source scanners. Consolidates web (DAST), static (SAST), infrastructure, and cloud scan results, correlates findings, reduces false positives, and supports shift-left DevSecOps via archerysec-cli, REST APIs, and Jira ticketing.
Primary testing surface
Falco
Security
ArcherySec
Security
Primary capability
Falco
Security
ArcherySec
Security
License and pricing
Falco
free · open source
ArcherySec
free · open source
Free trial
Falco
No
ArcherySec
No
Complexity
Falco
intermediate
ArcherySec
intermediate
Team fit
Falco
enterprise, large, medium, small
ArcherySec
large, medium, small
Test authoring languages
Falco
C++, Go, JSON, Shell Scripts, YAML
ArcherySec
CLI, Python, REST API
Supported platforms
Falco
aws eks, azure aks, cloud native environments, container orchestration platforms, containerd, cri-o, docker, google gke, kubernetes, linux, openshift, rancher
ArcherySec
api, ci/cd, cloud, docker, linux, network, on-premises, self-managed, web
MCP server
Falco
No
ArcherySec
No
Key features (catalog)
Falco
Alert management, Anomaly detection, Cloud-native integration, CNCF graduated project, Compliance monitoring, Container escape detection, Container runtime security, Cross-platform support, Custom rule creation with Falco rules, eBPF-based monitoring +22 more
ArcherySec
Application Security Orchestration and Correlation (ASOC), archerysec-cli for CI/CD shift-left scanning, Authenticated web scanning and Selenium-based application coverage, Consolidated vulnerability management for web, network, and cloud scans, Dynamic (DAST) and static (SAST) scan dashboards, Finding correlation and false-positive reduction, Infrastructure and network scan result consolidation, Integration with 80+ commercial and open-source security tools, Jira ticketing system integration, Open-source community-driven project +4 more
Limitations (catalog)
Falco
Learning curve for custom rule creation, Limited to runtime security (no static analysis), Linux-only (requires Linux kernel), May generate false positives requiring tuning, No built-in remediation capabilities, Requires external alerting and response systems, Requires kernel module or eBPF probe installation, Requires root/privileged access for installation +2 more
ArcherySec
Feature depth depends on which scanner connectors you configure, Learning curve for orchestration, correlation, and project workflows, Requires connecting and operating upstream scanners for full value, Self-hosted deployment needs infrastructure and maintenance, Website and documentation can feel less polished than commercial ASOC suites
| Attribute | Falco | ArcherySec |
|---|---|---|
| Primary testing surface | Security | Security |
| Primary capability | Security | Security |
| License and pricing | free · open source | free · open source |
| Free trial | No | No |
| Complexity | intermediate | intermediate |
| Team fit | enterprise, large, medium, small | large, medium, small |
| Test authoring languages | C++, Go, JSON, Shell Scripts, YAML | CLI, Python, REST API |
| Supported platforms | aws eks, azure aks, cloud native environments, container orchestration platforms, containerd, cri-o, docker, google gke, kubernetes, linux, openshift, rancher | api, ci/cd, cloud, docker, linux, network, on-premises, self-managed, web |
| MCP server | No | No |
| Key features (catalog) | Alert management, Anomaly detection, Cloud-native integration, CNCF graduated project, Compliance monitoring, Container escape detection, Container runtime security, Cross-platform support, Custom rule creation with Falco rules, eBPF-based monitoring +22 more | Application Security Orchestration and Correlation (ASOC), archerysec-cli for CI/CD shift-left scanning, Authenticated web scanning and Selenium-based application coverage, Consolidated vulnerability management for web, network, and cloud scans, Dynamic (DAST) and static (SAST) scan dashboards, Finding correlation and false-positive reduction, Infrastructure and network scan result consolidation, Integration with 80+ commercial and open-source security tools, Jira ticketing system integration, Open-source community-driven project +4 more |
| Limitations (catalog) | Learning curve for custom rule creation, Limited to runtime security (no static analysis), Linux-only (requires Linux kernel), May generate false positives requiring tuning, No built-in remediation capabilities, Requires external alerting and response systems, Requires kernel module or eBPF probe installation, Requires root/privileged access for installation +2 more | Feature depth depends on which scanner connectors you configure, Learning curve for orchestration, correlation, and project workflows, Requires connecting and operating upstream scanners for full value, Self-hosted deployment needs infrastructure and maintenance, Website and documentation can feel less polished than commercial ASOC suites |
Guidance below is inferred only from catalog differences. It is not a winner pick.