Rapid7 Labs

Cybersecurity Intelligence, Threat Data, and Research

Rapid7 Labs tracks adversaries, shares proprietary, curated intelligence and research, and builds trusted open-source communities—all to help you improve your security program.

Yes, you know Rapid7 Labs

5,500+

Metasploit modules for threat-informed purple teaming

10,000+

Open-source researchers, pen testers, and threat hunters

Initial Access Brokers Report

The Rapid7 2025 Access Brokers Report takes an in-depth look at the underground marketplace for initial access to corporate networks. Our threat intelligence analysts examined hundreds of initial access broker (IAB) posts across three major forums to uncover new insights for detecting and containing these risks before they escalate. 

Access-brokers-guide-2025-promo.jpg

Ransomware Radar Report

The ransomware landscape continued to evolve rapidly in 2024. Threat actors persisted with their innovative tactics, and Rapid7 Labs researchers were monitoring their every move. The Ransomware Radar Report details the behavioral trends our team uncovered based upon their independent research as well as data samples from Rapid7’s Incident Response team. 

ransomware-report-ebook-cover.png

11,000+ customers are safer, and so is everybody else

Curated threat intel and AI, baked in

Curated threat intel and AI, baked in

Rapid7 Labs holds a slew of AI patents that power risk and threat analysis, and detect threats faster and prioritize vulnerabilities better.

Big issues & emergent threats

Big issues & emergent threats

In 2023, we tracked over 160 state-sponsored attacks—from one-off APT attacks to ongoing tracking of almost daily activity from APT groups.

Security communities for everyone

Security communities for everyone

Our open-source projects like Metasploit, Velociraptor, and AttackerKB have bi-directional feeds into our platform solutions.

Internet-scale data and research

Internet-scale data and research

Get easy insight into public internet exposure and exploit prevalence with Project Sonar, our internet-wide scanning technology, and our honeypot network Project Lorelei.

Real-time emergent threat guidance

Between Rapid7 Labs and our 24/7 follow-the-sun MDR, we observe 3.3 trillion security events every week. We perform in-depth technical analysis of emergent attack vectors, follow attacks as they evolve, and communicate indicators of compromise and next-step guidance in real time—click below to see our latest emergent threat coverage.

Rapid7-labs-real-time-emergent-threat.webp

Expert intelligence infused into Rapid7 products and services

Intelligence from Rapid7 Labs is built into our products and service offerings to help prioritize risks and uncover threats. This includes vulnerability checks in InsightVM, behavioral detections in InsightIDR and MDR, attack modules in InsightAppSec, exploits in Metasploit, and more.

screenshot-platform-attack_surface_clarity.jpg

Meet the research and intelligence teams doing unambiguous good

Raj Samani head shot

Raj Samani

Chief scientist

READ BIO
Christiaan Beek head shot

Christiaan Beek

Threat analytics

READ BIO

Interested in threat intelligence product offerings from Rapid7?