Skip to main content
TrustRadius
Rapid7 InsightVM

Rapid7 InsightVM
Formerly Nexpose

Overview

What is Rapid7 InsightVM?

InsightVM is presented as the next evolution of Nexpose, by Rapid7. This Insight cloud-based solution features everything included in Nexpose, such as Adaptive Security and the proprietary Real Risk score, and extends visibility into cloud and containerized infrastructure. InsightVM also…

Read more
Recent Reviews

TrustRadius Insights

Rapid7 NeXpose is widely used across organizations for various use cases related to vulnerability management and security assessment. With …
Continue reading

Expose on Nexpose

8 out of 10
June 21, 2017
Incentivized
Nexpose from Rapid7 is a vulnerability scanner that supports the vulnerability management lifecycle. It addresses discovery, detection, …
Continue reading
Read all reviews
Return to navigation

Pricing

View all pricing

Log Management

$19

Cloud
per GB

Vulnerability Management

$22

Cloud
per asset

insightIDR

$52

Cloud
per asset

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Product Demos

Rapid7 InsightVM - Managing Remediation Activities for Discovered Vulnerabilities Lab Demo

YouTube

PrintNightmare and HiveNightmare Vulnerability Assessment with Rapid7 InsightVM - Lab Demo 5

YouTube

Rapid7 InsightVM - Security Console Features Lab Demo 3 by Jovo

YouTube

Rapid7 InsightVM –Vulnerability Analysis, Reporting & Dynamic Assets Filtering - Lab Demo 6 by Jovo

YouTube

Rapid7 InsightVM Walkthough Demo Rapid7 InsightVM Architecture and Components Session 1

YouTube
Return to navigation

Product Details

What is Rapid7 InsightVM?

Rapid7 InsightVM Video

Overview Video: InsightVM

Rapid7 InsightVM Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

InsightVM is presented as the next evolution of Nexpose, by Rapid7. This Insight cloud-based solution features everything included in Nexpose, such as Adaptive Security and the proprietary Real Risk score, and extends visibility into cloud and containerized infrastructure. InsightVM also offers advanced remediation, tracking, and reporting capabilities not included in Nexpose.

Reviewers rate Automated Alerts and Reporting and Configuration Monitoring highest, with a score of 8.7.

The most common users of Rapid7 InsightVM are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(74)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Rapid7 NeXpose is widely used across organizations for various use cases related to vulnerability management and security assessment. With its powerful scanning capabilities, it allows users to discover vulnerabilities in their infrastructure, including cloud-based servers. Many users implement NeXpose as a pentesting tool to scan sensitive servers and identify weaknesses that could potentially be exploited by hackers. This helps organizations proactively address vulnerabilities before they can be exploited, enhancing overall security posture. Users have found NeXpose to be valuable for vulnerability scanning of both current assets and new build servers, providing asset owners with weekly reports to track trends and prioritize remediation efforts. Security consultants also rely on NeXpose for performing vulnerability assessments for their clients, leveraging its robust features such as risk classification, impact analysis, and reporting.

In addition to vulnerability management, Rapid7 NeXpose is often utilized for meeting regulatory requirements, such as PCI compliance. Organizations leverage the tagging features of NeXpose to easily sort scans and reports for different asset owners or teams, streamlining the vulnerability management process. Furthermore, the software serves as the primary vulnerability scanner across the organization, acting as the source of truth for identifying current vulnerabilities in the environment. It supports the discovery and assessment of devices on networks, encompassing physical servers, virtual servers, and cloud-based servers. Another notable use case is its integration with Rapid7 InsightVM, allowing centralized compliance and vulnerability management by scanning services or devices in the network and generating comprehensive reports on vulnerabilities and remediation actions.

Overall, Rapid7 NeXpose provides organizations with a reliable solution to discover vulnerabilities, mitigate risks, and maintain a strong security posture through regular scanning and assessment of their infrastructure.

Attribute Ratings

Reviews

(1-11 of 11)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Rapid7 InsightVM is very much useful in using as a Centralized tool or console for Compliance and vulnerability management. It scans the services or devices in your network and generates reports based on its own database. This report include all the running vulnerabilities and also it gives details on remediation of it. So it becomes very much useful for handling vulnerability management and compliance requirement.
  • Automatic Scanning of devices
  • Good reporting
  • Easy to manage
  • Costing
  • False positive findings
Rapid7 InsightVM is well suited for large enterprises where it automatically detects new devices and start scanning it. So it completely eliminates the dependency of manually adding newly added services / devices for the scanning. Even same goes for the devices which are decommissioned. No need of manually removing it. So this way, it works very well with large enterprises as a Centralized tool for vulnerability and compliance management.
Varun Khare | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
As a financial institution, we have to be up and running securely 24x7x365. So be online is easier with Cloud services but security is concern when you operate in Cloud environment and that is where Rapid7 InsightVM helps us. Rapid7 InsightVM help us to scan our overall infrastructure including cloud infra. here we have complete glance our vulnerability and remediation.
  • Scanning Vulnerabilities
  • Checking Missing Configs
  • Asset Management
  • Policy Assessment has improvement needed
  • Shadow IT Host
Well, I would say It worked well in all aspects then Policy Assessments and Ghost Asset management. This need to improved because we are scanning many ghost host that are no longer anymore in system.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
I used to use Rapid7 InsightVM as a pentesting tool. I implemented the solution on servers to test the client environment by scanning sensitive servers. The main goal is to find weaknesses and vulnerabilities in the systems that could be exploited by hackers. And then generate a report that could be used as a reference for patching the system.
  • vulnerability managment
  • applicative security
  • orchestration
  • produt implementation
  • report clearness
  • time to execute scans can be improved
Rapid7 InsightVM is perfect for a scenario where IT admin or CISO wants to scan its infrastructure to be sure that there is no vulnerability that could be exploited from outside or inside the company. It also could be used to automate patching and dealing with vulnerabilities. It's also adapted for users that need cloud security management
Score 7 out of 10
Vetted Review
Verified User
Incentivized
We are currently using the software as our primary vulnerability scanner and source of truth for current vulnerabilities in the environment. For new systems, it is required for the system to be registered in Rapid7 InsightVM (Nexpose) and have a scan conducted before it is allowed into production. It is a critical pillar in our environment.
  • report on a system vulnerability
  • consistent scanning
  • easy to understand results
  • System management
  • UI
  • Noise tuning from the scans on systems
For highly detailed reports of vulnerabilities in an environment, Rapid7 InsightVM (Nexpose) is top-notch. The data is easily manipulated to get the results you are looking for. Setting up groups for active scans on a schedule has been a great help as well as the ad-hoc reports for any new vulns being reported.
Score 7 out of 10
Vetted Review
Verified User
Incentivized
We currently use Rapid7 Nexpose for all Vulnerability scanning for current and new assets. Several asset groups have been created with assets owners receiving weekly reports for just the assets they own for a weekly snapshot to gauge their trending. We also utilize ad-hoc scans to ensure new devices do not have outstanding patches before being deployed.
  • Creating Device Groups is very easy.
  • The API tie ins work well.
  • Frequent updates and console lockups.
  • A lot of issues with scans running long out of nowhere, causing resource issues for the next scans.
  • Works well most of the time for even large enterprise organizations, but takes a lot of care and feeding to ensure it's running properly.
  • We have had several issues with 'ghost machines' not updating and continue to report on IP's with no devices attached.
  • Could use better filtering and reporting built-in and more customized options.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
I have used Rapid7 Nexpose for performing vulnerability assessment scanning. It is a vulnerability management tool which can perform vulnerability scans and report the vulnerabilities. As a security consultant, I have used this tool to perform scans for our clients.
  • Being a vulnerability scanner tool, its purpose is to scan the systems to find the vulnerabilities. We can define the assets like IP address for the scans and it also allows to either schedule the scan at a preferred time or start the scan immediately. Upon completion of the scan, this tool can result provide the details like host type, OS information, hardware address, along with the vulnerabilities.
  • Rapid7 Nexpose has a list of templates to perform the scan. Once the templates are defined then the scans are performed accordingly.
  • It also contains an option to add credentials/authentication using passwords, usernames, private keys to perform the credential-based scans which I think is a great feature.
  • From my experience of using this tool, sometimes it gives more false positives. A few times I had performed the scan on the same IP address using Qualysguard and Nexpose, but after comparing the scan results I had found that Qualysguard had provided more accurate vulnerability information.
Being a vulnerability scanning tool, Rapid7 Nexpose is very well suited to perform vulnerability scans and document the scan results. Rapid7 Nexpose is well suited if someone wants to perform the credential/authentication scan for assets like public IP addresses. However, I think it is not appropriate when accurate scan results are required because of the number of false positives it provides.
Score 7 out of 10
Vetted Review
Verified User
Incentivized
This tool is being used across a subset of the organization; it is an intuitive vulnerability scanner with amazing support service and solves the purpose. However it has a few downsides when it comes to the level of reporting etc., we expect from a vulnerability management solution.
  • Intuitive
  • End point agent deployment and management is easy
  • RBAC on the console is great
  • Scanning capabilities like specific vulnerabilities & compliance etc. are good
  • In comparison to Tenable SecurityCenter we saw it didn't exactly find the same vulnerabilities which we would assume it should have
  • We rely on a ticketing system and not our VM tool to assign tasks so wasn't too useful having that in there
  • Filtering capabilities aren't as good as its competitors
All in all, it's a great vulnerability management platform and would work for most companies looking for a straightforward solution. We rely heavily on integration and automation and it has room for improvement there. We would like it to connect to applications out of the box or vendor supported rather than creating those connectors in-house.
Score 5 out of 10
Vetted Review
Verified User
Incentivized
Rapid7 NeXpose performs discovery and vulnerability assessment of devices on a network. This data can be exported into other tools, or produce reports for threat remediation. The software supports physical servers, virtual servers, and cloud-based servers. For large environments, additional scanners can be deployed with the same options. Multiple OSs are supported and backups can be enabled for restoration across platforms.

  • Queries against inventory are easy and useful
  • Most threats discovered a have plenty of detail about the nature of the problem and how to mitigate
  • Dashboards are abundant
  • Once the organization of the tool is understood, operation is easy
  • Devices found and scanned are never removed. Removal must be done manually with no option for automation.
  • The database can be fragile. Ours quietly corrupted and progressively degraded until we had to restore and lose 6 months of data. Still didn't fix it and had to be rebuilt again losing all data.
  • Workflow for delegating remediation is supposed to be helpful, but can also become cumbersome.
  • Scheduling can become a nightmare if not monitored closely. We found jobs had failed to run because the server had gone offline. When the server came online, it did not try to run missed jobs. Running missed jobs all at once can overload the server, but searching for and launching a large number of missed jobs manually is a pain.
When it works, its a fantastic tool with plenty of value to spare. When it doesn't work, its a time sucking money pit of despair. I've used the data to prove other systems were not reporting correctly. I could count systems by type faster than any other inventory system. I could find how many machines had a specific version of software in minutes. I've also lost weeks of time trying to get scans to run consistently. We've lost months of data from failure. Its a 50/50 crap shoot. Are you willing to put up with problems for fantastic data? It could work perfectly for you. It could also be a brick.
August 16, 2017

Rapid7 NeXpose

Charles Smunt, CISSP | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Rapid 7 NeXpose is used in the organization as the powerhouse of vulnerability management. It is used by the Information Security Office to discover vulnerabilities for the enterprise.
  • Real-Time Risk views
  • Streamlines your view on most vulnerable assets
  • Provides the ability to scan for policy configuration and compare with control requirements
  • Integration with many other vendors; SIEM, Ticketing, Next gen Firewalls, etc
  • Console crashes frequently
  • Licensing is very expensive, per asset
Best in small environments
June 21, 2017

Expose on Nexpose

Score 8 out of 10
Vetted Review
Verified User
Incentivized
Nexpose from Rapid7 is a vulnerability scanner that supports the vulnerability management lifecycle. It addresses discovery, detection, verification, risk classification, impact analysis, reporting and mitigation. There are a wide variety of versions available: standalone software, an appliance, virtual machine, a managed service, or a private cloud deployment. User interaction is through a web interface. There is a free (but limited) community edition. It integrates Metasploit for vulnerability exploitation which provides very timely results against known and active vulnerabilities.
  • Timely content by virtue of being tied to metasploit
  • Easy to use interface
  • Depth across the security life cycle
  • Management side of things is a bit less functional than [Nexus]
  • Perhaps more robust reporting for higher level reporting
  • The alerting/messaging system could use additional flexibility
Rapid7 is well suited for security operations teams and includes an ability to tie almost anything into it via the Ruby API. The reporting provides prioritization of results which easily directs the team to get the quickest security gains with the least amount of effort, "apply this patch to remediate this amount of vulnerabilities on this device."
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Rapid7 NeXpose is being used across the whole organization directly or indirectly by multiple departments. It is being used to scan the current assets and new build servers for vulnerabilities. It is also the main tool to find the vulnerabilities for PCI compliance and remediation. In addition, we utilize its tagging features to help sort out scans and reports for different asset owners or teams. We also use its features of services and software inventory findings to assist incident response in case any assets need a more deeper info, which may compensate some missing features in the product in case you can't find a away to achieve in the GUI.
  • The API is also a great tool for us to automate lots of routine procedures like scan and report of asset(s) BY EMAIL.
  • Tagging. It helps sort out results and reports for respective assets Owner for remediation without a lengthy report including unnecessary information for that particular team.
  • SQL Reporting. It provides advanced reporting and export capabilities that you can not find in the stock report template.
  • Scan for individual asset(s) (with schedule) should be more friendly and easy in GUI rather than going through its corresponding site for scheduling.
  • Scan with Credentials can not be customized or prioritized the use of credentials for different sites or assets. How credentials are applied or the order of applying is still not very customizable.
  • SQL database (PostgreSQL) should be opened to customer, since it lives on customer's appliance, so that we can do live monitoring and query in a more robust way.
This is NOT a point-and-click product.
Rapid7 NeXpose is well suited for company or team have member(s) with scripting and SQL skills. You may find some features missing or it is not working the way you want from time to time. It is great that Rapid7 open the products' API, and maybe they know their product is NOT perfect nor suit everyone's need. The API can allow you to do more advanced work like automation, but if the team who use or manage it does not has member proficient in scripting or SQL query, it maybe frustrated to just purely going through the GUI or wait the support for solution.
Return to navigation