App comparison

Add up to 4 apps below to see how they compare. You can also use the "Compare" buttons while browsing.

Orca Security Logo
Orca Security

Cloud security platform for AWS, Azure, and GCP environments

visit website

(1)

Orca Security Reviews

User ratings

Overall rating

4.8

/5

41
100%
positive reviews
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend9.22/10

See full reviews by rating

Pros and cons

Support - Wonderful support and leadership team that cares about their customers. Open API - Rich and open API that allows you to extend and build on top of the product.
The Orca UI is clean and provides a good overview, the alerts are relevant, and the export functionality is very useful.
Very innovative and responsive team, enjoy working with them to improve the product.
Lack of on-prem/legacy scanning is a real bummer.
Sometimes is hard to find the information you need, it's not because of all the data available but it's not available in the GUI.
Deploying cloud scanners is a hassle as is agents and we had no visibility into our containers. This product provided all of that in the much coveted "single pane of glass.

Orca Security users...

Nessus-logocaret
listing-logo

Nessus

RAPID-logocaret
listing-logo

RAPID

CloudSploit-logocaret
listing-logo

CloudSploit

How would you rate Orca Security?
AvatarImg
AvatarImg
AvatarImg
AvatarImg
AvatarImg
Filter reviews by

Overall rating


Company size


Industry


Time used


41 reviews

Recommended

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Orca - Scan from the side, 0 user impact

Reviewed 2 years ago

We switched to a custom Linux Kernel that agent based VMS could not support. Orca was the only solution that we found that could solve our use case.

Pros

Orca is an agentless approach to VMS. This means there is 0 user impact or performance degradation. Your Operations team does not have to manage agent roll out, it also does not need to manage upgrades/downtime. This saves you operating costs and allows your Ops team to focus on other security items. Orca is OS agnostic, it does not matter what your development/architecture team decides to pivot to. Orca supports Windows/Linux/Mac/Containerization. It also is Cloud agnostic, have subs in Azure or AWS? Orca can handle them all with a few clicks. The entire roll out took around 10 minutes.

Cons

There are features missing in Orca from a nice to have stand point. The product is fairly new and a lot of these enhancements are being worked on. The Orca team has been very responsive to enhancements thus far.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Know your entire cloud sprawl in minutes

Reviewed 2 years ago

Product Integration - It's as easy as they sell it. I had it up and running in multiple accounts in no time. Support - Wonderful support and leadership team that cares about their customers. Open API - Rich and open API that allows you to extend and build on top of the product.

Pros

The extensibility of the product, and how rich the API is. I can find out almost anything about my environment. Using Orca gives me insight into my entire cloud sprawl. I can get information about malware, open-ingress to EC2 instances, and open source vuln management. The only limit to its use is imagination.

Cons

Creating new alerts can be clunky. However, the Orca team is always improving and is currently working on a V2. Navigating the UI can be a bit of a challenge at times when looking for specific info. This is why I often opt for using the API over the UI.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend7/10

Share this review:

Orca is a great product

Reviewed 2 years ago

It was a great experience.

Pros

I liked the side scanning technology availab.e

Cons

The price was super high for a new to market tool.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Orca Security Review

Reviewed 2 years ago

The first step to increase the security posture of an environment is to understand it. Orca Security instantly gave me that visibility without the hurdles of an agent.

Pros

The ability to get quick visibility into the cloud assets without going through the technical hurdles of deploying an agent.

Cons

I think the UI could use a bit more improvement. I've been using this software for 6 months and not everything is intuitive. I still forget where things are exactly.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend9/10

Share this review:

Agent less solution is the future in security vulnerability and container security monitoring.

Reviewed 2 years ago

We were trying to solve container security challenges. Actively monitoring what is going on within container. Benefit of agent less solution is two fold, 1) Do not have to install agents on the host machine. 2) Effective in monitoring workloads running in managed containers. Orca security, ability of side-scanning technology examines block storage out of band via a software-as-a-service (SaaS) platform.

Pros

Agent less no installation required. Simple 3 step process to connect account and start monitoring. Extensive deep insight into installed packages within container. Clear categorization of alerts as Imminent compromises, Hazardous, Informational with color coding for clear visibility. Also builds digital asset inventory for tracking different types cloud based assets ex: S3 buckets, EC2 instances....

Cons

Reporting and user interface are immature, but improving, not real time. This is near real time solution depends on frequency of scanning. VM specific details if consolidated as actionable insights will be very helpful to narrow our focus to relevant issues (ex: identified affected packages within a container is great, giving link to specific patches will be very helpful.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Super Easy to Setup and Start Managing Your AWS Risks

Reviewed 2 years ago

Not having to deal with agents combined with direct integration with our ticking system has saved us countless hours of precious engineering time. Because of this, we have gained tremendous value from the product since we can effectively manage AWS risks while focusing on creating more features and values for our customers.

Pros

Since Orca Security does not require any agents to install, setup took less than five minutes. We are also use multiple AWS accounts and since setup was simple, within less than thirty minutes, we had a single pane view of most of our AWS risks. In addition, since Orca Security integrates with Atlasssian Jira, with only one click, we could quick open remediation tickets for high risk vulnerabilities.

Cons

Although Orca Security offers a ton of AWS coverage, I'd like to see more work with AWS RDS and AWS networking services such as VPC and Security Groups.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Wide, Accurate Coverage with No Effort

Reviewed 2 years ago

The best I've had with any vendor.

Pros

The agent-less service deployed immediately, with no effort, and replaced three different products. The false positive rate is low. The information presented is easily and immediately actionable. The product has allowed me to reduce effort by 90% of an FTE.

Cons

I would like to feed the raw data to our data warehouse, which is not yet possible, though it is coming.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend8/10

Share this review:

An efficient, All-In-One entry level solution to start tackling Cloud security issues.

Reviewed 4 months ago

Thanks to Orca we were able to quickly scale our vulnerability management program.

Pros

Very easy to set-up. Top-notch customer follow-up and support. Continual solution improvement included in the pricing. Single pane of glass visibility into your Cloud infrastructure with a powerful query language and automation features.

Cons

Limitations of agent-less scanning. Container and Kubernetes scanning could be more developed.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend9/10

Share this review:

Orca for the Cloud

Reviewed 4 months ago

This is a small, fast moving company, which really cares about their customers and their product.

Pros

How easy it was go get up, running, and scanning. They really listen to Feature requests and get them in quickly.

Cons

Some reporting issues and SIEM data passing early on. This has mostly been addressed via feature requests.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend9/10

Share this review:

Easy Quick Win

Reviewed 4 months ago

Awesome. Coming from nothing deployed to now seeing everything in AWS is awesome and scary at the same time. But it quickly helped us become more aware and more secure in deploying our AWS Infrastructure.

Pros

The on-boarding team was great, Scott and Joshua were and are still very helpful, Also the easy of use is critical to get action items out of the Alerts.

Cons

Support needs to be more engaged and ensure timeline (SLA's) are meet or at least presented.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend9/10

Share this review:

Probably the best Cloud Native Application Protection Platform I've used

Reviewed 4 months ago

Orca solves several problems we regularly face including producing asset inventories, helping with compliance, and providing focussed mitigation of security vulnerabilities. Orca's dashboards provide the necessary insights into the latest threats to allow a more focused application of security resources.

Pros

Orca's agentless side-scanning techniques mean that all assets are automatically scanned - even if not running. Their dashboards provide an intuitive, easy to digest view of the current state of application security without being swamped by alerts and information. Orca provides an excellent way of producing an inventory of assets - particularly useful for ephemeral assets that are perpetually being created and destroyed. The compliance feature is also useful for auditing purposes. The recently introduced attack paths feature shows graphically how an attacker could gain access and potentially pivot through the system.

Cons

Because of the way Orca's side-scanning technology works using snapshots, the downside is that the scanning is not performed in real-time so cannot provide true xDR capabilities. It would also be useful if older alerts were automatically dismissed after a while when the vulnerability is no longer detected. This would help to reduce the total number of vulnerabilities and alerts that are displayed in the dashboards.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Innovative Cloud posture tool that defined a new approach that makes use so easy.

Reviewed 4 months ago

Exceptional, I have already recommended to peers who have also purchased.

Pros

Ability to discovery new assets only having role built in parent org. It's visibility also of back plane to reduce false positives. Responsiveness of company to implement change to functionality and UI.

Cons

I would say API visibility but that is already in Beta now.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Agentless Cloud Security

Reviewed 2 years ago

With other tools we struggled with complete visibility into our cloud. Deploying cloud scanners is a hassle as is agents and we had no visibility into our containers. This product provided all of that in the much coveted "single pane of glass."

Pros

The fact that the gaining complete visibility into our cloud workload is agentless and that gives us a complete view into our configurations, VM's, containers and security.

Cons

At this point everything is headed in the right direction.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Orca saved us from Drowning

Reviewed 4 months ago

It works. It will scare you with what it can see.

Pros

Ease of implementation. We can easily see all our assets with very automated code

Cons

Nothing. Love it all. I wish i could say i didnt like anything

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Lightning Fast Deployment and Accurate Results

Reviewed 2 years ago

We've been able to rapidly get our arms around our cloud configuration and vilnerability management and reduce our risk

Pros

Within minutes we were able to deploy this product and begin receiving accurate and actionable insight. There is no performance impact, no agent deployment to worry about and it just works. We were able to integrate this into our devops toolchain and drive results directly to the people who will remediate.

Cons

We're still adjusting to the new UI, but that's just familiarity, there is really nothing we don't like about the software.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend9/10

Share this review:

Agentless Solution with quality results

Reviewed 4 months ago
Pros

Ease of deployment and accuracy of resutlts

Cons

Some features are clunky have to escape out of investigation panel multiple times.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend8/10

Share this review:

Orca's SideScanner is a game changer.

Reviewed 4 months ago

Orca is solving our visibility issue. Without it, we wouldn't have been able to triage log4j, see malware in our environments, investigate vulnerable cloud instances, and a range of other basic but tricky cloud problems.

Pros

Orca's SideScanning technology is excellent. The fact that it doesn't require an agent and is still able to provide as much insight as it does is truly amazing.

Cons

Orca needs to figure out how to separate the wheat from the chaff. There are always a lot of vulnerabilities that appear in our console from old kernel versions or something that has already been patched that we're still getting alerts on.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Easy to set up and quick return on investment

Reviewed 4 months ago

Overall experience has been great

Pros

How easy it is to set up and the visibility we get

Cons

I have trouble with the querying language

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend8/10

Share this review:

client-less malware detection

Reviewed 2 years ago

Orca provides me with contextual security risk, it can identify a server with PII file which is exposed to the internet and rate it with a higher severity than a server which is not exposed to the internet.

Pros

agentless malware detection and great server/ containers visibility to identify security-related threats

Cons

The one thing that I least liked about this software, is that it's not real-time protection

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Orca agent-less scanning is best I have seen

Reviewed 2 years ago

Wonderful, they quickly identify vulns and we are able to easily generate Jira tickets to get them assigned to the people that can fix them.

Pros

Jira ticket generation, agent-less scanning, Container domination, ease of use and setup, Clean dashboard.

Cons

Lack of on-prem/legacy scanning is a real bummer

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Orca - A Revolutionary Tool for Security Governance

Reviewed 2 years ago
Pros

Orca implements into an AWS account in minutes and is able to assess the risk of all EBS volumes WITHOUT the need for authentication. This revolutionary side-scanning technology allows for total DevOps and Security governance in cloud accounts where some assets may not follow strict IAM standards.

Cons

Orca has a lot of room to do much more than its current feature set. Looking forward to seeing what they do next.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Clean UI, Effective, Robust

Reviewed 2 years ago

Easy reporting of (mostly true positives) cloud-related alerts. I can just export the data, brush it up, and share. Alerting on unpatched resources and secrets is very good compared to competitors.

Pros

The Orca UI is clean and provides a good overview, the alerts are relevant, and the export functionality is very useful.

Cons

The compliance functionality is a work in progress.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend7/10

Share this review:

Great tool

Reviewed 4 months ago
Pros

Lots of easy to use dashboards, reasonable classification of vulnerabilities and threats, good integration and even better support.

Cons

Some bugs from time to time and inconsistencies with labelling of alerts as time goes by.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend10/10

Share this review:

Instant cloud visibility and value

Reviewed 2 years ago

Very innovative and responsive team, enjoy working with them to improve the product.

Pros

The product deployment was simple, quick and easy. The visibility gained for all cloud services was almost instant. The ability to conduct side scanning is a game changer that does not affect production.

Cons

Operational reporting was good, but executive reporting lacks in the early days of product development. For the value gained, we are willing to wait.

Overall Rating
  • Value for money
  • Ease of use
  • Features
  • Customer support
  • Likelihood to recommend8/10

Share this review:

Orca review

Reviewed 4 months ago
Pros

Easy integration, ease of understanding of risks and detailed information and categorization of risks in our environment

Cons

No AliCloud support and limited CI/CD and runtime serverless security visibility