- Automatically synchronize BloodHound Enterprise findings with Jira every five minutes
- Map BloodHound zones to Jira priorities and due dates
- Automatically close Jira issues when findings are remediated
Prerequisites
Before you configure the integration, confirm that you have the following:Install the integration
Install the integration in your Jira Cloud instance.Atlassian requires Organization Administrator or Site Administrator privileges to install Marketplace apps in Jira Cloud.
1
Start the installation
- Go to the SpecterOps BloodHound Enterprise listing on the Atlassian Marketplace.
- Click Get it now.
- Select the Jira Cloud site where you want to install the integration.
- Click Install app.
2
Review and install
Review the installation details, then start the installation.
Configure connection settings
Configure the connection between Jira and BloodHound Enterprise using your BloodHound Enterprise non-personal API key/ID pair.1
Navigate to Connection Settings
Navigate to the project where you want the integration to create issues.
- Go to Space Settings.
- In the Apps section, select BloodHound Enterprise Integration.
- Click the Connection Settings tab.
2
Enter the connection values
Enter the BloodHound Enterprise connection details.
3
Test the connection
Before you can access the Configuration tab, you must successfully test the connection.Click Test Connection and wait for Jira to confirm that it can reach your BloodHound Enterprise tenant.
Configure synchronization settings
After successfully testing the connection, you can configure how the integration should synchronize BloodHound Enterprise findings with your Jira project. The Configuration tab provides the following settings:For Jira Service Management projects, the integration detects the project type automatically and replaces the Issue Type selector with a Request Type selector filtered to incident request types.When the integration detects a Jira Service Management project, it automatically manages the following fields:
- Service Desk ID
- Request Type ID
- Request Type Field ID
- Incident Request Type Name
1
Choose the Jira issue model
Select the Jira issue type that should represent BloodHound Enterprise findings (for example, Task, Bug, or Story).
2
Select the synchronization scope
The integration dynamically fetches the available domains and zones from your BloodHound Enterprise tenant.Select the domains and zones that you want to include in the synchronization.
- Choose one or more BHE Domains.
-
Choose the BHE Zones that you want to synchronize with Jira.
- Tier Zero: Critical attack paths to high-value targets
- Tier One: Significant attack paths that require attention
- Hygiene: General security hygiene and best practices issues
3
Map priority and due dates
Customize the priority and due date settings for each BloodHound Enterprise zone.
-
Map each BloodHound Enterprise zone to the Jira priority you want to use based on your organization’s policies. The default priorities are:
-
Set the number of due days for each priority. The default due days are:
Use None to disable due dates for specific priorities.
4
Set auto-closure behavior
The integration can automatically close Jira issues when the corresponding BloodHound Enterprise finding is no longer detected (remediated).
When Auto-Closure is enabled:
- The cleanup interval runs hourly to check for orphaned issues.
- An issue is considered orphaned if the corresponding BloodHound Enterprise finding is no longer detected.
- The integration transitions orphaned issues to a Done status and adds a comment indicating that the issue has been automatically closed.
The integration closes remediated issues according to the cleanup interval that you set. For example, if you set the interval to 3 days, the integration closes eligible issues no more than once every 3 days.
5
Save and run the first synchronization
After you have configured the integration, you can save the configuration and run the first synchronization from the Configuration tab.
- Click Save Configuration.
- Click Run Sync Now to trigger the first synchronization immediately.
Verify the configuration
After you save the configuration and run the first synchronization, confirm the following:- Jira starts the synchronization successfully
- The configured project receives issues for findings that match the selected domains and zones
- The created issues use the expected priority and due date values
- Jira adds zone and domain labels that you can use for filtering