Tenable Attack Surface Management (formerly Tenable.asm, and previously Bit Discovery) is an external attack surface management (EASM) solution that integrates into a vulnerability management platform. Tenable.asm continuously maps the entire internet and discovers connections to internet-facing assets so that users can assess the security posture of the entire external attack surface, or those facets of an organization that face the public, and the Internet.
It can be used to access an attack…
N/A
Tenable Vulnerability Management
Score 9.3 out of 10
N/A
Vulnerability management specialist Tenable offers their cloud application and container security platform Tenable Web App Scanning (formerly Tenable.io), a vulnerability management tool that emphasizes visibility of web applications, automatic scanning, and a unified view of cloud infrastructure and possible inconsistencies indicating a vulnerability.
We didn't test any other solutions. Because to be frank no other solution can compare feature-wise as well as ease of use. Which makes reselling and supporting any Tenable product such an obvious choice for us.
Tenable Attack Surface Management simplifies not just your vulnerability management needs but also the mapping and discovery of known and unknown internet assets. All this within a very intuitive online dashboard, making it relatively easy to setup and configure. Without having to spend hours of training time in order to use basic functions.
I've been using this product since it began as an open source product, I really like it and for the money, I think it's probably the best choice for most companies who need a product like this. Over the years I've seen the interface change quite a bit and sometimes I think it's a bit unclear how to do certain things and the different packages can be confusing, these are the only reasons I'm giving it a 9 instead of a 10.
Expensive - You do pay a slight premium for the best product in the space.
Asset management is difficult to work with if you have a lot of asset turnover, the license can be ''held'' for 3-6 months after the asset is gone from your environment.
Very fast and helpful support staff. From the Vendor as well as the local Distributor. Support like that makes adding such a product to our MSSP offering the obvious choice.
Support is usually really great at walking you through any steps you need to take when you get stuck on something. There are a few false positives and errors that have come up over the years that required their help to get through. Unfortunately, the steps required to diagnose some problems are more tedious than I think should be necessary. (IE: SQL instances can throw errors that clog up your logs because one plugin affects it in a certain way. The process to diagnose this is to watch timestamps of plugins in a log while monitoring the SQL logs at the same time and using your best guess as to what is causing it.)
We didn't test any other solutions. Because to be frank no other solution can compare feature-wise as well as ease of use. Which makes reselling and supporting any Tenable product such an obvious choice for us.
Tenable.io has a comparable set of features, with excellent support and a competitive price. After less than desirable experiences with another company, we moved to Tenable and haven't looked back since.
This solution is most definitely a great Return on Investment because it can quickly and accurately discover and report on our clients' entire Internet facing real estate. And keep this data updated with any changes.
Since this is a requirement for our PCI compliance and the cost is relatively low, the ROI isn't really something we need to think too much about, Tenable's pricing is fair and affordable.