En savoir plus sur Orca Security

Plus de 100 ressources cloud ? Bénéficiez d'une sécurité instantanée et centrée sur la charge de travail pour AWS, Azure et GCP, sans lacunes de couverture et prise de tête des agents.

En savoir plus sur Orca Security

Avantages :

Ease of use, user experience, fast triage time to determine risk.

Inconvénients :

Some small bugs and issues, currently missing some features that competitors have.

Orca Security - Notes

Note moyenne

Facilité d'utilisation
4,8
Service client
4,8
Fonctionnalités
4,6
Rapport qualité-prix
4,7

Probabilité de recommander le produit

9,2/10

Orca Security a reçu une note globale de 4,8 étoiles sur 5 d'après 41 avis d'utilisateurs publiés sur Capterra.

Filtrer les avis (41)

Classer par

Avez-vous déjà utilisé Orca Security ?

Partagez vos expériences avec d'autres acheteurs de logiciels.

Filtrer les avis (41)

Utilisateur vérifié
Information Security Analyst (Canada)
Utilisateur LinkedIn vérifié
Services et technologies de l'information, 1 001-5 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Orca - Scan from the side, 0 user impact

5,0 il y a 2 ans

Commentaires : We switched to a custom Linux Kernel that agent based VMS could not support. Orca was the only solution that we found that could solve our use case.

Avantages :

Orca is an agentless approach to VMS. This means there is 0 user impact or performance degradation. Your Operations team does not have to manage agent roll out, it also does not need to manage upgrades/downtime. This saves you operating costs and allows your Ops team to focus on other security items. Orca is OS agnostic, it does not matter what your development/architecture team decides to pivot to. Orca supports Windows/Linux/Mac/Containerization. It also is Cloud agnostic, have subs in Azure or AWS? Orca can handle them all with a few clicks. The entire roll out took around 10 minutes.

Inconvénients :

There are features missing in Orca from a nice to have stand point. The product is fairly new and a lot of these enhancements are being worked on. The Orca team has been very responsive to enhancements thus far.

Alternatives envisagées : DivvyCloud

Pourquoi choisir Orca Security : Rapid7 could not be installed on our Linux Kernel.

Logiciel antérieur : InsightVM

Pourquoi passer à Orca Security : DivvyCloud is agent based and did not support our Linux distro.

Aaron
Senior Security Engineer (É.-U.)
Logiciels, 501-1 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Know your entire cloud sprawl in minutes

5,0 il y a 2 ans

Commentaires : Product Integration - It's as easy as they sell it. I had it up and running in multiple accounts in no time. Support - Wonderful support and leadership team that cares about their customers. Open API - Rich and open API that allows you to extend and build on top of the product.

Avantages :

The extensibility of the product, and how rich the API is. I can find out almost anything about my environment. Using Orca gives me insight into my entire cloud sprawl. I can get information about malware, open-ingress to EC2 instances, and open source vuln management. The only limit to its use is imagination.

Inconvénients :

Creating new alerts can be clunky. However, the Orca team is always improving and is currently working on a V2. Navigating the UI can be a bit of a challenge at times when looking for specific info. This is why I often opt for using the API over the UI.

Alternatives envisagées : Harmony Email & Collaboration

Pourquoi passer à Orca Security : I ended up choosing Dome9 because it's feature-rich, but bells-and-whistles light. It provides to me the most salient alerts and alarms, while not making too much noise. A lot of competitors' products are very opinionated, which can force a security organization to shape their processes around the tool. With Orca it's the opposite, the tool is powerful, lightweight and malleable.

Jon
Vice President, Technology Security, Risk & Compliance (É.-U.)
Services et technologies de l'information, 501-1 000 employés
Temps d'utilisation du logiciel : 1 à 5 mois
Source de l'avis

Orca is a great product

4,0 il y a 2 ans

Commentaires : It was a great experience.

Avantages :

I liked the side scanning technology availab.e

Inconvénients :

The price was super high for a new to market tool.

Alternatives envisagées : VM-Series et Harmony Email & Collaboration

Pourquoi choisir Orca Security : Functionality

Logiciel antérieur : VM-Series

Pourquoi passer à Orca Security : Ease of use

Paul
Principal, Application Security Architect (É.-U.)
Logiciels, 1 001-5 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Orca Security Review

5,0 il y a 2 ans

Commentaires : The first step to increase the security posture of an environment is to understand it. Orca Security instantly gave me that visibility without the hurdles of an agent.

Avantages :

The ability to get quick visibility into the cloud assets without going through the technical hurdles of deploying an agent.

Inconvénients :

I think the UI could use a bit more improvement. I've been using this software for 6 months and not everything is intuitive. I still forget where things are exactly.

Alternatives envisagées : InsightVM

Pourquoi choisir Orca Security : Not having to deal with agents on a machine was critical due to the various technical hurdles to install it on every cloud resource.

Logiciel antérieur : InsightVM

Pourquoi passer à Orca Security : Orca Security has a unique technology that is agentless. The ability to get that type of visibility was a key differentiator.

Abhinay
Director of Software Engineering (É.-U.)
Hôpitaux et soins de santé, 10 000+ employés
Temps d'utilisation du logiciel : 1 à 5 mois
Source de l'avis

Agent less solution is the future in security vulnerability and container security monitoring.

5,0 il y a 2 ans

Commentaires : We were trying to solve container security challenges. Actively monitoring what is going on within container. Benefit of agent less solution is two fold, 1) Do not have to install agents on the host machine. 2) Effective in monitoring workloads running in managed containers.
Orca security, ability of side-scanning technology examines block storage out of band via a software-as-a-service (SaaS) platform.

Avantages :

Agent less no installation required. Simple 3 step process to connect account and start monitoring. Extensive deep insight into installed packages within container. Clear categorization of alerts as Imminent compromises, Hazardous, Informational with color coding for clear visibility. Also builds digital asset inventory for tracking different types cloud based assets ex: S3 buckets, EC2 instances. Easy to connect multiple accounts across AWS, Azure, GCP. Under Vulnerability management some of the key features to highlight are Asset Discovery, Asset Tagging, Network Scanning, Patch Management,Vulnerability Assessment,Web Scanning, Risk Management and Policy Management. Couple of the key cloud security features to highlight are Endpoint Management,Threat Intelligence,Vulnerability Management, Intrusion Detection System, Behavioral Analytics, Encryption and Application Security. Ease of integration was one of the reason to consider Orca security solution.

Inconvénients :

Reporting and user interface are immature, but improving, not real time. This is near real time solution depends on frequency of scanning. VM specific details if consolidated as actionable insights will be very helpful to narrow our focus to relevant issues (ex: identified affected packages within a container is great, giving link to specific patches will be very helpful.

Alternatives envisagées : VM-Series

Pourquoi passer à Orca Security : Agent less deployment with similar functionality.

Jeremy
Cloud Security Engineer (Japon)
Services financiers, 51-200 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Super Easy to Setup and Start Managing Your AWS Risks

5,0 il y a 2 ans

Commentaires : Not having to deal with agents combined with direct integration with our ticking system has saved us countless hours of precious engineering time. Because of this, we have gained tremendous value from the product since we can effectively manage AWS risks while focusing on creating more features and values for our customers.

Avantages :

Since Orca Security does not require any agents to install, setup took less than five minutes. We are also use multiple AWS accounts and since setup was simple, within less than thirty minutes, we had a single pane view of most of our AWS risks. In addition, since Orca Security integrates with Atlasssian Jira, with only one click, we could quick open remediation tickets for high risk vulnerabilities.

Inconvénients :

Although Orca Security offers a ton of AWS coverage, I'd like to see more work with AWS RDS and AWS networking services such as VPC and Security Groups.

Alternatives envisagées : Nessus et Trend Micro Deep Security

Pourquoi passer à Orca Security : Partly because of the [SENSITIVE CONTENT HIDDEN] experience and track record but mainly because of the fact that we don't have to deal with installing and managing agents.

Jonathan
CISO (É.-U.)
Assurance, 201-500 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Wide, Accurate Coverage with No Effort

5,0 il y a 2 ans

Commentaires : The best I've had with any vendor.

Avantages :

The agent-less service deployed immediately, with no effort, and replaced three different products. The false positive rate is low. The information presented is easily and immediately actionable. The product has allowed me to reduce effort by 90% of an FTE.

Inconvénients :

I would like to feed the raw data to our data warehouse, which is not yet possible, though it is coming.

Alternatives envisagées : Nessus, Lacework, VM-Series et Threat Stack

Pourquoi passer à Orca Security : It's clearly better than Nessus, Lacework and Threat Stack. It is equivalent to Prisma Enterprise, but much easier to deploy, manage, use, and investigate.

Aristide
Product Security Engineer (Pays-Bas)
Vente au détail, 501-1 000 employés
Temps d'utilisation du logiciel : plus d'un an
Source de l'avis

An efficient, All-In-One entry level solution to start tackling Cloud security issues.

4,0 il y a 4 mois

Commentaires : Thanks to Orca we were able to quickly scale our vulnerability management program.

Avantages :

Very easy to set-up. Top-notch customer follow-up and support. Continual solution improvement included in the pricing. Single pane of glass visibility into your Cloud infrastructure with a powerful query language and automation features.

Inconvénients :

Limitations of agent-less scanning. Container and Kubernetes scanning could be more developed.

Alternatives envisagées : Lacework, Intezer Protect, Prisma SD-WAN et Rezilion Validate

Pourquoi passer à Orca Security : Agent-less technology so we could set it up quickly without impacting our current IT operation processes. Powerful correlation, prioritization and query engine. Reasonable pricing and top-notch customer support.

Brian
Director of Information Security (É.-U.)
Santé, bien-être et fitness, 1 001-5 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Orca for the Cloud

4,0 il y a 4 mois

Commentaires : This is a small, fast moving company, which really cares about their customers and their product.

Avantages :

How easy it was go get up, running, and scanning. They really listen to Feature requests and get them in quickly.

Inconvénients :

Some reporting issues and SIEM data passing early on. This has mostly been addressed via feature requests.

Alternatives envisagées : Lacework

Pourquoi passer à Orca Security : They had the features I needed at testing time. Lacework did not.

Nick
Security Architect (É.-U.)
Hôpitaux et soins de santé, 501-1 000 employés
Temps d'utilisation du logiciel : 1 à 5 mois
Source de l'avis

Easy Quick Win

5,0 il y a 4 mois

Commentaires : Awesome. Coming from nothing deployed to now seeing everything in AWS is awesome and scary at the same time. But it quickly helped us become more aware and more secure in deploying our AWS Infrastructure.

Avantages :

The on-boarding team was great, Scott and Joshua were and are still very helpful, Also the easy of use is critical to get action items out of the Alerts.

Inconvénients :

Support needs to be more engaged and ensure timeline (SLA's) are meet or at least presented.

Alternatives envisagées : Cortex XDR

Pourquoi passer à Orca Security : Quick and easy of deployment. Others required asset deployment to the Infrastructure. Which adds to the complexity.

Simon
Senior Application Security Engineer (R.-U.)
Gestion de l'enseignement, 501-1 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Probably the best Cloud Native Application Protection Platform I've used

5,0 il y a 4 mois

Commentaires : Orca solves several problems we regularly face including producing asset inventories, helping with compliance, and providing focussed mitigation of security vulnerabilities. Orca's dashboards provide the necessary insights into the latest threats to allow a more focused application of security resources.

Avantages :

Orca's agentless side-scanning techniques mean that all assets are automatically scanned - even if not running. Their dashboards provide an intuitive, easy to digest view of the current state of application security without being swamped by alerts and information. Orca provides an excellent way of producing an inventory of assets - particularly useful for ephemeral assets that are perpetually being created and destroyed. The compliance feature is also useful for auditing purposes. The recently introduced attack paths feature shows graphically how an attacker could gain access and potentially pivot through the system.

Inconvénients :

Because of the way Orca's side-scanning technology works using snapshots, the downside is that the scanning is not performed in real-time so cannot provide true xDR capabilities. It would also be useful if older alerts were automatically dismissed after a while when the vulnerability is no longer detected. This would help to reduce the total number of vulnerabilities and alerts that are displayed in the dashboards.

Weryke
Deputy CISO (É.-U.)
Automobile, 5 001-10 000 employés
Temps d'utilisation du logiciel : plus d'un an
Source de l'avis

Innovative Cloud posture tool that defined a new approach that makes use so easy.

5,0 il y a 4 mois

Commentaires : Exceptional, I have already recommended to peers who have also purchased.

Avantages :

Ability to discovery new assets only having role built in parent org. It's visibility also of back plane to reduce false positives. Responsiveness of company to implement change to functionality and UI.

Inconvénients :

I would say API visibility but that is already in Beta now.

Aaron
Director of Cloud Security (É.-U.)
Services financiers, 1 001-5 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Agentless Cloud Security

5,0 il y a 2 ans

Commentaires : With other tools we struggled with complete visibility into our cloud. Deploying cloud scanners is a hassle as is agents and we had no visibility into our containers. This product provided all of that in the much coveted "single pane of glass."

Avantages :

The fact that the gaining complete visibility into our cloud workload is agentless and that gives us a complete view into our configurations, VM's, containers and security.

Inconvénients :

At this point everything is headed in the right direction.

Charbel
Senior Cyber Security Engineer (Australie)
Services financiers, 1 001-5 000 employés
Temps d'utilisation du logiciel : plus d'un an
Source de l'avis

Orca saved us from Drowning

5,0 il y a 4 mois

Commentaires : It works. It will scare you with what it can see.

Avantages :

Ease of implementation. We can easily see all our assets with very automated code

Inconvénients :

Nothing. Love it all. I wish i could say i didnt like anything

Alternatives envisagées : Tenable.io

Pourquoi passer à Orca Security : Ease of use and its innovative way it works

Doug
CSO (É.-U.)
Services d'information, 5 001-10 000 employés
Temps d'utilisation du logiciel : plus d'un an
Source de l'avis

Lightning Fast Deployment and Accurate Results

5,0 il y a 2 ans

Commentaires : We've been able to rapidly get our arms around our cloud configuration and vilnerability management and reduce our risk

Avantages :

Within minutes we were able to deploy this product and begin receiving accurate and actionable insight. There is no performance impact, no agent deployment to worry about and it just works. We were able to integrate this into our devops toolchain and drive results directly to the people who will remediate.

Inconvénients :

We're still adjusting to the new UI, but that's just familiarity, there is really nothing we don't like about the software.

Alexey
Security Engineer (É.-U.)
Construction, 201-500 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Agentless Solution with quality results

5,0 il y a 4 mois

Avantages :

Ease of deployment and accuracy of resutlts

Inconvénients :

Some features are clunky have to escape out of investigation panel multiple times.

Andrew
Security Engineer II (É.-U.)
Télécommunications, 201-500 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Orca's SideScanner is a game changer.

5,0 il y a 4 mois

Commentaires : Orca is solving our visibility issue. Without it, we wouldn't have been able to triage log4j, see malware in our environments, investigate vulnerable cloud instances, and a range of other basic but tricky cloud problems.

Avantages :

Orca's SideScanning technology is excellent. The fact that it doesn't require an agent and is still able to provide as much insight as it does is truly amazing.

Inconvénients :

Orca needs to figure out how to separate the wheat from the chaff. There are always a lot of vulnerabilities that appear in our console from old kernel versions or something that has already been patched that we're still getting alerts on.

Grant
Manager of Security Operations (É.-U.)
Banque, 1 001-5 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Easy to set up and quick return on investment

5,0 il y a 4 mois

Commentaires : Overall experience has been great

Avantages :

How easy it is to set up and the visibility we get

Inconvénients :

I have trouble with the querying language

Idan
CISO (Israël)
Marketing et publicité, 201-500 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

client-less malware detection

4,0 il y a 2 ans

Commentaires : Orca provides me with contextual security risk, it can identify a server with PII file which is exposed to the internet and rate it with a higher severity than a server which is not exposed to the internet.

Avantages :

agentless malware detection and great server/ containers visibility to identify security-related threats

Inconvénients :

The one thing that I least liked about this software, is that it's not real-time protection

Owen
Information Security Engineer (É.-U.)
Services financiers, 501-1 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Orca agent-less scanning is best I have seen

5,0 il y a 2 ans

Commentaires : Wonderful, they quickly identify vulns and we are able to easily generate Jira tickets to get them assigned to the people that can fix them.

Avantages :

Jira ticket generation, agent-less scanning, Container domination, ease of use and setup, Clean dashboard.

Inconvénients :

Lack of on-prem/legacy scanning is a real bummer

John
CISO (É.-U.)
E-learning, 501-1 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Orca - A Revolutionary Tool for Security Governance

5,0 il y a 2 ans

Avantages :

Orca implements into an AWS account in minutes and is able to assess the risk of all EBS volumes WITHOUT the need for authentication. This revolutionary side-scanning technology allows for total DevOps and Security governance in cloud accounts where some assets may not follow strict IAM standards.

Inconvénients :

Orca has a lot of room to do much more than its current feature set. Looking forward to seeing what they do next.

Utilisateur vérifié
Cyber Security Lead (É.-U.)
Utilisateur LinkedIn vérifié
Divertissement, 501-1 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Clean UI, Effective, Robust

5,0 il y a 2 ans

Commentaires : Easy reporting of (mostly true positives) cloud-related alerts. I can just export the data, brush it up, and share. Alerting on unpatched resources and secrets is very good compared to competitors.

Avantages :

The Orca UI is clean and provides a good overview, the alerts are relevant, and the export functionality is very useful.

Inconvénients :

The compliance functionality is a work in progress.

Daniel
Senior SecOps Engineer (R.-U.)
Sécurité et enquêtes, 501-1 000 employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Great tool

5,0 il y a 4 mois

Avantages :

Lots of easy to use dashboards, reasonable classification of vulnerabilities and threats, good integration and even better support.

Inconvénients :

Some bugs from time to time and inconsistencies with labelling of alerts as time goes by.

Thomas
Ciso (É.-U.)
Banque, 501-1 000 employés
Temps d'utilisation du logiciel : 1 à 5 mois
Source de l'avis

Instant cloud visibility and value

5,0 il y a 2 ans

Commentaires : Very innovative and responsive team, enjoy working with them to improve the product.

Avantages :

The product deployment was simple, quick and easy. The visibility gained for all cloud services was almost instant. The ability to conduct side scanning is a game changer that does not affect production.

Inconvénients :

Operational reporting was good, but executive reporting lacks in the early days of product development. For the value gained, we are willing to wait.

Anurag
Security Analyst (É.-U.)
Vente au détail, 10 000+ employés
Temps d'utilisation du logiciel : 6 à 12 mois
Source de l'avis

Orca review

5,0 il y a 4 mois

Avantages :

Easy integration, ease of understanding of risks and detailed information and categorization of risks in our environment

Inconvénients :

No AliCloud support and limited CI/CD and runtime serverless security visibility