Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Rapid7 Nexpose On-Prem Connector Guide

Prev Next

Rapid7 Nexpose provides vulnerability assessment for local, remote, cloud, containerized, and virtual infrastructures. The Balbix integration with Rapid7 Nexpose ingests IT Infrastructure assets and associated vulnerabilities discovered by Rapid7 Nexpose. This guide provides the necessary steps to create and configure a Rapid7 Nexpose (on-premises) Balbix connector.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the Rapid7 Nexpose connector.

Integration Type

Fetch: An inbound API integration used to fetch IT infrastructure assets, OS information and associated vulnerabilities.

Types of Assets Fetched

Host devices (includes servers, virtual machines, desktops, laptops).

Types of Data Fetched

Asset names, hardware information, interface information (MAC address, IP address), OS information, software information, custom vulnerabilities information, timestamps (e.g., custom vulnerabilities first observed, etc.).

Prerequisites

To configure the Balbix connector, you must first create Rapid7 Nexpose API credentials with the appropriate permissions. These credentials are required for completing the configuration process. Here are the steps you need to complete:

  1. Log in to the Rapid7 Security Console.

  2. Select the Administration tab.

  3. Click Manage users In the User Management section.

  4. Click Add User and fill in the required details in the User Info section.

    • User Role: Choose the appropriate role for the user.

    • Site Permissions: Select the site(s) the user will have access to.

    • Asset Group Permissions: Specify the asset group(s) the user can access.

  5. Click Save to create the user account.

  6. Copy the username and password and securely save them for later use when setting up the Rapid7 Nexpose connector in Balbix.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Rapid7 Nexpose.

Field Mapping

Imported Field

Balbix Field

Asset IP Address

ip_address

Asset Names

host_name

Asset OS Name

os_name

Asset OS Version

os_version

Custom Tag

tags

Service Name

open_port_service

Service Port

open_port_num

Service Product

sw_product_name

Vulnerability CVE IDs

cve_id

Vulnerability Description

cve_description

Vulnerability ID

custom_vuln_id

Vulnerability Severity Level

custom_vuln_severity

Vulnerability Test Date

cve_last_observed_at

Vulnerability Test Result Description

cve_exploit_status

Vulnerability Title

cve_name

Vulnerable Since

cve_first_observed_at

Asset MAC Addresses

mac_address

Service Protocol

open_port_protocol

API Reference Documentation

To learn more about the Rapid7 Nexpose API, see the references listed below: