No more typing reviews! Try our Samantha, our new voice AI agent.

Invicti vs SUSE Rancher comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Container Security
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Cloud Workload Protection Platforms (CWPP) (9th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Invicti
Ranking in Container Security
32nd
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
31
Ranking in other categories
Static Application Security Testing (SAST) (16th), Software Composition Analysis (SCA) (14th), API Security (12th), Dynamic Application Security Testing (DAST) (6th), Application Security Posture Management (ASPM) (12th)
SUSE Rancher
Ranking in Container Security
17th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
13
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Container Security category, the mindshare of Qualys TotalCloud is 1.8%, up from 1.1% compared to the previous year. The mindshare of Invicti is 1.1%, up from 0.4% compared to the previous year. The mindshare of SUSE Rancher is 0.6%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Container Security Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud1.8%
SUSE Rancher0.6%
Invicti1.1%
Other96.5%
Container Security
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
PrashantUppuluri - PeerSpot reviewer
Solution Architect at a tech services company with 51-200 employees
Automated scanning has strengthened web application security and supports hybrid protection
A good scanning engine is what I appreciate about Invicti. When you want to find out the vulnerabilities within your web applications, Invicti has done a thorough job with respect to filtering out the vulnerabilities and identifying the risk factors with respect to the security modules within the solution. Invicti does have a segment of the solution which works on the automated scanning engine. As long as the license is active, the scanners that work within the solution are pretty effective. With respect to SAST and DAST, being a real-time scanning engine is one of the portfolios and one of the selling factors of the solution. Invicti is known to be a solution that works within the hybrid environment, be it cloud, on-premises, or a mix and match across multiple marketplaces. It does a thorough job. Most importantly, Invicti is a very good SAST and DAST solution that is very competitive in the market with respect to competitors. Invicti is a part of the Magic Quadrant with respect to Gartner's Magic Quadrant and has made a very good customer database and pipeline within the marketplace locally. With respect to security impacts in terms of support, Invicti is pretty much supportive. With respect to use cases or the POCs I have run on the solution, we have identified a couple of vulnerabilities and Invicti was able to trace them, detect, and quarantine the attacks.
Shivamp Kachole - PeerSpot reviewer
Associate System Engineer at Dhanyaayai enterprise private limited
Centralized cluster management has improved daily operations and simplifies troubleshooting
I am happy with SUSE Rancher, but there are a few areas where it could be improved. During major version upgrades, the process can become a bit complex, especially in air-gapped environments where image management and dependencies require extra planning. Additionally, troubleshooting sometimes still requires switching to the command line because not every error is visible in the UI. If the UI provided more detailed diagnostic and troubleshooting information, it would make our issue resolution even faster. Other than that, it has been a reliable platform for all of us. I think the documentation is already very good, but for complex scenarios such as air-gapped environments, disaster recovery, or multi-cluster upgrades, having more step-by-step examples and troubleshooting guides would be very helpful. On the UI side, if SUSE Rancher could provide more detailed error messages and built-in diagnostic recognition, it would reduce the need to switch to logs and command lines. Those improvements would make our daily operations even easier and smoother, especially for new administrators and fresh team members.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
"If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI."
"Qualys TotalCloud's most valuable features are its cloud security posture management, Kubernetes, and container security capabilities."
"I appreciate TotalCloud's real-time protection and remediation features. The remediation options include automated one-click remedies and custom changes that help manage vulnerabilities efficiently."
"The best feature would be the ability to create policies. It is easy to control and update policies as required."
"Generally, Qualys is very good at detections, whether on cloud or on-prem, and the agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us."
"Its excellent graphical interface makes the scanning process simple."
"TotalCloud's best feature is the integration of cloud accounts. It helps with the risk and security posture management of our cloud infrastructure."
"We use simultaneous products, but I found this to be the best of the lot."
"Crawling feature: Netsparker has very detail crawling steps and mechanisms. This feature expands the attack surface."
"I like that it's stable and technical support is great."
"Its ability to crawl a web application is quite different than another similar scanner, and sometimes it can find more vulnerabilities that another scanner can’t."
"Invicti's proactive scanning measures vulnerabilities each time we deploy or push code to a new environment."
"NetSparker is a very easy to use and understand product."
"Invicti is part of our SSDLC portfolio, and DAST dynamic testing is very important for our web applications and portfolios."
"The platform is stable."
"With SUSE Rancher, everything is in one place and centralized, daily operations are much faster and easier for us, it has reduced manual efforts and helped us troubleshoot issues faster because we get a single view from all our clusters, and overall, it has improved our team efficiency and consistency."
"SUSE Rancher has positively impacted my organization as productivity is the main point, and the productivity has improved because the main project goal was to finish the project faster, which was particularly important since we have many applications."
"SUSE Rancher has positively impacted my organization by making the teams' work easier and reducing project delivery time."
"SUSE Rancher is best used for large-scale applications such as ours; it manages very high-end infrastructure, and it has very good customer support, and it is very easy to understand in terms of usage."
"SUSE Rancher has made things easier for my team and organization by reducing errors, as I use it every day of the week, and it shows us issues through dashboards."
"SUSE Rancher helps me manage and automate processes with Kubernetes through full integration from hardware to application."
"SUSE Rancher has positively impacted our organization by helping our teams achieve greater results in delivering end-to-end initiatives."
"Rancher Desktop provides support for Kubernetes setup on local machines."
 

Cons

"Their support could be improved."
"To be honest, I would move out from this tool because it does not give a full view of vulnerability."
"The price is very expensive, actually."
"Their customer support needs improvement."
"Although TotalCloud is a helpful tool, some of its advanced features are still under development."
"In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys TotalCloud."
"We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage."
"Overall, we are satisfied with it. However, the response part of the Cloud Detection and Response (CDR) module can be improved. It is not yet in place according to requirements; it is not completely available even though the module has been released."
"It would be better for listing and attacking Java-based web applications to exploit vulnerabilities."
"The scan performance can be improved upon."
"Reporting should be improved. The reporting options should be made better for end-users. Currently, it is possible, but it's not the best. Being able to choose what I want to see in my reports rather than being given prefixed information would make my life easier. I had to depend on the API for getting the content that I wanted. If they could fix the reporting feature to make it more comprehensive and user-friendly, it would help a lot of end-users. Everything else was good about this product."
"Invicti takes too long with big applications, and there are issues with the login portal."
"It is a good tool, as we found out with the Community Edition trial, but the price point is quite expensive for a startup or average-sized company."
"The solution needs to make a more specific report."
"Improvement could be made in the area of production."
"They don't really provide the proof of concept up to the level that we need in our organization. We are a consultancy firm, and we provide consultancy for the implementation and deployment solutions to our customers. When you run the scans and the scan is completed, it only shows the proof of exploit, which really doesn't work because the tool is running the scan and exploiting on the read-only form. You don't really know whether it is actually giving the proof of exploit. We cannot prove it manually to a customer that the exploit is genuine. It is really hard to perform it manually and prove it to the concerned development, remediation, and security teams. It is currently missing the static application security part of the application security, especially web application security. It would be really cool if they can integrate a SAS tool with their dynamic one."
"Regarding the platform's features and advantages, it is unfortunate that observability and some artificial intelligence functionality work fully only with a paid subscription."
"I have noticed that SUSE Rancher's GUI is slow because we have more than 1,000 pods, and when searching for a pod name, the page takes some time to load."
"Additional features for a paid solution should be included, such as more detailed insights, better graphics, and an improved user interface."
"All the tasks that SUSE Rancher does can be done in alternative methods, so it is not a must-have or a necessary tool in my view."
"I wish the container could be more lightweight so that anyone can test and verify SUSE Rancher Prime."
"There are a lot of issues in the tool, such as addressing the errors, addressing the stability, and addressing the reliability."
"During major version upgrades, the process can become a bit complex, especially in air-gapped environments where image management and dependencies require extra planning."
"An improvement I wish for with SUSE Rancher is that we once had issues regarding some driver problems for the network on a particular laptop, and we had a hard time finding the exact error occurring."
 

Pricing and Cost Advice

"Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great."
"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"Qualys TotalCloud is expensive."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"The cost is high, but it meets our organizational needs."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"TotalCloud's price is about right where I would expect it to be."
"I think that price it too high, like other Security applications such as Acunetix, WebInspect, and so on."
"We are using an NFR license and I do not know the exact price of the NFR license. I think 20 FQDN for three years would cost around 35,000 US Dollars."
"We never had any issues with the licensing; the price was within our assigned limits."
"OWASP Zap is free and it has live updates, so that's a big plus."
"Invicti is best suited for large enterprises. I don't think small and medium-sized businesses can afford it. Maintenance costs aren't that great."
"Netsparker is one of the costliest products in the market. It would help if they could allow us to scan multiple URLs on the same license."
"It is competitive in the security market."
"The solution is very expensive. It comes with a yearly subscription. We were paying 6000 dollars yearly for unlimited scans. We have three licenses; basic, business, and ultimate. We need ultimate because it has unlimited scan numbers."
Information not available
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
13%
Manufacturing Company
10%
Construction Company
8%
Computer Software Company
6%
Outsourcing Company
28%
Computer Software Company
23%
Comms Service Provider
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise35
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise4
Large Enterprise13
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise2
Large Enterprise7
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Netsparker Web Application Security Scanner?
The setup cost is pretty competitive. For example, if you want to talk about the SAST license, it comes to about $150...
What needs improvement with Invicti?
At this time, there is nothing that comes to mind. However, most of the products in the market are pretty much neck-t...
What is your primary use case for Invicti?
I have worked on a couple of products, specifically in web application security. I have worked on Invicti, and with r...
What is your experience regarding pricing and costs for SUSE Rancher?
I wasn't directly involved in the commercial side such as pricing, negotiation, or licensing decisions. Since we are ...
What needs improvement with SUSE Rancher?
I am happy with SUSE Rancher, but there are a few areas where it could be improved. During major version upgrades, th...
What is your primary use case for SUSE Rancher?
I have been working in the DevOps field and platform engineering field for around two years, approximately 1.9 years....
 

Also Known As

Qualys TotalCloud with FlexScan
Netsparker
No data available
 

Overview

 

Sample Customers

Information Not Available
Samsung, The Walt Disney Company, T-Systems, ING Bank
Information Not Available
Find out what your peers are saying about Invicti vs. SUSE Rancher and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.