
Cracken + Rapid7 InsightVM
Rapid7 InsightVM's Active Risk score is built from what attackers are doing to everyone else. Cracken attacks those findings inside your scope. It reports which of them get an attacker anywhere here.
Connecting Rapid7 InsightVM
- Connect with
An InsightVM API key and your InsightVM base URL
- Cadence
Syncs on a schedule — every 6 hours by default, and the agent can force a fresh sync mid-operation
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from Rapid7 InsightVM
Vulnerability findings with severity (critical, high, medium, low, info) and state (new, active, re-opened, fixed)
cve list with cvss_base_score, cvss_vector, cvss_version and cvss_temporal_score
port, protocol and service on the affected host
device — hostnames, ipv4s, tags — which becomes a Device node linked to the Finding, and resource with its type and id/name
first_seen, last_seen, updated_at and state_updated_at
solution, patchable, category and vulnerability_url
vendor_id, vendor_severity and vendor_scan_id — Rapid7's own identifiers kept beside the normalized fields
What Rapid7 InsightVM does not do
Trigger Scan does not launch a scan in InsightVM — it posts an on-demand sync job to the hosted connection service to re-pull data, and its only parameter is optional tags. Nothing is written back: no InsightVM finding can be closed, excepted or assigned from Cracken, because the client exposes only read endpoints. Self-hosted deployments cannot connect it at all without the hosted connection service enabled.
How Cracken uses Rapid7 InsightVM
- 01
Connect Rapid7 InsightVM
- 02
Sync the vulnerability findings
- 03
Prove which findings reach something
- 04
Confirm it connected
Frequently asked questions
Does Cracken write anything back to Rapid7 InsightVM?
No — the Rapid7 InsightVM integration is read-only: Cracken pulls vulnerability findings and asset data out and keeps its validated results inside Cracken. It never closes findings, changes Active Risk scores, creates Remediation Projects, or launches InsightVM scans.
What does Cracken do with Rapid7 InsightVM findings?
Cracken loads InsightVM findings into the realm's Cybergraph as findings, CVEs, and affected devices. It attacks each inside the approved scope to establish which are genuinely reachable and which are noise.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Qualys
Cracken queries your Qualys detections live and launches a fresh scan when needed.
Amazon Inspector
Cracken proves which Amazon Inspector findings an attacker can actually reach.
Attack with real Rapid7 InsightVM context.
See how Cracken works what Rapid7 InsightVM already knows into attack paths it proves end to end.


