What is our primary use case?
I primarily use VulnCheck for newly discovered vulnerabilities and the remediation time period for those vulnerabilities, with the team reviewing the severities.
Using VulnCheck with real-world threat data, it has a capability where it updates 14 days before the NVD National Vulnerability Database has updated.
That is my main use case for VulnCheck.
What is most valuable?
I find that VulnCheck's best features include using CVSS, mapping it to the MITRE ATT&CK framework, and tagging indicators of compromise.
The features of mapping CVSS to the MITRE ATT&CK framework and tagging indicators of compromise help my team assess risks based on the severity: high, medium, low, and common.
The unique feature of VulnCheck is the 14-day advance notice, as it provides data on exploits with exploits, which is a very quick update compared to the NVD and open CVEs.
VulnCheck positively impacts my organization by enabling risk-based reduction, identifying actively exploited vulnerabilities, and providing valuable insights.
When I mention service-based reduction and identifying active risks, I notice faster remediation times and that we are compliant as per the SOC 2 Type 2 terms, which is the best threat intel so far.
What needs improvement?
I wish VulnCheck could improve by having a scoring system that is domain-based, IP-based, and reputation-based, along with an internal capability for checking internal inventory vulnerabilities.
My main addition about needed improvements is that if VulnCheck works on the inventory of the software my organization uses, it would be really helpful.
For how long have I used the solution?
I have been using VulnCheck for over a year.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
VulnCheck demonstrates good scalability.
How are customer service and support?
I find that customer support is good, and I'm impressed.
Which solution did I use previously and why did I switch?
Previously, I used a security scorecard, a domain rating level scorecard that provides a security rating, but it didn't have as many capabilities, so I switched to VulnCheck.
What's my experience with pricing, setup cost, and licensing?
Currently, I find the pricing of VulnCheck to be reasonable and not much expensive.
Which other solutions did I evaluate?
Before choosing VulnCheck, I compared it with Security Scorecard, and that was the extent of my evaluation.
What other advice do I have?
As a security engineer, I find it very easy and manageable to understand the exploitation data provided by VulnCheck's first-party exploitation intelligence.
With VulnCheck's early exploit visibility, I can remediate vulnerabilities quickly, making timely decisions before the vulnerabilities are known to the public and hackers.
I utilize operational exploit artifacts provided by VulnCheck, which help me prioritize them sooner based on severities and check the exploit status in terms of how deep the exploit can penetrate.
VulnCheck's scanless exposure insight feature is useful whenever scanning is not permitted, allowing me to perform vulnerability checks.
I have utilized the Initial Access Intelligence (IAI) artifacts, which add value to my security measures through data validation, active checks, and access control, ensuring only authorized users can access.
It is about the remediation of vulnerabilities to make it faster and to make sooner decisions based on the exploit status, which is the main factor.
I advise others looking into using VulnCheck to ensure it is useful for their specific needs and to check if the scope matches what VulnCheck offers.
I would rate this product a 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other