Skip to main content
Applies to BloodHound Enterprise only The BloodHound Enterprise Jira integration is a Jira Cloud app built on Atlassian Forge. It synchronizes BloodHound Enterprise attack path findings to Jira issues for remediation tracking. This page shows you how to install the integration, connect a Jira project to BloodHound Enterprise, and configure synchronization behavior for Jira Software or Jira Service Management. Use this integration to:
  • Automatically synchronize BloodHound Enterprise findings with Jira every five minutes
  • Map BloodHound zones to Jira priorities and due dates
  • Automatically close Jira issues when findings are remediated

Prerequisites

Before you configure the integration, confirm that you have the following:

Install the integration

Install the integration in your Jira Cloud instance.
Atlassian requires Organization Administrator or Site Administrator privileges to install Marketplace apps in Jira Cloud.
1

Start the installation

  1. Go to the SpecterOps BloodHound Enterprise listing on the Atlassian Marketplace.
  2. Click Get it now.
  3. Select the Jira Cloud site where you want to install the integration.
  4. Click Install app.
2

Review and install

Review the installation details, then start the installation.

Configure connection settings

Configure the connection between Jira and BloodHound Enterprise using your BloodHound Enterprise non-personal API key/ID pair.
1

Navigate to Connection Settings

Navigate to the project where you want the integration to create issues.
  1. Go to Space Settings.
  2. In the Apps section, select BloodHound Enterprise Integration.
  3. Click the Connection Settings tab.
2

Enter the connection values

Enter the BloodHound Enterprise connection details.
3

Test the connection

Before you can access the Configuration tab, you must successfully test the connection.Click Test Connection and wait for Jira to confirm that it can reach your BloodHound Enterprise tenant.

Configure synchronization settings

After successfully testing the connection, you can configure how the integration should synchronize BloodHound Enterprise findings with your Jira project. The Configuration tab provides the following settings:
For Jira Service Management projects, the integration detects the project type automatically and replaces the Issue Type selector with a Request Type selector filtered to incident request types.When the integration detects a Jira Service Management project, it automatically manages the following fields:
  • Service Desk ID
  • Request Type ID
  • Request Type Field ID
  • Incident Request Type Name
1

Choose the Jira issue model

Select the Jira issue type that should represent BloodHound Enterprise findings (for example, Task, Bug, or Story).
2

Select the synchronization scope

The integration dynamically fetches the available domains and zones from your BloodHound Enterprise tenant.Select the domains and zones that you want to include in the synchronization.
  1. Choose one or more BHE Domains.
  2. Choose the BHE Zones that you want to synchronize with Jira.
    • Tier Zero: Critical attack paths to high-value targets
    • Tier One: Significant attack paths that require attention
    • Hygiene: General security hygiene and best practices issues
3

Map priority and due dates

Customize the priority and due date settings for each BloodHound Enterprise zone.
  1. Map each BloodHound Enterprise zone to the Jira priority you want to use based on your organization’s policies. The default priorities are:
  2. Set the number of due days for each priority. The default due days are:
    Use None to disable due dates for specific priorities.
4

Set auto-closure behavior

The integration can automatically close Jira issues when the corresponding BloodHound Enterprise finding is no longer detected (remediated).When Auto-Closure is enabled:
  • The cleanup interval runs hourly to check for orphaned issues.
  • An issue is considered orphaned if the corresponding BloodHound Enterprise finding is no longer detected.
  • The integration transitions orphaned issues to a Done status and adds a comment indicating that the issue has been automatically closed.
The integration closes remediated issues according to the cleanup interval that you set. For example, if you set the interval to 3 days, the integration closes eligible issues no more than once every 3 days.
5

Save and run the first synchronization

After you have configured the integration, you can save the configuration and run the first synchronization from the Configuration tab.
  1. Click Save Configuration.
  2. Click Run Sync Now to trigger the first synchronization immediately.

Verify the configuration

After you save the configuration and run the first synchronization, confirm the following:
  • Jira starts the synchronization successfully
  • The configured project receives issues for findings that match the selected domains and zones
  • The created issues use the expected priority and due date values
  • Jira adds zone and domain labels that you can use for filtering

Next steps