Try our new research platform with insights from 80,000+ expert users

PortSwigger Burp Suite Enterprise Edition vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024
 

Categories and Ranking

PortSwigger Burp Suite Ente...
Ranking in Vulnerability Management
22nd
Average Rating
8.0
Reviews Sentiment
7.4
Number of Reviews
11
Ranking in other categories
Dynamic Application Security Testing (DAST) (5th)
Tenable Nessus
Ranking in Vulnerability Management
1st
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
80
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of December 2024, in the Vulnerability Management category, the mindshare of PortSwigger Burp Suite Enterprise Edition is 1.2%, down from 1.3% compared to the previous year. The mindshare of Tenable Nessus is 12.6%, down from 15.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
 

Featured Reviews

Hasan Abufreiha - PeerSpot reviewer
Used for web application auditing and security audits for web applications
I would advise users to limit Burp Suite usage to specific scenarios and applications. Users should use the solution as an expert testing tool instead of using it as a general scanner or for information gathering in general. The tool might be overwhelming initially for new users, but it will be easy after you get used to the UI, features, and options. PortSwigger Burp Suite Enterprise Edition has been doing an amazing job for years compared to other similar tools. Overall, I rate the solution an eight out of ten.
Matthew Weisler - PeerSpot reviewer
Unlimited assets for one price and quick, agentless results
The solution has a single price for unlimited assets. Value wise, the solution is also great for pen testers and consultants. The solution is useful for vulnerability and patch management from both the internal and public facing sides. Quick assessments, compliance scores, and results are provided without having to do agents.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Parallel scans can be done with PortSwigger Burp Suite Enterprise Edition."
"The most valuable part of it was probably the ability to intercept and modify calls."
"I like normal dynamic scanning, general web applications scanning, and vulnerability assessments."
"The product's initial setup phase was super easy."
"This tool helps identify vulnerabilities. We then provide the report to the developers, who address the issues identified automatically. Its most valuable feature is CI/CD integration."
"The product is easy to use."
"The tool is loaded with many features that give us ROI."
"The initial setup is straightforward."
"I like its ease of use. It has the script that is pre-built in it, and you just got to know which ones you're looking for."
"The plug-in text information is quite useful."
"Tenable Nessus has a good performance, is very user-friendly, and is easy to use."
"The most valuable feature of Tenable Nessus is vulnerability assessments. There are a lot of threats around the world and this solution is the first to come out with detection rules."
"The scanning capabilities are most valuable when compared to Nessus."
"Nessus is effortless to integrate."
"Once you get past the initial implementation, the solution is very stable."
"Easy to set up vulnerability scanner with good stability and a responsive technical support team."
 

Cons

"The cost per license per user could be cheaper, specifically for individual licensing."
"It would be better if the solution is cloud-based."
"The stability of the scans could be improved."
"There's definitely room for improvement. There are lots of false positives. Once I do the manual assessment, it comes as a false positive. They need to improve the Enterprise Edition, especially the part that gives false positives."
"The implementation of the solution is quite complicated and could be easier."
"Scalability could be better."
"There are features or functionality missing, but PortSwigger Burp Suite Enterprise Edition does try to update frequently to alleviate the shortcomings."
"From my personal experience, the solution's performance could be improved."
"The reports are okay, but the interface is a bit difficult to navigate in some cases."
"Tenable Nessus could improve the price."
"The reporting is a bit cumbersome."
"The features are limited when it comes to scanning network devices for vulnerabilities."
"Nessus' reporting could be more user-friendly."
"I would like to have a management option after the network scanning."
"They could make their reporting a little better."
"Tenable Nessus could improve by having more steady updates which will reduce the vulnerabilities."
 

Pricing and Cost Advice

"The tool's pricing is reasonable and costs around 400 dollars per year."
"For Professional, it's about $400 per year."
"Although the solution can be a bit expensive for small companies, its pricing is fairly reasonable for its capabilities."
"PortSwigger Burp Suite Enterprise Edition is expensive compared to other solutions."
"PortSwigger Burp Suite Enterprise Edition is neither a cheap nor an expensive product. PortSwigger Burp Suite Enterprise Edition is a good tool for companies."
"In general, it is extremely expensive."
"We pay approximately $2,500 on a yearly basis."
"The price of Tenable Nessus is too expensive for each service center."
"The newer tools are quite pricey. There is a case of some fine tuning that can be done in terms of licensing. The IP based licensing that is offered makes the tool very expensive. If they want the IT industry to adopt it, the price should be looked at."
"Nowadays, your vulnerability applications are going to be kind of pricey because lots of them, including Rapid7, are based upon a base price, but then they add in the nodes. That's where they get you. If you're a big network, obviously, you need to scan everything. Therefore, it's going to be costly. The risk and insurance money associated with having ransomware on my networks is going to cost me more money, time, and marketing than the price of the tool. That's why I'm speaking only as an information security officer to security operations. This is the tool that is there in my toolbox to say whether we vulnerable or not. At this point, I don't care about how much it costs my company to have it because if I wasn't able to report it and we got ransomware, then who cares? I'm probably going to be out of business because it happened. That's why I don't care about the price. I have it, and I could use it effectively and do my report. At the end of the day, even if we get ransomware, as long as I reported it, followed my protocol, and put in the change, irrespective of whether it was ignored or denied, I did my job."
"The price of the solution is reasonable."
"There is an annual license required to use this solution."
"When comparing the price of Tenable Nessus to other similar solutions, such as Acunetix, Tenable Nessus is not as expensive. It is averagely priced in the market. We pay for the solution annually."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
13%
Government
8%
Manufacturing Company
7%
Educational Organization
40%
Computer Software Company
9%
Government
6%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about PortSwigger Burp Suite Enterprise Edition?
Parallel scans can be done with PortSwigger Burp Suite Enterprise Edition.
What is your experience regarding pricing and costs for PortSwigger Burp Suite Enterprise Edition?
For Enterprise, I'm not sure of the pricing. For Professional, it's about $400 per year. If you're using it as it should be used, the pricing is reasonable based on the benefits it provides.
What needs improvement with PortSwigger Burp Suite Enterprise Edition?
Scalability could be better. It's primarily focused on dynamic application security testing but might require integration with another platform to handle larger environments efficiently.
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What do you like most about Tenable Nessus?
We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equi...
 

Overview

 

Sample Customers

Nasa, Disney, Dow Jones, Iberia Bank, IBM, Ernest and Young, Apple, Ryanair, Thyssenkrupp, Delivery Hero
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about PortSwigger Burp Suite Enterprise Edition vs. Tenable Nessus and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.