Try our new research platform with insights from 80,000+ expert users

DefectDojo vs Microsoft Defender Vulnerability Management comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Zafran Security
Sponsored
Ranking in Vulnerability Management
17th
Average Rating
9.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Continuous Threat Exposure Management (CTEM) (1st)
DefectDojo
Ranking in Vulnerability Management
41st
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
1
Ranking in other categories
DevSecOps (11th)
Microsoft Defender Vulnerab...
Ranking in Vulnerability Management
12th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
16
Ranking in other categories
Advanced Threat Protection (ATP) (16th), Microsoft Security Suite (20th), Risk-Based Vulnerability Management (5th)
 

Mindshare comparison

As of October 2025, in the Vulnerability Management category, the mindshare of Zafran Security is 1.0%, up from 0.1% compared to the previous year. The mindshare of DefectDojo is 0.8%, up from 0.2% compared to the previous year. The mindshare of Microsoft Defender Vulnerability Management is 2.7%, down from 2.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Microsoft Defender Vulnerability Management2.7%
Zafran Security1.0%
DefectDojo0.8%
Other95.5%
Vulnerability Management
 

Featured Reviews

Israel Cavazos Landini - PeerSpot reviewer
Weekly insights and risk analysis facilitate informed security decisions
I appreciate the weekly insights Zafran provides, which include critical topics for networks and IT security, allowing us to evaluate which insights apply to our environment. The organization score feature is valuable to keep the leadership team updated on how our infrastructure fares security-wise. The applicable risk level versus base risk level feature is beneficial because prior to Zafran, we only used the base risk level, but now understand that risk depends on the asset itself. Zafran is an excellent tool.
reviewer2267097 - PeerSpot reviewer
Easy to use with efficient vulnerability reporting and team collaboration
Use case, so all the reports from GitLeaks, DefectDojo, GitLeaks or dependency check or Trivy, they make reports, and we send this report to DefectDojo to have CVMs, Central Vulnerability Management. DefectDojo is Central Vulnerability Management. If you have a dashboard to set, we have…
Krishna R - PeerSpot reviewer
Achieve comprehensive endpoint and identity protection with continuous real-time monitoring
I have not thought about improvements for Microsoft Defender Vulnerability Management as of now, but this is typically an operational maintenance process. The operational maintenance process refers to these products being part of day-to-day operations. Threats keep coming almost daily, and we need to run it, prioritize the risk, and apply the patches. I am not able to think of many features for improvement at this point in time. There should be risk scoring added to Microsoft Defender Vulnerability Management; specifically, they call it quantification of the risk. If they can provide peer site reviews or risk scoring, such as how my organization in the healthcare industry fares against my peers on average, it would be valuable information. This scoring should be for specific industries as well. If I belong to the healthcare industry using Microsoft Defender Vulnerability Management, it should provide me with a risk score and show how I fare against the risk score of my industry. If there are guidelines or insights on this, it will compel customers to reduce risk levels or improve their risk scores. The application block capabilities in Microsoft Defender Vulnerability Management are effective and up to the standards, as everybody is looking at open OSINT and open-source security packages. I think on CV scoring, they are aligned with the industry.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Zafran is an excellent tool."
"Overall, we have seen about eighty-seven percent reduction of the number of vulnerabilities that require urgency to remediate, specifically the number of criticals."
"Zafran has become an indispensable tool in our cybersecurity arsenal."
"We are able to see the real risk of a vulnerability on our environment with our security tools."
"We saw benefits from Zafran Security almost immediately after deploying it."
"With the pipeline of detection and DefectDojo, we are able to see the real vulnerabilities, and we fix them."
"A valuable feature is the ease of management and integration with Microsoft products."
"The integration with Sentinel has been one of the most valuable features for my organization."
"Overall, I would rate Microsoft Defender Vulnerability Management a nine out of ten."
"Microsoft Defender Vulnerability Management has streamlined our threat management processes and provided region-specific customization for our healthcare operations."
"A valuable feature is the ease of management and integration with Microsoft products."
"One valuable feature is the Microsoft Security Scorecard."
"The recommendations, scores, and steps to remediate actions are highly useful."
"Microsoft Defender Vulnerability Management is versatile and assesses vulnerabilities, providing detailed information on CVEs, their categories, and exploit statuses."
 

Cons

"The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvements."
"Initially, we were somewhat concerned about the scalability of Zafran due to our large asset count and the substantial amount of information we needed to process."
"I think the ability to have some enhanced reporting capabilities is something they can improve on, as they have good reports but we have asked for some specific reporting enhancements."
"We need something to notify the team responsible for a product when vulnerabilities are found."
"Integration can be improved."
"Sometimes the stability of the agents could be improved."
"The general support could be improved."
"The technical support takes too much time to resolve tickets."
"There should be risk scoring added to Microsoft Defender Vulnerability Management; specifically, they call it quantification of the risk."
"The worst aspect is the refresh rate of the dashboard. A vulnerability I patch within 15 minutes takes 24 additional hours for an update."
"They may need to improve the portal refresh rate for Microsoft Defender Vulnerability Management because it takes time for recommendations to disappear after mitigation; sometimes, it takes one week, when it should ideally take only one to two hours."
"The setup phase of the product is not that easy and needs a person to have a certain level of expertise."
 

Pricing and Cost Advice

Information not available
Information not available
"I rate the product's price a three on a scale of one to ten, where one is a low price, and ten is a high price."
"The licensing costs are reasonable."
"The licensing model follows a per-user per-month structure."
"The tool is a bit costly."
"The product’s pricing is medium."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
872,778 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
9%
Manufacturing Company
8%
Government
5%
Financial Services Firm
17%
Computer Software Company
16%
Comms Service Provider
12%
Retailer
7%
Financial Services Firm
12%
Computer Software Company
11%
Government
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What is your experience regarding pricing and costs for Zafran Security?
Since we stood Zafran Security up in our private cloud, we handle the maintenance on our side. As we opted not to use...
What needs improvement with Zafran Security?
In terms of areas for improvement, Zafran Security is doing a really great job as a new and emerging company. Oftenti...
What is your primary use case for Zafran Security?
My use cases for Zafran Security revolve around two primary areas. One is around vulnerability management and priorit...
What is your experience regarding pricing and costs for DefectDojo?
The pricing is great. It is much cheaper compared to other solutions. We don't want to pay for things we are able to ...
What needs improvement with DefectDojo?
We need something to notify the team responsible for a product when vulnerabilities are found. We are able to attach ...
What is your primary use case for DefectDojo?
Use case, so all the reports from GitLeaks, DefectDojo, GitLeaks or dependency check or Trivy, they make reports, and...
What is your experience regarding pricing and costs for Microsoft Defender Vulnerability Management?
I would rate the price as a three for us due to the partnership discounts. For non-partners, however, the cost could ...
What needs improvement with Microsoft Defender Vulnerability Management?
I have not thought about improvements for Microsoft Defender Vulnerability Management as of now, but this is typicall...
 

Overview

Find out what your peers are saying about Tenable, Wiz, Qualys and others in Vulnerability Management. Updated: October 2025.
872,778 professionals have used our research since 2012.