Rapid7
runZero integrates with Rapid7’s InsightVM and Nexpose to enrich your asset inventory and show you the vulnerabilities detected in your environment.
Asset inventory
The asset inventory page has a column with the count of vulnerabilities Rapid7 detected for each asset. Select a single asset and the vulnerabilities table lists every result for it. The type of vulnerability scan and the import settings you select can both affect the vulnerability count.
Vulnerabilities table
The Vulnerabilities tab of the inventory lists every vulnerability result imported from Rapid7. Selecting a result takes you to the page for the affected asset.
Severity and risk scores
Rapid7 assigns every vulnerability a severity rating (Moderate, Severe, or Critical) based on its CVSSv2 score. runZero normalizes these severities so the vulnerability inventory is consistent across the runZero Console.
| runZero Severity | Rapid7 Severity | CVSS Range |
|---|---|---|
| Info | Moderate | 0.0 |
| Medium | Moderate | 0.1 - 3.4 |
| High | Severe | 3.5 - 7.4 |
| Critical | Critical | 7.5 - 10.0 |
runZero also normalizes the risk scores Rapid7 assigns. A risk score of 0.0 appears as none in the runZero Console, and every other risk score matches the assigned severity level.