HCL AppScan vs Rapid7 InsightAppSec comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

HCL AppScan
Ranking in Dynamic Application Security Testing (DAST)
1st
Average Rating
7.8
Number of Reviews
41
Ranking in other categories
Application Security Tools (14th), Static Application Security Testing (SAST) (11th)
Rapid7 InsightAppSec
Ranking in Dynamic Application Security Testing (DAST)
3rd
Average Rating
8.6
Number of Reviews
12
Ranking in other categories
No ranking in other categories
 

Market share comparison

As of June 2024, in the Dynamic Application Security Testing (DAST) category, the market share of HCL AppScan is 30.0% and it decreased by 5.4% compared to the previous year. The market share of Rapid7 InsightAppSec is 10.0% and it decreased by 48.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST)
Unique Categories:
Application Security Tools
3.1%
Static Application Security Testing (SAST)
2.6%
No other categories found
 

Featured Reviews

AnanyaRoy - PeerSpot reviewer
Sep 25, 2023
A stable and scalable product useful for application security scanning
I use HCL AppScan in my company for application security scanning The most valuable feature of the solution stems from the fact that it is good to run the scan faster. You can basically run the scan and take a break at work since the tool will compute the results, which makes the product quite…
RB
Jul 28, 2023
A highly scalable and robust product that enables users to automate scans
We use it as a web application scanner. It runs a ton of different detections and tests against our web applications and provides us with results. It connects directly with our SDLC for an API. We can automate the scanning of a web application during the development process when it changes from…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like the recording feature."
"The security and the dashboard are the most valuable features."
"It was easy to set up."
"The product has valuable features for static and dynamic testing."
"The reporting part is the most valuable feature."
"The solution is easy to install. I would rate the product's setup between six to seven out of ten. The deployment time depends on the applications that need to be scanned. We have a development and operations team to take care of the product's maintenance."
"The HCL AppScan turnaround time for Burp Suite or any new feature request is pretty good, and that is why we are sticking with the HCL."
"The UI was very intuitive."
"The solution is stable."
"You have various attack modules, and you also have the Attack Replay feature for the attack sequence. You can reproduce an attack and see it. That is a very good feature I noticed in this solution. It helps developers as well."
"We have seen measurable decrease in the mean time to respond to threats by 20 percent."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"It's very easy to use and user-friendly. It does the job."
"The most valuable feature of this solution is the graphical interface."
"In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to paste the provided CDN into your metadata. Once connected, every piece of information, including vulnerabilities, can be accessed. It also offers demo sessions."
"It is a very robust solution."
 

Cons

"The solution often has a high number of false positives. It's an aspect they really need to improve upon."
"In future releases, I would like to see more aggressive reports. I would also like to see less false positives."
"Many silly false positives are produced."
"One thing which I think can be improved is the CI/CD Integration"
"I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources."
"There is not a central management for static and dynamic."
"HCL AppScan needs to improve security."
"AppScan is too complicated and should be made more user-friendly."
"The number of web applications we can scan is limited."
"We get a lot of false positives during the tests."
"We'd like to see integrations with WAF solutions."
"In the future, if they can have integration with a lot of ticketing systems then it would be amazing."
"The reporting is definitely an aspect of the solution that's in need of some work. We found that we'd try to use widgets, but often getting them to work for us wasn't very clear. They need to be more user friendly or offer better instructions."
"The product’s pricing could be flexible."
"When you add new projects for the same product, it either duplicates or replaces the scan configuration. If I run a scan for the same product with a different scan configuration, it should keep the previous scan configuration and not replace it with the new scan configuration. It should just add the new scan configuration. That would be helpful. They do keep the results as it is, but the scan configuration keeps changing. For example, I have set a scan configuration to a full scan, and next week, I want to run a new scan for the same product with some changes or new functionalities. I want to run a partial scan. Currently, if I change the scan configuration to partial, it changes the old one also to partial. That should be improved."
"Rapid7 InsightAppSec needs improvement in detecting phishing pages."
 

Pricing and Cost Advice

"HCL AppScan is expensive."
"The price of HCL AppScan is okay, in my opinion. You just buy HCL AppScan and don't pay anything anymore, meaning it is just a one-time purchase."
"The tool was expensive."
"I would rate the product's pricing a nine out of ten. The product's pricing is expensive compared to the features that they offer."
"Our clients are willing to pay the extra money. It is expensive."
"The product has premium pricing and could be more competitive."
"I rate the product's price a seven on a scale of one to ten, where one is low, and ten is high. HCL AppScan is an expensive tool."
"Pricing was the main reason that we went ahead with this solution as they were the lowest in the market."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"The price of this product is very cheap."
"I'm not sure how much it costs exactly, but I know it's expensive."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"Its price is competitive. It is not expensive."
"Rapid7 InsightAppSec is cheap."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
15%
Government
10%
Manufacturing Company
9%
Computer Software Company
20%
Financial Services Firm
13%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
Improving usability could enhance the overall experience with AppScan. It would be beneficial to make the solution more user-friendly, ensuring that everyone can easily navigate and utilize its fea...
What is your primary use case for HCL AppScan?
I mainly use AppScan to secure various types of applications. I use its DAFDAT solution for black box scanning, as well as SaaS and source code validation. AppScan helps in scanning code for vulner...
What do you like most about Rapid7 InsightAppSec?
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to p...
What needs improvement with Rapid7 InsightAppSec?
Rapid7 InsightAppSec needs improvement in detecting phishing pages.
What is your primary use case for Rapid7 InsightAppSec?
I use the solution to check multiple websites, particularly dynamic and e-commerce websites, for vulnerabilities within the code. The tool helps identify any vulnerabilities present in the code, pr...
 

Also Known As

IBM Security AppScan, Rational AppScan, AppScan
InsightAppSec
 

Learn More

 

Overview

 

Sample Customers

Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about HCL AppScan vs. Rapid7 InsightAppSec and other solutions. Updated: May 2024.
787,061 professionals have used our research since 2012.