Rapid7 InsightIDR Room for Improvement

Awais Sajid - PeerSpot reviewer
Security Consultant at NUCES

The product allows us to make only 30 custom rules. The limit on custom rules must be changed.

View full review »
Gerard Konan - PeerSpot reviewer
Founder & CEO at AGILLY

Rapid7 InsightIDR is not intuitive to search for logs. It should be more user-friendly and improve the dashboards. We should be able to use ready-made templates instead of having to build one. 

View full review »
JensWolf - PeerSpot reviewer
Systems Administrator at Gernandt & Danielsson Advokatbyrå KB

Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries. In the future, I would like the tool to offer its uses with a pre-made set of queries.

View full review »
Buyer's Guide
Rapid7 InsightIDR
April 2024
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,740 professionals have used our research since 2012.
Agustinus DWIJOKO - PeerSpot reviewer
Network & Security Engineer at PT. Centrin Online Prima

The integration capabilities of the solution have certain shortcomings where improvements are required.

If possible, it would be great to see AI embedded in all the functionalities offered by the product.

View full review »
Khizar Butt - PeerSpot reviewer
Country Sales Lead at securic systems

Because Rapid7 was originally a vulnerability management solution, more and more companies are now moving towards their technologies and their existing SIEM applications and converting them to XDR solutions. Though Rapid7 provides its EDR option with SIEM, it has a long way to go to achieve an XDR status.

I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR because every SIEM solution provider is moving their solutions toward XDR.

View full review »
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer

The solution needs improvement in threat intelligence. Increasing the depth of intelligence to help users understand more about threats is a possibility. My suggestion is to expand access to other websites or resources. 

View full review »
BR
Security Solution Engineer II at a security firm with 501-1,000 employees

One of the things that could be better is digital forensics. It is there, but it can be better. They could provide more on the endpoint detection level.

It could have intelligence. It is available as a separate product but not as a part of the platform itself.

View full review »
Ali Sağlam - PeerSpot reviewer
System and Infrastructure Manager at iLab

Rapid7 doesn't integrate well with all our security tools from various vendors, so we plan to switch. Many of our solutions work with Rapid7, but some do not. We are already searching for a replacement already.

View full review »
JC
Product Manager at Bizinfo

Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA). So, User Behavior Analytics (UBA) should be added in the new release.

View full review »
Prasanth Prasad - PeerSpot reviewer
Director of Technology at a tech vendor with 11-50 employees

I believe that Rapid7 InsightIDR has moved to a complete cloud-first strategy. The tools offered by Rapid7 InsightIDR are amazing. The product should have provided some capabilities to users who wanted to stay or use the tool's on-premises version, as it would have provided the solution with more acceptance in the market, especially in the Middle East region.

It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required.

View full review »
Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd

They should add more configuration and security features to the solution.

View full review »
JS
Information Security Systems Administrator at a non-tech company with 5,001-10,000 employees

Personally, I feel it would greatly benefit from more supported log sources. Additionally, the ability to tune the collector for custom logs would greatly help.

View full review »
Chad Kliewer - PeerSpot reviewer
Information Security Officer at PTCI

I would like the ability to adjust the threshold of certain existing alerts.  Currently the only option is to change the notifications or create my own alert. 

View full review »
RicardoSilva3 - PeerSpot reviewer
Coordinator & Teacher at Pahldata

The main problem lies in the processes within the client's operating systems. XDR is superior to CMs. Observing how the processes function within the machine is essential if you are monitoring the client or servers, and not only the event with the first or second line but the third line is most important.

View full review »
CP
System Engineer at Starlabs Limited

InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal. 

View full review »
KimeangSuon - PeerSpot reviewer
Pre-Sale Consultant at Yip In Tsoi Co., LTD.

InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment. So it's a challenge to get the customer to see the benefits of a cloud-based product in terms of ROI. If they switch to a cloud application, they won't have to pay for hardware maintenance or inventory. So with the next update, the customers want to see how it applies to their environment and its advantages over on-premise solutions. 

View full review »
PD
Information Security Manager at a tech vendor with 51-200 employees

The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in.

View full review »
SamiAyyash - PeerSpot reviewer
Threat Intelligence Engineer at a tech services company with 11-50 employees

Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps.

View full review »
MK
Head of Infrastructure at Pearl Data Direct

I'd like to be able to get the compliance report within the solution which is currently not possible. For example, the P-Series was around 77001 compliance report of your SIEM solution. That option is unfortunately not available. 

View full review »
JC
Database Administrator with 501-1,000 employees

Threat Intelligence: It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.

View full review »
SP
Security Consultant at a comms service provider with 51-200 employees

I'd like to see a better ability to customize the check within the console. Rules can be customized better if the integration is improved. They now have integration with CrowdStrike so maybe they could have some kind of integration with Microsoft.

View full review »
NJ
Security Manager

Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition.

View full review »
it_user836481 - PeerSpot reviewer
Information Security Officer at a tech vendor with 201-500 employees

Although the solution has been improving continually in the time I have been using it, there could be areas of improvement. 

The one thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not.

View full review »
IO
Solution Specialist at a tech services company with 11-50 employees

The solution's XDR agents cannot compete with the XDR solutions out there yet. It has to be a stand-alone XDR solution, and I know they are working on that. They have to ensure that it has the full capabilities of an XDR solution.

View full review »
JS
IT Engineer Security Operation Team at a tech services company with 201-500 employees

The only thing I can think of to improve the product is that the interface for doing investigation needs to be enhanced. For example, we can add notes through the interface, but we can not attach files to the investigation. It would be a useful addition. It would give us more flexibility to resolve more complicated situations. 

View full review »
DB
CoFounder & Head of Technology at intuity

I'd like to see a mobile application included and some feature related to the generality of segregation for internal users that access the application.

View full review »
MS
Network Support Engineer at a tech services company with 51-200 employees

The APIs can be further improved in Rapid7. 

View full review »
OS
Linux admin at a wholesaler/distributor with 51-200 employees

The dashboard is an area that could be simplified.  For management, it should be clear and the files should be there.

View full review »
AS
Enterprise Sales at a tech vendor with 11-50 employees

Earlier they didn't have a network flow capture product, so they were not able to capture the network flows. We were able to capture the logs but not the network flows. Now, they have acquired a company called NetFort, and now they are also using the capture network flows. This was one of the shortcomings of the product which they have now rectified after acquisition of the company.

Cloud risk assessment is one area where I think they need a lot of improvement.

The solution should have a CIS Benchmark in terms of, I would say, config change detection.

View full review »
Buyer's Guide
Rapid7 InsightIDR
April 2024
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,740 professionals have used our research since 2012.