No more typing reviews! Try our Samantha, our new voice AI agent.
it_user836481 - PeerSpot reviewer
Information Security Officer at a tech vendor with 201-500 employees
Real User
Mar 13, 2018
Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns
Pros and Cons
  • "Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
  • "Great coverage of all systems within our network from endpoint to firewall."
  • "Integration with threat modeling from the Metasploit and InsightIDR repositories."
  • "Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
  • "One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
  • "One thing that springs to mind is easier API integration with ITSMs."

What is our primary use case?

It is used to maintain our security posture by monitoring inside our network for behavior likely to be conducive with elements of the kill chain.

I was an early adopter of the product. I have seen it get better over time, making use of the data and methodologies used by the industry standard and Rapid7 Metasploit community.

How has it helped my organization?

We were able to identify criminals attempting to login from China and put a stop on their IP locations.

What is most valuable?

  • Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs.
  • Great coverage of all systems within our network from endpoint to firewall.
  • Integration with threat modeling from the Metasploit and InsightIDR repositories.
  • Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns.

It gives all the advantages of a SIEM. However, using clever AI, it looks for patterns of behavior rather than just flooding me with all the alerts.

What needs improvement?

Although the solution has been improving continually in the time I have been using it, there could be areas of improvement. 

The one thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not.

Buyer's Guide
Rapid7 InsightIDR
July 2026
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,099 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

None at all. Even as an early adopter, there were no significant issues with stability. Due to the continual improvement, I do not recall the last issue that I had with the system.

What do I think about the scalability of the solution?

We are only a small PLC with 300 staff over six sites and two continents, so scalability has never been a major concern. However, the InsightIDR system looks to be scalable, if required.

How are customer service and support?

Technical support is excellent both technically, timely, and professional throughout any incident or enhancement request.

Which solution did I use previously and why did I switch?

This was our first look at a security as a single entity. After creating a threat register, we were able to mitigate over two-thirds of the threats with this one product.

How was the initial setup?

It is very simple. It is a case of requesting a trial from Rapid7, then connecting the relevant logging devices, such as our AD servers or DNS servers to it and sitting back. 

Obviously, there is more to it than that, but that is the principle.

What's my experience with pricing, setup cost, and licensing?

I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.

Which other solutions did I evaluate?

At the time, there was no other product that came close to InsightIDR feature set coupled with Rapid7's world leading security position producing other products, such as Metasploit and Nexpose (InsiteVR), which we also use.

What other advice do I have?

Use it. The setup is minimal, but the payback is phenomenal.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2185626 - PeerSpot reviewer
Security Consultant at a comms service provider with 51-200 employees
Reseller
May 18, 2023
Great user behavior analytics feature; easy to integrate and collect data from other solutions
Pros and Cons
  • "Features for user behavior analytics and the rules for attack review are good."
  • "Needs a better ability to customize the check within the console."

What is our primary use case?

We are distributors and sell this product to our customers. I'm a security consultant. 

What is most valuable?

The features for user behavior analytics and the rules for attack review are valuable. I also like the honeypot feature. It's easy to integrate and collect data from other solutions. 

What needs improvement?

I'd like to see a better ability to customize the check within the console. Rules can be customized better if the integration is improved. They now have integration with CrowdStrike so maybe they could have some kind of integration with Microsoft.

For how long have I used the solution?

I've been using this solution for a year. 

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

This is a cloud-based product so it's scalable.

How are customer service and support?

The technical support could be improved. We've had times when our requests get stuck with the engineering team and we sometimes don't get a response. That's a problem for us. 

How would you rate customer service and support?

Neutral

How was the initial setup?

All Rapid7 solutions are easy to deploy because if you have any one of the products, the integrations between these products become easier because they have a lot of the important things within a single port. You get a single platform to visualize a lot of different kinds of data.

What's my experience with pricing, setup cost, and licensing?

The pricing is very competitive because the licensing model that we use is based on endpoints which is different from most other solutions.

What other advice do I have?

This solution is suited to all sizes of organizations. We generally deal with small and medium-sized companies.  

I rate this solution eight out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Rapid7 InsightIDR
July 2026
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,099 professionals have used our research since 2012.
reviewer2275617 - PeerSpot reviewer
Network Support Engineer at a tech services company with 51-200 employees
Real User
Sep 27, 2023
Lets you simplify threat detection and has a fast deployment
Pros and Cons
  • "Rapid7 is easy to use and deploy. It is a simple solution and has easy data pulling."
  • "The APIs can be further improved in Rapid7."

What is our primary use case?

The solution is used as a platform for a better understanding of the Intelligence products that different vendors sell. 

What is most valuable?

Rapid7 is easy to use and deploy. It is a simple solution and has easy data pulling. 

What needs improvement?

The APIs can be further improved in Rapid7. 

For how long have I used the solution?

I have been using Rapid7 InsightIDR for two months. 

What do I think about the stability of the solution?

It is stable solution. 

What do I think about the scalability of the solution?

It is a scalable solution. Presently, there are only small businesses working with the solution. 

How are customer service and support?

The technical support team is good. 

How was the initial setup?

The initial setup is easy. The deployment took only half an hour. It's just a cloud platform. You just have to deploy a connector like Select Pro, and it will set the data from the on-premise. It will send it to the cloud platform, and you can have it installed in five to ten minutes.

What's my experience with pricing, setup cost, and licensing?

The pricing of the solution depends on the user. But there is a yearly licensing cost. 

What other advice do I have?

It is a good solution but just has some API issues. I rate the solution an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
PeerSpot user
Buyer's Guide
Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Buyer's Guide
Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.