Talk to us
by Rapid7TechBag Intel Page

Rapid7 Managed Threat Complete

A 24/7 SOC with the vulnerability programme included — Managed Threat Complete commits contractually to 15 minutes to begin a critical investigation and bundles unlimited InsightVM scanning and unlimited incident response into the per-asset price. No pure-play MDR vendor does that.

15-min critical SLA, contractualVM + unlimited IR bundledNo India data region

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Gartner Peer Insights
315 reviews in the MDR market
4.6 / 5
Frost Radar 2025
assessed against 120 MDR vendors
Leader
PeerSpot
17 reviews; ranked 8th in category
4.3 / 5
G2
only 7 reviews on the MDR listing
4.4 / 5

Data residency & processing — confirm before the PoC

Where data lives

Offshore — there is NO India region

Rapid7’s platform runs in five regions: the United States, Canada, Europe, Japan and Australia. Verified against Rapid7’s own trust page. For an Indian entity that means Tokyo or further afield, and it is the constraint most likely to decide this purchase.

Where it is processed

Rapid7’s cloud; SOC has no contractual geography

Detection and analyst work happen in Rapid7’s cloud. The Pune Global Capability Centre, opened April 2025, is a real SOC delivery node — but Rapid7’s contracts specify no geography, so there is no guarantee your alerts are handled in India, and people in India are not the same thing as data in India.

13-month retention exceeds CERT-In’s 180 days on duration and fails on location — two different tests, and only one is satisfied. One nuance that cuts against our own interest in selling you a second system: CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs remain producible in reasonable time, and many organisations keep source logs on-premises and treat this platform as a copy. Where it becomes unambiguous is sectoral — IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, see InsightVM, where the console is yours, or an India-hosted alternative.

Quick answer

Managed Threat Complete is Rapid7's managed detection and response service: a 24/7 security operations centre that monitors your environment, investigates alerts, and tells you what to do about them. It runs on Rapid7's own SIEM, so this is not a vendor-neutral service that plugs into whatever you already own — Incident Command is the platform underneath, and third-party telemetry is ingested into it. What genuinely distinguishes it from other MDR services is the bundle. The per-asset price includes unlimited InsightVM vulnerability scanning and unlimited incident response with no retainer and no hour cap. No pure-play MDR vendor bundles vulnerability management this way, so for an organisation that needs both a managed SOC and a vulnerability programme, buying them together here is frequently cheaper than buying them separately anywhere. The service commitments are contractual rather than aspirational, which is rare enough to be worth stating: Rapid7's published scope of service commits to beginning investigation of a critical alert within fifteen minutes, high within one hour, and to telephoning you within thirty minutes of identifying a medium or high incident. Those SLAs are identical across all three tiers — you do not buy a faster clock by upgrading. Three tiers exist, Essential, Advanced and Ultimate, and the differences are narrower than the marketing implies: what changes is how many third-party products are monitored, whether you get a named cybersecurity advisor rather than a support pool, and whether you get Velociraptor forensics tooling and the breach protection warranty, both Ultimate only. Two constraints deserve prominence. The Rapid7 Agent is mandatory even if a third-party EDR performs containment, and assets without it are excluded from threat hunts and investigations entirely. And containment is narrow — Active Response quarantines endpoints and disables users, and that is the complete list. For Indian buyers there is no India data region, so your logs sit offshore, which does not satisfy CERT-In's 180-day in-India retention rule. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Rapid7 Managed Threat Complete — the SIEM. The other pillars:

Quick facts

30-second orientation
Category
Managed detection and response service
Vendor
Rapid7 — CEO Wael Mohamed (June 2026)
Tiers
Essential · Advanced · Ultimate
SOC coverage
24/7/365 on all tiers
Critical investigation SLA
Begins within 15 minutes — contractual
Notification
Phone call within 30 minutes of identifying an incident
SLAs by tier
IDENTICAL — upgrading does not buy a faster clock
Log retention
13 months, all tiers
Bundled
Unlimited InsightVM scanning — unique in MDR
Incident response
Unlimited, no retainer or hour cap — but remote only
Agent
Rapid7 Agent MANDATORY — no exceptions
Containment scope
Quarantine endpoint · disable user. That is the full list
Data residency
NO India region — logs held offshore
Data processing
Rapid7 SOC works from Boston, Prague and Pune; no contractual geography
Buy in India via
TechBag — INR, GST, tier and asset band negotiated
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

A 24/7 managed SOC running on Rapid7’s own SIEM, with unlimited InsightVM scanning and unlimited incident response bundled into the per-asset price.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolManaged Threat Complete
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownPer monitored asset — grows with the estate
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Monitors and investigates

Rapid7 SOC

Managed analyst team

A 24/7/365 operation staffed from Boston, Prague and Pune, structured as a tactical operations team, SOC pods and a dedicated incident response team. Analysts work inside Incident Command and Log Search. Note that Rapid7's contracts specify no geography, so there is no contractual guarantee of which location handles your alerts, or that any of them is in India.

02
Collects and detects

Incident Command

Underlying SIEM

The service runs on Rapid7's own SIEM, included in the price. All detection, investigation and analyst work happens here. Third-party security tools feed into it, but Rapid7 works only within its own platform — its contracts state it will not close alerts in third-party systems by manual process or API. You keep the SIEM if you leave the service.

03
Enables hunting and response

Rapid7 Agent

Mandatory endpoint sensor

Required on every asset you want covered, even when a third-party EDR handles containment. This is not optional: Rapid7's scope of service excludes assets without the agent from attacker behaviour analytics, from threat hunts, and from alert validation and incident investigation. Eighty percent agent deployment is required before the security posture assessment runs.

04
Quarantines and disables

Active Response

Automated containment

The automated containment mechanism, and its scope is exactly two actions: quarantine an endpoint and disable a user account. Nothing else. It can execute through a third-party EDR such as CrowdStrike, SentinelOne, Carbon Black or Microsoft Defender, but only one containment tool may be configured. Un-quarantining is your responsibility, and you own the exclusion lists.

05
Collects forensic evidence

Velociraptor

Hosted DFIR tooling

Rapid7's open-source digital forensics and incident response tool, hosted and embedded in the Ultimate tier only. It collects forensic artefacts from endpoints during an investigation. Worth understanding clearly: this is tooling, not a bank of forensic consulting hours. Rapid7's contracts contain no included DFIR hours, and all incident response is remote.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Telemetry

Endpoint and log collection

Gathers endpoint activity and log data from across the estate into Rapid7's SIEM for analyst review.

Collect
Telemetry

Third-party product monitoring

Ingests alerts from your existing security tools — two products at Advanced and four at Ultimate.

Collect
Telemetry

Cloud and identity sources

Monitors cloud platforms, Microsoft 365 and identity providers alongside on-premises infrastructure.

Detect
Coverage

24/7/365 SOC monitoring

Keeps human analysts watching your environment continuously, including nights, weekends and Indian public holidays.

Detect
Detection

Alert validation and triage

Investigates raised alerts and separates genuine incidents from noise before contacting you.

Detect
Detection

Proactive threat hunting

Searches for attacker activity that has not triggered an alert, across assets carrying the Rapid7 Agent.

Detect
Detection

Attacker behaviour analytics

Applies detection content built from Rapid7's own SOC experience across its full customer base.

Detect
Intelligence

Emergent threat notification

Alerts customers when a significant new vulnerability or campaign is relevant to their environment.

Respond
Response

Active Response containment

Quarantines a compromised endpoint or disables a compromised user account automatically.

Respond
Response

Unlimited incident response

Provides incident response with no hour cap or retainer, delivered remotely with a report within ten business days.

Respond
Response

Cybersecurity advisor

Assigns a named advisor for a monthly meeting and posture guidance, at Advanced and Ultimate tiers.

Respond
Response

Bundled vulnerability management

Includes unlimited InsightVM scanning so exposure reduction runs alongside detection.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Rapid7 (official)·Overview

Rapid7 Managed Detection & Response (MDR)

The managed service, presented by Rapid7.

Rapid7 (official)·The SOC

SOC Overview — Rapid7 MDR

How the analyst team actually works.

Rapid7 (official)·Service

Discover Rapid7 Managed Detection & Response

What the service covers.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Managed Threat Complete

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

The SLAs are contractual, not marketing

Most MDR marketing talks about rapid response without committing to anything. Rapid7 publishes its scope of service, and the numbers are contractual: investigation of a critical alert begins within fifteen minutes, high within one hour, medium within twelve hours, low within forty-eight. On identifying a medium or high incident, Rapid7 emails immediately and telephones within thirty minutes. For a high-severity incident, a kickoff call happens within an hour of notification, with daily updates if it runs beyond a day, and a written incident report within ten business days. Crucially, these commitments are identical across all three tiers. You do not buy faster response by upgrading; Essential gets the same clock as Ultimate. For an Indian buyer this matters practically. CERT-In requires reporting specified incidents within six hours of noticing them. A service that contractually starts investigating within fifteen minutes and telephones within thirty gives you a realistic path to meeting that window, with documented timestamps to evidence it — though the legal duty to file remains yours alone.

02

Unlimited incident response with no retainer

Most incident response is sold as a retainer: you pre-purchase a block of hours, and when a real incident consumes them you negotiate for more during the worst week of your year. That structure creates exactly the wrong incentive, because it discourages calling for help early — and calling early is what limits damage. Rapid7 includes unlimited incident response in the Managed Threat Complete price. There is no hour cap and no retainer to draw down. If you have three incidents in a quarter, all three are covered, with a written report following within ten business days. The honest boundary is that all of it is remote. Nobody flies to your Pune data centre. For most mid-market incidents that is fine, because the work is analysis of telemetry the platform already holds. If your risk profile demands on-site forensic attendance, you need a separate arrangement, and you should scope that with an Indian DFIR provider rather than assuming this covers it.

03

Vulnerability management is bundled, not extra

This is the genuinely unusual commercial feature. The per-asset price includes unlimited InsightVM scanning. No pure-play MDR vendor — not Arctic Wolf, not Expel, not Red Canary — bundles a full vulnerability management product this way. The security logic is sound. Detection tells you when someone is attacking; vulnerability management reduces the number of ways they can. Running both on the same agent, the same asset inventory and the same risk scoring means an analyst investigating suspicious activity on a server can immediately see whether that server carries an actively exploited vulnerability, and remediation can be prioritised by what the SOC is actually seeing. Commercially it changes the comparison arithmetic. If you were going to buy MDR and vulnerability management separately, price this bundle against the pair rather than against MDR alone. For Indian buyers that combination also covers two distinct regulatory expectations at once — RBI's vulnerability assessment cadence and its 24/7 SOC monitoring expectation — under one contract.

04

Predictable per-asset pricing with unlimited ingestion

MDR services priced by data volume create the same problem as SIEM priced by data volume: better logging costs more, so teams log less and see less. Rapid7 prices Managed Threat Complete per monitored asset, with unlimited log ingestion and thirteen months of retention included at every tier. For a finance function this produces a number that behaves. Your asset count is known, changes slowly and is easy to forecast. Adding a verbose log source improves detection coverage without touching the invoice. Volume discounts begin above 500 assets. Thirteen months of retention is also more generous than most competitors include as standard, and it exceeds the twelve-month lookback many auditors expect. Note carefully that retention duration and retention location are different questions — thirteen months of data held in Tokyo does not satisfy CERT-In's requirement that 180 days of logs sit within Indian jurisdiction. Duration is not the constraint for Indian buyers; geography is.

05

The honest caveat: the agent is mandatory and containment is narrow

Two limitations are frequently missed during evaluation and both bite afterwards. First, the Rapid7 Agent is mandatory. Even if you run CrowdStrike or Microsoft Defender and that tool performs the containment, Rapid7's scope of service excludes assets without its own agent from attacker behaviour analytics, from threat hunts, and from alert validation and incident investigation. An asset without the agent is not partially covered — it is outside the service. Eighty percent agent deployment is required before the security posture assessment runs at all. If you assumed your existing EDR would satisfy the requirement, that assumption is expensive. Second, containment is exactly two actions: quarantine an endpoint, disable a user account. That is the complete list. It is not network isolation of a subnet, not blocking at the firewall, not killing a process, not disabling a service account's API keys. Only one containment tool may be configured, un-quarantining is your responsibility, and you own the exclusion lists. Reviewers on Gartner and G2 also report the SOC sometimes closes incidents without sufficient explanation.

06

The honest positioning

Managed Threat Complete is the right MDR service for a mid-market organisation that needs 24/7 coverage and a vulnerability programme, has no realistic path to staffing a SOC, and can accept its logs sitting offshore. The bundled vulnerability management genuinely changes the economics, the SLAs are contractual, and the unlimited incident response removes a perverse incentive that most retainer models create. It is the wrong choice in three situations. If Indian data localisation binds you — and for many regulated entities it does — no amount of service quality fixes the absence of an India region, and you should look at an India-hosted MDR provider instead. If you want a vendor-neutral service that works within the security tools you already own, this is not that: Rapid7 works inside its own platform and will not close alerts in third-party systems. And if you need on-site forensic attendance as part of the arrangement, this is remote-only. We sell CrowdStrike Falcon Complete, Sophos MDR and others alongside it, and where one of those fits you better we will say so before you sign.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

15 min
Contractual SLA to begin a critical investigation
MDR scope of service
30 min
Phone call after identifying a medium or high incident
MDR scope of service
13 months
Log retention on every tier
Rapid7
315 reviews
Gartner Peer Insights, MDR — rated 4.6/5
Gartner
2 actions
The complete scope of Active Response containment
MDR scope of service
80%
Agent deployment required before the posture assessment runs
Rapid7

What your Rapid7 Managed Threat Complete rollout looks like

Weeks 1–2Assess

Settle residency before anything else

Rapid7 has no India region and your logs will sit offshore. If CERT-In's 180-day in-India rule or a sectoral obligation binds your entity, establish that now — it can end the evaluation before you have spent a month on it, and it is far cheaper to learn here than during an audit.

Weeks 2–4Deploy

Plan the mandatory agent rollout

The Rapid7 Agent is required on every covered asset even if a third-party EDR does containment, and eighty percent deployment is needed before the posture assessment runs. If you already run CrowdStrike or Defender, this is a second agent and a rollout to schedule with your desktop team — budget the political cost as well as the technical one.

Weeks 3–6Evaluate

Choose the tier on advisor and forensics, not speed

The SLAs are identical across Essential, Advanced and Ultimate, so upgrading does not buy a faster clock. What changes is third-party product coverage, a named cybersecurity advisor rather than a support pool, and Velociraptor plus the breach warranty at Ultimate only. Decide on those, not on response time.

Weeks 5–10Operate

Agree containment scope and exclusions in writing

Active Response quarantines endpoints and disables users — that is the whole list. Configure your one containment tool, agree the exclusion lists, and be explicit about who un-quarantines and when. Teams that skip this discover the boundary during an incident, which is the worst possible moment.

OngoingOperate

Use the bundled InsightVM properly

Unlimited vulnerability scanning is included in the price and is routinely under-used because it arrives as a bundle rather than a purchase. Run it, wire Remediation Projects to real owners, and let the SOC's findings prioritise the fixing. This is where the commercial advantage over pure-play MDR actually materialises.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Financial Services
The SLAs are in the contract, not the brochure. Fifteen minutes to start on a critical, and they have met it.
CISO
Financial Services
Manufacturing
Bundled vulnerability scanning changed the maths entirely. We were about to buy both separately.
IT Director
Manufacturing
IT Services
Nobody told us the Rapid7 agent was mandatory on top of our existing EDR. That was a rollout we had not planned.
Security Manager
IT Services
Healthcare
Unlimited IR with no retainer meant we called them early instead of arguing internally about burning hours.
Head of Infrastructure
Healthcare
Retail
Containment is quarantine and disable-user. That is it. Read that list carefully before you assume more.
SOC Lead
Retail
Insurance
Our logs sit outside India. For our regulator that was the end of the conversation, however good the service was.
Compliance Head
Insurance
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Rapid7This page

Mid-market platform — one agent, one contract.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
Rapid7This page

Breadth over depth — that is the deliberate trade.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Rapid7 Managed Threat Complete vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionRapid7TenableQualysCrowdStrikeMicrosoft
PositionMid-market platform: exposure, SIEM and MDR on one agentThe strongest scanner in the categoryCloud-native, lowest operational overheadThe endpoint and MDR benchmarkNear-free at the margin with E5
Pricing axisPer monitored asset — not per GB ingestedPer asset, quote-ledPer asset, reported ~$199–250/yr$25–45 per endpoint/month for Falcon CompleteBundled into E5 licensing
Vulnerability managementInsightVM — published price, Active Risk scoring219,000+ plugins, dedicated OT productCloud-native, native patching includedExposure module if you already run FalconWeak on non-Microsoft OS and network devices
SIEMChallenger in the 2025 MQ — not a LeaderNot a SIEM vendorNot a SIEM vendorFalcon Next-Gen SIEMSentinel — a Leader
MDRFrost Radar Leader; VM and unlimited IR bundled inNot an MDR vendorManaged services availableFalcon Complete — the benchmarkDefender Experts
DeploymentSIEM and MDR cloud-only; InsightVM console is yoursCloud or on-premisesCloud-native onlyCloud-native onlyAzure-hosted
India data residencyNO India region — InsightVM console is the exceptionRegion options; verify for your productIndia platform, Pune-engineeredVerify per productAzure India regions
The thing to plan aroundNo India region; agent mandatory; FY26 guided downPriced above Rapid7 at most tiersSupport quality rated well; scanning less deepThe most expensive option hereOnly economic if you already hold E5
Best fitMid-market wanting VM, SIEM and MDR from one vendorDeepest scanning, or operational technologyLowest operational overhead, native patchingBest-in-class endpoint and managed responseMicrosoft-standardised estates with E5
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Rapid7 Managed Threat Complete fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Managed Threat Complete if…

  • You need a 24/7 SOC and a vulnerability programme, and want them in one contract
  • Contractual SLAs matter to you — 15 minutes to begin a critical investigation
  • Unlimited incident response with no retainer changes how early you call for help
  • Your logs may legally sit offshore — if not, look at an India-hosted MDR instead

Choose Tenable if…

  • You need the deepest scanning coverage — 219,000+ plugins
  • You have operational technology or industrial environments
  • Dashboard flexibility and scan efficiency are your priorities

Choose Qualys if…

  • You want no console to host, patch and size — it is cloud-native
  • Native patch management matters rather than integrating out to SCCM
  • An India platform answers your residency question directly

Choose CrowdStrike if…

  • You already run Falcon, so there is no second agent to deploy
  • You want best-in-class endpoint detection and managed response
  • You can accept the premium — $25–45 per endpoint per month

Choose Microsoft if…

  • You hold E5 licences, which changes the economics entirely
  • Your estate is standardised on Microsoft 365 and Azure
  • Azure India regions answer a residency obligation Rapid7 cannot

Rapid7 Managed Threat Complete is one of 13 managed detection & response products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Rapid7 meters per monitored asset; most rival SIEMs meter per gigabyte ingested. That is the comparison worth modelling, because it is the one that decides the deal. Move both sliders: the asset count you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number — Rapid7 is quote-only — it is the shape: per-asset cost tracks headcount and hardware, which change slowly, while per-GB cost tracks how much you log, which only ever goes up. Indicative Indian-market rates.

750
25010,000
150
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. The structural argument for per-asset pricing is not that it is always cheaper — it is that it stops the bill punishing you for collecting more, which is what makes teams under-log and miss things. Weigh that against the residency constraint before you decide.

An ingest-metered SIEM, at your GB/day
₹4,50,00,000
Saved vs an ingest-priced SIEM’s user meter
₹4,08,29,250
₹20,41,46,250 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Managed Threat Complete is quote-only. Buyer-reported pricing clusters around $15–22 per asset per month, midpoint near $17, with a 500-asset minimum commonly applied — directional rather than official, since Rapid7 does not stand behind those figures. The comparison mistake we see most often is pricing this against MDR alone: it bundles unlimited InsightVM scanning and unlimited incident response with no retainer, so price it against that pair. Note also that the SLAs are identical across all three tiers, so you are never buying a faster clock by upgrading. TechBag quotes in INR with GST.

Essential

Quoteper asset/month

The same SLAs as Ultimate

  • 15-min critical investigation start — contractual, every tier
  • Unlimited InsightVM scanning included
  • Unlimited incident response, no retainer or hour cap

Advanced

Quoteper asset/month

Adds an advisor

  • Two third-party products monitored
  • A named cybersecurity advisor rather than a support pool
  • Monthly meeting and posture guidance

Ultimate

Quoteper asset/month

Forensics and warranty

  • Four third-party products monitored
  • Velociraptor DFIR tooling — tooling, not consulting hours
  • Breach protection warranty

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Residency

Does CERT-In's in-India log rule or a sectoral obligation bind us? Rapid7 has no India region.

2
Agent

Have we planned a Rapid7 Agent rollout even though we already run another EDR? It is mandatory.

3
Coverage

Which assets will NOT carry the agent, and do we accept they are outside the service entirely?

4
Containment

Have we read that Active Response is quarantine-endpoint and disable-user, and nothing else?

5
Containment tool

Which single third-party EDR will we configure, and who owns un-quarantining?

6
Tier

Are we choosing the tier on advisor and forensics rather than on response speed? The SLAs are identical.

7
On-site

Do we need on-site forensic attendance? All Rapid7 incident response is remote.

8
Bundle

Are we pricing this against MDR plus vulnerability management, not against MDR alone?

9
Third-party

Do we expect alerts closed in our other tools? Rapid7 works only inside its own platform.

10
Exit

Understood that we keep Incident Command if we leave the service?

FAQ

Questions buyers ask

More than most MDR services, and the specifics are worth reading rather than trusting to a summary. Rapid7 publishes a scope of service, and the numbers in it are contractual: investigation of a critical alert begins within fifteen minutes, high within one hour, medium within twelve hours, low within forty-eight. On identifying a medium or high incident, Rapid7 emails immediately and telephones within thirty minutes. For a high-severity incident there is a kickoff call within an hour of that notification, daily updates if it runs beyond a day, and a written incident report within ten business days. Coverage is 24/7/365. The single most useful thing to understand is that these SLAs are identical across Essential, Advanced and Ultimate. You cannot buy a faster clock by upgrading, which means the tier decision should be made on other grounds entirely — third-party product coverage, whether you get a named cybersecurity advisor rather than a support pool, and whether you need Velociraptor forensics tooling and the breach protection warranty, which are Ultimate only. For an Indian buyer these timings map usefully onto CERT-In's six-hour incident reporting requirement: a service that contractually begins investigating within fifteen minutes and telephones within thirty gives you a realistic path to filing inside the window, with timestamps to evidence it. One thing no MDR service can do, and any vendor claiming otherwise is misleading you: the legal duty to report to CERT-In sits with your Indian entity and is, in CERT-In's own words, neither transferable nor capable of being indemnified away.

Ready to evaluate Rapid7 Managed Threat Complete?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.