category: Vulnerability Management provider: Rapid7 sectionorder: - Connect - Collect commonfields: id: Rapid7 Nexpose version: -1 configuration: - display: Server URL (e.g., https://192.0.2.0:8080) name: server required: true type: 0 section: Connect - display: Username name: credentials required: true type: 9 section: Connect - display: 2FA Token name: token type: 9 hiddenusername: true displaypassword: 2FA Token required: false section: Connect - display: Trust any certificate (not secure) name: unsecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - defaultvalue: '5' display: "Number of connection error retries" name: connection_error_retries additionalinfo: "The number of times to try and re-create connections with rapid7 instance when there are temporary connection errors" type: 0 section: Connect - display: Fetch Assets name: isFetchAssets type: 8 section: Collect required: false hidden: - xsoar supportedModules: - xsiam - exposure_management - additionalinfo: The interval between asset fetches. Default is 24 hours. defaultvalue: 1440 display: Assets Fetch Interval name: assetsFetchInterval type: 19 section: Collect advanced: true required: false hidden: - xsoar supportedModules: - xsiam - exposure_management description: Vulnerability management solution to help reduce threat exposure. display: Rapid7 InsightVM name: Rapid7 Nexpose script: commands: - arguments: - description: Asset ID. name: id required: true description: Returns the specified asset. name: nexpose-get-asset outputs: - contextPath: Nexpose.Asset.Addresses description: All addresses discovered on the asset. type: unknown - contextPath: Nexpose.Asset.AssetId description: Id of the asset. type: number - contextPath: Nexpose.Asset.Hardware description: The primary Media Access Control (MAC) address of the asset. The format is six groups of two hexadecimal digits separated by colons. type: string - contextPath: Nexpose.Asset.Aliases description: All host names or aliases discovered on the asset. type: unknown - contextPath: Nexpose.Asset.HostType description: The type of asset. Valid values are unknown, guest, hypervisor, physical, mobile. type: string - contextPath: Nexpose.Asset.Site description: Asset site name. type: string - contextPath: Nexpose.Asset.OperatingSystem description: Operating system of the asset. type: string - contextPath: Nexpose.Asset.Vulnerabilities description: The total number of vulnerabilities on the asset. type: number - contextPath: Nexpose.Asset.CPE description: The Common Platform Enumeration (CPE) of the operating system. type: string - contextPath: Nexpose.Asset.LastScanDate description: Last scan date of the asset. type: date - contextPath: Nexpose.Asset.LastScanId description: ID of the asset's last scan. type: number - contextPath: Nexpose.Asset.RiskScore description: The risk score (with criticality adjustments) of the asset. type: number - contextPath: Nexpose.Asset.Software.Software description: The description of the software. type: string - contextPath: Nexpose.Asset.Software.Version description: The version of the software. type: string - contextPath: Nexpose.Asset.Services.Name description: The name of the service. type: string - contextPath: Nexpose.Asset.Services.Port description: The port of the service. type: number - contextPath: Nexpose.Asset.Services.Product description: The product running the service. type: string - contextPath: Nexpose.Asset.Services.protocol description: The protocol of the service, valid values are ip, icmp, igmp, ggp, tcp, pup, udp, idp, esp, nd, raw. type: string - contextPath: Nexpose.Asset.Users.FullName description: The full name of the user account. type: string - contextPath: Nexpose.Asset.Users.Name description: The name of the user account. type: string - contextPath: Nexpose.Asset.Users.UserId description: The identifier of the user account. type: number - contextPath: Nexpose.Asset.Vulnerability.Id description: The identifier of the vulnerability. type: number - contextPath: Nexpose.Asset.Vulnerability.Instances description: The number of vulnerable occurrences of the vulnerability. This does not include invulnerable instances. type: number - contextPath: Nexpose.Asset.Vulnerability.Title description: The title (summary) of the vulnerability. type: string - contextPath: Nexpose.Asset.Vulnerability.Malware description: The malware kits that are known to be used to exploit the vulnerability. type: number - contextPath: Nexpose.Asset.Vulnerability.Exploit description: The exploits that can be used to exploit a vulnerability. type: number - contextPath: Nexpose.Asset.Vulnerability.CVSS description: The CVSS exploit score. type: string - contextPath: Nexpose.Asset.Vulnerability.Risk description: The risk score of the vulnerability, rounded to a maximum of to digits of precision. If using the default Rapid7 Real Risk™ model, this value ranges from 0-1000. type: number - contextPath: Nexpose.Asset.Vulnerability.PublishedOn description: The date the vulnerability was first published or announced. The format is an ISO 8601 date, YYYY-MM-DD. type: date - contextPath: Nexpose.Asset.Vulnerability.ModifiedOn description: The last date the vulnerability was modified. The format is an ISO 8601 date, YYYY-MM-DD. type: date - contextPath: Nexpose.Asset.Vulnerability.Severity description: 'The severity of the vulnerability, one of: "Moderate", "Severe", "Critical".' type: string - contextPath: Endpoint.IP description: Endpoint IP address. type: string - contextPath: Endpoint.HostName description: Endpoint host name. type: string - contextPath: Endpoint.OS description: Endpoint operating system. type: string - contextPath: CVE.ID description: Common Vulnerabilities and Exposures IDs. type: string - arguments: - description: Asset ID. name: asset_id required: true description: Returns the specified tags for an asset. name: nexpose-get-asset-tags outputs: - contextPath: Nexpose.AssetTag.Type description: Type of asset tag. type: string - contextPath: Nexpose.AssetTag.Name description: The value of the tag. type: string - contextPath: Nexpose.AssetTag.CreatedTime description: Timestamp of when the tag was created. type: string - contextPath: Nexpose.AssetTag.RiskModifier description: The risk modifier value associated with criticality tag type. type: string - arguments: - description: Number of records to retrieve in each API call when pagination is used. name: page_size - description: A specific page to retrieve when pagination is used. Page indexing starts at 0. name: page - description: 'Criteria to sort the records by, in the format: property[,ASC|DESC]. If not specified, default sort order is ascending. Multiple sort criteria can be specified, separated by a ";". For example: "riskScore,DESC;hostName,ASC".' name: sort - defaultValue: '10' description: A number of records to limit the response to. name: limit description: Returns all assets for which you have access. name: nexpose-get-assets outputs: - contextPath: Nexpose.Asset.AssetId description: The identifier of the asset. type: number - contextPath: Nexpose.Asset.Address description: The primary IPv4 or IPv6 address of the asset. type: string - contextPath: Nexpose.Asset.Name description: The primary host name (local or FQDN) of the asset. type: string - contextPath: Nexpose.Asset.Site description: Asset site name. type: string - contextPath: Nexpose.Asset.Exploits description: The number of distinct exploits that can exploit any of the vulnerabilities on the asset. type: number - contextPath: Nexpose.Asset.Malware description: The number of distinct malware kits that vulnerabilities on the asset are susceptible to. type: number - contextPath: Nexpose.Asset.OperatingSystem description: Operating system of the asset. type: string - contextPath: Nexpose.Asset.Vulnerabilities description: The total number of vulnerabilities. type: number - contextPath: Nexpose.Asset.RiskScore description: The risk score (with criticality adjustments) of the asset. type: number - contextPath: Nexpose.Asset.Assessed description: Whether the asset has been assessed for vulnerabilities at least once. type: boolean - contextPath: Nexpose.Asset.LastScanDate description: Last scan date of the asset. type: date - contextPath: Nexpose.Asset.LastScanId description: Id of the asset's last scan. type: number - contextPath: Endpoint.IP description: Endpoint IP address. type: string - contextPath: Endpoint.HostName description: Endpoint host name. type: string - contextPath: Endpoint.OS description: Endpoint operating system. type: string - arguments: - description: 'Queries to use as a filter, according to the Search Criteria API standard. Multiple queries can be specified, separated by a ";" separator. For example: "ip-address in-range 192.0.2.0,192.0.2.1;host-name is myhost". For more information regarding Search Criteria, refer to https://help.rapid7.com/insightvm/en-us/api/index.html#section/Overview/Responses' name: query - description: Number of records to retrieve in each API call when pagination is used. name: page_size defaultValue: '100' - description: A specific page to retrieve when pagination is used. Page indexing starts at 0. name: page - description: A number of records to limit the response to. name: limit defaultValue: '10' - description: 'Criteria to sort the records by, in the format: property[,ASC|DESC]. If not specified, default sort order is ascending. Multiple sort criteria can be specified, separated by a ";" separator. For example: "riskScore,DESC;hostName,ASC".' name: sort - description: A specific IP address to search. name: ipAddressIs - description: A specific host name to search. name: hostNameIs - description: A minimum risk score to use as a filter. name: riskScoreHigherThan - description: A string to search for in vulnerabilities titles. name: vulnerabilityTitleContains - description: Site IDs to filter for. Can be a comma-separated list. isArray: true name: siteIdIn - description: Site names to filter for. Can be a comma-separated list. isArray: true name: siteNameIn - auto: PREDEFINED defaultValue: all description: Operator to determine how to match filters. "all" requires that all filters match for an asset to be included. "any" requires only one filter to match for an asset to be included. name: match predefined: - all - any description: Search and return all assets matching specific filters. Returns only assets the user has access to. name: nexpose-search-assets outputs: - contextPath: Nexpose.Asset.AssetId description: The identifier of the asset. type: number - contextPath: Nexpose.Asset.Address description: The primary IPv4 or IPv6 address of the asset. type: string - contextPath: Nexpose.Asset.Name description: The primary host name (local or FQDN) of the asset. type: string - contextPath: Nexpose.Asset.Site description: Asset site name. type: string - contextPath: Nexpose.Asset.Exploits description: The number of distinct exploits that can exploit any of the vulnerabilities on the asset. type: number - contextPath: Nexpose.Asset.Malware description: The number of distinct malware kits that vulnerabilities on the asset are susceptible to. type: number - contextPath: Nexpose.Asset.OperatingSystem description: Operating system of the asset. type: string - contextPath: Nexpose.Asset.Vulnerabilities description: The total number of vulnerabilities. type: number - contextPath: Nexpose.Asset.RiskScore description: The risk score (with criticality adjustments) of the asset. type: number - contextPath: Nexpose.Asset.Assessed description: Whether the asset has been assessed for vulnerabilities at least once. type: boolean - contextPath: Nexpose.Asset.LastScanDate description: Last scan date of the asset. type: date - contextPath: Nexpose.Asset.LastScanId description: Id of the asset's last scan. type: number - contextPath: Endpoint.IP description: Endpoint IP address. type: string - contextPath: Endpoint.HostName description: Endpoint host name. type: string - contextPath: Endpoint.OS description: Endpoint operating system. type: string - arguments: - description: ID of a specific scan to retrieve. Can be a comma-separated list. isArray: true name: id required: true description: Get a specific scan. name: nexpose-get-scan outputs: - contextPath: Nexpose.Scan.Id description: The identifier of the scan. type: number - contextPath: Nexpose.Scan.ScanType description: The scan type (automated, manual, scheduled). type: string - contextPath: Nexpose.Scan.StartedBy description: The name of the user who started the scan. type: string - contextPath: Nexpose.Scan.Assets description: The number of assets found in the scan. type: number - contextPath: Nexpose.Scan.TotalTime description: The duration of the scan in minutes. type: string - contextPath: Nexpose.Scan.Status description: The scan status. Valid values are aborted, unknown, running, finished, stopped, error, paused, dispatched, integrating. type: string - contextPath: Nexpose.Scan.Completed description: The end time of the scan in ISO8601 format. type: date - contextPath: Nexpose.Scan.Vulnerabilities.Critical description: The number of critical vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Moderate description: The number of moderate vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Severe description: The number of severe vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Total description: The total number of vulnerabilities. type: number - arguments: - description: ID of an asset to search for the vulnerability. name: id required: true - description: "ID of a vulnerability to search for. Example: 7-zip-cve-2008-6536." name: vulnerabilityId required: true description: Returns details and possible remediations for an asset's vulnerability. name: nexpose-get-asset-vulnerability outputs: - contextPath: Nexpose.Asset.AssetId description: Identifier of the asset. type: number - contextPath: Nexpose.Asset.Vulnerability.Id description: The identifier of the vulnerability. type: number - contextPath: Nexpose.Asset.Vulnerability.Title description: The title (summary) of the vulnerability. type: string - contextPath: Nexpose.Asset.Vulnerability.Severity description: 'The severity of the vulnerability, one of: "Moderate", "Severe", "Critical".' type: string - contextPath: Nexpose.Asset.Vulnerability.RiskScore description: The risk score of the vulnerability, rounded to a maximum of to digits of precision. If using the default Rapid7 Real Risk™ model, this value ranges from 0-1000. type: number - contextPath: Nexpose.Asset.Vulnerability.CVSS description: The CVSS vector(s) for the vulnerability. type: string - contextPath: Nexpose.Asset.Vulnerability.CVSSV3 description: The CVSS v3 vector. type: string - contextPath: Nexpose.Asset.Vulnerability.Published description: The date the vulnerability was first published or announced. The format is an ISO 8601 date, YYYY-MM-DD. type: date - contextPath: Nexpose.Asset.Vulnerability.Added description: The date the vulnerability coverage was added. The format is an ISO 8601 date, YYYY-MM-DD. type: date - contextPath: Nexpose.Asset.Vulnerability.Modified description: The last date the vulnerability was modified. The format is an ISO 8601 date, YYYY-MM-DD. type: date - contextPath: Nexpose.Asset.Vulnerability.CVSSScore description: The CVSS score (ranges from 0-10). type: number - contextPath: Nexpose.Asset.Vulnerability.CVSSV3Score description: The CVSS3 score, which ranges from 0-10. type: number - contextPath: Nexpose.Asset.Vulnerability.Categories description: All vulnerability categories assigned to this vulnerability. type: unknown - contextPath: Nexpose.Asset.Vulnerability.CVES description: All CVEs assigned to this vulnerability. type: unknown - contextPath: Nexpose.Asset.Vulnerability.Check.Port description: The port of the service the result was discovered on. type: number - contextPath: Nexpose.Asset.Vulnerability.Check.Protocol description: The protocol of the service the result was discovered on, valid values ip, icmp, igmp, ggp, tcp, pup, udp, idp, esp, nd, raw. type: string - contextPath: Nexpose.Asset.Vulnerability.Check.Since description: The date and time the result was first recorded, in the ISO8601 format. If the result changes status this value is the date and time of the status change. type: date - contextPath: Nexpose.Asset.Vulnerability.Check.Proof description: The proof explaining why the result was found vulnerable. type: string - contextPath: Nexpose.Asset.Vulnerability.Check.Status description: The status of the vulnerability check result. Valid values are, unknown, not-vulnerable, vulnerable, vulnerable-version, vulnerable-potential, vulnerable-with-exception-applied, vulnerable-version-with-exception-applied, vulnerable-potential-with-exception-applied. type: string - contextPath: Nexpose.Asset.Vulnerability.Solution.Type description: 'The type of the solution. One of: "Configuration", "Rollup patch", "Patch".' type: string - contextPath: Nexpose.Asset.Vulnerability.Solution.Summary description: The summary of the solution. type: string - contextPath: Nexpose.Asset.Vulnerability.Solution.Steps description: The steps required to remediate the vulnerability. type: string - contextPath: Nexpose.Asset.Vulnerability.Solution.Estimate description: The estimated duration to apply the solution, in minutes. type: string - contextPath: Nexpose.Asset.Vulnerability.Solution.AdditionalInformation description: Additional information or resources that can assist in applying the remediation. type: string - contextPath: CVE.ID description: Common Vulnerabilities and Exposures IDs. type: string - arguments: - description: Name of the credential. name: name required: true - description: Site assignment configuration for the credential. Assign the shared scan credential either to be available to all sites, or a specific list of sites. name: site_assignment required: true auto: PREDEFINED predefined: - All-Sites - Specific-Sites - description: Credential service type. name: service required: true auto: PREDEFINED predefined: - AS400 - CIFS - CIFSHash - CVS - DB2 - FTP - HTTP - MS-SQL - MySQL - Notes - Oracle - POP - PostgresSQL - Remote-Exec - SNMP - SNMPv3 - SSH - SSH-Key - Sybase - Telnet - description: Database name. name: database - description: Description for the credential. name: description - description: Domain address. name: domain - description: Hostname or IP address to restrict the credentials to. name: host_restriction - description: HTTP realm. name: http_realm - description: Password for the notes account that will be used for authenticating. name: notes_id_password - description: NTLM password hash. name: ntlm_hash - auto: PREDEFINED description: Whether the scan engine should attempt to enumerate SIDs from the environment. name: oracle_enumerate_sids predefined: - 'true' - 'false' - description: Oracle Net Listener password. Used to enumerate SIDs from your environment. name: oracle_listener_password - description: Oracle database name. name: oracle_sid - description: Password for the credential. name: password - description: Further restricts the credential to attempt to authenticate on a specific port. Can be used only if `host_restriction` is used. name: port_restriction - description: List of site IDs for the shared credential that are explicitly assigned access to the shared scan credential, allowing it to use the credential during a scan. isArray: true name: sites - description: SNMP community for authentication. name: community_name - auto: PREDEFINED description: SNMPv3 authentication type for the credential. name: authentication_type predefined: - No-Authentication - MD5 - SHA - description: SNMPv3 privacy password to use. name: privacy_password - auto: PREDEFINED description: SNMPv3 Privacy protocol to use. name: privacy_type predefined: - No-Privacy - DES - AES-128 - AES-192 - AES-192-With-3-DES-Key-Extension - AES-256 - AES-256-With-3-DES-Key-Extension - description: PEM formatted private key. name: ssh_key_pem - auto: PREDEFINED description: Elevation type to use for scans. name: ssh_permission_elevation predefined: - None - sudo - sudosu - su - pbrun - Privileged-Exec - description: Password to use for elevation. name: ssh_permission_elevation_password - description: Username to use for elevation. name: ssh_permission_elevation_username - description: Password for the private key. name: ssh_private_key_password - auto: PREDEFINED description: Whether to use Windows authentication. name: use_windows_authentication predefined: - 'true' - 'false' - description: Username for the credential. name: username description: "Create a new shared credential. For detailed explanation of all parameters of this command, see: https://help.rapid7.com/insightvm/en-us/api/index.html#operation/createSharedCredential" name: nexpose-create-shared-credential outputs: - contextPath: Nexpose.SharedCredential.id description: ID of the generated credential. type: number - arguments: - description: Site name. Must be unique. name: name required: true - description: Site's description. name: description - description: Addresses of assets to include in site scans. Can be a comma-separated list. isArray: true name: assets required: true - description: ID of a scan template to use. If not specified, the default scan template will be used. Use `nexpose-get-report-templates` to get a list of all available templates. name: scanTemplateId - auto: PREDEFINED description: Site importance. Defaults to "normal" if not specified. name: importance predefined: - very_low - low - normal - high - very_high description: Creates a new site with the specified configuration. name: nexpose-create-site outputs: - contextPath: Nexpose.Site.Id description: ID of the created site. type: number - arguments: - description: The date and time the vulnerability exception is set to expire in ISO 8601 date format. name: expires - description: "ID of the vulnerability to create the exception for. Example: 7-zip-cve-2008-6536." name: vulnerability_id required: true - auto: PREDEFINED description: The type of the exception scope. If set to anything other than `Global`, `scope_id` parameter is required. name: scope_type predefined: - Global - Site - Asset - Asset Group # - Instance # We had issues with this option, so it's not currently supported required: true - auto: PREDEFINED description: State of the vulnerability exception. name: state predefined: - Expired - Approved - Rejected - Under Review required: true - description: A comment from the submitter as to why the exception was submitted. name: comment - auto: PREDEFINED description: Reason why the vulnerability exception was submitted. name: reason predefined: - False Positive - Compensating Control - Acceptable Use - Acceptable Risk - Other required: true - description: ID of the chosen `scope_type` (site ID, asset ID, etc.). Required if `scope_type` is anything other than `Global`. name: scope_id description: Create a new vulnerability exception. name: nexpose-create-vulnerability-exception outputs: - contextPath: Nexpose.VulnerabilityException.id description: ID of the generated vulnerability exception. type: number - description: Delete an asset. name: nexpose-delete-asset arguments: - description: ID of the asset to delete. name: id required: true - arguments: - description: ID of the site to delete. name: site_id - description: Name of the site to delete (can be used instead of `site_id`). name: site_name - description: ID of the scheduled scan to delete. name: schedule_id required: true description: Delete a scheduled scan. name: nexpose-delete-scan-schedule - arguments: - description: ID of the shared credential to delete. name: id required: true description: "Beta Command\n\nDelete a shared credential." name: nexpose-delete-shared-credential - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: ID of the site scan credential to delete. name: credential_id required: true description: "Beta Command\n\nDelete a site scan credential." name: nexpose-delete-site-scan-credential - arguments: - description: ID of a site to delete. name: id - description: Name of the site to delete (can be used instead of `site_id`). name: site_name description: Deletes a site. name: nexpose-delete-site - arguments: - description: ID of the vulnerability exception to delete. name: id required: true description: Delete a vulnerability exception. name: nexpose-delete-vulnerability-exception - arguments: - description: Number of records to retrieve in each API call when pagination is used. name: page_size - description: A specific page to retrieve when pagination is used. Page indexing starts at 0. name: page - defaultValue: '10' description: A number of records to limit the response to. name: limit - description: 'Criteria to sort the records by, in the format: property[,ASC|DESC]. If not specified, default sort order is ascending. Multiple sort criteria can be specified, separated by a ";". For example: "riskScore,DESC;hostName,ASC".' name: sort description: Retrieves accessible sites. name: nexpose-get-sites outputs: - contextPath: Nexpose.Site.Id description: The identifier of the site. type: number - contextPath: Nexpose.Site.Name description: The site name. type: string - contextPath: Nexpose.Site.Assets description: The number of assets that belong to the site. type: number - contextPath: Nexpose.Site.Type description: The type of the site. Valid values are agent, dynamic, static. type: string - contextPath: Nexpose.Site.Vulnerabilities description: The total number of vulnerabilities. type: number - contextPath: Nexpose.Site.Risk description: The risk score (with criticality adjustments) of the site. type: number - contextPath: Nexpose.Site.LastScan description: The date and time of the site's last scan. type: date - description: Returns all available report templates. name: nexpose-get-report-templates outputs: - contextPath: Nexpose.Template.Id description: The identifier of the report template. type: number - contextPath: Nexpose.Template.Name description: The name of the report template. type: string - contextPath: Nexpose.Template.Description description: The description of the report template. type: string - contextPath: Nexpose.Template.Type description: The type of the report template. document is a templatized, typically printable, report that has various sections of content. export is data-oriented output, typically CSV. file is a printable report template using a report template file. type: string - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: The date the data was collected on the asset in ISO 8601 format. name: date required: true - description: Primary IPv4 or IPv6 address of the asset. isArray: true name: ip required: true - description: Hostname of the asset. name: host_name - auto: PREDEFINED description: The source used to detect the host name. "User" indicates the host name source is user-supplied. name: host_name_source predefined: - User - DNS - NetBIOS - DCE - EPSEC - LDAP - Other description: Create a new asset. name: nexpose-create-asset outputs: - contextPath: Nexpose.Asset.id description: ID of the newly created asset. type: string - arguments: - description: Asset IDs to create the report on. Can be a comma-separated list. isArray: true name: assets required: true - description: Report template ID to create the report with. If not provided, the first available template will be used. name: template - description: Report name. name: name - auto: PREDEFINED description: Report format (uses PDF by default). name: format predefined: - pdf - rtf - xml - html - text - auto: PREDEFINED defaultValue: 'true' description: Whether to download the report immediately after the report is generated. Defaults to "true". If the report takes longer than 10 seconds to generate, set to "false". name: download_immediately predefined: - 'true' - 'false' description: Generates a new report on given assets according to a template and arguments. name: nexpose-create-assets-report outputs: - contextPath: InfoFile.EntryId description: Entry ID of the report file. type: string - contextPath: InfoFile.Name description: Name of the report file. type: string - contextPath: InfoFile.Extension description: File extension of the report file. type: string - contextPath: InfoFile.Info description: Information about the report file. type: string - contextPath: InfoFile.Size description: Size of the report file (in bytes). type: number - contextPath: InfoFile.Type description: Type of the report file. type: string - contextPath: Nexpose.Report.ID description: The identifier of the report. type: string - contextPath: Nexpose.Report.InstanceID description: The identifier of the report instance. type: string - contextPath: Nexpose.Report.Name description: The report name. type: string - contextPath: Nexpose.Report.Format description: The report format. type: string - name: nexpose-create-sites-report arguments: - name: sites description: Site IDs to create the report on. Can be a comma-separated list. isArray: true - name: site_names description: Names of sites to create the report on. Can be a comma-separated list. isArray: true - name: template description: Report template ID to use for report's creation. If not provided, the first available template will be used. - name: name description: Report name. - auto: PREDEFINED description: Report format (uses PDF by default). name: format predefined: - pdf - rtf - xml - html - text - auto: PREDEFINED defaultValue: 'true' description: If true, downloads the report immediately after the report is generated. The default is "true". If the report takes longer than 10 seconds to generate, set to "false". name: download_immediately predefined: - 'true' - 'false' outputs: - contextPath: InfoFile.EntryId description: Entry ID of the report file. type: string - contextPath: InfoFile.Name description: Name of the report file. type: string - contextPath: InfoFile.Extension description: File extension of the report file. type: string - contextPath: InfoFile.Info description: Info about the report file. type: string - contextPath: InfoFile.Size description: Size of the report file. type: number - contextPath: InfoFile.Type description: Type of the report file. type: string - contextPath: Nexpose.Report.ID description: The identifier of the report. type: string - contextPath: Nexpose.Report.InstanceID description: The identifier of the report instance. type: string - contextPath: Nexpose.Report.Name description: The report name. type: string - contextPath: Nexpose.Report.Format description: The report format. type: string description: Generates a new report on given sites according to a template and arguments. - name: nexpose-create-site-scan-credential arguments: - name: site_id description: ID of the site. - name: site_name description: Name of the site (can be used instead of `site_id`). - description: Name of the credential. name: name required: true - auto: PREDEFINED description: Credential service type. name: service predefined: - AS400 - CIFS - CIFSHash - CVS - DB2 - FTP - HTTP - MS-SQL - MySQL - Notes - Oracle - POP - PostgresSQL - Remote-Exec - SNMP - SNMPv3 - SSH - SSH-Key - Sybase - Telnet required: true - description: Database name. name: database - description: Description for the credential. name: description - description: Domain address. name: domain - description: Hostname or IP address to restrict the credentials to. name: host_restriction - description: HTTP realm. name: http_realm - description: Password for the notes account that will be used for authenticating. name: notes_id_password - description: NTLM password hash. name: ntlm_hash - auto: PREDEFINED description: Whether the scan engine should attempt to enumerate SIDs from the environment. name: oracle_enumerate_sids predefined: - 'true' - 'false' - description: Oracle Net Listener password. Used to enumerate SIDs from your environment. name: oracle_listener_password - description: Oracle database name. name: oracle_sid - description: Password for the credential. name: password - description: Further restricts the credential to attempt to authenticate on a specific port. Can be used only if `host_restriction` is used. name: port_restriction - description: SNMP community for authentication. name: community_name - auto: PREDEFINED description: SNMPv3 authentication type for the credential. name: authentication_type predefined: - No-Authentication - MD5 - SHA - description: SNMPv3 privacy password to use. name: privacy_password - auto: PREDEFINED description: SNMPv3 privacy protocol to use. name: privacy_type predefined: - No-Privacy - DES - AES-128 - AES-192 - AES-192-With-3-DES-Key-Extension - AES-256 - AES-256-With-3-DES-Key-Extension - description: PEM formatted private key. name: ssh_key_pem - auto: PREDEFINED description: Elevation type to use for scans. name: ssh_permission_elevation predefined: - None - sudo - sudosu - su - pbrun - Privileged-Exec - description: Password to use for elevation. name: ssh_permission_elevation_password - description: Username to use for elevation. name: ssh_permission_elevation_username - description: Password for the private key. name: ssh_private_key_password - auto: PREDEFINED description: Whether to use Windows authentication. name: use_windows_authentication predefined: - 'true' - 'false' - description: Username for the credential. name: username outputs: - contextPath: Nexpose.SiteScanCredential.id description: ID of the generated credential. type: number description: "Beta Command\n\nCreate a new site scan credential. For detailed explanation of all parameters of this command, see: https://help.rapid7.com/insightvm/en-us/api/index.html#operation/createSiteCredential" - arguments: - description: ID of the scan to create a report about. name: scan required: true - description: Report template ID to use for creation. If not provided, the first available template will be used. name: template - description: Report name. name: name - auto: PREDEFINED description: Report format (uses PDF by default). name: format predefined: - pdf - rtf - xml - html - text - auto: PREDEFINED defaultValue: 'true' description: If true, downloads the report immediately after the report is generated. The default is "true". If the report takes longer than 10 seconds to generate, set to "false". name: download_immediately predefined: - 'true' - 'false' description: Generates a new report for a specified scan. name: nexpose-create-scan-report outputs: - contextPath: InfoFile.EntryId description: Entry ID of the report file. type: string - contextPath: InfoFile.Name description: Name of the report file. type: string - contextPath: InfoFile.Extension description: File extension of the report file. type: string - contextPath: InfoFile.Info description: Info about the report file. type: string - contextPath: InfoFile.Size description: Size of the report file. type: number - contextPath: InfoFile.Type description: Type of the report file. type: string - contextPath: Nexpose.Report.ID description: The identifier of the report. type: string - contextPath: Nexpose.Report.InstanceID description: The identifier of the report instance. type: string - contextPath: Nexpose.Report.Name description: The report name. type: string - contextPath: Nexpose.Report.Format description: The report format. type: string - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - auto: PREDEFINED defaultValue: 'True' description: Whether to enable the scheduled scan after creation. name: enabled predefined: - 'True' - 'False' - auto: PREDEFINED description: The desired behavior of a repeating scheduled scan when the previous scan was paused due to reaching its maximum duration. name: on_scan_repeat predefined: - Restart-Scan - Resume-Scan required: true - description: The scheduled start date and time formatted in ISO 8601 format. Repeating schedules will determine the next schedule to begin based on this date and time. name: start required: true - description: A list of IDs for asset groups to exclude from the scan. isArray: true name: excluded_asset_group_ids - description: A list of addresses to exclude from the scan. isArray: true name: excluded_addresses - description: A list of IDs for asset groups to include in the scan. isArray: true name: included_asset_group_ids - description: A list of addresses to include in the scan. isArray: true name: included_addresses - description: Maximum duration of the scan in days. name: duration_days - description: Maximum duration of the scan in hours. name: duration_hours - description: Maximum duration of the scan in minutes. name: duration_minutes - auto: PREDEFINED description: How frequently the schedule should repeat (Every...). name: frequency predefined: - Hour - Day - Week - Date-of-month - description: The interval time the schedule should repeat. This depends on the value set in `frequency`. For example, if the value of `frequency` is set to "Day" and `interval` is set to 2, then the schedule will repeat every 2 days. Required only if frequency is used. name: interval_time - description: Specifies the schedule repeat day of the interval month. For example, if `date_of_month` is 17 and `interval` is set to 2, then the schedule will repeat every 2 months on the 17th day of the month. Required and used only if frequency is set to `Date of month`. name: date_of_month - description: A unique user-defined name for the scan launched by the schedule. If not explicitly set in the schedule, the scan name will be generated prior to the scan launching. name: scan_name - description: ID of the scan template to use. name: scan_template description: "Beta Command\n\nCreate a new site scan schedule." name: nexpose-create-scan-schedule outputs: - contextPath: Nexpose.ScanSchedule.id description: ID of the newly created scan schedule. type: int - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - defaultValue: '10' description: The number of records to limit the response to. name: limit description: Retrieve information about shared credentials for a specific site. name: nexpose-list-assigned-shared-credential outputs: - contextPath: Nexpose.AssignedSharedCredential.enabled description: Flag indicating whether the shared credential is enabled for the site's scans. type: string - contextPath: Nexpose.AssignedSharedCredential.id description: ID of the shared credential. type: string - contextPath: Nexpose.AssignedSharedCredential.name description: The name of the shared credential. type: string - contextPath: Nexpose.AssignedSharedCredential.service description: Credential service type. type: string - arguments: - description: ID of a specific vulnerability to retrieve. name: id - description: Number of records to retrieve in each API call when pagination is used. name: page_size - description: A specific page to retrieve when pagination is used. Page indexing starts at 0. name: page - defaultValue: '10' description: The number of records to limit the response to. name: limit - description: 'Criteria to sort the records by, in the format: property[,ASC|DESC]. If not specified, default sort order is ascending. Multiple sort criteria can be specified, separated by a ";". For example: "riskScore,DESC;hostName,ASC".' name: sort description: Retrieve information about all or a specific vulnerability. name: nexpose-list-vulnerability outputs: - contextPath: Nexpose.Vulnerability.added description: The date the vulnerability coverage was added in ISO 8601 format. type: string - contextPath: Nexpose.Vulnerability.categories description: All vulnerability categories assigned to this vulnerability. type: array - contextPath: Nexpose.Vulnerability.cves description: All CVEs assigned to this vulnerability. type: array - contextPath: Nexpose.Vulnerability.cvss.v2.accessComplexity description: Access Complexity (AC) component that measures the complexity of the attack required to exploit the vulnerability once an attacker has gained access to the target system. type: string - contextPath: Nexpose.Vulnerability.cvss.v2.accessVector description: Access Vector (Av) component that reflects how the vulnerability is exploited. type: string - contextPath: Nexpose.Vulnerability.cvss.v2.authentication description: Authentication (Au) component that measures the number of times an attacker must authenticate to a target in order to exploit a vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v2.availabilityImpact description: Availability Impact (A) component that measures the impact to availability of a successfully exploited vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v2.confidentialityImpact description: Confidentiality Impact (C) component that measures the impact on confidentiality of a successfully exploited vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v2.exploitScore description: The CVSS exploit score. type: number - contextPath: Nexpose.Vulnerability.cvss.v2.impactScore description: The CVSS impact score. type: number - contextPath: Nexpose.Vulnerability.cvss.v2.integrityImpact description: Integrity Impact (I) component that measures the impact to integrity of a successfully exploited vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v2.score description: The CVSS score (ranges from 0-10). type: number - contextPath: Nexpose.Vulnerability.cvss.v2.vector description: The CVSS v2 vector. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.attackComplexity description: Access Complexity (AC) component that measures the conditions beyond the attacker's control that must exist in order to exploit the vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.attackVector description: Attack Vector (AV) component that measures context by which vulnerability exploitation is possible. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.availabilityImpact description: Availability Impact (A) that measures the impact to the availability of the impacted component resulting from a successfully exploited vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.confidentialityImpact description: Confidentiality Impact (C) component that measures the impact on confidentiality of a successfully exploited vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.exploitScore description: The CVSS impact score. type: number - contextPath: Nexpose.Vulnerability.cvss.v3.impactScore description: The CVSS exploit score. type: number - contextPath: Nexpose.Vulnerability.cvss.v3.integrityImpact description: Integrity Impact (I) that measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and veracity of information. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.privilegeRequired description: Privileges Required (PR) that measures the level of privileges an attacker must possess before successfully exploiting the vulnerability. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.scope description: Scope (S) that measures the collection of privileges defined by a computing authority (e.g., an application, an operating system, or a sandbox environment) when granting access to computing resources (e.g., files, CPU, memory, etc.). These privileges are assigned based on some method of identification and authorization. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.score description: The CVSS score (ranges from 0-10). type: number - contextPath: Nexpose.Vulnerability.cvss.v3.userInteraction description: User Interaction (UI) that measures the requirement for a user, other than the attacker, to participate in the successful compromise of the vulnerable component. type: string - contextPath: Nexpose.Vulnerability.cvss.v3.vector description: The CVSS v3 vector. type: string - contextPath: Nexpose.Vulnerability.denialOfService description: Whether the vulnerability can lead to Denial of Service (DoS). type: boolean - contextPath: Nexpose.Vulnerability.description.html description: Hypertext Markup Language (HTML) representation of the content. type: string - contextPath: Nexpose.Vulnerability.description.text description: Textual representation of the content. type: string - contextPath: Nexpose.Vulnerability.exploits description: The exploits that can be used to exploit a vulnerability. type: number - contextPath: Nexpose.Vulnerability.id description: The identifier of the vulnerability. type: string - contextPath: Nexpose.Vulnerability.malwareKits description: The malware kits that are known to be used to exploit the vulnerability. type: number - contextPath: Nexpose.Vulnerability.modified description: The last date the vulnerability was modified in ISO 8601 format. type: string - contextPath: Nexpose.Vulnerability.pci.adjustedCVSSScore description: The CVSS score of the vulnerability, adjusted for PCI rules and exceptions, on a scale of 0-10. type: number - contextPath: Nexpose.Vulnerability.pci.adjustedSeverityScore description: The severity score of the vulnerability, adjusted for PCI rules and exceptions, on a scale of 0-10. type: number - contextPath: Nexpose.Vulnerability.pci.fail description: Whether, if present on a host, this vulnerability would cause a PCI failure. True if "status" is "Fail", false otherwise. type: boolean - contextPath: Nexpose.Vulnerability.pci.specialNotes description: Any special notes or remarks about the vulnerability that pertain to PCI compliance. type: string - contextPath: Nexpose.Vulnerability.pci.status description: The PCI compliance status of the vulnerability. Can be either "Pass", or "Fail". type: string - contextPath: Nexpose.Vulnerability.published description: The date the vulnerability was first published or announced in ISO 8601 format. type: string - contextPath: Nexpose.Vulnerability.riskScore description: The risk score of the vulnerability, rounded to a maximum of two digits of precision. If using the default Rapid7 Real Risk model, this value ranges from 0-1000. type: number - contextPath: Nexpose.Vulnerability.severity description: The severity of the vulnerability, can be either "Moderate", "Severe", or "Critical". type: string - contextPath: Nexpose.Vulnerability.severityScore description: The severity score of the vulnerability, on a scale of 0-10. type: number - contextPath: Nexpose.Vulnerability.title description: The title (summary) of the vulnerability. type: string - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: ID of the scheduled scan (optional, will return a single specific scan if used). name: schedule_id - defaultValue: '10' description: A number of records to limit the response to. name: limit description: "BetaCommand\n\nRetrieve information about scan schedules for a specific site or a specific scan schedule." name: nexpose-list-scan-schedule outputs: - contextPath: Nexpose.ScanSchedule.assets.excludedAssetGroups.assetGroupIDs description: List of asset group identifiers that will be excluded from scans. type: array - contextPath: Nexpose.ScanSchedule.assets.excludedTargets.addresses description: List of addresses that will be excluded from scans. type: array - contextPath: Nexpose.ScanSchedule.assets.includedAssetGroups.assetGroupIDs description: List of asset group identifiers that will be included in scans. type: array - contextPath: Nexpose.ScanSchedule.assets.includedTargets.addresses description: List of addresses that will be included in scans. type: array - contextPath: Nexpose.ScanSchedule.duration description: Specifies in ISO 8601 duration format the maximum duration the scheduled scan is allowed to run. type: string - contextPath: Nexpose.ScanSchedule.enabled description: Flag indicating whether the scan schedule is enabled. type: string - contextPath: Nexpose.ScanSchedule.id description: The identifier of the scan schedule. type: int - contextPath: Nexpose.ScanSchedule.nextRuntimes description: List the next 10 dates when the schedule will launch. type: array - contextPath: Nexpose.ScanSchedule.onScanRepeat description: Specifies the desired behavior of a repeating scheduled scan when the previous scan was paused due to reaching is maximum duration. type: string - contextPath: Nexpose.ScanSchedule.repeat.dayOfWeek description: Specifies the desired behavior of a repeating scheduled scan when the previous scan was paused due to reaching is maximum duration. - contextPath: Nexpose.ScanSchedule.repeat.every description: The frequency in which the schedule repeats. Each value represents a different unit of time and is used in conjunction with the property interval. - contextPath: Nexpose.ScanSchedule.repeat.interval description: The interval time the schedule should repeat. This depends on the value set in every. - contextPath: Nexpose.ScanSchedule.repeat.weekOfMonth description: This property only applies to schedules with an every value of "day-of-month". The week of the month the scheduled task should repeat. - contextPath: Nexpose.ScanSchedule.repeat.scanEngineId description: The identifier of the scan engine to be used for this scan schedule. If not set, the site's assigned scan engine will be used. - contextPath: Nexpose.ScanSchedule.repeat.scanName description: A user-defined name for the scan launched by the schedule. - contextPath: Nexpose.ScanSchedule.repeat.scanTemplateId description: The identifier of the scan template to be used for this scan schedule. If not set, the site's assigned scan template will be used. - contextPath: Nexpose.ScanSchedule.repeat.start description: The scheduled start date and time. Repeating schedules will determine the next schedule to begin based on this date and time. - arguments: - description: ID of a specific shared credential to retrieve. name: id - defaultValue: '10' description: A number of records to limit the response to. name: limit description: Retrieve information about all or a specific shared credential. name: nexpose-list-shared-credential outputs: - contextPath: Nexpose.SharedCredential.account.authenticationType description: SNMPv3 authentication type for the credential. type: string - contextPath: Nexpose.SharedCredential.account.communityName description: SNMP community for authentication. type: string - contextPath: Nexpose.SharedCredential.account.database description: Database name. type: string - contextPath: Nexpose.SharedCredential.account.domain description: Domain address. type: string - contextPath: Nexpose.SharedCredential.account.enumerateSids description: Whether the scan engine should attempt to enumerate SIDs from the environment. type: boolean - contextPath: Nexpose.SharedCredential.account.notesIDPassword description: Password for the notes account that will be used for authenticating. type: string - contextPath: Nexpose.SharedCredential.account.ntlmHash description: NTLM password hash. type: string - contextPath: Nexpose.SharedCredential.account.oracleListenerPassword description: The Oracle Net Listener password. Used to enumerate SIDs from the environment. type: string - contextPath: Nexpose.SharedCredential.account.password description: Password for the credential. type: string - contextPath: Nexpose.SharedCredential.account.pemKey description: PEM formatted private key. type: string - contextPath: Nexpose.SharedCredential.account.permissionElevation description: Elevation type to use for scans. type: string - contextPath: Nexpose.SharedCredential.account.permissionElevationPassword description: Password to use for elevation. type: string - contextPath: Nexpose.SharedCredential.account.permissionElevationUserName description: Username to use for elevation. type: string - contextPath: Nexpose.SharedCredential.account.privacyPassword description: SNMPv3 privacy password to use. type: string - contextPath: Nexpose.SharedCredential.account.privacyType description: SNMPv3 privacy protocol to use. type: string - contextPath: Nexpose.SharedCredential.account.privateKeyPassword description: Password for the private key. type: string - contextPath: Nexpose.SharedCredential.account.realm description: HTTP realm. type: string - contextPath: Nexpose.SharedCredential.account.service description: Credential service type. type: string - contextPath: Nexpose.SharedCredential.account.sid description: Oracle database name. type: string - contextPath: Nexpose.SharedCredential.account.useWindowsAuthentication description: Whether to use Windows authentication. type: boolean - contextPath: Nexpose.SharedCredential.account.username description: Username for the credential. type: string - contextPath: Nexpose.SharedCredential.description description: Description for the credential. type: string - contextPath: Nexpose.SharedCredential.hostRestriction description: Hostname or IP address to restrict the credentials to. type: string - contextPath: Nexpose.SharedCredential.id description: ID of the shared credential. type: number - contextPath: Nexpose.SharedCredential.name description: Name of the credential. type: string - contextPath: Nexpose.SharedCredential.portRestriction description: Further restricts the credential to attempt to authenticate on a specific port. Can be used only if `hostRestriction` is used. type: number - contextPath: Nexpose.SharedCredential.siteAssignment description: Site assignment configuration for the credential. type: string - contextPath: Nexpose.SharedCredential.sites description: List of site IDs for the shared credential that are explicitly assigned access to the shared scan credential, allowing it to use the credential during a scan. type: array - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: ID of a specific scan credential to retrieve. name: credential_id - default: true defaultValue: '10' description: A number of records to limit the response to. name: limit description: "Beta Command\n\nRetrieve information about all or a specific sca credential." name: nexpose-list-site-scan-credential outputs: - contextPath: Nexpose.SiteScanCredential.account.authenticationType description: SNMPv3 authentication type for the credential. type: string - contextPath: Nexpose.SiteScanCredential.account.communityName description: SNMP community for authentication. type: string - contextPath: Nexpose.SiteScanCredential.account.database description: Database name. type: string - contextPath: Nexpose.SiteScanCredential.account.domain description: Domain address. type: string - contextPath: Nexpose.SiteScanCredential.account.enumerateSids description: Whether the scan engine should attempt to enumerate SIDs from the environment. type: boolean - contextPath: Nexpose.SiteScanCredential.account.notesIDPassword description: Password for the notes account that will be used for authenticating. type: string - contextPath: Nexpose.SiteScanCredential.account.ntlmHash description: NTLM password hash. type: string - contextPath: Nexpose.SiteScanCredential.account.oracleListenerPassword description: The Oracle Net Listener password. Used to enumerate SIDs from the environment. type: string - contextPath: Nexpose.SiteScanCredential.account.password description: Password for the credential. type: string - contextPath: Nexpose.SiteScanCredential.account.pemKey description: PEM formatted private key. type: string - contextPath: Nexpose.SiteScanCredential.account.permissionElevation description: Elevation type to use for scans. type: string - contextPath: Nexpose.SiteScanCredential.account.permissionElevationPassword description: Password to use for elevation. type: string - contextPath: Nexpose.SiteScanCredential.account.permissionElevationUserName description: Username to use for elevation. type: string - contextPath: Nexpose.SiteScanCredential.account.privacyPassword description: SNMPv3 privacy password to use. type: string - contextPath: Nexpose.SiteScanCredential.account.privacyType description: SNMPv3 privacy protocol to use. type: string - contextPath: Nexpose.SiteScanCredential.account.privateKeyPassword description: Password for the private key. type: string - contextPath: Nexpose.SiteScanCredential.account.realm description: HTTP realm. type: string - contextPath: Nexpose.SiteScanCredential.account.service description: Credential service type. type: string - contextPath: Nexpose.SiteScanCredential.account.sid description: Oracle database name. type: string - contextPath: Nexpose.SiteScanCredential.account.useWindowsAuthentication description: Whether to use Windows authentication. type: boolean - contextPath: Nexpose.SiteScanCredential.account.username description: Username for the credential. type: string - contextPath: Nexpose.SiteScanCredential.description description: Description for the credential. type: string - contextPath: Nexpose.SiteScanCredential.hostRestriction description: Hostname or IP address to restrict the credentials to. type: string - contextPath: Nexpose.SiteScanCredential.id description: ID of the credential. type: number - contextPath: Nexpose.SiteScanCredential.name description: Name of the credential. type: string - contextPath: Nexpose.SiteScanCredential.portRestriction description: Further restricts the credential to attempt to authenticate on a specific port. Can be used only if `hostRestriction` is used. type: number - arguments: - description: ID of the vulnerability exception to retrieve. If not set, retrieve all vulnerability exceptions. name: id - description: Number of records to retrieve in each API call when pagination is used. name: page_size - description: A specific page to retrieve when pagination is used. Page indexing starts at 0. name: page - default: true defaultValue: submit.date,ASC description: 'Criteria to sort the records by, in the format: property[,ASC|DESC]. If not specified, default sort order is ascending. Multiple sort criteria can be specified, separated by a ";". For example: "riskScore,DESC;hostName,ASC".' name: sort - defaultValue: '10' description: A number of records to limit the response to. name: limit description: Retrieve information about scan schedules for a specific site or a specific scan schedule. name: nexpose-list-vulnerability-exceptions outputs: - contextPath: Nexpose.VulnerabilityException.expires description: The date and time the vulnerability exception is set to expire. type: string - contextPath: Nexpose.VulnerabilityException.id description: The The identifier of the vulnerability exception. type: int - contextPath: Nexpose.VulnerabilityException.scope.id description: The identifier of the vulnerability to which the exception applies. type: int - contextPath: Nexpose.VulnerabilityException.scope.key description: 'If the scope type is "Instance", an optional key to discriminate the instance the exception applies to.' type: string - contextPath: Nexpose.VulnerabilityException.scope.port description: 'If the scope type is "Instance" and the vulnerability is detected on a service, the port on which the exception applies.' type: int - contextPath: Nexpose.VulnerabilityException.scope.type description: 'The type of the exception scope. One of: "Global", "Site", "Asset", "Asset Group", "Instance".' type: string - contextPath: Nexpose.VulnerabilityException.scope.vulnerability description: The identifier of the vulnerability to which the exception applies. type: string - contextPath: Nexpose.VulnerabilityException.state description: 'The state of the vulnerability exception. One of: "Deleted", "Expired", "Approved", "Rejected", `"Under Review".' type: string - contextPath: Nexpose.VulnerabilityException.submit.comment description: A comment from the submitter as to why the exception was submitted. type: string - contextPath: Nexpose.VulnerabilityException.submit.date description: The date and time the vulnerability exception was submitted. type: string - contextPath: Nexpose.VulnerabilityException.submit.name description: The login name of the user who submitted the vulnerability exception. type: string - contextPath: Nexpose.VulnerabilityException.submit.reason description: 'The reason the vulnerability exception was submitted. One of: "False Positive", "Compensating Control", "Acceptable Use", "Acceptable Risk", "Other".' type: string - contextPath: Nexpose.VulnerabilityException.submit.user description: The identifier of the user who submitted the vulnerability exception. type: int - arguments: - description: ID of the site. name: site - description: Name of the site (can be used instead of `site`). name: site_name - description: Specific host(s) on the site to run the scan on. Can be an IP address or a hostname. Can be a comma-separated list. isArray: true name: hosts - description: Scan name. name: name description: Starts a scan for the specified site. name: nexpose-start-site-scan outputs: - contextPath: Nexpose.Scan.Id description: The identifier of the scan. type: number - contextPath: Nexpose.Scan.ScanType description: The scan type (automated, manual, scheduled). type: string - contextPath: Nexpose.Scan.StartedBy description: The name of the user who started the scan. type: date - contextPath: Nexpose.Scan.Assets description: The number of assets found in the scan. type: number - contextPath: Nexpose.Scan.TotalTime description: The duration of the scan in minutes. type: string - contextPath: Nexpose.Scan.Completed description: The end time of the scan in ISO8601 format. type: date - contextPath: Nexpose.Scan.Status description: The scan status. Valid values are aborted, unknown, running, finished, stopped, error, paused, dispatched, integrating. type: string - contextPath: Nexpose.Scan.Vulnerabilities.Critical description: The number of critical vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Moderate description: The number of moderate vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Severe description: The number of severe vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Total description: The total number of vulnerabilities. type: number - arguments: - description: IP addresses of assets to scan. Can be a comma-separated list. isArray: true name: IPs - description: Hostnames of assets to scan. Can be a comma-separated list. isArray: true name: hostNames - description: Scan name. name: name deprecated: true description: Deprecated. Use `nexpose-start-site-scan` using the `hosts` argument instead. name: nexpose-start-assets-scan outputs: - contextPath: Nexpose.Scan.Id description: The identifier of the scan. type: number - contextPath: Nexpose.Scan.ScanType description: The scan type (automated, manual, scheduled). type: string - contextPath: Nexpose.Scan.StartedBy description: The name of the user who started the scan. type: date - contextPath: Nexpose.Scan.Assets description: The number of assets found in the scan. type: number - contextPath: Nexpose.Scan.TotalTime description: The duration of the scan in minutes. type: string - contextPath: Nexpose.Scan.Completed description: The end time of the scan in ISO8601 format. type: date - contextPath: Nexpose.Scan.Status description: The scan status. Valid values are aborted, unknown, running, finished, stopped, error, paused, dispatched, integrating. type: string - contextPath: Nexpose.Scan.Vulnerabilities.Critical description: The number of critical vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Moderate description: The number of moderate vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Severe description: The number of severe vulnerabilities. type: number - contextPath: Nexpose.Scan.Vulnerabilities.Total description: The total number of vulnerabilities. type: number - arguments: - description: ID of a running scan. name: id required: true description: Stop a running scan. name: nexpose-stop-scan - arguments: - description: ID of a running scan. name: id required: true description: Pause a running scan. name: nexpose-pause-scan - arguments: - description: ID of a paused scan. name: id required: true description: Resume a paused scan. name: nexpose-resume-scan - arguments: - auto: PREDEFINED defaultValue: 'true' description: Whether to return only active scans. name: active predefined: - 'true' - 'false' - description: Number of records to retrieve in each API call when pagination is used. name: page_size - description: A specific page to retrieve when pagination is used. Page indexing starts at 0. name: page - defaultValue: '10' description: A number of records to limit the response to. name: limit - description: 'Criteria to sort the records by, in the format: property[,ASC|DESC]. If not specified, default sort order is ascending. Multiple sort criteria can be specified, separated by a ";". For example: "riskScore,DESC;hostName,ASC".' name: sort description: Return a list of scans. Returns only active scans by default (active=true). name: nexpose-get-scans outputs: - contextPath: Nexpose.Scan.Id description: The identifier of the scan. type: number - contextPath: Nexpose.Scan.ScanType description: The scan type (automated, manual, scheduled). type: string - contextPath: Nexpose.Scan.StartedBy description: The name of the user who started the scan. type: date - contextPath: Nexpose.Scan.Assets description: The number of assets found in the scan. type: number - contextPath: Nexpose.Scan.TotalTime description: The duration of the scan in minutes. type: string - contextPath: Nexpose.Scan.Completed description: The end time of the scan in ISO8601 format. type: date - contextPath: Nexpose.Scan.Status description: The scan status. Valid values are aborted, unknown, running, finished, stopped, error, paused, dispatched, integrating. type: string - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: ID of the scan schedule to update. name: credential_id required: true name: nexpose-disable-shared-credential description: "Beta Command\n\nDisable an assigned shared credential." - arguments: - name: report_id required: true description: ID of the report. - name: instance_id required: true description: ID of the report instance. Supports a "latest" value. - name: name description: Report name. - name: format auto: PREDEFINED predefined: - pdf - rtf - xml - html - text - nexpose-simple-xml description: Report format (uses PDF by default). defaultValue: pdf name: nexpose-download-report outputs: - contextPath: InfoFile.EntryId description: Entry ID of the report file. type: string - contextPath: InfoFile.Name description: Name of the report file. type: string - contextPath: InfoFile.Extension description: File extension of the report file. type: string - contextPath: InfoFile.Info description: Information about the report file. type: string - contextPath: InfoFile.Size description: Size of the report file (in bytes). type: number - contextPath: InfoFile.Type description: Type of the report file. type: string description: Returns the generated report. - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: ID of the scan schedule to update. name: credential_id required: true name: nexpose-enable-shared-credential description: "Beta Command\n\nEnable an assigned shared credential." - arguments: - name: report_id required: true description: ID of the report. - name: instance_id required: true description: ID of the report instance. Supports a "latest" value. name: nexpose-get-report-status outputs: - contextPath: Nexpose.Report.ID description: The identifier of the report. type: string - contextPath: Nexpose.Report.InstanceID description: The identifier of the report instance. type: string - contextPath: Nexpose.Report.Status description: 'The status of the report generation process. Valid values: "aborted", "failed", "complete", "running", "unknown".' type: string description: Returns the status of a report generation process. - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: ID of the scan schedule to update. name: schedule_id - auto: PREDEFINED defaultValue: 'True' description: A flag indicating whether the scheduled scan is enabled. name: enabled predefined: - 'True' - 'False' - auto: PREDEFINED description: The desired behavior of a repeating scheduled scan when the previous scan was paused due to reaching its maximum duration. name: on_scan_repeat predefined: - Restart-Scan - Resume-Scan required: true - description: The scheduled start date and time formatted in ISO 8601 format. Repeating schedules will determine the next schedule to begin based on this date and time. name: start required: true - description: A list of IDs for asset groups to exclude from the scan. isArray: true name: excluded_asset_group_ids - description: A list of addresses to exclude from the scan. isArray: true name: excluded_addresses - description: A list of IDs for asset groups to include in the scan. isArray: true name: included_asset_group_ids - description: A list of addresses to include in the scan. isArray: true name: included_addresses - description: Maximum duration of the scan in days. name: duration_days - description: Maximum duration of the scan in hours. name: duration_hours - description: Maximum duration of the scan in minutes. name: duration_minutes - auto: PREDEFINED description: How frequently should the schedule repeat (Every...). name: frequency predefined: - Hour - Day - Week - Date-of-month - description: The interval time the schedule should repeat. This depends on the value set in `frequency`. For example, if the value of `frequency` is set to "Day" and `interval` is set to 2, then the schedule will repeat every 2 days. Required only if frequency is used. name: interval_time - description: Specifies the schedule repeat day of the interval month. For example, if `date_of_month` is 17 and `interval` is set to 2, then the schedule will repeat every 2 months on the 17th day of the month. Required and used only if frequency is set to `Date of month`. name: date_of_month - description: A unique user-defined name for the scan launched by the schedule. If not explicitly set in the schedule, the scan name will be generated prior to the scan launching. name: scan_name - description: ID of the scan template to use. name: scan_template description: "Beta Command\n\nUpdate an existing site scan schedule." name: nexpose-update-scan-schedule - arguments: - description: ID of the site. name: site_id - description: Name of the site (can be used instead of `site_id`). name: site_name - description: ID of the site scan credential to update. name: credential_id required: true - description: Name of the credential. name: name required: true - auto: PREDEFINED description: Credential service type. name: service predefined: - AS400 - CIFS - CIFSHash - CVS - DB2 - FTP - HTTP - MS-SQL - MySQL - Notes - Oracle - POP - PostgresSQL - Remote-Exec - SNMP - SNMPv3 - SSH - SSH-Key - Sybase - Telnet required: true - description: Database name. name: database - description: Description for the credential. name: description - description: Domain address. name: domain - description: Hostname or IP address to restrict the credentials to. name: host_restriction - description: HTTP realm. name: http_realm - description: Password for the notes account that will be used for authenticating. name: notes_id_password - description: NTLM password hash. name: ntlm_hash - auto: PREDEFINED description: Whether the scan engine should attempt to enumerate SIDs from the environment. name: oracle_enumerate_sids predefined: - 'true' - 'false' - description: Oracle Net Listener password. Used to enumerate SIDs from your environment. name: oracle_listener_password - description: Oracle database name. name: oracle_sid - description: Password for the credential. name: password - description: Further restricts the credential to attempt to authenticate on a specific port. Can be used only if `host_restriction` is used. name: port_restriction - description: SNMP community for authentication. name: community_name - auto: PREDEFINED description: SNMPv3 authentication type for the credential. name: authentication_type predefined: - No-Authentication - MD5 - SHA - description: SNMPv3 privacy password to use. name: privacy_password - auto: PREDEFINED description: SNMPv3 Privacy protocol to use. name: privacy_type predefined: - No-Privacy - DES - AES-128 - AES-192 - AES-192-With-3-DES-Key-Extension - AES-256 - AES-256-With-3-DES-Key-Extension - description: PEM formatted private key. name: ssh_key_pem - auto: PREDEFINED description: Elevation type to use for scans. name: ssh_permission_elevation predefined: - None - sudo - sudosu - su - pbrun - Privileged Exec - description: Password to use for elevation. name: ssh_permission_elevation_password - description: Username to use for elevation. name: ssh_permission_elevation_username - description: Password for the private key. name: ssh_private_key_password - auto: PREDEFINED description: Whether to use Windows authentication. name: use_windows_authentication predefined: - 'true' - 'false' - description: Username for the credential. name: username description: "Beta Command\n\nUpdate an existing site scan credential. For detailed explanation of all parameters of this command, see: https://help.rapid7.com/insightvm/en-us/api/index.html#operation/setSiteCredentials." name: nexpose-update-site-scan-credential - arguments: - description: ID of the vulnerability exception to update. name: id required: true - description: An expiration date for the vulnerability exception formatted in ISO 8601 format. Must be a date in the future. name: expiration required: true description: Update an existing vulnerability exception. name: nexpose-update-vulnerability-exception-expiration - arguments: - description: ID of the vulnerability exception to update. name: id required: true - auto: PREDEFINED description: A status to update the vulnerability exception to. name: status required: true predefined: - Recall - Approve - Reject description: Update an existing vulnerability exception. name: nexpose-update-vulnerability-exception-status - arguments: - description: ID of the shared credential to update. name: id required: true - description: Name of the credential. name: name required: true - auto: PREDEFINED description: Site assignment configuration for the credential. Assign the shared scan credential either to be available to all sites, or a specific list of sites. name: site_assignment predefined: - All-Sites - Specific-Sites required: true - auto: PREDEFINED description: Credential service type. name: service predefined: - AS400 - CIFS - CIFSHash - CVS - DB2 - FTP - HTTP - MS-SQL - MySQL - Notes - Oracle - POP - PostgresSQL - Remote-Exec - SNMP - SNMPv3 - SSH - SSH-Key - Sybase - Telnet required: true - description: Database name. name: database - description: Description for the credential. name: description - description: Domain address. name: domain - description: Hostname or IP address to restrict the credentials to. name: host_restriction - description: HTTP realm. name: http_realm - description: Password for the notes account that will be used for authenticating. name: notes_id_password - description: NTLM password hash. name: ntlm_hash - auto: PREDEFINED description: Whether the scan engine should attempt to enumerate SIDs from the environment. name: oracle_enumerate_sids predefined: - 'true' - 'false' - description: Oracle Net Listener password. Used to enumerate SIDs from your environment. name: oracle_listener_password - description: Oracle database name. name: oracle_sid - description: Password for the credential. name: password - description: Further restricts the credential to attempt to authenticate on a specific port. Can be used only if `host_restriction` is used. name: port_restriction - description: List of site IDs for the shared credential that are explicitly assigned access to the shared scan credential, allowing it to use the credential during a scan. isArray: true name: sites - description: SNMP community for authentication. name: community_name - auto: PREDEFINED description: SNMPv3 authentication type for the credential. name: authentication_type predefined: - No-Authentication - MD5 - SHA - description: SNMPv3 privacy password to use. name: privacy_password - auto: PREDEFINED description: SNMPv3 Privacy protocol to use. name: privacy_type predefined: - No-Privacy - DES - AES-128 - AES-192 - AES-192-With-3-DES-Key-Extension - AES-256 - AES-256-With-3-DES-Key-Extension - description: PEM formatted private key. name: ssh_key_pem - auto: PREDEFINED description: Elevation type to use for scans. name: ssh_permission_elevation predefined: - None - sudo - sudosu - su - pbrun - Privileged-Exec - description: Password to use for elevation. name: ssh_permission_elevation_password - description: Username to use for elevation. name: ssh_permission_elevation_username - description: Password for the private key. name: ssh_private_key_password - auto: PREDEFINED description: Whether to use Windows authentication. name: use_windows_authentication predefined: - 'true' - 'false' - description: Username for the credential. name: username description: Update an existing shared credential. name: nexpose-update-shared-credential - name: nexpose-create-tag arguments: - name: name required: true description: The tag name. - name: type required: true auto: PREDEFINED predefined: - owner - location - custom description: The tag type. - name: color auto: PREDEFINED predefined: - blue - green - orange - red - purple - default description: The tag color - relevant only for "custom" type. defaultValue: Default - name: ip_address_is description: A specific IP address to search for. - name: host_name_is description: A specific host name to search for. - name: risk_score_higher_than description: A minimum risk score to use as a filter. - name: vulnerability_title_contains description: A string to search for in vulnerability titles. - name: site_id_in description: Site IDs to filter for. Can be a comma-separated list. isArray: true - name: site_name_in description: Site names to filter for. Can be a comma-separated list. isArray: true - name: match auto: PREDEFINED predefined: - All - Any description: Operator to determine how to match filters. "All" requires that all filters match for an asset to be included. "Any" requires only one filter to match for an asset to be included. defaultValue: Any - name: query description: Additional queries to use as a filter, following the Search Criteria API standard. The structure is {field} {operator} {value}. Multiple queries can be specified, separated by a ";" separator. For example, 'ip-address in-range 192.0.2.0,192.0.2.1;host-name is myhost'. description: Create a tag. outputs: - contextPath: Nexpose.Tag.id description: The tag ID. type: int - name: nexpose-delete-tag arguments: - name: id required: true description: The tag ID. description: Delete a tag. - name: nexpose-list-tag arguments: - name: id description: Get tag by ID. - name: name description: Filters the returned tags to only those containing the value within their name. - name: type auto: PREDEFINED predefined: - owner - location - custom description: Filters the returned tags to only those of this type. - name: page_size description: Number of records to retrieve in each API call when pagination is used. - name: page description: A specific page to retrieve when pagination is used. Page indexing starts at 0. - name: limit description: A number of records to limit the response to. description: Return a list of tags. outputs: - contextPath: Nexpose.Tag.color description: The color associated with the tag. type: String - contextPath: Nexpose.Tag.created description: The date when the tag was created. type: Date - contextPath: Nexpose.Tag.id description: The unique identifier of the tag. type: Number - contextPath: Nexpose.Tag.name description: The name of the tag. type: String - contextPath: Nexpose.Tag.searchCriteria.match description: The match criteria used for the tag search (e.g., "all" or "any"). type: String - contextPath: Nexpose.Tag.searchCriteria.filters.field description: The field name used in the tag search filter. type: String - contextPath: Nexpose.Tag.searchCriteria.filters.operator description: The operator used in the tag search filter (e.g., "is", "contains", "is-greater-than"). type: String - contextPath: Nexpose.Tag.searchCriteria.filters.lower description: The lower bound of the range used in the tag search filter. type: String - contextPath: Nexpose.Tag.searchCriteria.filters.upper description: The upper bound of the range used in the tag search filter. type: String - contextPath: Nexpose.Tag.source description: The source of the tag. type: String - contextPath: Nexpose.Tag.type description: The type of the tag. type: String - contextPath: Nexpose.Tag.searchCriteria.filters.value description: The value used in the tag search filter. type: String - contextPath: Nexpose.Tag.page.number description: The current page number in the paginated response. type: Number - contextPath: Nexpose.Tag.page.size description: The number of items per page in the paginated response. type: Number - contextPath: Nexpose.Tag.page.totalResources description: The total number of resources available. type: Number - contextPath: Nexpose.Tag.page.totalPages description: The total number of pages available. type: Number - name: nexpose-update-tag-search-criteria arguments: - name: tag_id required: true description: The tag ID. - name: ip_address_is description: A specific IP address to search for. - name: host_name_is description: A specific host name to search for. - name: risk_score_higher_than description: A minimum risk score to use as a filter. - name: vulnerability_title_contains description: A string to search for in vulnerability titles. - name: site_id_in description: Site IDs to filter for. Can be a comma-separated list. isArray: true - name: site_name_in description: Site names to filter for. Can be a comma-separated list. - name: match auto: PREDEFINED predefined: - All - Any description: Operator to determine how to match filters. "All" requires that all filters match for an asset to be included. "Any" requires only one filter to match for an asset to be included. defaultValue: Any - name: query description: Additional queries to use as a filter, following the Search Criteria API standard. The structure is {field} {operator} {value}. Multiple queries can be specified, separated by a ";" separator. For example, 'ip-address in-range 192.0.2.0,192.0.2.1;host-name is myhost'. - name: overwrite auto: PREDEFINED predefined: - "yes" - "no" description: Whether to overwrite the original search values or append new conditions to the existing search. defaultValue: "no" description: Update tag search criteria. - name: nexpose-list-tag-asset-group arguments: - name: tag_id required: true description: The tag ID. description: Return a list of asset groups for a tag. outputs: - contextPath: Nexpose.TagAssetGroup.id description: Asset group ID. type: int - name: nexpose-add-tag-asset-group arguments: - name: tag_id required: true description: The tag ID. - name: asset_group_ids required: true description: The asset group IDs to add. Can be a comma-separated list. description: Add existing asset groups to an existing tag. - name: nexpose-remove-tag-asset-group arguments: - name: tag_id required: true description: The tag ID. - name: asset_group_id required: true description: The asset group ID. description: Remove an asset group from a tag. - name: nexpose-list-tag-asset arguments: - name: tag_id required: true description: The tag ID. description: Return the tag assets list. outputs: - contextPath: Nexpose.TagAsset.id description: Asset ID. type: int - contextPath: Nexpose.TagAsset.sources description: The asset sources. type: string - name: nexpose-add-tag-asset arguments: - name: tag_id required: true description: The tag ID. - name: asset_id required: true description: The asset ID. description: Add an existing asset to an existing tag. - name: nexpose-remove-tag-asset arguments: - name: tag_id required: true description: The tag ID. - name: asset_id required: true description: The asset ID. description: Remove an asset from a tag. Note that the asset must be added through the asset or tag. If the asset is added using a site, asset group, or search criteria, this action will not remove the asset from the tag. - name: nexpose-add-site-included-asset arguments: - name: site_id required: true description: A URL parameter. - name: assets description: List of addresses to add to the site's included scan assets. Each address is a string that can represent either a hostname, IPv4 address, IPv4 address range, IPv6 address, or CIDR notation. isArray: true - name: asset_group_ids isArray: true description: List of asset group identifiers. description: Add included assets to a site. - name: nexpose-remove-site-included-asset arguments: - name: site_id required: true description: A URL parameter. - name: assets isArray: true description: List of addresses to remove from the site's included scan assets. Each address is a string that can represent either a hostname, IPv4 address, IPv4 address range, IPv6 address, or CIDR notation. - name: asset_group_ids isArray: true description: List of asset group identifiers. description: Remove included assets from a site. compliantpolicies: - EndPoint Isolation - name: nexpose-list-site-included-asset arguments: - name: site_id required: true description: A URL parameter. description: Return a list of included assets for a site. outputs: - contextPath: Nexpose.IncludedAsset.site_id description: The site ID. type: int - contextPath: Nexpose.IncludedAsset.addresses description: A list of addresses of the included assets for the specified site. type: string - name: nexpose-list-site-included-asset-group arguments: - name: site_id required: true description: A URL parameter. description: Return a list of included asset groups for a site. outputs: - contextPath: Nexpose.IncludedAssetGroup.site_id description: The site ID. type: int - contextPath: Nexpose.IncludedAssetGroup.resources description: The asset group ID. type: int - name: nexpose-add-site-excluded-asset arguments: - name: site_id required: true description: A URL parameter. - name: assets description: List of addresses to add to the site's excluded scan assets. Each address is a string that can represent either a hostname, IPv4 address, IPv4 address range, IPv6 address, or CIDR notation. - name: asset_group_ids description: List of asset group IDs to exclude. description: Add excluded assets to a site. - name: nexpose-remove-site-excluded-asset arguments: - name: site_id required: true description: A URL parameter. - name: assets description: List of addresses to remove from the site's excluded scan assets. Each address is a string that can represent either a hostname, IPv4 address, IPv4 address range, IPv6 address, or CIDR notation. - name: asset_group_ids description: List of asset group IDs to remove from the site's exclusion list. description: Remove excluded assets from a site. - name: nexpose-list-site-excluded-asset arguments: - name: site_id required: true description: A URL parameter. description: Return a list of excluded assets for a site. outputs: - contextPath: Nexpose.ExcludedAsset.site_id description: The site ID. type: int - contextPath: Nexpose.ExcludedAsset.addresses description: A list of addresses of the excluded assets for the specified site. type: string - name: nexpose-list-site-excluded-asset-group arguments: - name: site_id required: true description: A URL parameter. description: Return a list of excluded asset groups for a site. outputs: - contextPath: Nexpose.ExcludedAssetGroup.site_id description: The site ID. type: int - contextPath: Nexpose.ExcludedAssetGroup.resources description: The asset group ID. type: int - name: nexpose-create-asset-group arguments: - name: name required: true description: The asset group name. - name: type required: true auto: PREDEFINED predefined: - static - dynamic description: The asset group type. - name: description required: true description: The description of the asset group. - name: ip_address_is description: A specific IP address to search for. - name: host_name_is description: A specific host name to search for. - name: risk_score_higher_than description: A minimum risk score to use as a filter. - name: vulnerability_title_contains description: A string to search for in vulnerability titles. - name: site_id_in description: Site IDs to filter for. Can be a comma-separated list. isArray: true - name: site_name_in description: Site names to filter for. Can be a comma-separated list. isArray: true - name: match auto: PREDEFINED predefined: - All - Any description: Operator to determine how to match filters. "All" requires that all filters match for an asset to be included. "Any" requires only one filter to match for an asset to be included. defaultValue: Any - name: query description: Additional queries to use as a filter, following the Search Criteria API standard. The structure is {field} {operator} {value}. Multiple queries can be specified, separated by a ";" separator. For example, 'ip-address in-range 192.0.2.0,192.0.2.1;host-name is myhost'. description: 'Create an asset group. Note: All filters are relevant only for Dynamic asset groups.' outputs: - contextPath: Nexpose.AssetGroup.id description: The asset group ID. type: int - name: nexpose-list-asset-group arguments: - name: group_id description: Get asset group by ID. - name: group_name description: Filters the returned asset groups to only those containing the value within their name. - name: type auto: PREDEFINED predefined: - static - dynamic description: Filters the returned asset groups to only those of this type. - name: page_size description: Number of records to retrieve in each API call when pagination is used. - name: page description: A specific page to retrieve when pagination is used. Page indexing starts at 0. - name: limit description: A number of records to limit the response to. - name: sort description: The criteria to sort the records by, in the format property[,ASC|DESC]. The default sort order is ascending. Multiple sort criteria can be specified using multiple sort query parameters. description: Return a list of asset groups. outputs: - contextPath: Nexpose.AssetGroup.assets description: 'The number of assets in the asset group.' type: Number - contextPath: Nexpose.AssetGroup.id description: 'The unique identifier of the asset group.' type: Number - contextPath: Nexpose.AssetGroup.name description: 'The name of the asset group.' type: String - contextPath: Nexpose.AssetGroup.riskScore description: 'The cumulative risk score of the asset group.' type: Number - contextPath: Nexpose.AssetGroup.type description: 'The type of the asset group.' type: String - contextPath: Nexpose.AssetGroup.vulnerabilities.critical description: 'The number of critical vulnerabilities in the asset group.' type: Number - contextPath: Nexpose.AssetGroup.vulnerabilities.moderate description: 'The number of moderate vulnerabilities in the asset group.' type: Number - contextPath: Nexpose.AssetGroup.vulnerabilities.severe description: 'The number of severe vulnerabilities in the asset group.' type: Number - contextPath: Nexpose.AssetGroup.vulnerabilities.total description: 'The total number of vulnerabilities in the asset group.' type: Number - contextPath: Nexpose.AssetGroup.description description: 'The description of the asset group.' type: String runonce: false script: '-' type: python subtype: python3 isfetchassets: true dockerimage: demisto/auth-utils:1.0.0.10133006 fromversion: 5.0.0 tests: - nexpose_test supportedModules: - agentix - xsiam - edr - cloud - cloud_runtime_security - exposure_management