# Rapid7 is a collector + scan factory. Asset, then IDR or VM.

Source: https://ai.techclick.in/blog_rapid7_session_factory
Markdown: https://ai.techclick.in/blog_rapid7_session_factory.md
Publisher: Techclick Infosec Pvt Ltd

Rapid7 is a collector + scan factory: collector/agent → asset → InsightIDR detection / InsightVM finding. Official docs.rapid7.com only.

Quick answer

   Rapid7 is a  collector + scan factory . The on-premises  Collector  polls or receives  Event Sources  for SIEM (InsightIDR). The  Rapid7 Agent (Insight Agent)  sits on the host and feeds both IDR endpoint detections and VM local assessments. The  Scan Engine  walks a  site  for InsightVM. Those workers manufacture an  asset . InsightIDR then stamps a  detection  (Rule Action decides whether that becomes an investigation). InsightVM stamps a  finding  (First Found, risk, exception). Success is an Assessed asset, a healthy pipe, and one stamp you can quote — not “the dashboard is green.”

   Say this out loud

   I do not start with isolate. I ask whether a Collector, Insight Agent, or Scan Engine printed this host as an asset, whether the pipe is Active and the event source is Running, then whether the stamp is an InsightIDR detection or an InsightVM finding. Same IP is a pivot. Completed is not authenticated. Rule Action Off is not a miss.

## 1. Why a green tile is not an asset

 Every other briefing starts with the product logo. “Rapid7 missed it.” “Rapid7 says critical, isolate it.” That is why students freeze in interviews. The real object is the  asset the factory printed . Features are only stamps the factory puts on that asset after a worker — Collector, Insight Agent, or Scan Engine — actually saw the host.

 Official Rapid7 split: SIEM (InsightIDR) is behavior. Vulnerability Management (InsightVM) is weakness. Same hostname is a  pivot , not a merge. Official Collector Overview: the Collector is the on-premises component that polls or receives Event Sources and makes them available for InsightIDR analysis. Official Insight Agent: lightweight software on the host; Rapid7 strongly recommends it for real-time endpoint scanning and out-of-the-box detections. Official InsightVM: assets are  Assessed  after they have been scanned or when the Insight Agent is installed;  Unassessed  means discovered and assigned to a site but not yet assessed.

   Hero · the factory floor

   Notice: Rapid7 does not “see a host.” It tries to manufacture an asset from a collector, an agent, or a scan engine, then stamp it.

#### What the ticket asked

 “Rapid7 is not seeing this host. Why no detection?” That sentence is five hypotheses. The factory may already have printed the asset and stamped a finding you have not opened — or the worker never clocked in.

#### What you prove first

 Identity of the host, then whether an asset exists, then which worker last talked, then which stamp. The  evidence desk  is the night-shift version of this order.

   The lie every L1 repeats

   “The dashboard is green, so Rapid7 is working — isolate it / Scan Now the VLAN.” A green tile only means some collector or some site last reported health. If the host is Unassessed, the Pune collector is Inactive, or Rule Action is Off, the factory did not print the ticket you think it printed. Isolating a missing asset just darkens a box you cannot prove.

### Hard words before the runbook

#### Collector

 On-premises InsightIDR worker. Polls or receives Event Sources. Stores event-source credentials. Official: treat it like a valuable asset. Status  Active / Inactive .

#### Event Source

 One device that sends logs to a Collector — one firewall = one Event Source. Status  Running .  Monitor Health  shows incoming vs parsed. Official path: Data Collection → Event Sources.

#### Insight Agent

 One agent, two products. Feeds IDR endpoint detections (and quarantine) and VM local assessments (already authenticated from inside). Agent → Collector ports  5508, 6608, 8037 .

#### Scan Engine + site

 InsightVM worker. A  site  is a scoped collection of assets plus an engine and a scan template — not a building.  Last Scan  = last discovery, vulnerability, or policy scan.

#### Last Scan Time

 Query Builder column. Official wording: last time the asset was assessed by an  agent . Not the same as site Last Scan. Minutes = live. Days = dark.

#### Rule Action

 What InsightIDR does when rule logic matches:  Creates Investigations ,  Creates Alert ,  Tracks Notable Events ,  Assess Activity ,  Off . Off is configuration, not a miss.

 Official Collector advantage is  normalization  (common JSON) plus  user attribution  (IP → asset, user field → user). Attribution usually needs the Insight Agent plus a DHCP event source. Official: there can be a delay of up to  5 minutes  for endpoint information via the Collector. Official complementary scanning: if the agent already uploaded a local assessment, the Scan Engine can skip those local checks and run only the remote ones.

## 2. Mental model — three workers, one ticket, two stamps

 Hold four parts. Interviews fail when people mix them. Skipping a station is how you quarantine a host that was never an asset, or celebrate a completed scan that never authenticated.

#### 1. The workers are Collector, Agent, Engine

     Collector = IDR pipe. Insight Agent = host-side worker for both products. Scan Engine = VM walker. They are not three names for one service. A dark worker cannot print a ticket.

#### 2. The ticket is the asset

     Hostname, IP, site, OS, agent present. Official: Assessed after scan or agent install. Unassessed = discovered, not assessed. No asset = nothing for a detection or a finding to hang on.

#### 3. The stamps are IDR and VM

      InsightIDR detection  = what behavior, which Detection Rule, which Rule Action.  InsightVM finding  = what weakness, First Found, risk, exception. Same IP is a pivot.

#### 4. Proof is the live row, not the tile

     Data Collection Health is the live pipe. Assets / Asset Details is the ticket. Investigations and Vulnerabilities are the stamps. A dashboard tile is a poster on the wall.

   Path · collector or engine first

   Notice: the diamond is not “critical.” It is “did a worker print this asset, and which stamp should exist?”

   Flow 1 · one ticket, three workers, two stamps

       Rapid7 factory: collector or agent or scan engine prints an asset, then IDR detection or VM finding

- DEVICE-LAB-22 · 10.10.8.22 · COL-PUNE-01 Active 1 Collector Event Sources Active / Inactive Running · incoming IDR pipe 2 Agent on the host Last Scan Time ports 5508/6608/8037 feeds IDR + VM 3 Scan Engine site + template Last Scan Test Credentials VM walker 4 Asset Assessed? name · IP · site Assets / Details no asset = stop 5 Stamp IDR detection or VM finding never both as one pivot the IP IDR stamp · behavior Detection Rule + Rule Action INV-1042 · Creates Investigations VM stamp · weakness First Found + risk + exception msft-lab-01 · risk 842 Collector ≠ Insight Agent ≠ Scan Engine. Same asset ID is a pivot, not a merge. Data Collection Health is the live pipe. Assets is the ticket. Investigations and Vulnerabilities are stamps. A dashboard tile is not proof. Read left → right. Station 4 is the asset. If it does not exist, do not hunt a detection and do not quote First Found. Stamps come last. Concept: Rapid7 manufactures assets from collectors, agents, and scan engines, then stamps either behavior or weakness. Path: collector/agent/engine → asset → InsightIDR detection / InsightVM finding. Do: never open Take Action or Scan Now first. Collector answers “is the IDR pipe talking?” Official: Data Collection → Data Collection Health → Collectors (Active / Inactive). Event Sources tab: Running + Monitor Health incoming vs parsed. Source: Collector Overview + Monitor Event Source Health + Collector Shows as Inactive. Agent answers “is this host assessed from the inside?” Official: Last Scan Time is last agent assessment. Agent assessments for InsightVM run automatically about every 6 hours and are already authenticated. Agent to Collector uses TCP 5508, 6608, and 8037. Source: Using the Insight Agent with InsightVM + Collector Installation. Scan Engine answers “did a site actually look at this host?” Official: Last Scan is the last discovery, vulnerability, or policy scan. Authenticated scans need credentials (or Scan Assistant). Test Credentials before you trust completed. Source: Configuring scan credentials + Locating and working with assets. Stamps answer “what did the factory write?” Official IDR: Detection Rules → Detection Rule Library, Rule Action. Official VM: Vulnerabilities / asset listing, First Found, risk, exception. Source: Modify Detection Rules + Working with vulnerabilities. ## 3. First event / first scan vs later The first event of a new host, or the first scan of a new site member, has no stamp yet. It walks the factory: worker observes → asset is printed (Assessed) → assigned Detection Rule or scan template stamps behavior or weakness. Later events of the same asset ride that ticket. That is why “I flipped Rule Action” sometimes does nothing until the next match, and why “I added a credential” does nothing until the next scan or the next agent upload. Flow 2 · official factory order (student labels) Rapid7 first-event or first-scan factory path versus later events of the same asset Worker → asset exists? → print ticket → stamp IDR or VM → prove 1 Worker collector · agent · engine Asset? Assessed yes SETUP — first event / first scan of this host print Assessed asset, then apply the stamp Collector health Active · Running Agent / engine Last Scan Time / Last Scan Normalize + user attribution Product pick behavior or weakness Rule / template Action · creds Stamp INV or finding LATER EVENTS / LATER SCANS — same asset ticket refresh Last Scan Time · ride the investigation · complementary scan skips local checks the agent already ran yes → skip setup no Stop. Coverage ticket. Install agent or add to a site Official facts students invert 1. Last Scan ≠ Last Scan Time. Site Last Scan is engine. Query Builder Last Scan Time is agent. 2. Completed scan ≠ authenticated. Test Credentials. Agent assessments are already local. 3. Rule Action Off / Tracks Notable Events / Assess Activity will not open an investigation. 4. Collector Inactive, or event source Running with 0 EPM, is a pipe ticket — not a silent miss. Source: Locating assets · Configuring scan credentials · Modify Detection Rules · Collector troubleshooting Attribution delay up to 5 minutes via Collector. Agent → Collector 5508 / 6608 / 8037. Collector → platform 443. Read left → right, then the green later-events bar. Decision diamond = “does this host already exist as an Assessed asset?” No asset is a coverage ticket. #1 student trap — completed and silent A site that finished in minutes with 0 local findings on a fat Windows domain controller is usually an unauthenticated ping, not a clean box. Official: authenticated scans check software, packages, and patches; the Insight Agent is already authenticated from inside; Scan Assistant can replace admin passwords with a certificate. Test Credentials against one asset before you tell the CISO “clean.” Complementary scanning only skips local checks when the agent assessment uploaded in the expected window — and fully elevated credentials (or Scan Assistant) are required to recognize that. ## 4. How to choose the workers and stamps You are not choosing a logo. You are choosing which worker is allowed to print the asset, and which stamp the factory is allowed to write. Choice Use when Do not use when Proof you were right On-prem Collector + Event Source You need normalization and user attribution from AD, DHCP, VPN, firewall, proxy. You only have a cloud event source and you expected Collector health to explain it. Collector Active. Event source Running. Monitor Health shows incoming and parsed. EPM > 0. Insight Agent on the host Remote / cloud assets, endpoint detections, quarantine, VM local checks without scan creds. You treat agent Last Scan Time as site Last Scan, or you skip the Collector ports. Last Scan Time in minutes. Asset shows the agent icon. Quarantine toggle can arm (up to 6 hours). Scan Engine + shared credential Interior authenticated VM view. Windows SMB/CIFS or SSH + elevate. Assign to the site. You report “clean” after Test Credentials failed (invalid credentials / connection refused). Test Credentials green on 10.10.8.22. Local vulns appear. Last Scan is today’s job. Scan Assistant You want authenticated depth without storing an admin password. Certificate to the engine. You assume Assistant is the Insight Agent. It is a scan-time channel, not endpoint EDR. Engine connects; local checks run; no shared password on that site. Complementary scanning Scheduled site scans of agent-covered assets. Engine runs only remote checks the agent cannot. Ad-hoc Scan Now of a host whose agent is stale — official caveat: keep it off the primary ad-hoc template. Agent Last Scan Time is fresh. Engine job is shorter. Remote-only findings still appear. Rule Action = Creates Investigations SOC must open a case when this behavior matches. Set Rule Priority. You leave it Off and then ask “why no detection.” Off is a recipe, not a miss. Investigations list shows Status + Detection Rule + that Action. Tracks Notable Events / Assess Activity / Off Context only, 7-day noise study, or a rule you do not want. You flip Off because Log Search was empty for the wrong hour. Library shows the Action. Assess Activity auto-offs after 7 days unless you change it. Quarantine Asset IDR investigation, live agent, named contain owner. Insight Agent Actions. VM finding with no IR case. Or InsightConnect Isolate-Host already succeeded. Timeline shows Quarantine. Undo Quarantine is how you reverse. Toggle may lag 6 hours. Official Collector guidance: it is usually more efficient to deploy multiple Collectors than to break firewall rules or overload one. Recommended comfort band is about 50–60 Event Sources per Collector; maximum recommended is 80. Source: Collector Overview + Collector Requirements. ## 5. Runbook Side A → B → C Lab values only. Collector COL-PUNE-01 at 203.0.113.40 , asset DEVICE-LAB-22 / 10.10.8.22 , event source ES-AD-DC01 , site SITE-LAB-01 , engine ENG-DEL , shared credential LAB-WIN-SCAN-01 , investigation INV-1042 , finding msft-lab-01 , user example\finance.user . Nothing here is a live tenant. ### Side A — stand up the factory floor (Collector, Agent, scan creds) Primary source: Collector Installation and Deployment + Ports Used by SIEM (InsightIDR) + Configuring scan credentials. Path: Data Collection → Setup Collector → Activate Collector , then Administration → Scans → Shared Credentials → Manage shared credentials for scans . https://insight.lab.example — Data Collection › Collectors › COL-PUNE-01 Training mock · not live Data Collection → Data Collection Health → Collectors ### Collector COL-PUNE-01 Health Event Sources Agents Name COL-PUNE-01 Status Active Active · 203.0.113.40 Event source ES-AD-DC01 · Active Directory Source status Running · EPM 42 Monitor Health · incoming ok · last batch 00:01 ago Monitor Health · parsed ok · normalized Agent path DEVICE-LAB-22 → 5508 / 6608 / 8037 → COL-PUNE-01 → 443 → Insight Platform Active + Running + incoming is the pipe. It is not an investigation and it is not First Found. If this card is Inactive, restart the Collector service before you hunt detections. Setup Collector Monitor Health Source: Collector Installation — Data Collection → Setup Collector / Activate Collector. Monitor Event Source Health — Data Collection → Data Collection Health → Monitor Health. Dummy values only. #### Activate the Collector, then watch health — not the tile Official: Data Collection → Setup Collector (Windows .exe or Linux InsightSetup-Linux64.sh ), copy the activation key, then Setup Collector → Activate Collector , name it, paste the key. “Waiting for connection…” is the handshake. After keys exchange you should see host health metrics. If the card later shows Inactive, official first move is restart the Collector service ( service collector restart / Windows Services). Source: Collector Installation + Collector Troubleshooting.

- #### Open the agent path before you blame a rule Systems running the Insight Agent must reach the Collector on 5508, 6608, 8037 . The Collector must reach the Command Platform on 443 . Cloud-only agents can ingress on 443 without a Collector, but then you lose Collector-side attribution for those hosts. Official: the Insight Agent is the only source of up-to-date hostname-to-IP in cloud environments. Source: Collector Installation + Ports Used by SIEM (InsightIDR).

- #### Add one Event Source per device, then prove Running Data Collection → Event Sources → Add Event Source , filter Collected By → Collectors. One AD event source per domain controller. Status under the name should be Running . EPM 0 on a Running AD source is still a pipe ticket. Monitor Health is incoming vs parsed — Running ≠ data in Log Search. Source: InsightIDR Event Sources + Event Source Troubleshooting.

- #### Create the VM credential before the site job Official path: Administration → Scans → Shared Credentials → Manage shared credentials for scans (Global Admin / Manage Site). Or a site-specific credential in the site configuration. Then Test Credentials against one IP or FQDN and the auth port. Official failures: Invalid credentials , Connection refused . Source: Configuring scan credentials + InsightVM Quick Start.

     https://192.0.2.40:3780 — Administration › Scans › Shared Credentials

     Training mock · not live

       Administration → Scans → Shared Credentials → LAB-WIN-SCAN-01

### Shared Scan Credential Configuration

          Name  LAB-WIN-SCAN-01

          Service  Microsoft Windows/Samba (SMB/CIFS)

          Domain / username  LAB\svc-ivm-scan

          Assign to site  SITE-LAB-01

        Test against asset  10.10.8.22 · last test failed · Invalid credentials

       A completed site job with 0 local vulns on this DC is not clean until this box is green. Connection refused is port / firewall. Invalid credentials is the account.

         Cancel
         Test Credentials

    Source:  Configuring scan credentials — Administration &gt; Scans &gt; Shared Credentials &gt; Manage shared credentials for scans. Test Credentials dropdown: IP/FQDN + port. Dummy values only.

### Side B — print the ticket (site + Event Source + Rule Action)

 Primary source: Creating and editing sites + Modify Detection Rules + InsightIDR Event Sources. The recipe is: put the host in a site (or install the agent), keep the Event Source Running, set Rule Action to the outcome you actually want.

- #### Create or open the site, assign the engine, save the template choice Create → Site or Sites listing. Assign Scan Engine ENG-DEL . Official: one engine per site so sites can scan together without overloading one worker. Enable complementary scanning only on the scheduled template — official caveat: keep it disabled on the primary template used for ad-hoc scans. Source: Scan Engines + Scan Template Best Practices.

- #### Confirm the host became Assessed Assets icon → Assets page. Official: Assessed after scan or Insight Agent install. Unassessed = dynamic discovery (LDAP / Azure / AWS) assigned to a site but not yet assessed. Agent-installed assets show the agent icon and belong to the Rapid7 Agent site. Source: Locating and working with assets.

- #### Set the Detection Rule Action on purpose Detection Rules → Detection Rule Library → open the rule peek panel → Rule Action. Official list: Creates Investigations, Creates Alert, Tracks Notable Events, Assess Activity, Off. Rule Priority (Critical / High / Medium / Low / Unspecified) applies to investigations that rule creates. Exceptions override Action for a key-value pair. Source: Modify Detection Rules.

- #### Do not celebrate a Save A green Activate Collector, a saved site, or a changed Rule Action is a recipe. Side C is the proof — the asset row, the health card, and the stamp.

  Predicted factory — Techclick dummy lab
 collector     : COL-PUNE-01  203.0.113.40  status=Active
event_source  : ES-AD-DC01   type=Active Directory  status=Running  epm=42
agent         : DEVICE-LAB-22 → COL-PUNE-01 :5508,:6608,:8037
site          : SITE-LAB-01  engine=ENG-DEL  last_scan=2026-08-16T03:10Z
credential    : LAB-WIN-SCAN-01  test=FAIL  reason=Invalid credentials
rule          : Suspicious PowerShell  action=Creates Investigations  priority=High
asset         : 10.10.8.22  assessed=yes  last_scan_time=16m

 Say the word  predicted . This is the recipe you configured. The live investigation or the live First Found may still be missing if the credential failed or Rule Action is not Creates Investigations. Compare it in Side C.

### Side C — prove the asset, then the stamp

 Primary source: Locating and working with assets + Investigations / Analyze an investigation + Quarantine an Asset + Working with vulnerabilities. Path:  Assets / Asset Details , then either  Investigations → INV-1042  or the asset  Vulnerability Listing .

- #### Prove the host is an asset before you argue about stamps InsightVM Assets (Assessed / Unassessed). InsightIDR global search → Asset Details . Quote hostname, IP, site, OS, agent present. No row = coverage ticket. Do not Quarantine a missing host. Do not quote First Found from a weekly PDF.

- #### Read Last Scan versus Last Scan Time out loud Official: site / Assets Last Scan = last discovery, vulnerability, or policy scan. Query Builder Last Scan Time = last Insight Agent assessment. Asset Details also shows Last On Demand Agent Scan . Completed ≠ authenticated. Minutes on Last Scan Time means the inside worker is live.

- #### If the ticket is behavior, open the investigation and quote Rule Action Investigations → INV-1042 . Quote Status, Priority, Detection Rule, Rule Action. Empty queue is data: usually no asset, dead collector, or Action ≠ Creates Investigations. Then, and only then, Take Action → Rapid7 Agent (Insight Agent) Actions → Quarantine Asset . Reverse with Undo Quarantine on the timeline. Source: Quarantine an Asset.

- #### If the ticket is weakness, open the finding and quote First Found Asset Vulnerability Listing / Vulnerabilities . Quote First Found , risk, CVSS, Severity, exception reason + expiry. A completed site job with Test Credentials failed is not a clean finding list. Exception is accepted risk with an owner — not “ignore.”

     https://insight.lab.example — Investigations › INV-1042

     Training mock · not live

       Investigations → INV-1042

### Investigation details

         asset:10.10.8.22 AND rule:"Suspicious PowerShell"

         Apply

               ID
               Asset
               Detection Rule
               Rule Action
               Status
               Priority

               INV-1042
               10.10.8.22
                Suspicious PowerShell
               Creates Investigations
               Open
               High

               —
               10.10.8.22
                msft-lab-01
               VM finding · not IDR
               First Found 2026-08-02
               risk 842

         asset=DEVICE-LAB-22 assessed=yes last_scan_time=16m

         collector=COL-PUNE-01 Active  event_source=ES-AD-DC01 Running epm=42

         vm_cred=LAB-WIN-SCAN-01 test=FAIL  do not call SITE-LAB-01 clean

         do not Quarantine from the VM row · product pick first

       Row INV-1042 is the IDR stamp. The VM row is a pivot on the same IP, not a second isolate. Click Take Action only after you name one contain owner.

    Click next:  if IR owns it, Take Action → Rapid7 Agent (Insight Agent) Actions → Quarantine Asset. If VM owns it, open First Found + exception. Source: Analyze an investigation + Quarantine an Asset + Working with vulnerabilities.

   Proof · asset + stamp cockpit

   Notice: juniors stare at the dashboard. Seniors stare at Assessed, collector Active, Last Scan Time, Rule Action, and First Found.

  Live ticket — dummy lab, not a customer org
 asset                : DEVICE-LAB-22 / 10.10.8.22
assessed             : yes
collector            : COL-PUNE-01 Active
event_source         : ES-AD-DC01 Running  epm=42
last_scan            : 2026-08-16T03:10Z   (site SITE-LAB-01)
last_scan_time       : 16m                 (Insight Agent)
investigation        : INV-1042
detection_rule       : Suspicious PowerShell
rule_action          : Creates Investigations
status               : Open
vm_finding           : msft-lab-01
first_found          : 2026-08-02
risk                 : 842
credential_test      : FAIL  Invalid credentials
quarantine           : off

   Green success on this runbook

   Host is Assessed on Assets / Asset Details. Collector  Active , event source  Running  with incoming parsed (or Last Scan Time in minutes if this is an agent-only host). If behavior: investigation Status + Detection Rule + Rule Action quoted. If weakness: First Found + risk + exception quoted, and Test Credentials explained. Same IP in both is a pivot with one contain owner. A green dashboard tile with an Unassessed host is not success.

## 6. Runtime — complementary scan, Rule Action, quarantine

 After the asset exists, later events of the same host skip the “is this a new ticket?” question and ride the existing investigation or the existing finding. Official complementary scanning: the Scan Engine consults the agent assessment record and skips local checks the agent already ran, so scheduled jobs get shorter and you stop double-correlating the same local QIDs. Official caveat: fully elevated credentials or Scan Assistant are required to recognize a fresh agent upload; keep complementary scanning off the primary ad-hoc template.

 If you changed Rule Action after the last match, the open investigation keeps the old Action. The next match follows the new recipe. Assess Activity tracks for 7 days, writes an Assessment Report, then switches the Action Off unless you change it. That is the later-events bar in Flow 2, not a broken Library.

 Official quarantine: the Insight Agent backups the Windows firewall, blocks inbound/outbound except DNS UDP/53, DHCP UDP/67, Collectors, and the Insight Platform. ICMP and other UDP die. It can take up to  30 minutes  to regain Platform access; the Asset Details page may show offline during that window — expected. The Asset Info quarantine toggle can take up to  6 hours  to enable after firewall prep; during that lag you can still quarantine from the investigation. Undo Quarantine restores the original firewall. Source: Quarantine an Asset.

 Official Collector delay: up to 5 minutes for endpoint information to show in InsightIDR when you use the Collector path. Do not flip Rule Action because the last PowerShell line is not in Log Search yet. Attribution needs a supported Event Source plus reliable IP→asset (usually Insight Agent + DHCP).

   Flow 3 · quarantine runtime

       Quarantined Insight Agent host keeps DNS DHCP Collector and Insight Platform; everything else is cut

- Host quarantined Insight Agent FW Collector + Platform always allowed DNS / DHCP UDP/53 · UDP/67 Everything else blocked · ICMP dies Offline on Asset Details for a while is expected. Platform access can take 30 minutes. Toggle on Asset Info can lag 6 hours after firewall prep. Investigation Take Action still works. Source: Quarantine an Asset — Insight Agent firewall rules are not customizable during quarantine Quarantine is a network stamp on an existing asset with a live agent. It is not a VM exception, and it is not a second Isolate-Host. ## 7. Traps + factory proof Symptom Looks like Actually First move Dashboard green, “Rapid7 not seeing host” Platform outage Host Unassessed, or never in a site / no agent Assets / Asset Details. Coverage ticket if missing. Why no detection? Rule is broken Rule Action Off / Tracks Notable Events / Assess Activity, or collector Inactive Library Rule Action, then Data Collection Health. Scan completed, 0 local vulns on a DC Clean week Unauthenticated job or Test Credentials failed Test Credentials. Do not tell the CISO “clean.” Last Scan is last month, Last Scan Time is 16m Stale estate Engine job is old; agent is live Read both fields. Complementary scan next window. Last Scan Time is 12 days Fewer findings, we patched Dark agent — quieter list because nothing uploaded Coverage ticket. Do not celebrate the PDF. Event source Running, EPM 0 AD is fine No events — WMI / ports / wrong DC Monitor Health incoming vs parsed. Event Source Troubleshooting. Collector Inactive Need a new rule On-prem worker stopped Restart Collector service. Then re-check Event Sources. “Rapid7 critical, isolate it” One ticket VM finding vs IDR investigation mixed Name the product. One contain owner. Never isolate twice. Quarantine toggle grey Agent broken Firewall prep lag up to 6 hours Take Action from the investigation. Do not wait on the toggle. InsightConnect Isolate-Host last=success Need IDR quarantine too Already contained Collect and remediate. Do not isolate again. Proof checklist — the factory printed a live ticket Host is on Assets / Asset Details as Assessed (name, IP, site). Unassessed = not done.

- Pipe: Collector Active + event source Running + Monitor Health incoming/parsed — or agent Last Scan Time in minutes.

- Last Scan (engine / site) and Last Scan Time (agent) named separately.

- If behavior: Investigations Status + Detection Rule + Rule Action .

- If weakness: First Found + risk + exception (reason + expiry). Test Credentials explained if local vulns are empty.

- Same IP in VM and IDR is a pivot with one contain owner. Quarantine only from IDR / agent, and only once.

- A dashboard tile, a completed site job, or a green Activate toast is not the proof.

   Interview close you can steal

   Rapid7 is a collector + scan factory. A Collector, Insight Agent, or Scan Engine manufactures an asset. InsightIDR stamps a detection; InsightVM stamps a finding. I prove the ticket on Assets, then Data Collection Health or Last Scan Time, then either Rule Action on the investigation or First Found on the vulnerability. A green dashboard is not an asset. Completed is not authenticated. Same IP is a pivot, not a merge.

 Related:  Evidence desk — first tool + proof field  ·  InsightIDR interview Q&amp;A  ·  InsightVM + Exposure Command  ·  InsightConnect SOAR  ·  Rapid7 hub

## Knowledge check

   Six judgment questions. Map each miss back to the section named in the reason.

       Q1
       Slack says “Rapid7 is not seeing this host — why no detection?” What do you prove first?

           Flip the Detection Rule Action to Creates Investigations
           Whether a Collector, Insight Agent, or Scan Engine printed this host as an Assessed asset
           Take Action → Quarantine Asset from a blank investigation queue
           Scan Now the whole VLAN so Last Scan refreshes

       Correct:  b . No asset = nothing for a detection or a finding to hang on. Re-read Why a green tile is not an asset and Mental model.

       Q2
       What are the Collector, the Insight Agent, and the Scan Engine?

           Three names for the same Rapid7 cloud service
           Three extra SIEMs you buy and cable in series
           Three factory workers — Collector pipes Event Sources, Agent sits on the host for IDR and VM, Scan Engine walks a site
           Features that only run after you disable complementary scanning

       Correct:  c . Collector ≠ Agent ≠ Scan Engine. Re-read Mental model — three workers, one ticket, two stamps.

       Q3
       SITE-LAB-01 completed in minutes with 0 local vulnerabilities on a Windows domain controller. First move?

           Test Credentials — completed ≠ authenticated
           Report “clean” to the CISO because the job status is Completed
           Quarantine the DC from InsightIDR because empty means compromised
           Turn complementary scanning off and rescan the internet with a hosted engine

       Correct:  a . Official Test Credentials failures are Invalid credentials or Connection refused. Re-read First event / first scan vs later and Side A.

       Q4
       A Suspicious PowerShell rule you thought was “on” produced no investigation. Best official explanation?

           InsightVM must scan the host before any IDR rule can fire
           You must run InsightConnect Isolate-Host before detections appear
           Last Scan Time is required on every Event Source
           Rule Action is Off, Tracks Notable Events, or Assess Activity — a match will not create an investigation

       Correct:  d . Official Rule Actions: Creates Investigations, Creates Alert, Tracks Notable Events, Assess Activity, Off. Re-read How to choose and Side B.

       Q5
       What is the official difference between Last Scan and Last Scan Time?

           They are the same timestamp on the Assets page
           Last Scan is the last discovery / vulnerability / policy scan; Last Scan Time is the last Insight Agent assessment
           Last Scan Time is the Collector heartbeat
           Last Scan is only First Found on the vulnerability

       Correct:  b . Official note on Locating and working with assets. Re-read Hard words and Side C.

       Q6
       What proves the Rapid7 factory printed a live ticket?

           A green InsightIDR dashboard tile
           Site last=ok only, even if Test Credentials failed
           Assessed asset + collector Active (or agent Last Scan Time in minutes) + either an investigation (Status + Detection Rule + Rule Action) or a VM finding (First Found + risk)
           The Asset Info quarantine toggle is grey, so the factory must be healthy

       Correct:  c . Tile is a poster. Site last-ok is not authenticated. Grey toggle can be the 6-hour prep lag. Re-read Side C and the proof checklist.

       Check answers
       Reset

## Sources

- Collector Overview — on-prem worker, Event Source = one device, normalization + user attribution, 5-minute delay, DHCP + Insight Agent for attribution

- Collector Installation and Deployment — Data Collection → Setup Collector / Activate Collector, agent ports 5508 / 6608 / 8037, Collector → platform 443

- Collector Requirements — about 50–60 Event Sources per Collector, maximum recommended 80

- Collector Troubleshooting — Collector Shows as Inactive, restart Collector service

- Monitor Event Source Health — Data Collection → Data Collection Health → Monitor Health, incoming vs parsed

- Event Source Troubleshooting — status Running, Start Running / Stop Running

- SIEM (InsightIDR) Event Sources — Data Collection → Event Sources → Add Event Source, Collected By Collectors vs Rapid7 Cloud Platform

- Rapid7 Agents (Insight Agents) with SIEM (InsightIDR) — endpoint detections, quarantine, Settings → Rapid7 Agent (Insight Agent) → Domain Controller Events

- Modify Detection Rules — Detection Rule Library, Rule Action list, Rule Priority, exceptions, Assess Activity 7 days

- Quarantine an Asset — Investigations → Take Action → Rapid7 Agent (Insight Agent) Actions → Quarantine Asset, Undo Quarantine, 30-minute / 6-hour lags

- Configuring scan credentials — Administration > Scans > Shared Credentials > Manage shared credentials for scans, shared vs site-specific

- InsightVM Quick Start Guide — Test Credentials, Invalid credentials, Connection refused

- Locating and working with assets — Assessed vs Unassessed, Last Scan vs Last Scan Time, agent icon

- Using the Insight Agent with InsightVM — complementary scanning, agent assessments already authenticated, ~6-hour cycle

- Scan Template Best Practices — Skip checks performed by the Insight Agent, do not enable complementary scanning on the primary ad-hoc template

- Working with vulnerabilities — First Found, risk, exceptions

 Related:  Rapid7 evidence desk — first tool + proof field  ·  InsightIDR interview Q&amp;A  ·  InsightVM and Exposure Command  ·  InsightConnect SOAR  ·  Rapid7 interview hub  ·  Rapid7 security platform hub

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
