Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

Rapid7 Expands Integration Between Metasploit and Nexpose

On Tuesday, Boston-based Rapid7 announced that they have introduced the means to increase vulnerability management efficiency by offering tighter integration between Nexpose and Metasploit.

On Tuesday, Boston-based Rapid7 announced that they have introduced the means to increase vulnerability management efficiency by offering tighter integration between Nexpose and Metasploit.

The tie-in of the two products enables security teams to locate issues, prove they are exploitable and prioritize them, mitigate them, and then track the effectiveness of the mitigation itself. This process is important, Rapid7 explains, because while a given vulnerability may be a large problem for an organization, the same vulnerability could be no problem at all to a different organization; even if they are in the same market space.

Rapid7According to the release notes, the latest integrations between Nexpose and Metasploit Pro offer security teams the ability to import vulnerability scans; automatically validate the exploitability of a given high-risk vulnerability; spot-check individual vulnerabilities; push granular exploit results back to Nexpose via Vulnerability Exceptions; push device classifications back to Nexpose Asset Groups via Metasploit Tags; and monitor all of this with enhanced reports that are augmented with Nexpose data.

“Security professionals face a huge and complex challenge and they need to know that they are focusing their efforts on the highest risk vulnerabilities,” said HD Moore, CSO of Rapid7 and chief architect of the Metasploit Project.

“With Metasploit and Nexpose, security professionals can identify which of the numerous potential vulnerabilities are real in-roads for an attacker and prioritize these for remediation, making a more meaningful improvement to the organization’s security posture,” he added.

Metasploit version 4.4 is available now.

Advertisement. Scroll to continue reading.
Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.