What is our primary use case?
Rapid7 InsightIDR serves as our SIEM solution where all kinds of activity, including network logs, endpoint logs, user activity, user behavior analytics, and threat hunting, are tracked. Additionally, we use it to store logs and provide them for SOC analysts, and we utilize it completely as a SIEM tool. We also have used some of their other solutions, including Rapid7 Insight Vulnerability Management and Rapid7 Threat Command.
In our day-to-day operations, Rapid7 InsightIDR is useful for tracking everything happening at the cloud level, at Entra ID, or on-premises. All logs, including network logs and traffic between domains or inside the domain or between on-premises servers and endpoints, are collected in one place. Using various analytical rules, we get alerts, and we configure the alerts required for our organizational needs. There are many more use cases for this solution.
When it comes to threat hunting, we analyze dark web activity and track various activities related to users. We provide all user data to the agent, which searches the dark web for alerts based on our multiple domains. We actively monitor for any leaks detected with users or any spoofed domains and set up Rapid7 InsightIDR alerts to track these activities closely.
What is most valuable?
The best features that Rapid7 InsightIDR offers include its log display, which is easy to understand for any SOC analyst. In hunting, if there is any red team activity or a true positive incident and an analyst wants to hunt or review logs, Rapid7 has simple logic and features such as legacy log search and normal log search using KQL, Kusto Query Language, which allows for fetching and analyzing logs in detail. The way everything is arranged and easy to understand, along with insights into network sensors or devices configured with Rapid7, helps us understand where logs are being ingested and where traffic is moving.
Out of all the features, log search is what I find myself using the most. Compared to Microsoft Sentinel, Rapid7 InsightIDR's SIEM tool makes log search very easy. The log display is simple, and the investigation part is very intuitive using Rapid7. Logs are segregated into different categories, such as ingress logs, web traffic logs, Active Directory logs, and cloud security logs, making it seamless to present everything on their dashboard, which has been immensely helpful for my investigative work.
Rapid7 InsightIDR has positively impacted my organization by capturing most logs and every minute detail, including endpoint logs, network logs, and any email-related logs if a malicious link has been clicked. All logs are integrated and ingested into Rapid7 InsightIDR, which is useful for hunting or checking for any true positive incidents that trigger. A notable feature is that if an investigation opens on a single entity and any alerts are observed around that time, they are tagged under a single incident with all activity logged under one template or interface. This allows an analyst to make quick and easy decisions and analyze all investigation artifacts. Recently, when one of our users clicked a malicious URL that Microsoft Defender could not track immediately, Rapid7 notified us that a malicious email was found, helping us take action before Microsoft could respond.
Rapid7 InsightIDR provides very crisp, detailed, and on-point alerts whenever there is suspicious activity, which has led to very few false positives for the clients using Rapid7 InsightIDR. It has saved us a lot of time by reducing noisy alerts, and the dashboard is effortlessly managed and neatly organized, allowing us to create allow lists or block lists for any kind of activity.
What needs improvement?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations.
These two areas are the main areas for improvement; everything else is good.
For how long have I used the solution?
I have been working in my current field for around three years.
What do I think about the stability of the solution?
Rapid7 InsightIDR is stable with minimal downtimes or glitches; platform unavailability is very rare, and we have not experienced missed logs. Compared to Microsoft Sentinel, Rapid7 InsightIDR maintains high availability of logs and a reliable dashboard.
What do I think about the scalability of the solution?
Rapid7 InsightIDR's scalability fits very well for organizations of any size, making it a very easy-to-use, handy, and simple tool.
How are customer service and support?
The customer support at Rapid7 is really good. Over my 2.5 years of experience, I have submitted many support cases related to InsightIDR alerts, analytical rules, and even Insight Vulnerability Management, and they have been consistently supportive. I would rate the customer support a perfect 10 out of 10.
Which solution did I use previously and why did I switch?
For this client, we have exclusively used Rapid7 InsightIDR since the beginning as there were no other solutions in place. However, I can say that we used Microsoft Sentinel for other clients, and in comparison, Rapid7 InsightIDR has proven to be a more efficient and time-saving tool.
How was the initial setup?
The learning curve for new users of Rapid7 InsightIDR is very easy. Throughout my 2.5 years of experience, I have successfully onboarded three batches of users, totaling more than 10 users, and they adapted easily to this tool. The only challenging part was the log search, but once users got into it, it became very easy to use. Compared to the KQL of Microsoft Sentinel, Rapid7 InsightIDR has been much easier for users to learn.
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was straightforward thanks to the assistance from their team.
What about the implementation team?
We did not purchase Rapid7 InsightIDR through the AWS marketplace; we reached out to an agent through which we made the purchase.
What was our ROI?
I have seen a return on investment; all employees, particularly the SOC analysts, are satisfied as they easily got trained and adapted to this tool. The logs are delivered in a crisp and direct manner, simplifying analysis of the alerts significantly.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was straightforward thanks to the assistance from their team.
What other advice do I have?
I have completed my insights about my main use case and how we use Rapid7 InsightIDR day-to-day. All the improvements and features I have discussed are sufficient.
I am very satisfied with the speed and performance of Rapid7 InsightIDR when handling large volumes of data, giving it a rating of 9.5 out of 10. It can handle any volume of data for any organization, making it very cost-effective, which distinguishes it as a standout SIEM tool in the market. It is straightforward, time-efficient, and easy to use.
My advice for others considering using Rapid7 InsightIDR is to go for it if you are looking for a value-for-money and straightforward tool that suits any kind of analyst.
Rapid7 InsightIDR is deployed in my organization through AWS public cloud. The deployment model we use most is public cloud through AWS. We use Amazon Web Services, AWS, as our cloud provider.
Rapid7 InsightIDR integrates with other security tools or platforms in our environment, including CrowdStrike, Netskope, and email security through Defender.
I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part.
Rapid7 InsightIDR's AI capabilities are very helpful; the simulations or the SIEM injections they provide are useful for gaining alerts or insights about the organization, and it is very secure with no downtimes that affect client security. We have weekly meetings with support to discuss licenses or any new features added, which is really helpful in getting along with the tool.
Most of the AI capabilities are still in progress, with various features being introduced. In Rapid7 InsightIDR, it is not heavily related to AI capabilities because the focus is primarily on the SIEM aspects, including logs from your environment and the size of your setup. My overall review rating for Rapid7 InsightIDR is 8 out of 10.
Which deployment model are you using for this solution?
public cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
AWS