Try our new research platform with insights from 80,000+ expert users

Qualys VMDR vs Rapid7 Metasploit comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 29, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Qualys VMDR enhances security by detecting vulnerabilities, improving asset management, reducing breaches, and offering 30% time-cost savings.
No sentiment score available
We saw a return on investment through significant savings in time, money, and resources.
Metasploit has helped save time, especially with testing websites or VIPD projects.
 

Customer Service

Sentiment score
6.7
Qualys VMDR's customer service is responsive and efficient, though some users report delays in response speed and troubleshooting.
Sentiment score
7.8
Rapid7 Metasploit's customer service is inconsistent, with varied support across versions, sometimes slow but generally active in development.
The response time takes a while.
The technical support provided by Qualys is pretty good.
When reaching out via email, they reply quickly.
 

Scalability Issues

Sentiment score
8.0
Qualys VMDR offers scalable, flexible cloud-based architecture, praised for efficiency despite potential cost increases with higher usage.
Sentiment score
7.3
Users find Rapid7 Metasploit adequate for small teams but suggest improvements for better automation and larger operations.
Scalability depends on the license and the number of assets being monitored.
Qualys VMDR can handle scalability, although increasing the inventory can raise the licensing costs.
Metasploit can handle big projects and is already prepared for them.
 

Stability Issues

Sentiment score
8.0
Qualys VMDR is praised for stability and reliability, efficiently managing large scans with minor issues quickly resolved.
Sentiment score
9.3
Rapid7 Metasploit is stable and robust, with improved updates, earning user ratings of seven to nine out of ten.
I have never faced any technical issues or downtimes.
 

Room For Improvement

Qualys VMDR needs better reporting, UI, integration, asset management, reduced false positives, faster support, and enhanced features.
Rapid7 Metasploit faces slow updates, high resource use, needs better integration, broader coverage, user-friendliness, and improved support.
It does not automate patching unless the patch management module is purchased separately.
If AI features were integrated, it could enhance the capabilities significantly.
The response time of technical support takes a while.
The database is not always updated with the latest vulnerabilities or zero-day exploits.
 

Setup Cost

Qualys VMDR pricing is higher, flexible, and negotiable, with costs based on company size, assets, and features.
Buyers have mixed views on Rapid7 Metasploit pricing; some find it affordable, others choose open-source due to cost.
I would rate the pricing between seven to eight out of ten.
I have a notion that Qualys might be more expensive than Rapid7.
 

Valuable Features

Qualys VMDR excels in vulnerability management with automatic detection, seamless integration, real-time dashboards, and user-friendly deployment features.
Rapid7 Metasploit offers extensive modules and automation, enhancing penetration testing with graphical interfaces, PostgreSQL integration, and network scanning.
We use it daily to fix vulnerabilities by connecting with infrastructure to remediate.
Qualys VMDR offers a one-stop solution for monitoring and reporting.
I like the automated report generation and vulnerability report generation.
The ability to automate website testing and integrate it into my script makes it even more efficient.
 

Categories and Ranking

Qualys VMDR
Ranking in Vulnerability Management
2nd
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
92
Ranking in other categories
IT Asset Management (4th), Configuration Management Databases (3rd), Container Security (12th), Risk-Based Vulnerability Management (3rd)
Rapid7 Metasploit
Ranking in Vulnerability Management
21st
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
19
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of December 2024, in the Vulnerability Management category, the mindshare of Qualys VMDR is 11.4%, down from 13.5% compared to the previous year. The mindshare of Rapid7 Metasploit is 1.9%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
 

Featured Reviews

Harold Jensen - PeerSpot reviewer
Good visibility but expensive and needs better support
Support: It's often overseas and often following a script, basically asking us to redo what we opened the case with. Multiple APIs: There seems to be a lack of easy onboarding into Qualys. We had to use manual inputs and some API calls to get items in place. Dashboard: It is very rudimentary with very little customization. The Qualys Scripting Language (QSL) works differently in different Qualys modules, so when you get it working in one area you have to modify the syntax in others. User account management: We often have to give users more rights than needed just to give them what they need. Integration with the various Qualys Modules: You can tell the UI is different based on of the different teams that created them. QSL syntax same in all modules Responsiveness of some of the components: They time out, you get a blank screen, etc. Backend updates between the various modules: You update connectors and information takes a few minutes to show in VMDR or Global Asset View Connectors: Connectors have a throttling issue with AWS which causes them to frequently fail unless you manually run them again.
Aqeel Junaid - PeerSpot reviewer
Helps find vulnerabilities in a system to determine whether the system needs to be upgraded
The solution's exploit development functionality was easy to use and had all the scenarios I could use to run my security assessment. Since the solution has been updated regarding new malware, it gives data protection for security professionals. Rapid7 Metasploit is a good exploit tool, and users need to know what they're doing while using the solution. The solution provides perfect effectiveness in simulating real-world attacks for training purposes. Overall, I rate the solution a nine out of ten.
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
36%
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
6%
Computer Software Company
18%
Financial Services Firm
10%
Manufacturing Company
9%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are many applications. We also use the solution for asset management per team, and the ...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even ...
What is your experience regarding pricing and costs for Qualys VMDR?
For smaller enterprises, the pricing is on the pricier side. However, for larger enterprises, it's considered okay. I would rate the pricing between seven to eight out of ten.
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What is your experience regarding pricing and costs for Rapid7 Metasploit?
I am not very sure about the pricing. It falls into an intermediate range. However, I am not involved with the partition part.
What needs improvement with Rapid7 Metasploit?
The database is not always updated with the latest vulnerabilities or zero-day exploits. If a vulnerability arises a month or two ago, it might not be included in the database, which is something I...
 

Also Known As

Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
Metasploit
 

Learn More

 

Overview

 

Sample Customers

Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Qualys VMDR vs. Rapid7 Metasploit and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.