Moy says that the poor results of the NSS test are particularly surprising given that the vulnerabilities the lab tested were publicly described by government sources like CERT and MITRE, and the exploits they used came from the open-source penetration testing framework Metasploit.
FORBES: Study Shows Programs Designed To Catch Hackers' Exploits Miss Nearly Half