Try our new research platform with insights from 80,000+ expert users

Ivanti Neurons for RBVM vs Qualys VMDR vs Rapid7 Metasploit comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of January 2025, in the Vulnerability Management category, the mindshare of Ivanti Neurons for RBVM is 0.3%, down from 0.5% compared to the previous year. The mindshare of Qualys VMDR is 11.1%, down from 13.7% compared to the previous year. The mindshare of Rapid7 Metasploit is 1.9%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
 

Featured Reviews

Anon127 - PeerSpot reviewer
Useful for vulnerability management with many integrations
We use RiskSense for vulnerability management, and we have many integrations.  The solution is deployed on cloud. We use this solution daily. There are more than 200 people using this solution in my organization Most of the features are similar to what other tools have, but the UIs are quite user…
Harold Jensen - PeerSpot reviewer
Good visibility but expensive and needs better support
Support: It's often overseas and often following a script, basically asking us to redo what we opened the case with. Multiple APIs: There seems to be a lack of easy onboarding into Qualys. We had to use manual inputs and some API calls to get items in place. Dashboard: It is very rudimentary with very little customization. The Qualys Scripting Language (QSL) works differently in different Qualys modules, so when you get it working in one area you have to modify the syntax in others. User account management: We often have to give users more rights than needed just to give them what they need. Integration with the various Qualys Modules: You can tell the UI is different based on of the different teams that created them. QSL syntax same in all modules Responsiveness of some of the components: They time out, you get a blank screen, etc. Backend updates between the various modules: You update connectors and information takes a few minutes to show in VMDR or Global Asset View Connectors: Connectors have a throttling issue with AWS which causes them to frequently fail unless you manually run them again.
Mani Bommisetty - PeerSpot reviewer
Comprehensive insights with robust vulnerability detection and streamlined alert management
Rapid7 has a significant advantage in providing a clear picture of my environment. It provides insight and incident detection response capabilities. When deployed with the same agent in servers or endpoints, it identifies vulnerabilities and monitors data transmission to external sources. Rapid7 offers comprehensive features within one platform, eliminating the need to integrate multiple tools to see all alerts in one place.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Most of the features are similar to what other tools have, but the UIs are quite user friendly. A beginner could use it."
"Continuous monitoring is a crucial feature that we use more frequently."
"Qualys has a continuous endpoint monitoring feature for agent-based scanning. Once you deploy the solution, it monitors everything that is happening every 30 minutes. Then, if there are any vulnerabilities, they are reported."
"Qualys VMDR provides a real-time response and reporting feature, which is excellent."
"I find the solution's dashboard interesting...The response time is fine. You can pull up reports without dragging or consuming bandwidth."
"The most valuable feature of the solution is the external channel."
"The solution is easy to use."
"It's very configurable to adjust impact to systems."
"The product's patch management is excellent for keeping our critical servers and third-party applications updated efficiently."
"All of the features are great."
"The most valuable features of the solution are the scripts, the modules, and the tools that the Rapid7 Metasploit framework has."
"It's not possible to do penetration testing without being very proficient in Metasploit."
"I don't have any other tools like it, and I always use it when I'm doing a pen test. Metasploit is a great solution for penetration testing,"
"The most valuable feature for us is the support for testing Linux-based web server components."
"The reporting on the solution is good."
"Rapid7 Metasploit is a useful product."
"The option to generate phishing emails has proven to be very valuable in understanding the behavior of users."
 

Cons

"I would also like to see more integrations, plugins, and user-friendly automation, similar to the multiple integration scripts that Rapid7 has."
"Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."
"The reporting section needs improvement as running reports can take several hours."
"The response time of technical support takes a while."
"It is more expensive vs. other products on the market."
"The only improvement I can think of is on the implementation side. At times it is a bit slow."
"The IoT scan is not great."
"It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating."
"There are scenarios where a vulnerability is reported once yet not in subsequent scans, even if we have not fixed it."
"It is necessary to add some training materials and a tutorial for beginners."
"The solution is not very scalable, it does not provide any automation to be able to scale it."
"The solution should improve the responsiveness of its live technical support."
"The reporting feature needs improvement."
"Rapid7 Metasploit could be made easier for new users to learn."
"The reporting feature needs improvement. The time taken to fetch reports based on the number of events can be extensive, unlike Tenable, which is more user-friendly and faster."
"At the time I was using it, the graphical user interface needed some improvements."
"I think areas with shortcomings that need improvement are more integration and automation."
 

Pricing and Cost Advice

Information not available
"Usually every implementation is different and the quote is in function of number of assets."
"An annual license for a single scanner costs around $3,000."
"It is more expensive than other products on the market."
"It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost."
"Qualys is a pay-as-you-go model, so there's flexibility to the pricing."
"They have recently changed the pricing model, which is now better than it was before."
"There are no additional fees in addition to the standard licensing fees."
"It is different for every company, but for us, it's every three years."
"It is expensive. Our license expired, and our company is not thinking to renew because of our budget."
"The great advantage with Rapid7 Metasploit, of course, is that it's free."
"I have used the free version of Rapid7 Metasploit."
"Rapid7 Metasploit is cheaper than Tenable.io Vulnerability Management."
"Rapid7 Metasploit is an open-source solution."
"It is a reasonably priced solution. I would rate it from five out of ten."
"I use the open-source version of this product. Pricing is not relevant."
"We pay monthly. The pricing is reasonable."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
831,563 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Manufacturing Company
13%
Financial Services Firm
9%
Healthcare Company
7%
Educational Organization
36%
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
6%
Computer Software Company
19%
Financial Services Firm
10%
Manufacturing Company
9%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are man...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
For smaller enterprises, the pricing is on the pricier side. However, for larger enterprises, it's considered okay. I...
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What needs improvement with Rapid7 Metasploit?
The reporting feature needs improvement. The time taken to fetch reports based on the number of events can be extensi...
 

Also Known As

RiskSense
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
Metasploit
 

Overview

 

Sample Customers

Care First, City of Alburquerque, Electric Company El Paso, State of Arizona, Washington Gas
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Tenable, Qualys, Wiz and others in Vulnerability Management. Updated: December 2024.
831,563 professionals have used our research since 2012.