Try our new research platform with insights from 80,000+ expert users

HackerOne vs Tenable Security Center comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 14, 2024
 

Categories and Ranking

HackerOne
Ranking in Vulnerability Management
42nd
Average Rating
8.6
Number of Reviews
4
Ranking in other categories
Application Security Tools (34th), Bug Bounty Platforms (1st), Penetration Testing Services (2nd), Attack Surface Management (ASM) (12th)
Tenable Security Center
Ranking in Vulnerability Management
2nd
Average Rating
8.2
Number of Reviews
50
Ranking in other categories
Cloud Security Posture Management (CSPM) (12th), Risk-Based Vulnerability Management (1st)
 

Featured Reviews

VS
Sep 16, 2024
They have streamlined the complete process, which gives a sense of security to the users
I mainly use it for downtime activities, earning extra cash alongside a full-time job, and to get new sales and profits It helps me to get new sales, profits, and other benefits. The main thing I like about HackerOne is that it provides a direct way to contact the program directly without the…
OniRahman - PeerSpot reviewer
May 8, 2024
Great Predictive Prioritization and Risk-based VM with good reliability
In Tenable SecurityCenter, the Risk-based approach for Prioritizing vulnerability is something that is unique to any vulnerability management platform. Compared to Qualys and Rapid7, Tenable VPR is a special thing that those products don't have. The security over the CVSS and V1 and V2 with the VPR feature help an organization reveal the exact risk of any asset. There might be thousands of vulnerabilities, however, the most impactful vulnerabilities are listed and prioritized in the VPR. As tenable SecurityCenter is powered by popular Nessus technology, It is really easy to set up. The solution is stable and considered as the most solid vulnerability management platform in the industry. Tenable.sc provides a wide range of dashboards which makes it easy to grasp the vulnerability profile of the organization. These dashboards allow us to view vulnerabilities in different categories in a simple to understand format. The upgrade to Tenable.sc+ has improved on this as well. Regularity of plugin updates are also exceptional. The speed at which tenable has pushed plugin updates and overall platform updates is great. Also the automatic update capability makes maintenance very simplified. Easy to use User interface. For someone who is not familiar with Tenable.sc, the interface is not difficult to follow along and the documentation makes it very simple for anyone The solution has a very nice Asset discovery feature that gives you gives you unified visibility of your entire attack surface, As It leverages Nessus Sensors, a mix of active scanners, agents, passive network monitoring, and CMDB integrations to maximize scan coverage across your infrastructure to reduce vulnerability blind spots. This mix of data sensor types helps you track and assess both known and unknown assets and their vulnerabilities

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of HackerOne is its variety of programs. These programs provide depth into various areas, such as mobile, API, and websites."
"Apart from getting all the bug bounty opportunities, we also get the chance to practice in a safe environment, like a demo setup. These features are great for beginners who want to explore bug bounties in the future."
"It helps me to get new sales, profits, and other benefits."
"The scans are the most valuable aspect of this solution."
"We use Tenable to scan all of our environments and plugins for vulnerabilities. Tenable helps us discover network vulnerabilities to threats and piracy."
"The solution has a lean and easy-to-use interface that is not confusing to first-time users."
"Tenable is the leading product for vulnerability scanning."
"The product is our second solution, and we are happy that it meets our requirements."
"Has a great advanced scanning feature."
"Tenable SC's most valuable features are the low number of false positives and the strong capability of providing prioritization for the vulnerabilities detected."
"One of the most valuable features is their distributed scan model for allotting engines to work together as a pool and handle multiple scans at once, across multiple environments. Automatic scanning distribution is a distinguishing feature of their toolset."
 

Cons

"One issue I've experienced is traffic. Many people try to participate when an opportunity with a bounty of around 1,000-15,000 dollars comes up. In this case, the first person to report the vulnerability gets the bounty. If a second person reports the same vulnerability, they are marked as duplicated instead of receiving some recognition. The second person also invested time finding the issue, so I think this can be improved."
"Response time can be improved. The HackerOne Trust team can be slow to respond sometimes. They're not using AI, which could help reduce the number of duplicate reports."
"The ability to view the conversation between the triagers and the programs will be really good."
"For downloading reports, we have to go to the scan and then we have to go to the reports and download the Excel or CSV or PDF. I think these menus and clicks can be minimized."
"Its reporting can be improved. It is not easy to generate a scan report the way we want. The data is okay, but we can't easily change the template to make it look the way we want."
"Tenable SC can improve by adding more integrations with HCI-type tools and more accurate vulnerability detection."
"The web application is not very functional."
"The pricing is reasonable, but this could be brought down more aggressively, such as we see with Rapid7, Tenable SC's main competitor."
"Additional costs are associated with using the solution, as additional scanners are required for different endpoints connected to the Tenable Security Center. If Tenable Security Center could extract information from these scanners automatically rather than manually, it would enhance user-friendliness for customers."
"Certain aspects require manual effort, such as exporting and analyzing data for our dashboards. The built-in components of the Tenable solution are somewhat clumsy that require external tools. So, this is an area of improvement."
"The user interface can be improved."
 

Pricing and Cost Advice

"The tool is open-source and free for bug bounty hunters."
"The solution is free."
"I use a local license to perform penetration testing and I'm pretty happy with everything when it comes to pricing and licensing."
"Costing is pretty reasonable compared to the competition."
"We're happy with the licensing cost and find it affordable."
"This solution's price is quite high."
"Tenable SC is priced per asset, with the basic solution starting around US$12,000 for 500 assets."
"The pricing is more than Nexpose."
"The pricing depends upon the number of IPs."
"Compared to other companies or other products it could maybe be a little bit less, but the price is okay. I would say it's not very expensive."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
805,335 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Manufacturing Company
12%
Financial Services Firm
11%
Comms Service Provider
7%
Educational Organization
19%
Computer Software Company
12%
Government
11%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What needs improvement with HackerOne?
Response time can be improved. The HackerOne Trust team can be slow to respond sometimes. They're not using AI, which could help reduce the number of duplicate reports.
What is your primary use case for HackerOne?
I use the tool for vulnerability assessment and testing.
What do you like most about Tenable SC?
The tool's dashboard and reporting capabilities match our company's needs since we are able to modify the basic view to create a new dashboard, and it works out very well for our needs.
What is your experience regarding pricing and costs for Tenable SC?
For enterprise customers, it's acceptable. However, for smaller enterprises or businesses, the budget may be too restrictive to consider such extensive solutions. When proposing to small-scale indu...
What needs improvement with Tenable SC?
They are not currently handling call flows properly. Some call flows are being deleted from the registry but still show as active. Support is also lacking in onboarding properly in this area. This ...
 

Also Known As

HackerOne Assets, HackerOne Pentesting Services, HackerOne Security Assessments, HackerOne Vulnerability Management
Tenable.sc, Tenable Unified Security, Tenable SecurityCenter
 

Learn More

 

Overview

 

Sample Customers

Zenefits, Adobe, Yelp
IBM, Sempra Energy, Microsoft, Apple, Adidas, Union Pacific
Find out what your peers are saying about HackerOne vs. Tenable Security Center and other solutions. Updated: September 2024.
805,335 professionals have used our research since 2012.