Vulnerability management is our primary use case.
Trustwave App Scanner [EOL] was previously known as Hailstorm, Cenzic Hailstorm.
| Author info | Rating | Review Summary |
|---|---|---|
| Security Manager at a healthcare company with 1,001-5,000 employees | 5.0 | I rate this vulnerability management solution ten out of ten. Its great stability and straightforward setup boost my team's productivity and security maturity. I'd like more flexibility in vulnerability profiles and AI coverage, but it fits my needs. |
| Security Program Manager at a tech company with 10,001+ employees | 3.5 | I found this solution had fewer false positives and was more efficient than competitors. It integrated well for PCI scanning, and support was good, though older versions sometimes crashed due to performance. |
| Student Worker, Information Security Office at a university with 1,001-5,000 employees | 4.0 | I find Trustwave App Scanner a stable, user-friendly, and performance-oriented tool for web application vulnerability scanning. It's been my go-to since I started in this field, though I'd like a total application count in the GUI. |
| Associate Software Engineer(Security) at a tech company with 10,001+ employees | 3.5 | I found it valuable for web app security with straightforward setup. However, it only supports older web technologies, lacks modern tech support, and has scalability issues, making it suitable solely for legacy applications. |
| Associate QA Engineer at a tech company with 10,001+ employees | 3.0 | I've used Hailstorm for five months. It excels at early bug detection and SSL vulnerability identification, offering great ROI despite complex setup. I recommend this top dynamic code analysis tool, though reporting needs work. |
Vulnerability management is our primary use case.
It hasn't really affected the way our organization function. It just gives us preparedness, readiness. However, it has increased our staff productivity by about five percent, and it has increased the maturity of our security program.
I would like to see a little more flexibility with regards to setting up profiles for vulnerabilities. For the most part, it fits our needs but a little more flexibility would be great.
I would also like to have more information on AI. If we start to deploy AI in our infrastructure, does it cover that as well?
The stability is great. We haven't had any issues at all with it.
The scalability works because we're not really a large shop. For all intents and purposes, it fits us.
We haven't had to use technical support.
The initial setup was straightforward.
We did not use an integrator.
The simple fact that it puts us in a better place for identifying our vulnerabilities is a form of ROI. We're able to discover them faster, become cleaner. That's definitely our ROI.
This was the only vendor we looked at.
I rate this solution a ten out of ten. It fits our needs.
I believe it has produced less false positives compared to its competitors.
Was used for scanning PCI application along with Fortify for source code scans. Was tightly integrated with Secure SDLC.
Used to crash/freeze due to poor performance, not sure about newer versions.
Two years, approximately.
None that I can remember.
Had good technical support, as far I could remember.
This scanner was more efficient compared to its competitors.
Used the standalone software.
The purchase was done by a different team. So, no idea.
I have been using this platform to scan the application for vulnerabilities since I started in this field.
Trustwave App Scanner makes it really easy and convenient for us to notify the website owners before the scans, as well as providing the scan results.
One feature that I would really want is the number of total applications in the web GUI; after selecting a filter on the applications, it would be really helpful if it shows the number of applications.
I have been using it for more than a year now. I've been using it since July 2015.
I did not encounter any stability issues. It has always worked properly for me.
I did not previously use a different solution. This has been the platform I have been using since my introduction to this field.
Initial setup was straightforward; it was not so complex. I started with the basics and then slowly got deeper into it. If one goes systematically throughout the system, it shouldn't be hard to understand.
It's a perfect tool for someone who's looking for a stable, user-friendly and performance-oriented platform for web application scanning.
Web application security testing is a valuable feature.
It has automated security test-cases for web applications.
It doesn't support modern web technologies such as GWT, Angular, JS etc.
I've used it for six to seven years.
No issues encountered.
No issues encountered.
Yes there were some issues.
8/10.
Technical Support:7/10.
I wasn't using a different solution prior to this one.
It was straightforward.
We also looked at WebInspect.
It's a good product, but you should only use it if your products are based on old web technologies.
It identifies the vulnerabilities in SSL.
We were able to unravel bugs in earlier stages of product development and thus deliver maximum value to our customer during the release to market phase.
I've been using it for five months, since January 2015.
No issues encountered.
Yes we did, but I'm not sure if it was Hailstorm itself or the product onto which it was run.
No issues encountered.
7/10.
Technical Support:7/10.
No previous solution was used.
It was complex as I have to make sure all the requirements are in place before on-boarding Hailstorm.
We used a vendor team whose expertise was 7/10.
Overall, we have experienced a better ROI since using Hailstorm.
Go ahead and use Hailstorm as it's the best dynamic code analysis tool one can invest in and it gives a better ROI than most.