

Qualys Web Application Scanning and CrowdStrike Falcon Cloud Security are top contenders in web application security and cloud protection. Qualys holds an advantage in pricing and customer support, while CrowdStrike excels in features, offering justified value.
Features: Qualys Web Application Scanning provides comprehensive vulnerability detection, easy integration, and robust web application protection. CrowdStrike Falcon Cloud Security offers advanced threat detection, cloud-native security features, and is well-suited for dynamic environments. The primary difference is Qualys's focus on web vulnerabilities and CrowdStrike's attention to cloud security intelligence.
Room for Improvement: Qualys can enhance its reporting features, improve customization, and better analytics. CrowdStrike needs better documentation, more intuitive controls, and refined user accessibility and guidance.
Ease of Deployment and Customer Service: Qualys has a straightforward deployment process, supported by responsive customer service that eases implementation. CrowdStrike offers excellent technical support despite a more complex deployment. The key difference is Qualys’s ease of use against CrowdStrike’s comprehensive deployment support.
Pricing and ROI: Qualys is budget-friendly with low setup costs and solid ROI. CrowdStrike, though pricier, provides significant long-term value thanks to advanced threat prevention features. The distinction lies in Qualys’s cost efficiency and CrowdStrike’s focus on long-term security investment.
More than 12 million vulnerabilities have been identified and resolved while working with CrowdStrike Falcon Cloud Security over the past 10 years.
We have seen a return on investment through time saved and managed employee workload.
It is an expense we are willing to pay to conform to Cyber Essentials Plus and demonstrate responsibility in protecting our data and that of our partners.
Based on my experience with CrowdStrike Falcon Cloud Security's technical support, I would rate them a solid 10 out of 10.
Technical support is quite good.
I have contacted customer service, and they are fast.
They have various options in the vulnerability management process, and when we initially bought our license, we didn't realize we needed PCI for better results, which isn't included in the default configurations.
Once we purchase the license, we have access to top-notch support.
I have dealt with Qualys's technical support, and any enhancements are challenging.
It is deployed across multiple departments and multiple locations.
CrowdStrike Falcon Cloud Security is indeed highly scalable, ideally for enterprises with a minimum of 2,000 servers to ensure cost efficiency and easier setup.
The scalability of CrowdStrike Falcon Cloud Security is good, and it can easily scale up to over 20,000 or 30,000 endpoints.
My concern remains the lack of deep dive analysis and that it produces similar vulnerability results as other tools such as Nessus based on version checks instead of real impact checks.
It is licensed for assets, so we just contact the team for additional licenses if needed.
At one point, there was a limitation on reporting for 100,000 assets at a time.
Occasionally, when the workload increases, it slows down considerably and sometimes becomes unresponsive.
When evaluating the stability of CrowdStrike Falcon Cloud Security, their partnerships with all major cloud service providers ensure their servers are optimally positioned.
If CrowdStrike Falcon Cloud Security could implement pushing out remediation from the sensor installed on machines, that would be beneficial.
The user interface needs improvement as it's sometimes difficult to locate specific dashboards or reports.
Another issue is the lack of proper documentation.
With the growing reliance on AI, Qualys Web Application Scanning should be updated to handle AI-based applications and LLM-based attacks.
Qualys Web Application Scanning does IP-level testing, requiring direct input of credentials, and can only scan a few pages to provide known generic vulnerabilities.
I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus.
The pricing for CrowdStrike Falcon Cloud Security is reasonable, especially for small companies with limited budgets.
No additional cost for maintenance or support; it's all included in the quotation.
However, the main point is that even though it is expensive, it provides a huge capability to the organization.
They offer discounts on bulk licenses, making it cheaper compared to competitors like Veracode DAST.
I find it a bit expensive compared to other competitors.
Regarding pricing, I think for personal use, it is costly, but if organizations are ready to pay, then it is fine as they are using it.
It automatically blocks duplication and activities that could result in data loss, effectively preventing unintended copying of data to personal devices.
The threat detection capability of CrowdStrike Falcon Cloud Security has always been the major seller, and it works effectively.
CrowdStrike Falcon plays a crucial role in our environment and gives us a clear point where we can focus our efforts rather than hunting down what is happening.
It effectively detects vulnerabilities like the OWASP Top 10 without any issues in reporting.
Credential scanning is very effective because it goes in-depth into the system, crawling the pages, and reporting on vulnerabilities.
Qualys Web Application Scanning is accurate and provides minimal false positives.
| Product | Mindshare (%) |
|---|---|
| CrowdStrike Falcon Cloud Security | 1.3% |
| Qualys Web Application Scanning | 1.7% |
| Other | 97.0% |


| Company Size | Count |
|---|---|
| Small Business | 13 |
| Midsize Enterprise | 6 |
| Large Enterprise | 15 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 6 |
| Large Enterprise | 27 |
CrowdStrike Falcon Cloud Security helps organizations stop cloud breaches from code to runtime. As CrowdStrike's cloud-native application protection platform (CNAPP), it combines real-time cloud detection and response with proactive cloud security to help security teams prevent, detect, investigate, and stop modern cloud attacks.
Industry-leading threat intelligence and AI-powered insights help security teams understand how adversaries operate, uncover evasive threats, and respond with confidence. The result is a stronger cloud security posture, faster investigations, and reduced mean time to detect and respond.
What are CrowdStrike Falcon Cloud Security's key features?
What benefits should users look for in reviews?
Organizations use Falcon Cloud Security to stop cloud breaches from code to runtime. It helps teams reduce blind spots, focus on the risks most likely to lead to a breach, and detect and respond to attacks faster. By connecting proactive cloud security with real-time detection and response, it strengthens security from development through production.
Qualys Web Application Scanning offers advanced vulnerability management, progressive scheduling, and seamless integration with DevOps environments. Its user-friendly design enables enterprises to enhance security with comprehensive scanning and detailed forensic insights.
Qualys Web Application Scanning addresses enterprise-level security challenges by providing robust solutions for vulnerability management, penetration testing, and compliance checks. While easing the navigation process, it supports risk mitigation with precise risk ratings, minimal false positives, and detailed reporting. However, it faces challenges with its complex interface, authenticated scanning, and automation features. Integrating smoothly with CI/CD pipelines, it is suitable for continuous and automated scanning, adapting to diverse company requirements.
What are the standout features of Qualys Web Application Scanning?Organizations across sectors like education, banking, and international data centers leverage Qualys Web Application Scanning for conducting penetration testing, scanning web applications, and managing vulnerabilities. It aids in audit security and compliance, identifying threats, and generating user-friendly reports, making it a valuable asset for maintaining strong security postures.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.