Skip to content

HackerOne

Real-time updates with async data flow — this process creates risk records in Adversarial automatically from the HackerOne platform. The HackerOne integration allows you to manage vulnerabilities discovered through your HackerOne reports. Creates Risk records in the Risk Register aligned with your Bug Bounty findings.

  • Source: Bug Bounty
  • Type: Control Deficiency
  • Opened By: “HackerOne Integration”

The integration can be enabled directly from your Adversarial tenant via Settings > Integrations. The necessary details to connect your HackerOne environment are the API Token and your program handle.

This is a one-way, ingest-only integration:

  • New records in HackerOne are automatically synced.
  • Subsequent updates are reflected in the Adversarial RSK record.
  • Changes in Adversarial do not impact HackerOne.

HackerOne report states are mapped to Adversarial risk statuses:

HackerOne StateAdversarial Status
NewNew
Pending Program ReviewNew
TriagedNew
Needs More InfoClosed
ResolvedClosed
Not ApplicableClosed
DuplicateClosed
InformativeClosed
SpamClosed
RetestingClosed

HackerOne severity rating maps to Adversarial Initially Reported Urgency (IRU):

HackerOne SeverityAdversarial IRU
CriticalCritical
HighHigh
MediumMedium
LowLow
HackerOne FieldAdversarial FieldNotes
titleTitle
vulnerability_informationDescriptionPrefixed with a link to the HackerOne report
submitted_atDiscovered Date
severity.ratingIRUVia severity mapping above