Best Penetration Testing Tools - Page 2

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 136

Category Stats (Aug 2026)

  • Average Rating: 4.64/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Cyver Core (+1.26%) - Among all products in this category, Cyver Core recorded the largest rating increase compared to last month

Last updated: August 05, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,600+ Authentic Reviews
  • 136+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: Cobalt, vPenTest, Astra Pentest, Oneleet, NodeZero from Horizon3.ai, Bugcrowd, Verizon Penetration Testing, and H1 Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=vpentest&focus%5B%5D=astra-pentest&focus%5B%5D=oneleet&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=bugcrowd&focus%5B%5D=verizon-penetration-testing&focus%5B%5D=h1-platform)

Sponsored

Sprocket Security

By combining automation with expert-driven human testing, Sprocket Security delivers Continuous Penetration Testing to help businesses continuously validate their security posture and resilience. This innovative solution is tailored for organizations seeking to enhance their cybersecurity measures by proactively identifying vulnerabilities and assessing their defenses against potential threats. By employing a year-round testing methodology, Sprocket Security ensures that businesses remain vigilant and prepared in the ever-evolving landscape of cyber threats. The platform primarily targets organizations of all sizes that are committed to improving their security frameworks. Sprocket Security is particularly beneficial for IT and security teams that need to stay ahead of emerging attack techniques and adapt to changes in their IT structures. With features such as Attack Surface Management, Continuous Penetration Testing, and Adversary Simulation, Sprocket Security provides a comprehensive suite of tools that empower businesses to prioritize offensive security measures effectively. One of the key features of Sprocket Security is its Attack Surface Management, which allows organizations to gain visibility into their digital assets and potential vulnerabilities. By continuously monitoring and analyzing the attack surface, businesses can identify weak points before they are exploited by malicious actors. Additionally, the platform offers Continuous Penetration Testing, which simulates real-world attack scenarios to evaluate the effectiveness of existing security controls. This ongoing testing approach ensures that organizations can adapt their defenses in response to new threats and vulnerabilities. Another significant aspect of Sprocket Security is its commitment to retesting. Whenever a new attack technique emerges, a change occurs in the IT infrastructure, or a finding is patched, Sprocket Security provides unlimited retests at no additional cost. This feature not only enhances the overall security posture of an organization but also fosters a culture of continuous improvement and vigilance. By prioritizing offensive security, businesses can reduce their IT risk and enhance their resilience against cyber threats. Overall, Sprocket Security stands out in the cybersecurity landscape by offering a robust and flexible solution that integrates both automated and human-driven testing methodologies. This unique combination allows organizations to maintain a proactive stance against cyber threats, ensuring that their security measures evolve in tandem with the dynamic nature of the digital landscape.

Visit website

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 255

How Do G2 Users Rate Aikido Security?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    241 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 80% Small, 13% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
  • Users praise Aikido Security for its fast and user-friendly identification of security issues in codebases, enhancing development practices.
  • Users appreciate the robust features of Aikido Security, valuing its usability and effectiveness in enhancing security workflows.
  • Users value the easy integrations with GitLab, allowing for quick start and effective tracking of security issues.
  • Users commend the easy setup of Aikido Security, simplifying integration and enhancing their security workflow significantly.
Cons
  • Users note the missing features in Aikido Security, wishing for more integration and advanced configuration options.
  • Users find the pricing excessive, particularly for startups, despite acknowledging the product's value.
  • Users find Aikido Security has limited features, particularly in advanced customization and reporting for complex environments.
  • Users find the entry-level pricing of Aikido Security too high for startups, limiting adoption and experimentation.
  • Users are frustrated by the lack of features, especially with local scanning and branch handling limitations.

What Are Recent G2 Reviews of Aikido Security?

Metasploit

Metasploit is a comprehensive penetration testing platform developed by Rapid7, designed to help security professionals identify, exploit, and validate vulnerabilities within their networks. By simulating real-world attacks, Metasploit enables organizations to assess their security posture and enhance their defenses against potential threats. Key Features and Functionality: - Extensive Exploit Library: Access to a vast, regularly updated database of over 1,500 exploits and 3,300 modules, allowing users to simulate a wide range of attack scenarios. - Automated Exploitation: Features like Smart Exploitation and automated credential brute-forcing streamline the penetration testing process, increasing efficiency and accuracy. - Post-Exploitation Modules: Over 330 post-exploitation modules enable testers to assess the impact of a successful breach and gather critical information from compromised systems. - Credential Testing: Ability to run brute-force attacks against more than 20 account types, including databases, web servers, and remote administration tools, to uncover weak or reused passwords. - Integration Capabilities: Seamless integration with other Rapid7 products, such as InsightVM and Nexpose, facilitates closed-loop vulnerability validation and remediation prioritization. Primary Value and Problem Solving: Metasploit empowers organizations to proactively identify and address security weaknesses before malicious actors can exploit them. By simulating real-world attacks, it provides valuable insights into potential vulnerabilities, enabling security teams to prioritize remediation efforts effectively. This proactive approach enhances overall security awareness, reduces the risk of breaches, and ensures compliance with industry standards and regulations.

Average Rating: 4.6/5.0

Total Reviews: 53

How Do G2 Users Rate Metasploit?

  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.4/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.7/10 (Category avg: 9.1/10)
  • Extensibility: 8.1/10 (Category avg: 8.7/10)

Who Is the Company Behind Metasploit?

  • Seller: Rapid7
  • Year Founded: 2000
  • HQ Location: Boston, MA
  • Twitter: @rapid7
    124,405 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,274 employees on LinkedIn®
  • Ownership: NASDAQ:RPD

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 47% Small, 40% Medium

What Do G2 Reviewers Say About Metasploit?

AI-generated summary from verified user reviews

Pros
  • Users laud the pentesting efficiency of Metasploit, appreciating its extensive toolkit for creating diverse payloads.
  • Users value the expertise provided by Metasploit for creating diverse payloads and exploiting systems effectively.
Cons
  • Users find the complex setup of Metasploit frustrating, wishing for more automation to simplify installation.

What Are Recent G2 Reviews of Metasploit?

What Are G2 Users Discussing About Metasploit?

Indusface WAS

Indusface WAS (Web Application Scanner) provides comprehensive managed dynamic application security testing (DAST) solution. It is a zero-touch, non-intrusive cloud-based solution that provides daily monitoring for web applications, checking for systems and application vulnerabilities, and malware. Indusface WAS with its automated scans & manual pentesting done by certified security experts ensures none of the OWASP Top10, business logic vulnerabilities, and malware go unnoticed. With zero false-positive guarantee and comprehensive reporting with remediation guidance, Indusface web app scanning ensures developers to quickly fix vulnerabilities seamlessly.

Average Rating: 4.6/5.0

Total Reviews: 64

How Do G2 Users Rate Indusface WAS?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.3/10 (Category avg: 9.1/10)
  • Extensibility: 8.7/10 (Category avg: 8.7/10)

Who Is the Company Behind Indusface WAS?

  • Seller: Indusface
  • Year Founded: 2012
  • HQ Location: Vadodara
  • Twitter: @Indusface
    3,472 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    180 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Small, 37% Medium

What Do G2 Reviewers Say About Indusface WAS?

AI-generated summary from verified user reviews

Pros
  • Users value the effective vulnerability detection of Indusface WAS, ensuring rapid prioritization and reliable remediation support.
  • Users value the consistent and reliable vulnerability detection of Indusface WAS, ensuring secure deployments with ease.
  • Users commend the excellent customer support of Indusface WAS, ensuring timely responses and effective issue resolution.
  • Users value the scanning efficiency of Indusface WAS for detailed vulnerability reports and timely updates after deployments.
  • Users value the thorough security scans from Indusface WAS, enhancing their vulnerability identification and accreditation processes.
Cons
  • Users feel that the pricing for Indusface WAS is expensive, especially regarding staging and development environment scans.
  • Users find the confusing interface of Indusface WAS somewhat dated and in need of improvements for better usability.
  • Users find the lack of features for staging and development environments limits their testing in Indusface WAS.
  • Users find the limited scope of pricing for staging environments restricts functionality and increases testing challenges.
  • Users find the interface design outdated and unintuitive, often wishing for a more user-friendly experience.

What Are Recent G2 Reviews of Indusface WAS?

What Are G2 Users Discussing About Indusface WAS?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.5/10 (Category avg: 9.1/10)
  • Extensibility: 9.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    91 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate Edgescan's ease of use, enjoying its intuitive interface and streamlined navigation for effective vulnerability management.
  • Users value the automated vulnerability detection with intuitive reports, timely alerts, and effective risk management features.
  • Users value the excellent customer support from Edgescan, praising the team's responsiveness and proactive assistance.
  • Users value the thorough vulnerability identification features of Edgescan, enhancing risk management and resolution efficiency.
  • Users value the robust features of Edgescan, which streamline security assessments and enhance ease of use.
Cons
  • Users find the complex UI challenging initially, with navigation issues and a need for improved dashboard functionality.
  • Users highlight limited customization options in Edgescan, particularly regarding filtering and admin functionalities.
  • Users find the poor interface design of Edgescan challenging, affecting usability and data accessibility.
  • Users report experiencing slow performance as scans can take longer due to manual review processes.
  • Users find the UI not user friendly, lacking intuitiveness and advanced features for better navigation and data accessibility.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Pentest-Tools.com

Discover what's possible. Prove what's real. With proprietary tech and key experts in offensive security. Pentest-Tools.com is built for actual security testing, not just detection. We provide the coverage, consolidation, and automation cybersecurity teams need to optimize vulnerability assessment workflows. And we ensure the depth, control, and customization on which professional pentesters count to increase engagement quality and profitability. ✔️ Comprehensive toolkit with real-world coverage ✔️ Validated findings rich with evidence ✔️ Automation options with granular control ✔️ Flexible, high-quality reporting ✔️ Workflow-friendly by design Optimize and scale penetration testing and vulnerability assessment workflows - without sacrificing accuracy, control, or manual testing depth. 🎯 Attack surface mapping and recon 🎯 Comprehensive vulnerability scanning 🎯 Vulnerability exploitation 🎯 Customizable pentest reporting and data exports 🎯 Continuous vulnerability monitoring In our company, we build what we use We launched Pentest-Tools.com in 2017 as a team of professional penetration testers - and we've kept that mindset ever since. Our experts still drive product development today, focusing relentlessly on accuracy, speed, and control. Every new feature, detection, and workflow comes from real-world experience. We constantly improve the product with updated attack techniques, smarter automation, and validation that reflects how malicious hackers actually operate - so your team can deliver security work that's faster, more visible, and built on proof.

Average Rating: 4.8/5.0

Total Reviews: 108

How Do G2 Users Rate Pentest-Tools.com?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.1/10 (Category avg: 9.1/10)
  • Extensibility: 6.9/10 (Category avg: 8.7/10)

Who Is the Company Behind Pentest-Tools.com?

  • Seller: Pentest-Tools.com
  • Year Founded: 2017
  • HQ Location: Sectorul 1, Bucharest
  • Twitter: @pentesttoolscom
    4,062 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    68 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 66% Small, 19% Medium

What Do G2 Reviewers Say About Pentest-Tools.com?

AI-generated summary from verified user reviews

Pros
  • Users highly value the ease of use of Pentest-Tools.com, appreciating its intuitive interface and straightforward functionality.
  • Users find the automation features of Pentest-Tools.com invaluable for efficient scanning and simplified vulnerability management.
  • Users appreciate the quick and helpful customer support of Pentest-Tools.com, enhancing their overall experience significantly.
  • Users value the efficiency and ease of use of Pentest-Tools.com for effective vulnerability assessments and reporting.
  • Users highlight the efficient scheduling features of Pentest-Tools.com, significantly saving time in vulnerability management tasks.
Cons
  • Users find difficult customization in Pentest-Tools.com limits personalization options and impacts report flexibility.
  • Users find the limited report customization and unexpected changes frustrating, impacting their efficiency with Pentest-Tools.com.
  • Users find the slow scanning of Pentest-Tools.com a hassle, impacting efficiency during testing processes.
  • Users find the bugs in findings require extra manual work, which can be annoying, especially for small teams.
  • Users find the interface confusing, making navigation between tools and scans less intuitive and frustrating.

What Are Recent G2 Reviews of Pentest-Tools.com?

What Are G2 Users Discussing About Pentest-Tools.com?

SQLmap

Automatic SQL injection and database takeover tool

Average Rating: 4.3/5.0

Total Reviews: 37

How Do G2 Users Rate SQLmap?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.4/10 (Category avg: 9.1/10)
  • Extensibility: 7.8/10 (Category avg: 8.7/10)

Who Is the Company Behind SQLmap?

  • Seller: SQLmap
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Computer & Network Security
  • Company Size: 53% Small, 42% Medium

What Are Recent G2 Reviews of SQLmap?

What Are G2 Users Discussing About SQLmap?

Sprocket Security

By combining automation with expert-driven human testing, Sprocket Security delivers Continuous Penetration Testing to help businesses continuously validate their security posture and resilience. This innovative solution is tailored for organizations seeking to enhance their cybersecurity measures by proactively identifying vulnerabilities and assessing their defenses against potential threats. By employing a year-round testing methodology, Sprocket Security ensures that businesses remain vigilant and prepared in the ever-evolving landscape of cyber threats. The platform primarily targets organizations of all sizes that are committed to improving their security frameworks. Sprocket Security is particularly beneficial for IT and security teams that need to stay ahead of emerging attack techniques and adapt to changes in their IT structures. With features such as Attack Surface Management, Continuous Penetration Testing, and Adversary Simulation, Sprocket Security provides a comprehensive suite of tools that empower businesses to prioritize offensive security measures effectively. One of the key features of Sprocket Security is its Attack Surface Management, which allows organizations to gain visibility into their digital assets and potential vulnerabilities. By continuously monitoring and analyzing the attack surface, businesses can identify weak points before they are exploited by malicious actors. Additionally, the platform offers Continuous Penetration Testing, which simulates real-world attack scenarios to evaluate the effectiveness of existing security controls. This ongoing testing approach ensures that organizations can adapt their defenses in response to new threats and vulnerabilities. Another significant aspect of Sprocket Security is its commitment to retesting. Whenever a new attack technique emerges, a change occurs in the IT infrastructure, or a finding is patched, Sprocket Security provides unlimited retests at no additional cost. This feature not only enhances the overall security posture of an organization but also fosters a culture of continuous improvement and vigilance. By prioritizing offensive security, businesses can reduce their IT risk and enhance their resilience against cyber threats. Overall, Sprocket Security stands out in the cybersecurity landscape by offering a robust and flexible solution that integrates both automated and human-driven testing methodologies. This unique combination allows organizations to maintain a proactive stance against cyber threats, ensuring that their security measures evolve in tandem with the dynamic nature of the digital landscape.

Average Rating: 4.8/5.0

Total Reviews: 15

How Do G2 Users Rate Sprocket Security?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.3/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.1/10)
  • Extensibility: 8.6/10 (Category avg: 8.7/10)

Who Is the Company Behind Sprocket Security?

Who Uses This Product?

  • Company Size: 67% Medium, 13% Large

What Do G2 Reviewers Say About Sprocket Security?

AI-generated summary from verified user reviews

Pros
  • Users value the thorough and real-world penetration testing from Sprocket Security, enhancing their overall security posture.
  • Users praise the helpful customer support of Sprocket Security, making issue resolution quick and efficient.
  • Users find Sprocket Security's ease of use beneficial with a clean interface and responsive support enhancing the experience.
  • Users praise Sprocket Security for their top-tier expertise in cybersecurity, enhancing overall security effectiveness and support.
  • Users highlight the remediation efficiency of Sprocket Security, benefiting from clear, actionable guidance to quickly address vulnerabilities.
Cons
  • Users experience false positives with Sprocket Security, leading to alarm fatigue from alerts about non-malicious activity.
  • Users find Sprocket Security expensive, experiencing high renewal rates and slow support response times, causing frustration.
  • Users highlight the limited support scope of Sprocket Security, causing delays and unresolved issues post-pentest.
  • Users experience poor customer support, suffering from slow response times and ineffective communication during critical remediation processes.
  • Users find the poor integration of Sprocket Security problematic, leading to issues like false positives in alerting tools.

What Are Recent G2 Reviews of Sprocket Security?

RidgeBot

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

Average Rating: 4.5/5.0

Total Reviews: 98

How Do G2 Users Rate RidgeBot?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.2/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.0/10 (Category avg: 9.1/10)
  • Extensibility: 8.6/10 (Category avg: 8.7/10)

Who Is the Company Behind RidgeBot?

  • Seller: Ridge Security Technology
  • Company Website:
  • Year Founded: 2020
  • HQ Location: Santa Clara, California
  • Twitter: @RidgeSecurityAI
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    47 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Small, 45% Medium

What Do G2 Reviewers Say About RidgeBot?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of RidgeBot, enabling quick setup and straightforward penetration testing automation.
  • Users value the automation capabilities of RidgeBot, significantly enhancing efficiency in penetration testing and vulnerability validation.
  • Users value the high efficiency of RidgeBot's pentesting, enabling quick, automated vulnerability validation and seamless integration.
  • Users commend RidgeBot for its effective vulnerability identification, providing reliable, automated testing and integration for security efficiency.
  • Users praise RidgeBot for its efficiency in automating vulnerability testing and streamlining security processes seamlessly.
Cons
  • Users find the complex setup of RidgeBot challenging, particularly for new admins requiring better documentation and support.
  • Users find RidgeBot's setup overly complex, particularly when working with customized or legacy systems.
  • Users find the missing features in RidgeBot, such as limited reporting and API testing, hinder optimal usage.
  • Users find poor customer support frustrating, often lacking resources for resolving issues independently.
  • Users find the poor documentation of RidgeBot challenging, especially for new admins during setup and onboarding.

What Are Recent G2 Reviews of RidgeBot?

Strobes Security

Strobes is an AI-driven exposure management platform designed to help organizations streamline their security operations by unifying various security methodologies, including Attack Surface Management (ASM), Application Security Posture Management (ASPM), Risk-Based Vulnerability Management (RBVM), and Penetration Testing as a Service (PTaaS). This comprehensive solution provides users with a holistic view of their security posture, enabling them to identify, assess, and respond to potential risks and vulnerabilities effectively. Targeted primarily at security teams and IT professionals, Strobes caters to organizations of all sizes that require a robust approach to managing their security exposure. The platform is particularly beneficial for those who need to navigate the complexities of modern security environments, where multiple tools and processes can lead to fragmented insights. By consolidating various security functions into a single workflow, Strobes empowers users to make informed decisions based on a complete understanding of their risk landscape. One of the key features of Strobes is its extensive integration capabilities, boasting over 120 integrations with existing security tools and systems. This allows organizations to pull findings from disparate sources into a single view, enriching data with contextual information that enhances the relevance of insights. The platform's advanced correlation capabilities help identify relationships between different vulnerabilities and risks, enabling security teams to prioritize their remediation efforts effectively. The user-friendly dashboards in Strobes serve as a central hub for monitoring security activities, encompassing everything from asset discovery and vulnerability insights to Service Level Agreement (SLA) tracking and ticketing. This comprehensive visibility supports continuous prioritization and fix validation, allowing teams to address the most critical issues first. By automating triage processes, Strobes ensures that real risks and exposures are highlighted, facilitating a more efficient response to potential threats. Overall, Strobes stands out in the exposure management landscape by providing a cohesive and intelligent approach to security management. Its ability to unify various methodologies, coupled with powerful automation and integration features, positions it as a valuable tool for organizations seeking to enhance their security posture and effectively manage their exposure to risks.

Average Rating: 4.6/5.0

Total Reviews: 34

How Do G2 Users Rate Strobes Security?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.3/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.8/10 (Category avg: 9.1/10)

Who Is the Company Behind Strobes Security?

  • Seller: Strobes Security Inc
  • Company Website:
  • Year Founded: 2019
  • HQ Location: Plano, US
  • Twitter: @StrobesHQ
    218 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    97 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 37% Large, 37% Medium

What Do G2 Reviewers Say About Strobes Security?

AI-generated summary from verified user reviews

Pros
  • Users value the thorough vulnerability identification by Strobes, appreciating detailed insights and actionable remediation suggestions.
  • Users commend Strobes Security for its robust vulnerability detection, providing precise fixes that enhance security efficiency.
  • Users value the comprehensive security insights provided by Strobes, enhancing vulnerability management and productivity significantly.
  • Users value the proactive customer support of Strobes Security, noting quick responses and detailed follow-ups for issues.
  • Users find Strobes Security's ease of use refreshing, with a clean interface streamlining vulnerability management effectively.
Cons
  • Users criticize the inadequate reporting of Strobes Security, highlighting the need for improved transparency and customization options.
  • Users find the limited customization options of Strobes Security challenging, affecting initial setup and usability.
  • Users find Strobes Security's poor usability frustrating, noting a steep learning curve and difficulty in navigating features.
  • Users find the reporting issues in Strobes Security frustrating, lacking transparency and flexibility for effective data management.
  • Users find the UI complex, noting a learning curve for customization and slow loading for advanced features.

What Are Recent G2 Reviews of Strobes Security?

Evolve Security

Evolve Security's patent pending Darwin Attack® platform is a comprehensive collaboration and management tool designed to help organizations manage their cybersecurity services and reduce risks of successful cyberattacks. The platform serves as a repository for research, vulnerability and attack details, compliance requirements, remediation recommendations, and mitigating controls. It also functions as a security feed, collaboration tool, tracking tool, management platform, and reporting platform. The platform enables organizations to actively manage their security program by providing real-time updates on testing progress and findings, which allows for timely remediation. Darwin Attack® is constantly updated with new information and functionality to ensure that it remains effective and efficient in meeting the needs of Evolve Security's clients.

Average Rating: 4.8/5.0

Total Reviews: 53

How Do G2 Users Rate Evolve Security?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.4/10 (Category avg: 9.1/10)
  • Extensibility: 8.8/10 (Category avg: 8.7/10)

Who Is the Company Behind Evolve Security?

  • Seller: Evolve Security
  • Year Founded: 2016
  • HQ Location: Chicago, Illinois
  • Twitter: @theevolvesec
    788 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    65 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services
  • Company Size: 70% Medium, 21% Small

What Do G2 Reviewers Say About Evolve Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the actionable intelligence provided by Evolve Security, enhancing their ability to address vulnerabilities effectively.
  • Users value the effective vulnerability detection and guidance provided by Evolve Security's expert team.
  • Users commend Evolve Security's effective vulnerability identification, providing clear instructions and communication throughout the process.
  • Users value the thorough audit support provided, ensuring clear communication and effective remediation of vulnerabilities.
  • Users commend the excellent communication from Evolve Security, facilitating clear understanding and collaboration during pentesting.

What Are Recent G2 Reviews of Evolve Security?

Intigriti

Intigriti is the trusted leader in crowdsourced security, empowering the world’s largest organizations to find and fix vulnerabilities before cybercriminals can exploit them. Since 2016, the company has helped its customers reduce risk with the expertise of 125,000+ global security researchers, enabling real-time vulnerability detection and preventing costly breaches. Intigriti's flexible platform offers a full suite of solutions, including Bug Bounty, PTaaS, Focused Sprints, and Live Hacking Events, tailored to your evolving digital needs and delivered through a pay-for-impact model, meaning you only pay for valid vulnerabilities submitted. Our solutions span: - Bug Bounty - Vulnerability Disclosure Programs (VDP) - Focused Sprints - PTaaS - Live Hacking Events - Reward Services With industry-leading triage, commitment to legal compliance, and exceptional customer service, Intigriti is the go-to choice for organizations like Coca-Cola, Microsoft, and Intel to secure their digital assets and stay ahead in a changing world.

Average Rating: 4.7/5.0

Total Reviews: 32

How Do G2 Users Rate Intigriti?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 6.7/10 (Category avg: 9.1/10)
  • Extensibility: 8.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Intigriti?

  • Seller: Intigriti
  • Year Founded: 2016
  • HQ Location: Antwerpen, BE
  • Twitter: @intigriti
    209,768 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    762 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Human Resources
  • Company Size: 59% Medium, 34% Large

What Are Recent G2 Reviews of Intigriti?

Cyver Core

Cyver Core is a pentest collaboration and management platform to digitize, automate, and optimize manual work for pentest firms, while enabling Pentest-as-a-Service delivery. Cyver Core offers pentest report automation, branded client portals, pentest management, team management, and more.

Average Rating: 4.7/5.0

Total Reviews: 19

How Do G2 Users Rate Cyver Core?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 7.9/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.3/10 (Category avg: 9.1/10)
  • Extensibility: 8.6/10 (Category avg: 8.7/10)

Who Is the Company Behind Cyver Core?

  • Seller: Cyver
  • Year Founded: 2020
  • HQ Location: Amsterdam, NL
  • Twitter: @cyver_io
    42 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    10 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 74% Small, 21% Medium

What Do G2 Reviewers Say About Cyver Core?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced pentesting efficiency of Cyver Core, enabling streamlined workflows and reduced manual effort significantly.
  • Users commend the reporting quality of Cyver Core, highlighting its efficiency in communication and streamlined workflows.
  • Users appreciate the seamless communication in Cyver Core, enhancing workflow and client interactions significantly.
  • Users praise the fast and helpful customer support of Cyver Core, enhancing their overall experience and collaboration.
  • Users value the exceptional cybersecurity features of Cyver Core, enhancing pentesting efficiency and customer experience.
Cons
  • Users experience limited customization options in Cyver Core, restricting their ability to tailor features to specific needs.
  • Users occasionally face technical issues and stability concerns, impacting the overall performance of Cyver Core.
  • Users find the poor documentation leads to confusion, despite the team's efforts to address bugs promptly.
  • Users report a poor interface design in Cyver Core, with non-intuitive elements affecting user experience.
  • Users report experiencing slow performance at times on Cyver Core, impacting overall usability and efficiency.

What Are Recent G2 Reviews of Cyver Core?

What Are G2 Users Discussing About Cyver Core?

Acunetix by Invicti

Acunetix (by Invicti) is an automated application security testing tool that enables small security teams to tackle huge application security challenges. With fast scanning, comprehensive results, and intelligent automation, Acunetix helps organizations to reduce risk across all types of web applications, websites, and APIs. With Acunetix, security teams can: - Save time and resources by automating manual security processes - Work more seamlessly with developers, or embrace DevSecOps by integrating directly into development tools - Feel confident that every web application has been crawled entirely thanks to DAST + IAST scanning and intelligent crawling technology - Finally, make web application and API security a priority and not just an add-on with a solution that is dedicated to application and API security 100% of the time You can depend on Acunetix to meet your organization’s needs today and face the challenges of modern web technology together tomorrow.

Average Rating: 4.1/5.0

Total Reviews: 100

How Do G2 Users Rate Acunetix by Invicti?

  • Has the product been a good partner in doing business?: 8.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.6/10 (Category avg: 9.1/10)
  • Extensibility: 7.4/10 (Category avg: 8.7/10)

Who Is the Company Behind Acunetix by Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    335 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 40% Large, 34% Medium

What Do G2 Reviewers Say About Acunetix by Invicti?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the accurate and fast vulnerability detection of Acunetix, enhancing security with minimal false positives.
  • Users value the ease of use of Acunetix, making vulnerability scanning and integration into workflows seamless.
  • Users value Acunetix for its robust security capabilities, effectively enhancing web application safety with automatic vulnerability detection.
  • Users commend the accurate vulnerability identification of Acunetix, enhancing web application security and ease of use.
  • Users commend the accuracy of results from Acunetix, enhancing web application security with reliable vulnerability detection.
Cons
  • Users find Acunetix to be expensive, especially challenging for smaller teams or projects with limited budgets.
  • Users find the complexity in setup and resource consumption of Acunetix challenging, especially for large applications.
  • Users find the complex setup of Acunetix challenging, especially for initial configurations and tool integrations.
  • Users find the slow scanning process frustrating, especially during extensive audits of large web applications.
  • Users find difficult customization to be a challenge, requiring technical expertise and patience for effective integration and setup.

What Are Recent G2 Reviews of Acunetix by Invicti?

What Are G2 Users Discussing About Acunetix by Invicti?

Invicti (formerly Netsparker)

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

Average Rating: 4.5/5.0

Total Reviews: 69

How Do G2 Users Rate Invicti (formerly Netsparker)?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.7/10 (Category avg: 9.1/10)
  • Extensibility: 8.3/10 (Category avg: 8.7/10)

Who Is the Company Behind Invicti (formerly Netsparker)?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    335 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Large, 29% Medium

What Do G2 Reviewers Say About Invicti (formerly Netsparker)?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Invicti, appreciating its user-friendly setup and quick installation process.
  • Users value the efficient scanning technology of Invicti, enhancing workflow with hassle-free monthly website tests.
  • Users commend Invicti's accurate vulnerability detection and excellent integration with DevOps tools, enhancing their security testing efficiency.
  • Users value the high-quality reporting of Invicti, making it ideal for certifications and simplifying compliance processes.
  • Users value the effective vulnerability detection of Invicti, appreciating its ease of use and accurate reporting.
Cons
  • Users find the customer support lacking, with slow responses and inadequate solutions for technical issues.
  • Users experience slow performance during scans, setup, and upgrades, impacting the overall efficiency of Invicti.
  • Users find that slow scanning can hinder efficiency, especially when setup is tricky and API scanning is limited.
  • Users face API issues with Invicti, making it unsuitable for scanning purposes despite good support.
  • Users find the complex setup challenging initially, impacting their experience before they can effectively utilize the product.

What Are Recent G2 Reviews of Invicti (formerly Netsparker)?

What Are G2 Users Discussing About Invicti (formerly Netsparker)?

Titania Nipper InfraSight

Award-winning Risk-Based Vulnerability Management. Nipper InfraSight analyzes network device configurations in the way Advances Persistent Threat (APT) groups do, to identify misconfigurations that could create attack paths. This analysis offers unparalleled, pen-tester accuracy, finding critical vulnerabilities in firewalls, routers, switches that other tools simply cannot see. Our solutions then prioritize the biggest risks to your business and provide device-specific remediation guidance, right down to specific command line prompts.  By analyzing device configurations against key compliance standards and security frameworks (including STIGs/CIS Benchmarks/PCI DSS/CMMC/CORA/NIST SP 800-53), Nipper solutions tell you precisely which devices are at risk of failing, how significant that risk is, and how you can solve it, with auditor-ready reports. Whether your focus is taking pragmatic, risk-based security measures to minimize known vulnerabilities or ensuring compliance with industry security standards, Nipper solutions provide the targeted insights you need. No other security provider looks at the network in the same way. That’s why Nipper can uniquely provide the network configuration coverage that organizations urgently require. 30+ U.S. federal agencies and 800+ organizations globally trust Nipper solutions to deliver vulnerability analysis and compliance automation while supporting air-gapped environments, sovereign cloud requirements, and complex regulated infrastructures.

Average Rating: 4.3/5.0

Total Reviews: 28

How Do G2 Users Rate Titania Nipper InfraSight?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.4/10)
  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.1/10)
  • Extensibility: 10.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Titania Nipper InfraSight?

  • Seller: Titania
  • Company Website:
  • Year Founded: 2009
  • HQ Location: London, GB
  • Twitter: @TitaniaLtd
    2,821 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    104 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 43% Large, 25% Medium

What Do G2 Reviewers Say About Titania Nipper InfraSight?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Titania Nipper InfraSight remarkable, appreciating its straightforward and user-friendly design.
  • Users appreciate the reporting quality of Titania Nipper InfraSight, as it provides clear assessments and actionable recommendations.
  • Users value the scanning efficiency of Titania Nipper InfraSight, enabling quick detection of network misconfigurations.
  • Users value the effective vulnerability detection in Titania Nipper, providing actionable insights and continuous improvement for network security.
  • Users value the clear and user-friendly interface of Titania Nipper InfraSight, enhancing their assessment experience significantly.
Cons
  • Users express concerns about the licensing model, noting it requires a minimum of 100 devices, complicating usage.
  • Users encounter issues with false positives, leading to confusion and frustration when checking actual device findings.
  • Users find the lack of cloud support frustrating, particularly with device-specific recommendations that are often inaccurate.
  • Users face limited compatibility issues, resulting in the need for maintaining outdated versions and difficulties with integrations.
  • Users note the limited device support of Titania Nipper InfraSight, which complicates maintenance and functionality.

What Are Recent G2 Reviews of Titania Nipper InfraSight?

What Are G2 Users Discussing About Titania Nipper InfraSight?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated March 5, 2025