Overview
Rapid7s AI-powered Command Platform aggregates data from across your security ecosystem to provide a comprehensive, actionable view of your critical telemetry. With the Command Platform, you have threat- aware risk context to anticipate and prevent breaches, actionable detections and insights to pinpoint the most critical threats across your environment, and expert intelligence from our security experts, enabling you to take action confidently every time all within a single, consolidated platform bringing your team tangible value.
Threat-aware Exposure Management
Attack surface management - Surface Command breaks down data silos by aggregating comprehensive attack surface visibility across hybrid environments, along with external attack surface scans, to build a dynamic, 360-degree view of your entire attack surface in.
Vulnerability management - Vulnerability management delivers complete visibility across on-premise and remote endpoints to help teams identify, communicate, and remediate vulnerabilities, misconfigurations, and other risks across the business.
Cloud security - Cloud security provides code-to-cloud protection for cloud-native applications and workloads with seamless integration into the CI/CD pipeline, along with real-time, agentless risk assessment and prioritization based on reachability, exploitability and potential impact.
Exposure management - Exposure Command builds on the comprehensive attack surface visibility of Surface Command with high-fidelity risk context and insight into security posture of your entire digital estate, aggregating findings from Rapid7 native exposure assessment capabilities alongside data from all your third-party security tooling and enrichment sources. This enables security teams to understand and prioritize exposure from the endpoint to the cloud.
Application Security - Application security provides dynamic security testing to automatically assess web apps and APIs for vulnerabilities using an industry-leading attack framework and library, providing accurate and actionable remediation guidance to developers
Cloud-ready Detection and Response
Next-gen SIEM and XDR - Next-Gen SIEM delivers highly efficient, accelerated detection and response with frictionless SaaS deployment, a highly intuitive interface, robust out-of-the-box detections informed by our MDR SOC, and actionable built-in automation.
Digital Risk Protection - Digital Risk Protection anticipates and prevents breaches with visibility of the external attack surface through clear, deep, and dark web monitoring, credential and data leakage,protection against phishing attempts, and more.
Automation - Automation enables your team to accelerate and streamline time-intensive processes - with no code necessary. With plugins and customizable workflows, your team can accelerate detection and response, automate vulnerability management tasks, phishing investigations, and overall collaboration.
Threat Intelligence - Intelligence hub delivers high fidelity, actionable threat intelligence with significantly less noise than traditional Threat Intelligence Platforms. Infused with intelligence from Rapid7 Labs proprietary threat and vulnerability research and community- driven tools, your team can easily focus on the most meaningful risk signals and take high priority actions to stay ahead of critical threats most relevant to your organization.
Highlights
- End alert fatigue - with prioritized threats that provide more signal and less noise.
- Disrupt attackers, not your tech stack - as you seamlessly integrate and quickly deploy across any footprint.
- Start anywhere - scale anytime from one product up to the whole platform. Managed or SaaS, we're here for your evolving needs.
Details
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Command Platform | Contact us for a custom quote. | $10,000.00 |
Vendor refund policy
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration
What is our primary use case?
I am working with Rapid7 InsightOps and Rapid7 InsightIDR because the requirement is as such from the customer side, particularly the banks. Whatever the requirement is, these are the products that we are working with.
I usually recommend Rapid7 InsightIDRÂ for banks because that is the bigger chunk here who do business in cybersecurity or whose requirement is that compliance requirements need to be filled by certain products, which Rapid7 InsightIDR is one of them.
What is most valuable?
UEBAÂ is an important element these days, but usually the requirement is for threat detection, investigation, and response. This is what Rapid7 InsightIDR provides.
Banks typically go for threat detection, investigation, and response capabilities. End-user entity and behavior analysis, or UEBAÂ , is certainly an important addition if we provide the solution along with UEBA. It provides that and this is something that the customer cannot ignore because they want to have a 360-degree coverage of their emails or for their users and what they are doing. This is definitely their requirement.
What needs improvement?
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm , it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm . If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled.
Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.
For how long have I used the solution?
It has been about four to five years now that we have been working with Rapid7. Whatever the products, they were all related to vulnerability tools that we have been working with. It has been a journey of about five years with Rapid7.
What other advice do I have?
Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar. It is good for a middle-tier organization. In that market, there is competition now.
I do not recommend Rapid7 InsightIDR for bigger companies because they trust these big brands such as QRadar or LogRhythm. The general perception is that these are the solutions for big organizations having hundreds of branches or more. Rapid7 InsightIDR fits in the middle tier.
The integration of Rapid7 InsightIDR with the security stack works fine because the systems in this part of the world are not so much cloud-driven. They have something around 20% or 30% of services running from the cloud. The rest are usually on-premises. Office 365Â is one service that they get from the cloud. Networking typically includes Cisco and Fortinet in their networks. For endpoints, the operating system is usually Windows or Linux, not Mac in an enterprise environment. Windows and Linux can be easily integrated with this solution.
The dashboard functionalities of Rapid7 InsightIDR are usually about customer-friendliness. Customers want to have some rich enrichment of the analysis or the ticket alerts or the events that come out with some processing behind the scenes. They feel that it is a more rapid or more intense process at Splunk or LogRhythm or QRadar compared to Rapid7 InsightIDR.
For automated threat intelligence features, customers usually go for a full SOARÂ solution. They want to have playbooks and everything to run. Although Rapid7 InsightIDR does claim that it has integrated SOARÂ , called InsightConnect, this is not as advanced as a dedicated SOAR solution. LogRhythm solutions or Splunk solution or Sumo Logic solution are doing business here as well. These are considered more rich in features compared to Rapid7 InsightIDR.
I rate Rapid7 InsightIDR between a six and seven out of ten.
IDR situation
Providing comprehensive insight into alerts while working towards AI enhancement
What is our primary use case?
I am using Rapid7 InsightIDRÂ as an InsightIDRÂ solution. This tool is integrated with other solutions like endpoint and NDR, and it correlates alerts, giving me a comprehensive picture of the alerts.
What is most valuable?
The platform offers unlimited storage and agent-based solutions. I have user behavior analytics (UBAÂ ) and MITRE ATT&CK as well. The user behavior analytics feature helps in enhancing the security posture by helping to identify user behaviors and engineering alerts based on them.
What needs improvement?
There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on. I have already opened a list of features with Rapid7, and they are working on it.
For how long have I used the solution?
I have been using Rapid7 InsightIDR for about two years.
What do I think about the stability of the solution?
So far, I have not had any performance issues with Rapid7 InsightIDR. It is working well, and I have not faced any downtime in the last two years.
What do I think about the scalability of the solution?
Every product has some limitations, and Rapid7 is no exception, yet it is working for me perfectly right now.
How are customer service and support?
I rate their technical team 8.5 out of ten, which is pretty good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Currently, I am not working with the LogRhythm solution. I have another SIEM solution in place. Previously, three years back, I was working with LogRhythm , however, now I do not.
How was the initial setup?
The initial setup was straightforward, and I did not face any complexities during the setup of the IDR product.
What was our ROI?
The incident response time is good, and I can easily find or search any incident. I easily build the queries in Rapid7 and search my relevant logs or relevant investigation logs.
Which other solutions did I evaluate?
I have EDR, XDRÂ , NDR, TLP, and many other solutions like these.
What other advice do I have?
I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product.
Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.
A cost-effective and stable solution but lacks an AI-driven capability
What needs improvement?
The solution lacks an AI-driven capability. While other competitors emphasize AI as the most important feature.
For how long have I used the solution?
I have been using Rapid7 InsightIDR as a distributor for seven years.
What do I think about the stability of the solution?
The product's stability is high. I rate the solution’s stability an eight out of ten.
What do I think about the scalability of the solution?
Due to its cloud-based nature and numerous agents, its scalability is high. This, combined with its on-premise environment, ensures rapid performance. It can handle several thousand. It is best suited for large-scale businesses.
How are customer service and support?
Support is slow. I'm not satisfied with the support so far.
How would you rate customer service and support?
Neutral
How was the initial setup?
Due to the product's complexity, the initial setup can be challenging. Additionally, setting up the product and training the customer can be quite demanding. Deploying the appliance or sensor on-premises can take up to twelve months.
What's my experience with pricing, setup cost, and licensing?
The product pricing is very cheap.
What other advice do I have?
InsightIDR automates everything through InsightConnect in a seven-day cycle.
The product has improved significantly since its inception. However, based on feedback I've received from other products in the market, aside from InsightIDR.
It improved because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively.
If you combine it with InsightIDR, then it may become more compact. Maybe IBM was a bit larger. So, having MDR is the main key point for this product.
Overall, I rate the solution a four out of ten.
Offers unconventional detection rules and native integration features
What is our primary use case?
Our company is a system integrator for Rapid7 InsightIDR. We use the latest SaaS version of the product. Rapid7 InsightIDR works as the foundation of the security operation center in our company. The solution is used in our organization for data ingesting for multiple security devices and solutions. Rapid7 InsightIDR provides insights and stability on the security aspects of the company.
What is most valuable?
The unconventional detection rules of Rapid7 InsightIDR are quite beneficial. The solution provides satisfying native integration features.
What needs improvement?
The searching feature in Rapid7 InsightIDR needs to evolve. For instance, when pursuing an incident handling task, extensive searching is required, and the solution's own query language can only be used. In situations similar to the aforementioned example, the solution becomes difficult to use. It would be interesting if the vendor could make the search feature like the Google search engine.
For how long have I used the solution?
I have been working with Rapid7 InsightIDR for three years.
What do I think about the stability of the solution?
Overall, the solution is stable enough. I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
The product's scalability seems good enough. In our company, we are able to manage a couple of thousand devices comfortably using only one single tenant.
Through our company, thousands of users are using the interface of Rapid7 InsightIDR to process data and check incidents. I have implemented data ingestion for couple of thousand devices that include virtual machines, switches, routers and firewalls.
For all the aforementioned devices we haven't faced any issues in our company. Rapid7 InsightIDR is used in our company, majorly for medium and enterprise grade customers, where some enterprises have more than 5000 employees and some less than that.
How are customer service and support?
Our company mostly receives fast and suitable support from Rapid7 InsightIDR, but sometimes the response arrives quite slow. I would rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
I would rate the initial setup a nine out of ten. It's quite straightforward to put the solution to work. Once Rapid7 InsightIDR activates the tenant, the deployment process becomes straightforward. In our company, we just download the agents and install them in the customers' virtual machines.
Following the aforementioned step, some integration with Azure Entra ID authentication services or on-prem authentication is required. Thus, some base integration is required for login data. For the final stage of deployment, as part of the company, we configure a couple of customizations for the detection rules to start ingesting data; the niche customizations can be performed easily for the use cases.
In our company we have an engineering deployment team who are highly skilled in setup processes. For client companies with less than 500 devices, usually one full-time engineer is enough for the deployment. For clients with 500 devices, when we at our company use automation to deploy the agents, it takes only a couple of days to finish the deployment process.
What's my experience with pricing, setup cost, and licensing?
The solution has a mid-range price point in the market. The licensing cost depends on the customer size and the negotiation on whether to add IVM. There are multiple add-ons to the base licensing fee, we use them only for specific customers of our organization. The additional licenses increase the pricing drastically, so we try to stick with the base license at our company.
What other advice do I have?
At our company, along with Rapid7 InsightIDR we use multiple cloud providers like Azure, Google, Oracle and AWS infrastructure to ingest data.
I would advise others to select a reliable system integrator to implement Rapid7 InsightIDR for the correct use cases or business needs. The solution is satisfying, but there are multiple other solutions in the market, and having a partner can help a customer explore all the options before adopting one. Overall, I would rate Rapid7 InsightIDR an eight out of ten.