---
title: "Introduction"
canonical: "https://docs.infoblox.com/space/DeploymentGuideIPAMTDwithRapid7/1632470714/Introduction"
format: markdown
---
**Automated Threat-Driven Asset Sync and Scanning with Infoblox and Rapid7 InsightVM**

This solution integrates **Infoblox services**—including **Threat Defense™,** **DHCP**, **SOC Insights**, and **IPAM—with** **Rapid7 InsightVM** to deliver automated, policy-driven asset synchronization and vulnerability scanning across enterprise networks. It empowers security teams to respond swiftly to threats, maintain accurate asset inventories, and ensure timely vulnerability assessments.

**Rapid7 InsightVM** is a leading asset and vulnerability management platform that provides real-time visibility into risk, prioritizes vulnerabilities based on threat context, and supports automated remediation workflows. By combining InsightVM’s scanning capabilities with Infoblox’s network intelligence, this integration ensures that assets are continuously monitored and scanned based on real-time events and policy logic.

**Key Capabilities**

● **Threat-Triggered Scanning**  
            Automatically initiate scans when Infoblox Threat Defense detects malicious DNS activity, enabling rapid investigation of high-risk endpoints.

● **SOC Insights-Based Response**  
            Trigger scans based on SOC Insight events to reduce response time and accelerate remediation.

● **DHCP Lease Monitoring**  
            Scan new devices immediately after they join the network via DHCP, ensuring early detection of vulnerabilities.

● **IPAM-Driven Asset Synchronization, Grouping, and Scanning**  
            Use Infoblox IPAM as the source of truth for IP objects to maintain consistent asset records. Automatically assign assets to predefined groups and trigger scans based on tagging policies.

● **Selective Scanning and Exclusions**  
            Enforce scan restriction intervals and exclude specific IP ranges from synchronization and scanning to optimize performance and reduce noise.

● **Scheduled Asset Enrichment**  
            Periodically update asset metadata with scan results, including CVE IDs and severity levels, to support ongoing risk analysis.


This event-driven integration streamlines vulnerability management, reduces manual effort, and strengthens overall security posture by ensuring scan decisions are based on real-time network activity and asset intelligence.