Our company is a system integrator for Rapid7 InsightIDR. We use the latest SaaS version of the product. Rapid7 InsightIDR works as the foundation of the security operation center in our company. The solution is used in our organization for data ingesting for multiple security devices and solutions. Rapid7 InsightIDR provides insights and stability on the security aspects of the company.
InsightIDR - Next-gen SIEM
Rapid7External reviews
External reviews are not included in the AWS star rating for the product.
Offers unconventional detection rules and native integration features
What is our primary use case?
What is most valuable?
The unconventional detection rules of Rapid7 InsightIDR are quite beneficial. The solution provides satisfying native integration features.
What needs improvement?
The searching feature in Rapid7 InsightIDR needs to evolve. For instance, when pursuing an incident handling task, extensive searching is required, and the solution's own query language can only be used. In situations similar to the aforementioned example, the solution becomes difficult to use. It would be interesting if the vendor could make the search feature like the Google search engine.
For how long have I used the solution?
I have been working with Rapid7 InsightIDR for three years.
What do I think about the stability of the solution?
Overall, the solution is stable enough. I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
The product's scalability seems good enough. In our company, we are able to manage a couple of thousand devices comfortably using only one single tenant.
Through our company, thousands of users are using the interface of Rapid7 InsightIDR to process data and check incidents. I have implemented data ingestion for couple of thousand devices that include virtual machines, switches, routers and firewalls.
For all the aforementioned devices we haven't faced any issues in our company. Rapid7 InsightIDR is used in our company, majorly for medium and enterprise grade customers, where some enterprises have more than 5000 employees and some less than that.
How are customer service and support?
Our company mostly receives fast and suitable support from Rapid7 InsightIDR, but sometimes the response arrives quite slow. I would rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
I would rate the initial setup a nine out of ten. It's quite straightforward to put the solution to work. Once Rapid7 InsightIDR activates the tenant, the deployment process becomes straightforward. In our company, we just download the agents and install them in the customers' virtual machines.
Following the aforementioned step, some integration with Azure Entra ID authentication services or on-prem authentication is required. Thus, some base integration is required for login data. For the final stage of deployment, as part of the company, we configure a couple of customizations for the detection rules to start ingesting data; the niche customizations can be performed easily for the use cases.
In our company we have an engineering deployment team who are highly skilled in setup processes. For client companies with less than 500 devices, usually one full-time engineer is enough for the deployment. For clients with 500 devices, when we at our company use automation to deploy the agents, it takes only a couple of days to finish the deployment process.
What's my experience with pricing, setup cost, and licensing?
The solution has a mid-range price point in the market. The licensing cost depends on the customer size and the negotiation on whether to add IVM. There are multiple add-ons to the base licensing fee, we use them only for specific customers of our organization. The additional licenses increase the pricing drastically, so we try to stick with the base license at our company.
What other advice do I have?
At our company, along with Rapid7 InsightIDR we use multiple cloud providers like Azure, Google, Oracle and AWS infrastructure to ingest data.
I would advise others to select a reliable system integrator to implement Rapid7 InsightIDR for the correct use cases or business needs. The solution is satisfying, but there are multiple other solutions in the market, and having a partner can help a customer explore all the options before adopting one. Overall, I would rate Rapid7 InsightIDR an eight out of ten.
Useful for security operations, threat response, and DFIR
What is our primary use case?
We use the tool for deployment, incorporating both EDR and SIP management. It serves the purpose of event management, including log retrieval from endpoints, malware detection, and providing about system health. This includes assessing vulnerabilities and determining the level of risk the system is exposed to at specific points in time. Its dashboard is wonderful.
We use Rapid InsightIDR for security operations, threat response, and DFIR. It also provides lab practices to individuals.
What is most valuable?
During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an application belongs to a known ransomware group. The system rates the threat, offering a clear detection ratio, such as 97 out of 100. It not only identifies threats but also illustrates the associated behaviors, helping us understand the potential risk to a particular endpoint.
It provides user entity behavior analysis and a threat intelligence framework, combining SIEM and EDR for automation. My experience with user behavior analytics is positive and wonderful. It allows fetching logs, managing users, and overseeing endpoints. The capability to conduct investigations and import applications, along with configuring endpoints by collecting data, adds to its functionality. The platform offers a variety of features, including a dashboard for new alerts. This dashboard provides a quick overview of the number of users, endpoints, and noticeable behaviors.
What needs improvement?
The solution needs improvement in threat intelligence. Increasing the depth of intelligence to help users understand more about threats is a possibility. My suggestion is to expand access to other websites or resources.
For how long have I used the solution?
I have been using the product for more than three years.
What do I think about the stability of the solution?
I rate the product's stability a nine out of ten.
What do I think about the scalability of the solution?
I rate the tool's scalability a nine out of ten.
How was the initial setup?
The initial setup is easy. It involves tasks such as data collection, onboarding, and downloading, making the process straightforward for clients. You can deploy it on mobile devices as well. It offers deployment options for iPhone users and Windows.
What other advice do I have?
In one instance, we faced a threat from the DarkSide ransomware, known for its ability to execute without requiring administration privileges, including a privilege escalation part. This particular ransomware was embedded in an Excel file, and it didn't need any administrative privileges for execution. The hackers cleverly concealed the DarkSide ransomware within an Excel file. When an unsuspecting team member tried to open the file, an alert indicated the malicious nature of the Excel file.
The employee was unaware that the Excel file contained a ransomware threat. As security personnel monitoring the endpoint received an alert, they immediately contacted the individual, notifying them about the presence of the DarkSide ransomware. The security team advised against opening the file and guiding the user to delete it.
I cannot compare Rapid7 InsightIDR with other tools directly because it has integrated both EDR and SIM. It combines these functionalities into an XDR platform, operating at a different level compared to other services. Additionally, the network analysis provided is wonderful.
The product is easy to use and easy to understand. It is lightweight. I rate it a nine out of ten.
I recommend it for easy deployment, enabling swift detection from endpoints to the cloud. This accelerates security orchestration across various environments and endpoints, aiding in risk mitigation within hybrid environments. The system is valuable for discovering new threats and offers exposure management to enhance understanding of the entire security operation.
An affordable product that is easy to use and has many advanced features and default templates
What is most valuable?
It’s a great tool. The solution helps us a lot in threat detection. It’s one of the most updated tools. The UI is very good. We can easily start using the tool and explore it. It also provides features like legacy UBA that other products do not provide. We can customize the rules from the default template in InsightIDR. UBA is a great feature.
When a new user is created in Active Directory, an investigation is created. We can use the default features to create an investigation. The solution has many advanced features and default templates that help protect from attacks without a user’s intervention. It is quite impressive.
What needs improvement?
The product allows us to make only 30 custom rules. The limit on custom rules must be changed.
For how long have I used the solution?
I have been working with the product for two months.
What do I think about the scalability of the solution?
We have deployed the solution in 28 offices. We are using the basic features for now.
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
We chose Rapid7 because of its price. IBM QRadar charges us based on data storage. Rapid7 InsightIDR charges us based on the endpoints we connect to. We are satisfied with the product’s price.
Which other solutions did I evaluate?
I have used IBM QRadar, Splunk, and Sentinel. We use Splunk in our offices, too. Compared to other products, Rapid7 InsightIDR’s UI is very good. It is very easy to handle. We are working with the tool currently and are quite satisfied with it.
What other advice do I have?
Overall, I rate the solution a nine out of ten.
A tool to detect malicious activities and provide security to networks and endpoints
What is our primary use case?
Rapid7 InsightIDR helps me detect any malicious activities in any endpoints in my company.
How has it helped my organization?
I have seen that Rapid7 InsightIDR provides security to the networks and endpoints in the company.
What is most valuable?
With Rapid7 InsightIDR, you must install the Insight Agent, after which you may get to see some of the risks affecting endpoints.
What needs improvement?
The integration capabilities of the solution have certain shortcomings where improvements are required.
If possible, it would be great to see AI embedded in all the functionalities offered by the product.
For how long have I used the solution?
I have been using Rapid7 InsightIDR for four years. I use the solution's latest version since the version gets automatically updated as it is a cloud-based tool. I work as a distributor of the product.
What do I think about the stability of the solution?
Stability-wise, I rate the solution an eight out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Scalability-wise, I rate the solution an eight out of ten.
How was the initial setup?
The time required to complete the product's installation phase depends on the number of endpoints that a user has in their environment. Insight Agent can be deployed in a couple of minutes.
Five engineers in my company take care of the deployment phase of Rapid7 InsightIDR.
The solution is deployed on the public cloud services offered by AWS.
What's my experience with pricing, setup cost, and licensing?
Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight.
Which other solutions did I evaluate?
I did not evaluate any other options in the market against Rapid7 InsightIDR.
What other advice do I have?
I have never been involved with any maintenance process related to Rapid7 InsightIDR.
To those who plan to use the solution, I suggest that they undertake a training program to understand the product.
I rate the overall tool an eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
A stable solution that works well for playbooks and viewing events
What is our primary use case?
Normally, we use the solution as an event viewer to collect and resume cases and playbooks.
What needs improvement?
The main problem lies in the processes within the client's operating systems. XDR is superior to CMs. Observing how the processes function within the machine is essential if you are monitoring the client or servers, and not only the event with the first or second line but the third line is most important.
For how long have I used the solution?
I've been familiar with the solution for six months.
What do I think about the stability of the solution?
The solution is very stable and works very well for what I need it to do. The solution is completely different in an experienced environment and a real environment.
Which solution did I use previously and why did I switch?
I have worked with Wazuh before, but only to try it. Wazuh is more or less the same as Rapid7 InsightIDR.
What other advice do I have?
I rate Rapid7 InsightIDR an eight out of ten.
A solution that offers easy setup and deployment phases, along with great scalability and stability
What is our primary use case?
I use Rapid7 InsightIDR to collect logs and information from throughout our company's entire IT environment.
What is most valuable?
The most valuable feature of the solution is the single pane of glass that allows me to see all the information in one spot. I can see at one spot to see all the information from all the logs and everything.
What needs improvement?
Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries. In the future, I would like the tool to offer its uses with a pre-made set of queries.
For how long have I used the solution?
I have been using Rapid7 InsightIDR for a year. I use the solution's latest version. My company is a customer of the solution.
What do I think about the stability of the solution?
The product works well. Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
I rate the product's scalability a ten out of ten since, scalability-wise, it is a really good tool.
Rapid7 InsightIDR is managed by four people in my company.
How are customer service and support?
The speed of response from the technical support team may vary since I purchased it from a reseller in Sweden and not from Rapid7 directly.
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
In the past, my company used Unomaly, a tool from Sweden. My company switched from Unomaly to Rapid7 InsightIDR after seeing that the former could only checked syslogs, while we wanted something that checked our overall systems.
How was the initial setup?
I rate the initial setup a ten out of ten.
The solution's initial setup was very straightforward.
The solution is deployed on an on-premises and cloud model. The cloud services are provided by Rapid7.
The solution can be deployed in half a day or four hours in a small environment.
I was the only person involved in the product's deployment phase.
What's my experience with pricing, setup cost, and licensing?
After considering the prices of the product's competitors, I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive. There may be some additional costs attached to the solution only if you want to buy a SOC or something. I don't have to pay for any additional costs at the moment.
What other advice do I have?
I suggest that those who plan to use the solution give it a try since it is free for a couple of months. The solution has really easy setup and deployment phases, and you can even remove it from your environment if you want to do so later.
I rate the overall product a nine out of ten.
Which deployment model are you using for this solution?
Lets you simplify threat detection and has a fast deployment
What is our primary use case?
The solution is used as a platform for a better understanding of the Intelligence products that different vendors sell.
What is most valuable?
Rapid7 is easy to use and deploy. It is a simple solution and has easy data pulling.
What needs improvement?
The APIs can be further improved in Rapid7.
For how long have I used the solution?
I have been using Rapid7 InsightIDR for two months.
What do I think about the stability of the solution?
It is stable solution.
What do I think about the scalability of the solution?
It is a scalable solution. Presently, there are only small businesses working with the solution.
How are customer service and support?
The technical support team is good.
How was the initial setup?
The initial setup is easy. The deployment took only half an hour. It's just a cloud platform. You just have to deploy a connector like Select Pro, and it will set the data from the on-premise. It will send it to the cloud platform, and you can have it installed in five to ten minutes.
What's my experience with pricing, setup cost, and licensing?
The pricing of the solution depends on the user. But there is a yearly licensing cost.
What other advice do I have?
It is a good solution but just has some API issues. I rate the solution an eight out of ten.
A highly-rated entry-level SIEM solution that is ideal for SMBs
What is most valuable?
I like that it's a cloud-based solution. The features of all SIEM solutions are pretty much the same, but Rapid7 is user-friendly, totally cloud-based, and can integrate into the EDR solution whenever a customer wants it. Those are USPs for us.
What needs improvement?
Because Rapid7 was originally a vulnerability management solution, more and more companies are now moving towards their technologies and their existing SIEM applications and converting them to XDR solutions. Though Rapid7 provides its EDR option with SIEM, it has a long way to go to achieve an XDR status.
I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR because every SIEM solution provider is moving their solutions toward XDR.
For how long have I used the solution?
I've been working with Rapid7 InsightIDR for two years.
What do I think about the stability of the solution?
The product is stable.
Which solution did I use previously and why did I switch?
We used to use QRadar in my previous company. The first difference is in the deployment architecture. QRadar comes with cloud and on-prem options. In countries like Pakistan, where I am from, there are very strict regulations for using cloud solutions, especially in the banking sector. Rapid7 only offers a SaaS-based SIEM.
The second difference between the two is in their licensing. Rapid7 InsightIDR license is applied based on the number of nodes and devices. QRadar, on the other hand, does licenses the events per second.
The third difference is in the threat intelligence QRadar provides, and there's a huge difference between the two in this domain. QRadar is an IBM product that is very old in the SIEM market and provides relatively better threat intelligence than players like Rapid7.
How was the initial setup?
The solution is easy to implement.
What's my experience with pricing, setup cost, and licensing?
Rapid7 InsightIDR is priced very well and is cost-effective.
Which other solutions did I evaluate?
Enterprise-level customers have better options, such as LogRhythm, QRadar, and Splunk. These products are core SIEM-based companies that are old players in this market. Rapid7 is a relatively new entrant in the SIEM market. However, it has strong capabilities, and customers trust big names, big companies they've known from the beginning, who have been working on SIEM solutions since inception.
What other advice do I have?
The benefit of the solution, first of all, is that it's cost-effective. It is also a Gartner leading solution, which provides more credibility in the customer's eyes. Eventually, it benefits us to translate that credibility into achieving more and more revenue through it.
I recommend Rapid7 InsightIDR for SMB companies because there are better options in the market for enterprises.
I rate the solution an eight out of ten.
A cloud-based solution that is licensed based on the number of assets instead of the number of EPS
What is most valuable?
Rapid7 InsightIDR is a cloud-based solution. Customers don't have to provision storage either internally or externally, and everything is already factored into the cost of the solution. So that takes out the headache.
The solution is very scalable in terms of the licensing model. It's not licensed based on the number of EPS as in a traditional SIEM solution. It's licensed based on the number of assets, and I believe the customers have more control over their assets than their EPS.
What needs improvement?
The solution's XDR agents cannot compete with the XDR solutions out there yet. It has to be a stand-alone XDR solution, and I know they are working on that. They have to ensure that it has the full capabilities of an XDR solution.
For how long have I used the solution?
I have been working with Rapid7 InsightIDR for about two years.
What do I think about the stability of the solution?
Rapid7 InsightIDR is a stable solution.
How are customer service and support?
Rapid7 InsightIDR's technical support is great and very responsive. Of course, their support depends on the SLAs.
How would you rate customer service and support?
Positive
What about the implementation team?
Rapid7 InsightIDR can be up or running in a matter of hours or minutes. It takes about a week or two to deploy the solution for an enterprise account with full integration of an IT use case.
What's my experience with pricing, setup cost, and licensing?
Rapid7 InsightIDR's pricing is reasonable.
What other advice do I have?
Overall, I rate Rapid7 InsightIDR a nine out of ten.
Helps in the management of compliance, secret events and information
What is our primary use case?
We use the tool for secret events, compliance, and information management.
What is most valuable?
I like the tool's user analysis feature.
What needs improvement?
Rapid7 InsightIDR is not intuitive to search for logs. It should be more user-friendly and improve the dashboards. We should be able to use ready-made templates instead of having to build one.
For how long have I used the solution?
We had done our first deployment three years ago.
What do I think about the stability of the solution?
Rapid7 InsightIDR is stable.
What do I think about the scalability of the solution?
The tool is cloud-based and scalable.
How are customer service and support?
Rapid7 InsightIDR's technical support is reactive and supportive. However, they only speak English. Our native language is French and it would be better if they can have some French speaking agents.
Which solution did I use previously and why did I switch?
The solution provides better value than competitors with its modules. The deployment is simple and straightforward. However, Rapid7 InsightIDR is not good for log management.
How was the initial setup?
One of our customers had a Huawei firewall and we required help to do the configuration. However, the installation was easy with other standard vendors like Cisco and Check Point. The product's deployment got completed in four to five days and we required three people to handle it. One person was in charge of the portal's initial set up and the other one handled the integration of on-premises devices. The third one took care of Office 365 integration.
What's my experience with pricing, setup cost, and licensing?
Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs.
What other advice do I have?
I would rate Rapid7 InsightIDR an eight out of ten.