Listing Thumbnail

    InsightVM - Vulnerability Management

     Info
    Sold by: Rapid7 
    Deployed on AWS
    Vendor Insights
    Rapid7 InsightVM is a vulnerability management solution that doesn't just provide visibility into the risks present in your IT environment. It equips you with the reporting, automation, and integrations needed to prioritize and fix those vulnerabilities in a fast and efficient manner.

    Overview

    When it comes to risk management, the ability to detect problems is meaningless if you can't fix what you uncover. That's why we've designed InsightVM to detect risk and also arm security teams with the tools needed to overcome the communication barriers and organizational silos that can make remediation so hard.

    Rapid7 InsightVM starts with the array of capabilities you'd expect from a solution that's been named by Forrester as a leader in the last three consecutive Wave reports on Vulnerability Risk Management:

    • Get complete visibility into the presence of vulnerabilities through scan engines, the cross-product Rapid7 Insight Agent, and direct API integrations with AWS, other cloud providers, container repositories, and more.
    • Detect over 150 kinds of misconfigurations in your AWS environment.
    • Monitor your attack surface to uncover known and unknown external-facing assets.
    • Evaluate compliance with industry frameworks or custom policies.

    Once risks have been found, InsightVM helps teams take action:

    • Proprietary real-risk score helps teams prioritize the biggest threats
    • Automatically create tickets in JIRA or ServiceNow based on findings
    • Automation capabilities include integrations with SCCM and BigFix
    • Custom generated code snippets let you fix AWS misconfigurations with a few clicks
    • Goal and SLA reporting, remediation projects, and customizable dashboards help track progress over time and share results across the organization

    Highlights

    • Full Visibility: InsightVM assesses physical servers, virtual machines (such as EC2 instances), containers, and remote endpoints. Plus, since risk to your organization is more than just missing patches, it also detects misconfigurations in AWS.
    • Real-Time: Direct integrations with AWS and other cloud providers ensure data in InsightVM is always up-to-date. It also allows you to pull in all your EC2 tags for tracking, reporting, and organization.
    • Available as a Managed Service: Let our team, led by a dedicated security advisor, run InsightVM for you. The best part? You still get full access to InsightVM for those times when you want to roll up your sleeves.

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    InsightVM - Vulnerability Management

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Up to 128 Assets
    Includes unlimited scan engines and templates, up to 3 Consoles
    $3,840.00
    Managed VM
    Service terms and coverage to be defined in Private Offer
    $1,000,000.00
    Custom Pricing
    Custom Pricing w/ terms and coverage to be defined in Private Offer
    $1,000,000.00

    Vendor refund policy

    Please see the seller website for refund details.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Rapid7 Customer Support services provide rapid resolution of issues. We include Customer Portal Support, 24 hour vulnerability service level agreement, 24 hour incident response time, and a reliable testing guarantee. www.rapid7.com/for-customers 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Industrial IoT, Application Servers

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Vulnerability Detection
    Comprehensive scanning across physical servers, virtual machines, containers, and remote endpoints with detection of over 150 types of misconfigurations
    Cloud Integration
    Direct API integrations with AWS, cloud providers, container repositories for real-time asset discovery and risk assessment
    Risk Prioritization
    Proprietary real-risk scoring mechanism to help teams identify and prioritize the most critical security threats
    Automated Remediation
    Automatic ticket creation in JIRA and ServiceNow, with custom code snippets for fixing AWS misconfigurations
    Compliance Evaluation
    Capability to assess compliance with industry frameworks and custom security policies through comprehensive reporting mechanisms
    Vulnerability Detection
    Real-time vulnerability assessment and prioritization across hybrid IT environments
    Cloud Scanning
    Cloud context-aware scanning with pre-approved scanner for AWS EC2 infrastructure
    Asset Discovery
    Comprehensive inventory and visibility of global IT infrastructure and assets
    Security Integration
    Unified cloud-based platform combining discovery, assessment, detection, and response capabilities
    Hybrid Environment Support
    Seamless vulnerability management across diverse IT infrastructure including cloud and on-premises systems
    Vulnerability Detection Coverage
    Comprehensive vulnerability scanning with support for over 76,000 vulnerabilities and 186,000 security plugins
    Cloud Asset Assessment
    Agentless continuous discovery and assessment of EC2 instances without requiring agent installation or credential management
    Security Configuration Analysis
    Built-in compliance profiles with risk-based scoring to prioritize security threats and vulnerabilities
    Vulnerability Disclosure Tracking
    Real-time detection and response capabilities for newly disclosed zero-day vulnerabilities
    Hybrid Environment Support
    Unified vulnerability management and cloud security posture management for diverse infrastructure environments

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    1 AWS reviews
    |
    90 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Anusha Sadasivani

    Rapid deployment and user-friendly architecture streamline vulnerability management but customer support response needs improvement

    Reviewed on May 22, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We are still using Rapid7 InsightVM .

    I personally still use Rapid7 InsightVM .

    We use Rapid7 InsightVM for vulnerability scanning. It supports both agent-based and agentless scanning, which is part of our vulnerability management strategy.

    What is most valuable?

    The agentless scan in Rapid7 InsightVM is effective and represents the functionality I primarily work with. The risk scoring system in Rapid7 InsightVM is another valuable feature. When comparing to the main competitor QualysGuard, Rapid7 InsightVM is more preferable for me.

    What needs improvement?

    Customer support in Rapid7 InsightVM could be improved. The response time needs improvement.

    For how long have I used the solution?

    I have performed scans and explored the components of the product over the last three to four years.

    What do I think about the stability of the solution?

    I would rate the stability of Rapid7 InsightVM as seven out of ten.

    What do I think about the scalability of the solution?

    Rapid7 InsightVM rates approximately 8.5 for scalability. Rapid7 InsightVM is recommended for large-scale companies with more than 30,000 users.

    How are customer service and support?

    The response time for customer service needs improvement.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    My first tool was QualysGuard, which had more than 100,000 users. QualysGuard is more technical and problematic when implementing things, making it not as easy to use as Rapid7 InsightVM.

    How was the initial setup?

    Setup for Rapid7 InsightVM was simple. It was not complex because I had previous experience with Rapid7 when it was Nexpose.

    What's my experience with pricing, setup cost, and licensing?

    I would rate the pricing for Rapid7 InsightVM as eight out of ten.

    Which other solutions did I evaluate?

    QualysGuard is more challenging if you are not proficient in technical or environmental aspects, making deployment difficult. With Rapid7 InsightVM, the deployment process is more user-friendly.

    What other advice do I have?

    I would recommend Rapid7 InsightVM for large-scale companies. I can recommend it to other users. Overall, I rate Rapid7 InsightVM eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    FurqanLatif

    Offers robust compliance features but needs improved automation in remediation

    Reviewed on May 12, 2025
    Review provided by PeerSpot

    What is our primary use case?

    The main use case is the vulnerability assessment of their assets. Assets include Windows or Linux platforms. This is the only use case. They want to highlight and identify vulnerabilities in their platform to remediate them. For the remediation part, they want to integrate their IT teams with the Rapid7 InsightVM  platform so their IT team can get insights into the vulnerabilities, remediate them, and update over the same platform. These are the functionalities of their Rapid7 InsightVM  solution.

    What is most valuable?

    The most valuable feature of the Rapid7 InsightVM solution is the Live Risk Score. It provides dynamic Live Risk Scoring of the assets. Vulnerabilities can be classified between most critical and less critical vulnerabilities, which are dynamically updated in their dashboard. This is the most interesting and valuable feature from my perspective.

    It provides different compliance reports regarding PCI DSS, GDPR, and HIPAA. For compliance, it is a good solution for customers, and in this domain there is no improvement required for Rapid7 InsightVM.

    What needs improvement?

    The automation capability remediation needs improvement. The current process requires manually telling IT teams to remediate vulnerabilities, and then they update the status of these vulnerabilities in the platform. This basic feature that Rapid7 calls an automated remediation process is actually manual. We can update the status of vulnerabilities in the Rapid7 InsightVM platform and collectively see how many vulnerabilities we have identified and how many are remediated by our IT team.

    More automation in the remediation feature is a basic demand from many customers. The remediation part and vulnerability identification of network devices or rigid devices are not currently supported by Rapid7 InsightVM. More integration and automation are the two areas Rapid7 needs to improve in their product.

    For how long have I used the solution?

    I have been working with Rapid7 InsightVM for about one and a half years.

    What do I think about the stability of the solution?

    This is a very stable solution. I rate it around eight because I have faced only one problem in the Rapid7 InsightVM solution when configuring it for a customer due to a malfunction or bug. 

    Other than that, there have been no specific issues ever recorded or noticed by my team or myself. Rapid7 continuously updates it, which is why I rate it eight out of ten.

    What do I think about the scalability of the solution?

    This is a very scalable solution that I would rate eight out of ten. Scalability in the Rapid7 InsightVM solution is straightforward. We just need to deploy multiple scanning engines for scanning the assets. If we exceed assets from 5,000 to 10,000, we need to deploy more scanning engines to scan the solutions and assets. We simply need to deploy another scan engine to make it scalable.

    How are customer service and support?

    I cannot comment specifically regarding the support part because I have never needed Rapid7 support for the InsightVM solution as it is very stable. There were no bugs or specific problems that required raising a support ticket. Their support appears good, and some of their representatives are in direct contact with me through phone numbers. Their support seems good, but I cannot provide a specific rating.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    In the Pakistan region, there are multiple customers using Rapid7 InsightVM solution, including Rapid7 Nexpose. Nexpose and InsightVM are the same solution, with the difference being cloud versus on-premises versions. The on-premises version is called Nexpose, and the cloud version is called Rapid7 InsightVM solution. Their functionalities are almost the same. In Pakistan, I have deployed this solution in more than 15 organizations, and approximately 30 plus organizations are using this solution in total.

    How was the initial setup?

    Initial setup is very easy as this is a cloud solution. We just need to create the account and use it for integration with other assets. I would rate the initial setup nine out of ten.

    What's my experience with pricing, setup cost, and licensing?

    The customers are mostly SMBs, though some enterprise organizations have also deployed the solution. This is neither a cheap nor the most expensive solution. Qualys and some other vendors are more expensive than Rapid7 InsightVM.

    Which other solutions did I evaluate?

    I have experience with the Rapid7 VMDR solution - not with other solutions. I am exploring the differences between these solutions for customer pitches.

    What other advice do I have?

    Currently, there is no AI embedded in the solution available on the website. According to Rapid7, they are working on the Sonar  project and will soon launch this project to enhance their AI capability in the solution.

    My overall rating for Rapid7 InsightVM is seven out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    SohailHyder

    Enhancing cybersecurity while resolving technical challenges

    Reviewed on Apr 09, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We are resellers of Rapid7 InsightVM  in this market. We typically recommend it to banks and manufacturing groups interested in enhancing their cybersecurity.

    What is most valuable?

    We started with a couple of Rapid7 products, including Rapid7 InsightVM , and it runs quite fine with our customers. Although some customers raised issues, we resolved them with our technical team. Customers are interested in this product as it helps heighten their cybersecurity posture. Aside from technical challenges, the products offer comparable packages and services to other vendors in the market, such as Tenable.

    What needs improvement?

    The major improvement needed is prompt support. When issues arise, the customer's satisfaction is tied to how quickly they receive a response and a resolution. There have been delays, particularly when technical issues needed escalation, and we had to coordinate with business personnel to address them. Improving this area would be beneficial for Rapid7 InsightVM.

    For how long have I used the solution?

    I have been dealing with Rapid7 InsightVM for about three to four years.

    What do I think about the stability of the solution?

    There have been some challenges, especially with support response times, which affect stability. However, the product itself runs fine.

    What do I think about the scalability of the solution?

    Integration with other tools has been fine, with no major issues reported. We did not face any specific equipment or device that could not be integrated.

    How are customer service and support?

    Customer service needs significant improvement. There are delays in support response times, and support is not available promptly, especially when issues are escalated to another region.

    How would you rate customer service and support?

    Negative

    How was the initial setup?

    The initial setup was straightforward. We train our technical team before undertaking deployment, ensuring smoother setups.

    What was our ROI?

    The return on investment is something the customers evaluate themselves. Since it is a subscription-based service, they do not own hardware, and it fits within their budgetary requirements.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is reasonable and competitive compared to other solutions in the market. Customers are generally satisfied and do not ask for drastic price reductions during renewals.

    Which other solutions did I evaluate?

    Tenable and Invicti  are also doing good work here. The market is active with various players.

    What other advice do I have?

    I would rate Rapid7 InsightVM a six out of ten. Improvements in support responsiveness are crucial. Customers like Habib Bank faced delays, leading them to switch to other vendors. Addressing these support issues could enhance the product's effectiveness.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Mahmoud Elhamaymy

    Reliable scanning and integration strengthen security infrastructure

    Reviewed on Dec 30, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We are working in a region where all the regulations require security solutions to be implemented as on-premises solutions. We cannot use any cloud providers or vendors proposing services in a SaaS model. We use InsightVM  as an on-premises solution for vulnerability management practices.

    How has it helped my organization?

    InsightVM  provides a reliable and efficient solution with a very organized GUI, excellent ease of use, and reliable vulnerability scanning. The credential scan is a reliable feature, and everything about the product works well.

    What is most valuable?

    InsightVM has a very organized GUI with ease of use. The vulnerability scans are reliable, and the credential scan is a beneficial feature. The solution is efficient and trustworthy. It's based on the CVSS risk scoring system, which is well-recognized and effective. The integration capabilities through APIs allow easy integration with existing security infrastructure.

    What needs improvement?

    The product's documentation could be enhanced with clearer and more detailed instructions. Having the ability to build our own audit file, similar to a feature in Tenable, would be beneficial. This would provide a significant advantage for users.

    For how long have I used the solution?

    We have been using InsightVM for approximately four to five years.

    What do I think about the stability of the solution?

    InsightVM is a very stable product. We have not faced any issues with stability, and I would rate it a nine out of ten.

    What do I think about the scalability of the solution?

    The solution is very scalable. According to the environment requirements, we can scale the solution as needed.

    How are customer service and support?

    The customer service deserves an eight out of ten rating. The only issue is the response time, likely due to the time region differences. Sometimes support requests coincide with holidays in their support region, causing slight delays.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup was very simple and straightforward.

    What about the implementation team?

    Our customers usually come to our company to purchase the solution, and we communicate with the vendor as one of the largest local partners. We provide the solution and professional services to customers.

    Which other solutions did I evaluate?

    I also work with Tenable. In my opinion, Tenable is preferable because it offers fast updates in terms of its vulnerability database and allows for extensive customization. The ability to customize audit files is a significant benefit.

    What other advice do I have?

    I rate InsightVM an overall eight out of ten. It is a reliable product, and I can recommend it to other users. The integration with existing infrastructure is achievable, and with a little talent in coding, you can achieve the integration easily.

    Which deployment model are you using for this solution?

    On-premises
    reviewer2026317

    Seamless integration for enhanced vulnerability management while offering good reliability

    Reviewed on Dec 17, 2024
    Review provided by PeerSpot

    What is our primary use case?

    I find Rapid7 InsightVM  pretty useful since we are running it on every asset our company has. We are conducting authenticated scans. This is not just getting exposure from outside, but understanding vulnerabilities internally.

    What is most valuable?

    The connectivity provided by Rapid7 InsightVM  is valuable. We have integrated our SIEM  solutions and antivirus with each other through Rapid7. It allows for a lifecycle connection among different solutions. We are using it with CMDB  for tagging critical devices. However, the primary purpose remains running vulnerability scans.

    What needs improvement?

    The platform could be more intuitive and user-friendly. I cannot comment on technical specifics as it's like a black box, but improvements in user experience would be beneficial.

    For how long have I used the solution?

    I joined my current company two and a half years ago, and they already had this solution.

    What do I think about the stability of the solution?

    The stability of Rapid7 InsightVM is excellent. I would rate it as a ten out of ten.

    What do I think about the scalability of the solution?

    Rapid7 InsightVM is suitable for large enterprises and scales well for companies with over 1,000 users.

    How are customer service and support?

    I haven't interacted with Rapid7's technical support.It is crucial for tech support to resolve issues as quickly as possible, ideally available 24/7. Even if the support is good, there's always room for improvement, so I would rate them around a five because every company can improve.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I have recommended Tenable Nessus , which I used at Bitdefender and in previous roles. Tenable Nessus  offered a pay-per-asset option that I found economical.

    How was the initial setup?

    The initial setup can be simple or complex, depending on whether you're conducting authenticated or unauthenticated scans.

    What's my experience with pricing, setup cost, and licensing?

    Rapid7 InsightVM is expensive, possibly one of the highest in pricing among similar products.

    Which other solutions did I evaluate?

    I have experience with Tenable Nessus and have recommended it for its cost-effectiveness.

    What other advice do I have?

    Overall, I would recommend Rapid7 InsightVM to other users.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    View all reviews