Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightVM vs Rapid7 Metasploit comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightVM
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Risk-Based Vulnerability Management (4th)
Rapid7 Metasploit
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
20
Ranking in other categories
Vulnerability Management (19th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Rapid7 InsightVM is designed for Risk-Based Vulnerability Management and holds a mindshare of 20.7%, up 15.0% compared to last year.
Rapid7 Metasploit, on the other hand, focuses on Vulnerability Management, holds 1.9% mindshare, up 1.9% since last year.
Risk-Based Vulnerability Management
Vulnerability Management
 

Featured Reviews

Shakeel Ahmad - PeerSpot reviewer
Brilliant audit report and scorecard but scans often get blocked by firewalls
The solution cannot scan third-party tools that have firewalls within them. The firewalls detect and block the solution. Conversely, Nexus is able to bypass firewalls because it has low detectability. We use Nexus when the solution cannot bypass a firewall. The solution can scan 60% of the time but Nexus can scan 90% of the time. The solution needs to improve its vulnerability design to include CVC results. Nexus has a good, long range and a good database for finding CVC numbers. We need this level of security detail but the solution does not seem to provide it.
Mani Bommisetty - PeerSpot reviewer
Comprehensive insights with robust vulnerability detection and streamlined alert management
Rapid7 has a significant advantage in providing a clear picture of my environment. It provides insight and incident detection response capabilities. When deployed with the same agent in servers or endpoints, it identifies vulnerabilities and monitors data transmission to external sources. Rapid7 offers comprehensive features within one platform, eliminating the need to integrate multiple tools to see all alerts in one place.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have been in contact with technical support and they are not bad."
"InsightVM offers a robust platform for identifying, prioritizing, and addressing vulnerabilities across an organization's IT infrastructure."
"The most valuable feature for us is the different types of reporting it provides."
"There are many integrations with things like the VMware NSX that are great, the reporting is really solid."
"When you connect any new device to the network, Rapid7 has the ability to detect the new device immediately. It can scan that device to detect if it has any vulnerability. It tells you what is vulnerable and what has been misconfigured. It also tells you what is the risk of that misconfiguration or lack of patches and how to resolve the problem."
"You can bring in and get online to do reports fairly quickly,"
"The solution scales well."
"The most valuable features of the solution are the agent and the scanning."
"I don't have any other tools like it, and I always use it when I'm doing a pen test. Metasploit is a great solution for penetration testing,"
"The option to generate phishing emails has proven to be very valuable in understanding the behavior of users."
"Rapid7 has a significant advantage in providing a clear picture of my environment."
"It's not possible to do penetration testing without being very proficient in Metasploit."
"Rapid7 offers comprehensive features within one platform, eliminating the need to integrate multiple tools to see all alerts in one place."
"The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers."
"The greatest advantage of Rapid7 Metasploit is that it is the only system that can directly exploit vulnerabilities on the Metasploit platform."
"It is scalable. It's in line with our needs."
 

Cons

"The reporting is very bad when you compare it with other vulnerability assessment tools."
"The team needs to improve the speed and focus on the new bandwidth feed. Sometimes, it takes a while to scan, especially with new updates."
"Rapid7 InsightVM should improve its threat intelligence."
"The authentication scan is not working."
"Rapid7 InsightVM could be easier to use for those who are using it for the first time."
"InsightVM is getting a little stale and is in danger of falling behind its competitors."
"The drawback is that it is still not a fully SaaS solution, so you must deploy a console."
"We have some issues with how it scans patches."
"I think areas with shortcomings that need improvement are more integration and automation."
"The reporting feature needs improvement. The time taken to fetch reports based on the number of events can be extensive, unlike Tenable, which is more user-friendly and faster."
"Rapid7 Metasploit can add a GUI feature because it is only available online."
"The database is not always updated with the latest vulnerabilities or zero-day exploits."
"The open-source version has reporting limitations. You need to develop these capabilities yourself. Built-in reporting is an excellent feature for penetration testing, but it isn't a must-have. The solution could also cover more vulnerabilities. Metasploit has around 10,000 exploits in its library, but more is always better."
"The initial setup was a bit "tweaky" for the open-source version."
"I would like to see more capabilities, more functions, and more features. More types of attack vectors."
"It is necessary to add some training materials and a tutorial for beginners."
 

Pricing and Cost Advice

"Comparing the price with the value that we receive, I am not happy with it."
"InsightVM is an expensive product, especially compared to its competitors, at around a million NOK per year."
"Its price is too high. My only concern or issue with Rapid7 is its pricing."
"Licensing fees are paid on a yearly basis."
"The price of the solution is less than the competitors."
"The license is IP based. How many IPs you are using to scan is the amount of the license you have to buy. The number of users doesn't matter; many users can use it or only person. It depends on the culture of the organization."
"We purchase annual licenses."
"Pricing is reasonable because we pay according to asset usage. We can define our assets and sites according to our preference."
"The cost is approximately $15 per device."
"Rapid7 Metasploit is an open-source solution."
"I use the open-source version of this product. Pricing is not relevant."
"On a scale of one to ten, where one is cheap and ten is expensive, I rate the product's pricing a six. So it's fairly priced."
"The pricing structure involves a one-time purchase cost of approximately twenty thousand dollars or euros for all customers."
"It is expensive. Our license expired, and our company is not thinking to renew because of our budget."
"It is a reasonably priced solution. I would rate it from five out of ten."
"Rapid7 Metasploit is cheaper than Tenable.io Vulnerability Management."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
42%
Computer Software Company
10%
Financial Services Firm
7%
Manufacturing Company
6%
Computer Software Company
19%
Financial Services Firm
10%
Manufacturing Company
9%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
Rapid7 InsightVM is expensive, possibly one of the highest in pricing among similar products.
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What needs improvement with Rapid7 Metasploit?
The reporting feature needs improvement. The time taken to fetch reports based on the number of events can be extensive, unlike Tenable, which is more user-friendly and faster. Additionally, networ...
 

Also Known As

InsightVM, NeXpose
Metasploit
 

Learn More

 

Overview

 

Sample Customers

ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Rapid7 InsightVM vs. Rapid7 Metasploit and other solutions. Updated: March 2023.
831,265 professionals have used our research since 2012.