All integrations

Intigriti Integration with DefectDojo

Intigriti Integration with DefectDojo

Intigriti is a European crowdsourced security platform that runs bug bounty programs, vulnerability disclosure programs, and researcher-led testing for organizations. External security researchers test in-scope assets and file submissions, which Intigriti's team and the customer triage through statuses such as triage, accepted, and closed with a close reason. Each submission carries a severity (with Exceptional as the top tier), a CVSS vector, a vulnerability type with CWE, the affected asset, a proof of concept, impact, and a recommended solution. Submissions are available through the Intigriti external company API as JSON.

Intigriti Integration with DefectDojo

Our Intigriti program produces some of the highest-signal findings we get, because a person has already shown each one works. The program portal is good at managing researchers and payouts. It isn't where our engineers track fixes. Bringing Intigriti submissions into DefectDojo puts each accepted report on the Asset that owns the affected system, next to scanner and pentest findings, with an owner and an SLA. Rejected and duplicate submissions arrive already closed, so the engineering queue only holds real work.

Why Intigriti Matters

Scanners find known patterns. Researchers find the issues that need a person: broken access control, business logic flaws, and chained weaknesses.

  • A continuous program tests production systems between scheduled pentests.
  • Submissions are triaged before they reach the customer, which filters out much of the noise from unsolicited reports.
  • Each report includes a proof of concept and impact statement, which shortens the path from report to fix.
  • Close reasons record why a submission was rejected (not reproducible, out of scope, duplicate), which is useful context that should not be lost.
  • Without a central platform, bug bounty findings sit in a separate portal, so overall risk reporting for an application leaves them out.

Advantages of This Integration

What DefectDojo adds to Intigriti submissions:

  • Status and close reason become DefectDojo state. Accepted submissions are active and verified, open ones are active, and closed ones become mitigated, risk accepted, duplicate, out of scope, or false positive according to the close reason.
  • The top tier stays on top. Intigriti's Exceptional severity maps to Critical, alongside Critical itself.
  • One scan type for file and API. The parser and the DefectDojo Pro connector both report Intigriti - Connectors Import, so uploaded exports and connector syncs deduplicate against each other.
  • Exact matching. Submission codes are unique across the platform, and deduplication hashes unique_id_from_tool (the submission code) alone.
  • Safe rendering. Researcher-written prose is flattened to escaped plain text, with script and style content dropped, so nothing in a submission renders as markup in DefectDojo.
  • Engineering workflow. Findings can be assigned, pushed to Jira with the proof of concept attached, and measured against SLAs.

How This Integration Works

All methods use the scan type Intigriti - Connectors Import.

Option 1: Import a JSON export. The parser accepts the API's records envelope (also submissions, data, items, or a bare array). Intigriti's API lists submissions and serves each full report separately, so include the detail: either nested under detail on each entry, or as entries taken from the detail endpoint that carry the report directly. Without the detail, findings lose the CWE, impact, recommended solution, and most of the description.

In the UI, open the Engagement, choose Import Scan Results, select Intigriti - Connectors Import, and upload the file. To automate it in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Intigriti - Connectors Import" 
  -F "file=@intigriti-submissions.json" 
  -F "product_name=customer-portal" 
  -F "engagement_name=Bug Bounty" 
  -F "auto_create_context=true"

Option 2: Universal Importer (DefectDojo Pro).

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Intigriti - Connectors Import" 
  --report-path "./intigriti-submissions.json" 
  --product-name "customer-portal" 
  --engagement-name "Bug Bounty" 
  --auto-create-context

Option 3: The Intigriti connector (DefectDojo Pro). The connector syncs the whole company account. Generate a company API token in the Intigriti company portal under Company Settings, then API, with read access to programs and submissions. In the connector form:

  1. Enter https://api.intigriti.com/external/company in Location. It must be HTTPS.
  2. Enter the token in Secret. A dedicated token for DefectDojo is recommended.
  3. Optionally set a Minimum Severity.

DefectDojo discovers every program the token can access, creates a Record for each, and imports that program's submissions as findings keyed by submission code.

Data Granularity: What Gets Imported

DefectDojo Field Source in Intigriti Submission Notes
Title title Overview first, detail as fallback
Severity severity.value Exceptional and Critical to Critical; High, Medium, Low direct; others Info
Description Report type, asset, proof of concept, question answers, submission code Researcher text flattened to plain text
Impact report.impact Flattened
Mitigation report.recommendedSolution Flattened
CVSS v3 Vector severity.vector
CWE report.type.cwe Read from cwe-<n>
URL / References webLinks.details Link to the submission in the Intigriti portal
Status flags state.status and state.closeReason Active, verified, mitigated, risk accepted, duplicate, out of scope, or false positive
Unique ID / Vuln ID from Tool Submission code
Finding type Dynamic Researchers test running targets
Deduplication Hashcode unique_id_from_tool only

For closed or archived submissions, close reasons such as not applicable, not reproducible, spam, informative, won't fix, and Intigriti's terse "no" import as false positives. Solved, resolved, fixed, or a blank reason import as mitigated.

Use Cases

Routing accepted reports to engineering: A product security team syncs Intigriti with the connector and maps each program's Record to the Asset that owns its scope. Accepted submissions land with proof of concept and suggested fix, and are pushed to Jira for the owning team.

Measuring time to fix: Bug bounty findings carry discovery dates and SLA status in DefectDojo, so a security lead can report how long Critical researcher findings stay open next to scanner findings.

Closing the loop on retests: When Intigriti marks a submission closed as resolved, the next sync mitigates the finding. Accepted risks come across as risk accepted rather than reappearing as open work.

Programs that start on file import: An organization that hasn't approved an API token for another system yet imports exported submissions. When the connector is enabled, its findings deduplicate against the uploaded ones.

Operational Tips

  • Include the submission detail in every file export. Overview-only data imports with a title and severity but little else.
  • Accepted submissions import as verified, while new and triage ones do not. Filter on verified findings when planning engineering work so unconfirmed reports don't jump the queue.
  • Use minimum_severity on import, or Minimum Severity on the connector, if low-severity submissions belong in a separate backlog.
  • Keep each program's submissions on the Asset that matches its scope, so reports and SLAs line up with ownership.
  • Duplicates closed in Intigriti import as DefectDojo duplicates. Leave them as they are rather than reopening them.
  • Use the portal link in the finding's URL field to jump back to Intigriti when you need to talk to the researcher.