Rapid7 on Friday released Metasploit Pro 4.5, the latest version of its flagship penetration testing and security risk assessment tool. The new release brings capabilities that let organizations simulate social engineering attacks and help understand just how vulnerable they may be to phishing attacks.
Using the new features, users can set up fake websites to emulate real phishing attacks by entering the URL of a site they want to clone and Metasploit automatically modifies forms to capture any data submitted by users. Taking things one step further, the tool can even add client-side exploits.
Additionally, Metasploit Pro 4.5 can generate custom malware that can be put on a USB flash drive and purposely “dropped” in various spots such as the company parking lot or restrooms to find employees whose curiosity may pose a security risk to the organization.
“Metasploit Pro’s social engineering reports go above and beyond alternative penetration testing solutions by providing conversion rates, such as how many people clicked through a phishing email, how many entered username and password on a fake website, and how many systems were compromised,” the company explained in a statement.
Metasploit’s new social engineering functionality can also be useful for penetration testing engagements to compromise one or more systems as a starting point for a more comprehensive security assessment, the company said.
“Many organizations already conduct end-user trainings and implement technical security controls to protect their data, but it’s hard to know how effective these measures are, or even if you’re focusing on the right things,” said HD Moore, chief architect of Metasploit and chief security officer for Rapid7. “Metasploit assesses the effectiveness of these measures, and provides metrics and management for each step in the chain of compromise to help you reduce your risk.”
In addition, to releasing Metasploit 4.5, Boston-based Rapid7 also updated its vulnerability management solution, Nexpose, to version 5.5. New additions to that product include integrated configuration assessment to check if IT assets are appropriately configured, as well as enhanced reporting capabilities. The Nexpose update will also include the ability to deploy the product as a virtual appliance.
The new features are exclusive to the new Metasploit Pro edition, which is available immediately.

For more than 10 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.
More from Mike Lennon
- Watch Now: Threat Detection and Incident Response Virtual Summit
- Registration Now Open: 2023 ICS Cybersecurity Conference | Atlanta
- NetRise Adds $8 Million in Funding to Grow XIoT Security Platform
- Virtual Event Today: Zero Trust Strategies Summit
- Virtual Event Tomorrow: Zero Trust Strategies Summit
- Watch: How to Build Resilience Against Emerging Cyber Threats
- Video: How to Build Resilience Against Emerging Cyber Threats
- Webinar Today: Understanding Hidden Third-Party Identity Access Risks
Latest News
- Industrial Giant ABB Confirms Ransomware Attack, Data Theft
- Organizations Worldwide Targeted in Rapidly Evolving Buhti Ransomware Operation
- Google Cloud Users Can Now Automate TLS Certificate Lifecycle
- Zyxel Firewalls Hacked by Mirai Botnet
- Watch Now: Threat Detection and Incident Response Virtual Summit
- NCC Group Releases Open Source Tools for Developers, Pentesters
- Memcyco Raises $10 Million in Seed Funding to Prevent Website Impersonation
- New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids
