The typical use case for Rapid7 MDR is that it is highly valued. It is not so bad, but competition with EDR is tough. Rapid7 MDR does not position itself as EDR or XDR, so it is rather a SIEM type solution, which makes it different from CrowdStrike, SentinelOne, or Microsoft. They are not in the competition listing of EDR products.
Marketing Expert at J's communication
Threat detection benefits stand out while AI capabilities need improvement
Pros and Cons
- "The features of Rapid7 MDR that I find most effective for threat detection are the threat intelligence capabilities because it already collects many vulnerabilities and exploitations, as well as the configuration of network devices."
- "Rapid7 MDR is currently weak in AI solutions and intelligence, which is concerning."
What is our primary use case?
What is most valuable?
The features of Rapid7 MDR that I find most effective for threat detection are the threat intelligence capabilities because it already collects many vulnerabilities and exploitations, as well as the configuration of network devices. They integrate everything into one solution. The other solutions such as CrowdStrike or SentinelOne don't collect all the vulnerabilities or threat intelligence except within their product itself, making Rapid7 MDR very strong in this aspect.
I have seen an ROI from this solution in terms of time savings. Because it includes everything, including SIEM, EDR, and vulnerability control, other solutions require integration of every module and vendor. It is easier to implement once they start, as the modules of the EDR can be challenging to implement and may require consulting.
What needs improvement?
There are areas of Rapid7 MDR that have room for improvement. The market is now changing very quickly towards artificial intelligence, and all the SIEM, EDR, and XDR vendors are moving to apply artificial intelligence in their solutions. Rapid7 MDR is currently weak in AI solutions and intelligence, which is concerning. It is also somewhat delayed compared to many vendors such as CrowdStrike, SentinelOne, or Microsoft, who are heading in such directions.
For how long have I used the solution?
I have worked with Rapid7 MDR for approximately three years.
Buyer's Guide
Rapid7 MDR
July 2026
Learn what your peers think about Rapid7 MDR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would rate the stability of Rapid7 MDR rather high, approximately six or eight out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Rapid7 MDR very high on a scale of one to 10, approximately eight.
How are customer service and support?
The technical support from Rapid7 MDR is adequate, rating approximately six out of ten. The lower tier support is not very good. Additionally, Japanese customers require Japanese representatives as the support is primarily in English.
How was the initial setup?
The initial setup of Rapid7 MDR is relatively easy because it integrates everything. However, the complete setup process is challenging due to the numerous modules involved. This includes cloud deployment, on-premises implementation of network devices, data collection, and agent installation. Implementation is manageable for existing Rapid7 customers, but it can be very challenging for new customers.
What other advice do I have?
I have knowledge of CrowdStrike solutions as a competitor, though not direct experience.
I would recommend Rapid7 MDR to others, but this market is changing quickly due to artificial intelligence. I cannot say it is the best solution for customers as the market is evolving, with new solutions emerging and existing vendors improving their offerings in the near future.
Overall, I would rate Rapid7 MDR a seven out of ten. Once customers can implement it, it becomes a good solution for them, though implementation remains a significant consideration.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Security Engineer at a retailer with 201-500 employees
Managed detection has transformed our soc by improving visibility and speeding incident response
Pros and Cons
- "AI is present, and I think Rapid7 MDR could add good reporting, more reporting, and perhaps more templates in the future to make the product even better."
What is our primary use case?
Rapid7 MDR is our managed service that serves as our SOC and represents our starting point in utilizing a solution for cybersecurity. Rapid7 MDR is the primary use case for our company's SOC.
What is most valuable?
The consulting and monthly consulting and reporting are very useful features that we find most valuable.
Having a dedicated cybersecurity advisor through Rapid7 MDR helps us align our cybersecurity strategy to the up-to-date measurements and controls that we can take, which impacts how we align our security program with business needs.
With a very small IT operations team, we have experienced a positive impact from Rapid7 MDR. In the past, we had much effort to handle incidents, and now with the SOC on our side, the process is more streamlined, and we are much faster than before.
My impression of the Risk-Aware Detection features is positive; they work well for us.
We are starting to get into the AI solutions from Rapid7 MDR for our SIEM, but we are in the very beginning stages, focusing on AI-assisted Risk-Aware Investigation workflows.
We are using the integrated MDR for Microsoft environments feature. Up to now, it works well regarding its detection and response capabilities for Microsoft-centric environments.
Now we have a clear view of what has happened in our tenant, which has impacted our incident recovery process positively; before, we did not have this view. We have many signals, so we can control them and check if we are on the right path or if it is just a false incident, and it works very well. In the last several months, we have seen more than we have seen in the previous two years.
What needs improvement?
AI is present, and I think Rapid7 MDR could add good reporting, more reporting, and perhaps more templates in the future to make the product even better.
For how long have I used the solution?
Since the beginning of the year, we have been using this tool.
What do I think about the stability of the solution?
Rapid7 MDR works really well; we are completely satisfied with it. It is a nice service and I believe we have everything we need. From my perspective, I have no improvements to suggest. There is much more we have to discover.
What do I think about the scalability of the solution?
I do not think there are scalability issues regarding extending usage in the future.
How are customer service and support?
When ten is the best, I would rate their technical support at a ten.
Which solution did I use previously and why did I switch?
We have Rapid7 IVM and SIEM, and we are still using them. We have now added Rapid7 MDR as a service, which reflects our previous positive experience with Rapid7 solutions.
How was the initial setup?
I cannot speak to how the initial setup was because we had Rapid7 IVM and SIEM before, and that setup occurred before my time. The setup for Rapid7 MDR was very simple because we already had half of the infrastructure in place.
Which other solutions did I evaluate?
We evaluated many other solutions for various situations, but ultimately we chose Rapid7 MDR because of the price and the service, which were perfect for us.
What other advice do I have?
I find the pricing reasonable and competitive.
Rapid7 MDR is hybrid regarding whether it is on-premises, cloud-based, or hybrid.
I purchased Rapid7 MDR through our IT supplier.
Five people, at most, are working with the product in our company, indicating the usage is currently pretty limited.
The interface is very handy and user-friendly.
I would say Rapid7 MDR is popular; Rapid7 is a well-known name in my region.
I would rate this product a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 3, 2026
Flag as inappropriateBuyer's Guide
Rapid7 MDR
July 2026
Learn what your peers think about Rapid7 MDR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
Head, Networks And Security at First City Monument Bank Limited
Offers good integrations , very scalable and flexible and we can send as many logs as we want
Pros and Cons
- "We've filled in crucial gaps we had with our previous solution. This was a key factor in choosing Rapid7 during the selection process. The ROI is already starting to show, too."
- "There are potential improvements in reports and dashboards."
What is our primary use case?
We use it for our security and virtual center security. It helps us investigate incidents and physical issues.
How has it helped my organization?
We've filled in crucial gaps we had with our previous solution. This was a key factor in choosing Rapid7 during the selection process. The ROI is already starting to show, too.
We saw specific cost reductions. We used to pay extra for external user insight and availability management in our old setup. Now, that's all included in Rapid7, which saves us money and simplifies management.
What is most valuable?
The integrations are a big plus. We can easily onboard log sources and transition from our previous MSSP without any hassle. We don't have any major issues and it has good ease of use for resource onboarding a breeze.
What needs improvement?
There are potential improvements in reports and dashboards.
For how long have I used the solution?
We have been using it for a couple of months. It replaced SecureWorks in my current environment. We used SecureWorks MDR in my previous role.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
Our previous solution was limited by events per second or other load restrictions. With Rapid7, we can send as many logs as we want. We're not limited by any event or check numbers. It's very flexible and scalable, unlike our previous setup.
How are customer service and support?
The support is quite responsive. We often jump on calls for onboarding assets and custom configurations like log forwarding. We haven't needed much beyond that.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup was definitely straightforward. Onboarding and integrations were a breeze.
What about the implementation team?
We started by selecting a vendor, in this case, External Call.com. They handled a lot of the initial and out-of-box configuration and setup, and their consultants took care of the rest of the process. Everything was smooth and efficient in the business sense. The deployment took about six months.
As long as the collectors are running in the cloud, there's not much maintenance required. We decided to keep the programming on-premise, but that's a separate decision.
What was our ROI?
We saw an ROI. We saw specific cost reductions. We used to pay extra for external user insight and vulnerability management in our old setup. Now, that's all included in Rapid7, which saves us money and simplifies vulnerability management.
What's my experience with pricing, setup cost, and licensing?
It's reasonable compared to our previous solution. We conducted a cost-benefit analysis and based on that it met our needs and usage, so we are satisfied with the price.
What other advice do I have?
Rapid7 works well for us and meets our current needs. It's a solid eight out of ten. However, it depends on your organization's cybersecurity roadmap.
For example, if your long-term plan is to have an on-premise security team, then Rapid7 might not be the best fit.
We don't have on-premise capabilities and rely solely on the cloud, so it works for us. But other organizations might need that on-premise option. So, it really depends on their cybersecurity roadmap.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Security Specialist at KNIPPERX INC.
An affordable solution that provides automation workflows and allows users to customize alerts
Pros and Cons
- "The product allows us to customize our alerts."
- "The product should provide full transparency in security operations."
What is our primary use case?
We use the solution in our security operation center. We use the tool to provide more visibility into the security operation center.
What is most valuable?
It is a good solution. It's not a black box. Our security operations center has similar access to the console that we have access to. It's very open. The product has automation workflows. It has around 5000 detections in it. I trust the solution.
The product is continuously developing. Whenever something new comes out, the product is upgraded. We can also bring in community threat feeds. The product allows us to customize our alerts. Log query searching has come a long way. It doesn’t require us to code anymore. We can just type in what we are looking for.
We can also deploy our agents. The good thing about agents is that we can use the automation workflow to disable user accounts. We can also make it disable and quarantine an asset. These features are provided right out of the box. The workflows do not cost us more money.
What needs improvement?
The product should provide full transparency in security operations. I want to see what's exactly going on on the other side. I want to know what is happening, what my security operations center is doing, and whether they are working for me.
For how long have I used the solution?
I have been using the solution for four to five years for two to three different companies.
How are customer service and support?
The nice thing about MDR is that we have a number to call. If there's something major or risky, we have a telephone number for that group.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used Arctic Wolf. We switched to Rapid7 MDR because we didn’t get a lot of insight from Arctic Wolf, and it provided a lot of false positives.
How was the initial setup?
I rate the ease of setup a seven out of ten. It is not bad. It takes a little bit more time. It will probably take three weeks to get the product up and running, especially by the time we deploy all the agents.
What about the implementation team?
We need four people to deploy the solution. It includes server, network, security, and desktop experts.
What's my experience with pricing, setup cost, and licensing?
The product is not overly priced. We can buy products for a cheaper price, but we will not get as much technology.
What other advice do I have?
I trust the tool with my network. Overall, I rate the product a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Consultant at ITSEC Asia
Excels in incident response and minimize false positives at flexible pricing
How has it helped my organization?
My company is also implementing Rapid7 MDR for database security. When comparing it with other solutions like ductless systems, Rapid7 stands out specifically for MDR network protection and response.
What is most valuable?
Rapid7's MDR service offers several strong points. Firstly, it excels in incident response. Rapid7 focuses not only on incident detection but also on response, aiming to minimize false positives effectively. This capability is crucial for reducing unnecessary alerts and ensuring that responses are targeted and efficient.
Additionally, Rapid7's MDR service extends beyond just incident response. It includes features for vulnerability assessment and vulnerability management, which are essential for proactive security measures. These features help in identifying and managing potential risks before they can be exploited.
For how long have I used the solution?
I have been using Rapid7 MDR for three years. We are the vendor of this solution.
What do I think about the stability of the solution?
The product is stable. I rate the solution’s stability a nine out of ten.
What do I think about the scalability of the solution?
The scalability is high. It is suitable for enterprise businesses. I rate the solution’s scalability a seven out of ten.
How are customer service and support?
Support is excellent.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. To install the Rapid7, sensor and pull off kit, we only need less than a day.
I rate the initial setup an eight or nine out of ten, where one is difficult, and ten is easy.
What's my experience with pricing, setup cost, and licensing?
We have a very nice pricing. It is flexible.
What other advice do I have?
Rapid7 MDR leverage AI highly to enhance threat detection and response capabilities.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Buyer's Guide
Download our free Rapid7 MDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Managed Detection and Response (MDR)Popular Comparisons
IBM Security QRadar
Huntress Managed EDR
Intercept X Endpoint
SentinelOne Wayfinder Threat Detection and Response
CrowdStrike Falcon Complete MDR
Arctic Wolf Managed Detection and Response
Secureworks Taegis Managed XDR / MDR
Adlumin Security Operations
Red Canary
CompassOne by Blackpoint Cyber
ConnectWise SIEM
Fidelis Elevate
Sophos MDR
Netsurion
Binary Defense MDR
Buyer's Guide
Download our free Rapid7 MDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How do you estimate ROI of a Managed Detection and Response (MDR) solution?
- When evaluating Managed Detection and Response (MDR), what aspect do you think is the most important to look for?
- Which solution do you prefer: Optiv Managed Security Services or eSentire?
- Why is Managed Detection and Response (MDR) important for companies?















