Nightfall AI Integration with DefectDojo
Nightfall AI Integration with DefectDojo
Nightfall AI is a cloud data loss prevention (DLP) platform that detects sensitive data, such as API keys, credentials, and personal or financial information, inside the SaaS tools a company already uses. It connects to sources including Slack, Google Drive, GitHub, Jira, Confluence, Salesforce, Zendesk, Notion, Microsoft Teams, OneDrive, a browser extension, and inline email, and records each policy match as a violation. DefectDojo reads those violations, with their redacted detections, either from a JSON export or through the DefectDojo Pro API connector.
Nightfall AI Integration with DefectDojo
We send Nightfall AI violations into DefectDojo because a leaked credential in a Slack channel is a security finding, and we want it handled with the same discipline as a critical CVE. Nightfall tells us where sensitive data surfaced. DefectDojo gives each violation an owner, an SLA clock, and a history, and puts it on the Asset next to the scanner findings our teams already work. The parser and the connector share a scan type, so a team that starts with file exports can move to the API sync later without duplicating its backlog.
Why Nightfall AI Matters
Secrets and regulated data rarely stay in the systems built to hold them. They get pasted into chat, attached to tickets, and committed to repositories, and code scanners never look at most of those places.
- Nightfall inspects data at rest across many SaaS apps, which covers exposure paths that source code scanning misses.
- It checks API keys it finds, and marks a key
ACTIVEorSIGNATURE_VERIFIEDwhen it could confirm the credential works. That turns "possible secret" into "working secret" for triage. - Each violation records its integration and a location specific to that source: a workspace and channel, a repository and file path, a Drive file, or a Jira ticket.
- Detection text comes back redacted, so the evidence can be shared with responders without spreading the secret further.
Advantages of This Integration
- Live credentials rise to the top. A violation with a detection Nightfall verified as live is imported as Critical whatever the policy's risk label says, so the SLA for Critical findings applies to working secrets automatically.
- Status that reflects Nightfall's own triage. Active violations import as active and verified, pending ones as active but not verified, resolved ones as mitigated, and expired ones as out of scope. Nothing pending is presented as confirmed.
- File and API imports agree. The parser uses the same "Nightfall AI - Connectors Import" scan type as the Pro connector, and deduplication keys on Nightfall's violation ID first, so the two paths don't create two copies of the same violation.
- Ownership and tickets. Violations land on an Asset where they can be assigned, annotated with notes, or pushed to Jira for the team that owns the Slack workspace or repository.
- Reporting next to code findings. Secrets exposure shows up in DefectDojo metrics beside SAST, SCA, and infrastructure results, which gives a security lead one view of risk per Asset.
How This Integration Works
DefectDojo supports two routes for Nightfall AI data: a JSON file import with the Nightfall AI - Connectors Import scan type, and the API Connector (Pro).
1. Option A: export violations to JSON. The parser expects Nightfall's violation-list response, with rows under a violations key (a bare array of violations also works). Nightfall returns detections from a separate call, and those detections carry the redacted evidence, the confidence, and the API key verdict. Include them, either as a findings array on each violation or as a top-level findings (or detections) object keyed by violation ID. A violation-only export still imports, but it loses the Critical promotion for live keys and the credential type in the title.
2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select Nightfall AI - Connectors Import, and upload the file. To automate it, call the API, which works in Community Edition and DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Nightfall AI - Connectors Import"
-F "file=@nightfall-violations.json"
-F "product_name=saas-workspace"
-F "engagement_name=DLP Review"
-F "auto_create_context=true"
DefectDojo Pro users can run Universal Importer instead:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Nightfall AI - Connectors Import"
--report-path "./nightfall-violations.json"
--product-name "saas-workspace"
--engagement-name "DLP Review"
--auto-create-context
3. Option B: connect the API (DefectDojo Pro). In the DefectDojo Pro connector settings, enter https://api.nightfall.ai/dlp/v1 as the Location and a Nightfall API key as the Secret, and optionally set a Minimum Severity. The connector syncs on a schedule and creates one Record for each connected Nightfall integration that has violations. Integrations without violations are not mapped.
4. Keep it current. For file imports, reimport later exports into the same Test with /api/v2/reimport-scan/ so violations resolved in Nightfall are closed in DefectDojo.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Nightfall AI Export | Notes |
|---|---|---|
| Title | Credential kind or first policy, integration, location | Reads like "AWS credential exposed in GITHUB (org/repo:path)" |
| Severity | risk |
CRITICAL to LOW map directly; NO_RISK, UNSPECIFIED, and unknown values become Info. A verified live key forces Critical |
| Severity Justification | riskScore, riskSource |
Stored as "Nightfall risk score: N (source: ...)" |
| Description | Integration, location, policies, state, owner, file details, exposure | Ends with one line per redacted detection, with confidence |
| Mitigation | Fixed text | Remove the data, rotate exposed credentials, review who had access |
| References | Resource link, integration permalink, file permalink | Deduplicated list |
| Active / Verified / Mitigated / Out of Scope | state |
ACTIVE, PENDING, RESOLVED, EXPIRED handled separately |
| File Path / Line | GitHub file path, detection line range | GitHub violations only |
| Service | integration |
For example SLACK, GDRIVE, GITHUB |
| Vuln ID from Tool | First policy name | |
| Unique ID from Tool | Violation id |
|
| Tags | dlp, integration, risk, credential kinds |
Useful for filtering by source |
| Date | createdAt |
Unix seconds; today's date if missing |
| Finding type | Static | Data at rest, not a running application |
| Deduplication | Unique ID or hashcode | Violation ID first, then title, severity, description |
The parser reads only Nightfall's redacted detection text and ignores the redacted surrounding context, so no raw secret is imported. For Drive, Notion, and GitHub violations, the description adds an Exposure line when the resource is shared externally or the repository is not private.
Use Cases
Credential leak response: An engineer pastes a cloud access key into a public Slack channel. Nightfall verifies the key, and the violation arrives in DefectDojo as Critical with the workspace, channel, and redacted value in the description. The on-call security engineer is assigned, rotates the key, and the finding's history records when it was handled.
Restricted environments: A team that can't grant Nightfall API credentials to another system yet, perhaps during a vendor security review, exports violations with their detections and imports them by file. When the connector is approved later, findings already in DefectDojo match on violation ID.
Repository hygiene: GitHub violations carry a file path and line, and the description notes when the repository is public. A platform team can filter by the GITHUB tag to find every repository with exposed secrets and track them to closure alongside SAST results for the same Asset.
Audit evidence: For a SOC 2 or PCI review, DefectDojo shows when each sensitive data exposure was detected, who owned it, and when it was resolved, without anyone exporting spreadsheets from the DLP console.
Operational Tips
- Always export detections with violations. Without them, live keys are graded by policy risk alone and titles fall back to the policy name.
- Expect pending violations to show as unverified. Use that as your triage queue, and let Nightfall's state drive verification on the next import.
- Treat Critical as "rotate now." The parser reserves forced Critical for keys Nightfall authenticated with or whose signature it verified.
- Use the integration tag (SLACK, GITHUB, GDRIVE and so on) to route findings to the teams that administer each SaaS tool.
- Set
minimum_severityor the connector's Minimum Severity to drop Info violations if NO_RISK matches would bury real exposures. - Expired violations import as out of scope, not mitigated, because Nightfall can no longer see the resource. Review them before assuming the data is gone.