Skip to content

HackerOne

Integrate your Risk Register with HackerOne. This integration imports bug bounty reports as risk records, allowing you to manage vulnerabilities discovered through your HackerOne program.

  • Source: Bug Bounty
  • Type: Control Deficiency
  • Opened By: “HackerOne Integration”

The integration can be enabled directly from your Adversarial tenant via Settings > Integrations. The necessary details to connect your HackerOne environment are the API Token and your program handle.

HackerOne integration configuration

HackerOne report states are mapped to Adversarial risk statuses:

HackerOne StateAdversarial Status
NewNew
Pending Program ReviewNew
TriagedNew
Needs More InfoClosed
ResolvedClosed
Not ApplicableClosed
DuplicateClosed
InformativeClosed
SpamClosed
RetestingClosed

HackerOne severity rating maps to Adversarial Initially Reported Urgency (IRU):

HackerOne SeverityAdversarial IRU
CriticalCritical
HighHigh
MediumMedium
LowLow
HackerOne FieldAdversarial FieldNotes
titleTitle
vulnerability_informationDescriptionPrefixed with a link to the HackerOne report
submitted_atDiscovered Date
severity.ratingIRUVia severity mapping above
(static)SourceAlways “Bug Bounty”
(static)TypeAlways “Control Deficiency”