How Rapid7 Customers Are Using Network Traffic Analysis in Detection and Response

How Rapid7 Customers Are Using Network Traffic Analysis in Detection and Response

In case you missed it, we introduced Network Traffic Analysis for our InsightIDR and MDR customers a few months back. We took what was a very innovative traffic analysis system from NetFort, made it cloud-friendly, and integrated it with InsightIDR, our cloud SIEM platform.


The addition of Network Traffic Analysis (NTA) to the Rapid7 portfolio ensures we are strongly aligned with Gartner’s Security Operations Visibility Triad, which advocates for a three-pronged approach to gain the visibility and analytics needed for successful incident detection and response.



From a single console, you can now deploy log readers, agents, and NTA components—with no need to log on and manage separate systems.


Vendor-independent and available at any location on any network, network data is a great option to eliminate blind spots or enable deeper visibility at critical locations. Every user and device on every network leaves a traffic trail. It is continuous, always on, and can be also used to improve real-time visibility into user activity in and out of the network (north-south) and also inside the network (east-west).


Network Traffic Analysis is available within InsightIDR and MDR via the Insight Network Sensor. This is an installable package for Linux systems. We have more information about the install process on our sensor help site. The Insight Network Sensor is available to all customers, and we also have an add-on available for customers who want access to network flow type data.