Open Source pen test tool releases pro version based on open core
It was just a year ago that Rapid7 makers of a vulnerability management tool acquired the Metasploit open source penetration testing project. Along with Metasploit, Rapid7 also hired the driving force of Metasploit, HD Moore. To mark the anniversary, Rapid 7 released the Metasploit Pro version of the Metasploit software. I had a chance to speak with HD Moore yesterday about all of this and more (no pun intended).
Metasploit Pro is actually the 2nd commercial version of Metasploit that has been released under Rapid7. The first, Metasploit Express was aimed at the enterprise security technician performing pen testing on their network. The Pro version is aimed more at the professional pen testing team and has lots of advanced collaboration features. Featuring advanced VPN pivoting capabilities as well as social engineering capabilities to crack the perimeter, Metasploit Pro sells for about 15k per seat, as opposed to the 3k per seat that Metasploit Express sells for. The Pro product puts it squarely on par with Core Impact and some of the other commercial penetration testing tools out there.
But enough nuts and bolts on security that many of you may not be interested in. In terms of open source, Metasploit still offers its framework as an open source tool. It may not have the pretty GUI or polish of the commercial product, but the core of the commercial products is still the framework of the open source code. The open source framework is released under a Free BSD license by the way. That means that theoretically others can use it as the core of their product as well.
In this way Moore says that Metasploit has become an open core product. Users are free to use the open framework, but if they want the support and added functionality-features of the Pro or Express product they can upgrade. There is a clear upgrade path there. Moore likes this model and thinks it has been successful for him and the Metasploit team.
Since gaining commercial support Moore says that Metasploit has been much more responsive to users requests for new features. One change he has noticed is that with paid developers on his team, the core code is being improved and updated much faster. In fact so fast that many of the contributors to Metasploit in the past just can’t keep up with the rapid pace of development. So instead of contributing code to the core, many community developers are pitching in on other areas.
Of course when an open source project gets commercial backing one measure of success is watching to see if the community still contributes code back. I don’t follow the Metasploit community close enough to tell you for sure. But Moore would indicate they have not. On the other hand he has good reasons why they aren’t. Also many of my friends in the security community have nothing but good things to say about Metasploit since the acquisition. So I would tend to think the community is still solidly behind it. If you are a Metasploit user and have a different opinion, I would love to hear from you. Feel free to comment.
in the meantime, it looks like Metasploit has successfully navigated the move from pure open source project, to commercially supported product using an open core business model.




