Dear All,
Can you suggest 2 or 3 products that could compete with:
1. Fortify WebInspect
2. Fortify Static Code Analyzer
I need suggestions for similar products so I could compare for my consultant project.
Thanks in advance for the advice.
Regards
According to the IT Central Station community, the most popular alternatives to Fortify WebInspect are Micro Focus Fortify on Demand, OWASP Zap, PortSwigger Burp, and HCL AppScan. Hope that's helpful!
@Russell Rothstein Thank You russel
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
Rendra,
You need to ask yourself a few questions:
1. Do I know is the technology stack (languages) that needs to be supported?
2. Do I have access to the Source Code, just Binaries OR Both?
3. Do I need to support SCA(FOSS)
4. Do I need a unified Dashboard for reporting for SAST, DAST & SCA?
5. What is the size of the experienced team I have to support this?
For a DAST solution:
1. What is the size of the experienced team I have to support this?
2. Do I want the DAST to integrate with other tools (BurpSuite, MetaSploit, WAF, etc)
3. Do I want the DAST to automate from a Postman Script, Jenkins Build Server, JIRA, ServiceNow, etc.
4. Do I need a unified Dashboard for reporting for SAST, DAST & SCA?
Instead of asking who can compete with Fortify, it might be better to ask who can compliment Fortify OR what did I dislike most about Fortify. Then find some others who will give you a fair and unbiased opinion.
When you look at the top 4 players in the market being Fortify, VeraCode, Checkmarx, Synopsys.... what do you see? Then ask why? (Hint...all top leadership and top sales begin at Fortify)
Hope this helps.
Fortify Static Code Analyzer is actually NOT an SCA (Software Composition Analysis) tool! It competes more with Checkmarx and Veracode
@Oscar Van Der Meer Fortify SCA (Static Code Analyzer) was around way before SCA (Software Composition Analysis). There are various integrations with Software Composition Analysis (SonaType, BlackDuck, Snyk, WhiteSource, and OWASP Dependency Checker & Track. The reason behind it is to allow customers the flexibility to integrate with the tool the line of business chooses within the corporation.