Rapid7 built its reputation on InsightVM and Metasploit, both tools most pentesters have used at some point. Exposure Command is Rapid7’s answer to the same question every vendor in this space is now asking: once you’ve found a thousand vulnerabilities, how do you tell someone which twenty actually matter this week?
What is Rapid7 Exposure Command?
Exposure Command is Rapid7’s exposure management platform, built on top of the Insight Platform. It combines internal vulnerability data (from InsightVM), external attack surface data (from the acquired Alcide/attack surface tooling and Rapid7’s own internet-wide scanning), and cloud misconfiguration data (from InsightCloudSec) into a single risk model. The differentiator Rapid7 leans on hardest is its threat intelligence feed – the same research team that maintains Metasploit modules also feeds real-world exploitation data into Exposure Command’s prioritisation engine, so a CVE with a known, weaponised exploit gets bumped ahead of one that’s theoretical.
Key features
- Active Risk score – a prioritisation score that factors in exploitability, asset exposure, and business context rather than raw CVSS.
- External attack surface monitoring – continuous discovery of internet-facing assets, including shadow IT the security team didn’t know existed.
- Cloud risk correlation – ties cloud misconfigurations to the workloads and identities that could actually be reached from them.
- Remediation workflow integration – tickets can be routed to Jira/ServiceNow with the attack path context attached, not just a CVE number.
- MDR integration – Exposure Command data feeds directly into Rapid7’s managed detection and response service if you use it.
Who it’s for
Teams already running InsightVM who want to extend it outward – external attack surface and cloud – rather than replace it. It’s also a natural fit for organisations that use Rapid7’s MDR service, since the exposure and detection data live in the same platform and inform each other.
Rapid7 Exposure Command vs the alternatives
Against Tenable One, Rapid7’s pitch is tighter integration between exposure data and actual detection/response, since Rapid7 runs both. Against CrowdStrike Falcon Exposure Management, Rapid7 has a longer history in network and cloud vulnerability scanning rather than endpoint-first telemetry. Against Wiz-style pure cloud players, Rapid7 covers on-prem and external attack surface too, which matters if your estate isn’t cloud-only.
Getting started
If you’re already an InsightVM customer, Exposure Command is typically an add-on module rather than a separate deployment – ask your Rapid7 rep about enabling it against your existing scan data before buying additional attack surface or cloud modules separately.

Leave a Reply
You must be logged in to post a comment.