# rapid7/metasploitable3

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

Repository: https://github.com/rapid7/metasploitable3
Canonical: https://ross.abutalabs.com/products/metasploitable3
Language: HTML
License: NOASSERTION
License Family: other
Last push: 2025-02-13T14:49:38+00:00

## Health v2 (maintenance only)
Score: 35/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 6, release rhythm 35, longevity 100
- inputs: {"age_days": 3656, "days_push": 566, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5681, forks 1269 (observed 2026-08-28T04:09:27.852611+00:00)

## What it is
Metasploitable3 is a deliberately vulnerable virtual machine (Windows and Ubuntu builds) created by Rapid7 for practicing exploit development and penetration testing. It is built automatically with Packer and Vagrant and is intended as a target for the Metasploit Framework.

## Use cases
- practice penetration testing against a vulnerable VM
- test metasploit exploits safely
- set up a security training lab
- learn exploitation techniques on Windows and Linux
- build a deliberately vulnerable target environment with vagrant

## When to choose
- you need a realistic, intentionally vulnerable target for exploit testing
- you want a reproducible pentest lab built via Packer/Vagrant
- you are training or learning offensive security with Metasploit

## When to avoid
- you need a hardened production system or security tool
- you cannot isolate the VM from your network (it is intentionally insecure)
- you only want vulnerability scanning of your own infrastructure

## Facets
- artifact type: dataset
- maturity: maintenance
- function: security, penetration-testing, vulnerability-scanning, infrastructure-as-code
- domain: security, penetration-testing, self-hosted, developer-tools
- platform: windows, self-hosted
- tags: vulnerable-vm, pentest-lab, metasploit, vagrant, packer, security-training, exploit-target, linux, macos, docker

## Member repositories
- rapid7/metasploitable3 (main) score 35

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:27.852611+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:54:15.400923+00:00, confidence not recorded.
  - readme: https://github.com/rapid7/metasploitable3 (fetched 2026-08-28T04:09:27.852611+00:00, sha 68d0ee681381)
- Data as of 2026-08-30T08:39:29.467469+00:00.
