No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Security Hub vs VMware Aria Automation comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Cloud Security Posture Management (CSPM)
8th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
AWS Security Hub
Ranking in Cloud Security Posture Management (CSPM)
17th
Average Rating
7.6
Reviews Sentiment
6.5
Number of Reviews
27
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (8th)
VMware Aria Automation
Ranking in Cloud Security Posture Management (CSPM)
28th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
172
Ranking in other categories
Cloud Management (3rd), Configuration Management (10th), Network Automation (7th), Cloud Infrastructure Entitlement Management (CIEM) (7th)
 

Mindshare comparison

As of September 2026, in the Cloud Security Posture Management (CSPM) category, the mindshare of Qualys TotalCloud is 2.0%, up from 1.4% compared to the previous year. The mindshare of AWS Security Hub is 2.7%, down from 4.2% compared to the previous year. The mindshare of VMware Aria Automation is 1.0%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Security Posture Management (CSPM) Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud2.0%
AWS Security Hub2.7%
VMware Aria Automation1.0%
Other94.3%
Cloud Security Posture Management (CSPM)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Karthik Ekambaram - PeerSpot reviewer
Director at Scybers
Has helped identify misconfigurations and prioritize risks but lacks multi-cloud support and deeper integration features
AWS Security Hub cannot scale up to multiple different cloud environments; it only works for AWS. There are other products in the market for CSPM that can give you multi-cloud environment misconfigurations, even Microsoft for that matter. Regarding the integration of AWS Security Hub with third-party tools, I am not certain whether we can integrate them, but there is no need to do so. However, AWS Security Hub cannot integrate with other cloud providers, so it only supports the AWS environment. The compliance checks within AWS Security Hub are good, but we don't use them much. We utilize compliance frameworks such as CIS compliance frameworks and ISO 27017 framework, which are beneficial, but it can improve in other areas too, such as including NIST and other frameworks beyond just ISO and CIS. Improvements can be applicable for scalability, particularly on integration with multi-cloud environments, and compliance frameworks can be added for more variety as well. The unified dashboard in AWS Security Hub is adequate; I cannot say it is exceptional, but the content available in the dashboards is satisfactory for now.
VasilisGiannitsiotis - PeerSpot reviewer
Senior IT at ITSolutions
Automation has streamlined complex financial workflows but still needs more intuitive orchestration
Something to improve in VMware Aria Automation would be related to VCF 9, as I do not know what it is trying to bring because they exposed it as the solution of everything. So VCF 9 will bring VCF Automation and VCF Operations, the new product line of VMware. I have not seen what this brings or what else it includes. Maybe in the area of vRealize Orchestrator, this would be beneficial because VRO can do everything. Perhaps a more user-friendly way to use that tool would be helpful because the possibilities there are endless. I am looking for more user-friendly navigation in VMware Aria Automation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"While automatic inventory detection upon connection is a helpful feature, a truly valuable capability would be assessing an environment's security posture against Azure and CIS best practices."
"The most valuable feature of Qualys TotalCloud is the visibility it provides."
"By integrating TotalCloud, we have significantly reduced vulnerabilities in our deployment pipeline."
"Qualys TotalCloud has positively impacted our organization by helping us save time and manage all assets and remediation, allowing us to achieve quarterly and half-yearly goals."
"One of the features I appreciate is the ability to generate daily reports without relying on anyone else."
"I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers."
"I highly recommend Qualys TotalCloud to other users."
"Once you have your vulnerabilities fixed and your patches pushed out using Qualys TotalCloud, then you are able to eliminate threats and cyber risk."
"Within AWS Security Hub, there is a feature for aggregating and prioritizing security findings which allows for better risk prioritization based on misconfiguration, as they know AWS thoroughly."
"Security Hub provides insightful information about what is running and where there might be weaknesses."
"I like that AWS Security Hub currently has several good features, around four or five. The technical support for AWS Security Hub is also responsive."
"The most valuable feature of AWS Security Hub is the ability to track when monitoring is not enabled on any of my resources."
"The platform has valuable features for security."
"AWS Security Hub's unified dashboard does help streamline my process of identifying vulnerabilities, but we don't use Inspector."
"I really like the seamless integration with the AWS account structure. It can even be made mandatory as part of the landing zone. These are great features. And there's a single pane of glass for the entire account."
"AWS Security Hub brings many features into one table that is quite useful, and the app team finds it easier to see what is missing."
"We like vRA because it helps make systems available on time for our customers, on demand."
"This is such an all-encompassing solution."
"One of the most valuable features is lifecycle management. It allows my teams to create, manage, and retire all of our infrastructure objects in the data center."
"It is probably 90 percent quicker to get something out the door than it was before. For developers, depending on who is building VMs for them, sometimes they request anywhere from 20 to 100. Now, we can deploy them in a matter of an hour, where previously it might have taken me three days to deploy out 100 VMs."
"To manage when VM's aren't being used, we have it set up so that it will auto-destroy them after a certain amount of time, obviously with permission from the user who owns it."
"The setup was straightforward. We upgraded to a newer version seamlessly. It worked really well."
"It's much more stable than the highest available variant."
"We're automating a lot of OS builds, and the front-end gives us a way for users to go and request those services and the orchestrator part lets us automate a lot of the functions involved in them."
 

Cons

"There is room for improvement in the support."
"To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution."
"Their customer support needs improvement."
"Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA."
"I chose a rating of nine out of ten because there is a complex interface that sometimes overwhelms new engineers."
"Regarding technical support from Qualys, they respond, but the response time can be too long. Sometimes we need to wait weeks for solutions to simple questions."
"The support process is inefficient due to the excessive number of replies required when submitting tickets."
"I sometimes have difficulty detecting or uninstalling certain versions of applications, which I have to do manually."
"The solution is not wholly self-sufficient."
"However, the sheer number of services can be overwhelming when implementing something new."
"There is room for improvement in implementing AI capabilities."
"Security needs to be measured based on their own criteria. We can't add custom criteria specific to our organization. For example, having an S3 bucket publicly available might be flagged as a critical alert, but it might not be critical in a sandbox environment. So, it gets flagged as critical, which becomes a false positive. So, customization options and creating custom dashboards would be areas for improvement."
"It is not flexible for multi-cloud environments."
"The solution should be easier to learn and use"
"Although AWS Security Hub does a periodic scan of your overall infrastructure, it doesn't do it in real time."
"Many findings are too generic or irrelevant to the environment, which can lead to false positives."
"I'm not aware if a UI exists or not."
"If you are using Aria Automation by itself, you won't get the features you want, and the license cost is high."
"Technical support could be improved. I definitely feel that the product is accelerating faster than the support engineers are able to keep up with the knowledge needed to know what's going on. The developers maintaining vRealize Automation are doing a great job improving it, but VMware is not doing a great job of training the people who we call to get support for it."
"Having an overview and managing all this is a bit difficult in the beginning."
"I have not found this solution to be user-friendly. It's really complicated. The demo shows that you can automate anything but they only show basic scenarios. If you want to do anything more complicated than that, it becomes very complicated to set up."
"It is difficult to set up."
"Most of the time the upgrade experience has been good but sometimes things break after upgrading. For example, some API codes stopped working."
"It is not intuitive or user-friendly. It's complicated as heck. We actually hired VMware Professional Services to come in. I understand the newer version, which we're not quite on yet, is easier and that the interface is better. But the product is really a profession unto itself. The user interface could be improved on."
 

Pricing and Cost Advice

"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"The cost is high, but it meets our organizational needs."
"Qualys TotalCloud is expensive."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"TotalCloud's price is about right where I would expect it to be."
"The price of AWS Security Hub is average compared to other solutions."
"The cost is based on the number of compliances, core checks, and services required, and for more than 10,000 recommendations, the charge is just one dollar."
"Security Hub is not an expensive solution."
"The price of the solution is not very competitive but it is reasonable."
"AWS Security Hub is not an expensive tool. I would consider it to be a cheap solution. AWS Security Hub follows the PAYG pricing model, meaning you will have to pay for whatever you use."
"The pricing is fine. It is not an expensive tool."
"AWS Security Hub's pricing is pretty reasonable."
"There are multiple subscription models, like yearly, monthly, and packaged."
"It is an expensive product. After VMware's acquisition by Broadcom, there was a rise in the price of VMware Aria Automation."
"The pricing for this solution is roughly 20% lower than the competitive products in the market."
"As far as value is concerned, it has been essential to our environment. We have been able to deploy VMs quickly and the developers have their own sandbox, so they can spin up and destroy VMs at their own will."
"We do plan to see ROI with any new implementation of new technologies being implemented within our environment."
"The cost of the solution is reasonable for us. Although it is relatively high, we prioritize stability and integration over cost."
"The tool is expensive since it is an enterprise product."
"vRealize automation really should be a front door to the whole VMware suite of products."
"It is an open-source product."
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Comparison Review

it_user186927 - PeerSpot reviewer
Director of Operations at a comms service provider with 10,001+ employees
Feb 16, 2015
Cybereason vs. Interset vs. SQRRL
Capture DB - they all use NoSQL db and hence solve the ad hoc query and 'go back in time' problem with current best of breed SIEM and DLP solutions that rely on real time analysis of incoming logs (and don't store them). This means deeper and quicker iterative threat analysis and assessment…
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
7%
Comms Service Provider
7%
Outsourcing Company
14%
Financial Services Firm
9%
Manufacturing Company
8%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise5
Large Enterprise14
By reviewers
Company SizeCount
Small Business33
Midsize Enterprise24
Large Enterprise131
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel...
What needs improvement with AWS Security Hub?
I do not see any areas for improvement in AWS Security Hub itself, but the cost factor is something that is the main ...
What is your primary use case for AWS Security Hub?
AWS Security Hub is something I have used daily as it is a part of my job for cloud security purposes. If you are dea...
What's the difference between VMware vRA (automation) and vROps (operations)?
vROP is a virtualization management solution from VMWare. It is efficient and easy to manage. You can find anything y...
Is there any way to try VMware Aria Automation for free?
When it comes to VMware Aria Automation, you have three choices for free runs: Hands-on Lab (HOL) Advanced lab A fre...
Which sectors can benefit the most from VMware Aria Automation?
I was looking at VMware Aria Automation case studies recently and I got the impression that three main kinds of compa...
 

Also Known As

Qualys TotalCloud with FlexScan
SQRRL
VMware vRealize Automation, vRA, VMware DynamicOps Cloud Suite, SaltStack
 

Overview

 

Sample Customers

Information Not Available
Edmunds, Frame.io, GoDaddy, Realtor.com
Rent-a-Center, Amway, Vistra Energy, Liberty Mutual
Find out what your peers are saying about AWS Security Hub vs. VMware Aria Automation and other solutions. Updated: August 2026.
913,806 professionals have used our research since 2012.