Rapid7 Managed Threat Complete
AI-driven monitoring has reduced false positives and now needs more flexible reporting for stakeholders
What is our primary use case?
My main use case for Rapid7 MDR is to monitor incidents and ensure our applications are secured. I also want to make sure we are proactive in identifying threats.
I use Rapid7 MDR daily as part of our security process. My workflow starts on a day-to-day basis by checking the dashboard for overnight alerts to see if there are any incidents and to investigate them. If there is any incident that needs to be escalated to my SOC team, I handle that accordingly. It is mainly to monitor the applications 24/7 for any incidents or alerts. We also use Rapid7 MDR to investigate user activities.
We also use Rapid7 MDR for threat hunting with custom queries and for reports on a weekly and monthly basis to find how many incidents have occurred and to get all those details.
What is most valuable?
In my opinion, the best features Rapid7 MDR offers are the 24/7 coverage with unlimited incident response and also the latest AI-driven alerts, which is one of the best features I have seen recently. The integration models they have across different endpoints is also valuable.
After the AI-driven alert triage was used, our time spent on identifying false positive alerts was reduced drastically because a large portion of our time was previously spent on identifying false positives and segregating them. After the AI-driven alert triage was implemented, this was directly reduced, which helped us identify actual alerts and work on them quickly. The AI enrichment also provides assets and vulnerability context even before a cybersecurity analyst gets into the picture.
In terms of how Rapid7 MDR has impacted my organization positively, it has reduced our false positives after the AI feature was implemented. This reduction in false positive alerts gave us 24/7 coverage without having an in-house SOC team. It also helps us connect various endpoints to identify, detect, and monitor various endpoints across multi-cloud environments. It has helped us maintain our security posture on a day-to-day basis to keep our systems safe and secure, monitor our user usage, and identify vulnerabilities and asset criticalities.
Previously, the need for multiple analysts and multiple security personnel was reduced after the AI implementation. It gave us detailed response information, detailed incidents, and reduced false positives. It also provided us with the reports we needed for further analysis and gave us the gist of what the incident would look like and what would possibly be going wrong. It has reduced the number of billable hours and also gave us time to work on other improvement factors, which has actually reduced our overall human billing.
What needs improvement?
The major improvement I see is that the reporting and dashboarding experience could be more flexible because the needs for various companies would be different. Having a dashboard which is flexible and also having a more user experience friendly dashboard would be one of the major points I would like to see improved. Building custom reports for specific stakeholders is also important, especially because the current reports are generic and default, which are useful but not necessarily for stakeholders because they would like to see summaries, counts, and compliance-focused views.
I would say pricing transparency and a startup package would be great because pricing is one of the major standpoints for every company to adopt tools. Rapid7 does not have a startup package where companies can have lower pricing or a one-year startup trial or credits for new startups who are eligible to onboard. If that would be available, it could help growing companies use security tools like Rapid7. Additionally, log sources and third-party integrations sometimes require more manual work than expected.
For how long have I used the solution?
I have been using Rapid7 MDR for more than two years currently.
What do I think about the stability of the solution?
Rapid7 MDR is stable as of now.
What do I think about the scalability of the solution?
We have not seen any issues with Rapid7 MDR's scalability. We tried to add new endpoints and new locations, but we have not seen any issues in terms of adding new users or endpoints.
How are customer service and support?
We have only reached out during onboarding for customer support, so we did not have much experience with having calls or help with support.
Which solution did I use previously and why did I switch?
We did evaluate other tools in the market such as Fortify, OpenText, and Sonar before choosing Rapid7 MDR.
What was our ROI?
I would not be the right person to talk about the money saved, but I could say there has been lots of time saved since we have onboarded Rapid7 MDR. The need for cybersecurity personnel has also been reduced.
We were directly using Rapid7 MDR as the first solution.
The inclusion of digital forensics and incident response within Rapid7 MDR service has positively impacted my incident recovery process, both operationally and financially. During an incident, creating a separate retainer or negotiating scopes and often waiting for external responders to onboard before meaningful work could begin could actually delay our recovery time. However, with Rapid7 MDR, DFIR is fully included in the services, which means there is no hourly fee, no caps, or engagement limit. This means our forensics begins immediately, which gives us an upper hand. In terms of financials, we do not pay additional fees for investigators or separate tools to onboard or for negotiations on retainers.
What's my experience with pricing, setup cost, and licensing?
As for my experience with pricing, setup cost, and licensing, it is a corporate pricing structure and it was not startup friendly, which was one of the major issues I mentioned in improvements. The setup was not easy. We had to have someone already experienced in Rapid7 get involved in the setup and licensing. So it is not user friendly.
I would say the input cost could potentially be high when implementing Rapid7 MDR, but in the near future, you would be seeing a bigger saving factor in terms of time spent and the number of resources required.
What other advice do I have?
We have not used the multi-vector telemetry feature in Rapid7 MDR.
We have not used the integrated MDR for Microsoft environments feature.
We use the AI-assisted risk-aware investigation in Rapid7 MDR and it has impacted our triage by providing detailed context. It gives us detailed impact analysis and also does a deep analysis on what the threat could be and what the potential causes are. It also does a root analysis and gives us the impact event, impact asset, and also what a possible solution could be. This has made the security alert solving easier and faster to resolve.
We have not used the expanded ecosystem telemetry support.
I do not have anything else to add about the features.
I do not have any other improvements needed for Rapid7 MDR that we have not discussed yet.
I would need some time to think about the transparency of Rapid7 MDR in terms of gaining visibility into detections and investigations.
Rapid7 MDR's risk-aware detection features have created a very meaningful positive impact. The integration between the detection and exposure management within Rapid7 MDR unified platform means that the team can actually work on threats that impact the business rather than other threats. Vulnerability data, assets, critical user identity context, and attack path information all feed directly into the detections. When an alert actually fires, it evaluates the isolation and gives us the ability to focus on what needs to be fixed.
It has reduced 60 to 65 percent of false positives, which is actually very helpful and is good because it is almost near to accurate. The reasoning is also almost correct. I would say it is learning day by day but it is actually performing well.
In terms of Rapid7 MDR's AI governance and security, it is more transparent because with the AI capabilities, it has made a transparent approach to governance and security. This means it gives us the ability to see how alerts are triggered and on what actions, and also provides a list of details on the transparency of what AI takes action on and what decisions it has made. Every AI-driven triage decision is auditable and gives us a flow of what has been taken. Because auditing is one of the major factors in compliance, we are able to see what all decisions and when and what factors have made that decision. We can see the reasoning, the evidence considered, and the outcome. From the governance standpoint, the human analyst is still in the loop across the triage cycle.
My overall review rating for Rapid7 MDR is seven out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Automated threat detection has transformed network visibility and streamlined incident response
What is our primary use case?
Network detection and response is basically what I use Rapid7 MDR for, and it is a very good solution for that. I am using Rapid7 MDR for Microsoft environments, confirming its utility within those systems. I take advantage of the expanded ecosystem telemetry support offered by Rapid7 MDR. I have used InsightIDR, which is a SIEM for Rapid7, and InsightVM for vulnerability management. I appreciate their approach to detecting threats, and I consider it one of the best OEMs for threat detection and response, whether dealing with network issues, mobile devices, or user behaviors. Despite the pricing being a consideration, I always recommend Rapid7 MDR first.
What is most valuable?
The best features for me in Rapid7 MDR are the fact that it automates network traffic with users and the attacker behavior analytics, known as ABA, rather than UBA. The user behavior analytics and the attacker behavior analytics are important because it is a network-focused sensor that measures real-life patterns of users and attackers, which many other products do not provide. Rapid7 MDR has that real-life metrics, and I have gone through their platform, which also allows customers to correlate the newest attack patterns and methods they are using. They update their database periodically and integrate it with their MDR, which is why I appreciate their ABA and UBA so much.
The visibility of Rapid7 MDR is very accurate, and the transparency is commendable. If I am not too sure about its performance, I can correlate it with their cloud platform, which always has an updated dashboard about attacks. I also have access to the government database for correlation, and that shows they are doing real-time updates on these attacks, which is pre-built into the MDR. The accuracy and transparency for tracking are commendable.
What needs improvement?
Regarding improvements for Rapid7 MDR, I do not have anything specific for the product, but I would suggest synchronization time improvements for their vulnerability manager. For Rapid7 MDR itself, I am satisfied.
I have not thought about any missing features or functionalities that require enhancement in Rapid7 MDR at this moment.
For how long have I used the solution?
I have been working in my current field in the industry for six years.
What do I think about the stability of the solution?
When discussing stability, performance, and reliability specifically for Rapid7 MDR, I would say they are reliable and accurate. However, for other products like the vulnerability manager, I would not extend that same level of confidence.
What do I think about the scalability of the solution?
I find Rapid7 MDR to be very scalable. I can onboard more devices and expand easily.
How are customer service and support?
Regarding Rapid7's support team, I must say that their response time is not as quick as I would prefer. While they do respond, it can take a few days or even a week to get on a call.
On a scale of one to ten for tech support, I would rate them a seven. The support is good overall, but I believe the pace of response could improve.
How was the initial setup?
The setup process for Rapid7 MDR is always easy and straightforward. All their products are quite easy to implement; I do not need to overthink it. Reading the datasheet to understand it shows that it is not difficult at all.
What about the implementation team?
I implemented Rapid7 MDR myself, but for any issues, I can always reach out to Rapid7 support, and they join calls to assist.
Which other solutions did I evaluate?
The key differences between Rapid7 MDR and competitors such as ManageEngine or Sophos technologies are minimal as both OEMs have different approaches to implementation but aim for the same goal. Rapid7 MDR excels in accuracy over Sophos, especially concerning real-life monitoring, which is a significant differentiator for me.
What other advice do I have?
Having a dedicated security advisor through Rapid7 MDR positively impacts my alignment of security programs with business needs. As a security personnel using this for most of my customers, I can tell that the database is well updated. It gives me the most updated software for security regarding attacks and user behavior, which is crucial for business.
The key benefit of Rapid7 MDR is the way it automatically deploys on a port for me. I look at how to strengthen my customer's environment, ensuring that every IP address internally is accurate. Rapid7 MDR helps eliminate phishing IP addresses on the network, identifying and immediately rectifying them. It also deals with alert fatigue by preventing flooding of the dashboard with raw network anomalies and attacker behaviors. Their incident response is very quick; whenever there is a detection, they respond immediately. Some detections go to the administrator for approval, but with Rapid7 MDR, I can cancel and ask questions later, making it highly recommendable for real-time resolution, reducing alert fatigue, and addressing IP guessing.
With respect to risk-aware detection features, Rapid7 MDR provides full visibility into blind spots. I think I know my network, but I do not; Rapid7 MDR gives me full-time visibility and accurate data about things I am not seeing or paying attention to. Their third-party dashboard allows tracking of specific devices, which is essential in an enterprise environment where I cannot check each endpoint individually. Rapid7 MDR streamlines the information down to the exact affected endpoint and explains why it has been quarantined or removed from the network.
I have utilized the AI assistant for AI-assisted investigation workflow in Rapid7 MDR, and while I think it is a new feature for them, I find it similar to functions in other products. What makes their AI different is that it allows me to design and implement solutions. If there is an issue with the platform, AI can help pinpoint the source of the problem, even if it is a configuration issue. I have not fully used it yet, but I intend to explore its functionality within Rapid7 MDR infrastructure.
I have not actually used the multi-vector telemetry feature in Rapid7 MDR yet, although I have seen it.
My experience with Rapid7 MDR's detection and response capabilities for Microsoft-centric environments has been very smooth. I have not encountered any issues so far, and I believe that Rapid7 MDR and Microsoft have a good synchronization or handshake between their services, which contributes to this smooth operation.
The inclusion of digital forensics and incident response within Rapid7 MDR service impacts my incident recovery process by providing a dashboard that offers insightful reports on incident responses. They have a vast database that is continuously updated, which they incorporate into Rapid7 MDR for threat detection and response capabilities.
When it comes to pricing, Rapid7 MDR is known to have higher costs. However, the value is significant, and I believe that pricing should not be a problem if I recognize the worth of what I am paying for. Overall, I feel the value justifies the cost, though I see a need for a pricing reevaluation for some medium-class businesses.
I have seen cost-effectiveness with Rapid7 MDR solutions, comparing it to other options such as ManageEngine and Sophos.
My overall review rating for Rapid7 MDR is 8.5 out of 10.
Managed detection has transformed our response speed and reduced false positives dramatically
What is our primary use case?
My main use case for Rapid7 MDR is to manage detection and response, SIEM, and other threat management solutions from Rapid7, including the vulnerability part.
I use Rapid7 MDR in parallel to Rapid7 SIEM, where all the logs are ingested and where I carry out investigations and incident response activities.
The transparency of Rapid7 MDR detection is high, with detailed insights into each incident, including analyst notes, supporting evidence, attack timelines, and recommendations for remediation.
The risk-aware detection features in Rapid7 MDR are effective, as they help me focus on significant threats by correlating telemetry to identify realistic attack paths and prioritize incidents based on actual risk.
Having digital forensics and incident response included in Rapid7 MDR has greatly improved my incident recovery process by helping me determine root causes and the extent of compromises.
I utilize the integrated MDR for Microsoft environments, experiencing great visibility and effective incident response through this enhancement.
What is most valuable?
The best features Rapid7 MDR offers include the ability to configure alerts, log ingestion, monitoring capability, and threat detection that correlates telemetry from multiple security tools to detect advanced attacks, with every high priority incident validated by Rapid7 analysts initially, significantly reducing false positives.
I find myself relying most on the threat detection and investigation quality, as well as the threat intelligence, which has made a significant difference in the effectiveness of my incident response team.
Rapid7 MDR is an excellent choice for organizations that want enterprise-grade threat detection and response without building a 24/7 in-house SOC team, combining expert analysis, high fidelity detections, broad integration support, and actionable incident response.
Rapid7 MDR has positively impacted my organization by containing most of the false positives, as its in-house 24/7 team continuously monitors customer environments, enabling organizations to detect and respond to threats much faster.
Measurable improvements include seeing a reduced number of false positives compared to other tools because Rapid7's in-house team handles most of them, and the faster threat detection reduces the mean time to detect from hours or days to minutes due to continuous monitoring.
What needs improvement?
To improve Rapid7 MDR, I suggest enhancing detection and reporting, including customizable dashboards and more dynamic alert detection rules based on anomalies.
Everything mainly revolves around detections and reporting, and I find the user experience to be great with smooth integration from AWS.
For how long have I used the solution?
I have been working in my current field for almost three years.
What do I think about the scalability of the solution?
Rapid7 MDR is scalable and adapts well to any organization's size.
How are customer service and support?
Customer support is excellent, and they promptly connect whenever I raise a request, which I would rate more than nine.
I chose 9.5 because of their excellent customer support, efficient integration processes, and active communication during high incidents, helping my internal security team effectively handle critical situations.
Which solution did I use previously and why did I switch?
This is the only solution I have used for this particular customer.
What was our ROI?
Rapid7 MDR has provided a clear return on investment by significantly reducing the time my internal security team spends on alert triage through validated investigations and actionable recommendations.
What other advice do I have?
My advice to others is to choose Rapid7 MDR if you want a cost-effective SIEM solution backed by a great security support team.
I benefit from using AI-assisted risk-aware investigation workflows, which streamline investigations by correlating all relevant alerts and details into a single workflow, reducing manual effort in triaging incidents.
I gave this product a rating of 9.5 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Continuous monitoring has strengthened threat detection and has reduced false positive fatigue
What is our primary use case?
My primary use case of Rapid7 MDR is to do 24/7 threat monitoring and managed detection and response. We use it to identify suspicious activity across endpoint, network, and cloud environments and investigate the alerts and reduce false positive alerts through analysis.
One of the examples was we used Rapid7 MDR to detect a suspicious malware activity or PowerShell activity on a user's device. Rapid7 MDR can correlate that endpoint element with network authentication and identification, and it finds if it has suspicious activity and then escalates it with details. The alert had already been validated and with context, we were able to isolate the affected endpoint, investigate the user's activity, and confirm the incident. At the same point, Rapid7 MDR filtered several benign administrative activities such as PowerShell execution, which significantly allowed us to focus on genuine threats.
Overall, Rapid7 MDR helps us to strengthen our security operations by providing continuous monitoring, high quality threat detection, and expert analysis support. The contextual investigation and actionable recommendations have improved our SOC response and allowed the SOC team to focus on high priority activities rather than spending time on false positive alerts.
What is most valuable?
The best features that Rapid7 MDR offers are 24x7 alert monitoring, expert threat hunting, and high quality alert validation, which significantly reduces false positive alerts. I also appreciate the detailed incident investigations, actionable remediations and recommendations, and the ability to correlate the data from network and cloud environments. The service integrates all the security tools, and Rapid7 MDR analysts provide timely communication and valuable expertise that helps us to respond to attacks more efficiently.
I think the best feature is reducing the false positive alerts so we, instead of reviewing many alerts ourselves, Rapid7 MDR analysts validate the incidents with the relevant context before escalating them. This significantly reduces the alerts and false positives, allowing the SOC team to work on only high priority alerts.
Rapid7 MDR provides capabilities such as robust alert monitoring and investigation, and the Rapid7 MDR analysts already prioritize alerts and help the security analysts focus on high priority alerts only. Because of this, it improved our overall security posture and reduced the workload of the SOC analysts. With continuous monitoring, faster threat detection, and expert analyst support, we have been identifying security issues more quickly. Overall, it has ensured critical security events are detected and handled promptly.
What needs improvement?
I think Rapid7 MDR already has a strong managed security service, but I believe things can be improved. More customization options for detection rules and other workflows would help organizations to align their services more closely with the specific environment.
Additionally, improving the speed of the communication for the low priority alerts and providing more self-service investigation capabilities could further enhance the overall user experience.
I think the room for improvement is deeper customization and reporting flexibility. Rapid7 MDR is a solid solution overall. I think they can implement more customization options for detection, logging, workflows, and also the integration with other security platforms that would be helpful.
Rapid7 MDR transparency is quite good. It provides useful visibility into detections and investigations with detailed alert information and analyst notes. It shows severity classification and recommended actions. In these investigations, it helps our team to understand the alert, why it was generated, and what would be the next steps that we can take. For example, during a suspicious endpoint activity alert, the Rapid7 MDR team provides context around the process execution, related user activity, and supporting indicators, which help us quickly validate the incident and take appropriate actions. Additionally, more transparency into the detection logic and more customization visibility would further improve the experience.
For how long have I used the solution?
I have been working in this field since the last two point eight years.
What do I think about the stability of the solution?
Rapid7 MDR is quite stable according to my experience. The service has provided consistent monitoring and dependable support from the Rapid7 MDR team. We have not experienced availability issues.
What do I think about the scalability of the solution?
I think Rapid7 MDR is scalable. I have studied that it supports growth by allowing my organization to expand its monitoring coverage as the number of users, endpoints, and security data sources increases. The managed service model reduces the need to continuously scale the internal SOC resources while maintaining consistent monitoring and response capabilities. Also, the onboarding of assets and integration is relatively good, which helps to manage the increased volume of findings and investigations.
How are customer service and support?
Customer support is quite good, which is why I think it is quite good.
What other advice do I have?
We are utilizing the AI-assisted risk-aware investigation workflows in Rapid7 MDR. They help us improve our alert triage and prioritization by providing context around the alerts, identifying the risk factors, and helping analysts to focus on more critical security events. Instead of treating every alert with the same priority, the workflow considers factors such as asset criticality, behavior, threat intelligence, and attack patterns to determine the potential impact. This has helped in reducing false positive alerts and overall alert fatigue, and in speeding up the investigation of the real threats.
Rapid7 MDR AI capabilities are good for improving threat detection and alert prioritization and also in the investigation. From the governance and security perspective, I think they have strong controls around data handling, access management, and transparency, which helps in improving data security. Also, the combination of AI-driven analysis and Rapid7 MDR analysts provides a good balance where AI can help identify attack patterns quickly, while human experts validate findings and make the response decisions.
Rapid7 MDR is quite good and I appreciate the responses. I use it on a daily basis. I think it is really reliable as compared to the other platforms which I use, and it helps in reducing the investigation time by providing additional context and highlighting the important points.
The inclusion of the forensics and incident response capabilities has improved our investigations by providing deeper analysis and helping us to understand the scope of the threat and the impact of that on the environment. The forensic analysis also helps us identify the root cause, the affected systems, attackers' activities, and required remediation steps.
Rapid7 MDR has a few features that I think are very valuable because it goes beyond simple alert generation and focuses on the actual risk and potential impact of that risk in our organization. By considering factors such as important assets and user behavior, threat indicators, and the context of the attack, we can better assess our security posture.
I have used the multi-vector telemetry capabilities in Rapid7 MDR. It has helped me in improving investigation accuracy by correlating the data across different endpoints, user activity, and network activity. Having visibility across different telemetry sources provides better context for the alerts and helps us differentiate between legitimate and potential threats.
Cybersecurity advisor helps us make decisions by providing expert guidance and helping us focus on the risks and threats that matter the most to our business. They help us understand our security gaps, identify additional improvements, and also align our security strategy with the business requirements. This also ensures that our resources are used effectively and that security supports the organization's overall goals.
Currently, we are not using the integrated Rapid7 MDR for Microsoft environments feature. I think our team will be enabling that in the upcoming time.
My advice is that Rapid7 MDR is a good fit for organizations that want to use it for 24/7 security monitoring and expert investigation support. It also helps in reducing the workload of the internal SOC teams. With the help of this, SOC teams can mostly focus on the high priority alerts instead of wasting time on the false positives. I think this is a really good tool to have. I would give Rapid7 MDR a rating of eight out of ten because of its 24x7 monitoring capability and valuable analyst expertise that improves our security operations.
Continuous monitoring has improved threat detection and still needs a more intuitive dashboard
What is our primary use case?
I use Rapid7 MDR for security monitoring and easy onboarding and deployment. We primarily use Rapid7 MDR for threat detection and incident response, where it helps us to investigate deeply into those incidents.
What is most valuable?
One of the best features of Rapid7 MDR is 24/7 security monitoring, expert-led threat detection and response, AI-accelerated investigations, multi-vector visibility, informed defense, and incident response support. The full visibility of SIM, SIEM, and threat hunting is one of the features of Rapid7 MDR, and it has a strong customer partnership.
AI processes a large volume of security telemetry and helps us to speed up the triage and investigation, allowing human analysts to validate findings before action is taken. AI-accelerated investigation helps us significantly.
I particularly like the incident response support, as Rapid7 analysts assist with the investigation, containment, and remediation parts. The detailed incident reports and forensic analysis are very helpful and aid organizations in recovering from security events.
Rapid7 MDR has improved many policies in our organization and enhanced our ability to detect threats early before they become major incidents. It has increased our visibility across our environment, including servers, cloud resources, and user activities. Rapid7 MDR integration reduces the risk of security breaches through constant monitoring and proactive threat hunting, and it reduces filtering out false positives by focusing only on actionable threats. It saves valuable time for our internal security team because Rapid7 analysts perform initial investigations and triage, resulting in faster incident response due to timely detection.
The overall impact increases confidence in our security posture, enabling the security team to focus on strategic initiatives instead of spending excessive time reviewing alerts. It improves compliance readiness through detailed reporting and incident investigations and reduces our operational overhead by leveraging a team of security experts without needing to expand internal staffing.
Rapid7 MDR has helped our team to save approximately 10 to 15 hours per week by reducing the time spent on alert triage and initial investigation. It allows our security team to focus on remediation efforts and strategic security initiatives, whereas before implementing Rapid7 MDR, our security analysts used to spend significant time reviewing security alerts and triaging potential threats, which we estimate was nearly 30 to 40% of their time.
The biggest benefit has been operational efficiency. Instead of dedicating resources for around-the-clock monitoring, Rapid7 MDR acts as an extension of our security team, saving man-hours each month while improving detection and response capabilities. It has significantly reduced the time required for threat monitoring, alert validation, and incident investigation. The platform and analyst support help focus only on verified and actionable security incidents, which has improved efficiency and saved a considerable amount of our security operations team's time.
What needs improvement?
There are still a couple of areas where Rapid7 MDR can be improved. The visibility of the dashboard should be improved, and faster threat detection can also be enhanced. The dashboard visibility can be improved further, and the threat detection time also needs to be reduced to some extent.
For how long have I used the solution?
I have been using Rapid7 MDR for three years in my current organization.
What was our ROI?
This is a good return on investment, as Rapid7 MDR has saved a lot of money for this project.
What's my experience with pricing, setup cost, and licensing?
I feel the pricing cost of Rapid7 MDR is reasonable.
What other advice do I have?
Rapid7 MDR provides valuable visibility into security events, vulnerabilities, and risks, which relates to governance and security. The reporting and logging capabilities support all our readiness, help demonstrate security controls, and efficiently manage processes in our organization. The combination of AI-driven insights and expert analyst validation provides a well-balanced approach where automation improves speed while human expertise ensures accuracy. I particularly appreciate the Rapid7 analyst detections and investigations, which reduce alert fatigue, improve threat visibility, and speed up our security operations. Rapid7 MDR is a primary detection response service that makes it safer to say that our organization is well-protected.
For compliance support, Rapid7 MDR provides good visibility into vulnerabilities, threats, and security. When suspicious login activity is detected by Rapid7 MDR, the MDR team provides detailed information, including the affected user account, source IP address, and timeline of events, which helps us validate the event. The transparency is very good for Rapid7 MDR.
Rapid7 MDR follows a structured risk detection process that combines automated analysis and threat intelligence. It collects data, logs, and telemetry from endpoints, servers, and cloud environments, then enriches the data against multiple data sources and analyst validation.
The multi-vector feature is one of the best features, as it analyzes and correlates data across multiple attack vectors such as endpoints, identity, cloud environments, network, email systems, and other security tools. For example, an attacker may compromise a user account through phishing email, log in from an unusual location, and then try to access sensitive cloud resources. Individually, these events might appear harmless, but Rapid7 MDR correlates and analyzes data from email, identity, and cloud environments to recognize this attack chain and generate a high-fidelity alert. The benefits of multi-vector detection include better visibility across the attack, detection of complex attack chains, reduction of blind spots, improved threat detection accuracy, faster incident investigation, and providing better context for analysts.
The ecosystem is supported through endpoint telemetry, processing, and file activity, which has a significant positive impact on our security program. Rapid7 MDR is integrated with Microsoft and our other security tools. We are using AI-assisted risk workflows, including data ingestion, AI-based analysis, risk scoring and prioritization, analyst validation, investigation, and containment. The ecosystem supports endpoint telemetry, processing, file activity, and user behavior.
My overall review rating for Rapid7 MDR is 7 out of 10.
Managed detection has provided constant protection and removes the need for in-house expertise
What is our primary use case?
Our main use case for Rapid7 MDR is that they serve as our SOC.
What is most valuable?
Rapid7 MDR is an IDR that does what it is supposed to do. The vulnerability management helps us keep our products and systems up to date.
I am satisfied with the risk-aware detection feature in Rapid7 MDR and have no issues with it.
We use the AI-assisted feature in Rapid7 sometimes, mainly to understand the logs from systems that we are not familiar with.
The main benefits that Rapid7 MDR provides for me as an end-user are the security and that they are available 24 hours a day, always. This gives me reassurance because I do not have to be an expert on the cybersecurity part because they are. We are a quite small firm, so we do not have that in-house expertise, which is why we rely on them.
What needs improvement?
Regarding points for improvement in Rapid7 MDR, I do not have to do anything with them unless I have a problem. The less I hear from them, the better, because they contact us when there is a problem. We have our monthly meeting, and that is fine by me. That is pretty much it; I get what I want, and I do not want anything else.
The price of Rapid7 MDR could definitely be lower, as these are expensive systems, especially if you have the MDR. They could work on the price.
For how long have I used the solution?
I have been working with Rapid7 MDR for about two years.
What do I think about the stability of the solution?
I would rate Rapid7 MDR as a 10 for stability; it has always been there and has never been down.
What do I think about the scalability of the solution?
The ability to scale Rapid7 MDR is really super easy, so I would rate it a 10 as well.
How are customer service and support?
I would rate Rapid7 technical support as definitely a 10, because whenever we have had any problems, it is really fast and sensitive to our knowledge. I get the help I really need, and it is fast, so it is really good.
Which solution did I use previously and why did I switch?
I have only worked with Rapid7 when it comes to MDR; I have no experience with other products.
How was the initial setup?
Based on my experience, it is really easy to start working with Rapid7 MDR; you are up and running in a day or two.
The initial setup process for Rapid7 MDR is really easy; it was really easy for us.
What about the implementation team?
We did the setup processes in-house for Rapid7 MDR ourselves.
Which other solutions did I evaluate?
The main competitor for Rapid7 MDR would be CrowdStrike, in my opinion.
I have not looked into CrowdStrike; I do not know the specifics of what they call it, but they have the big offerings as well.
What other advice do I have?
I would definitely recommend Rapid7 MDR to other users. I would rate this review a 10.
Managed detection has transformed our soc by improving visibility and speeding incident response
What is our primary use case?
Rapid7 MDR is our managed service that serves as our SOC and represents our starting point in utilizing a solution for cybersecurity. Rapid7 MDR is the primary use case for our company's SOC.
What is most valuable?
The consulting and monthly consulting and reporting are very useful features that we find most valuable.
Having a dedicated cybersecurity advisor through Rapid7 MDR helps us align our cybersecurity strategy to the up-to-date measurements and controls that we can take, which impacts how we align our security program with business needs.
With a very small IT operations team, we have experienced a positive impact from Rapid7 MDR. In the past, we had much effort to handle incidents, and now with the SOC on our side, the process is more streamlined, and we are much faster than before.
My impression of the Risk-Aware Detection features is positive; they work well for us.
We are starting to get into the AI solutions from Rapid7 MDR for our SIEM, but we are in the very beginning stages, focusing on AI-assisted Risk-Aware Investigation workflows.
We are using the integrated MDR for Microsoft environments feature. Up to now, it works well regarding its detection and response capabilities for Microsoft-centric environments.
Now we have a clear view of what has happened in our tenant, which has impacted our incident recovery process positively; before, we did not have this view. We have many signals, so we can control them and check if we are on the right path or if it is just a false incident, and it works very well. In the last several months, we have seen more than we have seen in the previous two years.
What needs improvement?
AI is present, and I think Rapid7 MDR could add good reporting, more reporting, and perhaps more templates in the future to make the product even better.
For how long have I used the solution?
Since the beginning of the year, we have been using this tool.
What do I think about the stability of the solution?
Rapid7 MDR works really well; we are completely satisfied with it. It is a nice service and I believe we have everything we need. From my perspective, I have no improvements to suggest. There is much more we have to discover.
What do I think about the scalability of the solution?
I do not think there are scalability issues regarding extending usage in the future.
How are customer service and support?
When ten is the best, I would rate their technical support at a ten.
Which solution did I use previously and why did I switch?
We have Rapid7 IVM and SIEM, and we are still using them. We have now added Rapid7 MDR as a service, which reflects our previous positive experience with Rapid7 solutions.
How was the initial setup?
I cannot speak to how the initial setup was because we had Rapid7 IVM and SIEM before, and that setup occurred before my time. The setup for Rapid7 MDR was very simple because we already had half of the infrastructure in place.
Which other solutions did I evaluate?
We evaluated many other solutions for various situations, but ultimately we chose Rapid7 MDR because of the price and the service, which were perfect for us.
What other advice do I have?
I find the pricing reasonable and competitive.
Rapid7 MDR is hybrid regarding whether it is on-premises, cloud-based, or hybrid.
I purchased Rapid7 MDR through our IT supplier.
Five people, at most, are working with the product in our company, indicating the usage is currently pretty limited.
The interface is very handy and user-friendly.
I would say Rapid7 MDR is popular; Rapid7 is a well-known name in my region.
I would rate this product a ten out of ten.
Threat detection has improved for AI-driven traffic but confidence in AI security remains low
What is our primary use case?
Our primary use cases focus on threat detection and network-related security concerns, with an emphasis on cybersecurity-related areas.
What is most valuable?
My team is satisfied with the current capabilities, though there are certainly areas for improvement. Rapid7 MDR has not covered all the areas we need, which is why we also utilize Zscaler. For personalized security for developers, testers, and other audiences who are exposing their network to risk, we definitely need very micro-level monitoring of requests and network activity.
All stakeholders claim that Rapid7 MDR is very effective at identifying threats in today's AI era. It is quite difficult for all of us to identify what type of code or requests are coming through. This improvement is very important to the product itself and its realignment. We raised a request, and Rapid7 MDR has made changes to their product by conducting extensive research and development with thorough testing.
What needs improvement?
There are multiple areas for improvement, especially regarding generative AI-related threats. Secondly, proxy communication happens through agentic AI, making it very difficult to identify whether it is agentic AI, a human, or a hacker. That filtering and identification will need to be improved in Rapid7 MDR. Many products still do not make that effort, but Rapid7 MDR has started to address this; however, this remains a drawback at the moment. We moved our own artificial intelligence product, and our developers and testers are using it, but we still restrict its use to inside our Fujitsu premises. We cannot allow it to go outside because we do not have that level of trust at the moment.
It is quite difficult to specify all areas at the moment, but there are multiple features needed. Based on our transformation with a combination of cloud technology and artificial intelligence, we are using co-pilot and multiple AI models will require many enhancements aligned with new technology trends in the market. I cannot articulate or name all of them, but we are still not confident in asking customers to use AI in their environment. They are reluctant at the moment because of security concerns and other myths around AI. There should definitely be a tool that gives us the confidence that whatever AI model we are using is secured through that tool. That tool should assure customers that there is a 90% or 98% guarantee that their code or utilization of AI technology will meet the mark. Currently, customers are not flexible in beginning to utilize AI, especially for financial institutions, research and development institutes, or places where sensitive business operations occur or large customer volumes exist. No one can risk it at the moment. People are using co-pilot, chatbots, or bot services, but they are still not confident in utilizing them without taking risks. No one can claim that they are 100% secure in providing those services. We are expecting that type of confidence from Rapid7 MDR and other technologies playing a role in the market.
For how long have I used the solution?
We have been using this solution for more than four years.
How are customer service and support?
Getting responses from any service industry is challenging. We have an SLA, especially those SLAs from which we really need support based on our customer expectations, particularly for our developers. Every machine has Rapid7 MDR installed. We have our own IT department that is enabled with all training. The thing is that we do not directly rely on Rapid7 MDR for support, but we have built up our own competency with Rapid7 MDR. Only for very urgent issues do we get support from Rapid7 MDR, but that also depends upon the contract. We do not have extensive experience where we frequently interact with Rapid7 MDR, but wherever there is a setting, configuration management, or something similar, we are getting support from their technical or non-technical staff. It is about how you build your relationship with them. We are training our employees and providing them with training, and once they are trained, we believe this is a common shared responsibility.
What's my experience with pricing, setup cost, and licensing?
The setup cost is reasonable and not so expensive. It is simple and straightforward.
What other advice do I have?
We are primarily on Microsoft with a platinum contract, so all products we evaluate are in line with Microsoft's technology stack. Rapid7 MDR and Zscaler are both well-equipped and support Microsoft technology. Since Microsoft has its own products like Defender and others, we still use them for our daily work. I would rate my overall experience with customer service as a 3 out of 10.
Security team has gained deeper analytics and now maintains a stronger risk‑based posture
What is our primary use case?
I am using Rapid7 MDR for all the devices in a single data center. We have different devices including Windows servers, firewalls, endpoints, and various Arista devices. All those devices log different incidents that are managed by Rapid7 MDR.
We are using a Microsoft environment for our endpoints. We are collecting syslog logs for that. We also use EDR, and the correlation is quite useful. We have been getting new kinds of alerts and more insight into the endpoints. This proved valuable because we integrated EDR with it.
What is most valuable?
We were using an in-house SIEM before with different use cases and analytics. However, it did not give us more insight into the logs that we were fetching. The benefits that came with Rapid7 MDR is the analysis we are getting now, which is quite useful. Apart from that, we also got user behavior analytics and EDR integration, which helped us considerably.
Regulatory compliance basically guides us at the moment. Our infrastructure is quite critical, so security posture needs to be well maintained. We are relying on Rapid7 MDR and have had a good experience. It is fulfilling our strategy. We have a risk matrix ourselves that maps with the risk posture we have. We are relying on our in-house risk matrix at the moment, but we also have a good feature with Rapid7 MDR.
What needs improvement?
We currently come across more false positives. The tool is a bit more aggressive than other tools. However, this can be fixed with tuning. We are working on tuning it better. Our infrastructure is expanding a lot, so we are getting lots of logs. The ingestion then becomes an issue from a cost perspective. These are the main areas for improvement.
For how long have I used the solution?
I have been using the solution for one and a half years now.
How are customer service and support?
If we talk about different vendors, there is competition, but the user interface of Rapid7 MDR is quite useful for us. The support is also good. There are different vendors which have more experienced staff. However, Rapid7 MDR has been the best in zero-day attacks and the vulnerabilities that come into picture. We prefer that.
Which solution did I use previously and why did I switch?
We were using an in-house SIEM before with different use cases and analytics. It did not give us more insight into the logs that we were fetching. The benefits that came with Rapid7 MDR is the analysis we are getting now, which is quite useful.
How was the initial setup?
It is very easy.
What about the implementation team?
We have a team, though we do not have a segregated team for it at the moment. We have around fifty individuals in different places and different responsibilities.
What's my experience with pricing, setup cost, and licensing?
The log ingestion is the main criteria that comes into picture. I would not say it is cheap, but it is more efficient. It is economical for us. We evaluated different tools and services before. If we check the functional requirement and financial perspective, this is the best service.
What other advice do I have?
We generally do not get into the telemetry part of it, and that is impacting a few things that align with our strategy at the moment. However, we should use it more. We will be contacting the support team for that.
Regarding scalability, I would rate it a nine. If an organization is looking for an edge in security and they have any kind of on-prem, hybrid, or cloud solution, I think they should go for Rapid7 MDR. Based on my experience, I have evaluated different vendors and this came out to be the better solution for us. I would recommend this. My overall rating for this product is nine.
Compliance reporting has become fast and clear while pricing still needs improvement
What is our primary use case?
Our use case is to measure our compliance score. We measure our compliance status with CIS benchmarks implemented via Intune and Defender, which was a request from management.
What is most valuable?
I think the best feature of Rapid7 MDR is that it is silent and easy to use. Sometimes I had some problems with it, but I believe that was caused by Microsoft and their policies. It was really fast to measure our compliance.
Rapid7 MDR helped us find some gaps and vulnerabilities in our policies. It helped to make sure that we did not miss anything in our implementation.
It helped us to establish possible outcomes and what might happen if we want to implement something.
What needs improvement?
I did not use all features, so I am not sure what is already implemented or what would be good to implement. However, I think the best area for improvement is pricing.
For how long have I used the solution?
I have been using Rapid7 MDR for half of the year, a few months.
What do I think about the stability of the solution?
There were no problems, so I think stability is nine out of ten.
Which solution did I use previously and why did I switch?
I cannot compare Rapid7 MDR with other solutions because I did not use other detectors. If we are talking about Defender, I think it is really popular. I would say it is in the top five, and that is a really reasonable place for them.
How was the initial setup?
The setup was really quick and easy.
What about the implementation team?
Three people use Rapid7 MDR to manage and verify our compliance status. Three people was enough.
What other advice do I have?
I did not use the Risk-Aware Detection feature at all, so unfortunately I cannot answer questions about that.
Regarding Intune, I have been using it for six years and Defender for two and a half years. Those are the two products I use the most. I also use some admin center, Exchange admin center, and other tools.
I am not sure about certain features because I did not use them all. However, as I have been in a support role, I think I should rate that at eight out of ten.
From my perspective, Rapid7 MDR is a really good product that is easy to implement and use. I achieved everything I needed, prepared the whole report, and it took me a few days. That is pretty fast and awesome.
My overall review rating for this product is seven out of ten.