CoreOS Clair vs Qualys VMDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Container Security
6th
Average Rating
8.6
Number of Reviews
82
Ranking in other categories
Vulnerability Management (5th), Cloud and Data Center Security (7th), Cloud Workload Protection Platforms (CWPP) (6th), Cloud Security Posture Management (CSPM) (5th), Cloud-Native Application Protection Platforms (CNAPP) (5th), Compliance Management (4th)
CoreOS Clair
Ranking in Container Security
26th
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Qualys VMDR
Ranking in Container Security
11th
Average Rating
8.2
Number of Reviews
77
Ranking in other categories
IT Asset Management (7th), Configuration Management Databases (3rd), Risk-Based Vulnerability Management (3rd)
 

Market share comparison

As of June 2024, in the Container Security category, the market share of SentinelOne Singularity Cloud Security is 2.7% and it increased by 60.7% compared to the previous year. The market share of CoreOS Clair is 0.6% and it decreased by 19.1% compared to the previous year. The market share of Qualys VMDR is 4.9% and it increased by 4.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Container Security
Unique Categories:
Vulnerability Management
1.8%
No other categories found
IT Asset Management
4.0%
Configuration Management Databases
1.9%
 

Featured Reviews

SA
May 31, 2024
Gives us better visibility into our resources and enables faster resolution
The detection time could be better. It takes a long time to scan. I'm not sure how long other tools take for the same amount of scanning, so I cannot compare it with other tools, but it takes us half a day to a full day to complete the scan. I want to get the reports faster so we can start fixing the problems. The proof of exploitability is another area for improvement. While I have all the information to troubleshoot the problem, it isn't detailed enough for an administrator. It has sufficient information for a general user, but an administrator would like to know all the ins and outs of the vulnerabilities that have been reported. I would like to see the map feature improve. It's good, but it isn't fully developed. It lets us use custom resources and policies but does not allow us to perform some actions. I would also like more custom integration and runtime security for Kubernetes.
HB
Jul 6, 2022
Excellent detection accuracy
I use CoreOS Clair to detect OS components in images and containers CoreOS Clair's best feature is detection accuracy. An area for improvement is that CoreOS Clair doesn't provide information about the location of vulnerabilities it detects. They should disclose these details immediately in a…
PranjalGargava - PeerSpot reviewer
May 5, 2023
Helps with vulnerability scanning and understanding of cyber security controls
We use the solution for vulnerability and policy scan.  The product has helped us understand cybersecurity controls.  I am impressed with the VMDR feature.  The tool needs to improve the adding assets and report generation features. I would like to see the policy scan of offline appliances in…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's helped free up staff time so that they can work on other projects."
"The agentless vulnerability scanning is great."
"I did a lot of research before signing up and doing the demo. They have a good reputation as far as catching threats early on."
"All the features we use are equal and get the job done."
"There's real-time threat detection. It can show threats and find issues based on their severity and helps us with real-time monitoring."
"PingSafe offers comprehensive security posture management."
"The most valuable features of PingSafe are the asset inventory and issue indexing."
"The tool identifies issues quickly."
"CoreOS Clair's best feature is detection accuracy."
"They also have threat detection which maps threats. There is a feed that comes from Qualys when a new vulnerability is found. It tells us which machines are infected with that vulnerability."
"The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network."
"It is quite easy to implement."
"Performs automated, regular scans in the network."
"Technical support is fantastic."
"Qualys VM is very stable."
"I like Qualys because it is a very complete product, more so than Tenable."
"The integrations for this solution are very good. I use a different product for virtual patching of vulnerabilities and Qualys integrates well with that product."
 

Cons

"It took us a while to configure the software to work well in this type of environment, as the support documents were not always clear."
"The reporting works well, but sometimes the severity classifications are inaccurate. Sometimes, it flags an issue as high-impact, but it should be a lower severity."
"If I had to pick a complaint, it would be the way the hosts are listed in the tool. You have different columns separated by endpoint name, Cloud Account, and Cloud Instances ID. I wish there was something where we could change the endpoint name and not use just the IP address. We would like to have custom names or our own names for the instances. If I had a complaint, that would be it, but so far, it meets all the needs that we have."
"Whenever I view the processes and the process aspect, it takes a long time to load."
"PingSafe takes four to five hours to detect and highlight an issue, and that time should be reduced."
"I would like PingSafe to add real-time detection of vulnerabilities and cloud misconfigurations."
"In addition to the console alerts, I would like PingSafe to also send email notifications."
"Bugs need to be disclosed quickly."
"An area for improvement is that CoreOS Clair doesn't provide information about the location of vulnerabilities it detects."
"This solution could be improved by extending the agent capabilities to different operating systems including Mac and Linux. We would also like the capability to easily check for vulnerability in assets in the IOTs."
"Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time."
"They should make it accessible for more operating systems."
"The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions."
"It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating."
"Qualys should improve their customer experience. They need to improve the tech support experience and the turnaround time."
"Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."
"It's too early for me to say if there is any room for improvement since we're in the first couple of months of using this solution."
 

Pricing and Cost Advice

"The features included in PingSafe justify its price point."
"PingSafe is fairly priced."
"As a partner, we receive a discount on the licenses."
"For pricing, it currently seems to be in line with market rates."
"The tool is cost-effective."
"Singularity Cloud Workload Security's pricing is good."
"Singularity Cloud Workload Security's licensing and price were cheaper than the other solutions we looked at."
"The pricing for PingSafe in India was more reasonable than other competitors."
"CoreOS Clair is open-source and free of charge."
"In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus."
"The pricing and licensing for Qualys could be improved."
"Qualys VM is reasonably priced."
"The pricing is very competitive."
"It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost."
"Qualys Virtual Scanner Appliance isn't expensive right now. But the price for their product bundles could be better."
"The price is very reasonable."
"They have recently changed the pricing model, which is now better than it was before."
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
787,226 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
21%
Financial Services Firm
15%
Manufacturing Company
11%
Insurance Company
4%
Financial Services Firm
19%
Computer Software Company
14%
Manufacturing Company
14%
Government
7%
Educational Organization
33%
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What needs improvement with PingSafe?
When I joined my organization, I saw that PingSafe was already implemented. I started to use the tool's alerting feat...
What do you like most about CoreOS Clair?
CoreOS Clair's best feature is detection accuracy.
What needs improvement with CoreOS Clair?
An area for improvement is that CoreOS Clair doesn't provide information about the location of vulnerabilities it det...
What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are man...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
We have an annual contract for Qualys VMDR. I believe it's for either two years or five years.
 

Also Known As

PingSafe
No data available
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
 

Overview

 

Sample Customers

Information Not Available
eBay, Veritas, Verizon, SalesForce
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
Find out what your peers are saying about Palo Alto Networks, Wiz, Microsoft and others in Container Security. Updated: June 2024.
787,226 professionals have used our research since 2012.