StackHawk
StackHawk, Inc.External reviews
68 reviews
from
External reviews are not included in the AWS star rating for the product.
A good DAST Tool, easy to integrate in your CI pipeline
What do you like best about the product?
- A good knowledgeable and strong support and account team.
- Easy to integrate with the existing CI pipeline.
- Did a good job of reducing our vulnerabilities.
- A great UI to review.
- Easy to integrate with the existing CI pipeline.
- Did a good job of reducing our vulnerabilities.
- A great UI to review.
What do you dislike about the product?
- Needs better notification and improvements to the notifications.
- Alternate alerting system.
- Needs more product lines to make this a single use tool.
- Alternate alerting system.
- Needs more product lines to make this a single use tool.
What problems is the product solving and how is that benefiting you?
- Stackhawk has greatly reduced our vulnerabilities and keeps our code in check by integrating with the CI pipeline.
- The developers are always alerted for any new vulnerabilities introduced.
- The developers are always alerted for any new vulnerabilities introduced.
StackHawk proves to be an interesting tool in secure development pipelines
What do you like best about the product?
I like the ease of onboarding new applications. It is easy and practical, facilitating the user experience of security in the application development cycle. Additionally, the application utilizes native API development configurations through OpenAPI files.
What do you dislike about the product?
It still seems too simplistic for the level expected in corporate environments. There is a lack of a way to manage multiple projects, but I believe it will be implemented in future releases.
What problems is the product solving and how is that benefiting you?
I am implementing DAST analysis using the free tier, and this allows me to make my open-source environment more secure. The main feature is the automation of security tests directly in the CI/CD pipeline.
Solid CICD integration with a bright future
What do you like best about the product?
Slick CICD integration for a known scanning tool
What do you dislike about the product?
The core scanner is zap, without additional checks or enhancements.
What problems is the product solving and how is that benefiting you?
Automating our CICD pipeline for DAST with decent jira integration
StackHawk is a strong DAST product for companies that care about their application security programs
What do you like best about the product?
-Very strong CI/CD integration
-Augmented security detections to ZAP
-A slick, fast UI
-Supportive staff when we have questions
-Augmented security detections to ZAP
-A slick, fast UI
-Supportive staff when we have questions
What do you dislike about the product?
-Needs more augmented detection to discover real risks
-Needs ability for custom detections/plugins
-More customization on findings and options for suppression
-Faster scans!
-Needs ability for custom detections/plugins
-More customization on findings and options for suppression
-Faster scans!
What problems is the product solving and how is that benefiting you?
-Finding "real" problems through run-time scans
-CI/CD integration for low/no touch scans for developers
-CI/CD integration for low/no touch scans for developers
My encounter with StackHawk
What do you like best about the product?
The integration with my application was seamless. I just had to deploy a docker and run it, and the stat scanner reported the vulnerabilities almost instantly.
What do you dislike about the product?
StackHawk can improve the description of the vulnerabilities slightly to debug the issue faster. Stackhawk can give more examples for fixing security issues reported.
What problems is the product solving and how is that benefiting you?
I am trying to find security flaws in my application using StackHawk so that when I go into deployment, I don't get hacked. StackHawk benefitted me immensely by making the process seamless.
Recommendations to others considering the product:
Go ahead and use this product to get your applications tested for security vulnerabilities. Using StackHawk saves a lot of time and effort.
Excellent vulnerability scanner tool for REST APIs
What do you like best about the product?
The tool is straightforward to use and scan the APIs for vulnerabilities very quickly. Provides a docker image which could be directly used
What do you dislike about the product?
Sometimes, all the endpoints from the swagger spec is not recognized
What problems is the product solving and how is that benefiting you?
The main benefit is to scan the application for vulnerabilities quickly and helps in taking quick resolutions
Recommendations to others considering the product:
It is an excellent tool to scan your application for security vulnerabilities.
Great Dast for Modern Applications
What do you like best about the product?
The Stackhawk dashboard is intuitive and functional. I also really appreciate the low level of false positives as well.
What do you dislike about the product?
It would be helpful if there were a way to automatically scan APIs without swagger documentation.
What problems is the product solving and how is that benefiting you?
Stackhawk is allowing us to shift left security vulnerability patching. We can scan at commit time and allow developers to fix bugs before they are checked into version control.
Fast and effective DAST tool
What do you like best about the product?
StackHawk is an excellent tool built to find vulnerabilities developers typically miss and do not foresee when building applications. The support for both SOAP and REST APIs make it versatile to use for a variety of applications. The scan times are quick and resources are easily customizable in the Docker container. The ability to test against certain technologies using flags is a great plus to speed up scan times as well. The support team's quick turnaround times to resolve troubleshooting problems is a great asset to have when onboarding applications.
What do you dislike about the product?
Only supports running in a Docker container, would love to see a .jar extension to attach to applications for faster onboarding when containers are not readily available for use
What problems is the product solving and how is that benefiting you?
This is the first DAST tool we have adopted and have begun implementing this into our CI/CD workflows. Ultimately we aim to identify all vulnerabilities wherever possible to ensure our ecosystem is safe and secure, and StackHawk is providing great value to our goal. The quick scan times provide an easier integration with the remaining components of our pipelines, and the ability to scan SOAP apps is a must until we're able to retire our legacy apps or convert them to REST APIs. Developers are also able to scan applications from their local workstations to capture vulnerabilities early on and wherever else StackHawk is not yet integrated into our CI/CD pipeline for a particular application.
Very good on boarding process
What do you like best about the product?
The onboarding process to get the tests running is very helpful. The StackHawk employees take the time if you have questions, and they are very willing to help.
I like the technology of the test tool.
I like the technology of the test tool.
What do you dislike about the product?
I got some problems with our corporate firewall/proxy. It's not easy to get this running. But even thought StackHawk helped to look into the isuues.
What problems is the product solving and how is that benefiting you?
To find security issues in our apps. Without any big changes in our apps StackHawk is scanning the apps.
Recommendations to others considering the product:
Ask questions if you have any problems setting up StackHawk.
Great Product with even better support.
What do you like best about the product?
StackHawk has a nice, clean, no-nonsense interface that gets to the point, and gets out of the way. It integrates nicely with our workflow and the customer support and success teams have been great to help us get our product to a better state.
What do you dislike about the product?
There is a bit of manual setup required that seems a little non-trivial, but given how modern applications are built I can't see a better way this could be done!
What problems is the product solving and how is that benefiting you?
StackHawk helps us catch security vulnerabilities in an automated fashion as soon as they appear.
showing 21 - 30