
On the plus side, Core Impact has a friendly interface and is very easy to use for newbies. It alone can do many different tasks in pentesting from scanning to attack, ... and packaging everything in one RPT process. Core Impact has a lot of attack modules on many different platforms, it gets updated quite frequently and quickly. I like the feature of installing an agent on the server through services such as SSH, SMB, ... white box testing is much more effective. I have not had a chance to use the SCADA module to evaluate it, however, I see the module updates exploiting the vulnerability so this platform is a lot. Recently there are additional modules for medical devices, but I think few people dare to pentest these systems, lmao^^! Core Security has a very enthusiastic support team, very satisfied with them. Review collected by and hosted on G2.com.
On the downside, the ability to exploit web vulnerabilities is really bad, I feel like Core Security doesn't focus too much on this vector. Sometimes, modules that exploit new CVE vulnerabilities are updated very slowly, normally you can see an update for CVE vulnerabilities from 2017, 2018. Wireless network testing can only perform MITM attack, I expect more with this feature. Review collected by and hosted on G2.com.