You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Document the Group-IB Attack Surface Management connector in the
Pro connectors tool reference and add it to the supported-tools list.
Covers Basic Auth (username = ASM login, password = API key), the fixed
https://asm.group-ib.com location, per-company Record discovery, assets
mapped as endpoints, incremental sync, and the optional company_id
scoping fallback.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: docs/content/import_data/pro/connectors/connectors_tool_reference.md
+34Lines changed: 34 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -250,6 +250,40 @@ To generate a Dependency\-Track API key:
250
250
251
251
For more information, see **[Dependency\-Track Documentation](https://docs.dependencytrack.org/integrations/rest-api/)**.
252
252
253
+
## **Group-IB ASM**
254
+
255
+
The Group-IB ASM (Attack Surface Management) connector uses the Group-IB ASM REST API to pull external attack-surface **issues** (findings) into DefectDojo. DefectDojo discovers each Group-IB **company/tenant** as a separate Record and imports that company's issues on a scheduled, incremental basis. The asset each issue relates to (a domain, IP, or URL) is attached to the resulting finding as an **Endpoint**.
256
+
257
+
#### Prerequisites
258
+
259
+
You will need your Group-IB ASM login and an API key. We recommend creating a dedicated service account for DefectDojo so that automated activity can be distinguished from manual team actions.
260
+
261
+
To generate an API key:
262
+
263
+
1. Open Group-IB Attack Surface Management, click **Help** in the lower-left corner, and select **API**.
264
+
2. Click **Generate API Key** (top-right, under your username).
265
+
3. Enter your SSO password and click **Next**, then click **Copy token**.
266
+
4. Store the key in a secret manager and plan for regular rotation.
267
+
268
+
#### Connector Mappings
269
+
270
+
Group-IB ASM authenticates with HTTP Basic Auth, where the username is your ASM login and the password is your API key. **Both values are required** — the API key alone is not sufficient.
271
+
272
+
1. Enter `https://asm.group-ib.com` in the **Location** field. This is the same for all Group-IB ASM tenants.
273
+
2. Enter your ASM login (usually an email address) in the **Username** field.
274
+
3. Enter your API key in the **API Key** (Secret) field.
275
+
4. Optionally, set a **Minimum Severity** to limit which findings are imported. Findings below the selected severity are not imported.
276
+
277
+
DefectDojo maps each Group-IB **company** as a separate Record, using the company ID as the identifier. On the first Sync, DefectDojo backfills recent issue history; subsequent Syncs are incremental, pulling only issues changed since the last Sync (tracked by each issue's most recent `lastSeen` timestamp).
278
+
279
+
#### Scoping to a single company (optional)
280
+
281
+
By default, the connector automatically discovers the companies available to your API credentials (via the ASM `clients` endpoint) and creates one Record per company. This is the recommended setup and requires no extra configuration.
282
+
283
+
If the `clients` endpoint is not available for your tenant — for example, when it is restricted to partner/MSP accounts — the connector can be scoped to one company by supplying its **company ID** as a `company_id` tool-specific field on the connector configuration. When `company_id` is set, DefectDojo uses that company directly instead of enumerating companies. Leave it unset to use automatic discovery.
284
+
285
+
See the Group-IB ASM REST API manual (available in-product via **Help → API**) for more information.
286
+
253
287
## **Have I Been Pwned**
254
288
255
289
The Have I Been Pwned (HIBP) connector uses the HIBP REST API to report which accounts on your organization's own domains have appeared in known data breaches. DefectDojo discovers each domain you have verified with HIBP and imports one finding per breach affecting that domain.
0 commit comments