Automated pentesting has transformed our demos and now delivers rapid, actionable remediation
What is our primary use case?
My main use case for The NodeZero Platform by Horizon3.ai is to demo the platform to our channel partners and any end-user customers that they bring us, and also for my own benefit, as we look at our own pentests that we do on the business, both weekly and monthly, and speak to our technical SE Manager to discuss the weaknesses, vulnerabilities, and remediations that Horizon provides with the tasks.
When we conducted this for a customer within a POV, a proof of value, The NodeZero Platform by Horizon3.ai managed to run a pentest very quickly, rather than them doing a manual test that takes weeks to get the reports which are at a point in time. What we found was a weakness within the infrastructure, but it also provided step-by-step remediation instructions and showed how to address the issues, verifying remediation with one-click verification.
One thing I would add about The NodeZero Platform by Horizon3.ai features is how easy it is to follow on the platform at your fingertips, making it accessible and uncomplicated, even for non-technical users such as myself who can run a pentest on the infrastructure.
How has it helped my organization?
The NodeZero Platform by Horizon3.ai's impact on our organization's remediation time is impressive because it allows for swift identification and verification of fixes while prioritizing exploitables that provide business impact rather than getting lost in long lists of vulnerabilities.
What is most valuable?
The best features The NodeZero Platform by Horizon3.ai offers include ease of use and running a pentest, which can be done within four to six clicks of your mouse, and not only finding exploitables within your infrastructure but also the ease of remediation and the fix actions that are provided.
The main thing that I have always spoken about with customers, when our partners have brought the opportunity, is how long and drawn-out the process is with a manual pentester, as after days of work and high consultative fees, they have to wait weeks for a massive report. The NodeZero Platform by Horizon3.ai finds issues on the day, providing step-by-step remediation fix actions that are really easy to follow with various options for addressing the issues.
The NodeZero Platform by Horizon3.ai impacts our organization positively as we are a cybersecurity distributor that presents solutions to our partners, and I would have to say it is hands down one of the best solutions we sell to help address customer pain points related to manual testing, generating excitement in the channel, closing deals, and fostering discussions around pentesting.
Showing the attack paths with The NodeZero Platform by Horizon3.ai is crucial, as every exploitable that arises has a defined path leading to a business impact; this emphasizes the importance of tracking vulnerabilities due to their implications.
What needs improvement?
Improvements with The NodeZero Platform by Horizon3.ai are already underway; many people mention infrastructure testing is well-handled, but they seek better web application testing, which is currently in beta, as noted by their CEO, Snehal, and once it comes to market, we will demo it for our partners.
Regarding the needed improvements, I think their Tripwire, Insights, and Rapid Response add-ons are good, but web application testing is what is predominantly requested, which we know is coming soon.
For how long have I used the solution?
I have been working with The NodeZero Platform by Horizon3.ai since approximately May of last year, which represents just under a year from a full sales, technical point of view, end-user, and partners within our channel community.
What do I think about the stability of the solution?
The stability of The NodeZero Platform by Horizon3.ai is complete, with consistent performance noted.
What do I think about the scalability of the solution?
The scalability of The NodeZero Platform by Horizon3.ai is another massive positive; unlike competitors such as PenTera, which are on-premise and limit to 6,000 assets, The NodeZero Platform by Horizon3.ai demonstrates remarkable scalability and efficiency in running pentests across numerous assets.
How are customer service and support?
The customer support from the customer success team, channel team, and SE team has been notably good, assisting our partners and customers with POVs, enablements, and setting up the POV or tenant when interested in purchasing The NodeZero Platform by Horizon3.ai.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
A very measurable statistic regarding The NodeZero Platform by Horizon3.ai would be with one of our partners, who we met with at InfoSec in London; we booked a session with over 100 account managers, and after a sales enablement session with the Horizon team, they went out and secured 25 to 30 deal registrations that month, leading to potential revenue opportunities.
What's my experience with pricing, setup cost, and licensing?
Since we are a distributor setting pricing with Horizon for our partners, we know that customers find the pricing favorable, as it is cheaper than conducting a single manual pentest a year while allowing for multiple tests.
Which other solutions did I evaluate?
I did not evaluate other options before choosing The NodeZero Platform by Horizon3.ai.
What other advice do I have?
The way you find a vulnerability with The NodeZero Platform by Horizon3.ai, you can also fix and then verify if that vulnerability has been solved, which is the selling point itself, emphasizing exploitability as a massive factor since only 2% of vulnerabilities are actually exploitable.
My impression of The NodeZero Platform by Horizon3.ai's feature that allows security teams to fix and retest vulnerabilities instantly is that it alleviates concerns of lengthy lists of vulnerability scanners by focusing on exploitables, allowing teams to manage their time efficiently by addressing the most impactful issues.
More and more we are recognizing that all endpoint detection and response tools, such as Defender for Endpoint, CrowdStrike, and SentinelOne, have their weaknesses, and The NodeZero Platform by Horizon3.ai's EDR effectiveness demonstration highlights how we combat attackers, enhancing overall security.
I would advise others considering using The NodeZero Platform by Horizon3.ai to buy the product and utilize it as much as possible, as it is an excellent solution for reducing time, staff, costs, and identifying impactful vulnerabilities.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Intuitive Yet Powerful—A Critical Part of Our Cybersecurity Toolbox
What do you like best about the product?
It is both intuitive and thorough with easy integration and implementation. During product review, NodeZero became an obvious choice because interaction was simple enough for our nontechnical personnel to follow yet the platform capabilities matched those of skilled professionals. The company has VERY responsive customer service and keeps up with the most recently discovered vulnerabilities and offers rapid release of testing against them. This has become a highly used and critical part of our cybersecurity toolbox.
What do you dislike about the product?
The only issue is something I just discovered and have not brought to their product team yet. Tripwires doesn't report the specific machines it failed on and succeeded on in an obvious manner.
What problems is the product solving and how is that benefiting you?
The NodeZero platform continuously uncovers our unknown unknowns. If an organization does not know they have a vulnerability, they cannot patch it. NodeZero solves this problem of the unknown unknowns.
Essential for Compliance and Flexibility
What do you like best about the product?
I really like the service and attention that NodeZero from Horizon3.ai offers. The platform's CMMC aligned guidance is great, providing us with the necessary support to comply under CMMC and covering those pentest controls. I appreciate the flexibility to run focused or ad hoc tests, which is invaluable for us. The expertise of the team is unmatched, and I couldn't have chosen a better company. You all are great, and Will is particularly excellent. The initial setup was very easy too.
What do you dislike about the product?
N/A
What problems is the product solving and how is that benefiting you?
NodeZero from Horizon3.ai identifies vulnerabilities, provides solutions, and ensures compliance. It aligns with CMMC, covering pentest controls expertly. Its flexibility for focused or ad hoc tests and exceptional service make it invaluable.
Has improved internal and co-op security validation through detailed reporting and continuous vulnerability detection
What is our primary use case?
The NodeZero Platform is used internally every month, aligned with the patch cycle, to run the pen test and validate the patching that was done previously and find anything new in the environment. It is run at least monthly, and if something else comes up, it is run between those times. Additionally,
The NodeZero Platform is used to perform pen testing for co-ops. Since some internet infrastructure is shared with co-ops, the platform can be deployed and a virtual machine can be spun up in their environment. They provide IP ranges, the pen test is deployed, the report comes back, and it is shared with them. This has been a great capability to provide to co-ops.
What is most valuable?
My favorite feature of The NodeZero Platform is that all of it has been really good. The reporting piece is very clear and very useful, which was a big piece from the start. The reporting is huge, and the fact that it learns the environment on an ongoing basis is impressive. An external third-party pen tester is brought in every two years, and the plan is to move it to every three years. After the third party conducts the pen test, The NodeZero Platform is run, and it finds the same things they found and sometimes a few other things that they did not even identify. It has stood up against that test every time.
The feature that allows security teams to fix and retest vulnerabilities instantly adds a lot of quick mitigation and the ability to fix issues on the fly. Everything that has been added and modified and improved since acquiring the tool has worked seamlessly.
The Real Attack Capabilities help in identifying vulnerabilities in on-premises systems because if patching was missed, it will identify that. With deployment across the system, any recent vulnerability will be found. The way it learns the environment makes it an easy-to-use tool. It does what it says it is going to do, which is finding vulnerabilities as they appear.
The Endpoint Security Effectiveness feature helps in understanding potential security threats better because everything that it identifies improves things on an ongoing basis. It ensures that everything is kept current, so it adds an extra layer to what is being done with the main EDR solution.
What needs improvement?
The speed of the scans takes some time, but in my opinion, it is not surprising for what it is doing. It could be a little quicker, but speed does not necessarily mean it is going to be better, since speed does not equate to doing what it needs to do.
For how long have I used the solution?
The NodeZero Platform has been used for about close to four years.
What do I think about the stability of the solution?
Regarding stability, it has never crashed, and there has not been any lagging from deployment or running. It is sometimes run randomly to see if managed service personnel will get alerted, and it has performed as expected. There has not been anything with lag or alerts, it has not crashed, and it has not caused issues.
What do I think about the scalability of the solution?
The scalability of The NodeZero Platform has been great because it is offered out to the 26 co-ops that are worked with, and over half of those have had it run on their environment, and it has worked out great.
How are customer service and support?
Technical support has never been contacted because there have never been any issues that required reaching out to them.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
There have not been any alternatives encountered that can be compared with The NodeZero Platform. After conversations with people and they have looked at it, nothing has stood out as being worth even trying to test. There is nothing that compares to it from everything that has been seen.
How was the initial setup?
The initial deployment of The NodeZero Platform was easy, from what is remembered, as that was about four years ago.
What about the implementation team?
The networking team was involved in this type of job, and it was probably just one of the networking team members and a senior engineer.
What was our ROI?
A reduction in remediation time has been seen because it is finding things before they happen. Much time is not being spent on remediation since acquiring it because it is finding things before they become an issue. Even if there is a zero-day and patching is done and then run, it verifies that, so it is preventing a lot of remediation time with anything.
What's my experience with pricing, setup cost, and licensing?
The pricing has been good, as it has not made huge leaps. Contracts and renewals are handled, so the changes have not been astronomical. It has stayed typically below what was expected for the changes as contracts are renewed, so it has all been fine.
What other advice do I have?
The overall rating given to The NodeZero Platform is ten out of ten.
Has provided deep visibility into offensive tooling and improved trust through transparent command execution
What is our primary use case?
My use cases for The NodeZero Platform involve using the tool as a validation tool on top of existing vulnerability management processes. The general idea is that if I identify a subset of vulnerabilities that might be of interest to an attacker, I use The NodeZero Platform to validate my assumptions. Essentially, I'm using it as a red team validation tool to test and validate blue team findings.
What is most valuable?
The NodeZero Platform's real attack capabilities help identify vulnerabilities on my on-premise systems by adding an element of validation and offensive security testing on top of known vulnerabilities. That's the main use case and the consistent configuration purpose.
The feature that allows security teams to fix and retest vulnerabilities instantly is very useful, even though it may not happen literally 'instantly.' It's a necessary tool for any organization to understand whether vulnerabilities are genuinely exploitable by attackers. With its near-real-time testing capabilities, it's an essential part of any security portfolio.
The Endpoint Security Effectiveness feature impacts my understanding of potential security threats by providing validation through endpoint testing. The NodeZero Platform deploys a script to verify whether endpoint protection tools such as EDR or EPP can detect and prevent attacks. This validation ensures that endpoint protection is configured correctly, revealing that default settings often don't work as expected. This makes the feature unique, as no other vendor seems to offer such validation capabilities.
What needs improvement?
The areas for improvement for The NodeZero Platform involve integration and automation. It would be beneficial if it could integrate directly with vulnerability management tools such as Rapid7, Tenable, or Qualys. Such integration would allow the platform to automatically import data, identify vulnerable systems, and test targets immediately, potentially even enabling automated feedback loops for rescanning. Currently, this process is manual. Native API-based integration would make the workflow far more efficient.
For how long have I used the solution?
I have been using The NodeZero Platform in my career for about two and a half years, and I think it's coming up on the third year.
What do I think about the stability of the solution?
My thoughts about the stability of The NodeZero Platform are that it's not an issue in production. During initial testing in a VirtualBox virtual machine, it was less stable due to insufficient resources. The system requires fast SSD storage, at least 16 GB of RAM, and a 1G network interface. Once properly provisioned, it runs stably without issues.
What do I think about the scalability of the solution?
The scalability of The NodeZero Platform is limited by our license to 1,000 IPs, so my experience beyond that is limited. However, we successfully tested multiple NodeZero scanners running concurrently without any concerns. The system scales well within the licensed range.
How are customer service and support?
I have contacted The NodeZero Platform's technical support once in two and a half years. The issue was related to the reporting process getting stuck during telemetry capture and report generation. The support team resolved it quickly by restarting the process. I rate the support experience as 10 out of 10.
How would you rate customer service and support?
How was the initial setup?
The initial deployment of The NodeZero Platform has two components: external and internal. For the external scanner, which uses AWS hosting, setup takes just minutes once the cloud space is provisioned. The tool performs domain and IP validation (whois, DNS lookup, etc.) before allowing scans, which can take up to 24 hours.
For internal deployment, it depends on corporate practices. Our process took about two weeks due to our sprint cycle and change management procedures. For larger or more complex network environments, deployment may take longer. Ideally, a NodeZero scanner should be positioned in each segmented subnet for full coverage.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing for The NodeZero Platform, I can say it's reasonable and the vendor is flexible. When discussing licensing, they were initially limited to 10,000 IPs, but agreed to let us target 1,000 IPs instead. That flexibility allowed us to use the tool effectively despite a smaller license count. While managing subsets of IPs introduces some overhead, the flexibility and support make the pricing worthwhile.
What other advice do I have?
The NodeZero Platform requires minimal maintenance. The NodeZero scanner is a small Linux wrapper with scripts that need occasional package updates. Although it auto-updates before scans, it's safer to manually update dependencies beforehand to prevent issues during testing.
Overall, I think The NodeZero Platform is a necessity in any security portfolio. With 15 years in the industry, I see it as an essential tool for organizations of any size to determine whether vulnerabilities are truly exploitable. The product works well, is stable, and provides unique validation capabilities. I would rate it a 10 out of 10 for everything.
I am a customer of The NodeZero Platform.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)