Skip to main content
All CollectionsConnectionsProvider
Rapid7 InsightVM Connection
Rapid7 InsightVM Connection

This article walks through the details of configuring Rapid7 InsightVM to connect to Drata.

Updated over a week ago

Connecting Rapid7 InsightVM to Drata allows for the automated, continuous monitoring of SLA due dates and evidence collection of vulnerabilities issues required for compliance.

This integration automates evidence collection for the Vulnerability Scanning test, which is mapped to DCF-18 by default. You can view findings by selecting the View Findings button after connecting or navigating directly to the Vulnerabilities page through the left-side navigation menu.

Prerequisite

  • Create and copy Rapid7 API key. You will need this value when connecting Rapid7 to Drata.

    • To create a Rapid7 API key, you may need to enable Platform Administrator Privileges first.

      1. Log into Rapid7.

      2. Navigate to your Settings > User Management > Users.

      3. Edit User Details.

      4. Enable Make this user a Platform Administrator.

      5. After enabling the permission, you may need to sign out and then sign back in to ensure the changes are applied to your account. Once you have Platform administrator privileges, you can generate the API key within Rapid7.

  • Copy the base URL. You will need this value when connecting Rapid7 to Drata.

    • Note: The Base URL's format: https://{region}.api.insight.rapid7.com

      1. Log in to your account and navigate to the InsightVM page.

      2. Copy the base URL from the URL displayed in your browser's address bar. For example, if the URL is:
        โ€‹https://us3.exposure-analytics.api.insight.rapid7.com

        • BASE URL: https://us3.api.insight.rapid7.com

        • Region code: us3

      3. To learn more, refer to Rapid7's documentation.

Note: Drata will pull up to 1,000 new or updated vulnerabilities for each connection daily, ordered by severity from critical to low. You can select what kind of vulnerabilities will be synced based on the severity when connecting.

Connect Rapid7 InsightVM to Drata

  1. Select Connections from the left-side navigation menu.

  2. Go to the Available Connections tab and search for "Rapid7 InsightVM".

    • Alternatively, you can select Vulnerability Scanning under the Types section of the connections to search for the connection.

  3. In the connection drawer, you can select the severity and the date of the vulnerabilities you want to sync. These selections will also be included in the test result report for visibility.

    • Severity of vulnerabilities: Select the severity level of the vulnerabilities that you want to sync into Drata for compliance monitoring. Critical and High are auto-selected. Drata will bring up to 1000 new vulnerabilities or updates to vulnerabilities, sorted by severity.

    • First seen on: Select the date when the vulnerabilities you want to sync were first created. All vulnerabilities detected on and after this date will be synced.

  4. Select the connect button to proceed.

  5. Enter your API key and base URL.

Once the connection is successfully created, you can select the View Findings button on the connection card or navigate to the Vulnerabilities page to review and manage the synced vulnerabilities for compliance monitoring. Learn more at Vulnerabilities help article.

Did this answer your question?