No more typing reviews! Try our Samantha, our new voice AI agent.

Cymulate vs OffSec Penetration Testing Services comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cymulate
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
6
Ranking in other categories
Threat Intelligence Platforms (TIP) (11th), Breach and Attack Simulation (BAS) (2nd), Attack Surface Management (ASM) (10th), Continuous Threat Exposure Management (CTEM) (3rd)
OffSec Penetration Testing ...
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
1
Ranking in other categories
Penetration Testing Services (7th)
 

Featured Reviews

SB
Security Architec at Shikun & Binui
Support and integration enhance security posture over three years
I don't know if there's something that could be improved. They surprise me. As I mentioned, I returned a month ago. I haven't fully investigated the complete system yet. I must say that we have been with them for around three years. This is amazing because throughout these three years, they have supported us every week. We meet weekly to review results and fix issues together. Apart from occasional days off, this weekly support has been consistent for three years. It's remarkable because many products are sold and then the product teams forget about you, but this isn't the case with Cymulate.
Gabriel Woolverton - PeerSpot reviewer
Penetration Tester at a tech consulting company with 1-10 employees
Open source and easy to set up
Offensive Security Penetration Testing Services has a rating system for how exploitable vulnerability is, but that rating system does not really give you any transparency into how the rating for that exploit was reached. It would be useful to see on the back end what data led them to specify that a specific exploit may not be very good or may be great. If we had some data correlated with that, we could see why it is that this one should be successful versus another.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The security validation feature helps my organization in assessing our security posture."
"The most valuable feature for us is the zero-day."
"Cymulate is easy to set up, install, and configure."
"The reporting capabilities are very good."
"With Cymulate, the best features are the capacity to test the EDR or malware, anti-malware solution."
"Cymulate has positively impacted our organization by helping us to take care of the efficacy and reviewing the policies and configuration."
"Compared to Rapid7, Offensive Security might have more support on the back end in relation to exploits for Metasploit, for example."
"Offensive Security Penetration Testing Services is open source, so it is free and there are no licensing costs."
 

Cons

"The way Cymulate works for EDR could be improved, as it drops payload and requires action from the EDR console for remediation, which can block the whole process of Cymulate execution."
"I will be honest, we have it, but in the last year, I didn't maintain the system until a month ago."
"The product must provide consultancy for initial setup."
"The cost can be quite high, and it impacts scalability as more simulations require additional expenses."
"We have had some trouble with the agents."
"The reporting process requires significant improvement as it often takes longer than expected and the quality is lacking."
"Offensive Security Penetration Testing Services has a rating system for how exploitable vulnerability is, but that rating system does not really give you any transparency into how the rating for that exploit was reached."
"Offensive Security Penetration Testing Services has a rating system for how exploitable vulnerability is, but that rating system does not really give you any transparency into how the rating for that exploit was reached. It would be useful to see on the back end what data led them to specify that a specific exploit may not be very good or may be great."
 

Pricing and Cost Advice

"Cymulate's services are expensive."
"The product is affordable."
Information not available
report
Use our free recommendation engine to learn which Penetration Testing Services solutions are best for your needs.
885,444 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
9%
Manufacturing Company
9%
Comms Service Provider
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Large Enterprise3
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Cymulate?
I don't know if it's expensive. It depends on the modules that you want, or the time, because they give you a tenant. A tenant for you.
What needs improvement with Cymulate?
I don't know if that helped with quick decision making for my security team because I am the security team and you must have a dedicated team to work with this tool. I don't use the analytics modul...
What advice do you have for others considering Cymulate?
With Cymulate, I have experience using the vulnerability management tools. I don't know if I have used the Continuous Security Validation with Cymulate. I don't have that module licensed with Cymul...
Ask a question
Earn 20 points
 

Overview

 

Sample Customers

Euronext, YMCA, Telit, Nemours 
Amazon, IBM, Oracle, U.S. Department of Defense, Deloitte, Salesforce
Find out what your peers are saying about Horizon3.ai, HackerOne, Bugcrowd and others in Penetration Testing Services. Updated: March 2026.
885,444 professionals have used our research since 2012.