Skip to content

Greenbone

A German vulnerability management vendor and steward of the open-source OpenVAS scanning engine, operating as Greenbone AG and providing commercial vulnerability management appliances and feeds built on that open-source foundation since 2008.

Visit Website ↗ + Add to Compare
48/100Emerging / Unranked

Overview

Greenbone, founded in Osnabrück, Germany in 2008, is best known as the commercial steward of OpenVAS (Open Vulnerability Assessment Scanner), one of the most widely used open-source vulnerability scanning engines. The company, structured as a German stock corporation (Greenbone AG), sells commercial vulnerability management products and continuously-updated vulnerability test feeds built on top of the open-source core.

Greenbone’s open-source-plus-commercial model gives it a distinct trust and transparency position in the vulnerability scanning market — security teams and researchers can inspect the scanning engine itself rather than relying entirely on a closed-source black box — while the commercial layer funds continued development of new vulnerability test signatures and enterprise features like appliance management and compliance reporting.

Innovation Matrix Assessment

Innovation Velocity 5/10

Continuous open-source vulnerability-feed updates provide steady, ongoing iteration, though the core scanning approach has evolved incrementally since 2008.

Operational Value 6/10

A transparent, auditable scanning engine backed by commercial support and continuously updated test feeds is genuinely useful for security operations teams.

Market Momentum 4/10

No major recent funding events were found; growth appears steady and tied to its established open-source community rather than rapid commercial expansion.

Category Disruption 3/10

Strengthens and commercializes an established open-source vulnerability scanning approach rather than introducing a fundamentally new methodology.

Real-World Efficacy 6/10

Nearly two decades as the steward of one of the most widely deployed open-source vulnerability scanners is substantial, independently observable real-world evidence.

Enduring Relevance 5/10

Vulnerability scanning remains a foundational security control, though the category increasingly competes with more automated, AI-prioritized exposure-management platforms.

Why CISOs Should Care

CISOs who value auditability and want to avoid vendor lock-in get a vulnerability management platform built on a transparent, widely-vetted open-source scanning engine, backed by a commercial vendor providing enterprise support, feeds, and appliances.

What Makes It Different

Greenbone's open-source OpenVAS foundation, developed in the open and used by thousands of independent deployments and other vendors' tools, differentiates it from purely closed-source commercial vulnerability scanners.

The Matrix Verdict

48/100 — EMERGING / UNRANKED

A durable, transparent vulnerability-scanning vendor whose open-source foundation gives it unusual auditability and community trust; solid operational and relevance value, though limited disruption given its focus on strengthening an established scanning approach rather than reinventing vulnerability management.

Editorial Note: Claims vs. Verified Findings

OpenVAS stewardship and 2008 founding are independently well-documented across the open-source community and the company's own site; specific commercial customer-count claims were not independently verified.

Sources