Try our new research platform with insights from 80,000+ expert users

Qualys VMDR vs Rapid7 Metasploit comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys VMDR
Ranking in Vulnerability Management
2nd
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
92
Ranking in other categories
IT Asset Management (4th), Configuration Management Databases (2nd), Container Security (12th), Risk-Based Vulnerability Management (3rd)
Rapid7 Metasploit
Ranking in Vulnerability Management
19th
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
20
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2025, in the Vulnerability Management category, the mindshare of Qualys VMDR is 11.1%, down from 13.7% compared to the previous year. The mindshare of Rapid7 Metasploit is 1.9%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
 

Featured Reviews

Harold Jensen - PeerSpot reviewer
Good visibility but expensive and needs better support
Support: It's often overseas and often following a script, basically asking us to redo what we opened the case with. Multiple APIs: There seems to be a lack of easy onboarding into Qualys. We had to use manual inputs and some API calls to get items in place. Dashboard: It is very rudimentary with very little customization. The Qualys Scripting Language (QSL) works differently in different Qualys modules, so when you get it working in one area you have to modify the syntax in others. User account management: We often have to give users more rights than needed just to give them what they need. Integration with the various Qualys Modules: You can tell the UI is different based on of the different teams that created them. QSL syntax same in all modules Responsiveness of some of the components: They time out, you get a blank screen, etc. Backend updates between the various modules: You update connectors and information takes a few minutes to show in VMDR or Global Asset View Connectors: Connectors have a throttling issue with AWS which causes them to frequently fail unless you manually run them again.
Mani Bommisetty - PeerSpot reviewer
Comprehensive insights with robust vulnerability detection and streamlined alert management
Rapid7 has a significant advantage in providing a clear picture of my environment. It provides insight and incident detection response capabilities. When deployed with the same agent in servers or endpoints, it identifies vulnerabilities and monitors data transmission to external sources. Rapid7 offers comprehensive features within one platform, eliminating the need to integrate multiple tools to see all alerts in one place.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of Qualys VMDR include patch management and the use of virtual scanners to scan appliances and devices, especially those provided by vendors where we cannot manage them ourselves."
"It's very configurable to adjust impact to systems."
"Intuitive and easy to use."
"Qualys has a continuous endpoint monitoring feature for agent-based scanning. Once you deploy the solution, it monitors everything that is happening every 30 minutes. Then, if there are any vulnerabilities, they are reported."
"The initial setup was good. We didn't have any problems with it."
"Authenticated scans provide different options, including those using or not using the FactSet and adding option profiles."
"I like Qualys because it is a very complete product, more so than Tenable."
"Performs automated, regular scans in the network."
"I use Rapid7 Metasploit for payload generation and Post-Exploitation."
"The option to generate phishing emails has proven to be very valuable in understanding the behavior of users."
"The most valuable features of Metasploit include its powerful capabilities for exploitation and scanning."
"The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers."
"The Search Engineering feature is good."
"All of the features are great."
"The most valuable feature for us is the support for testing Linux-based web server components."
"Stability-wise, I rate the solution a nine out of ten...Scalability-wise, I rate the solution a nine out of ten."
 

Cons

"The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions."
"Qualys VMDR identifies vulnerabilities and suggests fixes. However, it does not automate patching unless the patch management module is purchased separately."
"The tool needs to improve the adding assets and report generation features. I would like to see the policy scan of offline appliances in the product's future releases."
"Qualys could improve the inbuilt dashboards."
"I would like to see this solution simplified to work more easily in a multi-cloud environment."
"The IoT scan is not great."
"From the application security perspective, Qualys has a way to go."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"The database is not always updated with the latest vulnerabilities or zero-day exploits. If a vulnerability arises a month or two ago, it might not be included in the database, which is something I would like to see improved."
"The open-source version has reporting limitations. You need to develop these capabilities yourself. Built-in reporting is an excellent feature for penetration testing, but it isn't a must-have. The solution could also cover more vulnerabilities. Metasploit has around 10,000 exploits in its library, but more is always better."
"I would like to see more capabilities, more functions, and more features. More types of attack vectors."
"The solution is not very scalable, it does not provide any automation to be able to scale it."
"The database is not always updated with the latest vulnerabilities or zero-day exploits."
"The solution is not user-friendly and has room for improvement."
"There are numerous outdated exploits in their database that should be updated."
"Advanced Infrastructure should be implemented in the next release for better orchestration."
 

Pricing and Cost Advice

"It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost."
"Qualys is cheaper and more affordable than other solutions."
"The solution is costly."
"There are no additional fees in addition to the standard licensing fees."
"The pricing and licensing for Qualys could be improved."
"Qualys VM is quite expensive. It's a subscription-based license, and it's yearly. Right now, it's open for me, and I don't have any limitations or caps on the licenses. They are seeing if the product is viable for 4500 users. I can add as much as I want, and at the end of the subscription, they'll let me know how many licenses were actually used and bill me accordingly. On a scale from one to five, I would give their pricing a three. It's still expensive."
"Qualys Virtual Scanner Appliance isn't expensive right now. But the price for their product bundles could be better."
"The price is very reasonable."
"I have used the free version of Rapid7 Metasploit."
"The cost is approximately $15 per device."
"The pricing structure involves a one-time purchase cost of approximately twenty thousand dollars or euros for all customers."
"Rapid7 Metasploit is an open-source solution."
"I use the open-source version of this product. Pricing is not relevant."
"We pay monthly. The pricing is reasonable."
"There are two versions available, one of which is the Pro version, and the other is the free version."
"It is a reasonably priced solution. I would rate it from five out of ten."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
36%
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
6%
Computer Software Company
19%
Financial Services Firm
10%
Manufacturing Company
9%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are many applications. We also use the solution for asset management per team, and the ...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even ...
What is your experience regarding pricing and costs for Qualys VMDR?
For smaller enterprises, the pricing is on the pricier side. However, for larger enterprises, it's considered okay. I would rate the pricing between seven to eight out of ten.
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What needs improvement with Rapid7 Metasploit?
The reporting feature needs improvement. The time taken to fetch reports based on the number of events can be extensive, unlike Tenable, which is more user-friendly and faster. Additionally, networ...
 

Also Known As

Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
Metasploit
 

Learn More

 

Overview

 

Sample Customers

Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Qualys VMDR vs. Rapid7 Metasploit and other solutions. Updated: January 2025.
831,265 professionals have used our research since 2012.