Intigriti Integration with DefectDojo
Intigriti Integration with DefectDojo
Intigriti is a European crowdsourced security platform that runs bug bounty programs, vulnerability disclosure programs, and researcher-led testing for organizations. External security researchers test in-scope assets and file submissions, which Intigriti's team and the customer triage through statuses such as triage, accepted, and closed with a close reason. Each submission carries a severity (with Exceptional as the top tier), a CVSS vector, a vulnerability type with CWE, the affected asset, a proof of concept, impact, and a recommended solution. Submissions are available through the Intigriti external company API as JSON.
Intigriti Integration with DefectDojo
Our Intigriti program produces some of the highest-signal findings we get, because a person has already shown each one works. The program portal is good at managing researchers and payouts. It isn't where our engineers track fixes. Bringing Intigriti submissions into DefectDojo puts each accepted report on the Asset that owns the affected system, next to scanner and pentest findings, with an owner and an SLA. Rejected and duplicate submissions arrive already closed, so the engineering queue only holds real work.
Why Intigriti Matters
Scanners find known patterns. Researchers find the issues that need a person: broken access control, business logic flaws, and chained weaknesses.
- A continuous program tests production systems between scheduled pentests.
- Submissions are triaged before they reach the customer, which filters out much of the noise from unsolicited reports.
- Each report includes a proof of concept and impact statement, which shortens the path from report to fix.
- Close reasons record why a submission was rejected (not reproducible, out of scope, duplicate), which is useful context that should not be lost.
- Without a central platform, bug bounty findings sit in a separate portal, so overall risk reporting for an application leaves them out.
Advantages of This Integration
What DefectDojo adds to Intigriti submissions:
- Status and close reason become DefectDojo state. Accepted submissions are active and verified, open ones are active, and closed ones become mitigated, risk accepted, duplicate, out of scope, or false positive according to the close reason.
- The top tier stays on top. Intigriti's Exceptional severity maps to Critical, alongside Critical itself.
- One scan type for file and API. The parser and the DefectDojo Pro connector both report
Intigriti - Connectors Import, so uploaded exports and connector syncs deduplicate against each other. - Exact matching. Submission codes are unique across the platform, and deduplication hashes
unique_id_from_tool(the submission code) alone. - Safe rendering. Researcher-written prose is flattened to escaped plain text, with script and style content dropped, so nothing in a submission renders as markup in DefectDojo.
- Engineering workflow. Findings can be assigned, pushed to Jira with the proof of concept attached, and measured against SLAs.
How This Integration Works
All methods use the scan type Intigriti - Connectors Import.
Option 1: Import a JSON export. The parser accepts the API's records envelope (also submissions, data, items, or a bare array). Intigriti's API lists submissions and serves each full report separately, so include the detail: either nested under detail on each entry, or as entries taken from the detail endpoint that carry the report directly. Without the detail, findings lose the CWE, impact, recommended solution, and most of the description.
In the UI, open the Engagement, choose Import Scan Results, select Intigriti - Connectors Import, and upload the file. To automate it in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Intigriti - Connectors Import"
-F "file=@intigriti-submissions.json"
-F "product_name=customer-portal"
-F "engagement_name=Bug Bounty"
-F "auto_create_context=true"
Option 2: Universal Importer (DefectDojo Pro).
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Intigriti - Connectors Import"
--report-path "./intigriti-submissions.json"
--product-name "customer-portal"
--engagement-name "Bug Bounty"
--auto-create-context
Option 3: The Intigriti connector (DefectDojo Pro). The connector syncs the whole company account. Generate a company API token in the Intigriti company portal under Company Settings, then API, with read access to programs and submissions. In the connector form:
- Enter
https://api.intigriti.com/external/companyin Location. It must be HTTPS. - Enter the token in Secret. A dedicated token for DefectDojo is recommended.
- Optionally set a Minimum Severity.
DefectDojo discovers every program the token can access, creates a Record for each, and imports that program's submissions as findings keyed by submission code.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Intigriti Submission | Notes |
|---|---|---|
| Title | title |
Overview first, detail as fallback |
| Severity | severity.value |
Exceptional and Critical to Critical; High, Medium, Low direct; others Info |
| Description | Report type, asset, proof of concept, question answers, submission code | Researcher text flattened to plain text |
| Impact | report.impact |
Flattened |
| Mitigation | report.recommendedSolution |
Flattened |
| CVSS v3 Vector | severity.vector |
|
| CWE | report.type.cwe |
Read from cwe-<n> |
| URL / References | webLinks.details |
Link to the submission in the Intigriti portal |
| Status flags | state.status and state.closeReason |
Active, verified, mitigated, risk accepted, duplicate, out of scope, or false positive |
| Unique ID / Vuln ID from Tool | Submission code |
|
| Finding type | Dynamic | Researchers test running targets |
| Deduplication | Hashcode | unique_id_from_tool only |
For closed or archived submissions, close reasons such as not applicable, not reproducible, spam, informative, won't fix, and Intigriti's terse "no" import as false positives. Solved, resolved, fixed, or a blank reason import as mitigated.
Use Cases
Routing accepted reports to engineering: A product security team syncs Intigriti with the connector and maps each program's Record to the Asset that owns its scope. Accepted submissions land with proof of concept and suggested fix, and are pushed to Jira for the owning team.
Measuring time to fix: Bug bounty findings carry discovery dates and SLA status in DefectDojo, so a security lead can report how long Critical researcher findings stay open next to scanner findings.
Closing the loop on retests: When Intigriti marks a submission closed as resolved, the next sync mitigates the finding. Accepted risks come across as risk accepted rather than reappearing as open work.
Programs that start on file import: An organization that hasn't approved an API token for another system yet imports exported submissions. When the connector is enabled, its findings deduplicate against the uploaded ones.
Operational Tips
- Include the submission detail in every file export. Overview-only data imports with a title and severity but little else.
- Accepted submissions import as verified, while new and triage ones do not. Filter on verified findings when planning engineering work so unconfirmed reports don't jump the queue.
- Use
minimum_severityon import, or Minimum Severity on the connector, if low-severity submissions belong in a separate backlog. - Keep each program's submissions on the Asset that matches its scope, so reports and SLAs line up with ownership.
- Duplicates closed in Intigriti import as DefectDojo duplicates. Leave them as they are rather than reopening them.
- Use the portal link in the finding's URL field to jump back to Intigriti when you need to talk to the researcher.