Ivanti Neurons for RBVM vs Qualys VMDR vs Rapid7 Metasploit comparison

 

Comparison Buyer's Guide

Executive Summary
 

Mindshare comparison

As of July 2024, in the Vulnerability Management category, the mindshare of Ivanti Neurons for RBVM is 0.6%, up from 0.4% compared to the previous year. The mindshare of Qualys VMDR is 20.0%, down from 23.0% compared to the previous year. The mindshare of Rapid7 Metasploit is 3.0%, down from 3.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
Unique Categories:
No other categories found
IT Asset Management
2.7%
Configuration Management Databases
6.5%
No other categories found
 

Featured Reviews

JV
Apr 27, 2022
Useful for vulnerability management with many integrations
We use RiskSense for vulnerability management, and we have many integrations.  The solution is deployed on cloud. We use this solution daily. There are more than 200 people using this solution in my organization Most of the features are similar to what other tools have, but the UIs are quite user…
KD
Sep 17, 2020
Easy to use and scalable but needs to be priced more competitively
Sometimes we face a problem with accessing the tool and not getting an expected result. From a technology point of view, they need to look into this. They need to consider how they can improve tool usability and different scanning options. Sometimes we are facing issues while performing a scan and things are not correctly shown on the GUI. Even as we are doing a task, it may show up as completed, and then something is not visible. Sometimes we face other technical problems. For example, sometimes we can't go to the next page. It's limiting any positive results. The solution needs to be easier to understand and configure. The pricing is a bit on the higher side compared to other products in the industry.
Aqeel Junaid - PeerSpot reviewer
Mar 14, 2024
Helps find vulnerabilities in a system to determine whether the system needs to be upgraded
I've been using Rapid7 Metasploit to create vulnerabilities and test exploits. I can create malicious Word documents through the Rapid7 Metasploit framework for testing purposes. I can create a backdoor through the solution to test a web server or a vulnerable machine The most valuable features…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Most of the features are similar to what other tools have, but the UIs are quite user friendly. A beginner could use it."
"The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network."
"I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even if tags aren't made."
"The process of defining and discovering scans is organized efficiently."
"There are fewer false positives when using this solution."
"It's really beneficial for scanning and interacting with the agent."
"The most valuable feature is the connection of threat intelligence information with identified vulnerabilities, which means you can prioritize vulnerabilities according to actual attacks."
"What I like about Qualys VM is the dashboard presentation. It's very good."
"Great web application security for scanning."
"It's not possible to do penetration testing without being very proficient in Metasploit."
"The Search Engineering feature is good."
"The option to generate phishing emails has proven to be very valuable in understanding the behavior of users."
"It is scalable. It's in line with our needs."
"Stability-wise, I rate the solution a nine out of ten...Scalability-wise, I rate the solution a nine out of ten."
"The greatest advantage of Rapid7 Metasploit is that it is the only system that can directly exploit vulnerabilities on the Metasploit platform."
"The tool's most useful feature for penetration testing is its automation capabilities. With the professional edition, you can upload the results from Nessus in the Rapid7 Metasploit solution portal."
"I use Rapid7 Metasploit for payload generation and Post-Exploitation."
 

Cons

"I would also like to see more integrations, plugins, and user-friendly automation, similar to the multiple integration scripts that Rapid7 has."
"The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement."
"The disadvantage of working with Qualys is that the graphical interface is quite outdated."
"They should make it accessible for more operating systems."
"Qualys could improve the inbuilt dashboards."
"They're still evolving their platform in terms of reporting capabilities."
"The reporting in this solution can be improved."
"It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating."
"If anything, I would like to see the user interface modernized a bit more."
"We'd like them to offer better coverage of malware."
"If your company's patch is not up to date, but you have other detection or defense solutions such as endpoint detection and response and antivirus software, the product exploit may not work effectively. This is because its exploit database update process is slow and not real-time. For zero-day vulnerabilities or new security threats, relying on Rapid7 Metasploit alone may not be effective."
"Rapid7 Metasploit can add a GUI feature because it is only available online."
"It is necessary to add some training materials and a tutorial for beginners."
"At the time I was using it, the graphical user interface needed some improvements."
"The open-source version has reporting limitations. You need to develop these capabilities yourself. Built-in reporting is an excellent feature for penetration testing, but it isn't a must-have. The solution could also cover more vulnerabilities. Metasploit has around 10,000 exploits in its library, but more is always better."
"Rapid7 Metasploit could be made easier for new users to learn."
"Metasploit cannot be installed on a machine with an antivirus."
 

Pricing and Cost Advice

Information not available
"Qualys Virtual Scanner Appliance isn't expensive right now. But the price for their product bundles could be better."
"They have recently changed the pricing model, which is now better than it was before."
"Qualys VM is reasonably priced."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"The pricing is very competitive."
"The product is more expensive than that of any other vendor."
"We do see over $100,000 in terms of price, for mid-size programs. You likely will pay more than $100,000 without any discount. It is a bit pricey."
"The solution is reasonably priced for the value it provides."
"We pay monthly. The pricing is reasonable."
"Rapid7 Metasploit is an open-source solution."
"It is a reasonably priced solution. I would rate it from five out of ten."
"The pricing structure involves a one-time purchase cost of approximately twenty thousand dollars or euros for all customers."
"It is expensive. Our license expired, and our company is not thinking to renew because of our budget."
"On a scale of one to ten, where one is cheap and ten is expensive, I rate the product's pricing a six. So it's fairly priced."
"Rapid7 Metasploit is cheaper than Tenable.io Vulnerability Management."
"I have used the free version of Rapid7 Metasploit."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
790,637 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
8%
Healthcare Company
8%
Insurance Company
8%
Educational Organization
33%
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
6%
Computer Software Company
18%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are man...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
We have an annual contract for Qualys VMDR. I believe it's for either two years or five years.
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What needs improvement with Rapid7 Metasploit?
Rapid7 Metasploit could be made easier for new users to learn.
 

Also Known As

RiskSense
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
Metasploit
 

Overview

 

Sample Customers

Care First, City of Alburquerque, Electric Company El Paso, State of Arizona, Washington Gas
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Tenable, Wiz, SentinelOne and others in Vulnerability Management. Updated: June 2024.
790,637 professionals have used our research since 2012.