Listing Thumbnail

    Rapid7 Command Platform

     Info
    Sold by: Rapid7 
    Deployed on AWS
    The Rapid7 Command Platform is a command center that gives you a holistic view of your security program. The central hub of your Rapid7 experience, the Command Platform brings your ecosystem of Rapid7 tools and capabilities into a single place to give you a trustworthy view into your attack surface, your risk posture, your threat response, and your whole security program.
    4.3

    Overview

    Rapid7s AI-powered Command Platform aggregates data from across your security ecosystem to provide a comprehensive, actionable view of your critical telemetry. With the Command Platform, you have threat- aware risk context to anticipate and prevent breaches, actionable detections and insights to pinpoint the most critical threats across your environment, and expert intelligence from our security experts, enabling you to take action confidently every time all within a single, consolidated platform bringing your team tangible value.

    Threat-aware Exposure Management

    Attack surface management - Surface Command breaks down data silos by aggregating comprehensive attack surface visibility across hybrid environments, along with external attack surface scans, to build a dynamic, 360-degree view of your entire attack surface in.

    Vulnerability management - Vulnerability management delivers complete visibility across on-premise and remote endpoints to help teams identify, communicate, and remediate vulnerabilities, misconfigurations, and other risks across the business.

    Cloud security - Cloud security provides code-to-cloud protection for cloud-native applications and workloads with seamless integration into the CI/CD pipeline, along with real-time, agentless risk assessment and prioritization based on reachability, exploitability and potential impact.

    Exposure management - Exposure Command builds on the comprehensive attack surface visibility of Surface Command with high-fidelity risk context and insight into security posture of your entire digital estate, aggregating findings from Rapid7 native exposure assessment capabilities alongside data from all your third-party security tooling and enrichment sources. This enables security teams to understand and prioritize exposure from the endpoint to the cloud.

    Application Security - Application security provides dynamic security testing to automatically assess web apps and APIs for vulnerabilities using an industry-leading attack framework and library, providing accurate and actionable remediation guidance to developers

    Cloud-ready Detection and Response

    Next-gen SIEM and XDR - Next-Gen SIEM delivers highly efficient, accelerated detection and response with frictionless SaaS deployment, a highly intuitive interface, robust out-of-the-box detections informed by our MDR SOC, and actionable built-in automation.

    Digital Risk Protection - Digital Risk Protection anticipates and prevents breaches with visibility of the external attack surface through clear, deep, and dark web monitoring, credential and data leakage,protection against phishing attempts, and more.

    Automation - Automation enables your team to accelerate and streamline time-intensive processes - with no code necessary. With plugins and customizable workflows, your team can accelerate detection and response, automate vulnerability management tasks, phishing investigations, and overall collaboration.

    Threat Intelligence - Intelligence hub delivers high fidelity, actionable threat intelligence with significantly less noise than traditional Threat Intelligence Platforms. Infused with intelligence from Rapid7 Labs proprietary threat and vulnerability research and community- driven tools, your team can easily focus on the most meaningful risk signals and take high priority actions to stay ahead of critical threats most relevant to your organization.

    Highlights

    • End alert fatigue - with prioritized threats that provide more signal and less noise.
    • Disrupt attackers, not your tech stack - as you seamlessly integrate and quickly deploy across any footprint.
    • Start anywhere - scale anytime from one product up to the whole platform. Managed or SaaS, we're here for your evolving needs.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Rapid7 Command Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Command Platform
    Contact us for a custom quote.
    $10,000.00

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Vulnerability and Patch Management, Data Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Attack Surface Management
    Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to provide 360-degree view of entire attack surface
    Vulnerability Management
    Delivers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities, misconfigurations, and risks
    Cloud Security
    Provides code-to-cloud protection for cloud-native applications with seamless CI/CD pipeline integration and agentless risk assessment based on reachability, exploitability, and potential impact
    Next-Generation SIEM and XDR
    Delivers accelerated detection and response with SaaS deployment, intuitive interface, out-of-the-box detections informed by MDR SOC, and built-in automation capabilities
    Threat Intelligence
    Delivers high-fidelity actionable threat intelligence infused with proprietary threat and vulnerability research from Rapid7 Labs and community-driven tools
    Cloud-Based Vulnerability Management Platform
    Single cloud-based application that integrates discovery, assessment, detection, and response capabilities for vulnerability management
    Real-Time Prioritization
    Real-time prioritization of vulnerabilities across global hybrid IT environments
    AWS EC2 Integration
    Pre-approved scanner for AWS EC2 Cloud with AWS EC2 Cloud Connector for seamless integration
    Cloud Context-Aware Scanning
    Cloud context aware scanning providing end-to-end visibility from inventory to remediation
    Comprehensive Asset Discovery and Assessment
    Discovers and assesses assets across hybrid IT environments with comprehensive coverage and visibility
    Vulnerability Data Aggregation
    Consolidates and evaluates vulnerability data from multiple Nessus scanners distributed across the enterprise infrastructure.
    Risk Assessment and Trend Analysis
    Illustrates vulnerability trends over time and assesses risk with actionable context for effective remediation prioritization.
    Advanced Analytics and Reporting
    Utilizes advanced analytics with customizable dashboards and reports to identify network weaknesses.
    Continuous Vulnerability Monitoring
    Continuously monitors systems for new vulnerabilities to enable proactive threat detection.
    Centralized Security Management
    Provides centralized management of security assets from a single console with support for up to 500 IP bands.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    91 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    56%
    41%
    2%
    1%
    0%
    5 AWS reviews
    |
    86 external reviews
    External reviews are from G2  and PeerSpot .
    Prajwal Chougale

    Centralized threat hunting has improved alert accuracy and simplifies incident investigations

    Reviewed on Jul 17, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Rapid7 InsightIDR  serves as our SIEM  solution where all kinds of activity, including network logs, endpoint logs, user activity, user behavior analytics, and threat hunting, are tracked. Additionally, we use it to store logs and provide them for SOC analysts, and we utilize it completely as a SIEM  tool. We also have used some of their other solutions, including Rapid7 Insight Vulnerability Management  and Rapid7 Threat Command.

    In our day-to-day operations, Rapid7 InsightIDR  is useful for tracking everything happening at the cloud level, at Entra ID, or on-premises. All logs, including network logs and traffic between domains or inside the domain or between on-premises servers and endpoints, are collected in one place. Using various analytical rules, we get alerts, and we configure the alerts required for our organizational needs. There are many more use cases for this solution.

    When it comes to threat hunting, we analyze dark web activity and track various activities related to users. We provide all user data to the agent, which searches the dark web for alerts based on our multiple domains. We actively monitor for any leaks detected with users or any spoofed domains and set up Rapid7 InsightIDR alerts to track these activities closely.

    What is most valuable?

    The best features that Rapid7 InsightIDR offers include its log display, which is easy to understand for any SOC analyst. In hunting, if there is any red team activity or a true positive incident and an analyst wants to hunt or review logs, Rapid7 has simple logic and features such as legacy log search and normal log search using KQL, Kusto Query Language, which allows for fetching and analyzing logs in detail. The way everything is arranged and easy to understand, along with insights into network sensors or devices configured with Rapid7, helps us understand where logs are being ingested and where traffic is moving.

    Out of all the features, log search is what I find myself using the most. Compared to Microsoft Sentinel , Rapid7 InsightIDR's SIEM tool makes log search very easy. The log display is simple, and the investigation part is very intuitive using Rapid7. Logs are segregated into different categories, such as ingress logs, web traffic logs, Active Directory logs, and cloud security logs, making it seamless to present everything on their dashboard, which has been immensely helpful for my investigative work.

    Rapid7 InsightIDR has positively impacted my organization by capturing most logs and every minute detail, including endpoint logs, network logs, and any email-related logs if a malicious link has been clicked. All logs are integrated and ingested into Rapid7 InsightIDR, which is useful for hunting or checking for any true positive incidents that trigger. A notable feature is that if an investigation opens on a single entity and any alerts are observed around that time, they are tagged under a single incident with all activity logged under one template or interface. This allows an analyst to make quick and easy decisions and analyze all investigation artifacts. Recently, when one of our users clicked a malicious URL that Microsoft Defender could not track immediately, Rapid7 notified us that a malicious email was found, helping us take action before Microsoft could respond.

    Rapid7 InsightIDR provides very crisp, detailed, and on-point alerts whenever there is suspicious activity, which has led to very few false positives for the clients using Rapid7 InsightIDR. It has saved us a lot of time by reducing noisy alerts, and the dashboard is effortlessly managed and neatly organized, allowing us to create allow lists or block lists for any kind of activity.

    What needs improvement?

    I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel , Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations.

    These two areas are the main areas for improvement; everything else is good.

    For how long have I used the solution?

    I have been working in my current field for around three years.

    What do I think about the stability of the solution?

    Rapid7 InsightIDR is stable with minimal downtimes or glitches; platform unavailability is very rare, and we have not experienced missed logs. Compared to Microsoft Sentinel, Rapid7 InsightIDR maintains high availability of logs and a reliable dashboard.

    What do I think about the scalability of the solution?

    Rapid7 InsightIDR's scalability fits very well for organizations of any size, making it a very easy-to-use, handy, and simple tool.

    How are customer service and support?

    The customer support at Rapid7 is really good. Over my 2.5 years of experience, I have submitted many support cases related to InsightIDR alerts, analytical rules, and even Insight Vulnerability Management , and they have been consistently supportive. I would rate the customer support a perfect 10 out of 10.

    Which solution did I use previously and why did I switch?

    For this client, we have exclusively used Rapid7 InsightIDR since the beginning as there were no other solutions in place. However, I can say that we used Microsoft Sentinel for other clients, and in comparison, Rapid7 InsightIDR has proven to be a more efficient and time-saving tool.

    How was the initial setup?

    The learning curve for new users of Rapid7 InsightIDR is very easy. Throughout my 2.5 years of experience, I have successfully onboarded three batches of users, totaling more than 10 users, and they adapted easily to this tool. The only challenging part was the log search, but once users got into it, it became very easy to use. Compared to the KQL of Microsoft Sentinel, Rapid7 InsightIDR has been much easier for users to learn.

    My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was straightforward thanks to the assistance from their team.

    What about the implementation team?

    We did not purchase Rapid7 InsightIDR through the AWS  marketplace; we reached out to an agent through which we made the purchase.

    What was our ROI?

    I have seen a return on investment; all employees, particularly the SOC analysts, are satisfied as they easily got trained and adapted to this tool. The logs are delivered in a crisp and direct manner, simplifying analysis of the alerts significantly.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was straightforward thanks to the assistance from their team.

    What other advice do I have?

    I have completed my insights about my main use case and how we use Rapid7 InsightIDR day-to-day. All the improvements and features I have discussed are sufficient.

    I am very satisfied with the speed and performance of Rapid7 InsightIDR when handling large volumes of data, giving it a rating of 9.5 out of 10. It can handle any volume of data for any organization, making it very cost-effective, which distinguishes it as a standout SIEM tool in the market. It is straightforward, time-efficient, and easy to use.

    My advice for others considering using Rapid7 InsightIDR is to go for it if you are looking for a value-for-money and straightforward tool that suits any kind of analyst.

    Rapid7 InsightIDR is deployed in my organization through AWS  public cloud. The deployment model we use most is public cloud through AWS. We use Amazon Web Services, AWS, as our cloud provider.

    Rapid7 InsightIDR integrates with other security tools or platforms in our environment, including CrowdStrike, Netskope , and email security through Defender.

    I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part.

    Rapid7 InsightIDR's AI capabilities are very helpful; the simulations or the SIEM injections they provide are useful for gaining alerts or insights about the organization, and it is very secure with no downtimes that affect client security. We have weekly meetings with support to discuss licenses or any new features added, which is really helpful in getting along with the tool.

    Most of the AI capabilities are still in progress, with various features being introduced. In Rapid7 InsightIDR, it is not heavily related to AI capabilities because the focus is primarily on the SIEM aspects, including logs from your environment and the size of your setup. My overall review rating for Rapid7 InsightIDR is 8 out of 10.

    Nihal J.

    Intuitive, High-Performance SIEM with Great Support and Cost-Effective Value

    Reviewed on Apr 29, 2026
    Review provided by G2
    What do you like best about the product?
    Rapid 7 SIEM has a intuitive UI/UX and straightforeard integrations with various third party vwendors which is crucial for a SIEM solution. rapid7 also has very good support and the perfomance of the SIEM in terms of log ingestion, correlation and detection is top nothc. Rapid 7 SIEM is also cost effectivr espocilly for SMB customers. Their in buit AI is also very helpfiu;l during query complex log data
    What do you dislike about the product?
    What I dislike is the lack of vendor support. Even though they have many options available, it still falls short compared to a few other SIEM solutions.
    What problems is the product solving and how is that benefiting you?
    The biggest problem Rapid 7 SIEM has solved for us is the lack of visibility into our infrastructure. We’re now able to see activity across firewalls, switches, cloud, and endpoints. This makes it easier to correlate events between each other and identify the attack path in the event of an attack. We can also integrate email security.
    bc@team-consulting.com C.

    Easy Log Search Across Our Estate with Clear, Understandable Alerts

    Reviewed on Jan 28, 2026
    Review provided by G2
    What do you like best about the product?
    It allows us to view and search the log sets generated across our estate with ease, and it produces clear, easy-to-understand alerts based on them.
    What do you dislike about the product?
    Honestly, there’s nothing to dislike. It really lifted the lid on our environments and helped us see what was going on more clearly.
    What problems is the product solving and how is that benefiting you?
    It’s been really helpful to be able to easily view and manage our various logs, and to have meaningful alerts generated from them.
    BENOIT C.

    Seamless UEBA Integration for Advanced Threat Detection

    Reviewed on Jan 13, 2026
    Review provided by G2
    What do you like best about the product?
    I highly value its seamless integration of UEBA and deception tools to detect lateral movement across the network.
    What do you dislike about the product?
    The platform lacks deep customization for complex correlation rules and can become quite expensive as log volume increases.
    What problems is the product solving and how is that benefiting you?
    It solves the problem of alert fatigue by unifying disparate logs into clear, actionable attack timelines for faster response.
    Joevanne V.

    Easiest SIEM Implementation with Transparent Pricing

    Reviewed on Jan 06, 2026
    Review provided by G2
    What do you like best about the product?
    In my experience, this is the easiest SIEM tool to implement. Another advantage is that, unlike many competitors, its pricing is not based on log ingestion. It has many pre-built integrations making it very easy to integrate with many 3rd party tools.
    What do you dislike about the product?
    This tool may feel somewhat limited when compared to some of the larger competitors in the industry.
    What problems is the product solving and how is that benefiting you?
    SIEM and managed detection and response have been advantageous for us, as they enable the collection of all necessary logs within our environment. This has removed our worries about costs or exceeding our log licensing limits.
    View all reviews