Try our new research platform with insights from 80,000+ expert users
Security Engineer at a computer software company with 51-200 employees
Reseller
Provides good discovery and prioritization of vulnerabilities; unfortunately no multitenancy feature yet
Pros and Cons
  • "The discovery and prioritization of vulnerabilities."

    What is our primary use case?

    We're mainly using this solution in-house for now and our primary use case is for Red Teaming. I'm a security engineer and we are resellers of Rapid7. 

    What is most valuable?

    The discovery and prioritization of vulnerabilities is a good feature along with the investigation, the trials function. It's also user friendly. 

    What needs improvement?

    The solution is not multitenancy and it would be great if they could add some of that to the platform. 

    What do I think about the stability of the solution?

    The solution is stable. 

    Buyer's Guide
    Rapid7 InsightVM
    March 2025
    Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
    845,485 professionals have used our research since 2012.

    What do I think about the scalability of the solution?

    It's scaled to the cloud so scalability is not an issue and it's pretty flexible. 

    How are customer service and support?

    I haven't used tech support. I've done all my troubleshooting online, it offers thorough explanations.

    How was the initial setup?

    The initial setup is definitely straightforward.

    What's my experience with pricing, setup cost, and licensing?

    There is an annual license fee which is pretty expensive because it's price per aspect. The pricing could definitely be cheaper.

    What other advice do I have?

    If your company has the budget for this product, I would recommend it. 

    I rate the solution seven out of 10. 

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer:
    PeerSpot user
    it_user606432 - PeerSpot reviewer
    Works at a insurance company with 501-1,000 employees
    Real User
    It is stable and scalable. The templates need improvement.
    Pros and Cons
    • "It is stable and scalable."
    • "There are not enough templates, and the reporting is weak with this solution."

    What needs improvement?

    There are not enough templates, and the reporting is weak with this solution. It would be great if there were more templates for the analytical reports, such as patch management reports. At present, these do not exist. 

    In addition, there are false positives.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    It is quite stable. 

    What do I think about the scalability of the solution?

    The scalability is good. 

    How are customer service and technical support?

    The tech support is quite good. 

    Which solution did I use previously and why did I switch?

    I have previously used Qualys, and I find the Rapid7 is a bit limited in terms of reporting.

    How was the initial setup?

    The initial setup was easy and straightforward.

    What's my experience with pricing, setup cost, and licensing?

    The price is cheaper than other products on the market.

    Which other solutions did I evaluate?

    We looked at Rapid7 vs Tenable Nessus.

    What other advice do I have?

    Users need to customize the policy compliance in order to optimize usage.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Rapid7 InsightVM
    March 2025
    Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
    845,485 professionals have used our research since 2012.
    PeerSpot user
    ITSM & AntiFraud Consultant at a tech company with 51-200 employees
    Real User
    It scans my production servers, checks their patching levels, and reports on their security. But, the community edition only supports paid domain registrations (so no free emails, such as gmail.com).

    What is most valuable?

    Rapid 7 offers the community edition, a free of charge edition( 32 IP's) that helps small companies to secure their IT environment. Also with this edition it helps the students to learn about Vulnerability Management.

    The report from Nexpose is very big, and gives you a description of the problems you have on your servers, and the solution for remediation.

    Other valuable feature is the ability to check the vulnerability with Metasploit with only one click.

    How has it helped my organization?

    I use Nexpose to scan my production servers, check the patching level on those servers, and use the reports to show the evolution of security on my servers.

    What needs improvement?

    For the community edition one of the big issues is with the registration. Rapid 7 only supports paid domains for registration, so no .gmail.com , .yahoo.com domains (once it was possible) . Also the resources needed by the scans can be an issue.

    For how long have I used the solution?

    I used Nexpose for more than 6 years.

    What was my experience with deployment of the solution?

    Some of issues apear on Linux instalation, but most of the issues are regarding the DB connection. On windows installation, usually the installation is smooth.In my latest test I have used the VM and everything was smooth.

    What do I think about the stability of the solution?

    The application is very stable, but sometimes I have issues with the comunication to the update server.

    What do I think about the scalability of the solution?

    I have tried all Nexpose editions, and I didn't had any issues with any of them. Starting this year Rapid 7 offers hardware appliances.

    How are customer service and technical support?

    Customer Service:

    i'll rate is 10/10. I had some presentation with them, and the person who presented us the solution really knew what to say to make us look on his screen.

    Technical Support:

    I never used technical support from Rapid 7.

    Which solution did I use previously and why did I switch?

    I have tried Nessus when it was a free edition. After that I have used OpenVAS and Qualys.

    Qualys is another good solution.

    How was the initial setup?

    The initial setup was straightforward, with small user input.

    What about the implementation team?

    All the Nexpose and Metasploit implemenations were made by me for various clients and for my firm for testing purposes.

    What's my experience with pricing, setup cost, and licensing?

    When you buy a vulnerability management tool, always count your IP's. If you miss one IP, and that server is compromised, you have left the door open for attackers into your enviorment.

    Which other solutions did I evaluate?

    OpenVAS, Nessus , Qualys, SAINT8,Beyond Trust

    What other advice do I have?

    Nexpose is one of the best solution on the market with very good development. One of it's key features was the On-Premise installation and Community Edition. Also it integrates flawless with Metasploit.

    Disclosure: My company has a business relationship with this vendor other than being a customer: We are an consulting firm, and I have installed this product to some of our clients.
    PeerSpot user
    reviewer1951863 - PeerSpot reviewer
    Cybersecurity Consultant at a wholesaler/distributor with 51-200 employees
    Real User
    Easy to use and great for both vulnerability scanning and remediation
    Pros and Cons
    • "The pricing is reasonable."
    • "There should be containerization within the VM."

    What is our primary use case?

    I'm helping customers manage vulnerabilities in their organization. It's for vulnerability scanning. 

    What is most valuable?

    It helps with the scanning of vulnerabilities. It's great at handling remediation after you've found an issue and managing the process of vulnerability remediation. The solution provides great advice.

    The solution offers very good intelligence and tracking the process of remediation.

    It goes very deep and doesn't just find the problem - it helps fix things too. 

    The setup is easy.

    The solution is easy to use.

    It offers good scalability.

    It's stable.

    The pricing is reasonable. 

    The solution can scale.

    What needs improvement?

    At times, some customers want more on-premises solutions, and yet vendors want us to load features onto the cloud. While it works in a hybrid way, they need to ensure they keep a customer's needs in mind.

    There should be containerization within the VM.

    For how long have I used the solution?

    I've been using the solution for two years. 

    What do I think about the stability of the solution?

    It is stable and reliable. I haven't had issues with it. There are no bugs or glitches. It doesn't crash or freeze. 

    What do I think about the scalability of the solution?

    The solution offers very good scalability. One license allows you to have three consoles. It's good for a distributed environment. 

    Which solution did I use previously and why did I switch?

    I didn't use different solutions previously.

    How was the initial setup?

    The initial setup is quite easy. It's easy to use. You can deploy it in less than one hour. Everything happens very fast. It just depends on how long you want to test before implementation. The tuning, however, is a bigger process. 

    What's my experience with pricing, setup cost, and licensing?

    The solution isn't too expensive. The company offers good bundles. The pricing is simple and based on assets. It's transparent. 

    Which other solutions did I evaluate?

    I did evaluate other solutions before using this solution. I looked online. 

    What other advice do I have?

    I'm a partner, not a customer.

    I've been using the solution's latest version and updating it often. 

    I'd advise people to use the product as a vulnerability scanner and as a remediation tool. They should look at the whole brand and see if any of their other products can integrate with the scanner. 

    I would rate the solution nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: partner
    PeerSpot user
    reviewer1327302 - PeerSpot reviewer
    Security Consultant at a tech vendor with 11-50 employees
    Real User
    Highly flexible, beneficial workflows, and accurate scanning
    Pros and Cons
    • "The most valuable features of Rapid7 InsightVM are the accurate level of scanning and the workflows are good."
    • "The on-premise updates could improve from Rapid7 InsightVM."

    What is our primary use case?

    The main use cases of Rapid7 InsightVM are finding configuration vulnerability checks and patching recommendations. These two are the main use cases that everybody's looking for.

    What is most valuable?

    The most valuable features of Rapid7 InsightVM are the accurate level of scanning and the workflows are good.

    What needs improvement?

    The on-premise updates could improve from Rapid7 InsightVM.

    For how long have I used the solution?

    I have been using Rapid7 InsightVM for approximately three years.

    What do I think about the scalability of the solution?

    Rapid7 InsightVM is scalable. You could use it for as many assets as you like. It is very scalable and flexible. 

    How are customer service and support?

    The technical support is good in their knowledge, but they are a little slow.

    How was the initial setup?

    The initial setup of Rapid7 InsightVM was straightforward.

    I would rate the ease of setup of Rapid7 InsightVM a three out of five.

    What other advice do I have?

    I rate Rapid7 InsightVM an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2025
    Buyer's Guide
    Download our free Rapid7 InsightVM Report and get advice and tips from experienced pros sharing their opinions.