---
title: "Integration Benefits and Key Use Cases"
canonical: "https://docs.infoblox.com/space/DeploymentGuideIPAMTDwithRapid7/1632567436/Integration%20Benefits%20and%20Key%20Use%20Cases"
format: markdown
---
### A. IPAM Integration – Asset Synchronization and Tag-Based Grouping

1. **Synchronizing, Grouping, and Scanning Assets of Infoblox IPAM**
  - The integration continuously synchronizes asset inventory from Infoblox IPAM into Rapid7, grouping assets-based tags. This enables up-to-date visibility and ensures that all managed assets are eligible for vulnerability scanning.
2. **Selective Synchronization of Used IPs Only**
  - By enabling the **restrictToUsedIps** parameter, users can ensure that only actively used IP addresses—such as those with MAC addresses—are synchronized and scanned, streamlining operations and focusing security on in-use assets.

### **B. Threat Defense—DNS-Based Threat Response and Targeted Scanning**

1. **Immediate Vulnerability Scans for Critical Assets Following Threat Detection**
  - When a threat is detected, Rapid7 automatically initiates vulnerability scans on the affected assets to assess exposure and prioritize remediation.
2. **Scan Criteria Evaluation Hierarchy**
  - The solution follows a hierarchical policy for scan initiation:
    - `IP Range
    - Subnet
    - Space (for DFP service) or Endpoint Group (for Endpoint service)
    - Global/default criteria at the Data Connector Destination level (Destination Parameters, least specific)

*This ensures the most specific and relevant scan policies are enforced.*

### C. DHCP Lease Integration – Real-Time Discovery and Scan Scheduling

1. **Automatic Scanning of Devices Upon DHCP Lease Assignment**
  - New devices receiving a DHCP lease from Infoblox are automatically discovered and scheduled for vulnerability scanning in Rapid7, ensuring that newly connected endpoints are assessed for vulnerabilities.

### **D. SOC Insight Alerts – Alert-Driven Scan Initiation**

1. **Scan Initiation Based on SOC Insight Alerts**
  - When Infoblox generates a SOC Insight alert (e.g., based on suspicious DNS activity), Rapid7 triggers a vulnerability scan on the implicated asset, supporting rapid investigation and response.

### E. Cross-Use Case Controls – IP Exclusions and Asset Enrichment

1. **Excluding IP Addresses to Sync and Scan**
  - Administrators can define exclusion lists to prevent specific IP addresses or ranges from being synchronized or scanned, ensuring that critical or trusted systems are not unnecessarily scanned. This exclusion specifically applies to assets processed through Threat Defense and DHCP logs.
2. **Schedule Enrich Assets with Scan Information with Critical Vulnerability**
  - The integration can schedule enrichment of asset records with the latest scan results, highlighting any critical vulnerabilities for prioritized remediation and reporting.