Hewlett Packard Enterprise (HPE) is a U.S.-based global provider of AST products and services under the Fortify brand. HPE offers Static Code Analyzer (SAST), WebInspect (DAST and IAST), Software Security Center (its console) and Application Defender (monitoring and RASP). HPE provides its AST as a product as well as in the cloud, with Fortify on Demand. DevInspect combines HPE's SAST with real-time, in-line vulnerability detection via a spell-checker (called Security Assistant) in the Eclipse IDE. Security Assistant highlights vulnerable code as the developer programs. It is also available in other versions and license models of the SAST solution.
In September 2016, HPE announced that it would be spinning off its software group to Micro Focus, including the Fortify portfolio, in addition to its IT operations management, security, data analytics, and information management and governance software. The deal is expected to finalize during mid-2017 and the Fortify brand is expected to be maintained.
On the product side, HPE's efforts have included employing machine learning with crowdsourced and customer historical results data to reduce false positives, as well as integration of Swagger-supported REST APIs to support security testing.
HPE's AST offerings should be considered by enterprises looking for a comprehensive set of AST capabilities, either as a product or service, or both combined, with enterprise-class reporting and integration capabilities.
STRENGTHS
HPE Fortify is a well-known brand worldwide. It very frequently appears on clients' shortlists, particularly where multiple testing technologies are desired, and was the first AST vendor to provide capabilities in SAST, DAST and IAST.
HPE's SAST has the broadest language support of any of the SAST providers, and its WebInspect IAST agent for Java and .NET is included at no cost for WebInspect DAST tool customers.
HPE has one of the strongest SDLC integrations and includes innovative features in this space, such as DevInspect and Security Assistant.
HPE has a comprehensive set of enterprise capabilities, such as role-based access control (RBAC), full authentication integration, extensive WAF integration and its own SCA capabilities, as well as integration with Sonatype and Black Duck.