sequenced.ai
Articles/Agents & support/Blueprint//8 min read

Rapid7 brings AI triage into an evidence-driven security operations workflow

Rapid7 combines asset context, SIEM and managed response, with distinct entitlements for suggested dispositions and automated triage.

By Sequenced deskAI-assisted, source-led · how we work
Visit Rapid7 website ↗
Incident CommandSecurity operationsSIEM and connected context
AI dispositionsAlert analysisExplanations and audit notes
Managed responseService routeMDR has additional triage actions
Asset-basedSubscription modelRetention varies by package
Rapid7 mark
Rapid7rapid7.com · independent research

Represent this company? Verify your work email to access its workspace, or send the desk a factual correction.

Rapid7 combines asset context, SIEM and managed response, with distinct entitlements for suggested dispositions and automated triage.

In brief
  1. 01What it does Combines security telemetry, attack-surface context, AI-assisted investigation and optional managed response.
  2. 02Best fit Security teams that need a more coherent alert-to-investigation process across existing tools.
  3. 03Buying question Which AI actions belong to the selected SIEM package, and which require the MDR service?

01 / ProductThe platform joins a detection queue to the context behind it

Rapid7 is a security company spanning exposure management, threat detection and managed services. Its security operations offer has two principal buying routes: Incident Command for an organisation operating its own security function, and Managed Threat Complete for expert-led managed detection and response. AI assists within those workflows rather than acting as a standalone general-purpose security chatbot.

The Incident Command setup guide brings together SIEM, attack-surface management, threat intelligence and automation. Existing documentation still uses the InsightIDR name for the SIEM component. These are related parts of the same Rapid7 offer, not independent companies. For a buyer, the relevant question is how alerts acquire enough asset, identity and threat context to support a decision.

Rapid7’s AI usage documentation identifies two concrete SIEM functions: assigning likely dispositions to alerts and helping users generate LEQL log-search queries from natural-language prompts. The latter includes an explanation of the proposed query. These capabilities can reduce preparation work, but the analyst still needs to know whether the right logs were searched and whether the conclusion follows from the available events. This review does not establish detection accuracy or incident outcomes.

02 / AudienceThe best fit depends on who will own the investigation

A team running its own SOC may want to reduce time spent collecting context and sorting a large alert queue. Incident Command is relevant when there are people available to validate detections, maintain integrations and decide what response is appropriate. The platform can connect work, but it does not create the staffing, escalation policy or business authority needed to handle a disruptive incident.

A smaller internal team might instead need a managed service that investigates alerts and shares its work. That is a service-responsibility decision as much as a feature comparison. Establish which systems the provider covers, when it contacts the customer and what actions are pre-authorised. A shared console is valuable only when both sides understand who takes the next step and what happens when the customer is unavailable.

CrowdStrike offers a relevant comparison around security agents operating in a broader detection platform. Elastic is useful for teams weighing more control over search and security data. Compare representative investigations, connected data sources and the human operating model. A generic claim that all three products use AI does little to explain which one fits the team’s actual sources of evidence and response responsibilities.

03 / WorkflowProposed workflow: inspect an AI disposition and reconstruct the evidence

Use a controlled set of existing, analyst-reviewed alerts involving ordinary administration and genuinely suspicious activity. Choose at least one supported process family rather than assuming all detection rules receive AI analysis. The alerts documentation explicitly restricts suggested dispositions to specified detection rules. This proposed pilot is a way to evaluate the workflow; no customer environment has been accessed for this article.

Follow the documented setup sequence to connect the required telemetry and establish asset context. For a new SIEM deployment, the guide calls for a Collector, the Rapid7 Agent and core event sources. Confirm successful collection using known events from the test systems before interpreting missing activity as a security result. An analysis cannot distinguish an uneventful host from a silent connector without that basic coverage check.

Open an alert and inspect the disposition explanation and corresponding audit entry. Preserve the underlying event, relevant identity, affected asset and the reason the analyst agrees or disagrees. Keep undecided and not-applicable results separate from benign results. They answer different questions: insufficient evidence and no AI analysis should not be reported as evidence that the activity is harmless.

Use natural-language log-search assistance to formulate a follow-up query, then inspect the generated LEQL and explanation before running it. Confirm the chosen time range, log set and identity fields. A syntactically valid query may still search the wrong interval or omit the system that matters. Compare the result with a known manual query for the same case to evaluate whether the assistant made the investigation easier to reproduce.

If using MDR, include the service’s additional triage behavior in the pilot. The documented flow can close benign alerts automatically and increase malicious alerts to High priority, while undecided cases receive no further action from that step. Reopen a sampled benign case and verify that its supporting history is still available. Agree how the customer challenges a disposition and how that feedback reaches the service.

End with a case that another analyst can follow without reconstructing the entire investigation. Measure evidence completeness, wrong dispositions, unresolved cases and time to a reviewed decision. Where response actions are tested, require the authorised operator to check the resulting state. An alert marked handled is not sufficient evidence that the intended host, account or network control changed successfully.

04 / PricingAsset-based packages and managed services need separate scopes

The Incident Command package page describes Essential, Advanced and Ultimate subscriptions with asset-based pricing. It does not display a universal currency price for those packages. Raw-log retention is listed as 90 days for Essential and 180 days for Advanced and Ultimate, with add-ons; alert and audit retention is shown separately as 13 months plus add-on options.

The feature grid includes AI-assisted disposition and agentic investigation rows, but its extracted checkmark cells are not reliable enough to assign every feature to a tier. Ask for an entitlement schedule and demonstrate the exact workflow in that package. This is especially important because the operational documentation distinguishes ordinary AI-suggested dispositions from MDR-only automatic triage actions. Buying the SIEM should not be assumed to buy the managed service.

The broader Rapid7 pricing page also lists separate Insight products with their own units. Those figures are not a price for an AI-powered SOC. Obtain a proposal covering the asset definition, data allowance, needed retention, deployment assistance, integrations and service responsibility. A cost estimate built from the wrong product’s starting price will look precise while describing a different purchase.

OfferCommercial basisBoundary
Incident Command EssentialQuoted asset-based subscription90-day log retention shown; confirm AI feature gates
Incident Command Advanced / UltimateQuoted asset-based subscription180-day log retention shown; modules vary
Alert and audit records13 months listed across packagesSeparate from raw-log retention; add-ons available
Managed Threat Complete / MDRSeparate managed-service scopeDocumented additional automatic triage behavior

Commercial terms from Incident Command packages, consulted 24 September 2026.

05 / DifferenceExplanations and audit records make triage reviewable

The most useful detail in Rapid7’s public documentation is the explicit disposition lifecycle. Analysis can be pending, insufficient, inapplicable, benign or malicious, and the alert view includes an explanation and audit note. This creates a place for the analyst to disagree and preserve that disagreement. A workflow that exposes uncertainty is more useful to evaluate than one that presents every generated conclusion as a final verdict.

The platform also links investigation to attack-surface context. An unusual command on a disposable test host and the same command on a business-critical system may justify different handling. The value of connected context is therefore not simply adding more text to an alert. It is helping the investigator understand what was affected and what consequences a containment action would have for the organisation.

06 / LimitsCoverage, retention and automation authority remain consequential

Check the supported detection rules for the activity the SOC actually sees. A pilot dominated by one well-supported process family can overstate coverage of the broader queue. Keep unanalysed alerts in the denominator when measuring workload reduction. Also inspect cases where the system remains undecided: the right outcome may be a request for additional telemetry rather than a more confident generated explanation.

Retention needs should follow the investigation horizon. A team that discovers a compromise months later may need raw events that are no longer in the standard retention window, even while the alert record remains available. Confirm what extended retention costs and how archived information can be queried. Do not equate a 13-month alert history with 13 months of searchable raw logs.

Finally, establish the boundary between recommending a response and executing it. The setup guide assigns roles across automation, SIEM, attack surface and threat intelligence. Those permissions should match operational duties, and production actions need clear approval and rollback arrangements. AI can accelerate an incorrect action just as easily as a correct one if the asset identity, policy or connected-system authority is wrong.

07 / DecisionChoose the operating model before comparing the AI features

Rapid7 is worth shortlisting when security evidence is fragmented and the team wants a connected investigation process. Decide first whether the organisation will run that process itself or buy managed help. Then test a supported alert class, inspect the explanations and audit history, and price the actual asset and retention footprint. Expand automation only when the people responsible can reproduce and challenge the decisions it produces.

Internal SOC

Analysts need clearer evidence and faster triage

Pilot supported alerts and compare AI explanations with reviewed dispositions.

Evaluate the case workflow
Lean security team

Coverage needs a service operator

Define MDR ownership, escalation and authorised actions in the service agreement.

Choose the operating model
Long investigations

Old raw events must remain searchable

Confirm log retention and retrieval separately from alert-history retention.

Price the evidence horizon
What should we explore next?

A business worth understanding.

Suggest your business or one you find interesting. Tell us what you want to understand about its product, positioning, design or workflows.

Suggestions are free. Selection and publication stay with the desk.

Sources
Filed under Agents & supportCompany Rapid7Not affiliated with Rapid7Request a correctionRequest a refresh by email

Continue reading

All in this category