Fortra Tripwire IP360 vs Qualys Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortra Tripwire IP360
Average Rating
7.0
Number of Reviews
6
Ranking in other categories
Vulnerability Management (40th)
Qualys Web Application Scan...
Average Rating
7.8
Number of Reviews
31
Ranking in other categories
Application Security Tools (19th), Static Application Security Testing (SAST) (14th)
 

Market share comparison

As of June 2024, in the Vulnerability Management category, the market share of Fortra Tripwire IP360 is 0.5% and it increased by 74.7% compared to the previous year. The market share of Qualys Web Application Scanning is 0.6% and it increased by 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
Unique Categories:
No other categories found
Application Security Tools
2.4%
Static Application Security Testing (SAST)
1.8%
 

Featured Reviews

Corey Cole - PeerSpot reviewer
Jul 12, 2023
The solution helps users to manage their entire IP range, but it's unreliable and very expensive to maintain
Only the administrator was using the product. He used it to read reports as part of our compliance programs. It wasn't heavily used by a lot of users. The tool comes in at a large scale, and we tried to scale it down. The scaling did not apply to us. It was neither difficult nor easy. I rate the scalability a five out of ten. We had some challenges while scaling it down. It could do 10,000 devices, and we wanted to use it for ten devices. The process was difficult and expensive. We did not need the product anymore.
Brammadevan K - PeerSpot reviewer
Feb 22, 2024
Operates as a DAST tool, examining the application from an external perspective to identify security issues
One area for improvement is the application scan interface. Although recent updates have introduced some features, there's a gap in supporting standards beyond OWASP. Currently, there isn't an option to select or integrate other security standards directly within the platform, which limits the scope of scans to primarily OWASP. For broader compliance, custom integrations are required, which is a cumbersome process. The platform primarily supports OWASP standards for scanning. If an organization needs to comply with other standards, such as ISO or NIST, there's no straightforward option to select these within the scanning interface. This limitation requires custom solutions to meet other compliance requirements, which is not ideal. Qualys should enhance its interface to allow users to easily select and scan according to multiple standards, not just OWASP. This includes both internal and external scans, providing a more flexible and comprehensive approach to web application security. In addition to choosing standards, there's a distinction between internal and external scanning processes that could be streamlined. Currently, for internal scanning, specific configurations and scanner appliances need to be deployed within the network, which differs from the simpler setup for external scans. This dual process complicates the setup for comprehensive scanning coverage. The process should be simplified to eliminate the need for two distinct setups for internal and external scans within Qualys.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Tripwire IP360 is a very stable solution."
"We could manage our entire IP range with the solution."
"It's become the pinnacle point for anything that enters the network or anything that's passing through to production to first be affected by IP360, hardened, and up to standard. For our integrity management, one was deployed in the bank about two years ago and that's still going to expand the usage and the product itself. That will go hand in hand with training and expanding the product as for where it's deployed."
"With our vulnerabilities under control, it's putting our services in compliance and minimizing our risk for exposure."
"It combines both web application vulnerability management and internal vulnerability management on one platform and dashboard. Usually, you have to purchase separate tools."
"The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera."
"​We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues.​"
"You can integrate your Burp Suite results and create an integrated report. Also, the way it shows the results - threats and exploit details - makes remediation very easy."
"The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
"It is a cloud-based solution, so it is easy to scale."
"The most valuable feature of Qualys Web Application Scanning is the effective scanning that can be done."
 

Cons

"The reporting functions can use improvement. There is room for growth because reporting functions differ a lot depending on what you're going to output. It depends on whether it's for technical or senior management and how it's interpreted. There could be growth within the reporting functionality side."
"We need to dedicate time and resources to keep it running."
"I am not very impressed by the technical support."
"The area of false positives could be improved. There are quite a number of false positives as compared to other solutions. They could probably fine tune the algorithm to be able to reduce the number of false positives being detected."
"The pricing does not seem to be competitive."
"The reporting contains too many false positives."
"The solution needs to adjust its pricing. They should make it more affordable."
"The product should allow users to upload their payloads."
"We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans."
"The support could be faster."
"There could be better management and faster scanning."
 

Pricing and Cost Advice

"I believe the price compares well within the market."
"The product was expensive for us."
"From my perspective, it is a budget-friendly option."
"Licensing was based on the number of assets that you want to scan on your network. You can also do licensing on subscription. On subscription, it is easier and more flexible. You tell Qualys that you want to move from the 1000 to 2000 band or the 3000 or 5000 band, then they will give you the quotation for it. Once you pay for it, applying the licensing is quite easy and effective."
"The product has a very good licensing model."
"There are different options available with respect to licensing."
"Pricing was reasonable and competitive. It was not too far above the other products."
"Qualys WAS' pricing is competitive."
"​It is best to be an institutional buyer and directly contact the sales team, as they can provide over-the-top discounts for bulk orders​."
"I rate the software’s pricing a six out of ten."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
18%
Energy/Utilities Company
10%
Government
9%
Computer Software Company
16%
Financial Services Firm
15%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Tripwire IP360?
We could manage our entire IP range with the solution.
What is your experience regarding pricing and costs for Tripwire IP360?
The product was expensive for us. It was not cost-effective for how we used it to do the job. We didn't think it was worth the money.
What needs improvement with Tripwire IP360?
It's an enterprise-level tool. If we’re not putting it in everything, it's very expensive to maintain in terms of people and time. We need to dedicate time and resources to keep it running. It was ...
What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What is your experience regarding pricing and costs for Qualys Web Application Scanning?
From my perspective, it is a budget-friendly option. Qualys offers good value for the features and protection it provides. The pricing seems reasonable, considering the comprehensive security solut...
What needs improvement with Qualys Web Application Scanning?
One area for improvement is the application scan interface. Although recent updates have introduced some features, there's a gap in supporting standards beyond OWASP. Currently, there isn't an opti...
 

Also Known As

IP360
Qualys WAS
 

Learn More

 

Overview

 

Sample Customers

1. Aetna 2. Accenture 3. Adidas 4. AIG 5. Airbus 6. Akamai 7. Amazon 8. American Express 9. Aon 10. Apple 11. ATT 12. Autodesk 13. Bank of America 14. Barclays 15. Bayer 16. Bechtel 17. BlackRock 18. Boeing 19. BNP Paribas 20. Cisco 21. CocaCola 22. Comcast 23. Dell 24. Deutsche Bank 25. eBay 26. ExxonMobil 27. FedEx 28. Ford 29. General Electric 30. Google 31. HP 32. IBM
BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Find out what your peers are saying about Tenable, Wiz, SentinelOne and others in Vulnerability Management. Updated: June 2024.
787,061 professionals have used our research since 2012.