PortSwigger Burp Suite vs. Salt Security API Protection Platform

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
PortSwigger Burp Suite
Score 9.4 out of 10
N/A
The Burp Suite, from UK-based alcohol-themed software company PortSwigger Web Security, is an application security and testing solution.N/A
Salt Security API Protection Platform
Score 8.5 out of 10
Enterprise companies (1,001+ employees)
For API-driven organizations, Salt Security is an API security platform that protects internal, external, and third-party APIs. The Salt C-3A Context-based API Analysis Architecture combines coverage and AI-powered big data to discover APIs and exposed sensitive data - continuous and automatic discovery stop attackers in their tracks - block attackers by integrating with inline devices provide remediation insights - for developers to improve API security…N/A
Pricing
PortSwigger Burp SuiteSalt Security API Protection Platform
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
PortSwigger Burp SuiteSalt Security API Protection Platform
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details——
More Pricing Information
Community Pulse
PortSwigger Burp SuiteSalt Security API Protection Platform
Top Pros
Top Cons
Best Alternatives
PortSwigger Burp SuiteSalt Security API Protection Platform
Small Businesses

No answers on this topic

Cloudflare
Cloudflare
Score 8.4 out of 10
Medium-sized Companies
Veracode
Veracode
Score 9.2 out of 10
Cloudflare
Cloudflare
Score 8.4 out of 10
Enterprises
Veracode
Veracode
Score 9.2 out of 10
Akamai App & API Protector
Akamai App & API Protector
Score 8.2 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
PortSwigger Burp SuiteSalt Security API Protection Platform
Likelihood to Recommend
10.0
(11 ratings)
8.5
(6 ratings)
Usability
9.0
(4 ratings)
-
(0 ratings)
Support Rating
10.0
(3 ratings)
-
(0 ratings)
User Testimonials
PortSwigger Burp SuiteSalt Security API Protection Platform
Likelihood to Recommend
PortSwigger Web Security
Burp Suite is a good general tool to test websites as long as your website is not too large or you have the time for it to complete. We have some websites that only about five to ten minutes for Burp Suite to complete an attack and a spider only takes about two minutes. Other websites have taken a few hours to complete. I have seen a tester actually run Burp Suite against one of our websites and it took all day to complete.
Read full review
Salt Security
Salt is highly recommended for anyone who wants to discover, monitor and protect their APIs against various types of attacks. Salt should not be used as a SIEM.
Read full review
Pros
PortSwigger Web Security
  • The passive scan feature is really awesome, it kind of covers areas that you might miss.
  • The CSRF POC is really helpful to my team. It helps development team see the issue and understand it.
  • Burp intruder and repeater are the features I myself and my team uses the most as it helps us use our payloads in a variety of different ways.
  • Active scan helps the team to ensure coverage for the whole application.
Read full review
Salt Security
  • PII identification in API traffic.
  • Divergence between API traffic and documentation (swagger files).
  • Potential attacks with information to take counter measures.
Read full review
Cons
PortSwigger Web Security
  • The interface is a big problem: No matter how many features a software provides you, if the features are not well presented, you will miss most of them when they are actually required. The presentation of the software should be improvised and made more presentable.
  • Tutorial videos for beginners: This software lacks a lot in tutorials. A beginner almost wastes most of the time in finding and understanding the features and the implementation of the same. The software vendor should work on providing more in-depth videos so that people can learn and understand the concepts.
Read full review
Salt Security
  • The platform could have more options for exporting detailed data from attackers' dashboards.
  • The Attackers dashboard could also have more options of filters in order to support the investigations of the attack.
  • The OAS analysis could present a more detailed view of the found issues.
Read full review
Usability
PortSwigger Web Security
Easy to use once you learn it; however, the user interface is not very intuitive at first view. Port Swigger does provide a lot of video resources for self-paced learning which helps. Most of the end users for PortSwigger Burp Suite will be technical and should be able to learn the product with the free resources.
Read full review
Salt Security
No answers on this topic
Support Rating
PortSwigger Web Security
BurpSuite does not have an amazing customer support. All the major help that you will find is from public forums and Google. Although you will find all the required information on Google, still at time professional support helps you solve the problem in much less time and make your operations go smoothly.
Read full review
Salt Security
No answers on this topic
Alternatives Considered
PortSwigger Web Security
Each tool is specific and are good for what they do. While Burp Suite can perform some level of the same functions, somehow security consultants prefer these tools as additional to the Burp Suite. Maybe due to open source and easy setup when compared to Burp Suite. But Burp Suite allows for one tool for many templates for each project.
Read full review
Salt Security
We tried controls offered by the IaaS providers but these were hard to manage and did not provide the visibility we wanted. We also protected APIs with a normal WAF but this was only helpful for assets we knew about and API attacks were not caught by the WAF.
Read full review
Return on Investment
PortSwigger Web Security
  • Scanned 100% of the orgs public facing web sites with a small team of analysts.
  • Provided a reputable second opinion source to back up the other product in use i.e. Webinspect.
  • Pro version $350 is amazing ROI, considering the thwarted attacks and that it's competition is priced in the tens of thousands last I checked.
  • No successful hacks. Q.E.D. :-)
Read full review
Salt Security
  • Salt Security API Protection Platform has provided detailed information that is helping us to identify and investigate attacks in our environment
Read full review
ScreenShots