Rapid7 AppSpider Connector Guide

Summary: How to set up and use the Rapid7 AppSpider connector in Ivanti Neurons.

Overview

The RiskSense platform provides an API-based connector that integrates with Rapid7’s AppSpider Enterprise that enables customers to bring their AppSpider findings into RiskSense to gain visibility of their overall risk due to vulnerabilities in their applications, thereby enabling a more simplified and efficient way to manage those vulnerabilities.

RiskSense users can configure the connector to pull scan data from AppSpider on a periodic basis. Data from AppSpider is ingested as Applications/Application Findings.

AppSpider Enterprise Overview

AppSpider Enterprise is a single console that includes multiple AppSpider Pro scan engines. It is an on-premises installation that manages scan configurations and schedules from a centralized location. It includes unique capabilities and integrations that enable teams to automate more of the security testing program across the entire software development lifecycle (SDLC), from creation through production.

AppSpider Enterprise Connector Setup Prerequisites

User Access and Permissions

To set up the connector, the user account must have API access to AppSpider Enterprise. The credentials used for creating a connector can be either a multi-client or normal user; RiskSense handles both scenarios.

In a multi-client user’s case, the RiskSense connector will pull all scan files associated with multiple clients and process them, as well.

AppSpider Enterprise Role Permissions

The user account associated with the connector must have the following Roles enabled for the connector to pull scan reports from AppSpider Enterprise:

Fetching the API Token Expiry from AppSpider Enterprise

When configuring the connector in Ivanti Neurons, you will need the API token expiry from AppSpider Enterprise. The API token expiry can be retrieved from the IIS Manager configuration file where AppSpider Enterprise is installed. This is custom to each user, and it can be retrieved by following these steps: