Ivanti Neurons for RBVM vs Qualys VMDR vs Rapid7 Metasploit comparison

 

Comparison Buyer's Guide

Executive Summary
 

Mindshare comparison

As of July 2024, in the Vulnerability Management category, the mindshare of Ivanti Neurons for RBVM is 0.4%, up from 0.4% compared to the previous year. The mindshare of Qualys VMDR is 17.2%, up from 16.2% compared to the previous year. The mindshare of Rapid7 Metasploit is 2.5%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
Unique Categories:
No other categories found
IT Asset Management
2.7%
Configuration Management Databases
6.5%
No other categories found
 

Featured Reviews

JV
Apr 27, 2022
Useful for vulnerability management with many integrations
We use RiskSense for vulnerability management, and we have many integrations.  The solution is deployed on cloud. We use this solution daily. There are more than 200 people using this solution in my organization Most of the features are similar to what other tools have, but the UIs are quite user…
Ruan Kotze - PeerSpot reviewer
Aug 8, 2023
Helped us quickly remediate vulnerabilities thanks to its automation and ease of use
Our use cases are primarily on-premises vulnerability management and remediation, external attack surface management and vulnerability scanning The benefits I've seen are twofold. The biggest benefit is from a security operations perspective, where we are able to drive our security posture…
Aqeel Junaid - PeerSpot reviewer
Mar 14, 2024
Helps find vulnerabilities in a system to determine whether the system needs to be upgraded
I've been using Rapid7 Metasploit to create vulnerabilities and test exploits. I can create malicious Word documents through the Rapid7 Metasploit framework for testing purposes. I can create a backdoor through the solution to test a web server or a vulnerable machine The most valuable features…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Most of the features are similar to what other tools have, but the UIs are quite user friendly. A beginner could use it."
"Qualys VM has allowed us to know the vulnerabilities we need to prioritize based on the threat levels and the possible impact if there's an intrusion."
"It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily."
"Qualys VM's best feature is vulnerability management."
"It is a simple solution that makes scanning easy. You just give it a scheduled task, and it will do everything for you."
"This is one of the best products I have worked with so far. I like the power of Qualys, and it's a better solution because you can scan a compact file, a BIT file, or batch files. The product already knows what's happening inside, and you don't need to expand the package. Tenable will do the same thing, but you need to have a package issuance claim. With Qualys, we can immediately understand the file, even a compact file. If there's some kind of discovery or incident, you will know what happened in the environment."
"Technical support is great and we've never really had a problem."
"I find Qualys VM very robust, and it's very useful for vulnerability management and patch management. The value that it brings to my environment is economies of scale. There is no limitation on adding any endpoints. You go by the rule, and it's added once another endpoint is added to our environment. It's automatically installed, and it's less work from our end. It frees up my license automatically if I don't need an endpoint or if my machine is decommissioned. I like the dashboard displays because I don't see any duplication. The most important part is vulnerability management and prioritization. Unlike Symantec, it shows the kind of vulnerability I would want to patch first. It provides a holistic view of the kind of vulnerabilities and the ones I should remediate first. I don't have to do a scan; it just brings up those critical kinds of vulnerabilities like zero-day vulnerabilities and tells me to prioritize them. You have to prioritize these vulnerabilities first and go on with the rest. The dashboard shows me the ones that have been fixed, so I don't have to complete an aging report. The user experience and the graphical interface are good. As it's user-friendly and understandable on an executive level, it brings real value. We also use this solution because it's robust and flexibile."
"The reporting functionality is great."
"It is scalable. It's in line with our needs."
"The greatest advantage of Rapid7 Metasploit is that it is the only system that can directly exploit vulnerabilities on the Metasploit platform."
"Stability-wise, I rate the solution a nine out of ten...Scalability-wise, I rate the solution a nine out of ten."
"It contains almost all the available exploits and payloads."
"It allows us to concentrate solely on identified vulnerabilities without the hassle of additional setup."
"The tool's most useful feature for penetration testing is its automation capabilities. With the professional edition, you can upload the results from Nessus in the Rapid7 Metasploit solution portal."
"The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers."
"The option to generate phishing emails has proven to be very valuable in understanding the behavior of users."
 

Cons

"I would also like to see more integrations, plugins, and user-friendly automation, similar to the multiple integration scripts that Rapid7 has."
"Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time."
"Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."
"We face issues while scanning multiple assets."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution."
"Finding things in management can be quite difficult."
"Qualys VM's scanner doesn't pick up every vulnerability, so we have to use multiple scanners to cover that gap."
"The reporting and the GUI need improvements."
"The solution is not very scalable, it does not provide any automation to be able to scale it."
"The solution should improve the responsiveness of its live technical support."
"The initial setup was a bit "tweaky" for the open-source version."
"Better automation capabilities would be an improvement."
"I would like to see more capabilities, more functions, and more features. More types of attack vectors."
"Advanced Infrastructure should be implemented in the next release for better orchestration."
"Rapid7 Metasploit can add a GUI feature because it is only available online."
"Rapid7 Metasploit could be made easier for new users to learn."
 

Pricing and Cost Advice

Information not available
"The solution is costly."
"In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"The solution is expensive."
"There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price."
"It is different for every company, but for us, it's every three years."
"Qualys VM is quite expensive. It's a subscription-based license, and it's yearly. Right now, it's open for me, and I don't have any limitations or caps on the licenses. They are seeing if the product is viable for 4500 users. I can add as much as I want, and at the end of the subscription, they'll let me know how many licenses were actually used and bill me accordingly. On a scale from one to five, I would give their pricing a three. It's still expensive."
"Qualys is cheaper and more affordable than other solutions."
"It is a reasonably priced solution. I would rate it from five out of ten."
"The great advantage with Rapid7 Metasploit, of course, is that it's free."
"The pricing structure involves a one-time purchase cost of approximately twenty thousand dollars or euros for all customers."
"There are two versions available, one of which is the Pro version, and the other is the free version."
"We pay monthly. The pricing is reasonable."
"I have used the free version of Rapid7 Metasploit."
"I use the open-source version of this product. Pricing is not relevant."
"Rapid7 Metasploit is cheaper than Tenable.io Vulnerability Management."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
790,916 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
9%
Healthcare Company
8%
Insurance Company
8%
Educational Organization
33%
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
6%
Computer Software Company
18%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are man...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
We have an annual contract for Qualys VMDR. I believe it's for either two years or five years.
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What needs improvement with Rapid7 Metasploit?
Rapid7 Metasploit could be made easier for new users to learn.
 

Also Known As

RiskSense
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
Metasploit
 

Overview

 

Sample Customers

Care First, City of Alburquerque, Electric Company El Paso, State of Arizona, Washington Gas
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Tenable, Wiz, SentinelOne and others in Vulnerability Management. Updated: July 2024.
790,916 professionals have used our research since 2012.