Have I Been Pwned Integration with DefectDojo
Have I Been Pwned Integration with DefectDojo
Have I Been Pwned (HIBP) is a data breach notification service created and run by security researcher Troy Hunt. It collects data from publicly disclosed breaches and lets people and organizations check whether their email addresses appear in them. Its domain search feature, available through the HIBP REST API on paid subscriptions, reports every breached account on a domain the organization has verified it owns. DefectDojo Pro reads that data through an Upstream Connector and imports one finding per breach that affects your domains.
Have I Been Pwned Integration with DefectDojo
We connected Have I Been Pwned to DefectDojo because breach exposure was the one security signal we were checking by hand. Someone would search our domain every few months, paste results into a document, and email the help desk. The DefectDojo Pro connector now discovers each domain we have verified with HIBP and imports a finding for every breach that included our accounts, with the affected accounts listed. Credential exposure gets an owner and a severity like any other finding, and new breaches show up without anyone remembering to look.
Why Have I Been Pwned Matters
Breached credentials are a common route into an organization, and the breach usually happens somewhere you have no visibility into: a third-party service where an employee used a work email address.
- HIBP aggregates publicly disclosed breaches, so you can learn about exposure of your accounts without monitoring each breach yourself.
- Domain search covers every account on your domain, not just the addresses someone thinks to check.
- Knowing which accounts appeared in which breach lets you target password resets, MFA enrollment, and user follow-up instead of resetting everyone.
- Breach data that lives in an inbox or a spreadsheet is hard to track to completion. Findings with owners and SLAs are not.
Advantages of This Integration
What the Have I Been Pwned connector adds to DefectDojo Pro:
- One Record per verified domain. DefectDojo discovers each domain you have verified with HIBP, so separate brands or subsidiaries can map to separate Assets.
- One finding per breach. Each breach affecting accounts on a domain becomes a finding, which keeps the volume manageable and the context clear.
- Severity based on what leaked. Each finding's severity reflects the kind of data the breach exposed, so a breach that included passwords stands out from one that only exposed email addresses.
- Affected accounts listed. The finding description lists the affected accounts on your domain, so the team handling it knows exactly who to contact.
- New breaches arrive automatically. Each Sync runs a reimport against the existing Test, adding findings for newly reported breaches.
- Standard workflow. Breach findings can be assigned, tracked against SLAs, risk-accepted, or pushed to Jira or another Downstream Connector.
How This Integration Works
The connector is a DefectDojo Pro feature, configured under Connect > Upstream.
1. Get an API key with domain search. Domain search requires a Have I Been Pwned Core subscription tier or higher. Obtain your key from your Have I Been Pwned account.
2. Verify at least one domain. Under Domain search in your HIBP account, verify that you control each domain you want to monitor. HIBP supports verification by DNS TXT record, meta tag, file upload, or email. Until a domain is verified, the connector discovers no domains and imports no findings.
3. Configure the connector. Enter https://haveibeenpwned.com in the Location field and your API key in the Secret field. Optionally set a Minimum Severity; findings below the selected severity are not imported.
4. Discover and Sync. Discover creates a separate Record for each verified domain. Map each Record to an Asset, or enable Auto-Map to create one per domain. Sync imports one finding per breach affecting accounts on that domain into a Test inside the Global Connectors Engagement on the mapped Asset, and repeats on a schedule.
Data Granularity: What Gets Imported
| DefectDojo Object | Source in Have I Been Pwned | Notes |
|---|---|---|
| Record | Verified domain | One Record per domain verified on your HIBP account |
| Asset | Mapped from the Record | Manual mapping or Auto-Map |
| Finding | Breach affecting the domain | One finding per breach |
| Severity | Kinds of data the breach exposed | Set by the connector from the exposed data types |
| Description | Affected accounts | Lists the accounts on your domain that appeared in the breach |
| Engagement / Test | Global Connectors | One Test per connector on the Asset |
| Severity filter | Minimum Severity setting | Findings below it are not imported |
The connector documentation does not publish a field-by-field mapping beyond this. If you want a value in a different field, Connector Field Mappings can rearrange or normalize what the connector sends for its scan type.
Use Cases
Targeted credential resets: A new breach appears as a finding on the corporate domain's Asset, listing the affected accounts. The identity team resets those passwords, confirms MFA is enforced for them, and closes the finding with a note, all without touching unaffected users.
Multiple brands: An organization with several verified domains maps each Record to the Asset for that brand or subsidiary. Each team handles its own exposure, and security leads can still report on breach findings across all of them.
Routing to the help desk: Findings above a chosen severity are pushed to Jira or another Downstream Connector, such as a service desk, so user follow-up happens in the queue that already handles account issues.
Evidence for audits: Each breach finding records when it was imported and what was done about it, which shows that credential exposure was reviewed and acted on.
Operational Tips
- Verify every domain you care about before relying on the connector. Unverified domains are not discovered, and a connector with no verified domains imports nothing.
- Confirm your subscription includes domain search. Without a Core tier or higher, the API key cannot return domain data.
- Use Minimum Severity to keep breaches that exposed only low-sensitivity data out of DefectDojo if your team only acts on password or sensitive-data exposure.
- The description lists account names from your domain. Limit who can view the mapped Asset accordingly, since the finding itself identifies people.
- Old breaches will appear on the first sync. Decide up front whether to triage them as current work or risk-accept historical ones with a note.
- Turn on the Connector Health Warning notification so an expired subscription or revoked key reaches you as a message.