Clean UI, Effective, Robust
Easy reporting of (mostly true positives) cloud-related alerts. I can just export the data, brush it up, and share. Alerting on unpatched resources and secrets is very good compared to competitors.
The Orca UI is clean and provides a good overview, the alerts are relevant, and the export functionality is very useful.
The compliance functionality is a work in progress.
Know your entire cloud sprawl in minutes
Product Integration - It's as easy as they sell it. I had it up and running in multiple accounts in no time.
Support - Wonderful support and leadership team that cares about their customers.
Open API - Rich and open API that allows you to extend and build on top of the product.
The extensibility of the product, and how rich the API is. I can find out almost anything about my environment. Using Orca gives me insight into my entire cloud sprawl. I can get information about malware, open-ingress to EC2 instances, and open source vuln management. The only limit to its use is imagination.
Creating new alerts can be clunky. However, the Orca team is always improving and is currently working on a V2. Navigating the UI can be a bit of a challenge at times when looking for specific info. This is why I often opt for using the API over the UI.
client-less malware detection
Orca provides me with contextual security risk, it can identify a server with PII file which is exposed to the internet and rate it with a higher severity than a server which is not exposed to the internet.
agentless malware detection and great server/ containers visibility to identify security-related threats
The one thing that I least liked about this software, is that it's not real-time protection
Agent less solution is the future in security vulnerability and container security monitoring.
We were trying to solve container security challenges. Actively monitoring what is going on within container. Benefit of agent less solution is two fold, 1) Do not have to install agents on the host machine. 2) Effective in monitoring workloads running in managed containers.
Orca security, ability of side-scanning technology examines block storage out of band via a software-as-a-service (SaaS) platform.
Agent less no installation required. Simple 3 step process to connect account and start monitoring. Extensive deep insight into installed packages within container. Clear categorization of alerts as Imminent compromises, Hazardous, Informational with color coding for clear visibility. Also builds digital asset inventory for tracking different types cloud based assets ex: S3 buckets, EC2 instances. Easy to connect multiple accounts across AWS, Azure, GCP.
Under Vulnerability management some of the key features to highlight are Asset Discovery, Asset Tagging, Network Scanning, Patch Management,Vulnerability Assessment,Web Scanning, Risk Management and Policy Management.
Couple of the key cloud security features to highlight are Endpoint Management,Threat Intelligence,Vulnerability Management,
Intrusion Detection System, Behavioral Analytics, Encryption and Application Security. Ease of integration was one of the reason to consider Orca security solution.
Reporting and user interface are immature, but improving, not real time. This is near real time solution depends on frequency of scanning. VM specific details if consolidated as actionable insights will be very helpful to narrow our focus to relevant issues (ex: identified affected packages within a container is great, giving link to specific patches will be very helpful.
Super Easy to Setup and Start Managing Your AWS Risks
Not having to deal with agents combined with direct integration with our ticking system has saved us countless hours of precious engineering time. Because of this, we have gained tremendous value from the product since we can effectively manage AWS risks while focusing on creating more features and values for our customers.
Since Orca Security does not require any agents to install, setup took less than five minutes. We are also use multiple AWS accounts and since setup was simple, within less than thirty minutes, we had a single pane view of most of our AWS risks. In addition, since Orca Security integrates with Atlasssian Jira, with only one click, we could quick open remediation tickets for high risk vulnerabilities.
Although Orca Security offers a ton of AWS coverage, I'd like to see more work with AWS RDS and AWS networking services such as VPC and Security Groups.
Wide, Accurate Coverage with No Effort
The best I've had with any vendor.
The agent-less service deployed immediately, with no effort, and replaced three different products. The false positive rate is low. The information presented is easily and immediately actionable. The product has allowed me to reduce effort by 90% of an FTE.
I would like to feed the raw data to our data warehouse, which is not yet possible, though it is coming.
Orca agent-less scanning is best I have seen
Wonderful, they quickly identify vulns and we are able to easily generate Jira tickets to get them assigned to the people that can fix them.
Jira ticket generation, agent-less scanning, Container domination, ease of use and setup, Clean dashboard.
Lack of on-prem/legacy scanning is a real bummer
Agentless Cloud Security
With other tools we struggled with complete visibility into our cloud. Deploying cloud scanners is a hassle as is agents and we had no visibility into our containers. This product provided all of that in the much coveted "single pane of glass."
The fact that the gaining complete visibility into our cloud workload is agentless and that gives us a complete view into our configurations, VM's, containers and security.
At this point everything is headed in the right direction.
Orca - A Revolutionary Tool for Security Governance
Orca implements into an AWS account in minutes and is able to assess the risk of all EBS volumes WITHOUT the need for authentication. This revolutionary side-scanning technology allows for total DevOps and Security governance in cloud accounts where some assets may not follow strict IAM standards.
Orca has a lot of room to do much more than its current feature set. Looking forward to seeing what they do next.
Ease of use, robust results
Instant cloud visibility and value
Very innovative and responsive team, enjoy working with them to improve the product.
The product deployment was simple, quick and easy. The visibility gained for all cloud services was almost instant. The ability to conduct side scanning is a game changer that does not affect production.
Operational reporting was good, but executive reporting lacks in the early days of product development. For the value gained, we are willing to wait.