Solution: Rapid7InsightVM
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | domains |
| Version | 3.2.0 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2021-07-07 |
| Solution Folder | Rapid7InsightVM |
| Marketplace | Azure Marketplace · Popularity: 🔵 Medium (71%) |
The Rapid7 Insight platform brings together Rapid7’s library of vulnerability research, exploit knowledge, global attacker behavior, Internet-wide scanning data, exposure analytics, and real-time reporting to provide a fully available, scalable, and efficient way to collect your vulnerability data and turn it into answers. InsightVM leverages this platform for live vulnerability and endpoint analytics.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor HTTP Data Collector API b. Azure Functions
This solution provides 2 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 4 table(s):
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 5 content item(s):
| Content Type | Count |
|---|---|
| Playbooks | 3 |
| Parsers | 2 |
| Name | Description | Tables Used |
|---|---|---|
| Rapid7 Insight VM - Enrich incident with asset info | Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... | - |
| Rapid7 Insight VM - Enrich vulnerability info | Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... | - |
| Rapid7 Insight VM - Run scan | Once a new Microsoft Sentinel incident is created, this playbook gets triggered and performs the fol... | - |
| Name | Description | Tables Used |
|---|---|---|
| InsightVMAssets | - | NexposeInsightVMCloud_assets_CL (read)Rapid7InsightVMCloudAssets (read) |
| InsightVMVulnerabilities | - | NexposeInsightVMCloud_vulnerabilities_CL (read)Rapid7InsightVMCloudVulnerabilities (read) |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.2.0 | 05-03-2026 | Added new Rapid7InsightVM CCP data connector. |
| 3.1.1 | 05-02-2026 | Update Az Func packages related to InsightVMCloudData Connector |
| 3.1.0 | 03-02-2026 | Update Data Connector to use latest 4.x Azure Functions extension bundles |
| 3.0.1 | 03-05-2024 | Fixed Metadata issue for ParserName and ParentId mismatch |
| 3.0.0 | 16-01-2024 | Updated Manual Deployment instructions in Data Connector Description |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊