Rapid7 Attribute Reference
Focus
Focus
Device Security

Rapid7 Attribute Reference

Table of Contents

Rapid7 Attribute Reference

This reference lists the attributes that Device Security collects from Rapid7, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Rapid7, it enhances vulnerability management for your devices. The attributes in this reference cover scan engine records, site asset data, network interface details, and individual vulnerability findings.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

3 Scan Engines Attributes

Device Security collects 3 scan engines attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
address
rapid7.scan_engine.address
IP Address; id
Address
lastUpdatedDate
rapid7.scan_engine.lastUpdatedDate
Last Activity
LastUpdatedDate
serialNumber
rapid7.scan_engine.serialNumber
Serial Number
SerialNumber
isAWSPreAuthEngine
rapid7.isAWSPreAuthEngine
IsAWSPreAuthEngine
contentVersion
rapid7.scan_engine.contentVersion
ContentVersion
id
rapid7.scan_engine.id
Id
lastRefreshedDate
rapid7.scan_engine.lastRefreshedDate
LastRefreshedDate
name
rapid7.scan_engine.name
Name of the device
port
rapid7.scan_engine.port
Port
productVersion
rapid7.scan_engine.productVersion
ProductVersion
status
rapid7.scan_engine.status
Status of the device
sites
rapid7.sites
Sites

3 Site Assets Attributes

Device Security collects 3 site assets attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
hostName
rapid7.hostName
hostname
HostName
ip
rapid7.ip
IP Address
Ip
mac
MAC
Mac
osFingerprint.family
rapid7.osFingerprint.family
OS Group
Family
osFingerprint.vendor
rapid7.osFingerprint.vendor
OS Name
Device vendor
osFingerprint.version
rapid7.osFingerprint.version
OS Version
Version
os
rapid7.os
os_combined
Os
osFingerprint
raw_os
OsFingerprint
software
third_party_learned_installed_software
Software
assessedForPolicies
rapid7.assessedForPolicies
AssessedForPolicies
assessedForVulnerabilities
rapid7.assessedForVulnerabilities
AssessedForVulnerabilities
id
rapid7.assetId
Id
osCertainty
rapid7.osCertainty
OsCertainty
osFingerprint.architecture
rapid7.osFingerprint.architecture
Architecture
osFingerprint.description
rapid7.osFingerprint.description
Description
osFingerprint.product
rapid7.osFingerprint.product
Product
osFingerprint.systemName
rapid7.osFingerprint.systemName
SystemName
rawRiskScore
rapid7.rawRiskScore
RawRiskScore
riskScore
rapid7.riskScore
RiskScore
site.scanEngine
rapid7.scanEngineId
ScanEngine
site.scanTemplate
rapid7.scanTemplate
ScanTemplate
site.lastScanTime
rapid7.site.lastScanTime
LastScanTime
site.id
rapid7.siteId
Id
site.name
rapid7.siteName
Name of the device

Insight Agent Assets Attributes

Device Security collects insight agent assets attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
host.hostNames.name
rapid7.hostName
hostname
Name of the device
host.primaryAddress.mac
id; MAC
Mac
host.primaryAddress.ip
IP Address
Ip
platform
rapid7.platform
OS Group
Platform
publicIpAddress
rapid7.public_ip_address
public_ip_address
PublicIpAddress
agent.agentSemanticVersion
rapid7.agent.agentSemanticVersion
AgentSemanticVersion
agent.agentStatus
rapid7.agent.agentStatus
AgentStatus
agent.id
rapid7.agent.id
Id
agent.quarantineState.currentState
rapid7.agent.quarantineState.currentState
CurrentState

3 Site Assets Interfaces Attributes

Device Security collects 3 site assets interfaces attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
mac
id; MAC
Mac
ip
IP Address
Ip
addresses
third_party_learned_network_interfaces
Addresses

3 Vuln Assets Attributes

Device Security collects 3 vuln assets attributes from Rapid7. The following table lists each Rapid7 attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Rapid7 Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cveId
cve
CveId
cvssScore
cvss_base_score
CvssScore
published
rapid7.published
detected_time
Published
mac
id
Mac
severity
rapid7.severity
risk_level; severity
Severity
solution
rapid7.solution
solution
Solution
title
rapid7.title
title
Title
asset_id
rapid7.assetId
Asset ID
riskScore
rapid7.riskScore
RiskScore
severityScore
rapid7.severityScore
SeverityScore
* Only some attributes map to a Device Security Common Attribute.