Picus Security (Pro)

The Picus Security connector imports breach and attack simulation (BAS) results from the Picus platform — whether your existing security controls prevented, logged and alerted on each simulated attack. DefectDojo creates a Record for each agent group, so one Record represents one environment under test.

Prerequisites

You need a Picus REST API refresh token, generated by hand at app.picussecurity.com > Settings > Rest API Token. It is valid for six months, and DefectDojo exchanges it for short-lived access tokens automatically.

Paste the refresh token, not an access token. Picus also issues a two-hour access token from the same area. An access token pasted into the connector will authenticate at first and then stop working the same afternoon. The connector needs the six-month refresh token.

Because the refresh token expires after six months, plan to rotate it — the connector cannot renew it for you.

Connector Mappings

  1. Enter https://api.picussecurity.com in the Location field.
  2. Enter the six-month REST API refresh token in the Refresh Token field.
  3. Optionally, set a Minimum Severity to limit which findings are imported.

Each agent group becomes a Record, and its findings come from the most recent run of every simulation bound to that group.