Prioritize and act on remediations

Remediation Hub provides a central location for recommended remediation actions on risks and vulnerabilities across your hybrid environment, so you can focus and prioritize your efforts on the most impactful changes and improve your overall security posture.

Requirements

To access Remediation Hub, you must have at least one of the following roles:

  • Vulnerability Management - any role

  • Attack Surface Management - Admin

If you also have a Cloud Security Domain Admin or Domain Viewer role, you can also see Cloud Security remediations.

Remediation Hub is scoped to your permissions

You can only see remediations for the assets you can access. For example, if you only have a Vulnerability Management role, you only see Vulnerability Management remediations.

To populate Remediation Hub with data, you must have already set up at least one of the following modules:

Third-party vulnerability and remediation support

Remediation Hub can report vulnerabilities and remediations from third-party sources when the corresponding Attack Surface Management connector is installed. Supported connectors include:

  • Amazon Inspector

  • Claroty xDome

  • Dragos Vulnerability

  • ManageEngine Endpoint

  • Orca

  • Qualys Vulnerability Management Detection & Response (VMDR)

  • Red Hat Insights

  • SentinelOne

  • Tenable (Tenable.io)

  • Tenable Security Center (SC)

  • Wiz

Review emergent threats

Rapid7’s security research team actively monitors and researches emergent threats. Rapid7’s Emergent Threat Response delivers fast expert analysis and first-rate security content for the highest priority security threats to help you understand your exposures and act quickly to protect your assets from exploitation. When an emergent threat is active, Remediation Hub displays a banner at the top of the page.

This banner:

  • Indicates that Rapid7 teams are actively responding to the threat

  • Links to a Rapid7 blog post with ongoing updates

  • Provides visibility into associated CVEs and impacted assets as more data becomes available

Emergent threats are displayed for 14 days. If no emergent threat is active, the banner is not shown.

Explore remediations

You can monitor the potential impact of the top 25 remediations using the key metrics, including:

Metric Description
Vulnerability Findings Remediated The number of vulnerability findings expected to be remediated if the top 25 remediations are implemented.
Assets Updated The number of assets that would be updated if the top 25 remediations are implemented.

Each risk or vulnerability in your environment is paired with a suggested action for remediation in the Remediations table, which is initially sorted by risk score. You can use filters to narrow your view of the results shown in the table.

To filter the Remediations table:

  1. From Command Home, go to Risk > Remediation Hub.

  2. Optionally adjust the columns or row density:

    1. Select Columns, then search and select columns to display in the table.

    2. Select Density and then a type to control how large the results table rows are.

  3. Select Filters.

  4. Select a Criteria to filter on, then select an Operator and Value.
    Note: Some criteria are for filtering remediations specific to Vulnerability Management or Cloud Security.

  5. Select Add Filter to add another filter.

  6. Select Apply.

Special filters

Some filters, such as Reboot Required (Patch Management) or Patch Management, are based on asset-level conditions. As a result, the Remediations table may not visibly change, even when a filter is applied. To confirm how a filter affects results, open a remediation and go to the Impacted Assets tab.

If you have endpoint protection or patch management software connected to Attack Surface Management, you can filter on either of these to quickly find remediations that rely on your existing mitigation controls. Review Assess endpoint protection and patch management coverage for more information.

Investigate remediation details

The remediation details panel hosts an AI summary for the remediation, the assets impacted by the remediation, the specific vulnerabilities mitigated by the remediation, access to Automation remediation action capabilities, and more.

To open remediation details:

  1. From Command Home, go to Risk > Remediation Hub.

  2. Select a remediation from the table to open the details panel.

Export and report on remediations

You can export or report on remediations to share clear, actionable remediation guidance with asset owners in your organization. There are a couple different ways to share your remediations and impacted assets outside of Remediation Hub:

  • As a CSV file

  • As a scheduled report, which can be an HTML, CSV, or PDF report

One report in Remediation Hub can convey your full attack surface without having to return to Vulnerability Management, Cloud Security, and Attack Surface Management to generate similar results.

To export the top 25 remediations as a CSV:

  1. From Command Home, go to Risk > Remediation Hub.

  2. Add filters as needed.

  3. Select Export to download the top 25 remediations in the current view.

To export impacted assets:

  1. From Command Home, go to Risk > Remediation Hub.

  2. Add filters as needed.

  3. Select a remediation from the table to view its details.

  4. Select Export > CSV.

To create a scheduled top 25 remediations report:

  1. From Command Home, go to Risk > Remediation Hub.

  2. Add filters as needed.

  3. Select Create Report.

  4. Choose a report type and select Open:

    • Top Remediations Summary - See the top 25 remediation actions from your current filters that reduce the most risk. Use this report to prioritize fixes based on their overall impact.

    • Top Remediations Summary with Assets - See the top 25 remediation actions from your current filters that reduce the most risk, including the affected assets for each action. Use this report to identify where to apply each fix.

  5. Optionally, adjust the report name and description.

  6. Select at least one format: HTML, PDF, or CSV.

  7. Optionally, update the Scheduling:

    • To generate a report now, turn on Trigger report on save.

    • To generate the report on a recurring schedule, select Add Schedule.

      1. Select the new schedule entry.

      2. Select a start date for the report.

      3. Enter a repeat timeframe. For example, repeat every 3 days.

      4. Enter a time to generate the report.

      5. Configure when the report should end (never or a select date).

      6. Select users or email addresses that you want to share the reports with.

    • Optionally, select Add Another Schedule to add a separate schedule.

  8. Select Create.