Ross ROSS = Recommend OSS · open-source software intelligence for agents

rapid7/metasploitable3 resource

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities. observed · 2026-08-28

github.com/rapid7/metasploitable3 · HTML · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

35/100

  • Activity 6
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3656
  • days_rel: n/a
  • days_push: 566
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

5681 stars · 1269 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Metasploitable3 is a deliberately vulnerable virtual machine (Windows and Ubuntu builds) created by Rapid7 for practicing exploit development and penetration testing. It is built automatically with Packer and Vagrant and is intended as a target for the Metasploit Framework.

Use cases

  • practice penetration testing against a vulnerable VM
  • test metasploit exploits safely
  • set up a security training lab
  • learn exploitation techniques on Windows and Linux
  • build a deliberately vulnerable target environment with vagrant

When to choose

  • you need a realistic, intentionally vulnerable target for exploit testing
  • you want a reproducible pentest lab built via Packer/Vagrant
  • you are training or learning offensive security with Metasploit

When to avoid

  • you need a hardened production system or security tool
  • you cannot isolate the VM from your network (it is intentionally insecure)
  • you only want vulnerability scanning of your own infrastructure

Facets

dataset · maturity maintenance

security penetration-testing vulnerability-scanning infrastructure-as-code security penetration-testing self-hosted developer-tools windows self-hosted vulnerable-vm pentest-lab metasploit vagrant packer security-training exploit-target linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
rapid7/metasploitable3main35

For agents

markdown · JSON · MCP: product_card(name="rapid7/metasploitable3")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem