No more typing reviews! Try our Samantha, our new voice AI agent.

Fortinet FortiSandbox vs Rapid7 InsightIDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiSandbox
Ranking in Threat Deception Platforms
3rd
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
39
Ranking in other categories
Advanced Threat Protection (ATP) (10th)
Rapid7 InsightIDR
Ranking in Threat Deception Platforms
4th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (24th), User Entity Behavior Analytics (UEBA) (11th), Endpoint Detection and Response (EDR) (34th), Extended Detection and Response (XDR) (19th)
 

Mindshare comparison

As of August 2026, in the Threat Deception Platforms category, the mindshare of Fortinet FortiSandbox is 6.6%, up from 3.9% compared to the previous year. The mindshare of Rapid7 InsightIDR is 7.5%, down from 13.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Threat Deception Platforms Mindshare Distribution
ProductMindshare (%)
Fortinet FortiSandbox6.6%
Rapid7 InsightIDR7.5%
Other85.9%
Threat Deception Platforms
 

Featured Reviews

AN
Security Manager at a computer software company with 11-50 employees
Advanced sandboxing has protected users from zero-day threats and has simplified secure file scanning
The smooth integrations between Fortinet FortiSandbox and other Fortinet solutions such as FortiWeb and FortiFirewall and with other Fortinet environments are what I really appreciate. We have minimum false positives during threat detection. Our clients have not given negative feedback from detection. As you know, it still needs some tuning after implementation. However, we never receive negative feedback for many false positives during implementation.
Prajwal Chougale - PeerSpot reviewer
SPC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the valuable features is its ability to detect new threats."
"The solution is very good because it catches a lot of threats in emails."
"The dynamic behavior analysis is excellent. We have many attacks caught by the FortiSandbox as zero-day attacks. Additionally, the administration is simple and can be customized to fit your companies needs."
"The GUI makes administration tasks straightforward."
"The adapter is beneficial as it allows integration with various devices, not just Fortinet."
"We have seen a measurable decrease in the mean time to detect or respond to threats, on the order of 20 percent."
"If there is malicious traffic that is going through the web application, we can halt that action, instead of waiting for the AntiVirus to take action."
"I'm very satisfied with this product."
"I definitely recommend Rapid7 InsightIDR."
"Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network."
"The log aggregation and storage provided by InsightIDR has shown no issues with scalability; aggregating over one hundred millions events daily."
"Previously, when something happened, such as when a hacker was attacking one of our customers, we were always behind, or we did not know that we were hacked until the ransomware started, but with the Rapid7 solution, at every step, we could online see what a person was doing, and we could prevent ransomware."
"This is a great product and the team is very willing to work with companies."
"The technical support is a solid 10 out of 10 as they take the time to answer any questions or problems which may arise in a reasonable time frame."
"Integration with threat modeling from the Metasploit and InsightIDR repositories."
"Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
 

Cons

"When you reach the maximum capacity, you cannot upgrade the solution because its hardware is very expensive."
"For additional features, maybe a form of execution pain files in a non-virtual environment because it has threats that identify when it is being run in a virtual machine."
"I would like to have machine learning added to the solution in a future release."
"The integration is limited. The solution needs to offer better integration with multiple vendors."
"If they plan to provide a feature that would make it easier for the customer to configure themselves, that would be appropriate."
"If you were to compare prices between vendors and manufacturers, you would see that the lowest equipment in the Sandbox line is quite expensive for a new customer."
"It would be better if it had support for Mac and Linux."
"The use cases in Fortinet FortiSandbox are not good. It is difficult to upload a custom VM for Fortinet FortiSandbox."
"It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.​"
"The searching feature in Rapid7 InsightIDR needs to evolve"
"The product allows us to make only 30 custom rules."
"If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is."
"The APIs can be further improved in Rapid7."
"There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on."
"Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
"Rapid7's customer support is awful. They didn't respond at all."
 

Pricing and Cost Advice

"I rate the product's pricing a five or six on a scale of one to ten, where one is low, and ten is high."
"The solution is not expensive at all."
"Fortinet FortiSandbox is a nominally priced product, so I would not say that it is a very cheap tool."
"There are additional costs, which isn't included in the licensing fee."
"There are no costs in addition to the standard licensing fees."
"We are on an annual license to use the solution. We have an additional feature that is integrated with S5, which is working well."
"The price of Fortinet FortiSandbox is expensive."
"The price of Fortinet FortiSandbox is not expensive."
"The pricing is good, and it is not very expensive."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"The pricing and licensing are competitive."
"It is a reasonably priced solution."
report
Use our free recommendation engine to learn which Threat Deception Platforms solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
12%
Financial Services Firm
12%
Comms Service Provider
9%
Construction Company
8%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise13
Large Enterprise9
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Fortinet FortiSandbox?
The cost is in the mid-range. It is not low and it is not high.
What needs improvement with Fortinet FortiSandbox?
I think Fortinet FortiSandbox could introduce more automation tools and AI tools.
What is your primary use case for Fortinet FortiSandbox?
Clients primarily ask us to integrate Fortinet FortiSandbox either with FortiMail or with firewalls to scan downloadable files and ensure that client access browsing is secure with no harmful files...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
 

Also Known As

FortiSandbox
InsightIDR
 

Overview

 

Sample Customers

Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Fortinet FortiSandbox vs. Rapid7 InsightIDR and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.