# Comparativa Gráfica

<table id="bkmrk-herramienta-%C2%BFes-open" style="width: 105.714%; height: 911px;"><thead><tr><th style="width: 8.46044%;">Herramienta</th><th style="width: 5.12393%;">¿Es Open Source?</th><th style="width: 8.34128%;">Alcance de evaluación</th><th style="width: 8.10295%;">Integrable en DevSecOps</th><th style="width: 7.38799%;">Tipo de vulnerabilidades</th><th style="width: 6.79218%;">Facilidad de uso</th><th style="width: 7.62631%;">Comunidad / Soporte</th><th style="width: 7.98379%;">Reportes comprensibles</th><th style="width: 7.98379%;">Automatizable en CI/CD</th><th style="width: 7.62631%;">Costo</th><th style="width: 7.50715%;">Integraciones</th><th style="width: 8.10295%;">Personalización de reglas</th><th style="width: 8.81792%;">Cumplimiento de estándares</th></tr></thead><tbody><tr><td style="width: 8.46044%;">**Trivy**</td><td style="width: 5.12393%;">✅ Sí</td><td style="width: 8.34128%;">Imágenes Docker, código, IaC</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">SCA, IaC, secretos, vuln.</td><td style="width: 6.79218%;">⭐⭐⭐⭐ Fácil</td><td style="width: 7.62631%;">✅ Activa (AquaSec)</td><td style="width: 7.98379%;">✅ Claro (CLI/JSON)</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">✅ Gratis (OSS)</td><td style="width: 7.50715%;">GitHub, GitLab, Jenkins</td><td style="width: 8.10295%;">✅ Parcial (políticas)</td><td style="width: 8.81792%;">✅ OWASP, CIS</td></tr><tr><td style="width: 8.46044%;">**Grype + Syft**</td><td style="width: 5.12393%;">✅ Sí</td><td style="width: 8.34128%;">Análisis de imágenes/SBOM</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">SCA (dependencias)</td><td style="width: 6.79218%;">⭐⭐⭐ Media</td><td style="width: 7.62631%;">✅ Sí (Anchore)</td><td style="width: 7.98379%;">CLI/JSON/SARIF</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">✅ Gratis (OSS)</td><td style="width: 7.50715%;">GitHub, GitLab</td><td style="width: 8.10295%;">✅ Avanzado (rules.yaml)</td><td style="width: 8.81792%;">✅ Parcial (CIS, OWASP)</td></tr><tr><td style="width: 8.46044%;">**SonarQube CE**</td><td style="width: 5.12393%;">✅ (CE) / ❌ (EE)</td><td style="width: 8.34128%;">Código fuente (SAST)</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">SAST</td><td style="width: 6.79218%;">⭐⭐⭐⭐ Fácil</td><td style="width: 7.62631%;">✅ Amplia</td><td style="width: 7.98379%;">✅ Muy buenos</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">✅ CE gratis / EE pago</td><td style="width: 7.50715%;">GitHub, GitLab, Jenkins</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 8.81792%;">✅ OWASP Top 10</td></tr><tr><td style="width: 8.46044%;">**OWASP ZAP**</td><td style="width: 5.12393%;">✅ Sí</td><td style="width: 8.34128%;">Web apps (DAST)</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">DAST</td><td style="width: 6.79218%;">⭐⭐ Intermedio</td><td style="width: 7.62631%;">✅ OWASP</td><td style="width: 7.98379%;">✅ GUI + JSON</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">✅ Gratis</td><td style="width: 7.50715%;">Jenkins, GitHub, Jira</td><td style="width: 8.10295%;">✅ Avanzado</td><td style="width: 8.81792%;">✅ OWASP Top 10</td></tr><tr><td style="width: 8.46044%;">**Semgrep**</td><td style="width: 5.12393%;">✅ Sí</td><td style="width: 8.34128%;">Código (SAST ligero + rules)</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">SAST</td><td style="width: 6.79218%;">⭐⭐⭐⭐ Fácil</td><td style="width: 7.62631%;">✅ Activa</td><td style="width: 7.98379%;">✅ Personalizables</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">✅ Gratis (OSS) / pago</td><td style="width: 7.50715%;">GitHub, GitLab, Jira</td><td style="width: 8.10295%;">✅ Muy flexible</td><td style="width: 8.81792%;">✅ OWASP, PCI, etc.</td></tr><tr><td style="width: 8.46044%;">**Checkov**</td><td style="width: 5.12393%;">✅ Sí</td><td style="width: 8.34128%;">Infraestructura como código</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">IaC (Terraform, etc.)</td><td style="width: 6.79218%;">⭐⭐⭐⭐ Fácil</td><td style="width: 7.62631%;">✅ Activa (Bridgecrew)</td><td style="width: 7.98379%;">✅ CLI/JSON</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">✅ Gratis (OSS)</td><td style="width: 7.50715%;">GitHub, GitLab, Terraform</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 8.81792%;">✅ CIS, NIST</td></tr><tr><td style="width: 8.46044%;">**Snyk**</td><td style="width: 5.12393%;">❌ (pero tiene CLI OSS)</td><td style="width: 8.34128%;">Código, IaC, dependencias</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">SAST, SCA, IaC</td><td style="width: 6.79218%;">⭐⭐⭐⭐ Fácil</td><td style="width: 7.62631%;">✅ Comercial y activa</td><td style="width: 7.98379%;">✅ Excelente GUI/CLI</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">❌ Pago (freemium)</td><td style="width: 7.50715%;">GitHub, GitLab, Jira</td><td style="width: 8.10295%;">✅ Sí (limitado OSS)</td><td style="width: 8.81792%;">✅ OWASP, NIST</td></tr><tr><td style="width: 8.46044%;">**Falco**</td><td style="width: 5.12393%;">✅ Sí</td><td style="width: 8.34128%;">Tiempo de ejecución (runtime)</td><td style="width: 8.10295%;">✅ Sí</td><td style="width: 7.38799%;">Runtime anomalies</td><td style="width: 6.79218%;">⭐⭐ Medio</td><td style="width: 7.62631%;">✅ CNCF, Sysdig</td><td style="width: 7.98379%;">Logs + alertas</td><td style="width: 7.98379%;">✅ Sí</td><td style="width: 7.62631%;">✅ Gratis (OSS)</td><td style="width: 7.50715%;">SIEM, Prometheus, etc.</td><td style="width: 8.10295%;">✅ Sí (reglas YAML)</td><td style="width: 8.81792%;">✅ CIS Benchmarks</td></tr></tbody></table>