17 años ayudando a las empresas
a elegir el mejor software
Orca Security
¿Qué es Orca Security?
¿Tienes más de 100 activos en la nube? Orca Security proporciona visibilidad y seguridad a nivel de la carga de trabajo para AWS, Azure y GCP, sin las brechas de cobertura y los costos operativos de los agentes. Con Orca, ya no habrá activos omitidos, ni inconvenientes de DevOps, ni bajas de rendimiento en entornos en vivo. Detecta vulnerabilidades, malware, configuraciones erróneas, riesgo de movimiento lateral, contraseñas débiles y filtradas y datos de alto riesgo, como PII (información de identificación personal, por sus siglas en inglés). Además prioriza los riesgos según el contexto ambiental.
¿Quién usa Orca Security?
Grandes empresas, así como empresas nacidas en la nube de sectores como SaaS, tecnología financiera, Internet, medios de comunicación, tecnología publicitaria y nube.
¿Tienes dudas sobre Orca Security?
Compara con una alternativa popular
Orca Security
Opiniones de Orca Security
Orca Security : intensive scrutiny of your cloud deployments
Comentarios: We feel that we've been able to significantly improve our organization's awareness across the board to security issues.
Puntos a favor:
I appreciate how Orca Security does side-scanning, unobtrusively collecting information about our cloud deployments, and then submitting those records through intensive scrutiny. The scan results are compared against CVEs to establish prioritized lists for mitigation efforts
Puntos en contra:
Integration of Orca Security with Microsoft Teams to provide realtime alerts when issues are detected is in it's infancy at present, and we had some troubles getting it going.
Alternativas consideradas previamente:
Faster and Stroger that´s Orca Security
Comentarios: Faster and easier deployment, full visibility into AWS and Azure.
Puntos a favor:
Easy deploy and powerfull visibility it´s most values of Orca.
Puntos en contra:
Lack of visibility into the on-premises environment
Orca security general overview
Comentarios: I have enjoyed the Orca security in the sense that it gives in-depth details of vulnerability, attack path, security posture among many others
Puntos a favor:
It is a reach platform which provides us with comprehensive security tooling features.
Puntos en contra:
The only part I have reservations about is the shift-left aspect whereby there is no known IDE extension for the CLI
Great Product
Puntos a favor:
I believe Orca is an amazing tool. The fact it is agentless, can be deployed in AWS, Azure, and GCP make it an all around tool. Another reason I like Orca is the support I have gotten. The team is always available when we have issues and is able to resolve anything we see quickly.
Puntos en contra:
I have no cons on this product. It works as intended.
Best in class, but expensive
Puntos a favor:
Orca has the complete package of security tooling available. If cybersecurity is a very important concern for your company, this is the best choice.
Puntos en contra:
While a complete package, they are very expensive. If you don't need all features other competitors might be more valuable for the money.
Great company! Awesome product! Amazing staff!
Comentarios: Great team, useful product! I loved working with Orca Security as vendor! Their product provided meaningful insights into overall project security and what can be done better on our side!
Puntos a favor:
I honestly love their innovative product! Used it with AWS cloud infrastructure - only really cool benefits!
Puntos en contra:
Nothing, really! The are clock-sharp in resolving any issues, hepling with setup and configuration, everythin was perfect!
Alternativas consideradas previamente:
Swim with ORCA. It will change your world
Comentarios: Great experience. The fact they take feedback and make it happen is great.
Puntos a favor:
Easy of deployment. I can deploy and auto deploy to environments
Puntos en contra:
Nothing. Its great. I have no issues with the product
Strong product, outstanding support
Comentarios: Overall our experience with Orca has been great and their support team is really on top of their game. So far Orca is ticking all the boxes for us and has quickly become a trusted tool in our security arsenal.
Puntos a favor:
Orca is extremely easy to set up and we got our 27 AWS accounts onboarded within minutes. The findings from Orca are very relevant and pertinent recommendations were provided for remediation, including links to external documentation when relevant. Orca is also great at providing peace of mind when it comes to staying on top of new threats and vulnerabilities as it automatically scans our assets when new vulnerabilities are published. Automated scanning for the log4j vulnerabilities were available within a couple of days of disclosure.
Puntos en contra:
A few bugs in the UI, which are being addressed quickly.
Alternativas consideradas previamente:
Excellent CSPM/CWPP
Comentarios: Orca helps us maintain and improve our cloud security by prioritizing and contextualizing findings
Puntos a favor:
Incredibly easy setup and 100% visibility of cloud assets
Puntos en contra:
It would be helpful to group similar findings across scaleable infrastructure rather than showing each finding individually
Orca Review
Comentarios: Orcas ability to create custom reporting per cloud computing module has been crucial in reporting for our vulnerability remediation. Our internal teams have the ability to rescan items on demand as well to ensure things are being fixed within SLA
Puntos a favor:
Orca has been a crucial tool for our enterprise to to enhance our visibility into our cloud resources. Ontop of being a great product, their support has been outstanding in answering all of our questions, fixing bugs, and expediting our open cases.
Puntos en contra:
The only dislikes of Orca that I have emphasized to their support team is around vulnerability management reporting and navigation within the tool. They have since released the Discovery module that allows us to create custom rules to provide the reports we need. I would like to see them continue to enhance their dashboarding capabilities for vulnerability trend data.
Orca Security review
Comentarios: Orca Security is constantly reviewing our AWS cloud environment security posture keeping our business as safe as possible
Puntos a favor:
The most I like about Orca is its extensive collection of security check for our AWS environment, also that Orca is always working on new features and new improvements
Puntos en contra:
I wish there was also a live scanner, but I guess its not part of the product or how its works, also if the price was lower
An easy to deploy, manage and administer security solution
Puntos a favor:
Agentless was a very big win for me. And now with API scanning, it goes to the next level!
Puntos en contra:
No dark mode. Seriously. We need to make sure that products have dark mode!
An efficient, All-In-One entry level solution to start tackling Cloud security issues.
Comentarios: Thanks to Orca we were able to quickly scale our vulnerability management program.
Puntos a favor:
Very easy to set-up. Top-notch customer follow-up and support. Continual solution improvement included in the pricing. Single pane of glass visibility into your Cloud infrastructure with a powerful query language and automation features.
Puntos en contra:
Limitations of agent-less scanning. Container and Kubernetes scanning could be more developed.
Orca Rocks
Puntos a favor:
Not only does Orca work, the customer success team is always on top of things and keeping what we want for the future in mind.
Puntos en contra:
Sometimes I feel like UI focuses a little too much on style rather than function.
IT Sec Review
Puntos a favor:
"Security score analysis" and "from the news" areas.
Puntos en contra:
Seeing already dismissed alerts & unclear algorithm for "security score analysis".
Orca Security
Comentarios: Orca has been great for our company as we are hosted in AWS and had limited visibility before.
Puntos a favor:
Orca is pretty simple to set up and provides a vast amount of data right out of the gate. There is very little continual maintenance needed.
Puntos en contra:
The inability to create exceptions based on characteristics. Ea File path, name
Orca - Scan from the side, 0 user impact
Comentarios: We switched to a custom Linux Kernel that agent based VMS could not support. Orca was the only solution that we found that could solve our use case.
Puntos a favor:
Orca is an agentless approach to VMS. This means there is 0 user impact or performance degradation. Your Operations team does not have to manage agent roll out, it also does not need to manage upgrades/downtime. This saves you operating costs and allows your Ops team to focus on other security items. Orca is OS agnostic, it does not matter what your development/architecture team decides to pivot to. Orca supports Windows/Linux/Mac/Containerization. It also is Cloud agnostic, have subs in Azure or AWS? Orca can handle them all with a few clicks. The entire roll out took around 10 minutes.
Puntos en contra:
There are features missing in Orca from a nice to have stand point. The product is fairly new and a lot of these enhancements are being worked on. The Orca team has been very responsive to enhancements thus far.
Probably the best Cloud Native Application Protection Platform I've used
Comentarios: Orca solves several problems we regularly face including producing asset inventories, helping with compliance, and providing focussed mitigation of security vulnerabilities. Orca's dashboards provide the necessary insights into the latest threats to allow a more focused application of security resources.
Puntos a favor:
Orca's agentless side-scanning techniques mean that all assets are automatically scanned - even if not running. Their dashboards provide an intuitive, easy to digest view of the current state of application security without being swamped by alerts and information. Orca provides an excellent way of producing an inventory of assets - particularly useful for ephemeral assets that are perpetually being created and destroyed. The compliance feature is also useful for auditing purposes. The recently introduced attack paths feature shows graphically how an attacker could gain access and potentially pivot through the system.
Puntos en contra:
Because of the way Orca's side-scanning technology works using snapshots, the downside is that the scanning is not performed in real-time so cannot provide true xDR capabilities. It would also be useful if older alerts were automatically dismissed after a while when the vulnerability is no longer detected. This would help to reduce the total number of vulnerabilities and alerts that are displayed in the dashboards.
Orca's SideScanner is a game changer.
Comentarios: Orca is solving our visibility issue. Without it, we wouldn't have been able to triage log4j, see malware in our environments, investigate vulnerable cloud instances, and a range of other basic but tricky cloud problems.
Puntos a favor:
Orca's SideScanning technology is excellent. The fact that it doesn't require an agent and is still able to provide as much insight as it does is truly amazing.
Puntos en contra:
Orca needs to figure out how to separate the wheat from the chaff. There are always a lot of vulnerabilities that appear in our console from old kernel versions or something that has already been patched that we're still getting alerts on.
Orca is a one-of-a-kind platform that makes it easy to manage cloud security.
Puntos a favor:
Orca allows collaboration across departments to manage cloud compliance, security, and posture. The UI is simple and easy to navigate. The integrations are straightforward to setup.
Puntos en contra:
Sometimes they roll out new features that don't extend to the rest of the product which can make it hard to use.
Innovative Cloud posture tool that defined a new approach that makes use so easy.
Comentarios: Exceptional, I have already recommended to peers who have also purchased.
Puntos a favor:
Ability to discovery new assets only having role built in parent org. It's visibility also of back plane to reduce false positives. Responsiveness of company to implement change to functionality and UI.
Puntos en contra:
I would say API visibility but that is already in Beta now.
Alternativas consideradas previamente:
Know your entire cloud sprawl in minutes
Comentarios: Product Integration - It's as easy as they sell it. I had it up and running in multiple accounts in no time. Support - Wonderful support and leadership team that cares about their customers. Open API - Rich and open API that allows you to extend and build on top of the product.
Puntos a favor:
The extensibility of the product, and how rich the API is. I can find out almost anything about my environment. Using Orca gives me insight into my entire cloud sprawl. I can get information about malware, open-ingress to EC2 instances, and open source vuln management. The only limit to its use is imagination.
Puntos en contra:
Creating new alerts can be clunky. However, the Orca team is always improving and is currently working on a V2. Navigating the UI can be a bit of a challenge at times when looking for specific info. This is why I often opt for using the API over the UI.
All around great CSPM
Puntos a favor:
easy to use/configure, great insights and automated remediation
Puntos en contra:
does not provide visibility into system activity (like applications in memory)
Agent less solution is the future in security vulnerability and container security monitoring.
Comentarios:
We were trying to solve container security challenges. Actively monitoring what is going on within container. Benefit of agent less solution is two fold, 1) Do not have to install agents on the host machine. 2) Effective in monitoring workloads running in managed containers.
Orca security, ability of side-scanning technology examines block storage out of band via a software-as-a-service (SaaS) platform.
Puntos a favor:
Agent less no installation required. Simple 3 step process to connect account and start monitoring. Extensive deep insight into installed packages within container. Clear categorization of alerts as Imminent compromises, Hazardous, Informational with color coding for clear visibility. Also builds digital asset inventory for tracking different types cloud based assets ex: S3 buckets, EC2 instances. Easy to connect multiple accounts across AWS, Azure, GCP. Under Vulnerability management some of the key features to highlight are Asset Discovery, Asset Tagging, Network Scanning, Patch Management,Vulnerability Assessment,Web Scanning, Risk Management and Policy Management. Couple of the key cloud security features to highlight are Endpoint Management,Threat Intelligence,Vulnerability Management, Intrusion Detection System, Behavioral Analytics, Encryption and Application Security. Ease of integration was one of the reason to consider Orca security solution.
Puntos en contra:
Reporting and user interface are immature, but improving, not real time. This is near real time solution depends on frequency of scanning. VM specific details if consolidated as actionable insights will be very helpful to narrow our focus to relevant issues (ex: identified affected packages within a container is great, giving link to specific patches will be very helpful.
Alternativas consideradas previamente:
Super Easy to Setup and Start Managing Your AWS Risks
Comentarios: Not having to deal with agents combined with direct integration with our ticking system has saved us countless hours of precious engineering time. Because of this, we have gained tremendous value from the product since we can effectively manage AWS risks while focusing on creating more features and values for our customers.
Puntos a favor:
Since Orca Security does not require any agents to install, setup took less than five minutes. We are also use multiple AWS accounts and since setup was simple, within less than thirty minutes, we had a single pane view of most of our AWS risks. In addition, since Orca Security integrates with Atlasssian Jira, with only one click, we could quick open remediation tickets for high risk vulnerabilities.
Puntos en contra:
Although Orca Security offers a ton of AWS coverage, I'd like to see more work with AWS RDS and AWS networking services such as VPC and Security Groups.