Hello, I would like to hear the process people are using for remediating vulnerabilities.
What we are doing
We are scanning; creating Goals and SLAs for business owners; then creating remediation projects out of them.
The remediation projects have shockingly little information within them. Really it’s just a solution. It’s the Goals and SLAs that you can get information about the vulnerabilities after selecting one. Reference websites, Exploits available, Malware Kits, a list of affected assets are all available in the Goals & SLAs section.
Remediation projects are the recommended path by Rapid7, but I don’t see why. They are all around worse than the Goals & SLAs they are made from.
Agreed - we use Remediation Projects because there is no real alternative, unless we develop an in-house tool (which I did once, but it just created multiple moving parts to maintain and additional cost). I’ve had multiple conversations with R7 and, more recently, had various AI chats to check I’m not missing something and come to the conclusion that delivering remediation information to the people that do the remediation is a bit of a feature gap.
A few things seem like odd design choices in the Remediation Projects, given the assumed purpose of the projects, and I have raised these as IDEAS with Rapid7. Also, I agree about any changes made reset the project statistics, but as we use dynamic projects anyway and the numbers are all over the place this isn’t a huge concern for us.
Rapid7 are pushing the Remediation Hub for prioritizing remediation, which is pretty good for my use, but when dealing with thousands of assets across multiple sites I can’t expect all our IT techs etc to start creating filters to find stuff relevant to them.
Sorry, I almost certainly haven’t helped you other than confirm your concerns!