We performed a comparison between Rapid7 Metasploit and Tenable Nessus based on real PeerSpot user reviews.
Find out in this report how the two Vulnerability Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."I don't have any other tools like it, and I always use it when I'm doing a pen test. Metasploit is a great solution for penetration testing,"
"The most valuable features of the solution are the scripts, the modules, and the tools that the Rapid7 Metasploit framework has."
"The solution is open source and has many small targetted penetration tests that have been written by many people that are useful. You can choose different subjects for the test, such as Oracle databases or Apache servers."
"The Search Engineering feature is good."
"Technical support has been helpful and responsive."
"The reporting on the solution is good."
"The greatest advantage of Rapid7 Metasploit is that it is the only system that can directly exploit vulnerabilities on the Metasploit platform."
"Stability-wise, I rate the solution a nine out of ten...Scalability-wise, I rate the solution a nine out of ten."
"The most valuable feature of Tenable Nessus is the support it provides for any new vulnerabilities quickly."
"I like its ease of use. It has the script that is pre-built in it, and you just got to know which ones you're looking for."
"The most valuable feature is the installation of Tenable which is incredibly easy."
"Makes ransomware checking and OS auditing and implementation relatively easy."
"User friendly and good dashboards."
"Tenable Nessus streamlines the process of scanning for our organization."
"The results are not that bad, but the key selling point is that it is an affordable tool set."
"The most valuable aspect of this solution is that you receive the entire report, which details the breakdown, especially in terms of critical, high, low, and mediums."
"The initial setup was a bit "tweaky" for the open-source version."
"I would like to see more capabilities, more functions, and more features. More types of attack vectors."
"The solution is not very scalable, it does not provide any automation to be able to scale it."
"If your company's patch is not up to date, but you have other detection or defense solutions such as endpoint detection and response and antivirus software, the product exploit may not work effectively. This is because its exploit database update process is slow and not real-time. For zero-day vulnerabilities or new security threats, relying on Rapid7 Metasploit alone may not be effective."
"Advanced Infrastructure should be implemented in the next release for better orchestration."
"Metasploit cannot be installed on a machine with an antivirus."
"Rapid7 Metasploit can add a GUI feature because it is only available online."
"I think areas with shortcomings that need improvement are more integration and automation."
"You can scale Nessus to the extent that you can afford it. You need to have a license for every device you scan. As long as you can afford the increased costs, you won't have a problem scaling it."
"Lacks some penetration testing-related services."
"We would like to have the option of using the solution for the cloud as well as on-premises with the same license at the same time. That would be very helpful."
"Nessus' reporting could be more user-friendly."
"We have had some false positives in the past, which we hope can improve in the future."
"The features are limited when it comes to scanning network devices for vulnerabilities."
"We'd like to see the solution embrace more user-friendliness."
"The solution could improve by having better integration with different vendors' IPS solutions. The ACLs and IPS policies signatures should be enabled based on the results of Tenable Nessus automatically, we currently have to do it manually which is very time-consuming. It has done a good job integrating with Fortinet but we would like it to be better integrated with other solutions that we have."
Rapid7 Metasploit is ranked 11th in Vulnerability Management with 18 reviews while Tenable Nessus is ranked 3rd in Vulnerability Management with 75 reviews. Rapid7 Metasploit is rated 7.6, while Tenable Nessus is rated 8.4. The top reviewer of Rapid7 Metasploit writes "Helps find vulnerabilities in a system to determine whether the system needs to be upgraded". On the other hand, the top reviewer of Tenable Nessus writes "Unlimited assets for one price and quick, agentless results". Rapid7 Metasploit is most compared with Pentera, Acunetix, Rapid7 InsightVM, Nucleus and Wireshark, whereas Tenable Nessus is most compared with Qualys VMDR, Rapid7 InsightVM, Tenable Security Center, Tenable Vulnerability Management and Microsoft Intune. See our Rapid7 Metasploit vs. Tenable Nessus report.
See our list of best Vulnerability Management vendors.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.