Rapid7 InsightVM
Rapid7 InsightVM: vulnerability management with risk-based prioritization. Active Risk scoring, remediation projects, agent and agentless scanning.

Key Features
- Active Risk Scoring - prioritization based on real risk
- Live Dashboards - real-time vulnerability visibility
- Remediation Projects - remediation project management
- Agent & Agentless - flexible scanning methods
- Cloud & Container - cloud and container support
Table of Contents
What is Rapid7 InsightVM?
Vulnerability management stops being a scanning problem within a week of the first scan and becomes a prioritization problem forever after. The cybersecurity question is not what was found but what gets fixed this month — and on what grounds the rest waits.
Rapid7 InsightVM is a vulnerability management platform that uses AI for risk prioritization and remediation automation. It is part of the Rapid7 Command Platform.
Key differentiators:
- Active Risk Scoring - scoring considering threat context
- Live Dashboards - real-time visibility
- Remediation Projects - remediation workflow
- 500+ integrations - ITOps automation
Active Risk Scoring
Unlike traditional CVSS, Active Risk Score considers:
graph LR
subgraph "Traditional CVSS"
A[Severity Score] --> B[Priority]
end
subgraph "Active Risk Score"
C[CVSS Base] --> G[Active Risk]
D[Exploit Availability] --> G
E[Malware Usage] --> G
F[Attacker Activity] --> G
H[Business Context] --> G
end
Active Risk Factors:
- CVSS Base Score - base vulnerability assessment
- Exploit Availability - exploit availability
- Malware Usage - usage in malware
- Attacker Activity - attacker activity
- Asset Criticality - asset criticality
Scanning Features
Discovery Methods
| Method | Description | Use Case |
|---|---|---|
| Agent-based | Insight Agent on endpoint | Endpoints, servers |
| Agentless | Network scanning | Legacy, OT |
| Cloud API | Cloud provider integration | AWS, Azure, GCP |
| Container | Image scanning | Docker, Kubernetes |
Scanning Scope
- Operating systems - Windows, Linux, macOS
- Applications - 80,000+ vulnerability checks
- Configurations - CIS Benchmarks, DISA STIG
- Cloud - AWS, Azure, GCP misconfigurations
- Containers - Docker, Kubernetes
Remediation Projects
InsightVM offers a unique approach to remediation:
[Vulnerability] --> [Remediation Project] --> [Assignment] --> [Tracking] --> [Verification]
|
[SLA Deadline]
|
[Progress Reports]
Remediation Projects Features:
- Vulnerability grouping - by solution, not individual CVEs
- Owner assignment - ticketing system integration
- SLA tracking - deadline monitoring
- Progress dashboards - progress visibility
- Auto-verification - automatic fix verification
Compliance & Reporting
Supported Standards
- CIS Benchmarks - Center for Internet Security
- PCI DSS - Payment Card Industry
- HIPAA - Healthcare compliance
- DISA STIG - Department of Defense
- NIST - National Institute of Standards
Reporting
- Executive dashboards - management view
- Technical reports - IT details
- Trend analysis - trend analysis
- Remediation reports - remediation reports
- Compliance reports - compliance reports
Integrations
ITSM & Ticketing
- ServiceNow (certified integration)
- Jira
- BMC Remedy
- Zendesk
Patch Management
- Microsoft SCCM/MECM
- Ivanti
- ManageEngine
- BigFix
SIEM/SOAR
- Splunk
- IBM QRadar
- Cortex XSOAR
Automation
- RESTful API
- PowerShell module
- Python SDK
Insight Agent
Lightweight agent for continuous monitoring:
- Size: ~25 MB
- CPU usage: <1%
- Memory: ~50 MB
- Automatic updates - self-updating
- Offline capability - offline operation
Agent Capabilities:
- Continuous vulnerability assessment
- Real-time asset data
- Log collection (for InsightIDR)
- Credential-less scanning
Who is it for?
Rapid7 InsightVM is for organizations that:
- Have many systems to monitor
- Need prioritization of thousands of vulnerabilities
- Require remediation workflow
- Want integration with ITSM and patch management
Comparison with Tenable
| Feature | InsightVM | Tenable.io |
|---|---|---|
| Active Risk Scoring | ✅ | VPR |
| Remediation Projects | ✅ | ✅ |
| Agent | ✅ | ✅ |
| Cloud scanning | ✅ | ✅ |
| Container scanning | ✅ | ✅ |
| SIEM integration | ✅ (InsightIDR) | Partial |
| Pricing model | Per-asset | Per-asset |
Deployment with nFlo
- Scoping - scanning scope definition
- Architecture - scanning architecture design
- Deployment - Scan Engine and Insight Agent installation
- Configuration - scan and policy configuration
- Integration - ITSM/patching integration
- Training - team training
- Optimization - tuning and optimization
Inquire about Rapid7 InsightVM
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
IT Vulnerability Management
Cybersecurity
Find and fix vulnerabilities before attackers exploit them. Prioritised by real risk.
Penetration Testing
Cybersecurity
Find vulnerabilities before hackers do. Report with PoC and recommendations in 5 days.
Web Services/API Security Testing
Cybersecurity
Find API vulnerabilities before they reach production. OWASP API Security Top 10.
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
From Our Knowledge Base
Articles related to this solution
IT services outsourcing — how to choose a provider and where to draw the line of responsibility
Choosing an IT provider is rarely settled on price. It is settled on where the line of responsibility runs between your company and the provider, and on who makes sure nothing on either side of that line is left without an owner.
Penetration test vs vulnerability scan: what really differs
A vulnerability scan and a penetration test answer two different questions, so they are not a cheaper and a pricier version of the same service. This article separates them by method, output, cost and place in the process.
Web application penetration testing cost and what creates it
The cost of a web application penetration test is a function of scope, not a property of the application. This article breaks the quote down into variables you can write into a request for proposal.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist