Skip to content

Commit 8c73932

Browse files
Maffoochclaude
andcommitted
docs(connectors): add Group-IB ASM connector setup guide
Document the Group-IB Attack Surface Management connector in the Pro connectors tool reference and add it to the supported-tools list. Covers Basic Auth (username = ASM login, password = API key), the fixed https://asm.group-ib.com location, per-company Record discovery, assets mapped as endpoints, incremental sync, and the optional company_id scoping fallback. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 5fc11c8 commit 8c73932

2 files changed

Lines changed: 35 additions & 0 deletions

File tree

docs/content/import_data/pro/connectors/about_connectors.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ We currently support Connectors for the following tools, with more on the way:
3232
* **BurpSuite**
3333
* **Checkmarx ONE**
3434
* **Dependency-Track**
35+
* **Group-IB ASM**
3536
* **IriusRisk**
3637
* **JFrog Xray**
3738
* **Probely**

docs/content/import_data/pro/connectors/connectors_tool_reference.md

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -148,6 +148,40 @@ To generate a Dependency\-Track API key:
148148

149149
For more information, see **[Dependency\-Track Documentation](https://docs.dependencytrack.org/integrations/rest-api/)**.
150150

151+
## **Group-IB ASM**
152+
153+
The Group-IB ASM (Attack Surface Management) connector uses the Group-IB ASM REST API to pull external attack-surface **issues** (findings) into DefectDojo. DefectDojo discovers each Group-IB **company/tenant** as a separate Record and imports that company's issues on a scheduled, incremental basis. The asset each issue relates to (a domain, IP, or URL) is attached to the resulting finding as an **Endpoint**.
154+
155+
#### Prerequisites
156+
157+
You will need your Group-IB ASM login and an API key. We recommend creating a dedicated service account for DefectDojo so that automated activity can be distinguished from manual team actions.
158+
159+
To generate an API key:
160+
161+
1. Open Group-IB Attack Surface Management, click **Help** in the lower-left corner, and select **API**.
162+
2. Click **Generate API Key** (top-right, under your username).
163+
3. Enter your SSO password and click **Next**, then click **Copy token**.
164+
4. Store the key in a secret manager and plan for regular rotation.
165+
166+
#### Connector Mappings
167+
168+
Group-IB ASM authenticates with HTTP Basic Auth, where the username is your ASM login and the password is your API key. **Both values are required** — the API key alone is not sufficient.
169+
170+
1. Enter `https://asm.group-ib.com` in the **Location** field. This is the same for all Group-IB ASM tenants.
171+
2. Enter your ASM login (usually an email address) in the **Username** field.
172+
3. Enter your API key in the **API Key** (Secret) field.
173+
4. Optionally, set a **Minimum Severity** to limit which findings are imported. Findings below the selected severity are not imported.
174+
175+
DefectDojo maps each Group-IB **company** as a separate Record, using the company ID as the identifier. On the first Sync, DefectDojo backfills recent issue history; subsequent Syncs are incremental, pulling only issues changed since the last Sync (tracked by each issue's most recent `lastSeen` timestamp).
176+
177+
#### Scoping to a single company (optional)
178+
179+
By default, the connector automatically discovers the companies available to your API credentials (via the ASM `clients` endpoint) and creates one Record per company. This is the recommended setup and requires no extra configuration.
180+
181+
If the `clients` endpoint is not available for your tenant — for example, when it is restricted to partner/MSP accounts — the connector can be scoped to one company by supplying its **company ID** as a `company_id` tool-specific field on the connector configuration. When `company_id` is set, DefectDojo uses that company directly instead of enumerating companies. Leave it unset to use automatic discovery.
182+
183+
See the Group-IB ASM REST API manual (available in-product via **Help → API**) for more information.
184+
151185
## **IriusRisk**
152186

153187
The IriusRisk connector uses an API token to pull threat modeling data from your IriusRisk instance.

0 commit comments

Comments
 (0)