Listing Thumbnail

    Rapid7 Insight Platform

     Info
    Sold by: Rapid7 
    Deployed on AWS
    The Rapid7 Insight platform combines best-in-class solutions, leading-edge research, and strategic expertise, giving you everything you need to stay ahead of attackers and out of the news.

    Overview

    Play video

    The Insight Platform unites your teams so you can stop putting out fires and focus on the threats that matter. Security, IT, and DevOps now have easy access to vulnerability management, application security, detection and response, external threat intelligence, orchestration and automation, and more. The Rapid7 Insight platform consists of six distinct SaaS security solutions designed to address different aspects of cybersecurity.

    1. InsightVM gives you live vulnerability management and endpoint analytics to view real-time risk -https://aws.amazon.com/marketplace/pp/prodview-iytoknlkgcesm 

    2. Insight IDR accelerates detection and response by increasing efficiency with embedded threat intelligence, expertly vetted detections, and automation for faster response - https://aws.amazon.com/marketplace/pp/prodview-lactu6axbhqkg 

    3. InsightCloudSec enables you to reduce risks of operating in the major cloud service providers through continuous security and compliance - https://aws.amazon.com/marketplace/pp/prodview-h6t2cifb2legg 

    4. InsightAppSec stays in step with your application development to easily introduce security throughout your SDLC - https://aws.amazon.com/marketplace/pp/prodview-erxu2bevxxsmc 

    5. InsightConnect unites your technology by automating workflows across IT and Security cloud apps, on-premise systems for users and administrators - https://aws.amazon.com/marketplace/pp/prodview-wzysgd4fdhfic 

    6. ThreatCommand monitors the clear, deep, and dark web to identify and mitigate threats.

    This is a modular solution, and we recommend discussing your specific needs with our team prior to purchase to ensure the appropriate products are selected.

    Highlights

    • End alert fatigue - with prioritized threats that provide more signal and less noise.
    • Disrupt attackers, not your tech stack - as you seamlessly integrate and quickly deploy across any footprint.
    • Start anywhere - scale anytime from one product up to the whole platform. Managed or SaaS, we're here for your evolving needs.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Rapid7 Insight Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    InsightPlatform
    Contact us for a custom quote.
    $10,000.00

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Vulnerability and Patch Management, Data Governance
    Top
    10
    In Industrial IoT, Application Servers

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Vulnerability Management
    Real-time vulnerability assessment and endpoint analytics with live risk visualization
    Cloud Security Monitoring
    Continuous security and compliance risk reduction across major cloud service providers
    Threat Detection
    Advanced detection and response capabilities with embedded threat intelligence and automated workflows
    Application Security
    Security integration throughout software development lifecycle with comprehensive application security testing
    Web Threat Intelligence
    Comprehensive monitoring of clear, deep, and dark web to identify and mitigate potential security threats
    Vulnerability Detection
    Real-time vulnerability assessment and prioritization across hybrid IT environments
    Cloud Scanning
    Cloud context-aware scanning with pre-approved scanner for AWS EC2 infrastructure
    Asset Discovery
    Comprehensive inventory and visibility of global IT infrastructure and assets
    Security Integration
    Unified cloud-based platform combining discovery, assessment, detection, and response capabilities
    Hybrid Environment Support
    Seamless vulnerability management across diverse IT infrastructure including cloud and on-premises systems
    Vulnerability Detection Coverage
    Comprehensive vulnerability scanning with support for over 76,000 vulnerabilities and 186,000 security plugins
    Cloud Asset Assessment
    Agentless continuous discovery and assessment of EC2 instances without requiring agent installation or credential management
    Security Configuration Analysis
    Built-in compliance profiles with risk-based scoring to prioritize security threats and vulnerabilities
    Vulnerability Disclosure Tracking
    Real-time detection and response capabilities for newly disclosed zero-day vulnerabilities
    Hybrid Environment Support
    Unified vulnerability management and cloud security posture management for diverse infrastructure environments

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    3 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    3 AWS reviews
    |
    83 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Financial Services

    IDR situation

    Reviewed on Aug 06, 2025
    Review provided by G2
    What do you like best about the product?
    It maps detections to MITRE ATT&CK, which helps a lot during investigations. So it makes the processes faster
    What do you dislike about the product?
    It's too limited. It's becomes difficult to create alerts and set up pattern based alerts do to the timing
    What problems is the product solving and how is that benefiting you?
    It gives us full visibility across endpoints, cloud apps, and logs. All in one place, and once
    Asim Naeem

    Providing comprehensive insight into alerts while working towards AI enhancement

    Reviewed on Feb 06, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I am using Rapid7 InsightIDR  as an InsightIDR  solution. This tool is integrated with other solutions like endpoint and NDR, and it correlates alerts, giving me a comprehensive picture of the alerts.

    What is most valuable?

    The platform offers unlimited storage and agent-based solutions. I have user behavior analytics (UBA ) and MITRE ATT&CK as well. The user behavior analytics feature helps in enhancing the security posture by helping to identify user behaviors and engineering alerts based on them.

    What needs improvement?

    There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on. I have already opened a list of features with Rapid7, and they are working on it.

    For how long have I used the solution?

    I have been using Rapid7 InsightIDR for about two years.

    What do I think about the stability of the solution?

    So far, I have not had any performance issues with Rapid7 InsightIDR. It is working well, and I have not faced any downtime in the last two years.

    What do I think about the scalability of the solution?

    Every  product has some limitations, and Rapid7 is no exception, yet it is working for me perfectly right now.

    How are customer service and support?

    I rate their technical team 8.5 out of ten, which is pretty good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Currently, I am not working with the LogRhythm  solution. I have another SIEM  solution in place. Previously, three years back, I was working with LogRhythm , however, now I do not.

    How was the initial setup?

    The initial setup was straightforward, and I did not face any complexities during the setup of the IDR product.

    What was our ROI?

    The incident response time is good, and I can easily find or search any incident. I easily build the queries in Rapid7 and search my relevant logs or relevant investigation logs.

    Which other solutions did I evaluate?

    I have EDR, XDR , NDR, TLP, and many other solutions like these.

    What other advice do I have?

    I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product. 

    Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Hiroshi Watanabe

    A cost-effective and stable solution but lacks an AI-driven capability

    Reviewed on May 24, 2024
    Review provided by PeerSpot

    What needs improvement?

    The solution lacks an AI-driven capability. While other competitors emphasize AI as the most important feature.

    For how long have I used the solution?

    I have been using Rapid7 InsightIDR as a distributor for seven years.

    What do I think about the stability of the solution?

    The product's stability is high. I rate the solution’s stability an eight out of ten.

    What do I think about the scalability of the solution?

    Due to its cloud-based nature and numerous agents, its scalability is high. This, combined with its on-premise environment, ensures rapid performance. It can handle several thousand. It is best suited for large-scale businesses.

    How are customer service and support?

    Support is slow. I'm not satisfied with the support so far.

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    Due to the product's complexity, the initial setup can be challenging. Additionally, setting up the product and training the customer can be quite demanding. Deploying the appliance or sensor on-premises can take up to twelve months.

    What's my experience with pricing, setup cost, and licensing?

    The product pricing is very cheap.

    What other advice do I have?

    InsightIDR automates everything through InsightConnect in a seven-day cycle.

    The product has improved significantly since its inception. However, based on feedback I've received from other products in the market, aside from InsightIDR.

    It improved because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively. 

    If you combine it with InsightIDR, then it may become more compact. Maybe IBM was a bit larger. So, having MDR is the main key point for this product.

    Overall, I rate the solution a four out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    reviewer1936950

    Offers unconventional detection rules and native integration features

    Reviewed on May 23, 2024
    Review from a verified AWS customer

    What is our primary use case?

    Our company is a system integrator for Rapid7 InsightIDR. We use the latest SaaS version of the product. Rapid7 InsightIDR works as the foundation of the security operation center in our company. The solution is used in our organization for data ingesting for multiple security devices and solutions. Rapid7 InsightIDR provides insights and stability on the security aspects of the company. 

    What is most valuable?

    The unconventional detection rules of Rapid7 InsightIDR are quite beneficial. The solution provides satisfying native integration features. 

    What needs improvement?

    The searching feature in Rapid7 InsightIDR needs to evolve. For instance, when pursuing an incident handling task, extensive searching is required, and the solution's own query language can only be used. In situations similar to the aforementioned example, the solution becomes difficult to use. It would be interesting if the vendor could make the search feature like the Google search engine. 

    For how long have I used the solution?

    I have been working with Rapid7 InsightIDR for three years. 

    What do I think about the stability of the solution?

    Overall, the solution is stable enough. I would rate the stability a nine out of ten. 

    What do I think about the scalability of the solution?

    The product's scalability seems good enough. In our company, we are able to manage a couple of thousand devices comfortably using only one single tenant.

    Through our company, thousands of users are using the interface of Rapid7 InsightIDR to process data and check incidents. I have implemented data ingestion for couple of thousand devices that include virtual machines, switches, routers and firewalls.

    For all the aforementioned devices we haven't faced any issues in our company. Rapid7 InsightIDR is used in our company, majorly for medium and enterprise grade customers, where some enterprises have more than 5000 employees and some less than that. 

    How are customer service and support?

    Our company mostly receives fast and suitable support from Rapid7 InsightIDR, but sometimes the response arrives quite slow. I would rate the technical support a seven out of ten. 

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    I would rate the initial setup a nine out of ten. It's quite straightforward to put the solution to work. Once Rapid7 InsightIDR activates the tenant, the deployment process becomes straightforward. In our company, we just download the agents and install them in the customers' virtual machines.

    Following the aforementioned step, some integration with Azure Entra ID authentication services or on-prem authentication is required. Thus, some base integration is required for login data. For the final stage of deployment, as part of the company, we configure a couple of customizations for the detection rules to start ingesting data; the niche customizations can be performed easily for the use cases. 

    In our company we have an engineering deployment team who are highly skilled in setup processes. For client companies with less than 500 devices, usually one full-time engineer is enough for the deployment. For clients with 500 devices, when we at our company use automation to deploy the agents, it takes only a couple of days to finish the deployment process. 

    What's my experience with pricing, setup cost, and licensing?

    The solution has a mid-range price point in the market. The licensing cost depends on the customer size and the negotiation on whether to add IVM. There are multiple add-ons to the base licensing fee, we use them only for specific customers of our organization. The additional licenses increase the pricing drastically, so we try to stick with the base license at our company. 

    What other advice do I have?

    At our company, along with Rapid7 InsightIDR we use multiple cloud providers like Azure, Google, Oracle and AWS infrastructure to ingest data. 

    I would advise others to select a reliable system integrator to implement Rapid7 InsightIDR for the correct use cases or business needs. The solution is satisfying, but there are multiple other solutions in the market, and having a partner can help a customer explore all the options before adopting one. Overall, I would rate Rapid7 InsightIDR an eight out of ten. 

    Vikas Dusa

    Useful for security operations, threat response, and DFIR

    Reviewed on Mar 04, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We use the tool for deployment, incorporating both EDR and SIP management. It serves the purpose of event management, including log retrieval from endpoints, malware detection, and providing about system health. This includes assessing vulnerabilities and determining the level of risk the system is exposed to at specific points in time. Its dashboard is wonderful. 

    We use Rapid InsightIDR for security operations, threat response, and DFIR. It also provides lab practices to individuals. 

    What is most valuable?

    During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an application belongs to a known ransomware group.  The system rates the threat, offering a clear detection ratio, such as 97 out of 100. It not only identifies threats but also illustrates the associated behaviors, helping us understand the potential risk to a particular endpoint.

    It provides user entity behavior analysis and a threat intelligence framework, combining SIEM and EDR for automation. My experience with user behavior analytics is positive and wonderful. It allows fetching logs, managing users, and overseeing endpoints. The capability to conduct investigations and import applications, along with configuring endpoints by collecting data, adds to its functionality. The platform offers a variety of features, including a dashboard for new alerts. This dashboard provides a quick overview of the number of users, endpoints, and noticeable behaviors. 

    What needs improvement?

    The solution needs improvement in threat intelligence. Increasing the depth of intelligence to help users understand more about threats is a possibility. My suggestion is to expand access to other websites or resources. 

    For how long have I used the solution?

    I have been using the product for more than three years. 

    What do I think about the stability of the solution?

    I rate the product's stability a nine out of ten.

    What do I think about the scalability of the solution?

    I rate the tool's scalability a nine out of ten. 

    How was the initial setup?

    The initial setup is easy. It involves tasks such as data collection, onboarding, and downloading, making the process straightforward for clients. You can deploy it on mobile devices as well. It offers deployment options for iPhone users and Windows. 

    What other advice do I have?

    In one instance, we faced a threat from the DarkSide ransomware, known for its ability to execute without requiring administration privileges, including a privilege escalation part. This particular ransomware was embedded in an Excel file, and it didn't need any administrative privileges for execution. The hackers cleverly concealed the DarkSide ransomware within an Excel file. When an unsuspecting team member tried to open the file, an alert indicated the malicious nature of the Excel file.

    The employee was unaware that the  Excel file contained a ransomware threat. As security personnel monitoring the endpoint received an alert, they immediately contacted the individual, notifying them about the presence of the DarkSide ransomware. The security team advised against opening the file and guiding the user to delete it.

    I cannot compare Rapid7 InsightIDR with other tools directly because it has integrated both EDR and SIM. It combines these functionalities into an XDR platform, operating at a different level compared to other services. Additionally, the network analysis provided is wonderful.

    The product is easy to use and easy to understand. It is lightweight. I rate it a nine out of ten.

    I recommend it for easy deployment, enabling swift detection from endpoints to the cloud. This accelerates security orchestration across various environments and endpoints, aiding in risk mitigation within hybrid environments. The system is valuable for discovering new threats and offers exposure management to enhance understanding of the entire security operation.

    View all reviews