2018-07-29T06:51:00Z

What needs improvement with Rapid7 InsightVM?


Please share with the community what you think needs improvement with Rapid7 InsightVM.

What are its weaknesses? What would you like to see changed in a future version?

Guest
1010 Answers

author avatar
Top 10Reseller

I have had some difficult problems with InsightVM. The InsightVM cannot scan if we connect to our customer by the VPN. I asked the Rapid7 support, they told me that the InsightVM can only work on the same network. We cannot use InsightVM by VPN. It also consumes a lot of memory. It would be good if they could resolve that.

2020-03-16T06:56:00Z
author avatar
Top 5Real User

It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console. I don't have the time to log onto the console and use SSH to go through the logs. We have some users with certain privileges, and sometimes they do things that I don't like. This is why it would be nice to have an easy way to report what is in the logs. In the next release, I would like to see reporting added to the console. It would be helpful to have reports to tell you who did what, who created reports, who created groups or who created tags.

2020-03-05T08:39:38Z
author avatar
Top 10Real User

The reporting is a little bit tricky because it can be difficult to exactly pinpoint some of the assets to filter them and generate a report. Improving the filtering capability would make the reporting easier. We would like to have penetration testing features built into Nexpose, as it is the next area that we are going to be concentrating on. We have not yet tried it, but it is on our roadmap.

2020-02-24T06:02:43Z
author avatar
Top 10Real User

There are some difficulties with the online reporting and lack of integrations, the information that you can get from the APIs in the software is not the best. There's still some fleshing out of their API that I think could benefit them as well. I'd like to see more integrations with ticketing systems. Right now, JIRA and ServiceNow are the only ticketing systems that have integration with Rapid7. Extending that would be big. Some additional integrations with some patch management solutions would be good too. IBM BigFix and SCCM. Microsoft has integrations there. In our situation, we're not using either of those and that feature doesn't really give us a whole lot. If there were to be new integrations added on, both on the patch management and the ITMS side, that would be a big improvement. Additional features would be the additional integrations for ticketing systems that I mentioned. There are always updates rolling out for new scans and things.

2020-02-24T06:02:00Z
author avatar
Top 5LeaderboardReal User

The reporting has room for improvement. You cannot customize any report. If I need a specific requirement, I have to create a new report for it. I cannot pull up two or three things in one report.

2020-01-15T08:03:00Z
author avatar
Top 5LeaderboardReal User

We need to scan and identify the different RPGs, the critical ones and the major ones that can generate risk or a measure of risk. We generate the reporting from the system and relay the report to our internal developers. We have our internal developers in the bank. This solution integrates with another module in Metasploit, that doesn't exist in the other solutions. It is subscribed to on our roadmap, but we chose to implement both Nexppose and AppSpider.

2019-11-07T10:35:00Z
author avatar
Top 20Real User

A definite improvement would be to make it easier to run ad-hoc scans without needing to assign the asset to a site or group.

2019-04-25T23:21:00Z
author avatar
Real User

There are not enough templates, and the reporting is weak with this solution. It would be great if there were more templates for the analytical reports, such as patch management reports. At present, these do not exist. In addition, there are false positives.

2018-10-28T09:33:00Z
author avatar
Consultant

It gives false positives at times, and this a problem. It causes problems with reporting. In addition, I did not find plug-ins for a Rapid7 InsightVM. It would be much more informational to run it through directly, so once the app is installed, once the software is installed on that particular server, it would find what exactly that application is open for. This would make things easier for us.

2018-10-28T09:33:00Z
author avatar
Real User

We could always have a cheaper price, but other than that it's pretty good stuff. Also, if they’d expand their product line, that would be good, and they are doing so, but they're not done yet.

2018-07-29T06:51:00Z
Learn what your peers think about Rapid7 InsightVM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
442,764 professionals have used our research since 2012.