Rapid7 InsightVM
Overview
Rapid7 InsightVM (formerly Nexpose) provides vulnerability management with live monitoring, risk scoring, and remediation tracking. KYRA MDR collects vulnerability assessment data, asset inventories, and risk scores via the InsightVM API to correlate vulnerability context with detected threats and prioritize incident response.
Prerequisites
- KYRA MDR account (MDR tier or above)
- KYRA Collector installed with outbound HTTPS access to the InsightVM console or Rapid7 Insight platform
- Rapid7 InsightVM on-premises console or InsightVM Cloud account
- API key with appropriate permissions (Global Administrator or custom role with asset/vulnerability read access)
Configuration
Step 1: Generate an API Key
For InsightVM Cloud (Insight Platform):
- Log in to insight.rapid7.com
- Navigate to Settings > API Keys
- Click New User Key
- Enter a name (e.g., “KYRA MDR Integration”)
- Click Generate and record the API key
For on-premises InsightVM Console:
- Log in to the InsightVM Security Console at
https://<console>:3780 - Navigate to Administration > Global Settings > Authentication
- Generate an API key for the integration service account
Step 2: Configure KYRA Collector
source: type: rapid7-insightvm # For InsightVM Cloud: api_url: "https://us.api.insight.rapid7.com" # For on-premises console: # api_url: "https://<CONSOLE_IP>:3780" api_key: "<API_KEY>" poll_interval: 3600 # seconds (hourly for vulnerability data) verify_ssl: true # set to false for self-signed certs on-prem collect: - assets - vulnerabilities - risk_scoreskyra-collector reloadkyra-collector statusStep 3: Verify API Connectivity
Test the InsightVM API directly:
# InsightVM Cloud - List assets (paginated)curl -s -H "X-Api-Key: <API_KEY>" \ "https://us.api.insight.rapid7.com/vm/v4/integration/assets?size=5" \ | jq '.resources[:3] | .[].host_name'
# InsightVM Cloud - Get vulnerability detailscurl -s -H "X-Api-Key: <API_KEY>" \ "https://us.api.insight.rapid7.com/vm/v4/integration/vulnerabilities?size=5" \ | jq '.resources[:3] | .[] | {id, title, severity, cvss_v3_score: .cvss.v3.score}'
# On-premises console - List sitescurl -s -k -u '<USERNAME>:<PASSWORD>' \ "https://<CONSOLE_IP>:3780/api/3/sites" \ | jq '.resources[:3] | .[] | {id, name, assets}'Step 4: API Endpoints Used by KYRA Collector
The Collector polls these InsightVM API endpoints:
# Asset inventoryGET /vm/v4/integration/assets?size=500&page={n}
# Vulnerability findings per assetGET /vm/v4/integration/assets/{asset_id}/vulnerabilities
# Vulnerability definitions (title, description, CVSS, references)GET /vm/v4/integration/vulnerabilities?size=500&page={n}
# Asset search (filter by OS, software, risk score)POST /vm/v4/integration/assets/search{ "filters": [ {"field": "risk-score", "operator": "is-greater-than", "value": 5000} ]}
# Scan historyGET /api/3/sites/{site_id}/scan_history
# Remediation projects (on-premises API v3)GET /api/3/remediationsStep 5: Configure Vulnerability Export (Bulk)
For large environments, use the export API for efficient bulk data retrieval:
# Start a vulnerability exportEXPORT_ID=$(curl -s -X POST \ -H "X-Api-Key: <API_KEY>" \ -H "Content-Type: application/json" \ -d '{"status": ["vulnerable"], "severity": "critical"}' \ "https://us.api.insight.rapid7.com/vm/v4/exports/vulnerabilities" \ | jq -r '.id')
# Check export statuscurl -s -H "X-Api-Key: <API_KEY>" \ "https://us.api.insight.rapid7.com/vm/v4/exports/vulnerabilities/${EXPORT_ID}/status" \ | jq '.status'
# Download export when readycurl -s -H "X-Api-Key: <API_KEY>" \ "https://us.api.insight.rapid7.com/vm/v4/exports/vulnerabilities/${EXPORT_ID}/download" \ -o vuln-export.csvStep 6: Verify on KYRA Collector
kyra-collector logs --source rapid7 --tail 10Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Asset Inventory | Hostname, IP, OS, installed software, last scan time | Asset management |
| Vulnerability Findings | CVE ID, CVSS score, severity, affected asset, exploit availability | Risk identification |
| Risk Scores | Real Risk Score per asset (factors: CVSS, exploit maturity, asset exposure) | Risk prioritization |
| Scan Results | Scan completion, coverage percentage, new vs. remediated findings | Assessment tracking |
| Remediation Projects | Assigned remediations with status and deadline | Fix verification |
| Exploit Availability | Known exploit modules (Metasploit, public PoC) per vulnerability | Threat context |
Key Risk Score Thresholds
| Risk Score Range | Severity | Recommended Action |
|---|---|---|
| 0 - 999 | Low | Schedule remediation in next cycle |
| 1,000 - 4,999 | Medium | Remediate within 30 days |
| 5,000 - 9,999 | High | Remediate within 7 days |
| 10,000+ | Critical | Immediate remediation required |
Security Correlation Use Cases
| Correlation | Description |
|---|---|
| Alert + Critical Vuln | Alert targeting an asset with known critical vulnerability = high-priority incident |
| New Exploit Published | Vulnerability with newly available exploit on exposed asset = escalate |
| Scan Coverage Gap | Asset with no recent scan data = potential blind spot |
| Remediation Overdue | Vulnerability past remediation deadline = compliance risk |
Troubleshooting
- 401 Unauthorized: Verify the API key is valid and has not been revoked. For on-premises, ensure the user account has API access enabled.
- SSL certificate error: On-premises consoles use self-signed certificates by default. Set
verify_ssl: falsein the Collector configuration. - Connection refused on port 3780: Verify the InsightVM console is running and accessible. Check firewall rules between the Collector and the console.
- Large dataset timeouts: Use the export API (
/vm/v4/exports/) for environments with 10,000+ assets instead of paginated list endpoints. - Stale vulnerability data: InsightVM data reflects the last scan. If scans run weekly, vulnerability data may be up to 7 days old. Monitor
last_scan_timeper asset. - Rate limiting: The Insight Platform API has rate limits. The Collector uses exponential backoff. If limits are hit frequently, increase
poll_interval.
Contact kyra@seekerslab.com for integration support.