Skip to content

BugCrowd

Integrate your Risk Register with BugCrowd. This integration imports bug bounty submissions as risk records, allowing you to manage vulnerabilities discovered through your BugCrowd program.

  • Source: Bug Bounty
  • Type: Control Deficiency
  • Opened By: “BugCrowd Integration”

The integration can be enabled directly from your Adversarial tenant via Settings > Integrations. The necessary detail to connect your BugCrowd environment is the API Token.

BugCrowd integration configuration

BugCrowd submission states are mapped to Adversarial risk statuses:

BugCrowd StateAdversarial Status
NewNew
TriagedNew
UnresolvedNew
ResolvedClosed
InformationalClosed
Out of ScopeClosed
Not ReproducibleClosed
Not ApplicableClosed

BugCrowd priority maps to Adversarial Initially Reported Urgency (IRU):

BugCrowd PriorityAdversarial IRU
P1 (Critical)Critical
P2 (Severe)High
P3 (Moderate)Medium
P4 (Low)Low
P5 (Informational)Info
BugCrowd FieldAdversarial FieldNotes
titleTitle
descriptionDescriptionPrefixed with a link to the BugCrowd submission
submitted_atDiscovered Date
last_transitioned_to_resolved_atClosed Date
severityIRUVia priority mapping above
remediation_adviceRemediation Task
(static)SourceAlways “Bug Bounty”
(static)TypeAlways “Control Deficiency”