TrustRadius: an HG Insights company

HackerOne vs. Tenable Attack Surface Management

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    HackerOne

    Score9 out of 10
    N/AHackerOne is a hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be exploited, from the company of the same name in San Francisco. The service is used for vulnerability location, pen testing, bug bounty, and vulnerability triage services.N/A

    Tenable Attack Surface Management

    Score6.1 out of 10
    N/ATenable Attack Surface Management (formerly Tenable.asm, and previously Bit Discovery) is an external attack surface management (EASM) solution that integrates into a vulnerability management platform. Tenable.asm continuously maps the entire internet and discovers connections to internet-facing assets so that users can assess the security posture of the entire external attack surface, or those facets of an organization that face the public, and the Internet. It can be used to access an attack…N/A
    Pricing
    HackerOneTenable Attack Surface Management
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    HackerOneTenable Attack Surface Management
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional DetailsFor more information please email www.hackerone.com/contact or find us on the AWS Marketplace: https://aws.amazon.com/marketplace/seller-profile?id=10857e7c-011b-476d-b938-b587deba31cf—
    More Pricing Information
    Features
    HackerOneTenable Attack Surface Management
    Threat Intelligence
    Comparison of Threat Intelligence features of HackerOne and Tenable Attack Surface Management
    Feature
    HackerOne
    -
    Ratings
    Tenable Attack Surface Management
    9.3
    1 Ratings
    14% above category average
    Threat Recognition00 Ratings9.01 Ratings
    Vulnerability Classification00 Ratings10.01 Ratings
    Automated Alerts and Reporting00 Ratings10.01 Ratings
    Threat Analysis00 Ratings9.01 Ratings
    Threat Intelligence Reporting00 Ratings9.01 Ratings
    Automated Threat Identification00 Ratings9.01 Ratings
    Vulnerability Management Tools
    Comparison of Vulnerability Management Tools features of HackerOne and Tenable Attack Surface Management
    Feature
    HackerOne
    -
    Ratings
    Tenable Attack Surface Management
    9.4
    1 Ratings
    12% above category average
    IT Asset Realization00 Ratings10.01 Ratings
    Authentication00 Ratings9.01 Ratings
    Configuration Monitoring00 Ratings9.01 Ratings
    Web Scanning00 Ratings9.01 Ratings
    Vulnerability Intelligence00 Ratings10.01 Ratings
    Best Alternatives
    HackerOneTenable Attack Surface Management
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    No answers on this topic
    Tenable Nessus
    Score8.8 out of 10
    Enterprises
    No answers on this topic
    Tenable Vulnerability Management
    Score8.9 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    HackerOneTenable Attack Surface Management
    Likelihood to Recommend
    7.0
    (2 ratings)
    10.0
    (1 ratings)
    Support Rating
    -
    (0 ratings)
    10.0
    (1 ratings)
    User Testimonials
    HackerOneTenable Attack Surface Management
    Likelihood to Recommend
    HackerOne
    It is one of the good platforms for security researchers to submit bugs and other vulnerabilities, it however, has some challenges, in terms of un-verified and duplicate submissions.
    Incentivized
    Read full review
    Tenable
    Tenable Attack Surface Management simplifies not just your vulnerability management needs but also the mapping and discovery of known and unknown internet assets. All this within a very intuitive online dashboard, making it relatively easy to setup and configure. Without having to spend hours of training time in order to use basic functions.
    Incentivized
    Read full review
    Pros
    HackerOne
    • Filter for spammy bug reports
    • Nice central interface
    • Payment/reward system is nice
    Incentivized
    Read full review
    Tenable
    • Maps external facing infrastructure and continuously updates this data
    • Can display the scan results in Business Context to help with management reporting
    • Great Asset Management tool
    • Powerful vulnerability scanning engine
    Incentivized
    Read full review
    Cons
    HackerOne
    • A lot of duplicate bugs get reported, although it does offer automatic suggestion of previously reported bugs that may be duplicates, it is far from perfect.
    • Anyone can report bugs, a lot of them are not verified before submission. This sometimes leads to a lot of time spent in verifying if the bug is really actionable.
    • Each submission has to be treated with equal potential, a lot of time, some time gets invested in vulnerabilities that aren't as important as some others.
    Incentivized
    Read full review
    Tenable
    • No improvement can be suggested at this moment as it fits our needs and more
    Incentivized
    Read full review
    Support Rating
    HackerOne
    No answers on this topic
    Tenable
    Very fast and helpful support staff. From the Vendor as well as the local Distributor. Support like that makes adding such a product to our MSSP offering the obvious choice.
    Incentivized
    Read full review
    Alternatives Considered
    HackerOne
    These were very close and we liked HackerOne better. For a time we did have both and we felt the need to consolidate the information into one platform and end of life our internal offering. Overall we've been fairly happy with HackerOne.
    Incentivized
    Read full review
    Tenable
    We didn't test any other solutions. Because to be frank no other solution can compare feature-wise as well as ease of use. Which makes reselling and supporting any Tenable product such an obvious choice for us.
    Incentivized
    Read full review
    Return on Investment
    HackerOne
    • Bugs that can't be tracked internally are submitted by external researchers, which is an important factor for security vulnerabilities.
    • Even if the bugs reported are duplicates, there still is provision to award reputation points, that keep the researchers engaged.
    • It also requires a lot of verification and validation, as a lot of the submissions are unverified to begin with.
    Incentivized
    Read full review
    Tenable
    • This solution is most definitely a great Return on Investment because it can quickly and accurately discover and report on our clients' entire Internet facing real estate. And keep this data updated with any changes.
    Incentivized
    Read full review
    ScreenShots