针对 Rapid7InsightVMCloudVulnerabilities 表的查询

有关在 Azure 门户中使用这些查询的信息,请参阅 Log Analytics 教程。 有关 REST API,请参阅 查询

Rapid7 InsightVM 云漏洞

汇总漏洞。

source  
| project
    TimeGenerated               = now(),
    Added                       = todatetime(added),
    Categories                  = tostring(categories),
    Cves                        = tostring(cves),
    CvssV2AccessComplexity      = tostring(cvss_v2_access_complexity),
    CvssV2AccessVector          = tostring(cvss_v2_access_vector),
    CvssV2Authentication        = tostring(cvss_v2_authentication),
    CvssV2AvailabilityImpact    = tostring(cvss_v2_availability_impact),
    CvssV2ConfidentialityImpact = tostring(cvss_v2_confidentiality_impact),
    CvssV2ExploitScore          = todouble(cvss_v2_exploit_score),
    CvssV2ImpactScore           = todouble(cvss_v2_impact_score),
    CvssV2IntegrityImpact       = tostring(cvss_v2_integrity_impact),
    CvssV2Score                 = todouble(cvss_v2_score),
    CvssV2Vector                = tostring(cvss_v2_vector),
    CvssV3AttackComplexity      = tostring(cvss_v3_attack_complexity),
    CvssV3AttackVector          = tostring(cvss_v3_attack_vector),
    CvssV3AvailabilityImpact    = tostring(cvss_v3_availability_impact),
    CvssV3ConfidentialityImpact = tostring(cvss_v3_confidentiality_impact),
    CvssV3ExploitScore          = todouble(cvss_v3_exploit_score),
    CvssV3ImpactScore           = todouble(cvss_v3_impact_score),
    CvssV3IntegrityImpact       = tostring(cvss_v3_integrity_impact),
    CvssV3PrivilegesRequired    = tostring(cvss_v3_privileges_required),
    CvssV3Scope                 = tostring(cvss_v3_scope),
    CvssV3Score                 = todouble(cvss_v3_score),
    CvssV3UserInteraction       = tostring(cvss_v3_user_interaction),
    CvssV3Vector                = tostring(cvss_v3_vector),
    DenialOfService             = tobool(denial_of_service),
    Description                 = tostring(description),
    Exploits                    = tostring(exploits),
    Id                          = tostring(id),
    Links                       = tostring(links),
    MalwareKits                 = tostring(malware_kits),
    Modified                    = todatetime(modified),
    PciCvssScore                = todouble(pci_cvss_score),
    PciFail                     = tobool(pci_fail),
    PciSeverityScore            = todouble(pci_severity_score),
    PciSpecialNotes             = tostring(pci_special_notes),
    PciStatus                   = tostring(pci_status),
    Published                   = todatetime(published),
    References                  = tostring(references),
    RiskScore                   = todouble(risk_score),
    Severity                    = tostring(severity),
    SeverityScore               = todouble(severity_score),
    VulnerabilityTitle          = tostring(['title'])