Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

A dynamic application security testing solution that combines robust analytics with exceptional usability. This web application assessment leverages cutting-edge technologies such as HTML5 and Ajax. It can replicate the vulnerability exploitation process by tracking events, while automatically scanning subdirectories linked to a web application's URL. The system identifies security flaws from the URLs it crawls and performs open-source web library vulnerability assessments. Additionally, it integrates with Sparrow's analytical tools to address the shortcomings found in traditional DAST methods. The TrueScan module enhances detection capabilities through IAST integration, and its web-based interface allows for seamless access without the need for installation. The centralized management system facilitates the organization and sharing of analysis results effectively. By utilizing browser event replay technology, it further identifies vulnerabilities in web applications. This solution also addresses the constraints of dynamic analysis through its collaboration with Sparrow SAST and RASP, while the IAST functionality via TrueScan enhances the overall security assessment process even further. As a comprehensive tool, it exemplifies the future of web application security testing.

Description

Recognized as the top-rated DAST solution by an independent research organization for three consecutive years, this tool automatically evaluates contemporary web applications and APIs while minimizing false positives and overlooked vulnerabilities. It accelerates remediation efforts through comprehensive reporting and seamless integrations, keeping compliance and development teams informed. Regardless of the scale of your application portfolio, it enables effective management of security assessments. The solution autonomously navigates and evaluates web applications to uncover vulnerabilities such as SQL Injection, XSS, and CSRF. With a modern interface and user-friendly workflows built on the Insight platform, InsightAppSec is straightforward to deploy, manage, and operate. Additionally, it can scan applications hosted on isolated networks with the optional on-premise engine. Furthermore, InsightAppSec provides assessments and reports on your web application's compliance with PCI-DSS, HIPAA, OWASP Top Ten, and various other regulatory standards, ensuring a comprehensive approach to application security. This multifaceted solution supports organizations in enhancing their security posture while streamlining assessment processes.

API Access

Has API No 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

Azure Pipelines No 
BMC Helix ITSM No 
BeyondTrust Endpoint Privilege Management No 
Carbon Black EDR No 
Cisco pxGrid No 
Coalfire No 
CyberArk Privileged Access Manager No 
Do Status No 
Jenkins No 
Jira No 
Jira Work Management No 
Microsoft 365 No 
Modulo Risk Manager No 
Rapid7 Command Platform No 
RedSeal No 
Selenium No 
Selenium IDE No 
Swagger No 
VMware NSX No 

Integrations

Azure Pipelines Yes 
BMC Helix ITSM Yes 
BeyondTrust Endpoint Privilege Management Yes 
Carbon Black EDR Yes 
Cisco pxGrid Yes 
Coalfire Yes 
CyberArk Privileged Access Manager Yes 
Do Status Yes 
Jenkins Yes 
Jira Yes 
Jira Work Management Yes 
Microsoft 365 Yes 
Modulo Risk Manager Yes 
Rapid7 Command Platform Yes 
RedSeal Yes 
Selenium Yes 
Selenium IDE Yes 
Swagger Yes 
VMware NSX Yes 

Pricing Details

one-time payment
Free Trial No 
Free Version No 

Pricing Details

$2000 per app per year
Free Trial Yes 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises Yes 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

Sparrow

Founded

2018

Country

South Korea

Website

www.sparrowfasoo.com/en/product/dast

Vendor Details

Company Name

Rapid7

Founded

2000

Country

United States

Website

www.rapid7.com/products/insightappsec/

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration No 
Training Resources No 
Vulnerability Detection No 
Vulnerability Remediation No 

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration No 
Training Resources No 
Vulnerability Detection No 
Vulnerability Remediation No 

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Alternatives

AppScan Reviews

AppScan

HCLSoftware

Alternatives

PT Application Inspector Reviews

PT Application Inspector

Positive Technologies
Invicti Reviews

Invicti

Invicti Security