All integrations
Rapid7 InsightVM logo
// Data Integration · Vulnerability Management

Cracken + Rapid7 InsightVM

Rapid7 InsightVM's Active Risk score is built from what attackers are doing to everyone else. Cracken attacks those findings inside your scope. It reports which of them get an attacker anywhere here.

Get started
// 01

Connecting Rapid7 InsightVM

Connect with

An InsightVM API key and your InsightVM base URL

Cadence

Syncs on a schedule — every 6 hours by default, and the agent can force a fresh sync mid-operation

Requires

The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces

// 02

What Cracken gets from Rapid7 InsightVM

  • Vulnerability findings with severity (critical, high, medium, low, info) and state (new, active, re-opened, fixed)

  • cve list with cvss_base_score, cvss_vector, cvss_version and cvss_temporal_score

  • port, protocol and service on the affected host

  • device — hostnames, ipv4s, tags — which becomes a Device node linked to the Finding, and resource with its type and id/name

  • first_seen, last_seen, updated_at and state_updated_at

  • solution, patchable, category and vulnerability_url

  • vendor_id, vendor_severity and vendor_scan_id — Rapid7's own identifiers kept beside the normalized fields

// 03

What Rapid7 InsightVM does not do

Trigger Scan does not launch a scan in InsightVM — it posts an on-demand sync job to the hosted connection service to re-pull data, and its only parameter is optional tags. Nothing is written back: no InsightVM finding can be closed, excepted or assigned from Cracken, because the client exposes only read endpoints. Self-hosted deployments cannot connect it at all without the hosted connection service enabled.

// 04

How Cracken uses Rapid7 InsightVM

  1. 01

    Connect Rapid7 InsightVM

  2. 02

    Sync the vulnerability findings

  3. 03

    Prove which findings reach something

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does Cracken write anything back to Rapid7 InsightVM?

No — the Rapid7 InsightVM integration is read-only: Cracken pulls vulnerability findings and asset data out and keeps its validated results inside Cracken. It never closes findings, changes Active Risk scores, creates Remediation Projects, or launches InsightVM scans.

What does Cracken do with Rapid7 InsightVM findings?

Cracken loads InsightVM findings into the realm's Cybergraph as findings, CVEs, and affected devices. It attacks each inside the approved scope to establish which are genuinely reachable and which are noise.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Rapid7 InsightVM context.

See how Cracken works what Rapid7 InsightVM already knows into attack paths it proves end to end.