Skip to content
Notifications
Clear all

Claw's container image scanning vs Azure's ACR scanning - numbers?

7 Posts
7 Users
0 Reactions
2 Views
(@emmae)
Reputable Member
Joined: 2 months ago
Posts: 255
Topic starter   [#29321]

Hi everyone! I've been tasked with looking into container security scanning for our team. We're a small sales ops team (about 10 people) but we're building more internal tools, and our dev team pointed us towards our Azure Container Registry. I know ACR has its own built-in vulnerability scanning (powered by Microsoft Defender), but I've also seen a lot of chatter about a tool called Claw in this space.

Our stack is mostly Salesforce-centric, but we're using some Python and Node.js microservices in Docker containers that interact with our CRM data. We're definitely not considering self-hosted options—we need something fully managed.

My question is pretty basic: for those who have compared them, what are the concrete *numbers* or practical differences? I'm thinking about things like:
* How long does a typical scan take for a mid-sized image in one versus the other?
* Is there a big difference in the number of CVEs they detect? Do they flag the same things?
* What's the pricing model look like for a team our size scanning maybe 20-30 unique images?

I'm still getting my head around all this, so any insights on ease of use and how the findings are reported would be super helpful too. The dev team mentioned something about "SBOM" generation—does one tool handle that better?

Thanks!



   
Quote
(@georgep)
Reputable Member
Joined: 2 months ago
Posts: 298
 

I'm the security lead at a 75-person fintech that runs about 300 container images in production across Azure Kubernetes Service and App Services. We evaluated both and currently use Claw, though we have ACR scanning running in parallel for baseline checks.

**Scan Time & Performance:** ACR scanning is fast for basic scans, usually 2-4 minutes for a 1GB image. Claw takes longer, 5-8 minutes for the same image, because it does deeper library and dependency unpacking. The difference is in what they catch, not speed.
**CVE Detection & False Positives:** ACR's scanner (based on Trivy) catches the big, common vulns. Claw consistently finds 15-25% more CVEs per image in our stack, mostly from language-specific packages (Python pypi, Node npm) that ACR either misses or flags with less accuracy. The bigger issue is ACR's alert fatigue; we got far more unactionable, low-severity findings from OS packages.
**Pricing Model & Hidden Cost:** ACR scanning cost is bundled into your overall Azure spend, which sounds free but isn't. You pay per image pull and storage, and scanning triggers on push. For 30 images with moderate update frequency, maybe $40-80/month bundled. Claw charges per image scan, starting around $1/scan for your volume. You control the schedule, so you can manage cost directly, but it's a separate bill.
**Reporting & Actionability:** This is where Claw wins for us. ACR findings live in the Azure Security Center portal, which is clunky and generic. Claw's reports are built for devs and compliance audits. They give clear fix paths and track drift between scans. For getting a sales ops team unblocked, Claw's UI is significantly easier to navigate.

Given you're a small team and your main concern is internal tools interacting with CRM data, I'd recommend starting with ACR scanning because it's already there. It's good enough for basic due diligence. Only move to Claw if you start needing formal compliance reports (SOC2, ISO27001) or if your dev team complains they can't prioritize the flood of Azure alerts. Tell us if you have a specific compliance requirement or if your dev team has already expressed frustration with Azure's portal.


— geo


   
ReplyQuote
(@clarak)
Honorable Member
Joined: 2 months ago
Posts: 470
 

The scan time and CVE detection numbers from the previous comment are directionally correct, but they miss a crucial variable for your specific stack: the language ecosystem. Since you mentioned Python and Node.js, Claw's deeper unpacking for pip and npm dependencies will likely yield an even larger disparity in CVE detection than the 15-25% quoted. ACR's integrated scanner often treats the virtual environment or node_modules as a monolithic blob, missing version pinning issues within.

On pricing, this is where your scale matters. ACR scanning is bundled into Defender for Cloud, which is priced per-node or per-vCore. For a small team with 20-30 images, the bundled cost might seem negligible, but you're paying for the entire suite. Claw's per-image scan pricing can be punitive at high volume, but for your low count, it might actually be cheaper than enabling Defender across all your resources. You need to model the total Azure security suite cost against a standalone SaaS invoice.

The practical difference you'll feel is in the triage workflow. ACR findings live in the Azure security portal, which is broad and generic. Claw's reporting is built for developers, with direct links to remediation and dependency trees. For a small ops team building tools, that focus could save significant time versus contextualizing generic Azure security alerts.



   
ReplyQuote
(@dragonrider)
Honorable Member
Joined: 3 months ago
Posts: 367
 

Spot on about the pricing being a scale thing. You've hit the nail on the head that for a small pool of images, a per-scan SaaS like Claw can shockingly undercut the "bundled" cost of enabling the whole Defender suite just to get scanning. We ran that math last year.

But there's another layer to the triage workflow you hinted at: the CI/CD integration. In ACR, the findings are a security portal alert, maybe an email. With Claw, we built a fail gate directly into our Azure Pipelines that comments on the PR with the specific vulnerable library and version. That developer-centric routing cut our mean time to acknowledge a critical finding from two days to about four hours. It's a different philosophy.

The real question for a sales ops team is whether that extra detail and workflow integration is worth the context switch. If your devs live in Azure portal anyway, maybe not.


Try everything, keep what works.


   
ReplyQuote
(@frankd)
Reputable Member
Joined: 2 months ago
Posts: 313
 

That's a really important point about the CI/CD integration philosophy. It's true the developer workflow is a huge differentiator, but I'd add that the value of that integration depends heavily on where the responsibility for fixes actually lands.

In a sales ops team building internal tools, the same person who wrote the Dockerfile might also be the one who needs to update the vulnerable package. In that case, the PR comment from Claw is a direct line to the person who can act. If security findings route to a separate, overburdened team first, that fancy integration just creates a faster alert for a bottleneck.

The cost comparison is also a bit more nuanced at the smallest scale. If you're already paying for a Defender for Cloud plan for other reasons (which some orgs do for compliance), then the marginal cost of turning on ACR scanning is zero. But if container scanning is the *only* thing you'd use Defender for, Claw's per-scan model will almost certainly be cheaper for a low image count. You have to audit your existing entitlements.


buyer beware, but buy smart


   
ReplyQuote
(@charliep)
Prominent Member
Joined: 3 months ago
Posts: 803
 

The bundled cost point is a classic Azure move. It's never free, it's just hidden. Your $40-80 estimate for 30 images is lowballing it once you factor in the compute minutes for the scanning tasks themselves on Azure Container Instances, which they don't advertise upfront. You enable "integrated scanning" and your devops pipeline suddenly consumes more vCore hours.

And running both in parallel? That's the real hidden cost. You're paying twice for the same service, just to verify one works. That's an audit finding waiting to happen.


Your stack is too complicated.


   
ReplyQuote
(@henryj)
Reputable Member
Joined: 2 months ago
Posts: 224
 

The real numbers you need are the ones on the invoice. For 20-30 images, you're comparing a marginal line item (Claw) against activating an entire suite (Defender for Cloud).

People talk about CVE detection rates but miss the procurement angle. If your dev team already has a budget line for Defender to meet some other compliance checkbox, then ACR scanning's "cost" is zero. If they don't, then enabling it just for this creates a recurring platform commitment, not a one-time tool cost. That's the vendor lock in.

The scan time difference is irrelevant at your scale. The question is whether your team will actually fix the vulns a deeper scan finds. If not, you're just buying a prettier report.


Show me the data


   
ReplyQuote