- Best for
- Mid-market and enterprise teams that want MDR, SIEM and vulnerability context in one Rapid7-led workflow
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
Your team still owns
- Scoping protected endpoints, servers, networks and third-party event sources
- Maintaining telemetry quality, agent coverage and third-party alert integrations
- Defining Active Response permissions, exclusions and approval rules
- Handling business remediation, recovery and changes outside Rapid7-managed workflows
- Validating package tier, add-ons, renewal terms and private-offer pricing
Pricing
| Line | Figure |
|---|---|
| Published price | AWS Marketplace lists a 12-month Managed Threat Complete Essential contract from $73,000. |
| Billing model | Per-asset, Tiered, Custom |
| Contract | 12 months |
| Onboarding | Rapid7 service material says MDR monitoring starts detecting threats within the first 60 days of onboarding. |
Tradeoffs
Works well
- Documented containment actions make it stronger than alert-only or advice-only MDR
- Rapid7's exposure-management context can help prioritize which alerts and weaknesses matter most
- Public AWS Marketplace pricing gives buyers a better starting point than quote-only MDR profiles
- Works well for buyers that want Rapid7 SIEM, vulnerability context and managed response in one service family
Watch out for
- The service is centered on Rapid7 SIEM, so buyers committed to another SIEM should verify workflow fit
- Third-party alert response is bounded by supported integrations, source-system APIs and configured data flow
- Public package pages do not expose every entitlement boundary, add-on cost or response authority rule
- Community discussion includes concerns about pricing, automation depth, portal workflow and integration friction
- SOC locations are not published clearly enough to claim regional coverage in this draft
What buyers say
Alert noise
High
Transparency
Mixed
Customers like
- Reviewers commonly value 24/7 monitoring, analyst support and investigation help
- Customers point to useful SIEM visibility, vulnerability context and long retention
- PeerSpot and G2 reviews describe Rapid7 as useful for both mid-market and enterprise teams
Watch out for
- MDR-specific G2 review volume is small
- Community discussion raises pricing, automation and portal workflow concerns
- Third-party alert handling can be limited by source-system APIs and data-flow reliability
Recurring complaints that the platform is aggressive and buyers constantly battle false positives.
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which containment and remediation actions can Rapid7 execute in our environment without waiting for approval?
- Which third-party tools will Rapid7 only triage inside Rapid7 SIEM, and which systems receive bidirectional updates?
- How do Essential, Advanced and Ultimate differ for threat hunting, third-party monitoring, advisors, Velociraptor and breach protection?
Integrations
Editorial notes
Why contain threats
Rapid7 publishes Active Response documentation showing SOC analysts can isolate endpoints and disable compromised user accounts through supported agents and EDR tools. That supports the Contain threats lane, but not full SOC ownership.
Not a neutral managed SIEM
The public MDR page says the service is delivered on Rapid7's SIEM and uses Rapid7 platform context. Enterprise MDR can ingest custom event sources, but the normal operating model still centers Rapid7's platform rather than any customer-owned SIEM.
Third-party boundary
Rapid7 documentation says the SOC can triage, investigate and respond to selected third-party security alerts within Rapid7 SIEM, while also noting that Rapid7 does not control disruptions in third-party data flow or universally close alerts in source systems.
Pricing boundary
Rapid7 publishes package names and asset-based pricing logic, while AWS Marketplace exposes public 12-month contract starting prices. The profile uses those marketplace amounts as indicative procurement signals and keeps final pricing quote-dependent.
Review caveat
Public customer sentiment is mostly favorable on analyst quality, visibility and bundled vulnerability context, but review volume for the MDR-specific G2 surface is small and community comments include pricing, automation, portal and integration caveats.