2018-12-24T07:46:00Z

What needs improvement with Rapid7 Metasploit?

Miriam Tover - PeerSpot reviewer
  • 0
  • 19
PeerSpot user
13

13 Answers

Md. Shahriar Hussain - PeerSpot reviewer
Real User
Top 5
2024-02-23T10:40:25Z
Feb 23, 2024

If your company's patch is not up to date, but you have other detection or defense solutions such as endpoint detection and response and antivirus software, the product exploit may not work effectively. This is because its exploit database update process is slow and not real-time. For zero-day vulnerabilities or new security threats, relying on Rapid7 Metasploit alone may not be effective. Adding features to Rapid7 Metasploit that enhance evasion of Endpoint Detection and Response systems would significantly improve its utility within modern organizations.

Search for a product comparison
SE
Real User
Top 5
2023-11-20T08:47:32Z
Nov 20, 2023

I would like to see more capabilities, more functions, and more features. More types of attack vectors.

Andrei Bigdan - PeerSpot reviewer
Real User
Top 5Leaderboard
2023-11-07T14:18:01Z
Nov 7, 2023

There are numerous outdated exploits in their database that should be updated.

Agustinus DWIJOKO - PeerSpot reviewer
Reseller
Top 5Leaderboard
2023-11-07T10:39:00Z
Nov 7, 2023

Advanced Infrastructure should be implemented in the next release for better orchestration.

Alen Bohcelyan - PeerSpot reviewer
Real User
Top 10
2023-06-09T14:18:13Z
Jun 9, 2023

The open-source version has reporting limitations. You need to develop these capabilities yourself. Built-in reporting is an excellent feature for penetration testing, but it isn't a must-have. The solution could also cover more vulnerabilities. Metasploit has around 10,000 exploits in its library, but more is always better.

Rostum Tampor - PeerSpot reviewer
Reseller
Top 10
2023-06-06T08:31:00Z
Jun 6, 2023

I think areas with shortcomings that need improvement are more integration and automation.

Find out what your peers are saying about Rapid7, Tenable, Invicti and others in Vulnerability Management. Updated: March 2024.
765,234 professionals have used our research since 2012.
AdeelAgha - PeerSpot reviewer
Real User
Top 5Leaderboard
2023-03-03T13:34:50Z
Mar 3, 2023

Rapid7 is able to identify vulnerabilities, but the only way to remediate them is to manually apply patches. This can be time-consuming, as evidenced by the six months it took our team to remediate vulnerabilities found in the Tenable ICS and OT security VT. To make this process easier, there should be an automated system or API to align with the PET solution, allowing systems to quickly align with it. The solution is not user-friendly and has room for improvement. I would like a feature for mobile tracking, allowing us to operate it from a mobile device or at least track it technologically, the basic functionality would be something I would like. For example, when I execute a vulnerability assessment activity, it takes around two to three days to complete all the plans. In order to track that, I would have to log into my system repeatedly. Therefore, I would like to have a feature that allows me to track it from my mobile device.

Agustinus DWIJOKO - PeerSpot reviewer
Reseller
Top 5Leaderboard
2022-05-12T06:51:41Z
May 12, 2022

It would be better if Metasploit had a wider module, to do explorations of vulnerabilities. We'd like them to offer better coverage of malware.

ME
Real User
2021-10-05T12:26:03Z
Oct 5, 2021

Rapid7 Metasploit can add a GUI feature because it is only available online. While it is simple to use, including a GUI would make things easier. It would be very helpful.

MM
Real User
2020-10-20T04:19:00Z
Oct 20, 2020

At the time I was using it, the graphical user interface needed some improvements. It might be better now because there was a very big community behind it, and of course, newer versions are always improved. The free, community edition I was using, lacked some very specific exploits but, as I remember, under the commercial version, you could find your exploits. All the features that are available on the command line could be integrated with the graphical user interface.

EG
Real User
2020-06-25T10:49:27Z
Jun 25, 2020

The solution should be more user friendly. Right now, a user needs a certain level of technicality. The solution should improve the responsiveness of its live technical support.

AS
Real User
2020-06-04T09:41:24Z
Jun 4, 2020

Integration with popular vulnerability scanners would be a useful feature. Better automation capabilities would be an improvement. For example, if a project is moving from a development to a testing environment, then automation is crucial. We are using Jenkins, JIRA, and other tools for SecOps and DevOps. If somebody is storing code or a project in SVN then it needs to be fully automated. We need the ability for the scanner to run, then have Checkmarx scan them, then exploit the vulnerabilities if any are found.

AA
Real User
2018-12-24T07:46:00Z
Dec 24, 2018

* The GUI version is not as effective as a command prompt. For general users, the PT using GUI could be improved. At the same, the track of a phishing emails were not accurate sometimes. Rapid7 could work on this further. * Metasploit cannot be installed on a machine with an antivirus. This could be improved. * There were times when it hung, then I had to restart the DB service. This leaves an area of improvement for them. * It is necessary to add some training materials and a tutorial for beginners.

Vulnerability Management
What is vulnerability management? Vulnerability management is the meticulous, exhaustive, systematic process implemented to discover any potential threats or vulnerabilities, stop those threats, and repair those vulnerabilities before any serious problems develop with your important operating systems. Vulnerability management also involves fixes and patches to repair those threats and vulnerabilities. It is generally accomplished in combination with additional risk assessment and...
Download Vulnerability Management ReportRead more