Set up an integration with Kenna Security.
:::info Configure the integration to import Cobalt pentest findings into the Kenna Security platform.
You can also refer to the Kenna Security documentation.
:::
Kenna Security is a risk and vulnerability intelligence platform.
You can retrieve findings data from Cobalt using the API and import it into Kenna Security. Then you can measure risk associated with vulnerabilities and prioritize remediation efforts on the Kenna Security platform.
To configure the integration, you need the following:
We recommend creating a dedicated connector for importing Cobalt findings in Kenna Security, even if you already have other connectors configured.
The Kenna Security Toolkit is wrapped in a container image. You can get it in two ways:
Pull the toolkit image from Docker Hub using this request:
docker pull kennasecurity/toolkit
When ready, go to step 3.
git clone git@github.com:KennaSecurity/toolkit.git
docker build . -t toolkit:latest
COBALT_API_TOKEN: Cobalt API token
COBALT_ORG_TOKEN: Cobalt organization tokenKENNA_API_KEY: Kenna Security API keyKENNA_CONNECTOR_ID: ID of the Kenna Security Data Importer connectorexport COBALT_API_TOKEN=xxx
export COBALT_ORG_TOKEN=xxx
export KENNA_API_KEY=xxx
export KENNA_CONNECTOR_ID=xxx
cobaltiotask selected. This command imports all findings from the configured organization in Cobalt into Kenna Security.
kenna_appsec_module=false to the command below.docker run -it --rm toolkit:latest \
task=cobaltio \
cobalt_api_token=$COBALT_API_TOKEN \
cobalt_org_token=$COBALT_ORG_TOKEN \
kenna_api_key=$KENNA_API_KEY \
kenna_connector_id=$KENNA_CONNECTOR_ID
You can view findings imported from Cobalt in one of these modules, depending on which one you’re using:
In Kenna Security, navigate to AppSec > Explore.
You should see findings imported from Cobalt. If the page contains findings from other sources, you can apply a filter for the Cobalt connector.
In Kenna Security, navigate to VM > Explore.
You should see findings imported from Cobalt. If the page contains vulnerabilities from other sources, use search to find newly added vulnerabilities.