Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Claroty Platform comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx One
Ranking in Vulnerability Management
15th
Average Rating
7.6
Number of Reviews
69
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
Claroty Platform
Ranking in Vulnerability Management
14th
Average Rating
8.0
Number of Reviews
11
Ranking in other categories
Remote Access (11th), Operational Technology (OT) Security (1st), Cyber-Physical Systems Protection (1st)
 

Featured Reviews

MH
Feb 7, 2024
Specifies the exact line of code where it finds the problem and gives good reports
There's one thing Checkmarx can maybe fix, actually two things. First, when we first ran it on a big project, there wasn't enough memory on the computer. It originally ran with eight gigabytes, and now it runs with 32. The software stopped at some point, and while I don't think it said it ran out of memory, it just said "stopped" and something else. We had to go to the logs and send them to the integrator, and eventually, they found a memory issue in the logs and recommended increasing the memory. We doubled it once, and it didn't seem enough. We doubled it again, and it helped. So, even if the software reaches capacity on the computer, even though it writes it in the logs, it should also give an indication in the GUI to the person running it, saying "not enough memory" or "not enough disk space." Another problem is that when it's scanning and it has an internal problem, for example, it cannot check something, or an internal bug or internal problem, it's being found in the logs, but there's no indication to the user. Now, this is good for them because the user runs it, gets a report, everything's fine. But in a way, it's not good for them because the user doesn't know there's a problem since they don't check the logs. Because mostly, only the manager looks at the logs and only if there's a problem being reported. You run a process, get a report, but in the logs, there might be an indication that it couldn't check several files or understand something. There's a problem, an internal problem that can be fixed, but nobody knows about it because we don't look at the code. The user doesn't look at the logs; only the business manager does, but they don't know because the user doesn't report it, because the user doesn't know. So, my suggestion for them is this: if they have problems, they should say, 'Here is the report,' but also indicate to the user somewhere, perhaps in the GUI, not necessarily in the report itself, 'We found 100 problems while looking at your code. Please provide us the logs so we can try to fix those.' Then they can ask if the user has any problems. This way, users would know to send them their logs, and they could improve their software, meaning fix the problems. Now, they may not want to do this because they'll get flooded with millions of responses and millions of problems from all over the world. They would have to fix them, and people might get angry, asking why they provided a report when there were hidden problems. People might say, 'How come you gave me a report with seven or eight problems when analyzing it, there were internal problems with your code? So it's not a perfect report.'" So, these internal issues are logged but not communicated to the user through the Checkmarx interface (GUI) or report. The solution also has a few false positives. So, if they had an easier way for users to send an email directly, instead of just opening a ticket. Because when we open a ticket, they want all the logs and everything, and it becomes a hassle. Perhaps they could implement an easier system where users can send a snippet of the code, along with an explanation of why they believe it's a false positive, referencing the specific report. This way, Checkmarx could analyze the information and the development team could potentially fix the product in those areas. It wouldn't require them to necessarily respond to the user, but I'm not sure if that's feasible for most companies.
MG
Jul 4, 2024
Custom rules that help reduce noise and ensure we receive meaningful alerts and events
Threat detection and vulnerability management are the most valuable features. There are also custom rules that help reduce noise and ensure we receive meaningful alerts and events. The vulnerability management capabilities that helped mitigate potential threats have been very helpful. Claroty identifies all vulnerabilities available in our environment, and while the tool provides the information, a skilled team is needed to manage and address these vulnerabilities effectively. It can also be integrated with third-party vulnerability management tools for a unified view, where all the vulnerabilities can be displayed and prioritized based on asset criticality. It is easy to integrate Claroty into our existing system.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature for me is the Jenkins Plugin."
"Less false positive errors as compared to any other solution."
"One of the most valuable features is it is flexible."
"Overall, the ability to find vulnerabilities in the code is better than the tool that we were using before."
"It gives the proper code flow of vulnerabilities and the number of occurrences."
"The only thing I like is that Checkmarx does not need to compile."
"The most valuable features of Checkmarx are the automation and information that it provides in the reports."
"The solution improved the efficiency of our code security reviews. It helps tremendously because it finds hundreds of potential problems sometimes."
"The solution's asset management is really great compared to Dragos or Nozomi."
"Claroty provides continuous threat protection and identifies pre-empty stuff and false positives."
"The solution offers comprehensive tools that greatly enhance your IT operations if implemented correctly."
"The product helps mitigate potential threats, especially if its users have signature rules. The product also provides alerts."
"I appreciate the active coding, deep inspection of packages, and data retrieval. The tool covers information about assets and attack vectors, which I find superior to other tools. Based on alerts, I create reports detailing how an attacker can penetrate the plant, both externally and internally."
"Claroty identifies all vulnerabilities available in our environment."
"The tool's best feature was the UI and the simplicity it offers."
"The solution's most valuable feature is the map, which shows everything that is connected and communicates with each other."
 

Cons

"We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level."
"Checkmarx needs to be more scalable for large enterprise companies."
"We can run only one project at a time."
"Checkmarx needs improvement in its Dynamic Application Security Testing (DAST) and API security features."
"Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed."
"We have received some feedback from our customers who are receiving a large number of false positives."
"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"They can support the remaining languages that are currently not supported. They can also create a different model that can identify zero-day attacks. They can work on different patterns to identify and detect zero-day vulnerability attacks."
"I've reported four bugs and three feature requests so far. The main area of focus should be on how attacks are detected. The attack vector information needs to be more detailed. For example, it's not enough to state that an SMB v1 version open can lead to a WannaCry attack. A more detailed explanation should help clients understand the various ways an attack could occur."
"We face issues in the alert investigation area because it does not properly give the alert communication patterns."
"The product could be improved in terms of user interface design."
"There are a few protocols that Claroty doesn't currently support."
"For improvement, I think the training could be more practical. We have external training, but they're mostly theoretical. I want the solution to provide hands-on lab experience to help users learn better."
"The graphical user interface is quite poor."
"Claroty Platform could improve the pricing to get more acceptability in the market."
"The product's integration capabilities are an area of concern where improvements are required."
 

Pricing and Cost Advice

"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"It is a good product but a little overpriced."
"Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"The tool's pricing is fine."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"The tool is quite expensive."
"The licensing for physical devices is cheap, but the software version is expensive. The software version costs around 26-28 dollars. I was surprised and even double-checked. It was shocking."
"It's a bit expensive compared to other solutions."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
805,335 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
16%
Manufacturing Company
10%
Government
5%
Computer Software Company
15%
Manufacturing Company
15%
Energy/Utilities Company
12%
Financial Services Firm
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
Which solution do you prefer: Nozomi Networks or Claroty Platform?
Nozomi Networks and Claroty Platform are both leading operational technology (OT) security solutions offering a wide range of features, including asset discovery, risk assessment, and threat detect...
What do you like most about Claroty Platform?
The product helps mitigate potential threats, especially if its users have signature rules. The product also provides alerts.
What needs improvement with Claroty Platform?
For improvement, I think the training could be more practical. We have external training, but they're mostly theoretical. I want the solution to provide hands-on lab experience to help users learn ...
 

Comparisons

 

Learn More

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Rockwell Automation
Find out what your peers are saying about Checkmarx One vs. Claroty Platform and other solutions. Updated: September 2024.
805,335 professionals have used our research since 2012.