Rapid7 InsightVM (beta)

Connect Nebulock Helix to Rapid7 InsightVM for just-in-time vulnerability enrichment.

The Rapid7 InsightVM integration enables Nebulock Helix to query vulnerability data from Rapid7 InsightVM on demand, during hunts and investigations.

Create a dedicated InsightVM user

Log in to Rapid7 InsightVM at insight.rapid7.com as an administrator, click the settings gear (top right), and go to Users.

Click Create User and fill in a first name, last name, and an email address you can access. The account must be activated by email, but it does not need to belong to a real person.

  • Under Manage Individual Permissions > Products, assign the user to the InsightVM product for your organization.
  • Under Manage Individual Permissions > Roles, assign the Administrator (shared) role or higher.

Click Add User, then open the activation email and activate the account.

📘

API keys inherit the permissions of the user they belong to. Use a dedicated service account with only the minimum permissions required, rather than a personal admin account.

Create the Platform API key

Log in as the user created above, click the settings gear (top right), and go to API Keys.

In the left navigation, go to API Key Management > Organization Keys. Click Generate New Admin Key and select Organization Admin Key. Select your organization, name the key, and generate it.

Copy the API key to a safe location — this is your integration token.

🚧

Rapid7 only displays the API key once. If it's lost, you cannot view it again — you'll need to generate a new one.

Enable the integration in Nebulock

In Nebulock, go to Settings > Integrations.

In the search bar, type "InsightVM" and click Add New Connection.

Enter the connection details:

  • Name: a description of your choice, e.g. "Nebulock InsightVM"
  • URL: your regional InsightVM base URL, without any path components, e.g. https://us2.api.insight.rapid7.com
  • Token: the Platform API key created above

Click Test, then Create Configuration.

Test the integration

Within Nebulock, navigate to Investigate. A simple "List the vulnerabilities from InsightVM" will pull data from your Rapid7 InsightVM instance.


What’s Next

Did this page help you?