TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    HackerOne

    Score9 out of 10
    N/AHackerOne is a hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be exploited, from the company of the same name in San Francisco. The service is used for vulnerability location, pen testing, bug bounty, and vulnerability triage services.N/A

    Qualys VMDR

    Score9.4 out of 10
    N/AQualys VMDR 2.0 with TruRisk gives enterprises visibility and insight into cyber risk exposure with the goal of making it easy to prioritize vulnerabilities, assets, or groups of assets based on business risk. Security teams can take action to mitigate risk, helping the business measure its true risk, and track risk reduction over time.N/A
    Pricing
    HackerOneQualys VMDR
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    HackerOneQualys VMDR
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional DetailsFor more information please email www.hackerone.com/contact or find us on the AWS Marketplace: https://aws.amazon.com/marketplace/seller-profile?id=10857e7c-011b-476d-b938-b587deba31cf—
    More Pricing Information
    Community Pulse
    HackerOneQualys VMDR
    Considered Both Products
    HackerOne
    No answer on this topic
    Qualys
    No answer on this topic
    Key User Insights
    Would buy again
    No answers on this topic
    86%
    Would buy again
    6 Answers
    Delivers good value for the price
    No answers on this topic
    100%
    Delivers good value for the price
    6 Answers
    Happy with the feature set
    No answers on this topic
    100%
    Happy with the feature set
    7 Answers
    Lived up to sales and marketing promises
    No answers on this topic
    100%
    Lived up to sales and marketing promises
    6 Answers
    Implementation went as expected
    No answers on this topic
    100%
    Implementation went as expected
    6 Answers
    Features
    HackerOneQualys VMDR
    Threat Intelligence
    Comparison of Threat Intelligence features of HackerOne and Qualys VMDR
    Feature
    HackerOne
    -
    Ratings
    Qualys VMDR
    8.4
    7 Ratings
    4% above category average
    Network Analytics00 Ratings7.47 Ratings
    Threat Recognition00 Ratings8.07 Ratings
    Vulnerability Classification00 Ratings9.67 Ratings
    Automated Alerts and Reporting00 Ratings9.27 Ratings
    Threat Analysis00 Ratings8.67 Ratings
    Threat Intelligence Reporting00 Ratings8.07 Ratings
    Automated Threat Identification00 Ratings8.07 Ratings
    Vulnerability Management Tools
    Comparison of Vulnerability Management Tools features of HackerOne and Qualys VMDR
    Feature
    HackerOne
    -
    Ratings
    Qualys VMDR
    8.8
    7 Ratings
    6% above category average
    IT Asset Realization00 Ratings9.07 Ratings
    Authentication00 Ratings8.47 Ratings
    Configuration Monitoring00 Ratings9.07 Ratings
    Web Scanning00 Ratings8.66 Ratings
    Vulnerability Intelligence00 Ratings9.27 Ratings
    Best Alternatives
    HackerOneQualys VMDR
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    No answers on this topic
    Tenable Nessus
    Score8.8 out of 10
    Enterprises
    No answers on this topic
    Tenable Vulnerability Management
    Score8.9 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    HackerOneQualys VMDR
    Likelihood to Recommend
    7.0
    (2 ratings)
    9.6
    (7 ratings)
    Likelihood to Renew
    -
    (0 ratings)
    10.0
    (1 ratings)
    Usability
    -
    (0 ratings)
    8.4
    (2 ratings)
    Availability
    -
    (0 ratings)
    10.0
    (1 ratings)
    Performance
    -
    (0 ratings)
    9.0
    (1 ratings)
    Support Rating
    -
    (0 ratings)
    8.0
    (2 ratings)
    Implementation Rating
    -
    (0 ratings)
    9.0
    (1 ratings)
    Configurability
    -
    (0 ratings)
    9.0
    (1 ratings)
    Contract Terms and Pricing Model
    -
    (0 ratings)
    9.0
    (1 ratings)
    Ease of integration
    -
    (0 ratings)
    9.0
    (1 ratings)
    Product Scalability
    -
    (0 ratings)
    9.0
    (1 ratings)
    Vendor post-sale
    -
    (0 ratings)
    8.0
    (1 ratings)
    Vendor pre-sale
    -
    (0 ratings)
    8.0
    (1 ratings)
    User Testimonials
    HackerOneQualys VMDR
    Likelihood to Recommend
    HackerOne
    It is one of the good platforms for security researchers to submit bugs and other vulnerabilities, it however, has some challenges, in terms of un-verified and duplicate submissions.
    Incentivized
    Read full review
    Qualys
    Qualys VMDR is best suited for larger companies with a very large IT asset footprint. Qualys VMDR is not suited for businesses that are small and upcoming as the price for the tool is very expensive and could be a budget sink if not used properly. In our organization we use the Qualys VMDR dashboard and reporting in order to collect any vulnerabilities we miss during our routine audits to ensure that our environment is stable and protected for attacks.
    Incentivized
    Read full review
    Pros
    HackerOne
    • Filter for spammy bug reports
    • Nice central interface
    • Payment/reward system is nice
    Incentivized
    Read full review
    Qualys
    • Seamless reporting across the different widgets (i.e. TruRisk)
    • DEEP-DIVE into an asset's info/vulns
    • Baked-in PCI ASV scans that a Qualys QSA can approve
    Incentivized
    Read full review
    Cons
    HackerOne
    • A lot of duplicate bugs get reported, although it does offer automatic suggestion of previously reported bugs that may be duplicates, it is far from perfect.
    • Anyone can report bugs, a lot of them are not verified before submission. This sometimes leads to a lot of time spent in verifying if the bug is really actionable.
    • Each submission has to be treated with equal potential, a lot of time, some time gets invested in vulnerabilities that aren't as important as some others.
    Incentivized
    Read full review
    Qualys
    • Qualys VMDR can definitely improve on its reporting of assets as we have caught devices not captured in the Qualys VMDR scans.
    • We would like to see an improvement on the dashboard interface as it is faulty sometimes.
    • Qualys VMDR should focus on more competitive pricing as it is very expensive.
    Incentivized
    Read full review
    Likelihood to Renew
    HackerOne
    No answers on this topic
    Qualys
    Next to Veeam (which is a tremendous product for backup/DR) this is the best service/software I have used in the past three decades. Should be called the Swiss Army Knife of security.
    Incentivized
    Read full review
    Usability
    HackerOne
    No answers on this topic
    Qualys
    infrastructure to identify vulnerabilities
    Read full review
    Reliability and Availability
    HackerOne
    No answers on this topic
    Qualys
    Always available with the exception on maint windows
    Incentivized
    Read full review
    Performance
    HackerOne
    No answers on this topic
    Qualys
    Once in a while it would be slow -
    Incentivized
    Read full review
    Support Rating
    HackerOne
    No answers on this topic
    Qualys
    This is iron but I am giving it 5 star and I can give more If I can do because they are best in support. So once you own this product they will assign a dedicated support for you and when you are under the weather with anything just connect them with anything call, ping or ticket they will come like Genie.
    Read full review
    Implementation Rating
    HackerOne
    No answers on this topic
    Qualys
    Not really - the integrations via connectors is not heavy lifting. Any complexity has to do with a service that requires more steps (i.e. AWS/GCP)
    Incentivized
    Read full review
    Alternatives Considered
    HackerOne
    These were very close and we liked HackerOne better. For a time we did have both and we felt the need to consolidate the information into one platform and end of life our internal offering. Overall we've been fairly happy with HackerOne.
    Incentivized
    Read full review
    Qualys
    It is a very similar tool but Qualys VMDR is much better when it comes to reporting and solutions provided. Asset management is really good in Qualys VMDR. Qualys VMDR support is really quick , you can get a TPM if you run into any issues. Qualys VMDR has wide variety of scanning options which lacks in tenable.
    Incentivized
    Read full review
    Contract Terms and Pricing Model
    HackerOne
    No answers on this topic
    Qualys
    MOSTLY good - but as noted having all features purchased on portal only - nothing that is not purchased.
    Incentivized
    Read full review
    Scalability
    HackerOne
    No answers on this topic
    Qualys
    Outside some pretty arcane apps or OS this is painless. The problem - and self-inflicted - is that older stuff is not supported.
    Incentivized
    Read full review
    Return on Investment
    HackerOne
    • Bugs that can't be tracked internally are submitted by external researchers, which is an important factor for security vulnerabilities.
    • Even if the bugs reported are duplicates, there still is provision to award reputation points, that keep the researchers engaged.
    • It also requires a lot of verification and validation, as a lot of the submissions are unverified to begin with.
    Incentivized
    Read full review
    Qualys
    • Cut down on manual efforts to investigate or remediate vulnerabilities, which can be a big driver of ROI
    • Avoidance of potential incidents with upfront risk mitigation
    • Patching efficiency gains
    Incentivized
    Read full review
    ScreenShots