Learn More

Average Ratings 21 Ratings

Total
ease
features
design
support

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Criminal IP's Attack Surface Management (ASM) is an intelligence-driven platform designed to continuously identify, catalog, and oversee all internet-connected assets linked to an organization, including overlooked and shadow resources, enabling teams to understand their actual external exposure from the perspective of potential attackers. This solution integrates automated asset detection with open-source intelligence (OSINT) methods, artificial intelligence enhancements, and sophisticated threat intelligence to reveal exposed hosts, domains, cloud services, IoT devices, and other internet-facing entry points, while also collecting evidence such as screenshots and metadata, and linking findings to known vulnerabilities and attacker techniques. By evaluating exposures through the lens of business relevance and risk, ASM emphasizes vulnerable elements and misconfigurations, providing instantaneous alerts and interactive dashboards that facilitate quicker investigations and remediation efforts. Furthermore, this comprehensive tool empowers organizations to proactively manage their security posture, ensuring that they remain vigilant against emerging threats.

Description

A powerful cloud-based solution enables ongoing discovery and identification of vulnerabilities and misconfigurations in web applications. Designed entirely for the cloud, it offers straightforward deployment and management while accommodating millions of assets with ease. The Web Application Scanner (WAS) systematically locates and records all web applications within your network, including those that are new or previously unidentified, and can scale from just a few applications to thousands. Utilizing Qualys WAS, you have the ability to assign your own labels to applications, allowing for customized reporting and restricted access to scanning results. WAS employs dynamic deep scanning to thoroughly assess all applications within your perimeter, internal environment, active development stages, and APIs that serve mobile devices. Furthermore, it extends its coverage to public cloud instances, providing immediate insight into vulnerabilities such as SQL injection and cross-site scripting. The system supports authenticated, intricate, and progressive scanning methods. In addition, it incorporates programmatic scanning capabilities for SOAP and REST API services, effectively evaluating IoT services and the APIs utilized by contemporary mobile architectures, thereby enhancing your overall security posture. This comprehensive approach ensures that all aspects of your web applications are monitored and protected continuously.

API Access

Has API Yes 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

Splunk Cloud Platform Yes 
AlgoSec No 
Allgress No 
CA Flowdock No 
Core Security Access Assurance Suite No 
CyberArk Conjur No 
Google Chrome Yes 
Hitachi Content Platform No 
LogRhythm SIEM No 
NAVEX IRM No 
PolySwarm Yes 
Prisma No 
RSA ID Plus No 
VirusTotal Yes 
WALLIX Bastion No 
runZero No 

Integrations

Splunk Cloud Platform Yes 
AlgoSec Yes 
Allgress Yes 
CA Flowdock Yes 
Core Security Access Assurance Suite Yes 
CyberArk Conjur Yes 
Google Chrome No 
Hitachi Content Platform Yes 
LogRhythm SIEM Yes 
NAVEX IRM Yes 
PolySwarm No 
Prisma Yes 
RSA ID Plus Yes 
VirusTotal No 
WALLIX Bastion Yes 
runZero Yes 

Pricing Details

Send us an inquiry about purchasing the Criminal IP Enterprise license.
Our sales team will get in touch with you as soon as possible.
Free Trial Yes 
Free Version No 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours Yes 
Live Rep (24/7) Yes 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person Yes 

Vendor Details

Company Name

AI Spera

Founded

2017

Country

United States

Website

www.criminalip.io/products/asm/attack-surface-management

Vendor Details

Company Name

Qualys

Founded

1999

Country

United States

Website

www.qualys.com/apps/web-app-scanning/

Product Features

Cybersecurity

AI / Machine Learning No 
Behavioral Analytics No 
Endpoint Management No 
IOC Verification No 
Incident Management No 
Tokenization No 
Vulnerability Scanning No 
Whitelisting / Blacklisting No 

Vulnerability Scanners

Asset Discovery No 
Black Box Scanning No 
Compliance Monitoring No 
Continuous Monitoring No 
Defect Tracking No 
Interactive Scanning No 
Logging and Reporting No 
Network Mapping No 
Perimeter Scanning No 
Risk Analysis No 
Threat Intelligence No 
Web Inspection No 

Product Features

Vulnerability Scanners

Asset Discovery No 
Black Box Scanning No 
Compliance Monitoring No 
Continuous Monitoring No 
Defect Tracking No 
Interactive Scanning No 
Logging and Reporting No 
Network Mapping No 
Perimeter Scanning No 
Risk Analysis No 
Threat Intelligence No 
Web Inspection No 

Alternatives

Silent Armor Reviews

Silent Armor

Silent Breach

Alternatives

Criminal IP Reviews

Criminal IP

AI SPERA
Acunetix Reviews

Acunetix

Invicti Security
Cloudxray Reviews

Cloudxray

Cloudnosys