# Best Risk-Based Vulnerability Management Software - Page 2

## How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

**Total Products under this Category:** 194

### Category Stats (Aug 2026)

- **Average Rating:** 4.48/5 (↓0.02 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Ivanti Neurons for RBVM (+2.94%) - Among all products in this category, Ivanti Neurons for RBVM recorded the largest rating increase compared to last month

_Last updated: August 04, 2026_

## How Does G2 Rank Risk-Based Vulnerability Management Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 4,700+ Authentic Reviews
- 194+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Risk-Based Vulnerability Management Software
 ![G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence](https://www.g2.com/categories/risk-based-vulnerability-management/grids.png?focus%5B%5D=38011&focus%5B%5D=31923&focus%5B%5D=7337&focus%5B%5D=160601&focus%5B%5D=130651&focus%5B%5D=39589&focus%5B%5D=98391&focus%5B%5D=55997)

Highlighted products: Arctic Wolf, Tenable Vulnerability Management, Recorded Future, RiskProfiler - External Threat Exposure Management, YesWeHack, H1 Platform, Pentera, and Check Point Exposure Management.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=recorded-future&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=h1-platform&focus%5B%5D=pentera&focus%5B%5D=check-point-exposure-management)

**Sponsored**

### Upwind

Upwind is the runtime-first cloud security platform that secures your deployments, configurations, and applications by providing real-time visibility from the inside out. We’ve built a unified fabric that maps your environment as it runs - revealing what’s truly at risk, what’s actively happening, and how to respond quickly and effectively. With Upwind, security, dev, and ops teams move faster, stay focused, and fix risks that matter most.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2246&secure%5Bchosen_at%5D=2026-08-04T22%3A25%3A54Z&secure%5Bdisplayable_resource_id%5D=2246&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=2246&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1333227&secure%5Bresource_id%5D=2246&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Frisk-based-vulnerability-management%3Fpage%3D2%26post_lead_product%3Dtenable-sc&secure%5Btoken%5D=e668733b6ef5335fb7b1ccdf8e12be1475af66f55ccc69850a5348301819cd02&secure%5Burl%5D=https%3A%2F%2Fwww.upwind.io&secure%5Burl_type%5D=custom_url)

### [ZeroFox](https://www.g2.com/products/zerofox/reviews)

ZeroFox is the solution used to illuminate threat actor intent, mitigate threats and exposures, remove threats from the internet, and preemptively safeguard your reputation. ZeroFox uniquely fuses the core capabilities of Cyber Threat Intelligence, Brand and Domain Protection, Attack Surface Intelligence, Executive Protection and Physical Security Intelligence in one platform packed with intelligence you’ll actually use. ZeroFox defends your business from the everyday attacks that impact revenue, erode trust, and frustrate teams by: Discovering exposed assets, brands, domains, accounts, and emerging threats Validating the risks that matter most to you and your digital estate Disrupting attacks before they harm your business, your customers, and your people Our continuous cycle—Discover, Validate, Disrupt—delivers outcomes and helps organizations achieve deeper threat contextualization, faster detection and response times, and longer-term cost savings by anticipating, understanding, and mitigating external digital threats at scale. Join thousands of customers, including some of the largest public sector organizations and leaders in finance, media, technology, retail, and healthcare, and let ZeroFox deliver timely, personal, and usable intelligence so you can stay ahead of what’s next and reclaim what’s right.

**Average Rating:** 4.4/5.0

**Total Reviews:** 164

#### How Do G2 Users Rate ZeroFox?

- **Has the product been a good partner in doing business?:** 9.2/10 (Category avg: 9.2/10)
- **Reporting:** 9.0/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.8/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind ZeroFox?

- **Seller:** [ZeroFox](https://www.g2.com/sellers/zerofox)
- **Company Website:** www.zerofox.com
- **Year Founded:** 2013
- **HQ Location:** Baltimore, MD
- **Twitter:** @ZeroFOX  
5,205 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=26ceb832516427322e84b1b83b63a726a07325d7380bc2024edc4e8bb3934eeb&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2890672&secure%5Burl_type%5D=linkedin_company_website)  
859 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Cyber Security Analyst
- **Top Industries:** Financial Services, Banking
- **Company Size:** 51% Large, 27% Medium

#### What Do G2 Reviewers Say About ZeroFox?

_AI-generated summary from verified user reviews_

##### Pros

- Users find ZeroFox to be very **user-friendly** , appreciating its smooth onboarding and effective brand protection.
- Users appreciate the **effective brand protection** of ZeroFox, highlighting its ability to identify and combat scam sites efficiently.
- Users value the **real-time threat detection** of ZeroFox, enhancing their security awareness across various digital platforms.
- Users appreciate the **quick and effective alert notifications** from ZeroFox, enhancing daily operational efficiency and responsiveness.
- Users value the **quick and effective alerts** from ZeroFox, enhancing daily operations and reducing false positives.

##### Cons

- Users are frustrated with the **inefficient alerts** of ZeroFox, experiencing delays in takedown processing and incomplete actions.
- Users find the **repetitive false alerts** cumbersome, requiring time-consuming manual reviews that disrupt efficiency.
- Users experience **slow performance** with ZeroFox, including delays in alert reporting and UI loading times.
- Users experience **false positive alerts** with ZeroFox, leading to time-consuming manual reviews and frustration in monitoring.
- Users experience issues with the **inefficient alert system** , facing delays and false positives that hinder timely responses.

#### What Are Recent G2 Reviews of ZeroFox?

**["ZeroFox Unifies External Threat Intelligence for Faster Detection and Takedowns"](https://www.g2.com/survey_responses/zerofox-review-13121291)**

**Rating:** 5.0/5.0 stars

_— NITIN W._

[Read full review](https://www.g2.com/survey_responses/zerofox-review-13121291)

**["Zerofox Delivers White-Glove Support and an Easy-to-Use, Reliable Platform"](https://www.g2.com/survey_responses/zerofox-review-13130846)**

**Rating:** 5.0/5.0 stars

_— Matt K._

[Read full review](https://www.g2.com/survey_responses/zerofox-review-13130846)

#### What Are G2 Users Discussing About ZeroFox?

- [Who owns ZeroFox?](https://www.g2.com/discussions/who-owns-zerofox) - 1 comment
- [How much does ZeroFox cost?](https://www.g2.com/discussions/how-much-does-zerofox-cost) - 1 comment
- [Is ZeroFox safe?](https://www.g2.com/discussions/is-zerofox-safe) - 1 comment

### [Tenable Security Center](https://www.g2.com/products/tenable-security-center/reviews)

Tenable Security Center (formerly Tenable.sc) is the industry's most comprehensive risk-based vulnerability management (RBVM) solution, enabling you to: • See all your vulnerabilities and continuously assess all assets the moment they join the network -- including transient devices that aren’t regularly connected • Predict what matters by understanding vulnerabilities in the context of business risk, as well as the criticality of affected assets • Act on each high priority vulnerability to effectively manage risk, and measure KPIs to effectively communicate effectiveness Legacy vulnerability management tools weren't designed to handle the modern attack surface and the growing number of threats that come with them. Instead, they’re limited to a theoretical view of risk, leading security teams to waste the majority of their time chasing after the wrong issues while missing many of the most critical vulnerabilities that pose the greatest risk to the business. By taking a risk-based approach to vulnerability management, Tenable.sc enables security teams to focus on the vulnerabilities and assets that matter most, so they can address the organization’s true business risk instead of wasting their valuable time on vulnerabilities that have a low likelihood of being exploited. Tenable delivers the most comprehensive risk-based vulnerability management solution available to help you prioritize your remediation efforts, so you can take decisive action to reduce the greatest amount of business risk with the least amount of effort.

**Average Rating:** 4.6/5.0

**Total Reviews:** 73

#### How Do G2 Users Rate Tenable Security Center?

- **Has the product been a good partner in doing business?:** 8.8/10 (Category avg: 9.2/10)
- **Reporting:** 8.6/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.5/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.4/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Tenable Security Center?

- **Seller:** [Tenable](https://www.g2.com/sellers/tenable)
- **HQ Location:** Columbia, MD
- **Twitter:** @TenableSecurity  
87,752 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=029266d223c06e6b09e6d209209f15aad3bbad59d05069b38d5ec2757e74adef&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F25452%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,350 employees on LinkedIn®
- **Ownership:** NASDAQ: TENB

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Banking
- **Company Size:** 59% Large, 24% Medium

#### What Do G2 Reviewers Say About Tenable Security Center?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **compliance management** features of Tenable Security Center, ensuring adherence to ISO 27001 and audit standards.
- Users value the **responsive customer support** of Tenable Security Center, effectively addressing queries and licensing concerns.
- Users value the **comprehensive compliance scanning** capabilities of Tenable Security Center, aiding in ISO 27001 adherence.
- Users value the **informative dashboard** of Tenable Security Center, appreciating its clear overview of crucial data.
- Users value the **informative dashboard** of Tenable Security Center, which offers crucial insights and effective management tools.

##### Cons

- Users report that the **complexity of installation and documentation** makes setup and troubleshooting quite challenging.
- Users find the **complex queries** of Tenable Security Center challenging, as documentation is hard to understand.
- Users find the **complex setup** of Tenable Security Center challenging, requiring significant time and effort to resolve installation issues.
- Users often struggle with the **difficult setup** of Tenable Security Center, requiring significant time and support to resolve issues.
- Users experience **integration issues** with Tenable Security Center, complicating installation and reliance on complex documentation.

#### What Are Recent G2 Reviews of Tenable Security Center?

**["Comprehensive Review of Tenable Security Center: Features, Benefits, and Insights"](https://www.g2.com/survey_responses/tenable-security-center-review-10789575)**

**Rating:** 4.5/5.0 stars

_— Kiran R._

[Read full review](https://www.g2.com/survey_responses/tenable-security-center-review-10789575)

**["Unified Vulnerability Dashboard with Clear, Standardized Reporting"](https://www.g2.com/survey_responses/tenable-security-center-review-12601930)**

**Rating:** 4.5/5.0 stars

_— Kenneth W._

[Read full review](https://www.g2.com/survey_responses/tenable-security-center-review-12601930)

#### What Are G2 Users Discussing About Tenable Security Center?

- [What is Tenable.sc used for?](https://www.g2.com/discussions/tenable-security-center-what-is-tenable-sc-used-for) - 1 comment
- [What are tenable plugins?](https://www.g2.com/discussions/what-are-tenable-plugins)
- [What is the difference between Nessus and tenable io?](https://www.g2.com/discussions/tenable-sc-what-is-the-difference-between-nessus-and-tenable-io)
- [What database does tenable SC use?](https://www.g2.com/discussions/what-database-does-tenable-sc-use)
- [What is tenable SC used for?](https://www.g2.com/discussions/what-is-tenable-sc-used-for)

### [Semperis Purple Knight](https://www.g2.com/products/semperis-purple-knight/reviews)

Community-driven hybrid Active Directory security assessment tool. Purple Knight is an identity system security assessment tool used by thousands of organizations to quickly identify vulnerabilities in AD, Entra ID, and Okta environments and receive prioritized, expert remediation guidance.

**Average Rating:** 4.7/5.0

**Total Reviews:** 11

#### How Do G2 Users Rate Semperis Purple Knight?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 9.2/10)
- **Reporting:** 8.7/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.2/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Semperis Purple Knight?

- **Seller:** [Semperis](https://www.g2.com/sellers/semperis)
- **Company Website:** www.semperis.com
- **Year Founded:** 2015
- **HQ Location:** Hoboken, New Jersey
- **Twitter:** @SemperisTech  
10,074 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0018c787ec107d113f80de57fe0ac60f83b23d2d2fb56018ab80191a760d408c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsemperis%2F&secure%5Burl_type%5D=linkedin_company_website)  
674 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 45% Medium, 45% Small

#### What Do G2 Reviewers Say About Semperis Purple Knight?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **immediate and prioritized security insights** from Semperis Purple Knight, enhancing Active Directory protection efficiently.
- Users appreciate the **ease of use** of Semperis Purple Knight, enabling quick identification of security vulnerabilities effortlessly.
- Users value the **immediate identification of critical security gaps** in Active Directory, streamlining their security assessment process.
- Users value the **immediate, actionable insights** provided by Semperis Purple Knight for enhancing Active Directory security.
- Users appreciate the **ease of implementation** of Semperis Purple Knight, making integration straightforward and efficient.

##### Cons

- Users note the **lack of continuous monitoring** in Semperis Purple Knight, which limits its effectiveness and requires manual intervention.
- Users find the **lack of automation** requiring manual remediation and setup to be a significant drawback of Purple Knight.
- Users find the **difficult learning curve** challenging due to overwhelming reports and lack of automated remediation.
- Users find the **difficult setup** of Semperis Purple Knight adds complexity, especially for hybrid environments needing manual configuration.
- Users criticize the **inadequate reporting** of Semperis Purple Knight, highlighting static reports and lack of real-time alerts.

#### What Are Recent G2 Reviews of Semperis Purple Knight?

**["Best tool to audit your active directory"](https://www.g2.com/survey_responses/semperis-purple-knight-review-11877575)**

**Rating:** 5.0/5.0 stars

_— Nicolas B._

[Read full review](https://www.g2.com/survey_responses/semperis-purple-knight-review-11877575)

**["Essential Free Tool for Clear AD and Entra ID Security Insights"](https://www.g2.com/survey_responses/semperis-purple-knight-review-11940160)**

**Rating:** 5.0/5.0 stars

_— Chris J._

[Read full review](https://www.g2.com/survey_responses/semperis-purple-knight-review-11940160)

### [Cisco Vulnerability Management (formerly Kenna.VM)](https://www.g2.com/products/cisco-vulnerability-management-formerly-kenna-vm/reviews)

Cisco Vulnerability Management (formerly Kenna.VM), the original SaaS risk-based vulnerability management platform, prioritizes vulnerabilities that pose a real risk, enabling Security and IT teams to focus their limited resources and remediate more efficiently. Cisco’s data science-driven prioritization evaluates both enterprise data and a wealth of data on real-world exploit activity and translates that context into actionable intelligence to guide remediation.

**Average Rating:** 4.3/5.0

**Total Reviews:** 200

#### How Do G2 Users Rate Cisco Vulnerability Management (formerly Kenna.VM)?

- **Has the product been a good partner in doing business?:** 8.9/10 (Category avg: 9.2/10)
- **Reporting:** 8.5/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.7/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.1/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Cisco Vulnerability Management (formerly Kenna.VM)?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 76% Large, 17% Medium

#### What Are Recent G2 Reviews of Cisco Vulnerability Management (formerly Kenna.VM)?

**["Vulnerability prioritization tool for non-technical"](https://www.g2.com/survey_responses/cisco-vulnerability-management-formerly-kenna-vm-review-9891371)**

**Rating:** 4.5/5.0 stars

_— Verified User in Retail_

[Read full review](https://www.g2.com/survey_responses/cisco-vulnerability-management-formerly-kenna-vm-review-9891371)

**["Ease of use and better transparency"](https://www.g2.com/survey_responses/cisco-vulnerability-management-formerly-kenna-vm-review-9928180)**

**Rating:** 4.5/5.0 stars

_— Verified User in Utilities_

[Read full review](https://www.g2.com/survey_responses/cisco-vulnerability-management-formerly-kenna-vm-review-9928180)

#### What Are G2 Users Discussing About Cisco Vulnerability Management (formerly Kenna.VM)?

- [What is Kenna Security used for?](https://www.g2.com/discussions/what-is-kenna-security-used-for)
- [How do you use Kenna Security?](https://www.g2.com/discussions/how-do-you-use-kenna-security)
- [What is risk based vulnerability management?](https://www.g2.com/discussions/what-is-risk-based-vulnerability-management)
- [What is Kenna vulnerability?](https://www.g2.com/discussions/what-is-kenna-vulnerability)
- [What does Kenna Security do?](https://www.g2.com/discussions/what-does-kenna-security-do) - 1 comment

### [SecOps Solution](https://www.g2.com/products/secops-solution/reviews)

SecOps Solution is a next-gen, agentless patch and vulnerability management platform that helps organizations fix vulnerabilities fast — without agents, manual effort, or complex setups. We automate patching across operating systems and third-party applications, including remote and on-prem devices — all in a fraction of the time traditional tools take.

**Average Rating:** 4.8/5.0

**Total Reviews:** 48

#### How Do G2 Users Rate SecOps Solution?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Reporting:** 9.7/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.7/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind SecOps Solution?

- **Seller:** [SecOps Solution](https://www.g2.com/sellers/secops-solution)
- **Year Founded:** 2021
- **HQ Location:** Mountain View, California, USA
- **Twitter:** @secopsolution  
35 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=432f2a2ebd041a5008b2d0a46aa782658ff7b510dd1b508ef23f2ece4363d481&secure%5Burl%5D=http%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsecopsolution&secure%5Burl_type%5D=linkedin_company_website)  
7 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 61% Small, 35% Medium

#### What Do G2 Reviewers Say About SecOps Solution?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **intuitive centralized dashboard** that significantly streamlines patch management and enhances visibility of vulnerabilities.
- Users praise the **responsive customer support** of SecOps Solution, ensuring smooth communication and assistance throughout the process.
- Users value the **detailed patch testing and reporting** of SecOps Solution, enhancing confidence and communication with stakeholders.
- Users value the **built-in reporting** of SecOps Solution, enhancing communication and supporting compliance audits effectively.
- Users benefit from the **effective reporting efficiency** of SecOps Solution, simplifying communication of security status to stakeholders.

#### What Are Recent G2 Reviews of SecOps Solution?

**["SecOps Feels Like an Extra Teammate for Patch Tracking and Vulnerability Visibility"](https://www.g2.com/survey_responses/secops-solution-review-12931714)**

**Rating:** 5.0/5.0 stars

_— Shruti M._

[Read full review](https://www.g2.com/survey_responses/secops-solution-review-12931714)

**["Great Third-Party App Patching and Misconfiguration Audits"](https://www.g2.com/survey_responses/secops-solution-review-12888845)**

**Rating:** 5.0/5.0 stars

_— Maroti P._

[Read full review](https://www.g2.com/survey_responses/secops-solution-review-12888845)

#### What Are G2 Users Discussing About SecOps Solution?

- [What is SecOps Solution used for?](https://www.g2.com/discussions/what-is-secops-solution-used-for) - 1 comment

### [PlexTrac](https://www.g2.com/products/plextrac/reviews)

PlexTrac is the leading AI-powered platform for pentest reporting and threat exposure management, trusted by Fortune 500 companies and top security providers. Built to help cybersecurity teams continuously manage and reduce threat exposure, PlexTrac centralizes security data, streamlines reporting, prioritizes risk, and automates remediation workflows—empowering teams to drive measurable risk reduction. The platform is ideal for enterprises & service providers looking to deliver a Continuous Threat Exposure Management (CTEM) framework across their business. With our suite of solutions, you can consolidate security data from tools and manual testing, automatically prioritize risks based on business impact, and automate remediation and retesting workflows for ongoing, more effective threat management.

**Average Rating:** 4.8/5.0

**Total Reviews:** 15

#### How Do G2 Users Rate PlexTrac?

- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.2/10)
- **Reporting:** 9.9/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 6.9/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind PlexTrac?

- **Seller:** [PlexTrac](https://www.g2.com/sellers/plextrac)
- **Company Website:** plextrac.com
- **Year Founded:** 2016
- **HQ Location:** Boise, Idaho
- **Twitter:** @plextrac  
1,648 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f139e8ef184bca3db4ed2b0a3bdcfdcf4e1883c3d0c84356cd9bae715b4ca40c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F19015522&secure%5Burl_type%5D=linkedin_company_website)  
91 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Consulting
- **Company Size:** 40% Large, 40% Small

#### What Do G2 Reviewers Say About PlexTrac?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **intuitive interface** and **customizability** of PlexTrac, enhancing their reporting efficiency and collaboration.
- Users commend the **excellent customer support** from PlexTrac, providing timely assistance and enhancing overall experience.
- Users commend the **ease of use** of PlexTrac, highlighting its intuitive navigation and customizable features.
- Users appreciate the **reporting efficiency** of PlexTrac, enhancing organization and speeding up the reporting process significantly.
- Users value the **seamless integrations** of PlexTrac, enhancing efficiency and standardizing reporting across various tools.

##### Cons

- Users note **missing features** in PlexTrac's on-premise version compared to the SaaS, impacting their overall experience.
- Users find that **complexity in report formatting** occasionally requires extra effort, which can hinder the overall experience.
- Users find the **complex setup** of PlexTrac challenging initially, requiring time to learn the interface effectively.
- Users face a **difficult learning curve** with PlexTrac, despite support, particularly with cloud versus on-prem options.
- Users desire more streamlined reporting options for **inadequate reporting** in PlexTrac, particularly for Threat Hunting and Incident Response.

#### What Are Recent G2 Reviews of PlexTrac?

**["A Game-Changer for Offensive Security Services"](https://www.g2.com/survey_responses/plextrac-review-11036693)**

**Rating:** 5.0/5.0 stars

_— Rene V._

[Read full review](https://www.g2.com/survey_responses/plextrac-review-11036693)

**["Game Changer for My Cybersecurity Consultancy"](https://www.g2.com/survey_responses/plextrac-review-11388903)**

**Rating:** 5.0/5.0 stars

_— Anthony T._

[Read full review](https://www.g2.com/survey_responses/plextrac-review-11388903)

### [Edgescan](https://www.g2.com/products/edgescan/reviews)

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

**Average Rating:** 4.6/5.0

**Total Reviews:** 58

#### How Do G2 Users Rate Edgescan?

- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 9.2/10)
- **Reporting:** 9.0/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.2/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Edgescan?

- **Seller:** [Edgescan](https://www.g2.com/sellers/edgescan)
- **Company Website:** www.edgescan.com
- **Year Founded:** 2017
- **HQ Location:** Dublin, Dublin
- **Twitter:** @edgescan  
2,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=51edeb949934c6f870f2d6720fefabf6632464f3895af4d8276b3c60c0fe37db&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2928425%2F&secure%5Burl_type%5D=linkedin_company_website)  
89 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 38% Large, 28% Medium

#### What Do G2 Reviewers Say About Edgescan?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate Edgescan's **ease of use** , enjoying its intuitive interface and streamlined navigation for effective vulnerability management.
- Users value the **automated vulnerability detection** with intuitive reports, timely alerts, and effective risk management features.
- Users value the **excellent customer support** from Edgescan, praising the team's responsiveness and proactive assistance.
- Users value the **thorough vulnerability identification** features of Edgescan, enhancing risk management and resolution efficiency.
- Users value the **robust features** of Edgescan, which streamline security assessments and enhance ease of use.

##### Cons

- Users find the **complex UI** challenging initially, with navigation issues and a need for improved dashboard functionality.
- Users highlight **limited customization** options in Edgescan, particularly regarding filtering and admin functionalities.
- Users find the **poor interface design** of Edgescan challenging, affecting usability and data accessibility.
- Users report experiencing **slow performance** as scans can take longer due to manual review processes.
- Users find the **UI not user friendly** , lacking intuitiveness and advanced features for better navigation and data accessibility.

#### What Are Recent G2 Reviews of Edgescan?

**["Edgescan: Easy Setup, Clear Insights, and Expert Security Support"](https://www.g2.com/survey_responses/edgescan-review-12224347)**

**Rating:** 5.0/5.0 stars

_— Matt W._

[Read full review](https://www.g2.com/survey_responses/edgescan-review-12224347)

**["Efficient Vulnerability Scanning with Easy Navigation"](https://www.g2.com/survey_responses/edgescan-review-12218850)**

**Rating:** 5.0/5.0 stars

_— Simon L._

[Read full review](https://www.g2.com/survey_responses/edgescan-review-12218850)

#### What Are G2 Users Discussing About Edgescan?

- [What is edgescan used for?](https://www.g2.com/discussions/what-is-edgescan-used-for) - 1 comment

### [Microsoft Defender Vulnerability Management](https://www.g2.com/products/microsoft-defender-vulnerability-management/reviews)

Defender Vulnerability Management delivers asset visibility, intelligent assessments, and built-in remediation tools for Windows, macOS, Linux, Android, iOS, and network devices. Leveraging Microsoft threat intelligence, breach likelihood predictions, business contexts, and devices assessments, Defender Vulnerability Management rapidly and continuously prioritizes the biggest vulnerabilities on your most critical assets and provides security recommendations to mitigate risk. Reduce risk with continuous vulnerability assessment, risk-based prioritization, and remediation. Defender Vulnerability Management is available for cloud workloads and endpoints. Defender for Endpoint Plan 2 customers can access advanced vulnerability management capabilities with the Defender Vulnerability Management add-on, now generally available.

**Average Rating:** 4.4/5.0

**Total Reviews:** 34

#### How Do G2 Users Rate Microsoft Defender Vulnerability Management?

- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 9.2/10)
- **Reporting:** 8.7/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.8/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Microsoft Defender Vulnerability Management?

- **Seller:** [Microsoft](https://www.g2.com/sellers/microsoft)
- **Year Founded:** 1975
- **HQ Location:** Redmond, Washington
- **Twitter:** @microsoft  
13,091,739 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9458f51bd6ded48ad432a804f19ad736469f007787569b63827154231c315630&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmicrosoft%2F&secure%5Burl_type%5D=linkedin_company_website)  
231,632 employees on LinkedIn®
- **Ownership:** MSFT

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 41% Small, 35% Large

#### What Are Recent G2 Reviews of Microsoft Defender Vulnerability Management?

**["Amazing vulnerability management solution"](https://www.g2.com/survey_responses/microsoft-defender-vulnerability-management-review-9057478)**

**Rating:** 5.0/5.0 stars

_— Marko V._

[Read full review](https://www.g2.com/survey_responses/microsoft-defender-vulnerability-management-review-9057478)

**["Probably the best choice to defend your PC (Windows 10 and 11)"](https://www.g2.com/survey_responses/microsoft-defender-vulnerability-management-review-8596658)**

**Rating:** 4.0/5.0 stars

_— Markus M._

[Read full review](https://www.g2.com/survey_responses/microsoft-defender-vulnerability-management-review-8596658)

### [SAFE](https://www.g2.com/products/safe-security-safe/reviews)

SAFE has reinvented cyber risk management with Agentic AI. The company helps CISOs, TPRM, and GRC leaders become strategic business partners by automating the understanding, prioritization and management of cyber risk—accelerating AI adoption and digital transformation. SAFE is the #1 platform to unify the management of all cyber risks—enterprise, third-party, and AI-related—and deliver autonomous cyber risk management through a fleet of specialized AI agents. Its platform replaces manual effort with agentic automation, backed by the world’s most trusted risk standards. Trusted by hundreds of global organizations, SAFE has more than doubled revenue three years in a row and raised $100M+ to fuel the future of cyber risk automation.

**Average Rating:** 4.4/5.0

**Total Reviews:** 59

#### How Do G2 Users Rate SAFE?

- **Has the product been a good partner in doing business?:** 8.5/10 (Category avg: 9.2/10)
- **Reporting:** 7.4/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.1/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind SAFE?

- **Seller:** [Safe Security](https://www.g2.com/sellers/safe-security)
- **Year Founded:** 2012
- **HQ Location:** Palo Alto, US
- **Twitter:** @safecrq  
3,248 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e8030ec0a0fbe49ebd50f7bbf676485b37881efb34d296757d55a1e5b2eafa5c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsafesecurity-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,217 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Hospital & Health Care
- **Company Size:** 73% Large, 13% Medium

#### What Do G2 Reviewers Say About SAFE?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **revolutionary approach to cyber risk management** that SAFE offers with its FAIR analysis integration.
- Users commend the **exceptional customer support** of SAFE, consistently receiving timely assistance and expert guidance.
- Users value SAFE for its **robust features** that enhance decision-making and streamline risk analysis effectively.
- Users praise the **seamless data integration** in SAFE, enhancing insights and empowering strategic decision-making.
- Users find SAFE to have **intuitive usability** , with easy implementation and clear dashboards enhancing their experience.

##### Cons

- Users find the **missing features** in SAFE limit functionality and hinder effective risk analysis and onboarding.
- Users find that **information management needs improvement** , as granularity and transparency issues hinder effective data utilization.
- Users face **integration issues** with SAFE, limiting data access and complicating use for smaller teams.
- Users find **limited customization** options in SAFE, lacking deep integrations and the ability to tailor configurations effectively.
- Users find the **interface confusing** , with a cluttered dashboard and unclear group creation methods complicating risk assessments.

#### What Are Recent G2 Reviews of SAFE?

**["Fast Customer Support, Automated FAIR Analysis, Real-time CTI informed TEF make SAFE the #1 CRQ tool"](https://www.g2.com/survey_responses/safe-review-11385254)**

**Rating:** 5.0/5.0 stars

_— Joshua C._

[Read full review](https://www.g2.com/survey_responses/safe-review-11385254)

**["Elevating risk management with a trusted partner."](https://www.g2.com/survey_responses/safe-review-11388553)**

**Rating:** 4.5/5.0 stars

_— Zoe S._

[Read full review](https://www.g2.com/survey_responses/safe-review-11388553)

#### What Are G2 Users Discussing About SAFE?

- [What is an FME workflow?](https://www.g2.com/discussions/what-is-an-fme-workflow)
- [Is FME a GIS?](https://www.g2.com/discussions/is-fme-a-gis)
- [What can FME be used for?](https://www.g2.com/discussions/what-can-fme-be-used-for)
- [How can I make software safe?](https://www.g2.com/discussions/how-can-i-make-software-safe)

### [Bugcrowd](https://www.g2.com/products/bugcrowd/reviews)

Bugcrowd frees organizations with a low tolerance for risk from chronic talent shortages, noisy tools that breed false positives, and the fear of critical hidden or emerging vulnerabilities. Our SaaS platform provides access to the unlimited capacity and skills of the global ethical hacker/pentester community for deeper, proactive risk reduction and faster regulatory compliance. With 12+ years of experience and 1200+ customers in every industry (including OpenAI, National Australia Bank, Indeed, USAA, Twilio, and CISA), we know what long-term with crowdsourced security looks like.

**Average Rating:** 4.3/5.0

**Total Reviews:** 60

#### How Do G2 Users Rate Bugcrowd?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Reporting:** 8.6/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 8.3/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.1/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Bugcrowd?

- **Seller:** [Bugcrowd](https://www.g2.com/sellers/bugcrowd)
- **Year Founded:** 2012
- **HQ Location:** San Francisco, CA
- **Twitter:** @Bugcrowd  
199,211 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=333aa242026c6a6270d8f7652054439cb3c591cdb724d0ffb00a0108b2f6b966&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbugcrowd%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,701 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 34% Large, 33% Small

#### What Do G2 Reviewers Say About Bugcrowd?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **high reporting quality** on Bugcrowd, appreciating detailed reports and organized submission processes for effective vulnerability discovery.
- Users find Bugcrowd to be **easy to use** , with a seamless setup and an intuitive interface enhancing their experience.
- Users praise Bugcrowd's **excellent customer support** , noting their responsiveness and genuine helpfulness throughout their experience.
- Users value the **consistent and transparent communication** from Bugcrowd, enhancing the overall research experience.
- Users value Bugcrowd for its **efficient vulnerability detection** through a skilled community, enhancing security and saving time.

##### Cons

- Users express frustration with **poor customer support** , highlighting issues with triaging delays and unresponsive reporting processes.
- Users often experience **slow performance** in triaging and report validation, affecting their engagement and satisfaction with Bugcrowd.
- Users face **slow response times and inconsistent triaging** from companies, impacting their overall experience with Bugcrowd.
- Users experience **inadequate reporting** , facing delays and slow validation that can hinder timely resolutions and frustrate researchers.
- Users find the **learning curve steep** on Bugcrowd, making it challenging for beginners to navigate the platform.

#### What Are Recent G2 Reviews of Bugcrowd?

**["Empowers Vulnerability Management with Expert Community"](https://www.g2.com/survey_responses/bugcrowd-review-12088640)**

**Rating:** 4.0/5.0 stars

_— Mariam A._

[Read full review](https://www.g2.com/survey_responses/bugcrowd-review-12088640)

**["Bugcrowd Delivers Top-Notch Security Solutions for Robust Vulnerability Management"](https://www.g2.com/survey_responses/bugcrowd-review-8940044)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/bugcrowd-review-8940044)

### [InsightVM (Nexpose)](https://www.g2.com/products/insightvm-nexpose/reviews)

InsightVM is Rapid7’s vulnerability risk management offering that advances security through cross-department clarity, a deeper understanding of risk, and measurable progress. By informing and aligning technical teams, security teams can remediate vulnerabilities and build Security into the core of the organization. With InsightVM, security teams can: Gain Clarity Into Risk and Across Teams Better understand the risk in your modern environment so you can work in lockstep with technical teams. Extend Security’s Influence Align traditionally siloed teams and drive impact with the shared view and common language of InsightVM. See Shared Progress Take a proactive approach to security with tracking and metrics that create accountability and recognize progress.

**Average Rating:** 4.4/5.0

**Total Reviews:** 70

#### How Do G2 Users Rate InsightVM (Nexpose)?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Reporting:** 8.4/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.1/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 8.9/10 (Category avg: 8.8/10)

#### Who Is the Company Behind InsightVM (Nexpose)?

- **Seller:** [Rapid7](https://www.g2.com/sellers/rapid7)
- **Year Founded:** 2000
- **HQ Location:** Boston, MA
- **Twitter:** @rapid7  
124,405 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=04bdb542ee8372d372b62e305f57e5c7aefbd59efac3d6831f78fcc71f4f819c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F39624%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,274 employees on LinkedIn®
- **Ownership:** NASDAQ:RPD

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Large, 33% Medium

#### What Do G2 Reviewers Say About InsightVM (Nexpose)?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **automation capabilities** of InsightVM, streamlining workflows and reducing effort in vulnerability management.
- Users value the **real-time visibility** of InsightVM, enabling effective continuous monitoring and swift vulnerability detection.
- Users value the **efficient asset management** features of InsightVM, enhancing tracking, tagging, and prioritization of vulnerabilities.
- Users appreciate the **clear, actionable risk scoring** and live dashboards of InsightVM that enhance asset management.
- Users value the **clear risk scoring and live dashboards** of InsightVM for prioritizing asset exposure effectively.

##### Cons

- Users find the **complexity** of InsightVM challenging, particularly during initial setup and ongoing administration.
- Users experience **performance issues** with heavy scans and slow support responses impacting their overall experience with InsightVM.
- Users face **resource limitations** that can complicate optimization efforts, impacting overall performance when using InsightVM.
- Users often face challenges with **high memory consumption** , requiring careful management to optimize resource usage effectively.
- Users find **InsightVM's resource consumption management** tedious, particularly when optimizing scans and custom reports at scale.

#### What Are Recent G2 Reviews of InsightVM (Nexpose)?

**["InsightVM"](https://www.g2.com/survey_responses/insightvm-nexpose-review-13141902)**

**Rating:** 4.0/5.0 stars

_— Diogo A._

[Read full review](https://www.g2.com/survey_responses/insightvm-nexpose-review-13141902)

**["InsightVM’s Actionable Risk Scoring and Live Dashboards Impress"](https://www.g2.com/survey_responses/insightvm-nexpose-review-11922296)**

**Rating:** 5.0/5.0 stars

_— tali k._

[Read full review](https://www.g2.com/survey_responses/insightvm-nexpose-review-11922296)

#### What Are G2 Users Discussing About InsightVM (Nexpose)?

- [What is InsightVM (Nexpose) used for?](https://www.g2.com/discussions/what-is-insightvm-nexpose-used-for) - 1 comment
- [What is InsightVM?](https://www.g2.com/discussions/what-is-insightvm) - 1 comment
- [What is nexpose InsightVM agent?](https://www.g2.com/discussions/what-is-nexpose-insightvm-agent)
- [What is the difference between nexpose and InsightVM?](https://www.g2.com/discussions/what-is-the-difference-between-nexpose-and-insightvm)
- [What can nexpose scan?](https://www.g2.com/discussions/what-can-nexpose-scan)

### [SecureFlag](https://www.g2.com/products/secureflag/reviews)

SecureFlag is a Developer Security Enablement Platform designed to assist organizations in mitigating application risk throughout the software development lifecycle (SDLC). By integrating automated threat modeling with practical secure coding training, SecureFlag addresses critical vulnerabilities that arise from insecure design decisions and inadequate secure coding skills among development teams. This platform empowers enterprises to identify potential security threats early in the design phase and cultivate a culture of secure coding, ultimately enhancing the overall security posture of their applications. Targeted primarily at enterprise engineering and application security teams, SecureFlag serves as a comprehensive solution for organizations looking to strengthen their security frameworks. The platform effectively tackles two fundamental issues: the need for proactive security measures during the design phase and the necessity for ongoing education in secure coding practices. By providing tools that facilitate early detection of vulnerabilities and hands-on training, SecureFlag enables teams to create more secure applications while fostering a knowledgeable workforce capable of addressing security challenges. One of the standout features of SecureFlag is its automated threat modeling tool powered by AI, ThreatCanvas. This innovative solution automates the generation of threat models during the design stage, allowing teams to visualize security risks before any code is written. This proactive approach reduces reliance on manual processes and ensures that security considerations are consistently integrated into design decisions as systems evolve. Additionally, SecureFlag's secure coding training platform offers hands-on labs in real development environments, allowing developers, DevOps, Cloud, and QA engineers to practice defensive programming in real-world scenarios. This practical training is designed to replace traditional multiple-choice assessments, providing immediate feedback on code changes and fostering skill development over time. SecureFlag also emphasizes compliance and integration, mapping its training and threat modeling capabilities to various industry standards such as PCI DSS, ISO 27001, SOC 2, HIPAA, and ASVS. This feature includes exportable evidence packs for audits, simplifying the compliance process for organizations. Furthermore, SecureFlag seamlessly integrates with popular developer workflows through tools like Jira and GitHub, enabling teams to address security issues within their existing engineering processes. The platform’s AppSec team dashboards provide continuous visibility into skill coverage, risk reduction, and training adoption, allowing organizations to track their progress and make informed decisions regarding their security initiatives. With over 300 organizations across more than 30 countries utilizing SecureFlag, the platform has demonstrated measurable outcomes in enhancing security and engineering efficiency. Users have reported a 27% reduction in the time required to fix vulnerabilities, a 21% decrease in new security tickets, and an average savings of 3,600 developer hours per 100 engineers annually. SecureFlag is also recognized as an OWASP Partner, providing valuable training resources for OWASP members alongside its enterprise offerings, further solidifying its commitment to advancing secure software development practices.

**Average Rating:** 4.8/5.0

**Total Reviews:** 41

#### How Do G2 Users Rate SecureFlag?

- **Has the product been a good partner in doing business?:** 9.7/10 (Category avg: 9.2/10)
- **Risk-Prioritization:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind SecureFlag?

- **Seller:** [SecureFlag](https://www.g2.com/sellers/secureflag)
- **Company Website:** www.secureflag.com
- **HQ Location:** London, United Kingdom
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8ce9d54ac04e2d217083fcc4ad836eed2203f3512b6199450451f4103adb1ee5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsecureflag%2F&secure%5Burl_type%5D=linkedin_company_website)  
66 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Financial Services, Computer Software
- **Company Size:** 46% Medium, 29% Large

#### What Are Recent G2 Reviews of SecureFlag?

**["Real-world, hands-on labs to build effective security skills for developers"](https://www.g2.com/survey_responses/secureflag-review-13043765)**

**Rating:** 5.0/5.0 stars

_— Verified User in Retail_

[Read full review](https://www.g2.com/survey_responses/secureflag-review-13043765)

**["Hands-On SecureFlag Labs"](https://www.g2.com/survey_responses/secureflag-review-12949617)**

**Rating:** 5.0/5.0 stars

_— Syed S._

[Read full review](https://www.g2.com/survey_responses/secureflag-review-12949617)

### [RidgeBot](https://www.g2.com/products/ridgebot/reviews)

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

**Average Rating:** 4.5/5.0

**Total Reviews:** 98

#### How Do G2 Users Rate RidgeBot?

- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Reporting:** 8.7/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 9.0/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.1/10 (Category avg: 8.8/10)

#### Who Is the Company Behind RidgeBot?

- **Seller:** [Ridge Security Technology](https://www.g2.com/sellers/ridge-security-technology)
- **Company Website:** ridgesecurity.ai
- **Year Founded:** 2020
- **HQ Location:** Santa Clara, California
- **Twitter:** @RidgeSecurityAI  
1,291 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f4ee553fba315e6da91ba8fe2c2763c183623acefb48c5a2db8aa8bcd2d740de&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fridge-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
47 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Small, 45% Medium

#### What Do G2 Reviewers Say About RidgeBot?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of RidgeBot, enabling quick setup and straightforward penetration testing automation.
- Users value the **automation capabilities** of RidgeBot, significantly enhancing efficiency in penetration testing and vulnerability validation.
- Users value the **high efficiency of RidgeBot's pentesting** , enabling quick, automated vulnerability validation and seamless integration.
- Users commend RidgeBot for its **effective vulnerability identification** , providing reliable, automated testing and integration for security efficiency.
- Users praise RidgeBot for its **efficiency** in automating vulnerability testing and streamlining security processes seamlessly.

##### Cons

- Users find the **complex setup** of RidgeBot challenging, particularly for new admins requiring better documentation and support.
- Users find RidgeBot's setup overly **complex** , particularly when working with customized or legacy systems.
- Users find the **missing features** in RidgeBot, such as limited reporting and API testing, hinder optimal usage.
- Users find **poor customer support** frustrating, often lacking resources for resolving issues independently.
- Users find the **poor documentation** of RidgeBot challenging, especially for new admins during setup and onboarding.

#### What Are Recent G2 Reviews of RidgeBot?

**["Powerful Vulnerability Assessment and Remediation Capabilities"](https://www.g2.com/survey_responses/ridgebot-review-12910247)**

**Rating:** 5.0/5.0 stars

_— Daniel Felipe P._

[Read full review](https://www.g2.com/survey_responses/ridgebot-review-12910247)

**["Powerful and Efficient, Although It Requires Manual Validations"](https://www.g2.com/survey_responses/ridgebot-review-12940521)**

**Rating:** 4.5/5.0 stars

_— Henry A._

[Read full review](https://www.g2.com/survey_responses/ridgebot-review-12940521)

### [DeCYFIR by CYFIRMA](https://www.g2.com/products/decyfir-by-cyfirma/reviews)

DeCYFIR is an AI-powered preemptive External Threat Landscape Management platform engineered to help organizations predict and prevent cyberattacks before they occur. Adopting a hacker's perspective, it delivers early warnings, prioritized insights, and actionable intelligence across the full external threat landscape. Built on a proprietary 9-pillar architecture — spanning Attack Surface Discovery & Intelligence, Vulnerability Intelligence & Threat Prioritization, Brand & Online Exposure Management, Digital Risk & Identity Protection, Third Party Risk Management, Situational Awareness & Emerging Threats, Predictive Threat Intelligence, Threat Adaptive Awareness & Training, and Sector Tailored Deception Intelligence. DeCYFIR correlates signals across all pillars to cut through noise, surface what is truly critical, and empower security teams to stay decisively ahead of emerging threats.

**Average Rating:** 4.8/5.0

**Total Reviews:** 46

#### How Do G2 Users Rate DeCYFIR by CYFIRMA?

- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Reporting:** 10.0/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 10.0/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind DeCYFIR by CYFIRMA?

- **Seller:** [CYFIRMA](https://www.g2.com/sellers/cyfirma)
- **Year Founded:** 2017
- **HQ Location:** Singapore, SG
- **Twitter:** @cyfirma  
1,002 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1919a4379cea7874a5d1f81b237bf9a7f47700c8be2dc1c7f695f4953b9719ab&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcyfirma%2F&secure%5Burl_type%5D=linkedin_company_website)  
132 employees on LinkedIn®
- **Phone:** marketing@cyfirma.com

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 50% Medium, 26% Large

#### What Do G2 Reviewers Say About DeCYFIR by CYFIRMA?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **advanced threat detection** capabilities of DeCYFIR, enhancing their ability to prevent cyber incidents effectively.
- Users value the **informative threat intelligence** of DeCYFIR, aiding in proactive threat detection and prevention efforts.
- Users value DeCYFIR for its **contextual and predictive intelligence** , enhancing threat identification and risk mitigation strategies.
- Users value the **comprehensive multi-layered intelligence** of DeCYFIR, enhancing proactive cyber threat detection and risk management.
- Users value the **proactive threat detection** capabilities of DeCYFIR, enhancing their organization's security strategies effectively.

##### Cons

- Users find DeCYFIR **not user-friendly** , especially for first-time users and those without technical expertise.
- Users find DeCYFIR's interface **too complex for newcomers** , which can hinder effectiveness and overwhelm with data.
- Users find DeCYFIR's platform to have a **steep learning curve** , especially for those unfamiliar with threat intelligence workflows.
- Users find the **limited customization** of DeCYFIR's dashboards to be a barrier for effective usage and adaptation.
- Users find the **complex setup** of DeCYFIR challenging, especially for newcomers to threat intelligence workflows.

#### What Are Recent G2 Reviews of DeCYFIR by CYFIRMA?

**["Product Receives Appreciation for the Takedown Service provided by DeCYFIR"](https://www.g2.com/survey_responses/decyfir-by-cyfirma-review-13085063)**

**Rating:** 5.0/5.0 stars

_— Protiva B._

[Read full review](https://www.g2.com/survey_responses/decyfir-by-cyfirma-review-13085063)

**["Decyfir Streamlines Threat Analysis with Clear Incident Views and Relevant Filtering"](https://www.g2.com/survey_responses/decyfir-by-cyfirma-review-13077182)**

**Rating:** 5.0/5.0 stars

_— Surbhi S._

[Read full review](https://www.g2.com/survey_responses/decyfir-by-cyfirma-review-13077182)

### [ThreatMon](https://www.g2.com/products/threatmon/reviews)

ThreatMon is an AI-powered cyber risk intelligence platform designed to assist organizations in detecting, analyzing, and responding to external cyber threats that may impact their digital assets, brand reputation, and third-party ecosystem. This comprehensive solution provides real-time visibility into an organization’s attack surface exposure, the evolving threat landscape, and overall cyber risk posture, all accessible from a single, unified platform. The platform is particularly beneficial for security and risk management teams who require a holistic view of their cyber environment. ThreatMon integrates various functionalities including attack surface management, threat intelligence, dark web monitoring, fraud detection, surface web monitoring, and supply chain risk intelligence. This integration eliminates the need for multiple, disconnected tools, streamlining the process of threat detection and risk assessment. By consolidating these capabilities, ThreatMon allows organizations to efficiently manage their cyber risk landscape while reducing operational complexity. Key features of ThreatMon include the ability to discover exposed assets, detect phishing attempts, monitor for brand impersonation, and track leaked credentials and data breaches. Additionally, it provides insights into threat actors and assesses vendor and third-party risks, which is crucial for organizations that rely on a complex ecosystem of partners and suppliers. The platform’s built-in governance, risk, and compliance (GRC) capabilities further enhance its utility by mapping compliance requirements and generating executive-level reports. This functionality translates technical findings into actionable business-level insights, enabling stakeholders to make informed decisions regarding their cyber risk management strategies. By unifying external exposure monitoring, threat intelligence, fraud detection, supply chain risk visibility, and governance-level reporting, ThreatMon empowers both security operations teams and executives to understand, prioritize, and respond to cyber risks more effectively. This shift from fragmented, reactive security measures to a proactive, intelligence-driven approach allows organizations to better safeguard their assets and maintain their reputation in an increasingly complex digital landscape. With ThreatMon, organizations can enhance their overall security posture and foster a culture of proactive risk management, ensuring they remain resilient against evolving cyber threats.

**Average Rating:** 4.9/5.0

**Total Reviews:** 26

#### How Do G2 Users Rate ThreatMon?

- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.2/10)
- **Reporting:** 9.8/10 (Category avg: 8.8/10)
- **Vulnerability Intelligence:** 10.0/10 (Category avg: 8.7/10)
- **Risk-Prioritization:** 9.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind ThreatMon?

- **Seller:** [ThreatMon](https://www.g2.com/sellers/threatmon)
- **Company Website:** threatmon.io
- **Year Founded:** 2022
- **HQ Location:** Sterling VA
- **Twitter:** @MonThreat  
17,241 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c28b55c352d0fbfbd688afb38e84a36ab05a74dd9e1e19f39acda6031fb830de&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fthreatmon%2F&secure%5Burl_type%5D=linkedin_company_website)  
38 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 38% Medium, 38% Large

#### What Do G2 Reviewers Say About ThreatMon?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **advanced risk scoring system** of ThreatMon, enabling effective prioritization and actionable insights on threats.
- Users value the **reliable threat intelligence** of ThreatMon, enhancing security through proactive threat detection and analysis.
- Users value the **advanced cybersecurity measures** of ThreatMon, enhancing their protection with real-time monitoring and AI insights.
- Users value the **real-time notifications** from ThreatMon, ensuring they stay ahead of potential security threats effectively.
- Users value the **comprehensive security protection** from ThreatMon, enhancing confidence through proactive threat detection and notifications.

##### Cons

- Users find the **amount of threat data overwhelming** , making the Mobile Application Monitoring Module less understandable at times.
- Users note the need for more **customization options** in reporting features to better suit their specific requirements.
- Users find the **excessive notifications** from ThreatMon can create unnecessary work during initial data collection.
- Users feel the **lack of customization** in reporting features limits their ability to tailor outputs to specific needs.
- Users desire more **customization options for reporting features** to enhance functionality and user experience in ThreatMon.

#### What Are Recent G2 Reviews of ThreatMon?

**["Extremely efficient platform for managing vulnerabilities, threat intelligence and attack surface"](https://www.g2.com/survey_responses/threatmon-review-11623161)**

**Rating:** 5.0/5.0 stars

_— Mario P._

[Read full review](https://www.g2.com/survey_responses/threatmon-review-11623161)

**["ThreatMon Review: External Attack Surface Monitoring and Threat Intelligence Platform"](https://www.g2.com/survey_responses/threatmon-review-12551412)**

**Rating:** 5.0/5.0 stars

_— Aarón David E._

[Read full review](https://www.g2.com/survey_responses/threatmon-review-12551412)

- [&lsaquo; Prev‹ Prev](/categories/risk-based-vulnerability-management?order=g2_score&post_lead_product=tenable-sc#product-list)
- [1](/categories/risk-based-vulnerability-management?order=g2_score&post_lead_product=tenable-sc#product-list)
- 2
- [3](/categories/risk-based-vulnerability-management?order=g2_score&page=3&post_lead_product=tenable-sc#product-list)
- [4](/categories/risk-based-vulnerability-management?order=g2_score&page=4&post_lead_product=tenable-sc#product-list)
- [5](/categories/risk-based-vulnerability-management?order=g2_score&page=5&post_lead_product=tenable-sc#product-list)
- [6](/categories/risk-based-vulnerability-management?order=g2_score&page=6&post_lead_product=tenable-sc#product-list)
- …
- [12](/categories/risk-based-vulnerability-management?order=g2_score&page=12&post_lead_product=tenable-sc#product-list)
- [13](/categories/risk-based-vulnerability-management?order=g2_score&page=13&post_lead_product=tenable-sc#product-list)
- [Next &rsaquo;Next ›](/categories/risk-based-vulnerability-management?order=g2_score&page=3&post_lead_product=tenable-sc#product-list)

Spotlight Categories

[Social Media Listening Tools](https://www.g2.com/categories/social-media-listening-tools)

[Analytics Platforms](https://www.g2.com/categories/analytics-platforms)

[Virtual Data Room Software](https://www.g2.com/categories/virtual-data-room-vdr)

[Sales Tax and VAT Compliance Software](https://www.g2.com/categories/sales-tax-and-vat-compliance)

[Loyalty Management Software](https://www.g2.com/categories/loyalty-management)

Similar Categories

- [Attack Surface Management](/categories/attack-surface-management)
- [Cybersecurity Professional Development](/categories/cybersecurity-professional-development)

- [Exposure Management Platforms](/categories/exposure-management-platforms)
- [Patch Management](/categories/patch-management)

- [Secure Code Training](/categories/secure-code-training)
- [Security Awareness Training](/categories/security-awareness-training)

[Browse Risk-Based Vulnerability Management Themes](/categories/risk-based-vulnerability-management/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Risk-based vulnerability management software is used to identify and prioritize vulnerabilities based on customizable risk factors. These tools are more advanced than traditional vulnerability management solutions, as they assist in the prioritization of issues and execution of remedies based on the results of machine learning algorithms.

Companies use risk-based vulnerability management solutions to analyze entire organizations’ IT systems, cloud services, and/or applications and identify priorities. Instead of manually identifying vulnerabilities and remediating them in order of discovery, an organization can automate that process to remediate vulnerabilities impacting critical business components first. From there, they can address issues as the system has ordered by impact and remediation time. Companies can customize these priorities as they see fit by weighing risk factors differently.

Risk-based vulnerability management solutions are primarily used by IT professionals and security staff. These teams will integrate system and application information, outline priorities, and analyze assets. Automation within these tools saves significant time; furthermore, addressing critical vulnerabilities first can significantly reduce the likelihood of security incidents, failover, and data loss.

There is some overlap between risk-based vulnerability management solutions and [security risk analysis software](https://www.g2.com/categories/security-risk-analysis), but there are a few key differences. Security risk analysis tools provide similar capabilities in identifying vulnerabilities and other security risks. But security risk analysis tools, aside from a few outlier products, will not utilize machine learning and automation to assist in the prioritization and execution of vulnerability remediation.

To qualify for inclusion in the Risk-Based Vulnerability Management category, a product must:

- Integrate threat intelligence and contextual data for analysis
- Analyze applications, networks, and cloud services for vulnerabilities
- Utilize risk factors and machine learning to prioritize vulnerabilities

Show More