“We wanted an assessment services vendor that would run a penetration test of applications on Windows, Macs, and other devices, For that kind of undertaking, we preferred to work alongside someone in order to collaborate with them face-to-face – rather than remotely. You just can’t get the same results communicating exclusively via email and phone.”
"Whenever you log into IDR, it's simple. It maps to the kill chain. It allows me to prioritize. That visualization just makes my job a lot easier."
“We pull event data for InsightIDR directly from the event source, and every log source requires a transformation. The Rapid7 user behavior analytics approach is great, especially when it comes to enriching log data with user data. Your developers have properly invested in being able to show the right data in the right format.”
"Since using [InsightVM], we’ve cut down vulnerability detection and remediation time to under a week, added real-time progress tracking, and more easily reported metrics to the C-suite."
"Rapid7 Nexpose is simple to use and still meets the bank's security needs even after the organization doubled in size. Today Bridgehampton National Bank receives stellar audits and relies upon Nexpose to scan hundreds of workstations and a virtualized server environment."
"Verdict: For a large enterprise – really, no matter how large – this product is well worth your consideration. It brings the power of significant functionality with a history of reliability and excellent support options."
"Nexpose gives me live vulnerability data that updates the second my environment changes."
"Time is precious, so I don’t want to do something manually that I can automate. Leveraging the Metasploit Framework when automating any task keeps us from having to re-create the wheel as we can use the existing libraries and focus our efforts where it matters."
"Metasploit and Nexpose just work. They both have intuitive designs and provide a fast way to collect all the low-hanging security problems when a new system is deployed."
"Attack Replay saves me a lot of time. Developers don’t ask me nearly as often to run additional scans to test a new security bug patch—instead they can test it directly from the vulnerability report."
“Before, we had one scanner and it would come up with certain vulnerabilities. There wasn’t a lot on the internet side, and we would fix them and go with it. Then we got Nexpose on the production network and thought ‘Wow, there are a lot of vulnerabilities here.’ Maybe it’s because they’re not on the internet and the patching is done a little differently.”
“The saving grace is that you can have Nexpose vulnerabilities automatically imported into Metasploit to validate exploitability. It’s a seamless integration which saves me countless hours and allows me to focus on my highest risks.”
“Sometimes you purchase something and get buyer’s remorse. You wonder if you made the right decision. When we were doing the installation, though, that’s when I thought ‘Wow, these guys know their software.’ They knew a fix immediately, for everything.”
“We’ve used a lot of security products, between the two of us. All the big vulnerability players: Qualys, Nessus, Rapid7. They’re all great, but we’re a Nexpose customer, because it has been very user friendly and has given us the reporting functionality that we were looking for.”
“Integrating with Metasploit gives us the ability to easily penetration test, as well. Rapid7 is a trusted brand in the industry, and that means a lot.”