Try our new research platform with insights from 80,000+ expert users

Rapid7 Metasploit vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 Metasploit
Ranking in Vulnerability Management
19th
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
20
Ranking in other categories
No ranking in other categories
Tenable Nessus
Ranking in Vulnerability Management
1st
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
80
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2025, in the Vulnerability Management category, the mindshare of Rapid7 Metasploit is 1.9%, up from 1.9% compared to the previous year. The mindshare of Tenable Nessus is 12.5%, down from 15.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management
 

Featured Reviews

Mani Bommisetty - PeerSpot reviewer
Comprehensive insights with robust vulnerability detection and streamlined alert management
Rapid7 has a significant advantage in providing a clear picture of my environment. It provides insight and incident detection response capabilities. When deployed with the same agent in servers or endpoints, it identifies vulnerabilities and monitors data transmission to external sources. Rapid7 offers comprehensive features within one platform, eliminating the need to integrate multiple tools to see all alerts in one place.
HarshBhardiya - PeerSpot reviewer
Provided increased visibility across the organization's servers
The user interface of Tenable Nessus feels outdated and could be more user-friendly. Additionally, the documentation is not well-organized, which can be confusing when searching for solutions or specific information related to Tenable Nessus Professional. The reporting feature could be improved by allowing users to create their own templates instead of relying on predefined ones.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It contains almost all the available exploits and payloads."
"The option to generate phishing emails has proven to be very valuable in understanding the behavior of users."
"Technical support has been helpful and responsive."
"All of the features are great."
"The greatest advantage of Rapid7 Metasploit is that it is the only system that can directly exploit vulnerabilities on the Metasploit platform."
"It is scalable. It's in line with our needs."
"The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers."
"Rapid7 has a significant advantage in providing a clear picture of my environment."
"Quick assessments, compliance scores, and results are provided without having to do agents."
"We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equipment, and appliances in our infrastructure."
"The stability is very good."
"With the Tenable Nessus enterprise edition, you have unlimited licenses to scan the device."
"Once you get past the initial implementation, the solution is very stable."
"Its initial setup was simple and straightforward."
"The results are not that bad, but the key selling point is that it is an affordable tool set."
"Nessus is effortless to integrate."
 

Cons

"We'd like them to offer better coverage of malware."
"Rapid7 Metasploit could be made easier for new users to learn."
"The solution is not user-friendly and has room for improvement."
"The initial setup was a bit "tweaky" for the open-source version."
"It is necessary to add some training materials and a tutorial for beginners."
"I think areas with shortcomings that need improvement are more integration and automation."
"The database is not always updated with the latest vulnerabilities or zero-day exploits."
"The reporting feature needs improvement. The time taken to fetch reports based on the number of events can be extensive, unlike Tenable, which is more user-friendly and faster."
"There should be a possibility to install agents on scanned machines. Tenable IO provides the capability of using local agents to check local problems, but this feature is not there in Tenable Nessus Professional. It would be nice to have something similar in Tenable Nessus Professional. We should have the capability to use local agents installed on the machines to locally check a problem."
"The user interface of Tenable Nessus feels outdated and could be more user-friendly."
"We would like to have the option of using the solution for the cloud as well as on-premises with the same license at the same time. That would be very helpful."
"The accuracy of the vulnerability assessment is not up to par yet, as false alarms and false positives occur often."
"Some things in the user interface could be better. The user interface could allow more adjustments to plugins. The price could also be better."
"In terms of what could be improved, I would say its reporting portion."
"One significant drawback we encounter is the tool's tendency to flag patched packages incorrectly. For instance, if a package is patched by Debian maintainers but not updated to a major or minor version, Nessus may still flag it as vulnerable based on its database. This discrepancy leads to false alarms and requires our developers, system admins, and DevOps teams to address them."
"Tenable Nessus could improve the reporting by adding some dashboards. The reports are a hassle at this time. Tenable.io has more detailed reports. Having a better dashboard that can show where the vulnerabilities are and be categorized would be helpful. We then could present them to upper management for a deep overview of our network posture which they do not see."
 

Pricing and Cost Advice

"It is expensive. Our license expired, and our company is not thinking to renew because of our budget."
"Rapid7 Metasploit is an open-source solution."
"The great advantage with Rapid7 Metasploit, of course, is that it's free."
"The pricing structure involves a one-time purchase cost of approximately twenty thousand dollars or euros for all customers."
"On a scale of one to ten, where one is cheap and ten is expensive, I rate the product's pricing a six. So it's fairly priced."
"We pay monthly. The pricing is reasonable."
"I use the open-source version of this product. Pricing is not relevant."
"There are two versions available, one of which is the Pro version, and the other is the free version."
"The price is okay. I would give it a seven out of ten, where one is cheap and ten is expensive."
"Tenable Nessus is affordable."
"I rate the product's price seven or eight on a scale of one to ten, where one is low price and ten is high price."
"The solution has a single price for unlimited assets."
"We have a subscription, the licensing fees are paid yearly, and I am using the latest version."
"While Tenable Nessus is a good enterprise solution, the high price would likely make it prohibitive to smaller organizations."
"Nessus is affordable, but its licensing model could be improved with more flexibility for adding assets."
"The solution is expensive."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
10%
Manufacturing Company
9%
Educational Organization
7%
Educational Organization
41%
Computer Software Company
9%
Government
6%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What needs improvement with Rapid7 Metasploit?
The reporting feature needs improvement. The time taken to fetch reports based on the number of events can be extensive, unlike Tenable, which is more user-friendly and faster. Additionally, networ...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What do you like most about Tenable Nessus?
We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equi...
 

Also Known As

Metasploit
No data available
 

Learn More

 

Overview

 

Sample Customers

City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about Rapid7 Metasploit vs. Tenable Nessus and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.