Skip to content

HackerOne

Integrate your Risk Register with HackerOne. This integration imports bug bounty reports as risk records, allowing you to manage vulnerabilities discovered through your HackerOne program.

  • Source: Bug Bounty
  • Type: Control Deficiency
  • Opened By: “HackerOne Integration”

The integration can be enabled directly from your Adversarial tenant via Settings > Integrations. The necessary details to connect your HackerOne environment are your Username, API Key, and Program Handle.

HackerOne integration configuration

HackerOne report states are mapped to Adversarial risk statuses:

HackerOne State Adversarial Status
New New
Pending Program Review New
Triaged New
Needs More Info Closed
Resolved Closed
Not Applicable Closed
Duplicate Closed
Informative Closed
Spam Closed
Retesting Closed

HackerOne severity rating maps to Adversarial Initially Reported Urgency (IRU):

HackerOne Severity Adversarial IRU
Critical Critical
High High
Medium Medium
Low Low
None Info

HackerOne severity ratings are Critical, High, Medium, Low, and None; all five are imported. A rating Adversarial doesn’t recognize imports as Low, and a report with no severity rating at all imports with its IRU left unset.

HackerOne Field Adversarial Field Notes
title Title
vulnerability_information Description Prefixed with a link to the HackerOne report
submitted_at Discovered Date
severity.rating IRU Via severity mapping above
custom_remediation_guidance Remediation Task The program team’s remediation recommendation from the report timeline. Updates on re-sync if the guidance in HackerOne changes.
assignee Assigned To Individual users only; matched to an organization member by email — see Assigned To
(static) Source Always “Bug Bounty”
(static) Type Always “Control Deficiency”

When a report is assigned to someone in HackerOne, Adversarial matches that person to a member of your organization by email address. If an active member has the same email, they are set in the Assigned To field on the imported risk. If no member matches — or the report is unassigned — the risk is imported unassigned. Only individual assignees are matched: a report assigned to a HackerOne group is imported unassigned.

Assignee matching requires the API token to be able to view your HackerOne organization’s members. If it cannot, reports import unassigned.

On later syncs, Adversarial fills in the assignee only when the risk doesn’t already have one. It never changes an assignee you’ve set in Adversarial, so reassigning a risk on the platform sticks even when the HackerOne assignee is different.