Skip to content

Commit 1fcab14

Browse files
Maffoochclaude
andauthored
docs(connectors): add Group-IB ASM connector setup guide (#15208)
Document the Group-IB Attack Surface Management connector in the Pro connectors tool reference and add it to the supported-tools list. Covers Basic Auth (username = ASM login, password = API key), the fixed https://asm.group-ib.com location, per-company Record discovery, assets mapped as endpoints, incremental sync, and the optional company_id scoping fallback. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent aa90681 commit 1fcab14

2 files changed

Lines changed: 35 additions & 0 deletions

File tree

docs/content/import_data/pro/connectors/about_connectors.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ We currently support Connectors for the following tools, with more on the way:
3333
* **BurpSuite**
3434
* **Checkmarx ONE**
3535
* **Dependency-Track**
36+
* **Group-IB ASM**
3637
* **IriusRisk**
3738
* **JFrog Xray**
3839
* **Probely**

docs/content/import_data/pro/connectors/connectors_tool_reference.md

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -250,6 +250,40 @@ To generate a Dependency\-Track API key:
250250

251251
For more information, see **[Dependency\-Track Documentation](https://docs.dependencytrack.org/integrations/rest-api/)**.
252252

253+
## **Group-IB ASM**
254+
255+
The Group-IB ASM (Attack Surface Management) connector uses the Group-IB ASM REST API to pull external attack-surface **issues** (findings) into DefectDojo. DefectDojo discovers each Group-IB **company/tenant** as a separate Record and imports that company's issues on a scheduled, incremental basis. The asset each issue relates to (a domain, IP, or URL) is attached to the resulting finding as an **Endpoint**.
256+
257+
#### Prerequisites
258+
259+
You will need your Group-IB ASM login and an API key. We recommend creating a dedicated service account for DefectDojo so that automated activity can be distinguished from manual team actions.
260+
261+
To generate an API key:
262+
263+
1. Open Group-IB Attack Surface Management, click **Help** in the lower-left corner, and select **API**.
264+
2. Click **Generate API Key** (top-right, under your username).
265+
3. Enter your SSO password and click **Next**, then click **Copy token**.
266+
4. Store the key in a secret manager and plan for regular rotation.
267+
268+
#### Connector Mappings
269+
270+
Group-IB ASM authenticates with HTTP Basic Auth, where the username is your ASM login and the password is your API key. **Both values are required** — the API key alone is not sufficient.
271+
272+
1. Enter `https://asm.group-ib.com` in the **Location** field. This is the same for all Group-IB ASM tenants.
273+
2. Enter your ASM login (usually an email address) in the **Username** field.
274+
3. Enter your API key in the **API Key** (Secret) field.
275+
4. Optionally, set a **Minimum Severity** to limit which findings are imported. Findings below the selected severity are not imported.
276+
277+
DefectDojo maps each Group-IB **company** as a separate Record, using the company ID as the identifier. On the first Sync, DefectDojo backfills recent issue history; subsequent Syncs are incremental, pulling only issues changed since the last Sync (tracked by each issue's most recent `lastSeen` timestamp).
278+
279+
#### Scoping to a single company (optional)
280+
281+
By default, the connector automatically discovers the companies available to your API credentials (via the ASM `clients` endpoint) and creates one Record per company. This is the recommended setup and requires no extra configuration.
282+
283+
If the `clients` endpoint is not available for your tenant — for example, when it is restricted to partner/MSP accounts — the connector can be scoped to one company by supplying its **company ID** as a `company_id` tool-specific field on the connector configuration. When `company_id` is set, DefectDojo uses that company directly instead of enumerating companies. Leave it unset to use automatic discovery.
284+
285+
See the Group-IB ASM REST API manual (available in-product via **Help → API**) for more information.
286+
253287
## **Have I Been Pwned**
254288

255289
The Have I Been Pwned (HIBP) connector uses the HIBP REST API to report which accounts on your organization's own domains have appeared in known data breaches. DefectDojo discovers each domain you have verified with HIBP and imports one finding per breach affecting that domain.

0 commit comments

Comments
 (0)