Try our new research platform with insights from 80,000+ expert users
Amr Abdelnaser - PeerSpot reviewer
Senior Information Security Analyst at EastNets Holding Ltd.
Real User
Top 5Leaderboard
Conducts general scan which wastes time
Pros and Cons
  • "We use the tool for our websites. We have a vulnerable subdomain. The tool helps to scan it for vulnerabilities."
  • "Tenable.io Web Application Scanning conducts a general scan, which wastes time. The scan needs to be specific."

What is our primary use case?

We use the tool for our websites. We have a vulnerable subdomain. The tool helps to scan it for vulnerabilities. 

What needs improvement?

Tenable.io Web Application Scanning conducts a general scan, which wastes time. The scan needs to be specific. 

For how long have I used the solution?

I have been working with the product for two years. 

What do I think about the scalability of the solution?

Tenable.io Web Application Scanning is scalable. We have two users for the product. We don't use it extensively. 

Buyer's Guide
Application Security Tools
January 2025
Find out what your peers are saying about Tenable, Invicti, PortSwigger and others in Application Security Tools. Updated: January 2025.
838,713 professionals have used our research since 2012.

What about the implementation team?

We deployed the tool using in-house resources. 

What other advice do I have?

I rate the product a two out of ten. I am unsatisfied with the product and don't recommend it.  

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1990596 - PeerSpot reviewer
Director of Cyber Security at a outsourcing company with 501-1,000 employees
Reseller
Simple deployment, priced well, and reliable
Pros and Cons
  • "The most valuable features of Tenable.io Web Application Scanning are the integration into specific use cases and scanning. All of the features of the solution are useful."
  • "Tenable.io Web Application Scanning could improve by offering faster fuzzing."

What is our primary use case?

We are using Tenable.io Web Application Scanning for security assurance, workability management, and patch management.

What is most valuable?

The most valuable features of Tenable.io Web Application Scanning are the integration into specific use cases and scanning. All of the features of the solution are useful.

What needs improvement?

Tenable.io Web Application Scanning could improve by offering faster fuzzing.

For how long have I used the solution?

I have been using Tenable.io Web Application Scanning for approximately one year.

What do I think about the stability of the solution?

Tenable.io Web Application Scanning is stable.

What do I think about the scalability of the solution?

We have not had any problems with the scalability of Tenable.io Web Application Scanning.

How are customer service and support?

I provide support to my customers. I have not run into an issue that I needed to contact the support from Tenable.io Web Application Scanning.

How was the initial setup?

The initial deployment of Tenable.io Web Application Scanning is easy.

I rate the initial setup of the Tenable.io Web Application Scanning a five out of five.

What about the implementation team?

We did the deployment of the solution.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is reasonable compared to the competitors. The license cost is based on the number of users and the annual usage.

What other advice do I have?

If customers need a cost-efficient way to do very good ramification scanning and vulnerability management, this is the right solution. It's a valuable piece of technology.

I rate Tenable.io Web Application Scanning a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
Application Security Tools
January 2025
Find out what your peers are saying about Tenable, Invicti, PortSwigger and others in Application Security Tools. Updated: January 2025.
838,713 professionals have used our research since 2012.
reviewer1248330 - PeerSpot reviewer
Security Specialist at a security firm with 51-200 employees
Real User
Collects the vulnerabilities on the hostnames and sends them to the cloud
Pros and Cons
  • "It collects the vulnerabilities on the hostnames and sends them to the Tenable.io cloud. Tenable has its own cloud where Tenable.io is running, but there are many connectors to other cloud solutions. Tenable can do vulnerability scanning for other cloud managers such as Azure, Amazon, and so on."
  • "They have a general dashboard for web application scanning, but the dashboards and reporting can be improved. They probably have some features in their roadmap."

What is our primary use case?

I work for a security company, and I implement Tenable for our customers. I just implement this technology. I'm not working with the users. 

Our main use case is for implementing and starting scans for the whole company or a specific host. It is used for creating reports or dashboards for the vulnerabilities of the whole company. As a product for web application scanning, the results are uploaded to the cloud, and the management is on the cloud, but we can implement an on-premises scanner, or we can scan the on-premises web applications of our customers.

What is most valuable?

It collects the vulnerabilities on the hostnames and sends them to the Tenable.io cloud. Tenable has its own cloud where Tenable.io is running, but there are many connectors to other cloud solutions. Tenable can do vulnerability scanning for other cloud managers such as Azure, Amazon, and so on.

What needs improvement?

They have a general dashboard for web application scanning, but the dashboards and reporting can be improved. They probably have some features in their roadmap.

For how long have I used the solution?

I have been working for this company for two years and eight months, and I have had many opportunities to implement Tenable.

What do I think about the stability of the solution?

It is a cloud solution. It has 100% reliability.

What do I think about the scalability of the solution?

Being a cloud solution, it must be scalable.

How are customer service and support?

In general, it is fast. In some cases, we need L3 support, which can take some time, but overall, it is really fast. As compared to other vendors who implemented such solutions, the support is fast.

How was the initial setup?

It is a complex solution. Tenable.io is an enterprise solution. So, it is not that easy to set up.

The deployment duration varies depending on the size of a company. It can take five days, and it can also take a month.

What about the implementation team?

We have our own team. The number of people required for its deployment varies, but we have been able to implement it for most of the projects with just three people.

For its maintenance, we have five or six people in support.

What other advice do I have?

I would rate it a nine out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Software Asset Management/Software & Cloud Analytics Consultant at Crayon Group
Real User
Top 20
Gives detailed information about vulnerabilities but support is not responsive
Pros and Cons
  • "We can get detailed information about vulnerabilities."
  • "Tenable.io Web Application Scanning is not very user-friendly and you need a lot of information to get proper reports. The tool's support is not very responsive."

What is our primary use case?

We used the solution to asses the security risk of our client's customer-facing platform. 

What is most valuable?

We can get detailed information about vulnerabilities. 

What needs improvement?

Tenable.io Web Application Scanning is not very user-friendly and you need a lot of information to get proper reports. The tool's support is not very responsive. 

For how long have I used the solution?

I have been working with the solution for more than half a year. 

What do I think about the stability of the solution?

I would rate Tenable.io Web Application Scanning's stability a nine out of ten. 

What do I think about the scalability of the solution?

I alone use the product.

How was the initial setup?

I would rate the tool's setup a seven out of ten. We encountered some challenges during the installation process. We have deployed it over the cloud which took about a week to complete. You need to make the environment ready, connect and scan it. 

What's my experience with pricing, setup cost, and licensing?

Tenable.io Web Application Scanning is expensive for small businesses. 

What other advice do I have?

I would rate the solution a nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Flag as inappropriate
PeerSpot user
OniRahman - PeerSpot reviewer
Technical Consultant at a tech consulting company with 51-200 employees
Real User
A good automated scanning solution but could be more flexible with customization
Pros and Cons
  • "It is fully automated."
  • "The report customization needs to be better."

What is our primary use case?

Our primary use case for the solution is automated scanning. It doesn't require scripting knowledge or any of those suites or other tools. So it is fully automated, and we provide the credentials and URL. The tool does all scanning and will show the result per the requirement.

What is most valuable?

We find the scanning and reporting features most valuable.

What needs improvement?

For the OWASP there is a predefined dashboard but a detailed report template would have been perfect . The report customization needs to be better. It can be more flexible in the customization. Additionally, the API Scanning features can be improved.

For how long have I used the solution?

We have been using the solution for a couple of years and currently use Tenable.io and Tenable Vulnerability Management, which are grouped in a single dashboard.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

I rate customer service and support a six out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We used Qualys WAS previously but the exact scanning and reporting features we were looking was not there.

How was the initial setup?

The initial setup is straightforward. It uses the external scanners provided, so it does not require additional effort to configure it in our WAS. Furthermore, it does not require any time to deploy because it comes pre-configured with Tenable.io Web Application Scanning.

What's my experience with pricing, setup cost, and licensing?

The minimum license starts from $3,578.

What other advice do I have?

I rate the solution a seven out of ten. The solution is good, but the API scanning features and the flexibility of the report customization can be improved. My advice to new users considering the solution is to go through the documentation on YouTube videos provided by Tenable, and you can get started right away.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Mahmoud Elhamaymy - PeerSpot reviewer
Professional services team lead at a tech services company with 1,001-5,000 employees
Reseller
User-friendly GUI, simple to manage, the support is excellent and quick to respond
Pros and Cons
  • "Tenable.io Web Application Scanning is very easy to use."
  • "The reporting has a very limited customization capability."

What is our primary use case?

Tenable.io Web Application Scanning is very useful for scanning container exposure, and also for scanning all of the external IP addresses for any organization using Tenable predefined scanners.

What is most valuable?

It's a good product. It works as expected.

Tenable.io Web Application Scanning is very easy to use.

It provides very reliable results.

It is very useful. 

The GUI is very easy to use, for anyone.

It is easily managed by someone who lacks prior knowledge, information, or experience.

What needs improvement?

The reporting in Tenable.io Web Application Scanning is not as good as the reporting in Tenable SC. Tenable SC's reporting is extremely powerful.

The reporting has a very limited customization capability. It would be beneficial if this feature could be enhanced.

For how long have I used the solution?

I have been using Tenable.io Web Application Scanning for three years.

What do I think about the stability of the solution?

Tenable.io Web Application Scanning is extremely stable.

What do I think about the scalability of the solution?

Tenable.io Web Application Scanning is very easy to scale. 

The scalability surpasses Tenable.sc. All of the resources are based on the cloud. You don't need to add any extra resources if you want to add any external scanning or any internal scanners for the hardware specifications. This solution is very scalable.

How are customer service and support?

I have dealt with technical support once. They were very good and very responsive.

Which solution did I use previously and why did I switch?

I have also worked with Tenable SC. Asset management is a bit different.

How was the initial setup?

There is no need to install anything. You get it pre-installed from the vendor.

You have access to the GUI, and log in with your credentials.

What's my experience with pricing, setup cost, and licensing?

It follows the same licensing scheme as Tenable.io and Tenable SC.

A separate license is required for support.

I can't be certain, but I believe the fees are determined by the number of IP addresses or users.

What other advice do I have?

I would recommend this solution to others who are interested in using it.

I would rate Tenable.io Web Application Scanning an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer889494 - PeerSpot reviewer
Security Consultant at a tech consulting company with 51-200 employees
Consultant
Multi-faceted solution that offers good replication testing and vulnerability assessment
Pros and Cons
  • "Our customers adopt this solution because of the replication testing and the vulnerability assessment it can do. It is a multi-faceted product."
  • "I would like for them to add proxy filtering, where you can transfer and alter the package. It is fully automated. Other web application testers programs are actually proxy software, and the proxy software gives you the flexibility of modifying the outgoing package, which will actually help you in exploiting any vulnerability in detail."

What is most valuable?

Our customers adopt this solution because of the replication testing and the vulnerability assessment it can do. It is a multi-faceted product. 

What needs improvement?

I would like for them to add intervening proxy, whereby you can alter the get/put requests. It is fully automated. Other web application testers programs are actually proxy software, and the proxy software gives you the flexibility of modifying the outgoing traffic packets which will actually help you in exploiting any vulnerability in detail.

What do I think about the stability of the solution?

It is quite stable. We haven't had any bugs. 

What do I think about the scalability of the solution?

There is no need to scale, because generally the customers, whenever they scan their applications, they generally take a couple of applications at a time. And Tenable.io is already cloud instituted so you don't have to worry about that aspect.

How are customer service and technical support?

I never needed to contact support. It is very easy to understand and easy to configure. 

What other advice do I have?

I would rate it an eight out of ten. 

To make it a ten, I would like for there to be more flexibility for the testers. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Cyber Security Architect at a comms service provider with 10,001+ employees
Real User
Centralized license management transforms asset manipulation based on functions and improves security posture
Pros and Cons
  • "Now that the license is centralized, it's a significant feature to manipulate assets based on their functions."
  • "I would recommend Tenable.io Web Application Scanning to others."
  • "The market is standard for vulnerability scanning, however, the posture can be improved through Tenable's prioritization engine."

What is our primary use case?

I have at least three use cases. One is for ITDR solutions for threat detection. Another is the vulnerability scanning process that I designed and implemented across five companies based on Gartner implementation papers, and one is for OT.

What is most valuable?

Now that the license is centralized, it's a significant feature to manipulate assets based on their functions. It provides a centralized view from end-to-end to its assets' identities and vulnerabilities. 

One of the greatest features is Kubernetes. The automated scanning capability is pretty standard in the market, and Tenable's prioritization engine helps improve the security posture.

What needs improvement?

The market is standard for vulnerability scanning, however, the posture can be improved through Tenable's prioritization engine. This is one key area for improvement.

For how long have I used the solution?

From Tenable itself, I have close to three to five years of experience. Additionally, I did some three or four implementations over the course of my career.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

Scalability is very easy. It uses distributive engines by default, making it scalable as a default setting.

How are customer service and support?

Tenable services in Brazil are regional services. The global services would be rated around nine, while the global and local services are around seven or eight out of ten. We usually have to talk to the reseller, who then escalates it to Tenable.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

People usually use Microsoft Defender. It does vulnerability scanning at some level but not in the active manner Tenable does. Tenable has all three fronts, whereas Defender does not run through vulnerability engines at the same time.

How was the initial setup?

The setup is pretty straightforward and is plug and play. The engines report back to the cloud platform, and the documentation is centralized and easy to follow.

What about the implementation team?

The security team consisted of around five to six professionals, mostly security analysts, security architects, and a network engineer. The company's size is about 30,000 employees.

What was our ROI?

The ROI is feasible when considering the mean time to resolve. Security metrics help determine how long it takes to solve a vulnerability, and once the product is installed, you can see the difference. A business impact analysis on costs makes it easy to calculate the ROI.

What's my experience with pricing, setup cost, and licensing?

The pricing is market standard and comparable to the competition.

What other advice do I have?

I would recommend Tenable.io Web Application Scanning to others. 

I rate the overall solution a nine out of ten.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Application Security Tools Report and find out what your peers are saying about Tenable, Invicti, PortSwigger, and more!
Updated: January 2025
Product Categories
Application Security Tools
Buyer's Guide
Download our free Application Security Tools Report and find out what your peers are saying about Tenable, Invicti, PortSwigger, and more!