Rapid7 Course Content

Rapid7 InsightVM is a leading vulnerability management solution for identifying, prioritizing, and remediating security risks. This instructor-led training covers InsightVM architecture, deployment, configuration, vulnerability assessment, remediation, etc. Below are the core modules covered in the course.

  • What is InsightIDR?
  • Overview of Rapid7 SIEM/XDR capabilities.
  • SIEM vs XDR vs EDR
  • Difference between log-based monitoring, endpoint detection, and extended detection.
  • InsightIDR Architecture
  • Cloud-based design, collectors, agents, network sensors.
  • Components Overview
  • Event Sources, detections, UEBA, Investigations.
  • Supported Logs
  • Windows, Linux, Cloud, Firewalls, Proxies, SaaS apps.
     
  • Collectors
  • Installing Windows/Linux collectors
  • Collector health monitoring
  • Scaling collectors for load
  • Event Sources
  • Adding cloud logs
  • Troubleshooting misconfigured sources
  • Insight Agent
  • Agent capabilities (processes, DNS, file changes)
  • Agent health monitoring
  • LEQL Basics
  • Structure of LEQL queries
  • Fields, operators, filters
  • Time window handling
  • Basic log search examples
  • LEQL Advanced
  • parse() — extract key-value pairs
  • match() — regex-based filtering
  • groupby — grouping events
  • Aggregations: COUNT, SUM, AVERAGE
  • Creating dashboards using LEQL
  • Detect brute-force attempts (Hands-On)
  • Identify suspicious PowerShell (Hands-On)
  • Detect DNS tunneling (Hands-On)
  • Save and automate log searches (Hands-On)
     
  • Detection Fundamentals
  • Types of detections
  • ABA (Attacker Behavior Analytics)
  • UEBA
  • Custom correlation rules
  • MITRE ATT&CK mapping
  • Rule prioritization & tuning
  • Create user login anomaly rule (Hands-On)
  • Create PowerShell suspicious rule (Hands-On)
  • Tune false positives (Hands-On)
     
  • Built-In Threat Intel
  • Rapid7 curated intelligence
  • Malicious IP/domain detection
  • Suspicious hash identification
  • How threat intel enhances investigations
  • IOC Management
  • Adding custom IOCs
  • IOC expiration
  • IOC-based alert creation
  • Threat Hunting
  • Proactive hunting using LEQL
  • Hash-based malware search
  • IP/domain threat search
  • Import threat intel feed (Hands-On)
  • Create IOC-based detection (Hands-On)
  • Correlate IOCs with logs (Hands-On)
     

  • What is InsightIDR?
  • Overview of Rapid7 SIEM/XDR capabilities.
  • SIEM vs XDR vs EDR
  • Difference between log-based monitoring, endpoint detection, and extended detection.
  • InsightIDR Architecture
  • Cloud-based design, collectors, agents, network sensors.
  • Components Overview
  • Event Sources, detections, UEBA, Investigations.
  • Supported Logs
  • Windows, Linux, Cloud, Firewalls, Proxies, SaaS apps.
     

  • Collectors
  • Installing Windows/Linux collectors
  • Collector health monitoring
  • Scaling collectors for load
  • Event Sources
  • Adding cloud logs
  • Troubleshooting misconfigured sources
  • Insight Agent
  • Agent capabilities (processes, DNS, file changes)
  • Agent health monitoring

  • LEQL Basics
  • Structure of LEQL queries
  • Fields, operators, filters
  • Time window handling
  • Basic log search examples
  • LEQL Advanced
  • parse() — extract key-value pairs
  • match() — regex-based filtering
  • groupby — grouping events
  • Aggregations: COUNT, SUM, AVERAGE
  • Creating dashboards using LEQL
  • Detect brute-force attempts (Hands-On)
  • Identify suspicious PowerShell (Hands-On)
  • Detect DNS tunneling (Hands-On)
  • Save and automate log searches (Hands-On)
     

  • Detection Fundamentals
  • Types of detections
  • ABA (Attacker Behavior Analytics)
  • UEBA
  • Custom correlation rules
  • MITRE ATT&CK mapping
  • Rule prioritization & tuning
  • Create user login anomaly rule (Hands-On)
  • Create PowerShell suspicious rule (Hands-On)
  • Tune false positives (Hands-On)
     

  • Built-In Threat Intel
  • Rapid7 curated intelligence
  • Malicious IP/domain detection
  • Suspicious hash identification
  • How threat intel enhances investigations
  • IOC Management
  • Adding custom IOCs
  • IOC expiration
  • IOC-based alert creation
  • Threat Hunting
  • Proactive hunting using LEQL
  • Hash-based malware search
  • IP/domain threat search
  • Import threat intel feed (Hands-On)
  • Create IOC-based detection (Hands-On)
  • Correlate IOCs with logs (Hands-On)
     

  • Investigation Workflow
  • Alert (Case creation)
  • Evidence correlation
  • User/Asset timeline analysis
  • Lateral movement investigation
  • Incident Response Techniques
  • Enrichment with threat intel
  • Marking false positives
  • Adding notes, tagging evidence
  • Investigate suspicious login (Hands-on)
  • Investigate malware execution (Hands-on)
  • Combine LEQL + Threat Intel for deep investigation (Hands-on)
     

  • Pre-built SOC dashboards
  • Building custom dashboards
  • Exporting & automating reports
  • Compliance mapping (PCI, SOC2, SOX, HIPAA)
     

  • Integrating AD, Okta, Firewalls, Cloud
  • IDR (InsightConnect automation)
  • Auto Ticket creation
  • Alert enrichment
  • Auto user lockout
     

  • What is SOAR
  • Automation vs Orchestration
  • InsightConnect architecture
  • Use cases (Phishing, IOC enrichment, Auto containment)
  • Understanding plugins & workflows
     

  • Installing Orchestrator (Linux/VM)
  • Connecting to Insight Platform
  • API keys and credential storage
  • Troubleshooting orchestrator issues
     

  • Triggers (manual, scheduled, alert-based)
  • Steps, decision trees, data pills
  • Error handling paths
  • ChatOps integration (Slack/Teams)
  • Plugins
  • VirusTotal
  • IOC enrichment workflow (Hands-On)
  • Auto Tickets (Hands-On)
  • Alert notification workflow (Hands-On)
     

  • Threat Intelligence Automation
  • Auto-ingest threat intel
  • Auto enrich IDR investigations
  • Auto isolate malicious indicators
  • Incident Response Automation
  • Phishing triage
  • Auto block malicious IP
  • User lockout workflow
  • Malware containment with EDR plugin
  • Phishing triage workflow (Hands-On)
  • IOC hunting + alerting workflow (Hands-On)
  • Automated remediation workflow (Hands-On)

  • InsightIDR Tasks
  • Create a custom LEQL query
  • Configure an IOC rule
  • Perform an investigation using threat intel
  • Build a dashboard
  • InsightConnect Tasks
  • Create a ticket automation flow
  • Build an IOC enrichment workflow

Looking for a detailed curriculum? Enquire now!

Get the full course details to your inbox!

LIVE SESSIONS


  • Real-time Trainers
  • Live interactive Sessions
  • Cloud Labs

CORPORATE TRAINING


  • Customized Training Solutions
  • Blended Delivery Model
  • Project Implementation Support

SELF-PACED LEARNING


  • High-Quality Videos
  • Access to Materials
  • Permanent Access

Rapid7 Course Objectives

Upon successful completion of this Rapid7 InsightVM training, you will be able to:

  • Understand Rapid7 InsightVM fundamentals
  • Explore InsightVM architecture and components.
  • Install, deploy, and configure InsightVM.
  • Configure scan engines and templates.
  • Perform asset management and discovery
  • Execute different types of credential vulnerability scans.
  • Configure scanning credentials for Windows, Linux, network devices, etc.
  • Analyze vulnerabilities using CVSS,  risk prioritization, and Rapid Risk Score.
  • Configure user roles, permissions, and access control.
  • Manage dynamic asset groups, tags, and sites.
  • Create and manage remediation projects.
  • Understand exception workflows
  • Explore vulnerability lifecycle management.
  • Configure remediation workflows and automated actions.
  • Build executive security summaries.
  • Integrate InsightVM with SIEM, Jira, ServiceNow, and security tools.
  • Perform policy-based vulnerability assessments.
  • Monitor scan performance.
  • Apply best practices for enterprise environments.
     

The Rapid7 learners should have a basic understanding of the areas:

  • Linux & Windows Operating Systems
  • Network protocols

Following are the professionals who can join this Rapid7 InsightVM course

  • System Administrators
  • Cybersecurity professionals
  • Vulnerability management professionals

Rapid7 Certification

Rapid7 offers an official product certification for InsightVM to test and certify the skills of Rapid7 Professionals. Below are the certification exam details:

Exam Name: InsightVM Certified Administrator
Cost: US$215
Exam Type: Multiple Choice
Number of Questions: 60
Duration: 2 hours (120 minutes)

This Rapid7 InsightVM training course offers the knowledge required to clear the Rapid7 InsightVM Certified Administrator exam. In addition to training, participants will receive certification guidance and a course completion certificate.
 

techsolidity-certification

Rapid7 InsightVM Training Projects

Our Rapid7 InsightVM training is more of a practical-oriented program. From day one, you will work on assignments and get a chance to explore each component. By the end of this Rapid7 InsightVM certification course, you will have gained complete knowledge and will be able to work on enterprise-grade projects.

Rapid7 Training Reviews

Rapid7 FAQ's

Yes, Techsolidty offers you two types of Discounts: one is group discount and the other is referral discount.
Yes, In order to provide you the financial flexibility, we provide you the chance to pay the course fee in two installments.
Due to any reasons, you would like to cancel your registration after paying the fee, you should intimate the same to us within the first two classes. The refund amount will be processed within 30 days from the requested date.
To meet the customer expectations we provide multiple types of training which include, Live instructor-led training, Self-paced training, blended training, classroom training, corporate training, etc.
Yes, at Techsolidity all the training courses consist of a minimum of two projects to offer the candidates real-time work understanding!