As we reach the end of September 2024, ThreadFix version 3.x on-premises has officially reached its End-of-Life. Therefore, there is no longer support or updates for this version of the product. We have fully transitioned our product and development teams to focus ThreadFix SaaS and migrating all customers over from the on-premises versions. Our Customer Success and Support teams are here to help you in migrating to ThreadFix SaaS and maximizing the value you see from this improved offering from Coalfire. This is the next phase of ThreadFix and our team is looking forward to continuing to support you on this journey.
Netsparker Enterprise Remote Provider (ThreadFix 3.X)
You will learn
About Netsparker Enterprise Remote Provider and its permissions, formats, and scan orchestration.
Prerequisites
Audience: IT Professional, or End User
Difficulty: Basic
Time needed: Approximately 5 minutes
Tools required: N/A
For general information & instructions on the use of Remote Providers within ThreadFix, please refer to the Remote Providers parent page. For information on REST API functionality for Remote Providers, please refer to the following: Remote Providers API
Introduction
Netsparker Enterprise Import and track Netsparker DAST results and merge DAST and SAST scan results with the ThreadFix Netsparker integration.
Permission
The Netsparker Enterprise user account integrating with ThreadFix must be granted the following permissions, in addition to having API Access enabled:
Manage Websites
View Reports
Remote Provider Configuration
When setting up the Remote Provider integration in ThreadFix, you’ll need to use https://www.netsparkercloud.com/api/1.0 as the URL.
Manual Uploads Date Formats
For manual uploads, the scan date will be the date the xml report was generated. The accepted date formats are:
dd/mm/yyyy
yyyy-mm-dd
If the scan date for the report does not match either format, the date used will be the date the scan was uploaded to ThreadFix.
Warning
A date with the format mm/dd/yyyy (ex. 03/17/2021) will parse successfully, however, there may be unintended side effects such as scan dates set in the future.
Scan Orchestration
ThreadFix supports scan orchestration via the UI for Netsparker Enterprise. In order to use the Scan Orchestration feature the ThreadFix user must have “Manage Remote Provider Scans” permission. After having configured the Remote Provider and mapped it to a ThreadFix application, click the Request button to initiate a scan, after which users can click the Import button to import the result.
Another method to initiate a scan orchestration is to click the Scan Orchestration (rocket) button within the Remove Provider Application tab as seen below.
Note an import for an application must be run before scans orchestration can be utilized.
This page will be updated at a future time with more details on the Remote Provider integration with this specific scanning tool.
Table of Contents
www.threadfix.it | www.coalfire.com
Copyright © 2024 Coalfire. All rights reserved.
This Information Security Policy is CoalFire - Public: Distribution of this material is not limited.