Rapid7 InsightVM Posture Report
Delivers a weekly report on InsightVM coverage across your assets, what changed in the vulnerability backlog, and anything in the console that needs an admin, from offline engines to license use.
What this agent does
This read-only agent checks the health of a Rapid7 InsightVM console every week. It finds assets that InsightVM has never scanned, has not scanned recently, or scans only without credentials. It summarizes the Critical and Severe vulnerabilities that appeared, were fixed, and were excepted since last week. It flags anything that needs an admin, such as a scan engine that is offline, Insight Agent assets with no recent assessment, a site schedule that keeps failing, pending exceptions nobody has reviewed, or license use close to the contract.
The challenge
InsightVM only finds vulnerabilities on the assets it scans, and coverage gaps raise no alert. A scan engine loses its connection to the console. Insight Agents behind a proxy change stop reporting. A discovery connection stops running, and new cloud instances never appear. A shared credential expires, and every scan on that site turns unauthenticated. Exceptions wait for approval for weeks, and approved exceptions expire with no one noticing. The licensed asset count grows past the contract, and admins find out at renewal.
The solution
The agent checks coverage, scan health, backlog movement, exception state, and console limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
Find assets with no scan, no scan in the window, or only unauthenticated scans, and compare with the cloud inventory when I grant access.
- 02
Check scan health
Check scan engines, Insight Agent assessments, discovery connections, site schedules, and credential failures.
- 03
Check the backlog
Summarize Critical and Severe vulnerabilities opened, fixed, and excepted since last week, and list exceptions pending or expiring.
- 04
Report
Publish what changed, the license position, and what needs action, with the fix for each item.
Agent template
# Rapid7 InsightVM Posture Report
## Measurable outcomes
Every week, the admin knows which assets InsightVM is not covering, how the Critical and Severe backlog moved, and what needs action before it breaks. Track covered and uncovered assets, scan failures, pending exceptions, and open action items on every run.
## Procedure
Once a week, list the assets Rapid7 InsightVM knows about. Flag the ones with no scan in the last 14 days, unless I set another window, and the ones whose only recent scans ran without credentials. Judge authentication from the scan's credential results, not from the site's configuration alone. When I give it read-only access to my cloud accounts, compare their running instances with the assets in InsightVM and flag any instance InsightVM has never seen. Flag AWS and Azure discovery connections that failed or have not run during the window. Check each scan engine and flag any that are offline or on an outdated version. Flag assets in the Insight Agents site with no assessment during the window. Flag site schedules whose last scan failed, was aborted, or scanned fewer assets than the scan before. Summarize the Critical and Severe vulnerabilities that appeared, were fixed, and were excepted since the last report, with who submitted and approved each exception and the reason they gave. List exceptions pending approval for more than 7 days and exceptions that expire within 30 days. Compare licensed asset use with the contract's limit, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Replace hostnames, IP addresses, and user names with stable pseudonyms in the report. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Rapid7 InsightVM API access to assets, vulnerabilities, sites, scans, scan engines, discovery connections, and vulnerability exceptions, optional read-only access to the cloud accounts for the inventory comparison, and nothing more. It never changes scans, sites, exceptions, connections, or settings. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools