Softwr
Metasploit logo

Metasploit

The world's most used penetration testing framework

Overview

What Metasploit does

Metasploit is the world's most widely used penetration testing framework. It helps security teams verify vulnerabilities, test security awareness, and manage security assessments.

What people use it for

  • Penetration testing and exploit development against known vulnerabilities
  • Validating whether a reported vulnerability is actually exploitable
  • Running phishing and credential attack simulations on the Pro edition

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Metasploit.

  • The free Framework edition is command line only; the web interface is Pro only
  • Automated exploitation, automated credential attacks and antivirus evading dynamic payloads are restricted to Metasploit Pro
  • Reporting, audit wizards, task chains and closed loop vulnerability validation are Pro only
  • Rapid7 publishes no price for Metasploit Pro and routes buyers to contact sales

Pricing

What Metasploit costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Metasploit Framework (OSS)

Free

  • Open source
  • 1500+ exploits
  • Command line
  • Community modules
  • Scripting

Metasploit Pro

Free

  • Web interface
  • Automated testing
  • Phishing campaigns
  • Reporting
  • Contact sales for pricing

Capabilities

Features

  • Exploit database

    Exploit database capability

  • Payload generation

    Payload generation capability

  • Post-exploitation

    Post-exploitation capability

  • Evasion modules

    Evasion modules capability

  • Auxiliary scanners

    Auxiliary scanners capability

  • Social engineering

    Social engineering capability

  • Credential harvesting

    Credential harvesting capability

  • Session management

    Session management capability

  • Nmap

    Integration with Nmap

  • Nessus

    Integration with Nessus

  • Nexpose

    Integration with Nexpose

  • Cobalt Strike

    Integration with Cobalt Strike

Behind it

Who makes Metasploit

Company
Rapid7
Based in
Boston, Massachusetts, USA

Keep looking

Where to go from Metasploit

Other Security Cybersecurity software

Softwr does not host reviews and shows no star rating for Metasploit, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Metasploit