Verified against independent
leading scanners.
We ran a differential benchmark against two independent leading scanners, Grype (Anchore) and Trivy (Aqua Security), on the same real production inventory. Here is exactly what we found, and how.
of the fixable OS-package CVEs that Grype and Trivy both agree on, SentriKat detects. That is 818 consensus CVEs, on a real production inventory.
On a real production inventory, of the fixable OS-package CVEs that Grype (Anchore) and Trivy (Aqua Security), two independent leading scanners, both agree on, SentriKat detects 97.3% (818 consensus CVEs). And with less noise: no false alarms on distro backports already patched that the individual scanners still report.
What we measured, and why
Consensus, not a single tool
Every scanner has findings only it reports (Grype 12, Trivy 24 on this host). Those are individual noise. We measure against the CVEs on which two independent leading scanners both agree, so the number reflects real detection, not one tool's bias.
Actionable perimeter (fix available)
The comparison covers CVEs with a fix available. CVEs marked affected but with no fix (wont-fix or needs-triage, thousands on Ubuntu) are out of scope for every tool here, by construction. Coverage of that unfixed tail is on the roadmap via the Ubuntu CVE Tracker ingest.
Reference consensus, not ground truth
Grype and Trivy are the reference consensus we measure against, not an absolute source of truth. Each divergence is triaged against an authoritative source (NVD, OSV, the distribution tracker) before any number is published.
Fewer false positives on backports
Distributions frequently backport a fix into an older package version without changing the version string. A scanner that reads the version alone raises an alert that is already resolved. SentriKat follows the vendor advisory, so those already-patched backports do not become false alarms. On this inventory that is a measured reduction in noise, not a gap in detection.
Counting is the wrong metric. Here's the proof.
Recall against the consensus is one half of the story. The other half is what the raw counts actually look like. We pointed the same two scanners at a set of public AI-agent container images, pinned by digest. Two things stood out.
| Image (base) | Grype total | Trivy total | Grype OS crit+high | Trivy OS crit+high |
|---|---|---|---|---|
| Runtime A (Debian 12) | 4,872 | 9,454 | 1,630 | 2,351 |
| Runtime B (Ubuntu 22.04) | 1,160 | 4,961 | 6 | 360 |
Two respected scanners barely agree
On the identical bytes of Runtime B, Grype flagged 6 critical/high OS packages, Trivy flagged 360. A 60x spread. Counting gives you a near-random number.
Both buried the exploited ones
The two actively-exploited CVEs (git CVE-2025-48384, FreeType CVE-2025-27363) were present in every scan, drowned in the noise. The signal was there. Adjudication pulls it to the top.
Counting gives 10 alarms. Adjudicating gives the 2 that matter.
Of every CVE the raw scanners flagged, about 10 are on CISA's KEV list. Adjudicated: 7 are Linux-kernel bugs a container can't be attacked through (it borrows the host kernel, it never runs the one baked into the image), 1 is a situational HTTP/2 denial-of-service, and 2 are in userspace and reachable, the git and FreeType flaws. That's exactly what SentriKat surfaces.
Full transparency
The 2.7% that is not consensus is two small buckets, both in triage. We show them because a benchmark you cannot inspect is not a benchmark.
Almost all very fresh 2026 CVEs. This points to feed timing, not the matcher, so the number can only rise as the feed catches up.
CVEs not yet in our knowledge base. A coverage question we track against the feed broker for completeness.
Reproducible by design
Measured on 17 July 2026 on a real production inventory (Ubuntu 24.04), on the same host all scanners ran against, with a documented method. The metric is consensus recall on the fixable OS-package segment. Same inputs, same result.
- · Same inventory the SentriKat agent reported for that host.
- · Fixed-only perimeter for every tool, so no tool is credited for the unfixed tail.
- · Comparison on the CVE axis, robust to how each tool names packages.
- · Every divergence triaged against an authoritative source before publishing.
See it on your own inventory
Cloud or on-premises, launch pricing for founding customers. Run SentriKat next to the scanners you already trust and compare on your real environment.
Get started