Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Rapid7 InsightVM Connector Guide

Prev Next

Rapid7 InsightVM provides vulnerability assessment for local, remote, cloud, containerized, and virtual infrastructures. The Balbix integration with Rapid7 InsightVM ingests IT Infrastructure assets and associated vulnerabilities discovered by Rapid7 InsightVM.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the Rapid7 InsightVM connector.

Integration Type

Fetch: An inbound API integration used to fetch IT infrastructure assets, OS information and associated vulnerabilities.

Types of Assets Fetched

Host devices including servers, virtual machines, desktops, laptops.

Types of Data Fetched

Asset names, hardware information, interface information (MAC Address, IP Address), OS information​, custom vulnerabilities information, timestamps (e.g., custom vulnerabilities first observed at), tags.

Prerequisites

To configure the Balbix connector, you must first create Rapid7 InsightVM API credentials with the appropriate permissions. These credentials are required for completing the configuration process. Here are the steps you need to complete:

  1. Create an Organization or User Key: The platform supports two types of API keys, as outlined below.

    • User Key: A unique key associated with a specific user within an organization. This key is created by the user and inherits the user's permissions. You cannot generate a user key for other users.

    • Organization Key: A powerful key assigned to the entire organization. As a super key, it grants full access to all actions across all products. You can generate an organization key only if you are a platform or organization administrator.

Generate an User Key

Any user can generate a user key, which inherits the permissions of their account. This means your API key can perform any actions that you are authorized to do. Follow these steps to create a user API key in Rapid7 InsightVM:

  1. Log in to your Insight account.

  2. Go to the API Keys page.

  3. Click New User Key.

  4. In the Generate New Organization Key panel, select an organization and provide a name for the key.

  5. Generate the key. A new window opens and displays the generated key.

  6. Copy the key and and securely save it for later use when setting up the Rapid7 InsightVM connector in Balbix.

Generate an Organization Key

Only a platform or organization administrator can generate an organization key. Follow these steps to create an organization API key in Rapid7 InsightVM:

  1. Log in to your Insight account.

  2. Go to the API Keys page.

  3. Go to the Organization Keys tab and click New Organization Key.

  4. In the Generate New Organization Key panel, select an organization and provide a name for the key.

  5. Generate the key. A new window opens and displays the generated key.

  6. Copy the key and securely save it for later use when setting up the Rapid7 InsightVM connector in Balbix.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Rapid7 InsightVM.

Field Mapping

Imported Field

Balbix Field

Asset IP Address

ip_address

Asset Names

host_name

Asset OS Name

os_name

Asset OS Version

os_version

Custom Tag

tags

Service Name

open_port_service

Service Port

open_port_num

Service Product

sw_product_name

Vulnerability CVE IDs

cve_id

Vulnerability Description

cve_description

Vulnerability ID

custom_vuln_id

Vulnerability Severity Level

custom_vuln_severity

Vulnerability Test Date

cve_last_observed_at

Vulnerability Test Result Description

cve_exploit_status

Vulnerability Title

cve_name

Vulnerable Since

cve_first_observed_at

Asset MAC Addresses

mac_address

Service Protocol

open_port_protocol

API Documentation

To learn more about the Rapid7 InsightVM API, see the references listed below: