---
title: "Immediate Vulnerability Scans for Critical Assets After Threat Detection"
canonical: "https://docs.infoblox.com/space/DeploymentGuideIPAMTDwithRapid7/1631879262/Immediate%20Vulnerability%20Scans%20for%20Critical%20Assets%20After%20Threat%20Detection"
format: markdown
---
To trigger **asset synchronization and vulnerability scan** based on **Threat Defense (TD) logs**, the asset must be tagged with:

`VM_Scan_on_Policy_Hit = true`

- The integration script **evaluates this tag in the following priority order**:
  - **IP Address**
  - **IP Range**
  - **Subnet**
  - **IP Space** *(applicable to DFP service)*
  - **Endpoint** *(applicable to Endpoint service)*
  - **Endpoint Group** *(applicable to Endpoint service)*

### Example Scenarios

- **Scenario 1:**  
A **Subnet** is tagged with `VM_Scan_on_Policy_Hit = true`.
  Any asset within that subnet that triggers a **threat defense log** will be:
  - **Synchronized** to Rapid7
  - **Immediately scanned** for vulnerabilities
- **Scenario 2:**  
An **Endpoint Group** is tagged with `VM_Scan_on_Policy_Hit = true`.
  Any **device** in that group generating a **threat defense log** will also be:
  - **Synchronized**
  - **Scanned** in Rapid7