Rapid7 Nexpose
Connect an on-premises Nexpose console to import its assets and vulnerabilities into Guard.
Overview
PGP imports assets and vulnerabilities from an on-premises Rapid7 Nexpose Security Console through the Rapid7 InsightVM integration. Nexpose and InsightVM consoles use the same API v3, so there is no separate Nexpose integration card. See also Rapid7 InsightVM.
PGP only reads data from the Nexpose API. It never changes scan configurations, policies, or remediation states in Nexpose.
What the Integration Does
On each sync, PGP connects to the Nexpose Security Console REST API (v3) and:
- Imports assets -- Pages through all assets in the console and creates a PGP asset for each combination of hostname and IP address.
- Imports vulnerabilities -- For each asset with vulnerabilities, retrieves the findings at the asset level and for each service (protocol and port), and creates risks in triage.
- Maps severity -- Maps each vulnerability's Nexpose severity score (0--10) to a PGP severity (Info, Low, Medium, High, Critical).
- Attaches proof -- Attaches the Nexpose result data to each risk as proof.
Prerequisites
Before setting up the integration, ensure you have:
- A running Rapid7 Nexpose Security Console (or InsightVM console) with API access enabled
- A Nexpose user account with at least read-only permissions to view assets, sites, and vulnerabilities
- Network connectivity from PGP to your Nexpose console on the API port (default: TCP 3780)
- The base URL of your Nexpose console (e.g.,
https://nexpose.yourcompany.com:3780)
Creating a Nexpose API User
- Log in to your Nexpose Security Console
- Navigate to Administration > Users
- Click Create to add a new user
- Set the Authentication method to Normal
- Assign the Security Manager or Global Reader role (read-only access is sufficient)
- Save the user and note the username and password
Setup
- In PGP, go to Integrations > Vulnerability Management > Rapid7 InsightVM
- Enter the Security Console URL, Username, and Password
- Leave Import Assets and Import Vulnerabilities selected to import both, or clear one to skip it
- Click Connect. PGP saves the integration without testing the credentials; check the first sync for errors
Field Reference
Once connected, PGP will begin syncing asset and vulnerability data on its regular integration schedule.
What Data Is Synced
Assets
Each asset discovered by Nexpose is imported into PGP. An asset is created for every combination of hostname and IP address reported by the scanner.
Assets that lack either a hostname or IP address are skipped. Services are used only to look up per-service vulnerabilities; they are not imported as ports or attributes.
Risks (Vulnerabilities)
Vulnerabilities are imported at both the asset level and the per-service level. Risks are attached to the asset, not to a port.
API Endpoints Used
PGP uses the Nexpose Security Console REST API v3. All requests use Basic authentication and are read-only (GET).
PGP limits concurrent API requests to 10 parallel calls to avoid overloading your Nexpose console.
Troubleshooting
Security and Data Handling
- Read-only access -- PGP only performs GET requests against the Nexpose API. It never creates, modifies, or deletes any data in your Nexpose environment.
- Basic authentication -- Credentials are sent as a Base64-encoded
Authorization: Basicheader over HTTPS. Ensure your Nexpose console is configured with a valid TLS certificate. - Data residency -- Imported asset and vulnerability data is stored within your PGP tenant and subject to your organization's data retention policies.
- Minimal permissions -- Only read-level access is required. Use a dedicated account with the least privileges necessary.
If you need help with this integration, contact support@praetorian.com.
Still need help? Ask the team