Skip to main content
Vulnerability Management (VM)

Rapid7 Nexpose

Connect an on-premises Nexpose console to import its assets and vulnerabilities into Guard.

Overview

PGP imports assets and vulnerabilities from an on-premises Rapid7 Nexpose Security Console through the Rapid7 InsightVM integration. Nexpose and InsightVM consoles use the same API v3, so there is no separate Nexpose integration card. See also Rapid7 InsightVM.

PGP only reads data from the Nexpose API. It never changes scan configurations, policies, or remediation states in Nexpose.

What the Integration Does

On each sync, PGP connects to the Nexpose Security Console REST API (v3) and:

  • Imports assets -- Pages through all assets in the console and creates a PGP asset for each combination of hostname and IP address.
  • Imports vulnerabilities -- For each asset with vulnerabilities, retrieves the findings at the asset level and for each service (protocol and port), and creates risks in triage.
  • Maps severity -- Maps each vulnerability's Nexpose severity score (0--10) to a PGP severity (Info, Low, Medium, High, Critical).
  • Attaches proof -- Attaches the Nexpose result data to each risk as proof.

Prerequisites

Before setting up the integration, ensure you have:

  • A running Rapid7 Nexpose Security Console (or InsightVM console) with API access enabled
  • A Nexpose user account with at least read-only permissions to view assets, sites, and vulnerabilities
  • Network connectivity from PGP to your Nexpose console on the API port (default: TCP 3780)
  • The base URL of your Nexpose console (e.g., https://nexpose.yourcompany.com:3780)

Creating a Nexpose API User

  • Log in to your Nexpose Security Console
  • Navigate to Administration > Users
  • Click Create to add a new user
  • Set the Authentication method to Normal
  • Assign the Security Manager or Global Reader role (read-only access is sufficient)
  • Save the user and note the username and password

Setup

  • In PGP, go to Integrations > Vulnerability Management > Rapid7 InsightVM
  • Enter the Security Console URL, Username, and Password
  • Leave Import Assets and Import Vulnerabilities selected to import both, or clear one to skip it
  • Click Connect. PGP saves the integration without testing the credentials; check the first sync for errors

Field Reference

Field

Description

Example

Security Console URL

The base URL of your Nexpose Security Console, including port

https://nexpose.yourcompany.com:3780

Username

Nexpose user account with API read access

pgp-readonly

Password

Password for the Nexpose user account

****

Once connected, PGP will begin syncing asset and vulnerability data on its regular integration schedule.

What Data Is Synced

Assets

Each asset discovered by Nexpose is imported into PGP. An asset is created for every combination of hostname and IP address reported by the scanner.

Nexpose Field

PGP Field

Description

hostnames[].name

Asset name

The hostname associated with the asset

addresses[].ip

Asset IP

The IP address of the asset

Assets that lack either a hostname or IP address are skipped. Services are used only to look up per-service vulnerabilities; they are not imported as ports or attributes.

Risks (Vulnerabilities)

Vulnerabilities are imported at both the asset level and the per-service level. Risks are attached to the asset, not to a port.

Nexpose Field

PGP Field

Description

Vulnerability ID

Risk ID

The Nexpose vulnerability identifier (e.g., ssl-cve-2014-0224)

severityScore (0--10)

Severity

Mapped to PGP severity: 0--2 = Info, 3--4 = Low, 5--6 = Medium, 7--8 = High, 9--10 = Critical

Vulnerability results

Proof artifact

Raw scan evidence attached to each risk

API Endpoints Used

PGP uses the Nexpose Security Console REST API v3. All requests use Basic authentication and are read-only (GET).

Purpose

Endpoint

Method

Notes

List assets

GET /api/3/assets?page={n}&size=500

GET

Paginated; retrieves all assets with addresses, hostnames, and services

Asset vulnerabilities

GET /api/3/assets/{id}/vulnerabilities?page={n}&size=500

GET

Paginated; all vulnerabilities for a given asset

Service vulnerabilities

GET /api/3/assets/{id}/services/{protocol}/{port}/vulnerabilities?page={n}&size=500

GET

Paginated; vulnerabilities specific to a service on an asset

Vulnerability detail

GET /api/3/vulnerabilities/{id}

GET

Retrieves severity score for a specific vulnerability; results are cached

PGP limits concurrent API requests to 10 parallel calls to avoid overloading your Nexpose console.

Troubleshooting

Issue

Cause

Fix

Connection refused or timeout

PGP cannot reach the Nexpose console on the network

Verify network connectivity and firewall rules allow PGP to reach the console URL and port (default 3780)

401 Unauthorized

Invalid username or password

Verify the credentials in PGP match a valid Nexpose user account

403 Forbidden

User account lacks sufficient permissions

Ensure the Nexpose user has at least a Global Reader or Security Manager role

No assets appearing

Nexpose has no completed scans or all assets are filtered

Confirm that Nexpose has completed at least one scan and that assets have hostnames and IP addresses

Missing vulnerabilities

Asset has no vulnerability findings in Nexpose

Verify the asset has been scanned with a policy that includes vulnerability checks

SSL certificate errors

Nexpose console uses a self-signed certificate

Ensure the console URL uses HTTPS and that PGP can trust the certificate (contact your Praetorian team if needed)

Security and Data Handling

  • Read-only access -- PGP only performs GET requests against the Nexpose API. It never creates, modifies, or deletes any data in your Nexpose environment.
  • Basic authentication -- Credentials are sent as a Base64-encoded Authorization: Basic header over HTTPS. Ensure your Nexpose console is configured with a valid TLS certificate.
  • Data residency -- Imported asset and vulnerability data is stored within your PGP tenant and subject to your organization's data retention policies.
  • Minimal permissions -- Only read-level access is required. Use a dedicated account with the least privileges necessary.

If you need help with this integration, contact support@praetorian.com.

Still need help? Ask the team