---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response vulnerable item detections from third-party integrations

# Vulnerability Response vulnerable item detections from third-party integrations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Vulnerability Response Vulnerable Item Detections from Third-Party Integrations

The Vulnerability Response application in ServiceNow enables the retrieval of vulnerable item data from third-party integrations.
It imports detailed detection data, which represents distinct occurrences of vulnerabilities reported by scanners, and displays this information on detection and vulnerable item records.
If a vulnerable item (VI) is not found during data ingestion, a new one is created, ensuring accurate tracking and management of vulnerabilities.
Show full answer Show less  

## Key Features

* **Integration Support:** Compatible with multiple third-party scanners including Qualys, Rapid7, Tenable, and Microsoft Defender, requiring separate subscriptions.
* **Detection Data Management:** Detections are paired with VIs, and their states are updated based on scanner inputs. A new system property allows for automatic updates of VIs with the last open detection values.
* **Customizable Fields:** Users can modify the DetectionBase script to customize which detection fields are updated.
* **Reopening Resolved VIs:** VIs that were previously resolved but not closed can be automatically reopened based on new detection data or specific configurations in Rapid7 and Qualys.

## Key Outcomes

By utilizing the Vulnerability Response application, ServiceNow customers can effectively manage and respond to vulnerabilities in their environment. This includes maintaining accurate records of vulnerabilities, enhancing detection capabilities through integration, and ensuring timely updates and resolutions. Customers can expect improved visibility into their vulnerability landscape and a streamlined process for addressing security risks.  
View all of the information that is gathered by third-party scans in your ServiceNow AI Platform® instance. View the returned results of the scans on detection and
vulnerable item (VI) records in your instance as these results are viewed on the
scanners.

## Overview {#vr_host_detections__section_mtv_dk1_wkb}

The Vulnerability Response application supports third-party Integrations that retrieve vulnerable item data from your enterprise environment. Detailed data about detections, that is, single, distinct occurrences of
vulnerabilities as reported by the scanners of your third-party integrations, are imported and displayed on both the detection and the vulnerable item records in your ServiceNow AI Platform instance.

Third-party Integrations retrieve vulnerable item detection data. Detections are distinct occurrences of vulnerabilities as reported by the scanners. Detection data are paired with vulnerable items and VI state is updated based
on the state of the detections. If a VI is not found, a new one is created. Detections are only opened or closed by data found directly by a scanner.

In previous versions of Vulnerability Response, vulnerable item detections, the relationship between a CI (asset) in your environment and an imported vulnerability from a third-party scanner, created a unique vulnerable item in your ServiceNow AI Platform
instance.

The granularity of the original data provided by the scanner is preserved. With detections, the detection data is paired with vulnerable items. During an ingestion, if a vulnerable item is not found, a
new VI is created.

Starting from version 21.1.2 of Vulnerability Response, a system property sn_vul.show_last_open_detection is provided in the base system. By default, the value of this property is set to false, and the current behavior of aggregating
the values from the initial detection to the VI remains unchanged. However, if it is set to true, a VI is automatically updated with the last open detection after an ingestion. The fields such as IP address, SSL, Port, Protocol,
NetBIOS, and Proof are updated for the VI detections. If needed, you can customize the detection fields that should be updated by modifying the DetectionBase script.

To view the values for the last open detection, navigate to the Last Open Detection tab on the VI form view. To update all the VIs opened in the past year with the last open detection values, you can run
the scheduled job Update Last Open Detection Value To VITs on-demand. This scheduled job is also provided in the base system.  
Note:  
When a configuration item (CI) changes on a discovered item, the corresponding updates are also reflected in the detections. As a result, the detections may be moved from one VI to another VI. Based on this change and the value of the sn_vul.show_last_open_detection property, the values of the detections are rolled up to the source and target VIs.

## Supported versions of Vulnerability Response {#vr_host_detections__section_t5s_br1_wkb}

For more information about installing or updating the Vulnerability Response application,
see [Install Vulnerability Response](https://servicenow-prod.fluidtopics.net/sB5D1~3XOF2DyOX7hmc5dA "Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it.").

## Supported third-party integrations {#vr_host_detections__section_ok4_5k1_wkb}

A supported third-party integration with your Vulnerability Response application is required for vulnerable item detections. The following third-party integrations are supported by the Vulnerability Response application for vulnerable item detections:

* Qualys Host Detection Integration
* Rapid7 Data Warehouse:
  * Vulnerable Item Integration
  * Vulnerable Item Resolution Integration
  {#vr_host_detections__ul_fjw_1cc_wkb}
* Rapid7  Vulnerable Item Resolution Integration (InsightVM)
  * Insight VM integration
  * Vulnerable Item Integration - API
  {#vr_host_detections__ul_wzt_pcc_wkb}
* Tenable Vulnerability Integration
* Microsoft Defender Vulnerability Management
{#vr_host_detections__ul_vyf_4k1_wkb}

These third-party integrations are available with a separate subscription from the ServiceNow Store. For more information about these integrations, see [Vulnerability Response integrations](https://servicenow-prod.fluidtopics.net/5tRtjEBZLs~2Uym3WljEBw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") and [Security Operations and the ServiceNow Store](https://servicenow-prod.fluidtopics.net/jBa~11BcDnkn~s9DxBYDkw "Starting with Madrid, all Security Operations applications and supported integrations are available for download from the ServiceNow Store. This allows you to obtain new and updated features more rapidly. Before you can use any Security Operations applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them), download them from the ServiceNow Store, and activate them.") for more
information about obtaining entitlement.

To verify that your third-party scanner is configured for import, see [Install and configure the Rapid7 Integration for Security Operations application](https://servicenow-prod.fluidtopics.net/8QYrJRzRRzMx_oecEzk4tw "After you complete the set up steps for the integration so that it properly integrates with Vulnerability Response, get entitlements, download, and install the application on your ServiceNow AI Platform instance.")
and [Install the Qualys Vulnerability Integration](https://servicenow-prod.fluidtopics.net/u0YksIzyNUVcHWeSsF8kEQ "Before you run the Qualys Vulnerability Integration in your instance, you must install and configure the Qualys Vulnerability Integration application. This application is available as a separate subscription.").

## Key terms for vulnerable item detections {#vr_host_detections__section_yvj_jl1_wkb}

Vulnerability
:   Data about weaknesses in software, operating systems, and assets imported from
    internal and external sources. This data is imported and compared to existing assets
    (configuration items, CIs) listed in the CMDB.

Vulnerable item
:   A vulnerable item is created or updated when an imported vulnerability matches a CI
    in the CMDB.

Detection
:   A single, distinct occurrence of a vulnerability as reported by a scanner referred
    to as a Vulnerable Item Detection within the ServiceNow AI Platform environment. A
    detection includes enriched data about a vulnerability and any corresponding
    vulnerable items. This data is displayed on the Detection record (VID#) and the
    vulnerable item list view that includes the following details:

    * First found (data)
    * Last found (date)
    * DNS name
    * Net BIOSname
    * IP address
    * Port
    * Protocol
    * Proof
    * SSL
    * Times found

    {#vr_host_detections__ul_t3m_vl1_wkb}  
    Note:  
    Adding a business rule on the detection table will impact the performance of the ingestion.

Detection key
:   A hashed combination of fields that provided a way to identify and tie a detection to a vulnerable item. Detection keys are integration-specific. {#vr_host_detections__table_prn_3y4_5pb__entry__7}

    | Scanner | Vulnerability | Port | Protocol | Asset ID | Proof | NIC |
    |-|-|-|-|-|-|-|
    | Qualys | Yes | Yes | Yes | Yes | No | NA |
    | Tenable | Yes | Yes | Yes | Yes | No | NA |
    | Rapid7 | Yes | Yes | Yes | Yes | Yes (it is not case sensitive) | Yes |
    [Table 1. Detection key configurations]

    {#vr_host_detections__table_prn_3y4_5pb}  
    Note:  
    * If the detection key is not specified, or for versions earlier than Vulnerability Response 14.0, the detection key is a combination of vulnerability entry, port, protocol, asset ID, and proof.
    * Starting with v19.0 of Vulnerability Response, a new detection key NIC is added for Rapid7 InsightVM, that is activated by default. Existing detections without NIC are updated with the first incoming NIC in the payload from Rapid7. The detection key is recalculated and repopulated on the detection including NIC. New detections are created if similar detections are seen with different NIC values. This data is not rolled up to the Vulnerable Item table. The NIC value is stored in a new column on the sn_vul_detection_key_config and sn_vul_detection table.
    {#vr_host_detections__ul_if4_hjb_fyb}

De dup
:   The process used by the Vulnerability Response application of collapsing of
    individual detections into a single VI when the data meets certain hard-coded
    criteria.

VI External ID
:   The value stored in the External ID field of the VI table. This value is a hash
    comprised of the combination of keys within a VI that represents what makes it unique
    within the application. It is composed of a CI and a vulnerable entry.

## Reopen resolved vulnerable items {#vr_host_detections__section_b3m_bg5_vlb}

Vulnerable items set to Resolved in your ServiceNow AI Platform
instance but not transitioned to Closed/Fixed by the subsequent
integration runs are reopened if they are detected during rescans.

Closed VIs with a substate of fixed or
stale are reopened if a new detection is created and the VIs can be
matched with the new vulnerability.

As per the script include, DetectionBase, method
_shouldReOpenVI(), if the VIT was earlier
Closed with substate Fixed,
Stale, or CI Decommissioned, it is reopened,
and the detection is mapped to the existing VIT.

For example, say a VIT's closed date is later than the last_found date of a detection. You
would expect these VIT records to remain closed. However, if you see a previously closed VIT
reopened, it means that the VIT was closed by an earlier detection and the vulnerability was
found again in a later scan. When a new detection is found that matches the closed VIT that
has the same vulnerability on the VIT's configuration item, the VIT is reopened.

For Rapid7 detections, an option is now available on the Rapid7
configuration page in your instance to reopen resolved VIs by age. If enabled, VIs set to
Resolved but then not transitioned to
Closed/Fixed by subsequent scans transition back to
Open after the number of days you enter.

For Qualys detections, if the scanner continues to find VIs that were set to
Resolved but then not transitioned to
Closed/Fixed by subsequent scans, these VIs move back to
Open when the last found date is later than the Resolved date.

## View detection data {#vr_host_detections__section_y4f_zm1_wkb}

You view the data imported from vulnerable item detections on the VI record. For more
information, see [View Vulnerability Response vulnerable item detection data](https://servicenow-prod.fluidtopics.net/jQycMVuXZcxhXVtBbRPl8A "The complete data gathered by your third-party scanner integrations with Vulnerability Response are displayed on the Detections and Initial Detections tabs on the vulnerable item records (VIT). It is also displayed on Detection records on the Vulnerable Item Detection list in your ServiceNow AI Platform instance.") and [Verify Vulnerability Response vulnerable item detection data on integration run (VINTRUN) records](https://servicenow-prod.fluidtopics.net/qUa416izHlB4AmFZnaxQgw "From integration run records in your ServiceNow AI Platform instance, you can locate third-party integration vulnerable item detection data based on the date and time of scans. Verify the scan successfully completed, view the number (counts) of individual detections, as well as any vulnerable items (VIs) that are created or updated directly as a result of the scans.").

