Our primary use case for Offensive Security Penetration Testing Services is the vulnerability database.
What is our primary use case?
What is most valuable?
Compared to Rapid7, Offensive Security might have more support on the back end in relation to exploits for Metasploit, for example. Offensive Security owns Metasploit and maintains it, which is why they might have some better documentation for it than than Rapid7 would.
What needs improvement?
Offensive Security Penetration Testing Services has a rating system for how exploitable vulnerability is, but that rating system does not really give you any transparency into how the rating for that exploit was reached. It would be useful to see on the back end what data led them to specify that a specific exploit may not be very good or may be great. If we had some data correlated with that, we could see why it is that this one should be successful versus another.
What do I think about the stability of the solution?
I would not say there's issues with stability.
How was the initial setup?
There is not a setup because Offensive Security Penetration Testing Services is a web application. All you have to do is go to the website and basically they have it all set up on the back end.
What's my experience with pricing, setup cost, and licensing?
Offensive Security Penetration Testing Services is open source, so it is free and there are no licensing costs.

