Black Duck Application Security Testing (AST) for AWS logo

    Black Duck Application Security Testing (AST) for AWS

    Application security tools and services that integrate security testing into DevOps workflows. Available via Private Offer.

    Ratings and reviews

    4.2
    103 ratings
    0 AWS reviews
    |
    103 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (103)
    Sonal K.

    Accurate Vulnerability Insights and Remediation—A Must-Have SCA Platform

    Reviewed on Jul 20, 2026
    Review provided by G2
    What do you like best about the product?
    Black Duck is the world leader for its SCA platform. The platform gives accurate vulnerabilities, line-to-line, along with correct remediations to fix the code. Must to have in your organisation.
    What do you dislike about the product?
    Nothing so far. Everything is good as per any organisation requirements.
    What problems is the product solving and how is that benefiting you?
    It solves Software Composition Analysis vulnerabilities like any deprecated libraries or packages used in your organisation and to replace them with the updated ones.
    Computer Software

    Excellent Visibility into Open-Source Vulnerabilities

    Reviewed on Jun 28, 2026
    Review provided by G2
    What do you like best about the product?
    Black Duck provides excellent visibility into open-source vulnerabilities. It makes it very easy to track our dependencies and confirm we aren’t shipping code that contains known security flaws.
    What do you dislike about the product?
    At times, the scans return a high number of false positives, which creates extra manual work for our team to review and dismiss them.
    What problems is the product solving and how is that benefiting you?
    Black Duck helps us address the problem of hidden vulnerabilities in our open-source dependencies. The biggest benefit is that it significantly reduces our security risk by enabling developers to spot and remediate issues well before they make it into production.
    Md Sarfaraz H.

    Reliable Open Source Security Tool with Strong CI/CD Integration

    Reviewed on Jun 25, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Black Duck SCA makes it easy to identify vulnerable open-source dependencies and keeps track of newly discovered security issues. The reports are clear, and the CI/CD integration fits well into the development workflow. It also helps with license compliance, which is a big plus. The AI-powered insights are useful for understanding and prioritizing risks. The only downside is the pricing—it can be expensive, especially for smaller teams, but the features and visibility it provides make it worthwhile for larger organizations.
    What do you dislike about the product?
    One thing I don't like is the pricing—it can be quite expensive, especially for smaller teams. The initial setup and configuration also take some time, and the interface can feel a bit overwhelming for new users. Occasionally, there are false positives that need manual review, and I'd like to see faster scans and more intuitive reporting and dashboards. Overall, it's a solid tool, but there's definitely room to improve usability and cost.
    What problems is the product solving and how is that benefiting you?
    Black Duck SCA helps us identify security vulnerabilities and license compliance issues in open-source dependencies before they become bigger problems. It gives us visibility into the components used across our applications and alerts us when new vulnerabilities are discovered. This helps our team fix issues earlier in the development cycle, reduces security risks, supports compliance requirements, and saves time during security reviews and audits.
    VIVEK S.

    Powerful Open-Source Risk Management, Needs Easier Setup

    Reviewed on May 18, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate how Black Duck reduces audit stress with its automated compliance reporting. It strengthens DevSecOps workflows by embedding open-source risk management directly into the CI/CD process. I find the detailed dashboards for audits very useful, and I like the customizable rules for governance offered by the policy control features.
    What do you dislike about the product?
    The UI sometimes feels dated and requires expertise to configure effectively. Additionally, the setup is heavy and tough, with a need to make it lighter and reduce the installation process.
    What problems is the product solving and how is that benefiting you?
    Black Duck helps manage open-source risks by detecting vulnerabilities and ensuring license compliance. It automates compliance reporting, reducing audit stress, and strengthens DevSecOps workflows by integrating risk management into CI/CD pipelines.
    Renato Z.

    High-Performing and Effective, with Appreciated Automatic Alerts

    Reviewed on Apr 07, 2026
    Review provided by G2
    What do you like best about the product?
    Perfoming and effective. Automatic alerts are really appreciated and
    What do you dislike about the product?
    Prices are not affordable and UX interface not so easy. Sometimes scanning are a little slow
    What problems is the product solving and how is that benefiting you?
    Black Duck helped us to understand where our code was not performing well. We improved visibility and we were able to keep under control security and legal risks
    Harshitha Y.

    Perfect for Managing Daily Tasks Efficiently

    Reviewed on Dec 09, 2025
    Review provided by G2
    What do you like best about the product?
    I like for handling my day to day tasks and it is very handy
    What do you dislike about the product?
    nothing . i like synopsys e leraning but it is huge to follow tutorials
    What problems is the product solving and how is that benefiting you?
    I am handling my tasks efficiently
    Lokesh T.

    Powerful SCA Tool with Extensive Knowledge, but Resource-Heavy On-Prem Deployment

    Reviewed on Oct 17, 2025
    Review provided by G2
    What do you like best about the product?
    I found it as a best SCA tool, where its engine is very powerful in identifying Open source issues, And the main thing is that its Black Duck Knowledge is very huge
    What do you dislike about the product?
    The only drawback is it require huge resource to deploy in on-prem
    What problems is the product solving and how is that benefiting you?
    It solves addressing Open Source Issues basically its a Software composition Analysis tool.
    Ambrish M.

    A decent security software for any organization which is lightweight and useful also.

    Reviewed on Nov 17, 2024
    Review provided by G2
    What do you like best about the product?
    Sentinel requires minimum RAM and processor to operate on a system that makes it easy to deploy amongst a large number of users. It is small in size that makes it easy to implement and use in multiple types of devices such as servers, endpoint devices etc. The support is also available with a handsome amount of SLA for the users. Since it is used in many organizations, I believe this software is used very often by many companies all over the world.
    What do you dislike about the product?
    Sentinel is connected via cloud and uses on-cloud services to deploy security policies that makes it a little bit slow to deploy security policies to users.
    What problems is the product solving and how is that benefiting you?
    It is implemented to enhance security and provide a layer of data protection in any organization, which it is fulfilling its main purpose of use and it is cost-effective too as compared to other competitors in the market such as Trend Micro Apex One, Sophos Intercept X, Kaspersky etc.
    Muhammad M.

    Sentinel has significantly made it easy for identifying threat and response process

    Reviewed on Oct 27, 2024
    Review provided by G2
    What do you like best about the product?
    The ability to provide real-time insights into the entire network's security threats and the ease of integration with other services makes it a Swiss army knife, and the scalability accommodates large volumes of data without affecting performance. It also enables us to customize alerts and dashboards according to our needs, which I've personally found very effective.
    What do you dislike about the product?
    Sentinel is not a beginner-friendly tool as it requires proper training and the interface isn't very intuitive, making it harder to navigate. Additionally, costs can escalate quickly with large volumes of data, which may be a concern for organizations with a tight budget.
    What problems is the product solving and how is that benefiting you?
    Sentinel is solving the challenge of managing and analyzing vast amounts of security data by providing a centralized, cloud-based SIEM solution. This benefits me as a cybersecurity professional by automating threat detection and response, reducing manual workloads, and allowing me to focus on strategic initiatives.
    Keerthi Kumar S.

    One of the best threat protections on devices

    Reviewed on Sep 25, 2024
    Review provided by G2
    What do you like best about the product?
    Sentinel one runs smoothly on the background without causing any hindrance to work.
    What do you dislike about the product?
    There is nothing much to dislike about sentinel one
    What problems is the product solving and how is that benefiting you?
    Sentinel one helps in identifying any threats from external or internal applications that might affect the device security which is helpful in avoiding risks.