Rapid7 MDR is a managed detection and response service from Rapid7 that provides 24/7 SOC monitoring and incident response across endpoints, network, identity, cloud and email. Pricing is quote-only, based on the number of endpoints, servers and networks protected, with no published per-unit figure.
Listing updated . Checked by MSP Software .
Rapid7 MDR is a managed detection and response service from Rapid7 for organisations that want a staffed security operations centre rather than a self-run detection tool. It covers endpoint telemetry (using Rapid7's own agent alongside the open-source Velociraptor digital forensics tooling), network monitoring, identity and access monitoring, email threat detection and cloud coverage, and ingests third-party telemetry through what Rapid7 calls an open extension library, which supports 190+ integrations including Microsoft and AWS environments. The service is sold in three named tiers: Essentials, which covers 24x7x365 SOC monitoring, incident response, vulnerability scanning, SOAR automation and 13-month data retention; Advanced, which adds third-party ecosystem monitoring, a dedicated cybersecurity advisor and monthly posture reviews; and Ultimate, which adds expanded monitoring, a breach protection warranty, embedded digital forensics tooling, vulnerability prioritisation guidance and proactive remediation coaching.
Rapid7 does not publish specific prices for MDR. Pricing is asset-based, meaning it is quoted against the number of endpoints, servers and networks an organisation wants protected rather than data volume or incident count, and a prospective buyer has to request a demo to get a figure (checked September 2026). There is no separate free trial for MDR itself; the free trials Rapid7 advertises elsewhere on its site are for its Attack Surface Management and InsightVM products, not for MDR. Rapid7 also runs a dedicated MDR variant aimed at organisations already using Microsoft security tooling, and a partner programme (PACT for Service Providers) aimed at MSSPs and resellers, which suggests the service is designed to be sold and delivered through a partner channel as well as direct.
Rapid7 is a publicly traded cybersecurity company (Nasdaq: RPD), founded in 2000 and headquartered in Boston, Massachusetts. An MSP or MSSP considering Rapid7 MDR should confirm during a demo which tier includes the specific coverage they need (third-party ecosystem monitoring and a dedicated advisor only start at the Advanced tier), what counts as an asset for pricing purposes, and whether their existing endpoint, identity or email tools are on Rapid7's current extension library list, since Rapid7's own MDR pages do not spell out ticketing or PSA integration for service delivery.
Rapid7 MDR suits an MSSP or larger MSP that wants a named, tiered managed SOC service with a defined upgrade path (Essentials to Ultimate) rather than a single flat offering, and that is comfortable with quote-only, asset-based pricing rather than a published rate card. It is worth comparing against Sophos MDR, Arctic Wolf and Huntress, which compete in the same managed-SOC space and are more commonly seen in smaller MSP stacks. Because Rapid7 does not publish numbers or a PSA/ticketing integration on its own pages, get a written quote against your actual endpoint and server count, ask exactly what 'asset' means for billing, and confirm coverage and ticket handoff for your specific tools before signing.
| Feature | Supported | Note |
|---|---|---|
| 24-hour human-staffed SOC | yes | 24x7x365 SOC monitoring at every tier. |
| Managed threat response and isolation | yes | Incident response included from the Essentials tier; breach protection warranty at Ultimate. |
| Own endpoint telemetry agent | yes | Own endpoint agent plus the open-source Velociraptor tool for digital forensics. |
| Identity threat detection | yes | Identity and access monitoring listed as a coverage area. |
| Network monitoring | yes | Network-based threat detection listed as a coverage area. |
| Microsoft 365 monitoring | unknown | Rapid7 lists a Microsoft-focused MDR variant and Microsoft as a supported ecosystem, but M365-specific monitoring is not spelled out on the pages checked. |
| Monthly threat reporting | yes | Monthly posture reviews from the Advanced tier up. |
| PSA integration for ticketing | unknown | Not documented on the vendor pages checked. |
| Multi-tenant console | unknown | Rapid7 runs a service-provider partner programme (PACT) aimed at MSSPs, but a multi-tenant console is not confirmed on the pages checked. |
| Works with third-party EDR | yes | Ingests third-party telemetry through an extension library supporting 190+ integrations. |
| Dedicated incident response | yes | Dedicated incident response included, with a breach protection warranty at the Ultimate tier. |
Rapid7 MDR is priced by quote rather than a published rate card. Rapid7 says pricing is asset-based, meaning it is set against the number of endpoints, servers and networks being protected rather than data volume or number of incidents, and a demo request is needed to get a figure (checked September 2026). This differs from a per-endpoint list price you can look up directly, so budgeting requires an actual quote against your environment.
Essentials covers 24x7x365 SOC monitoring, incident response, vulnerability scanning, SOAR automation and 13-month data retention. Advanced adds third-party ecosystem monitoring, a dedicated cybersecurity advisor and monthly posture reviews on top of Essentials. Ultimate adds expanded monitoring, a breach protection warranty, embedded digital forensics tooling and vulnerability prioritisation guidance on top of Advanced.
No. Rapid7 MDR is the managed service, staffed by Rapid7's SOC, while the underlying detection and analytics technology sits in Rapid7's own platform (branded InsightIDR historically, shown as 'Incident Command' in Rapid7's current product navigation). An organisation can buy the underlying technology as a self-run product separately from buying the managed MDR service, which includes SOC monitoring and incident response on top.
Rapid7 does not advertise a free trial for MDR itself; access is via a demo request rather than a self-service trial. Rapid7 does offer free trials for other products, including Attack Surface Management and InsightVM, but those are separate products from the managed MDR service.
Yes. Rapid7 MDR ingests third-party telemetry through what it calls an open extension library, supporting 190+ integrations, and names Microsoft and AWS environments as supported ecosystems. Rapid7 also sells a Microsoft-focused MDR variant for organisations standardised on Microsoft security tooling. An MSP should confirm its specific tools are on Rapid7's current extension list before buying.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review