Rapid7 Attribute Reference
Focus
Focus
Device Security

Rapid7 Attribute Reference

Table of Contents

Rapid7 Attribute Reference

This reference lists the attributes that Device Security collects from Rapid7, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Rapid7, it enhances vulnerability management for your devices. The attributes in this reference cover scan engine records, site asset data, network interface details, and individual vulnerability findings.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Scan Engine Attributes

Device Security collects scan engine attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
address
rapid7.scan_engine.address
IP Address; id
Address
lastUpdatedDate
rapid7.scan_engine.lastUpdatedDate
Last Activity
Last updated date
serialNumber
rapid7.scan_engine.serialNumber
Serial Number
Serial number
isAWSPreAuthEngine
rapid7.isAWSPreAuthEngine
—
Is aws pre auth engine
contentVersion
rapid7.scan_engine.contentVersion
—
Content version
id
rapid7.scan_engine.id
—
Unique identifier
lastRefreshedDate
rapid7.scan_engine.lastRefreshedDate
—
Last refreshed date
name
rapid7.scan_engine.name
—
Name of the device
port
rapid7.scan_engine.port
—
Port
productVersion
rapid7.scan_engine.productVersion
—
Product version
status
rapid7.scan_engine.status
—
Status of the device
sites
rapid7.sites
—
Sites

Asset Attributes

Device Security collects asset attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
hostName
rapid7.hostName
hostname
Host name
ip
rapid7.ip
IP Address
IP
mac
—
MAC Address; id
MAC address
osFingerprint.family
rapid7.osFingerprint.family
OS Group
Family
osFingerprint.product
rapid7.osFingerprint.product
OS Name
Product
osFingerprint.version
rapid7.osFingerprint.version
OS Version
Version
osFingerprint
—
raw_os
OS fingerprint
software
—
third_party_learned_installed_software
Software
assessedForPolicies
rapid7.assessedForPolicies
—
Assessed for policies
assessedForVulnerabilities
rapid7.assessedForVulnerabilities
—
Assessed for vulnerabilities
id
rapid7.assetId
—
Unique identifier
os
rapid7.os
—
OS
osCertainty
rapid7.osCertainty
—
OS certainty
osFingerprint.architecture
rapid7.osFingerprint.architecture
—
Architecture
osFingerprint.description
rapid7.osFingerprint.description
—
Description
osFingerprint.systemName
rapid7.osFingerprint.systemName
—
System name
osFingerprint.vendor
rapid7.osFingerprint.vendor
—
Device vendor
rawRiskScore
rapid7.rawRiskScore
—
Raw risk score
riskScore
rapid7.riskScore
—
Risk score
site.scanEngine
rapid7.scanEngineId
—
Scan engine
site.scanTemplate
rapid7.scanTemplate
—
Scan template
site.lastScanTime
rapid7.site.lastScanTime
—
Last scan time
site.id
rapid7.siteId
—
Unique identifier
site.name
rapid7.siteName
—
Name of the device

Asset Attributes (Legacy)

Device Security collects asset attributes (legacy) from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
host.hostNames.name
rapid7.hostName
hostname
Name of the device
host.primaryAddress.mac
—
id; MAC Address
MAC address
host.primaryAddress.ip
—
IP Address
IP
platform
rapid7.platform
OS Group
Platform
publicIpAddress
rapid7.public_ip_address
public_ip_address
Public IP address
agent.agentSemanticVersion
rapid7.agent.agentSemanticVersion
—
Agent semantic version
agent.agentStatus
rapid7.agent.agentStatus
—
Agent status
agent.id
rapid7.agent.id
—
Unique identifier
agent.quarantineState.currentState
rapid7.agent.quarantineState.currentState
—
Current state

Asset Interface Attributes

Device Security collects asset interface attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
mac
—
id; MAC Address
MAC address
ip
—
IP Address
IP
addresses
—
third_party_learned_network_interfaces
Addresses

Vulnerable Asset Attributes

Device Security collects vulnerable asset attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cveId
—
cve
Cve ID
cvssScore
—
cvss_base_score
Cvss score
published
rapid7.published
detected_time
Published
mac
—
id
MAC address
severity
rapid7.severity
risk_level; severity
Severity
solution
rapid7.solution
solution
Solution
title
rapid7.title
title
Title
asset_id
rapid7.assetId
—
Asset ID
riskScore
rapid7.riskScore
—
Risk score
severityScore
rapid7.severityScore
—
Severity score
* Only some attributes map to a Device Security Common Attribute.