Rapid7 Attribute Reference
This reference lists the attributes that Device Security collects from Rapid7,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with Rapid7, it enhances vulnerability
management for your devices. The attributes in this reference cover scan engine
records, site asset data, network interface details, and individual vulnerability
findings.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Scan Engine Attributes
Device Security collects scan engine attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
address | rapid7.scan_engine.address | IP Address; id | Address |
lastUpdatedDate | rapid7.scan_engine.lastUpdatedDate | Last Activity | Last updated date |
serialNumber | rapid7.scan_engine.serialNumber | Serial Number | Serial number |
isAWSPreAuthEngine | rapid7.isAWSPreAuthEngine | — | Is aws pre auth engine |
contentVersion | rapid7.scan_engine.contentVersion | — | Content version |
id | rapid7.scan_engine.id | — | Unique identifier |
lastRefreshedDate | rapid7.scan_engine.lastRefreshedDate | — | Last refreshed date |
name | rapid7.scan_engine.name | — | Name of the device |
port | rapid7.scan_engine.port | — | Port |
productVersion | rapid7.scan_engine.productVersion | — | Product version |
status | rapid7.scan_engine.status | — | Status of the device |
Asset Attributes
Device Security collects asset attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
hostName | rapid7.hostName | hostname | Host name |
mac | — | MAC Address; id | MAC address |
osFingerprint.family | rapid7.osFingerprint.family | OS Group | Family |
osFingerprint.product | rapid7.osFingerprint.product | OS Name | Product |
osFingerprint.version | rapid7.osFingerprint.version | OS Version | Version |
osFingerprint | — | raw_os | OS fingerprint |
software | — | third_party_learned_installed_software | Software |
assessedForPolicies | rapid7.assessedForPolicies | — | Assessed for policies |
assessedForVulnerabilities | rapid7.assessedForVulnerabilities | — | Assessed for vulnerabilities |
id | rapid7.assetId | — | Unique identifier |
osCertainty | rapid7.osCertainty | — | OS certainty |
osFingerprint.architecture | rapid7.osFingerprint.architecture | — | Architecture |
osFingerprint.description | rapid7.osFingerprint.description | — | Description |
osFingerprint.systemName | rapid7.osFingerprint.systemName | — | System name |
osFingerprint.vendor | rapid7.osFingerprint.vendor | — | Device vendor |
rawRiskScore | rapid7.rawRiskScore | — | Raw risk score |
riskScore | rapid7.riskScore | — | Risk score |
site.scanEngine | rapid7.scanEngineId | — | Scan engine |
site.scanTemplate | rapid7.scanTemplate | — | Scan template |
site.lastScanTime | rapid7.site.lastScanTime | — | Last scan time |
site.id | rapid7.siteId | — | Unique identifier |
site.name | rapid7.siteName | — | Name of the device |
Asset Attributes (Legacy)
Device Security collects asset attributes (legacy) from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
host.hostNames.name | rapid7.hostName | hostname | Name of the device |
host.primaryAddress.mac | — | id; MAC Address | MAC address |
host.primaryAddress.ip | — | IP Address | IP |
platform | rapid7.platform | OS Group | Platform |
publicIpAddress | rapid7.public_ip_address | public_ip_address | Public IP address |
agent.agentSemanticVersion | rapid7.agent.agentSemanticVersion | — | Agent semantic version |
agent.agentStatus | rapid7.agent.agentStatus | — | Agent status |
agent.id | rapid7.agent.id | — | Unique identifier |
agent.quarantineState.currentState | rapid7.agent.quarantineState.currentState | — | Current state |
Asset Interface Attributes
Device Security collects asset interface attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
mac | — | id; MAC Address | MAC address |
addresses | — | third_party_learned_network_interfaces | Addresses |
Vulnerable Asset Attributes
Device Security collects vulnerable asset attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
cvssScore | — | cvss_base_score | Cvss score |
published | rapid7.published | detected_time | Published |
severity | rapid7.severity | risk_level; severity | Severity |
solution | rapid7.solution | solution | Solution |
title | rapid7.title | title | Title |
asset_id | rapid7.assetId | — | Asset ID |
riskScore | rapid7.riskScore | — | Risk score |
severityScore | rapid7.severityScore | — | Severity score |
* Only some attributes map to a Device Security Common Attribute.