What is our primary use case?
I can describe many use cases for Rapid7 MDR, as there are multiple times when a person's PC gets compromised. There is an attacker behavior analysis, ABA, which is already part of the specific Rapid7 MDR XDR solution. We define a specific set of built-in rules in the MDR services and remap those rules according to our infrastructure for specific use cases.
We also deal with multiple phishing emails that we receive, and Rapid7 MDR is effective in identifying those specific use cases. In the Fintech sector, we encounter many anomalies from different servers that are publicly exposed on the internet, and Rapid7 MDR provides very beneficial use cases that eliminate the need to write custom use cases. We can define the logic in predefined use cases such as Attacker Behavior Analysis and User Behavior Analytics.
Additionally, when onboarding any log sources, there is a RegEx parser designed for parsing every log source on the built-in platform, making it quite user-friendly.
What is most valuable?
The best features in Rapid7 MDR are their team, which is made up of professionals. I interact with them whenever we face issues, even though we are running our own SOC, but we sometimes rely on Rapid7. It is having a human eye on everything. The MDR AI platform they recently transformed into is very helpful for defining use cases, real-time detections from a dashboard, and the reporting mechanism they have created within Rapid7 MDR.
Even the orchestrator platform they introduced for playbook creation is very helpful, as I create playbooks on Rapid7 using their predefined orchestrator platform.
Having a dedicated cybersecurity advisor through Rapid7 MDR significantly impacts aligning our security program with business needs because it approaches MDR better for big organizations such as mine. My first organization, Afiniti, was a significant AI-based company where I introduced Rapid7 MDR. The MDR is beneficial for both small and large organizations, unlike Splunk, which has more conditional formatting in their product.
Rapid7 MDR has positively impacted my organization by providing us with very effective management tools. Once we introduced Rapid7 MDR along with their vulnerability assessment tool, IVM, we transitioned from using Qualys and Tenable, which are top-tier tools in the market. The management tool from Rapid7 allows us to access a variety of vulnerabilities in real time to fix them effectively. How we tackle that specific MDR is indicative of its market quality. We analyzed the tool during our POC before purchasing.
We deployed endpoints on a specific server and attacked that machine using different methods, such as Metasploit, conducting DDoS attempts, and generating alerts for every anomaly from Rapid7. While a competitor's solution failed to detect many attacks, Rapid7 identified them in real time, which effectively pushed my management towards choosing Rapid7 MDR.
What needs improvement?
My experience with detection and response capabilities for Microsoft-centric environments has been positive. While API integration can be challenging with some third-party tools, Microsoft's built-in features facilitate seamless communication. I have found it relatively easy to triage and integrate Microsoft systems with Rapid7 MDR.
In terms of digital forensics and incident response included in the MDR service, my experience is that it is not very robust. We lack a dedicated forensic team, which is essential for thorough investigation. Rapid7 has introduced honeypots, which is an encouraging feature, but it is not a comprehensive solution such as those offered by competitors, such as Palo Alto's Unit 42.
Apart from forensics, I believe Rapid7 MDR should introduce more forensic services. Another area to improve is the active platform's handling of on-premises tools versus cloud-based tools. We prefer on-premises options for data security, and we find limitations in features compared to cloud-based tools, concerning data access and privacy controls.
For how long have I used the solution?
I have been working with Rapid7 MDR for the last five to six years.
What do I think about the stability of the solution?
Regarding stability and scalability, I have had no significant issues. Stability is good, and I have not experienced delays, even with on-premises deployments. I did encounter minor latency during a scheduled upgrade but was informed that it would occur.
How are customer service and support?
Evaluating the customer service and technical support teams of Rapid7 MDR, I would rate them a six out of ten. I have previous experience with IBM support, which was excellent and proactive. In contrast, Rapid7 MDR support often takes longer to respond to issues. Despite their large customer base, this highlights a need for enhancement in their support team.
Which solution did I use previously and why did I switch?
I decided to switch from those products because, while Qualys is a good vulnerability scanner, it is not very user-friendly. When scanning two machines, one with Rapid7 having an agent deployed for a level three scan and another with Qualys, the results were different. Rapid7 MDR indicated more vulnerabilities that were accurate upon verification, whereas Qualys missed many of them. This highlighted that IVM, Rapid7 MDR, and MDR stand out as top products in the market, especially for our financial sector.
How was the initial setup?
The deployment setup process for Rapid7 MDR is straightforward. I have deployed both the cloud environment and on-premises Nexpose service. Their services, whether on-premises or cloud-based, are easy to deploy, and the endpoints are lightweight and compatible with other tools in our environment.
What about the implementation team?
I bought Rapid7 MDR directly from the vendor, which is uncommon for sectors such as Fintech that usually work through intermediaries. I have had direct interactions with the Rapid7 team, specifically with someone named Nikola, and I find that beneficial.
What was our ROI?
I have seen a positive return on investment concerning Rapid7 MDR, as we have invested wisely, yielding results in detection mechanisms. I can confidently say that investing in Rapid7 MDR has been worthwhile, despite acknowledging that every tool has its flaws. Overall, the category is very good.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, I manage everything with Rapid7 MDR, and I find their pricing very reasonable compared to the market. They negotiate well with us on various aspects of MDR, and we have received great rates for services such as IVM, including Threat Command.
What other advice do I have?
I am taking advantage of the expanded ecosystem telemetry support in Rapid7 MDR. We have enhanced the logging mechanism within Rapid7 MDR, allowing us to assign projects to different teams with visibility only of their specific assets. This approach supports various vulnerability assessments and compliance achievements. My management is overall pleased as we have managed to meet compliance standards such as ISO 27001 and NIST due to features provided by Rapid7 MDR.
I utilize AI-assisted Risk-Aware Investigation workflows, integrating both our on-prem and cloud infrastructure. By using APIs in our environment, we gain enhanced visibility, giving us detailed insights that greatly assist in real-time monitoring.
This approach impacts my alert triage and prioritization processes since Active Directory is a crucial element in our industry. Rapid7 MDR improves the alerting mechanism for Active Directories and all connected user activities. Previously used SIEM solutions did not adequately capture anomalies on ADs. With Rapid7 MDR, any anomaly triggers escalated alerts in real time.
I am using the Integrated MDR for Microsoft Environments feature, having integrated Microsoft 365 with our MDR and endpoints from Microsoft Active Directory and Azure. This integration provides us with comprehensive visibility into our infrastructure.
Regarding transparency in detection and investigations with Rapid7 MDR, we receive metrics such as MTTR and MTTD (Mean Time to Detect and Mean Time to Respond). We monitor how quickly the tool detects anomalies and how long it takes to respond, which shows improvement due to the specific MDR product. My overall review rating for Rapid7 MDR is 8.5 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure