Rapid7 Insight Connect is powerful if you are a Rapid7 shop
Use Cases and Deployment Scope
We used rapid7 insight connect to connect our vuln management platform, insight M, to our Jira and Slack for ticket/project creation and notifications. I found both of the integrations as pre-built modules that I could customize for our environment so was able to get them up and working quickly and effectively. This enabled me to replicate and improve ticketing and alerting workflows that I had previously built in Tenable's Security Center platform by allowing for interaction with the vuln management tool from Slack. Now our devs and sysadmins could pull up device or application vuln info from Slack and would be notified via slack of changes to any devices or apps they owned, assuming they were being scanned by the vuln management tool.
Pros
- Offers pre-built integrations with multiple common alerting tools
- Offers pre-built workflows for multiple common tools
- Easy to create custom workflows and integrations
Cons
- Sometimes too point and clicky
- Cost is high
- Workflows often require users from several teams to work on various tools
Most Important Features
- Integration
- Automation
- Ease of use
Return on Investment
- The automation and integration we set up in the dev cycle helped us provide evidence in audits
- The automation and integration we set up in the dev cycle helped us fix vulns in our software prior to implementation thus increasing our security
- Automations save massive time and headache's between infosec and devs
Alternatives Considered
Snyk, Splunk SOAR (Security Orchestration, Automation and Response) (formerly Phantom), Sensu, by Sumo Logic and SonarQube
Other Software Used
Splunk Enterprise Security (ES), CrowdStrike Falcon Endpoint Protection, Splunk SOAR (Security Orchestration, Automation and Response) (formerly Phantom)


