Best Penetration Testing Tools - Page 9

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 172

Category Stats (Sep 2026)

  • Average Rating: 4.64/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 26, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,800+ Authentic Reviews
  • 172+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: vPenTest, Cobalt, Astra Pentest, Oneleet, Pentera, NodeZero from Horizon3.ai, H1 Platform, and Bugcrowd.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=vpentest&focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=astra-pentest&focus%5B%5D=oneleet&focus%5B%5D=pentera&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=h1-platform&focus%5B%5D=bugcrowd)

Informer

Informer's Attack Surface Management (ASM) and Pentesting platform helps CISOs, CTOs and IT teams map external assets and identify vulnerabilities in real-time so they can be remediated before attackers can exploit them

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Informer?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.4/10)

Who Is the Company Behind Informer?

  • Seller: Informer
  • Year Founded: 2012
  • HQ Location: San Francisco, California, United States
  • LinkedIn® Page: www.linkedin.com
    3,858 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Informer?

Inspectiv

Inspectiv is an all-in-one AppSec testing platform that simplifies the process of discovering, validating, and remediating vulnerabilities. By offering penetration testing, bug bounty programs, dynamic application security testing (DAST), and vulnerability disclosure (VDP) in a single solution, organizations can reduce risk, maintain compliance, and strengthen their security posture. With streamlined management, minimal operational overhead, and predictable pricing, Inspectiv delivers impactful results that make security testing more efficient and effective.

Who Is the Company Behind Inspectiv?

Intrudify

Intrudify is an AI-assisted penetration testing platform for web applications and APIs. Teams use it for one-time assessments, continuous testing, and audit preparation. The platform discovers assets, tests authenticated flows, validates findings with evidence, and provides developer-ready remediation guidance. Standard delivery uses automated multi-pass AI validation, with human expert review available as an add-on. Reports can be used as evidence for SOC 2, ISO 27001, NIS 2, and DORA audits. Intrudify itself is not certified in those frameworks. Intrudify runs on Microsoft Azure with encrypted storage, network-restricted data services, Cloudflare Zero Trust access, and Azure RBAC with managed identities.

Who Is the Company Behind Intrudify?

IT services

Techsila is a forward-thinking IT consultancy and software development firm headquartered in Burlington, Massachusetts. We excel in delivering custom AI & machine-learning solutions, cloud & DevOps services, cybersecurity and penetration testing, and full-stack web & mobile app development. With flexible engagement models such as outsourcing, staff augmentation, dedicated teams and offshore development centers, we support industries like healthcare, fintech, e-commerce, logistics and more. Partner with us to scale your business through innovative, secure and future-ready technology.

Who Is the Company Behind IT services?

  • Seller: Techsila
  • Year Founded: 2022
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    16 employees on LinkedIn®

Kaspersky Security Assessment

Kaspersky Security Assessment is an expert-led set of services that simulate how real attackers could exploit your applications, networks, and devices, giving you a clear view of actual risks. Our experts in practical cybersecurity use real-world attack techniques to uncover hidden vulnerabilities, test defenses beyond automated scans, and deliver actionable, tailored insights - all conducted ethically and safely. Our security assessment portfolio: • Kaspersky Penetration Testing – Maps real attack paths from external perimeter to critical internal assets by chaining exploitable flaws into real vectors. • Kaspersky Red Teaming – Simulates goal-driven, scenario-based adversary attacks to validate detection and response capabilities and strengthen resilience against real threats. • Kaspersky Application Security Assessment – Uncovers vulnerabilities and business logic flaws through in-depth technical testing and analysis of application workflows. • Kaspersky Appliance Security Assessment – Provides in-depth analysis of hardware, software, and wired / wireless interfaces to identify weaknesses, assess protection mechanisms and reduce threats in IoT and embedded devices. • Kaspersky ICS Security Assessment – Assesses the attack surface, and evaluates the security of OT environment from Level 4 to Level 0 of Purdue Model, including network equipment, DCS, SCADA, PLC, IED, and mission-critical systems to identify cyber threats. • Kaspersky ATM Security Assessment – Comprehensive analysis of ATMs and POS devices to reveal attack surface and uncover exploitable flaws, showing how attackers could steal funds, capture card data, or disrupt services.

Who Is the Company Behind Kaspersky Security Assessment?

  • Seller: Kaspersky
  • Year Founded: 1997
  • HQ Location: Moscow
  • Twitter: @kasperskylabind
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4,616 employees on LinkedIn®
  • Phone: 1-866-328-5700

Maced AI

AI pentesting agents attack your code, APIs, and infrastructure - then deliver audit-ready reports compatible with SOC 2 and ISO 27001, complete with proof of exploit and fix guidance.

Who Is the Company Behind Maced AI?

MaxPatrol

MaxPatrol is an all-in-one vulnerability management solution designed to provide vulnerability and compliance management for applications, databases, network and operating systems, as well as ERP (SAP), ICS/SCADA, Core Telecom and Banking infrastructure.

Who Is the Company Behind MaxPatrol?

Nemesis

Nemesis by Persistent Security Industries is a Breach & Attack Simulation (BAS) platform that lets organizations emulate real-world cyberattacks in a controlled environment. Stay ahead of cyber threats with our continuous, automated security testing and proactive breach simulation. Nemesis Breach and Attack Simulation exposes the issues that really matter. • Ransomware Simulation Library. Run safe emulations of tactics used by top ransomware groups. • End-to-End Attack Chains. Validate each layer of your defense from initial access to data encryption attempts. • Cloud Security Testing. Validate configurations and controls in dynamic cloud environments • Detection & Response Insights. Understand where your EDR/SIEM picks up the threat (and where it does not). SOC Validation. Objectively measure the detection and response capabilities of your SOC (vendor).

Who Is the Company Behind Nemesis?

Novee Security

Novee Security is a cybersecurity company that offers an AI-powered penetration testing platform called Novee. The company focuses on offensive security, providing continuous, automated penetration testing that starts from a true black-box perspective — requiring only a domain name to begin. Its platform uses purpose-trained AI models built on real attacker tradecraft to discover novel vulnerabilities, validate findings with reproduction steps, and deliver personalized remediation guidance tailored to each customer's architecture. Novee Security serves enterprises, particularly software companies and organizations storing sensitive data, helping CISOs and security teams reduce risk at the speed attackers create it.

Who Is the Company Behind Novee Security?

Ostorlab

Ostorlab helps security and development teams find the application risks that matter, validate whether they are truly exploitable, and fix them faster. Instead of leaving teams with long lists of alerts to investigate manually, Ostorlab provides clear evidence, risk context, and actionable remediation guidance across web applications, APIs, mobile applications, source code, and third-party apps. It also helps organizations make safer app approval decisions by assessing security, privacy, malware, and trust risks in Android and iOS applications. With broader coverage, less manual validation, and clearer prioritization, Ostorlab helps teams reduce risk, release with greater confidence, and improve security throughout the application lifecycle. Trusted by more than 18,000 application developers and security professionals

Who Is the Company Behind Ostorlab?

  • Seller: Ostorlab
  • Year Founded: 2021
  • HQ Location: Middletown, US
  • Twitter: @OstorlabSec
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

Pandava

Who Is the Company Behind Pandava?

  • Seller: Peris.ai
  • Year Founded: 2022
  • HQ Location: Jakarta, ID
  • Twitter: @peris_ai
    155 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®

Payatu

Payatu follows a strict methodology when conducting an Application Security Assessment. This method ensures that a structured process is followed and provides the client with the baseline against which the quality of the assessment can be measured. Our methodology takes into consideration the industry-wide projects looking at the most commonly vulnerable areas of the application deployments, considering the OWASP top 10 and Web Application Security Consortium.

Who Is the Company Behind Payatu?

  • Seller: Payatu
  • Year Founded: 2011
  • HQ Location: Pune, IN
  • LinkedIn® Page: www.linkedin.com
    153 employees on LinkedIn®

Penetration Testing

We specialize in offensive security testing, firmly believing that the most effective way to protect modern organizations is by subjecting their networks and applications to the same real-world attacks they face every day. This is why our comprehensive approach to security testing focuses on identifying and mitigating your organization’s exposure to potential threats.

Who Is the Company Behind Penetration Testing?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated March 5, 2025