Best Penetration Testing Tools - Page 2

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 172

Category Stats (Sep 2026)

  • Average Rating: 4.64/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 26, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,800+ Authentic Reviews
  • 172+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: vPenTest, Cobalt, Astra Pentest, Oneleet, Pentera, NodeZero from Horizon3.ai, H1 Platform, and Bugcrowd.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=vpentest&focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=astra-pentest&focus%5B%5D=oneleet&focus%5B%5D=pentera&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=h1-platform&focus%5B%5D=bugcrowd)

Metasploit

Metasploit is a comprehensive penetration testing platform developed by Rapid7, designed to help security professionals identify, exploit, and validate vulnerabilities within their networks. By simulating real-world attacks, Metasploit enables organizations to assess their security posture and enhance their defenses against potential threats. Key Features and Functionality: - Extensive Exploit Library: Access to a vast, regularly updated database of over 1,500 exploits and 3,300 modules, allowing users to simulate a wide range of attack scenarios. - Automated Exploitation: Features like Smart Exploitation and automated credential brute-forcing streamline the penetration testing process, increasing efficiency and accuracy. - Post-Exploitation Modules: Over 330 post-exploitation modules enable testers to assess the impact of a successful breach and gather critical information from compromised systems. - Credential Testing: Ability to run brute-force attacks against more than 20 account types, including databases, web servers, and remote administration tools, to uncover weak or reused passwords. - Integration Capabilities: Seamless integration with other Rapid7 products, such as InsightVM and Nexpose, facilitates closed-loop vulnerability validation and remediation prioritization. Primary Value and Problem Solving: Metasploit empowers organizations to proactively identify and address security weaknesses before malicious actors can exploit them. By simulating real-world attacks, it provides valuable insights into potential vulnerabilities, enabling security teams to prioritize remediation efforts effectively. This proactive approach enhances overall security awareness, reduces the risk of breaches, and ensures compliance with industry standards and regulations.

Average Rating: 4.6/5.0

Total Reviews: 53

How Do G2 Users Rate Metasploit?

  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.4/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.7/10 (Category avg: 9.2/10)
  • Extensibility: 8.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Metasploit?

  • Seller: Rapid7
  • Year Founded: 2000
  • HQ Location: Boston, MA
  • Twitter: @rapid7
    124,405 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    8,746 employees on LinkedIn®
  • Ownership: NASDAQ:RPD

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 47% Small, 40% Medium

What Do G2 Reviewers Say About Metasploit?

AI-generated summary from verified user reviews

Pros
  • Users value the pentesting efficiency of Metasploit, highlighting its comprehensive toolkit for creating various payloads.
  • Users praise the expertise of Metasploit, noting its ability to create various payloads for effective system exploitation.
Cons
  • Users find the complex setup of Metasploit challenging and desire better automation features for improved usability.

What Are Recent G2 Reviews of Metasploit?

What Are G2 Users Discussing About Metasploit?

BeEF

BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.

Average Rating: 4.4/5.0

Total Reviews: 11

How Do G2 Users Rate BeEF?

  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 6.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind BeEF?

  • Seller: BeEF
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 58% Small, 33% Medium

What Are Recent G2 Reviews of BeEF?

What Are G2 Users Discussing About BeEF?

Indusface WAS

Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily monitoring for web applications, checking for systems and application vulnerabilities, and malware. Indusface WAS with its automated scans & manual pentesting done by certified security experts ensures none of the OWASP Top10, business logic vulnerabilities, and malware go unnoticed. With zero false-positive guarantee and comprehensive reporting with remediation guidance, Indusface web app scanning ensures developers to quickly fix vulnerabilities seamlessly.

Average Rating: 4.6/5.0

Total Reviews: 64

How Do G2 Users Rate Indusface WAS?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Indusface WAS?

  • Seller: Indusface
  • Year Founded: 2012
  • HQ Location: Vadodara
  • Twitter: @Indusface
    3,472 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    172 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Small, 37% Medium

What Do G2 Reviewers Say About Indusface WAS?

AI-generated summary from verified user reviews

Pros
  • Users commend the reliable vulnerability detection of Indusface WAS, ensuring comprehensive scans and quick resolution of issues.
  • Users value the effective vulnerability identification of Indusface WAS, enhancing security with reliable manual and automated scans.
  • Users commend the responsive customer support of Indusface WAS, facilitating quick resolutions and effective communication throughout the process.
  • Users value the scanning efficiency of Indusface WAS, delivering deep insights into vulnerabilities without false positives.
  • Users value the deep-dive security scans of Indusface WAS, enhancing their security accreditation and vulnerability management.
Cons
  • Users feel that the pricing is too high for staging scans and SSL certificates compared to competitors.
  • Users find the interface confusing and suggest improvements for a more intuitive and informative design.
  • Users find the lack of features for staging and development environments limits their testing capabilities before deployment.
  • Users note the limited scope of Indusface WAS regarding staging/development environment scans, impacting functionality and testing.
  • Users find the interface design outdated, expressing a need for a more intuitive and informative experience.

What Are Recent G2 Reviews of Indusface WAS?

What Are G2 Users Discussing About Indusface WAS?

Pentest-Tools.com

Vulnerability detection | Autonomous pentesting | Human expertise Built by offensive security practitioners, Pentest-Tools.com gives security teams a unified place to test their defenses continuously, go deeper when needed, and prove what needs to be fixed. Pentest-Tools.com covers multiple classes of assets, from web applications to network and cloud infrastructures, with daily detection and exploitation updates. Experienced offensive security professionals, including our customers and our own services team, constantly battle-test it across numerous engagements. Their feedback helps us keep improving the product so it delivers: ✔️ a low false positive rate ✔️ rich evidence, including screenshots, attack replay, data snippets, and more ✔️ detailed, customizable reporting Behind all of this, our vulnerability research team proactively looks for new security issues in widely used software and explores attack techniques, using them to enrich our exploit database and vulnerability feed. Unlike vulnerability scanners that primarily stop at detection, or testing approaches built around a single level of depth, Pentest-Tools.com lets teams match testing depth to the situation. Security teams can: ✔️ control what gets tested, how & when with deterministic Scanning & Validation ✔️ investigate web apps on-demand with autonomous AI Pentests ✔️ bring in human-led Offensive Security Services when business context, independent attestation, or custom reporting matter. As the target or situation changes, internal security teams can move between these testing modes without changing vendors or breaking their workflow.

Average Rating: 4.8/5.0

Total Reviews: 108

How Do G2 Users Rate Pentest-Tools.com?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.1/10 (Category avg: 9.2/10)
  • Extensibility: 6.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Pentest-Tools.com?

  • Seller: Pentest-Tools.com
  • Year Founded: 2017
  • HQ Location: Sectorul 1, Bucharest
  • Twitter: @pentesttoolscom
    4,062 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    67 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 66% Small, 19% Medium

What Do G2 Reviewers Say About Pentest-Tools.com?

AI-generated summary from verified user reviews

Pros
  • Users commend the ease of use of Pentest-Tools.com, enabling seamless integration for all skill levels in cybersecurity.
  • Users value the pentesting efficiency of Pentest-Tools.com, appreciating its comprehensive and easy-to-use features for vulnerability testing.
  • Users appreciate the automation features of Pentest-Tools.com, streamlining scans and reporting for enhanced security management.
  • Users commend the responsive customer support at Pentest-Tools.com, highlighting their patience and helpfulness.
  • Users appreciate the ease of scheduling scans with Pentest-Tools.com, significantly saving time on vulnerability management.
Cons
  • Users find difficult customization options in Pentest-Tools.com, hindering their ability to tailor reports effectively.
  • Users are frustrated by the limited features, such as lack of report customization and unexpected asset limitations.
  • Users find the slow scanning process frustrating, impacting efficiency and report customization options significantly limit flexibility.
  • Users find the buggy findings require extra manual work, which can be frustrating despite not being critical.
  • Users find the confusing interface hinders navigation, impacting the efficient use of Pentest-Tools.com.

What Are Recent G2 Reviews of Pentest-Tools.com?

What Are G2 Users Discussing About Pentest-Tools.com?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.5/10 (Category avg: 9.2/10)
  • Extensibility: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    90 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Edgescan, highlighting its intuitive interface and straightforward navigation.
  • Users value the automated vulnerability detection features of Edgescan for efficient risk assessment and remediation support.
  • Users value the excellent customer support from Edgescan, noting their responsiveness and proactivity in addressing queries.
  • Users value the detailed vulnerability identification from Edgescan, enabling effective risk management and threat mitigation strategies.
  • Users value Edgescan for its intuitive interface and comprehensive functionality that streamlines security assessments and support.
Cons
  • Users find the complex UI of Edgescan challenging, often requiring guidance to navigate key functions effectively.
  • Users find limited customization options frustrating, particularly with filtering systems and administrative functionalities.
  • Users find the poor interface design of Edgescan challenging, causing navigation and task completion difficulties.
  • Users experience slow performance with Edgescan as manual reviews lead to longer scan completion times.
  • Users find the user interface challenging and unintuitive, leading to difficulties in navigation and task completion.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Sprocket Security

Sprocket Security — Technology-Powered. Human-Verified. Sprocket Security is a technology-powered continuous penetration testing platform that eliminates the blind spots left by annual testing. Traditional pentests give you a point-in-time snapshot and then leave you exposed for the other 345 days of the year — while your infrastructure keeps changing. Sprocket closes that gap by combining automation with US-based human pentesters who validate what actually matters, so your security posture is tested continuously, not once a quarter or once a year. Sprocket runs on the Continuous Lifecycle: Attack Surface Monitoring surfaces what you have exposed, Bleeding-Edge Testing puts expert pentesters against it using the latest attacker techniques, IT Change Detection automatically triggers new testing whenever your environment changes, and Notifications & Support push findings straight into the workflows your team already uses. When something changes, testing happens — no waiting for the next scheduled engagement. What makes Sprocket different -Continuous, not calendar-based. Testing is triggered by change, not by the calendar. No 345-day gaps between engagements. -Human-verified findings, not scanner noise. Automation does the heavy lifting; expert US-based pentesters validate real, exploitable risk so your team gets signal instead of a 200-page PDF to triage. -Continuous, not coin-operated. Unlimited retests are included. When you patch a finding, verify the fix at no additional cost — no per-retest fees, no surprise invoices for scope changes. -From finding to fixed, faster. Findings flow into your existing tools in real time, so remediation starts immediately instead of waiting on a report. -Compliance-ready, always. Generate on-demand reporting for SOC 2, ISO 27001, HIPAA, PCI-DSS, and more — built from live data, not a stale snapshot. Who it's for Sprocket is built for security and IT teams at growing organizations that need offensive security coverage without standing up a full internal red team. CISOs, Directors of Security, IT leaders, and compliance and risk owners rely on Sprocket to continuously validate their defenses, prove control effectiveness to auditors and the board, and stay ahead of an attack surface that never stops changing — with particularly strong fit for financial services, healthcare, SaaS, and other compliance-driven industries. Doing what Gartner now calls Continuous Offensive Security Testing since 2018, Sprocket gives you the coverage of a dedicated adversary and the visibility of an always-on platform — so you find your weaknesses before an attacker does.

Average Rating: 4.8/5.0

Total Reviews: 17

How Do G2 Users Rate Sprocket Security?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.3/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind Sprocket Security?

Who Uses This Product?

  • Company Size: 71% Medium, 12% Large

What Do G2 Reviewers Say About Sprocket Security?

AI-generated summary from verified user reviews

Pros
  • Users commend Sprocket Security for their thorough pentesting efficiency, enhancing security and providing actionable remediation guidance.
  • Users praise the helpful customer support of Sprocket Security for being responsive and easy to communicate with.
  • Users find Sprocket Security's ease of use excellent, facilitated by a user-friendly interface and responsive support.
  • Users praise the expertise of Sprocket Security, noting their top-tier penetration testing and exceptional support for security goals.
  • Users value the effective remediation efficiency of Sprocket Security, enhancing their cybersecurity strategy through actionable insights.
Cons
  • Users experience false positives from Sprocket Security, complicating alert management and causing unnecessary notifications.
  • Users find Sprocket Security to be expensive, with steep renewal costs and inadequate support affecting timely resolutions.
  • Users experience limited support and communication, resulting in prolonged remediation and dissatisfaction with the contract process.
  • Users experience poor customer support with slow response times and inadequate communication following pentests and contract renewals.
  • Users struggle with poor integration, as Sprocket Security doesn't connect with existing security tools, causing alert confusion.

What Are Recent G2 Reviews of Sprocket Security?

SQLmap

Automatic SQL injection and database takeover tool

Average Rating: 4.3/5.0

Total Reviews: 37

How Do G2 Users Rate SQLmap?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.4/10 (Category avg: 9.2/10)
  • Extensibility: 7.8/10 (Category avg: 8.8/10)

Who Is the Company Behind SQLmap?

  • Seller: SQLmap
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Computer & Network Security
  • Company Size: 53% Small, 42% Medium

What Are Recent G2 Reviews of SQLmap?

What Are G2 Users Discussing About SQLmap?

Intigriti

Intigriti is the trusted leader in crowdsourced security, empowering the world’s largest organizations to find and fix vulnerabilities before cybercriminals can exploit them. Since 2016, the company has helped its customers reduce risk with the expertise of 125,000+ global security researchers, enabling real-time vulnerability detection and preventing costly breaches. Intigriti's flexible platform offers a full suite of solutions, including Bug Bounty, PTaaS, Focused Sprints, and Live Hacking Events, tailored to your evolving digital needs and delivered through a pay-for-impact model, meaning you only pay for valid vulnerabilities submitted. Our solutions span: - Bug Bounty - Vulnerability Disclosure Programs (VDP) - Focused Sprints - PTaaS - Live Hacking Events - Reward Services With industry-leading triage, commitment to legal compliance, and exceptional customer service, Intigriti is the go-to choice for organizations like Coca-Cola, Microsoft, and Intel to secure their digital assets and stay ahead in a changing world.

Average Rating: 4.7/5.0

Total Reviews: 32

How Do G2 Users Rate Intigriti?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 6.7/10 (Category avg: 9.2/10)
  • Extensibility: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Intigriti?

  • Seller: Intigriti
  • Year Founded: 2016
  • HQ Location: Antwerpen, BE
  • Twitter: @intigriti
    209,768 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    829 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Human Resources
  • Company Size: 59% Medium, 34% Large

What Are Recent G2 Reviews of Intigriti?

Strobes Security

Strobes is an AI-driven exposure management platform designed to help organizations streamline their security operations by unifying various security methodologies, including Attack Surface Management (ASM), Application Security Posture Management (ASPM), Risk-Based Vulnerability Management (RBVM), and Penetration Testing as a Service (PTaaS). This comprehensive solution provides users with a holistic view of their security posture, enabling them to identify, assess, and respond to potential risks and vulnerabilities effectively. Targeted primarily at security teams and IT professionals, Strobes caters to organizations of all sizes that require a robust approach to managing their security exposure. The platform is particularly beneficial for those who need to navigate the complexities of modern security environments, where multiple tools and processes can lead to fragmented insights. By consolidating various security functions into a single workflow, Strobes empowers users to make informed decisions based on a complete understanding of their risk landscape. One of the key features of Strobes is its extensive integration capabilities, boasting over 120 integrations with existing security tools and systems. This allows organizations to pull findings from disparate sources into a single view, enriching data with contextual information that enhances the relevance of insights. The platform's advanced correlation capabilities help identify relationships between different vulnerabilities and risks, enabling security teams to prioritize their remediation efforts effectively. The user-friendly dashboards in Strobes serve as a central hub for monitoring security activities, encompassing everything from asset discovery and vulnerability insights to Service Level Agreement (SLA) tracking and ticketing. This comprehensive visibility supports continuous prioritization and fix validation, allowing teams to address the most critical issues first. By automating triage processes, Strobes ensures that real risks and exposures are highlighted, facilitating a more efficient response to potential threats. Overall, Strobes stands out in the exposure management landscape by providing a cohesive and intelligent approach to security management. Its ability to unify various methodologies, coupled with powerful automation and integration features, positions it as a valuable tool for organizations seeking to enhance their security posture and effectively manage their exposure to risks.

Average Rating: 4.6/5.0

Total Reviews: 34

How Do G2 Users Rate Strobes Security?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.3/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.8/10 (Category avg: 9.2/10)

Who Is the Company Behind Strobes Security?

  • Seller: Strobes Security Inc
  • Company Website:
  • Year Founded: 2019
  • HQ Location: Plano, US
  • Twitter: @StrobesHQ
    218 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    97 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 37% Large, 37% Medium

What Do G2 Reviewers Say About Strobes Security?

AI-generated summary from verified user reviews

Pros
  • Users commend Strobes Security for its thorough vulnerability identification, providing detailed insights and actionable solutions for fixes.
  • Users commend Strobes Security for its thorough vulnerability detection that enhances security and streamlines management processes.
  • Users highlight the exceptional security identification features of Strobes, improving vulnerability management and operational efficiency.
  • Users commend the proactive support from Strobes Security, ensuring quick resolutions and excellent follow-up on issues.
  • Users commend the ease of use of Strobes Security, highlighting its intuitive interface and efficient workflows.
Cons
  • Users criticize the inadequate reporting in Strobes Security, citing lack of detail and flexibility for effective analysis.
  • Users find limited customization options frustrating, particularly during the initial workflow setup and dashboard clarity improvements.
  • Users report poor usability in Strobes Security due to a steep learning curve and challenging navigation.
  • Users express concerns about the lack of transparency and flexibility in reporting, hindering effective analysis and customization.
  • Users find the UI complex and experience a learning curve, especially when customizing workflows and integrations.

What Are Recent G2 Reviews of Strobes Security?

AI-Native Continuous Offensive Security Platform

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

Average Rating: 4.5/5.0

Total Reviews: 98

How Do G2 Users Rate AI-Native Continuous Offensive Security Platform?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.0/10 (Category avg: 9.2/10)
  • Extensibility: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind AI-Native Continuous Offensive Security Platform?

  • Seller: Ridge Security Technology
  • Company Website:
  • Year Founded: 2020
  • HQ Location: Santa Clara, California
  • Twitter: @RidgeSecurityAI
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    49 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Small, 45% Medium

What Do G2 Reviewers Say About AI-Native Continuous Offensive Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the automation capabilities of RidgeBot, streamlining penetration testing and providing accurate vulnerability assessments efficiently.
  • Users appreciate the ease of use of the AI-Native Continuous Offensive Security Platform for streamlined penetration testing.
  • Users commend the pentesting efficiency of RidgeBot, automating tests and validating vulnerabilities seamlessly to save time.
  • Users appreciate the automated vulnerability identification of RidgeBot, which effectively validates risks and streamlines security processes.
  • Users value the efficiency of RidgeBot, as it automates testing to save time and enhance security processes.
Cons
  • Users find RidgeBot's setup to be complex and challenging, particularly in customized or legacy system environments.
  • Users find the complex setup challenging, especially due to limited documentation and support for new admins.
  • Users find the missing features such as improved API testing and customizable reporting templates quite limiting.
  • Users find the poor customer support challenging, as documentation is often lacking for troubleshooting issues.
  • Users find the poor documentation challenging, making initial setup and onboarding confusing for new admins.

What Are Recent G2 Reviews of AI-Native Continuous Offensive Security Platform?

Evolve Security

Evolve Security's patent pending Darwin Attack® platform is a comprehensive collaboration and management tool designed to help organizations manage their cybersecurity services and reduce risks of successful cyberattacks. The platform serves as a repository for research, vulnerability and attack details, compliance requirements, remediation recommendations, and mitigating controls. It also functions as a security feed, collaboration tool, tracking tool, management platform, and reporting platform. The platform enables organizations to actively manage their security program by providing real-time updates on testing progress and findings, which allows for timely remediation. Darwin Attack® is constantly updated with new information and functionality to ensure that it remains effective and efficient in meeting the needs of Evolve Security's clients.

Average Rating: 4.8/5.0

Total Reviews: 53

How Do G2 Users Rate Evolve Security?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.4/10 (Category avg: 9.2/10)
  • Extensibility: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Evolve Security?

  • Seller: Evolve Security
  • Year Founded: 2016
  • HQ Location: Chicago, Illinois
  • Twitter: @theevolvesec
    788 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    63 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services
  • Company Size: 70% Medium, 21% Small

What Do G2 Reviewers Say About Evolve Security?

AI-generated summary from verified user reviews

Pros
  • Users value the actionable intelligence provided by Evolve Security, enhancing their understanding and response to vulnerabilities.
  • Users commend the effective communication from Evolve Security, facilitating real-time clarity during penetration testing.
  • Users appreciate the ease of use of Evolve Security, enjoying a friendly interface and efficient onboarding process.
  • Users value the thorough vulnerability detection that includes actionable insights and excellent communication from the team.
  • Users commend the vulnerability identification and correction process, appreciating clear communication and detailed debriefs.

What Are Recent G2 Reviews of Evolve Security?

Acunetix by Invicti

Acunetix (by Invicti) is an automated application security testing tool that enables small security teams to tackle huge application security challenges. With fast scanning, comprehensive results, and intelligent automation, Acunetix helps organizations to reduce risk across all types of web applications, websites, and APIs. With Acunetix, security teams can: - Save time and resources by automating manual security processes - Work more seamlessly with developers, or embrace DevSecOps by integrating directly into development tools - Feel confident that every web application has been crawled entirely thanks to DAST + IAST scanning and intelligent crawling technology - Finally, make web application and API security a priority and not just an add-on with a solution that is dedicated to application and API security 100% of the time You can depend on Acunetix to meet your organization’s needs today and face the challenges of modern web technology together tomorrow.

Average Rating: 4.1/5.0

Total Reviews: 100

How Do G2 Users Rate Acunetix by Invicti?

  • Has the product been a good partner in doing business?: 8.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.6/10 (Category avg: 9.2/10)
  • Extensibility: 7.4/10 (Category avg: 8.8/10)

Who Is the Company Behind Acunetix by Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 40% Large, 34% Medium

What Do G2 Reviewers Say About Acunetix by Invicti?

AI-generated summary from verified user reviews

Pros
  • Users value the accurate and fast vulnerability detection of Acunetix, enhancing their security scanning capabilities efficiently.
  • Users praise the ease of use of Acunetix, highlighting its simple integration and effective security scanning capabilities.
  • Users value the robust security features of Acunetix, enhancing the safety of web applications effectively.
  • Users value the effective vulnerability identification by Acunetix, enhancing web application security and streamlining remediation processes.
  • Users highlight the accuracy of results from Acunetix, noting its impressive ability to identify vulnerabilities effectively.
Cons
  • Users find Acunetix by Invicti to be expensive, making it less accessible for smaller teams or projects.
  • Users find Acunetix's complex setup and resource intensity challenging, especially for large applications and first-time configurations.
  • Users find the setup process complex, particularly for new users and large application configurations.
  • Users note that the scanning process is often slow, affecting efficiency and delaying normal workflows, especially with large applications.
  • Users find the difficult customization of Acunetix challenging, requiring technical expertise to set up and fine-tune integrations.

What Are Recent G2 Reviews of Acunetix by Invicti?

What Are G2 Users Discussing About Acunetix by Invicti?

Cyver Core

Cyver Core is a pentest collaboration and management platform to digitize, automate, and optimize manual work for pentest firms, while enabling Pentest-as-a-Service delivery. Cyver Core offers pentest report automation, branded client portals, pentest management, team management, and more.

Average Rating: 4.7/5.0

Total Reviews: 20

How Do G2 Users Rate Cyver Core?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 7.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.3/10 (Category avg: 9.2/10)
  • Extensibility: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind Cyver Core?

  • Seller: Cyver
  • Year Founded: 2020
  • HQ Location: Amsterdam, NL
  • Twitter: @cyver_io
    42 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    10 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 75% Small, 20% Medium

What Do G2 Reviewers Say About Cyver Core?

AI-generated summary from verified user reviews

Pros
  • Users value the pentesting efficiency of Cyver Core, significantly reducing reporting time and enhancing team management.
  • Users value the high reporting quality of Cyver Core, enhancing efficiency and improving client communication in vulnerability management.
  • Users appreciate the seamless and fast communication in Cyver Core, enhancing the overall user experience significantly.
  • Users praise the fast and helpful customer support of Cyver Core, enhancing collaboration and user satisfaction.
  • Users value the exceptional cybersecurity features of Cyver Core, enhancing team collaboration and improving customer experience significantly.
Cons
  • Users find limited customization in Cyver Core, restricting adaptability for specific roles and templates.
  • Users report technical issues with Cyver Core, including stability problems and occasional slow performance affecting usability.
  • Users experience poor documentation, as the UI/UX lacks intuitiveness, leading to confusion and inefficiency.
  • Users find the poor interface design of Cyver Core frustrating due to non-intuitive elements and occasional bugs.
  • Users report occasional slow performance on Cyver Core, which can interrupt their experience and productivity.

What Are Recent G2 Reviews of Cyver Core?

What Are G2 Users Discussing About Cyver Core?

Invicti

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

Average Rating: 4.5/5.0

Total Reviews: 69

How Do G2 Users Rate Invicti?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.7/10 (Category avg: 9.2/10)
  • Extensibility: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Large, 29% Medium

What Do G2 Reviewers Say About Invicti?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Invicti, facilitating quick setup and effective vulnerability scanning in their workflow.
  • Users value the quick and easy scanning technology of Invicti, enhancing workflow efficiency and accuracy in vulnerability detection.
  • Users value the simplicity and integration of Invicti, enhancing security measures through user-friendly report generation and detailed views.
  • Users value the easy-to-read and well-formatted reports from Invicti, enhancing efficiency and supporting ISO certification needs.
  • Users value the high accuracy and ease of use in Invicti's vulnerability detection, effectively identifying true issues.
Cons
  • Users find the customer support lacking, often experiencing slow responses and inadequate technical assistance.
  • Users experience slow performance during scans and setups, impacting overall efficiency and satisfaction.
  • Users experience slow scanning issues with Invicti, often leading to frustrating delays during the scanning process.
  • Users face API scanning issues with Invicti, limiting its effectiveness for their specific needs despite decent support.
  • Users find the complex setup of Invicti challenging initially, hindering their ability to quickly navigate configurations.

What Are Recent G2 Reviews of Invicti?

What Are G2 Users Discussing About Invicti?

Titania Nipper InfraSight

Award-winning Risk-Based Vulnerability Management. Nipper InfraSight analyzes network device configurations in the way Advances Persistent Threat (APT) groups do, to identify misconfigurations that could create attack paths. This analysis offers unparalleled, pen-tester accuracy, finding critical vulnerabilities in firewalls, routers, switches that other tools simply cannot see. Our solutions then prioritize the biggest risks to your business and provide device-specific remediation guidance, right down to specific command line prompts.  By analyzing device configurations against key compliance standards and security frameworks (including STIGs/CIS Benchmarks/PCI DSS/CMMC/CORA/NIST SP 800-53), Nipper solutions tell you precisely which devices are at risk of failing, how significant that risk is, and how you can solve it, with auditor-ready reports. Whether your focus is taking pragmatic, risk-based security measures to minimize known vulnerabilities or ensuring compliance with industry security standards, Nipper solutions provide the targeted insights you need. No other security provider looks at the network in the same way. That’s why Nipper can uniquely provide the network configuration coverage that organizations urgently require. 30+ U.S. federal agencies and 800+ organizations globally trust Nipper solutions to deliver vulnerability analysis and compliance automation while supporting air-gapped environments, sovereign cloud requirements, and complex regulated infrastructures.

Average Rating: 4.2/5.0

Total Reviews: 30

How Do G2 Users Rate Titania Nipper InfraSight?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.2/10)
  • Extensibility: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Titania Nipper InfraSight?

  • Seller: Titania
  • Company Website:
  • Year Founded: 2009
  • HQ Location: London, GB
  • Twitter: @TitaniaLtd
    2,821 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    104 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Large, 27% Medium

What Do G2 Reviewers Say About Titania Nipper InfraSight?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Titania Nipper InfraSight exceptional, ensuring a smooth and straightforward experience.
  • Users value the high-quality reporting of Titania Nipper, which delivers insightful recommendations and clear misconfiguration assessments.
  • Users value the scanning efficiency of Titania Nipper InfraSight, enabling quick detection of network misconfigurations.
  • Users enjoy the effective vulnerability detection of Titania Nipper, offering actionable insights and structured assessments for network configuration.
  • Users appreciate the clear and user-friendly interface of Titania Nipper InfraSight, enhancing their experience and efficiency.
Cons
  • Users express concerns about licensing issues, particularly the minimum device requirement and the ongoing license model.
  • Users experience false positives in Titania Nipper InfraSight, causing confusion and affecting trust in its findings.
  • Users find the lack of cloud support limiting, especially with specific devices like wireless controllers and security groups.
  • Users face limited compatibility with devices, necessitating older versions and complicating integration with cloud services.
  • Users face challenges with limited device support, leading to complications with version maintenance and security auditing.

What Are Recent G2 Reviews of Titania Nipper InfraSight?

What Are G2 Users Discussing About Titania Nipper InfraSight?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated March 5, 2025