Alle leverandører

Vendor lineage

Rapid7

Bought the industry's best-known attack toolkit, which is the opposite of what its main competitor did with open source.

Rapid7 was founded in 2000 in Boston, and the decision that gave it a distinct position came nine years later: in 2009 it acquired the Metasploit Framework, the open-source exploitation toolkit HD Moore had created in 2003, and brought Moore with it.

The significance is best seen against Tenable, which is on this timeline too. Tenable was built on an open-source scanner and closed it in 2005 to fund the company. Rapid7 went the other way and bought an open-source project outright, kept it open, and used it as the reason to trust the commercial products beside it. Two vendors in one market took opposite positions on the same question about open source, and both are still trading.

Owning Metasploit also changed what Rapid7 could say. A scanner reports that a host is probably vulnerable; an exploitation framework demonstrates that it is. Holding both meant the company could close the gap between a finding and a proof, and that distinction is the whole argument for penetration testing over scanning alone.

The problem the segment has spent two decades on is not detection but volume. A large organisation's scan returns tens of thousands of findings and nobody can act on all of them, so the useful work became ranking - which is why every vendor here, Rapid7 included, ended up shipping a risk score and leaning on the public catalogue of vulnerabilities known to be actively exploited.

Rapid7 went public in 2015 and has expanded into detection and response, cloud posture and managed services, on the same logic every security company on this page eventually follows: once you are the system of record for one kind of risk, the adjacent kinds are the cheapest thing you can sell next.

Founding stories

2000

Rapid7

Boston, Massachusetts · Founders:

Founded in 2000, and the decision that gave it a distinct position came nine years later when it acquired the Metasploit Framework and kept it open source. A vulnerability management company owning the industry's best-known exploitation toolkit is an unusual arrangement, and it is the reverse of what its closest competitor did with the scanner it was built on.

Founder names are not consistently reported and are not supplied here.

The timeline

  1. Founded

    In Boston, in the vulnerability assessment market.

  2. Metasploit

    Acquired, and kept open. The framework remained free while the company built commercial products beside it - the opposite direction of travel from Nessus four years earlier.

  3. NASDAQ listing

    Listed as RPD.

  4. Insight platform consolidation

    Vulnerability findings, detection and response, application security and cloud posture assembled onto shared data, on the bet that customers want findings correlated with live telemetry rather than delivered as a separate report.

Flagship products and solutions

  • InsightVMThe cloud successor to Nexpose: live dashboards, risk-based prioritisation, and integration into ticketing and delivery pipelines so findings become work items rather than PDFs.
  • MetasploitThe exploitation framework, still open source, alongside a commercial Pro edition. It is simultaneously a product, a recruiting tool and the reason a great many practitioners know the company at all.
  • InsightIDRDetection and response, drawing on the same platform data - the argument being that a vulnerability matters differently when something is already moving on the network.
  • InsightAppSecDynamic application security testing, probing running applications rather than scanning hosts. A separate product because it answers a different question.
  • Active RiskPrioritisation using threat intelligence and machine learning rather than published severity alone, aimed directly at the gap between what is scored critical and what is actually being exploited.

Key innovations

  • Stewardship of a dual-use toolKeeping Metasploit open made the company responsible for a framework that attackers use as readily as defenders. Every new module is a capability released to both sides at once, and the justification - that the technique is already known and defenders are the ones who need it packaged - is the same argument the whole disclosure debate turns on.
  • Validation inside the same platformBecause the exploitation framework and the scanner share an owner, confirming a finding is a workflow step rather than a separate engagement with a separate vendor - which changes who can do it and how often.
  • Findings as workflow, not reportsNative integration with issue trackers reflects the actual failure mode: the report is produced, and nothing happens. Making a finding into an assigned ticket with a service-level target is a product decision about organisational behaviour rather than about scanning.
  • Correlating exposure with live attack dataVulnerability findings and detection telemetry on one platform means the question shifts from which of these fifty thousand findings matters to which of them is being touched right now.

Main markets

Mid-market and enterprise, with entry pricing below its main competitor and a reputation for fitting teams that want vulnerability work inside their existing delivery process rather than beside it.

It competes with Tenable and Qualys, both on this timeline, and its detection products put it against a second set of vendors entirely - which is the consolidation trade every security company in this segment has taken.

Analyst standing

  • Regularly assessed among the established vulnerability management vendors, with prioritisation and integration breadth cited as strengths and setup complexity as the consistent criticism in practitioner reviews.
  • The category observation applies here too: the branding has moved to exposure management across all three vendors, and none has finished the move, so evaluations still turn on scan architecture, coverage and scoring.

Acquisitions

  1. 2009 Metasploit Framework

    The most widely used open-source exploitation toolkit, kept open after the acquisition.

    HD Moore, 2003

    Metasploit Pro alongside the community edition, and the reason Rapid7 could prove exploitability rather than only report it.