All integrations

Group-IB ASM Integration with DefectDojo

Group-IB ASM Integration with DefectDojo

Group-IB ASM is the Attack Surface Management product from Group-IB, a cybersecurity company known for threat intelligence and incident response. It discovers an organization's internet-facing assets, such as domains, IP addresses, URLs, certificates, and exposed services, and raises issues when it finds weaknesses or risky exposures on them. Issues carry a category, a type, a severity label, a lifecycle status, and in many cases MITRE ATT&CK technique references. They are available through the Group-IB ASM REST API as JSON.

Group-IB ASM Integration with DefectDojo

We use Group-IB ASM to find the things nobody told us about: the forgotten staging host, the expired certificate on a marketing domain, the admin login that should never have been public. Discovering them is half the work. Bringing Group-IB ASM issues into DefectDojo gives each one an Asset, an owner, and an SLA, and keeps the triage decisions our analysts already made in Group-IB. Solved issues arrive mitigated, false positives arrive flagged, and only the open ones land in someone's queue.

Why Group-IB ASM Matters

External exposure changes faster than any asset inventory. Teams spin up cloud hosts, register domains, and connect vendors without a security review.

  • It looks at the organization from the outside, the same way an attacker would, and finds assets internal inventories miss.
  • Issues map to MITRE ATT&CK techniques, which helps explain why an exposure matters to someone outside security.
  • Group-IB tracks a lifecycle per issue (Detected, Under review, Solved, Ignored, False positive), so triage done there carries meaning.
  • Without a central platform, ASM issues sit in their own portal, disconnected from the application and infrastructure findings for the same systems.

Advantages of This Integration

What we get from routing Group-IB ASM issues through DefectDojo:

  • Triage decisions survive the import. A Solved issue is imported inactive and mitigated, a False positive is flagged as one, and an Ignored issue is marked out of scope. Detected and Under review issues stay active.
  • One scan type for file and API. The parser and the DefectDojo Pro connector both report Group-IB ASM - Connectors Import, so findings from an uploaded export and a later connector sync deduplicate against each other.
  • Endpoints when they are real. When the affected asset is a host, IP address, or URL, it becomes an Endpoint on the finding. Software names and certificate descriptors go to the component field instead, so imports do not fail on values that are not hosts.
  • ATT&CK tags for filtering. Each technique becomes a mitre-attack:<technique> tag, so you can filter or report on exposures by technique.
  • SLAs and ticketing. External exposures get the same severity-based SLAs, assignment, and Jira pushes as every other finding on the Asset.

How This Integration Works

All three methods use the scan type Group-IB ASM - Connectors Import.

Option 1: Import an issue export. The parser expects the ASM issues response: a JSON object with an items list (data, results, issues, or a bare array also work). Save the issues response from the Group-IB ASM API (the REST API manual is available in the product under Help, then API) and import the file. In the UI, open the Engagement, choose Import Scan Results, select Group-IB ASM - Connectors Import, and upload it. With the API, in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Group-IB ASM - Connectors Import" 
  -F "file=@groupib-issues.json" 
  -F "product_name=external-perimeter" 
  -F "engagement_name=ASM" 
  -F "auto_create_context=true"

Option 2: Universal Importer (DefectDojo Pro).

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Group-IB ASM - Connectors Import" 
  --report-path "./groupib-issues.json" 
  --product-name "external-perimeter" 
  --engagement-name "ASM" 
  --auto-create-context

Option 3: The Group-IB ASM connector (DefectDojo Pro). The connector authenticates with HTTP Basic Auth, using your ASM login as the username and an API key as the password. Both are required. To configure it:

  1. Generate an API key in Group-IB ASM under Help, then API, then Generate API Key. A dedicated service account keeps automated activity separate from analysts.
  2. Enter https://asm.group-ib.com in Location, your ASM login in Username, and the key in API Key.
  3. Optionally set a Minimum Severity.

DefectDojo discovers each Group-IB company or tenant as a Record, keyed by company ID. The first sync backfills recent history, and later syncs pull only issues changed since the last run, based on each issue's lastSeen timestamp. If company discovery is restricted for your tenant, a company_id tool-specific field scopes the connector to one company.

Data Granularity: What Gets Imported

DefectDojo Field Source in Group-IB Issue Notes
Title body.type Falls back to reason, then category, then issue ID
Severity body.status (severity label) Matched by containment: critical, high, medium, low, info; anything else is Info
Description Category, type, asset, asset status, asset discovered, reason, details, context One labeled line per populated field
Status Issue status (lifecycle) Solved: mitigated. False positive: false positive. Ignored: out of scope. Others: active
Endpoint body.asset Only when it is a host, IP, or URL
Component Name body.asset When the asset is not host-shaped, such as a software name
Tags body.alertMitreInfo mitre-attack:<technique>, sorted
Date firstSeen First-seen date
Unique ID / Vuln ID from Tool Issue id / body.type
Finding type Dynamic ASM findings come from external scanning
Deduplication Unique ID or hashcode Title and severity

Two different fields are called status in a Group-IB issue. The issue's own status is its lifecycle, and body.status is the severity label. The parser reads each for its proper purpose.

Use Cases

For perimeter ownership: A security team imports Group-IB ASM issues into an "external perimeter" Asset, then reassigns findings for specific domains to the application teams that own them. Each team works its exposures under the SLA for that severity.

After an acquisition: A newly acquired company's domains show up in Group-IB ASM before anyone has documented them. Importing those issues into a dedicated Organization gives the integration team a measurable backlog to close.

When API access is still pending: A team that cannot yet approve outbound credentials imports a saved issues export. When the connector is approved, its findings deduplicate against the uploaded ones because the scan type matches.

For threat-informed reporting: Because ATT&CK techniques become tags, a security lead can report on how many open external exposures map to initial-access techniques without building a separate spreadsheet.

Operational Tips

  • Triage in Group-IB first if that is where your analysts work. Solved, Ignored, and False positive states carry over, so DefectDojo only surfaces what is still open.
  • Severity is read from a phrase such as "Critical severity". If you see many Info findings, check whether a label in your data does not contain one of the expected words.
  • Deduplication hashes only title and severity, because ASM issues have no file or package. Because a different domain can share the same title and severity, keep separate perimeters in separate Assets (or use separate Engagements with deduplication_on_engagement) so one domain's issue is not marked a duplicate of another's.
  • Filter by component name to find issues about software or certificates rather than hosts, since those values are stored there instead of as Endpoints.
  • Use minimum_severity on import, or Minimum Severity on the connector, to keep informational discoveries out of team queues.
  • Reimport exports into the same Test to keep a clean open-to-mitigated history.