All vendors

Vendor lineage

Rapid7

Bought the industry's best-known attack toolkit, which is the opposite of what its main competitor did with open source.

Rapid7 was founded in 2000 in Boston, and the decision that gave it a distinct position came nine years later: in 2009 it acquired the Metasploit Framework, the open-source exploitation toolkit HD Moore had created in 2003, and brought Moore with it.

The significance is best seen against Tenable, which is on this timeline too. Tenable was built on an open-source scanner and closed it in 2005 to fund the company. Rapid7 went the other way and bought an open-source project outright, kept it open, and used it as the reason to trust the commercial products beside it. Two vendors in one market took opposite positions on the same question about open source, and both are still trading.

Owning Metasploit also changed what Rapid7 could say. A scanner reports that a host is probably vulnerable; an exploitation framework demonstrates that it is. Holding both meant the company could close the gap between a finding and a proof, and that distinction is the whole argument for penetration testing over scanning alone.

The problem the segment has spent two decades on is not detection but volume. A large organisation's scan returns tens of thousands of findings and nobody can act on all of them, so the useful work became ranking - which is why every vendor here, Rapid7 included, ended up shipping a risk score and leaning on the public catalogue of vulnerabilities known to be actively exploited.

Rapid7 went public in 2015 and has expanded into detection and response, cloud posture and managed services, on the same logic every security company on this page eventually follows: once you are the system of record for one kind of risk, the adjacent kinds are the cheapest thing you can sell next.

Sources