A 24/7 SOC with the vulnerability programme included — Managed Threat Complete commits contractually to 15 minutes to begin a critical investigation and bundles unlimited InsightVM scanning and unlimited incident response into the per-asset price. No pure-play MDR vendor does that.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Where data lives
Offshore — there is NO India region
Rapid7’s platform runs in five regions: the United States, Canada, Europe, Japan and Australia. Verified against Rapid7’s own trust page. For an Indian entity that means Tokyo or further afield, and it is the constraint most likely to decide this purchase.
Where it is processed
Rapid7’s cloud; SOC has no contractual geography
Detection and analyst work happen in Rapid7’s cloud. The Pune Global Capability Centre, opened April 2025, is a real SOC delivery node — but Rapid7’s contracts specify no geography, so there is no guarantee your alerts are handled in India, and people in India are not the same thing as data in India.
13-month retention exceeds CERT-In’s 180 days on duration and fails on location — two different tests, and only one is satisfied. One nuance that cuts against our own interest in selling you a second system: CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs remain producible in reasonable time, and many organisations keep source logs on-premises and treat this platform as a copy. Where it becomes unambiguous is sectoral — IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, see InsightVM, where the console is yours, or an India-hosted alternative.
Quick answer
This page covers Rapid7 Managed Threat Complete — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A 24/7 managed SOC running on Rapid7’s own SIEM, with unlimited InsightVM scanning and unlimited incident response bundled into the per-asset price.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Managed Threat Complete |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Per monitored asset — grows with the estate |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A 24/7/365 operation staffed from Boston, Prague and Pune, structured as a tactical operations team, SOC pods and a dedicated incident response team. Analysts work inside Incident Command and Log Search. Note that Rapid7's contracts specify no geography, so there is no contractual guarantee of which location handles your alerts, or that any of them is in India.
The service runs on Rapid7's own SIEM, included in the price. All detection, investigation and analyst work happens here. Third-party security tools feed into it, but Rapid7 works only within its own platform — its contracts state it will not close alerts in third-party systems by manual process or API. You keep the SIEM if you leave the service.
Required on every asset you want covered, even when a third-party EDR handles containment. This is not optional: Rapid7's scope of service excludes assets without the agent from attacker behaviour analytics, from threat hunts, and from alert validation and incident investigation. Eighty percent agent deployment is required before the security posture assessment runs.
The automated containment mechanism, and its scope is exactly two actions: quarantine an endpoint and disable a user account. Nothing else. It can execute through a third-party EDR such as CrowdStrike, SentinelOne, Carbon Black or Microsoft Defender, but only one containment tool may be configured. Un-quarantining is your responsibility, and you own the exclusion lists.
Rapid7's open-source digital forensics and incident response tool, hosted and embedded in the Ultimate tier only. It collects forensic artefacts from endpoints during an investigation. Worth understanding clearly: this is tooling, not a bank of forensic consulting hours. Rapid7's contracts contain no included DFIR hours, and all incident response is remote.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Gathers endpoint activity and log data from across the estate into Rapid7's SIEM for analyst review.
Ingests alerts from your existing security tools — two products at Advanced and four at Ultimate.
Monitors cloud platforms, Microsoft 365 and identity providers alongside on-premises infrastructure.
Keeps human analysts watching your environment continuously, including nights, weekends and Indian public holidays.
Investigates raised alerts and separates genuine incidents from noise before contacting you.
Searches for attacker activity that has not triggered an alert, across assets carrying the Rapid7 Agent.
Applies detection content built from Rapid7's own SOC experience across its full customer base.
Alerts customers when a significant new vulnerability or campaign is relevant to their environment.
Quarantines a compromised endpoint or disables a compromised user account automatically.
Provides incident response with no hour cap or retainer, delivered remotely with a report within ten business days.
Assigns a named advisor for a monthly meeting and posture guidance, at Advanced and Ultimate tiers.
Includes unlimited InsightVM scanning so exposure reduction runs alongside detection.
Endpoint protection, XDR and Security Copilot.
The managed service, presented by Rapid7.
How the analyst team actually works.
What the service covers.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
Most MDR marketing talks about rapid response without committing to anything. Rapid7 publishes its scope of service, and the numbers are contractual: investigation of a critical alert begins within fifteen minutes, high within one hour, medium within twelve hours, low within forty-eight. On identifying a medium or high incident, Rapid7 emails immediately and telephones within thirty minutes. For a high-severity incident, a kickoff call happens within an hour of notification, with daily updates if it runs beyond a day, and a written incident report within ten business days. Crucially, these commitments are identical across all three tiers. You do not buy faster response by upgrading; Essential gets the same clock as Ultimate. For an Indian buyer this matters practically. CERT-In requires reporting specified incidents within six hours of noticing them. A service that contractually starts investigating within fifteen minutes and telephones within thirty gives you a realistic path to meeting that window, with documented timestamps to evidence it — though the legal duty to file remains yours alone.
Most incident response is sold as a retainer: you pre-purchase a block of hours, and when a real incident consumes them you negotiate for more during the worst week of your year. That structure creates exactly the wrong incentive, because it discourages calling for help early — and calling early is what limits damage. Rapid7 includes unlimited incident response in the Managed Threat Complete price. There is no hour cap and no retainer to draw down. If you have three incidents in a quarter, all three are covered, with a written report following within ten business days. The honest boundary is that all of it is remote. Nobody flies to your Pune data centre. For most mid-market incidents that is fine, because the work is analysis of telemetry the platform already holds. If your risk profile demands on-site forensic attendance, you need a separate arrangement, and you should scope that with an Indian DFIR provider rather than assuming this covers it.
This is the genuinely unusual commercial feature. The per-asset price includes unlimited InsightVM scanning. No pure-play MDR vendor — not Arctic Wolf, not Expel, not Red Canary — bundles a full vulnerability management product this way. The security logic is sound. Detection tells you when someone is attacking; vulnerability management reduces the number of ways they can. Running both on the same agent, the same asset inventory and the same risk scoring means an analyst investigating suspicious activity on a server can immediately see whether that server carries an actively exploited vulnerability, and remediation can be prioritised by what the SOC is actually seeing. Commercially it changes the comparison arithmetic. If you were going to buy MDR and vulnerability management separately, price this bundle against the pair rather than against MDR alone. For Indian buyers that combination also covers two distinct regulatory expectations at once — RBI's vulnerability assessment cadence and its 24/7 SOC monitoring expectation — under one contract.
MDR services priced by data volume create the same problem as SIEM priced by data volume: better logging costs more, so teams log less and see less. Rapid7 prices Managed Threat Complete per monitored asset, with unlimited log ingestion and thirteen months of retention included at every tier. For a finance function this produces a number that behaves. Your asset count is known, changes slowly and is easy to forecast. Adding a verbose log source improves detection coverage without touching the invoice. Volume discounts begin above 500 assets. Thirteen months of retention is also more generous than most competitors include as standard, and it exceeds the twelve-month lookback many auditors expect. Note carefully that retention duration and retention location are different questions — thirteen months of data held in Tokyo does not satisfy CERT-In's requirement that 180 days of logs sit within Indian jurisdiction. Duration is not the constraint for Indian buyers; geography is.
Two limitations are frequently missed during evaluation and both bite afterwards. First, the Rapid7 Agent is mandatory. Even if you run CrowdStrike or Microsoft Defender and that tool performs the containment, Rapid7's scope of service excludes assets without its own agent from attacker behaviour analytics, from threat hunts, and from alert validation and incident investigation. An asset without the agent is not partially covered — it is outside the service. Eighty percent agent deployment is required before the security posture assessment runs at all. If you assumed your existing EDR would satisfy the requirement, that assumption is expensive. Second, containment is exactly two actions: quarantine an endpoint, disable a user account. That is the complete list. It is not network isolation of a subnet, not blocking at the firewall, not killing a process, not disabling a service account's API keys. Only one containment tool may be configured, un-quarantining is your responsibility, and you own the exclusion lists. Reviewers on Gartner and G2 also report the SOC sometimes closes incidents without sufficient explanation.
Managed Threat Complete is the right MDR service for a mid-market organisation that needs 24/7 coverage and a vulnerability programme, has no realistic path to staffing a SOC, and can accept its logs sitting offshore. The bundled vulnerability management genuinely changes the economics, the SLAs are contractual, and the unlimited incident response removes a perverse incentive that most retainer models create. It is the wrong choice in three situations. If Indian data localisation binds you — and for many regulated entities it does — no amount of service quality fixes the absence of an India region, and you should look at an India-hosted MDR provider instead. If you want a vendor-neutral service that works within the security tools you already own, this is not that: Rapid7 works inside its own platform and will not close alerts in third-party systems. And if you need on-site forensic attendance as part of the arrangement, this is remote-only. We sell CrowdStrike Falcon Complete, Sophos MDR and others alongside it, and where one of those fits you better we will say so before you sign.
Rapid7 has no India region and your logs will sit offshore. If CERT-In's 180-day in-India rule or a sectoral obligation binds your entity, establish that now — it can end the evaluation before you have spent a month on it, and it is far cheaper to learn here than during an audit.
The Rapid7 Agent is required on every covered asset even if a third-party EDR does containment, and eighty percent deployment is needed before the posture assessment runs. If you already run CrowdStrike or Defender, this is a second agent and a rollout to schedule with your desktop team — budget the political cost as well as the technical one.
The SLAs are identical across Essential, Advanced and Ultimate, so upgrading does not buy a faster clock. What changes is third-party product coverage, a named cybersecurity advisor rather than a support pool, and Velociraptor plus the breach warranty at Ultimate only. Decide on those, not on response time.
Active Response quarantines endpoints and disables users — that is the whole list. Configure your one containment tool, agree the exclusion lists, and be explicit about who un-quarantines and when. Teams that skip this discover the boundary during an incident, which is the worst possible moment.
Unlimited vulnerability scanning is included in the price and is routinely under-used because it arrives as a bundle rather than a purchase. Run it, wire Remediation Projects to real owners, and let the SOC's findings prioritise the fixing. This is where the commercial advantage over pure-play MDR actually materialises.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“The SLAs are in the contract, not the brochure. Fifteen minutes to start on a critical, and they have met it.”
“Bundled vulnerability scanning changed the maths entirely. We were about to buy both separately.”
“Nobody told us the Rapid7 agent was mandatory on top of our existing EDR. That was a rollout we had not planned.”
“Unlimited IR with no retainer meant we called them early instead of arguing internally about burning hours.”
“Containment is quarantine and disable-user. That is it. Read that list carefully before you assume more.”
“Our logs sit outside India. For our regulator that was the end of the conversation, however good the service was.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Mid-market platform — one agent, one contract.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Breadth over depth — that is the deliberate trade.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Rapid7 | Tenable | Qualys | CrowdStrike | Microsoft |
|---|---|---|---|---|---|
| Position | Mid-market platform: exposure, SIEM and MDR on one agent | The strongest scanner in the category | Cloud-native, lowest operational overhead | The endpoint and MDR benchmark | Near-free at the margin with E5 |
| Pricing axis | Per monitored asset — not per GB ingested | Per asset, quote-led | Per asset, reported ~$199–250/yr | $25–45 per endpoint/month for Falcon Complete | Bundled into E5 licensing |
| Vulnerability management | InsightVM — published price, Active Risk scoring | 219,000+ plugins, dedicated OT product | Cloud-native, native patching included | Exposure module if you already run Falcon | Weak on non-Microsoft OS and network devices |
| SIEM | Challenger in the 2025 MQ — not a Leader | Not a SIEM vendor | Not a SIEM vendor | Falcon Next-Gen SIEM | Sentinel — a Leader |
| MDR | Frost Radar Leader; VM and unlimited IR bundled in | Not an MDR vendor | Managed services available | Falcon Complete — the benchmark | Defender Experts |
| Deployment | SIEM and MDR cloud-only; InsightVM console is yours | Cloud or on-premises | Cloud-native only | Cloud-native only | Azure-hosted |
| India data residency | NO India region — InsightVM console is the exception | Region options; verify for your product | India platform, Pune-engineered | Verify per product | Azure India regions |
| The thing to plan around | No India region; agent mandatory; FY26 guided down | Priced above Rapid7 at most tiers | Support quality rated well; scanning less deep | The most expensive option here | Only economic if you already hold E5 |
| Best fit | Mid-market wanting VM, SIEM and MDR from one vendor | Deepest scanning, or operational technology | Lowest operational overhead, native patching | Best-in-class endpoint and managed response | Microsoft-standardised estates with E5 |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Rapid7 Managed Threat Complete is one of 13 managed detection & response products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Rapid7 meters per monitored asset; most rival SIEMs meter per gigabyte ingested. That is the comparison worth modelling, because it is the one that decides the deal. Move both sliders: the asset count you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number — Rapid7 is quote-only — it is the shape: per-asset cost tracks headcount and hardware, which change slowly, while per-GB cost tracks how much you log, which only ever goes up. Indicative Indian-market rates.
If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. The structural argument for per-asset pricing is not that it is always cheaper — it is that it stops the bill punishing you for collecting more, which is what makes teams under-log and miss things. Weigh that against the residency constraint before you decide.
Managed Threat Complete is quote-only. Buyer-reported pricing clusters around $15–22 per asset per month, midpoint near $17, with a 500-asset minimum commonly applied — directional rather than official, since Rapid7 does not stand behind those figures. The comparison mistake we see most often is pricing this against MDR alone: it bundles unlimited InsightVM scanning and unlimited incident response with no retainer, so price it against that pair. Note also that the SLAs are identical across all three tiers, so you are never buying a faster clock by upgrading. TechBag quotes in INR with GST.
The same SLAs as Ultimate
Adds an advisor
Forensics and warranty
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does CERT-In's in-India log rule or a sectoral obligation bind us? Rapid7 has no India region.
Have we planned a Rapid7 Agent rollout even though we already run another EDR? It is mandatory.
Which assets will NOT carry the agent, and do we accept they are outside the service entirely?
Have we read that Active Response is quarantine-endpoint and disable-user, and nothing else?
Which single third-party EDR will we configure, and who owns un-quarantining?
Are we choosing the tier on advisor and forensics rather than on response speed? The SLAs are identical.
Do we need on-site forensic attendance? All Rapid7 incident response is remote.
Are we pricing this against MDR plus vulnerability management, not against MDR alone?
Do we expect alerts closed in our other tools? Rapid7 works only inside its own platform.
Understood that we keep Incident Command if we leave the service?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.