HCL AppScan Valuable Features

AnanyaRoy - PeerSpot reviewer
Risk Analyst at Deloitte

The most valuable feature of the solution stems from the fact that it is good to run the scan faster. You can basically run the scan and take a break at work since the tool will compute the results, which makes the product quite intuitive. HCL AppScan doesn't require constant monitoring.

View full review »
RR
Head of Data Link at Telecom Egypt

The product is useful, particularly in its sensitivity and scanning capabilities. Additionally, it allows for investigation while the developer is writing the code. It is a more efficient process compared to other tools like App Scan.

View full review »
Rishi Anupam - PeerSpot reviewer
Senior Manager at Airtel

The reporting part is the most valuable feature.

View full review »
Buyer's Guide
HCL AppScan
March 2024
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,246 professionals have used our research since 2012.
PD
Director at KPMG

SAST is the only feature that works using the on-prem version. It's becoming very difficult for us to integrate it with the other SecOps solutions. It is a very good solution but only when using the standard version.

View full review »
Gladwin Christian - PeerSpot reviewer
QA manager at SmartStream Technologies ltd.

The most valuable feature of the solution is the scanning or security part.

View full review »
AnshulTomar - PeerSpot reviewer
Cyber Security Architect and Presales Consultant at Kyndryl

The product has valuable features for static and dynamic testing. It is one of the leaders in the market amongst SAST solutions.

View full review »
SG
Application Security Engineer at a transportation company with 1,001-5,000 employees

It depends on the application, but it's generally a very user-friendly tool. Anyone can easily learn how to scan and boost their security.  

View full review »
RN
Principal Architect, Application Build Security. at a transportation company with 10,001+ employees

There are many features that are valuable. such as the APIs. API calls in AppScan, and similar to Burp Suite enterprise edition, which is also for API scans. I can trigger the scan ware API.

The HCL AppScan turnaround time for Burp Suite or any new feature request is pretty good, and that is why we are sticking with the HCL.

View full review »
JH
Security Engineer at KEPCO KDN

The solution is easy to use. It is useful for finding basic information about systems.

View full review »
Miar Ahmad - PeerSpot reviewer
Software Engineer at Inspire for Solutions Development

The most valuable feature of the solution is Postman. As a security engineer, Postman allows me to specify exactly what information I need to scan for, rather than just dropping all information and running a scan. I can also use it to do some information gathering before scanning. This allows me to specify APIs and scan accordingly. The feature also saves us time.

View full review »
TH
Director For Security Products at a manufacturing company with 10,001+ employees

The most valuable feature is the web scan from our perspective. Being able to quickly find the vulnerabilities if any developer has inadvertently put them in. The source scan is of value, but it is so hard to use that it is of less value.

View full review »
JB
Solutions Architect at a tech vendor with 10,001+ employees

The scanning is quite good. It's good for helping us seek out vulnerabilities and fixing hot spots. 

The pricing is fine. 

It's on a managed cloud, and that makes it very easy. It's straightforward to use.

The solution has been stable, and we haven't really had downtime. 

It's stable. 

Technical support is helpful.

View full review »
Basit Shah - PeerSpot reviewer
Software Quality Assurance Engineer at IT22

The UI was very intuitive. It was very easy to understand. It was very easy to scan the websites, see the results, and deliver them to higher management.

View full review »
CV
CTO at SAQ

Compared to other tools only AppScan supports special language.

View full review »
Manh Duong - PeerSpot reviewer
General Manager at Groupe PROGEREAL- FINAREAL - PROMOREAL

The most valuable feature of HCL AppScan is scanning QR codes.

View full review »
SH
Owner/ Consultant at a tech services company with 1-10 employees

AppScan is within the top three or four static analyzers. Its features include support for many languages. 

The product has a relatively reasonable scan time.

There's extensive functionality with custom rules and a custom knowledge base.

View full review »
it_user841956 - PeerSpot reviewer
Director Of Product Cyber Security at a aerospace/defense firm with 10,001+ employees

For me, as a manager, it was the ease of use. Inserting security into the development process is not normally an easy project to do. The ability for the developer to actually use it and get results and focuses, that's what counted.

View full review »
EE
Innovation manager at a computer software company with 51-200 employees

The dynamic scan, the DAST tool, dynamic applications scanning and testing tool, is great.

It was easy to set up.

It's a stable solution.

The product is easy to scale. 

The solution is affordable and reasonably priced.

View full review »
David Mawazo - PeerSpot reviewer
Chief Information Officer at TeleTracking Technologies, Inc.

The security and the dashboard are the most valuable features.

View full review »
FM
Senior Manager, IT Test Automation Engineering at a outsourcing company with 10,001+ employees

The solution offers services in a few specific development languages.

View full review »
EO
Senior Security Specialist at a transportation company with 10,001+ employees

There's a recording feature that I really like. You pass through the login pages. If you record the login part, it becomes very fast with the solution.

View full review »
it_user842904 - PeerSpot reviewer
CTO at Anzen

It helps you to enforce security practices, beyond the reach of just operations and training. So give the training, but besides that you can detect some deviations in the development process. I think that's the most valuable of all the features.

View full review »
it_user634890 - PeerSpot reviewer
Chief information with 5,001-10,000 employees

We are currently using it in the integration of our agile process so we can find any breaches in the apps while they're in the development process. We can then fix breaches before they go into a production environment.

It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply.

That being said, we have to be very rigorous about what we are protecting, such as the type of data and the code itself. Having those features in the app is a huge must.

View full review »
it_user483672 - PeerSpot reviewer
Security Consultant at a tech vendor with 501-1,000 employees

The most valuable feature of this product is its capability to detect XSS and SQL injection.

View full review »
TD
General Manager at a consultancy with 51-200 employees

It's a good product. It's automated crawler identifies all urls and performs security tests. It has a very rich test cases which ensures pretty good coverage in terms of security testing. The UI is user friendly and intuitive. 

View full review »
it_user840837 - PeerSpot reviewer
Manager at a tech vendor with 501-1,000 employees

Scalability, and it's a very powerful tool.

View full review »
it_user840909 - PeerSpot reviewer
Managing director at Accenture

It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code.

View full review »
PN
Security Consultant at a consultancy with 10,001+ employees

Many features are valuable but some features stand out, like using our own scripts, and capturing the authentication.

View full review »
MH
Senior Cloud Architect at a tech company with 1,001-5,000 employees

Its integration from a UI perspective. You can easily find particular features and functions through the UI. 

For its first initial release, the integration was pretty good.

View full review »
it_user844479 - PeerSpot reviewer
People Leader Of Cyber Strategy And Solutions at a insurance company with 10,001+ employees

We leverage it as a quality check against code.

View full review »
SC
Chief researcher at INSEC Security

AppScan seems to be very good at detecting reflected XSS vulnerabilities. This increases the security of web applications that are in operation.

View full review »
JS
Cybersecurity Architecture and Technology Lead at Appxone

The most valuable feature is that it achieves a very low false-positive detection rate.

View full review »
it_user634947 - PeerSpot reviewer
Application Security Consultant at a financial services firm with 10,001+ employees

It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings.

View full review »
it_user841920 - PeerSpot reviewer
Business Development Manager at a tech services company with 10,001+ employees

The static scans are good, and the SaaS as well. 

View full review »
it_user279198 - PeerSpot reviewer
CEO at a government

I think it's easy to use and gives back some pretty good results, certainly for vulnerabilities.

View full review »
Buyer's Guide
HCL AppScan
March 2024
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,246 professionals have used our research since 2012.