Share your experience using WhiteHat Dynamic

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 84,000+ reviews on PeerSpot:

Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer
Real User
Top 5Leaderboard
Helps to check multiple websites, particularly dynamic and e-commerce websites, for vulnerabilities within the code
Pros and Cons
  • "In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to paste the provided CDN into your metadata. Once connected, every piece of information, including vulnerabilities, can be accessed. It also offers demo sessions."
  • "Rapid7 InsightAppSec needs improvement in detecting phishing pages."

What is our primary use case?

I use the solution to check multiple websites, particularly dynamic and e-commerce websites, for vulnerabilities within the code. The tool helps identify any vulnerabilities present in the code, providing precise information about the code that contains vulnerabilities.

What is most valuable?

In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to paste the provided CDN into your metadata. Once connected, every piece of information, including vulnerabilities, can be accessed. It also offers demo sessions. 

If there is any malicious network traffic targeting a specific web application, it is designed to detect and showcase the entire scenario. It provides insights into potential vulnerabilities, including issues related to process scripting or content security policy vulnerabilities.

Setting up and configuring scans within the tool is easy, and I would rate it a nine out of ten. It provides videos on YouTube, along with documentation that breaks down the process into step-by-step instructions. 

What needs improvement?

Rapid7 InsightAppSec needs improvement in detecting phishing pages. 

For how long have I used the solution?

I have been using the product for four years. 

What do I think about the stability of the solution?

I rate the solution's stability a six out of ten. There have been instances where fetching data, even for old users, took a long time.

What do I think about the scalability of the solution?

I would rate the scalability at an eight out of ten on a scale from one to ten. There are occasional challenges with the product, particularly in onboarding, where delays can be experienced. This delay sometimes makes it difficult to address issues promptly, and reliance on queries may not always yield the desired results due to occasional bugs. Additionally, there have been instances where data retrieval after deployment takes time, sometimes up to 30 minutes to an hour. Scanning a single website can also be time-consuming, ranging from 25 to 30 minutes, and for multi-vendor e-commerce websites, it may take even longer to scan the entire site.

How was the initial setup?

The initial setup is easy, to the extent that even a non-IT person can set it up. 

What's my experience with pricing, setup cost, and licensing?

Rapid7 InsightAppSec is cheap. 

What other advice do I have?

In a scenario involving the tool and preventing potential security breaches, let's consider a case where a security feature is deployed using Rapid7 InsightAppSec. Although I haven't personally experienced this, I can provide an example. Suppose there is a vulnerability in WordPress or Apache servers, and it identifies a new one-level zero-day attack template associated with it. In this case, it may have detected this vulnerability three months after its initial occurrence.

We utilize dynamic application security testing. It involves deploying an application by onboarding it onto a device, which is then linked to the application. The notable aspect is that we don't need to maintain a server for this process. Instead, we simply log in and configure Splunk Enterprise to connect with the product. There is no need to deploy a separate server. It provides clear, step-by-step instructions, including the provision of a dynamic key by the application, making it easy to implement with documentation.

I rate it an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Cyber security Lead at PCS
Real User
Top 10
Can be used for dynamic application scanning, but its stability of the scans could be improved
Pros and Cons
  • "Parallel scans can be done with PortSwigger Burp Suite Enterprise Edition."
  • "The stability of the scans could be improved."

What is our primary use case?

We use the solution for dynamic application scanning. We used the solution in a big IT solution company to do some certification for the government agency.

What is most valuable?

Parallel scans can be done with PortSwigger Burp Suite Enterprise Edition. Since the solution was deployed in a vCenter solution, the reports could be kept for a longer duration.

What needs improvement?

The stability of the scans could be improved.

For how long have I used the solution?

I have been using PortSwigger Burp Suite Enterprise Edition for six months.

What do I think about the stability of the solution?

I rate the solution a seven out of ten for stability.

What do I think about the scalability of the solution?

I rate the solution six and a half out of ten for scalability.

What other advice do I have?

I rate the solution six and a half out of ten for its user-friendly interface. PortSwigger Burp Suite Enterprise Edition is suited for large projects, and you can increase the memory.

Overall, I rate the solution six and a half out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate