Rapid7 Command Platform logo

    Rapid7 Command Platform

    Sold by
    The Rapid7 Command Platform is a command center that gives you a holistic view of your security program. The central hub of your Rapid7 experience, the Command Platform brings your ecosystem of Rapid7 tools and capabilities into a single place to give you a trustworthy view into your attack surface, your risk posture, your threat response, and your whole security program.

    Ratings and reviews

    4.3
    91 ratings
    56%
    41%
    2%
    1%
    0%
    5 AWS reviews
    |
    86 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (91)
    Prajwal Chougale

    Centralized threat hunting has improved alert accuracy and simplifies incident investigations

    Reviewed on Jul 17, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Rapid7 InsightIDR serves as our SIEM solution where all kinds of activity, including network logs, endpoint logs, user activity, user behavior analytics, and threat hunting, are tracked. Additionally, we use it to store logs and provide them for SOC analysts, and we utilize it completely as a SIEM tool. We also have used some of their other solutions, including Rapid7 Insight Vulnerability Management and Rapid7 Threat Command.

    In our day-to-day operations, Rapid7 InsightIDR is useful for tracking everything happening at the cloud level, at Entra ID, or on-premises. All logs, including network logs and traffic between domains or inside the domain or between on-premises servers and endpoints, are collected in one place. Using various analytical rules, we get alerts, and we configure the alerts required for our organizational needs. There are many more use cases for this solution.

    When it comes to threat hunting, we analyze dark web activity and track various activities related to users. We provide all user data to the agent, which searches the dark web for alerts based on our multiple domains. We actively monitor for any leaks detected with users or any spoofed domains and set up Rapid7 InsightIDR alerts to track these activities closely.

    What is most valuable?

    The best features that Rapid7 InsightIDR offers include its log display, which is easy to understand for any SOC analyst. In hunting, if there is any red team activity or a true positive incident and an analyst wants to hunt or review logs, Rapid7 has simple logic and features such as legacy log search and normal log search using KQL, Kusto Query Language, which allows for fetching and analyzing logs in detail. The way everything is arranged and easy to understand, along with insights into network sensors or devices configured with Rapid7, helps us understand where logs are being ingested and where traffic is moving.

    Out of all the features, log search is what I find myself using the most. Compared to Microsoft Sentinel, Rapid7 InsightIDR's SIEM tool makes log search very easy. The log display is simple, and the investigation part is very intuitive using Rapid7. Logs are segregated into different categories, such as ingress logs, web traffic logs, Active Directory logs, and cloud security logs, making it seamless to present everything on their dashboard, which has been immensely helpful for my investigative work.

    Rapid7 InsightIDR has positively impacted my organization by capturing most logs and every minute detail, including endpoint logs, network logs, and any email-related logs if a malicious link has been clicked. All logs are integrated and ingested into Rapid7 InsightIDR, which is useful for hunting or checking for any true positive incidents that trigger. A notable feature is that if an investigation opens on a single entity and any alerts are observed around that time, they are tagged under a single incident with all activity logged under one template or interface. This allows an analyst to make quick and easy decisions and analyze all investigation artifacts. Recently, when one of our users clicked a malicious URL that Microsoft Defender could not track immediately, Rapid7 notified us that a malicious email was found, helping us take action before Microsoft could respond.

    Rapid7 InsightIDR provides very crisp, detailed, and on-point alerts whenever there is suspicious activity, which has led to very few false positives for the clients using Rapid7 InsightIDR. It has saved us a lot of time by reducing noisy alerts, and the dashboard is effortlessly managed and neatly organized, allowing us to create allow lists or block lists for any kind of activity.

    What needs improvement?

    I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations.

    These two areas are the main areas for improvement; everything else is good.

    For how long have I used the solution?

    I have been working in my current field for around three years.

    What do I think about the stability of the solution?

    Rapid7 InsightIDR is stable with minimal downtimes or glitches; platform unavailability is very rare, and we have not experienced missed logs. Compared to Microsoft Sentinel, Rapid7 InsightIDR maintains high availability of logs and a reliable dashboard.

    What do I think about the scalability of the solution?

    Rapid7 InsightIDR's scalability fits very well for organizations of any size, making it a very easy-to-use, handy, and simple tool.

    How are customer service and support?

    The customer support at Rapid7 is really good. Over my 2.5 years of experience, I have submitted many support cases related to InsightIDR alerts, analytical rules, and even Insight Vulnerability Management, and they have been consistently supportive. I would rate the customer support a perfect 10 out of 10.

    Which solution did I use previously and why did I switch?

    For this client, we have exclusively used Rapid7 InsightIDR since the beginning as there were no other solutions in place. However, I can say that we used Microsoft Sentinel for other clients, and in comparison, Rapid7 InsightIDR has proven to be a more efficient and time-saving tool.

    How was the initial setup?

    The learning curve for new users of Rapid7 InsightIDR is very easy. Throughout my 2.5 years of experience, I have successfully onboarded three batches of users, totaling more than 10 users, and they adapted easily to this tool. The only challenging part was the log search, but once users got into it, it became very easy to use. Compared to the KQL of Microsoft Sentinel, Rapid7 InsightIDR has been much easier for users to learn.

    My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was straightforward thanks to the assistance from their team.

    What about the implementation team?

    We did not purchase Rapid7 InsightIDR through the AWS marketplace; we reached out to an agent through which we made the purchase.

    What was our ROI?

    I have seen a return on investment; all employees, particularly the SOC analysts, are satisfied as they easily got trained and adapted to this tool. The logs are delivered in a crisp and direct manner, simplifying analysis of the alerts significantly.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was straightforward thanks to the assistance from their team.

    What other advice do I have?

    I have completed my insights about my main use case and how we use Rapid7 InsightIDR day-to-day. All the improvements and features I have discussed are sufficient.

    I am very satisfied with the speed and performance of Rapid7 InsightIDR when handling large volumes of data, giving it a rating of 9.5 out of 10. It can handle any volume of data for any organization, making it very cost-effective, which distinguishes it as a standout SIEM tool in the market. It is straightforward, time-efficient, and easy to use.

    My advice for others considering using Rapid7 InsightIDR is to go for it if you are looking for a value-for-money and straightforward tool that suits any kind of analyst.

    Rapid7 InsightIDR is deployed in my organization through AWS public cloud. The deployment model we use most is public cloud through AWS. We use Amazon Web Services, AWS, as our cloud provider.

    Rapid7 InsightIDR integrates with other security tools or platforms in our environment, including CrowdStrike, Netskope, and email security through Defender.

    I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part.

    Rapid7 InsightIDR's AI capabilities are very helpful; the simulations or the SIEM injections they provide are useful for gaining alerts or insights about the organization, and it is very secure with no downtimes that affect client security. We have weekly meetings with support to discuss licenses or any new features added, which is really helpful in getting along with the tool.

    Most of the AI capabilities are still in progress, with various features being introduced. In Rapid7 InsightIDR, it is not heavily related to AI capabilities because the focus is primarily on the SIEM aspects, including logs from your environment and the size of your setup. My overall review rating for Rapid7 InsightIDR is 8 out of 10.

    Nihal J.

    Intuitive, High-Performance SIEM with Great Support and Cost-Effective Value

    Reviewed on Apr 29, 2026
    Review provided by G2
    What do you like best about the product?
    Rapid 7 SIEM has a intuitive UI/UX and straightforeard integrations with various third party vwendors which is crucial for a SIEM solution. rapid7 also has very good support and the perfomance of the SIEM in terms of log ingestion, correlation and detection is top nothc. Rapid 7 SIEM is also cost effectivr espocilly for SMB customers. Their in buit AI is also very helpfiu;l during query complex log data
    What do you dislike about the product?
    What I dislike is the lack of vendor support. Even though they have many options available, it still falls short compared to a few other SIEM solutions.
    What problems is the product solving and how is that benefiting you?
    The biggest problem Rapid 7 SIEM has solved for us is the lack of visibility into our infrastructure. We’re now able to see activity across firewalls, switches, cloud, and endpoints. This makes it easier to correlate events between each other and identify the attack path in the event of an attack. We can also integrate email security.
    bc@team-consulting.com C.

    Easy Log Search Across Our Estate with Clear, Understandable Alerts

    Reviewed on Jan 28, 2026
    Review provided by G2
    What do you like best about the product?
    It allows us to view and search the log sets generated across our estate with ease, and it produces clear, easy-to-understand alerts based on them.
    What do you dislike about the product?
    Honestly, there’s nothing to dislike. It really lifted the lid on our environments and helped us see what was going on more clearly.
    What problems is the product solving and how is that benefiting you?
    It’s been really helpful to be able to easily view and manage our various logs, and to have meaningful alerts generated from them.
    BENOIT C.

    Seamless UEBA Integration for Advanced Threat Detection

    Reviewed on Jan 13, 2026
    Review provided by G2
    What do you like best about the product?
    I highly value its seamless integration of UEBA and deception tools to detect lateral movement across the network.
    What do you dislike about the product?
    The platform lacks deep customization for complex correlation rules and can become quite expensive as log volume increases.
    What problems is the product solving and how is that benefiting you?
    It solves the problem of alert fatigue by unifying disparate logs into clear, actionable attack timelines for faster response.
    Joevanne V.

    Easiest SIEM Implementation with Transparent Pricing

    Reviewed on Jan 06, 2026
    Review provided by G2
    What do you like best about the product?
    In my experience, this is the easiest SIEM tool to implement. Another advantage is that, unlike many competitors, its pricing is not based on log ingestion. It has many pre-built integrations making it very easy to integrate with many 3rd party tools.
    What do you dislike about the product?
    This tool may feel somewhat limited when compared to some of the larger competitors in the industry.
    What problems is the product solving and how is that benefiting you?
    SIEM and managed detection and response have been advantageous for us, as they enable the collection of all necessary logs within our environment. This has removed our worries about costs or exceeding our log licensing limits.
    SohailHyder

    Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration

    Reviewed on Nov 05, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I am working with Rapid7 InsightOps and Rapid7 InsightIDR because the requirement is as such from the customer side, particularly the banks. Whatever the requirement is, these are the products that we are working with.

    I usually recommend Rapid7 InsightIDR for banks because that is the bigger chunk here who do business in cybersecurity or whose requirement is that compliance requirements need to be filled by certain products, which Rapid7 InsightIDR is one of them.

    What is most valuable?

    UEBA is an important element these days, but usually the requirement is for threat detection, investigation, and response. This is what Rapid7 InsightIDR provides.

    Banks typically go for threat detection, investigation, and response capabilities. End-user entity and behavior analysis, or UEBA, is certainly an important addition if we provide the solution along with UEBA. It provides that and this is something that the customer cannot ignore because they want to have a 360-degree coverage of their emails or for their users and what they are doing. This is definitely their requirement.

    What needs improvement?

    If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled.

    Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.

    For how long have I used the solution?

    It has been about four to five years now that we have been working with Rapid7. Whatever the products, they were all related to vulnerability tools that we have been working with. It has been a journey of about five years with Rapid7.

    What other advice do I have?

    Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar. It is good for a middle-tier organization. In that market, there is competition now.

    I do not recommend Rapid7 InsightIDR for bigger companies because they trust these big brands such as QRadar or LogRhythm. The general perception is that these are the solutions for big organizations having hundreds of branches or more. Rapid7 InsightIDR fits in the middle tier.

    The integration of Rapid7 InsightIDR with the security stack works fine because the systems in this part of the world are not so much cloud-driven. They have something around 20% or 30% of services running from the cloud. The rest are usually on-premises. Office 365 is one service that they get from the cloud. Networking typically includes Cisco and Fortinet in their networks. For endpoints, the operating system is usually Windows or Linux, not Mac in an enterprise environment. Windows and Linux can be easily integrated with this solution.

    The dashboard functionalities of Rapid7 InsightIDR are usually about customer-friendliness. Customers want to have some rich enrichment of the analysis or the ticket alerts or the events that come out with some processing behind the scenes. They feel that it is a more rapid or more intense process at Splunk or LogRhythm or QRadar compared to Rapid7 InsightIDR.

    For automated threat intelligence features, customers usually go for a full SOAR solution. They want to have playbooks and everything to run. Although Rapid7 InsightIDR does claim that it has integrated SOAR, called InsightConnect, this is not as advanced as a dedicated SOAR solution. LogRhythm solutions or Splunk solution or Sumo Logic solution are doing business here as well. These are considered more rich in features compared to Rapid7 InsightIDR.

    I rate Rapid7 InsightIDR between a six and seven out of ten.

    Financial Services

    IDR situation

    Reviewed on Aug 06, 2025
    Review provided by G2
    What do you like best about the product?
    It maps detections to MITRE ATT&CK, which helps a lot during investigations. So it makes the processes faster
    What do you dislike about the product?
    It's too limited. It's becomes difficult to create alerts and set up pattern based alerts do to the timing
    What problems is the product solving and how is that benefiting you?
    It gives us full visibility across endpoints, cloud apps, and logs. All in one place, and once
    Asim Naeem

    Providing comprehensive insight into alerts while working towards AI enhancement

    Reviewed on Feb 06, 2025
    Review from a verified AWS customer

    What is our primary use case?

    I am using Rapid7 InsightIDR as an InsightIDR solution. This tool is integrated with other solutions like endpoint and NDR, and it correlates alerts, giving me a comprehensive picture of the alerts.

    What is most valuable?

    The platform offers unlimited storage and agent-based solutions. I have user behavior analytics (UBA) and MITRE ATT&CK as well. The user behavior analytics feature helps in enhancing the security posture by helping to identify user behaviors and engineering alerts based on them.

    What needs improvement?

    There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on. I have already opened a list of features with Rapid7, and they are working on it.

    For how long have I used the solution?

    I have been using Rapid7 InsightIDR for about two years.

    What do I think about the stability of the solution?

    So far, I have not had any performance issues with Rapid7 InsightIDR. It is working well, and I have not faced any downtime in the last two years.

    What do I think about the scalability of the solution?

    Every product has some limitations, and Rapid7 is no exception, yet it is working for me perfectly right now.

    How are customer service and support?

    I rate their technical team 8.5 out of ten, which is pretty good.

    Which solution did I use previously and why did I switch?

    Currently, I am not working with the LogRhythm solution. I have another SIEM solution in place. Previously, three years back, I was working with LogRhythm, however, now I do not.

    How was the initial setup?

    The initial setup was straightforward, and I did not face any complexities during the setup of the IDR product.

    What was our ROI?

    The incident response time is good, and I can easily find or search any incident. I easily build the queries in Rapid7 and search my relevant logs or relevant investigation logs.

    Which other solutions did I evaluate?

    I have EDR, XDR, NDR, TLP, and many other solutions like these.

    What other advice do I have?

    I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product.

    Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.

    Hiroshi Watanabe

    A cost-effective and stable solution but lacks an AI-driven capability

    Reviewed on May 24, 2024
    Review provided by PeerSpot

    What needs improvement?

    The solution lacks an AI-driven capability. While other competitors emphasize AI as the most important feature.

    For how long have I used the solution?

    I have been using Rapid7 InsightIDR as a distributor for seven years.

    What do I think about the stability of the solution?

    The product's stability is high. I rate the solution’s stability an eight out of ten.

    What do I think about the scalability of the solution?

    Due to its cloud-based nature and numerous agents, its scalability is high. This, combined with its on-premise environment, ensures rapid performance. It can handle several thousand. It is best suited for large-scale businesses.

    How are customer service and support?

    Support is slow. I'm not satisfied with the support so far.

    How was the initial setup?

    Due to the product's complexity, the initial setup can be challenging. Additionally, setting up the product and training the customer can be quite demanding. Deploying the appliance or sensor on-premises can take up to twelve months.

    What's my experience with pricing, setup cost, and licensing?

    The product pricing is very cheap.

    What other advice do I have?

    InsightIDR automates everything through InsightConnect in a seven-day cycle.

    The product has improved significantly since its inception. However, based on feedback I've received from other products in the market, aside from InsightIDR.

    It improved because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively.

    If you combine it with InsightIDR, then it may become more compact. Maybe IBM was a bit larger. So, having MDR is the main key point for this product.

    Overall, I rate the solution a four out of ten.

    reviewer1936950

    Offers unconventional detection rules and native integration features

    Reviewed on May 23, 2024
    Review from a verified AWS customer

    What is our primary use case?

    Our company is a system integrator for Rapid7 InsightIDR. We use the latest SaaS version of the product. Rapid7 InsightIDR works as the foundation of the security operation center in our company. The solution is used in our organization for data ingesting for multiple security devices and solutions. Rapid7 InsightIDR provides insights and stability on the security aspects of the company.

    What is most valuable?

    The unconventional detection rules of Rapid7 InsightIDR are quite beneficial. The solution provides satisfying native integration features.

    What needs improvement?

    The searching feature in Rapid7 InsightIDR needs to evolve. For instance, when pursuing an incident handling task, extensive searching is required, and the solution's own query language can only be used. In situations similar to the aforementioned example, the solution becomes difficult to use. It would be interesting if the vendor could make the search feature like the Google search engine.

    For how long have I used the solution?

    I have been working with Rapid7 InsightIDR for three years.

    What do I think about the stability of the solution?

    Overall, the solution is stable enough. I would rate the stability a nine out of ten.

    What do I think about the scalability of the solution?

    The product's scalability seems good enough. In our company, we are able to manage a couple of thousand devices comfortably using only one single tenant.

    Through our company, thousands of users are using the interface of Rapid7 InsightIDR to process data and check incidents. I have implemented data ingestion for couple of thousand devices that include virtual machines, switches, routers and firewalls.

    For all the aforementioned devices we haven't faced any issues in our company. Rapid7 InsightIDR is used in our company, majorly for medium and enterprise grade customers, where some enterprises have more than 5000 employees and some less than that.

    How are customer service and support?

    Our company mostly receives fast and suitable support from Rapid7 InsightIDR, but sometimes the response arrives quite slow. I would rate the technical support a seven out of ten.

    How was the initial setup?

    I would rate the initial setup a nine out of ten. It's quite straightforward to put the solution to work. Once Rapid7 InsightIDR activates the tenant, the deployment process becomes straightforward. In our company, we just download the agents and install them in the customers' virtual machines.

    Following the aforementioned step, some integration with Azure Entra ID authentication services or on-prem authentication is required. Thus, some base integration is required for login data. For the final stage of deployment, as part of the company, we configure a couple of customizations for the detection rules to start ingesting data; the niche customizations can be performed easily for the use cases.

    In our company we have an engineering deployment team who are highly skilled in setup processes. For client companies with less than 500 devices, usually one full-time engineer is enough for the deployment. For clients with 500 devices, when we at our company use automation to deploy the agents, it takes only a couple of days to finish the deployment process.

    What's my experience with pricing, setup cost, and licensing?

    The solution has a mid-range price point in the market. The licensing cost depends on the customer size and the negotiation on whether to add IVM. There are multiple add-ons to the base licensing fee, we use them only for specific customers of our organization. The additional licenses increase the pricing drastically, so we try to stick with the base license at our company.

    What other advice do I have?

    At our company, along with Rapid7 InsightIDR we use multiple cloud providers like Azure, Google, Oracle and AWS infrastructure to ingest data.

    I would advise others to select a reliable system integrator to implement Rapid7 InsightIDR for the correct use cases or business needs. The solution is satisfying, but there are multiple other solutions in the market, and having a partner can help a customer explore all the options before adopting one. Overall, I would rate Rapid7 InsightIDR an eight out of ten.