Listing Thumbnail

    VulnCheck

     Info
    Sold by: VulnCheck 
    Deployed on AWS
    VulnCheck helps organizations outpace adversaries with vulnerability intelligence that predicts avenues of attack with speed and accuracy.
    4.4

    Overview

    VulnCheck Exploit & Vulnerability Intelligence replaces the need to have separate scripts for downloading the NIST National Vulnerability Database (NVD), the CISA KEV catalog, etc. By integrating with VulnCheck Exploit & Vulnerability Intelligence, you're integrating with an Open Source Intelligence (OSINT) product that has best-in-class information, in a timely manner, on vulnerability exploitation and vulnerabilities generally.

    Unlike alternative vulnerability intelligence approach, the VulnCheck platform and VulnCheck Exploit & Vulnerability Intelligence products are built from a fully autonomous system in software.

    Organization leverage VulnCheck Exploit & Vulnerability Intelligence to make better decisions on which vulnerabilities need immediate remediation.

    Unlike other vulnerability databases, VulnCheck includes the latest information on a wider range of vulnerabilities, including:
    -Vulnerabilities in Open Source packages/dependencies
    -Vulnerabilities in ICS/OT, IoMT, IoT, mobile, etc., devices

    Most importantly, unlike other purely vulnerability-centric solutions, VulnCheck marries exploit intelligence with vulnerability intelligence. By coupling exploit intelligence with vulnerability intelligence, better insights into vulnerability prioritization & remediation can be gained.

    Highlights

    • Exploit Intelligence for Vulnerability Prioritization
    • Next-generation Cyber Threat Intelligence platform
    • Initial Access Intelligence for Detection

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (5)

     Info
    Dimension
    Description
    Cost/12 months
    EVI
    Exploit & Vulnerability Intelligence
    $259,200.00
    IAI
    Initial Access Intelligence
    $302,400.00
    IPI
    IP Intelligence
    $216,000.00
    GOV
    VulnCheck for Government
    $747,000.00
    CI
    Canary Intelligence
    $288,000.00

    Vendor refund policy

    All fees are non-refundable and non-cancellable except as required by law.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    VulnCheck customers will be assigned a dedicated Customer Success Manager and Engineer to ensure that they are able to use VulnCheck intelligence to its fullest potential. We provide direct support via Slack/Teams, web meetings, phone, or email.
    support@vulncheck.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Analytic Platforms
    Top
    10
    In Vulnerability and Patch Management

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    3 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    4 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Exploit Intelligence Integration
    Couples exploit intelligence with vulnerability intelligence to provide insights into vulnerability prioritization and remediation strategies.
    Multi-Domain Vulnerability Coverage
    Includes vulnerability data across open source packages, dependencies, ICS/OT, IoMT, IoT, and mobile devices.
    Integrated Vulnerability Data Aggregation
    Consolidates data from NIST National Vulnerability Database (NVD) and CISA KEV catalog into a single platform.
    Autonomous Intelligence System
    Built on a fully autonomous system in software for vulnerability and exploit intelligence generation.
    Initial Access Intelligence
    Provides intelligence for detection of initial access vectors used by adversaries.
    Native Data Connectors
    Supports native connectors for integrating vulnerability data from multiple sources and scanning tools
    Threat Intelligence Integration
    Integrates Mandiant threat intelligence, publicly available threat intelligence from NVD and CISA KEV, and Recorded Future intelligence for contextual vulnerability analysis
    Role-Based Access Control
    Implements role-based access control and asset group access control for managing user permissions and data visibility
    Automated Workflow and Ticketing
    Supports manual and automated ticket integrations for streamlined remediation workflows and response automation at scale
    Reporting and Data Export
    Provides in-platform reporting capabilities, trends analysis, and bulk data export functionality for vulnerability program visibility and analysis
    Environment-Specific Exploitability Analysis
    AI-native platform that replaces CVSS-based prioritization with environment-specific exploitability analysis by aggregating findings from connected scanners and security tools, enriched with runtime presence, internet reachability, active threat intelligence, and live defense configuration.
    Compensating Control Deployment
    Deploys compensating controls through existing EDR solutions (CrowdStrike, SentinelOne, Defender), WAF, and NGFW to neutralize risk while patching runs in parallel.
    Agentless Integration
    Integrates agentlessly with 100+ tools across scanners (Tenable, Qualys, Rapid7, Wiz, Prisma), EDR, CNAPP, firewall, and ITSM platforms via existing APIs without requiring new agents.
    Automated Remediation Workflow
    RemOps deduplicates overlapping CVEs into single high-fidelity remediation tickets, routes to verified owners through Jira or ServiceNow, and tracks through to closure with SLA tracking.
    Compliance Reporting and Audit Capabilities
    Provides out-of-the-box executive and compliance reporting for SOX, HIPAA, PCI-DSS, and SOC 2 with audit-ready exports on demand, supported by agentic AI layer for natural-language queries and copilot workflows.

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    4.4
    7 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    57%
    43%
    0%
    0%
    0%
    3 AWS reviews
    |
    4 external reviews
    External reviews are from G2  and PeerSpot .
    Hardik Murdia

    Automated exploit-aware checks have improved vulnerability prioritization and reduced remediation time

    Reviewed on Jul 23, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for VulnCheck is vulnerability checks, which allows us to check what vulnerabilities we have in our dependencies, ensuring we are on the latest versions of the dependencies we are using in the code, and it also manages the CVSS score.

    The primary use case of VulnCheck is to enhance our vulnerability management by helping us identify vulnerabilities that are already actively exploited. For example, the CVSS score of Log4j, which is a well-known vulnerability, can be easily detected across all modules and potentially entangled between different modules. These are critical scenarios as we prioritize our remediation efforts based on exploit intelligence rather than relying solely on CVSS scores.

    When VulnCheck flagged the Log4j vulnerability, it provided an alert to the security team, which was handed over as a Jira ticket. We fixed it right away. It was not a production issue because production had a version without that CVSS score, but the vulnerability was real and we checked everything behind the VPN.

    I use VulnCheck for vulnerability checks, as we prioritize vulnerabilities across the entire infrastructure, allowing our security team to focus on critical risks, reducing remediation time by presenting everything on one page and improving the overall vulnerability management system.

    What is most valuable?

    VulnCheck offers helpful endpoint security, providing centralized visibility and enabling us to automate incident response effectively, translating that to the actual team responsible for fixes. Additionally, we really appreciate its backup and disaster recovery features and commendable network access control.

    The biggest benefit of automated incident response with VulnCheck is reducing overall time in identifying and solving problems right away, which has reduced our mean time to recovery in scenarios where we need to identify vulnerabilities, as we already have complete information on the page to address the exact issue.

    VulnCheck positively impacts our organization by allowing us to manage our secrets properly. We use the platform to detect exposed APIs, passwords, tokens, and other sensitive credentials across source codes or repositories, ensuring no API is exposed during our CI/CD pipeline and allowing us to maintain strong security policies for our cloud applications.

    VulnCheck's early exploit visibility has positively influenced our threat response strategy by enabling us to check vulnerabilities faster while reducing overall time. We utilize a bot called Raccoon that creates a PR based on this exploitation data.

    The scanless exposure insight feature of VulnCheck effectively provides exposure mapping without active scanning, as it maps everything first and only checks for changes, which saves time during CI/CD runs.

    We have utilized the Initial Access Intelligence artifacts to better understand how attackers gain access to our systems, significantly improving our security posture by supporting faster threat hunting.

    We have utilized VulnCheck's machine-readable threat intelligence feeds and API integrations, automating threat responses and eliminating manual analysis, giving us an edge in managing vulnerabilities.

    What needs improvement?

    I'm not completely sure how VulnCheck can be improved, but based on my experience, it does what it says, covering most features reliably. However, I suggest improvements in the reporting dashboard and customization for management understanding.

    For the needed improvements, I would recommend making it simpler, as the current reporting is more catered to engineering, while management should easily access the dashboard. It should be straightforward enough for anyone to check.

    Regarding VulnCheck's AI capabilities, I find that it currently lacks AI-driven capabilities. It mainly utilizes vulnerability checks and could benefit from integrating a small chatbot for better prioritization and summarization of vulnerabilities.

    For how long have I used the solution?

    I have been working in my current field for two and a half years.

    What do I think about the stability of the solution?

    We evaluated other options before choosing VulnCheck, and I can confirm that it is stable. We have not faced any problems.

    What do I think about the scalability of the solution?

    In terms of scalability, I have not experienced any issues. I'm not the primary manager of scalability, but there have been no trouble signs.

    How are customer service and support?

    VulnCheck's customer support is good, and I have no complaints. They have been very helpful.

    Which solution did I use previously and why did I switch?

    We previously used Tenable but switched due to pricing issues. This switch was not something I directly decided.

    What was our ROI?

    We have seen a return on investment, observing a reduction of 20% to 30% in critical and high-risk vulnerabilities due to the automated end-to-end flow, which significantly enhances our efficiency.

    What other advice do I have?

    We have covered everything around VulnCheck's aspects that need discussion.

    I have not utilized the operational exploit artifacts provided by VulnCheck.

    I'm not using the Canary Intelligence feature. The security team manages it, and they may be utilizing it, but I do not have extensive information on that.

    We have observed a measurable reduction in our vulnerability backlog since using VulnCheck, estimating a decrease of 20% to 35% for high-priority vulnerabilities and reducing our mean time to remediation for critical vulnerabilities by around 30%. I would rate this review an 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Prajwal Chougale

    Vulnerability intelligence has transformed risk-based remediation and now drives faster patching

    Reviewed on Jul 15, 2026
    Review from a verified AWS customer

    What is our primary use case?

    VulnCheck serves as our primary vulnerability management platform for managing organizational vulnerabilities. VulnCheck is exceptional because it provides not only CVE listings of exploited vulnerabilities but also known exploited vulnerabilities, referred to as KEV, enabling us to assess ransomware associations and proof-of-concept availability. This allows us to ensure that our EPSS score is reliable and receive notifications for any vulnerabilities that are globally exposed.

    As a vulnerability management tool, VulnCheck scans our on-premise environment and cloud infrastructure, primarily on AWS. It provides comprehensive results of all vulnerabilities present on our endpoints, servers, hosts, or network devices. VulnCheck also provides the initial CVSS score for all vulnerabilities, which is later elevated to EPSS scores based on breaches recorded worldwide, including known exploited vulnerabilities, ransomware associations, proof-of-concept availability, and attacker activity in the environment. We conduct these local and hybrid scans throughout our organization and prioritize the vulnerabilities for remediation.

    We have scheduled scans during our downtimes on Sundays and Saturdays, allowing us to receive comprehensive updates regarding vulnerabilities across our public cloud and on-premises environments. This approach ensures reliable updates and visibility on vulnerabilities, where VulnCheck's scans are quick and efficient, unlike Rapid7, which often fails to accurately scan cloud resources.

    How has it helped my organization?

    VulnCheck has positively impacted our organization. Initially, we had thousands of vulnerabilities on the server side. After introducing VulnCheck, we constantly monitor the vulnerabilities and the EPSS score, which updates based on real threats associated with existing vulnerabilities in the market. This has enabled us to identify, correlate, and find solutions to upgrade our systems, servers, hosts, and network devices, ensuring everything is up-to-date and secure from potential attackers. Therefore, VulnCheck plays a crucial role for us, and the reporting is clear and to the point, making the major vulnerability patching process simple and efficient.

    Before using VulnCheck, our vulnerability count exceeded 4,000, but after three to four months of using it, we are down to just hundreds, which represents the major improvement we have seen on the server level. The endpoints and network devices are managed effectively because we can reboot and patch them as needed.

    What is most valuable?

    The best features VulnCheck offers are the feasible scans it provides and the local and hybrid scans that are very helpful for gathering vulnerability details and prioritizing the exploits or vulnerabilities happening worldwide. Additionally, the comprehensive exploit intelligence, including all the POCs and ransomware associations, stands out. The detailed descriptions of all present vulnerabilities along with emerging threats, well-documented details, and frequent updates of threat intelligence contribute significantly to reducing the remediation workload by prioritizing the vulnerabilities that matter most.

    VulnCheck is an emerging next-generation AI-implemented vulnerability security tool, and its governance and security capabilities are impressive. The AI capabilities enhance the EPSS scores, making them more specific and helpful for prioritizing remediation. VulnCheck is a reliable tool that supports multi-tenancy and multi-cloud environments, with effective scans for both on-premises and cloud assets. It is essentially a one-stop solution for all vulnerability management needs.

    VulnCheck outputs are very consistent, with a level of precision in outputs, and the remediation status for vulnerabilities is immediately actionable as soon as we complete remediation. The stability of daily vulnerability intelligence operations is maintained, with a consistent threat integration feed and API responses delivering smooth updates.

    What needs improvement?

    Regarding improvements needed for VulnCheck, there are not many areas, as the pre-built integrations with common vulnerability scanners and SIMS are seamless. Integration with ITSM ticketing tools is also quite good. However, it would be beneficial to have more customizable dashboards and executive-level reporting, as well as improved visibility into vulnerability remediation.

    I chose a rating of nine for VulnCheck because some parts, such as the implementation aspect and the patch remediation trackers, are lacking. Additionally, VulnCheck could benefit from providing simpler executable dashboards and more conceptual insights, potentially taking references from Rapid7 for the reporting and remediation project areas.

    For how long have I used the solution?

    I have been using VulnCheck for more than 1.5 years.

    What do I think about the stability of the solution?

    VulnCheck is stable, and I have not experienced any issues with uptime or reliability.

    What do I think about the scalability of the solution?

    VulnCheck scales exceptionally in our organization, regardless of size. As an AI-driven and cloud-hosted tool, it integrates efficiently with enterprise vulnerability management workflows and supports a large number of assets and vulnerability records without needing additional infrastructure.

    How are customer service and support?

    We have not engaged with VulnCheck's customer support because we already use multiple vulnerability tools. However, others have reported positive responses and helpful documentation available regarding various reports missing in the tool.

    Which solution did I use previously and why did I switch?

    Before utilizing VulnCheck, we used Rapid7 InsightIDR. Switching to VulnCheck is cost-effective and reliable, using VulnCheck intelligence for risk-based remediation instead of merely prioritizing vulnerabilities by CVSS score. We continuously monitor newly published KEVs and exploit intelligence for timely risk management, highlighting significant improvements in risk-based vulnerability management and efficient remediation processes.

    We previously used Rapid7 due to scanning issues, but after switching to VulnCheck, our operations have improved considerably. Pricing for VulnCheck is more favorable compared to Rapid7.

    What was our ROI?

    Since using VulnCheck, we see a significant return on investment as we no longer spend excessive time on scanning, which was an issue with Rapid7. VulnCheck provides a solid security vulnerability management solution that allows SOC analysts to work more efficiently without wasting time.

    What's my experience with pricing, setup cost, and licensing?

    I do not have visibility on the pricing, setup costs, and licensing for VulnCheck, as only higher management is involved in those decision-making processes.

    Which other solutions did I evaluate?

    We did not evaluate other options before selecting VulnCheck.

    What other advice do I have?

    I have completed everything regarding my main use case and any unique ways I use VulnCheck in my environment. I have added all the points regarding VulnCheck. If you are looking for a one-stop solution for vulnerability management that offers lower costs and superior visibility into vulnerabilities, then VulnCheck is the right choice. We do not use the operational exploit artifacts provided by VulnCheck. My overall rating for VulnCheck is nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Sandip Ade

    Real-time monitoring has improved incident response and maintains reliable network operations

    Reviewed on Jul 12, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for VulnCheck is network monitoring and incident management. I use it to monitor network devices, identify outages and alarms, track incidents, and respond to network issues. It helps me keep an eye on the health of the network, troubleshoot problems effectively, and ensure that services remain available with minimum downtime. As a network engineer in the NOC team, VulnCheck is an important part of my daily workflow.

    What is most valuable?

    The best features of VulnCheck are its real-time monitoring, instant alarms, and centralized dashboard. It makes it easy to identify network issues quickly and monitor the status of devices from one place. I also appreciate how it helps track incidents and provides clear information for troubleshooting. The interface is user-friendly, which makes it easy to navigate even for new users. Overall, VulnCheck helps improve response time, reduces downtime, and supports efficient network operations.

    The real-time alerts and centralized dashboard help our team detect issues quickly, respond faster, and reduce downtime. It also improved communication between teams because everyone has access to the same incident information. Overall, VulnCheck has increased operational efficiency, helped us maintain better network availability, and enabled us to provide more reliable service to our users.

    What needs improvement?

    Overall, I'm very satisfied with VulnCheck, but there is always room for improvement. It would be helpful to have more customizable dashboards and notification options so users can focus on the most relevant alerts. Faster report generation and more detailed analytics would also be useful for troubleshooting and tracking. Even in its current form, VulnCheck is a reliable and effective platform that helps our team monitor the network, respond to incidents quickly, and improve daily operations.

    The current features of VulnCheck already meet most of our daily operational needs, but a few enhancements could make the platform even better. More customizable dashboards and better alert filtering would reduce unnecessary notifications, and more detailed reporting would help improve efficiency. Better integration with other IT and ticketing tools would also streamline workflows. Overall, VulnCheck is already a reliable platform, and these improvements would make it even more valuable for network operations and incident management.

    For how long have I used the solution?

    I have been using VulnCheck for about two months, and I use it regularly to monitor network incidents and support daily operations.

    What do I think about the stability of the solution?

    VulnCheck is exceptionally stable with consistent uptime and zero issues.

    What do I think about the scalability of the solution?

    It is fully integrated as a cloud-based platform across our entire department.

    How are customer service and support?

    Customer support for VulnCheck is highly responsive, knowledgeable, and resolves technical issues very quickly. This is greatly appreciated.

    I want to give customer support for VulnCheck a perfect score because it is knowledgeable, responsive, and very supportive.

    Which solution did I use previously and why did I switch?

    We switched from Tenable to VulnCheck to get better real-time exploit visibility.

    How was the initial setup?

    We purchased VulnCheck directly through our AWS Marketplace account to streamline procurement and billing.

    What about the implementation team?

    We are an official technology integration partner with VulnCheck and help co-develop custom security plugins.

    What was our ROI?

    We have seen an immediate ROI with VulnCheck, cutting our weekly threat triage time by around 40%.

    What's my experience with pricing, setup cost, and licensing?

    The pricing model for VulnCheck is fair, transparent, and accurate.

    Which other solutions did I evaluate?

    We thoroughly evaluated alternative vulnerability and risk management vendors before choosing VulnCheck.

    What other advice do I have?

    Take full advantage of the trial period to test how easily VulnCheck's automated API-first integrations integrate with your existing security and IT stack.

    The AI output of VulnCheck is highly accurate and delivers precise, trustworthy results every time I've used it.

    It is very easy to understand the exploitation data provided by VulnCheck's first-party exploitation intelligence because the threat data is presented in a clear, actionable dashboard without unnecessary complexity.

    The early exploit visibility of VulnCheck is highly impressive and lets us patch vulnerabilities before they are actively exploited.

    We use the operational exploit artifacts provided by VulnCheck to perform proactive threat hunting across our network indicators.

    It is highly effective, mapping our external attack surface accurately without the network overhead of active scans.

    We use the IAI artifacts from VulnCheck.

    The enhanced machine-readable delivery and integrations of VulnCheck let us ingest threat data directly into our SOAR playbook automatically.

    Security protocols for VulnCheck seem highly robust, and the AI features operate safely without any privacy or data leak complaints.

    I give this review a perfect rating of 10 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Salbu Kumar

    Prioritization has transformed how we focus on actively exploited vulnerabilities and real risk

    Reviewed on Apr 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for VulnCheck is vulnerability intelligence and prioritization, especially to identify which vulnerabilities are actively exploited.

    What is most valuable?

    The best features VulnCheck offers are exploit intelligence and KEV-style tracking, real-time vulnerability enrichment, API integration with existing tools, and clear prioritization based on risk.

    VulnCheck's real-time vulnerability enrichment and API integration have significantly helped my workflow. This provides a practical vulnerability management experience rather than textbook answers. From my experience with VulnCheck, this is one of the most valuable features. We often see hundreds of CVEs from scans, but not all are actually dangerous. VulnCheck helps us identify which vulnerabilities are being actively exploited or are listed as similar to known exploited vulnerabilities. Instead of patching everything blindly, we focus first on vulnerabilities that attackers are actively using, which makes our response much more practical.

    When a new CVE comes in, VulnCheck adds details including exploit availability, attack complexity, and real-world usage. Instead of just seeing the CVSS score, we understand the actual risk, which helps in better decision-making. We integrated VulnCheck with our vulnerability scanning and SIEM tools, and when vulnerabilities are detected, the API enriches them automatically with threat intelligence. This reduces manual effort and speeds up prioritization. The clear prioritization based on risk is probably the biggest day-to-day benefit. Instead of handling hundreds of vulnerabilities equally, we focus on actively exploited ones, internet-facing assets, and critical systems, which helps us reduce the noise and focus on what really matters.

    The most important features—exploit intelligence and prioritization—have the biggest impact on real life. In our organization, the biggest impact is that exploit intelligence and knowing whether a vulnerability is actively being exploited changes how we spend our resources. It helps reduce the noise from vulnerability scans by focusing on what really matters.

    What needs improvement?

    VulnCheck's UI and reporting can be improved for better visibility. More customization in dashboards and reporting would be helpful for management-level insights.

    For how long have I used the solution?

    I have been using VulnCheck for around one year.

    What do I think about the stability of the solution?

    VulnCheck is stable.

    What do I think about the scalability of the solution?

    VulnCheck scales well since it is API-driven.

    How are customer service and support?

    Support for VulnCheck is very responsive, active, and helpful.

    Which solution did I use previously and why did I switch?

    We relied on a basic vulnerability scanner and public CVE databases previously.

    What was our ROI?

    We have seen ROI mainly through better prioritization and reduced effort on low-impact vulnerabilities.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is reasonable for the value VulnCheck provides, especially for threat intelligence. We evaluated the differentiation and licensing options.

    Which other solutions did I evaluate?

    We looked at other threat intelligence sources and platforms.

    What other advice do I have?

    Do not rely only on CVSS scores; instead, use tools such as VulnCheck to understand real-world risk. In today's environment, prioritization is key, and VulnCheck helps focus on vulnerabilities that actually matter. I would rate this review an 8.

    Jaswanth Kotla

    Early exploit insights have accelerated remediation and support rapid risk-based decisions

    Reviewed on Apr 24, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I primarily use VulnCheck for newly discovered vulnerabilities and the remediation time period for those vulnerabilities, with the team reviewing the severities.

    Using VulnCheck with real-world threat data, it has a capability where it updates 14 days before the NVD National Vulnerability Database has updated.

    That is my main use case for VulnCheck.

    What is most valuable?

    I find that VulnCheck's best features include using CVSS, mapping it to the MITRE ATT&CK framework, and tagging indicators of compromise.

    The features of mapping CVSS to the MITRE ATT&CK framework and tagging indicators of compromise help my team assess risks based on the severity: high, medium, low, and common.

    The unique feature of VulnCheck is the 14-day advance notice, as it provides data on exploits with exploits, which is a very quick update compared to the NVD and open CVEs.

    VulnCheck positively impacts my organization by enabling risk-based reduction, identifying actively exploited vulnerabilities, and providing valuable insights.

    When I mention service-based reduction and identifying active risks, I notice faster remediation times and that we are compliant as per the SOC 2 Type 2 terms, which is the best threat intel so far.

    What needs improvement?

    I wish VulnCheck could improve by having a scoring system that is domain-based, IP-based, and reputation-based, along with an internal capability for checking internal inventory vulnerabilities.

    My main addition about needed improvements is that if VulnCheck works on the inventory of the software my organization uses, it would be really helpful.

    For how long have I used the solution?

    I have been using VulnCheck for over a year.

    What do I think about the stability of the solution?

    VulnCheck is stable.

    What do I think about the scalability of the solution?

    VulnCheck demonstrates good scalability.

    How are customer service and support?

    I find that customer support is good, and I'm impressed.

    Which solution did I use previously and why did I switch?

    Previously, I used a security scorecard, a domain rating level scorecard that provides a security rating, but it didn't have as many capabilities, so I switched to VulnCheck.

    What's my experience with pricing, setup cost, and licensing?

    Currently, I find the pricing of VulnCheck to be reasonable and not much expensive.

    Which other solutions did I evaluate?

    Before choosing VulnCheck, I compared it with Security Scorecard, and that was the extent of my evaluation.

    What other advice do I have?

    As a security engineer, I find it very easy and manageable to understand the exploitation data provided by VulnCheck's first-party exploitation intelligence.

    With VulnCheck's early exploit visibility, I can remediate vulnerabilities quickly, making timely decisions before the vulnerabilities are known to the public and hackers.

    I utilize operational exploit artifacts provided by VulnCheck, which help me prioritize them sooner based on severities and check the exploit status in terms of how deep the exploit can penetrate.

    VulnCheck's scanless exposure insight feature is useful whenever scanning is not permitted, allowing me to perform vulnerability checks.

    I have utilized the Initial Access Intelligence (IAI) artifacts, which add value to my security measures through data validation, active checks, and access control, ensuring only authorized users can access.

    It is about the remediation of vulnerabilities to make it faster and to make sooner decisions based on the exploit status, which is the main factor.

    I advise others looking into using VulnCheck to ensure it is useful for their specific needs and to check if the scope matches what VulnCheck offers.

    I would rate this product a 9 out of 10.

    View all reviews