Try our new research platform with insights from 80,000+ expert users

Digital Shadows vs Rapid7 InsightVM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Digital Shadows
Average Rating
6.6
Reviews Sentiment
5.5
Number of Reviews
2
Ranking in other categories
Digital Risk Protection (6th)
Rapid7 InsightVM
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Risk-Based Vulnerability Management (4th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Digital Shadows is designed for Digital Risk Protection and holds a mindshare of 4.4%, down 8.1% compared to last year.
Rapid7 InsightVM, on the other hand, focuses on Risk-Based Vulnerability Management, holds 11.0% mindshare, down 13.2% since last year.
Digital Risk Protection Market Share Distribution
ProductMarket Share (%)
Digital Shadows4.4%
Recorded Future13.6%
ZeroFOX13.5%
Other68.5%
Digital Risk Protection
Risk-Based Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Rapid7 InsightVM11.0%
Qualys VMDR12.7%
Tenable Security Center9.0%
Other67.3%
Risk-Based Vulnerability Management
 

Featured Reviews

DavidJones7 - PeerSpot reviewer
Head of Content at Pharmaflow
Has required additional context for alerts but supports monitoring impersonation and threat activity effectively
I do not rate Digital Shadows a nine or ten because there are many things that need improvement. The information we get is kind of generic. For instance, for impersonation, we don't have much detail on their history, when it was used or how it was misused. Those further details would be really helpful, but the information we receive is basic, such as when it was last registered and when it was updated, without more insight about the malicious factors. For basic support from Digital Shadows, my impression is that it is six to seven because many times we see duplications or bugs, and the quality of the alerts is not up to the mark. We have escalated many times, but we do not receive solid responses from them in terms of fixes. Digital Shadows should focus on the engineering side rather than the support aspect because support is there to help us get updates, but in terms of quick fixes, it is not as responsive. The need for improvement lies more with the engineering part in fixing issues, which is linked to support.
FL
Senior Manager - Pre-Sales at Trillium Information Security Systems
Offers robust compliance features but needs improved automation in remediation
The automation capability remediation needs improvement. The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform. This basic feature that Rapid7 calls an automated remediation process is actually manual. We can update the status of vulnerabilities in the Rapid7 InsightVM platform and collectively see how many vulnerabilities we have identified and how many are remediated by our IT team. More automation in the remediation feature is a basic demand from many customers. The remediation part and vulnerability identification of network devices or rigid devices are not currently supported by Rapid7 InsightVM. More integration and automation are the two areas Rapid7 needs to improve in their product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Digital Shadows helps our organization identify and mitigate cyber threats through their crawling of the internet, gathering information, pivoting it, and then sending those alerts to us which we monitor from our SIEM tool."
"The most effective feature for threat intelligence, in my opinion, is collecting impersonating websites."
"The most effective feature for threat intelligence, in my opinion, is collecting impersonating websites."
"The assessment is most valuable."
"We can create our own templates."
"The performance is good."
"The most important aspect of the solution is that it rarely gives false positives, especially compared to other products. It provides very clear reports for our IT teams to look at."
"The discovery and prioritization of vulnerabilities."
"most valuable features of Rapid7 InsightVM for me are creating dynamic asset tags, generating reports, and deploying the agent. The agent scans assets every four hours, providing real-time data on any devices. Although there weren't any significant new features compared to our previous tool, having both SIEM and vulnerability management handled by one tool made things easier. We could gather logs from different devices and cloud sources, and perform detailed investigations without switching tools. I haven't worked with the automation capabilities of InsightVM. For remediation prioritization, we check the vulnerability, search for solutions on open platforms, and work with different teams to apply patches after proper testing. Currently, we don’t have any AI or ASM projects assisted by InsightVM"
"The most valuable features of the solution are the agent and the scanning."
"The solution is automatically scheduled so it runs by itself."
 

Cons

"The solution doesn't pick up all the brands of the URLs. I have a relatively small company name, however, the solution still misses a certain number of URLs with my company's name in it that are impersonating websites. It's not very comprehensive, to be honest."
"The solution doesn't pick up all the brands of the URLs."
"For basic support from Digital Shadows, my impression is that it is six to seven because many times we see duplications or bugs, and the quality of the alerts is not up to the mark."
"Within InsightVM, there is no feature to assign a ticket. If we can have more API calls, we can do that from InsightVM."
"Rapid7 InsightVM on-premise version is not that effective in the web-related systems."
"In terms of improvements, its price could be better. Our main issue with Rapid7 is that it is too expensive. You can only sell it to enterprise accounts. In terms of new features, Rapid7 came up with a product called InsightIDR a couple of years ago, which is a good SIEM solution. We expect that Rapid7 will work on some sort of integration between InsightVM and InsightIDR, where vulnerability or anomaly detected by InsightVM can be reported in InsightIDR in some sort of real-time. Rapid7 doesn't patch. For example, if you have a vulnerability, some products can scan and also do the patching, but Rapid7 does not do the patching. It would be nice if it can also patch."
"InsightVM is getting a little stale and is in danger of falling behind its competitors."
"I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective."
"All products have room for increased security and Rapid7 InsightVM is no exception."
"There have been instances where technical support takes a long time to update the status of a ticket, which is something that can be improved."
"We have some issues with how it scans patches."
 

Pricing and Cost Advice

Information not available
"Its pricing depends on the number of users per month."
"The solution is a bit more reasonably priced than other products."
"I do not have experience with the pricing of the solution."
"We have an annual license to use Rapid7 InsightVM and if we want to extend it, we will possibly choose more than one year."
"Its price is too high. My only concern or issue with Rapid7 is its pricing."
"Pricing is reasonable because we pay according to asset usage. We can define our assets and sites according to our preference."
"The tool's price is neither too high nor too low. My company needs to pay 65,000 per year. There are no additional costs apart from the licensing fees attached to the solution."
"A full license for the solution is expensive because it is at the organizational level and not by individual users."
report
Use our free recommendation engine to learn which Digital Risk Protection solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Manufacturing Company
8%
Government
7%
Engineering Company
7%
Financial Services Firm
13%
Manufacturing Company
10%
Computer Software Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise25
 

Questions from the Community

What is your experience regarding pricing and costs for Digital Shadows?
Regarding the cost of Digital Shadows, I think prices are a bit higher. The information provided is already available; some of it is paid information. However, considering all the information they ...
What needs improvement with Digital Shadows?
I do not rate Digital Shadows a nine or ten because there are many things that need improvement. The information we get is kind of generic. For instance, for impersonation, we don't have much detai...
What is your primary use case for Digital Shadows?
Our main use cases for Digital Shadows are mainly using it for threat intel. For instance, we have our domain listed on Digital Shadows. Whenever we see any sort of impersonation domain registratio...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
The customers are mostly SMBs, though some enterprise organizations have also deployed the solution. This is neither a cheap nor the most expensive solution. Qualys and some other vendors are more ...
 

Also Known As

No data available
InsightVM, NeXpose
 

Overview

 

Sample Customers

Accenture, Pret A Manger, Human Rights Watch
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about Recorded Future, ZeroFOX, Proofpoint and others in Digital Risk Protection. Updated: January 2026.
881,082 professionals have used our research since 2012.