All integrations

CyCognito Integration with DefectDojo

CyCognito Integration with DefectDojo

CyCognito is a commercial external attack surface management (EASM) platform. It discovers an organization's internet-facing assets, including IP addresses, domains, certificates, web applications, and IP ranges, attributes them to organizations and business units, and tests them for exposures such as vulnerable software and weak cryptography. Each problem is reported as an issue with a severity, the affected asset, evidence, remediation steps, and context about how attractive the asset is to an attacker. Issues are available as JSON from the CyCognito API.

CyCognito Integration with DefectDojo

We rely on CyCognito to tell us about internet-facing assets we didn't know we had, and we send its issues into DefectDojo because that is where our remediation process runs. In DefectDojo, each CyCognito issue becomes a Finding with the affected host as its endpoint, the CVEs attached, CyCognito's remediation steps in Mitigation, and its business context in the description. External exposures then sit on the same SLA clock and in the same reports as the findings from our internal scanners and application tests.

Why CyCognito Matters

Attackers start from the outside, and the external footprint is rarely what the asset inventory says it is.

  • It discovers assets rather than relying on a list you provide, which surfaces forgotten subdomains, acquired properties, and shadow IT.
  • It attributes assets to organizations and business units, which is the first step to finding an owner.
  • Issues include attacker-oriented context such as attractiveness, exploitation complexity, and potential threat, which helps prioritization.
  • It covers multiple asset types (hosts, domains, certificates, web apps) in one view.
  • Discovery is only half of the job. Someone still has to own each issue and prove it was fixed, which is a workflow problem, not a discovery one.

Advantages of This Integration

What running CyCognito through DefectDojo adds:

  • Endpoints you can filter on. The affected asset is added as an endpoint host (with CyCognito's ip/, domain/, webapp/, or cert/ prefix removed), so external findings can be searched by host alongside DAST and network results.
  • Deduplication across imports. File-imported findings are hashed on title and severity. Because the endpoint is not part of that hash, DefectDojo's default endpoint comparison (host and path) also applies, so the same issue on different hosts stays separate.
  • Remediation guidance in place. CyCognito's remediation method, effort, and steps are written to Mitigation, and its potential impact to Impact.
  • CVE tracking. CVE IDs from the issue are attached as vulnerability IDs, so external exposures can be matched against CVE-driven reporting.
  • Automatic asset coverage with the connector. DefectDojo Pro's connector creates Records for newly discovered assets with no per-asset configuration, which suits a source whose purpose is finding the unknown.
  • One SLA and reporting model. External issues follow the same SLA rules, assignment, risk acceptance, and Jira workflow as everything else.

How This Integration Works

There are two supported ways to get CyCognito issues into DefectDojo.

Option 1: JSON file import (Community Edition and DefectDojo Pro). Retrieve issues as JSON from the CyCognito API's /v1/issues endpoint, authenticating with a CyCognito API key, and save the response array to a file. Then import it with the Cycognito Scan scan type. In the UI, open the Engagement, choose Import Scan Results, select Cycognito Scan, and upload the file. To automate it:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Cycognito Scan" 
  -F "file=@cycognito-issues.json" 
  -F "product_name=external-attack-surface" 
  -F "engagement_name=CyCognito" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Cycognito Scan" 
  --report-path "./cycognito-issues.json" 
  --product-name "external-attack-surface" 
  --engagement-name "CyCognito" 
  --auto-create-context

Option 2: CyCognito connector (DefectDojo Pro). The connector imports EASM findings from the CyCognito platform on a schedule. Create an API key under Settings > API in CyCognito, then configure the connector with:

  1. https://api.platform.cycognito.com in the Location field.
  2. Your CyCognito API key in the API Key field.
  3. Optionally, Asset Grouping set to organization to create one Record per CyCognito organization instead of one per asset. Assets that belong to no organization are collected into a Record named Unattributed Assets.
  4. Optionally, a Minimum Severity to limit what is imported.

By default the connector creates a Record for each discovered asset across every asset type CyCognito tracks. There is deliberately no per-asset configuration, so new assets appear as Records without anyone editing settings. You then map Records to DefectDojo Assets.

Data Granularity: What Gets Imported

This table describes the Cycognito Scan file parser.

DefectDojo Field Source in CyCognito Issue Notes
Title title CyCognito's issue title
Severity base_severity Capitalized (for example medium becomes Medium)
Date first_detected Date the issue was first seen
Description Issue context fields Includes confidence, affected asset, package, summary, issue ID, attractiveness, port, platforms, issue type, organizations, business units, evidence, and more
Mitigation remediation_method, remediation_effort, remediation_steps Combined into one section
Impact potential_impact Listed when present
References references One per line
Vulnerability IDs cve_ids All CVEs on the issue
Endpoint affected_asset Host with type prefix removed
Finding type Dynamic Issues are marked dynamic
Deduplication Hashcode title, severity (endpoint host and path compared by default)

Use Cases

Taking ownership of the external footprint: A security team enables the connector with organization grouping. Each CyCognito organization becomes a Record mapped to a DefectDojo Asset owned by that business unit, and the Unattributed Assets Record becomes a weekly triage queue for assets nobody has claimed.

After an acquisition: CyCognito discovers the acquired company's internet-facing assets. Importing those issues into a dedicated Asset gives the integration team a tracked backlog with SLAs instead of a list in a slide deck.

Combining inside-out and outside-in views: External issues on a host appear next to internal scanner findings for the same endpoint, so a team can see whether an exposed service also has unpatched vulnerabilities found from inside.

Restricted environments: Where a connector cannot be approved yet, a scheduled job exports issues from the CyCognito API and imports the JSON, so external exposures are still tracked in DefectDojo.

Operational Tips

  • Choose Asset Grouping on the connector deliberately. Per-asset Records give fine-grained mapping; organization grouping is easier to assign to owners when CyCognito attribution is accurate.
  • Review the Unattributed Assets Record regularly. It is where unknown exposures accumulate.
  • File imports use base_severity, not CyCognito's enhanced severity, so severities in DefectDojo can differ from the enhanced severity CyCognito also reports.
  • Use minimum_severity on file import, or the connector's Minimum Severity, to start with Critical and High issues.
  • Reimport file exports into the same Test so resolved issues are mitigated and new ones added.
  • Tag imports with the business unit or organization (for example tags=emea,retail) to report external exposure by owner.