All integrations

Nightfall AI Integration with DefectDojo

Nightfall AI Integration with DefectDojo

Nightfall AI is a cloud data loss prevention (DLP) platform that detects sensitive data, such as API keys, credentials, and personal or financial information, inside the SaaS tools a company already uses. It connects to sources including Slack, Google Drive, GitHub, Jira, Confluence, Salesforce, Zendesk, Notion, Microsoft Teams, OneDrive, a browser extension, and inline email, and records each policy match as a violation. DefectDojo reads those violations, with their redacted detections, either from a JSON export or through the DefectDojo Pro API connector.

Nightfall AI Integration with DefectDojo

We send Nightfall AI violations into DefectDojo because a leaked credential in a Slack channel is a security finding, and we want it handled with the same discipline as a critical CVE. Nightfall tells us where sensitive data surfaced. DefectDojo gives each violation an owner, an SLA clock, and a history, and puts it on the Asset next to the scanner findings our teams already work. The parser and the connector share a scan type, so a team that starts with file exports can move to the API sync later without duplicating its backlog.

Why Nightfall AI Matters

Secrets and regulated data rarely stay in the systems built to hold them. They get pasted into chat, attached to tickets, and committed to repositories, and code scanners never look at most of those places.

  • Nightfall inspects data at rest across many SaaS apps, which covers exposure paths that source code scanning misses.
  • It checks API keys it finds, and marks a key ACTIVE or SIGNATURE_VERIFIED when it could confirm the credential works. That turns "possible secret" into "working secret" for triage.
  • Each violation records its integration and a location specific to that source: a workspace and channel, a repository and file path, a Drive file, or a Jira ticket.
  • Detection text comes back redacted, so the evidence can be shared with responders without spreading the secret further.

Advantages of This Integration

  • Live credentials rise to the top. A violation with a detection Nightfall verified as live is imported as Critical whatever the policy's risk label says, so the SLA for Critical findings applies to working secrets automatically.
  • Status that reflects Nightfall's own triage. Active violations import as active and verified, pending ones as active but not verified, resolved ones as mitigated, and expired ones as out of scope. Nothing pending is presented as confirmed.
  • File and API imports agree. The parser uses the same "Nightfall AI - Connectors Import" scan type as the Pro connector, and deduplication keys on Nightfall's violation ID first, so the two paths don't create two copies of the same violation.
  • Ownership and tickets. Violations land on an Asset where they can be assigned, annotated with notes, or pushed to Jira for the team that owns the Slack workspace or repository.
  • Reporting next to code findings. Secrets exposure shows up in DefectDojo metrics beside SAST, SCA, and infrastructure results, which gives a security lead one view of risk per Asset.

How This Integration Works

DefectDojo supports two routes for Nightfall AI data: a JSON file import with the Nightfall AI - Connectors Import scan type, and the API Connector (Pro).

1. Option A: export violations to JSON. The parser expects Nightfall's violation-list response, with rows under a violations key (a bare array of violations also works). Nightfall returns detections from a separate call, and those detections carry the redacted evidence, the confidence, and the API key verdict. Include them, either as a findings array on each violation or as a top-level findings (or detections) object keyed by violation ID. A violation-only export still imports, but it loses the Critical promotion for live keys and the credential type in the title.

2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select Nightfall AI - Connectors Import, and upload the file. To automate it, call the API, which works in Community Edition and DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Nightfall AI - Connectors Import" 
  -F "file=@nightfall-violations.json" 
  -F "product_name=saas-workspace" 
  -F "engagement_name=DLP Review" 
  -F "auto_create_context=true"

DefectDojo Pro users can run Universal Importer instead:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Nightfall AI - Connectors Import" 
  --report-path "./nightfall-violations.json" 
  --product-name "saas-workspace" 
  --engagement-name "DLP Review" 
  --auto-create-context

3. Option B: connect the API (DefectDojo Pro). In the DefectDojo Pro connector settings, enter https://api.nightfall.ai/dlp/v1 as the Location and a Nightfall API key as the Secret, and optionally set a Minimum Severity. The connector syncs on a schedule and creates one Record for each connected Nightfall integration that has violations. Integrations without violations are not mapped.

4. Keep it current. For file imports, reimport later exports into the same Test with /api/v2/reimport-scan/ so violations resolved in Nightfall are closed in DefectDojo.

Data Granularity: What Gets Imported

DefectDojo Field Source in Nightfall AI Export Notes
Title Credential kind or first policy, integration, location Reads like "AWS credential exposed in GITHUB (org/repo:path)"
Severity risk CRITICAL to LOW map directly; NO_RISK, UNSPECIFIED, and unknown values become Info. A verified live key forces Critical
Severity Justification riskScore, riskSource Stored as "Nightfall risk score: N (source: ...)"
Description Integration, location, policies, state, owner, file details, exposure Ends with one line per redacted detection, with confidence
Mitigation Fixed text Remove the data, rotate exposed credentials, review who had access
References Resource link, integration permalink, file permalink Deduplicated list
Active / Verified / Mitigated / Out of Scope state ACTIVE, PENDING, RESOLVED, EXPIRED handled separately
File Path / Line GitHub file path, detection line range GitHub violations only
Service integration For example SLACK, GDRIVE, GITHUB
Vuln ID from Tool First policy name
Unique ID from Tool Violation id
Tags dlp, integration, risk, credential kinds Useful for filtering by source
Date createdAt Unix seconds; today's date if missing
Finding type Static Data at rest, not a running application
Deduplication Unique ID or hashcode Violation ID first, then title, severity, description

The parser reads only Nightfall's redacted detection text and ignores the redacted surrounding context, so no raw secret is imported. For Drive, Notion, and GitHub violations, the description adds an Exposure line when the resource is shared externally or the repository is not private.

Use Cases

Credential leak response: An engineer pastes a cloud access key into a public Slack channel. Nightfall verifies the key, and the violation arrives in DefectDojo as Critical with the workspace, channel, and redacted value in the description. The on-call security engineer is assigned, rotates the key, and the finding's history records when it was handled.

Restricted environments: A team that can't grant Nightfall API credentials to another system yet, perhaps during a vendor security review, exports violations with their detections and imports them by file. When the connector is approved later, findings already in DefectDojo match on violation ID.

Repository hygiene: GitHub violations carry a file path and line, and the description notes when the repository is public. A platform team can filter by the GITHUB tag to find every repository with exposed secrets and track them to closure alongside SAST results for the same Asset.

Audit evidence: For a SOC 2 or PCI review, DefectDojo shows when each sensitive data exposure was detected, who owned it, and when it was resolved, without anyone exporting spreadsheets from the DLP console.

Operational Tips

  • Always export detections with violations. Without them, live keys are graded by policy risk alone and titles fall back to the policy name.
  • Expect pending violations to show as unverified. Use that as your triage queue, and let Nightfall's state drive verification on the next import.
  • Treat Critical as "rotate now." The parser reserves forced Critical for keys Nightfall authenticated with or whose signature it verified.
  • Use the integration tag (SLACK, GITHUB, GDRIVE and so on) to route findings to the teams that administer each SaaS tool.
  • Set minimum_severity or the connector's Minimum Severity to drop Info violations if NO_RISK matches would bury real exposures.
  • Expired violations import as out of scope, not mitigated, because Nightfall can no longer see the resource. Review them before assuming the data is gone.