Try our new research platform with insights from 80,000+ expert users

Share your experience using FireEye Penetration Testing [EOL]

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 96,000+ reviews on PeerSpot:

CEO at cybovate
Reseller
Top 20
Deploying autonomous security tools improves network protection and efficiency
Pros and Cons
  • "I rate the stability of the NodeZero Platform a ten out of ten."
  • "One of the areas where improvement is needed is in the visibility and reporting for large enterprises."

What is our primary use case?

The primary use case for the NodeZero Platform is as an extension to existing vulnerability management systems. Initially, it complemented solutions like Qualys or Tenable. However, there has been a shift towards using NodeZero to replace existing vulnerability management solutions altogether. The motivations include cost savings and addressing issues that traditional vulnerability managers might report but do not actually affect system security.

What is most valuable?

Deploying the NodeZero Platform is straightforward for me as it involves just a Docker container in a network or a network segment, saving time and eliminating the need for agents on every endpoint. Its autonomous operation, safe for production use, makes it practical to schedule pen tests during business hours. The tripwires feature acts like a honeypot, providing network alerts for potential threats. These factors make it an effective tool for enhancing security in organizations.

What needs improvement?

One of the areas where improvement is needed is in the visibility and reporting for large enterprises. The existing GUI or NodeZero insights provide better visibility, but there's still room for enhancement. Moreover, there is a need to automate interactions with other systems, particularly in triggering or opening tickets in ServiceNow. Adding the application layer would also be valuable for clients.

For how long have I used the solution?

I have used the solution for 1.5 years.

What was my experience with deployment of the solution?

No issues were encountered in deploying the NodeZero Platform. Once the firewalls are open and communication with the cloud is enabled, it's a matter of installing a Docker container or VMware and opening the ports for smooth operation.

What do I think about the stability of the solution?

I rate the stability of the NodeZero Platform a ten out of ten. We have not encountered any issues on the platform regarding accessibility, performance, or stability.

What do I think about the scalability of the solution?

I rate the scalability of the NodeZero Platform a ten out of ten. We have conducted pen tests in environments with hundreds of thousands of IP addresses without any scalability issues. The platform is built for large scale deployment and operation.

How are customer service and support?

I rate their support an eight out of ten. The support is skilled and effective, although there are sometimes delays due to bandwidth issues, possibly due to the size of the team.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Initially, NodeZero and similar solutions were used alongside existing vulnerability management solutions like Qualys or Tenable. However, there has been a shift towards replacing these existing solutions as businesses seek to address vulnerability issues more efficiently.

How was the initial setup?

The initial setup is very easy, rated 10 out of 10. It involves straightforward steps of installing a Docker container, configuring firewalls, and ensuring communication with the cloud.

What about the implementation team?

The deployment process involves an initial meeting with the client to choose the deployment method—either on a VMware or Docker container. This is followed by defining and setting up firewall rules. After preparing everything, deploying the Docker container or VMware takes a few minutes, and the pen test can begin.

What's my experience with pricing, setup cost, and licensing?

I rate the pricing a six out of ten. Pricing is moderate compared to competitors but depends on the solutions in comparison. While cheaper than XM Cyber and human pen testers, it's more expensive than vulnerability managers.

Which other solutions did I evaluate?

I evaluated Pentera and XM Cyber alongside the NodeZero Platform at various points. Pentera was assessed about two years ago, and we have clients currently using XM Cyber.

What other advice do I have?

I rate the NodeZero Platform an eight out of ten. The platform is scalable and stable, suitable for large enterprises and businesses. It needs improvement in areas like visibility, reporting, and automation with third-party systems. The overall product rating is eight.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Flag as inappropriate
Manager, Information Technology at a performing arts with 11-50 employees
Real User
Top 5Leaderboard
Penetration testing adapts to our schedule with cloud integration
Pros and Cons
  • "Overall, I'd rate NodeZero at nine to 9.5 out of ten."

    What is our primary use case?

    To meet standards, I am required to do penetration testing periodically. This is something I can do on-demand anytime I choose, or I can set it up to recur on a recurring schedule.

    What is most valuable?

    The NodeZero Platform has a great cost, and its usability is straightforward. It can be deployed in the cloud. There is an on-premise container that I need to spin up to allow it to run in my environment, but it is automatically updated because it is cloud-based. It uses AI to try and gain access to my network and learns from the environment as it goes, providing a report on vulnerabilities, and demonstrates how their system exploits them to either elevate privilege or gain access to specific credentials or devices.

    What needs improvement?

    I haven't really come across anything that I say needs to be improved with it, other than the container runner, which tends to lose time. It does not always sync with the cloud versions, so I have to do it manually.

    For how long have I used the solution?

    I have used the solution for over a year.

    What do I think about the stability of the solution?

    Initially, there were some devices that, when it scanned, it caused network issues. So I had to exclude those, but that was fairly simple to do.

    How are customer service and support?

    I reached out to support and they were very responsive. I would rate them a nine out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have reviewed other penetration testing solutions but haven't used them due to cost constraints, as they were really expensive compared to the NodeZero Platform.

    How was the initial setup?

    The initial setup was simple and easy to operate.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is much more affordable than traditional penetration tests.

    Which other solutions did I evaluate?

    I have reviewed other penetration testing solutions but did not use any due to cost constraints.

    What other advice do I have?

    I would advise taking advantage of the support when you have it. For Horizon360 NodeZero, they are always responsive. Let them show you how to use it and the best way to get the most out of it. Overall, I'd rate NodeZero at nine to 9.5 out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Flag as inappropriate