On Tuesday, Boston-based Rapid7 announced that they have introduced the means to increase vulnerability management efficiency by offering tighter integration between Nexpose and Metasploit.
The tie-in of the two products enables security teams to locate issues, prove they are exploitable and prioritize them, mitigate them, and then track the effectiveness of the mitigation itself. This process is important, Rapid7 explains, because while a given vulnerability may be a large problem for an organization, the same vulnerability could be no problem at all to a different organization; even if they are in the same market space.
According to the release notes, the latest integrations between Nexpose and Metasploit Pro offer security teams the ability to import vulnerability scans; automatically validate the exploitability of a given high-risk vulnerability; spot-check individual vulnerabilities; push granular exploit results back to Nexpose via Vulnerability Exceptions; push device classifications back to Nexpose Asset Groups via Metasploit Tags; and monitor all of this with enhanced reports that are augmented with Nexpose data.
“Security professionals face a huge and complex challenge and they need to know that they are focusing their efforts on the highest risk vulnerabilities,” said HD Moore, CSO of Rapid7 and chief architect of the Metasploit Project.
“With Metasploit and Nexpose, security professionals can identify which of the numerous potential vulnerabilities are real in-roads for an attacker and prioritize these for remediation, making a more meaningful improvement to the organization’s security posture,” he added.
Metasploit version 4.4 is available now.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Cyberattacks Target Websites of German Airports, Admin
- US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’
- Tenable Launches $25 Million Early-Stage Venture Fund
- 820k Impacted by Data Breach at Zacks Investment Research
- Mapping Threat Intelligence to the NIST Compliance Framework Part 2
- Hive Ransomware Operation Shut Down by Law Enforcement
- US Government Agencies Warn of Malicious Use of Remote Management Software
- UK Gov Warns of Phishing Attacks Launched by Iranian, Russian Cyberspies
