Case Study Deskcasestudydesk.com
CybersecuritySourced

Case Study: Grip Security cuts SCA noise by 99% after replacing its incumbent tool with Endor Labs

Grip Security Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
Grip Security
Industry
Cybersecurity
Challenge
The incumbent SCA tool marked findings as reachable that were unreachable in context, wasting developer time.
Headline result
Grip Security reports a 99% noise reduction with Endor Labs, after its previous SCA tool flagged roughly 100 times more reachable vulnerabilities than Endor Labs found on its first scan.

Key results

99%
Noise reduction
after replacing the incumbent SCA tool with Endor Labs
~100x
Fewer reachable vulnerabilities than the old tool claimed
Endor Labs' first scan vs. the incumbent tool

The challenge

Grip Security's previous SCA tool marked many findings as reachable when they were actually unreachable in the application's context. Developers spent time manually evaluating findings to confirm reachability, and had to choose between upgrading packages at the risk of dependency issues or waiting on DevOps investigation.

The solution

Grip replaced its incumbent SCA tool with Endor Labs, which prioritizes findings using call-path analysis to distinguish reachable from unreachable vulnerabilities. The change surfaced the smaller set of findings that were actually exploitable in Grip's code.

Endor Labs delivered on its promise to make SCA way more efficient and bubble up what actually matters much quicker.

IF
Idan Fast
Co-Founder & CTO, Grip Security

The results, in context

Grip Security reported a 99% noise reduction with Endor Labs. Its previous tool had claimed roughly 100 times more reachable vulnerabilities than Endor Labs surfaced on its first scan, and developers gained faster, more accurate prioritization.

Products used

Endor Labs Open Source SCA with Reachability