Try our new research platform with insights from 80,000+ expert users

Fortra's Cobalt Strike vs Tenable One Exposure Management Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortra's Cobalt Strike
Average Rating
9.6
Reviews Sentiment
7.2
Number of Reviews
2
Ranking in other categories
Breach and Attack Simulation (BAS) (6th)
Tenable One Exposure Manage...
Average Rating
9.0
Reviews Sentiment
7.3
Number of Reviews
4
Ranking in other categories
Threat Intelligence Platforms (15th), Continuous Threat Exposure Management (CTEM) (6th)
 

Mindshare comparison

Fortra's Cobalt Strike and Tenable One Exposure Management Platform aren’t in the same category and serve different purposes. Fortra's Cobalt Strike is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 1.7%, up 1.4% compared to last year.
Tenable One Exposure Management Platform, on the other hand, focuses on Continuous Threat Exposure Management (CTEM), holds 6.9% mindshare, up 3.2% since last year.
Breach and Attack Simulation (BAS)
Continuous Threat Exposure Management (CTEM)
 

Featured Reviews

reviewer2519427 - PeerSpot reviewer
Compact, versatile, creates shell codes for bypassing antivirus and built-in report templates streamline the process
Probably its delivery methods could be improved. It might need some improvements on its spear phishing module. You can clone a web page, and then you can spear phish a target, and the target connects to your beacon. I believe that it needs to be more modernized to the current standards of multi-factor authentication bypass. Although there are already tools that actually do that, like Evilginx that’s been used as a proxy server, I truly believe Cobalt Strike could do something like that. I believe if Cobalt modernize this specific feature to try to bypass multi-factor authentication, it’s gonna be something. I’m not aware if it’s actually a feature in the latest Cobalt Strike updates, but from my version, I don’t see that it’s possible right now. I don’t think AI is at the stage where it can conduct such complex operations. AI is mostly being used to create phishing templates, very simple stuff. AI is not mature enough to do something more complex, although I truly believe that in a few years, it might have such capabilities.
Yusuf_Hashmi - PeerSpot reviewer
Good discovery and vulnerability features and is easy to use
I think it's a good product for risk-based or exposure-based vulnerability management. It gives me the ability to identify potential weaknesses in my environment quickly. Once those vulnerabilities get identified on the console, it is only a matter of performing those actions. I would rate it nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cobalt Strike offers significant customization capabilities."
"It also made a lot of post-exploitation activities easier."
"The feature of vulnerability management and discovery is what I use."
"The product gives us a lot of insight."
"The solution is very easy to set up."
"I think it's a good product for risk-based or exposure-based vulnerability management."
"For me, the setup has been an easy process."
 

Cons

"The stability of the tool can be improved."
"Probably its delivery methods could be improved."
"The product has limited reporting capabilities and it isn't great at allowing for customization in reports."
"The sensor update is a challenge that Tenable needs to address."
"It would be nice if the product provided an agent for enforcing policies."
"Tenable needs to provide a better way to manage private clouds."
"The sensor update is a challenge that Tenable needs to address. Sometimes they behave abruptly, requiring me to rework reinstalling the sensors on the endpoints."
 

Pricing and Cost Advice

"It's expensive."
"The pricing is fair."
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
858,435 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
16%
Financial Services Firm
13%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Fortra's Cobalt Strike?
While not inexpensive, Cobalt Strike is a comprehensive platform. Its pricing reflects the capabilities and flexibility it offers. The solution can be cost-effective when utilizing its full potenti...
What needs improvement with Fortra's Cobalt Strike?
The stability of the tool can be improved. There are some limitations, but they tend to be more from outside of the tool rather than within it. The limitations often come from operators who may lac...
What is your primary use case for Fortra's Cobalt Strike?
I use Cobalt Strike to emulate threat actor activities.
What do you like most about Tenable.ep?
The product gives us a lot of insight.
What needs improvement with Tenable.ep?
There is not much room for improvement. However, the sensor update is a challenge that Tenable needs to address. Sometimes they behave abruptly, requiring me to rework reinstalling the sensors on t...
 

Also Known As

No data available
Tenable.ep
 

Overview

Find out what your peers are saying about Fortra's Cobalt Strike vs. Tenable One Exposure Management Platform and other solutions. Updated: December 2024.
858,435 professionals have used our research since 2012.