Metasploit vs. Onapsis

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Metasploit
Score 9.0 out of 10
N/A
Metasploit is open source network security software described by Rapid7 as the world’s most used penetration testing framework, designed to help security teams do more than just verify vulnerabilities, manage security assessments, and improve security awareness.N/A
Onapsis
Score 9.7 out of 10
N/A
Onapsis, headquartered in Boston, offers application security software to enterprises in the form of the Onapsis Security Platform for SAP and the Onapsis Security Platform for Oracle E-Business Suite.N/A
Pricing
MetasploitOnapsis
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
MetasploitOnapsis
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
MetasploitOnapsis
Best Alternatives
MetasploitOnapsis
Small Businesses

No answers on this topic

GitLab
GitLab
Score 8.6 out of 10
Medium-sized Companies
Veracode
Veracode
Score 9.2 out of 10
Veracode
Veracode
Score 9.2 out of 10
Enterprises
Veracode
Veracode
Score 9.2 out of 10
Veracode
Veracode
Score 9.2 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
MetasploitOnapsis
Likelihood to Recommend
10.0
(5 ratings)
9.0
(3 ratings)
Support Rating
7.0
(1 ratings)
-
(0 ratings)
User Testimonials
MetasploitOnapsis
Likelihood to Recommend
Rapid7
It is easy to use with sufficient documentation on how to use the tools for end users or newbies. Experienced testers will find it easy to customise and configure the test cases. Just wished that I could have taken up a course on using this tool in my study days so that I could had explored more and improved my familiarity with the tool, unlike when working where access and time to explore the other features of the tool is limited
Read full review
Onapsis
Onapsis is divided into 4 major components,
  1. Assess
  2. Comply
  3. Defend
  4. Control
In assess, it does a whitebox and blackbox testing of the ERP systems that have been added to the Onapsis console. It highlights relevant application issues and automates the process, also provides the solutions to implement the fix. In comply, it provides a governance on the various regulatory compliances which the firm has to follow, as well as provides a firm grip to the audit and ERP admin team. In control, it enables a workflow of 15 pre-defined parameter values within the SAP system and helps monitor, and track the changes made to those parameters. The capabilities are to either block, or request for an approval for changes made to those parameters in addition to just monitoring them. In defend, it goes through the SAP logs; and compares it with a pre-defined ruleset to alert the end-users via email or SIEM tool or both.
Read full review
Pros
Rapid7
  • Easy to use.
  • Many exploits available.
  • Multi-platform.
Read full review
Onapsis
  • Eliminating the manual process improves the overall accuracy of results and also frees up valuable resources to focus on other different projects.
  • Onapsis provides great leverage to our technical teams in order to review in a standardized way of the landscape.
  • Onapsis always matches vulnerabilities with useful context and finds possible solutions.
  • Onapsis is usually implemented to continuously monitor, and alert us on any issues on the SAP systems. Not only this but implementing Onapsis also eliminates the network on the year-end and month-end audits and helps in making the overall process faster, smooth, efficient as well as accurate.
Read full review
Cons
Rapid7
  • More robust menus
  • Better plugin inter-operation
Read full review
Onapsis
  • Multiple UIs
  • No proper customization of UI log-off
  • Tedious setup of Control component
  • No proper error messages received
Read full review
Support Rating
Rapid7
We don't use it.
Read full review
Onapsis
No answers on this topic
Alternatives Considered
Rapid7
Metasploit is the most well-known tool in the average pen tester's toolkit. It's hard to compare to its neighbor's due to its size and following.
Read full review
Onapsis
Honestly, I havent use something like Onapsis before and currently I am not aware if there is something similiar out there. They are one of a kind and is a complete suit, so is unlikelly that someone from outside will appear with a better solution.
Read full review
Return on Investment
Rapid7
  • Positive: Improves efficiency of our network penetration testing operations.
  • Positive: Allows for collaboration and information sharing during a penetration test.
Read full review
Onapsis
  • It offers very reasonable packages.
  • The customer support of Onapsis is reliable and efficient.
  • It is a great platform as it shows a unified and easy-to-read different and complex topics in a simpler way.
Read full review
ScreenShots