Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Rapid7 InsightVM Posture Report

Delivers a weekly report on InsightVM coverage across your assets, what changed in the vulnerability backlog, and anything in the console that needs an admin, from offline engines to license use.

What this agent does

This read-only agent checks the health of a Rapid7 InsightVM console every week. It finds assets that InsightVM has never scanned, has not scanned recently, or scans only without credentials. It summarizes the Critical and Severe vulnerabilities that appeared, were fixed, and were excepted since last week. It flags anything that needs an admin, such as a scan engine that is offline, Insight Agent assets with no recent assessment, a site schedule that keeps failing, pending exceptions nobody has reviewed, or license use close to the contract.

The challenge

InsightVM only finds vulnerabilities on the assets it scans, and coverage gaps raise no alert. A scan engine loses its connection to the console. Insight Agents behind a proxy change stop reporting. A discovery connection stops running, and new cloud instances never appear. A shared credential expires, and every scan on that site turns unauthenticated. Exceptions wait for approval for weeks, and approved exceptions expire with no one noticing. The licensed asset count grows past the contract, and admins find out at renewal.

The solution

The agent checks coverage, scan health, backlog movement, exception state, and console limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Find assets with no scan, no scan in the window, or only unauthenticated scans, and compare with the cloud inventory when I grant access.

  2. 02

    Check scan health

    Check scan engines, Insight Agent assessments, discovery connections, site schedules, and credential failures.

  3. 03

    Check the backlog

    Summarize Critical and Severe vulnerabilities opened, fixed, and excepted since last week, and list exceptions pending or expiring.

  4. 04

    Report

    Publish what changed, the license position, and what needs action, with the fix for each item.

Agent template

# Rapid7 InsightVM Posture Report

## Measurable outcomes

Every week, the admin knows which assets InsightVM is not covering, how the Critical and Severe backlog moved, and what needs action before it breaks. Track covered and uncovered assets, scan failures, pending exceptions, and open action items on every run.

## Procedure

Once a week, list the assets Rapid7 InsightVM knows about. Flag the ones with no scan in the last 14 days, unless I set another window, and the ones whose only recent scans ran without credentials. Judge authentication from the scan's credential results, not from the site's configuration alone. When I give it read-only access to my cloud accounts, compare their running instances with the assets in InsightVM and flag any instance InsightVM has never seen. Flag AWS and Azure discovery connections that failed or have not run during the window. Check each scan engine and flag any that are offline or on an outdated version. Flag assets in the Insight Agents site with no assessment during the window. Flag site schedules whose last scan failed, was aborted, or scanned fewer assets than the scan before. Summarize the Critical and Severe vulnerabilities that appeared, were fixed, and were excepted since the last report, with who submitted and approved each exception and the reason they gave. List exceptions pending approval for more than 7 days and exceptions that expire within 30 days. Compare licensed asset use with the contract's limit, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Replace hostnames, IP addresses, and user names with stable pseudonyms in the report. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Rapid7 InsightVM API access to assets, vulnerabilities, sites, scans, scan engines, discovery connections, and vulnerability exceptions, optional read-only access to the cloud accounts for the inventory comparison, and nothing more. It never changes scans, sites, exceptions, connections, or settings.