Free CLI + paid platform

ScanRook

Installed-state-first vulnerability scanning for containers, ISO images, and binaries.

Install Free Scanner

Run locally with no login required. Authenticate only for cloud enrichment and org workflows.

Install
curl -fsSL https://scanrook.sh/install | bash
Run a scan
scanrook scan ./artifact.tar --mode deep
Optional auth for cloud features
scanrook auth login --base https://scanrook.io

What You Get

  • Installed-state-first findings for containers and ISO artifacts.
  • Workflow timeline with stage-by-stage visibility.
  • Paginated findings, file tree, package explorer, and org API keys.

Learn SBOM Workflows

New to Software Bill of Materials workflows? Start with our technical guide on SBOM import, enrichment, and diff-based change monitoring.

Read: What Is an SBOM?