Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Metasploit
Score 9.0 out of 10
N/A
Metasploit is open source network security software described by Rapid7 as the world’s most used penetration testing framework, designed to help security teams do more than just verify vulnerabilities, manage security assessments, and improve security awareness.N/A
Nmap
Score 8.4 out of 10
N/A
Nmap is a free, open source network discovery, mapper, and security auditing software. Its core features include port scanning identifying unknown devices, testing for security vulnerabilities, and identifying network issues.
$49,980
one-time fee
Qualys TruRisk Platform
Score 6.0 out of 10
N/A
Qualys TruRisk Platform (formerly Qualys Cloud Platform, or Qualysguard), from San Francisco-based Qualys, is network security and vulnerability management software featuring app scanning and security, network device mapping and detection, vulnerability prioritization schedule and remediation, and other features to provide vulnerability management and network attack surface reduction.N/A
Pricing
MetasploitNmapQualys TruRisk Platform
Editions & Modules
No answers on this topic
Nmap OEM Small/Startup Company Redistribution License - Quarterly Term Maintenance Fee
$7,980
Every Three Months per license
Nmap OEM Mid-Sized Company Redistribution License - Quarterly Term Maintenance Fee
$11,980
Every Three Months per license
Nmap OEM Enterprise Redistribution License - Quarterly Term Maintenance Fee
$13,980
Every Three Months per license
Nmap OEM Small/Startup Company Redistribution License - Annual Maintenance Fee
$14,980
per year per license
Nmap OEM Mid-Sized Company Redistribution License - Annual Maintenance Fee
$19,980
per year per license
Nmap OEM Enterprise Redistribution License - Annual Maintenance Fee
$23,980
per year per license
Nmap OEM Small/Startup Company Redistribution License - Perpetual License
$49,980
one-time fee per license
Nmap OEM Small/Startup Company Redistribution License - 5 year prepay Maintenance Fee
$59,920
Every Five Years per license
Nmap OEM Mid-Sized Company Redistribution License - 5 year prepay Maintenance Fee
$79,920
Every Five Years per license
Nmap OEM Mid-Sized Company Redistribution License - Perpetual License
$79,980
one-time fee per license
Nmap OEM Enterprise Redistribution License - 5 year prepay Maintenance Fee
$95,920
Every Five Years per license
Nmap OEM Enterprise Redistribution License - Perpetual License
$98,980
one-time fee per license
No answers on this topic
Offerings
Pricing Offerings
MetasploitNmapQualys TruRisk Platform
Free Trial
NoNoNo
Free/Freemium Version
NoNoNo
Premium Consulting/Integration Services
NoNoNo
Entry-level Setup FeeNo setup feeNo setup feeNo setup fee
Additional DetailsAll perpetual licenses include a six-month trial period during which you can cancel for any reason and receive a full refund of all money paid (including maintenance). The term license is only a 3-month commitment and cal also be terminated with full refund during the first 30 days of the initial quarter.
More Pricing Information
Community Pulse
MetasploitNmapQualys TruRisk Platform
Considered Multiple Products
Metasploit
Chose Metasploit
Metasploit is an all around good suite of tools to test and validate potential vulnerabilites. Other tools have bits and pecies such as Nmap, Nessus, Burp Suite, etc. but Metasploit can function in the same way but more.
Nmap
Chose Nmap
While mainly a CLI tool, there is an unofficial GUI. This can help the learning curve but unlike Nessus and Nexpose where there is a well-made user interface, with NMAP you need to really leverage the CLI for the power behind it. When it comes to modules being community-driven …
Qualys TruRisk Platform
Chose Qualys TruRisk Platform
Qualysguard gave us the tools we needed that were benificial to our job without us having to do too much manual interaction such as with Nmap, Metasploit , etc. It was a very efficient platform that I would go to again.
Chose Qualys TruRisk Platform
Deploying Qualys is really easy, in less than a day you can have everything ready for scanning. Also, Qualys has tons of reports and has tons of extension apps (such as the Asset Management App, which I love).
Features
MetasploitNmapQualys TruRisk Platform
Network Performance Monitoring
Comparison of Network Performance Monitoring features of Product A and Product B
Metasploit
-
Ratings
Nmap
5.3
17 Ratings
41% below category average
Qualys TruRisk Platform
-
Ratings
Automated network device discovery00 Ratings5.011 Ratings00 Ratings
Network monitoring00 Ratings10.012 Ratings00 Ratings
Baseline threshold calculation00 Ratings9.06 Ratings00 Ratings
Alerts00 Ratings3.04 Ratings00 Ratings
Network capacity planning00 Ratings6.07 Ratings00 Ratings
Packet capture analysis00 Ratings2.07 Ratings00 Ratings
Network mapping00 Ratings10.016 Ratings00 Ratings
Customizable reports00 Ratings1.010 Ratings00 Ratings
Wireless infrastructure monitoring00 Ratings2.08 Ratings00 Ratings
Hardware health monitoring00 Ratings5.06 Ratings00 Ratings
Threat Intelligence
Comparison of Threat Intelligence features of Product A and Product B
Metasploit
-
Ratings
Nmap
-
Ratings
Qualys TruRisk Platform
8.7
7 Ratings
8% above category average
Network Analytics00 Ratings00 Ratings8.96 Ratings
Threat Recognition00 Ratings00 Ratings8.37 Ratings
Vulnerability Classification00 Ratings00 Ratings8.87 Ratings
Automated Alerts and Reporting00 Ratings00 Ratings9.07 Ratings
Threat Analysis00 Ratings00 Ratings8.27 Ratings
Threat Intelligence Reporting00 Ratings00 Ratings8.97 Ratings
Automated Threat Identification00 Ratings00 Ratings8.77 Ratings
Vulnerability Management Tools
Comparison of Vulnerability Management Tools features of Product A and Product B
Metasploit
-
Ratings
Nmap
-
Ratings
Qualys TruRisk Platform
8.5
9 Ratings
3% above category average
IT Asset Realization00 Ratings00 Ratings8.89 Ratings
Authentication00 Ratings00 Ratings7.96 Ratings
Configuration Monitoring00 Ratings00 Ratings8.57 Ratings
Web Scanning00 Ratings00 Ratings8.88 Ratings
Vulnerability Intelligence00 Ratings00 Ratings8.67 Ratings
Best Alternatives
MetasploitNmapQualys TruRisk Platform
Small Businesses

No answers on this topic

NinjaOne
NinjaOne
Score 9.1 out of 10
Action1
Action1
Score 9.5 out of 10
Medium-sized Companies
Veracode
Veracode
Score 8.8 out of 10
SolarWinds NetFlow Traffic Analyzer (NTA)
SolarWinds NetFlow Traffic Analyzer (NTA)
Score 9.4 out of 10
Action1
Action1
Score 9.5 out of 10
Enterprises
Veracode
Veracode
Score 8.8 out of 10
SolarWinds NetFlow Traffic Analyzer (NTA)
SolarWinds NetFlow Traffic Analyzer (NTA)
Score 9.4 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
MetasploitNmapQualys TruRisk Platform
Likelihood to Recommend
10.0
(5 ratings)
10.0
(18 ratings)
8.6
(25 ratings)
Usability
-
(0 ratings)
10.0
(1 ratings)
2.0
(1 ratings)
Support Rating
7.0
(1 ratings)
8.4
(7 ratings)
5.0
(7 ratings)
User Testimonials
MetasploitNmapQualys TruRisk Platform
Likelihood to Recommend
Rapid7
It is easy to use with sufficient documentation on how to use the tools for end users or newbies. Experienced testers will find it easy to customise and configure the test cases. Just wished that I could have taken up a course on using this tool in my study days so that I could had explored more and improved my familiarity with the tool, unlike when working where access and time to explore the other features of the tool is limited
Read full review
Open Source
If you're a sysadmin, or anyone who's had to deploy network services, you've almost certainly had to use Nmap at some point or other. Need to see what devices are on your LAN? Nmap can tell you that. Want to check which ports your web server has open to the internet? Nmap is your friend.
Nmap is a powerful command-line tool and has many options that require some reading of documentation to get the best out of (although generally straightforward). If the thought of working at the command-line scares you (presumably not if you're reading this review), then you may want a much simpler tool, or at least check out Zenmap GUI.
Read full review
Qualys
Qualys Cloud Platform is well suited for organizations that need additional tools to secure and bolster their security from end to end. The automated, real-time threat protection is very quick to notify an admin of potential vulnerabilities and risks, as well as recommending quick fixes to resolve/close the gap before an incident occurs. QCP excels at portraying all of these in a single pane of glass, and find that the Qualys reports are more detailed than competitor product lines. One of our big issues with QCP is that you do have to pay for each scanner, which can quickly add up to large costs. For this reason, I would rate Qualys at a ~7 due to great features and functionality, but overall value could be better for a large organization. I would also say that QCP may make more sense for smaller organizations due to this pricing model.
Read full review
Pros
Rapid7
  • Easy to use.
  • Many exploits available.
  • Multi-platform.
Read full review
Open Source
  • NMap provides a very fast and a very thorough network "sweep" that allows you to quickly map out exactly what's on your network.
  • NMap is highly configurable. The "canned" choices are very good in most instances, but using various switches and options, you can create a very specific scan and get exactly the results you're looking for.
  • NMap is easy to use. Even a new administrator will be able to use the graphical version (Zenmap) with efficiency right away.
Read full review
Qualys
  • It really does well at vulnerability scanning, which it is well known for. It's accuracy at finding vulnerabilities is top notch, more so than a lot of other vulnerability tools out there. In an organization/company you want this kind of accuracy at finding vulnerabilities in your network/endpoints
  • It is very good at managing endpoints on a consistent basis, meaning you can add endpoints to Qualys and have the platform scan/track/protect for vulnerabilities on an ongoing basis, without user intervention
  • It does really well at separating out and identifying what levels of criticality each vulnerability should fall into. This way, an organization/company can attack the more critical vulnerabilities first
Read full review
Cons
Rapid7
  • More robust menus
  • Better plugin inter-operation
Read full review
Open Source
  • The GUI version on Nmap could use some improvement with the options that are available to do scans. For example, they could make it easier to select options for the different types of scanning for people who are beginners
  • There are no abilities to schedule a scan in the Nmap tool.
  • An intensive scan sometimes takes too much time to complete.
Read full review
Qualys
  • This program is really complicated, the multiple functions that are presented to us are not very clear and in some cases, it is a matter of intuition to execute a function, it is not very informative.
  • The interface of this program can be a real problem; for our taste, this program looks a bit messy, and the interface does not help or guide you to find the options you need.
Read full review
Usability
Rapid7
No answers on this topic
Open Source
Nmap uses are very practical and I don't think there is a better tools for what Nmap does. It is open-sources that therefore there is no cost to use it. It offers a number of benefits, including but not limited to network mapping, port scanning and more. It is very reliable as a network scanning tool.
Read full review
Qualys
Again, the usability of Qualys has been a pinpoint for this entire review. It was easily the worst thing about the product and because of this, I would not recommend Qualys to anybody in my field. This should be something that Qualys strives to improve if they wish to stay in business.
Read full review
Support Rating
Rapid7
We don't use it.
Read full review
Open Source
There is a very large support community and a robust selection of add-ons and scripts. Once you get the use down this is one of the most powerful tools and you can find anything you are looking for as far as examples on the web. While not having official support its not lacking by any means.
Read full review
Qualys
They had a support page within the WAS to report any concerns or seek help. But the UI of that is not smooth. Regardless support staff were pretty responsive and helpful. They scheduled calls to understand and address our problems. Email support is good as well.
Read full review
Alternatives Considered
Rapid7
Metasploit is the most well-known tool in the average pen tester's toolkit. It's hard to compare to its neighbor's due to its size and following.
Read full review
Open Source
Alternatives to Nmap (other IP scanners) are often much more limited in what they can do; They often only allow you to scan a specific subset of ports or a limited number of IP addresses in one command. Nmap is unrestricted in that regard. What makes Nmap stand out above the rest, is the complete network analysis package you get with it. It allows IP scanner, network deep-dives, hardware analysis, vulnerability analysis, encryption detailing, and so much more, in one free application
Read full review
Qualys
As described before Qualys is used to scan periodically the environment in order to check if there are some packages (Linux) or Applications (Windows) outdated, generating reports to the Service Owners, fulfilling what's is expected from us, attending all our expectations regarding the tool. That's why we'd choose Qualys to our organization.
Read full review
Return on Investment
Rapid7
  • Positive: Improves efficiency of our network penetration testing operations.
  • Positive: Allows for collaboration and information sharing during a penetration test.
Read full review
Open Source
  • Nmap with Wireshark is free, so it's been a great combo team to gather info and test.
  • It's allowed us to avoid fines from false positives and to fix actual issues ourselves.
  • Great for finding hosts, helps keep the network secure.
Read full review
Qualys
  • Big time-saving tool vs. having to comb through several system reports which ultimately can still have you missing unapproved software.
  • Quick snapshot via the dashboard provided a nice summary of where you're assets meet or do not meet your organization's policy requirements.
Read full review
ScreenShots