RequiredExperience with Government
RequiredAnnual Turnover
RequiredOEM Authorization Certificate Penetration Testing Tool Software ( 5 ) ( Under PAC ) Make rapid7 Model rapid7-metasploitpro Technical Specifications * As per GeM Category Specification Specification Specification Name Values Bid Requirement (Allowed Values) BASIC INFORMATION (GOLDEN) Type of Penetration Testing Tool Software Application Security Penetration Testing Tool Software Application Security Penetration Testing Tool Software Name of Software Tool Metasploit Pro * Name of the OEM Rapid 7 * 1/8 OEM Model/Part No Metasploit Pro * Product Id of OEM MSPPRO * Brief Description of the software Tool Penetration Testing * Software Tool Version Name 4.14.3 * Date of Launch of Version 1 Feb 2019 * Number of Years upto which Technical Support is available from OEM Seller(WARRANTY) 3 3 Installation
RequiredDeployment and Integration The offered product supports installation on Linux and Window 64 bit 64 bit Installation
RequiredDeployment and Integration features of the offered product 1. Supports latest updates (e.g. exploit module) as frequent as on a weekly basis.
Required2. Supports offline activation and manual updates
Required3. Performs full backup to prevent data loss and enable to easily migrate data 1. Supports latest updates (e.g. exploit module) as frequent as on a weekly basis.
Required2. Supports offline activation and manual updates
Required3. Performs full backup to prevent data loss and enable to easily migrate data Administration Administration features available in the offered product 1. Web-based user interface through encrypted channels.
Required2. Supports command line console within.
Required3. Allows API integration with other systems or be able to automate workflow.
Required4. Ables to run jobs or tasks (e.g. scan
Requiredexploit) on schedule. 1. Web-based user interface through encrypted channels.
Required2. Supports command line console within.
Required3. Allows API integration with other systems or be able to automate workflow.
Required4. Ables to run jobs or tasks (e.g. scan
Requiredexploit) on schedule. Host Scan and Web Scan Host Scan and Web Scan features in the offered product 1. Conducts scans and discover the host's OS and running services. * The offered product supports importing of scan result from external solutions including Nexpose
RequiredMetasploit
RequiredFou ndstone
RequiredMicrosoft
RequirednCirc le
RequiredNetSparker
RequiredNessus
RequiredQ ualys
RequiredBurp
RequiredAcunetix
RequiredAp pScan
RequiredNmap
RequiredRetina
RequiredAm ap
RequiredCritical Watch
RequiredIP Address List
RequiredLibpcap
RequiredSp iceworks
RequiredCore Impact
RequiredOthers Nessus
RequiredNexpose 2/8 If Others
Requiredin above parameter then indicate External solution NA * System Exploitation Number of reliability levels of exploit codes for automated exploitation in the offered product 6 6.0 - 15.0 Or higher System Exploitation feature in the offered product 1. Capable to apply exploits on individual IP or multiple IPs.
Required2. Automatically selects to apply exploit modules based on OS
Requiredservice and vulnerability references.
Required3. Support running individual exploit module manually from the user interface.
Required4. Dry run to show exploit information in task log only.
Required5. Supports replay of exploitation tasks .
Required6. Supports automation of common yet complicated security tests (Metamodules) that provide a more efficient way to get specific jobs done.
Required7. Supports the reuse of manually added or captured credentials within a project to validate specified credentials on additional hosts in the target network. 1. Capable to apply exploits on individual IP or multiple IPs.
Required2. Automatically selects to apply exploit modules based on OS
Requiredservice and vulnerability references.
Required3. Support running individual exploit module manually from the user interface.
Required4. Dry run to show exploit information in task log only.
Required5. Supports replay of exploitation tasks .
Required6. Supports automation of common yet complicated security tests (Metamodules) that provide a more efficient way to get specific jobs done.
Required7. Supports the reuse of manually added or captured credentials within a project to validate specified credentials on additional hosts in the target network. Bruteforcing Offered product supports Bruteforcing testing on services including AFP
RequiredSMB
RequiredPostgres
RequiredDB2
RequiredMySQL
RequiredMSSQL
RequiredHTTP
RequiredHT TPS
RequiredSSH
RequiredSSH
RequiredPUBKEY
RequiredT elnet
RequiredFTP
RequiredPOP3
RequiredVNC
RequiredSN MP
RequiredWinRM
RequiredOthers HTTP If Others
Requiredin above parameter then indicate Bruteforce testing NA * Bruteforcing feature in the offered product 1.Provides password references for factory default logins.
Required2. 1.Provides password references for factory default logins.
Required2. 3/8 Supports customized credentials and dictionary import for bruteforce.
Required3. Supports credential mutation to create multiple permutations of a specified password
Requiredwhich enables building of a larger list based on a defined set of passwords. Supports customized credentials and dictionary import for bruteforce.
Required3. Supports credential mutation to create multiple permutations of a specified password
Requiredwhich enables building of a larger list based on a defined set of passwords. Post Exploitation Action And Evidence Collection The offered product supports exploitation payload types Meterpreter
RequiredCommand Shell
RequiredPowershell Meterpreter
RequiredCommand Shell
RequiredPowershell Powershell Collect system data (screen capture
Requiredpassword
Requiredsystem information)
RequiredBuild a virtual desktop connection
RequiredAccess file system
RequiredSearch the file system
RequiredRun a command shell
RequiredCreate proxy pivot
RequiredCreate VPN pivot Run a command shell Post Exploitation Action And Evidence Collection feature in the offered product 1.Supports customized macros to run selected operations automatically after exploit.
Required2.Supports deploying of persistent listeners to allow exploited hosts to connect back to Metasploit automatically. 1.Supports customized macros to run selected operations automatically after exploit.
Required2.Supports deploying of persistent listeners to allow exploited hosts to connect back to Metasploit automatically. Social Engineering Campaign Social Engineering Campaign feature in the offered product 1.Supports web campaign
RequiredEmail campaign and USB campaign.
Required2. Allows web campaign.
Required3. Supports web content to be cloned from another web site (e.g. www.google.com).
Required4.Su pports web campaign that browser autopwn (apply all the appropriate exploit modules based on the browser version)
Requiredspecific browser exploit (e.g. MS11-050) and 1.Supports web campaign
RequiredEmail campaign and USB campaign.
Required2. Allows web campaign.
Required3. Supports web content to be cloned from another web site (e.g. www.google.com).
Required4.Supports web campaign that browser autopwn (apply all the appropriate exploit modules based on the browser version)
Requiredspecific browser exploit (e.g. MS11-050) and 4/8 not do anything (just checking the connection from the users).
Required5. Supports email campaign content customization to include a specific URL or an agent attachment.
Required6. Supports USB campaign that generates an agent deployment .exe file. not do anything (just checking the connection from the users).
Required5. Supports email campaign content customization to include a specific URL or an agent attachment.
Required6. Supports USB campaign that generates an agent deployment .exe file. Web Application Exploitation Web Application Exploitation feature in the offered product 1. Supports web crawling on IPv4 and IPv6 web sites.
Required2. Supports web crawling applied on a web site (e.g. http:/www.abc.com) or started from a specific point (e.g. http:/www.a bc.com/path/starthere/) .
Required3. Supports detection of vulnerable URLs and parameters such as SQL Injection and Cross Site Scripting. 1. Supports web crawling on IPv4 and IPv6 web sites.
Required3. Supports detection of vulnerable URLs and parameters such as SQL Injection and Cross Site Scripting. Report and Data Export Number of Built - in- Standard reports in the offered product 10 10.0 - 30.0 Or higher The offered product supports report formats PDF
RequiredWord
RequiredRTF
RequiredHTML PDF
RequiredWord
RequiredHTML Report and Data Export feature of the offered product 1.Provides built-in standard reports and support customized report functionality.
Required2. Supports reports to be stored locally and sent to recipient by email after created.
Required3. Ables to support data export which allows a zip archive of the project suitable for importing into an another instance of the solution. 3. Ables to support data export which allows a zip archive of the project suitable for importing into an another instance of the solution. SUPPORTED HARDWARE REQUIREMENTS PARAMETERS Hard Disk Space Required 50 GB * RAM Size required 16 GB * CPU required 2 GHz+ * 5/8 Operating Systems supported (Driver) Linux
RequiredWindows * Supported Devices ALL * Supported Servers ALL * Supported Web browsers IE
RequiredMozilla
RequiredChrome * Supported Database ALL * GENERIC PARAMETERS "Free Upgradation to Higher Version WITHIN WARRANTY PERIOD " Yes Yes Valid Licence copy to be provided YES * Software supplied through Media & URL Link * Certifications Benchmarking of Software Products Forresterwave Leader * Installation and Demonstration Yes Yes List of items included in the package 1 * Hyper link to Data sheet www.rapid7.com * No of Days training provided at site upto 5 upto 5 No of Software sold 30 * Number of User Referance from Government Department where Software installed 5 * Details of Government Department email
Requiredphone no Of concerned authority where Software installed for above NA * * Bold specifications are the golden parameters.