Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs CrowdStrike Falcon Cloud Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx One
Ranking in Application Security Tools
3rd
Average Rating
7.6
Number of Reviews
68
Ranking in other categories
Static Application Security Testing (SAST) (3rd), Vulnerability Management (15th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
CrowdStrike Falcon Cloud Se...
Ranking in Application Security Tools
13th
Average Rating
8.2
Number of Reviews
20
Ranking in other categories
Container Security (9th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), Cloud-Native Application Protection Platforms (CNAPP) (7th), Cloud Infrastructure Entitlement Management (CIEM) (4th), Application Security Posture Management (ASPM) (3rd)
 

Featured Reviews

NH
Feb 9, 2024
A highly scalable solution that reduces workloads, saves time, and fixes loopholes and vulnerabilities swiftly
It is very easy for the analyst to have everything in a consolidated single pane of glass. Previously, they ran multiple tools. They used one tool for source code analysis and another for static code review. Then, I manually verified each result. Since we moved to Checkmarx, it has been very easy for the analyst. The tool gives us a shareable report that can be easily shared with management once the product is done. The solution’s performance and the consolidated information it provides are valuable. The platform is completely on the cloud. There are no scalability or connectivity issues. The platform is stable. It can be accessed from anywhere. We used open-source tools before. We had to deploy the tools in the customers' environment to establish the connection between the tools and their product application. Since Checkmarx is a SaaS-based platform, we need only the forward connection from Checkmarx to the tool. The tool handles everything else. We just need a single firewall rule to be enabled on the platform to establish the connection. The deployment is very simple. We need just one rule to forward the web application to Checkmarx. The scanning engine is very good. Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%. The tool has greatly reduced the time and effort our analysts need to do their tasks. It's very useful if we need to perform a short-term project. It is greatly helpful in fixing loopholes and vulnerabilities swiftly.
Abraham Pasamar - PeerSpot reviewer
Jul 3, 2024
Effective for detecting and mitigating threats and good automated response capabilities
We give MDR services to many clients and extend the basic capabilities with these modules The automation capabilities that the tool has in order to automate responses and actions. It's quite easy to use, as I understand the feedback from the team. It is effective for detecting and mitigating…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Scan reviews can occur during the development lifecycle."
"We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code."
"It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results."
"The report function is the solution's greatest asset."
"The solution allows us to create custom rules for code checks."
"It is a stable product."
"It shows in-depth code of where actual vulnerabilities are."
"The solution is scalable, but other solutions are better."
"The most significant benefit is how quickly malware and other malicious attacks are detected."
"Technical support is helpful."
"The RTR feature stands out as particularly valuable to me due to its capability to log into machines."
"Cloud security posture management (CSPM) is most valuable."
"The immediate mitigation of potential threats and instant alerts are valuable."
"CrowdStrike utilizes signatureless technology, eliminating the need for regular signature updates on endpoint systems."
"The most valuable feature of Falcon Cloud Security is its comprehensive threat-hunting ability."
"It is fully cloud-based, so we don't need to invest in third-party agents repeatedly."
 

Cons

"The interactive application security testing, or IAST, the interactive part where you're looking at an application that lives in a runtime environment on a server or virtual machine, needs improvement."
"Checkmarx could improve by reducing the price."
"In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now."
"Checkmarx being Windows only is a hindrance. Another problem is: why can't I choose PostgreSQL?"
"Checkmarx could improve the solution reports and false positives. The false positives could be reduced. For example, we have alerts that are tagged as vulnerabilities but when you drill down they are not."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"Meta data is always needed."
"The only suggestion for improvement would be the pricing."
"Different file options should be available, and clients should be able to select from the options."
"The CrowdStrike partner portal documentation could be improved to provide proper instructions for integrating their products."
"There were some integration issues with this product."
"CrowdStrike Falcon Cloud Security is expensive."
"The CrowdStrike dashboard currently lacks a username field."
"The log scale or Humio side of it where it collects the data and expands into the XDR world still needs time to develop in terms of the way it combines the data and metadata that flows into the platform. I know they're working on it."
"The only challenge lies in token verification."
 

Pricing and Cost Advice

"We have purchased an annual license to use this solution. The price is reasonable."
"The solution's price is high and you pay based on the number of users."
"I believe pricing is better compared to other commercial tools."
"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"It is the right price for quality delivery."
"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"Its price is moderate."
"It's an expensive product"
"It's an expensive package but does what it says it will do."
"I am not the one who handled the pricing. A different team worked on it, but it is pretty expensive."
"The pricing is fair for what you get. I'd rate them a solid nine out of ten in terms of pricing."
"CrowdStrike Falcon Cloud Security is pricy."
"The pricing is reasonable, neither overly expensive nor excessively cheap, making it competitive compared to other market options."
"The price is not too high, it is okay."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
800,688 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
16%
Manufacturing Company
10%
Government
5%
Computer Software Company
16%
Financial Services Firm
16%
Manufacturing Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What do you like most about CrowdStrike Falcon Cloud Security?
It's easy to gather insights and conduct analysis about existing threats.
What is your experience regarding pricing and costs for CrowdStrike Falcon Cloud Security?
It's an expensive product. The solution costs around $60 for a single user on a yearly basis. I would rate the pricing a four out of ten.
What needs improvement with CrowdStrike Falcon Cloud Security?
I am not part of the current monitoring team, so I do not know how they feel about the tool. I am sharing information related to the tool based on the feedback and on my experience deploying it fou...
 

Also Known As

No data available
CrowdStrike Falcon ASPM
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Information Not Available
Find out what your peers are saying about Checkmarx One vs. CrowdStrike Falcon Cloud Security and other solutions. Updated: September 2024.
800,688 professionals have used our research since 2012.