Rapid7, Inc. (‘Rapid7’) operates as a global cybersecurity software and service provider.
Rapid7 has partnered with enterprises across the globe, representing a diverse range of industries, to improve the efficacy and productivity of their security operations (‘SecOps’). The company empowers security professionals to manage a modern attack surface through its trusted AI-infused technology, leading-edge research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help the...
Rapid7, Inc. (‘Rapid7’) operates as a global cybersecurity software and service provider.
Rapid7 has partnered with enterprises across the globe, representing a diverse range of industries, to improve the efficacy and productivity of their security operations (‘SecOps’). The company empowers security professionals to manage a modern attack surface through its trusted AI-infused technology, leading-edge research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help the company’s global customers unite exposure management with threat detection and response to reduce attack surfaces and eliminate threats with speed and precision.
The company’s Command Platform is anchored on its cloud security, security information and event management (‘SIEM’), advanced detection and response, and vulnerability management offerings. Rapid7 enables the Security Operations Center (‘SOC’) to understand its fragmented attack surface with an attacker perspective, allowing it to proactively secure its attack surface and better detect and respond to threats. The company’s integrated security operations platform enables SecOps teams to move away from a reactive approach, reduce their attack surface, and enhance response efficiency with a deep contextual understanding of their environment.
As the company has shifted its strategic focus to SecOps consolidation, it is focused on continuing to drive innovation across its core products and capabilities to accelerate customer value and provide a frictionless and integrated cloud security experience.
As of December 31, 2024, the company had more than 11,700 customers that rely on Rapid7 technology, services, and research to improve security outcomes and securely advance their organizations.
Platform
Rapid7’s Command Platform is a unified threat exposure, detection, and response platform that allows SecOps teams to integrate their critical security data by providing a unified view of vulnerabilities, exposures, and threats from endpoint to cloud, to close security gaps and prevent attacks. By integrating native cloud, on-premises, and security monitoring data, and correlating it with an organization’s ecosystem of IT and business data, the Command Platform provides visibility of a customer’s attack surface. By providing the means to confidently discover, identify, prioritize, and remediate risk, detect threats, and respond, the fully-integrated, AI-enabled platform gives SecOps teams greater visibility they can trust.
The company’s Command Platform is delivered via integrated technology, managed services, threat intelligence, and threat-aware risk context, enabling it to anticipate, detect, and promptly respond to threats once identified. The platform was built using its extensive experience in collecting and analyzing data from diverse sources, including multi-cloud platforms, applications, endpoints, and networks, and thus enables its customers to create and manage analytics-driven cybersecurity risk management programs. By utilizing the company’s powerful proprietary analytics to assess and understand the context and relationships related to users, IT assets, and cyber threats within a customer’s environment, its solutions make it faster and easier for teams to identify and remediate vulnerabilities, monitor for misconfigurations and malicious behavior, investigate and shut down attacks, and automate operations.
Endpoint to Cloud Data Collection and Sharing
In response to the company’s customers’ expanding digital footprints, it has invested in its capacity to gather, standardize, enrich, and correlate diverse telemetry within its platform. The company’s cloud architecture utilizes a combination of native collection technologies and application programming interfaces, as well as third-party event sources, to scale in alignment with the digital transformation occurring within its customers’ organizations.
Rapid7 Insight Agent: The company’s universal endpoint agent, the Insight Agent, is a lightweight, software-based agent that can be installed on assets across on-premises and cloud environments to centralize and monitor data on its platform. This single agent enables a number of impactful use cases across the platform, including next-generation antivirus (‘NGAV’), vulnerability scanning, endpoint detections, investigation and forensic search capabilities, and threat containment.
Rapid7 Insight Network Sensor: The company’s lightweight Insight Network Sensor passively analyzes raw end-to-end network traffic to increase visibility into user activity, pinpoint real threats, and accelerate investigations with granular detail of attacker movement.
Rapid7 Cloud Event Data Harvesting: Given the scale, complexity, and rapid evolution of modern dynamic cloud environments, real-time detection of risks and threats is paramount. The company’s event-driven harvesting offers visibility into changes made to vital cloud resources.
Third-Party Integrations and Ecosystem: The company has integrations for hundreds of different technologies and solutions to deliver visibility across a customer’s attack surface, customized to their unique ecosystem.
Orchestration and Automation: The connective tissue of the company’s platform is its ability to orchestrate workflows across both its solutions and the customers’ wider security ecosystem. This connectivity enables its customers to focus on security outcomes, rather than systems integrations, and accelerates both tasks associated with the normal course of business, as well as time-sensitive containment and remediation activities to minimize exposure and eliminate threats.
Offerings
Offerings are consumed via the company’s platform and delivered as either Software-as-a-Service (‘SaaS’) solutions, managed services, or professional services. Customers can consume consolidated software and/or managed service offerings that combine leading capabilities and lean into vendor consolidation to maximize security budgets.
Detection and Response
Managed Threat Complete (‘MTC’) is the company’s flagship offering that unifies Managed Detection and Response (‘MDR’) and the robust exposure management of Managed Vulnerability Management (‘MVM’) delivered via a shared agent to prevent attacks across the kill chain, pinpoint advanced threats wherever they are, and respond confidently with unlimited incident response from an always-on MDR. MDR delivers end-to-end threat detection and response, encompassing 24x7 monitoring to incident containment to breach response. Customers are also able to add NGAV, which delivers high-fidelity prevention against both known static threats and suspicious behavior, or Managed Digital Risk Protection (‘MDRP’), which searches for potential threats from stolen or leaked data and phishing attempts.
Threat Complete unifies InsightIDR (‘InsightIDR’) and InsightVM (‘InsightVM’) to provide vulnerability management and threat coverage in a single offering. Using a shared agent, customers receive clarity and higher-efficacy detection coverage around priority vulnerabilities, enabling them to eliminate risks and threats faster across their environments.
InsightIDR is a next-generation Security Information and Event Management (‘SIEM’) and Extended Detection and Response (‘XDR’) solution with high-fidelity detections that eliminate alert noise to pinpoint incidents and accelerate response with expert recommendations and automation.
Incident Response Services are proactive and responsive professional services to help customers prepare and respond to potential breaches.
Exposure Management
Exposure Command is an exposure management offering that provides attack surface visibility with proactive exposure mitigation and remediation prioritization optimized for hybrid environments. Customers with advanced cloud security use cases can purchase Exposure Command Advanced to provide strong security for workloads leveraging real-time visibility, identity analysis, and automated remediation. The code-to-cloud protection also includes continuous web-app scanning and expanded risk coverage.
Surface Command is the most accessible Cyber Asset Attack Service Management (‘CAASM’) solution in the market, providing customers a 360° attack surface view they can trust to detect and prioritize security issues from endpoint to cloud.
Vector Command is a continuous red-teaming service that validates the external attack surface exposures and tests defenses with continuous red team operations to provide trusted insights into the exposures that matter.
InsightCloudSec is a cloud risk and compliance management solution that provides Cloud-Native Application Protection Platform (‘CNAPP’) capabilities and enables organizations to securely accelerate cloud adoption with continuous security and compliance throughout the software development lifecycle.
InsightVM is a Vulnerability Management (‘VM’) solution that provides visibility across on-premise and remote endpoints, enabling security teams to evaluate the business risk of vulnerabilities and configurations and share with their IT counterparts for remediation.
InsightAppSec is a Dynamic Application Security Testing (‘DAST’) tool, delivered via the cloud, that combines powerful application crawling and attack capabilities, flexibility in scan and scheduling, and accuracy in results with a modern user interface, intuitive workflows, and sensible data organization.
Managed VM offloads day-to-day VM operations to experts and extends coverage across the attack surface.
Managed AppSec provides guidance from a dedicated security advisor and AppSec experts to validate application test results, reduce noise for the AppSec team assessing results, and save time for developers remediating issues.
Penetration Testing is professional services that assess the modern attack surface for exposures with offerings covering internal and external networks, web applications, mobile applications, Internet of Things, wireless network testing, social engineering, and red team attack simulation.
The company’s platform products are available globally and reduce the need for customers to manage a large, complex data infrastructure. Customers can add expertise via its managed services delivered out of its SOCs located in the U.S., Ireland, Australia, and the Czech Republic. Each of these SOCs is staffed with security analysts, threat engineers, incident responders, and customer advisors that provide full-lifecycle support for its global managed services customers.
Growth Strategy
The main drivers of the company’s growth strategy are continued investments in product innovation; expanding the company’s partner ecosystem, including strategic partnerships, channel partners, and Managed Security Service Providers (‘MSSPs’); growing the company’s customer base; upselling and cross-selling to its existing customer base; strengthening its customer renewal rate; international expansion; and strategic M&A.
Rapid7 Labs: Open Source Community
The company’s industry-leading attack experts analyze vulnerabilities, misconfigurations, and threat data to offer proactive guidance for organizations’ security programs. Leveraging threat intelligence from its free and open-source projects, it continuously enhances its products and services to improve the customer experience. The company’s open-source projects that serve the community and enrich its offerings include:
Metasploit: The company’s Metasploit framework has an active community of contributors and users, including security researchers who contribute modules to the Metasploit Framework that serve as a resource about real-world attacker techniques. The Metasploit community also provides the company with visibility into new cyber attacks as they occur and a deeper understanding of attacker behaviors.
Velociraptor: Velociraptor is a unique, advanced open-source endpoint monitoring, digital forensic, and cyber response platform. It provides the company with the ability to more effectively respond to a wide range of digital forensic and cyber-incident response investigations and data breaches.
AttackerKB: The AttackerKB was created in 2020 as a forum for the security community to discuss, analyze, and prioritize threats. This community-driven platform empowers security professionals to exchange information about vulnerabilities so they can better understand the impact and likelihood of being exploited.
Project Lorelei: Project Lorelei began in 2014 to understand what attackers, researchers, and organizations are doing in, across, and against cloud environments and gain deeper insights into the tactics, techniques, and procedures employed by both bots and human attackers.
Project Sonar: The company conducts internet-wide scans across many services and protocols to gain insight into global exposures and vulnerabilities and collect data for platform analytics and preparation of core research reports.
Threat Intelligence and Detections Engineering
Rapid7’s threat content library leverages unique raw threat from the company’s open-source communities, as well as expertly vetted third-party intelligence, and insights from across its platform, to provide customers with a curated repository of detections and emergent threat coverage. With a combination of proprietary AI-driven detections and indicators of compromise mapped to the ATT&CK Framework (a public resource that maps adversary tactics, techniques, and procedures), its detection content spans both known and unknown threats across the threat life cycle. When analyzed against the diverse telemetry data, this content enables the company to pinpoint threats across endpoints, network, users, cloud, and customers’ wider ecosystem. This library is leveraged by the company’s Rapid7 MDR services, as well as within its InsightIDR technology, meaning alerts are vetted in the field by its security experts, offering a feedback loop and ensuring strong signal-to-noise alerting.
Professional Services
The company’s professional services offerings include, but are not limited to: Penetration Testing, Cybersecurity Maturity Assessments, Security & Incident Response Program Development Services, Internet of Things & Internet Embedded Device testing, as well as Threat Modeling, Tabletop Exercises, and Incident Response services. In addition, it offers deployment and training services related to its platform to further help customers operationalize and customize their platform experience. By accessing the company’s security talent, it helps organizations develop an approach and roadmap to further mature and strengthen their security programs.
Customers
As of December 31, 2024, the company had more than 11,700 customers in 147 countries, including 43% of the organizations in the Fortune 100. The company defines a customer as any entity that has an active Rapid7 recurring revenue contract as of the specified measurement date, excluding customers of only InsightOps or Logentries that have a contract value of less than $2,400 per year.
The company’s customers span a wide variety of industries, including technology, energy, financial services, healthcare and life sciences, manufacturing, media and entertainment, retail, education, real estate, transportation, government, and professional services, with customers in the manufacturing industry representing the company’s largest industry in 2024 at 15% of its revenue. In 2024, 43% of its revenue was generated from enterprises, which the company defines as organizations that have either annual revenue greater than $1.0 billion or more than 2,500 employees, and the balance was generated from middle-market and small organizations.
Intellectual Property
The company has over two hundred and fifty issued patents and a number of registered and unregistered trademarks. The standard length of the company’s patents is 20 years, and while the grant dates of its patents vary, the duration of the company’s issued patents is sufficient when considering the expected lives of its products.
‘Rapid7,’ the Rapid7 logo, and other trademarks or service marks of Rapid7, Inc. are the property of the company.
History
Rapid7, Inc. was founded in 2000. The company was incorporated in 2000 in Delaware.