SecurityScorecard's Vulnerability Assessment Scanner
Overview
SecurityScorecard's Vulnerability Assessment Scanner is a tool designed to identify and assess vulnerabilities in an organization's digital infrastructure, offering real-time insights and prioritized recommendations to strengthen security measures and reduce cyber risk.
Event Categories
The following table lists the data source offered by this integration.
Data Source | Description |
---|---|
Application logs |
collect activities from the source |
In details, the following table denotes the type of events produced by this integration.
Name | Values |
---|---|
Kind | alert |
Category | intrusion_detection , vulnerability |
Type | info |
Event Samples
Find below few samples of events and how they are normalized by Sekoia.io.
{
"message": "{\"trigger\":{\"type\":\"breach_reported\",\"breach\":{\"domain\":\"example.com\",\"root_cause\":\"hacked\",\"company_name\":\"Example Company\",\"records_lost\":10000,\"date_discovered\":0,\"type_of_breach\":\"\",\"description\":\"Company was breached, exposing authentication details of senior employees. An insider is believed to have helped.\"}},\"created_at\":\"2022-08-09T16:36:42.397Z\",\"execution_id\":\"87b786f3-76c9-4a2e-a44b-985be679ef80\",\"scorecard_id\":\"8e21f4aa-ee49-5f6d-be70-366b95ecc586\",\"domain\":\"example.com\"}",
"event": {
"action": "breach_reported",
"category": [
"intrusion_detection"
],
"dataset": "breach",
"kind": "alert",
"reason": "Company was breached, exposing authentication details of senior employees. An insider is believed to have helped.",
"type": [
"info"
]
},
"@timestamp": "2022-08-09T16:36:42.397000Z",
"cloud": {
"account": {
"name": "example.com"
}
},
"observer": {
"product": "Vulnerability Assessment Scanner",
"vendor": "SecurityScorecard"
},
"organization": {
"name": "Example Company"
},
"securityscorecard": {
"vas": {
"breach": {
"root_cause": "hacked"
},
"id": "8e21f4aa-ee49-5f6d-be70-366b95ecc586"
}
}
}
{
"message": "{\"trigger\":{\"type\":\"new_issues\",\"issues\":{\"csp_no_policy_v2\":{\"active\":{\"count\":26},\"departed\":{\"count\":3},\"resolved\":{\"count\":2}},\"domain_missing_https_v2\":{\"active\":{\"count\":15}}},\"selected\":\"by_severity\",\"severity\":\"low\"},\"created_at\":\"2022-08-10T19:49:46.029Z\",\"execution_id\":\"ee08b90e-98fe-45e1-9261-91eb0a80275d\",\"scorecard_id\":\"8e21f4aa-ee49-5f6d-be70-366b95ecc586\",\"domain\":\"example.com\"}",
"event": {
"action": "new_issues",
"category": [
"vulnerability"
],
"dataset": "issue",
"type": [
"info"
]
},
"@timestamp": "2022-08-10T19:49:46.029000Z",
"cloud": {
"account": {
"name": "example.com"
}
},
"observer": {
"product": "Vulnerability Assessment Scanner",
"vendor": "SecurityScorecard"
},
"securityscorecard": {
"vas": {
"id": "8e21f4aa-ee49-5f6d-be70-366b95ecc586",
"selected": "by_severity",
"severity": "low"
}
}
}
Extracted Fields
The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.
Name | Type | Description |
---|---|---|
@timestamp |
date |
Date/time when the event originated. |
cloud.account.name |
keyword |
The cloud account name. |
event.action |
keyword |
The action captured by the event. |
event.category |
keyword |
Event category. The second categorization field in the hierarchy. |
event.dataset |
keyword |
Name of the dataset. |
event.kind |
keyword |
The kind of the event. The highest categorization field in the hierarchy. |
event.reason |
keyword |
Reason why this event happened, according to the source |
event.type |
keyword |
Event type. The third categorization field in the hierarchy. |
observer.product |
keyword |
The product name of the observer. |
observer.vendor |
keyword |
Vendor name of the observer. |
organization.name |
keyword |
Organization name. |
securityscorecard.vas.breach.root_cause |
keyword |
Scorecard breach root cause |
securityscorecard.vas.id |
keyword |
Scorecard event id |
securityscorecard.vas.selected |
keyword |
Scorecard event selected |
securityscorecard.vas.severity |
keyword |
Scorecard event severity |
Configure
This setup guide will show you how to provide an integration between Security Scorecard Vunerability Assessment Scanner events and Sekoia.io.
Create an intake
Go to the intake page and create a new intake from the format Security Scorecard VAS. Copy the intake key.
Configure Security Scorecard
-
Login to admin panel and go to
Rule Builder
tab. -
Click
Create Rule
button. -
In the forms that you see please feel all the fields with correct values and use
Send web request to
as action. Set the destination url tohttps://intake.sekoia.io/plain?intake_key=<intake_key>
with value from previous steps. -
Save the configuration and enjoy your events