No more typing reviews! Try our Samantha, our new voice AI agent.

Fortra Tripwire IP360 vs HCL AppScan comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortra Tripwire IP360
Average Rating
7.0
Reviews Sentiment
4.3
Number of Reviews
6
Ranking in other categories
Vulnerability Management (58th)
HCL AppScan
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
44
Ranking in other categories
Application Security Tools (19th), Static Application Security Testing (SAST) (16th), Dynamic Application Security Testing (DAST) (6th)
 

Mindshare comparison

Fortra Tripwire IP360 and HCL AppScan aren’t in the same category and serve different purposes. Fortra Tripwire IP360 is designed for Vulnerability Management and holds a mindshare of 0.7%, up 0.4% compared to last year.
HCL AppScan, on the other hand, focuses on Application Security Tools, holds 2.4% mindshare, down 2.6% since last year.
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Fortra Tripwire IP3600.7%
Wiz5.0%
Qualys VMDR4.2%
Other90.1%
Vulnerability Management
Application Security Tools Mindshare Distribution
ProductMindshare (%)
HCL AppScan2.4%
SonarQube13.6%
Checkmarx One8.8%
Other75.2%
Application Security Tools
 

Featured Reviews

Corey Cole - PeerSpot reviewer
Service Coordinator - Technology Security at a government with 10,001+ employees
The solution helps users to manage their entire IP range, but it's unreliable and very expensive to maintain
Only the administrator was using the product. He used it to read reports as part of our compliance programs. It wasn't heavily used by a lot of users. The tool comes in at a large scale, and we tried to scale it down. The scaling did not apply to us. It was neither difficult nor easy. I rate the scalability a five out of ten. We had some challenges while scaling it down. It could do 10,000 devices, and we wanted to use it for ten devices. The process was difficult and expensive. We did not need the product anymore.
Ravi Khanchandani - PeerSpot reviewer
Founder Director at Techsa Services
Has improved identification of encryption and authentication issues across cloud and on-prem applications
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interface. However, there is one feature called SCA, which stands for Software Composition Analysis, that could be improved. When I'm doing an application scan, HCL AppScan has the ability to generate information about what components are in use. For example, if I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present. I would like to see more detailed reports from the tool. Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities. For instance, I could identify that I had the Log4j vulnerability and know that I need to fix my application accordingly. If they add the features I'm describing, I would consider giving them a higher rating. However, I've only been experienced with the product for three months.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has enhanced the security program by ensuring that all external-facing systems are scanned on a routine basis."
"It's become the pinnacle point for anything that enters the network or anything that's passing through to production to first be affected by IP360, hardened, and up to standard. For our integrity management, one was deployed in the bank about two years ago and that's still going to expand the usage and the product itself. That will go hand in hand with training and expanding the product as for where it's deployed."
"Tripwire IP360 is a very stable solution."
"Tripwire is one of the most mature in terms of companies, suites, support, everything, much more than any other product."
"Tripwire IP360 helps me to discover most of the vulnerabilities, and I like the way that it prioritizes these vulnerabilities, as it allows me to focus on the most important ones first and then follow up with the rest."
"The company probably chose this solution because they thought that they would be getting the best bang for their buck."
"We could manage our entire IP range with the solution."
"This product detects vulnerabilities which exist in the environment, and provides enough information that allows for remediation, thereby securing the environment."
"The platform has valuable security features, helping us identify sensitive code issues and the possibility of internal applications' exposure to external threats."
"You can easily find particular features and functions through the UI."
"There's extensive functionality with custom rules and a custom knowledge base."
"I like the recording feature."
"The solution offers services in a few specific development languages."
"It identifies all the URLs and domains on its own and then performs tests and provides the results."
"The product has valuable features for static and dynamic testing."
"Now we just send it to AppScan and we can do other stuff like defining processes or dealing with management issues."
 

Cons

"The reporting functions can use improvement."
"I am not very impressed by the technical support."
"The reporting functions can use improvement. There is room for growth because reporting functions differ a lot depending on what you're going to output. It depends on whether it's for technical or senior management and how it's interpreted. There could be growth within the reporting functionality side."
"For IP360, unfortunately, scans for certain vulnerabilities often cause issues, as they are mainly false positive."
"If you are looking for better reporting capabilities and vulnerability tracking over time for remediation purposes, then this is not the best solution."
"We would like to have better reporting capabilities and for them to be more granular."
"We need to dedicate time and resources to keep it running."
"I am not very impressed by the technical support."
"I would love to see more containers. Many of the tools are great, they require an amount of configuration, setup and infrastructure. If most the applications were in a container, I think everything would be a little bit faster, because all our clients are now using containers."
"The pricing has room for improvement."
"Sometimes it doesn't work so well."
"We would like to be able to integrate to some of the other tools that we are using."
"Visibility is an issue for us. Our partners were not even aware that we had an integration with AppSense."
"Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
"I would love to see more containers. Many of the tools are great, they require an amount of configuration, setup and infrastructure."
"The solution could improve by having a mobile version."
 

Pricing and Cost Advice

"I believe the price compares well within the market."
"The product was expensive for us."
"The tool was expensive."
"The price is very expensive."
"With the features, that they offer, and the support, they offer, AppScan pricing is on a higher level."
"The product is moderately priced, though it's an investment due to extensive code analysis needs."
"The product has premium pricing and could be more competitive."
"HCL AppScan is expensive."
"AppScan is a little bit expensive. IBM needs to work a little bit on the pricing model, decreasing the license cost."
"The price of HCL AppScan is okay, in my opinion. You just buy HCL AppScan and don't pay anything anymore, meaning it is just a one-time purchase."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
893,164 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
13%
Construction Company
10%
Comms Service Provider
9%
Energy/Utilities Company
6%
Financial Services Firm
11%
Government
10%
Computer Software Company
10%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise31
 

Questions from the Community

Ask a question
Earn 20 points
What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interf...
What is your primary use case for HCL AppScan?
I'm currently working with BigFix and HCL AppScan. At least three people in my company are using HCL AppScan. Since we are a reseller, we run it in both lab environments and live production applica...
 

Also Known As

IP360
IBM Security AppScan, Rational AppScan, AppScan
 

Overview

 

Sample Customers

1. Aetna 2. Accenture 3. Adidas 4. AIG 5. Airbus 6. Akamai 7. Amazon 8. American Express 9. Aon 10. Apple 11. ATT 12. Autodesk 13. Bank of America 14. Barclays 15. Bayer 16. Bechtel 17. BlackRock 18. Boeing 19. BNP Paribas 20. Cisco 21. CocaCola 22. Comcast 23. Dell 24. Deutsche Bank 25. eBay 26. ExxonMobil 27. FedEx 28. Ford 29. General Electric 30. Google 31. HP 32. IBM
Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Find out what your peers are saying about Wiz, Tenable, Qualys and others in Vulnerability Management. Updated: April 2026.
893,164 professionals have used our research since 2012.