Try our new research platform with insights from 80,000+ expert users
Agustinus DWIJOKO - PeerSpot reviewer
Network & Security Engineer at PT. Centrin Online Prima
Reseller
Top 5
Affordable, reliable and easy to set up
Pros and Cons
  • "Technical support has been helpful and responsive."
  • "We'd like them to offer better coverage of malware."

What is our primary use case?

The last use case is for customers that want to use the features of Metasploit, for phishing detection. We give awareness about phishing on their email accounts in the organization.

How has it helped my organization?

The affordability of the asset for the organization has been the biggest improvement.

What is most valuable?

The initial setup is straightforward. 

The product scales well.

It's very stable and reliable. 

Technical support has been helpful and responsive. 

It's great for detecting phishing campaigns. 

What needs improvement?

It would be better if Metasploit had a wider module, to do explorations of vulnerabilities. We'd like them to offer better coverage of malware.

Buyer's Guide
Rapid7 Metasploit
January 2025
Learn what your peers think about Rapid7 Metasploit. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

For how long have I used the solution?

I've been using the solution for three to four years. It's been a while. 

What do I think about the stability of the solution?

The solution is stable and reliable. There are no bugs or glitches and it doesn't crash or freeze.

What do I think about the scalability of the solution?

It's a product that can scale as necessary.

How are customer service and support?

Technical support is very good. Whenever we need assistance, they are quite helpful and responsive. We are very satisfied with them.

How was the initial setup?

It's a very simple setup. The process is not overly complex or difficult. I'd rate it two out of five in terms of how easy it is (with one being the easiest and five being the hardest).

What's my experience with pricing, setup cost, and licensing?

The licensing is per user account. We're set up with one account per user. The price of the product is quite reasonable and very affordable. 

What other advice do I have?

We're a Rapid7 distributer.

I'm not sure which version of the solution we're using. It's likely the latest one. 

Any organization or enterprise should want to check for vulnerabilities in any kind of asset that they have. Using tools like Metasploit can help companies check internally.

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1675638 - PeerSpot reviewer
Cyber Security Director at a manufacturing company with 5,001-10,000 employees
Real User
Top 5
It's a great open-source solution for penetration testing
Pros and Cons
  • "I don't have any other tools like it, and I always use it when I'm doing a pen test. Metasploit is a great solution for penetration testing,"
  • "The open-source version has reporting limitations. You need to develop these capabilities yourself. Built-in reporting is an excellent feature for penetration testing, but it isn't a must-have. The solution could also cover more vulnerabilities. Metasploit has around 10,000 exploits in its library, but more is always better."

What is our primary use case?

We use Metasploit for penetration testing. Three to five testers use it annually. 

What needs improvement?

The open-source version has reporting limitations. You need to develop these capabilities yourself. Built-in reporting is an excellent feature for penetration testing, but it isn't a must-have. The solution could also cover more vulnerabilities. Metasploit has around 10,000 exploits in its library, but more is always better. 

For how long have I used the solution?

I have used Metasploit for more than 10 years.

What do I think about the stability of the solution?

I rate Metasploit nine out of 10 for stability. 

How was the initial setup?

Deploying Metasploit is straightforward and only took a few minutes. I'm using a pre-installed package that updates itself in a couple of minutes, but I don't think it takes much time to install it from scratch. Metasploit doesn't require maintenance after deployment. 

What's my experience with pricing, setup cost, and licensing?

We use the free open-source edition. 

What other advice do I have?

I rate Rapid7 Metasploit eight out of 10. I would recommend it. I don't have any other tools like it, and I always use it when I'm doing a pen test. Metasploit is a great solution for penetration testing, but end-to-end testing can be hard to manage if you don't have deep expertise. From the perspective of comprehensively addressing vulnerabilities, it may be hard for the average user in the community. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Rapid7 Metasploit
January 2025
Learn what your peers think about Rapid7 Metasploit. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
it_user1065 - PeerSpot reviewer
Senior Manager of Data Center at a integrator with 51-200 employees
Vendor
Metasploit is the top choice of the best information security professionals and penetration testers

Valuable Features:

Good features- 1) Availability of both graphical and command line interfaces. 2) HTML based report collection 3) Integration with PostgreSQL 4) Integration of NMAP for network scanning, brute force techniques 5) Around 800 active modules with exploits for linux, bsd , microsoft and MacOS 6) Collaboration with team feature also available 7) Open Source 8)Integration with Backtrack OS

Room for Improvement:

Few cons of metasploit are 1) Exploit updates are slow after security patches to a certain OS 2) High resource utilization when run under Window7 and Windows Server 2008 R2 3) Fewer browser exploits 4) Payloads not extremely effective against updated anti viruses.

Other Advice:

Metasploit is the most favored toolkit for network security professionals and penetration testers. It is one of the best tools for zero day exploits and payloads for operating systems such as, Microsoft Windows, Linux, and Sun Solaris. Metasploit, which has been written in Ruby, provides the ability to seamlessly create and simulate attacks on networks and provide protection. It deals with the largest database of exploits, till date available, in a single tool for both active and passive attacks on networks and applications.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2295975 - PeerSpot reviewer
Senior cybersecurity engineer at a aerospace/defense firm with 5,001-10,000 employees
Real User
Top 5
Easy to setup and good for penetration testing
Pros and Cons
  • "It is scalable. It's in line with our needs."
  • "I would like to see more capabilities, more functions, and more features. More types of attack vectors."

What is our primary use case?

Our use case is for penetration testing. 

What is most valuable?

My organization has been happy with it.

What needs improvement?

I would like to see more capabilities, more functions, and more features. More types of attack vectors.

For how long have I used the solution?

I have experience with this solution. Like, I have been aware of this product for a few years. 

What do I think about the stability of the solution?

I would rate the stability a seven out of ten. It's not a ten. There is room for improvement.

What do I think about the scalability of the solution?

It is scalable. It's in line with our needs. There are around five end users. We have possible plans to increase the further usage.

How was the initial setup?

The initial setup is fairly easy.

What about the implementation team?

We deployed it ourselves.

What was our ROI?

It is worth it.

What's my experience with pricing, setup cost, and licensing?

We pay monthly. The pricing is reasonable. There are additional costs. 

Which other solutions did I evaluate?

I may have considered others, but Rapid7 was the one that stood out to me.

What other advice do I have?

It's definitely one of the best penetration testing tools available. Overall, I would rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1432815 - PeerSpot reviewer
Project Director at a tech services company with 1,001-5,000 employees
Real User
A free and impactful penetration testing solution
Pros and Cons
  • "All of the features are great."
  • "At the time I was using it, the graphical user interface needed some improvements."

What is our primary use case?

I used the community edition. It's a very handy and powerful product. For a free product, the capabilities are absolutely astonishing.

I used Rapid7 Metasploit as a marketing solution. I was working as a security expert and whenever I would meet a client as a consultant or a freelancer, I would open my laptop and start using the software.

Rapid7 Metasploit is a standalone solution, intended to be used by one person, but it can be used by a few people in a team — maybe 10 people or less.

What is most valuable?

All of the features are great. I used it as a tool for penetration testing. The exploitation capabilities and the development in general, are all great. It's open-source and very handy. 

What needs improvement?

At the time I was using it, the graphical user interface needed some improvements. It might be better now because there was a very big community behind it, and of course, newer versions are always improved. The free, community edition I was using, lacked some very specific exploits but, as I remember, under the commercial version, you could find your exploits.

All the features that are available on the command line could be integrated with the graphical user interface.

For how long have I used the solution?

I used Rapid7 Metasploit for more than five years.

What do I think about the stability of the solution?

The earlier versions had some bugs, but the last version, Version Four, was much more stable compared to the previous versions — which we stopped using because of the bugs.

What do I think about the scalability of the solution?

The scalability is not that good.

When you use the command-line interface, not very much of the process is automated. There should always be an expert present to work with the software. Under the GUI, I believe there are some features that can be automated for testing.

The solution was not intended to be automated because penetration testing requires attention and caution because it's done on a live network with line services. Automation can damage the target network or the system on the network.

You can automate the input of data, but the results are not satisfactory.

The scalability should definitely be improved.

How are customer service and technical support?

As it's a free product, the community edition doesn't include any technical support. I haven't used the commercial edition so I can't comment on their support.

In terms of development, the team of developers that supports the software is very active and quick to help. In short, the software is being maintained very actively, and I do believe the customer support should be the same.

I would like to see some support available for the free version; however, there are a lot of open-source materials available to solve any issues, so for me personally, there wasn't any need for technical support.

How was the initial setup?

If you want to install it separately on a fresh new Linux, the solution is still effective. The installation is very, very straightforward.

What other advice do I have?

The great advantage with Rapid7 Metasploit, of course, is that it's free. You can download it and start using it for free, right away. The features are satisfactory, and you can do your job strictly with the free edition. Of course, you could do your job even better with the commercial edition. 

There are better products available, like Core Impact, but they are much more expensive.

On a scale from one to ten, I would give Rapid7 Metasploit a rating of eight.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1369920 - PeerSpot reviewer
Senior Information Technology Security Officer at a financial services firm with 501-1,000 employees
Real User
Good reporting; very good at detecting vulnerabilities, and quite stable
Pros and Cons
  • "The reporting on the solution is good."
  • "The solution should improve the responsiveness of its live technical support."

What is our primary use case?

We're using the solution in conjunction with some governmental agencies.

What is most valuable?

The solution automatically discovers vulnerabilities. We don't need to update or fine-tune the tool. It automatically handles that itself.

The reporting on the solution is good.

What needs improvement?

The solution should be more user friendly. Right now, a user needs a certain level of technicality.

The solution should improve the responsiveness of its live technical support.

What do I think about the stability of the solution?

The solution has been stable so far. I hope it stays that way. We haven't experienced bugs or glitches. There haven't been crashes.

What do I think about the scalability of the solution?

So far, for our purposes, we've never run into issues with scalability. It's been good. I'm not sure how it would be for other companies, however, I don't forsee there being any issues if they should require the solution to expand to meet their needs.

How are customer service and technical support?

Technical support is okay. If you access its resources online, it's quite helpful. However, if you need to contact them directly, they can be quite sluggish in their response. It's sort-of unpredictable.

Which solution did I use previously and why did I switch?

We did use different solutions previously. I know of a few other products the organization utilized before this product.

How was the initial setup?

The initial setup isn't too complex. If you have a bit of a technical background, you should be fine installing the solution without facing any issues. A person with no technical background, however, may find it challenging.

What's my experience with pricing, setup cost, and licensing?

The pricing of the solution is pretty good. That said, it would be good if there could be more of a discount. It would be better for us.

What other advice do I have?

I used the product previously. Now, I am more of a consultant.

I'm not sure what version of the solution I'm currently using is.

This product is fantastic. I prefer using it. I'd rate it seven out of ten. If it wasn't for the unpredictable support, I would rate it a bit higher. If it added just a few more advancements, it would be even better still.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Mahmoud Elhamaymy - PeerSpot reviewer
Professional services team lead at a tech services company with 1,001-5,000 employees
Reseller
Open-source, simple and quick to install, with a variety of payload options
Pros and Cons
  • "Rapid7 Metasploit is a useful product."
  • "Rapid7 Metasploit can add a GUI feature because it is only available online."

What is our primary use case?

We mainly use Rapid7 Metasploit for the network penetration testing activities.

We have used the payload during our penetration testing activities.

What is most valuable?

It is easy to use.

Rapid7 Metasploit is a useful product.

It has a very long list of available payloads.

What needs improvement?

Rapid7 Metasploit can add a GUI feature because it is only available online.

While it is simple to use, including a GUI would make things easier. It would be very helpful.

For how long have I used the solution?

I have been using Rapid7 Metasploit for more than four years.

What do I think about the scalability of the solution?

Our company performs penetration testing for our clients. It is not used in the client's organization by any users normally, instead, it is used by the penetration tester, who performs the penetration testing activities.

Our company is a professional services company with 15 team members. All 15 team members are using this solution.

How are customer service and support?

We have not opened any tickets, as we have not experienced any issues.

Also, the free version does not offer support, it is only included with the Pro Version.

If you're using the free version, there's an online community where you can look for a similar problem that needs to be solved.

How was the initial setup?

The initial setup is straightforward. It's very easy to install Rapid7 Metasploit.

It's only five minutes to install.

This solution can be deployed and managed by a single person.

What's my experience with pricing, setup cost, and licensing?

There are two versions available, one of which is the Pro version, and the other is the free version.

In the four years that we've been using this solution, we've only used the free version. We haven't had any reason to use the Pro Version.

What other advice do I have?

I would recommend this solution to others who are interested in using it.

I would rate Rapid7 Metasploit an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
CEO at Virtual Security International
Real User
Many tests available, tests capable through networks, but scalability could improve
Pros and Cons
  • "The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers."
  • "The solution is not very scalable, it does not provide any automation to be able to scale it."

What is our primary use case?

We have Rapid7 Metasploit installed on our Kali Linux system and we use it for penetration testing.

What is most valuable?

The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers.

Someone has created a graphical interface for this solution called Armitage which has been very useful and easier to use. The solution typically only has a command-line interface.

You are able to do network tests over a network, not necessarily on the web server, but on desktops and other devices.

For how long have I used the solution?

I have been using Rapid7 Metasploit for approximately two years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is not very scalable, it does not provide any automation to be able to scale it.

What other advice do I have?

I rate Rapid7 Metasploit a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Rapid7 Metasploit Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Product Categories
Vulnerability Management
Buyer's Guide
Download our free Rapid7 Metasploit Report and get advice and tips from experienced pros sharing their opinions.