I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective.
Network and Security engineer at a university with 1,001-5,000 employees
Real User
Top 5
2024-07-26T09:23:00Z
Jul 26, 2024
Other solutions, like Cisco, have strengths, but Rapid7 InsightVM has some solid features, such as the RapidServer Active Response, the ability to create endpoint agents, and a live dashboard. However, the main concern is the system's reliability. For instance, during a scan on an Ubuntu machine, the system mistakenly identified the OS as Windows. This kind of inaccuracy is problematic.
I think the improvement in the tool should be to provide a better update to users because sometimes the information within the cloud and the scanner are not synchronized very fast. For example, like, when we upgrade to a patch with the devices, it should be able to make it up to date right away, but it takes more than hours to update in the portal. We need to then do a rescan manually.
Marketing Expert at a comms service provider with 51-200 employees
Reseller
Top 5
2024-04-08T08:04:00Z
Apr 8, 2024
The product is not a cloud solution. The tool can only be used as a hybrid solution, meaning it can be used on the cloud and on an on-premises deployment model. There are certain limitations because of the product being used on a hybrid model. Rapid7 InsightVM doesn't offer a solution purely in the cloud. Competitors of Rapid7 InsightVM, like Tenable.io and Qualys, offer pure cloud solutions.
One area I would like to improve in InsightVM is its integration with other solutions, particularly for better compatibility with upcoming tools we plan to adopt. Enhanced functionality for budget management or change management databases could also be beneficial.
Rapid7 InsightVM, has impressive capabilities, especially when it comes to managing video equipment. However, we've noticed that Rapid7 also offers a cloud solution called CloudSec, and we don't have that. We think it would be better if InsightVM had all the features for both on-premise and cloud management.
The primary issue I encountered initially with this tool was related to configuration. There is a significant learning curve, that non-technical individuals, especially those not specialized in computer science or the information security industry, might face.
Cybersecurity Consultant at a wholesaler/distributor with 51-200 employees
Real User
Top 20
2023-03-16T14:45:00Z
Mar 16, 2023
At times, some customers want more on-premises solutions, and yet vendors want us to load features onto the cloud. While it works in a hybrid way, they need to ensure they keep a customer's needs in mind. There should be containerization within the VM.
System Analyst II at a energy/utilities company with 1,001-5,000 employees
Real User
Top 5
2023-01-24T19:59:57Z
Jan 24, 2023
There are some issues with how it scans patches. Sometimes one patch will have been superseded by another but it won't see that, because one little key hasn't changed.
The solution cannot scan third-party tools that have firewalls within them. The firewalls detect and block the solution. Conversely, Nexus is able to bypass firewalls because it has low detectability. We use Nexus when the solution cannot bypass a firewall. The solution can scan 60% of the time but Nexus can scan 90% of the time. The solution needs to improve its vulnerability design to include CVC results. Nexus has a good, long range and a good database for finding CVC numbers. We need this level of security detail but the solution does not seem to provide it.
Chief Executive Officer at a outsourcing company with 11-50 employees
Reseller
2022-10-18T13:40:26Z
Oct 18, 2022
I see ongoing progress constantly. There isn't much opportunity to make recommendations for improvement from our end. Technology does what we want it to do. The only issue I have with their business plan is how they interact with South African enterprises. They have one singular distributor that I must work with, and that is where my two points go. I can't interact with Rapid7 directly. I must work via the local incumbent, the distributor. And working with this third party can be tiresome at times. Rapid7 InsightVM doesn't work with us directly. I have to work with a distributor. If I need quotes or technical support, for example, I have to work with the distributor rather than Rapid7 InsightVM directly. We are a registered reseller and a trusted partner. However, for us to get any support from them I can't log a call directly with Rapid7 InsightVM. I have to work with the distributor to log the call for me.
Cyber Security Analyst at a tech services company with 1-10 employees
Real User
2022-09-20T18:49:00Z
Sep 20, 2022
In order to be able to properly test the solution and make a decision, I would like to receive the test license code instantly and eliminate the wait time. If I have to wait a week to test the solution it may force me to move on to another solution.
Their channel program and the process of their deal registration could be improved. Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option.
Within InsightVM, there is no feature to assign a ticket. If we can have more API calls, we can do that from InsightVM. There is room for improvement when it comes to JIRA integration. If they can collaborate with the JIRA team, then it will be easier for people to use it. If we can configure and define more features such as the critical elite level through InsightVM, it would be better. I would prefer to have vulnerability assessment with more features, like code analysis, code coverage, etc. I would also prefer to have a method of custom image analysis for assessment. In the SDLC (software development lifecycle), if we could easily integrate with a particular lifecycle, then we could have more descriptive reports.
Cyber Security Engineer at a manufacturing company with 5,001-10,000 employees
Real User
2021-08-02T13:27:42Z
Aug 2, 2021
It would be very helpful to have integration. There are many plugins that can be used for tasks that would help the visibility and be able to locate the exact problem. I would like to see more integration. I would also like to see more flexibility when scheduling the scans. We should be able to schedule scans when we want them to be scheduled. Currently, they have to be scheduled before a certain day of the week.
The solution isn't missing any features, and I haven't noticed any shortcomings. There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version. That, or we must share to the internet on-prem Jira Service Desk. It's not easy for us since we use only the on-prem Service Desk service, and we don't straight to the internet for our service. InsightVM can only directly connect to the internet. So, we can't use this integration and send tasks to our technical team from InsightVM. We, therefore, need better integration with Jira Service Desk.
Security Solution Engineer II at a security firm with 501-1,000 employees
Real User
2022-08-12T16:37:49Z
Aug 12, 2022
It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment.
Senior Manager Cyber Security Services & Solutions at Trillium
Vendor
Top 10
2022-06-26T13:12:00Z
Jun 26, 2022
InsightVM could be improved by providing passive scanning as an option. They could also introduce license packages for fewer than 128 users for smaller organizations.
Head of Cyber security analysis at DNV Poland Sp. z o.o.
Real User
2022-06-08T07:18:10Z
Jun 8, 2022
InsightVM is getting a little stale and is in danger of falling behind its competitors. It's also becoming more complicated, and I prefer it to be kept simple. Its cloud coverage could also be stepped up.
Network & Security Engineer at PT. Centrin Online Prima
Reseller
Top 5
2022-05-12T06:51:43Z
May 12, 2022
The agent must be covered if the customer wants to do a combined thing. InsightVM cannot do that if they are using an agent. We'd like the agent to cover more compliance issues.
The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier.
It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform. It would be nice to have someone in the technical support team who speaks Italian.
Senior Consultant at a tech services company with 11-50 employees
Real User
2021-06-09T14:04:00Z
Jun 9, 2021
All products have room for increased security and Rapid7 InsightVM is no exception. This is why I do not give a perfect score to any product on principle.
Head of Cybersecurity Assurance & Controls Director at a tech services company with 1,001-5,000 employees
Real User
2021-03-30T15:10:25Z
Mar 30, 2021
The reporting is very bad when you compare it with other vulnerability assessment tools. This product is for basic vulnerability assessments, only, and is lacking in features such as compliance, assessment, assets, inventory, and batch management.
In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts. In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time. Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch.
Owner at a tech services company with 1-10 employees
Real User
2020-12-08T15:02:57Z
Dec 8, 2020
They just need to fix it to make it more fluid. If it shows you vulnerabilities, I want to be able to click on the vulnerability and drill down into the vulnerability. If it's rating it as a 10 and it says it's got 30 hosts in it for this vulnerability, I want to click on that vulnerability and get a separate report that says, "Here's the vulnerability specific and here's the host involved." That way I could export it and say, "Hey, this vulnerability's out there, it matches a CVE number that is critical, that Microsoft, Cisco, whatever, has put a patch out there, and here guys, here's what it is and here's the proof. Here's your host that's vulnerable. Here's a change request, fix it, send me back the proof that you fixed it, then allow me to rerun a scan specific to that, on-demand, to say 'Yes, boss, we have mitigated it.'" I want to be able to just drill down on the reports. If it showing me there's a vulnerability and there's a said number of nodes that's vulnerable to it, I want to be able to drill down and export that list without having to come back out of it, going into my assets, trying to find the name of the vulnerability, which doesn't match what the dashboard says. To me, that was backward.
Director of Cyber Security (CISO) at a marketing services firm with 201-500 employees
Real User
2020-09-27T04:10:18Z
Sep 27, 2020
Now that we have been using it, I think there are some things Rapid7 needs to consider and address in improving InsightsVM. I think the reporting piece has room for improvement. While they have a lot of reporting, and some of the reporting is really good, there are some things that I think they can do better on. They need to add some categories that are not covered and expand a few things that have only surface coverage. I would love to be on a customer advisory board so that I could provide feedback to them and show them what their solution does not do. For example, I could point out things that I can not do with a widget on the dashboard that I would expect it to be able to do. Things like that might help them improve the product from a real user's perspective. That could amount to a lot of different things, but ideally, it would focus on your most common issues. There were a couple of things I know that the security analyst and I were looking at and we were wondering why Rapid7 would choose to implement it that way. Like if they did not include something we needed as part of a report, we could not do what we expected when running the report. That is a little frustrating. I would say that they need to spend some more time evaluating enhancements suggested by customers so that they can get those things implemented and round out the user experience. That is the reason why I think a CAB (Customer Advisory Board) is important for vendors like Rapid7.
Director of Information Technology at a government with 201-500 employees
Real User
2020-08-09T07:20:00Z
Aug 9, 2020
We found that after you passed an endpoint, it didn't always reflect it in the next scan. I'm not sure if it was a glitch or some issue with the product's software. That was never clear. That was always an issue and something that definitely needed improvement.
The solution needs to improve its smart monitoring. There needs to be much clearer instructions surrounding scanning. As for new features, I can't think of anything that's lacking. It's pretty good overall in terms of feature offerings.
I have had some difficult problems with InsightVM. The InsightVM cannot scan if we connect to our customer by the VPN. I asked the Rapid7 support, they told me that the InsightVM can only work on the same network. We cannot use InsightVM by VPN. It also consumes a lot of memory. It would be good if they could resolve that.
It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console. I don't have the time to log onto the console and use SSH to go through the logs. We have some users with certain privileges, and sometimes they do things that I don't like. This is why it would be nice to have an easy way to report what is in the logs. In the next release, I would like to see reporting added to the console. It would be helpful to have reports to tell you who did what, who created reports, who created groups or who created tags.
Infrastructure Security Architect at a comms service provider with 11-50 employees
Real User
2020-02-24T06:02:43Z
Feb 24, 2020
The reporting is a little bit tricky because it can be difficult to exactly pinpoint some of the assets to filter them and generate a report. Improving the filtering capability would make the reporting easier. We would like to have penetration testing features built into Nexpose, as it is the next area that we are going to be concentrating on. We have not yet tried it, but it is on our roadmap.
IT Security Architect at a government with 1,001-5,000 employees
Real User
2020-02-24T06:02:00Z
Feb 24, 2020
There are some difficulties with the online reporting and lack of integrations, the information that you can get from the APIs in the software is not the best. There's still some fleshing out of their API that I think could benefit them as well. I'd like to see more integrations with ticketing systems. Right now, JIRA and ServiceNow are the only ticketing systems that have integration with Rapid7. Extending that would be big. Some additional integrations with some patch management solutions would be good too. IBM BigFix and SCCM. Microsoft has integrations there. In our situation, we're not using either of those and that feature doesn't really give us a whole lot. If there were to be new integrations added on, both on the patch management and the ITMS side, that would be a big improvement. Additional features would be the additional integrations for ticketing systems that I mentioned. There are always updates rolling out for new scans and things.
Senior Security Analyst at a financial services firm with 1,001-5,000 employees
Real User
2020-01-15T08:03:00Z
Jan 15, 2020
The reporting has room for improvement. You cannot customize any report. If I need a specific requirement, I have to create a new report for it. I cannot pull up two or three things in one report.
Information Security Senior Expert (Founding member, African Cybersecurity Center) at a financial services firm with 10,001+ employees
Real User
2019-11-07T10:35:00Z
Nov 7, 2019
We need to scan and identify the different RPGs, the critical ones and the major ones that can generate risk or a measure of risk. We generate the reporting from the system and relay the report to our internal developers. We have our internal developers in the bank. This solution integrates with another module in Metasploit, that doesn't exist in the other solutions. It is subscribed to on our roadmap, but we chose to implement both Nexppose and AppSpider.
It gives false positives at times, and this a problem. It causes problems with reporting. In addition, I did not find plug-ins for a Rapid7 InsightVM. It would be much more informational to run it through directly, so once the app is installed, once the software is installed on that particular server, it would find what exactly that application is open for. This would make things easier for us.
Works at a insurance company with 501-1,000 employees
Real User
2018-10-28T09:33:00Z
Oct 28, 2018
There are not enough templates, and the reporting is weak with this solution. It would be great if there were more templates for the analytical reports, such as patch management reports. At present, these do not exist. In addition, there are false positives.
Information Security Manager at a educational organization with 5,001-10,000 employees
Real User
2018-07-29T06:51:00Z
Jul 29, 2018
We could always have a cheaper price, but other than that it's pretty good stuff. Also, if they’d expand their product line, that would be good, and they are doing so, but they're not done yet.
Rapid7 InsightVM is a comprehensive vulnerability management platform that protects your systems from attackers and is easy to scale. The solution provides easy access to vulnerability management, application security, detection and response, external threat intelligence, orchestration and automation, and more. Rapid7 InsightVM is ideal for security, IT, and DevOps teams, helping them reduce risk by enabling them to detect and respond to attacks quickly.
Rapid7 InsightVM Features
Rapid7...
I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective.
Other solutions, like Cisco, have strengths, but Rapid7 InsightVM has some solid features, such as the RapidServer Active Response, the ability to create endpoint agents, and a live dashboard. However, the main concern is the system's reliability. For instance, during a scan on an Ubuntu machine, the system mistakenly identified the OS as Windows. This kind of inaccuracy is problematic.
I think the improvement in the tool should be to provide a better update to users because sometimes the information within the cloud and the scanner are not synchronized very fast. For example, like, when we upgrade to a patch with the devices, it should be able to make it up to date right away, but it takes more than hours to update in the portal. We need to then do a rescan manually.
The product is not a cloud solution. The tool can only be used as a hybrid solution, meaning it can be used on the cloud and on an on-premises deployment model. There are certain limitations because of the product being used on a hybrid model. Rapid7 InsightVM doesn't offer a solution purely in the cloud. Competitors of Rapid7 InsightVM, like Tenable.io and Qualys, offer pure cloud solutions.
One area I would like to improve in InsightVM is its integration with other solutions, particularly for better compatibility with upcoming tools we plan to adopt. Enhanced functionality for budget management or change management databases could also be beneficial.
Rapid7 InsightVM, has impressive capabilities, especially when it comes to managing video equipment. However, we've noticed that Rapid7 also offers a cloud solution called CloudSec, and we don't have that. We think it would be better if InsightVM had all the features for both on-premise and cloud management.
The primary issue I encountered initially with this tool was related to configuration. There is a significant learning curve, that non-technical individuals, especially those not specialized in computer science or the information security industry, might face.
They should improve the cybersecurity feature of the solution.
At times, some customers want more on-premises solutions, and yet vendors want us to load features onto the cloud. While it works in a hybrid way, they need to ensure they keep a customer's needs in mind. There should be containerization within the VM.
There are some issues with how it scans patches. Sometimes one patch will have been superseded by another but it won't see that, because one little key hasn't changed.
The solution cannot scan third-party tools that have firewalls within them. The firewalls detect and block the solution. Conversely, Nexus is able to bypass firewalls because it has low detectability. We use Nexus when the solution cannot bypass a firewall. The solution can scan 60% of the time but Nexus can scan 90% of the time. The solution needs to improve its vulnerability design to include CVC results. Nexus has a good, long range and a good database for finding CVC numbers. We need this level of security detail but the solution does not seem to provide it.
I see ongoing progress constantly. There isn't much opportunity to make recommendations for improvement from our end. Technology does what we want it to do. The only issue I have with their business plan is how they interact with South African enterprises. They have one singular distributor that I must work with, and that is where my two points go. I can't interact with Rapid7 directly. I must work via the local incumbent, the distributor. And working with this third party can be tiresome at times. Rapid7 InsightVM doesn't work with us directly. I have to work with a distributor. If I need quotes or technical support, for example, I have to work with the distributor rather than Rapid7 InsightVM directly. We are a registered reseller and a trusted partner. However, for us to get any support from them I can't log a call directly with Rapid7 InsightVM. I have to work with the distributor to log the call for me.
In order to be able to properly test the solution and make a decision, I would like to receive the test license code instantly and eliminate the wait time. If I have to wait a week to test the solution it may force me to move on to another solution.
Their channel program and the process of their deal registration could be improved. Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option.
Within InsightVM, there is no feature to assign a ticket. If we can have more API calls, we can do that from InsightVM. There is room for improvement when it comes to JIRA integration. If they can collaborate with the JIRA team, then it will be easier for people to use it. If we can configure and define more features such as the critical elite level through InsightVM, it would be better. I would prefer to have vulnerability assessment with more features, like code analysis, code coverage, etc. I would also prefer to have a method of custom image analysis for assessment. In the SDLC (software development lifecycle), if we could easily integrate with a particular lifecycle, then we could have more descriptive reports.
Rapid7 could be easier to manage. When you compare it to other similar solutions, it is a bit difficult to manage. The reporting could be improved.
The solution is not multitenancy and it would be great if they could add some of that to the platform.
It would be very helpful to have integration. There are many plugins that can be used for tasks that would help the visibility and be able to locate the exact problem. I would like to see more integration. I would also like to see more flexibility when scheduling the scans. We should be able to schedule scans when we want them to be scheduled. Currently, they have to be scheduled before a certain day of the week.
The solution isn't missing any features, and I haven't noticed any shortcomings. There was functionality present previously, however, currently, we can't integrate directly with Jira Service Desk - only the cloud version. That, or we must share to the internet on-prem Jira Service Desk. It's not easy for us since we use only the on-prem Service Desk service, and we don't straight to the internet for our service. InsightVM can only directly connect to the internet. So, we can't use this integration and send tasks to our technical team from InsightVM. We, therefore, need better integration with Jira Service Desk.
It is still not a fully cloud-based solution. It will be helpful for customers if it is a complete cloud solution. It is a hybrid solution at the moment.
The reporting could be better. We do not need any additional features.
InsightVM could be improved by providing passive scanning as an option. They could also introduce license packages for fewer than 128 users for smaller organizations.
InsightVM is getting a little stale and is in danger of falling behind its competitors. It's also becoming more complicated, and I prefer it to be kept simple. Its cloud coverage could also be stepped up.
The agent must be covered if the customer wants to do a combined thing. InsightVM cannot do that if they are using an agent. We'd like the agent to cover more compliance issues.
Their customer support should be improved, and the effectiveness of scans also needs to be improved.
The on-premise updates could improve from Rapid7 InsightVM.
Rapid7 InsightVM could be easier to use for those who are using it for the first time. The updates should be fixed in the next release.
There is room for improvement on its cloud side. In the next release I would like to see better reporting.
The solution could improve by being more secure.
The integration with other solutions like JIRA could be better. Perhaps there could be some additional updates in the next phase that could integrate with it, so then you can proceed with the VT much easier.
It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform. It would be nice to have someone in the technical support team who speaks Italian.
All products have room for increased security and Rapid7 InsightVM is no exception. This is why I do not give a perfect score to any product on principle.
The reporting is very bad when you compare it with other vulnerability assessment tools. This product is for basic vulnerability assessments, only, and is lacking in features such as compliance, assessment, assets, inventory, and batch management.
In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts. In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time. Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch.
They just need to fix it to make it more fluid. If it shows you vulnerabilities, I want to be able to click on the vulnerability and drill down into the vulnerability. If it's rating it as a 10 and it says it's got 30 hosts in it for this vulnerability, I want to click on that vulnerability and get a separate report that says, "Here's the vulnerability specific and here's the host involved." That way I could export it and say, "Hey, this vulnerability's out there, it matches a CVE number that is critical, that Microsoft, Cisco, whatever, has put a patch out there, and here guys, here's what it is and here's the proof. Here's your host that's vulnerable. Here's a change request, fix it, send me back the proof that you fixed it, then allow me to rerun a scan specific to that, on-demand, to say 'Yes, boss, we have mitigated it.'" I want to be able to just drill down on the reports. If it showing me there's a vulnerability and there's a said number of nodes that's vulnerable to it, I want to be able to drill down and export that list without having to come back out of it, going into my assets, trying to find the name of the vulnerability, which doesn't match what the dashboard says. To me, that was backward.
Now that we have been using it, I think there are some things Rapid7 needs to consider and address in improving InsightsVM. I think the reporting piece has room for improvement. While they have a lot of reporting, and some of the reporting is really good, there are some things that I think they can do better on. They need to add some categories that are not covered and expand a few things that have only surface coverage. I would love to be on a customer advisory board so that I could provide feedback to them and show them what their solution does not do. For example, I could point out things that I can not do with a widget on the dashboard that I would expect it to be able to do. Things like that might help them improve the product from a real user's perspective. That could amount to a lot of different things, but ideally, it would focus on your most common issues. There were a couple of things I know that the security analyst and I were looking at and we were wondering why Rapid7 would choose to implement it that way. Like if they did not include something we needed as part of a report, we could not do what we expected when running the report. That is a little frustrating. I would say that they need to spend some more time evaluating enhancements suggested by customers so that they can get those things implemented and round out the user experience. That is the reason why I think a CAB (Customer Advisory Board) is important for vendors like Rapid7.
There have been instances where technical support takes a long time to update the status of a ticket, which is something that can be improved.
We found that after you passed an endpoint, it didn't always reflect it in the next scan. I'm not sure if it was a glitch or some issue with the product's software. That was never clear. That was always an issue and something that definitely needed improvement.
The solution needs to improve its smart monitoring. There needs to be much clearer instructions surrounding scanning. As for new features, I can't think of anything that's lacking. It's pretty good overall in terms of feature offerings.
I have had some difficult problems with InsightVM. The InsightVM cannot scan if we connect to our customer by the VPN. I asked the Rapid7 support, they told me that the InsightVM can only work on the same network. We cannot use InsightVM by VPN. It also consumes a lot of memory. It would be good if they could resolve that.
It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console. I don't have the time to log onto the console and use SSH to go through the logs. We have some users with certain privileges, and sometimes they do things that I don't like. This is why it would be nice to have an easy way to report what is in the logs. In the next release, I would like to see reporting added to the console. It would be helpful to have reports to tell you who did what, who created reports, who created groups or who created tags.
The reporting is a little bit tricky because it can be difficult to exactly pinpoint some of the assets to filter them and generate a report. Improving the filtering capability would make the reporting easier. We would like to have penetration testing features built into Nexpose, as it is the next area that we are going to be concentrating on. We have not yet tried it, but it is on our roadmap.
There are some difficulties with the online reporting and lack of integrations, the information that you can get from the APIs in the software is not the best. There's still some fleshing out of their API that I think could benefit them as well. I'd like to see more integrations with ticketing systems. Right now, JIRA and ServiceNow are the only ticketing systems that have integration with Rapid7. Extending that would be big. Some additional integrations with some patch management solutions would be good too. IBM BigFix and SCCM. Microsoft has integrations there. In our situation, we're not using either of those and that feature doesn't really give us a whole lot. If there were to be new integrations added on, both on the patch management and the ITMS side, that would be a big improvement. Additional features would be the additional integrations for ticketing systems that I mentioned. There are always updates rolling out for new scans and things.
The reporting has room for improvement. You cannot customize any report. If I need a specific requirement, I have to create a new report for it. I cannot pull up two or three things in one report.
We need to scan and identify the different RPGs, the critical ones and the major ones that can generate risk or a measure of risk. We generate the reporting from the system and relay the report to our internal developers. We have our internal developers in the bank. This solution integrates with another module in Metasploit, that doesn't exist in the other solutions. It is subscribed to on our roadmap, but we chose to implement both Nexppose and AppSpider.
A definite improvement would be to make it easier to run ad-hoc scans without needing to assign the asset to a site or group.
It gives false positives at times, and this a problem. It causes problems with reporting. In addition, I did not find plug-ins for a Rapid7 InsightVM. It would be much more informational to run it through directly, so once the app is installed, once the software is installed on that particular server, it would find what exactly that application is open for. This would make things easier for us.
There are not enough templates, and the reporting is weak with this solution. It would be great if there were more templates for the analytical reports, such as patch management reports. At present, these do not exist. In addition, there are false positives.
We could always have a cheaper price, but other than that it's pretty good stuff. Also, if they’d expand their product line, that would be good, and they are doing so, but they're not done yet.