
The most important I like about this is the IAST- Interactive application security testing is the best part which I like because it will crawl the application with us and get more chances to get more vulnerabilities as compare to DAST and SAST.
SAST and DAST obviously these feature will do there best.
Mobile application is also adding plus point which will make this tool as all rounder just like in cricket the player who knows batting, bowling, fielding and wicket keeping.
This is the tool which added the advantage of all the things. Review collected by and hosted on G2.com.
No support for the react js applications as it should have. which will improve appscan support
Anyway it is having SAST, DAST, Mobile apps and IAST. which is best part of it. Review collected by and hosted on G2.com.
In report side, developers can understand details and solution method of vulnerability. On my side(security engineer) I have been tested AppScan with 2 other rival. The vulnerability analysis AppScan is doing is quite sufficient. In my review I think that was enough for OWASP TOP10 requirements. Review collected by and hosted on G2.com.
User interface could be more colorful :) Review collected by and hosted on G2.com.
This one of best tool for Application scan to identify the flaws and remediation to fix the flaws in the application Review collected by and hosted on G2.com.
Some time IBM Security AppScan provides false positive results Review collected by and hosted on G2.com.
IBM® Security AppScan Standard automates application security testing by scanning applications, identifying vulnerabilities, and generating reports with intelligent fix recommendations to ease remediation. It provides static and dynamic application security testing throughout development Review collected by and hosted on G2.com.
it doesn't have support for Oracle fusion middleware stack scaning which is a limitation and doesnt provide any support for SCA based application Review collected by and hosted on G2.com.
Real time agent status monitorning, agent logging and It is very cost effective compared to its performance and the features it offers. I like the way it assesses the applications. Review collected by and hosted on G2.com.
The tool IBM Security AppScan Standard is oblivious of the inner workings of the application being tested. It is unaware of the programming languate, OS, database, etc. Review collected by and hosted on G2.com.
Generate accurate results based on the inputs. Uses the solid base of IAST and DAST technologies that are most reliable for detecting the security and other issue of application. Advance configuration options for testing broad range of case. Review collected by and hosted on G2.com.
Deviation from the real output when number of test cases increase. No option to test the complexity of the code while issue being identified in on the real environment. Review collected by and hosted on G2.com.
IBM is one of a few vendors that offer all DAST, SAST & IAST scanning technology. IDM AppScan Standard contains both DAST and IAST via glassbox. IBM can generate the accurate result with high computational time. The reporting format is centralized on risks that is easier for developers to understand. Review collected by and hosted on G2.com.
IBM AppScan standard doesn't offer SCA which is limited only for AppScan Enterprise. Review collected by and hosted on G2.com.
Advance configurations for running the authenticity test of an application. Scope of verification is wide, you can not think all security issues it offers to identify. Integration process is easy. Review collected by and hosted on G2.com.
Sometime gives few results when number of test performed is increased. Review collected by and hosted on G2.com.
Alert of possible threat/vulnerability, Range of testing is quiet impressive, Quick remediation results and authentication test with advanced configuration. Review collected by and hosted on G2.com.
Retesting fails when number of issues increased. It also reports non-threats sometime. Review collected by and hosted on G2.com.
it classify and prioritize assets based on impact of business and identify the high risk areas and also test the the applications before real deployment.It is easy to configure Review collected by and hosted on G2.com.
its is not granular as standard.they have sometime confusing licensees. Review collected by and hosted on G2.com.
It automatically identifies possible breaches, provides solutions too. Review collected by and hosted on G2.com.
Web apps today can be developed in many languages, and every framework has a different set of parameters. It should be tailored for specific frameworks. Review collected by and hosted on G2.com.