Automated Vulnerability Remediation FAQ

The following are common questions and answers about Automated VulnerabilityClosed A flaw, weakness, or error in code, design, or configuration that can be exploited by threat actors to compromise the security, functionality, or data of an application or system. RemediationClosed The act of mitigating a vulnerability or a threat, or the neutralization or elimination of a vulnerability or the likelihood of its exploitation. (AVR)

  1. If I execute any actions from AVR, will it restart those systems?
  2. Can I recreate a connection?
  3. Can you use Automated Vulnerability Remediation with Rapid7 Nexpose?
  4. Is it currently possible to leverage workletsClosed Represents an automation script that can execute on a set of devices, consisting of evaluation and remediation code blocks. Worklets can be OS-specific or targeting a platform-agnostic language. from the Worklet CatalogClosed Respository of pre-built, Automox-verified worklets, available in the Automox Console. for remediations?
  5. Is it possible to configure the integration to run at a particular time during the day?
    • No - The integration with Rapid7 is only configured to run on a schedule once per day at 4 AM MT.
  6. Why don't I see any CVEsClosed Represents a unique identifier for a vulnerability record as defined and cataloged by https://cve.mitre.org. for App Store on macOS?

Troubleshooting

  1. When a saved configuration runs, I receive an “invalid action connection unauthorized” error.
    • This error occurs when you select an invalid API key or region when creating a connection. Create a new connection and verify the API key and region are correct for your Rapid7 Platform organization.