5 min
MDR Vendor Must-Haves, Part 7: Managed Response Actions
Security teams face unprecedented challenges as the threat landscape expands in scope and complexity. Protecting the organization in today’s environment has led to analyst fatigue, with many organizations struggling to respond to both user and host threats in a timely manner.
2 min
Managed Detection and Response (MDR)
MDR Vendor Must-Haves, Part 4: Ingestion of Authentication Data Across Local, Domain, and Cloud Sources
There isn’t a single threat or breach that doesn’t involve attackers using legitimate credentials to cause harm.
3 min
Managed Detection and Response (MDR)
MDR Vendor Must-Haves, Part 2: Ingestion of Network Device Data
One area that can offer incredible benefits in a Managed Detection and Response provider is the ingestion of network device data.
4 min
Detection and Response
Attack vs. Data: What You Need to Know About Threat Hunting
While the definition of threat hunting may be straightforward—proactively hunting for threats—the reality of implementing a threat-hunting program is a bit more complicated, as there are different threat-hunting methodologies to choose from.
18 min
Zero-Day
Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange
In recent weeks, there has been quite a lot of reporting on the exploitation of the latest disclosed vulnerabilities in Microsoft’s Exchange Server by an attacker referred to as HAFNIUM.
6 min
SOAR
SOC Automation with InsightIDR and InsightConnect
It may not be a surprise that automating your security operations will augment your team’s skills and expertise to detect and respond to threats with super speed.
1 min
Detection and Response
InsightIDR’s NTA Capabilities Expanded to AWS
We’re excited to announce we have expanded the Network Traffic Analysis (NTA) capabilities in InsightIDR to support Amazon Web Services (AWS) environments.
2 min
InsightIDR
How to Combat Alert Fatigue With Cloud-Based SIEM Tools
Fortunately, there’s a way to get the visibility your team needs and streamline alerts: leveraging a cloud-based SIEM.
2 min
Cloud Infrastructure
Why More Teams are Shifting Security Analytics to the Cloud This Year
As the threat landscape continues to evolve in size and complexity, so does the security skills and resource gap, leaving organizations both understaffed and overwhelmed.
2 min
InsightIDR
Monitor Google Cloud Platform (GCP) Data With InsightIDR
Today, more and more organizations are adopting multi-cloud or hybrid environments, creating increasingly more dispersed security environments
11 min
Security Operations (SOC)
Talkin’ SMAC: Alert Labeling and Why It Matters
This blog post will demonstrate some common pitfalls of alert labeling, and offers a new framework for SOCs to use.
6 min
InsightIDR
InsightIDR: 2020 Highlights and What’s Ahead in 2021
As we kick off the New Year, we wanted to highlight some key InsightIDR product investments and take a look ahead at detection and response in 2021.
4 min
Detection and Response
Mobile Device Security Management
Remote workforces and mobile device management (MDM) are more important than ever in 2020’s pandemic reality.
4 min
Detection and Response
2021 Detection and Response Planning, Part 4: Planning for Success with a Cloud SIEM
In this post, we’ll explore how a cloud SIEM, like Rapid7 InsightIDR, may be more relevant and impactful than ever before.
5 min
InsightIDR
Visualizing Network Traffic Data to Drive Action
In this blog, we cover the top five multi-groupby queries that can be used to visualize network sensor data with the Insight Network Sensor.