Best Attack Surface Management Software - Page 2

How Many Attack Surface Management Software Products Does G2 Track?

Total Products under this Category: 170

Category Stats (Aug 2026)

  • Average Rating: 4.6/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Forescout Platform (+0.74%) - Among all products in this category, Forescout Platform recorded the largest rating increase compared to last month

Last updated: August 06, 2026

How Does G2 Rank Attack Surface Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 170+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Attack Surface Management Software

G2 Grid® for  Attack Surface Management Software plotting products by satisfaction and market presence

Highlighted products: Wiz, SOCRadar Extended Threat Intelligence, CTM360, CloudSEK, Cyble, RiskProfiler - External Threat Exposure Management, Check Point Exposure Management, and Falcon Security and IT operations.

Underlying data: [Grid® JSON](https://www.g2.com/categories/attack-surface-management/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=socradar-extended-threat-intelligence&focus%5B%5D=ctm360-ctm360&focus%5B%5D=cloudsek&focus%5B%5D=cyble&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=check-point-exposure-management&focus%5B%5D=falcon-security-and-it-operations)

Sponsored

Intruder

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

Visit website

DeCYFIR by CYFIRMA

DeCYFIR is an AI-powered preemptive External Threat Landscape Management platform engineered to help organizations predict and prevent cyberattacks before they occur. Adopting a hacker's perspective, it delivers early warnings, prioritized insights, and actionable intelligence across the full external threat landscape. Built on a proprietary 9-pillar architecture — spanning Attack Surface Discovery & Intelligence, Vulnerability Intelligence & Threat Prioritization, Brand & Online Exposure Management, Digital Risk & Identity Protection, Third Party Risk Management, Situational Awareness & Emerging Threats, Predictive Threat Intelligence, Threat Adaptive Awareness & Training, and Sector Tailored Deception Intelligence. DeCYFIR correlates signals across all pillars to cut through noise, surface what is truly critical, and empower security teams to stay decisively ahead of emerging threats.

Average Rating: 4.8/5.0

Total Reviews: 46

How Do G2 Users Rate DeCYFIR by CYFIRMA?

  • Vulnerability Intelligence: 10.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 10.0/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.4/10 (Category avg: 8.9/10)

Who Is the Company Behind DeCYFIR by CYFIRMA?

  • Seller: CYFIRMA
  • Year Founded: 2017
  • HQ Location: Singapore, SG
  • Twitter: @cyfirma
    1,002 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    132 employees on LinkedIn®
  • Phone: marketing@cyfirma.com

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 50% Medium, 26% Large

What Do G2 Reviewers Say About DeCYFIR by CYFIRMA?

AI-generated summary from verified user reviews

Pros
  • Users value the advanced threat detection capabilities of DeCYFIR, enhancing their ability to prevent cyber incidents effectively.
  • Users value the informative threat intelligence of DeCYFIR, aiding in proactive threat detection and prevention efforts.
  • Users value DeCYFIR for its contextual and predictive intelligence, enhancing threat identification and risk mitigation strategies.
  • Users value the comprehensive multi-layered intelligence of DeCYFIR, enhancing proactive cyber threat detection and risk management.
  • Users value the proactive threat detection capabilities of DeCYFIR, enhancing their organization's security strategies effectively.
Cons
  • Users find DeCYFIR not user-friendly, especially for first-time users and those without technical expertise.
  • Users find DeCYFIR's interface too complex for newcomers, which can hinder effectiveness and overwhelm with data.
  • Users find DeCYFIR's platform to have a steep learning curve, especially for those unfamiliar with threat intelligence workflows.
  • Users find the limited customization of DeCYFIR's dashboards to be a barrier for effective usage and adaptation.
  • Users find the complex setup of DeCYFIR challenging, especially for newcomers to threat intelligence workflows.

What Are Recent G2 Reviews of DeCYFIR by CYFIRMA?

Microsoft Defender External Attack Surface Management

In this era of hybrid work, shadow IT creates an increasingly serious security risk. Defender EASM helps cloud security teams see unknown and unmanaged resources outside the firewall.

Average Rating: 4.3/5.0

Total Reviews: 17

How Do G2 Users Rate Microsoft Defender External Attack Surface Management?

  • Vulnerability Intelligence: 9.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.9/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 8.8/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.7/10 (Category avg: 8.9/10)

Who Is the Company Behind Microsoft Defender External Attack Surface Management?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    231,632 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 35% Small, 35% Medium

What Are Recent G2 Reviews of Microsoft Defender External Attack Surface Management?

Pentera

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

Average Rating: 4.5/5.0

Total Reviews: 171

How Do G2 Users Rate Pentera?

  • Vulnerability Intelligence: 8.3/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 7.9/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 7.8/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.6/10 (Category avg: 8.9/10)

Who Is the Company Behind Pentera?

  • Seller: Pentera
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Boston, MA
  • Twitter: @penterasec
    3,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    483 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Banking, Government Administration
  • Company Size: 52% Large, 36% Medium

What Do G2 Reviewers Say About Pentera?

AI-generated summary from verified user reviews

Pros
  • Users value the automation features of Pentera, enhancing ease of use and enabling efficient continuous operation.
  • Users recognize the powerful automation and detailed remediation suggestions of Pentera for effective vulnerability detection.
  • Users value Pentera's effective vulnerability scanning and remediation suggestions, enhancing their overall security posture and testing efficacy.
  • Users value the responsive customer support of Pentera, enhancing their overall vulnerability scanning experience.
  • Users appreciate the efficiency of Pentera, notably for its quick implementation and time-saving automation.
Cons
  • Users find the reporting inadequate, particularly for enterprise-level assessments, necessitating significant improvements.
  • Users experience a lack of essential features, including limited TTP updates and inadequate user permissions management.
  • Users find the reporting in Pentera lacking, especially for enterprise-level needs and multilingual support.
  • Users find Pentera demands a high amount of system resources, which can hinder overall performance and efficiency.
  • Users report technical issues, particularly with module compatibility and unexpected upgrade failures, though support is responsive.

What Are Recent G2 Reviews of Pentera?

ThreatMon

ThreatMon is an AI-powered cyber risk intelligence platform designed to assist organizations in detecting, analyzing, and responding to external cyber threats that may impact their digital assets, brand reputation, and third-party ecosystem. This comprehensive solution provides real-time visibility into an organization’s attack surface exposure, the evolving threat landscape, and overall cyber risk posture, all accessible from a single, unified platform. The platform is particularly beneficial for security and risk management teams who require a holistic view of their cyber environment. ThreatMon integrates various functionalities including attack surface management, threat intelligence, dark web monitoring, fraud detection, surface web monitoring, and supply chain risk intelligence. This integration eliminates the need for multiple, disconnected tools, streamlining the process of threat detection and risk assessment. By consolidating these capabilities, ThreatMon allows organizations to efficiently manage their cyber risk landscape while reducing operational complexity. Key features of ThreatMon include the ability to discover exposed assets, detect phishing attempts, monitor for brand impersonation, and track leaked credentials and data breaches. Additionally, it provides insights into threat actors and assesses vendor and third-party risks, which is crucial for organizations that rely on a complex ecosystem of partners and suppliers. The platform’s built-in governance, risk, and compliance (GRC) capabilities further enhance its utility by mapping compliance requirements and generating executive-level reports. This functionality translates technical findings into actionable business-level insights, enabling stakeholders to make informed decisions regarding their cyber risk management strategies. By unifying external exposure monitoring, threat intelligence, fraud detection, supply chain risk visibility, and governance-level reporting, ThreatMon empowers both security operations teams and executives to understand, prioritize, and respond to cyber risks more effectively. This shift from fragmented, reactive security measures to a proactive, intelligence-driven approach allows organizations to better safeguard their assets and maintain their reputation in an increasingly complex digital landscape. With ThreatMon, organizations can enhance their overall security posture and foster a culture of proactive risk management, ensuring they remain resilient against evolving cyber threats.

Average Rating: 4.9/5.0

Total Reviews: 26

How Do G2 Users Rate ThreatMon?

  • Vulnerability Intelligence: 10.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 10.0/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.8/10 (Category avg: 8.9/10)

Who Is the Company Behind ThreatMon?

  • Seller: ThreatMon
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Sterling VA
  • Twitter: @MonThreat
    17,241 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    38 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 38% Large, 38% Medium

What Do G2 Reviewers Say About ThreatMon?

AI-generated summary from verified user reviews

Pros
  • Users value the advanced risk scoring system of ThreatMon, enabling effective prioritization and actionable insights on threats.
  • Users value the reliable threat intelligence of ThreatMon, enhancing security through proactive threat detection and analysis.
  • Users value the advanced cybersecurity measures of ThreatMon, enhancing their protection with real-time monitoring and AI insights.
  • Users value the real-time notifications from ThreatMon, ensuring they stay ahead of potential security threats effectively.
  • Users value the comprehensive security protection from ThreatMon, enhancing confidence through proactive threat detection and notifications.
Cons
  • Users find the amount of threat data overwhelming, making the Mobile Application Monitoring Module less understandable at times.
  • Users note the need for more customization options in reporting features to better suit their specific requirements.
  • Users find the excessive notifications from ThreatMon can create unnecessary work during initial data collection.
  • Users feel the lack of customization in reporting features limits their ability to tailor outputs to specific needs.
  • Users desire more customization options for reporting features to enhance functionality and user experience in ThreatMon.

What Are Recent G2 Reviews of ThreatMon?

UpGuard Breach Risk

UpGuard Breach Risk is an AI-powered attack surface management solution that empowers lean security teams to see what attackers see and take control of their external risk. As part of the UpGuard Cyber Risk Posture Management (CRPM) platform, it integrates seamlessly with Vendor Risk and User Risk to provide a unified defense against modern cyber threats. As organizations scale, their digital footprint expands beyond the firewall, creating dangerous blind spots. Traditional tools often miss these external signals, leaving teams vulnerable to shadow IT, exposed credentials, and brand abuse. Breach Risk solves this by combining Attack Surface Management (ASM), Digital Risk Protection (DRP), and advanced Threat Monitoring into a single, automated platform. Key Capabilities: • Continuous Attack Surface Discovery: You can’t protect what you can’t see. Breach Risk continuously maps your internet-facing assets like domains, IPs, and cloud resources, to uncover shadow IT and misconfigurations. We automatically inventory your digital footprint to close the gaps that attackers exploit, ensuring no asset goes unmonitored. • AI-Powered Threat Monitoring: Move beyond static feeds. Our Threat Monitoring engine scans the open, deep, and dark web to detect leaked employee credentials, infostealer logs, and malware signals before they are weaponized. Unlike traditional threat intelligence that floods you with raw data, our AI Threat Analyst triages signals to filter out noise and prioritize high-fidelity threats for immediate action. • Brand Protection & Disinformation Defense: Safeguard your reputation against fraud. We proactively detect lookalike domains (typosquatting) and fraudulent social media profiles used to launch phishing attacks and disinformation campaigns. Our integrated workflows help you identify and neutralize these impersonation attempts before they erode customer trust. • Actionable Remediation: We don’t just find problems; we help you fix them. Breach Risk provides guided remediation plans and integrates with your security tech stack, allowing lean teams to accelerate response times without adding headcount. By translating complex technical risks into a quantifiable Cyber Risk Score, UpGuard enables security leaders to benchmark performance, justify budget, and prove risk reduction to the board.

Average Rating: 4.5/5.0

Total Reviews: 27

How Do G2 Users Rate UpGuard Breach Risk?

  • Vulnerability Intelligence: 10.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.7/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.9/10)

Who Is the Company Behind UpGuard Breach Risk?

  • Seller: UpGuard
  • Company Website:
  • Year Founded: 2012
  • HQ Location: Mountain View, California
  • Twitter: @UpGuard
    8,705 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    371 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 59% Large, 37% Medium

What Are Recent G2 Reviews of UpGuard Breach Risk?

Rankiteo

Rankiteo's Monitoring product offers a comprehensive cybersecurity monitoring solution designed to enhance an organization's digital defense mechanisms. This service provides real-time insights into potential vulnerabilities and threats, enabling businesses to proactively manage and mitigate cyber risks. By leveraging advanced technologies, Rankiteo ensures that organizations can maintain a robust security posture without the need for additional agents or workloads. Key Features and Functionality: - Security Ratings: Evaluate security strengths across ten risk factors to identify and address potential weaknesses. - Cyber Risk Quantification: Translate cyber risks into financial terms, facilitating informed decision-making. - Exploit Prediction: Utilize data-driven models to estimate the likelihood of vulnerability exploitation. - Vulnerability Prioritizer: Determine which vulnerabilities require immediate attention to optimize mitigation efforts. - Threat and Risk Intelligence: Access data-driven insights for proactive cybersecurity risk management. - Attack Surface Intelligence: Obtain on-demand, contextualized global threat intelligence to understand and manage exposure. - Automatic Vendor Detection: Identify and manage third and fourth-party vendors to enhance risk control. - SBOM (Supply Chain): Improve supply chain transparency and security with detailed software inventories. - Cyber Insurance Prediction: Predict cyber risks and tailor coverage for robust cybersecurity protection. - Malware Simulation: Simulate malware scenarios to predict risks and strengthen cybersecurity defenses. Primary Value and Problem Solved: Rankiteo's Monitoring product addresses the critical need for continuous and proactive cybersecurity oversight. By offering real-time monitoring and comprehensive risk assessments, it empowers organizations to identify and mitigate potential threats before they escalate. This proactive approach not only enhances security but also supports compliance with industry standards and regulations. Additionally, the solution's affordability makes enterprise-grade cybersecurity intelligence accessible to small and mid-sized businesses, democratizing access to essential security tools. By focusing on sectors like healthcare and frontline services, Rankiteo ensures that organizations can protect sensitive data and maintain trust without incurring exorbitant costs.

Average Rating: 4.7/5.0

Total Reviews: 37

How Do G2 Users Rate Rankiteo?

  • Vulnerability Intelligence: 8.9/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.9/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.4/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.6/10 (Category avg: 8.9/10)

Who Is the Company Behind Rankiteo?

  • Seller: Rankiteo
  • Year Founded: 2022
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    6 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Marketing and Advertising
  • Company Size: 68% Medium, 16% Large

What Do G2 Reviewers Say About Rankiteo?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Rankiteo, enabling straightforward prioritization and effective visibility in security management.
  • Users value the clear risk assessments from Rankiteo, facilitating easy prioritization and improved security visibility.
  • Users value the responsive customer support of Rankiteo, helping effectively manage and secure their server environments.
  • Users find that Rankiteo provides actionable intelligence, greatly simplifying security management and enhancing team understanding.
  • Users value the ease of use and efficiency in security management provided by Rankiteo, saving time and resources.
Cons
  • Users find the product expensive, particularly for organizations with limited budgets and beta features.
  • Users find integration issues challenging, noting it requires manual effort and lacks smoothness with third-party tools.
  • Users find the limited features of Rankiteo challenging, especially since some remain in beta phase.
  • Users find the complex setup of Rankiteo daunting, especially for smaller organizations lacking dedicated expertise.
  • Users find the lack of integration challenging, forcing them to rely on manual workarounds for some tools.

What Are Recent G2 Reviews of Rankiteo?

Saner CVEM

Prevention-first Vulnerability and Exposure Management for unified visibility, prioritization, compliance, and remediation Saner Continuous Vulnerability and Exposure Management unifies asset exposure, posture anomaly detection, vulnerability assessment, compliance management, risk prioritization, patching, and endpoint actions in one dashboard. Saner CVEM is built to help teams continuously detect, assess, prioritize, and remediate vulnerabilities and other security risks from a unified console Why Choose Saner CVEM? • Unified dashboard with interactive views across visibility, detection, prioritization, and remediation for a single source of truth • Complete asset visibility across endpoint and non-endpoint devices, operating system applications, third-party applications, and lifecycle changes • Continuous risk discovery with rapid scans, daily-updated risk intelligence, and posture anomaly detection that helps surface outliers and misconfigurations faster • Context-driven prioritization with SSVC categories such as Act, Attend, Track, and Track* so teams can focus on the risks that deserve action first. • Continuous compliance management with built-in templates, customizable profiles, daily checks, and deviation tracking across common frameworks. • Integrated patching and remediation with vulnerability-to-patch mapping, automated deployment workflows, and endpoint actions from the same ecosystem. • Machine-learning-assisted analysis to identify deeper risk patterns, detect unusual posture, and support smarter remediation decisions. • Customizable, audit-ready reporting for security, IT, and compliance teams that need clearer evidence and easier tracking. • Flexible deployment on cloud or on-premises, with remediation support across Windows, Linux, macOS, and AIX environments.

Average Rating: 4.5/5.0

Total Reviews: 72

How Do G2 Users Rate Saner CVEM?

  • Vulnerability Intelligence: 9.5/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.0/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Saner CVEM?

  • Seller: SecPod
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Redwood City, California
  • Twitter: @secpod
    542 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    168 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 41% Small, 38% Medium

What Do G2 Reviewers Say About Saner CVEM?

AI-generated summary from verified user reviews

Pros
  • Users value the effective automation of security patches with Saner CVEM, enhancing compliance for remote systems.
  • Users appreciate the automated endpoint security and compliance tracking of Saner CVEM, simplifying patch management for remote systems.
  • Users appreciate the ease of use of Saner CVEM, benefiting from its intuitive interface and efficient functionalities.
  • Users appreciate the responsive customer support of Saner CVEM, enhancing their overall security management experience.
  • Users value the automated compliance management of Saner CVEM, ensuring timely security updates across hybrid workforces.
Cons
  • Users face integration issues with Saner CVEM, especially requiring custom solutions and troubleshooting during data synchronization.
  • Users experience limited features in multi-tenant support, integration, and dashboard usability, affecting overall efficiency.
  • Users experience slow performance during initial dashboard loading and while handling large data sets, affecting efficiency.
  • Users experience slow scanning with initial dashboard loads and large data sets, impacting daily checks and efficiency.
  • Users find the limited cloud integration challenging, requiring workarounds and custom scripts for effective use.

What Are Recent G2 Reviews of Saner CVEM?

What Are G2 Users Discussing About Saner CVEM?

RidgeBot

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

Average Rating: 4.5/5.0

Total Reviews: 98

How Do G2 Users Rate RidgeBot?

  • Vulnerability Intelligence: 8.9/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.6/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 8.5/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.1/10 (Category avg: 8.9/10)

Who Is the Company Behind RidgeBot?

  • Seller: Ridge Security Technology
  • Company Website:
  • Year Founded: 2020
  • HQ Location: Santa Clara, California
  • Twitter: @RidgeSecurityAI
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    47 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 52% Small, 44% Medium

What Do G2 Reviewers Say About RidgeBot?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of RidgeBot, enabling quick setup and straightforward penetration testing automation.
  • Users value the automation capabilities of RidgeBot, significantly enhancing efficiency in penetration testing and vulnerability validation.
  • Users value the high efficiency of RidgeBot's pentesting, enabling quick, automated vulnerability validation and seamless integration.
  • Users commend RidgeBot for its effective vulnerability identification, providing reliable, automated testing and integration for security efficiency.
  • Users praise RidgeBot for its efficiency in automating vulnerability testing and streamlining security processes seamlessly.
Cons
  • Users find the complex setup of RidgeBot challenging, particularly for new admins requiring better documentation and support.
  • Users find RidgeBot's setup overly complex, particularly when working with customized or legacy systems.
  • Users find the missing features in RidgeBot, such as limited reporting and API testing, hinder optimal usage.
  • Users find poor customer support frustrating, often lacking resources for resolving issues independently.
  • Users find the poor documentation of RidgeBot challenging, especially for new admins during setup and onboarding.

What Are Recent G2 Reviews of RidgeBot?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • Vulnerability Intelligence: 9.4/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.3/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 6.7/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.9/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    91 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate Edgescan's ease of use, enjoying its intuitive interface and streamlined navigation for effective vulnerability management.
  • Users value the automated vulnerability detection with intuitive reports, timely alerts, and effective risk management features.
  • Users value the excellent customer support from Edgescan, praising the team's responsiveness and proactive assistance.
  • Users value the thorough vulnerability identification features of Edgescan, enhancing risk management and resolution efficiency.
  • Users value the robust features of Edgescan, which streamline security assessments and enhance ease of use.
Cons
  • Users find the complex UI challenging initially, with navigation issues and a need for improved dashboard functionality.
  • Users highlight limited customization options in Edgescan, particularly regarding filtering and admin functionalities.
  • Users find the poor interface design of Edgescan challenging, affecting usability and data accessibility.
  • Users report experiencing slow performance as scans can take longer due to manual review processes.
  • Users find the UI not user friendly, lacking intuitiveness and advanced features for better navigation and data accessibility.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Heimdal

Accommodate all your cybersecurity needs under one convenient roof with the Heimdal® Unified Cybersecurity Platform. Our cybersecurity solutions can be used as standalone products or integrated into one another as part of a cohesive and unified XDR platform. Whether you’re a reseller, distributor, MSSP, or an organization committed to bolstering your online security, we provide an array of cutting-edge products to make your mission smoother. Heimdal® is a fast-growing cybersecurity company focused on continuous technological innovation. Since its establishment in 2014 in Copenhagen, based on the winning idea of CTF World Champions, Heimdal has experienced spectacular growth by proactively building products that anticipate threatscape trends. The company offers a multi-layeredand unified security suite that combines threat prevention, patch and asset management, endpoint rights management, antivirus and mail security which together secure customers against cyberattacks and keep critical information and intellectual property safe. Heimdal has been recognized as a thought leader in the industry and has won multiple international awards both for its solutions and for its educational content creation. The Heimdal line of products currently consists of 10 products and 2 services. The former category encompasses DNS Security for Endpoints & Network, Patch & Asset Management, Privileged Access Management, Application Control, Next-Gen Endpoint Antivirus, Ransomware Encryption Protection, Email Security, Email Fraud Prevention, and Remote Desktop. The latter is represented by Endpoint Detection & Response, as well as eXtended Detection & Response, or EDR and XDR for short. Currently, Heimdal’s cybersecurity solutions are deployed in more than 45 countries and supported regionally from offices in 15+ countries, by 175+ highly qualified specialists. Heimdal is ISAE 3000 certified and secures more than 2 million endpoints for over 10,000 companies. The company supports its partners without concessions on the basis of predictability and scalability. The common goal is to create a sustainable ecosystem and a strategic partnership.

Average Rating: 4.4/5.0

Total Reviews: 76

How Do G2 Users Rate Heimdal?

  • Ease of Admin: 8.3/10 (Category avg: 8.9/10)

Who Is the Company Behind Heimdal?

  • Seller: Heimdal®
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Copenhagen, Denmark
  • Twitter: @HeimdalSecurity
    5,086 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    277 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Construction
  • Company Size: 58% Medium, 27% Small

What Do G2 Reviewers Say About Heimdal?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the simple and straightforward user interface of Heimdal, making it accessible for entry-level personnel.
  • Users commend Heimdal's exceptional customer support, noting prompt responses and professional assistance that often exceeds expectations.
  • Users value the robust security of Heimdal, noting its reliability and user-friendly interface for effective defense.
  • Users praise Heimdal for its reliable security solutions, delivering consistent performance and dependable support for their needs.
  • Users value Heimdal for its reliable security solutions and responsive 24/7 support, enhancing user confidence.
Cons
  • Users face significant access issues with Heimdal's admin portal, finding navigation complex and essential resources hard to locate.
  • Users find the complex interface of Heimdal frustrating, struggling with navigation and accessing essential features.
  • Users find the limited customization options frustrating, particularly in navigating the complex admin portal and UI.
  • Users find Heimdal not user-friendly due to its complex admin portal and difficult navigation for essential tasks.
  • Users report challenges with poor customer support during initial setup, affecting overall experience and efficiency.

What Are Recent G2 Reviews of Heimdal?

Detectify

Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it's too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain & cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Detectify?

  • Vulnerability Intelligence: 9.0/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.4/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.7/10 (Category avg: 8.9/10)

Who Is the Company Behind Detectify?

  • Seller: Detectify
  • Year Founded: 2013
  • HQ Location: Stockholm, Sweden
  • Twitter: @detectify
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    94 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Small, 35% Medium

What Do G2 Reviewers Say About Detectify?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the automation capabilities of Detectify, enjoying seamless integration and tailored security testing processes.
  • Users value the easy automation and integration features of Detectify that enhance security testing efficiently.
  • Users value the customizability of Detectify, enabling easy integration and tailored security testing to fit diverse needs.
  • Users appreciate the easy integration and comprehensive features of Detectify for efficient security testing.
  • Users appreciate Detectify for its effective dynamic application security testing, ensuring comprehensive security without complex setups.
Cons
  • Users find the initial complexity of setting up Detectify to be a challenging aspect of the product.
  • Users find the complex queries in Detectify challenging, impacting clarity on spidering results and app assessment.
  • Users find the complex setup of Detectify to be a challenging start, impacting its usability for newcomers.
  • Users find Detectify to be expensive when testing multiple sites, impacting its affordability for small operations.
  • Users find inaccuracy in outcomes from Detectify's spidering, lacking clarity on app assessment completeness.

What Are Recent G2 Reviews of Detectify?

What Are G2 Users Discussing About Detectify?

Evolve Security

Evolve Security's patent pending Darwin Attack® platform is a comprehensive collaboration and management tool designed to help organizations manage their cybersecurity services and reduce risks of successful cyberattacks. The platform serves as a repository for research, vulnerability and attack details, compliance requirements, remediation recommendations, and mitigating controls. It also functions as a security feed, collaboration tool, tracking tool, management platform, and reporting platform. The platform enables organizations to actively manage their security program by providing real-time updates on testing progress and findings, which allows for timely remediation. Darwin Attack® is constantly updated with new information and functionality to ensure that it remains effective and efficient in meeting the needs of Evolve Security's clients.

Average Rating: 4.8/5.0

Total Reviews: 53

How Do G2 Users Rate Evolve Security?

  • Vulnerability Intelligence: 9.6/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.0/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.3/10 (Category avg: 8.9/10)

Who Is the Company Behind Evolve Security?

  • Seller: Evolve Security
  • Year Founded: 2016
  • HQ Location: Chicago, Illinois
  • Twitter: @theevolvesec
    788 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    65 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services
  • Company Size: 70% Medium, 21% Small

What Do G2 Reviewers Say About Evolve Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the actionable intelligence provided by Evolve Security, enhancing their ability to address vulnerabilities effectively.
  • Users value the effective vulnerability detection and guidance provided by Evolve Security's expert team.
  • Users commend Evolve Security's effective vulnerability identification, providing clear instructions and communication throughout the process.
  • Users value the thorough audit support provided, ensuring clear communication and effective remediation of vulnerabilities.
  • Users commend the excellent communication from Evolve Security, facilitating clear understanding and collaboration during pentesting.

What Are Recent G2 Reviews of Evolve Security?

VIPRE Endpoint Security Cloud

VIPRE Endpoint Security Cloud is a next-generation antivirus (NGAV) platform, a.k.a. Endpoint Protection Platform (EPP), that detects and blocks malicious activity on your Microsoft Windows and Apple MacOS desktops, laptops, and servers. Consistently ranked at the top of independent testing agencies' lists, VIPRE combines excellent detection with low false positives, minimal system impact, and an easy to use mobile-ready administrative console. Packed with other goodies such as integrated vulnerability and patch management, web access control, and DNS protection, VIPRE will keep you safe against even the most sophisticated threats.

Average Rating: 4.3/5.0

Total Reviews: 56

How Do G2 Users Rate VIPRE Endpoint Security Cloud?

  • Vulnerability Intelligence: 6.7/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 10.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 5.0/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.5/10 (Category avg: 8.9/10)

Who Is the Company Behind VIPRE Endpoint Security Cloud?

  • Seller: VIPRE Security
  • Year Founded: 1994
  • HQ Location: Clearwater, FL
  • Twitter: @VIPRESecurity
    8,293 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    236 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 48% Small, 43% Medium

What Do G2 Reviewers Say About VIPRE Endpoint Security Cloud?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of VIPRE Endpoint Security Cloud, finding its management console very efficient.
  • Users value the alert notifications from VIPRE Endpoint Security Cloud, enhancing their awareness and response to potential threats.
  • Users find Vipre Endpoint Security Cloud to be easy to install and efficient, providing reliable protection without hassle.
  • Users appreciate the central management console of VIPRE Endpoint Security Cloud, simplifying network management significantly.
  • Users value the centralized management console of VIPRE Endpoint Security Cloud for simplifying network management effectively.
Cons
  • Users note that backup issues persist, particularly regarding the restoration of removed email links.
  • Users note a lack of important features, particularly regarding link restoration in emails that need enhancements.
  • Users note that the link restoration feature in VIPRE Endpoint Security Cloud requires improvement for better usability.

What Are Recent G2 Reviews of VIPRE Endpoint Security Cloud?

What Are G2 Users Discussing About VIPRE Endpoint Security Cloud?

Glasstrail

Glasstrail is a cloud-native External Attack Surface Management (EASM) platform designed to help organizations continuously discover, monitor, and remediate vulnerabilities across their entire digital footprint. By identifying exposed assets—such as domains, subdomains, IP addresses, and cloud services—Glasstrail enables businesses to proactively manage their external attack surface, reducing the risk of cyber threats. Key Features and Functionality: - Automated Vulnerability Detection: Conducts regular scans to identify issues like breached account credentials, misconfigured DNS and email security policies, untrusted SSL certificates, and website vulnerabilities. - Comprehensive Asset Inventory: Maintains an up-to-date inventory of external assets, including web technologies, domains, IP addresses, cloud services, and social media profiles. - Risk Prioritization and Remediation Guidance: Provides actionable insights with clear descriptions to help organizations understand and address identified risks effectively. - Dashboard and Reporting: Offers a visual dashboard to track risks, remediation activities, and progress over time, along with options to download and share reports. - Notifications and Integrations: Allows users to set up notification rules for new findings and integrates with existing security tools and platforms for streamlined workflows. Primary Value and Problem Solved: Glasstrail addresses the challenge of managing an organization's external attack surface by providing continuous monitoring and proactive identification of vulnerabilities. This enables businesses to detect and remediate potential security risks before they can be exploited by malicious actors, thereby enhancing overall cybersecurity posture and protecting sensitive data and systems.

Average Rating: 4.6/5.0

Total Reviews: 19

How Do G2 Users Rate Glasstrail?

  • Vulnerability Intelligence: 9.7/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 9.6/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 9.5/10 (Category avg: 8.6/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.9/10)

Who Is the Company Behind Glasstrail?

Who Uses This Product?

  • Company Size: 38% Medium, 38% Small

What Do G2 Reviewers Say About Glasstrail?

AI-generated summary from verified user reviews

Pros
  • Users commend the easy integrations of Glasstrail, enhancing productivity and streamlining workflows effortlessly.
  • Users value the automation features of Glasstrail, which enhance security and streamline system management effortlessly.
  • Users appreciate the effective detection of external assets and valuable monitoring features of Glasstrail.
  • Users find the monitoring efficiency of Glasstrail exceptional, aiding in productivity and effective risk management.
  • Users value the strong cybersecurity protection of Glasstrail, ensuring safety for their data and systems.
Cons
  • Users find Glasstrail to be expensive, particularly for smaller organizations when compared to more affordable options.
  • Users find the complexity of Glasstrail challenging, especially when multiple stakeholders need to collaborate on settings.
  • Users feel the user interface is complex and require significant upgrades for better usability and experience.
  • Users experience false positives with Glasstrail, encountering incorrect data capture that leads to confusion.
  • Users find the lack of integration limits the accessibility of advanced features in Glasstrail, requiring technical expertise.

What Are Recent G2 Reviews of Glasstrail?

Ethiack

Ethiack is an autonomous offensive security platform that continuously tests and validates vulnerability exploitation across entire attack surfaces using agentic AI pentesting and hacker intelligence so security teams fix what matters before attackers strike. Traditional pentests give you a snapshot. Ethiack runs 24/7, combining agentic AI pentesting and human hacker intelligence to validate real-world risks with near-zero false positives. Stop triaging scanner noise. Know what attackers can actually exploit, right now. What you get: - Continuous Adversarial Exposure Validation (AEV) - 99.5% precision on exploitable vulnerabilities - 90% noise reduction - 80% faster remediation (MTTR) - <10 min setup, no installation required - Coverage across +200 vulnerability classes and +1500 technologies - Proof-of-exploit for every validated risk

Average Rating: 4.4/5.0

Total Reviews: 14

How Do G2 Users Rate Ethiack?

  • Vulnerability Intelligence: 8.9/10 (Category avg: 9.0/10)
  • Continuous Monitoring: 8.0/10 (Category avg: 9.2/10)
  • Compliance Monitoring: 7.2/10 (Category avg: 8.6/10)
  • Ease of Admin: 9.1/10 (Category avg: 8.9/10)

Who Is the Company Behind Ethiack?

  • Seller: Ethiack
  • Year Founded: 2022
  • HQ Location: Coimbra, Coimbra, Portugal
  • LinkedIn® Page: www.linkedin.com
    52 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Medium, 33% Small

What Do G2 Reviewers Say About Ethiack?

AI-generated summary from verified user reviews

Pros
  • Users commend the exceptional customer support of Ethiack, highlighting its responsiveness and understanding of client needs.
  • Users value the exceptional cybersecurity support from Ethiack, enhancing their platform's security and user confidence.
  • Users commend the innovation in security practices provided by Ethiack, enhancing platform protection and team engagement.
  • Users value the automation capabilities of Ethiack, enhancing vulnerability detection and streamlining security in development processes.
  • Users value the real-time monitoring of Ethiack, enhancing security through continuous insights and proactive development integration.
Cons
  • Users find the high cost of Ethiack challenging for scaling testing across all critical assets.
  • Users find the high cost of Ethiack makes scaling testing across critical assets challenging.
  • Users are frustrated by the lack of scheduling automation, making it difficult to set scans for specific dates/times.
  • Users find the limited features in Ethiack somewhat underdeveloped, impacting overall user experience and functionality.
  • Users find the missing features in Ethiack limit the security enhancements for their API-based applications.

What Are Recent G2 Reviews of Ethiack?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated April 10, 2026