Make penetration tests to manage expert-driven security assessments.
A collaboration between the open source community and Rapid7, Metasploit software helps security and IT professionals identify security issues, verify vulnerability mitigations, and manage expert-driven security assessments, providing true security risk intelligence. Capabilities include smart exploitation, password auditing, web application scanning, and social engineering. Teams can collaborate in Metasploit and present their findings in consolidated reports. Metasploit editions range from a free edition to professional enterprise editions, all based on the Metasploit Framework, an open source software development kit with the world's largest, public collection of quality-assured exploits.
FAR TOO LIMITED IN COMMUNITY EDITION, features absent
Jheckman5
Pros
Nothing really, interface is nice and organized.
Cons
1. Community edition is nothing more than a glorified nmap tool, i can download nmap for free and i don't need a serial key to use it.
2. No advanced features are included in community edition so i am unable to test it out to see if i even like it, again 220 mb of space is too much for a glorified nmap.
3. Using Wireshark, Zenmap and a few other choice freeware tools i can probably duplicate what metasploit does and i would learn more while doing it. Not including the actual exploits which i am sure freeware versions can be found if i look hard enough.
4. pradameinhoff is way off on his review, this is a bad way to learn this stuff when there are far superior tools available that offer a more upfront functionality without demanding 3000 in cash to be able to actually use it.
Sorry but as of now i hate metasploit and I'm going to stick with what my instructor recommends. After all the only good way to learn this stuff is to use the real solid tools that are actually time tested.
Summary
My advice is to stear away until they reconsider making the community edition more useable for the average folk.
Makes pwning so much easier...
pradameinhoff
Pros
Metasploit Express is much easier to use than the regular Metasploit, especially because it uses a web interface rather than command line only. I liked the nmap integration, making network discovery much easier. It's more like point, click, pwn...
Cons
Liked the software but the $3,000 price tag is a little heftyfor personal use, so it's for business only. The 7 day trial gives you access to all the features, doesn't seem to be limited.
Summary
If you want to give pentesting a try, this is the easy way to go...