Top Free Vulnerability Scanner Software - Page 3

How Many Vulnerability Scanner Software Products Does G2 Track?

Total Products under this Category: 235

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Armis (+0.18%) - Among all products in this category, Armis recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Vulnerability Scanner Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 7,900+ Authentic Reviews
  • 235+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Vulnerability Scanner Software

G2 Grid® for Vulnerability Scanner Software plotting products by satisfaction and market presence

Highlighted products: Wiz, Aikido Security, CrowdStrike Falcon Cloud Security, Tenable Nessus, Orca Security, Astra Pentest, Intruder, and Burp Suite.

Underlying data: [Grid® JSON](https://www.g2.com/categories/vulnerability-scanner/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=tenable-nessus&focus%5B%5D=orca-security&focus%5B%5D=astra-pentest&focus%5B%5D=intruder&focus%5B%5D=burp-suite)

StackHawk

StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate StackHawk?

  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.2/10)
  • Detection Rate: 8.7/10 (Category avg: 9.0/10)
  • Automated Scans: 8.7/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 5.3/10 (Category avg: 8.5/10)

Who Is the Company Behind StackHawk?

  • Seller: StackHawk
  • Year Founded: 2019
  • HQ Location: Denver, CO
  • Twitter: @StackHawk
    1,137 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 46% Small, 35% Medium

What Do G2 Reviewers Say About StackHawk?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of StackHawk, facilitating seamless setups with major CI tools and configurations.
  • Users praise the excellent customer support from StackHawk, highlighting their responsiveness and helpfulness in addressing queries.
  • Users value the customizability of StackHawk, appreciating its flexibility and integration options for unique workflows.
  • Users find that StackHawk greatly enhances efficiency, enabling quicker identification and resolution of security vulnerabilities.
  • Users commend StackHawk for its scanning efficiency, enabling quick identification of vulnerabilities and seamless CI/CD integration.
Cons
  • Users find the complex setup challenging, particularly with the YAML configurations and onboarding processes for applications.
  • Users find the high learning curve of StackHawk challenging due to its complex scripting and setup process.
  • Users find StackHawk lacking features, specifically in API management and vulnerability reproducibility, hindering its usability.
  • Users find the limited scope of StackHawk restricts functionality and automation in vulnerability management.
  • Users find the setup complexity of StackHawk frustrating due to YAML configuration and onboarding challenges.

What Are Recent G2 Reviews of StackHawk?

What Are G2 Users Discussing About StackHawk?

Cyrisma

Cyrisma helps MSPs and MSSPs turn cyber risk and compliance into revenue. Its unified platform combines vulnerability management, data and asset discovery, compliance tracking, secure configuration, and dark web monitoring into one continuous experience - enabling partners to identify, prioritize, and remediate cyber risk efficiently. With executive-ready reporting, risk monetization insights, and elegant visuals, Cyrisma helps MSPs demonstrate measurable value, strengthen client relationships, and scale their security services profitably.

Average Rating: 4.6/5.0

Total Reviews: 60

How Do G2 Users Rate Cyrisma?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Detection Rate: 8.7/10 (Category avg: 9.0/10)
  • Automated Scans: 8.7/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.9/10 (Category avg: 8.5/10)

Who Is the Company Behind Cyrisma?

  • Seller: Cyrisma
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Rochester, NY
  • Twitter: @Cyrisma_USA
    43 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 75% Small, 22% Medium

What Do G2 Reviewers Say About Cyrisma?

AI-generated summary from verified user reviews

Pros
  • Users value the time-saving integration of Cyrisma, streamlining cybersecurity processes and enhancing overall efficiency.
  • Users value the ease of use of Cyrisma, benefiting from its intuitive interface and seamless integration.
  • Users value the fantastic customer support from Cyrisma, noting its helpfulness and product improvement initiatives.
  • Users value the actionable vulnerability intelligence and integrated patch management features of Cyrisma for efficiency and effectiveness.
  • Users appreciate CYRISMA for its actionable vulnerability intelligence, making it easy to identify and address critical security issues.
Cons
  • Users find a lack of essential features, particularly in UI navigation, data correlation, and patch management capabilities.
  • Users find Cyrisma to be not user-friendly, struggling with navigation, deployment, and overall support for their needs.
  • Users face integration issues with Cyrisma, including broken data scans and delayed API functionality for automation.
  • Users report limited flexibility in Cyrisma, especially with data scanning and agent deployment, hindering efficiency.
  • Users express frustration with the poor customer support from Cyrisma, hindering their ability to effectively use the product.

What Are Recent G2 Reviews of Cyrisma?

Threatspy

ThreatSpy is an Autonomous Application & API Security platform designed to help organizations discover, validate, prioritize, and remediate security vulnerabilities faster. Traditional security tools often generate large volumes of findings, leaving security and engineering teams to manually determine what is exploitable and what should be fixed first. ThreatSpy helps eliminate that noise by combining Dynamic Application Security Testing (DAST), API Security Testing, exploitability validation, reachability-based prioritization, and AI-assisted security review into a single workflow. ThreatSpy continuously evaluates web applications and APIs to identify both known vulnerabilities and hidden security weaknesses, helping teams focus on risks that have real business impact. The platform provides contextual remediation guidance, workflow integrations, and executive-level visibility to improve collaboration between security and development teams.

Average Rating: 4.7/5.0

Total Reviews: 24

How Do G2 Users Rate Threatspy?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Detection Rate: 9.7/10 (Category avg: 9.0/10)
  • Automated Scans: 9.4/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.7/10 (Category avg: 8.5/10)

Who Is the Company Behind Threatspy?

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 42% Small, 42% Medium

What Do G2 Reviewers Say About Threatspy?

AI-generated summary from verified user reviews

Pros
  • Users value the proactive threat identification of Threatspy, enhancing security and streamlining workflow for teams.
  • Users find Threatspy's interface very easy to use, enabling effortless threat detection and management for everyone.
  • Users commend Threatspy for its proactive vulnerability identification, enabling early threat remediation and improved security efficiency.
  • Users highlight the helpful customer support of Threatspy, enhancing their experience in managing security vulnerabilities.
  • Users benefit from improved efficiency in security processes, allowing teams to focus on critical tasks and reduce alert fatigue.
Cons
  • Users find that limited customization in Threatspy restricts their ability to tailor scans to specific application needs.
  • Users express concern over poor customer support, which detracts from the overall value of Threatspy.
  • Users experience slow scanning, causing delays and inefficiencies during threat detection with Threatspy.
  • Users find that Threatspy has a limited capability in managing complex vulnerabilities, impacting tailored security assessments.

What Are Recent G2 Reviews of Threatspy?

Defendify All-In-One Cybersecurity Solution

Founded in 2017, Defendify is pioneering All-In-One Cybersecurity® for organizations with growing security needs, backed by experts offering ongoing guidance and support. Delivering multiple layers of protection, Defendify provides an all-in-one, easy-to-use platform designed to strengthen cybersecurity across people, process, and technology, continuously. With Defendify, organizations streamline cybersecurity assessments, testing, policies, training, detection, response & containment in one consolidated and cost-effective cybersecurity solution. 3 layers, 13 solutions, 1 platform, including: • Managed Detection & Response • Cyber Incident Response Plan • Cybersecurity Threat Alerts • Phishing Simulations • Cybersecurity Awareness Training • Cybersecurity Awareness Videos • Cybersecurity Awareness Posters & Graphics • Technology Acceptable Use Policy • Cybersecurity Risk Assessments • Penetration Testing • Vulnerability Scanning • Compromised Password Scanning • Website Security Scanning See Defendify in action at www.defendify.com.

Average Rating: 4.7/5.0

Total Reviews: 57

How Do G2 Users Rate Defendify All-In-One Cybersecurity Solution?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 9.4/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.9/10 (Category avg: 8.5/10)

Who Is the Company Behind Defendify All-In-One Cybersecurity Solution?

  • Seller: Defendify
  • Year Founded: 2017
  • HQ Location: Portland, Maine
  • Twitter: @defendify
    305 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    36 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 65% Small, 35% Medium

What Do G2 Reviewers Say About Defendify All-In-One Cybersecurity Solution?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Defendify, streamlining cybersecurity management for small and medium-sized businesses.
  • Users praise Defendify for its comprehensive and cost-effective cybersecurity features, streamlining management for small to medium-sized businesses.
  • Users appreciate the easy setup of Defendify, finding it quick and simple for effective cybersecurity management.
  • Users value the ease of use of Defendify, appreciating quick setup and actionable insights for cybersecurity management.
  • Users value the continuous monitoring features of Defendify, easing the burden of network security management significantly.
Cons
  • Users note that inadequate reporting hinders effective communication, calling for improvements in clarity and detail.
  • Users feel that the poor reporting features hinder effective communication and internal analysis of cybersecurity efforts.
  • Users express frustration over the lack of concise information in reports, preferring clearer and more detailed summaries.
  • Users find the limited customization options restrictive, wishing for more personalized reporting and branding capabilities.
  • Users desire custom reporting options and co-branding features to enhance the personalization of their experience.

What Are Recent G2 Reviews of Defendify All-In-One Cybersecurity Solution?

What Are G2 Users Discussing About Defendify All-In-One Cybersecurity Solution?

Gomboc.AI

Gomboc.AI is a platform engineering solution redefining AI Code Security Assistants (ACSA) for cloud and Infrastructure-as-Code environments. Built for DevOps and platform engineering teams, Gomboc focuses on closing the gap between security findings and reliable remediation. While many AI Code Security Assistants emphasize detection or inline suggestions, Gomboc applies deterministic AI to execute remediation directly in code. When an issue is identified, Gomboc generates a production-ready, standards-aligned code fix and delivers it as a merge-ready pull request through Git and CI/CD workflows. This approach eliminates manual triage, reduces remediation cycles, and helps teams scale secure infrastructure without slowing delivery.

Average Rating: 4.0/5.0

Total Reviews: 28

How Do G2 Users Rate Gomboc.AI?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 9.4/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.2/10 (Category avg: 8.5/10)

Who Is the Company Behind Gomboc.AI?

  • Seller: Gomboc.AI
  • Company Website:
  • Year Founded: 2022
  • HQ Location: New York, US
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 21% Medium, 11% Large

What Do G2 Reviewers Say About Gomboc.AI?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Gomboc.AI, enjoying its intuitive setup and integration in their workflow.
  • Users value the simple and intuitive setup of Gomboc.AI, making it easy to start using effectively.
  • Users value the automation of Gomboc.AI, enabling engineers to focus on more engaging tasks with ease.
  • Users appreciate Gomboc.AI for its ease of use in identifying and remediating security vulnerabilities, enhancing code security effectively.
  • Users appreciate the easy integrations of Gomboc.AI with VS Code, enhancing focus and streamlining their workflow.
Cons
  • Users find the complex setup of Gomboc.AI time-consuming, needing significant effort for API key acquisition and integration.
  • Users face bugs and misleading detections in Gomboc.AI, complicating integration and requiring additional support.
  • Users find Gomboc.AI to be a little on the expensive side, but see value as they scale their operations.
  • Users face integration issues with Gomboc.AI, especially concerning compatibility with other IaC tools like Ansible.
  • Users find that the complex integration process with existing CI/CD pipelines can be challenging and time-consuming.

What Are Recent G2 Reviews of Gomboc.AI?

ARMO Platform

ARMO Platform is the only runtime-driven, open-source first, cloud security platform. It is the only security platform that continuously minimizes cloud attack surface based on runtime insights, while actively detecting and responding to cyberattacks with real risk context. Using an eBPF-based runtime sensor to record application behavior and related activities, ARMO Platform enables DevOps, security, and platform teams to eliminate the security noise and go from thousands of irrelevant alerts to focus on the most important and exploitable threats. This allows those teams to shift from managing hypothetical security issues to mitigating actual risks and providing them with the means to remediate them. ARMO is an open-source-driven company and the creator of Kubescape, a leading open-source Kubernetes security project, now an official CNCF project. To learn more about ARMO Platform please visit: https://www.armosec.io/

Average Rating: 4.5/5.0

Total Reviews: 44

How Do G2 Users Rate ARMO Platform?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.2/10)
  • Detection Rate: 8.4/10 (Category avg: 9.0/10)
  • Automated Scans: 8.7/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.2/10 (Category avg: 8.5/10)

Who Is the Company Behind ARMO Platform?

  • Seller: ARMO
  • Year Founded: 2019
  • HQ Location: Tel Aviv, IL
  • Twitter: @armosec
    3,074 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    103 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 59% Small, 36% Medium

What Do G2 Reviewers Say About ARMO Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of ARMO Platform, as it simplifies security operations and streamlines workflows.
  • Users value the robust automation and integration capabilities of ARMO Platform, enhancing security and efficiency in Kubernetes environments.
  • Users commend ARMO Platform for its superior security capabilities, enhancing the protection of Kubernetes application clusters significantly.
  • Users value the deployment ease of ARMO Platform, enabling quick setup and seamless integration with existing tools.
  • Users value the easy setup and automation of ARMO Platform, enhancing security and compliance for cloud-native applications.
Cons
  • Users report integration issues with ARMO Platform that lead to disruptions and confusion during project workflows.
  • Users often experience missing features like upload issues and outdated updates, impacting workflow and causing confusion.
  • Users face a difficult configuration process on the ARMO Platform, requiring time and effort to master.
  • Users face a noticeable learning curve with ARMO Platform's complex interface, impacting efficiency and integration ease.
  • Users find the complex setup of ARMO Platform challenging, especially those with less experience in Kubernetes.

What Are Recent G2 Reviews of ARMO Platform?

What Are G2 Users Discussing About ARMO Platform?

Detectify

Detectify sets a new standard for advanced application security testing, challenging traditional DAST by providing evolving coverage of each and every exposed asset across the changing attack surface. AppSec teams trust Detectify to expose how attackers will exploit their Internet-facing applications. The Detectify platform automates continuous real-world, payload-based attacks fuelled by its global community of elite ethical hackers into its own expert-built engines, exposing critical weaknesses before it's too late. The Detectify solution includes: - Automated discovery of known and unknown digital assets via domain & cloud connectors - Continuous coverage (24/7) of every corner of the attack surface with dynamic testing. Not just predefined targets - 100% payload-based testing fuelled by elite ethical hackers for a high signal-to-noise ratio - Distributed coverage across an unmatched array of relevant technologies - Actionable remediation tips for software development teams - Team functionality to easily share reports - Powerful integrations platform to prioritize and triage vulnerability findings onward to development teams -Advanced API functionality -Capabilities to set custom attack surface security policies

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Detectify?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.2/10)
  • Detection Rate: 8.5/10 (Category avg: 9.0/10)
  • Automated Scans: 8.9/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Detectify?

  • Seller: Detectify
  • Year Founded: 2013
  • HQ Location: Stockholm, Sweden
  • Twitter: @detectify
    11,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    96 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 47% Small, 35% Medium

What Do G2 Reviewers Say About Detectify?

AI-generated summary from verified user reviews

Pros
  • Users praise Detectify for its automation capabilities, making security testing seamless and adaptable to existing workflows.
  • Users appreciate Detectify's automation testing capabilities, making security assessments easier and more efficient to manage.
  • Users appreciate the customizability of Detectify, enjoying its easy integration and tailored security testing options.
  • Users praise Detectify for its easy integration and comprehensive dynamic application security testing, enhancing security without complex setups.
  • Users value Detectify for its effective dynamic application security testing and seamless integration into existing workflows.
Cons
  • Users find the initial setup complex, which can create challenges in getting started with Detectify.
  • Users struggle with the complex queries in Detectify, which hinder understanding of the spidering outcomes and assessments.
  • Users find the complex setup of Detectify challenging, making initial use more difficult than expected.
  • Users find Detectify expensive when testing multiple sites, affecting its accessibility for wider use.
  • Users face inaccuracies in Detectify's spidering results, leading to uncertainty in thorough application assessments.

What Are Recent G2 Reviews of Detectify?

What Are G2 Users Discussing About Detectify?

Runecast

Runecast is an enterprise CNAPP platform which saves your Security and Operations teams time and resources by enabling a proactive approach to ITOM, CSPM, and compliance. It helps you proactively remediate vulnerabilities for continuous compliance, whether on-prem, cloud or containers. By proactively using our agentless scanning in real-time admins discover potential risks and remediation solutions before any issues can develop into a major outage. Runecast’s AI-RAIKA, leverages advanced natural language processing (NLP) capabilities to interpret a vast amount of information to provide automated audits for security compliance standards, vulnerabilities (such as KEVs, CVEs or VMSAs) and technology vendor best practices. The platform has been recognized with Frost & Sullivan's 2023 European New Product Innovation Award in the CNAPP industry for its strong overall performance and commitment to user experience. NAVIGATING YOUR COMPLEXITY Runecast helps teams with a simpler transition to cloud, enabling admins to fully understand their hybrid environments and Cloud Security Posture Management (CSPM) and Kubernetes Security Posture Management (KSPM). Running securely on-premises, it provides insights into what is happening both in the cloud and on-site. IMMEDIATE VALUE FOR TEAMS As Runecast helps teams to stabilize availability and ensure security compliance, it contributes also to greater ROI for both existing and future investments with AWS, Azure, Kubernetes and VMware. FULLY ON-PREM SECURE Operates fully on-prem to analyze your hybrid-cloud environment, so that your data remains safely on-site. To provide additional security, Runecast features a customizable, transparent rules engine. RUNECAST FOR SECURITY AND COMPLIANCE Vulnerability Management Regular automated scanning, recommendations, remediation, and the ability to set up vulnerability management policies are just some of the requirements many enterprises have. The Runecast platform is constantly updated to detect the latest vulnerabilities for all of the supported technologies. Container Security Runecast scans container images for known vulnerabilities and misconfigurations, and can also detect runtime issues such as exposed ports and running processes. It also provides a public API which can be used in your CI/CD platform to analyze the container images and whether they are vulnerable or not to known vulnerabilities, before deploying them in production. Compliance with Security Standards Runecast offers automated audits against security hardening guidelines and common industry standards like CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. RUNECAST FOR IT OPERATIONS TEAMS Vendor Best Practices for Security Hardening Runecast continuously monitors your complex environment, reporting violations and providing recommendations against Vendor Best Practices. It maintains a database with Best Practices of the latest AWS, Azure, Kubernetes, GCP, VMware and Windows and Linux OS. It analyzes your environment to detect any configuration issues against Vendor Best Practices. This delivers valuable insights to improve the stability and security of your infrastructure. Configuration Vault Tracks your configuration to help you prevent drift. Reports your entire configuration and provides the ability to compare your configurations over time. Hardware Compatibility and Upgrade Stimulations Runecast has automated the process of validating the hardware compliance of hosts and clusters against a selected ESXi version, ensuring compliance with the VMware Compatibility Guide (VCG) and vSAN Hardware Compatibility List (vSAN HCL). The AI-powered platform runs a quick and automated analysis using the latest HCL for your servers, I/O devices, and vSAN controllers. For upgrade planning, admins can see the results of multiple HCL upgrade simulation scenarios within seconds, and the findings are presented in a comprehensive way with details about any non-compatibility and how to resolve it. Validates your hardware, drivers, and firmware against current and upstream releases of ESXi for faster upgrade planning. Remediation Scripts A growing number of findings in Runecast offer remediation actions – allowing you to download the customized script to perform the reconfiguration. Some rules offer more than one remediation option, for example PowerCLI and Ansible. SUPPORTED SERVICES SUPPORTED SYSTEMS: AWS, Azure GCP, Kubernetes (1.20 and above), VMware (VMware vSphere, NSX-V, NSX-T, VMware Horizon, VMware Cloud Director, AP HANA for VMware, VMware on Nutanix, Pure Storage), Windows (Microsoft Windows) and Linux OS (RHEL 8, CentOS 7). SECURITY STANDARDS: CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. INTEGRATIONS: Jira, ServiceNow, vSphere Client Plugin, OpenID Connect, REST API, HPE Ezmeral. REMEDIATION TOOLS: Ansible (VMware), PowerCLI (VMware), AWS CLI (AWS), AWS Tools for PowerShell (AWS), GCP CLI

Average Rating: 4.8/5.0

Total Reviews: 21

How Do G2 Users Rate Runecast?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind Runecast?

  • Seller: Runecast Solutions
  • Year Founded: 2014
  • HQ Location: London, London
  • Twitter: @Runecast
    1,093 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 48% Large, 24% Medium

What Are Recent G2 Reviews of Runecast?

BugProve

As former security researchers, we founded BugProve to deliver the level of security that IoT deserves! Experience peace of mind by leveraging our automated firmware analysis platform: Swift Results: Upload your firmware image and receive first results in just 5 minutes. - Supply Chain Risk Management and Compliance: Identify components and known vulnerabilities, and opt for continuous CVE monitoring for compliance assurance. - Zero-day detection: Our built-in zero-day detection engine, PRIS, detects memory corruption vulnerabilities before they can be exploited. - All-in-One Hub: Seamlessly access product security reevaluations, comparisons, and updates, presented in an easily digestible format. - Effortless Sharing: Share findings via live links or export them as PDFs for convenient reporting. Involve your product development team with AI-assisted remediation recommendations. - Accelerated Testing: Save weeks in the pentesting process, enabling you to focus on in-depth discoveries and launch more secure products, without security bottlenecks. - IoT specific, detailed scans: BugProve runs checks directly on firmware, no source code needed. We run advanced static and dynamic analysis, unique multi-binary taint analysis, cryptographic analysis, and security configuration checks. No long-term contracts, commitments, and hidden fees. What’s more, we believe you should test the platform to see what it can do, so we offer a Free Plan. Sign up, and start scanning!

Average Rating: 4.9/5.0

Total Reviews: 20

How Do G2 Users Rate BugProve?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.2/10)
  • Detection Rate: 8.7/10 (Category avg: 9.0/10)
  • Automated Scans: 9.5/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.9/10 (Category avg: 8.5/10)

Who Is the Company Behind BugProve?

  • Seller: BugProve
  • Year Founded: 2021
  • HQ Location: Budapest, HU
  • Twitter: @Bugprove
    147 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 90% Small, 10% Large

What Are Recent G2 Reviews of BugProve?

FOSSA

Open source is a critical part of your software. In the average modern software product, over 80% of the source code shipped is derived from open source. Each component can have cascading legal, security, and quality implications for your customers, making it one of the most important things to manage correctly. FOSSA helps you manage your open source components. We plug into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use to: - Stay compliant with software licenses and generate required attribution documents - Enforce usage and licensing policies throughout your CI/CD workflow - Monitor and remediate security vulnerabilities - Flag code quality issues and outdated components proactively By enabling open source, we help development teams increase development velocity and decrease risk.

Average Rating: 4.2/5.0

Total Reviews: 15

How Do G2 Users Rate FOSSA?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Detection Rate: 10.0/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind FOSSA?

  • Seller: FOSSA
  • Year Founded: 2015
  • HQ Location: San Francisco, California
  • Twitter: @getfossa
    774 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    63 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 47% Small, 33% Medium

What Do G2 Reviewers Say About FOSSA?

AI-generated summary from verified user reviews

Pros
  • Users highlight the easy integrations of FOSSA, seamlessly working with Spring Boot and Angular applications through their pipeline.
  • Users appreciate FOSSA for its effective issue resolution, identifying library problems and recommending fixes in real-time.
  • Users find FOSSA's remediation solutions valuable for quickly identifying and recommending fixes for vulnerabilities in dependencies.
  • Users value the effective risk management provided by FOSSA, ensuring security and quality for applications.
  • Users value FOSSA for its robust security scanning, ensuring vulnerabilities are identified and managed effectively.

What Are Recent G2 Reviews of FOSSA?

Rainforest Application

Rainforest is the all-in-one cyber security platform with an end-to-end approach to simplify corporate reputation protection by using multiple intelligences and proactive observability, adding Application and Cloud Security (from DevOps to DevSecOps), Vulnerability Intelligence, and Brand reputation (Fraud and Leak monitoring). Rainforest Application, Rainforest Cloud, and Rainforest Asset modules allow development and security teams have visibility of all applications lifecycle, in a simple and quick way, providing vulnerability management always that a new line is coded. Rainforest Fraud, Rainforest Leak, and Rainforest Asset build an integrated vision of Vulnerability and Brand Intelligence, guiding security and compliance teams in an efficient manner on potential exposure points, according to their importance to the business regarding the company's reputation.

Average Rating: 4.9/5.0

Total Reviews: 12

How Do G2 Users Rate Rainforest Application?

  • Has the product been a good partner in doing business?: 9.8/10 (Category avg: 9.2/10)
  • Detection Rate: 9.0/10 (Category avg: 9.0/10)
  • Automated Scans: 9.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Rainforest Application?

Who Uses This Product?

  • Company Size: 42% Small, 42% Medium

What Are Recent G2 Reviews of Rainforest Application?

HostedScan.com

HostedScan provides 24x7 alerts and detection for security vulnerabilities. Industry-standard, open-source, vulnerability scans. Automated alerts when something changes. Manage target list manually or import automatically from providers, such as AWS, DigitalOcean, and Linode, with read-only access. Manage and audit risks with dashboarding and reporting.

Average Rating: 4.3/5.0

Total Reviews: 13

How Do G2 Users Rate HostedScan.com?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Detection Rate: 9.2/10 (Category avg: 9.0/10)
  • Automated Scans: 10.0/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 10.0/10 (Category avg: 8.5/10)

Who Is the Company Behind HostedScan.com?

  • Seller: HostedScan
  • Year Founded: 2019
  • HQ Location: Seattle, Washington
  • Twitter: @hostedscan
    59 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 85% Small, 15% Medium

What Are Recent G2 Reviews of HostedScan.com?

Core6

StorageGuard - Verify and Harden the Security Posture of your Storage and Backup Systems The tactics being used by ransomware groups have changed. And it puts organizations’ storage and backup systems at major risk. The attackers realize that an attack on the storage or system is the single biggest determining factor to show if the organization will pay the ransom. Security Hardening for Storage and Backup Systems StorageGuard - by Core6 provides security hardening for all storage and backup systems, to improve your security posture, enable cyber-resiliency, and meet IT audit requirements. StorageGuard checks the security configuration of your storage and backup systems - ensuring those systems are hardened, meet security best practices, and comply with industry standards and regulatory requirements. For the first time, get complete visibility of security risks across these mission-critical systems, and ensure compliance with security regulations and industry standards StorageGuard supports Dell, NetApp, Hitachi Vantara, Everpure (formerly Pure Storage), IBM, Broadcom (Brocade), Cisco, VAST, HPE, Huawei, Infinidat (Lenovo), Nasuni, Rubrik, Cohesity (incl. Veritas Netbackup), Commvault, Veeam, and more. Benefits: • Ensure your storage and backup systems are continuously hardened, to withstand cyberattacks • Eliminate manual security validation efforts, and continuously validate against your security baseline • Eliminate configuration drift – by tracking security configuration changes • Leverage remediation guidance to speed time-to-resolve • Meet IT audit requirements, providing evidence for compliance Discover Continuously analyzes your storage & backup systems, to automatically detect security misconfigurations and vulnerabilities, The built-in knowledgebase of checks covers: • Security best-practices from storage & backup vendors • Standards (NIST, ISO, CIS, DORA, PCI etc.) as applied to storage & backup systems • Vulnerabilities (CVEs) in the storage & backup environment • Commonly used security baselines Prioritize Prioritizes those risks in order of urgency and business impact. Remediate Provides clear security remediation commands and guidance, which can be integrated into your IT service management and SIEM workflows. For every finding, StorageGuard provides detailed remediation commands for your team to quickly resolve the issue. This can also be integrated into your IT service management and SIEM workflows. Improve your security posture StorageGuard improves the ransomware-readiness and overall security posture of your storage and backup systems. We reduce the effort required by IT operations and storage teams to develop and enforce security policies, prove compliance for audit, and chase down false positive CVE alerts raised by tools that aren’t storage-aware. Meet IT Audit requirements StorageGuard provides broad storage and backup system support, and an extremely wide knowledgebase of automated checks, built on industry standards (e.g., NIST, ISO, and CIS), regulatory frameworks (e.g., PCI and DORA), and storage & backup vendor best practices. This makes it easy to audit and report on security misconfigurations and vulnerabilities across your entire storage and backup infrastructure. Fills a major gap StorageGuard fills a critical gap in security posture management. Existing tools by the likes of Tenable, Qualys and Rapid7 provide almost zero coverage for storage and backup systems.

Average Rating: 4.4/5.0

Total Reviews: 18

How Do G2 Users Rate Core6?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Detection Rate: 9.3/10 (Category avg: 9.0/10)
  • Automated Scans: 9.3/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 9.3/10 (Category avg: 8.5/10)

Who Is the Company Behind Core6?

  • Seller: Core6
  • Year Founded: 2005
  • HQ Location: New York, US
  • Twitter: @Core6cyber
    444 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 53% Large, 26% Small

What Are Recent G2 Reviews of Core6?

What Are G2 Users Discussing About Core6?

S4E

S4E.io offers a cutting-edge Continuous Threat Exposure Management (CTEM) solution that leverages a robust microservice architecture to deliver unparalleled security. The platform utilizes the power of artificial intelligence to autonomously conduct comprehensive scans across various attack vectors, identifying and prioritizing potential risks in real time. By assessing vulnerabilities and defining their severity, S4E.io provides actionable insights and AI-supported remediation advice, enabling organizations to efficiently address security gaps. Furthermore, its continuous monitoring capabilities ensure that systems remain under vigilant protection, offering round-the-clock surveillance to detect and respond to emerging threats fastly. With S4E.io, businesses can fortify their defenses with advanced, automated, and intelligent security measures, ensuring a proactive approach to safeguarding digital assets. To visit our pricing packages to get an opinion. https://s4e.io/pricing Pleese do not hesitate to contact with our sales team to benefit discounted rates! sales@s4e.io

Average Rating: 4.3/5.0

Total Reviews: 15

How Do G2 Users Rate S4E?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.2/10)
  • Detection Rate: 8.3/10 (Category avg: 9.0/10)
  • Automated Scans: 9.8/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 8.5/10 (Category avg: 8.5/10)

Who Is the Company Behind S4E?

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 73% Small, 40% Medium

What Do G2 Reviewers Say About S4E?

AI-generated summary from verified user reviews

Pros
  • Users value the robust security features of S4E, offering peace of mind with automated vulnerability scanning and updates.
  • Users value the automated scanning feature of S4E, making vulnerability detection easy and efficient for all skill levels.
  • Users love the CTEM feature, appreciating its intuitive dashboard and accurate alerts for enhanced website security.
  • Users appreciate the timely vulnerability identification by S4E, enhancing security and reducing stress after deployments.
  • Users value the automation and timely alerts of S4E, enhancing their awareness of weaknesses post-deployment.
Cons
  • Users note a steep learning curve with S4E, requiring time to adapt to its numerous features.
  • Users note that navigation issues hinder a smoother and more efficient experience with S4E.

What Are Recent G2 Reviews of S4E?

What Are G2 Users Discussing About S4E?

Offensity

Offensity is an automated vulnerability scanner helping professional IT teams identify and fix vulnerabilities. Offensity is an easy to use External Attack Surface Management solution and minimizes human effort in your team. You will be set up in minutes: IT admins enter and verify their domain (e.g. company-demo.com). Additional subdomains will be suggested automatically. Scanning starts. That’s it.

Average Rating: 4.4/5.0

Total Reviews: 10

How Do G2 Users Rate Offensity?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Detection Rate: 8.7/10 (Category avg: 9.0/10)
  • Automated Scans: 8.3/10 (Category avg: 9.1/10)
  • Configuration Monitoring: 7.8/10 (Category avg: 8.5/10)

Who Is the Company Behind Offensity?

  • Seller: A1 Digital
  • Year Founded: 2017
  • HQ Location: Wien, AT
  • Twitter: @offensity
    260 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    218 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Large, 27% Small

What Are Recent G2 Reviews of Offensity?

What Are G2 Users Discussing About Offensity?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated April 10, 2026