Likelihood to Recommend
It is best suited for integrated security testing of applications which are hosted on web servers. The most important thing is the integration of DevSecOps which is crucial in today's fast paced environment of rapid development. The core of Acunetix is application scanning which is really great and I highly recommend this product to everyone
Read full review
Onapsis is divided into 4 major components,
Assess Comply Defend Control
In assess, it does a whitebox and blackbox testing of the ERP systems that have been added to the Onapsis console. It highlights relevant application issues and automates the process, also provides the solutions to implement the fix. In comply, it provides a governance on the various regulatory compliances which the firm has to follow, as well as provides a firm grip to the audit and ERP admin team. In control, it enables a workflow of 15 pre-defined parameter values within the SAP system and helps monitor, and track the changes made to those parameters. The capabilities are to either block, or request for an approval for changes made to those parameters in addition to just monitoring them. In defend, it goes through the SAP logs; and compares it with a pre-defined ruleset to alert the end-users via email or SIEM tool or both.
Read full review Pros Fast. Easy-to-use. Great customer support. Reporting features. Supports importing state files from other popular application testing tools. Has other features built-in beyond just scanning for vulnerabilities. Read full review Eliminating the manual process improves the overall accuracy of results and also frees up valuable resources to focus on other different projects. Onapsis provides great leverage to our technical teams in order to review in a standardized way of the landscape. Onapsis always matches vulnerabilities with useful context and finds possible solutions. Onapsis is usually implemented to continuously monitor, and alert us on any issues on the SAP systems. Not only this but implementing Onapsis also eliminates the network on the year-end and month-end audits and helps in making the overall process faster, smooth, efficient as well as accurate. Read full review Cons Configuration of DevSecOps can be improved for ease Dashboard can have API integration Broaden the scope of vulnerabilities Read full review Multiple UIs No proper customization of UI log-off Tedious setup of Control component No proper error messages received Read full review Alternatives Considered
ZAP is a free tool, and adequate. But it is to that extent less friendly. I would not be as confident of the results and it definitely can't produce reports on par with Acunetix. There would be a lot of legwork on our end if we desired to switch to this tool.
Read full review
Honestly, I havent use something like Onapsis before and currently I am not aware if there is something similiar out there. They are one of a kind and is a complete suit, so is unlikelly that someone from outside will appear with a better solution.
Read full review Return on Investment Saved money compared to other commercial scanners, especially over the long run. Scan speed seems to be pretty good compared to some of the bulkier commercial products out there. However, that largely has to do with proper configuration. A downside is that is requires a bit of extra work just to get it set up to scan APIs, web services, etc. Read full review It offers very reasonable packages. The customer support of Onapsis is reliable and efficient. It is a great platform as it shows a unified and easy-to-read different and complex topics in a simpler way. Read full review ScreenShots Acunetix by Invicti Screenshots