Try our new research platform with insights from 80,000+ expert users

Claroty Platform vs HackerOne comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 14, 2024
 

Categories and Ranking

Claroty Platform
Ranking in Vulnerability Management
15th
Average Rating
8.0
Number of Reviews
11
Ranking in other categories
Remote Access (10th), Operational Technology (OT) Security (1st), Cyber-Physical Systems Protection (1st)
HackerOne
Ranking in Vulnerability Management
39th
Average Rating
8.6
Number of Reviews
4
Ranking in other categories
Application Security Tools (32nd), Bug Bounty Platforms (1st), Penetration Testing Services (2nd), Attack Surface Management (ASM) (12th)
 

Featured Reviews

AnandKumar2 - PeerSpot reviewer
Jul 8, 2024
Useful for active coding, deep inspection of packages, and data retrieval
I appreciate the active coding, deep inspection of packages, and data retrieval. The tool covers information about assets and attack vectors, which I find superior to other tools. Based on alerts, I create reports detailing how an attacker can penetrate the plant, both externally and internally. Initially, I felt the Claroty Platform wasn't up to the mark for vulnerability management, but recent upgrades have been very helpful. The new features provide more detailed information, including CVE numbers and thorough explanations, such as for MS17-010 (WannaCry). This level of detail meets my expectations and allows me to determine how much of the plant's assets and devices would be compromised if a vulnerability is exploited. This information is crucial for reporting to the CISO.
Hrithik Kumar - PeerSpot reviewer
May 28, 2024
Offers bug bounty opportunities and helps to earn extra money
In college, I started using HackerOne and taught my 10-20 juniors how to use it. I'm sure they might still be using it in their lives right now. The biggest challenge integrating HackerOne into my existing security protocols has been on my side, not the tool's. I need to take the time out to use and practice with it, but currently, I'm unable to give it the time I used to. There's no issue from the application side. To use the tool, you first need a basic knowledge of cybersecurity terms, like exploits and vulnerabilities, and how to identify them. Once familiar with these basics, you can learn more from the resources and platforms HackerOne provides. They offer tickets and guides to help you understand the methods for finding and exploiting vulnerabilities. Before deciding to use the solution in your organization, consider the purpose. HackerOne is a multi-platform. If the goal is to spread awareness about cybersecurity or to make the security team more active in learning about hacking methods and new vulnerabilities, then it can be very effective. It allows the team to earn extra money while learning and exploring new vulnerabilities in the market, potentially even finding zero-day vulnerabilities. I would rate HackerOne around an eight to nine out of ten. The application is simple to use, offering numerous opportunities and scopes for exploration. It covers many platforms, including web, Android, and iOS applications. However, the high traffic can sometimes be a drawback. If they manage this issue by implementing features like consolidation pricing for duplicate vulnerabilities, it could easily be a ten out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product helps mitigate potential threats, especially if its users have signature rules. The product also provides alerts."
"The solution's asset management is really great compared to Dragos or Nozomi."
"The solution's most valuable feature is the map, which shows everything that is connected and communicates with each other."
"I appreciate the active coding, deep inspection of packages, and data retrieval. The tool covers information about assets and attack vectors, which I find superior to other tools. Based on alerts, I create reports detailing how an attacker can penetrate the plant, both externally and internally."
"The solution offers comprehensive tools that greatly enhance your IT operations if implemented correctly."
"The tool's best feature was the UI and the simplicity it offers."
"Claroty provides continuous threat protection and identifies pre-empty stuff and false positives."
"Claroty identifies all vulnerabilities available in our environment."
"It helps me to get new sales, profits, and other benefits."
"Apart from getting all the bug bounty opportunities, we also get the chance to practice in a safe environment, like a demo setup. These features are great for beginners who want to explore bug bounties in the future."
"The most valuable feature of HackerOne is its variety of programs. These programs provide depth into various areas, such as mobile, API, and websites."
 

Cons

"Claroty Platform only gives the vulnerabilities based on the make and model of the devices, so it doesn't provide any resolution or any detailed explanation of how one can resolve such issues."
"We face issues in the alert investigation area because it does not properly give the alert communication patterns."
"The product could be improved in terms of user interface design."
"The graphical user interface is quite poor."
"There are a few protocols that Claroty doesn't currently support."
"Claroty Platform could improve the pricing to get more acceptability in the market."
"For improvement, I think the training could be more practical. We have external training, but they're mostly theoretical. I want the solution to provide hands-on lab experience to help users learn better."
"I've reported four bugs and three feature requests so far. The main area of focus should be on how attacks are detected. The attack vector information needs to be more detailed. For example, it's not enough to state that an SMB v1 version open can lead to a WannaCry attack. A more detailed explanation should help clients understand the various ways an attack could occur."
"Response time can be improved. The HackerOne Trust team can be slow to respond sometimes. They're not using AI, which could help reduce the number of duplicate reports."
"The ability to view the conversation between the triagers and the programs will be really good."
"One issue I've experienced is traffic. Many people try to participate when an opportunity with a bounty of around 1,000-15,000 dollars comes up. In this case, the first person to report the vulnerability gets the bounty. If a second person reports the same vulnerability, they are marked as duplicated instead of receiving some recognition. The second person also invested time finding the issue, so I think this can be improved."
 

Pricing and Cost Advice

"It's a bit expensive compared to other solutions."
"The licensing for physical devices is cheap, but the software version is expensive. The software version costs around 26-28 dollars. I was surprised and even double-checked. It was shocking."
"The tool is quite expensive."
"The solution is free."
"The tool is open-source and free for bug bounty hunters."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
814,528 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Manufacturing Company
15%
Energy/Utilities Company
12%
Financial Services Firm
5%
Computer Software Company
17%
Manufacturing Company
11%
Financial Services Firm
11%
University
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which solution do you prefer: Nozomi Networks or Claroty Platform?
Nozomi Networks and Claroty Platform are both leading operational technology (OT) security solutions offering a wide range of features, including asset discovery, risk assessment, and threat detect...
What do you like most about Claroty Platform?
The product helps mitigate potential threats, especially if its users have signature rules. The product also provides alerts.
What needs improvement with Claroty Platform?
For improvement, I think the training could be more practical. We have external training, but they're mostly theoretical. I want the solution to provide hands-on lab experience to help users learn ...
What needs improvement with HackerOne?
The ability to view the conversation between the triagers and the programs will be really good. When an issue gets reported, the understanding conveyed to the program by the triagers is not visible...
What is your primary use case for HackerOne?
I mainly use it for downtime activities, earning extra cash alongside a full-time job, and to get new sales and profits.
 

Comparisons

 

Also Known As

No data available
HackerOne Assets, HackerOne Pentesting Services, HackerOne Security Assessments, HackerOne Vulnerability Management
 

Learn More

 

Overview

 

Sample Customers

Rockwell Automation
Zenefits, Adobe, Yelp
Find out what your peers are saying about Claroty Platform vs. HackerOne and other solutions. Updated: October 2024.
814,528 professionals have used our research since 2012.