Best Risk-Based Vulnerability Management Software - Page 3

How Many Risk-Based Vulnerability Management Software Products Does G2 Track?

Total Products under this Category: 215

Category Stats (Sep 2026)

  • Average Rating: 4.5/5 (↓0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Ethiack (+0.86%) - Among all products in this category, Ethiack recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Risk-Based Vulnerability Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 215+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Risk-Based Vulnerability Management Software

G2 Grid® for Risk-Based Vulnerability Management Software plotting products by satisfaction and market presence

Highlighted products: Ivanti Autonomous Endpoint Management, Arctic Wolf, Tenable Vulnerability Management, RiskProfiler - External Threat Exposure Management, YesWeHack, Check Point Exposure Management, H1 Platform, and Pentera.

Underlying data: [Grid® JSON](https://www.g2.com/categories/risk-based-vulnerability-management/grids.json?focus%5B%5D=ivanti-autonomous-endpoint-management&focus%5B%5D=arctic-wolf&focus%5B%5D=tenable-vulnerability-management&focus%5B%5D=riskprofiler-external-threat-exposure-management&focus%5B%5D=yeswehack&focus%5B%5D=check-point-exposure-management&focus%5B%5D=h1-platform&focus%5B%5D=pentera)

ThreatMon

ThreatMon is an AI-powered end-to-end cyber risk intelligence platform designed to assist organizations in identifying, analyzing, prioritizing, and responding to external cyber risks within their digital ecosystems. This comprehensive solution caters to security operations, threat intelligence, risk management, and executive teams, offering continuous visibility into exposed assets, emerging threats, threat actors, compromised data, and third-party risks from a unified environment. As a robust cyber risk intelligence platform, ThreatMon combines various capabilities to provide organizations with a thorough understanding of their external exposure and the evolving threat landscape. By collecting and analyzing threat data, the platform supports proactive risk identification, enabling informed security decisions that are crucial in today’s complex digital environment. This proactive approach is essential for organizations aiming to stay ahead of potential cyber threats and vulnerabilities. Key features of ThreatMon include Attack Surface Intelligence, which allows users to discover and monitor internet-facing assets, exposures, and vulnerabilities. Additionally, the platform offers Cyber Threat Intelligence and Dark Web Intelligence, enabling organizations to track threat actors, emerging threats, leaked credentials, and compromised data. Fraud Intelligence capabilities help identify phishing attempts, brand impersonation, and other external fraud-related risks, while Supply Chain Risk Management focuses on monitoring cyber risks associated with vendors and third-party ecosystems. The AI-driven analysis, risk prioritization, dashboards, alerts, and reporting features empower teams to transform complex threat data into actionable intelligence. By integrating these capabilities, ThreatMon provides security teams with a consolidated view of external cyber risks, reducing reliance on fragmented tools and enhancing operational efficiency. Continuous monitoring and contextual intelligence facilitate the identification of relevant threats, the investigation of exposures, and the prioritization of risks based on their potential impact. Furthermore, ThreatMon aids technical security teams in effectively communicating risk information to decision-makers through structured insights, dashboards, and reporting. This comprehensive visibility across the digital environment supports risk-based decision-making and fosters a more proactive, intelligence-driven approach to cyber risk management.

Average Rating: 4.9/5.0

Total Reviews: 27

How Do G2 Users Rate ThreatMon?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Reporting: 9.8/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.5/10 (Category avg: 8.8/10)

Who Is the Company Behind ThreatMon?

  • Seller: ThreatMon
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Sterling VA
  • Twitter: @MonThreat
    17,241 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    43 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 41% Large, 37% Medium

What Do G2 Reviewers Say About ThreatMon?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the real-time monitoring capabilities of ThreatMon, enabling proactive management of cybersecurity threats and vulnerabilities.
  • Users value the advanced threat detection capabilities of ThreatMon, offering actionable insights and early warnings.
  • Users find ThreatMon incredibly easy to use, streamlining configuration and management with user-friendly dashboards and reports.
  • Users commend the detailed analysis of ThreatMon, enabling proactive identification of vulnerabilities and informed threat prioritization.
  • Users value the reliable threat intelligence of ThreatMon, enhancing security through proactive threat detection and response.
Cons
  • Users find the excessive notifications from ThreatMon create unnecessary work and can be overwhelming initially.
  • Users find the threat data overwhelming, making it challenging to effectively manage and understand the Mobile Application Monitoring Module.
  • Users find the limited reporting features restrictive, desiring more customization and clarity for specific needs.
  • Users find the inefficient alerts from ThreatMon create unnecessary work and can be challenging to manage.
  • Users face challenges with the inefficient alert system, finding too many alerts create unnecessary work and confusion.

What Are Recent G2 Reviews of ThreatMon?

AI-Native Continuous Offensive Security Platform

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

Average Rating: 4.5/5.0

Total Reviews: 98

How Do G2 Users Rate AI-Native Continuous Offensive Security Platform?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Reporting: 8.7/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind AI-Native Continuous Offensive Security Platform?

  • Seller: Ridge Security Technology
  • Company Website:
  • Year Founded: 2020
  • HQ Location: Santa Clara, California
  • Twitter: @RidgeSecurityAI
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    49 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Small, 45% Medium

What Do G2 Reviewers Say About AI-Native Continuous Offensive Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the automation capabilities of RidgeBot, streamlining penetration testing and providing accurate vulnerability assessments efficiently.
  • Users appreciate the ease of use of the AI-Native Continuous Offensive Security Platform for streamlined penetration testing.
  • Users commend the pentesting efficiency of RidgeBot, automating tests and validating vulnerabilities seamlessly to save time.
  • Users appreciate the automated vulnerability identification of RidgeBot, which effectively validates risks and streamlines security processes.
  • Users value the efficiency of RidgeBot, as it automates testing to save time and enhance security processes.
Cons
  • Users find RidgeBot's setup to be complex and challenging, particularly in customized or legacy system environments.
  • Users find the complex setup challenging, especially due to limited documentation and support for new admins.
  • Users find the missing features such as improved API testing and customizable reporting templates quite limiting.
  • Users find the poor customer support challenging, as documentation is often lacking for troubleshooting issues.
  • Users find the poor documentation challenging, making initial setup and onboarding confusing for new admins.

What Are Recent G2 Reviews of AI-Native Continuous Offensive Security Platform?

DefenseStorm

DefenseStorm is a comprehensive cybersecurity platform specifically designed for financial institutions, focusing on cyber risk assessment, governance, security, and fraud prevention. This integrated solution addresses the unique challenges that banks and other financial entities face in maintaining cyber risk readiness amidst a complex landscape of regulations and technological demands. The platform is tailored to meet the stringent requirements of the banking sector, making it a vital resource for organizations seeking to enhance their cybersecurity posture. DefenseStorm's intelligent data engine, known as GRID ACTIVE, plays a crucial role in this process by providing real-time access to critical threat data. This capability allows financial institutions to analyze and respond to potential threats swiftly, ensuring they remain vigilant against evolving cyber risks. Targeted at banks and financial service providers, DefenseStorm offers a range of use cases that are essential for maintaining compliance and safeguarding sensitive data. The platform not only helps institutions assess their current cyber risk levels but also provides governance tools that facilitate adherence to regulatory requirements. By integrating security measures with fraud detection capabilities, DefenseStorm enables organizations to create a robust defense against both internal and external threats. One of the standout features of DefenseStorm is its Cyber Threat Surveillance Operations (CTS Ops) team, which provides round-the-clock support. This managed service ensures that financial institutions have access to expert resources at all times, allowing them to leverage specialized knowledge and experience in combating cyber threats. The continuous monitoring and proactive threat management offered by the CTS Ops team enhance the overall security framework of the institution, providing peace of mind to stakeholders. Overall, DefenseStorm's unique focus on the banking sector, combined with its advanced data analytics and dedicated support services, positions it as a critical tool for financial institutions aiming to navigate the complexities of cybersecurity. By equipping organizations with the necessary tools and expertise, DefenseStorm helps them not only to meet regulatory obligations but also to foster a culture of security that is essential in today's digital landscape.

Average Rating: 4.8/5.0

Total Reviews: 30

How Do G2 Users Rate DefenseStorm?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.2/10)
  • Reporting: 8.8/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 7.7/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind DefenseStorm?

  • Seller: DEFENSESTORM
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Alpharetta, Georgia
  • LinkedIn® Page: www.linkedin.com
    85 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Banking, Financial Services
  • Company Size: 80% Medium, 20% Small

What Do G2 Reviewers Say About DefenseStorm?

AI-generated summary from verified user reviews

Pros
  • Users commend the exceptional customer support from DefenseStorm, highlighting their responsiveness and expertise in meeting needs.
  • Users value the exceptional support team at DefenseStorm, praising their friendliness, knowledge, and availability 24/7.
  • Users appreciate the ease of use of DefenseStorm, benefiting from intuitive solutions and responsive support.
  • Users praise the expertise and support of DefenseStorm staff, enhancing collaboration and customer satisfaction throughout the experience.
  • Users value the 24/7 alert notifications from DefenseStorm, providing peace of mind and proactive issue management.
Cons
  • Users find difficult navigation in DefenseStorm, struggling to synthesize detailed information into clear executive summaries.
  • Users find the lack of clear training materials a hurdle in fully utilizing DefenseStorm's features effectively.
  • Users find the manual asset management system cumbersome, impacting the overall reliability of DefenseStorm's offerings.
  • Users find the difficult organization of DefenseStorm's dashboards hinders effective executive reporting and summary interpretation.
  • Users find inadequate reporting in DefenseStorm, struggling to extract clear executive summaries from complex dashboards.

What Are Recent G2 Reviews of DefenseStorm?

CloudBees

The Complete DevOps solution. CloudBees empowers your software delivery teams to transform your business. CloudBees solution brings together development, operations, IT, security, and business teams to: Create fast with scalable repeatable workflows. Continuously improve customer experiences by progressively delivering features with speed and control. Command everything with higher-order visibility, management, and intelligence across tools, teams, pipelines, and process... all at enterprise scale.

Average Rating: 4.4/5.0

Total Reviews: 591

How Do G2 Users Rate CloudBees?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.2/10)
  • Reporting: 9.6/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.8/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind CloudBees?

  • Seller: CloudBees
  • Company Website:
  • Year Founded: 2010
  • HQ Location: San Jose, CA
  • Twitter: @CloudBees
    39,175 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    485 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, DevOps Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 48% Large, 41% Medium

What Do G2 Reviewers Say About CloudBees?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the centralized management and robust security of CloudBees, enhancing their CI/CD lifecycle and workflows.
  • Users value the reliability of CloudBees, benefiting from its scalable tools and robust security in CI/CD processes.
  • Users value the customization options of CloudBees, enhancing integration and efficiency across various tools and workflows.
  • Users find CloudBees' ease of use exceptional, enabling seamless integration and efficient workflow management across teams.
  • Users value the seamless integrations of CloudBees with major DevOps tools, enhancing workflow automation and efficiency.
Cons
  • Users struggle with the complex interface of CloudBees, making understanding and configuration quite challenging.
  • Users face complexity in understanding and configuration of CloudBees, requiring significant time and specialized expertise.
  • Users find the complex setup of CloudBees time-consuming and difficult to navigate, requiring specialized expertise.
  • Users find the complex user interface of CloudBees challenging, complicating understanding and configuration processes.
  • Users face configuration issues with CloudBees, finding it complex and time-consuming to manage effectively.

What Are Recent G2 Reviews of CloudBees?

What Are G2 Users Discussing About CloudBees?

Strobes Security

Strobes is an AI-driven exposure management platform designed to help organizations streamline their security operations by unifying various security methodologies, including Attack Surface Management (ASM), Application Security Posture Management (ASPM), Risk-Based Vulnerability Management (RBVM), and Penetration Testing as a Service (PTaaS). This comprehensive solution provides users with a holistic view of their security posture, enabling them to identify, assess, and respond to potential risks and vulnerabilities effectively. Targeted primarily at security teams and IT professionals, Strobes caters to organizations of all sizes that require a robust approach to managing their security exposure. The platform is particularly beneficial for those who need to navigate the complexities of modern security environments, where multiple tools and processes can lead to fragmented insights. By consolidating various security functions into a single workflow, Strobes empowers users to make informed decisions based on a complete understanding of their risk landscape. One of the key features of Strobes is its extensive integration capabilities, boasting over 120 integrations with existing security tools and systems. This allows organizations to pull findings from disparate sources into a single view, enriching data with contextual information that enhances the relevance of insights. The platform's advanced correlation capabilities help identify relationships between different vulnerabilities and risks, enabling security teams to prioritize their remediation efforts effectively. The user-friendly dashboards in Strobes serve as a central hub for monitoring security activities, encompassing everything from asset discovery and vulnerability insights to Service Level Agreement (SLA) tracking and ticketing. This comprehensive visibility supports continuous prioritization and fix validation, allowing teams to address the most critical issues first. By automating triage processes, Strobes ensures that real risks and exposures are highlighted, facilitating a more efficient response to potential threats. Overall, Strobes stands out in the exposure management landscape by providing a cohesive and intelligent approach to security management. Its ability to unify various methodologies, coupled with powerful automation and integration features, positions it as a valuable tool for organizations seeking to enhance their security posture and effectively manage their exposure to risks.

Average Rating: 4.6/5.0

Total Reviews: 34

How Do G2 Users Rate Strobes Security?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Strobes Security?

  • Seller: Strobes Security Inc
  • Company Website:
  • Year Founded: 2019
  • HQ Location: Plano, US
  • Twitter: @StrobesHQ
    218 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    97 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 37% Large, 37% Medium

What Do G2 Reviewers Say About Strobes Security?

AI-generated summary from verified user reviews

Pros
  • Users commend Strobes Security for its thorough vulnerability identification, providing detailed insights and actionable solutions for fixes.
  • Users commend Strobes Security for its thorough vulnerability detection that enhances security and streamlines management processes.
  • Users highlight the exceptional security identification features of Strobes, improving vulnerability management and operational efficiency.
  • Users commend the proactive support from Strobes Security, ensuring quick resolutions and excellent follow-up on issues.
  • Users commend the ease of use of Strobes Security, highlighting its intuitive interface and efficient workflows.
Cons
  • Users criticize the inadequate reporting in Strobes Security, citing lack of detail and flexibility for effective analysis.
  • Users find limited customization options frustrating, particularly during the initial workflow setup and dashboard clarity improvements.
  • Users report poor usability in Strobes Security due to a steep learning curve and challenging navigation.
  • Users express concerns about the lack of transparency and flexibility in reporting, hindering effective analysis and customization.
  • Users find the UI complex and experience a learning curve, especially when customizing workflows and integrations.

What Are Recent G2 Reviews of Strobes Security?

Palo Alto Cortex XSIAM

Product Description: Palo Alto Networks' Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.

Average Rating: 4.5/5.0

Total Reviews: 96

How Do G2 Users Rate Palo Alto Cortex XSIAM?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.2/10)
  • Reporting: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Palo Alto Cortex XSIAM?

  • Seller: Palo Alto Networks
  • Company Website:
  • Year Founded: 2005
  • HQ Location: Santa Clara, CA
  • Twitter: @PaloAltoNtwks
    128,951 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,492 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 40% Large, 36% Medium

What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

AI-generated summary from verified user reviews

Pros
  • Users value the best-in-class log management of Palo Alto Cortex XSIAM, benefiting from its effective alerting and integration features.
  • Users find the user-friendly dashboard of Palo Alto Cortex XSIAM essential for monitoring and understanding alerts effectively.
  • Users value the real-time monitoring capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency.
  • Users value the simple and user-friendly interface of Palo Alto Cortex XSIAM, making monitoring effortless.
  • Users value the good dashboard creation tools in Palo Alto Cortex XSIAM, enhancing ease of use and implementation.
Cons
  • Users note that Palo Alto Cortex XSIAM requires significant resources, impacting implementation time and increasing infrastructure costs.
  • Users find the complexity of implementation for Palo Alto Cortex XSIAM to be time-consuming and resource-intensive.
  • Users find the cost of Palo Alto Cortex XSIAM to be high, especially for smaller businesses.
  • Users face dashboard issues with XSIAM, finding it difficult to monitor assets and navigate the interface.
  • Users face difficult setup issues with Palo Alto Cortex XSIAM, requiring expertise and extensive time for initial implementation.

What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

Fortra VM

Fortra VM is a proactive, risk-based vulnerability management solution that helps organizations identify, assess, and prioritize security weaknesses across their infrastructure. Beyond basic scanning, Fortra VM provides contextual risk prioritization through its Security GPA rating system, Peer Insight for industry benchmarking, and threat ranking to identify exploitation vectors that are used in real world attacks. Conveniently delivered via SAAS, Fortra VM creates easily understood reporting for efficient and effective remediation.

Average Rating: 4.3/5.0

Total Reviews: 67

How Do G2 Users Rate Fortra VM?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.2/10)
  • Reporting: 8.6/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.6/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Fortra VM?

  • Seller: Fortra
  • Year Founded: 1982
  • HQ Location: Eden Prairie, Minnesota
  • Twitter: @fortraofficial
    2,773 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,784 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Banking
  • Company Size: 45% Medium, 35% Small

What Do G2 Reviewers Say About Fortra VM?

AI-generated summary from verified user reviews

Pros
  • Users find Fortra VM to be highly reliable, providing great value and effective security vulnerability assessments over the years.
  • Users are thrilled with Fortra VM, particularly praising its excellent customer support since its lightweight usage began in 2020.
  • Users value the data security of Fortra VM, using it effectively for vulnerability assessments and remediation planning.
  • Users find Fortra VM easy to use, appreciating its lightweight design and excellent customer support.
  • Users appreciate the incident management capabilities of Fortra VM, effectively addressing vulnerabilities and enhancing security posture.

What Are Recent G2 Reviews of Fortra VM?

What Are G2 Users Discussing About Fortra VM?

Saner CVEM

Prevention-first Vulnerability and Exposure Management for unified visibility, prioritization, compliance, and remediation Saner Continuous Vulnerability and Exposure Management unifies asset exposure, posture anomaly detection, vulnerability assessment, compliance management, risk prioritization, patching, and endpoint actions in one dashboard. Saner CVEM is built to help teams continuously detect, assess, prioritize, and remediate vulnerabilities and other security risks from a unified console Why Choose Saner CVEM? • Unified dashboard with interactive views across visibility, detection, prioritization, and remediation for a single source of truth • Complete asset visibility across endpoint and non-endpoint devices, operating system applications, third-party applications, and lifecycle changes • Continuous risk discovery with rapid scans, daily-updated risk intelligence, and posture anomaly detection that helps surface outliers and misconfigurations faster • Context-driven prioritization with SSVC categories such as Act, Attend, Track, and Track* so teams can focus on the risks that deserve action first. • Continuous compliance management with built-in templates, customizable profiles, daily checks, and deviation tracking across common frameworks. • Integrated patching and remediation with vulnerability-to-patch mapping, automated deployment workflows, and endpoint actions from the same ecosystem. • Machine-learning-assisted analysis to identify deeper risk patterns, detect unusual posture, and support smarter remediation decisions. • Customizable, audit-ready reporting for security, IT, and compliance teams that need clearer evidence and easier tracking. • Flexible deployment on cloud or on-premises, with remediation support across Windows, Linux, macOS, and AIX environments.

Average Rating: 4.5/5.0

Total Reviews: 72

How Do G2 Users Rate Saner CVEM?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.2/10)
  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.4/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Saner CVEM?

  • Seller: SecPod
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Redwood City, California
  • Twitter: @secpod
    542 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 41% Small, 38% Medium

What Do G2 Reviewers Say About Saner CVEM?

AI-generated summary from verified user reviews

Pros
  • Users value the automatic security updates from Saner CVEM, ensuring timely compliance for remote workforce systems.
  • Users appreciate the advanced automation features of Saner CVEM, streamlining security patch management for remote systems.
  • Users value the seamless integrations of Saner CVEM, enhancing operational efficiency and strengthening digital security across IT processes.
  • Users value the automated compliance management of Saner CVEM, enhancing efficiency and reducing manual intervention significantly.
  • Users highlight the exceptional customer support from Saner CVEM, enhancing security and helping organizations stay protected.
Cons
  • Users often face integration issues with Saner CVEM, leading to frustrations during setup and ongoing maintenance.
  • Users note limited features in Saner CVEM, especially in multi-tenant support and integration capabilities, impacting efficiency.
  • Users experience slow performance when loading large data sets and during initial setup, affecting usability.
  • Users experience slow scanning, especially with initial dashboard load times and large data sets affecting daily checks.
  • Users find the limited cloud integration challenging, requiring workarounds and custom scripts for effective use.

What Are Recent G2 Reviews of Saner CVEM?

What Are G2 Users Discussing About Saner CVEM?

Ethiack

Ethiack is an autonomous offensive security platform that continuously tests and validates vulnerability exploitation across entire attack surfaces using agentic AI pentesting and hacker intelligence so security teams fix what matters before attackers strike. Traditional pentests give you a snapshot. Ethiack runs 24/7, combining agentic AI pentesting and human hacker intelligence to validate real-world risks with near-zero false positives. Stop triaging scanner noise. Know what attackers can actually exploit, right now. What you get: - Continuous Adversarial Exposure Validation (AEV) - 99.5% precision on exploitable vulnerabilities - 90% noise reduction - 80% faster remediation (MTTR) - <10 min setup, no installation required - Coverage across +200 vulnerability classes and +1500 technologies - Proof-of-exploit for every validated risk

Average Rating: 4.5/5.0

Total Reviews: 15

How Do G2 Users Rate Ethiack?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.5/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Ethiack?

  • Seller: Ethiack
  • Year Founded: 2022
  • HQ Location: Coimbra, Coimbra, Portugal
  • LinkedIn® Page: www.linkedin.com
    56 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 40% Medium, 33% Small

What Do G2 Reviewers Say About Ethiack?

AI-generated summary from verified user reviews

Pros
  • Users commend Ethiack for its outstanding customer support, which enhances their experience and improves security efforts.
  • Users value the exceptional cybersecurity services of Ethiack, greatly enhancing platform security through continuous insights and manual pentesting.
  • Users appreciate the continuous innovation of Ethiack, significantly enhancing platform security and integration in daily operations.
  • Users value the automation capabilities of Ethiack, enhancing efficiency in vulnerability discovery and protection against threats.
  • Users value the real-time monitoring capabilities of Ethiack, enhancing platform security and integrating it into daily operations.
Cons
  • Users criticize the high costs of Ethiack, making it challenging to scale testing for essential assets.
  • Users find the high cost of Ethiack challenging, hindering the ability to scale testing effectively.
  • Users are frustrated by the lack of automation to schedule scans, limiting efficiency and convenience.
  • Users feel that the limited features in Ethiack may lack maturity and reliability due to constant updates.
  • Users note the lack of essential security features in Ethiack, impacting API-based application safety.

What Are Recent G2 Reviews of Ethiack?

Cyrisma

Cyrisma helps MSPs and MSSPs turn cyber risk and compliance into revenue. Its unified platform combines vulnerability management, data and asset discovery, compliance tracking, secure configuration, and dark web monitoring into one continuous experience - enabling partners to identify, prioritize, and remediate cyber risk efficiently. With executive-ready reporting, risk monetization insights, and elegant visuals, Cyrisma helps MSPs demonstrate measurable value, strengthen client relationships, and scale their security services profitably.

Average Rating: 4.6/5.0

Total Reviews: 60

How Do G2 Users Rate Cyrisma?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Reporting: 8.2/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.8/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind Cyrisma?

  • Seller: Cyrisma
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Rochester, NY
  • Twitter: @Cyrisma_USA
    43 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 75% Small, 22% Medium

What Do G2 Reviewers Say About Cyrisma?

AI-generated summary from verified user reviews

Pros
  • Users value the time-saving integration of Cyrisma, streamlining cybersecurity processes and enhancing overall efficiency.
  • Users value the ease of use of Cyrisma, benefiting from its intuitive interface and seamless integration.
  • Users value the fantastic customer support from Cyrisma, noting its helpfulness and product improvement initiatives.
  • Users value the actionable vulnerability intelligence and integrated patch management features of Cyrisma for efficiency and effectiveness.
  • Users appreciate CYRISMA for its actionable vulnerability intelligence, making it easy to identify and address critical security issues.
Cons
  • Users find a lack of essential features, particularly in UI navigation, data correlation, and patch management capabilities.
  • Users find Cyrisma to be not user-friendly, struggling with navigation, deployment, and overall support for their needs.
  • Users face integration issues with Cyrisma, including broken data scans and delayed API functionality for automation.
  • Users report limited flexibility in Cyrisma, especially with data scanning and agent deployment, hindering efficiency.
  • Users express frustration with the poor customer support from Cyrisma, hindering their ability to effectively use the product.

What Are Recent G2 Reviews of Cyrisma?

Nucleus

Nucleus Security is a vulnerability and asset management solution that automates processes and workflows, enabling organizations to mitigate vulnerabilities 10 times faster, using a fraction of the resources that it takes to perform these tasks today. Nucleus aggregates, cleans, correlates, and analyzes data from all sources of asset and vulnerability data and organizes it into a logical hierarchy. Once the data is organized, Nucleus streamlines operational processes with efficient workflows and time-saving automation that accelerate vulnerability management and response.

Average Rating: 4.5/5.0

Total Reviews: 31

How Do G2 Users Rate Nucleus?

  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 9.2/10)
  • Reporting: 8.5/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.2/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Nucleus?

  • Seller: Nucleus Security, Inc
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Sarasota, Florida
  • Twitter: @nucleussec
    565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    129 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Airlines/Aviation, Computer & Network Security
  • Company Size: 53% Large, 38% Medium

What Do G2 Reviewers Say About Nucleus?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the streamlined automation in Nucleus, significantly enhancing efficiency and minimizing manual intervention in reporting tasks.
  • Users value the customization options in Nucleus, enhancing reporting efficiency and user experience significantly.
  • Users appreciate the dashboard customization of Nucleus, which enhances reporting efficiency and simplifies risk management tasks.
  • Users appreciate the advanced dashboard of Nucleus, enhancing reporting efficiency and streamlining risk prioritization efforts.
  • Users find the dashboard usability of Nucleus to be efficient and powerful for streamlined reporting and risk management.
Cons
  • Users note the need for improved remediation capabilities to address critical vulnerabilities more effectively in Nucleus.

What Are Recent G2 Reviews of Nucleus?

Flashpoint

Flashpoint is the largest privately held threat intelligence provider, enabling mission-critical organizations to proactively confront security challenges globally. Flashpoint Ignite, our unified threat intelligence platform, harnesses the power of primary-source collections, curated human insight, and artificial intelligence to deliver decisive action against a comprehensive range of critical threats. Core Capabilities: → Identify and remediate cyber threats, fraud, vulnerabilities, physical security, and national security risks. → Access over 3.6 petabytes of continuously collected data from the internet’s open and difficult-to-access spaces. Add new channels and data sources in minutes to track sources as they surface. → Operationalize intelligence across your entire security stack with seamless integrations throughout the intelligence lifecycle.

Average Rating: 4.5/5.0

Total Reviews: 82

How Do G2 Users Rate Flashpoint?

  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 9.2/10)
  • Reporting: 8.3/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 7.5/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 7.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Flashpoint?

Who Uses This Product?

  • Top Industries: Financial Services, Security and Investigations
  • Company Size: 64% Large, 23% Small

What Do G2 Reviewers Say About Flashpoint?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Flashpoint, highlighting its intuitive navigation and quick deployment for teams.
  • Users appreciate the raw, actionable threat actor visibility provided by Flashpoint, enhancing proactive fraud detection.
  • Users appreciate the impressive quality of data and advanced filtering options that enhance their research experience.
  • Users appreciate the extensive data collection of Flashpoint, benefiting from streamlined searches and rich actionable insights.
  • Users value Flashpoint's efficient search functionality, enabling easy access to relevant data from various channels.
Cons
  • Users express frustration over the lack of features in Flashpoint, impacting efficiency and integration capabilities.
  • Users find the complexity of the query system in Flashpoint makes navigation and alert customization challenging.
  • The confusing interface of Flashpoint can hinder user experience, especially with navigation and alert management.
  • Users find some features limited and under-developed, especially in investigation and customization options.
  • Users experience frustration with Flashpoint due to confusing queries and noisy alerts that complicate their workflow.

What Are Recent G2 Reviews of Flashpoint?

What Are G2 Users Discussing About Flashpoint?

VulScan

Automated Vulnerability Scanning. Affordably Priced For Everyone! With almost 70 new hidden vulnerabilities identified every day, you would need to be a super hero with X-ray vision to find them all. Or, you can let VulScan do it for you. VulScan is purpose-built for MSPs and for IT Departments that handle their own IT security. It has all the features you need for both internal and external vulnerability management, but without all the complexity found in older solutions. Best of all, VulScan is priced so that cost is no longer a barrier to scanning as many assets as you need, as frequently as you want. That’s why our slogan is “Vulnerability Management For The Rest of Us! VulScan is an affordable cloud-based vulnerability management platform. It includes the software needed to spin up an unlimited number of virtual network scanner appliances using Hyper-V or VMWare, and a cloud-based portal to control the scanners and manage the discovered issues. For internal network scanning, the appliances can be installed on any existing computer that has excess capacity on the network, or installed on a dedicated box to be permanently installed. You can add multiple scanners and configure them each to scan separate parts of the network to get even faster results pushed into the same client site dashboard at no additional cost. For external scanning, the appliances are installed on the MSP’s data center or other remote location and “pointed” to the public facing IP addresses of the target network.

Average Rating: 4.1/5.0

Total Reviews: 121

How Do G2 Users Rate VulScan?

  • Has the product been a good partner in doing business?: 8.2/10 (Category avg: 9.2/10)
  • Reporting: 7.2/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 7.6/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 7.5/10 (Category avg: 8.8/10)

Who Is the Company Behind VulScan?

  • Seller: Kaseya
  • Company Website:
  • Year Founded: 2000
  • HQ Location: Miami, FL
  • Twitter: @KaseyaCorp
    17,411 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,483 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 66% Small, 32% Medium

What Do G2 Reviewers Say About VulScan?

AI-generated summary from verified user reviews

Pros
  • Users find VulScan's ease of use exceptional, appreciating its simplicity in scheduling scans and generating reports.
  • Users appreciate the ease of reporting with VulScan, benefiting from automated scans and consolidated reports.
  • Users value the seamless integrations of VulScan, enhancing efficiency in documentation and vulnerability management.
  • Users appreciate the easy automated scanning of VulScan, simplifying network assessments and uncovering hidden vulnerabilities effectively.
Cons
  • Users are frustrated by the poor customer support from VulScan, facing difficulty in obtaining timely assistance.
  • Users find the difficult setup of VulScan to be a hindrance, requiring extensive configuration and proper hardware.

What Are Recent G2 Reviews of VulScan?

IBM QRadar EDR

IBM Security QRadar EDR (formerly ReaQta) combines automation and dashboards to minimize analyst workloads, detect anomalous endpoint behavior and remediate threats in near real time. IBM Security QRadar EDR is available on AWS Marketplace. With visibility across endpoints, it combines expected features, like MITRE ATT&CK mapping and attack visualizations, with dual-engine AI and automation. For teams that need extended support, managed detection and response (MDR) services offers 24/7 monitoring and response to help keep users protected. IBM Security QRadar EDR (formerly ReaQta) can be deployed as SaaS, on-premises and in air-gapped environments. For more information, visit https://www.ibm.com/products/qradar-edr

Average Rating: 4.2/5.0

Total Reviews: 45

How Do G2 Users Rate IBM QRadar EDR?

  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 9.2/10)
  • Reporting: 9.5/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind IBM QRadar EDR?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 45% Small, 40% Medium

What Do G2 Reviewers Say About IBM QRadar EDR?

AI-generated summary from verified user reviews

Pros
  • Users find the advanced threat detection of IBM QRadar EDR essential for maintaining system security and integrity.
  • Users appreciate the ease of use of IBM QRadar EDR, noting its simple installation and effective logging capabilities.
  • Users value the advanced threat detection and endpoint protection of IBM QRadar EDR, ensuring robust security and continuous updates.
  • Users praise the advanced threat detection capabilities of IBM QRadar EDR, enhancing security and responsiveness significantly.
  • Users value the robust threat detection of IBM QRadar EDR, enhancing security against cyber threats effectively.
Cons
  • Users find IBM QRadar EDR too expensive for small and mid-sized businesses, limiting accessibility and affordability.
  • Users find difficult learning due to initial setup challenges and a need for programming knowledge, complicating effective use.
  • Users find IBM QRadar EDR to be resource intensive, leading to increased costs and implementation challenges.
  • Users experience many false positives with QRadar EDR, requiring additional manual investigation and attention from the team.
  • Users experience high resource usage with IBM QRadar EDR, requiring powerful devices for optimal performance.

What Are Recent G2 Reviews of IBM QRadar EDR?

BugBase

BugBase is a Continuous Vulnerability Assessment Platform that conducts comprehensive security operations such as bug bounty programs and next-gen pentesting (VAPT) to assist startups and enterprises in effectively identifying, managing and mitigating vulnerabilities.

Average Rating: 4.5/5.0

Total Reviews: 45

How Do G2 Users Rate BugBase?

  • Has the product been a good partner in doing business?: 9.5/10 (Category avg: 9.2/10)
  • Reporting: 9.1/10 (Category avg: 8.8/10)
  • Vulnerability Intelligence: 9.2/10 (Category avg: 8.7/10)
  • Risk-Prioritization: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind BugBase?

  • Seller: BugBase
  • Year Founded: 2021
  • HQ Location: Singapore, US
  • Twitter: @BugBase
    1,673 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    43 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Computer Software
  • Company Size: 60% Small, 21% Large

What Do G2 Reviewers Say About BugBase?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the user-friendly interface of BugBase, making it ideal for new bug bounty hunters.
  • Users appreciate the simple and user-friendly interface of BugBase, making it ideal for new bug bounty hunters.
  • Users value the enhanced cybersecurity of BugBase, benefiting from secure bounty programs and robust vulnerability detection.
  • Users value the user-friendly interface and powerful features of BugBase, enhancing security and project efficiency.
  • Users value the easy integrations of BugBase, simplifying workflows and enhancing security across various tools and technologies.
Cons
  • Users experience slow performance on BugBase, facing lagging issues and delayed support responses that hinder their productivity.
  • Users feel that BugBase is expensive and lacks competitive pricing compared to other bug bounty platforms.
  • Users find the difficult setup of BugBase challenging, particularly for those lacking technical expertise in vulnerability assessment.
  • Users face a steep learning curve with BugBase, which can hinder the experience for those new to bug bounty programs.
  • Users report poor customer support with BugBase, causing frustration and hindering their bug hunting experience.

What Are Recent G2 Reviews of BugBase?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024