Skip to main content
Vulnerability Management (VM)

Rapid7 InsightVM

Import InsightVM assets and vulnerabilities into Guard from your Security Console or an uploaded XML report.

The Rapid7 InsightVM integration imports assets and vulnerabilities from InsightVM into the Praetorian Guard Platform (PGP). There are two methods: an API integration that syncs on a schedule, and a manual import of an InsightVM XML report.

API Integration

PGP connects to the InsightVM Security Console through its API v3.

  1. In PGP, go to Integrations > Vulnerability Management > Rapid7 InsightVM.
  2. Click Connect and enter:
    • Security Console URL -- for example https://<console-host>:3780.
    • Username and Password for an InsightVM user that can read assets and vulnerabilities.
  3. Leave Import Assets and Import Vulnerabilities selected to import both, or clear one to skip it.
  4. Click Connect.

What the API integration imports

  • Assets -- For each InsightVM asset, PGP creates an asset for each combination of the asset's hostnames and IP addresses. Assets are filtered through your PGP scope.
  • Vulnerabilities -- For each asset with vulnerabilities, PGP imports the asset-level and service-level (port and protocol) vulnerabilities as risks in triage, named by the InsightVM vulnerability ID. The InsightVM results for each finding are attached as proof.
  • Severity -- PGP maps the InsightVM severity score (0–10): 0–2 is Info, 3–4 is Low, 5–6 is Medium, 7–8 is High, and 9–10 is Critical.

Manually import scan results

  1. In the InsightVM console, go to Reports > Console-Generated and select Create a report.
  2. Enter a name for the report and select Export.
  3. Select the XML Export 2.0 format.
  4. Select the scope of the export, usually a subset of the sites defined in InsightVM.
  5. Click Save and Run the Report and download the .xml file.
  6. In PGP, go to Vulnerabilities, click Import, and select InsightVM.

PGP creates an asset for each node name and address in the report, and a risk in triage for each test result on the node and its endpoints. Severity uses the same 0–10 mapping as the API integration. If the file cannot be read, PGP shows InsightVM XML file was invalid. Did you upload a XML 2.0 export file?

If you need help with this integration, contact support@praetorian.com.

Still need help? Ask the team