SOAR / MDR / Rapid7

Rapid7 MDR

Rapid7 MDR combines a staffed security operations center, an advisor, hunting and exposure-informed investigations. The service works with customer teams under an agreed scope, so learners should distinguish provider investigation and response duties from the separate Rapid7 Automation software.

Managed detection and responseResearch reviewed

What you are evaluating

The Elite scope of service frames a collaboration and excludes anything not listed. Telemetry onboarding, supported detections, response prerequisites, and customer responsibilities limit what the service can do.

A useful evaluation context

Evaluation is the responsibility split for containment actions Rapid7 performs versus customer IT, and which event sources are standard versus Custom Monitoring.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Around-the-clock SOC, advisor, hunting, and exposure-informed investigations on contracted sources.
  • Standard event sources versus Custom Monitoring add-ons that must be listed to be in scope.
  • Collaborative response where Rapid7 and customer IT split contain actions according to the signed RACI.

Where it fits in the work

  1. Onboard the event sources in the signed scope, and list Custom Monitoring separately if needed.
  2. Investigate SOC cases using the collaboration model; customer IT still performs actions Rapid7 is not authorized to take.
  3. Hand work outside the listed scope, including unlisted telemetry or surge forensics, to a documented exception or retainer.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In an authorized test environment, onboard only a listed event source, raise a supported harmless detection, and record which contain step Rapid7 performed versus which customer IT had to execute.

Evidence to look for

The investigation record matches the signed collaboration model, lists the event source, and shows no action on systems outside that scope.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which event sources are standard in the signed scope versus Custom Monitoring add-ons?
  2. Which contain actions does Rapid7 perform, and which remain customer IT prerequisites?
  3. How does this service responsibility matrix differ from Rapid7 Automation playbooks the customer staffs?

Find your next idea.

Tip: press / to open search. Escape closes this window.