Top Free Penetration Testing Tools

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 170

Category Stats (Sep 2026)

  • Average Rating: 4.63/5 (↓0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,800+ Authentic Reviews
  • 170+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: vPenTest, Cobalt, Astra Pentest, Oneleet, NodeZero from Horizon3.ai, Pentera, H1 Platform, and Bugcrowd.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=vpentest&focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=astra-pentest&focus%5B%5D=oneleet&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=pentera&focus%5B%5D=h1-platform&focus%5B%5D=bugcrowd)

vPenTest

Vonahi Security is building the future of offensive cybersecurity by delivering automated, high-quality penetration testing through its SaaS platform, vPenTest. Designed to replicate the tools, techniques, and methodologies of experienced consultants, vPenTest brings the benefits of manual network penetration testing into an easy-to-use, automated solution. Traditionally, penetration testing has been a manual, time consuming, and expensive process that many organizations only perform once or twice a year. This often leaves businesses exposed to emerging threats between assessments. vPenTest addresses this gap by offering fast, consistent, and on-demand testing that helps organizations evaluate their real-time cybersecurity risk more effectively. Powered by a proprietary framework that evolves through continuous research and real-world insights, vPenTest stays aligned with the latest attack techniques and industry best practices. The platform is backed by over 13 years of offensive security expertise, with the team holding certifications such as CISSP, OSCP, OSCE, CEH, and more. Their knowledge is built directly into the platform, ensuring each test is conducted with depth, consistency, and accuracy—without the delays or variability of manual testing.
 vPenTest enables organizations to run internal and external network penetration tests as often as needed monthly, quarterly, or prior to audits or insurance reviews. The automated reports provide actionable insights that make it easy to prioritize remediation and demonstrate progress toward compliance. Today, over 22,000 organizations rely on vPenTest to strengthen their security posture and reduce risk. This includes managed service providers, managed security service providers, financial institutions, compliance-driven organizations, and internal IT teams. Whether you're working to meet regulatory requirements, secure cyber insurance coverage, or proactively defend against evolving threats, vPenTest makes network penetration testing easy, affordable, and scalable.

Average Rating: 4.6/5.0

Total Reviews: 244

How Do G2 Users Rate vPenTest?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.0/10 (Category avg: 9.2/10)
  • Extensibility: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind vPenTest?

  • Seller: Kaseya
  • Company Website:
  • Year Founded: 2000
  • HQ Location: Miami, FL
  • Twitter: @KaseyaCorp
    17,411 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,483 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 69% Small, 24% Medium

What Do G2 Reviewers Say About vPenTest?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of vPenTest, praising its intuitive interface and smooth setup process.
  • Users praise the detailed and reliable technical reports from vPenTest, enhancing their remediation efforts effectively.
  • Users appreciate the user-friendly interface of vPenTest, enhancing their efficiency in conducting penetration tests.
  • Users commend the easy setup of vPenTest, finding it a smooth experience for managing security solutions effectively.
  • Users highlight the ease of implementation of vPenTest, appreciating its quick setup and seamless integration into workflows.
Cons
  • Users find the limited scope of vPenTest frustrating, as it doesn't cover all necessary pentesting aspects.
  • Users find the setup process complex, highlighting challenges with initial configuration and integration with existing systems.
  • Users find the lack of detail in vPenTest confusing, complicating communication and understanding of findings.
  • Users find the inadequate reporting of vPenTest restricts customization and leads to repetitive findings over time.
  • Users find vPenTest to be expensive, especially for smaller organizations facing pricing and contract challenges.

What Are Recent G2 Reviews of vPenTest?

Astra Pentest

Astra Security is a leading continuous penetration testing platform that combines AI-powered autonomous pentesting with certified expert-led assessments. Powered by Attack AI, trained on 6.8M+ security findings and insights from 5,000+ real-world pentests. Astra deploys intelligent agents that continuously discover, validate, prioritize, and help remediate vulnerabilities at scale. While AI handles speed and scale, Astra’s certified security experts focus on what automation alone cannot: complex business logic flaws, multi-step attack chains, advanced exploit paths, and emerging AI/LLM-specific threats. Built for modern engineering teams, Astra integrates directly into CI/CD workflows, enabling continuous security validation between releases instead of relying on outdated annual pentests. The platform delivers comprehensive Autonomous Pentest powered by AI agents, DAST vulnerability scanner and human-driven pentests across web apps, AI/LLMs, mobile apps, APIs, cloud infrastructure. Astra is CREST-accredited, CERT-IN empaneled, and a PCI ASV-certified vendor. Our team also led the development of the OWASP APTS framework, helping shape the industry standard for continuous security testing. Today, 1,500+ organizations across 70+ countries trust Astra Security, including Ford, Loom, CompTIA, Hitachi, HackerRank, and OLX.

Average Rating: 4.6/5.0

Total Reviews: 242

G2 Deal: For G2 users: 10% off across all pentest plans

Avail Astra Pentest at 10% off, our comprehensive pentest suite scans for 8000+ security tests including OWASP Top 10, SANS 25, known CVEs & security best practices. This offer is exclusive to G2 users!

Price: ~~$5999~~ → $5400

View this exclusive G2 deal

How Do G2 Users Rate Astra Pentest?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.0/10 (Category avg: 9.2/10)
  • Extensibility: 8.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Astra Pentest?

  • Seller: ASTRA IT, Inc.
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Bengaluru, IN
  • Twitter: @getastra
    694 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    154 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, CEO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 66% Small, 28% Medium

What Do G2 Reviewers Say About Astra Pentest?

AI-generated summary from verified user reviews

Pros
  • Users commend Astra Pentest's excellent customer support, noting their responsiveness and flexibility throughout the process.
  • Users praise the comprehensive vulnerability detection of Astra Pentest, which simplifies tracking and prioritizing security issues.
  • Users appreciate the user-friendly interface of Astra Pentest, enhancing their experience with clear and efficient vulnerability management.
  • Users commend Astra Pentest for its efficient scanning and penetration testing, enhancing security preparedness and team responsiveness.
  • Users value the vulnerability identification of Astra Pentest, enhancing confidence in security and business growth.
Cons
  • Users report poor customer support with Astra Pentest, noting slow email responses and lack of instant messaging options.
  • Users find the poor interface design of Astra Pentest frustrating, leading to confusion and difficulties in usage.
  • Users report slow performance with Astra Pentest, citing delays in results and instability during use.
  • Users find the UI challenging, particularly with note-taking and clarity on rescan needs during pentests.
  • Users face a lack of information with Astra Pentest, as documentation and updates are often insufficient or slow to arrive.

What Are Recent G2 Reviews of Astra Pentest?

What Are G2 Users Discussing About Astra Pentest?

NodeZero from Horizon3.ai

Horizon3's NodeZero® platform empowers your organization to continuously find, fix, and verify your exploitable attack surface. Reduce your security risk by autonomously finding weaknesses in your network, knowing how to prioritize and fix them, and immediately verifying that your fixes work. NodeZero delivers production-safe autonomous pentests and other key assessment operations that scale across your largest internal, external, cloud, and hybrid cloud environments. No required agents, no code to write, and no consultants to hire.

Average Rating: 4.5/5.0

Total Reviews: 39

How Do G2 Users Rate NodeZero from Horizon3.ai?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.6/10 (Category avg: 9.2/10)
  • Extensibility: 9.8/10 (Category avg: 8.8/10)

Who Is the Company Behind NodeZero from Horizon3.ai?

  • Seller: Horizon3.ai
  • Company Website:
  • Year Founded: 2019
  • HQ Location: San Francisco, US
  • Twitter: @Horizon3ai
    2,802 Twitter followers
  • LinkedIn® Page: linkedin.com
    548 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 49% Medium, 26% Small

What Do G2 Reviewers Say About NodeZero from Horizon3.ai?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the intuitive vulnerability detection of NodeZero, enhancing their cybersecurity capabilities effectively.
  • Users appreciate the intuitive communication of NodeZero, making it accessible and effective for both technical and nontechnical users.
  • Users value the intuitive and thorough integration of NodeZero, making it essential for effective cybersecurity.
  • Users appreciate the ease of implementation of NodeZero, finding it intuitive and accessible for all team members.
  • Users value the easy integrations of NodeZero, making it accessible for both technical and non-technical teams.
Cons
  • Users feel that reporting is inadequate, as specific machines for tripwires are not clearly identified in the results.
  • Users note a lack of detail in reporting specific machine successes and failures with Tripwires functionality.

What Are Recent G2 Reviews of NodeZero from Horizon3.ai?

Synack

Synack is a continuous penetration testing platform that combines agentic AI with a global network of vetted security researchers to uncover real, exploitable vulnerabilities across the entire attack surface. Most organizations test only a fraction of what matters. Synack closes that coverage gap—using AI to scale discovery and human expertise to validate real risk. The platform enables enterprises to move from periodic testing to continuous security validation across web applications, APIs, cloud, and infrastructure—prioritizing findings based on what is actually exploitable, not just detected. Synack supports penetration testing, continuous security testing, vulnerability management, and attack surface management in dynamic, cloud-based, and hybrid environments. Founded by former NSA professionals, Synack supports enterprise and public sector organizations where security, compliance, and risk management are mission-critical.

Average Rating: 4.8/5.0

Total Reviews: 21

How Do G2 Users Rate Synack?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Synack?

  • Seller: Synack
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Redwood City, California, United States
  • Twitter: @synack
    26,716 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    244 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 71% Large, 14% Medium

What Are Recent G2 Reviews of Synack?

What Are G2 Users Discussing About Synack?

Intruder

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

Average Rating: 4.8/5.0

Total Reviews: 220

How Do G2 Users Rate Intruder?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.4/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.6/10 (Category avg: 9.2/10)
  • Extensibility: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Intruder?

  • Seller: Intruder
  • Company Website:
  • Year Founded: 2015
  • HQ Location: London
  • Twitter: @intruder_io
    979 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    81 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, Director
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 56% Small, 37% Medium

What Do G2 Reviewers Say About Intruder?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Intruder, with quick setup and intuitive system design enhancing their experience.
  • Users value the clarity and prioritization of Intruder's findings, enabling effective risk management and actionable insights.
  • Users value the quick and efficient customer support from Intruder, enhancing their overall scanning experience.
  • Users appreciate the intuitive interface of Intruder, finding it easy to set up and navigate.
  • Users value the efficient vulnerability identification from Intruder, enhancing their cybersecurity management effortlessly.
Cons
  • Users find the product expensive due to high costs for add-ons and fees per endpoint scanned.
  • Users find the slow scanning process frustrating, leading to inefficiencies and missed vulnerabilities during security assessments.
  • Users find licensing issues challenging, particularly regarding costs and constraints that affect system configurations.
  • Users experience false positives which can obscure the detection of critical vulnerabilities in security monitoring.
  • Users find the limited features of Intruder less accommodating for specific reporting and customization needs.

What Are Recent G2 Reviews of Intruder?

What Are G2 Users Discussing About Intruder?

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 263

How Do G2 Users Rate Aikido Security?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    320 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 79% Small, 14% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, thanks to its clear insights and seamless integration.
  • Users appreciate Aikido Security's robust security capabilities, providing a comprehensive and seamless integration in their workflow.
  • Users value the intuitive dashboard of Aikido Security, which simplifies security issue identification and management.
  • Users value the easy integrations of Aikido Security, enhancing workflows with seamless connections to existing GitLab repositories.
  • Users find Aikido's easy setup highly efficient, enabling quick implementation and immediate usability for security assessments.
Cons
  • Users note the lack of advanced features in Aikido Security, such as dark mode and in-depth analysis options.
  • Users find the pricing structure expensive for micro businesses, making upgrades difficult to justify.
  • Users note the limited features of Aikido Security, wishing for more customization and advanced options.
  • Users find the pricing issues challenging, especially for micro businesses, due to the steep upgrade costs.
  • Users feel Aikido Security is lacking features like advanced reporting and deeper compliance analysis compared to competitors.

What Are Recent G2 Reviews of Aikido Security?

Metasploit

Metasploit is a comprehensive penetration testing platform developed by Rapid7, designed to help security professionals identify, exploit, and validate vulnerabilities within their networks. By simulating real-world attacks, Metasploit enables organizations to assess their security posture and enhance their defenses against potential threats. Key Features and Functionality: - Extensive Exploit Library: Access to a vast, regularly updated database of over 1,500 exploits and 3,300 modules, allowing users to simulate a wide range of attack scenarios. - Automated Exploitation: Features like Smart Exploitation and automated credential brute-forcing streamline the penetration testing process, increasing efficiency and accuracy. - Post-Exploitation Modules: Over 330 post-exploitation modules enable testers to assess the impact of a successful breach and gather critical information from compromised systems. - Credential Testing: Ability to run brute-force attacks against more than 20 account types, including databases, web servers, and remote administration tools, to uncover weak or reused passwords. - Integration Capabilities: Seamless integration with other Rapid7 products, such as InsightVM and Nexpose, facilitates closed-loop vulnerability validation and remediation prioritization. Primary Value and Problem Solving: Metasploit empowers organizations to proactively identify and address security weaknesses before malicious actors can exploit them. By simulating real-world attacks, it provides valuable insights into potential vulnerabilities, enabling security teams to prioritize remediation efforts effectively. This proactive approach enhances overall security awareness, reduces the risk of breaches, and ensures compliance with industry standards and regulations.

Average Rating: 4.6/5.0

Total Reviews: 53

How Do G2 Users Rate Metasploit?

  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.4/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.7/10 (Category avg: 9.2/10)
  • Extensibility: 8.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Metasploit?

  • Seller: Rapid7
  • Year Founded: 2000
  • HQ Location: Boston, MA
  • Twitter: @rapid7
    124,405 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    8,746 employees on LinkedIn®
  • Ownership: NASDAQ:RPD

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 47% Small, 40% Medium

What Do G2 Reviewers Say About Metasploit?

AI-generated summary from verified user reviews

Pros
  • Users value the pentesting efficiency of Metasploit, highlighting its comprehensive toolkit for creating various payloads.
  • Users praise the expertise of Metasploit, noting its ability to create various payloads for effective system exploitation.
Cons
  • Users find the complex setup of Metasploit challenging and desire better automation features for improved usability.

What Are Recent G2 Reviews of Metasploit?

What Are G2 Users Discussing About Metasploit?

Indusface WAS

Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily monitoring for web applications, checking for systems and application vulnerabilities, and malware. Indusface WAS with its automated scans & manual pentesting done by certified security experts ensures none of the OWASP Top10, business logic vulnerabilities, and malware go unnoticed. With zero false-positive guarantee and comprehensive reporting with remediation guidance, Indusface web app scanning ensures developers to quickly fix vulnerabilities seamlessly.

Average Rating: 4.6/5.0

Total Reviews: 64

How Do G2 Users Rate Indusface WAS?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Indusface WAS?

  • Seller: Indusface
  • Year Founded: 2012
  • HQ Location: Vadodara
  • Twitter: @Indusface
    3,472 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    172 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Small, 37% Medium

What Do G2 Reviewers Say About Indusface WAS?

AI-generated summary from verified user reviews

Pros
  • Users commend the reliable vulnerability detection of Indusface WAS, ensuring comprehensive scans and quick resolution of issues.
  • Users value the effective vulnerability identification of Indusface WAS, enhancing security with reliable manual and automated scans.
  • Users commend the responsive customer support of Indusface WAS, facilitating quick resolutions and effective communication throughout the process.
  • Users value the scanning efficiency of Indusface WAS, delivering deep insights into vulnerabilities without false positives.
  • Users value the deep-dive security scans of Indusface WAS, enhancing their security accreditation and vulnerability management.
Cons
  • Users feel that the pricing is too high for staging scans and SSL certificates compared to competitors.
  • Users find the interface confusing and suggest improvements for a more intuitive and informative design.
  • Users find the lack of features for staging and development environments limits their testing capabilities before deployment.
  • Users note the limited scope of Indusface WAS regarding staging/development environment scans, impacting functionality and testing.
  • Users find the interface design outdated, expressing a need for a more intuitive and informative experience.

What Are Recent G2 Reviews of Indusface WAS?

What Are G2 Users Discussing About Indusface WAS?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.5/10 (Category avg: 9.2/10)
  • Extensibility: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    90 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Edgescan, highlighting its intuitive interface and straightforward navigation.
  • Users value the automated vulnerability detection features of Edgescan for efficient risk assessment and remediation support.
  • Users value the excellent customer support from Edgescan, noting their responsiveness and proactivity in addressing queries.
  • Users value the detailed vulnerability identification from Edgescan, enabling effective risk management and threat mitigation strategies.
  • Users value Edgescan for its intuitive interface and comprehensive functionality that streamlines security assessments and support.
Cons
  • Users find the complex UI of Edgescan challenging, often requiring guidance to navigate key functions effectively.
  • Users find limited customization options frustrating, particularly with filtering systems and administrative functionalities.
  • Users find the poor interface design of Edgescan challenging, causing navigation and task completion difficulties.
  • Users experience slow performance with Edgescan as manual reviews lead to longer scan completion times.
  • Users find the user interface challenging and unintuitive, leading to difficulties in navigation and task completion.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Acunetix by Invicti

Acunetix (by Invicti) is an automated application security testing tool that enables small security teams to tackle huge application security challenges. With fast scanning, comprehensive results, and intelligent automation, Acunetix helps organizations to reduce risk across all types of web applications, websites, and APIs. With Acunetix, security teams can: - Save time and resources by automating manual security processes - Work more seamlessly with developers, or embrace DevSecOps by integrating directly into development tools - Feel confident that every web application has been crawled entirely thanks to DAST + IAST scanning and intelligent crawling technology - Finally, make web application and API security a priority and not just an add-on with a solution that is dedicated to application and API security 100% of the time You can depend on Acunetix to meet your organization’s needs today and face the challenges of modern web technology together tomorrow.

Average Rating: 4.1/5.0

Total Reviews: 100

How Do G2 Users Rate Acunetix by Invicti?

  • Has the product been a good partner in doing business?: 8.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.6/10 (Category avg: 9.2/10)
  • Extensibility: 7.4/10 (Category avg: 8.8/10)

Who Is the Company Behind Acunetix by Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 40% Large, 34% Medium

What Do G2 Reviewers Say About Acunetix by Invicti?

AI-generated summary from verified user reviews

Pros
  • Users value the accurate and fast vulnerability detection of Acunetix, enhancing their security scanning capabilities efficiently.
  • Users praise the ease of use of Acunetix, highlighting its simple integration and effective security scanning capabilities.
  • Users value the robust security features of Acunetix, enhancing the safety of web applications effectively.
  • Users value the effective vulnerability identification by Acunetix, enhancing web application security and streamlining remediation processes.
  • Users highlight the accuracy of results from Acunetix, noting its impressive ability to identify vulnerabilities effectively.
Cons
  • Users find Acunetix by Invicti to be expensive, making it less accessible for smaller teams or projects.
  • Users find Acunetix's complex setup and resource intensity challenging, especially for large applications and first-time configurations.
  • Users find the setup process complex, particularly for new users and large application configurations.
  • Users note that the scanning process is often slow, affecting efficiency and delaying normal workflows, especially with large applications.
  • Users find the difficult customization of Acunetix challenging, requiring technical expertise to set up and fine-tune integrations.

What Are Recent G2 Reviews of Acunetix by Invicti?

What Are G2 Users Discussing About Acunetix by Invicti?

Cyver Core

Cyver Core is a pentest collaboration and management platform to digitize, automate, and optimize manual work for pentest firms, while enabling Pentest-as-a-Service delivery. Cyver Core offers pentest report automation, branded client portals, pentest management, team management, and more.

Average Rating: 4.7/5.0

Total Reviews: 20

How Do G2 Users Rate Cyver Core?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 7.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind Cyver Core?

  • Seller: Cyver
  • Year Founded: 2020
  • HQ Location: Amsterdam, NL
  • Twitter: @cyver_io
    42 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    10 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 75% Small, 20% Medium

What Do G2 Reviewers Say About Cyver Core?

AI-generated summary from verified user reviews

Pros
  • Users value the pentesting efficiency of Cyver Core, significantly reducing reporting time and enhancing team management.
  • Users value the high reporting quality of Cyver Core, enhancing efficiency and improving client communication in vulnerability management.
  • Users appreciate the seamless and fast communication in Cyver Core, enhancing the overall user experience significantly.
  • Users praise the fast and helpful customer support of Cyver Core, enhancing collaboration and user satisfaction.
  • Users value the exceptional cybersecurity features of Cyver Core, enhancing team collaboration and improving customer experience significantly.
Cons
  • Users find limited customization in Cyver Core, restricting adaptability for specific roles and templates.
  • Users report technical issues with Cyver Core, including stability problems and occasional slow performance affecting usability.
  • Users experience poor documentation, as the UI/UX lacks intuitiveness, leading to confusion and inefficiency.
  • Users find the poor interface design of Cyver Core frustrating due to non-intuitive elements and occasional bugs.
  • Users report occasional slow performance on Cyver Core, which can interrupt their experience and productivity.

What Are Recent G2 Reviews of Cyver Core?

What Are G2 Users Discussing About Cyver Core?

Titania Nipper InfraSight

Award-winning Risk-Based Vulnerability Management. Nipper InfraSight analyzes network device configurations in the way Advances Persistent Threat (APT) groups do, to identify misconfigurations that could create attack paths. This analysis offers unparalleled, pen-tester accuracy, finding critical vulnerabilities in firewalls, routers, switches that other tools simply cannot see. Our solutions then prioritize the biggest risks to your business and provide device-specific remediation guidance, right down to specific command line prompts.  By analyzing device configurations against key compliance standards and security frameworks (including STIGs/CIS Benchmarks/PCI DSS/CMMC/CORA/NIST SP 800-53), Nipper solutions tell you precisely which devices are at risk of failing, how significant that risk is, and how you can solve it, with auditor-ready reports. Whether your focus is taking pragmatic, risk-based security measures to minimize known vulnerabilities or ensuring compliance with industry security standards, Nipper solutions provide the targeted insights you need. No other security provider looks at the network in the same way. That’s why Nipper can uniquely provide the network configuration coverage that organizations urgently require. 30+ U.S. federal agencies and 800+ organizations globally trust Nipper solutions to deliver vulnerability analysis and compliance automation while supporting air-gapped environments, sovereign cloud requirements, and complex regulated infrastructures.

Average Rating: 4.2/5.0

Total Reviews: 30

How Do G2 Users Rate Titania Nipper InfraSight?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Titania Nipper InfraSight?

  • Seller: Titania
  • Company Website:
  • Year Founded: 2009
  • HQ Location: London, GB
  • Twitter: @TitaniaLtd
    2,821 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    104 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Large, 27% Medium

What Do G2 Reviewers Say About Titania Nipper InfraSight?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Titania Nipper InfraSight exceptional, ensuring a smooth and straightforward experience.
  • Users value the high-quality reporting of Titania Nipper, which delivers insightful recommendations and clear misconfiguration assessments.
  • Users value the scanning efficiency of Titania Nipper InfraSight, enabling quick detection of network misconfigurations.
  • Users enjoy the effective vulnerability detection of Titania Nipper, offering actionable insights and structured assessments for network configuration.
  • Users appreciate the clear and user-friendly interface of Titania Nipper InfraSight, enhancing their experience and efficiency.
Cons
  • Users express concerns about licensing issues, particularly the minimum device requirement and the ongoing license model.
  • Users experience false positives in Titania Nipper InfraSight, causing confusion and affecting trust in its findings.
  • Users find the lack of cloud support limiting, especially with specific devices like wireless controllers and security groups.
  • Users face limited compatibility with devices, necessitating older versions and complicating integration with cloud services.
  • Users face challenges with limited device support, leading to complications with version maintenance and security auditing.

What Are Recent G2 Reviews of Titania Nipper InfraSight?

What Are G2 Users Discussing About Titania Nipper InfraSight?

APPCHECK

AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a hacker would, leveraging multiple proprietary crawling engines to analyse target behaviour across both modern and traditional technologies, including Single Page Applications (SPAs), APIs, and complex authentication flows such as SSO, 2FA, and TOTP. Organisations can conduct unlimited security assessments across Web Applications, SPAs, APIs, cloud services, networks, across internal or external assets. Supporting production and UAT testing, AppCheck also helps organisations ‘shift left’ by integrating with CI/CD pipelines and build servers, including ADO, GitHub, Jenkins, TeamCity, CircleCI, TravisCI, Bamboo, and GitLab CI/CD. Allowing automated security testing throughout development, identifying risks as soon as changes are introduced. AppCheck are proud to be part of the CVE Numbering Authority (CNA), contributing to global security research

Average Rating: 4.7/5.0

Total Reviews: 68

How Do G2 Users Rate APPCHECK?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.3/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.5/10 (Category avg: 9.2/10)
  • Extensibility: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind APPCHECK?

  • Seller: APPCHECK
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Leeds, GB
  • Twitter: @AppcheckNG
    649 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    104 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 49% Medium, 31% Small

What Do G2 Reviewers Say About APPCHECK?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of AppCheck, making complex processes straightforward and efficient.
  • Users commend AppCheck for its exceptional vulnerability detection, providing thorough coverage and easy integration into workflows.
  • Users value the excellent pricing and functionality of AppCheck, praising its usability and proactive support from the team.
  • Users commend AppCheck for its efficiency in pentesting, notably for thorough vulnerability coverage and seamless integration.
  • Users love the scanning efficiency of AppCheck, finding it reliable and easy to integrate within development workflows.
Cons
  • Users suggest that UX improvements in scoring, customization, and integrations could enhance the AppCheck experience.
  • Users find the API issues frustrating, as endpoint changes require a service request and delays functionality.
  • Users find difficult customization in AppCheck's reporting features, needing more flexibility for contextual adjustments.
  • Users experience a notable difficult learning curve with Appcheck, which may hinder initial ease of use.
  • Users find the false positives in scan results problematic, necessitating manual validation and complicating the reporting process.

What Are Recent G2 Reviews of APPCHECK?

Black Duck Polaris Platform

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Average Rating: 4.2/5.0

Total Reviews: 103

How Do G2 Users Rate Black Duck Polaris Platform?

  • Has the product been a good partner in doing business?: 8.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 6.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Black Duck Polaris Platform?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Large, 32% Medium

What Do G2 Reviewers Say About Black Duck Polaris Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the accuracy of findings from Black Duck SCA, highlighting its powerful engine and extensive knowledge base.
  • Users value the powerful identification of open source issues by Black Duck SCA, aided by extensive knowledge resources.
Cons
  • Users find that Black Duck SCA requires huge resources to deploy on-prem, which can be a significant drawback.

What Are Recent G2 Reviews of Black Duck Polaris Platform?

What Are G2 Users Discussing About Black Duck Polaris Platform?

StackHawk

StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate StackHawk?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind StackHawk?

  • Seller: StackHawk
  • Year Founded: 2019
  • HQ Location: Denver, CO
  • Twitter: @StackHawk
    1,137 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 46% Small, 35% Medium

What Do G2 Reviewers Say About StackHawk?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of StackHawk, facilitating seamless setups with major CI tools and configurations.
  • Users praise the excellent customer support from StackHawk, highlighting their responsiveness and helpfulness in addressing queries.
  • Users value the customizability of StackHawk, appreciating its flexibility and integration options for unique workflows.
  • Users find that StackHawk greatly enhances efficiency, enabling quicker identification and resolution of security vulnerabilities.
  • Users commend StackHawk for its scanning efficiency, enabling quick identification of vulnerabilities and seamless CI/CD integration.
Cons
  • Users find the complex setup challenging, particularly with the YAML configurations and onboarding processes for applications.
  • Users find the high learning curve of StackHawk challenging due to its complex scripting and setup process.
  • Users find StackHawk lacking features, specifically in API management and vulnerability reproducibility, hindering its usability.
  • Users find the limited scope of StackHawk restricts functionality and automation in vulnerability management.
  • Users find the setup complexity of StackHawk frustrating due to YAML configuration and onboarding challenges.

What Are Recent G2 Reviews of StackHawk?

What Are G2 Users Discussing About StackHawk?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated March 5, 2025