← All projects

PROFESSIONAL CASE STUDY / AUTOMATION & EXPOSURE REPORTING

Rapid7 Automation
& Asset Visibility

Worked with the team to automate inventory cleanup across more than 2,800 enterprise assets and make vulnerability exposure easier to understand through category-based reporting.

PowerShellRapid7 APIVulnerability managementGRC reporting support
Assets in the cleanup effort
2,800+
Category views + overall KPI
3 + 1
Vulnerability score threshold
CVSS 7+
Metric basis
Vulnerabilities

01 / THE PROBLEM

Reliable reporting starts with the inventory.

Asset classifications in Rapid7 needed cleanup: some endpoints appeared in server groups and some servers appeared in endpoint groups. Other asset types also needed review. These mismatches made category-level vulnerability reporting harder to interpret.

The team needed a clearer view of the proportion of vulnerability findings rated CVSS 7 or higher within each reporting group.

02 / MY CONTRIBUTION

Automation and dashboard reporting.

I worked with the team to develop PowerShell scripts using the Rapid7 API to automate inventory cleanup. The work included correcting asset categorization so the reporting groups better reflected the inventory.

We organized the vulnerability views into servers, endpoints, and high-risk assets. For this dashboard, high-risk assets meant internet-facing assets. Within each group, the updated script divides CVSS 7+ vulnerability findings by total vulnerability findings and multiplies by 100. Both counts are restricted to vulnerabilities published at least 30 days ago. It also calculates an overall KPI across all assets.

03 / EXPOSURE METRICS

Three views of CVSS 7+ exposure.

Each percentage answers: among findings for vulnerabilities published at least 30 days ago, what share in this reporting group have a CVSS score of 7 or higher?

All calculations below apply the same publication-age filter: at least 30 days
Reporting groupNumeratorPercentage calculation
ServersCVSS 7+ vulnerabilities on serversCVSS 7+ server vulnerabilities ÷ total server vulnerabilities × 100
EndpointsCVSS 7+ vulnerabilities on endpointsCVSS 7+ endpoint vulnerabilities ÷ total endpoint vulnerabilities × 100
High-risk assetsCVSS 7+ vulnerabilities on internet-facing assetsCVSS 7+ vulnerabilities on internet-facing assets ÷ total vulnerabilities on internet-facing assets × 100
All assetsCVSS 7+ vulnerabilities across all assetsCVSS 7+ vulnerabilities across all assets ÷ total vulnerabilities across all assets × 100

The numerator and denominator both count asset-vulnerability findings. The same vulnerability on multiple assets can contribute multiple findings. The 30-day filter uses vulnerability publication date, not first discovery on an asset or remediation age. The script prefers a nonzero CVSS v3 score and otherwise uses the older CVSS score field. Internet-facing assets may also be servers or endpoints, so the three views should not be added together. Company counts, percentages, hostnames, and internal dashboard screenshots are omitted.

04 / IMPACT & GRC CONNECTION

Make exposure easier to explain.

Automated cleanup reduced manual effort and improved inventory accuracy. The dashboard made CVSS 7+ exposure visible within each group and helped the team track vulnerability remediation efforts.

This work connects vulnerability management with risk reporting: technical findings become understandable measures that can support prioritization and management review. It supports exposure management and GRC reporting; the dashboard alone does not establish compliance or represent a complete CTEM program.

CVSS describes vulnerability severity. Asset exposure and business context still matter when deciding what to address first.

POWERSHELL KPI CALCULATION

Keep metric definitions explicit.

The updated PowerShell KPI is calculated as CVSS 7+ findings ÷ total findings × 100, restricted on both sides to vulnerabilities published at least 30 days ago. Asset inventory cleanup helps ensure that findings are attributed to the correct group.

The updated implementation uses InsightVM SQL Query Export to aggregate finding-level data. PowerShell validates asset-group identity, creates a temporary report, polls for completion with a deadline, downloads its CSV, and attempts report cleanup in a finally block. Structural and numerical validation checks gate the dashboard export; critical failures block the write. Results include category counts, percentages, and an overall KPI. The company script remains private.

VALIDATION & NEXT IMPROVEMENTS

Make missing data visible.

The reviewed version checks report structure, count ranges, API/report asset totals, duplicate reporting dates, and large KPI changes. Some checks are warnings rather than export blockers.

A next improvement is to distinguish a missing category row or an empty denominator from a measured 0%. Missing category rows currently return zero with a warning, and same-date warnings do not prevent another CSV append. Stronger completeness checks and duplicate-run handling would make the output more reliable.

Email and on-call notification integration are documented future enhancements. These observations come from static code review; the script was not executed against InsightVM for this portfolio update.

05 / WHAT I LEARNED

Data quality changes the meaning of a metric.

I developed my skills in API integration, PowerShell automation, asset classification, and vulnerability reporting. The key lesson was that useful percentages depend on a trustworthy inventory and a clearly defined denominator.

The project strengthened my ability to connect operational security work with reporting that helps people understand and act on exposure.