Skip to content

Vectasec · Reference

Connector reference

All 39 Vectasec read-only connectors with their configuration fields, which fields are stored as secrets, and rule counts per pack.

On this page

How connectors are configured#

Each connector declares its own fields. In the table below, R marks a required field and S marks a secret. The console form, the CLI and POST /connections all reject a connection that is missing a required field. Keys a connector reads but does not declare, such as timeout, pass through unchecked.

Secret fields are split out of the saved config and stored as one Supabase Vault secret per connection. They are merged back in memory only at scan or test time, and are never echoed back to the console. A collector-mode connection is scanned with the config in the collector's own targets file, where credentials are ${ENV_VAR} references resolved from the collector's environment, so they stay in your network.

GET /connectors returns the live catalog: every type, its field declarations and a rule count. Each connector registers itself when the engine starts, so a new connector appears in that response and in vectasec rules without a central list to edit.

The CLI has named flags for common fields: --bootstrap, --url, --host, --port, --token, --admin-token, --username and --password. Pass every other field with --set key=value, which you can repeat. Values arrive as strings. Without --tenant, the CLI writes to the built-in demo tenant. Run these from the engine directory of the release:

bash
uv run vectasec connections add --type vault --name prod-vault \
  --set base_url=https://vault.example.com:8200 --token "$VAULT_TOKEN" \
  --tenant YOUR_TENANT_UUID
uv run vectasec connections test prod-vault --tenant YOUR_TENANT_UUID

Connector catalog#

The Rules column counts the rule ids under each connector's prefix, for example every KAFKA. rule for kafka. All 39 connectors are read-only.

TypeSystemFieldsRules
kafkaApache Kafkabootstrap (R)25
confluentConfluent Cloudapi_key (R), api_secret (R, S)6
redpandaRedpanda Admin APIurl (R), username, password (S), verify4
kafka_connectKafka Connect RESTurl (R), username, password (S), verify5
schema_registrySchema Registryurl (R), username, password (S), verify3
rabbitmqRabbitMQ management APIurl (R), username (R), password (R, S)18
activemqActiveMQ Classic and Artemis, via Jolokiajolokia_url (R), username (R), password (R, S), flavor (R): classic or artemis10 (6 ACTIVEMQ, 4 ARTEMIS)
pulsarApache Pulsar Admin APIadmin_url (R), token (S), tls, broker_config, proxy_config10
natsNATS and JetStream monitoringmonitoring_url (R), username, password (S), config_json9
solaceSolace PubSub+ SEMP v2semp_url (R), username (R), password (R, S)10
ibmmqIBM MQ administrative RESTbase_url (R), username (R), password (R, S), qmgr (R), tls11
mqttMosquitto, EMQX, HiveMQsystem (R), config_path, config_text, base_url, api_key, api_secret (S), token (S)13
redisRedishost (R), port, password (S), tls6
memcachedMemcachedhost (R), port4
kongKong Admin APIurl (R), admin_token (S)17
openapiOpenAPI and Swagger descriptionsspec_url, spec8
graphqlGraphQL endpointsurl (R), auth_header_name, auth_header_value (S)9
grpcgRPC server reflectiontarget (R), tls, token (S)6
mcpMCP servers over Streamable HTTPurl (R), token (S)24
k8sKubernetes with Istio, Linkerd, Gateway API, Ingress and RBACkubeconfig, context, api_server, token (S), ca_cert, in_cluster23
awsAWS SQS, SNS, EventBridge, MSK, API Gatewayregions (R), role_arn, external_id, profile, access_key_id, secret_access_key (S), session_token (S)21
azureAzure Service Bus, Event Hubs, API Management, Logic Appstenant_id (R), client_id (R), client_secret (R, S), subscription_id (R)16
gcpGoogle Cloud Pub/Sub and Apigeeservice_account_key (S), access_token (S), project_id, apigee_org12
coordetcd, ZooKeeper, Consul, Nacossystem (R), host (R), port, peer_port, username, password (S), token (S), tls15
vaultHashiCorp Vaultbase_url (R), token (R, S), namespace, verify_tls11
keycloakKeycloakbase_url (R), realm (R), token (S), client_id, client_secret (S), token_realm, verify_tls12
elasticsearchElasticsearch and OpenSearchbase_url (R), username, password (S), api_key (S), verify_tls11
solrApache Solrbase_url (R), username, password (S), verify_tls6
vectordbChroma, Weaviate, Qdrant, Milvus, pgvectorengine (R), base_url, host, port, tls, api_key (S), dsn (S)12
pgbouncerPgBouncer admin consolehost (R), port, admin_user (R), admin_password (S), sslmode6
flinkApache Flink RESTurl (R), username, password (S), verify4
airflowApache Airflow 2.x RESTbase_url (R), username, password (S), token (S)8
mulesoftMuleSoft Anypointorg_id (R), environments, host, client_id, client_secret (S), access_token (S)8
boomiBoomi AtomSphereaccount_id (R), username (R), token (S), host6
workatoWorkatoapi_token (R, S), data_center, host6
n8nn8n public APIbase_url (R), api_key (S)10
mftMOVEit, GoAnywhere, Cleo, Sterling, Axwaybase_urls (R), product, admin_token (S), verify_tls16
iacdocker-compose, Kubernetes manifests, Kafka Connect JSONsource_path, source_text, source_name8 (SUPPLY.IAC)
discoveryNetwork fingerprinting of middlewaretargets (R), ports, allow_public, timeout9

Connector notes#

  • ActiveMQ. GET /connectors counts 6 rules for activemq, because the 4 ARTEMIS rules are not attributed to it there.
  • IaC. vectasec rules groups rules by the first segment of the rule id, so the 8 SUPPLY.IAC rules appear under SUPPLY together with the 3 SUPPLY.LIFECYCLE rules.
  • MCP. The connector reads discovery, tools/list and unauthenticated OAuth discovery documents, and never issues tools/call. Extra probes, such as an invalid protocol version or a forged Origin, run only when active_probes is set. Any non-empty value turns them on, including the string false, so leave the key out to keep them off. source_zone records where the scan ran from and is quoted in finding evidence.
  • Azure and GCP. Their test suites run against fixture API responses rather than a live tenant, so treat both connectors as preview. The supported agentless path today is AWS, through a cross-account read-only role. See Scan AWS with a read-only role.

TLS verification#

Where a connector has a TLS verification switch, verification is on by default. Keep it on in production. The key name varies by connector:

KeyDeclared fieldRead but not declared
verifyredpanda, kafka_connect, schema_registry, flinkkong, mqtt, n8n, boomi, mulesoft, workato
verify_tlselasticsearch, keycloak, mft, solr, vaultactivemq, ibmmq, nats, pulsar, rabbitmq, solace
insecure_skip_tls_verifynonecoord, and k8s when you connect with api_server

Declared fields and insecure_skip_tls_verify accept true or false as text. The undeclared verify and verify_tls keys expect a JSON boolean, so set them in the POST /connections body or a collector targets file rather than with --set. For a cluster with a private CA, give k8s the CA in ca_cert instead of turning verification off.

Cross-cutting rule packs#

Thirty rules are not tied to one connector. They match resource kinds that several connectors emit, such as grants, identities, credentials, data-carrying topics and queues, runtime clients, TLS endpoints and versioned components.

PrefixRulesWhat it checks
NHI4Wildcard grants; default, shared or anonymous identities; weak or unverifiable credential storage
CREDENTIAL7Unrotated, dormant, non-expiring, shared and default credentials; identities with grants but no owner or activity signal
DATA2Resources named like sensitive data, and that data on an unencrypted or unauthenticated broker
ATTACKPATH3Exposure, over-privileged identity and sensitive data chained together
RUNTIME5Observed client connections: cleartext credentials, plaintext transport, default accounts in use, unattributed clients and unexpected peers
TLS5Expired or untrusted certificates, protocols below TLS 1.2, missing TLS, transit settings that allow plaintext alongside TLS
SUPPLY.LIFECYCLE3End-of-life and approaching end-of-life versions, and components whose support status can't be determined
CVE1Known vulnerabilities in detected versions

With the 418 connector rules, that makes 448. GET /connectors does not attribute these packs to any connector. To see the rulepack your engine has loaded, run uv run vectasec rules, which lists every rule grouped by the first segment of its id.

Discovery guardrails#

The discovery connector fingerprints middleware on network ranges you name. Each probe sends what a normal client sends before authenticating, reads one response and disconnects. Scope is resolved before any probe runs.

  • Declared targets only. Give hosts, host:port pairs or CIDRs, separated by commas or newlines. An empty list probes nothing.
  • Private by default. IP addresses and CIDRs outside private, loopback and link-local space are refused unless allow_public is 1, true or yes. Hostnames are not resolved while scope is checked, so list only hostnames you are authorized to scan.
  • Bounded. One scan expands to at most 1024 hosts. A CIDR larger than the cap is refused on its own. If your targets together exceed the cap, the whole sweep is refused and nothing is probed.
  • Do-not-contact ports. 9100-9107 (raw print), 1414-1416 (IBM MQ), 515 (LPD) and 631 (IPP) are never contacted, even when named.
  • No credentials. No credential is sent, guessed or defaulted. The Kafka and MQTT probes identify themselves with the client id vectasec-discovery.
  • Default ports. Targets without a port get the list you set in ports, or by default these 20 middleware ports: 1883, 2181, 2379, 4222, 5432, 5672, 6379, 6650, 8001, 8080, 8161, 8200, 8500, 8883, 9000, 9092, 9200, 11211, 15672 and 61616. Ports 5432, 6650 and 61616 have no protocol probe of their own, so a default sweep does not identify services on them.
  • Non-standard ports. A port you name on a target, such as 10.0.4.7:6380, is tried with a set of generic probes when no specific probe covers it. Ports from ports get only their specific probe, or an API-descriptor check on common HTTP ports, so an unmapped port listed there is not probed.

Every refused target is recorded with its reason. DISCOVERY.SCOPE.TARGETS_REFUSED raises refusals as a finding, and DISCOVERY.SCOPE.NOTHING_PROBED flags a sweep that had nothing in scope. After each discovery scan, the engine compares the services it found with your configured connections by host and port. It files COVERAGE.SERVICE.UNMONITORED for any service no connection covers. When a connection's config names no endpoint it can match, the finding is filed as not assessable rather than as an unmonitored system.