Vulnerability Management Tools
Compare the best vulnerability management tools. Discover, prioritize, and remediate vulnerabilities across your attack surface.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.
Axonius provides holistic asset management for cloud and on-premise that extends deeply into the vulnerability management space. They have a strong focus on integrations and a robust API.
Qualys offers just about every vulnerability scanner you could want from a single vendor - from cloud to on premise to code. They have great vulnerability insights and scanning capabilities in a holistic place, but the platform UX can be difficult compared to more specialized vendors.
Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.
Intruder offers holistic network vulnerability scanner, DAST, and CSPM scanning solutions, a great option for mid size businesses looking for a flexible scanner
Acquired by Tenable. Vulcan offers the robust flexibility of the legacy offerings in this category, but with a much nicer UI/UX. A strong choice for enterprises looking to manage huge amounts of very diverse assets, but a lot of the setup will be manual tinkering (no worse than the incumbents).
Acquired by ZScaler. Avalor creates a platform for the vulnerability fixes you're probably coding yourself. They offer an elegant no/low code approach for uniting all of your vulnerability data in one place. Their approach heavily relies on the flexibility of their data standardization.
Vicarius is just a straight up better version of most legacy vulnerability scanners. They have great agent based scanning, reporting, and prioritization for endpoints, but are not as advanced on the cloud or kubernetes side.
SecOps Solution has created a network based scanner for detecting and remediating vulnerabilities across hosts. It's an elegant solution that's great for non-containerized environments.
Nucleus's approach to vulnerability remediation emphasizes risk based prioritization, which we think is less exciting than the functionality around getting the right information to the right teams, automatically. They have a more traditional model for standardizing data.