# Best Penetration Testing Tools

*By [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)*


Penetration testing tools are used to test vulnerabilities within computer systems and applications. These tools work by simulating cyberattacks that target known vulnerabilities as well as general application components in an attempt to breach core systems. Companies conduct penetration tests to uncover new defects and test the security of communication channels and integrations.

While the [best penetration testing tools](https://learn.g2.com/best-penetration-testing-tools) are related to [application security software](https://www.g2.com/categories/application-security) and [vulnerability management software](https://www.g2.com/categories/vulnerability-management), only these tools specifically perform penetration tests. There are also a number of [cybersecurity services providers](https://www.g2.com/categories/security-and-privacy-services) that offer [penetration testing services](https://www.g2.com/categories/penetration-testing-services).

To qualify for inclusion in the Penetration Testing category, a product must:

- Simulate cyberattacks on computer systems or applications
- Gather intelligence on potential known vulnerabilities
- Analyze exploits and report on test outcomes





---
## What Are the Most Common Questions About Penetration Testing Tools?
*AI-generated · Last updated: May 26, 2026*
### What platform integrates penetration testing with security monitoring tools?
Based on G2 reviews, several penetration testing platforms mention integrations that help security teams connect findings to their broader workflows. According to verified users, [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) stands out for integrations with Slack, ticketing systems, APIs, and Google Sheets workflows, which reviewers say helps teams collaborate with testers and move findings into remediation faster. G2 reviewers also mention platforms like [Edgescan](https://www.g2.com/products/edgescan/reviews) and [Strobes Security](https://www.g2.com/products/strobes-security/reviews) for connecting with Jira and other security operations processes. Across reviews, buyers most often value integrations that reduce back-and-forth, keep findings visible, and support ongoing vulnerability tracking rather than one-time reporting.


### What platform provides compliance-focused penetration testing?
Based on G2 reviews, compliance is a common reason buyers choose penetration testing tools, but [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) appears most often in recent review data and is frequently described as helping teams meet annual testing, PCI, SOC 2, HIPAA, and broader audit requirements. According to verified users, reviewers value its straightforward reporting, retesting workflows, and support for external and internal assessments tied to compliance needs. G2 reviewers mention that it helps security teams demonstrate requirements to customers and auditors while giving developers findings they can act on. Reviews also note tradeoffs such as pricing and occasional variation in tester depth, but compliance support and easy-to-share reports are recurring strengths.


### Which vendor offers AI-powered threat simulation?
Based on G2 reviews, [Pentera](https://www.g2.com/products/pentera/reviews) is the clearest fit for AI-powered threat simulation in this category. According to verified users, reviewers describe Pentera as automating attack simulation in a way that mimics real attackers, validates exploitable paths, and helps teams focus on real risk rather than broad vulnerability lists. G2 reviewers mention AI-driven insights, automated validation, and continuous testing as strengths that help security teams prioritize remediation and reduce manual effort. Some users also note setup complexity, reporting customization limits, or higher cost, but the reviews consistently frame Pentera as a platform built around automated attack emulation and validation rather than just traditional scanning.


### Which penetration testing platform offers the most comprehensive vulnerability coverage?
Based on G2 reviews, buyers describe comprehensive coverage in different ways, including application, network, API, cloud, and continuous testing support. According to verified users, [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) is praised for external and internal testing, application assessments, collaboration with testers, and retesting. G2 reviewers also highlight [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) for combining automated scanning with manual validation across web apps, APIs, and cloud-related findings, while [vPenTest](https://www.g2.com/products/vpentest/reviews) is often cited for broad automated internal and external coverage with clear reports. In reviews, the most comprehensive platforms tend to balance strong discovery, practical remediation guidance, and enough testing breadth to support both engineering and compliance goals.

**Here are some of the top-rated products on G2:**

- [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) – often used for external, internal, application, and compliance-driven testing with collaborative remediation workflows
- [vPenTest](https://www.g2.com/products/vpentest/reviews) – commonly used for automated internal and external testing with clear reporting for recurring assessments
- [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) – frequently chosen for web app, API, and cloud-related testing with validated findings and responsive support


### What is the most affordable penetration testing software for SMBs?
Based on G2 reviews, affordability for SMBs usually means faster setup, repeatable testing, and lower overhead than traditional engagements. According to verified users, [vPenTest](https://www.g2.com/products/vpentest/reviews) is often described as a cost-effective option for smaller businesses and MSPs because it supports recurring testing, clear customer-friendly reporting, and easier self-managed workflows. G2 reviewers mention that it helps teams test more frequently without the effort and delay of manual-only engagements. Reviewers also note that some findings may still need manual verification and that scan or report turnaround can vary, but the platform is repeatedly framed as strong value for teams that need practical security coverage on tighter budgets.

**Here are some of the top-rated products on G2:**

- [vPenTest](https://www.g2.com/products/vpentest/reviews) – often chosen by MSPs and smaller teams for affordable recurring internal and external testing
- [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) – reviewers describe it as reasonable for some use cases, especially when teams value reporting and tester collaboration
- [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) – users often highlight strong value from validated findings, responsive support, and efficient remediation workflows


### Which vendor provides real-time penetration testing reports?
Based on G2 reviews, [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) is most consistently associated with real-time penetration testing visibility. According to verified users, reviewers say vulnerabilities appear in the dashboard as testers discover them, which allows teams to ask questions immediately, validate fixes faster, and keep remediation aligned with development work. G2 reviewers mention direct collaboration through the platform and Slack, plus continuous updates rather than waiting only for a final report. While some reviews note variability in tester quality or report interface improvements they would like to see, the recurring theme is immediate findings visibility and active communication during the engagement rather than delayed, static reporting.


### What is the top-rated penetration testing platform for enterprises?
Based on G2 reviews, enterprise buyers tend to prioritize scalability, reporting, collaboration, and dependable remediation workflows. According to verified users, [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) is the most visible choice in recent review data and is often described as fitting enterprise needs through real-time findings visibility, ticketing integrations, structured retesting, and support for recurring application and infrastructure testing. G2 reviewers mention that it works well for security teams that need to coordinate across engineering, compliance, and stakeholder reporting. Some users note pricing or scoping constraints, but reviews repeatedly describe Cobalt as a mature option for organizations managing larger programs and ongoing testing demands.

**Here are some of the top-rated products on G2:**

- [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) – frequently used by larger teams for collaborative testing, retesting, and integration with engineering workflows
- [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) – valued for dashboard visibility, manual-plus-automated testing, and structured support through remediation
- [vPenTest](https://www.g2.com/products/vpentest/reviews) – used for scalable recurring assessments with strong reporting and self-managed scheduling


### Which tool supports penetration testing for cloud environments?
Based on G2 reviews, several products are used for cloud-related penetration testing, but buyers often call out support for cloud apps, infrastructure visibility, and validation of cloud exposures. According to verified users, [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) is noted for cloud target integration and reviews that cover misconfigurations, exposed services, IAM gaps, and broader attack-surface visibility. G2 reviewers also mention [Intruder](https://www.g2.com/products/intruder/reviews) for scanning cloud resources across environments like AWS and Azure, and [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) for cloud and web application tests scheduled around changing development needs. In reviews, the strongest cloud tools combine clear reporting with practical remediation guidance.


### What is the best tool for simulating cyberattacks?
Based on G2 reviews, the best fit for cyberattack simulation depends on whether teams want validated attack paths, automation, or continuous testing. According to verified users, [Pentera](https://www.g2.com/products/pentera/reviews) is repeatedly described as simulating real attacker behavior, including lateral movement, validation of exploitable weaknesses, and clear attack-path organization. G2 reviewers mention that it helps teams understand real risk, reduce manual effort, and focus remediation on what is actually actionable. Reviews also note occasional concerns around installation complexity, reporting customization, or cost, but the product is consistently positioned as a strong option for organizations that want realistic attack simulation rather than basic vulnerability discovery alone.

**Here are some of the top-rated products on G2:**

- [Pentera](https://www.g2.com/products/pentera/reviews) – designed for attacker-style simulation with validated attack paths and remediation guidance
- [NodeZero from Horizon3.ai](https://www.g2.com/products/nodezero-from-horizon3-ai/reviews) – used for automated attack-path testing and repeated validation after fixes
- [RidgeBot](https://www.g2.com/products/ridgebot/reviews) – valued for simulating exploitability and helping teams prioritize risks based on validated impact


### Which solution supports both automated and manual penetration testing?
Based on G2 reviews, [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) is strongly associated with combining automated scanning and manual penetration testing in one workflow. According to verified users, reviewers say this approach helps validate findings, reduce false positives, and keep teams focused on real issues instead of generic scanner output. G2 reviewers mention a unified dashboard, responsive support, and easier tracking of findings, remediation, and certification-related progress. Some users would like smoother onboarding or faster communication in certain cases, but the recurring review pattern is clear: Astra is chosen by teams that want the efficiency of automation alongside human verification and collaborative remediation support.




## How Many Penetration Testing Tools Products Does G2 Track?
**Total Products under this Category:** 131

### Category Stats (Jul 2026)
- **Average Rating**: 4.64/5 (↑0.02 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product**: CybaOps (+8.33%) - Among all products in this category, CybaOps recorded the largest rating increase compared to last month
*Last updated: July 04, 2026*


## How Does G2 Rank Penetration Testing Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 3,300+ Authentic Reviews
- 131+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.


## Which Penetration Testing Tools Is Best for Your Use Case?

- **Leader:** [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews)
- **Highest Performer:** [Sprocket Security](https://www.g2.com/products/sprocket-security/reviews)
- **Easiest to Use:** [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews)
- **Top Trending:** [Pentera](https://www.g2.com/products/pentera/reviews)
- **Best Free Software:** [vPenTest](https://www.g2.com/products/vpentest/reviews)


---

**Sponsored**

### Sprocket Security

By combining automation with expert-driven human testing, Sprocket Security delivers Continuous Penetration Testing to help businesses continuously validate their security posture and resilience. This innovative solution is tailored for organizations seeking to enhance their cybersecurity measures by proactively identifying vulnerabilities and assessing their defenses against potential threats. By employing a year-round testing methodology, Sprocket Security ensures that businesses remain vigilant and prepared in the ever-evolving landscape of cyber threats. The platform primarily targets organizations of all sizes that are committed to improving their security frameworks. Sprocket Security is particularly beneficial for IT and security teams that need to stay ahead of emerging attack techniques and adapt to changes in their IT structures. With features such as Attack Surface Management, Continuous Penetration Testing, and Adversary Simulation, Sprocket Security provides a comprehensive suite of tools that empower businesses to prioritize offensive security measures effectively. One of the key features of Sprocket Security is its Attack Surface Management, which allows organizations to gain visibility into their digital assets and potential vulnerabilities. By continuously monitoring and analyzing the attack surface, businesses can identify weak points before they are exploited by malicious actors. Additionally, the platform offers Continuous Penetration Testing, which simulates real-world attack scenarios to evaluate the effectiveness of existing security controls. This ongoing testing approach ensures that organizations can adapt their defenses in response to new threats and vulnerabilities. Another significant aspect of Sprocket Security is its commitment to retesting. Whenever a new attack technique emerges, a change occurs in the IT infrastructure, or a finding is patched, Sprocket Security provides unlimited retests at no additional cost. This feature not only enhances the overall security posture of an organization but also fosters a culture of continuous improvement and vigilance. By prioritizing offensive security, businesses can reduce their IT risk and enhance their resilience against cyber threats. Overall, Sprocket Security stands out in the cybersecurity landscape by offering a robust and flexible solution that integrates both automated and human-driven testing methodologies. This unique combination allows organizations to maintain a proactive stance against cyber threats, ensuring that their security measures evolve in tandem with the dynamic nature of the digital landscape.



[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&amp;secure%5Bad_slot%5D=category_product_list&amp;secure%5Bcategory_id%5D=1519&amp;secure%5Bchosen_at%5D=2026-07-05T01%3A32%3A21Z&amp;secure%5Bdisplayable_resource_id%5D=1519&amp;secure%5Bdisplayable_resource_type%5D=Category&amp;secure%5Bmedium%5D=sponsored&amp;secure%5Bplacement_reason%5D=page_category&amp;secure%5Bplacement_resource_ids%5D%5B%5D=1519&amp;secure%5Bprioritized%5D=false&amp;secure%5Bproduct_id%5D=1380783&amp;secure%5Bresource_id%5D=1519&amp;secure%5Bresource_type%5D=Category&amp;secure%5Bsource_type%5D=category_page&amp;secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fpenetration-testing-tools&amp;secure%5Btoken%5D=aae54a1100b0b54db7245f04e8d9b9bc6d9287e4caac5e30b11a72d71ed55a8e&amp;secure%5Burl%5D=https%3A%2F%2Fwww.sprocketsecurity.com%2F&amp;secure%5Burl_type%5D=custom_url)

---

## What Are the Top-Rated Penetration Testing Tools Products in 2026?
### 1. [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews)
Cobalt is the pioneer in pentesting as a service (PTaaS) and a leader in human-led, AI-powered offensive security services. We are focused on combining talent and technology with speed, scalability, and expertise. Thousands of customers and hundreds of partners rely on the Cobalt Offensive Security Platform, along with 500+ trusted security experts, to find and fix vulnerabilities across their environments. By enabling faster pentest launches, real-time collaboration with pentesters, and seamless integration with remediation workflows, we help organizations identify critical issues and accelerate risk mitigation so they can operate fearlessly and innovate securely.


**Average Rating:** 4.5/5.0
**Total Reviews:** 176
**How Do G2 Users Rate Cobalt?**

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.1/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 8.7/10 (Category avg: 9.1/10)
- **Extensibility:** 8.5/10 (Category avg: 8.7/10)

**Who Is the Company Behind Cobalt?**

- **Seller:** [Cobalt](https://www.g2.com/sellers/cobalt-33275b9c-c870-4949-8fd5-a68eb12f96bb)
- **Company Website:** https://cobalt.io/
- **Year Founded:** 2013
- **HQ Location:** San Francisco, California
- **Twitter:** @cobalt_io (8,462 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/cobalt_io/ (557 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** CTO, Security Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 51% Mid-Market, 23% Small-Business


#### What Are Cobalt's Pros and Cons?

**Pros:**

- Pentesting Efficiency (50 reviews)
- Customer Support (40 reviews)
- Ease of Use (39 reviews)
- Communication (31 reviews)
- Reporting Quality (28 reviews)

**Cons:**

- Expensive (14 reviews)
- Limited Scope (8 reviews)
- Lack of Detail (7 reviews)
- Pricing Issues (6 reviews)
- Inaccuracy (5 reviews)


### What Do G2 Reviewers Say About Cobalt?
*AI-generated summary from verified user reviews*

**Pros:**

- Users praise Cobalt for its **immediate reporting and seamless pentesting efficiency** , ensuring a stress-free experience overall.
- Users value Cobalt&#39;s **exceptional customer support** , which significantly enhances their application security experience and confidence.
- Users appreciate the **ease of use** of Cobalt, enjoying seamless pentesting with immediate reports and excellent support.
- Users value the **constant communication** and transparency provided by Cobalt, enhancing their overall experience and collaboration.
- Users value the **immediate reporting quality** of Cobalt, appreciating its seamless and thorough pentest management.

**Cons:**

- Users find Cobalt to be **expensive** , particularly for smaller organizations with limited budgets and needs.
- Users find the **limited scope** of Cobalt&#39;s testing ineffective, resulting in superficial assessments and overlooked vulnerabilities.
- Users note a **lack of detail** in instructions, leading to confusion and requiring more guidance from the Cobalt team.
- Users find Cobalt&#39;s **pricing issues** confusing, suggesting a need for review and clearer integration costs.
- Users experience **inaccuracy** in Cobalt audits, with inconsistent scoping and variable quality in testing reports.

#### What Are Recent G2 Reviews of Cobalt?

**"[Collaborative, Real-World Pentesting with Actionable Findings](https://www.g2.com/survey_responses/cobalt-review-12683090)"**

**Rating:** 5.0/5.0 stars
*— Arpit G.*

[Read full review](https://www.g2.com/survey_responses/cobalt-review-12683090)

---

**"[Flexible Scheduling and Clear, Consistent Pen Test Communication](https://www.g2.com/survey_responses/cobalt-review-12678239)"**

**Rating:** 4.0/5.0 stars
*— Chris A.*

[Read full review](https://www.g2.com/survey_responses/cobalt-review-12678239)

---


#### What Are G2 Users Discussing About Cobalt?

- [How do you use Cobalt?](https://www.g2.com/discussions/how-do-you-use-cobalt)
- [What is cobalt database?](https://www.g2.com/discussions/what-is-cobalt-database)
- [What is a cobalt developer?](https://www.g2.com/discussions/what-is-a-cobalt-developer)
- [Is cobalt an operating system?](https://www.g2.com/discussions/is-cobalt-an-operating-system)

### 2. [vPenTest](https://www.g2.com/products/vpentest/reviews)
Vonahi Security is building the future of offensive cybersecurity by delivering automated, high-quality penetration testing through its SaaS platform, vPenTest. Designed to replicate the tools, techniques, and methodologies of experienced consultants, vPenTest brings the benefits of manual network penetration testing into an easy-to-use, automated solution. Traditionally, penetration testing has been a manual, time consuming, and expensive process that many organizations only perform once or twice a year. This often leaves businesses exposed to emerging threats between assessments. vPenTest addresses this gap by offering fast, consistent, and on-demand testing that helps organizations evaluate their real-time cybersecurity risk more effectively. Powered by a proprietary framework that evolves through continuous research and real-world insights, vPenTest stays aligned with the latest attack techniques and industry best practices. The platform is backed by over 13 years of offensive security expertise, with the team holding certifications such as CISSP, OSCP, OSCE, CEH, and more. Their knowledge is built directly into the platform, ensuring each test is conducted with depth, consistency, and accuracy—without the delays or variability of manual testing.  vPenTest enables organizations to run internal and external network penetration tests as often as needed monthly, quarterly, or prior to audits or insurance reviews. The automated reports provide actionable insights that make it easy to prioritize remediation and demonstrate progress toward compliance. Today, over 22,000 organizations rely on vPenTest to strengthen their security posture and reduce risk. This includes managed service providers, managed security service providers, financial institutions, compliance-driven organizations, and internal IT teams. Whether you&#39;re working to meet regulatory requirements, secure cyber insurance coverage, or proactively defend against evolving threats, vPenTest makes network penetration testing easy, affordable, and scalable.


**Average Rating:** 4.6/5.0
**Total Reviews:** 238
**How Do G2 Users Rate vPenTest?**

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.1/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.0/10 (Category avg: 9.1/10)
- **Extensibility:** 8.5/10 (Category avg: 8.7/10)

**Who Is the Company Behind vPenTest?**

- **Seller:** [Kaseya](https://www.g2.com/sellers/kaseya)
- **Company Website:** https://www.kaseya.com/
- **Year Founded:** 2000
- **HQ Location:** Miami, FL
- **Twitter:** @KaseyaCorp (17,411 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/kaseya/ (5,471 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** CEO
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 68% Small-Business, 25% Mid-Market


#### What Are vPenTest's Pros and Cons?

**Pros:**

- Ease of Use (25 reviews)
- Reporting Quality (23 reviews)
- Pentesting Efficiency (22 reviews)
- Setup Ease (15 reviews)
- Ease of Implementation (12 reviews)

**Cons:**

- Complex Setup (7 reviews)
- Limited Scope (7 reviews)
- Expensive (5 reviews)
- Inadequate Reporting (5 reviews)
- Lack of Detail (5 reviews)


### What Do G2 Reviewers Say About vPenTest?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find vPenTest **easy to use** , with an intuitive interface that enhances efficiency for beginners and experts alike.
- Users find the **reporting quality** of vPenTest exceptional, providing detailed, reliable insights that enhance client satisfaction.
- Users value the **pentesting efficiency** of vPenTest, appreciating its user-friendly interface and streamlined testing process.
- Users find vPenTest&#39;s **setup ease** exceptional, facilitating quick integration and management across multiple clients effortlessly.
- Users appreciate the **ease of implementation** of vPenTest, finding it seamless and quick to integrate into their workflow.

**Cons:**

- Users find the **complex setup** of vPenTest to be challenging, requiring multiple attempts and leading to frustration.
- Users express frustration with the **limited scope** of vPenTest, feeling it misses key pentest elements and known issues.
- Users find vPenTest **expensive** , especially due to pricing structures that challenge smaller organizations effectively.
- Users find the **inadequate reporting** of vPenTest limiting, with repetitive findings and short report availability causing frustration.
- Users find the **lack of detail** in vPenTest requires additional explanation, complicating the overall user experience.

#### What Are Recent G2 Reviews of vPenTest?

**"[Great Product, Easy to Use, does exactly as described.](https://www.g2.com/survey_responses/vpentest-review-9009510)"**

**Rating:** 5.0/5.0 stars
*— Kamran H.*

[Read full review](https://www.g2.com/survey_responses/vpentest-review-9009510)

---

**"[Fast, Actionable Pen Testing Baselines with Clear, Customer-Ready Reports](https://www.g2.com/survey_responses/vpentest-review-12881608)"**

**Rating:** 4.5/5.0 stars
*— Darren .*

[Read full review](https://www.g2.com/survey_responses/vpentest-review-12881608)

---



### 3. [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews)
Astra Security is a leading continuous penetration testing platform that combines AI-powered autonomous pentesting with certified expert-led assessments. Powered by Attack AI, trained on 6.8M+ security findings and insights from 5,000+ real-world pentests. Astra deploys intelligent agents that continuously discover, validate, prioritize, and help remediate vulnerabilities at scale. While AI handles speed and scale, Astra’s certified security experts focus on what automation alone cannot: complex business logic flaws, multi-step attack chains, advanced exploit paths, and emerging AI/LLM-specific threats. Built for modern engineering teams, Astra integrates directly into CI/CD workflows, enabling continuous security validation between releases instead of relying on outdated annual pentests. The platform delivers comprehensive Autonomous Pentest powered by AI agents, DAST vulnerability scanner and human-driven pentests across web apps, AI/LLMs, mobile apps, APIs, cloud infrastructure. Astra is CREST-accredited, CERT-IN empaneled, and a PCI ASV-certified vendor. Our team also led the development of the OWASP APTS framework, helping shape the industry standard for continuous security testing. Today, 1,500+ organizations across 70+ countries trust Astra Security, including Ford, Loom, CompTIA, Hitachi, HackerRank, and OLX.


**Average Rating:** 4.6/5.0
**Total Reviews:** 203
**How Do G2 Users Rate Astra Pentest?**

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.0/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.0/10 (Category avg: 9.1/10)
- **Extensibility:** 8.1/10 (Category avg: 8.7/10)

**Who Is the Company Behind Astra Pentest?**

- **Seller:** [ASTRA IT, Inc.](https://www.g2.com/sellers/astra-it-inc)
- **Company Website:** https://www.getastra.com/
- **Year Founded:** 2018
- **HQ Location:** New Delhi, IN
- **Twitter:** @getastra (694 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/getastra/ (130 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** CTO, CEO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 65% Small-Business, 29% Mid-Market


#### What Are Astra Pentest's Pros and Cons?

**Pros:**

- Customer Support (63 reviews)
- Vulnerability Detection (51 reviews)
- Ease of Use (50 reviews)
- Pentesting Efficiency (42 reviews)
- Vulnerability Identification (37 reviews)

**Cons:**

- Poor Customer Support (12 reviews)
- Poor Interface Design (10 reviews)
- Slow Performance (8 reviews)
- UX Improvement (7 reviews)
- Lack of Information (6 reviews)


### What Do G2 Reviewers Say About Astra Pentest?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend the **responsive customer support** of Astra Pentest, highlighting their flexibility and exceptional service throughout the process.
- Users value the **comprehensive vulnerability management features** of Astra Pentest, enhancing security tracking and prioritization.
- Users appreciate the **ease of use** of Astra Pentest, enjoying its straightforward implementation and user-friendly design.
- Users value the **quick and efficient penetration testing** provided by Astra Pentest, ensuring timely and successful outcomes.
- Users value the **thorough vulnerability identification** by Astra Pentest, enhancing security confidence and providing valuable solutions.

**Cons:**

- Users experience **poor customer support** with slow response times and a lack of assistance for vulnerability queries.
- Users criticize the **poor interface design** of Astra Pentest, finding it clunky and non-intuitive for effective use.
- Users experience **slow performance** with Astra Pentest, affecting the speed of testing results and overall efficiency.
- Users note that **UX improvement** is necessary due to confusing UI and occasional false positives during scans.
- Users note a **lack of information** in documentation, causing delays and uncertainty in obtaining crucial audit status updates.

#### What Are Recent G2 Reviews of Astra Pentest?

**"[Smooth Onboarding, Responsive Support, and Strong Pentest Lifecycle Controls](https://www.g2.com/survey_responses/astra-pentest-review-13001206)"**

**Rating:** 5.0/5.0 stars
*— Sivakumar S.*

[Read full review](https://www.g2.com/survey_responses/astra-pentest-review-13001206)

---

**"[Exceptional VAPT Solution with Prompt Support](https://www.g2.com/survey_responses/astra-pentest-review-9603864)"**

**Rating:** 5.0/5.0 stars
*— Nikhil Ajit S.*

[Read full review](https://www.g2.com/survey_responses/astra-pentest-review-9603864)

---


#### What Are G2 Users Discussing About Astra Pentest?

- [What is Astra Pentest used for?](https://www.g2.com/discussions/what-is-astra-pentest-used-for) - 2 comments

### 4. [Oneleet](https://www.g2.com/products/oneleet/reviews)
Oneleet is the all-in-one security and compliance platform that gets companies genuinely secure while achieving SOC 2, ISO 27001, HIPAA and other compliance certifications faster than traditional approaches. Unlike compliance platforms that focus on checkbox evidence collection, Oneleet implements real security first. Compliance follows automatically as a natural outcome of effective cybersecurity, not as a separate goal. Most companies face a false choice: painful but effective security, or painless but ineffective compliance theater. Traditional compliance platforms require juggling multiple vendors, managing fragmented tools, spending months with consultants, and doing manual evidence collection to achieve a certificate that doesn&#39;t actually make you secure. Oneleet consolidates what previously required half a dozen vendors into one integrated platform: penetration testing by real security experts (not just vulnerability scans), code scanning with SAST and DAST, cloud security posture management, attack surface monitoring, mobile device management, security training and awareness, policy generation and management, and continuous compliance monitoring. Because we build everything ourselves and control the entire stack, we deploy comprehensive security with a click. No blind spots. No integration gaps. No vendor sprawl. We guarantee audit outcomes because our standards are higher than auditors&#39; standards. We use AI extensively but responsibly, automating threat modeling and risk assessments while keeping humans in the loop to ensure quality. Clients never see AI hallucinations. We take full responsibility for the entire security journey, from initial setup through audit completion and continuous monitoring. Companies achieve compliance readiness faster with Oneleet, not by doing less, but by making real security easier. We ship all the tools you would normally spend weeks or months setting up and adopting. Our customers regularly win deals they previously lost due to inadequate security postures. Oneleet is the fastest growing compliance company in the sector. A large number of Oneleet&#39;s newer clients come from platforms like Vanta and Drata. With Oneleet&#39;s all-in-one bundle pricing its ROI is significantly higher than that of Vanta, Drata and Delve. Companies that switch from Vanta, Drata, or Delve to Oneleet report faster audits, higher approval rates, and less manual effort. Vanta and Drata rely heavily on manual evidence collection and vendor integrations, creating delays and gaps. Delve emphasizes AI automation but often sacrifices accuracy—its generated outputs are frequently rejected or require manual fixes. Oneleet achieves both precision and speed by combining full-stack automation with expert oversight, producing the industry’s lowest audit-rejection rate and the fastest path to verified security. Oneleet serves SMBs and growth-stage companies that need compliance certifications to close enterprise deals, but want to be genuinely secure, not just certified on paper. Founded by professional penetration testers who spent over a decade breaching Fortune 500s and startups, we built Oneleet to end the disconnect between compliance and security.


**Average Rating:** 4.9/5.0
**Total Reviews:** 139
**How Do G2 Users Rate Oneleet?**

- **Performance and Reliability:** 10.0/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 10.0/10 (Category avg: 9.1/10)
- **Extensibility:** 10.0/10 (Category avg: 8.7/10)

**Who Is the Company Behind Oneleet?**

- **Seller:** [Oneleet](https://www.g2.com/sellers/oneleet)
- **Company Website:** https://www.oneleet.com/
- **Year Founded:** 2022
- **HQ Location:** Atlanta, US
- **LinkedIn® Page:** http://www.linkedin.com/company/oneleet (40 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** Engineer
- **Top Industries:** Computer Software, Medical Devices
- **Company Size:** 15% Small-Business, 11% Mid-Market


#### What Are Oneleet's Pros and Cons?

**Pros:**

- Security (302 reviews)
- Compliance (251 reviews)
- Ease of Use (228 reviews)
- Helpful (210 reviews)
- Compliance Management (199 reviews)

**Cons:**

- Integration Issues (22 reviews)
- Limited Customization (21 reviews)
- Limited Integrations (17 reviews)
- Lack of Integration (14 reviews)
- Lack of Customization (13 reviews)


### What Do G2 Reviewers Say About Oneleet?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **continuous monitoring and automation** in Oneleet, enhancing security and simplifying compliance processes.
- Users find Oneleet enhances **compliance management** , making it easier to handle ISO 27001 documentation for enterprise deals.
- Users find Oneleet&#39;s platform to have **exceptional ease of use** , simplifying compliance and providing clear support throughout.
- Users value the **quick and expert responses** from Oneleet, feeling supported like having a senior colleague available.
- Users value the **comprehensive compliance management** features of Oneleet, streamlining documentation and ensuring adherence to various standards.

**Cons:**

- Users report **integration issues** with Oneleet, limiting connection options and requiring support for resolution.
- Users find **limited customization options** in Oneleet, expressing a desire for quicker integration rollouts.
- Users find the **limited integrations** with Oneleet restrict their ability to connect with preferred tools.
- Users note a **lack of integration** with smaller platforms, limiting overall functionality and usability of Oneleet.
- Users feel the **lack of customization** in reports limits their ability to meet specific needs effectively.

#### What Are Recent G2 Reviews of Oneleet?

**"[Oneleet made SOC 2 practical, not painful](https://www.g2.com/survey_responses/oneleet-review-12855748)"**

**Rating:** 4.5/5.0 stars

[Read full review](https://www.g2.com/survey_responses/oneleet-review-12855748)

---

**"[Oneleet&#39;s Speed and AI Automation Exceeded Expectations](https://www.g2.com/survey_responses/oneleet-review-11879146)"**

**Rating:** 5.0/5.0 stars
*— Antoine D.*

[Read full review](https://www.g2.com/survey_responses/oneleet-review-11879146)

---



### 5. [Bugcrowd](https://www.g2.com/products/bugcrowd/reviews)
Bugcrowd frees organizations with a low tolerance for risk from chronic talent shortages, noisy tools that breed false positives, and the fear of critical hidden or emerging vulnerabilities. Our SaaS platform provides access to the unlimited capacity and skills of the global ethical hacker/pentester community for deeper, proactive risk reduction and faster regulatory compliance. With 12+ years of experience and 1200+ customers in every industry (including OpenAI, National Australia Bank, Indeed, USAA, Twilio, and CISA), we know what long-term with crowdsourced security looks like.


**Average Rating:** 4.3/5.0
**Total Reviews:** 60
**How Do G2 Users Rate Bugcrowd?**

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.5/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 8.3/10 (Category avg: 9.1/10)
- **Extensibility:** 8.2/10 (Category avg: 8.7/10)

**Who Is the Company Behind Bugcrowd?**

- **Seller:** [Bugcrowd](https://www.g2.com/sellers/bugcrowd)
- **Year Founded:** 2012
- **HQ Location:** San Francisco, CA
- **Twitter:** @Bugcrowd (199,211 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/bugcrowd/ (3,701 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 34% Enterprise, 33% Small-Business


#### What Are Bugcrowd's Pros and Cons?

**Pros:**

- Reporting Quality (8 reviews)
- Ease of Use (7 reviews)
- Customer Support (6 reviews)
- Communication (5 reviews)
- Vulnerability Detection (5 reviews)

**Cons:**

- Poor Customer Support (4 reviews)
- Slow Performance (4 reviews)
- Bug Management (3 reviews)
- Inadequate Reporting (3 reviews)
- Learning Curve (3 reviews)


### What Do G2 Reviewers Say About Bugcrowd?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend the **report quality** of Bugcrowd, appreciating well-structured, legitimate opportunities for detailed vulnerability reporting.
- Users appreciate the **ease of use** of Bugcrowd, enjoying a seamless setup and organized workflow for efficient testing.
- Users commend Bugcrowd for its **exceptional customer support** , highlighting responsiveness and a strong sense of cooperation.
- Users value the **consistent and transparent communication** from Bugcrowd, enhancing their research experience and collaboration.
- Users value Bugcrowd for its **thorough vulnerability detection** , enhancing security without the need for an in-house team.

**Cons:**

- Users express frustration with **poor customer support** , citing slow triaging and inconsistent communication during report submissions.
- Users often experience **slow performance** in triaging and reporting, which hinders their ability to navigate the platform effectively.
- Users express frustration with the **slow and inconsistent triaging process** , leading to a lack of timely updates and clarity.
- Users find the **inadequate reporting** in Bugcrowd can delay resolutions and complicate communication, affecting overall efficiency.
- Users find the **learning curve steep** for Bugcrowd, making onboarding and understanding program complexities challenging for newcomers.

#### What Are Recent G2 Reviews of Bugcrowd?

**"[Bugcrowd Delivers Top-Notch Security Solutions for Robust Vulnerability Management](https://www.g2.com/survey_responses/bugcrowd-review-8940044)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Information Technology and Services*

[Read full review](https://www.g2.com/survey_responses/bugcrowd-review-8940044)

---

**"[Empowers Vulnerability Management with Expert Community](https://www.g2.com/survey_responses/bugcrowd-review-12088640)"**

**Rating:** 4.0/5.0 stars
*— Mariam A.*

[Read full review](https://www.g2.com/survey_responses/bugcrowd-review-12088640)

---



### 6. [H1 Platform](https://www.g2.com/products/h1-platform/reviews)
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world&#39;s largest community of security researchers to secure the AI-native enterprise. The H1 Platform unites agentic AI solutions with security researchers ingenuity to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing.


**Average Rating:** 4.5/5.0
**Total Reviews:** 73
**How Do G2 Users Rate H1 Platform?**

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.0/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 10.0/10 (Category avg: 9.1/10)
- **Extensibility:** 10.0/10 (Category avg: 8.7/10)

**Who Is the Company Behind H1 Platform?**

- **Seller:** [HackerOne](https://www.g2.com/sellers/hackerone)
- **Company Website:** https://hackerone.com
- **Year Founded:** 2012
- **HQ Location:** San Francisco, California
- **Twitter:** @Hacker0x01 (337,493 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/hackerone/ (6,738 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 42% Enterprise, 41% Mid-Market


#### What Are H1 Platform's Pros and Cons?

**Pros:**

- Ease of Use (19 reviews)
- Helpful (12 reviews)
- Collaboration (11 reviews)
- Security Protection (11 reviews)
- Customer Support (10 reviews)

**Cons:**

- Complexity Issues (5 reviews)
- Expensive (5 reviews)
- Time Management (5 reviews)
- Poor Customer Support (4 reviews)
- Poor Interface Design (4 reviews)


### What Do G2 Reviewers Say About H1 Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of HackerOne, enabling quick setup and efficient bug bounty management.
- Users value HackerOne for its **streamlined management of bug bounties and strong community support** , enhancing security collaboration.
- Users value the **collaborative community** of HackerOne, enhancing security through shared expertise and user-friendly engagement.
- Users value the **strong security protection** of HackerOne, benefiting from its extensive vulnerability management capabilities.
- Users value the **excellent customer support** of H1 Platform, offering guidance and assistance throughout the setup process.

**Cons:**

- Users experience **complexity issues** with triage and credentials management, affecting the overall efficiency of the platform.
- Users feel the H1 Platform is **expensive** , impacting budgets despite appreciating its community features and security value.
- Users find **time management challenges** due to inconsistent triage speed and hacker guideline breaches on the H1 Platform.
- Users report **poor customer support** , experiencing slow ticket resolution and unresolved queries during transitions.
- Users complain about the **poor interface design** of H1 Platform, making navigation and finding reports challenging.

#### What Are Recent G2 Reviews of H1 Platform?

**"[Straightforward, Practical Vulnerability Management with Clear Visibility](https://www.g2.com/survey_responses/h1-platform-review-12788653)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Automotive*

[Read full review](https://www.g2.com/survey_responses/h1-platform-review-12788653)

---

**"[Powerful Bug Bounty Platform with Room for Improvements](https://www.g2.com/survey_responses/h1-platform-review-12784912)"**

**Rating:** 4.5/5.0 stars
*— Mikhail Y.*

[Read full review](https://www.g2.com/survey_responses/h1-platform-review-12784912)

---


#### What Are G2 Users Discussing About H1 Platform?

- [How many hackers are there in HackerOne?](https://www.g2.com/discussions/how-many-hackers-are-there-in-hackerone) - 2 comments, 1 upvote
- [What is managed program in HackerOne?](https://www.g2.com/discussions/what-is-managed-program-in-hackerone)
- [How many programs are managed by HackerOne?](https://www.g2.com/discussions/how-many-programs-are-managed-by-hackerone)
- [What is the use of HackerOne?](https://www.g2.com/discussions/what-is-the-use-of-hackerone)

### 7. [Pentera](https://www.g2.com/products/pentera/reviews)
Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey&#39;s General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.


**Average Rating:** 4.5/5.0
**Total Reviews:** 169
**How Do G2 Users Rate Pentera?**

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.6/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 8.6/10 (Category avg: 9.1/10)
- **Extensibility:** 7.4/10 (Category avg: 8.7/10)

**Who Is the Company Behind Pentera?**

- **Seller:** [Pentera](https://www.g2.com/sellers/pentera)
- **Company Website:** https://pentera.io/
- **Year Founded:** 2015
- **HQ Location:** Boston, MA
- **Twitter:** @penterasec (3,291 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/penterasecurity/ (483 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Government Administration, Banking
- **Company Size:** 52% Enterprise, 36% Mid-Market


#### What Are Pentera's Pros and Cons?

**Pros:**

- Vulnerability Identification (5 reviews)
- Automation (4 reviews)
- Customer Support (4 reviews)
- Improvement (4 reviews)
- Automated Testing (3 reviews)

**Cons:**

- Inadequate Reporting (2 reviews)
- Missing Features (2 reviews)
- Resource Intensive (2 reviews)
- Access Control (1 reviews)
- Access Restrictions (1 reviews)


### What Do G2 Reviewers Say About Pentera?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **robust vulnerability identification** features of Pentera, enhancing their security posture through continuous validation.
- Users value the **automation capabilities** of Pentera, enhancing security through continuous validation and user-friendly features.
- Users benefit from Pentera&#39;s **responsive customer support** , enhancing their experience with quick implementation and effective solutions.
- Users value the **time-saving efficiency** of Pentera, enabling focus on critical tasks with automated and customizable scanning.
- Users praise Pentera for its **fully automated testing** , highlighting its user-friendly interface and quick implementation.

**Cons:**

- Users find the **reporting inadequate** , needing improvements for better enterprise-level insights and clarity.
- Users note a **lack of features** in Pentera, including missing new vulnerabilities and inadequate user permissions.
- Users face **high resource utilization** with Pentera, leading to potential performance issues on various systems.
- Users express concern about the **lack of a robust RBAC system** , limiting proper access control and user rights management.
- Users report **access restrictions** due to inadequate RBAC, limiting usability and feature access for certain users.

#### What Are Recent G2 Reviews of Pentera?

**"[Cutting-Edge Security with a Real Attacker Approach](https://www.g2.com/survey_responses/pentera-review-12864952)"**

**Rating:** 4.5/5.0 stars
*— Yaron C.*

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864952)

---

**"[Reliable Tool for Vulnerability Detection but Script Issues](https://www.g2.com/survey_responses/pentera-review-12864934)"**

**Rating:** 4.0/5.0 stars
*— Avitzur Y.*

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864934)

---



### 8. [Verizon Penetration Testing](https://www.g2.com/products/verizon-penetration-testing/reviews)
Penetration testing is an important part of managing risk. It helps you probe for cyber vulnerabilities so you can put resources where theyre needed most. Assess your risks and measure the dangers, then use real-world scenarios to help you strengthen your security.


**Average Rating:** 4.6/5.0
**Total Reviews:** 15
**How Do G2 Users Rate Verizon Penetration Testing?**

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.4/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.4/10 (Category avg: 9.1/10)
- **Extensibility:** 8.3/10 (Category avg: 8.7/10)

**Who Is the Company Behind Verizon Penetration Testing?**

- **Seller:** [Verizon Enterprise](https://www.g2.com/sellers/verizon-enterprise)
- **Year Founded:** 1988
- **HQ Location:** Basking Ridge, NJ
- **Twitter:** @VerizonEnterpr (7 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/1094/ (15,424 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 58% Small-Business, 21% Enterprise



#### What Are Recent G2 Reviews of Verizon Penetration Testing?

**"[review about verizon penetration testing](https://www.g2.com/survey_responses/verizon-penetration-testing-review-6551460)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Computer &amp; Network Security*

[Read full review](https://www.g2.com/survey_responses/verizon-penetration-testing-review-6551460)

---

**"[Correct pentesting tool for enterprise](https://www.g2.com/survey_responses/verizon-penetration-testing-review-5299305)"**

**Rating:** 4.5/5.0 stars
*— DHARMENDRA V.*

[Read full review](https://www.g2.com/survey_responses/verizon-penetration-testing-review-5299305)

---


#### What Are G2 Users Discussing About Verizon Penetration Testing?

- [What is Verizon Penetration Testing used for?](https://www.g2.com/discussions/what-is-verizon-penetration-testing-used-for) - 1 comment, 1 upvote

### 9. [Burp Suite](https://www.g2.com/products/burp-suite/reviews)
Burp Suite is a complete ecosystem for web application and API security testing, combining two products: Burp Suite DAST - a best-of-breed, precision DAST solution that automates runtime testing, and Burp Suite Professional - the industry-standard toolkit for manual penetration testing. Developed by PortSwigger, more than 85,000 security professionals rely on Burp Suite to find, verify, and understand vulnerabilities across complex modern web applications. Burp Suite DAST is PortSwigger’s enterprise dynamic application security testing (DAST) solution, purpose-built for continuous, automated scanning of web applications and APIs. Unlike many DAST solutions, which are part of a wider AST offering, Burp Suite DAST is not a bolt-on tool - instead it’s precision-built from over 20 years of dynamic testing experience. Burp Suite DAST reveals the runtime issues that static analysis tools miss, such as authentication flaws, configuration drift, and chained vulnerabilities. Built on the same proprietary scanning engine that powers Burp Suite Professional, it delivers precise, low-noise results that security teams trust. Key capabilities of Burp Suite DAST include: Continuous, automated scanning of web applications and APIs, integration with CI/CD pipelines and vulnerability management tools, flexible deployment across cloud, and on-premise environments, shared scanning logic and configurations between automated and manual testing, accurate, low-noise detection informed by PortSwigger Research. Burp Suite Professional complements DAST with deep manual testing capability. It’s the industry-standard toolkit for penetration testers, consultants, and AppSec engineers who need complete insight and flexibility when validating or exploring vulnerabilities. Findings discovered by DAST can be investigated and verified in Burp Suite Professional, ensuring every result is accurate, contextual, and actionable. Together, Burp Suite DAST and Burp Suite Professional create a unified ecosystem that delivers automation at breadth and manual depth where it counts. Burp Suite is built for AppSec teams who need scalable, trustworthy coverage across web and API environments, enabling a seamless handoff between automated and manual testing.


**Average Rating:** 4.8/5.0
**Total Reviews:** 126
**How Do G2 Users Rate Burp Suite?**

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.8/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 8.9/10 (Category avg: 9.1/10)
- **Extensibility:** 8.9/10 (Category avg: 8.7/10)

**Who Is the Company Behind Burp Suite?**

- **Seller:** [PortSwigger](https://www.g2.com/sellers/portswigger)
- **Company Website:** https://www.portswigger.net
- **Year Founded:** 2008
- **HQ Location:** Knutsford, GB
- **Twitter:** @Burp_Suite (138,186 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/portswigger-web-security/ (321 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** Cyber Security Analyst
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 41% Mid-Market, 31% Small-Business


#### What Are Burp Suite's Pros and Cons?

**Pros:**

- Ease of Use (12 reviews)
- User Interface (8 reviews)
- Testing Services (7 reviews)
- Features (5 reviews)
- Clear Interface (4 reviews)

**Cons:**

- Expensive (5 reviews)
- Slow Performance (5 reviews)
- High Learning Curve (2 reviews)
- Learning Curve (2 reviews)
- Limited Customization (2 reviews)


### What Do G2 Reviewers Say About Burp Suite?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of Burp Suite, enabling quick setup and effective security testing for all skill levels.
- Users appreciate the **user-friendly interface** of Burp Suite, making penetration testing easy for both beginners and experts.
- Users value the **deep automation and manual testing capabilities** of Burp Suite, enhancing their penetration testing experience.
- Users appreciate the **user-friendly interface and comprehensive features** of Burp Suite, enhancing both ease of use and effectiveness.
- Users find Burp Suite&#39;s **clear interface** incredibly user-friendly, making traffic interception and analysis effortless for beginners.

**Cons:**

- Users express concerns about the **expensive** pricing of Burp Suite, which can limit access to essential features.
- Users experience **slow performance** with Burp Suite, especially on systems with limited resources and during extensive scans.
- Users struggle with the **steep learning curve** of Burp Suite, making it challenging for beginners to navigate effectively.
- Users struggle with the **steep learning curve** of Burp Suite, making it challenging for beginners to effectively navigate the tool.
- Users find the **limited customization** in Burp Suite restricting, particularly impacting beginners&#39; ability to explore effectively.

#### What Are Recent G2 Reviews of Burp Suite?

**"[Complete Control Over Web Requests with Burp Suite](https://www.g2.com/survey_responses/burp-suite-review-12677559)"**

**Rating:** 5.0/5.0 stars
*— Arish B.*

[Read full review](https://www.g2.com/survey_responses/burp-suite-review-12677559)

---

**"[Burp Suite Pro: A Powerful, All-in-One Platform for Web App Pen Testing](https://www.g2.com/survey_responses/burp-suite-review-12818180)"**

**Rating:** 4.5/5.0 stars
*— Aryan S.*

[Read full review](https://www.g2.com/survey_responses/burp-suite-review-12818180)

---


#### What Are G2 Users Discussing About Burp Suite?

- [What are the benefits and challenges of using BurpSuite for web application security?](https://www.g2.com/discussions/what-are-the-benefits-and-challenges-of-using-burpsuite-for-web-application-security)
- [What is BurpSuite used for?](https://www.g2.com/discussions/burpsuite-what-is-burpsuite-used-for)
- [What types of vulnerabilities can Burp Suite detect?](https://www.g2.com/discussions/what-types-of-vulnerabilities-can-burp-suite-detect)
- [What is Burp Suite Professional?](https://www.g2.com/discussions/what-is-burp-suite-professional) - 1 comment
- [Is BurpSuite free?](https://www.g2.com/discussions/is-burpsuite-free) - 2 comments

### 10. [YesWeHack](https://www.g2.com/products/yeswehack/reviews)
YesWeHack is a leading Offensive Security and Exposure Management platform delivering integrated, API-based solutions to secure organisations’ growing attack surfaces. Its human-in-the-loop model combines Bug Bounty (leveraging a global community of 150,000+ skilled ethical hackers), Autonomous Pentesting, Continuous Pentesting and unified vulnerability management to deliver agile, exhaustive security testing at scale. Customers include Louis Vuitton, Ferrero, the European Commission, Tencent and L’Oréal Groupe. ISO 27001-certified, CREST-accredited, and EU-hosted with full GDPR compliance. YesWeHack #1 Bug Bounty Platform in Europe and APAC


**Average Rating:** 4.8/5.0
**Total Reviews:** 31
**How Do G2 Users Rate YesWeHack?**

- **Has the product been a good partner in doing business?:** 9.9/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.9/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.4/10 (Category avg: 9.1/10)
- **Extensibility:** 9.1/10 (Category avg: 8.7/10)

**Who Is the Company Behind YesWeHack?**

- **Seller:** [YesWeHack](https://www.g2.com/sellers/yeswehack)
- **Company Website:** https://www.yeswehack.com/
- **Year Founded:** 2015
- **HQ Location:** Paris, France
- **LinkedIn® Page:** https://www.linkedin.com/company/yes-we-hack/ (728 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security
- **Company Size:** 45% Enterprise, 32% Small-Business


#### What Are YesWeHack's Pros and Cons?

**Pros:**

- Ease of Use (15 reviews)
- Customer Support (10 reviews)
- Features (9 reviews)
- Reporting Quality (7 reviews)
- Team Quality (7 reviews)

**Cons:**

- Expensive (2 reviews)
- Poor Interface Design (2 reviews)
- Limited Scope (1 reviews)
- Missing Features (1 reviews)
- Pricing Issues (1 reviews)


### What Do G2 Reviewers Say About YesWeHack?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find YesWeHack&#39;s platform to be **easy to use** , streamlining vulnerability management and enhancing communication with hunters.
- Users commend the **exceptional customer support** of YesWeHack, ensuring a smooth and effective partnership throughout the process.
- Users praise the **efficient triage process and user-friendly platform** for managing vulnerabilities and communicating effectively.
- Users commend the **exceptional reporting quality** of YesWeHack, highlighting clear and fast vulnerability reports from triagers.
- Users value the **exceptional quality and trustworthiness** of YesWeHack&#39;s bug bounty platform and dedicated support services.

**Cons:**

- Users find the **pricing steep** , making YesWeHack less accessible for smaller organizations and budget-conscious users.
- Users note the **poor interface design** as a downside, suggesting it could benefit from updates and enhanced tracking features.
- Users note that YesWeHack has a **limited scope** and may struggle with a high number of programs.
- Users note the **missing tracking features** on YesWeHack&#39;s interface, which could enhance the overall experience.
- Users find the **pricing steep** for smaller organizations, which limits accessibility for a wider audience.

#### What Are Recent G2 Reviews of YesWeHack?

**"[The experience was satisfactory](https://www.g2.com/survey_responses/yeswehack-review-7640568)"**

**Rating:** 4.0/5.0 stars
*— Teboho P.*

[Read full review](https://www.g2.com/survey_responses/yeswehack-review-7640568)

---

**"[Effortless Security and Superior Vulnerability Detection](https://www.g2.com/survey_responses/yeswehack-review-11990115)"**

**Rating:** 4.5/5.0 stars
*— Brian O.*

[Read full review](https://www.g2.com/survey_responses/yeswehack-review-11990115)

---



### 11. [NodeZero from Horizon3.ai](https://www.g2.com/products/nodezero-from-horizon3-ai/reviews)
Horizon3.ai&#39;s NodeZero® platform empowers your organization to continuously find, fix, and verify your exploitable attack surface. Reduce your security risk by autonomously finding weaknesses in your network, knowing how to prioritize and fix them, and immediately verifying that your fixes work. NodeZero delivers production-safe autonomous pentests and other key assessment operations that scale across your largest internal, external, cloud, and hybrid cloud environments. No required agents, no code to write, and no consultants to hire.


**Average Rating:** 4.7/5.0
**Total Reviews:** 27
**How Do G2 Users Rate NodeZero from Horizon3.ai?**

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 10.0/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.5/10 (Category avg: 9.1/10)
- **Extensibility:** 9.8/10 (Category avg: 8.7/10)

**Who Is the Company Behind NodeZero from Horizon3.ai?**

- **Seller:** [Horizon3.ai](https://www.g2.com/sellers/horizon3-ai)
- **Company Website:** https://www.horizon3.ai
- **Year Founded:** 2019
- **HQ Location:** San Francisco, US
- **Twitter:** @Horizon3ai (2,802 Twitter followers)
- **LinkedIn® Page:** https://linkedin.com/company/horizon3ai/ (444 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 56% Mid-Market, 22% Enterprise


#### What Are NodeZero from Horizon3.ai's Pros and Cons?

**Pros:**

- Communication (1 reviews)
- Cybersecurity (1 reviews)
- Ease of Implementation (1 reviews)
- Easy Integrations (1 reviews)
- Efficiency (1 reviews)

**Cons:**

- Inadequate Reporting (1 reviews)
- Lack of Detail (1 reviews)


### What Do G2 Reviewers Say About NodeZero from Horizon3.ai?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **intuitive communication** of NodeZero, appreciating its ease of use and excellent customer support.
- Users value the **intuitive integration and thorough capabilities** of NodeZero, making it essential for their cybersecurity needs.
- Users find **ease of implementation** and intuitive integration with NodeZero, essential for both technical and non-technical staff.
- Users value the **easy integrations** of NodeZero, making it accessible for both technical and non-technical staff.
- Users appreciate the **efficiency** of NodeZero, quickly identifying long-standing misconfigurations and new vulnerabilities.

**Cons:**

- Users note the **inadequate reporting** of NodeZero, making it difficult to identify successful or failed machine actions.
- Users note a **lack of detail** in reporting, making it hard to identify specific machine performance.

#### What Are Recent G2 Reviews of NodeZero from Horizon3.ai?

**"[Node Zero from Autonomous Pentesting to Patching Validation](https://www.g2.com/survey_responses/nodezero-from-horizon3-ai-review-12675504)"**

**Rating:** 4.5/5.0 stars
*— Daniel L.*

[Read full review](https://www.g2.com/survey_responses/nodezero-from-horizon3-ai-review-12675504)

---

**"[Proactive Cybersecurity Testing](https://www.g2.com/survey_responses/nodezero-from-horizon3-ai-review-12656970)"**

**Rating:** 4.5/5.0 stars
*— Kevin D.*

[Read full review](https://www.g2.com/survey_responses/nodezero-from-horizon3-ai-review-12656970)

---



### 12. [NetSPI](https://www.g2.com/products/netspi-2026-02-04/reviews)
NetSPI PTaaS is a type of penetration testing as a service (PTaaS) solution designed to help organizations identify and remediate vulnerabilities within their systems, applications, and networks. This service utilizes a combination of skilled professionals, established processes, and advanced AI technology to provide contextualized security outcomes in real time, all accessible through a unified platform. By addressing the limitations of traditional penetration testing methods, NetSPI PTaaS offers a more efficient and comprehensive approach to security assessments. This service is targeted at businesses of all sizes, from startups to large enterprises, making it particularly beneficial for security teams looking to enhance their vulnerability management strategies. NetSPI PTaaS caters to a variety of use cases, including application security assessments, infrastructure testing, and evaluations of emerging technologies such as artificial intelligence. With over 50 different types of penetration tests available, including traditional point in time testing and our continuous offerings, organizations can customize their security evaluations to meet specific needs, ensuring thorough coverage across all potential attack surfaces. A key feature of NetSPI PTaaS is its commitment to delivering real-time findings through a single platform. This capability allows security teams to receive immediate insights into vulnerabilities, enabling them to act swiftly to mitigate risks based on role and priority, managing testing in just a few clicks. The platform&#39;s integration capabilities enhance its usability, allowing organizations to seamlessly incorporate findings into their existing security workflows. This streamlined approach not only saves time but also ensures that remediation efforts are based on high-fidelity, manually validated findings, thus improving overall security effectiveness. The expertise of NetSPI&#39;s team of over 350 in-house security professionals is another significant differentiator. Their extensive experience and knowledge in the field of cybersecurity ensure that the testing methodologies employed are rigorous and consistent, uncovering vulnerabilities, exposures, and misconfigurations that may be overlooked by other solutions. This white-glove approach to penetration testing emphasizes the importance of manual validation, providing organizations with reliable and actionable insights that can significantly enhance their security posture. NetSPI PTaaS stands out in the realm of penetration testing services by combining expert human analysis with advanced AI technology, delivering timely and accurate results. This empowers organizations to strengthen their defenses against evolving cyber threats, ensuring that they remain resilient in an increasingly complex security landscape.


**Average Rating:** 4.9/5.0
**Total Reviews:** 13
**How Do G2 Users Rate NetSPI?**

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.8/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 10.0/10 (Category avg: 9.1/10)
- **Extensibility:** 9.5/10 (Category avg: 8.7/10)

**Who Is the Company Behind NetSPI?**

- **Seller:** [NetSPI](https://www.g2.com/sellers/netspi)
- **Company Website:** https://www.netspi.com
- **Year Founded:** 2001
- **HQ Location:** Minneapolis, MN
- **Twitter:** @NetSPI (4,041 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/netspi/ (568 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 46% Enterprise, 38% Mid-Market


#### What Are NetSPI's Pros and Cons?

**Pros:**

- Expertise (4 reviews)
- Team Quality (4 reviews)
- Communication (3 reviews)
- Ease of Use (3 reviews)
- Service Quality (3 reviews)

**Cons:**

- Difficult Navigation (1 reviews)
- False Positives (1 reviews)
- Information Management (1 reviews)
- Lack of Detail (1 reviews)
- Lack of Information (1 reviews)


### What Do G2 Reviewers Say About NetSPI?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **expertise** of NetSPI, praising their exceptional penetration testing and project management capabilities.
- Users commend the **top-notch quality of the NetSPI team** for their exceptional support and effective engagement.
- Users appreciate the **effective communication** with NetSPI, ensuring clarity and transparency throughout their assessments.
- Users value the **ease of use** of NetSPI, appreciating the simple interface and effective communication tools.
- Users commend NetSPI for their **exceptional service quality** , highlighting strong leadership and effective communication throughout engagements.

**Cons:**

- Users find the **difficult navigation** of NetSPI&#39;s interface to be a significant challenge in their workflow.
- Users experience **false positives** in vulnerability reports, leading to confusion about impacted devices.
- Users experience **confusion regarding impacted devices** on vulnerability reports, which affects clarity and response strategies.
- Users find a **lack of detail** in vulnerability reports regarding impacted devices, leading to confusion and uncertainty.
- Users face a **lack of information** regarding device impact on vulnerability reports, leading to confusion and uncertainty.

#### What Are Recent G2 Reviews of NetSPI?

**"[Attentive, Knowledgeable NetSPI Specialists with a Truly Human Touch](https://www.g2.com/survey_responses/netspi-review-12678851)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Transportation/Trucking/Railroad*

[Read full review](https://www.g2.com/survey_responses/netspi-review-12678851)

---

**"[Exceptional Pentesting and Seamless Collaboration](https://www.g2.com/survey_responses/netspi-review-12705364)"**

**Rating:** 4.5/5.0 stars
*— Jake B.*

[Read full review](https://www.g2.com/survey_responses/netspi-review-12705364)

---



### 13. [Intruder](https://www.g2.com/products/intruder/reviews)
Intruder is an exposure management platform for scaling to mid-market businesses. Over 3000 companies - across all industries - use Intruder to find critical exposures, respond faster and prevent breaches. Unifying Attack Surface Management, Vulnerability Management and Cloud security into one powerful, easy to use platform, Intruder simplifies the complex task of securing an ever-expanding attack surface. Recognizing no two business are alike, Intruder provides real-time, accurate scanning combined with intelligent risk prioritization, ensuring businesses focus on the exposures that are most relevant to them. And our proactive approach limits the window of risk, continuously monitoring for new threats while eliminating the noise that slows teams down. Whether you&#39;re an IT Manager, in DevOps or a CISO, Intruder&#39;s easy setup and context-driven approach will free you up to focus on exposures that cause real breaches, not just technical vulnerabilities. Keeping you one step ahead of attackers.


**Average Rating:** 4.8/5.0
**Total Reviews:** 206
**How Do G2 Users Rate Intruder?**

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.4/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.6/10 (Category avg: 9.1/10)
- **Extensibility:** 8.5/10 (Category avg: 8.7/10)

**Who Is the Company Behind Intruder?**

- **Seller:** [Intruder](https://www.g2.com/sellers/intruder)
- **Company Website:** https://www.intruder.io
- **Year Founded:** 2015
- **HQ Location:** London
- **Twitter:** @intruder_io (979 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/6443623/ (84 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** CTO, Director
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 57% Small-Business, 36% Mid-Market


#### What Are Intruder's Pros and Cons?

**Pros:**

- Ease of Use (41 reviews)
- Vulnerability Detection (30 reviews)
- Customer Support (25 reviews)
- User Interface (24 reviews)
- Vulnerability Identification (24 reviews)

**Cons:**

- Expensive (9 reviews)
- Slow Scanning (8 reviews)
- Licensing Issues (7 reviews)
- False Positives (6 reviews)
- Limited Features (6 reviews)


### What Do G2 Reviewers Say About Intruder?
*AI-generated summary from verified user reviews*

**Pros:**

- Users find Intruder&#39;s **ease of use** remarkable, enabling quick setup and effective scanning of vulnerabilities.
- Users value the **ease of configuring vulnerability detection** , ensuring timely identification of security issues across cloud resources.
- Users praise Intruder&#39;s **exceptional customer support** , highlighting quick responses and friendly assistance during security management tasks.
- Users commend Intruder&#39;s **intuitive interface** , praising its seamless integration and simplicity in managing complex security tasks.
- Users commend the **effortless vulnerability identification** of Intruder, making cybersecurity management seamless and efficient.

**Cons:**

- Users find the product **expensive** , expressing a desire for more flexible pricing options to improve value.
- Users experience **slow scanning** with Intruder, leading to missed vulnerabilities and challenges in testing integration.
- Users struggle with **licensing issues** , finding the model complex and not intuitive, affecting overall understanding.
- Users experience **false positives** with Intruder, which may lead to confusion over vulnerability prioritization and management.
- Users find the **limited features** of Intruder restrictive, especially around license clarity and advanced reporting options.

#### What Are Recent G2 Reviews of Intruder?

**"[Intruder: Insightful Vulnerability Management Platform That Strengthens Security Operation](https://www.g2.com/survey_responses/intruder-review-12395645)"**

**Rating:** 4.5/5.0 stars
*— HALADU A.*

[Read full review](https://www.g2.com/survey_responses/intruder-review-12395645)

---

**"[Outstanding Experience with No Drawbacks](https://www.g2.com/survey_responses/intruder-review-12097237)"**

**Rating:** 5.0/5.0 stars
*— Nic H.*

[Read full review](https://www.g2.com/survey_responses/intruder-review-12097237)

---


#### What Are G2 Users Discussing About Intruder?

- [Who developed intruder?](https://www.g2.com/discussions/who-developed-intruder)
- [What is an intruder in cyber security?](https://www.g2.com/discussions/what-is-an-intruder-in-cyber-security)
- [Is intruder IO safe?](https://www.g2.com/discussions/is-intruder-io-safe) - 1 comment
- [What is intruder software?](https://www.g2.com/discussions/what-is-intruder-software) - 1 comment

### 14. [Synack](https://www.g2.com/products/synack/reviews)
Synack is a continuous penetration testing platform that combines agentic AI with a global network of vetted security researchers to uncover real, exploitable vulnerabilities across the entire attack surface. Most organizations test only a fraction of what matters. Synack closes that coverage gap—using AI to scale discovery and human expertise to validate real risk. The platform enables enterprises to move from periodic testing to continuous security validation across web applications, APIs, cloud, and infrastructure—prioritizing findings based on what is actually exploitable, not just detected. Synack supports penetration testing, continuous security testing, vulnerability management, and attack surface management in dynamic, cloud-based, and hybrid environments. Founded by former NSA professionals, Synack supports enterprise and public sector organizations where security, compliance, and risk management are mission-critical.


**Average Rating:** 4.8/5.0
**Total Reviews:** 18
**How Do G2 Users Rate Synack?**

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.2/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 10.0/10 (Category avg: 9.1/10)
- **Extensibility:** 10.0/10 (Category avg: 8.7/10)

**Who Is the Company Behind Synack?**

- **Seller:** [Synack](https://www.g2.com/sellers/synack)
- **Company Website:** https://www.synack.com/
- **Year Founded:** 2013
- **HQ Location:** Redwood City, California, United States
- **Twitter:** @synack (26,716 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/synack-inc-/ (247 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 78% Enterprise, 17% Mid-Market



#### What Are Recent G2 Reviews of Synack?

**"[Trusted Testing with Powerful Analytics and Assurance](https://www.g2.com/survey_responses/synack-review-13049363)"**

**Rating:** 5.0/5.0 stars
*— Jan F.*

[Read full review](https://www.g2.com/survey_responses/synack-review-13049363)

---

**"[High-Quality Security Testing Through Trusted Researchers](https://www.g2.com/survey_responses/synack-review-13043980)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Chemicals*

[Read full review](https://www.g2.com/survey_responses/synack-review-13043980)

---


#### What Are G2 Users Discussing About Synack?

- [What is Synack used for?](https://www.g2.com/discussions/what-is-synack-used-for)

### 15. [BeEF](https://www.g2.com/products/beef/reviews)
BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.


**Average Rating:** 4.4/5.0
**Total Reviews:** 11
**How Do G2 Users Rate BeEF?**

- **Has the product been a good partner in doing business?:** 8.8/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.0/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 6.3/10 (Category avg: 9.1/10)
- **Extensibility:** 8.6/10 (Category avg: 8.7/10)

**Who Is the Company Behind BeEF?**

- **Seller:** [BeEF](https://www.g2.com/sellers/beef)
- **Year Founded:** 2008
- **HQ Location:** San Francisco, CA
- **Twitter:** @github (2,673,925 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/No-Linkedin-Presence-Added-Intentionally-By-DataOps (1 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 58% Small-Business, 33% Mid-Market



#### What Are Recent G2 Reviews of BeEF?

**"[my Journey with BeEF](https://www.g2.com/survey_responses/beef-review-6750724)"**

**Rating:** 4.5/5.0 stars
*— Animesh R.*

[Read full review](https://www.g2.com/survey_responses/beef-review-6750724)

---

**"[Most Capable and Trusted API prsenet in market](https://www.g2.com/survey_responses/beef-review-6811780)"**

**Rating:** 5.0/5.0 stars
*— santosh p.*

[Read full review](https://www.g2.com/survey_responses/beef-review-6811780)

---


#### What Are G2 Users Discussing About BeEF?

- [What is BeEF tool used for?](https://www.g2.com/discussions/beef-what-is-beef-tool-used-for)
- [What is BeEF tool used for?](https://www.g2.com/discussions/what-is-beef-tool-used-for)
- [What is BeEF browser exploitation?](https://www.g2.com/discussions/beef-what-is-beef-browser-exploitation)
- [What is BeEF browser exploitation?](https://www.g2.com/discussions/what-is-beef-browser-exploitation)
- [What is the username and password for BeEF?](https://www.g2.com/discussions/beef-what-is-the-username-and-password-for-beef)

### 16. [Metasploit](https://www.g2.com/products/metasploit/reviews)
Metasploit is a comprehensive penetration testing platform developed by Rapid7, designed to help security professionals identify, exploit, and validate vulnerabilities within their networks. By simulating real-world attacks, Metasploit enables organizations to assess their security posture and enhance their defenses against potential threats. Key Features and Functionality: - Extensive Exploit Library: Access to a vast, regularly updated database of over 1,500 exploits and 3,300 modules, allowing users to simulate a wide range of attack scenarios. - Automated Exploitation: Features like Smart Exploitation and automated credential brute-forcing streamline the penetration testing process, increasing efficiency and accuracy. - Post-Exploitation Modules: Over 330 post-exploitation modules enable testers to assess the impact of a successful breach and gather critical information from compromised systems. - Credential Testing: Ability to run brute-force attacks against more than 20 account types, including databases, web servers, and remote administration tools, to uncover weak or reused passwords. - Integration Capabilities: Seamless integration with other Rapid7 products, such as InsightVM and Nexpose, facilitates closed-loop vulnerability validation and remediation prioritization. Primary Value and Problem Solving: Metasploit empowers organizations to proactively identify and address security weaknesses before malicious actors can exploit them. By simulating real-world attacks, it provides valuable insights into potential vulnerabilities, enabling security teams to prioritize remediation efforts effectively. This proactive approach enhances overall security awareness, reduces the risk of breaches, and ensures compliance with industry standards and regulations.


**Average Rating:** 4.6/5.0
**Total Reviews:** 53
**How Do G2 Users Rate Metasploit?**

- **Has the product been a good partner in doing business?:** 8.7/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.4/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 8.7/10 (Category avg: 9.1/10)
- **Extensibility:** 8.1/10 (Category avg: 8.7/10)

**Who Is the Company Behind Metasploit?**

- **Seller:** [Rapid7](https://www.g2.com/sellers/rapid7)
- **Year Founded:** 2000
- **HQ Location:** Boston, MA
- **Twitter:** @rapid7 (124,405 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/39624/ (3,274 employees on LinkedIn®)
- **Ownership:** NASDAQ:RPD

**Who Uses This Product?**
- **Top Industries:** Computer &amp; Network Security, Information Technology and Services
- **Company Size:** 47% Small-Business, 40% Mid-Market


#### What Are Metasploit's Pros and Cons?

**Pros:**

- Pentesting Efficiency (2 reviews)
- Expertise (1 reviews)

**Cons:**

- Complex Setup (1 reviews)


### What Do G2 Reviewers Say About Metasploit?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **pentesting efficiency** of Metasploit, benefiting from its extensive toolkit for system exploitation.
- Users praise the **expertise of Metasploit** , highlighting its versatility in creating various payloads for exploitation.

**Cons:**

- Users find the **complex setup** of Metasploit challenging and desire an automation feature for easier installation.

#### What Are Recent G2 Reviews of Metasploit?

**"[The Best Exploitation framework](https://www.g2.com/survey_responses/metasploit-review-10690494)"**

**Rating:** 5.0/5.0 stars
*— Abhinav N.*

[Read full review](https://www.g2.com/survey_responses/metasploit-review-10690494)

---

**"[Metasploit: the master blaster](https://www.g2.com/survey_responses/metasploit-review-10815364)"**

**Rating:** 5.0/5.0 stars
*— Anamta Z.*

[Read full review](https://www.g2.com/survey_responses/metasploit-review-10815364)

---


#### What Are G2 Users Discussing About Metasploit?

- [What is Metasploit used for?](https://www.g2.com/discussions/what-is-metasploit-used-for)

### 17. [Indusface WAS](https://www.g2.com/products/indusface-was/reviews)
Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily monitoring for web applications, checking for systems and application vulnerabilities, and malware. Indusface WAS with its automated scans &amp; manual pentesting done by certified security experts ensures none of the OWASP Top10, business logic vulnerabilities, and malware go unnoticed. With zero false-positive guarantee and comprehensive reporting with remediation guidance, Indusface web app scanning ensures developers to quickly fix vulnerabilities seamlessly.


**Average Rating:** 4.6/5.0
**Total Reviews:** 63
**How Do G2 Users Rate Indusface WAS?**

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.2/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.3/10 (Category avg: 9.1/10)
- **Extensibility:** 8.7/10 (Category avg: 8.7/10)

**Who Is the Company Behind Indusface WAS?**

- **Seller:** [Indusface](https://www.g2.com/sellers/indusface)
- **Year Founded:** 2012
- **HQ Location:** Vadodara
- **Twitter:** @Indusface (3,472 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/indusface/ (180 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 52% Small-Business, 37% Mid-Market


#### What Are Indusface WAS's Pros and Cons?

**Pros:**

- Vulnerability Detection (19 reviews)
- Vulnerability Identification (16 reviews)
- Customer Support (6 reviews)
- Scanning Efficiency (6 reviews)
- Security (6 reviews)

**Cons:**

- Expensive (2 reviews)
- Confusing Interface (1 reviews)
- Lacking Features (1 reviews)
- Limited Scope (1 reviews)
- Poor Interface Design (1 reviews)


### What Do G2 Reviewers Say About Indusface WAS?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **effective vulnerability detection** and prioritization features of Indusface WAS for enhancing security management.
- Users value the **consistent and reliable vulnerability detection** of Indusface WAS, ensuring thorough security across deployments.
- Users praise the **excellent customer support** of Indusface WAS, ensuring timely assistance and effective issue resolution.
- Users value the **scanning efficiency** of Indusface WAS, as it provides thorough reports on various vulnerabilities.
- Users value the **comprehensive security scanning** of Indusface WAS, enhancing their accreditation and vulnerability management processes.

**Cons:**

- Users find the pricing of Indusface WAS to be **expensive** , particularly for staging and development environments.
- Users find the **interface confusing** , noting it could be more intuitive and visually appealing for better usability.
- Users find the **lack of features** in the free version limiting for staging and development environment scans.
- Users feel the **limited scope** of Indusface WAS hinders testing in development environments due to pricing constraints.
- Users find the **interface design outdated** and urge for a more intuitive and informative user experience.

#### What Are Recent G2 Reviews of Indusface WAS?

**"[Vulnerability and malware scanner in one](https://www.g2.com/survey_responses/indusface-was-review-11323529)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Insurance*

[Read full review](https://www.g2.com/survey_responses/indusface-was-review-11323529)

---

**"[Great support Given by shivani](https://www.g2.com/survey_responses/indusface-was-review-11074325)"**

**Rating:** 5.0/5.0 stars
*— Sai N.*

[Read full review](https://www.g2.com/survey_responses/indusface-was-review-11074325)

---


#### What Are G2 Users Discussing About Indusface WAS?

- [What is Indusface WAS used for?](https://www.g2.com/discussions/what-is-indusface-was-used-for)

### 18. [Sprocket Security](https://www.g2.com/products/sprocket-security/reviews)
By combining automation with expert-driven human testing, Sprocket Security delivers Continuous Penetration Testing to help businesses continuously validate their security posture and resilience. This innovative solution is tailored for organizations seeking to enhance their cybersecurity measures by proactively identifying vulnerabilities and assessing their defenses against potential threats. By employing a year-round testing methodology, Sprocket Security ensures that businesses remain vigilant and prepared in the ever-evolving landscape of cyber threats. The platform primarily targets organizations of all sizes that are committed to improving their security frameworks. Sprocket Security is particularly beneficial for IT and security teams that need to stay ahead of emerging attack techniques and adapt to changes in their IT structures. With features such as Attack Surface Management, Continuous Penetration Testing, and Adversary Simulation, Sprocket Security provides a comprehensive suite of tools that empower businesses to prioritize offensive security measures effectively. One of the key features of Sprocket Security is its Attack Surface Management, which allows organizations to gain visibility into their digital assets and potential vulnerabilities. By continuously monitoring and analyzing the attack surface, businesses can identify weak points before they are exploited by malicious actors. Additionally, the platform offers Continuous Penetration Testing, which simulates real-world attack scenarios to evaluate the effectiveness of existing security controls. This ongoing testing approach ensures that organizations can adapt their defenses in response to new threats and vulnerabilities. Another significant aspect of Sprocket Security is its commitment to retesting. Whenever a new attack technique emerges, a change occurs in the IT infrastructure, or a finding is patched, Sprocket Security provides unlimited retests at no additional cost. This feature not only enhances the overall security posture of an organization but also fosters a culture of continuous improvement and vigilance. By prioritizing offensive security, businesses can reduce their IT risk and enhance their resilience against cyber threats. Overall, Sprocket Security stands out in the cybersecurity landscape by offering a robust and flexible solution that integrates both automated and human-driven testing methodologies. This unique combination allows organizations to maintain a proactive stance against cyber threats, ensuring that their security measures evolve in tandem with the dynamic nature of the digital landscape.


**Average Rating:** 4.8/5.0
**Total Reviews:** 14
**How Do G2 Users Rate Sprocket Security?**

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.8/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 10.0/10 (Category avg: 9.1/10)
- **Extensibility:** 8.6/10 (Category avg: 8.7/10)

**Who Is the Company Behind Sprocket Security?**

- **Seller:** [Sprocket Security](https://www.g2.com/sellers/sprocket-security)
- **Year Founded:** 2017
- **HQ Location:** Madison, US
- **LinkedIn® Page:** https://www.linkedin.com/company/sprocket-security/ (48 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 71% Mid-Market, 14% Enterprise


#### What Are Sprocket Security's Pros and Cons?

**Pros:**

- Pentesting Efficiency (5 reviews)
- Customer Support (3 reviews)
- Ease of Use (3 reviews)
- Expertise (2 reviews)
- Remediation Efficiency (2 reviews)

**Cons:**

- False Positives (2 reviews)
- Expensive (1 reviews)
- Limited Scope (1 reviews)
- Poor Customer Support (1 reviews)
- Poor Integration (1 reviews)


### What Do G2 Reviewers Say About Sprocket Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **ongoing and thorough pentesting** by Sprocket Security, significantly enhancing their security posture with actionable insights.
- Users value the **helpful customer support** of Sprocket Security, enhancing their overall experience and problem resolution.
- Users find Sprocket Security’s **ease of use** exceptional, appreciating the intuitive interface and supportive team.
- Users commend Sprocket Security for their **exceptional expertise** in cybersecurity and penetration testing, ensuring robust security solutions.
- Users value the **remediation efficiency** of Sprocket Security, enhancing their security posture with actionable insights and support.

**Cons:**

- Users report frequent **false positives** from Sprocket Security, complicating integration with existing security tools and alerting systems.
- Users find Sprocket Security to be **expensive** , facing issues with support responsiveness and contract renewal negotiations.
- Users report **limited support and slow responses** that hinder the remediation process and escalate frustrations.
- Users report **poor customer support** , facing slow response times and lack of communication regarding fixes and contract issues.
- Users face **poor integration** with Sprocket Security, leading to false positives and difficulties in alert management.

#### What Are Recent G2 Reviews of Sprocket Security?

**"[Spot-On Security Findings with Clear Fix Guidance](https://www.g2.com/survey_responses/sprocket-security-review-12804349)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Logistics and Supply Chain*

[Read full review](https://www.g2.com/survey_responses/sprocket-security-review-12804349)

---

**"[Continuous Penetration Testing With A Personal Touch](https://www.g2.com/survey_responses/sprocket-security-review-10011896)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Non-Profit Organization Management*

[Read full review](https://www.g2.com/survey_responses/sprocket-security-review-10011896)

---



### 19. [Edgescan](https://www.g2.com/products/edgescan/reviews)
What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.


**Average Rating:** 4.7/5.0
**Total Reviews:** 51
**How Do G2 Users Rate Edgescan?**

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.5/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.6/10 (Category avg: 9.1/10)
- **Extensibility:** 8.9/10 (Category avg: 8.7/10)

**Who Is the Company Behind Edgescan?**

- **Seller:** [Edgescan](https://www.g2.com/sellers/edgescan)
- **Company Website:** https://www.edgescan.com
- **Year Founded:** 2017
- **HQ Location:** Dublin, Dublin
- **Twitter:** @edgescan (2,256 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/2928425/ (88 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 32% Enterprise, 32% Mid-Market


#### What Are Edgescan's Pros and Cons?

**Pros:**

- Ease of Use (25 reviews)
- Vulnerability Detection (24 reviews)
- Customer Support (19 reviews)
- Vulnerability Identification (19 reviews)
- Features (18 reviews)

**Cons:**

- Complex UI (5 reviews)
- Limited Customization (5 reviews)
- Poor Interface Design (5 reviews)
- Slow Performance (5 reviews)
- UX Improvement (5 reviews)


### What Do G2 Reviewers Say About Edgescan?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** with Edgescan, benefiting from seamless setup, integration, and effective reporting dashboards.
- Users praise Edgescan for its **validated, near false positive free vulnerability scanning** , enhancing security with effective scanning solutions.
- Users appreciate Edgescan&#39;s **responsive customer support** , ensuring smooth transitions and quick answers throughout the experience.
- Users value the **validated vulnerability scanning** by Edgescan for its accuracy and ease of integration.
- Users appreciate the **continuous improvement and user-friendly features** of Edgescan, enhancing their overall experience.

**Cons:**

- Users find the **UI complex and non-intuitive** , making navigation and access to settings challenging at times.
- Users find the **limited customization** of Edgescan frustrating, especially with infrequent host configuration updates.
- Users find the **poor interface design** of Edgescan frustrating, impacting usability and ease of access to information.
- Users often experience **slow performance** with scan results taking longer than expected, impacting overall efficiency.
- Users find the **UI to be outdated and user-unfriendly** , complicating data access and support requests within Edgescan.

#### What Are Recent G2 Reviews of Edgescan?

**"[Edgescan: Easy Setup, Clear Insights, and Expert Security Support](https://www.g2.com/survey_responses/edgescan-review-12224347)"**

**Rating:** 5.0/5.0 stars
*— Matt W.*

[Read full review](https://www.g2.com/survey_responses/edgescan-review-12224347)

---

**"[Edgescan Is Amazing!](https://www.g2.com/survey_responses/edgescan-review-11014532)"**

**Rating:** 5.0/5.0 stars
*— Greg S.*

[Read full review](https://www.g2.com/survey_responses/edgescan-review-11014532)

---


#### What Are G2 Users Discussing About Edgescan?

- [What is edgescan used for?](https://www.g2.com/discussions/what-is-edgescan-used-for) - 1 comment

### 20. [RidgeBot](https://www.g2.com/products/ridgebot/reviews)
RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It&#39;s dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.


**Average Rating:** 4.5/5.0
**Total Reviews:** 98
**How Do G2 Users Rate RidgeBot?**

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.2/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.0/10 (Category avg: 9.1/10)
- **Extensibility:** 8.6/10 (Category avg: 8.7/10)

**Who Is the Company Behind RidgeBot?**

- **Seller:** [Ridge Security Technology](https://www.g2.com/sellers/ridge-security-technology)
- **Company Website:** https://ridgesecurity.ai/
- **Year Founded:** 2020
- **HQ Location:** Santa Clara, California
- **Twitter:** @RidgeSecurityAI (1,291 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/ridge-security/ (47 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 51% Small-Business, 45% Mid-Market


#### What Are RidgeBot's Pros and Cons?

**Pros:**

- Ease of Use (12 reviews)
- Automation (11 reviews)
- Pentesting Efficiency (10 reviews)
- Vulnerability Identification (9 reviews)
- Efficiency (8 reviews)

**Cons:**

- Complex Setup (4 reviews)
- Complexity (3 reviews)
- Missing Features (3 reviews)
- Poor Customer Support (3 reviews)
- Poor Documentation (3 reviews)


### What Do G2 Reviewers Say About RidgeBot?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of RidgeBot, highlighting its straightforward setup and efficient automation features.
- Users value the **automation capabilities** of RidgeBot, streamlining penetration testing and enhancing overall security efficiency.
- Users value RidgeBot for its **high pentesting efficiency** , automating vulnerability testing and providing clear, actionable reports.
- Users value the **automated vulnerability identification** by RidgeBot, enhancing security efficiency and accuracy in assessments.
- Users value the **efficiency** of RidgeBot, as it automates penetration testing and accelerates security threat identification.

**Cons:**

- Users find the **complex setup** challenging, especially newcomers who struggle without sufficient documentation and support.
- Users find RidgeBot&#39;s **configuration complexity** challenging, particularly with customized or legacy systems in their environments.
- Users point out **missing features** in RidgeBot, particularly in API testing and reporting templates for compliance standards.
- Users find RidgeBot&#39;s **poor customer support** frustrating, often needing to solve issues independently due to insufficient resources.
- Users struggle with **poor documentation** that hinders initial setup and requires self-sourcing solutions for smaller issues.

#### What Are Recent G2 Reviews of RidgeBot?

**"[Powerful and Efficient, Although It Requires Manual Validations](https://www.g2.com/survey_responses/ridgebot-review-12940521)"**

**Rating:** 4.5/5.0 stars
*— Henry A.*

[Read full review](https://www.g2.com/survey_responses/ridgebot-review-12940521)

---

**"[Powerful Vulnerability Assessment and Remediation Capabilities](https://www.g2.com/survey_responses/ridgebot-review-12910247)"**

**Rating:** 5.0/5.0 stars
*— Daniel Felipe P.*

[Read full review](https://www.g2.com/survey_responses/ridgebot-review-12910247)

---



### 21. [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.


**Average Rating:** 4.6/5.0
**Total Reviews:** 145
**How Do G2 Users Rate Aikido Security?**

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 10.0/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 10.0/10 (Category avg: 9.1/10)

**Who Is the Company Behind Aikido Security?**

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** https://aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity (11,770 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/aikido-security/ (241 employees on LinkedIn®)

**Who Uses This Product?**
- **Who Uses This:** CTO, Founder
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 70% Small-Business, 18% Mid-Market


#### What Are Aikido Security's Pros and Cons?

**Pros:**

- Ease of Use (78 reviews)
- Security (55 reviews)
- Features (52 reviews)
- Easy Integrations (47 reviews)
- Easy Setup (47 reviews)

**Cons:**

- Missing Features (19 reviews)
- Expensive (17 reviews)
- Limited Features (16 reviews)
- Pricing Issues (15 reviews)
- Lacking Features (14 reviews)


### What Do G2 Reviewers Say About Aikido Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear insights and seamless integration.
- Users commend Aikido Security for its **intuitive interface** , streamlining the identification and management of security issues effectively.
- Users value Aikido Security for its **user-friendly dashboard and meaningful free tier features** that enhance security workflows.
- Users value the **easy integrations** with GitLab, enhancing day-to-day workflows and security management effortlessly.
- Users laud the **easy setup** of Aikido Security, facilitating seamless integration into existing workflows and enhancing security practices.

**Cons:**

- Users feel a need for **missing features** like code quality checks and advanced integrations for a better experience.
- Users find the **pricing overly high** , especially for startups, despite acknowledging its value.
- Users find Aikido Security&#39;s **limited features** restrict customization and reporting capabilities for complex enterprise needs.
- Users find **pricing issues** with Aikido Security, especially the high entry fees for startups and limited trial duration.
- Users find Aikido Security **lacking features** like local PR annotations and deeper analysis tools crucial for development.

#### What Are Recent G2 Reviews of Aikido Security?

**"[Effortless Security Testing with Comprehensive Coverage](https://www.g2.com/survey_responses/aikido-security-review-12747129)"**

**Rating:** 4.0/5.0 stars
*— Dylan E.*

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-12747129)

---

**"[AI Code Reviews That Catch Vulnerabilities and Logic Bugs Across Multiple Repos](https://www.g2.com/survey_responses/aikido-security-review-13024655)"**

**Rating:** 5.0/5.0 stars
*— Jonathon K.*

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13024655)

---



### 22. [SQLmap](https://www.g2.com/products/sqlmap/reviews)
Automatic SQL injection and database takeover tool


**Average Rating:** 4.3/5.0
**Total Reviews:** 37
**How Do G2 Users Rate SQLmap?**

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.0/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 8.4/10 (Category avg: 9.1/10)
- **Extensibility:** 7.8/10 (Category avg: 8.7/10)

**Who Is the Company Behind SQLmap?**

- **Seller:** [SQLmap](https://www.g2.com/sellers/sqlmap)
- **Year Founded:** 2008
- **HQ Location:** San Francisco, CA
- **Twitter:** @github (2,673,925 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/No-Linkedin-Presence-Added-Intentionally-By-DataOps (1 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software, Computer &amp; Network Security
- **Company Size:** 53% Small-Business, 42% Mid-Market



#### What Are Recent G2 Reviews of SQLmap?

**"[A single masterpiece for hunting and automating sql injection](https://www.g2.com/survey_responses/sqlmap-review-8116856)"**

**Rating:** 5.0/5.0 stars
*— Atul T.*

[Read full review](https://www.g2.com/survey_responses/sqlmap-review-8116856)

---

**"[Helps developers](https://www.g2.com/survey_responses/sqlmap-review-8251812)"**

**Rating:** 5.0/5.0 stars
*— SHASHIDHAR KUDARI .*

[Read full review](https://www.g2.com/survey_responses/sqlmap-review-8251812)

---


#### What Are G2 Users Discussing About SQLmap?

- [What is SQLmap used for?](https://www.g2.com/discussions/what-is-sqlmap-used-for)

### 23. [Evolve Security](https://www.g2.com/products/evolve-security-evolve-security/reviews)
Evolve Security&#39;s patent pending Darwin Attack® platform is a comprehensive collaboration and management tool designed to help organizations manage their cybersecurity services and reduce risks of successful cyberattacks. The platform serves as a repository for research, vulnerability and attack details, compliance requirements, remediation recommendations, and mitigating controls. It also functions as a security feed, collaboration tool, tracking tool, management platform, and reporting platform. The platform enables organizations to actively manage their security program by providing real-time updates on testing progress and findings, which allows for timely remediation. Darwin Attack® is constantly updated with new information and functionality to ensure that it remains effective and efficient in meeting the needs of Evolve Security&#39;s clients.


**Average Rating:** 4.8/5.0
**Total Reviews:** 53
**How Do G2 Users Rate Evolve Security?**

- **Has the product been a good partner in doing business?:** 9.8/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 9.1/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.4/10 (Category avg: 9.1/10)
- **Extensibility:** 8.8/10 (Category avg: 8.7/10)

**Who Is the Company Behind Evolve Security?**

- **Seller:** [Evolve Security](https://www.g2.com/sellers/evolve-security)
- **Year Founded:** 2016
- **HQ Location:** Chicago, Illinois
- **Twitter:** @theevolvesec (788 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/evolve-security/ (65 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Financial Services
- **Company Size:** 70% Mid-Market, 21% Small-Business


#### What Are Evolve Security's Pros and Cons?

**Pros:**

- Actionable Intelligence (2 reviews)
- Vulnerability Detection (2 reviews)
- Vulnerability Identification (2 reviews)
- Audit Support (1 reviews)
- Communication (1 reviews)



### What Do G2 Reviewers Say About Evolve Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **actionable intelligence** provided by Evolve Security for effectively addressing security vulnerabilities.
- Users value the **vulnerability detection** by Evolve Security, appreciating detailed guidance and effective communication throughout the process.
- Users value the **effective vulnerability identification** by Evolve Security, helping them improve security with clear guidance.
- Users value the **excellent audit support** from Evolve Security, appreciating clear communication and actionable insights.
- Users appreciate the **effective communication** from Evolve Security, facilitating timely insights and guidance throughout the pentesting process.


#### What Are Recent G2 Reviews of Evolve Security?

**"[Outstanding Cybersecurity Partner with Thorough, Actionable Pen Testing](https://www.g2.com/survey_responses/evolve-security-review-13059557)"**

**Rating:** 5.0/5.0 stars
*— Lesly V.*

[Read full review](https://www.g2.com/survey_responses/evolve-security-review-13059557)

---

**"[Professional, Well-Managed ASM and Pen Testing Experience](https://www.g2.com/survey_responses/evolve-security-review-12743932)"**

**Rating:** 5.0/5.0 stars
*— Kevin C.*

[Read full review](https://www.g2.com/survey_responses/evolve-security-review-12743932)

---



### 24. [Strobes Security](https://www.g2.com/products/strobes-security/reviews)
Strobes is an AI-driven exposure management platform designed to help organizations streamline their security operations by unifying various security methodologies, including Attack Surface Management (ASM), Application Security Posture Management (ASPM), Risk-Based Vulnerability Management (RBVM), and Penetration Testing as a Service (PTaaS). This comprehensive solution provides users with a holistic view of their security posture, enabling them to identify, assess, and respond to potential risks and vulnerabilities effectively. Targeted primarily at security teams and IT professionals, Strobes caters to organizations of all sizes that require a robust approach to managing their security exposure. The platform is particularly beneficial for those who need to navigate the complexities of modern security environments, where multiple tools and processes can lead to fragmented insights. By consolidating various security functions into a single workflow, Strobes empowers users to make informed decisions based on a complete understanding of their risk landscape. One of the key features of Strobes is its extensive integration capabilities, boasting over 120 integrations with existing security tools and systems. This allows organizations to pull findings from disparate sources into a single view, enriching data with contextual information that enhances the relevance of insights. The platform&#39;s advanced correlation capabilities help identify relationships between different vulnerabilities and risks, enabling security teams to prioritize their remediation efforts effectively. The user-friendly dashboards in Strobes serve as a central hub for monitoring security activities, encompassing everything from asset discovery and vulnerability insights to Service Level Agreement (SLA) tracking and ticketing. This comprehensive visibility supports continuous prioritization and fix validation, allowing teams to address the most critical issues first. By automating triage processes, Strobes ensures that real risks and exposures are highlighted, facilitating a more efficient response to potential threats. Overall, Strobes stands out in the exposure management landscape by providing a cohesive and intelligent approach to security management. Its ability to unify various methodologies, coupled with powerful automation and integration features, positions it as a valuable tool for organizations seeking to enhance their security posture and effectively manage their exposure to risks.


**Average Rating:** 4.6/5.0
**Total Reviews:** 34
**How Do G2 Users Rate Strobes Security?**

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.3/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 9.8/10 (Category avg: 9.1/10)

**Who Is the Company Behind Strobes Security?**

- **Seller:** [Strobes Security Inc](https://www.g2.com/sellers/strobes-security-inc)
- **Company Website:** https://www.strobes.co/
- **Year Founded:** 2019
- **HQ Location:** Plano, US
- **Twitter:** @StrobesHQ (218 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/strobeshq (98 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software
- **Company Size:** 37% Mid-Market, 37% Enterprise


#### What Are Strobes Security's Pros and Cons?

**Pros:**

- Vulnerability Identification (14 reviews)
- Vulnerability Detection (13 reviews)
- Security (11 reviews)
- Customer Support (10 reviews)
- Ease of Use (10 reviews)

**Cons:**

- Inadequate Reporting (4 reviews)
- Limited Customization (4 reviews)
- Poor Usability (4 reviews)
- Reporting Issues (4 reviews)
- Complexity (2 reviews)


### What Do G2 Reviewers Say About Strobes Security?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend Strobes for its **thorough vulnerability identification** , enhancing security through clear insights and actionable fixes.
- Users commend Strobes Security for its **exceptional vulnerability detection** , pinpointing flaws and offering clear remediation suggestions.
- Users commend Strobes for its **robust security solutions** , effectively identifying vulnerabilities and streamlining vulnerability management processes.
- Users commend the **proactive and engaging customer support** of Strobes Security, ensuring timely resolutions and effective communication.
- Users commend the **ease of use** of Strobes Security, appreciating its intuitive interface and efficient vulnerability management lifecycle.

**Cons:**

- Users criticize the **inadequate reporting** features of Strobes Security, lacking depth and flexibility for effective analysis and presentations.
- Users find **limited customization** options frustrating, particularly in workflow integration and dashboard clarity.
- Users note a **poor usability** experience with Strobes Security due to its steep learning curve and daunting interface.
- Users express frustration with the **lack of transparency and flexibility in reporting** , hindering effective analysis and customization.
- Users find the **UI complex** and the initial setup of Strobes Security can be unintuitive and challenging.

#### What Are Recent G2 Reviews of Strobes Security?

**"[Valuable Security Assessments with Practical Findings](https://www.g2.com/survey_responses/strobes-security-review-12795666)"**

**Rating:** 4.5/5.0 stars
*— Apoorva J.*

[Read full review](https://www.g2.com/survey_responses/strobes-security-review-12795666)

---

**"[Comprehensive and Reliable Attack Surface Management Solution](https://www.g2.com/survey_responses/strobes-security-review-12638010)"**

**Rating:** 5.0/5.0 stars
*— Divya D.*

[Read full review](https://www.g2.com/survey_responses/strobes-security-review-12638010)

---



### 25. [Acunetix by Invicti](https://www.g2.com/products/acunetix-by-invicti/reviews)
Acunetix (by Invicti) is an automated application security testing tool that enables small security teams to tackle huge application security challenges. With fast scanning, comprehensive results, and intelligent automation, Acunetix helps organizations to reduce risk across all types of web applications, websites, and APIs. With Acunetix, security teams can: - Save time and resources by automating manual security processes - Work more seamlessly with developers, or embrace DevSecOps by integrating directly into development tools - Feel confident that every web application has been crawled entirely thanks to DAST + IAST scanning and intelligent crawling technology - Finally, make web application and API security a priority and not just an add-on with a solution that is dedicated to application and API security 100% of the time You can depend on Acunetix to meet your organization’s needs today and face the challenges of modern web technology together tomorrow.


**Average Rating:** 4.1/5.0
**Total Reviews:** 100
**How Do G2 Users Rate Acunetix by Invicti?**

- **Has the product been a good partner in doing business?:** 8.2/10 (Category avg: 9.4/10)
- **Performance and Reliability:** 8.1/10 (Category avg: 9.1/10)
- **Vulnerability Scan:** 8.6/10 (Category avg: 9.1/10)
- **Extensibility:** 7.4/10 (Category avg: 8.7/10)

**Who Is the Company Behind Acunetix by Invicti?**

- **Seller:** [Invicti Security](https://www.g2.com/sellers/invicti-security-04cb0d3d-fd96-45b2-83dc-2038fc9dac92)
- **Company Website:** https://www.invicti.com/
- **Year Founded:** 2018
- **HQ Location:** Austin, Texas
- **Twitter:** @InvictiSecurity (2,557 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/invicti-security/people/ (335 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 40% Enterprise, 34% Mid-Market


#### What Are Acunetix by Invicti's Pros and Cons?

**Pros:**

- Vulnerability Detection (7 reviews)
- Ease of Use (6 reviews)
- Security (5 reviews)
- Vulnerability Identification (5 reviews)
- Accuracy of Results (4 reviews)

**Cons:**

- Expensive (4 reviews)
- Complexity (3 reviews)
- Complex Setup (3 reviews)
- Slow Scanning (3 reviews)
- Difficult Customization (2 reviews)


### What Do G2 Reviewers Say About Acunetix by Invicti?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **accurate and fast vulnerability detection** of Acunetix, enabling efficient security management with minimal false positives.
- Users praise the **ease of use** in Acunetix, appreciating its quick setup and integration into workflows.
- Users highlight the **effective vulnerability detection** of Acunetix, enhancing overall web application security and efficiency.
- Users value the **effective vulnerability identification** of Acunetix, enhancing security and simplifying remediation processes.
- Users commend Acunetix for its **impressive accuracy in vulnerability detection** , greatly enhancing web application security.

**Cons:**

- Users find the **pricing structure expensive** , making it less accessible for smaller teams or projects.
- Users find the **complexity** of setup and scans in Acunetix can be overwhelming and resource-intensive, impacting workflow.
- Users find the **complex setup** of Acunetix challenging, especially for beginners and during deep scans of large applications.
- Users experience **slow scanning** with Acunetix, particularly with large applications, affecting overall efficiency and workflow.
- Users find **difficult customization** in Acunetix, requiring technical know-how and patience for effective integration and setup.

#### What Are Recent G2 Reviews of Acunetix by Invicti?

**"[Powerful Security Scanning Made Easy with Acunetix](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11964967)"**

**Rating:** 5.0/5.0 stars
*— Deepesh V.*

[Read full review](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11964967)

---

**"[Effortless Vulnerability Detection That Fits Seamlessly into DevSecOps](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11909125)"**

**Rating:** 5.0/5.0 stars
*— Ranit D.*

[Read full review](https://www.g2.com/survey_responses/acunetix-by-invicti-review-11909125)

---


#### What Are G2 Users Discussing About Acunetix by Invicti?

- [How has Acunetix supported your web security efforts, and what features do you rely on most?](https://www.g2.com/discussions/how-has-acunetix-supported-your-web-security-efforts-and-what-features-do-you-rely-on-most)
- [What is Acunetix by Invicti used for?](https://www.g2.com/discussions/what-is-acunetix-by-invicti-used-for)


## What Is Penetration Testing Tools?

[DevSecOps Software](https://www.g2.com/categories/devsecops)

## What Software Categories Are Similar to Penetration Testing Tools?

- [Vulnerability Scanner Software](https://www.g2.com/categories/vulnerability-scanner)
- [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast)
- [Risk-Based Vulnerability Management Software](https://www.g2.com/categories/risk-based-vulnerability-management)


