TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Metasploit

    Score9 out of 10
    N/AMetasploit is open source network security software described by Rapid7 as the world’s most used penetration testing framework, designed to help security teams do more than just verify vulnerabilities, manage security assessments, and improve security awareness.N/A

    Onapsis

    Score9.9 out of 10
    N/AOnapsis, headquartered in Boston, offers application security software to enterprises in the form of the Onapsis Security Platform for SAP and the Onapsis Security Platform for Oracle E-Business Suite.N/A
    Pricing
    MetasploitOnapsis
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    MetasploitOnapsis
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details——
    More Pricing Information
    Best Alternatives
    MetasploitOnapsis
    Small Businesses
    No answers on this topic
    Rencore Code (SPCAF)
    Score8.8 out of 10
    Medium-sized Companies
    No answers on this topic
    Trend Vision One Email and Collaboration Security
    Score9.9 out of 10
    Enterprises
    No answers on this topic
    Checkmarx
    Score7.5 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    MetasploitOnapsis
    Likelihood to Recommend
    10.0
    (5 ratings)
    9.0
    (3 ratings)
    Support Rating
    7.0
    (1 ratings)
    -
    (0 ratings)
    User Testimonials
    MetasploitOnapsis
    Likelihood to Recommend
    Rapid7
    It is easy to use with sufficient documentation on how to use the tools for end users or newbies. Experienced testers will find it easy to customise and configure the test cases. Just wished that I could have taken up a course on using this tool in my study days so that I could had explored more and improved my familiarity with the tool, unlike when working where access and time to explore the other features of the tool is limited
    Incentivized
    Read full review
    Onapsis
    Onapsis is divided into 4 major components,
    1. Assess
    2. Comply
    3. Defend
    4. Control
    In assess, it does a whitebox and blackbox testing of the ERP systems that have been added to the Onapsis console. It highlights relevant application issues and automates the process, also provides the solutions to implement the fix. In comply, it provides a governance on the various regulatory compliances which the firm has to follow, as well as provides a firm grip to the audit and ERP admin team. In control, it enables a workflow of 15 pre-defined parameter values within the SAP system and helps monitor, and track the changes made to those parameters. The capabilities are to either block, or request for an approval for changes made to those parameters in addition to just monitoring them. In defend, it goes through the SAP logs; and compares it with a pre-defined ruleset to alert the end-users via email or SIEM tool or both.
    Incentivized
    Read full review
    Pros
    Rapid7
    • Easy to use.
    • Many exploits available.
    • Multi-platform.
    Incentivized
    Read full review
    Onapsis
    • Eliminating the manual process improves the overall accuracy of results and also frees up valuable resources to focus on other different projects.
    • Onapsis provides great leverage to our technical teams in order to review in a standardized way of the landscape.
    • Onapsis always matches vulnerabilities with useful context and finds possible solutions.
    • Onapsis is usually implemented to continuously monitor, and alert us on any issues on the SAP systems. Not only this but implementing Onapsis also eliminates the network on the year-end and month-end audits and helps in making the overall process faster, smooth, efficient as well as accurate.
    Incentivized
    Read full review
    Cons
    Rapid7
    • More robust menus
    • Better plugin inter-operation
    Incentivized
    Read full review
    Onapsis
    • Multiple UIs
    • No proper customization of UI log-off
    • Tedious setup of Control component
    • No proper error messages received
    Incentivized
    Read full review
    Support Rating
    Rapid7
    We don't use it.
    Incentivized
    Read full review
    Onapsis
    No answers on this topic
    Alternatives Considered
    Rapid7
    Metasploit is the most well-known tool in the average pen tester's toolkit. It's hard to compare to its neighbor's due to its size and following.
    Incentivized
    Read full review
    Onapsis
    Honestly, I havent use something like Onapsis before and currently I am not aware if there is something similiar out there. They are one of a kind and is a complete suit, so is unlikelly that someone from outside will appear with a better solution.
    Incentivized
    Read full review
    Return on Investment
    Rapid7
    • Positive: Improves efficiency of our network penetration testing operations.
    • Positive: Allows for collaboration and information sharing during a penetration test.
    Incentivized
    Read full review
    Onapsis
    • It offers very reasonable packages.
    • The customer support of Onapsis is reliable and efficient.
    • It is a great platform as it shows a unified and easy-to-read different and complex topics in a simpler way.
    Incentivized
    Read full review
    ScreenShots