# Best Vulnerability Scanner Software

## How Many Vulnerability Scanner Software Products Does G2 Track?

**Total Products under this Category:** 223

### Category Stats (Jul 2026)

- **Average Rating:** 4.58/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+1.29%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: July 31, 2026_

## How Does G2 Rank Vulnerability Scanner Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 7,700+ Authentic Reviews
- 223+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Vulnerability Scanner Software
 ![G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence](https://www.g2.com/categories/vulnerability-scanner/grids.png?focus%5B%5D=146504&focus%5B%5D=1259627&focus%5B%5D=123609&focus%5B%5D=32494&focus%5B%5D=151443&focus%5B%5D=154599&focus%5B%5D=27706&focus%5B%5D=20460)

Highlighted products: Wiz, Aikido Security, Orca Security, Tenable Nessus, CrowdStrike Falcon Cloud Security, Astra Pentest, Intruder, and Sysdig Secure.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=orca-security&focus%5B%5D=tenable-nessus&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=sysdig-sysdig-secure)

### [Wiz](https://www.g2.com/products/wiz-wiz/reviews)

Wiz transforms cloud security for customers – including more than 50% of the Fortune 100 – by enabling a new operating model. With Wiz, organizations can democratize security across the development lifecycle, empowering them to build fast and securely. Its Cloud Native Application Protection Platform (CNAPP) consolidates CSPM, KSPM, CWPP, Vulnerability management, IaC scanning, CIEM, DSPM into a single platform. Wiz drives visibility, risk prioritization, and business agility. Protecting Your Cloud Environments Requires a Unified, Cloud Native Platform. Wiz connects to every cloud environment, scans every layer, and covers every aspect of your cloud security - including elements that normally require installing agents. Its comprehensive approach has all of these cloud security solutions built in. Hundreds of organizations worldwide, including 50 percent of the Fortune 100, to rapidly identify and remove critical risks in cloud environments. Its customers include Salesforce, Slack, Mars, BMW, Avery Dennison, Priceline, Cushman & Wakefield, DocuSign, Plaid, and Agoda, among others. Wiz is backed by Sequoia, Index Ventures, Insight Partners, Salesforce, Blackstone, Advent, Greenoaks, Lightspeed and Aglaé. Visit https://www.wiz.io for more information.

**Average Rating:** 4.7/5.0

**Total Reviews:** 834

#### How Do G2 Users Rate Wiz?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.8/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.8/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Wiz?

- **Seller:** [Wiz](https://www.g2.com/sellers/wiz-76a0133b-42e5-454e-b5da-860e503471db)
- **Company Website:** www.wiz.io
- **Year Founded:** 2020
- **HQ Location:** New York, US
- **Twitter:** @wiz\_io  
24,733 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fc8f5e9bf3787dc70dd506314d2a37e0cc0ea32fb3ecf53e678c506b7e53eff0&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fwizsecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,383 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CISO, Security Engineer
- **Top Industries:** Financial Services, Computer Software
- **Company Size:** 54% Large, 39% Medium

#### What Do G2 Reviewers Say About Wiz?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **capable APIs and user-friendly UI** , providing valuable insights and continuous improvements in security features.
- Users value the **unmatched security features** of Wiz, providing comprehensive visibility and proactive threat management capabilities.
- Users find Wiz's product suite **extremely easy to use** , benefiting from seamless integration and a user-friendly interface.
- Users appreciate the **visibility** Wiz offers, enhancing security posture and prioritizing critical vulnerabilities effectively.
- Users praise the **easy setup** of Wiz, enabling quick deployment and seamless integration across modules for enhanced security.

##### Cons

- Users experience a **steep learning curve** with Wiz, making it challenging for newcomers to fully utilize the platform.
- Users find the **feature limitations** of Wiz, such as complex reporting and management, hinder user-friendliness and efficiency.
- Users highlight the need for **improvement in performance and reporting capabilities** to enhance overall usability of Wiz.
- Users note several **improvements needed** , particularly in dashboard reporting and the complexity of the pricing model.
- Users find the **complexity of the interface** overwhelming initially, requiring time to adapt and learn effectively.

#### What Are Recent G2 Reviews of Wiz?

**["Unmatched Security Insights, Excellent Reporting, and Strong Post-Sales Support"](https://www.g2.com/survey_responses/wiz-review-13153618)**

**Rating:** 5.0/5.0 stars

_— Alastair J._

[Read full review](https://www.g2.com/survey_responses/wiz-review-13153618)

**["Excellent Cloud Risk Visibility and Fast Insights with Wiz"](https://www.g2.com/survey_responses/wiz-review-12964571)**

**Rating:** 4.5/5.0 stars

_— Ruben F._

[Read full review](https://www.g2.com/survey_responses/wiz-review-12964571)

### [Aikido Security](https://www.g2.com/products/aikido-security/reviews)

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 251

#### How Do G2 Users Rate Aikido Security?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.0/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.1/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Aikido Security?

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
- Users praise Aikido Security for its **fast and user-friendly identification of security issues** in codebases, enhancing development practices.
- Users appreciate the **robust features of Aikido Security** , valuing its usability and effectiveness in enhancing security workflows.
- Users value the **easy integrations** with GitLab, allowing for quick start and effective tracking of security issues.
- Users commend the **easy setup** of Aikido Security, simplifying integration and enhancing their security workflow significantly.

##### Cons

- Users note the **missing features** in Aikido Security, wishing for more integration and advanced configuration options.
- Users find the **pricing excessive** , particularly for startups, despite acknowledging the product's value.
- Users find Aikido Security has **limited features** , particularly in advanced customization and reporting for complex environments.
- Users find the **entry-level pricing** of Aikido Security too high for startups, limiting adoption and experimentation.
- Users are frustrated by the **lack of features** , especially with local scanning and branch handling limitations.

#### What Are Recent G2 Reviews of Aikido Security?

**["Enterprise Security Without an Enterprise Security Team"](https://www.g2.com/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13108704)

**["Seamless GitHub Integration with Solid Security Findings and Smart False-Positive Analysis"](https://www.g2.com/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13109689)

### [Orca Security](https://www.g2.com/products/orca-security/reviews)

The Orca Cloud Security Platform identifies, prioritizes, and remediates risks and compliance issues in workloads, configurations, and identities across your cloud estate spanning AWS, Azure, Google Cloud, Kubernetes, Alibaba Cloud, and Oracle Cloud. Orca offers the industry’s most comprehensive cloud security solution in a single platform — eliminating the need to deploy and maintain multiple point solutions. Orca is agentless-first, and connects to your environment in minutes using Orca’s patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca can integrate with third-party agents for runtime visibility and protection for critical workloads. Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation – reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes. As a Cloud Native Application Protection Platform (CNAPP), Orca consolidates many point solutions in one platform, including: CSPM, CWPP, CIEM, Vulnerability Management, Container and Kubernetes Security, DSPM, API Security, CDR, Multi-cloud Compliance, Shift Left Security, and AI-SPM.

**Average Rating:** 4.7/5.0

**Total Reviews:** 312

#### How Do G2 Users Rate Orca Security?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.8/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.2/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.7/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Orca Security?

- **Seller:** [Orca Security](https://www.g2.com/sellers/orca-security)
- **Company Website:** orca.security
- **Year Founded:** 2019
- **HQ Location:** Portland, Oregon
- **Twitter:** @orcasec  
4,835 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=748783d01ede7f6257a73c5b241286a1a578863351af7d43122bbc25f576192b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F35573984%2F&secure%5Burl_type%5D=linkedin_company_website)  
515 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer, CISO
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 53% Large, 36% Medium

#### What Do G2 Reviewers Say About Orca Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise the **ease of use** of Orca Security, appreciating its intuitive interface and quick setup process.
- Users value the **visibility and prioritization** of vulnerabilities provided by Orca Security, enhancing their cloud security posture.
- Users praise Orca Security for its **agentless features** , intuitive interface, and effective compliance and security modules.
- Users value the **exceptional visibility** provided by Orca Security, enhancing insight into their cloud environment effortlessly.
- Users value the **comprehensive security** features of Orca Security, enhancing visibility and ease of implementation across cloud environments.

##### Cons

- Users note that Orca Security has **security vulnerabilities** , particularly regarding API security and vulnerable package detection.
- Users experience **dashboard issues** like cluttered information and slow performance, leading to navigation challenges and bugs.
- Users experience **delayed detection** with Orca Security due to slow scans and accumulated issues affecting troubleshooting efficiency.
- Users report frequent **false positives** in Orca Security, causing confusion over actual vulnerabilities in their systems.
- Users note that **improvement is needed** in reporting, automation, and granularity for a better Orca Security experience.

#### What Are Recent G2 Reviews of Orca Security?

**["Orca’s Attack Path View Transformed How We Prioritize Fixes"](https://www.g2.com/survey_responses/orca-security-review-13183653)**

**Rating:** 5.0/5.0 stars

_— Cathrine S._

[Read full review](https://www.g2.com/survey_responses/orca-security-review-13183653)

**["Orca Uncovered Hidden Malware and Suspicious Workflows Our Other Tools Missed"](https://www.g2.com/survey_responses/orca-security-review-13182617)**

**Rating:** 5.0/5.0 stars

_— Kishore K._

[Read full review](https://www.g2.com/survey_responses/orca-security-review-13182617)

#### What Are G2 Users Discussing About Orca Security?

- [Where is Orca security based?](https://www.g2.com/discussions/where-is-orca-security-based) - 2 comments
- [How much does Orca security cost?](https://www.g2.com/discussions/how-much-does-orca-security-cost) - 1 comment
- [What is ORCA platform?](https://www.g2.com/discussions/what-is-orca-platform) - 1 comment
- [What does Orca Security do?](https://www.g2.com/discussions/what-does-orca-security-do) - 1 comment

### [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews)

Built for security practitioners, by security professionals, Nessus products by Tenable are the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to help security professionals quickly and easily identify and fix vulnerabilities, including software flaws, missing patches, malware, and misconfigurations - across a variety of operating systems, devices, and applications. With features such as pre-built policies and templates, customizable reporting, group “snooze” functionality, and real-time updates, Nessus is designed to make vulnerability assessment simple, easy, and intuitive. The result: less time and effort to assess, prioritize, and remediate issues.

**Average Rating:** 4.5/5.0

**Total Reviews:** 290

#### How Do G2 Users Rate Tenable Nessus?

- **Has the product been a good partner in doing business?:** 8.7/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.9/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.4/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Tenable Nessus?

- **Seller:** [Tenable](https://www.g2.com/sellers/tenable)
- **Company Website:** www.tenable.com
- **HQ Location:** Columbia, MD
- **Twitter:** @TenableSecurity  
87,752 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=029266d223c06e6b09e6d209209f15aad3bbad59d05069b38d5ec2757e74adef&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F25452%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,350 employees on LinkedIn®
- **Ownership:** NASDAQ: TENB

#### Who Uses This Product?

- **Who Uses This:** Security Engineer, Network Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 40% Medium, 34% Large

#### What Do G2 Reviewers Say About Tenable Nessus?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **vulnerability identification** capabilities of Tenable Nessus, highlighting its accuracy and comprehensive coverage for security management.
- Users value the **advanced vulnerability detection** capabilities of Tenable Nessus, enhancing their security risk management effectively.
- Users value the **ease of use** of Tenable Nessus, appreciating its simple setup and user-friendly interface.
- Users value the **automated scanning** capabilities of Tenable Nessus, benefiting from its comprehensive and up-to-date vulnerability checks.
- Users commend the **comprehensive scanning capabilities** of Tenable Nessus, alongside its robust reporting and automation features.

##### Cons

- Users note the **slow scanning** process, especially in large environments, significantly impacting resource usage and production times.
- Users find the **cost of running and maintaining Tenable Nessus** to be extensively high and burdensome.
- Users find **limited features** in Tenable Nessus, including restrictions on hosts, scans, and mobile application testing.
- Users find the **complexity** of Tenable Nessus challenging, especially with advanced features requiring significant technical knowledge.
- Users report that Nessus generates **false positives** , resulting in extra workload and hindering effective security management.

#### What Are Recent G2 Reviews of Tenable Nessus?

**["Self-Contained Nessus Scanning with Full Control in Offline Environments"](https://www.g2.com/survey_responses/tenable-nessus-review-12937668)**

**Rating:** 4.0/5.0 stars

_— Verified User in Higher Education_

[Read full review](https://www.g2.com/survey_responses/tenable-nessus-review-12937668)

**["Reliable and Efficient Vulnerability Management Tool"](https://www.g2.com/survey_responses/tenable-nessus-review-12989192)**

**Rating:** 5.0/5.0 stars

_— Mohsin H._

[Read full review](https://www.g2.com/survey_responses/tenable-nessus-review-12989192)

#### What Are G2 Users Discussing About Tenable Nessus?

- [What is Nessus used for?](https://www.g2.com/discussions/what-is-nessus-used-for) - 1 comment
- [What types of vulnerabilities are scanned by Nessus?](https://www.g2.com/discussions/what-types-of-vulnerabilities-are-scanned-by-nessus)
- [Is there a free version of Nessus?](https://www.g2.com/discussions/is-there-a-free-version-of-nessus) - 2 comments
- [What is an advantage of using Nessus?](https://www.g2.com/discussions/what-is-an-advantage-of-using-nessus)
- [What does Nessus scan for?](https://www.g2.com/discussions/what-does-nessus-scan-for) - 1 comment

### [CrowdStrike Falcon Cloud Security](https://www.g2.com/products/crowdstrike-falcon-cloud-security/reviews)

Crowdstrike Falcon Cloud Security is the only CNAPP to stop breaches in the cloud Built for today’s hybrid and multi-cloud environments, Falcon Cloud Security protects the entire cloud attack surface - from code to runtime - by combining continuous agentless visibility with real-time detection and response. At runtime, Falcon Cloud Security delivers best-in-class cloud workload protection and real-time cloud detection and response (CDR) to stop active threats across hybrid environments. Integrated with the CrowdStrike Falcon platform, it correlates signals across endpoint, identity, and cloud to detect sophisticated cross-domain attacks that point solutions miss—enabling teams to respond faster and stop breaches in progress. To reduce risk before attacks occur, Falcon Cloud Security also delivers agentless-driven posture management that proactively shrinks the cloud attack surface. Unlike typical solutions, Crowdstrike enriches cloud risk detections with adversary intelligence and graph-based context, enabling security teams to prioritize exploitable exposures and prevent breaches before they happen. Customers using Falcon Cloud Security consistently see measurable results: 89% faster cloud detection and response 100x reduction in false positives by prioritizing exploitable, business-critical risk 83% reduction in cloud security licenses due to elimination of redundant tools

**Average Rating:** 4.5/5.0

**Total Reviews:** 157

#### How Do G2 Users Rate CrowdStrike Falcon Cloud Security?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.0/10 (Category avg: 8.9/10)
- **Automated Scans:** 10.0/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.9/10 (Category avg: 8.5/10)

#### Who Is the Company Behind CrowdStrike Falcon Cloud Security?

- **Seller:** [CrowdStrike](https://www.g2.com/sellers/crowdstrike)
- **Company Website:** www.crowdstrike.com
- **Year Founded:** 2011
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @CrowdStrike  
110,809 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f13dce0bc1628ccb762ed9d5acb4e0f0998a717639b903c3d3a271ef1da6ad7b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2497653%2F&secure%5Burl_type%5D=linkedin_company_website)  
11,343 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 54% Large, 32% Medium

#### What Do G2 Reviewers Say About CrowdStrike Falcon Cloud Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **complete protection** from code to cloud offered by CrowdStrike Falcon Cloud Security, enhancing security efficiently.
- Users appreciate the **strong security and compliance features** of CrowdStrike Falcon Cloud Security, enhancing visibility and threat intelligence.
- Users commend the **detection efficiency** of CrowdStrike Falcon Cloud Security, ensuring robust protection with minimal false positives.
- Users value the **complete protection and efficient vulnerability detection** offered by CrowdStrike Falcon Cloud Security for all organization sizes.
- Users appreciate the **user-friendly interface** of CrowdStrike Falcon Cloud Security, making it easy to navigate and investigate alerts.

##### Cons

- Users note that the pricing of CrowdStrike Falcon Cloud Security is **expensive** , making it hard for smaller organizations to afford.
- Users suggest that **improvements are needed** for better uptime and user experience in CrowdStrike Falcon Cloud Security.
- Users note that **improvement is needed** in uptime and user experience during enrollment for CrowdStrike Falcon Cloud Security.
- Users find the **feature complexity** of CrowdStrike Falcon Cloud Security overwhelming, requiring a significant learning curve to navigate.
- Users face a **steep learning curve** with CrowdStrike Falcon Cloud Security, complicating the onboarding process for new users.

#### What Are Recent G2 Reviews of CrowdStrike Falcon Cloud Security?

**["Real-Time Cloud Protection with eBPF and Unified Telemetry"](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13173504)**

**Rating:** 4.0/5.0 stars

_— Aswindev P._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13173504)

**["CrowdStrike Falcon Cloud Security: Unified Console and Smart Prioritization That Keeps Us Focused"](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13138386)**

**Rating:** 4.0/5.0 stars

_— Tamanna T._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13138386)

### [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews)

Astra Security is a leading continuous penetration testing platform that combines AI-powered autonomous pentesting with certified expert-led assessments. Powered by Attack AI, trained on 6.8M+ security findings and insights from 5,000+ real-world pentests. Astra deploys intelligent agents that continuously discover, validate, prioritize, and help remediate vulnerabilities at scale. While AI handles speed and scale, Astra’s certified security experts focus on what automation alone cannot: complex business logic flaws, multi-step attack chains, advanced exploit paths, and emerging AI/LLM-specific threats. Built for modern engineering teams, Astra integrates directly into CI/CD workflows, enabling continuous security validation between releases instead of relying on outdated annual pentests. The platform delivers comprehensive Autonomous Pentest powered by AI agents, DAST vulnerability scanner and human-driven pentests across web apps, AI/LLMs, mobile apps, APIs, cloud infrastructure. Astra is CREST-accredited, CERT-IN empaneled, and a PCI ASV-certified vendor. Our team also led the development of the OWASP APTS framework, helping shape the industry standard for continuous security testing. Today, 1,500+ organizations across 70+ countries trust Astra Security, including Ford, Loom, CompTIA, Hitachi, HackerRank, and OLX.

**Average Rating:** 4.6/5.0

**Total Reviews:** 220

#### How Do G2 Users Rate Astra Pentest?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.8/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.9/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.7/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Astra Pentest?

- **Seller:** [ASTRA IT, Inc.](https://www.g2.com/sellers/astra-it-inc)
- **Company Website:** www.getastra.com
- **Year Founded:** 2018
- **HQ Location:** New Delhi, IN
- **Twitter:** @getastra  
694 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fbe109060085ad9c09016ddbb00bd4f363004bed188f1fd0e5a11ea004d08c89&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fgetastra%2F&secure%5Burl_type%5D=linkedin_company_website)  
130 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CTO, CEO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 67% Small, 28% Medium

#### What Do G2 Reviewers Say About Astra Pentest?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **responsive customer support** of Astra Pentest, enhancing their experience and ensuring smooth collaboration.
- Users value the **comprehensive vulnerability management features** of Astra Pentest, enhancing their ability to address security issues effectively.
- Users love the **ease of use** of Astra Pentest, appreciating its intuitive design and accessible features.
- Users commend Astra Pentest for its **efficient penetration testing** , enabling swift execution and effective communication throughout the process.
- Users value the **thorough vulnerability identification** of Astra Pentest, enhancing confidence and security in their development processes.

##### Cons

- Users experience **poor customer support** , citing slow responses and difficulties with account setup and vulnerability inquiries.
- Users find the **poor interface design** of Astra Pentest to be clunky and not user-friendly, affecting usability.
- Users experience **slow performance** with Astra Pentest, affecting testing speed and response times for results.
- Users feel that the **UX could be improved** for a smoother experience, as navigation can sometimes be confusing.
- Users face a **lack of information** with Astra Pentest, as documentation and updates are often insufficient or slow to arrive.

#### What Are Recent G2 Reviews of Astra Pentest?

**["Smooth Onboarding, Responsive Support, and Strong Pentest Lifecycle Controls"](https://www.g2.com/survey_responses/astra-pentest-review-13001206)**

**Rating:** 5.0/5.0 stars

_— Sivakumar S._

[Read full review](https://www.g2.com/survey_responses/astra-pentest-review-13001206)

**["Exceptional VAPT Solution with Prompt Support"](https://www.g2.com/survey_responses/astra-pentest-review-9603864)**

**Rating:** 5.0/5.0 stars

_— Nikhil Ajit S._

[Read full review](https://www.g2.com/survey_responses/astra-pentest-review-9603864)

#### What Are G2 Users Discussing About Astra Pentest?

- [What is Astra Pentest used for?](https://www.g2.com/discussions/what-is-astra-pentest-used-for) - 2 comments

### [Intruder](https://www.g2.com/products/intruder/reviews)

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

**Average Rating:** 4.8/5.0

**Total Reviews:** 209

#### How Do G2 Users Rate Intruder?

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.3/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.5/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.5/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Intruder?

- **Seller:** [Intruder](https://www.g2.com/sellers/intruder)
- **Company Website:** www.intruder.io
- **Year Founded:** 2015
- **HQ Location:** London
- **Twitter:** @intruder\_io  
979 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f067752387faaf8e51f29bfa65216c4d098142c0465fc0e1e9614d24e55d97f8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F6443623%2F&secure%5Burl_type%5D=linkedin_company_website)  
83 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CTO, Director
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 57% Small, 36% Medium

#### What Do G2 Reviewers Say About Intruder?

_AI-generated summary from verified user reviews_

##### Pros

- Users find the **ease of use** of Intruder perfect for configuring and scanning cloud resources efficiently.
- Users appreciate the **easy configuration of vulnerability detection** , making it simple to secure cloud resources efficiently.
- Users value the **exceptional customer support** from Intruder, highlighting quick responses and friendliness during their experience.
- Users value Intruder's **easy-to-use interface** and seamless integration, enhancing their cybersecurity management experience significantly.
- Users value the **easy configuration** of Intruder, allowing timely identification of vulnerabilities across cloud resources.

##### Cons

- Users find the service to be **expensive** , suggesting improvements in pricing models for better value.
- Users report **slow scanning** as Intruder misses some vulnerabilities and lacks integration with comprehensive testing tools.
- Users struggle with the **licensing model** of Intruder, finding it complex and not immediately intuitive.
- Users experience **false positives** from Intruder, leading to confusion between critical and lower-risk vulnerabilities.
- Users find the **limited features** of Intruder frustrating, especially regarding reporting flexibility and license understanding.

#### What Are Recent G2 Reviews of Intruder?

**["Reliable Service with Flexible Plans and Strong Support"](https://www.g2.com/survey_responses/intruder-review-13110046)**

**Rating:** 4.0/5.0 stars

_— Ossama M._

[Read full review](https://www.g2.com/survey_responses/intruder-review-13110046)

**["Revolutionized Our Vulnerability Management with Real-Time Insights"](https://www.g2.com/survey_responses/intruder-review-13100568)**

**Rating:** 4.5/5.0 stars

_— Verified User_

[Read full review](https://www.g2.com/survey_responses/intruder-review-13100568)

#### What Are G2 Users Discussing About Intruder?

- [Who developed intruder?](https://www.g2.com/discussions/who-developed-intruder)
- [What is an intruder in cyber security?](https://www.g2.com/discussions/what-is-an-intruder-in-cyber-security)
- [Is intruder IO safe?](https://www.g2.com/discussions/is-intruder-io-safe) - 1 comment
- [What is intruder software?](https://www.g2.com/discussions/what-is-intruder-software) - 1 comment

### [Sysdig Secure](https://www.g2.com/products/sysdig-sysdig-secure/reviews)

Sysdig Secure is the real-time cloud-native application protection platform (CNAPP) trusted by organizations of all sizes around the world.. Built by the creators of Falco and Wireshark, Sysdig uniquely delivers runtime-powered visibility and agentic AI to stop cloud attacks instantly, not after the damage is done. With Sysdig, you can: - Stop threats in 2 seconds and respond in minutes - Cut vulnerability noise by 95% with runtime prioritization - Detect real risk instantly across workloads, identities, and misconfigurations - Close permissions gaps in under 2 minutes Sysdig Secure consolidates CSPM, CWPP, CIEM, vulnerability management, and threat detection into a single open, real-time platform. Unlike other CNAPPs, Sysdig connects signals across runtime, identity, and posture to eliminate blind spots, reduce tool sprawl, and accelerate innovation without compromise. No guesswork. No black boxes. Just cloud security, the right way. Learn more at https://sysdig.com

**Average Rating:** 4.8/5.0

**Total Reviews:** 110

#### How Do G2 Users Rate Sysdig Secure?

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.5/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.5/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.5/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Sysdig Secure?

- **Seller:** [Sysdig](https://www.g2.com/sellers/sysdig-715eaed9-9743-4f27-bd2b-d3730923ac3e)
- **Company Website:** www.sysdig.com
- **Year Founded:** 2013
- **HQ Location:** San Francisco, California
- **Twitter:** @Sysdig  
10,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e5c0f852b6c0be7154c4d09c247c33d5e88c069b4300bc23e43c3141120836ba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F3592486%2F&secure%5Burl_type%5D=linkedin_company_website)  
609 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 47% Large, 40% Medium

#### What Do G2 Reviewers Say About Sysdig Secure?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Sysdig Secure for its **runtime threat detection** and comprehensive scanning capabilities across diverse environments.
- Users value the **extensive vulnerability detection** of Sysdig Secure, enabling them to effectively manage cloud security risks.
- Users value the **real-time threat detection** and extensive scanning features of Sysdig Secure for enhanced security.
- Users value the **runtime threat detection and extensive scanning** capabilities of Sysdig Secure, enhancing their cloud security efforts.
- Users value the **comprehensive visibility** provided by Sysdig Secure, enhancing security and compliance across environments.

##### Cons

- Users note **feature limitations** in Sysdig Secure, particularly with UI quirks and incomplete functionalities such as agentless scanning.
- Users find the **complexity during initial setup** of Sysdig Secure to be challenging for those lacking technical knowledge.
- Users note **missing features** like runtime detection and logging, which limit capabilities in Sysdig Secure.
- Users find the **difficult learning curve** of Sysdig Secure challenging, especially during initial setup and configuration.
- Users find Sysdig Secure's **feature complexity** overwhelming, hindering ease of use and quick threat response.

#### What Are Recent G2 Reviews of Sysdig Secure?

**["Excellent Real-Time Kubernetes Security Visibility and Threat Detection"](https://www.g2.com/survey_responses/sysdig-secure-review-12711991)**

**Rating:** 5.0/5.0 stars

_— Syed Shahid A._

[Read full review](https://www.g2.com/survey_responses/sysdig-secure-review-12711991)

**["Next-Level Threat Detection: Bridging Runtime Security with Compliance Excellence"](https://www.g2.com/survey_responses/sysdig-secure-review-10601664)**

**Rating:** 5.0/5.0 stars

_— Anil Z._

[Read full review](https://www.g2.com/survey_responses/sysdig-secure-review-10601664)

#### What Are G2 Users Discussing About Sysdig Secure?

- [What does Sysdig Platform do?](https://www.g2.com/discussions/what-does-sysdig-platform-do)
- [What Sysdig secure?](https://www.g2.com/discussions/what-sysdig-secure)
- [Is Sysdig free?](https://www.g2.com/discussions/is-sysdig-free) - 1 comment
- [What is Sysdig used for?](https://www.g2.com/discussions/what-is-sysdig-used-for) - 1 comment

### [Burp Suite](https://www.g2.com/products/burp-suite/reviews)

Burp Suite is a complete ecosystem for web application and API security testing, combining two products: Burp Suite DAST - a best-of-breed, precision DAST solution that automates runtime testing, and Burp Suite Professional - the industry-standard toolkit for manual penetration testing. Developed by PortSwigger, more than 85,000 security professionals rely on Burp Suite to find, verify, and understand vulnerabilities across complex modern web applications. Burp Suite DAST is PortSwigger’s enterprise dynamic application security testing (DAST) solution, purpose-built for continuous, automated scanning of web applications and APIs. Unlike many DAST solutions, which are part of a wider AST offering, Burp Suite DAST is not a bolt-on tool - instead it’s precision-built from over 20 years of dynamic testing experience. Burp Suite DAST reveals the runtime issues that static analysis tools miss, such as authentication flaws, configuration drift, and chained vulnerabilities. Built on the same proprietary scanning engine that powers Burp Suite Professional, it delivers precise, low-noise results that security teams trust. Key capabilities of Burp Suite DAST include: Continuous, automated scanning of web applications and APIs, integration with CI/CD pipelines and vulnerability management tools, flexible deployment across cloud, and on-premise environments, shared scanning logic and configurations between automated and manual testing, accurate, low-noise detection informed by PortSwigger Research. Burp Suite Professional complements DAST with deep manual testing capability. It’s the industry-standard toolkit for penetration testers, consultants, and AppSec engineers who need complete insight and flexibility when validating or exploring vulnerabilities. Findings discovered by DAST can be investigated and verified in Burp Suite Professional, ensuring every result is accurate, contextual, and actionable. Together, Burp Suite DAST and Burp Suite Professional create a unified ecosystem that delivers automation at breadth and manual depth where it counts. Burp Suite is built for AppSec teams who need scalable, trustworthy coverage across web and API environments, enabling a seamless handoff between automated and manual testing.

**Average Rating:** 4.8/5.0

**Total Reviews:** 126

#### How Do G2 Users Rate Burp Suite?

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.6/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.6/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.0/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Burp Suite?

- **Seller:** [PortSwigger](https://www.g2.com/sellers/portswigger)
- **Company Website:** www.portswigger.net
- **Year Founded:** 2008
- **HQ Location:** Knutsford, GB
- **Twitter:** @Burp\_Suite  
138,186 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=89be7395b22b93d4e5529122592390dc29238f493eef5dbfe060e81d512f33b1&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fportswigger-web-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
345 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Cyber Security Analyst
- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 41% Medium, 31% Small

#### What Do G2 Reviewers Say About Burp Suite?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Burp Suite, enabling quick setup for both beginners and advanced professionals.
- Users appreciate the **user-friendly interface** of Burp Suite, making penetration testing straightforward and accessible for all levels.
- Users value the **deep automation and manual testing capabilities** of Burp Suite for effective web and Android security testing.
- Users admire the **user-friendly interface** and seamless integration of Burp Suite, enhancing both navigation and testing efficiency.
- Users love the **clear interface** of Burp Suite, enabling effortless traffic interception and easy navigation.

##### Cons

- Users find Burp Suite **expensive** , especially students, limiting accessibility to its powerful features and community support.
- Users report **slow performance** with Burp Suite, particularly on low-spec systems and during resource-intensive scans.
- Users find the **steep learning curve** of Burp Suite challenging, especially for beginners navigating its complex features.
- Users struggle with the **steep learning curve** of Burp Suite, finding it challenging, especially for beginners.
- Users find the **limited customization options** in Burp Suite restrict their ability to tailor the tool to their needs.

#### What Are Recent G2 Reviews of Burp Suite?

**["Complete Control Over Web Requests with Burp Suite"](https://www.g2.com/survey_responses/burp-suite-review-12677559)**

**Rating:** 5.0/5.0 stars

_— Arish B._

[Read full review](https://www.g2.com/survey_responses/burp-suite-review-12677559)

**["Burp Suite Pro: A Powerful, All-in-One Platform for Web App Pen Testing"](https://www.g2.com/survey_responses/burp-suite-review-12818180)**

**Rating:** 4.5/5.0 stars

_— Aryan S._

[Read full review](https://www.g2.com/survey_responses/burp-suite-review-12818180)

#### What Are G2 Users Discussing About Burp Suite?

- [What are the benefits and challenges of using BurpSuite for web application security?](https://www.g2.com/discussions/what-are-the-benefits-and-challenges-of-using-burpsuite-for-web-application-security)
- [What is BurpSuite used for?](https://www.g2.com/discussions/burpsuite-what-is-burpsuite-used-for)
- [What types of vulnerabilities can Burp Suite detect?](https://www.g2.com/discussions/what-types-of-vulnerabilities-can-burp-suite-detect)
- [What is Burp Suite Professional?](https://www.g2.com/discussions/what-is-burp-suite-professional) - 1 comment
- [Is BurpSuite free?](https://www.g2.com/discussions/is-burpsuite-free) - 2 comments

### [Amazon Inspector](https://www.g2.com/products/amazon-inspector/reviews)

Amazon Inspector is an automated vulnerability management service that continuously scans AWS workloads—including Amazon EC2 instances, container images in Amazon ECR, AWS Lambda functions, and code repositories—for software vulnerabilities and unintended network exposure. By integrating seamlessly with AWS environments, it provides real-time detection and prioritization of security issues, enabling organizations to enhance their security posture efficiently. Key Features and Functionality: - Automated Discovery and Continuous Scanning: Automatically identifies and assesses AWS resources for vulnerabilities and network exposures, ensuring comprehensive coverage without manual intervention. - Contextualized Risk Scoring: Generates risk scores by correlating vulnerability data with environmental factors such as network accessibility and exploitability, aiding in the prioritization of remediation efforts. - Integration with AWS Services: Seamlessly integrates with AWS Security Hub and Amazon EventBridge, facilitating automated workflows and centralized management of security findings. - Support for Multiple Resource Types: Extends vulnerability management to various AWS services, including EC2 instances, container images, Lambda functions, and code repositories, providing a unified security assessment across the cloud environment. - Agentless Scanning for EC2 Instances: Offers continuous monitoring of EC2 instances for software vulnerabilities without the need for installing additional agents, simplifying deployment and maintenance. Primary Value and Problem Solved: Amazon Inspector addresses the critical need for continuous and automated vulnerability management within AWS environments. By providing real-time detection and prioritization of security issues, it enables organizations to proactively identify and remediate vulnerabilities, reducing the risk of security breaches and ensuring compliance with industry standards. Its integration with existing AWS services and support for various resource types streamline security operations, allowing teams to focus on strategic initiatives while maintaining a robust security posture.

**Average Rating:** 4.4/5.0

**Total Reviews:** 25

#### How Do G2 Users Rate Amazon Inspector?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.2/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.2/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 7.8/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Amazon Inspector?

- **Seller:** [Amazon Web Services (AWS)](https://www.g2.com/sellers/amazon-web-services-aws-3e93cc28-2e9b-4961-b258-c6ce0feec7dd)
- **Year Founded:** 2006
- **HQ Location:** Seattle, WA
- **Twitter:** @awscloud  
2,232,483 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=072881eee28a2afe24f8d1bda9f20e3e146b9fb4b214f216411ce2ed6898b31e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Famazon-web-services%2F&secure%5Burl_type%5D=linkedin_company_website)  
147,094 employees on LinkedIn®
- **Ownership:** NASDAQ: AMZN

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 41% Small, 33% Medium

#### What Do G2 Reviewers Say About Amazon Inspector?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **robust security features** of Amazon Inspector, enhancing their cloud environment's safety and compliance.
- Users commend the **excellent customer support** from AWS, which enhances their experience with Amazon Inspector.
- Users value the **centralized management** of Amazon Inspector, enhancing visibility and compliance while simplifying security monitoring.
- Users value the **collaborative tools** of Amazon Inspector, enhancing monitoring and compliance through integrated resources and support.
- Users appreciate the **automated security issue detection** of Amazon Inspector, making setup and maintenance effortless.

##### Cons

- Users find the **complexity** of AWS's security features requires a well-trained admin for proper configuration and effectiveness.
- Users find **complexity issues** in configuring Amazon Inspector, requiring well-trained admins to optimize its advanced security features.
- Users note a **steep learning curve** for effectively configuring advanced security features in Amazon Inspector.
- Users find **limited features** in Amazon Inspector, which restricts their ability to effectively manage sensitive information.
- Users find Amazon Inspector **not user-friendly** , as it requires advanced knowledge for proper configuration and effective security.

#### What Are Recent G2 Reviews of Amazon Inspector?

**["Continuous AWS Vulnerability Scanning With Minimal Operational Overhead"](https://www.g2.com/survey_responses/amazon-inspector-review-13159187)**

**Rating:** 4.5/5.0 stars

_— Atharva P._

[Read full review](https://www.g2.com/survey_responses/amazon-inspector-review-13159187)

**["Easy AWS Integration with Clear Vulnerability Reporting"](https://www.g2.com/survey_responses/amazon-inspector-review-12534377)**

**Rating:** 4.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/amazon-inspector-review-12534377)

### [SentinelOne Singularity Cloud Security](https://www.g2.com/products/sentinelone-singularity-cloud-security/reviews)

Singularity Cloud Security is SentinelOne’s comprehensive, cloud-native application protection platform (CNAPP). It combines the best of agentless insights with AI-powered threat protection, to secure and protect your multi-cloud infrastructure, services, and containers from build time to runtime. SentinelOne’s CNAPP applies an attacker’s mindset to help security practitioners better prioritize their remediation tasks with evidence-backed Verified Exploit Paths™. The efficient and scalable runtime protection, proven over 5 years and trusted by many of the world’s leading cloud enterprises, harnesses local, autonomous AI engines to detect and thwart runtime threats in real-time. CNAPP data and workload telemetry is recorded to SentinelOne’s unified security lake, for easy access and investigation.

**Average Rating:** 4.9/5.0

**Total Reviews:** 121

#### How Do G2 Users Rate SentinelOne Singularity Cloud Security?

- **Has the product been a good partner in doing business?:** 9.8/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.8/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.8/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 9.9/10 (Category avg: 8.5/10)

#### Who Is the Company Behind SentinelOne Singularity Cloud Security?

- **Seller:** [SentinelOne](https://www.g2.com/sellers/sentinelone)
- **Company Website:** www.sentinelone.com
- **Year Founded:** 2013
- **HQ Location:** Mountain View, CA
- **Twitter:** @SentinelOne  
57,863 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=74020d53a476ae0e483a0d2613eaf520ba6aa350af89839fdb2bae462d053ed2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2886771%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,174 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 59% Medium, 30% Large

#### What Do G2 Reviewers Say About SentinelOne Singularity Cloud Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **real-time alert system** of SentinelOne Singularity, enhancing proactive threat management and security.
- Users find the **user-friendly interface** of SentinelOne Singularity Cloud Security makes managing security straightforward for everyone.
- Users value the **automated vulnerability detection** in PingSafe, enhancing proactive cloud security management effortlessly.
- Users appreciate the **real-time alert system** of PingSafe, enhancing proactive cloud security management effectively.
- Users commend SentinelOne Singularity Cloud Security for its **ease of use and strong visibility** across cloud environments.

##### Cons

- Users feel that SentinelOne Singularity Cloud Security has a **complex setup** that can be challenging for less technical users.
- Users experience **ineffective alerts** that require tuning, leading to confusion and potential oversight in security management.
- Users find the **complex setup** of SentinelOne Singularity Cloud Security challenging, requiring time for effective configuration and tuning.
- Users find **difficult configuration** of SentinelOne Singularity Cloud Security requires time and experience for optimal setup and tuning.
- Users find the **UI to be clunky** , making the platform's complexity and learning curve more challenging.

#### What Are Recent G2 Reviews of SentinelOne Singularity Cloud Security?

**["At the heart of the Singularity Platform is Singularity Cloud Security"](https://www.g2.com/survey_responses/sentinelone-singularity-cloud-security-review-13146859)**

**Rating:** 4.5/5.0 stars

_— Jawahar A._

[Read full review](https://www.g2.com/survey_responses/sentinelone-singularity-cloud-security-review-13146859)

**["Clear Cloud Visibility with SentinelOne Singularity Cloud Security"](https://www.g2.com/survey_responses/sentinelone-singularity-cloud-security-review-13147820)**

**Rating:** 5.0/5.0 stars

_— Adaku O._

[Read full review](https://www.g2.com/survey_responses/sentinelone-singularity-cloud-security-review-13147820)

### [SentinelOne Singularity Endpoint](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews)

SentinelOne Singularity Endpoint is a software designed to protect endpoints by autonomously detecting, preventing, and responding to threats across devices within an organization. The software leverages machine learning and behavioral AI to identify and mitigate a wide range of cyber threats, including malware, ransomware, and fileless attacks. It provides continuous monitoring and automated remediation capabilities to help reduce manual intervention and response time during security incidents. SentinelOne Singularity Endpoint integrates with existing IT security and management workflows, offering visibility into endpoint activities and assisting organizations in maintaining compliance by ensuring devices meet security standards. The software is engineered to address business challenges related to endpoint protection, threat management, and operational efficiency in cybersecurity environments.

**Average Rating:** 4.7/5.0

**Total Reviews:** 204

#### How Do G2 Users Rate SentinelOne Singularity Endpoint?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.5/10 (Category avg: 8.9/10)
- **Automated Scans:** 8.7/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 7.6/10 (Category avg: 8.5/10)

#### Who Is the Company Behind SentinelOne Singularity Endpoint?

- **Seller:** [SentinelOne](https://www.g2.com/sellers/sentinelone)
- **Company Website:** www.sentinelone.com
- **Year Founded:** 2013
- **HQ Location:** Mountain View, CA
- **Twitter:** @SentinelOne  
57,863 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=74020d53a476ae0e483a0d2613eaf520ba6aa350af89839fdb2bae462d053ed2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2886771%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,174 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 44% Medium, 36% Large

#### What Do G2 Reviewers Say About SentinelOne Singularity Endpoint?

_AI-generated summary from verified user reviews_

##### Pros

- Users find SentinelOne Singularity Endpoint to be **easy to deploy and manage** , enhancing overall security efficiency.
- Users value the **tool efficiency** of SentinelOne, noting its user-friendly interface and effective threat detection capabilities.
- Users value the **setup ease** of SentinelOne Singularity, appreciating its simple deployment and swift implementation process.
- Users commend SentinelOne for its **exceptional malware protection** , effectively defending against various threats and attacks.
- Users find the **incident notification system** of SentinelOne very effective, enhancing their ability to respond quickly.

##### Cons

- Users face **update issues** with SentinelOne, including frequent login problems and difficulties with self-updating agents.
- Users find the **difficult learning curve** challenging, especially for beginners navigating the complex interface.
- Users face challenges with **frequent updates** that complicate login processes and require constant adjustments to policies.
- Users experience frequent **agent removal issues** that disrupt functionality and complicate application performance.
- Users report **ineffective alerts** that complicate troubleshooting and hinder application compatibility during migration between EDR providers.

#### What Are Recent G2 Reviews of SentinelOne Singularity Endpoint?

**["Powerful AI Threat Detection with Fast, Autonomous Endpoint Response"](https://www.g2.com/survey_responses/sentinelone-singularity-endpoint-review-12718230)**

**Rating:** 5.0/5.0 stars

_— Dr. Jagannath S._

[Read full review](https://www.g2.com/survey_responses/sentinelone-singularity-endpoint-review-12718230)

**["Real-Time Endpoint Visibility with AI-Powered Protection"](https://www.g2.com/survey_responses/sentinelone-singularity-endpoint-review-13138678)**

**Rating:** 5.0/5.0 stars

_— Adaku O._

[Read full review](https://www.g2.com/survey_responses/sentinelone-singularity-endpoint-review-13138678)

#### What Are G2 Users Discussing About SentinelOne Singularity Endpoint?

- [How does Sentinel one work?](https://www.g2.com/discussions/sentinelone-singularity-how-does-sentinel-one-work)
- [How does Sentinel one work?](https://www.g2.com/discussions/how-does-sentinel-one-work)
- [Is SentinelOne an antivirus?](https://www.g2.com/discussions/sentinelone-singularity-is-sentinelone-an-antivirus)
- [Is SentinelOne an antivirus?](https://www.g2.com/discussions/is-sentinelone-an-antivirus) - 3 comments
- [What is SentinelOne used for?](https://www.g2.com/discussions/sentinelone-singularity-what-is-sentinelone-used-for)

### [Tenable Vulnerability Management](https://www.g2.com/products/tenable-vulnerability-management/reviews)

Tenable Vulnerability Management provides a risk-based approach to identifying, prioritizing, and remediating vulnerabilities across your entire attack surface. Powered by Nessus technology and AI-driven analytics, it goes beyond CVSS scores to assess exploitability, asset criticality, and business impact—so you can focus on what matters most. With continuous visibility, automated scanning, and real-time risk insights, security teams can quickly expose and close critical vulnerabilities before they’re exploited. Advanced asset identification ensures accurate tracking in dynamic environments, while intuitive dashboards, comprehensive reporting, and seamless third-party integrations help streamline workflows. As a cloud-based solution, Tenable Vulnerability Management scales with your organization, empowering security teams to maximize efficiency, reduce risk, and improve resilience against evolving threats.

**Average Rating:** 4.5/5.0

**Total Reviews:** 114

#### How Do G2 Users Rate Tenable Vulnerability Management?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 9.2/10)
- **Detection Rate:** 9.0/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.3/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.7/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Tenable Vulnerability Management?

- **Seller:** [Tenable](https://www.g2.com/sellers/tenable)
- **Company Website:** www.tenable.com
- **HQ Location:** Columbia, MD
- **Twitter:** @TenableSecurity  
87,752 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=029266d223c06e6b09e6d209209f15aad3bbad59d05069b38d5ec2757e74adef&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F25452%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,350 employees on LinkedIn®
- **Ownership:** NASDAQ: TENB

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 55% Large, 33% Medium

#### What Do G2 Reviewers Say About Tenable Vulnerability Management?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **user-friendly interface** of Tenable Vulnerability Management, making prioritization and action on vulnerabilities seamless.
- Users praise the **scanning efficiency** of Tenable Vulnerability Management, highlighting its speed and comprehensive capabilities.
- Users value the **powerful scanning and reporting features** of Tenable Vulnerability Management for enhanced asset management.
- Users appreciate the **fast and efficient automated scanning** of Tenable Vulnerability Management, enhancing resource management and reporting.
- Users value the **effective vulnerability identification** that helps prioritize remediation efforts efficiently within their environments.

##### Cons

- Users find the **cost of Tenable Vulnerability Management** to be prohibitive, especially for organizations with tight budgets.
- Users find the **reporting capabilities inadequate** , often needing external tools for refined and personalized analysis.
- Users find the **reporting capabilities to be limited** , often needing external tools for better data insights.
- Users find the **pricing issues** of Tenable Vulnerability Management to be a barrier, especially for smaller organizations.
- Users find the platform's **complexity** to manage licensing and reporting options challenging, especially under budget constraints.

#### What Are Recent G2 Reviews of Tenable Vulnerability Management?

**["TVM Does What You Need"](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-12937561)**

**Rating:** 4.5/5.0 stars

_— Verified User in Higher Education_

[Read full review](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-12937561)

**["Intuitive, Easy to Deploy, and Packed with Comprehensive Reporting"](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-13067235)**

**Rating:** 4.5/5.0 stars

_— Grace Y._

[Read full review](https://www.g2.com/survey_responses/tenable-vulnerability-management-review-13067235)

#### What Are G2 Users Discussing About Tenable Vulnerability Management?

- [What is your primary use case for Tenable Vulnerability Management, and how has it impacted your security posture?](https://www.g2.com/discussions/what-is-your-primary-use-case-for-tenable-vulnerability-management-and-how-has-it-impacted-your-security-posture) - 1 comment
- [What is Tenable.io used for?](https://www.g2.com/discussions/what-is-tenable-io-used-for) - 1 comment
- [How much is tenable io?](https://www.g2.com/discussions/how-much-is-tenable-io)
- [How do I link Nessus to tenable io?](https://www.g2.com/discussions/how-do-i-link-nessus-to-tenable-io)
- [What is the difference between Nessus and tenable io?](https://www.g2.com/discussions/what-is-the-difference-between-nessus-and-tenable-io)

### [InsightVM (Nexpose)](https://www.g2.com/products/insightvm-nexpose/reviews)

InsightVM is Rapid7’s vulnerability risk management offering that advances security through cross-department clarity, a deeper understanding of risk, and measurable progress. By informing and aligning technical teams, security teams can remediate vulnerabilities and build Security into the core of the organization. With InsightVM, security teams can: Gain Clarity Into Risk and Across Teams Better understand the risk in your modern environment so you can work in lockstep with technical teams. Extend Security’s Influence Align traditionally siloed teams and drive impact with the shared view and common language of InsightVM. See Shared Progress Take a proactive approach to security with tracking and metrics that create accountability and recognize progress.

**Average Rating:** 4.4/5.0

**Total Reviews:** 70

#### How Do G2 Users Rate InsightVM (Nexpose)?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.8/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.4/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 8.4/10 (Category avg: 8.5/10)

#### Who Is the Company Behind InsightVM (Nexpose)?

- **Seller:** [Rapid7](https://www.g2.com/sellers/rapid7)
- **Year Founded:** 2000
- **HQ Location:** Boston, MA
- **Twitter:** @rapid7  
124,405 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=04bdb542ee8372d372b62e305f57e5c7aefbd59efac3d6831f78fcc71f4f819c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F39624%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,274 employees on LinkedIn®
- **Ownership:** NASDAQ:RPD

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Large, 33% Medium

#### What Do G2 Reviewers Say About InsightVM (Nexpose)?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **automation capabilities** of InsightVM, streamlining workflows and reducing effort in vulnerability management.
- Users value the **real-time visibility** of InsightVM, enabling effective continuous monitoring and swift vulnerability detection.
- Users value the **efficient asset management** features of InsightVM, enhancing tracking, tagging, and prioritization of vulnerabilities.
- Users appreciate the **clear, actionable risk scoring** and live dashboards of InsightVM that enhance asset management.
- Users value the **clear risk scoring and live dashboards** of InsightVM for prioritizing asset exposure effectively.

##### Cons

- Users find the **complexity** of InsightVM challenging, particularly during initial setup and ongoing administration.
- Users experience **performance issues** with heavy scans and slow support responses impacting their overall experience with InsightVM.
- Users face **resource limitations** that can complicate optimization efforts, impacting overall performance when using InsightVM.
- Users often face challenges with **high memory consumption** , requiring careful management to optimize resource usage effectively.
- Users find **InsightVM's resource consumption management** tedious, particularly when optimizing scans and custom reports at scale.

#### What Are Recent G2 Reviews of InsightVM (Nexpose)?

**["InsightVM"](https://www.g2.com/survey_responses/insightvm-nexpose-review-13141902)**

**Rating:** 4.0/5.0 stars

_— Diogo A._

[Read full review](https://www.g2.com/survey_responses/insightvm-nexpose-review-13141902)

**["InsightVM’s Actionable Risk Scoring and Live Dashboards Impress"](https://www.g2.com/survey_responses/insightvm-nexpose-review-11922296)**

**Rating:** 5.0/5.0 stars

_— tali k._

[Read full review](https://www.g2.com/survey_responses/insightvm-nexpose-review-11922296)

#### What Are G2 Users Discussing About InsightVM (Nexpose)?

- [What is InsightVM (Nexpose) used for?](https://www.g2.com/discussions/what-is-insightvm-nexpose-used-for) - 1 comment
- [What is InsightVM?](https://www.g2.com/discussions/what-is-insightvm) - 1 comment
- [What is nexpose InsightVM agent?](https://www.g2.com/discussions/what-is-nexpose-insightvm-agent)
- [What is the difference between nexpose and InsightVM?](https://www.g2.com/discussions/what-is-the-difference-between-nexpose-and-insightvm)
- [What can nexpose scan?](https://www.g2.com/discussions/what-can-nexpose-scan)

### [Pentera](https://www.g2.com/products/pentera/reviews)

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

**Average Rating:** 4.5/5.0

**Total Reviews:** 171

#### How Do G2 Users Rate Pentera?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Detection Rate:** 8.4/10 (Category avg: 8.9/10)
- **Automated Scans:** 9.1/10 (Category avg: 9.0/10)
- **Configuration Monitoring:** 7.8/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Pentera?

- **Seller:** [Pentera](https://www.g2.com/sellers/pentera)
- **Company Website:** pentera.io
- **Year Founded:** 2015
- **HQ Location:** Boston, MA
- **Twitter:** @penterasec  
3,291 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9f2c0c558c875a98d2d9fc35b9d10d7247ea125fd4eaf33d374195bfe744ebba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpenterasecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
483 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Government Administration, Banking
- **Company Size:** 52% Large, 36% Medium

#### What Do G2 Reviewers Say About Pentera?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **automation features** of Pentera, enhancing ease of use and enabling efficient continuous operation.
- Users recognize the **powerful automation and detailed remediation suggestions** of Pentera for effective vulnerability detection.
- Users value Pentera's **effective vulnerability scanning and remediation suggestions** , enhancing their overall security posture and testing efficacy.
- Users value the **responsive customer support** of Pentera, enhancing their overall vulnerability scanning experience.
- Users appreciate the **efficiency** of Pentera, notably for its quick implementation and time-saving automation.

##### Cons

- Users find the **reporting inadequate** , particularly for enterprise-level assessments, necessitating significant improvements.
- Users experience a **lack of essential features** , including limited TTP updates and inadequate user permissions management.
- Users find the **reporting in Pentera lacking** , especially for enterprise-level needs and multilingual support.
- Users find Pentera demands a **high amount of system resources** , which can hinder overall performance and efficiency.
- Users report **technical issues** , particularly with module compatibility and unexpected upgrade failures, though support is responsive.

#### What Are Recent G2 Reviews of Pentera?

**["Cutting-Edge Security with a Real Attacker Approach"](https://www.g2.com/survey_responses/pentera-review-12864952)**

**Rating:** 4.5/5.0 stars

_— Yaron C._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864952)

**["Reliable Tool for Vulnerability Detection but Script Issues"](https://www.g2.com/survey_responses/pentera-review-12864934)**

**Rating:** 4.0/5.0 stars

_— Avitzur Y._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864934)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/vulnerability-scanner?order=g2_score&page=2#product-list)
- [3](/categories/vulnerability-scanner?order=g2_score&page=3#product-list)
- [4](/categories/vulnerability-scanner?order=g2_score&page=4#product-list)
- [5](/categories/vulnerability-scanner?order=g2_score&page=5#product-list)
- …
- [14](/categories/vulnerability-scanner?order=g2_score&page=14#product-list)
- [15](/categories/vulnerability-scanner?order=g2_score&page=15#product-list)
- [Next &rsaquo;Next ›](/categories/vulnerability-scanner?order=g2_score&page=2#product-list)

Spotlight Categories

[Project Management Software](https://www.g2.com/categories/project-management)

[Influencer Marketing Platforms](https://www.g2.com/categories/influencer-marketing-platforms)

[Low-Code Development Platforms](https://www.g2.com/categories/low-code-development-platforms)

[Sales Tax and VAT Compliance Software](https://www.g2.com/categories/sales-tax-and-vat-compliance)

[A/B Testing Tools](https://www.g2.com/categories/a-b-testing-tools)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)

- [Software Composition Analysis](/categories/software-composition-analysis)
- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Vulnerability Scanner Themes](/categories/vulnerability-scanner/themes)

 ![Lauren Worth](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Lauren Worth")
LW

Researched and written by [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)

Updated April 10, 2026

Vulnerability scanners continuously monitor applications and networks against an up-to-date database of known vulnerabilities, identifying potential exploits, producing analytical reports on the security state of applications and networks, and providing recommendations to remedy known issues.

### Core Capabilities of Vulnerability Scanner Software

To qualify for inclusion in the Vulnerability Scanner category, a product must:

- Maintain a database of known vulnerabilities
- Continuously scan applications for vulnerabilities
- Produce reports analyzing known vulnerabilities and new exploits

### Common Use Cases for Vulnerability Scanner Software

Security and IT teams use vulnerability scanners to proactively identify and address weaknesses before they can be exploited. Common use cases include:

- Running scheduled and on-demand scans of applications and network infrastructure for known CVEs
- Generating prioritized vulnerability reports to guide remediation efforts
- Testing application and network security posture as part of ongoing compliance and risk management programs

### How Vulnerability Scanner Software Differs from Other Tools

Some vulnerability scanners operate similarly to [dynamic application security testing (DAST)](https://www.g2.com/categories/dynamic-application-security-testing-dast) tools, but the key distinction is that vulnerability scanners test applications and networks against known vulnerability databases rather than mimicking real-world attacks or performing penetration tests. DAST tools simulate attacker behavior to uncover runtime vulnerabilities, while scanners focus on identification and reporting of known weaknesses.

### Insights from G2 on Vulnerability Scanner Software

Based on category trends on G2, continuous scanning and comprehensive vulnerability reporting stand out as standout capabilities. Faster identification of critical exposures and improved compliance readiness stand out as primary benefits of adoption.

Top Tools at a Glance

| 

 | 

Risk-based cloud vulnerability prioritization with context

 | 

User Review

"Unmatched Security Insights, Excellent Reporting, and Strong Post-Sales Support"

 |
| 

 | 

Auto-triaged DevSecOps scanning with low false positives

 | 

User Review

"Enterprise Security Without an Enterprise Security Team"

 |
| 

 | 

Agentless cloud vulnerability scanning with contextual risk prioritization

 | 

User Review

"Orca’s Attack Path View Transformed How We Prioritize Fixes"

 |
| 

 | 

Credentialed infrastructure scans with compliance auditing

 | 

User Review

"Self-Contained Nessus Scanning with Full Control in Offline Environments"

 |
| 

 | 

SaaS pentest certification with manual validation

 | 

User Review

"Smooth Onboarding, Responsive Support, and Strong Pentest Lifecycle Controls"

 |
| 

 | 

Continuous vulnerability scanning with emerging threat detection

 | 

User Review

"Reliable Service with Flexible Plans and Strong Support"

 |
| 

 | 

Runtime vulnerability detection in Kubernetes workloads

 | 

User Review

"Excellent Real-Time Kubernetes Security Visibility and Threat Detection"

 |
| 

 | 

Manual web application penetration testing workflows

 | 

User Review

"Complete Control Over Web Requests with Burp Suite"

 |

* * *

Show More

* * *

## How Do You Choose the Right Vulnerability Scanner Software?

### What You Should Know About Vulnerability Scanner Software

### What is Vulnerability Scanner Software?

Vulnerability scanners are used to examine applications, networks, and environments for security flaws and misconfigurations. These tools run a variety of dynamic security tests to identify security threats along an application or network’s attack surface. Scans can be used for anything from an application penetration test to a compliance scan. Depending on the specific objectives a user has, they can customize the vulnerability scanner to test for specific issues or requirements.

Companies can configure these tests to their unique environment. Companies that handle lots of personal or financial data may scan to ensure every transaction or datastore is encrypted from the public. They could also test their web applications against specific threats like SQL injection or cross-site scripting (XSS) attacks. The highly-customizable nature of vulnerability scanners provides users with tailor-made solutions for application and network security examination.

Many of these tools offer continuous scanning and testing for nonstop protection and monitoring. Whatever administrators set as a priority will be tested periodically and inform employees of issues or incidents. Continuous monitoring makes it much easier to discover vulnerabilities before they become an issue and drastically reduce the amount of time a vulnerability takes to remediate.

Top vulnerability scanner software with CVE remediation guidance typically combines automated scanning with prioritized fix recommendations that map findings to severity scores, exposure paths, and patch availability. Based on G2 reviews, security teams evaluate vulnerability scanner software by comparing CVE remediation depth, false positive rates, and how quickly the platform integrates into existing CI/CD pipelines and cloud environments.

Key Benefits of Vulnerability Scanner Software

- Scan networks and applications for security flaws
- Diagnose, track, and remediate vulnerabilities
- Identify and resolve misconfigurations
- Perform ad hoc security tests

### Why Use Vulnerability Scanner Software?

Applications and networks are only beneficial to a business if they operate smoothly and securely. Vulnerability scanners are a useful tool to view internal systems and applications from the perspective of the attacker. These tools allow for dynamic testing while applications operate. This helps security teams take a step beyond patches and code analysis to evaluate security posture while the application, network, or instance actually runs.

**Application security—** Cloud, web, and desktop applications all require security, but operate differently. While many vulnerability scanners support testing for all kinds of applications, vulnerability scanners often support a few application types, but not others. Still, they will all examine the application itself, as well as the paths a user needs to access it. For example, if a vulnerability scanner is used on a web application, the tool will take into account the various attack vectors a hacker might take. This includes a site’s navigation, regional access, privileges, and other factors decided by the user. From there, the scanner will output reports on specific vulnerabilities, compliance issues, and other operational flaws.

**Networks —** While software applications are often the most obvious use cases for vulnerability scanners, network vulnerability scanners are also quite common. These tools take into account the network itself, as well as computers, servers, mobile devices and any other asset accessing a network. This helps businesses identify vulnerable devices and abnormal behaviors within a network to identify and remediate issues as well as improve their network's security posture. Many even provide visual tools for mapping networks and their associated assets to simplify the management and prioritization of vulnerabilities requiring remediation.

**Cloud environments —** Not to be confused with cloud-based solutions delivered in a SaaS model, cloud vulnerability scanners examine cloud services, cloud computing environments, and integrated connections. Like network vulnerability scanners, cloud environments require an examination on a few levels. Cloud assets come in many forms including devices, domains, and instances; but all must be accounted for and scanned. In a properly secured cloud computing environment, integrations and API connections, assets, and environments must all be mapped, configurations must be monitored, and requirements must be enforced.

Based on G2 reviews, vulnerability scanner platforms generating VLAN audit reports are evaluated primarily by security teams running segmented enterprise networks where compliance frameworks (PCI, HIPAA, SOC 2, ISO 27001) require documented scans across each network zone. Reviewers point to audit-ready compliance reporting, granular scan scope by IP range and network segment, and exportable evidence formats as the features that determine whether the platform shortens the audit prep cycle or adds another step to it.

### What are the Common Features of Vulnerability Scanner Software?

Vulnerability scanners can provide a wide range of features, but here are a few of the most common found in the market.

**Network mapping —** Network mapping features provide a visual representation of network assets including endpoints, servers, and mobile devices to intuitively demonstrate an entire network’s components.

**Web inspection —** Web inspection features are used to assess the security of a web application in the context of its availability. This includes site navigation, taxonomies, scripts, and other web-based operations that may impact a hacker’s abilities.

[**Defect tracking**](https://www.g2.com/categories/vulnerability-scanner/f/issue-tracking) **—** Defect and issue tracking functionality helps users discover and document vulnerabilities and track them to their source through the resolution process.

**Interactive scanning —** Interactive scanning or interactive application security testing features allow a user to be directly involved in the scanning process, watch tests in real time, and perform ad hoc tests.

[**Perimeter scanning**](https://www.g2.com/categories/vulnerability-scanner/f/perimeter-scanning) **—** Perimeter scanning will analyze assets connected to a network or cloud environment for vulnerabilities.

[**Black box testing**](https://www.g2.com/categories/vulnerability-scanner/f/black-box-testing) **—** Black box scanning refers to tests conducted from the hacker’s perspective. Black box scanning examines functional applications externally for vulnerabilities like SQL injection or XSS.

**Continuous monitoring —** Continuous monitoring allows users to set it and forget it. They enable scanners to run all the time as they alert users of new vulnerabilities.

[**Compliance monitoring**](https://www.g2.com/categories/vulnerability-scanner/f/compliance-testing) **—** Compliance-related monitoring features are used to monitor data quality and send alerts based on violations or misuse.

**Asset discovery —** Asset discovery features unveil applications in use and trends associated with asset traffic, access, and usage.

**Logging and reporting —** Log documentation and reporting provides required reports to manage operations. It provides adequate logging to troubleshoot and support auditing.

**Threat intelligence —** Threat intelligence features integrate with or store information related to common threats and how to resolve them once incidents occur.

**Risk analysis —** Risk scoring and risk analysis features identify, score, and prioritize security risks, vulnerabilities, and compliance impacts of attacks and breaches.

**Extensibility —** Extensibility and integration features provide the ability to extend the platform or product to include additional features and functionalities.

Based on G2 reviews, the most trusted vulnerability scanner platforms in 2026 for security teams lead on CVE remediation guidance and easy setup onboarding, with reviewers describing time-to-first-scan in hours rather than weeks. SOC and AppSec teams point to clear remediation steps, severity scoring, and actionable findings as the features that distinguish platforms they actively use from ones that produce noise. Vulnerability scanner solutions with easy setup onboarding are highlighted in recent reviews for delivering full environment visibility on day one through agentless, API-driven architectures, with documentation that reduces the engineering lift typically associated with rolling out vulnerability scanning.

Many vulnerability scanner tools will also offer the following features:&nbsp;

- [Configuration monitoring capabilities](https://www.g2.com/categories/vulnerability-scanner/f/configuration-monitoring)
- [Automated scan capabilities](https://www.g2.com/categories/vulnerability-scanner/f/automated-scans)
- [Manual application testing capabilities](https://www.g2.com/categories/vulnerability-scanner/f/manual-application-testing)
- [Static code analysis capabilities](https://www.g2.com/categories/vulnerability-scanner/f/static-code-analysis)

### Potential Issues with Vulnerability Scanner Software

**False positives —** False positives are one of the most common issues with security tools. They indicate a tool is not running efficiently and introduce lots of unnecessary labor. Users should examine figures related to specific products and their accuracy before purchasing a solution.

**Integrations —** Integrations can make an application or product do virtually anything, but only if the integration is supported. If a specific solution must be integrated or a specific data source is highly relevant, be sure it’s compatible with the vulnerability scanner before making that decision.

**Scalability —** Scalability is always important, especially for growing teams. Cloud and SaaS-based solutions are traditionally the most scalable, but desktop and open source tools may be as well. Scalability will be important for teams considering collaborative use, concurrent use, and multi-application and environment scanning.

### Software and Services Related to Vulnerability Scanner Software

These technology families are either closely related to vulnerability scanners or there is frequent overlap between products.

[**Risk-based vulnerability management software**](https://www.g2.com/categories/risk-based-vulnerability-management) **—** Risk-based vulnerability management software is used to analyze security posture based on a wide array of risk factors. From there, companies prioritize vulnerabilities based on their risk score. These tools often have some overlapping features, but they’re more geared towards prioritizing risks in large organizations rather than identifying vulnerabilities to individual applications or environments.

[**Dynamic application security testing (DAST) software**](https://www.g2.com/categories/dynamic-application-security-testing-dast) **—** DAST software is very closely related to vulnerability scanners and are sometimes used interchangeably. The differentiating factor here, though, is the ability to scan networks, cloud services, and IT assets in addition to applications. While they do scan for vulnerabilities, they won’t allow users to map networks, visualize environments, or examine vulnerabilities beyond the scope of the application.

[**Static application security testing (SAST) software**](https://www.g2.com/categories/static-application-security-testing-sast) **—** SAST software is not that similar to vulnerability scanners, unlike DAST tools. SAST tools allow for the examination of source code and non-operational application components. They also can’t simulate attacks or perform functional security tests. Still, these can be useful for defect and bug tracking if the vulnerability is rooted in an application’s source code.

[**Penetration testing software**](https://www.g2.com/categories/penetration-testing) **—** Penetration testing software is one aspect of vulnerability scanning, but a penetration test will not provide a wide variety of security tests. They are useful for testing common attack types, but they won’t be very effective in identifying and remediating the root cause of a vulnerability.

Based on G2 reviews, Software Composition Analysis tools Jenkins GitLab integration continuous vulnerability scanning is the workflow pattern reviewers describe as the standard for developer-led security programs running checks inside the build pipeline rather than as a separate stage. Reviewers point to agentless, API-driven scanners integrating into CI/CD pipelines to catch secrets, misconfigurations, and open-source dependency vulnerabilities pre-deployment as the setup that scales with engineering velocity. Reviewers note that consolidated platforms unifying SCA, SAST, and exposure-management scanning under one interface are the preferred consolidation pattern over stitching together standalone tools.