Soc Analyst at a manufacturing company with 10,001+ employees
Real User
Top 5
Jul 29, 2026
We are utilizing the AI-assisted risk-aware investigation workflows in Rapid7 MDR. They help us improve our alert triage and prioritization by providing context around the alerts, identifying the risk factors, and helping analysts to focus on more critical security events. Instead of treating every alert with the same priority, the workflow considers factors such as asset criticality, behavior, threat intelligence, and attack patterns to determine the potential impact. This has helped in reducing false positive alerts and overall alert fatigue, and in speeding up the investigation of the real threats. Rapid7 MDR AI capabilities are good for improving threat detection and alert prioritization and also in the investigation. From the governance and security perspective, I think they have strong controls around data handling, access management, and transparency, which helps in improving data security. Also, the combination of AI-driven analysis and Rapid7 MDR analysts provides a good balance where AI can help identify attack patterns quickly, while human experts validate findings and make the response decisions. Rapid7 MDR is quite good and I appreciate the responses. I use it on a daily basis. I think it is really reliable as compared to the other platforms which I use, and it helps in reducing the investigation time by providing additional context and highlighting the important points. The inclusion of the forensics and incident response capabilities has improved our investigations by providing deeper analysis and helping us to understand the scope of the threat and the impact of that on the environment. The forensic analysis also helps us identify the root cause, the affected systems, attackers' activities, and required remediation steps. Rapid7 MDR has a few features that I think are very valuable because it goes beyond simple alert generation and focuses on the actual risk and potential impact of that risk in our organization. By considering factors such as important assets and user behavior, threat indicators, and the context of the attack, we can better assess our security posture. I have used the multi-vector telemetry capabilities in Rapid7 MDR. It has helped me in improving investigation accuracy by correlating the data across different endpoints, user activity, and network activity. Having visibility across different telemetry sources provides better context for the alerts and helps us differentiate between legitimate and potential threats. Cybersecurity advisor helps us make decisions by providing expert guidance and helping us focus on the risks and threats that matter the most to our business. They help us understand our security gaps, identify additional improvements, and also align our security strategy with the business requirements. This also ensures that our resources are used effectively and that security supports the organization's overall goals. Currently, we are not using the integrated Rapid7 MDR for Microsoft environments feature. I think our team will be enabling that in the upcoming time. My advice is that Rapid7 MDR is a good fit for organizations that want to use it for 24/7 security monitoring and expert investigation support. It also helps in reducing the workload of the internal SOC teams. With the help of this, SOC teams can mostly focus on the high priority alerts instead of wasting time on the false positives. I think this is a really good tool to have. I would give Rapid7 MDR a rating of eight out of ten because of its 24x7 monitoring capability and valuable analyst expertise that improves our security operations.
Rapid7 MDR provides valuable visibility into security events, vulnerabilities, and risks, which relates to governance and security. The reporting and logging capabilities support all our readiness, help demonstrate security controls, and efficiently manage processes in our organization. The combination of AI-driven insights and expert analyst validation provides a well-balanced approach where automation improves speed while human expertise ensures accuracy. I particularly appreciate the Rapid7 analyst detections and investigations, which reduce alert fatigue, improve threat visibility, and speed up our security operations. Rapid7 MDR is a primary detection response service that makes it safer to say that our organization is well-protected. For compliance support, Rapid7 MDR provides good visibility into vulnerabilities, threats, and security. When suspicious login activity is detected by Rapid7 MDR, the MDR team provides detailed information, including the affected user account, source IP address, and timeline of events, which helps us validate the event. The transparency is very good for Rapid7 MDR. Rapid7 MDR follows a structured risk detection process that combines automated analysis and threat intelligence. It collects data, logs, and telemetry from endpoints, servers, and cloud environments, then enriches the data against multiple data sources and analyst validation. The multi-vector feature is one of the best features, as it analyzes and correlates data across multiple attack vectors such as endpoints, identity, cloud environments, network, email systems, and other security tools. For example, an attacker may compromise a user account through phishing email, log in from an unusual location, and then try to access sensitive cloud resources. Individually, these events might appear harmless, but Rapid7 MDR correlates and analyzes data from email, identity, and cloud environments to recognize this attack chain and generate a high-fidelity alert. The benefits of multi-vector detection include better visibility across the attack, detection of complex attack chains, reduction of blind spots, improved threat detection accuracy, faster incident investigation, and providing better context for analysts. The ecosystem is supported through endpoint telemetry, processing, and file activity, which has a significant positive impact on our security program. Rapid7 MDR is integrated with Microsoft and our other security tools. We are using AI-assisted risk workflows, including data ingestion, AI-based analysis, risk scoring and prioritization, analyst validation, investigation, and containment. The ecosystem supports endpoint telemetry, processing, file activity, and user behavior. My overall review rating for Rapid7 MDR is 7 out of 10.
Senior Technical Service Engineer Expert at a tech vendor with 10,001+ employees
MSP
Top 5
May 29, 2026
We are primarily on Microsoft with a platinum contract, so all products we evaluate are in line with Microsoft's technology stack. Rapid7 MDR and Zscaler are both well-equipped and support Microsoft technology. Since Microsoft has its own products like Defender and others, we still use them for our daily work. I would rate my overall experience with customer service as a 3 out of 10.
I did not use the Risk-Aware Detection feature at all, so unfortunately I cannot answer questions about that. Regarding Intune, I have been using it for six years and Defender for two and a half years. Those are the two products I use the most. I also use some admin center, Exchange admin center, and other tools. I am not sure about certain features because I did not use them all. However, as I have been in a support role, I think I should rate that at eight out of ten. From my perspective, Rapid7 MDR is a really good product that is easy to implement and use. I achieved everything I needed, prepared the whole report, and it took me a few days. That is pretty fast and awesome. My overall review rating for this product is seven out of ten.
I am taking advantage of the expanded ecosystem telemetry support in Rapid7 MDR. We have enhanced the logging mechanism within Rapid7 MDR, allowing us to assign projects to different teams with visibility only of their specific assets. This approach supports various vulnerability assessments and compliance achievements. My management is overall pleased as we have managed to meet compliance standards such as ISO 27001 and NIST due to features provided by Rapid7 MDR. I utilize AI-assisted Risk-Aware Investigation workflows, integrating both our on-prem and cloud infrastructure. By using APIs in our environment, we gain enhanced visibility, giving us detailed insights that greatly assist in real-time monitoring. This approach impacts my alert triage and prioritization processes since Active Directory is a crucial element in our industry. Rapid7 MDR improves the alerting mechanism for Active Directories and all connected user activities. Previously used SIEM solutions did not adequately capture anomalies on ADs. With Rapid7 MDR, any anomaly triggers escalated alerts in real time. I am using the Integrated MDR for Microsoft Environments feature, having integrated Microsoft 365 with our MDR and endpoints from Microsoft Active Directory and Azure. This integration provides us with comprehensive visibility into our infrastructure. Regarding transparency in detection and investigations with Rapid7 MDR, we receive metrics such as MTTR and MTTD (Mean Time to Detect and Mean Time to Respond). We monitor how quickly the tool detects anomalies and how long it takes to respond, which shows improvement due to the specific MDR product. My overall review rating for Rapid7 MDR is 8.5 out of 10.
I have knowledge of CrowdStrike solutions as a competitor, though not direct experience. I would recommend Rapid7 MDR to others, but this market is changing quickly due to artificial intelligence. I cannot say it is the best solution for customers as the market is evolving, with new solutions emerging and existing vendors improving their offerings in the near future. Overall, I would rate Rapid7 MDR a seven out of ten. Once customers can implement it, it becomes a good solution for them, though implementation remains a significant consideration.
Head, Networks And Security at First City Monument Bank Limited
Real User
Dec 20, 2023
Rapid7 works well for us and meets our current needs. It's a solid eight out of ten. However, it depends on your organization's cybersecurity roadmap. For example, if your long-term plan is to have an on-premise security team, then Rapid7 might not be the best fit. We don't have on-premise capabilities and rely solely on the cloud, so it works for us. But other organizations might need that on-premise option. So, it really depends on their cybersecurity roadmap.
Rapid7 MDR is a leading service offering transparency, integration, incident response, and proactive security. It is designed for efficient SIEM and EDR integration to facilitate threat detection, making it effective for organizations of all sizes.Renowned for robust threat detection, Rapid7 MDR combines transparency, automation, and integration. It provides excellent incident response, vulnerability management, AI-driven log queries, and significant time savings. Despite competitive...
We are utilizing the AI-assisted risk-aware investigation workflows in Rapid7 MDR. They help us improve our alert triage and prioritization by providing context around the alerts, identifying the risk factors, and helping analysts to focus on more critical security events. Instead of treating every alert with the same priority, the workflow considers factors such as asset criticality, behavior, threat intelligence, and attack patterns to determine the potential impact. This has helped in reducing false positive alerts and overall alert fatigue, and in speeding up the investigation of the real threats. Rapid7 MDR AI capabilities are good for improving threat detection and alert prioritization and also in the investigation. From the governance and security perspective, I think they have strong controls around data handling, access management, and transparency, which helps in improving data security. Also, the combination of AI-driven analysis and Rapid7 MDR analysts provides a good balance where AI can help identify attack patterns quickly, while human experts validate findings and make the response decisions. Rapid7 MDR is quite good and I appreciate the responses. I use it on a daily basis. I think it is really reliable as compared to the other platforms which I use, and it helps in reducing the investigation time by providing additional context and highlighting the important points. The inclusion of the forensics and incident response capabilities has improved our investigations by providing deeper analysis and helping us to understand the scope of the threat and the impact of that on the environment. The forensic analysis also helps us identify the root cause, the affected systems, attackers' activities, and required remediation steps. Rapid7 MDR has a few features that I think are very valuable because it goes beyond simple alert generation and focuses on the actual risk and potential impact of that risk in our organization. By considering factors such as important assets and user behavior, threat indicators, and the context of the attack, we can better assess our security posture. I have used the multi-vector telemetry capabilities in Rapid7 MDR. It has helped me in improving investigation accuracy by correlating the data across different endpoints, user activity, and network activity. Having visibility across different telemetry sources provides better context for the alerts and helps us differentiate between legitimate and potential threats. Cybersecurity advisor helps us make decisions by providing expert guidance and helping us focus on the risks and threats that matter the most to our business. They help us understand our security gaps, identify additional improvements, and also align our security strategy with the business requirements. This also ensures that our resources are used effectively and that security supports the organization's overall goals. Currently, we are not using the integrated Rapid7 MDR for Microsoft environments feature. I think our team will be enabling that in the upcoming time. My advice is that Rapid7 MDR is a good fit for organizations that want to use it for 24/7 security monitoring and expert investigation support. It also helps in reducing the workload of the internal SOC teams. With the help of this, SOC teams can mostly focus on the high priority alerts instead of wasting time on the false positives. I think this is a really good tool to have. I would give Rapid7 MDR a rating of eight out of ten because of its 24x7 monitoring capability and valuable analyst expertise that improves our security operations.
Rapid7 MDR provides valuable visibility into security events, vulnerabilities, and risks, which relates to governance and security. The reporting and logging capabilities support all our readiness, help demonstrate security controls, and efficiently manage processes in our organization. The combination of AI-driven insights and expert analyst validation provides a well-balanced approach where automation improves speed while human expertise ensures accuracy. I particularly appreciate the Rapid7 analyst detections and investigations, which reduce alert fatigue, improve threat visibility, and speed up our security operations. Rapid7 MDR is a primary detection response service that makes it safer to say that our organization is well-protected. For compliance support, Rapid7 MDR provides good visibility into vulnerabilities, threats, and security. When suspicious login activity is detected by Rapid7 MDR, the MDR team provides detailed information, including the affected user account, source IP address, and timeline of events, which helps us validate the event. The transparency is very good for Rapid7 MDR. Rapid7 MDR follows a structured risk detection process that combines automated analysis and threat intelligence. It collects data, logs, and telemetry from endpoints, servers, and cloud environments, then enriches the data against multiple data sources and analyst validation. The multi-vector feature is one of the best features, as it analyzes and correlates data across multiple attack vectors such as endpoints, identity, cloud environments, network, email systems, and other security tools. For example, an attacker may compromise a user account through phishing email, log in from an unusual location, and then try to access sensitive cloud resources. Individually, these events might appear harmless, but Rapid7 MDR correlates and analyzes data from email, identity, and cloud environments to recognize this attack chain and generate a high-fidelity alert. The benefits of multi-vector detection include better visibility across the attack, detection of complex attack chains, reduction of blind spots, improved threat detection accuracy, faster incident investigation, and providing better context for analysts. The ecosystem is supported through endpoint telemetry, processing, and file activity, which has a significant positive impact on our security program. Rapid7 MDR is integrated with Microsoft and our other security tools. We are using AI-assisted risk workflows, including data ingestion, AI-based analysis, risk scoring and prioritization, analyst validation, investigation, and containment. The ecosystem supports endpoint telemetry, processing, file activity, and user behavior. My overall review rating for Rapid7 MDR is 7 out of 10.
We are primarily on Microsoft with a platinum contract, so all products we evaluate are in line with Microsoft's technology stack. Rapid7 MDR and Zscaler are both well-equipped and support Microsoft technology. Since Microsoft has its own products like Defender and others, we still use them for our daily work. I would rate my overall experience with customer service as a 3 out of 10.
I did not use the Risk-Aware Detection feature at all, so unfortunately I cannot answer questions about that. Regarding Intune, I have been using it for six years and Defender for two and a half years. Those are the two products I use the most. I also use some admin center, Exchange admin center, and other tools. I am not sure about certain features because I did not use them all. However, as I have been in a support role, I think I should rate that at eight out of ten. From my perspective, Rapid7 MDR is a really good product that is easy to implement and use. I achieved everything I needed, prepared the whole report, and it took me a few days. That is pretty fast and awesome. My overall review rating for this product is seven out of ten.
I am taking advantage of the expanded ecosystem telemetry support in Rapid7 MDR. We have enhanced the logging mechanism within Rapid7 MDR, allowing us to assign projects to different teams with visibility only of their specific assets. This approach supports various vulnerability assessments and compliance achievements. My management is overall pleased as we have managed to meet compliance standards such as ISO 27001 and NIST due to features provided by Rapid7 MDR. I utilize AI-assisted Risk-Aware Investigation workflows, integrating both our on-prem and cloud infrastructure. By using APIs in our environment, we gain enhanced visibility, giving us detailed insights that greatly assist in real-time monitoring. This approach impacts my alert triage and prioritization processes since Active Directory is a crucial element in our industry. Rapid7 MDR improves the alerting mechanism for Active Directories and all connected user activities. Previously used SIEM solutions did not adequately capture anomalies on ADs. With Rapid7 MDR, any anomaly triggers escalated alerts in real time. I am using the Integrated MDR for Microsoft Environments feature, having integrated Microsoft 365 with our MDR and endpoints from Microsoft Active Directory and Azure. This integration provides us with comprehensive visibility into our infrastructure. Regarding transparency in detection and investigations with Rapid7 MDR, we receive metrics such as MTTR and MTTD (Mean Time to Detect and Mean Time to Respond). We monitor how quickly the tool detects anomalies and how long it takes to respond, which shows improvement due to the specific MDR product. My overall review rating for Rapid7 MDR is 8.5 out of 10.
I have knowledge of CrowdStrike solutions as a competitor, though not direct experience. I would recommend Rapid7 MDR to others, but this market is changing quickly due to artificial intelligence. I cannot say it is the best solution for customers as the market is evolving, with new solutions emerging and existing vendors improving their offerings in the near future. Overall, I would rate Rapid7 MDR a seven out of ten. Once customers can implement it, it becomes a good solution for them, though implementation remains a significant consideration.
Rapid7 MDR leverage AI highly to enhance threat detection and response capabilities. Overall, I rate the solution an eight out of ten.
Rapid7 works well for us and meets our current needs. It's a solid eight out of ten. However, it depends on your organization's cybersecurity roadmap. For example, if your long-term plan is to have an on-premise security team, then Rapid7 might not be the best fit. We don't have on-premise capabilities and rely solely on the cloud, so it works for us. But other organizations might need that on-premise option. So, it really depends on their cybersecurity roadmap.
I trust the tool with my network. Overall, I rate the product a nine out of ten.