LICENSEWARE
Rapid7 Rule

Customer must be authorised for every system it scans or tests

Catalog row in Vendor License Rules · Cited

Kind
Use rights
Statement
MSSA §2.2 and §9.9: the customer warrants that it has appropriate authorisations for the networks, systems, IP addresses, assets and hardware it deploys the Offerings on or targets, scans, monitors or tests, and must comply with laws governing network scanners and vulnerability assessment software. Scanning or testing third-party assets without authorisation is outside the licence and triggers the customer indemnity in §6.2.
Applies when
Scanning cloud providers, partners or subsidiaries not owned by the customer.
Applies to
InsightVM, Nexpose, Metasploit, InsightAppSec, Surface Command.
Esc