# Scan a Github/Gitlab

{% embed url="<https://youtu.be/8JsX1X9HjWE>" %}

### Prerequisites&#x20;

* You must have a valid Github/Gitlab/Azure account

### 1. Github/Gitlab Cloud&#x20;

#### **Step 1: Sign in or Integrate Github/Gitlab**&#x20;

Sign in with Github or Gitlab (or integrate them from the integration page if you are signing up by email or with any other IDP)

<figure><img src="https://lh4.googleusercontent.com/T2FrsHezTKqTDDTVQbGWALaZTbbB-7znWixYNX2oXWmsDZf-i9_Da1GYVg-nVFE4zHyL6qsIR7rsBYUwl0n1XskFofbRozDQwaEoshygPTs29mSgs6XbLuP_EQWcPYyZiMcmfI155vd6aOvVIQcPQUCTeDczxk6DPfR391-AHW9HEogZN0nzqoGGBA" alt=""><figcaption></figcaption></figure>

**Step 2: Scan Repositories**&#x20;

If you are logged in with a GitHub/Gitlab account or integrate the accounts, it will redirect you to the Github/Gitlab Scan Page where you will see all of your repositories (both public and private). You can select any repository (or multiple) and run the scans.

<figure><img src="https://lh6.googleusercontent.com/cf2ltaUT_jASkAAczg_Jp9oPtkzLeioUQm6yAn9dhA6yEj04qzSs1WzK-O_m3gyNrJkkPgjQ9tohWAhB4z1DWnk7u_ykGSrhYo7MLirIPA2QWUs2xrptCH2_okVzf3VTv78TAhvHV3YjBMQt4vS4mkrMItgIMHm3god3AYfv-LSdvJmhocZyNAhHWQ" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh4.googleusercontent.com/MwdO5MCyNrI-g2M0TwilKJ7Tgg9lEct2VhWn9dv2VchTGHwejuPaQcaDYMSPNYvkEyaG-pfyF0g9FeELYuVhY1bUKpu2ePeVqN86ucnUWW19NMCGKTl6AJQSWWru8ldvuGPUZO8k8MYfB_FlV0CRQPEj_Ni2V24GdFSDlHj_aj837X6ghsPQZyvXZA" alt=""><figcaption></figcaption></figure>

#### **Step 3: Scan any public repository.**&#x20;

You can scan any public Github or Gitlab repository using the input form (check below). Scan your public GitLab repositories in the marked option

<figure><img src="https://lh6.googleusercontent.com/07lm6WI5RWUJ-75e2wNxv-1OrNf4Ggalz4p8213Fan8VCbVC6pLlyzmGvcwWljOStv78_CozhM4OGLlruWxkJP4_sqbAhD6wQtaHcga46VzKyAGlswbyj5iK7FkKiyb6xihhBsjMms_Ay20OaZp-8-peF3gO4MZE4QH7dhOmi5e8-5Y06Q3mRamijw" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh6.googleusercontent.com/DVGruhvn5S6g3wjfWq3p4LEDwdUUplK_kYL_MBPk3OANT5RG_n_BqmGYsho6_YDGDc2gVMquarKYfzG9rY-6OMwqahk1IZF7E64G4axEbkE4bbG3OJ0OCUJ_BsMqfoVyCpvd1jajRrV6GqhBZHLfzmKrkQ9p5o-dqMmgRbGcDIH_Pu68c9mtHexlqA" alt=""><figcaption></figcaption></figure>

### **2. Github/Gitlab Enterprise**&#x20;

#### **Step 1:** Contact CD Support to enable&#x20;

By default, the option for Github/Gitlab enterprise is disabled. You need to contact CloudDefense support at <support@clouddefense.ai> to enable the option. Please email us with these details:

* Organization Name&#x20;
* Account email address

<figure><img src="https://lh6.googleusercontent.com/RbNlqWGsV1XGo5OmOOG5I1XJmn-ccXfTRw0j3-tgyJA1yO37LL88PSQd6oB1wuZJipUYnhzhiK3JWCnR3zMJxx33SP3KHFYpPhjk9E5njjn_9LtJ4DhENLyOWBFUz8zmJtR-TSOMtt0NnmhO9SK-Tn3YC7mbm05ptUDw3YwypmPhwjE9-8jtCD0e4A" alt=""><figcaption></figcaption></figure>

#### How to Get GitHub Enterprise link and Generate Access Token:

1. **Enterprise Token:**

To integrate GitHub enterprise users must have an enterprise account. If the user have an enterprise account user can see all enterprises here <https://github.com/settings/enterprises>

<figure><img src="https://lh3.googleusercontent.com/d-5FeMX1ZmQdzKDbof67ySmJr--6bXDKIeLyl27zOBu7hP1qkoQYVu6_4XMs8ki5IGUG_fUjoW9nvh-lHeBOKwHPo7rww4GL23W59Y2DuWtpYGzyrSzNl9C3cz8aM3rO9Q1Z6weTAy0VBQWVP14zIZo8DRy_IiVCdSh0xrS-FprYVeE9ydgSuifOcQsjCQ" alt=""><figcaption></figcaption></figure>

Clicking on the enterprise user will get an enterprise link. If the user doesn't have a GitHub enterprise, the user can easily open an enterprise account from the link below. <https://github.com/enterprise>

2\. **Access token**&#x20;

To integrate GitHub enterprise users need access tokens. To find the access token user need to go to **Setting > tokens** Here is the URL : <https://github.com/settings/tokens>

<figure><img src="https://lh5.googleusercontent.com/WWT3KGDoLzxnDhIdkdOLeftA09jDl7fyWMK463ARv6GuqlU5PY6ho4aZx7bSgq9xOhnJDRttC7XqAb3GsOduroJ2T0IvxRROzcT4hMiGSNg0lXSTDINZajhmdr2_nstgxJvR8UUcKt1DOEQRZGPC7DBmEvBvGuq9eq-_EMFiDVunFMERPoLhqlUd8okFXA" alt=""><figcaption></figcaption></figure>

After creating an access token, the user must copy and paste it into the enterprise access token field.

<figure><img src="https://lh4.googleusercontent.com/AC2E5YC3euGBNTWQPgX5fmtTJNDa3S9fgZYdwMEFhm46gPpKq3XLW4ohPjGp4MsQg5OczJ-J6QzM-yaEG2MQxRYiz0JqML1hSOmkdb6muYzSy0POniBUV3s9Mf2lcE-pA9DiBLjOnwUN453RNbU-WG0Aoc1ueXhkGYFFIY9EB6sgJjC9jB9g-KVbsg" alt=""><figcaption></figcaption></figure>

#### **Step 2: Configure**&#x20;

Once your account is ready for integration, you will see the options to provide details as below:

1. Enterprise Link&#x20;
2. Enterprise Access Token of Github and Gitlab

<figure><img src="https://lh6.googleusercontent.com/zxq8miw3zbjoXW-8JUJ0cNeqKxQ8r7fuxLw0p9XCQ_E5Cmda9mhcPL0ub19TW_Cyl5S7GIgpxPNpC22obopjBfBde3hNV9eYmJ3OsBuHHg_CojNcRZjrEozG8tM7h5SUG5Bwsy48KFMakSwSgWHjPI5_-71saW3cjPhtYUyTXRSj2fAoXmKI5yRdCA" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh3.googleusercontent.com/_OGA9b3ahkkPTRZNO4vcO81VtSBjSdfsXDdrzb02xJ8DcX2SPkMjNqV_y8G8MLfxFphfV-Zk-itQca_MuHeisrfzyXsCjDxPmFY8QfNjBTRnV_hlzxSXkMPV4y3j6rfgzH6hSc3jNSA45DpmOH2Us7brR8GsKnc9pBC3tC7eF4lLbrN2zxZ18EKxyQ" alt=""><figcaption></figcaption></figure>

#### How to Get **Gitlab** Enterprise link and Generate Access Token:

1. **Enterprise link :**

To integrate Gitlab enterprise users must have an enterprise account. If the user have an enterprise account user can see all enterprises/groups here <https://gitlab.com/dashboard/groups>

<figure><img src="https://lh6.googleusercontent.com/iKdhlNu0whISY_xWKsad07uy2Iit6pF2KVsBZXHsHIOTom8uyq3KC7At-iCbTN5oQWn7GdPnvRbNaiNCeg49fMRKajXmyq59sivDFh5bWIjMYh9dVHq3LiZ8ZXQ8JMbzR_afNgE6Hm0vNXigAXr2LJ92MeFDY7rXXFluRNPJgtIL2Hai68wKkzjxldqMrQ" alt=""><figcaption></figcaption></figure>

Clicking on the enterprise user will get an enterprise link. If the user doesn't have any Gitlab enterprise, the user can easily open an enterprise account from the link below. <https://github.com/enterprise>

**2. Access token:**

To integrate Gitlab enterprise users need access tokens. To find access token user need to go from profile dropdown Preference > Access token

<figure><img src="https://lh3.googleusercontent.com/9MAfwmR8LdJ6s7MudKWS-WLaDJx_F1TKrUUMKg5dB6SCXhdXrcXMuv7LhYXHvTrN2cI7Vw2isSNxq2TI-gXybOFM9nOcuMhTbk9V7dg3Epfmil9mfjeoSjyOJJsAMjIlnP_2XKxOFNMbBFfVpjf9Xg5Iif6sGfQ7fn-UQKs0T81XXKmEdh69UO_QYqMrpg" alt=""><figcaption></figcaption></figure>

Here is the **URL** : <https://gitlab.com/-/profile/personal_access_tokens> After creating the access token users need to copy that and paste it to the enterprise access token field.

Once you provide the required information, click **configure.**


# Scan an Azure DevOps repository

{% embed url="<https://youtu.be/tt_CeIH1TYc>" %}

### **How to integrate Azure Repository**

To integrate Azure Repositories with Cloud Defense, please follow the mentioned guidelines.

### Prerequisites

Users must have an existing Azure account, which requires :&#x20;

* Azure Username
* &#x20;Azure Personal Access Token&#x20;
* Azure Organization Name&#x20;
* Azure Project Name

### **Instructions**

### **Step 1:** **Select Azure Repos Integration**

Please select the Integration Page from your CloudDefense Dashboard and click on Azure Repos.

<figure><img src="https://lh6.googleusercontent.com/qbX_mJNSjL2WLcM6EOywlpLQDjJWqkSnT1DS16f8d2At22x7p5gII0Jrib1g2TvDR8mS_dHa7nt20Mufjs0ecwzcPto3dCq4fWQRkm29usXTwZBK5xvDXuxt3gl_QFrsYAHtBFZg1KRrq-B8SZ8dfORz17SnHPi72VUIBAghAg8c4jsKHfM0yqN83OViQOnKI_zipQ" alt=""><figcaption></figcaption></figure>

### **Step 2:** **Fill Up the Azure Integration Form**

Then you will see the Azure integration form which requires username and account token details and configures the repos accordingly.

<figure><img src="https://lh5.googleusercontent.com/rS7RCePTYH5VWiVWnV80ZvKCN21UHtDs5mRe0iuC8FTggBDIyyBNMG0x1UlMHmyhwwjlLmIBcBS3gVghiOVTGVtTVFgvZ-8BM9K-t2bu6mUm9Sqnq5AnXhBbPTlb_QgAdE2mUOflG4p7Y_HKS6R7ivWVZk9TwYyQnp2kx_lQLApT1eAl7OKBxWYBQXyIE4_Xj3Is_Q" alt=""><figcaption></figcaption></figure>

Now fill up the form with all the required information. Check the screenshot below.

<figure><img src="https://lh6.googleusercontent.com/QgjVdOJpXOZnShaWKO5FMcQkWQR5fb4sxJBuo96BU5BQuGOqDrl_5__ERiMDC_9dj4XDQjyIOAVHNwbkgJ_tSKUOGt6g5hhLxwOmi9OIMNKa_eD2gGSoYOinFrbkh7VGOjEOarofhSsEHBVQB4LNlvZY_rgpos1u5QSXbOs01fTIyxNI8kH_bZisqBJUvfEmqy-vjw" alt=""><figcaption></figcaption></figure>

**Important**: Make sure to check the “Full Access” for Scope.

<figure><img src="https://lh5.googleusercontent.com/B1FebxFLq-qlNn_PZ0jQ0dCsq96FPbLo94ZfGHuICR_Bs9ebWV1Ul4bX2TDcG_8CjXlbw1_3Z8YYQ7vvXbzoyM_7f-LYlXq6VAkDEujCfNezsthiOHIRR-s2rTuZefWiYf12oiRjhCPa4ylQZyNBe5KTKZ_50Ez-DeJkhB3Eh9kXs6Uvl-DvtL-8tnxxq6t7glRDIA" alt=""><figcaption></figcaption></figure>

Now fill up the form with all the required information. Check the screenshot below.

<figure><img src="https://lh5.googleusercontent.com/nfu2v8N56pxXPa_lNNYbw4e9KZcURDxbMgrULcMdLlAKRW_L6VxfQFyi4mOYgFHynD2WTbof7kiHjJdpVIy0GDkR-M-eq0ck4c3b16V5RkIkOHevPM01V8w6kxcpJiDnQFjXAiJljJMRhhodciAwuHZbG5S-_5r12BPdY-upoo-SgHqC5KW1vmmoJudSyBt6_qSAQg" alt=""><figcaption></figcaption></figure>

### **Step 3: Configure "Azure Repos"**

Once you are done, please click **"CONFIGURE."**

<figure><img src="https://lh3.googleusercontent.com/zjZgjc2jLUq00EG5oMunI0t_03A4Va-nN10WaQUXHv1LVuOsEfmfqspeKFDUSzYvVgjjSv7Bx5IO4BWGnEbwqa7aprX3XEK_s4gE39qC3kf9pJQj3akW6Xxdf_-St9mzgFP7YM_Ox2lUkKsPGnjaBH2sDttLy3BGPz0atiVxTVTwG6QRRiLO7S46_LtNzX6d9z0l1Q" alt=""><figcaption></figcaption></figure>

Now you can see all of your Azure Repos and start scanning as shown in the following screenshot.

<figure><img src="https://lh5.googleusercontent.com/eNh3aDL2y6bsPzl998gHBbv3j1eDZiOEeylu-lyHAK5TQi9ro84s8rhwLpMc2x31vG-fp3FuQha-vHzndJlfc_qNj4GNLJf-gdftDEultkg9gUTEBeYQEEYfzEXIdgsgKExdlyD1fvn5GA9lpDXyscMDLTDjqlaBJDmNxqH3M8FvNfF73uchtFfIhNSsEIaxurw6xA" alt=""><figcaption></figcaption></figure>


# Scan a Bitbucket repository

{% embed url="<https://youtu.be/MeQm6bBRg_o>" %}

To integrate Bitbucket Repositories with Cloud Defense, please follow the mentioned guidelines.

### Prerequisites

* Users must have an existing Bitbucket account, which requires: Bitbucket Credentials

### Instructions

### Step 1: Select Bitbucket Repos Integration

Please select the Integration Page from your CloudDefense Dashboard and click on **Bitbucket**.

<figure><img src="https://lh3.googleusercontent.com/YNVdPpNXHTFIYkaDLOrxq40gnkUN1aLkKa_lFXALzNxzoJldXINGU80R53n0MkfEHoOqvyiCjoN2afXindNXKirepGPHO7IrgXyB7yC_clq4G4OxkKFdtvf-xcQ-SPdwjRqmzJoSbXWs1TW7lvYBZkGum8y1u5RKG5e8gpfMlyPPGewdVgx5b7NZv4As" alt=""><figcaption></figcaption></figure>

### Step 2: Click Configure and connect the account

Once you are here, hit **Configure**.

<figure><img src="https://lh3.googleusercontent.com/SwGbNxkzi7LONFOOQzc5Fv1TZQS9ire1bKyzc38kh0Jn6CtLG6tNMEMM02w5-zKrSqemgC8gDcFQwds733fCqaJ9U_CHpJ7Frgf_xzCOCOPrKdszgDxJBQXjEy7ogfH0EtckB9xNZwHnI4pICK0V6m3IZ0mCG4L8gCT8rv1h6gvMCBY_Z2VneNnVse3J" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh6.googleusercontent.com/6xXu_Cd9J1xYxP89kSFZ8L4tCq5ethzqDhnQ2NJZCYW4k7YpSukeyxaUUBFfiQqizbPjtVDvLbyOps3vf6yJBnhMA5oRsJ3t7Uc8zLulpvUlcc8FoueQmL3xjh3ve6xI2X8QqBXznu8qfDWmzrxJgADpvmDzlb0-o_dKQDetexEV7NI_B2ovbKmvFk2a" alt=""><figcaption></figcaption></figure>

### Step 3: Scan "Bitbucket Repos"

Once you are done, please click "Scan Application."

<figure><img src="https://lh3.googleusercontent.com/BLd_eaABOJ40KbnWivGjcjiB6btoTC2q26-5yxlkn_T9038ql0vsEJs8h98Mcnrgk1aue--uxdwapU8q8K2xIt-D4V6STIfnc-vSnTzFFUlYng-uAhcEnysihzZkuphGgtrFQSOe8LCoNK2imvfY-VfbgHjG_KXwCnLnBkRj5IWnpyjLWPRGJNpHjg5F" alt=""><figcaption></figcaption></figure>

Now you can see all of your Bitbucket Repos and start scanning as shown in the following screenshot.

<figure><img src="https://lh6.googleusercontent.com/3oqp5uUIptznr4hagj9WUKUlB-pZGcKymTRniN0E-XkoxzMW1HE4rFN-WOrZIEHdMOZyuydfY-aEcOM3pd4Gl4YcpW-h7EmSJs5e0AZCDHDMdBPrMPE5BKt7OVnrRDhmwFtgmR0khcfits8jOIY4qiyudyOg_JMgP6nCYQZ5WN1QyMNzs3kMaPQpJSAk" alt=""><figcaption></figcaption></figure>

### How to integrate Bitbucket Server?

To integrate Bitbucket Server Repositories with Cloud Defense, please follow the mentioned guidelines.

### Prerequisites

Users must have an existing Bitbucket Server, which requires : Bitbucket server Credentials

### Instructions

#### Step 1: Select Bitbucket Server Integration from Source control

Please select the Integration Page from your CloudDefense Dashboard and click on Bitbucket Server

<figure><img src="https://lh5.googleusercontent.com/KNAVjL101nO7hRhgMGSVW-5wmbP1_jQh2IZ5sqrcNZN2Thf8B1gGPqqcVyX_UMxoFmRW0KudwEGVixvQH4W-AVEIkAIJigDFIaDsyUQRCxEtgjSpLU5LSZz0i7FYKjOXseX0gktI79dx5CW2jp87tawBCsYSYhERysf2bDaiq_k7FEoWsEEqVIpgc1hy" alt=""><figcaption></figcaption></figure>

#### Step 2: Fill up your credentials in the input field

In the input field “Give the host link” you need to provide your server host link and from Bitbucket Server you will get your access token, you need to provide that in “Enter your access token”

<figure><img src="https://lh3.googleusercontent.com/Fo243I-9q06FIiGiQuS8enLXKk9aKBPHlZcaTD3Glh_zw3u3wePyNfiC3zx_JgrSh1Z6ER6mE_BPXegpTZRUwD-GxAn55--eNaBFxP84QAPx5JbHjGVuExo-gMLnzxRgwlYWfbETGRhWK80Mr4Z7Zos9q6UxWrCDQrt5LIsOlbxTuJv8hQb2JKrbECJ3" alt=""><figcaption></figcaption></figure>

**-- How to give the host link?**

Your bitbucket server link will be the host link for the input field. Here is a sample host link

<figure><img src="https://lh5.googleusercontent.com/pPhlRDhyH5gXIdHQ_mQvTkm44IHJugC-Ooe2qjY8zYB73R0927if6yOTBzAwj2yIKnQbohXXAKVAhklxlrGKy2lg_YeBZw0mdeIN7bAzlEXDQfcZmwu5eU5PuwkxEKZ_Ig2ZvtxJExaF6UsZMo4SS9B6geR4BJ6iDx7LsucJIuX0ktiP9kRnmCyNeRe1" alt=""><figcaption></figcaption></figure>

**-- How to get your access token?**

<figure><img src="https://lh5.googleusercontent.com/r-WhLvSX6bzsPax5mHkHlLewp63S7dWYRW1QGaW4ga3j4pP-wI9w6TCcUKcifuJWtJW_NI6GE7xWdzKWPLxuZdrhjFxNa_p83-pj2On7YF0nqrSa_ZNn7rKez3LqTHEATwjFRYsVSur3WBd1Eycthuqwwvsa84bRS7oD7DCUImPj6ZWY4NCeHooI3f6J" alt=""><figcaption></figcaption></figure>

* After login to your Bitbucket server account, click on “Manage account” from your profile upper right side corner&#x20;

<figure><img src="https://lh3.googleusercontent.com/yDVw3kcW0Nqr-A-r1T_DYvlF3jrtN_QG7t4eROHrIK89AWRT6aQ5K3JhMkgBx4qACnI6C08u_3M5OVMfQ3aZW3IVjcgJ2jTKg2ZJbL2nEuMbZ2blFl9RGFudWvOodqkd7Lz_xp2K6tjFBv32LnPSDTnoXdwpc-MlY5VWF7QXT8M4SL_r2atGHqbBevRR" alt=""><figcaption></figcaption></figure>

* For creating access token click on “HTTP access Token” and click on “Create token”

<figure><img src="https://lh4.googleusercontent.com/YTrCZFrTnwvGh_jBtrW2ZdKSELm_KmFtVgZvfPA7TKIJ1OTVlcS1U9nVJNdY8tdBpjjrGt2oz4T1MsIISKj1Ko0YDGdedAsNzqszayI365FsB_nmWmHo56rWU7afK6zwwtkAy4Aq4PfIKADbHdeWvx7zurAWHTKUgXgizQrXKyDPBX-5CazhGprfOAcS" alt=""><figcaption></figcaption></figure>

* After clicking on “Create token” you will be able to see a token creation form, put a token name and click on the “create” button. Your token will be created.

N.B : After creating your access token you just copy that token one time. After continuing you will not be able to view this token again.&#x20;

#### Step 3: Click Configure and connect the account

After providing all information, click the configure button. It will automatically connect it to the Bitbucket server and show this screen.

&#x20;&#x20;

<figure><img src="https://lh3.googleusercontent.com/79L1yQsoogYVddYtJ-kdubUtwnf8JbQZpN9zm_YZOf8Qjz66lDmjflikeVAR6i_DG3VnhZ1xrE8A4DXIRyUa2Pe2XZLr-YdlrigKM2SXYl5gnW0oWgiu9ZtCxB30gU9J-kF7ThPhNKhIG0kyahHr9kSNt60tXpIePfYFXbXti38iu0jY3PkzS1vzbL2_" alt=""><figcaption></figcaption></figure>

#### Step 4: Scan "Bitbucket Server Repos"

Once you are done, please click "Scan Application." and you will see your server's entire repository. You can easily select each or all your repositories and start scanning.

<figure><img src="https://lh4.googleusercontent.com/WYyHZ7gKBmc_CxsIMXz6QJxudS0qm1k28kGpRD9qUFQLiLR0ccPMsieAxhkbNpHFmmefh2dZxR-MdNZuDZON3LxZ2yucqI0ZUkkTGWisHfGXx3YcajgZ646qIGjWPSn0c7Tl-vDeupcCPLdp493_dIY50EhGdk2qJ562EnUdQAWeZ7Ih3yBz4c0MoBf9" alt=""><figcaption></figcaption></figure>


# Written code Scan (SAST)

{% embed url="<https://youtu.be/AC3CNEXKbN0>" %}

#### **For SAST Scans users need to follow the mentioned steps.**

We can start an online scan by clicking on the **SCAN** button on top right

<figure><img src="https://lh6.googleusercontent.com/VqnfAmR3N3V7DkNNi3QwU0GikgB0NptS5c8-LIQYVMuL-fUc9oPcceq2cT6T1b1tAd3adomsrnLpGlpsXHWXGT8DuDsKMxkcTmfuLUwbAFodB2_S3-x-pfv3IH1UdWJEbjQbsAyBBcNMCU5gxru_UPSA8aQ48kFPT42mByyl4Tfw_fNVhTKnPuB2kA" alt=""><figcaption></figcaption></figure>

We chose **Github** for this example. Once clicked, you get a repo to scan. For the demonstration purpose we take **Vulnado.**

<figure><img src="https://lh6.googleusercontent.com/47OhyaL8GWofSaRIk1kQ9d5NIrcxRNQ0SyInFwVUwcFU1ujVrPyJaFcyKjpL3Ve7vw5Nd64I9rnAJ6PzbiyyQ3WG90Rk_P25Qow7qcqKoGS0AoGEuU-q-fYoE0dbzIlJ3kfg1u-j8aOP53hP_n27FRdivQejFg1zLfi5LjTxwP-maxDHaDoh8etCUg" alt=""><figcaption></figcaption></figure>

We clone the repo and paste it like,

<figure><img src="https://lh6.googleusercontent.com/LoRr3UdM4pxtU0yx4ytimfLaMZC1epKgY3RTJRM6ugZfDjnexUXjTqmWYnTH2hU-9jybQlNpEOGXPC6rZ9wKul4-ezRNdkVaFtA4-W7ey55X46ndeCN9GBVdXHmqwn6cKxhmY9YgAvtYl2MkwZ6sXLWybdVaccVpNt6nNGYq7YKv6-CBFY_Xpkikgw" alt=""><figcaption></figcaption></figure>

Hit the green plus sign and scan.

<figure><img src="https://lh5.googleusercontent.com/9Wrq7AmEnhQqkKlm0mxlm4v9gYWv9ZeKz4PVrxtTQORmObqWCYE-1EWw5uJ5wY_GE9w2jyH1hfIQqW5CEZ3ZWwTLwf5GdmHMqnqeoe5w40qr6O96VPcAcrNVh6-cBmuSzj8HMh4qkvZ3iz2sJO_JlDG7n4JSOCSIk1Pb5QknIY9Snl-366yNKGphbA" alt=""><figcaption></figcaption></figure>

Scan with start

<figure><img src="https://lh5.googleusercontent.com/5mLWHQKuJQn7_e9jkmqF1PAtWki9lhn_Lf2kHDu5f_m_tiVudkaUkHvMLGe0IBurBhnnAr69K5d1nqhr9QnEZj3ggMQR3mO8awblej2mbCMwYqQUhWjXQYSgdonXXWCM9-vonh3GtRrgsb7e1aTi6CkqofJsRnIIW3Pbj8OIjRe666RBPSA9ZpDceA" alt=""><figcaption></figcaption></figure>

Once online scans finishes we get the result like following

<figure><img src="https://lh4.googleusercontent.com/QljpfaZy-EZM62yP_Z0g2ZrSZB_EaiJmA7eJjxdZ30kIwCoDkr00LOb2FnoikKsMSCkcpGSWJhaYeJ6Y62oJihWGxNrqur1ZPd3AmFwNY26pYlZluOGdANs-O5j_ZqoJ3QcH968c3JlvV9c4v6Niovx6nZV2Y2K3n6mNVtxv90IETWcE5VNKYq8o5A" alt=""><figcaption></figcaption></figure>

Above picture shows that we scanned a project names “vulnado-test” which has our Code Analysis (SAST) and other scans. Let’s dive into that.

Once you click on it you will be redirected to a page like following

Which will contain the following information about your SAST scan

```
  1) Project Scanned
```

Named of our current project. In this case vulnado-test

```
 2)  Scan Date
```

When scan was performed, on which date and at what time

```
 3) User’s Email
```

Which user performed this scan? We show their email address

```
4) RuleId 
```

Which rules matched our sets of backend rules. We show that

```
5) Vulnerable Code Snippet
```

Code block which is vulnerable

```
6) Rule description 
```

More information about the ruleid

```
 7) File Path
```

Vulnerable code file path

```
  8) Filter Severity 

	      -  To filter your results based upon the criticality 
          
```


# Open Source Libraries Scan (SCA)

{% embed url="<https://youtu.be/zcvgQsCkSs0>" %}

### Starting Scan

We can start an online scan by clicking on the **SCAN** button on top right

<figure><img src="https://lh6.googleusercontent.com/sF-IDM1q2a_FTcpYxw96oFPb4NET-L5ra-g_ZXRHfyAPQ9wY5Mt61evfSUuvCyr5716DR6_heUh0wgse7kNJLj4Y02-nqwiMRagwbtpxErEvXLjKujJikpvgMDFhTKytITYn6TiDFulljUL9p3tiGA01tikXmpfHiA9BkiUtfUD4umvXulqsEnVyPQ" alt=""><figcaption></figcaption></figure>

We choose Github for this example.

Once clicked get a repo to scan. For the demonstration purpose we take **Vulnado.**

<figure><img src="https://lh4.googleusercontent.com/4sSjKi0y9xjBnbJgzbSx_-zx_Kybl0sOHbEwHs0S2OssbR1EpE9HC-WwAsN3DnBn9sm7WOqQFziQTDwlFaCKi-_IxDC-T6--1tl1SSJwGrfXwMrMvqTdI9ZnjoMTUP9p2Wm0n-aTsfsu9HD_Rt5xliNx9lZ6AC1qVwiBfRhbzxRi3Zkl2UhyQjb2ZA" alt=""><figcaption></figcaption></figure>

We clone the repo and paste it like,

<figure><img src="https://lh6.googleusercontent.com/LyM0PZXOunevJ4_I5SJ2on5PH5_65L9-DpAQnGkNkM49yLLFhyTQVk-26Yt4R-6FKc38STvcISpE463zTHF1rxcQ4tBAQc03GPwXW9LgW1d0KDY2iprP6_da4KxYQs1k2YUJweHRIBC9GbUwEs-fd1_TAOANUxcDukEfvw-c4AfYVPsTF3mpFdSRyA" alt=""><figcaption></figcaption></figure>

Hit the green plus sign and scan

<figure><img src="https://lh6.googleusercontent.com/yMtUjPqFM2U7JnbuLsGaSs-rZiNl2rqrAmmizALSj083HceEBm4xmjpZyYnkaPdLEoE42Y2nRDfHzSTaXXlHp7xUNyjA6HbCmzaLsRA0dAEKnoLCHWDIKYDeRqH-2_fh6Prihov6KIRWSOdfR3lR-fUhCY27qp2b-7-TQNTfr5QUYgcxdzgqe7uo-Q" alt=""><figcaption></figcaption></figure>

Scan with start

<figure><img src="https://lh3.googleusercontent.com/2fpF5rif5jxsUCfCNZ8wiRIEgmUPpiwK4R2bMntDzbFMvVbsVYKLX5E1-yhWu0JSaeOmSaQ3iruQHAQh1Wvii7l_Ihkbma3OWzKnd_N1bUQuGeVQlElNndJBcf47wlWIGQ3Z4BlVCyKSltKauzxJUlPrC8DQzm6z_QQCdZDT4P2slTMeiObUGzTQFw" alt=""><figcaption></figcaption></figure>

Once online scans finishes we get the result like following

<figure><img src="https://lh6.googleusercontent.com/YpBd2CC37FNaab15MyHc1FpGLeTQf9aLSmufUSfX5vmVrIrmFELxGkNd3MoOcTpl11k3xzN5HkosYxgwQwt5eLt3vqPakIPfSdN8PKqFQS7M24ntxhOClPH-qpX2iwyfPfrvUgh3lOawLAebDv-OnHTuPjUTgnAwwq9W6TRsadIJf58WWTZJ02myLg" alt=""><figcaption></figcaption></figure>

Above picture shows that we scanned a project names “vulnado-test” which has our pom.xml (SCA JAVA) and other scans. Let’s dive into that.

Once you click on it you will be redirected to a page like following

<figure><img src="https://4095801085-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtErerJyslHxJo5moBxJo%2Fuploads%2F4hkVi7hN9WVdMsHb1qqp%2F111.png?alt=media&amp;token=f6a49f69-8d17-444d-bfe7-ab855838f040" alt=""><figcaption></figcaption></figure>

Which will contain the following information about your SAST scan

```
  1) Project Scanned
```

Named of our current project. In this case vulnado-test

```
 2)  Scan Date
```

When scan was performed on which date and at what time

```
 3) User’s Email
```

Which user performed this scan, we show their email address

```
4) RuleId 
```

Which rule matched our sets of backend rules. We show that

```
5) Vulnerable Depedency 
```

Vulnerable dependencies with exact verion

```
6)Description of CVE 
```

More information about the vulnerability that dependency have

```
 7) Patch
```

How to fix that issue

```
  8) Filter Severity 

	      -  To filter your results based upon the criticality 
          
```

Once sca scan is done, we can patch the vulnerable dependencies directly from UI if Source Control (Github/ Gitlab/ Bitbucket) is configured and you know that repo.


# Secrets Scan

{% embed url="<https://youtu.be/UVbRxRU7chA>" %}

### **Prerequisite**

* Clouddefense CLI&#x20;
* Gitleaks

### Steps

To scan for secrets we need to pass “--no-git” flag from the CLI like,

```
// Some codecdefense full --api-key=6262fe7f-1434-2711-78fa-268ce4187339 --path=/opt/secretsandstuff --project-name=leaks --no-git
```

In the above command we pass our api-key, with the project path to scan and –no-git to include secret scans.

Once scans finish we can look the data in UI

<figure><img src="https://lh5.googleusercontent.com/Olyfc_pWxOrZ2JLEcacRI_giu5zTCTdNAxkUtXVK4sTqq6X2zp7GGtZJ7n4m3jx_cZUmUCWDdZz_sAWMsiWGIdaZhG7zNH98XszFvD8eZxCzMOsRBjeYBwwfMVpQj_tcuqiPk8UKLiIgBMKUqclATHgT-QhHdXkZqO6wLEX642VNwBzH6t6R58T4EA" alt=""><figcaption></figcaption></figure>

And once expanded ,we can see our data

<figure><img src="https://lh6.googleusercontent.com/4mccujsfm-nC_gNp6cypwl0PUZRc3NmrWB62d9jsLjPxjPdELfkdU9fu44em5vXJCbbxh-fEXYiBCjl6qWpjtqCZcv0roRdsVBs8v2LhVwj3JV-DdM7tAWAYag1YqAl42uegFWyIPIzVASBjTcK_5JkPaz9shgZzU-up7IT8VE4qiO1UZhWNu-aq3Q" alt=""><figcaption></figcaption></figure>


# DAST Scans

Dynamic application security testing (DAST) is a process of testing an operating application or software product in order to identify potential security vulnerabilities and architectural weaknesses.

{% embed url="<https://youtu.be/pCBPNFOjJn8>" %}

### DAST Scan or Website Scan from CloudDefense UI

In DAST scan we provide a website address for example <https://console.clouddefenseai.com> and DAST scanner will check for vulnerabilities on the provided target.To Start a new DAST Scan from UI follow below steps:

#### Step 1 : Login Cloud Defense console instance

Please login to your Cloud Defense by clicking [**here**](https://console.clouddefenseai.com/)

#### Step 2: Click on “Scan” on top and then select “Other”  <br>

<figure><img src="https://lh6.googleusercontent.com/MENFzDsw-hjyAZO40giTk3hOp1dRsMCSWc6pYpbRQo8RtzQlwf38ptnhbnUafUAFhcCeY0RYDUmkouZM6JBpioIL7Pii0Q3F2ZwNRfhBw83wMBkOds0s-fUWwMeuXkykUf1GxdFaouIP23U5_c4ZFv9B5goBRj_hzjoo4whW_jJzKr9g74mCObPHWg" alt=""><figcaption></figcaption></figure>

#### Step 3: After clicking on “Other” select “DAST”

<br>

<figure><img src="https://lh5.googleusercontent.com/X3n8zZsZvMAwOnHTAJlvPwhaSzmn3UMos6WXKXAXmuZyWudNixPeyXEuUC38yKNLO_QrFLtVy6UDzQI0wNg7UBmOSfGY0tAukuO9UeJETAT6ZtsMkCKc7TSL4Y0O1ZjmXI1b2LKzYh7ap5ayfwdV4mtH_yK6OUGFmSaC5QK1ssw0Hxen-YfC8Nf42Q" alt=""><figcaption></figcaption></figure>

**Step 4:  Now you can run a simple scan by just providing Resource URL**

<br>

<figure><img src="https://lh5.googleusercontent.com/7mGGYBT1I2MACcUfuZzx0hBQJlsOArEh26_aCb-ZSc6xyUu02Onj2V4aaK-BQtLkx7sXX_Fj0kKV2QtLek9N0dG2XulvrLVq_jPMFlJ4WUvJtsvsNidzT9M0xP2Rm_D2J_ZrCB3UVJkEKcG0Ol_VaK03JPq__tbnz_vJIm9rEP3rxQTiggWVVPk3Tg" alt=""><figcaption></figcaption></figure>

If you want more control over your scanning configuration and features then you can use **“Advanced options”**<br>

<figure><img src="https://lh6.googleusercontent.com/_RMAEF2J8gu9hGXmCVOaYVKjgSgGX-ur-Sx7Ne0Pn7IG2T3Xh0ETFnYkjeYQ0fuVeiHjQYvo9K6aSLKeYEcbjDsAHhybda55nmR9GOmlY6PPNohswZHyx-6RHenR8u64dQreH89XLHFc7lS02U53BPhGMtfo4JeKCUz_yYxb4wmYXnqBV79SJywCew" alt=""><figcaption></figcaption></figure>

1. **Resource URL** - Provide target address, example: <https://console.clouddefenseai.com&#x20>;
2. **Login URL** - Page where we can submit login credentials for example <https://website.com/login.php&#x20>;
3. **Submit field** - Name of Submit field which needs to be clicked automatically&#x20;
4. **Username** - This could be email, phone, username value which you use&#x20;
5. **Username field** - This is input field username’s name&#x20;
6. **Password** - This is part of your credential value&#x20;
7. **Password field** - This is input field password’s name&#x20;
8. **Proxy Host** - If your website is behind VPN and you have Proxy VPN Credentials for that, then provide Host from that credential&#x20;
9. **Proxy Port** - Provide Port number from your VPN Credentials&#x20;
10. **Scan Type** -&#x20;

&#x20;   a) **Website Scan** - This is the fastest scan and it scans websites without sending a lot of        requests to perform tests, you can also call it light-weight scan.&#x20;

&#x20;   b) **Deep scan** - This scan takes more time and sends a lot of requests to perform different kinds of vulnerability checks.

### DAST Scan from CLI

1. Install cdefense CLI in your Device using these steps - <https://github.com/CloudDefenseAI/cd#installation&#x20>;
2. Now run below command to run DAST Scan from CLI

`cdefense dast --api-key=<CLOUDDEFENSE_API_KEY> --url=https://website.com --project-name=example-website-scan --scan-type="full" --verbose`

\
\
\
\
\
\
\ <br>


# API Scan from CloudDefense UI

We support only swagger endpoints for API Scans for now, so if you have any APIs which aren't in swagger, we request you to create a swagger file using those APIs. To run API Scans follow these steps

{% embed url="<https://youtu.be/AMYMaCTUzdc>" %}

### Step 1: Access to API application

Login to your CloudDefense Instance and click on “Scan” then “Other”. After this select “API”\
\ <br>

<figure><img src="https://lh3.googleusercontent.com/9fmHE141reijUEqChiaPfVqYZO7ontCePjP2jnNsXmV4KWIvhxeFmxtqOaV3sTyR45gdTb3-FiNXxoY_kpRkc6ltym0ixkXFyt4Lp-eqGXNvU2Qz0RSCp4rrbQG0PZIklfSHwhj9Kw6LDCFmzo4XiL16PssFy4-TojCyTIDxhyU06zrS5J1t2ieRyw" alt=""><figcaption><p><br></p></figcaption></figure>

<figure><img src="https://lh6.googleusercontent.com/GQ25WtEtuQdHV6EziO-FZvq2_MqWkXh-iIWv6I3AS55FuBIRGIAMOP15bihJGY4ztovxjHYxLM_a4J4KYSvhx402EsqZVYUZRM10IxlA54Ks7_RIxfGWA9zD6ibLX4JpnuSVNwDirb3Sdv-WQs2v07FpKS0OyQ2VGzRWR09gwMkchAeaqsRSvFlhWw" alt=""><figcaption></figcaption></figure>

### Step 2: Provide Swagger Details

<figure><img src="https://lh4.googleusercontent.com/6FkniAdC9N807-RqxhRKQJaUdpkS7y9r63gYXA9qvd9njDawbvLsW4J2Kf6yywNwe7O3gPzmMwYbszEq1lxxjSPYen6VePGm02gafr16DaFUy1qIfh_7llW1MZtg34sotSufaZIUJBm87skXUEGVJhnA-Fhw1tD8G_HafQnmUVqHy5ajjJXiHBylLg" alt=""><figcaption></figcaption></figure>

We’ll use `https://petstore.swagger.io/v2/swagger.json` for testing here (Remember we need json as output not any html website, there is difference between swagger viewer and swagger json)

In App URL you need to provide (Base URL) example - `https://petstore.swagger.io/` In JSON Path provide full URL of JSON - `https://petstore.swagger.io/v2/swagger.json`

### Step 3: Scan your API Key

Then click on “Run Scan” and your scan should start. API Scan from CloudDefense CLI guidelines are given below:

**a)** Install cdefense CLI in your Device using these steps - `https://github.com/CloudDefenseAI/cd#installation`&#x20;

**b)** Now run below command to run DAST Scan from CLI

`cdefense api --api-key=<CLOUDDEFENSE_API_KEY> --url=https://petstore.swagger.io/ --openapi-jsonurl=https://petstore.swagger.io/v2/swagger.json --project-name=example-api-scan --verbose`\
\
\
\
\
\ <br>


# GitHub Enterprise Actions

{% embed url="<https://youtu.be/uN7ndkmgvqQ>" %}

### **Step 1:** Setting up runners

GitHub enterprise needs “self-hosted” runners to support action system calls if needed. For our actions, we need to host a Linux VM that we listen to for the jobs. To do so we need to follow these steps

* Go to settings -> Runners

<figure><img src="https://lh3.googleusercontent.com/CIBwFlRLRfAt1PcrDVQmKaZxzm_BUbIn5u-cua6qmKNviqnzAFMs6FIjG16d3YEPKFU8i6-KLyw0wIFmbKJ9I81R4fRqv5hPJfYe_Pa8Y7bpalOABkvu7XzA0epMiSqeWV-W7slgnVqNg0R-yYUTq6MjT2ftq7gXa_z_TKrltyXITN3Wykc-ba4-NQ" alt=""><figcaption></figcaption></figure>

* Click on add runner and follow the setups to connect your Linux VM with Github

<figure><img src="https://lh5.googleusercontent.com/mjv1wIHQ8l8i9LyNa78k6b_ASfVY_jMYWiryC12ETLZ2r_b2ZfN3GfirQnWR3A6e4MPufvan7sAdF51lrc1MMhbTYCplbTlx7JiRAgZFIo9Xl2r_kFmrlZpJ9C-R5ZvhVvH_NVGTMi_ZGBhKPc_ThrPA-2Tw89NAidYnMBiNis5hh1CDvlJc3w5CZQ" alt=""><figcaption></figcaption></figure>

We use these above commands in our vm like:

<figure><img src="https://lh4.googleusercontent.com/LSYl9qIl4p-go4i1HWy0jBh4V-8p4-6lyuXqxsvDdmYhMtfSH5vy7i1R9xlHdFP0lURrF5G8Ob2WCMfzespTL42wK3ml498msi0rQY6VjtHNUWsKZwHpNm8azLzc-1ubjat-g9KRW-k3q7gQeuSamk6Eaxs_QKrTDmWXBQ0rzjeM85bKpkvS-eNC0g" alt=""><figcaption></figcaption></figure>

**Note: Make sure you mkdir the same as the repo name on your GitHub. For example, here we made “ObjcTest” which is the repo name**

Check runner if connection “Idle” is available

<figure><img src="https://lh5.googleusercontent.com/rAu-OQz3rhfQoAu0ca3leyoUlGu6H5lIfTF2wE2snhnlWj8VmNsH3YZ1YQ9b4_XytEZMOtSRuB8o9YTVORc8jusE1UbULONHlT_1oWlM4uExcX06E9RMHF8CDfEDx2WWLobMKprOowOXuv8oJh95Rg5cSyvYT8KDT_af6y-aTwC9BPusTv_ANkWSbg" alt=""><figcaption></figcaption></figure>

### Step:2 Adding Repo secrets

* To add secrets (API-KEY). Settings -> Secrets -> New Repository Secrets

<figure><img src="https://lh3.googleusercontent.com/HqFLaKliyviVe-u6N20DzoXC70YFSwHsBSv3Oq-8dTTqaFCtoTd0Rl1TDUVo6iOmHbfHxigKze8P816rYCmHRxPXFwEDuHSaUPuxpcOMXOSpbtoDpnGFEiqdaaQlxyotKlLuDH9DGUtb7CKB8uJY9UHrM0cDj9GAF7zbbsE5jYVQn_Cgb64r3owSPg" alt=""><figcaption></figcaption></figure>

* For our use case we will name the secret as API\_KEY

<figure><img src="https://lh6.googleusercontent.com/pGYHx8_31qQxkJ1ZWmWylgWckZGBCWyskeP19xiTdT9RO1kfP_zjWbn1BIBjtyJWsUWTWjnKPdirtTw1NGiSYlcyrAkLdlbGcH-cozDvZjceX88xMM0mnv0hER2968EXZzlYca7NqGwM7gVDHSqpXnBqoz4E77__zuEUc9S2Cj6QTDGE3CXRtQjG0A" alt=""><figcaption></figcaption></figure>

### **Step 3:** Adding our actions.yml

* Now add our action.yml. In order to do that, make a folder structure like .github -> workflows -> action.yml, On the repo

<figure><img src="https://lh5.googleusercontent.com/EoXjsqC2mDQUSrfvQhuPxkreBGKshEvcH54xNKtCuqW_qOFiemuvRqSXnBDlhhMVjlI-zw5G_9-qyA77WRDeGDsKdfIE-Ootb6ODaAVWDSYRRjy6wZYY3d7SSzeVXQOw3feNItZzT4F5he8GD0wWyklctdnQ2Xjw1UsYU0Igi0K-hbfRPJyKkp65jg" alt=""><figcaption><p>\</p></figcaption></figure>

* Make sure that at line 18 of action.yml we have the same APP\_NAME as that of the repo name
* Commit and see the action run

<figure><img src="https://lh4.googleusercontent.com/U2rmCjJcxDTDWifIU3Vdi72hStEj4bydQEF6tpNBEs4cl4uevTRyGGpvSoJs5_slxxXRUdMPL_03c26T6PRfT_YSN7QCyWvkjDUN0J059UENH1L21-EOX6MDlPvct-jBXnwZUDj4clSuVmJ587M81_mPqEH-8Tz8dOwO4Vlii9DGGSMcF05QMoV_UQ" alt=""><figcaption></figcaption></figure>

* Once the action is done. Check our UI for the results

<figure><img src="https://lh4.googleusercontent.com/VZH7-MgT4fm5ndw64ItujSkyiM1m9CU3Or4zwTuPcBkSOkVJx_2Y_vYlwiH6VLTfGqMbDd17ROSCI75cto874o3MUU0_NMCzCAIG8UQPGPDczAJyxOizptutW0lYsN0ISniexISJ7Zk-d1pou05Ebfu9ZFqxX560hRIFE8HHaIJXMnFCNt1BU7aQzw" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh3.googleusercontent.com/6-WxaZGXVglm0FRhwFqCWaYfhtPu7GeZ23_ATQtcXDy5OvQ3MaapfxlsvQEd7As7CCciSbHs8QkPL9TGwaC5N1Jb6ftoOkeV7X08pkoNmC09Mqx30QmuDejvfMsyvr8nIBlq8_4zPyp0NGE0TxkRUy7Pak5C0pn7SwkXQnhFuNlC9FgzQRtvDlGjbA" alt=""><figcaption></figcaption></figure>


# Methods  for CI/CD integration with CLI

CI/CD integration with CLI Now you can start online scans with the new CLI command:&#x20;

### Method 1: Scan repo using our cluster

### &#x20;`cdefense online`

### Options:

`cdefense online --api-key={} --repository-url={} --branch-name= {optional} --tag={optional} (You should have ENV variable SCAN_URL=https://console.clouddefenseai. com)`

### `Example:`&#x20;

`cdefense online --api-key=76858509-fe91-4969-b57a-decc36d0726a --repository-url=`[`https://github.com/mono/mono`](https://github.com/mono/mono) `--branch-name= example --tag=example (You should have ENV variable SCAN_URL=https://console.clouddefenseai. com)`

Command will return exit status 1 if build policy was failed.

### `Scan private repo`&#x20;

`We also support private repositories. To do this you need to provide API key related to account where integration is configured or provide an access token into repository URL:`

`GitHub:`&#x20;

`https://{private-access-token}@github.com/username/repo.git`&#x20;

#### `GitLab:`&#x20;

`https://oauth2:{personal-access-token}@gitlab.com/username/repo.git`&#x20;

`https://{username}:{password}@gitlab.com/username/repo.git`&#x20;

#### `Azure Repo:`&#x20;

`https://{private-access-token}@dev.azure.com/orgname/projectname/_git/repo`&#x20;

#### `Bitbucket:`&#x20;

`https://{username}:{access_token}@bitbucket.org/username/repo.git`&#x20;

### `Example output`&#x20;

#### `Without verbose:`&#x20;

```
// cdefense online --api-key=76858509-fe91-4969-b57a-decc36d0726a --repository-url=https://bitbucket.org/kilaruoleh/vulnado 
2022/07/15 16:59:52 [INFO] Connecting to server... 
2022/07/15 16:59:53 [INFO] Welcome [developer@clouddefense.ai]. You have been successfully connected to [Cloud Defense] organization 
2022/07/15 16:59:53 [INFO] Running full online scan... 
2022/07/15 17:01:19 [INFO] Scan was finished 
2022/07/15 17:01:19 [INFO] Build policy status: FAILURE
Failed build policy results:
 /app/pom.xml : java_maven: 
- Rule [CWE PART_OF_OWASP Injection] failed. Number of occurrences: 1 
- Rule [TITLE CONTAINS inje] failed. Number of occurrences: 1
[INFO] Scan started at 16:59:52 finished at 17:01:19 
[INFO] Total scan time: 1m27s
```

#### With verbose:&#x20;

```
// cdefense online --api-key=76858509-fe91-4969-b57a-decc36d0726a --repository-url=https://bitbucket.org/kilaruoleh/vulnado --verbose
2022/07/15 17:00:16 [INFO] Connecting to server...
2022/07/15 17:00:16 [INFO] Welcome [developer@clouddefense.ai]. You have been successfully connected to [Cloud Defense] organization
2022/07/15 17:00:17 [INFO] Running full online scan...
2022/07/15 17:01:43 [INFO] Scan was finished
2022/07/15 17:01:43 [INFO] Build policy status: FAILURE
{
  "/app/pom.xml : java_maven": {
    "failureBuildPolicyResults": [
      {
        "message": "Rule [CWE PART_OF_OWASP Injection] failed. Number of occurrences: 1",
        "rule": {
          "operand": "CWE",
          "operator": "PART_OF_OWASP",
          "value": "Injection"
        },
        "count": 1
      },
      {
        "message": "Rule [TITLE CONTAINS inje] failed. Number of occurrences: 1",
        "rule": {
          "operand": "TITLE",
          "operator": "CONTAINS",
          "value": "inje"
        },
        "count": 1
      }
    ],
    "passedBuildPolicyResults": [
      {
        "message": "Success",
        "rule": {
          "operand": "CRITICAL_SEVERITY_COUNT",
          "operator": "GREATER_THAN",
          "value": "1"
        },
        "count": 1
      },
      {
        "message": "Success",
        "rule": {
          "operand": "CWE",
          "operator": "PART_OF_OWASP",
          "value": "Broken Authentication"
        },
        "count": 0
      },
      {
        "message": "Success",
        "rule": {
          "operand": "CWE_ID",
          "operator": "CONTAINS",
          "value": "264"
        },
        "count": 0
      }
    ]
  }
} 
[INFO] Scan started at 17:00:16 finished at 17:01:43
[INFO] Total scan time: 1m27s


```

### Method 2: Scan repo on your system, but download repo from external (any git)

Example:

{% code overflow="wrap" %}

```
cdefense clidocker --api-key={} --scan-url=https://console.
clouddefenseai.com --project-name={} --git=true --repourl=https://github.com/scalesec/vulnado --branch={optional} --tag={optional}
```

{% endcode %}

### Method 3: Scan repo on your system, but copy project from your PC

Example:

{% code overflow="wrap" %}

```
cdefense clidocker --api-key={} --scan-url=https://console.
clouddefenseai.com --project-name={} --path={path-to-folder-with-app} --
repo-url=https://github.com/scalesec/vulnado --branch={optional} --tag={optional}
```

{% endcode %}

Command will push data to console.clouddefenseai.com


# CI/CD Policies

{% embed url="<https://youtu.be/pcBv8wQtnfk>" %}

During a CI/CD pipeline, there are multiple ways a developer can make a build pass or fail by using <https://console.clouddefenseai.com/compliance> policies like the following

### OSS Policy Licenses

<figure><img src="https://lh4.googleusercontent.com/GxSgQ2O9XajmpIwv64nHVbtFUAX-CWlmENglNZ2qJq0VDLbtFT6T9-2j-975QZRBmaZRtQxJLRteWTqMzwI6EXEeCEpQ_qMCDE2yLaAS2FV7qi5Lhv6Of539ktMqe_5iXRdMkFUFBfFw-yncQDDjUZf4V3uWS3fp41xsokArS56iwu9uOL2aFOC5rQ" alt=""><figcaption></figcaption></figure>

With this a developer need to add the license either in Approved or Denied list via drag and drop

<figure><img src="https://lh6.googleusercontent.com/sZQ8OFnsSroJq3YH1w8PaszlRxRdYl0_KJUvssZxzPJla1KmTXAWsjrG50KFxvDhjme_wre5mIE1rJRCFQqS804FjJ-9eU_XmsJLc1uxNo9QeZi4TSliIn11fCDaUBXFDv6Y8M406cAWd09jLvKfC-jke4fb1S1lDMwTEkqYiehQ37Z1Z8CN5_A8qw" alt=""><figcaption></figcaption></figure>

Any license detected by our scan, if it’s in approved list the build will pass from the CI/CD if not then it will fail the build

### Build Policy List

<figure><img src="https://lh3.googleusercontent.com/AiO8jtexrQSefIZquQcwhBYr94p98AwR40PFNBEElM3FTsF8LZJUGWPmXq2qDaPMtsHn6fq3l_1TMHPKfncLceEk3Po0g0FbGlUXSqV6ITvuEaPvw6-ydM26LFAWS6JUc-bHOGRmxMfbGJ0qQ6e-bVEmUj52eyfuunyp8F2mS8St-b79TS7bGHzFUw" alt=""><figcaption></figcaption></figure>

With this feature a developer scan pass or fail a build based on the criteria like,

1. Secrets Detection&#x20;
2. Owasp Top 10 Detection&#x20;
3. Vulnerability Count&#x20;
4. ID/CVE/CWE Match

<figure><img src="https://lh4.googleusercontent.com/qD99DPDMaP1Bun-3yhheeOoLoZjhYMak79sLA9-Semc62TEQkhTVyqIJRjCFiFknrJIY5MrNXYSD67lIs3-oYKnw5zk9FNYi8HTl2YDjYcKkF854M3t2in5Gt8BXDqRFKmjDJVrD2xrDghvGZQ9j_kib_Zz7232ZwjWbMmC89cM7CStm8Q1QWfzgJA" alt=""><figcaption></figcaption></figure>

Any number or criteria set can will make a build stop or pass during a CI/CD pipeline


# Jenkins integration with cdefence

{% embed url="<https://youtu.be/Z4GQXNKOFok>" %}

### Setting up pipeline script

Click on your JOB -> Configure and setup up the pipeline script like following

<figure><img src="https://lh4.googleusercontent.com/WE6_jKzzFSz62E4YRqYesVtaj8PZVrEOAF1db7YiAmONMOSfibxvJ1QXM78wPyQ765QjbLjTo7ImDYWdFTEbDkcR0_EMyW4JzENK_wJU8VZg0i8AyR5fgoK5SpyK9P8ImupshqHbmbaKx3e-gxhOZFJjNPgwH1tiTnhODEGq6TAeYLcPeqO5qslWxA" alt=""><figcaption></figcaption></figure>

From above screenshot we conclude that,&#x20;

* We are cloning the project we want to scan&#x20;
* Getting our cdefense cli&#x20;
* Running it against that project

### Running build and results on UI

Click save and apply and hit build now

<figure><img src="https://lh6.googleusercontent.com/Ve0JoIsrQunQzRFVluTKOxRP5sohGlRJaDs_mAwXFohxBZHfGmDma9PG04hCzHZlcF9ZGjr6umXK6Uk3dGvaYPI-l0QZasY6QRUur83IBZ4srYICIUO6rB7M768daZbMrllK7bggzwklvRfEFjhrCVr_05ihlQGRlHr2_atkLAPKmGOru0k_jEdgxA" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh4.googleusercontent.com/g9dUsr3vX51sUT3Dbeyq4iWfCCdegumUKa-s3yYgFl-Yi_D3YoToNAibPHixNkg8jG2vVLEyE4mi-KDBYFwBnnYnHQ00ZXf7IitPspcqNZ76fGJfaFkZBFJe6-qywGmxqBF1GCS1riRfONLcwNm3ROTEtY3gMDjXUe1zzxuMRjy6NHakiWm2R38FsA" alt=""><figcaption></figcaption></figure>

Once it done with the build and cdefense cli is done scanning you can see the results on our UI

<figure><img src="https://lh4.googleusercontent.com/41SoXnjcYw1tzcF55x9RXl8kKGIuvVUNkcgidrwRGWi_B2ZrVT89z1RlLfBwwiNUYUSu5zZvlwCq6jYdxqYTG80p47rNC-X5GLqVLvpTPDCednUXJuybGrt5XB7fWoVJJzBZ8jQCRsGnUs_R8ZGoK-BcoHYL9kYJd2YZZ627TcruuxgPwRV2IBczTA" alt=""><figcaption></figcaption></figure>


# IaC on GCR Scan

{% embed url="<https://youtu.be/uYTivs_22to>" %}

### Prerequisites&#x20;

* Google account&#x20;
* Created project in Google Console&#x20;
* Private repositories with images in Google Container Registry&#x20;

### Scan Public images

Go to **‘Applications’ -> ‘Scan’ -> ‘Other’ -> ‘GCR’** and insert name of the image you want to scan:

<figure><img src="https://lh4.googleusercontent.com/OyYOKQmoHNRRwu1XoJEBDzm8g-fd9QYPXusqs2BmaKcCHgXO69KpK9sYZ9nIuVCK1vSiAGoY6TIBqNJBeGzW1ZyVGxhdWRW_WWuJz3e-4Jl0qGgw76DSgPVUVMzTxaQHSU_nppAG04YCUrYm0kkIQZ9IWH5v9mXnDra3-i9BvwCuu7PmNF7voJSzYA" alt=""><figcaption></figcaption></figure>

After the scan new application with the name of the image will be created:

<figure><img src="https://lh4.googleusercontent.com/UZjyQ5E1ksIt-3m65TF2jJQJPECnowIMMHCwKtAjBe9J5cocxO3VkX3GUWs4m0-hUdLRfznzLSY0RKV6I4A24W0hhogwG6Re67N6exbUw5pdr9OXJKHPvTVoneOuX0EsiK2QKRk5Rjx2f9iezAAzHkyACxy5Pu0nGds5RLA24AFDL3ZAZSJJKEZvMw" alt=""><figcaption></figcaption></figure>

### Scan Private images

#### Step 1: Create a Service account.&#x20;

Go to ‘Google console’ -> ‘IAM & Admin’ -> ‘Service accounts’ -> ‘Create service account’. Fill ‘Service account name’ and ‘Service account ID’:

<figure><img src="https://lh4.googleusercontent.com/pKESeKQhJ3i9s8zbArY5e7zug4qQzvgcIliwlTeTys1BeP3pMlOknD22x04oDCTy39TJR0fFYV6uVrUgH8QoL2pBbLC5x_74zisFIX0CW86VDh_dgSzN3504JHl7l5Y4gKIP9CGSEMeSg83zCnhv3F86NPFxTGBS0Wzh3f9rac0lTFA6kz5Qf_EtmA" alt=""><figcaption></figcaption></figure>

In the next section select ‘Storage Object Viewer’ role:

<figure><img src="https://lh6.googleusercontent.com/aD_SQiYUoLBalVbySIoEmVTKz5UgTLscoUSXmVWz3hpQhiOpoR9mWO-8-Tt1Tzo4VTWdRj23pxpR81lXD35FjdCR8sj5HO-iSzTVubyG-aUEo26Xs0W6ZSuIsP7L4QapY7ZKw7oFCthEBrJRlA6Gkhj9QLzMERoOkxcQ2WmKdjh-dJ7s27GxOMMXFA" alt=""><figcaption></figcaption></figure>

Click on the created account and go to the ‘Keys’ tab. Create JSON key:

<figure><img src="https://lh6.googleusercontent.com/NBlI26PATPQ6sf_Cf-1hcnydkBHoBI1TeOoI0o2MgtUrVpLW6UFHXjhnVrkNmmiV2BHvbyrGmLsJy5cpQA4puXZe94_07w49Ezw_Gp_fgx06dfbef8B1sHO1z1LyIACYyfE2BHDMFITFjPdgOY4qYECDHGAzeQqPG16z3i9LDKio3UoI9hBs844zIg" alt=""><figcaption></figcaption></figure>

Credentials file will automatically download.

#### Step 2: Add Google Container Registry integration in CloudDefense.&#x20;

Go to ‘Integrations’ -> ‘Container Coverage’ -> ‘Google Container Registry’. Choose downloaded credentials file:

<figure><img src="https://lh5.googleusercontent.com/830hvhya33oknzF5ohescKnANf820LZd-NFCKQZ6OhDcsZOnBpFGdISC1NklXXs9eSTQmcA1zF-p_7TsSfXCF38_g3naJg3uYPOmfwC85q9PtLM10YgvG5eoisuI8GzZjzpzaaO3aD36OJf64lfbLLcQ9-_Rg-Ih7_UI-aXzoRogOuP1OvXBOT9g2A" alt=""><figcaption></figcaption></figure>

Click ‘Configure’.

#### Step 3: Scan your private images.

After successful configuration you can scan your own images.

Go to the **‘Integrations’ -> ‘Container Coverage’ -> ‘Google Container Registry’ or ‘Applications’ -> ‘Scan’ -> ‘Other’ -> ‘Google Container Registry’ -> ‘Your own images’.** Choose host and the image (images) you want to scan:

<figure><img src="https://lh3.googleusercontent.com/i3eaj0AzOcJG2Kg23rE7MggfPFKvjCzZS65_hwnUQv1n5kVJJN8KruTmczyfYppOPYmUrx-tGPPNvydMR183MjLo7T7afFy3mtmU4qCPMboLJCE_A0Cu-zGpX-W-8Ek0DfJUyuHgwtVbPhaJnbsxxKCw_FVoB208nWocuxbB8k38lubmQt0aG7DAWA" alt=""><figcaption></figcaption></figure>


# IaC on Amazon ECR Scan

{% embed url="<https://youtu.be/LzDqc6wMQIo>" %}

### Prerequisites&#x20;

* Amazon Root user&#x20;
* Private repositories with images in Elastic Container Registry&#x20;

### Scan Public Images

Go to ‘**Applications’ -> ‘Scan’ -> ‘Other’ -> ‘Amazon ECR’** and insert the name of the image you want to scan:

<figure><img src="https://lh3.googleusercontent.com/lxXf98cO4JSw9Fxxdcm5OWZpWeTN2OBVwGvLlfkERxk4Y0sYU5EOIfAXkr33IYr4b-BtuXrF4sXvCqkRalv2sGGunaYKDg8o8g2exQQBz8FwAkIlp-buQtYkVr_t_fYvcVHtaCJcwla4eWcIP1-wFwt86wAff4xcTh8PvoHZkBr-doopidjeXn22Uw" alt=""><figcaption></figcaption></figure>

After scanning the new application with the name of the image will be created:

<figure><img src="https://lh6.googleusercontent.com/UwshXFUy8XyAVnJaFnljqdltK-yoLqhR-wTo7X8C3C69DCWUTbKW9WtHuymJY_PhdtN55x1kT4j34kntqsjACtwtwRcdW846EraMepnd5jZq2g_JyKN8--r3oblJzYhjSZCHza1QwGuYPsGnGUI5SCZZ_5yMvs_zXp13W2h1Sdtr9Gx1YBQ_SSSWlQ" alt=""><figcaption></figcaption></figure>

## Scan Private Images&#x20;

### Step 1: Create an IAM user.&#x20;

Login as a root user in Amazon Web Services.&#x20;

Go to **‘Identity and Access Management (IAM)’ -> ‘Users’ -> ‘Add Users’.**&#x20;

Fill **‘User name’ and select ‘Access key’** credential type:

<figure><img src="https://lh5.googleusercontent.com/QOO0hagTUWpMR4840kHMjfAn_RZhvPtyRX1z_k_2MbnOn3ARN2hMo6CadMHNq8_crNnH5eNJRgdQ76TWwSV1Z24TeBOT3KkHBdf7D1jK7Frqo9XpG3EWlEiQepg7PXM5Re5SjydU3-n8epxavejnk7ZtJOrlbuKTAQU__ulmrT212O87qDbviY1X2w" alt=""><figcaption></figcaption></figure>

Go to **‘Attach existing policies directly’** and select&#x20;

‘**AmazonEC2ContainerRegistryReadOnly’** permission:

<figure><img src="https://lh5.googleusercontent.com/87VQ5nOxuO3or_n5sH2oHVbBlGLNlZ67FzaAlIESbMASBBS9-oMgT2wLhX09NCuRieNGFu5TND84FT0_vYNHwBSH-6M0KEHRlYrkhC_doY7PN6qelNm1xATcHiJ40QpSI8yfTl0hyfUQIzyfbOeCrMFdYnGvTMpjSCcJgpN8VL28iEHA7teRo6d6ew" alt=""><figcaption></figcaption></figure>

Click **‘Next: Tags’**,&#x20;

then **‘Next: Review’,**&#x20;

then **‘Create user’**.&#x20;

Copy **‘Access key ID’** and **‘Secret access key’.**

<figure><img src="https://lh6.googleusercontent.com/TOObCXvs4NcaoGIthNiEFBs6IUAmdVcyxEsFmYjnZkre0tcdGa-ebMOGR4B-bFIShsAQw01r95RvGqPD02_grYu45qcmq6OpOm-W-aupIojNyaWTQ_-JVaPVAPHuwY9UohffPByDkjouAS5sOTXy1xnEWwpmJyR8FuEVANx0CVE1kCpIMe8zRrjhVQ" alt=""><figcaption></figcaption></figure>

### Step 2: Add Amazon ECR integration in CloudDefense.

Go to **‘Integrations’ -> ‘Container Coverage’ -> ‘Amazon ECR’.** Paste your Access key ID and Secret access key, choose default region and click **‘Configure’:**

<figure><img src="https://lh6.googleusercontent.com/PE8uSV4UbwfxS-RKZ0QAm19pWWbn5Q8-fvwGlNE6h8Aznd9bw9RKGxlYMzeXoRIKKbIjkdfIzJpmnuJsp2i8EXoZ0uNC4ZU0o70p6kPCJ8DXctnXJEOKQwK_qYRj_maabtTFROsr_bMJXB0JE1JBItfb93C36e9eDVrXkeKsT2xyzIxwSBb082_gmA" alt=""><figcaption></figcaption></figure>

### Step 3: Scan your private images.

After successful configuration you can scan your own images.

Go to the **‘Integrations’ -> ‘Container Coverage’ -> ‘Amazon ECR’ or ‘Applications’ -> ‘Scan’ -> ‘Other’ -> ‘Amazon ECR’ -> ‘Your own images’.** Choose region, default one always will be selected (you can choose other default region in integration configuration) and choose the image (images) you want to scan:

<figure><img src="https://lh6.googleusercontent.com/991zMvSIaeHlHwMlHBNVic6DMZFUJ4VDHkcrSed-Pf1jt-DiuByHiz-M5x5QROUX8QqlP2fzymv8-Rat17pA40V7qaESjPWXEj8Tj3F5UOYsnST9-cu93M9mlkl-VguqgFmIYKu6PLZ-ENl-mHRbrG0f6R_n6Kf4L9uexP00ytzaU2jS8G_H93JIkw" alt=""><figcaption></figcaption></figure>


# IaC on Docker Hub Scan

{% embed url="<https://youtu.be/c2grj-xHz1o>" %}

### &#x20;Prerequisites&#x20;

To integrate Docker Hub, users must have the following requirements available.

* Docker Hub account&#x20;
* Private images in Docker Hub

## To Scan Public Images

Go to ‘Applications’ -> ‘Scan’ -> ‘Other’ -> ‘Docker Hub’ and insert name of the image you want to scan:

<figure><img src="https://lh4.googleusercontent.com/BH5KruePuddcBJortzCuK7eoQvhNWJoA8em5Ep8UAWQS_afI5WLEFqL3DIlssW-NFD7BlgQdVVqXCMFeStYHjWv5HWC86vVrw6yDyDYpzcZQeUsh9wdTxSzDJNsutsGtcKh9GSRwLAOf4jHvs9lKulzVkY7Pu8KVPEA5-HFL6Mnj81HWaVTwsky1Lg" alt=""><figcaption></figcaption></figure>

After the scan new application with the name of the image will be created:

<figure><img src="https://lh3.googleusercontent.com/-4xum4gxCbDsaE1s2PPy-ULKrVW4T3ClTDtz8ESAR6pXBKuM3lTghdic3Bo5jFL6sHjIFre3HkBSo8XzoAHV6tp8yRHAFP1wtSeSeNg0dYVZWGJsPaAYUiQkovvg8Ii_UL6hY2WFCZmFAzP9JoxNLbgPRbo_1gFMJhiB1xdDsSLIQ7t7eSnFX7TWvQ" alt=""><figcaption></figcaption></figure>

## To Scan Private images

### Step 1: Create Access Token in Docker Hub.

Go to **‘Account settings’ -> ‘Security’ -> ‘New Access Token’.** Fill ‘Token Description’ and choose Read-Only access permission:

<figure><img src="https://lh5.googleusercontent.com/WuCivPo6G8Isx6ANWzYSrD6YhtcPWbbsQuuNB0cvtfIcwZ_kzHG5lO6cuyJ0IVJoR8gz500sk_EAUPUPg1P7-cpEIpwc62SNcGZxXIfF_buzJbuKd1OthzILPJkNMGQR6D_ZSFDZsWDRzDJjaAjcXcUlB8r0ZCasLDN4cWAEMtBy68Tz3MI4Xo0bug" alt=""><figcaption></figcaption></figure>

Click on ‘**Generate**’ and copy your Docker Hub ID and Access Token:

<figure><img src="https://lh4.googleusercontent.com/sTT4pQEeATXYg0iBxqTagJSs820n3RMrqG-qU839M6_ODlqW1dZxcgJ8ZpORf6KPerga1ze2v3G-NgTNalWcMO0Mx5oSQBzTwj-zFmWEvU7XVe4b5L6tIjC06S6__3zay6qV6mC0OIdqYLnck4tZ5bMg75bQynjrKmRHGqv0sCtmmtBZPzBRCY053Q" alt=""><figcaption></figcaption></figure>

### Step 2: Add Docker Hub integration in CloudDefense.

Go to **‘Integrations’ -> ‘Container Coverage’ -> ‘Docker Hub’.** Paste your Docker Hub ID and Access token and click **‘Configure’:**

<figure><img src="https://lh3.googleusercontent.com/54IaLZcUHRgHEZMgogwTSPvbqbH39jdggUaxdR8Aa0FldEjLPphygIzek2a9AklZXqFl_ZsihBsbQQ_4FNt9Etn0BX46giIbd2WfNJN0qn5ug1XgfO9r7hKkSXWLiL6SY_pga0s96meUVB6Zp_auShtromoXs9GKhnOhIckACqtRi1Se6X51VcX_ZQ" alt=""><figcaption></figcaption></figure>

### Step 3: Scan your private images.

After successful configuration you can scan your own images.

Go to the **‘Integrations’ -> ‘Container Coverage’ -> ‘Docker Hub’ or ‘Applications’ -> ‘Scan’ -> ‘Other’ -> ‘Docker Hub’ -> ‘Your own images’** and choose the image (images) you want to scan:

<figure><img src="https://lh3.googleusercontent.com/0xBsZzPTESJIJkFsMfPRQQZJDoKr_GBtU01tyJAocxQ_FabpGUlcnYfKyVO0VnnvGkr7PSMGivjktpnmG2id9vy3epRlHxPLIcUYbZ5Qou8Rq5uqSlpkHsFp7gsiYDTsH0ZpgXS8M8EZjxssv_RPdH-xBZjRa-GZpcDYQdYQq7gn4T8mQdzIjPZPsA" alt=""><figcaption></figcaption></figure>


# Integration with ServiceNow

{% embed url="<https://youtu.be/F5B3gmemr5c>" %}

In order to create a new integration with your organization’s ServiceNow account, please consider the following guidelines.

### Step 1: Select ServiceNow from Integration Tab

Once you are done with team creation, open the **Integration Tab** and then click the **ServiceNow** option under Team Tools.

<figure><img src="https://lh3.googleusercontent.com/lY30tsDKNOEu9JuRdFUVWqe69FO1TfxhNgFR2wecMQvj_y5Vl7xdfROHC4EO9FkNsiZ-Tmo1put06RV7AEM3GjKVP6FpyqeP3JslXVxTZ4TjxRMU04-PVHiCsq6n91e4p5FU1JWKelx7CLrqsQ85OwRs0E3CndCdxRFm-8vAOvTyAY9RyTE_2Ox1rg" alt=""><figcaption></figcaption></figure>

### Step 2: Create New Integration with ServiceNow

You must select the **NEW INTEGRATION** button, which is indicated in the accompanying image, and enter the necessary data for your team account to link with the team in order to integrate your existing ServiceNow account to the ClouldDefense ServiceNow Team Tool.

<figure><img src="https://lh6.googleusercontent.com/zsJA0ZVMbYlgczOaQXwVNrbjsCST1AhFcmZO7ebhIqVE57iBX5gvphcGSJu-gxjKMll4JINi_WpL84rpcM-F8fsDevzHRVT_6MmQJ5QepiXNgrZxIBw7gJ4NCExF2Mls2qI0XzJQengRHgAqA_lb5RjRrgKBnQ-FGzHtjSRVhxPvfqKTftZ8f3xMCw" alt=""><figcaption></figcaption></figure>

### Step 3: Input necessary information from your existing ServiceNow account

Please enter all the data required for your team (optional), project, and ServiceNow integration credentials. In order to effectively integrate ServiceNow into the Clouddefense product, kindly give all the necessary information. To help you understand, we have included sample input.

<figure><img src="https://lh5.googleusercontent.com/S7fm4FJyIPoP2FNoBx_2RDUNlbbvSCoTfsHzTHq04nWwHZrQqdm-ltjnt8As5FTg9V622rwcYBe_bV9uvT2yD-4FXwFuuRRBP2TvBRd-NfZKdIjVk3XcWZwJd0YOZC3YraG4RWk_bbpOjagzt8CO29KMUo7bOOPo1RB4lKL6Vyvz-2Nnb1i47HO2zg" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh6.googleusercontent.com/CzKqKfqkFXa4Un0C15l_suI-OqIhA3sI0uHY7yDdomGOqWhdezy-vtee_f3tGuGKzJRCd7-oNi2Yg8l40FVuLDDIMJ8JTu5XR8jAyApN7JEFTsj-Ec9doaQY4T2B1HADmnXbvkN-cGyzB-_ggqanzMbDp1gpI9N6zJNGIp0GAshCgMaDjFD8F3vtbw" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh5.googleusercontent.com/165YrW1uNNTERS_2uOa5NJDAnldtH_DK9r0qkl7QuOd7GveOx1WoKUBXV6dhq1L7Zh4if-TD8-dYPQanxu79owVkttd5FLt9Cs31hsId2lNYua8f9FECS0U8T9XUzbJMQk3QRsbGeGfzLYyvWYX4snQYqIIdCq37hVbZ_fo3nWYIf8aR5cvMoI9McQ" alt=""><figcaption></figcaption></figure>

### Step 4: Integrate ServiceNow Account

Once you are done inputting all the valid information, then click on **INTEGRATE** button.

<figure><img src="https://lh3.googleusercontent.com/R9rZf9qgxWSDAuj-M0poImJYVQ7L0DeElWElJoBWCPB5Z8JOhCTrXSfJRYzdjCb-1OvEuf1Wt_C-PWVjBPyl0pjHUUdRAqiEFs73XgjtYD8V3xKIo1Ag_jpoVCMsHmrtNSPnS0kEfeDk5mNI0zOfvm7smM3vOV6wh_FGYQWz8n0sUPBWWtuS2vtvkw" alt=""><figcaption></figcaption></figure>

Within a few seconds, the system will successfully merge your ServiceNow account. The indicated interface will appear.


# Integration with Jira

{% embed url="<https://youtu.be/kQE--qdze8w>" %}

In order to create new integration with your organization’s Jira account, please consider the following guidelines.

## Jira Cloud

### Step 1: Select Jira from Integration Tab

Once you are done with team creation, open the **Integration Tab** and then click the **Jira** option under Team Tools.

<figure><img src="https://lh5.googleusercontent.com/HaDJk3QEphcQzuaijYa_1JqafcZM7wKXieRw5JIph0T6aupOhwTJyBa0xk5KnMTfX-NVuBq55e4jcC7uwjH-7Nf89LxJyQa6B4pbMItB8AIPnZex1idnzIEe20eRFBrpxdCC9XjaLxw5OK5Dh0QvaZGwKE0it-ztfo6PMnMKHPwxSmClj9ZWF5N1Qw" alt=""><figcaption></figcaption></figure>

### Step 2: Create New Integration with Jira

To add your existing Jira account with the ClouldDefense Team Tools Jira, you need to Click the **NEW INTEGRATION** button as marked in the following picture and input the required information of your team Jira account to link with the team.

<figure><img src="https://lh3.googleusercontent.com/QK7YCQLVfiG47sPEmWdyqeO_B4jNNvv10lmhQVN-reKoJRtKXS8aHByRAGvFLKRbkVdUo5jIt0a2m1zi_DE5DNw3ExW8_spzZ7P44gar8bbNH5s3uvN4d80q-M7Tm8SibUCz9FV4TYIF-auppiDstmkV1yceE6leRjJXvwFqhMcOA0_KOb4fUkbT6Q" alt=""><figcaption></figcaption></figure>

### Step 3: Input necessary information from your existing Jira account

Please input all the necessary information related to your team (optional), project, and credentials for Jira integration. Please provide all the valid information to successfully integrate Jira into the Clouddefense tool. We have given sample input for your better understanding.

<figure><img src="https://lh3.googleusercontent.com/n0XKC5d7MhCRq3n4tKXDjSxPxMSr2Q2VuINZgHFLm3kUhAhM3WBvLTfEnzj7Hynqpn-bL2LRxgYAg8UkyK0ENuLR6PzDCo4Hexwxwwt1iKgQos74Wism7vt_t31lgweMQrjrfDXNImbw2XwRpvCRvu5Qb2IzHq5Xi03NC1BwfQuv2nW-6Ml2gr41NQ" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh6.googleusercontent.com/ITPwAMoB39OC3j_CIipOZujLUtFiIaCSfWtK8kwINf1sZTuyrLjj1j0euHN1EOkiykWnW2WC0XOcFPbbK6umU5KIPqKSN7GNPbawTiozqsswBGji0xP5ySxAUEvPbuMarAzBHNd5BniI3nliRwskO3qUaNWm8EagIQW2Chfkl6wl1BvEt9pbQ1zATQ" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh4.googleusercontent.com/eySttXU35eAZtF7Qe11zP1my4tzudtRZcrc8xB5apkzUgAODjkcQUUwjceEEXyKvpDasj3UusTcuh5y03QPqpXpfg9OXUjUDOKHbva5k1RIv_zMzQ1FVf9ALgGcfqoXg-EJpIGVpRch2ZbDsEkY20gYz2tW-AJqoZ_60gKKPxy-nzBa82hI1Svu89A" alt=""><figcaption></figcaption></figure>

### Step 4: Integrate Jira Account

Once you are done inputting all the valid information, then click on **INTEGRATE** button.&#x20;

<figure><img src="https://lh4.googleusercontent.com/TTmG28l1BrpoqJ9YHgZNdVxu3WrY4njXwBH5Z_AF7FSc5p-aVBhC_y9BQw3GvEgbMPDFYHOJeFkSlGggzrXps53klYVBa2kS2wAC2uOdx_-zPs1fRpMgKSKK9ubuwQcqMXkVW6CiRHAbi2Jq4uvqd5LHgvb8QHJyhXj_6_j2lNEDkfwY2D2IB7iTUA" alt=""><figcaption></figcaption></figure>

The system will successfully integrate your Jira account in a few seconds. The marked interface will be displayed.

<figure><img src="https://lh5.googleusercontent.com/-KYetJWiwZAUIPDmWc4l7L-Ttslym6ynIzVqNsf3RR_ORIwu2w11Kmdf41PXrJflm0bSmzAL5m-sXcEm9A9WpzEPqRHMIYtDpq2MVzO44cUYYjvmMI32S7uA0Bn9fW1MS_b3e6rnCrqrqDEnw0LNaPhi3GonpvmkZ6IAHboDVuk_ifodtaY649AMiQ" alt=""><figcaption></figcaption></figure>

## JIRA Server

### Prerequisites&#x20;

* Users must have an existing Atlassian account, which requires: JIRA Software Credentials

### Step 1: in the integration page, select Jira

<figure><img src="https://lh5.googleusercontent.com/3h6gCUfML9k1K5iFpS8xK_e9zW2a-3rO_f3xrlXVbscrn4_SZGIZIGOgpXnjkdkJChVzoKYmUKo5-cfBBrNcPPn9pZ9FRhna1J5GsqxEr8JfiCoXQJec1j7b0qb80TViofFyqrZ9Lafa1HXqgptnd9usJA0hoPziber2FfkT-axJXCMQM0M84gb73g" alt=""><figcaption></figcaption></figure>

### **Step 2: Check the "Jira Server" checkbox**

Now you need to go through all of the previous steps mentioned above until you see the "Jira Server" checkbox:

<figure><img src="https://lh6.googleusercontent.com/nQlkVuBMXZxQrGQTmLKO5SSfaSA3jQZ8Jk2e0UIZn0AvyM8OTFJ-VUKAyXvr77Rfyw7UUyOrOeyzHuLfWs1RNRwv_ws0b6VncUoz5kuyIHqEXk8u7S97EgwaXjs0or3TG68_Mg832IneAYv0dzg-DQSYBp4yEiRQKosbs8QCv_DaAnrlLk_-HtTPgQ" alt=""><figcaption></figcaption></figure>

### Step 3: copy the project key from here

Please copy the project key. Here is an example for this:

<figure><img src="https://4095801085-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtErerJyslHxJo5moBxJo%2Fuploads%2FJJdebyjwl5MXeCRpcllJ%2FScreenshot%202022-10-07%20at%209.53.40%20PM.png?alt=media&amp;token=6ed85fc1-3f14-478a-9b0e-320d407f3579" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh4.googleusercontent.com/2_fmExF_oBuT9Dk0j6v5uxGdhpSlddjds57YvjhNR7tjKrWFJ4XAuQrGOJ5dAEs7d6bjSPppJE1dgDB9kg6YHYMWk4LF2-vUnY61Pj56qv-wfGuMovikO8iEpGAnJXpNf0EqZFhTKO7yAtplmpf9ZEsnBsEHvk-RCw04hsCisbupayvl9YdoKFl5kQ" alt=""><figcaption></figcaption></figure>

### Step 4: Input the “Domain name/organization / Jira server domain”

Domain name / Organization / Jira server domain is found in the url of the project. For example:

<figure><img src="https://4095801085-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtErerJyslHxJo5moBxJo%2Fuploads%2FyQRwFIEqBT6JlNjuLqwJ%2FScreenshot%202022-10-07%20at%209.41.51%20PM.png?alt=media&amp;token=a7aca716-b1ab-47ca-98e6-b0747bb46cbb" alt=""><figcaption></figcaption></figure>

### Step 5: Type the Jira Email and Authorization key

<figure><img src="https://lh5.googleusercontent.com/qslCIuvhRrhP67qA6O-dXLOJcId88KjkrhVu8eRbOypl7671b2Pm5CJCCpCzk2MwjfyPoNCVuLkV8FjP-Q7EplGW6LxugFStNf2mR-3Z-TW6PRfyJYvXCYcB5gOqTCh8OIKvUyKLEBaKaKOyRsPLEzDIkUfAz-jeZ4O1w7eXL8QGWaMKOIyvazic8Q" alt=""><figcaption></figcaption></figure>

#### Create Jira Authorization key and generate a Jira api token.&#x20;

*<mark style="color:green;">Note</mark>: The Jira API token will be used as the Jira Authorization key.*

*G*o to <https://id.atlassian.com/manage-profile/security/api-tokens> and click the “Create API token“ button for generating a new the API token.

<figure><img src="https://lh6.googleusercontent.com/8pMbUJmGtcNfQtNjHPa4iWMzKK6FDuukCJvuk2zgJI_VzeFc22qSKV74gRkVMbs0XzneRwK6afQ_Z1BU8rvEFu9qjHMmxsKVO4aueH7i-yI7uf-a6BL50Y1ifxmuIgQo5p99LK_yEEACd2vl3IXhoyjOlJ-jaQcyvekFP9HKSiOeFrFb3DgXVUXmVw" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh3.googleusercontent.com/FfRhhZ7cUTcPF-kO8pTWhu_qaG6SFzY6FoAnVhcSFDaDj9tQ1RKZbjqucexgDdAkGR6JG5IP-cU_Z8w80bYhV2DG4no4nOnSLCUxBRroXPvMguPk0izgnZyHl56EGAVEqMLoj03aPAvL8OXh30E-n88NofT6RyRoBG4n6rXQq2RabaxbpjIbiI7zgQ" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh5.googleusercontent.com/0OIzhKGzBkIwM1FEYrn2ywR2QBNSB6zXnIBzKKp6U168cc9q3Pc55y3RKoVFqJgKdM28nkD1KtBeMndOlndESLtNuavfUPEki3k4OXOKwoIAB9cpxUNoz557N9Dc6XpWJpG59vAVOYaMe0fjxuJhz4Ws1DzekVWjlbiTed7bokTFabN8uE-TMs57yg" alt=""><figcaption></figcaption></figure>

Copy the API token and paste it in the Jira authorization key field.

<figure><img src="https://4095801085-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtErerJyslHxJo5moBxJo%2Fuploads%2F4H4BqSpYjZn70OIBKcq7%2FScreenshot%202022-10-07%20at%209.49.23%20PM.png?alt=media&amp;token=719048cc-0d26-4d3f-9ba3-e19b620b221f" alt=""><figcaption></figcaption></figure>

### **Step 6: Integrate Jira Server**

<figure><img src="https://4095801085-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtErerJyslHxJo5moBxJo%2Fuploads%2Fx82oh1lbYg6Mu5LlLBwm%2FScreenshot%202022-10-07%20at%209.51.55%20PM.png?alt=media&amp;token=47ce24d0-189f-4973-85e4-0aad42d4a9a0" alt=""><figcaption></figcaption></figure>


# SSO Okta App Integration

{% embed url="<https://youtu.be/WRz2Xt0xIdo>" %}

### Prerequisites&#x20;

* Users are required to access to Cloud Defense Account

### Step 1: SignUp with OKTA account

Before creating an APP in OKTA, first login to Cloud Defense. Inside the Integrations tab, go to SSO, click on OKTA and copy the redirect URL.

<figure><img src="https://lh5.googleusercontent.com/OhZ1HI6jI5xl_HPtnf0jeJGwz7EKNkmzXT-c0cRsGBp_3pX6F06ekcWX9hWXg1W_0WBuIyrmF5TuOeuH1R168m906t_s5joFrvO1OsKbNjyBeipif0JYHgSf2pUR9OaTyvkKbK2kdjwLRICcE2eUtAQ-48ziVjm4IKFlzyUc9x0Irm21Hyj_tOpt2A" alt=""><figcaption></figcaption></figure>

### Step 2: Create App Integration with OKTA Account

Go to the applications page in OKTA, and click on Create App Integration.

<figure><img src="https://lh6.googleusercontent.com/WxuC36QCQRxFtx8_sU_fkTJhpPTz-IN8V0C63dkWwdN7YE8qZ_caEWHCKUnRMUHZrY-e1Ro-7hx3jY_q6x16e8GjIi6MWJOtiZjiLuT_FwOdXCryuYdo-X9eLSBPpFbitSA4_xtUVlHNc36srO9owjWgvU5HPoV9yVwp8SHqT6PR4YIsZRDR9y5kDw" alt=""><figcaption></figcaption></figure>

**Select Open-id connect as sign in method, and web application as Application**

<figure><img src="https://lh4.googleusercontent.com/UvtIWel5t6-UsekPHJI68FgqTd5ZjeI6fICfV0-fOLzlTggI9X4mF2d7T3fTw27lRspoiUdzdO828x93XnB9fcPCc5uQ854dPFAUYpIdc8GoMNQY3ZJTBHWzdANQBaDChDLHrJFkb9VX9YQenbLJoz8oglrzn6O2V1bkX-YVR8afXfjrC3YbefdYyg" alt=""><figcaption></figcaption></figure>

In General Settings, enter App name, select Grant type as Client credentials and Authorization code as Client acting on half of a user, enter the redirect url copied from Cloud defense application, and paste it in redirect URLs.

<figure><img src="https://lh4.googleusercontent.com/30e-Az3JHlKmH9wRZ5IfbV7_kS-oLlQfc4SYmzHpmvg9Ea7pXmRNnF0CXFDwgMSxaeR3N27wKbk1dI7cmxCwGdSlNJJhNQD12jhJ6axMh86tgoYjiSLh-hQMZSQfai_RclnYK49GsbwjdCHr84l_0Qs5EoAAD80_QTIis3FngcHR1XJiwHTMa2C80w" alt=""><figcaption></figcaption></figure>

#### &#x20;   Select Controlled access value from Dropdown option.

<figure><img src="https://lh3.googleusercontent.com/__9PsT0x7TRADJtqDOsfsmFDh9ts_JFRrmijs9bSjt7yoKf5IgHb5YM9gJ3dN3nGRWNj1xV1nB_7Knl9kTYYCOoLdU1yL6nPFq8ecl0TPYu8Nr5zELovvsfBYRwHO5xqnGOd_KKlQ8MWajZv9_0_j6_nZno6I8LsZkF8OpkvwLe031DWrY4yT0M8LQ" alt=""><figcaption></figcaption></figure>

#### Cope the client ID and secret of the APP

<figure><img src="https://lh3.googleusercontent.com/eGKJwAPYOLox-47GFiS-Dg6OdyDXmL71zo1-B3luyy1A538WSJjqOoeXIbNTJUjJsJfcenl6FNpo1-itHV5yco4Wye14K91onKQiO0UlqS3YOi-IpLbKcQZFbnruReH69jUEktVmTMflphoc0pYymnHcSZI70k8AwaQeWkWXwA-nUDd8RB7t9u-U3A" alt=""><figcaption></figcaption></figure>

#### Paste Id and Secret in our application integration page inside OKTA

<figure><img src="https://lh6.googleusercontent.com/Y2PRSEwH9vu5Gb8SDjt6EqPwYe65MLNL-KCyu_n0uAAXMYixLCuzpNcEcqkqgUtzsmuyNBk6B6FRR6G5_5v8irAT9JBPF6M0OktLnqQIhmtxxmGv5sIrBvOcazI9IsAvK3qHoq5K2aVgEOnmjA1hKSY4cKDRafwabixSOr9Hv-gHETT9m4K8tJs5ag" alt=""><figcaption></figcaption></figure>

#### Sign in with your email ID with which you registered on OKTA

<figure><img src="https://lh5.googleusercontent.com/YhYtCGnugAwCLhv6asSUP1GmC6XzChtzWtX0biFRTe0F_Lh8L94Il7wplUSELYx5eZaFZ6qlboHo_TpL5iiqv6vvyYodhuE9u_ucqIYDUXyOvx_cJXRmjcmdDAtjR1B146CTyRSynha7TvZfq14NTx3Ak-0NwslGBjuysCD-yHWXOyh1S4y3ZonWsQ" alt=""><figcaption></figcaption></figure>

### TROUBLESHOOTING STEPS:

#### 1- Unexpected error while authenticating with identity provider and API is giving 502 bad gateway.&#x20;

#### **JIRA LINK - <https://clouddefense.atlassian.net/browse/CD-187>**

Fix- Check the client id and client secret. Most probably the issue will be with credentials, if other IDPs are working. In case all IDPs are not working and showing the same issue, then we can probably look at ingress logs. <https://stackoverflow.com/questions/42613491/azure-ad-webapp-behind-reverse-proxy-receives-502-bad-gateway>

#### 2- Invalid Username or Password

This error comes when we add the first login flow in identity provider settings as Linking Broker Flow. This error comes when we try to login with a new identity provider and email already exists with some other identity provider. In this case the below API fails and in the events we receive&#x20;

**IDENTITY\_PROVIDER\_FIRST\_LOGIN\_ERROR** `https://staging.clouddefenseai.com/auth/realms/cdefense/login-actions/first-broker-login?client_id=cdconsole&tab_id=o`

The first step to debug this issue is to check the linking broker flow settings inside the authentication tab. Make sure if *Create User If Unique* and *Automatically Set Existing User* both are set to Alternative. Also check if both are added in the same order mentioned above.

#### 3- Issues related to application redirecting to incorrect URLs

<figure><img src="https://lh6.googleusercontent.com/rBusJ4hDAYVZ2XRcjMbmRmeMSJU0w-oBDTZ8Pib5wMJMwW53ntWvNJgQF0q8jPLyUmiM1kXQ8Ni7ATpdUDTjn5v-goqtbC51DtCOxdTHCleXlDftHmsPMcb7_NjDzEJ-apBpuA0U05Kgg_kL7nG4R4mDxk1IYUSO1oh9QZt75lye5iS-WFrDWtFbaA" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh6.googleusercontent.com/pbPjZjsRkZD5fEqITAlISAxcNC2EOocsxfVLTUWqTba54xQh_UzgtpFZaLFCreK-lhsuusXw2cMXVP9kZJaPrCsGioxz6w_QTW4_aCkyuafUTFiOINAD_-9pfgf675Edrrhk5A4ItakG9HAaorbkbT9wZZ1s56sOgWt3j2Nk7EVbYKXoZl_Lj5pEyw" alt=""><figcaption></figcaption></figure>

Make sure the correct frontend url is added in the realm settings as shown in screenshot 1. This is the frontend Url of our realm.

\
Also, in the clients section, select cdconsole and make sure Root URL, Valid Redirect URIs and Base URL are added correctly as mentioned in screenshot 2.

#### 4- Sometimes on fresh setup, we get the below error in keycloak.  ERROR: value too long for type character varying(255)

In order to fix this error, please update the type of *value* column in *user\_attribute* table as text. This will solve this error.<br>

<figure><img src="https://lh5.googleusercontent.com/OSnXBHDDlp2UrXI-oCmNdaEKIYshAIJBZbwWVXGRSmHtVtABMsjwBGN6pNTHnCMttTxZu54ksCo700JGXXxN8MJe3O3qjZmYXLQEIfXGkXgx3lnwRhAaZZYmXiM1-I-OCfe4aur2HPwxP5XPf6JX6Ll_LQdLUCgpmHbz0PtAGDX81VVGg_SF0_V5Sw" alt=""><figcaption></figcaption></figure>


# Set up CloudDefense Single Sign-On (SSO)

{% embed url="<https://youtu.be/tPr0ykXufys>" %}

Do you use an SSO provider and want to allow your developers easy access to CloudDefense via that? In this case, you can set up a single sign-on through your provider. The information you need to establish trust between CloudDefense and the identity provider depends on which type of SSO you are using.

## Overview

Just a few simple steps are needed to establish trust between your identity provider (IdP) and CloudDefense.

* In your identity provider platform, enter details about the CloudDefense.&#x20;
* Provide CloudDefense with details from your IdP.&#x20;
* Confirm the login process is working correctly.

Depending on the type of SSO connection different details are required for establishing the trust between your identity provider and CloudDefense. The following sections elucidate those details.

## Use SAML for SSO

To establish trust with CloudDefense, add an ACS URL/Single Sign On URL.&#x20;

* The Assertion Consumer Service (ACS) is the endpoint on the CloudDefense network that listens for requests from your identity provider to enable communication between users on your network and CloudDefense. This URL is sometimes called a Reply URL.&#x20;

If some more information is needed such as Entity ID etc. it can be found in CloudDefense metadata.&#x20;

* The Entity ID is the URL that uniquely identifies CloudDefense as a SAML entity or service provider--note, default Entity ID must be checked manually as no default is set for this.

Use these details to set up the connection with your Identity provider (IdP):

| Details                                                                                                       | Description                                                                                                                         |
| ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| ACS URL                                                                                                       | <https://console.clouddefenseai.com/auth/realms/cdefense/broker/{organization-name}-saml/endpoint> \*can be found in SAML (SSO) tab |
| Entity ID                                                                                                     | <https://console.clouddefenseai.com/auth/realms/cdefense> \*can be found in CloudDefense metadata                                   |
| Metadata                                                                                                      | <p>\<a href="                                                                                                                       |
| <https://console.clouddefenseai.com/auth/realms/cdefense/broker/{organization-name}-saml/endpoint/descriptor> |                                                                                                                                     |

"> <br><https://console.clouddefenseai.com/auth/realms/cdefense/broker/{organization-name}-saml/endpoint/descriptor> <br> <br></a></p> |

### SAML information to provide to CloudDefense

Obtain metadata URL from your identity provider. Provide this information to CloudDefense to establish trust on the service-provider side. Information contained in metadata:

| Details                                                    | Description                                                              |
| ---------------------------------------------------------- | ------------------------------------------------------------------------ |
| Sign-In URL                                                | The URL for your identity provider sign-in page                          |
| The URL for your identity provider sign-in page            | The identity provider public key, encoded in Base64 format               |
| The identity provider public key, encoded in Base64 format | Optional - The URL for redirect whenever a user logs out of CloudDefense |
| Protocol binding                                           | HTTP-POST is recommended, HTTP-Redirect is also supported                |

### Use OpenID Connect (OIDC) for SSO (using Okta)

When using OIDC for the connection between your Identity provider and CloudDefense, add the Callback/Redirect URIs in your identity provider to establish trust with CloudDefense.

| Details                | Description                                                                                                                    |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| Callback/Redirect URIs | <https://console.clouddefenseai.com/auth/realms/cdefense/broker/{organization-name}/endpoint> \*can be found in Okta (SSO) tab |

### OIDC information to provide to CloudDefense

Get the following information from your identity provider. Provide this information to CloudDefense to establish trust on the service-provider side.

| Details       | Description                                                |
| ------------- | ---------------------------------------------------------- |
| Client ID     | The public identifier unique for your authorization server |
| Client Secret | Needed to get access token                                 |
| Domain        | IdP domain                                                 |


# SIEM

{% embed url="<https://youtu.be/myYEAj2qc1k>" %}

Security information and event management (SIEM) technology supports threat detection, compliance and security incident management through the collection and analysis (both near real time and historical) of security events, as well as a wide variety of other event and contextual data sources.&#x20;

The core capabilities are a broad scope of log event collection and management, the ability to analyze log events and other data across disparate sources, and operational capabilities (such as incident management, dashboards and reporting).

Some of the most used SIEM solutions are - Splunk, IBM Qradar and Azure sentinel

<figure><img src="https://4095801085-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtErerJyslHxJo5moBxJo%2Fuploads%2FdOZH5uvbIG8RdjxHYhh1%2Fimage.png?alt=media&amp;token=1faaf156-332c-4b6a-961d-39ce6f9ef094" alt=""><figcaption></figcaption></figure>


# Azure Sentinel

Microsoft Sentinel is a cloud-native security information and event manager (SIEM) platform that uses built-in AI to help analyse large volumes of data across an enterprise.

1. Get API key from - [https://console.clouddefenseai.com/profile-management ](<https://console.clouddefenseai.com/profile-management >)
2. Now in your Azure Sentinel, we will use the Microsoft Management Agent (MMA) feature.&#x20;
3. Let’s configure HTTP Data Source for showing a list of vulnerabilities in any specific application
4. &#x20;Use this API endpoint with Application ID in end, to get list of all vulnerabilities, <https://console.clouddefenseai.com/api-v2/integrations/application/584174528>, you also need to send 1 header with key “apikey” and you can obtain your api key from - [https://console.clouddefenseai.com/profile-management ](<https://console.clouddefenseai.com/profile-management >)
5. Now, you can configure your parser / schema within Azure Sentinel, to access different key / values from json.

**For more detailed information visit this  -** <https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/sending-rest-api-data-to-azure-sentinel/ba-p/558896>


# IBM Qradar

IBM® QRadar® is a network security management platform that provides situational awareness and compliance support. QRadar uses a combination of flow-based network knowledge, security event correlation, and asset-based vulnerability assessment.

1. Open Dashboard Designer.
2. In the navigation pane, go to **Connector & Sources > Connector Sources.**&#x20;
3. In the Connector Sources tab, click Add Source. An Add Connector Source window is displayed.&#x20;
4. From the Connector Type list, select QRadar connector.&#x20;
5. In the Connector Source Name field, enter a name for QRadar source.&#x20;
6. Source name can contain alphanumeric characters and underscores.&#x20;
7. In the Endpoint URL field, enter URL details for QRadar web service in the following format: <https://console.clouddefenseai.com/api-v2/integrations/application/584174528> &#x20;
8. Above API endpoint requires Application ID in end, to get list of all vulnerabilities, you also need to send 1 header with key “apikey” and you can obtain your api key from - <https://console.clouddefenseai.com/profile-management>

For more detailed information, check Qradar’s official documentation - <https://www.ibm.com/docs/en/cabi/1.1.2?topic=products-configuring-qradar-connector-sources>


# Micro Focus ArcSight Logger

Micro Focus ArcSight Logger is a comprehensive solution for security event log management for easier compliance and efficient log search.

1. For configuring CloudDefense’s HTTP API with ArcSight logger, we will use the FlexConnector feature from MicroFocus ArchSight logger.&#x20;
2. Obtain a Vulnerability listing Rest API from CloudDefense [https://console.clouddefenseai.com/api-v2/integrations/application/584174528 ](<https://console.clouddefenseai.com/api-v2/integrations/application/584174528 >)
3. Above API endpoint requires Application ID in end, to get list of all vulnerabilities, you also need to send 1 header with key “apikey” and you can obtain your api key from - [https://console.clouddefenseai.com/profile-management ](<https://console.clouddefenseai.com/profile-management >)
4. Now, you need to create a custom parser within your ArcSight, We recommend you at this stage follow all instructions, mentioned by MicroFocus arcsight logger

You can follow this official documentation for more clarity, get in touch with Microfocus customer support in case of any other configuration issues <https://www.microfocus.com/documentation/arcsight/arcsight-smartconnectors-8.3/pdfdoc/RESTFlexConn_DevGuideConfig/RESTFlexConn_DevGuideConfig.pdf>


# Sharing Integration

{% embed url="<https://youtu.be/yktTv_ZG7Lc>" %}

You can share your integaration of:

* Github
* Github Enterprise
* Gitlab
* Gitlab Enterprise
* Bitbucket
* Bitbucket Server
* Azure

Here, we will be using Sharing integration on Bitbucket.&#x20;

### Prerequisites&#x20;

* [ ] Users must have an existing Bitbucket account integrated, which requires: Bitbucket Credentials

Integration settings can be shared on the Organization level and Team level.

* **Sharing with the Organizations:** If the SuperAdmin share integration with the organization, all organization members will get access to that integration and be able to see the all repos.
* **Sharing with Team:** If integration is shared with the team, all team members of that specific (you can select team) will get the access to that integration and be able to see all repos.

### Sharing Integration with Organization

#### **Step 1: Click the “**<img src="https://lh4.googleusercontent.com/zFtQeA2OAD-0tpVttJIziAobHvjmU2gy1lJfYL1uuKlD_Cqk0bo2Sj-OIK7yJNd6JiIvpKINY0w-9Yf6bjfE-koJaTa8npa9KON5nKeYIqcJpfSJ2Lp1ydJP_NUw_zsGWkl5mk51_FnXzLh4TpU5UIUYoijUHk7o8kT_t-RopucqOCOd8qeSXvUP1w" alt="" data-size="line">**” settings icon on that Integration**

Please select the option button on the bitbucket integration from the Integration page.

<figure><img src="https://lh4.googleusercontent.com/GyfuYKINVequ8yr8PpJJdQOSWxgPP1QqdCku5uErYVT3of0M2HlgQGV-e1xlU-XjnBz-XhPsNJMt0yJFLbbXmoomwdZZOzRRU99gITahDYiCr6NZJ8KgAI4ngdRaHu-19fGqAin8cQFKRPAi3Il-Aid46Ppj8VdsRvgCNZajVPUaybkpYJS9akpiwQ" alt=""><figcaption></figcaption></figure>

#### Step 2: Click share with Organization

To share this integration with the whole organization, please select the “Share with Organization” option

<figure><img src="https://lh4.googleusercontent.com/EXWubQvQVaXvsX6bzGd0eGNKWvdQC-PkucBp5XeKt022zSBf5S4FGa-7hXfWqYhdK4B36PqZXCsNJgNFdWcdi73aGxsaxwkalfOlU_012sarobi1xxxlB-wTjBvEXGHlvHa1-Zsf4Q-XVcxznZHjnqoHztQ_ivecFcnun17TED4pwyy6OZPqGkdIQg" alt=""><figcaption></figcaption></figure>

#### Step 3: click share

Please click share button to share this integration with the whole organization

<figure><img src="https://lh3.googleusercontent.com/KYanWzWVCs38933xO48v_-50RCkEdaAG2WY2OneSsTT-W7Ofw---wSmKCc3sGgxVNK_EtTmwHiLli1OVojyivHQKmUHKrfPWLFZIs2nb7B2_jtl3iXsQxvh7HTduFxayF78f_Yx8fX0WkRTykvSo3Wc0ngVUkGMumx-1A79Nl-gaEcOQTxL58VZqug" alt=""><figcaption></figcaption></figure>

### Sharing Integration with Team

#### **Step 1: Click the “**<img src="https://lh4.googleusercontent.com/zFtQeA2OAD-0tpVttJIziAobHvjmU2gy1lJfYL1uuKlD_Cqk0bo2Sj-OIK7yJNd6JiIvpKINY0w-9Yf6bjfE-koJaTa8npa9KON5nKeYIqcJpfSJ2Lp1ydJP_NUw_zsGWkl5mk51_FnXzLh4TpU5UIUYoijUHk7o8kT_t-RopucqOCOd8qeSXvUP1w" alt="" data-size="line">**” settings icon on that Integration**

Please select the option button on the bitbucket integration from the Integration page.

<figure><img src="https://lh4.googleusercontent.com/GyfuYKINVequ8yr8PpJJdQOSWxgPP1QqdCku5uErYVT3of0M2HlgQGV-e1xlU-XjnBz-XhPsNJMt0yJFLbbXmoomwdZZOzRRU99gITahDYiCr6NZJ8KgAI4ngdRaHu-19fGqAin8cQFKRPAi3Il-Aid46Ppj8VdsRvgCNZajVPUaybkpYJS9akpiwQ" alt=""><figcaption></figcaption></figure>

#### Step 2: Click “Share with The Team”

To share this integration with a specific team only, please select the “Share with The Team” option

<figure><img src="https://lh3.googleusercontent.com/NpKSH22_ALbswRgeRNKJDdxZ1mA5kaeoPNB0Glm3KHkIl8On3KaUY8kUTeld5rd15QXGtIct8BBOu8srp61amGlkhoSKXFNoUkR9p4Ss4ITkiCaPsuK6-DnwevWEJ__AwMG88SGY-WDv3b6Pokwk1RXhbKbm-CwCPP6_DjFayArY_Z_CLSLLXBlWbA" alt=""><figcaption></figcaption></figure>

#### **Step 3: click the dropdown button of “select team…”**

Please click the dropdown button of “select team…” to share this integration with the specific team

<figure><img src="https://lh4.googleusercontent.com/RtJ5xBxvxqPh6X4NJVZSSfwMHWTvUzZKKBbIrCcEvn5_2lFP2OfBiy8CqZtFnd6TmUDMtlahcYqd-L7Vnso_LpgRUttLLwdYV3pYPMyD5NAUrGedrfhDAVa-R_o3j25zrv0qwCLgdbknfPZCDZxuMDF3y3t0CMHpwZt6GMf-kf7egB6F562ao5ZX8w" alt=""><figcaption></figcaption></figure>

#### Step 4: search the desired team

Please search the name of the desired team on the search bar

<figure><img src="https://lh4.googleusercontent.com/bQJnsZOvdNWPVUJbQN0P6IzCJbWA1lCBhhdkYXYWpuZv0yRc2dixEfY3KPv2JSRtmY-1Tr42pT40Nplu8YZVWXLklJ_DsoZ_T4Ria960ikgs7Z1NpxBE2J4-qduWAEBBAqTdxnQpvHkXC_NCGHQd1BMlXikt6iLOUPOEsIdupWK5FCOXQ0D4AD-13A" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh4.googleusercontent.com/GJodpNBgSB1_H6__pk5OY2KoVIhy8bwFTDJtuuc5vx57Tn15Coz-22HLy5S41GbZRVX1hsCHIgj4yY9EkrStyCI8ZtjTfIxrO-wOKjacLqSQHIVL7A2B7PvaJdfO217cZ2_tpzSJoNqIgYrw2GsiqLn31irFCvt4Mt1ffwenf1dX-Su4pGFU2qWpRQ" alt=""><figcaption></figcaption></figure>

#### Step **5**: click share.

Please click the share button to share this integration with the selected team only.

<figure><img src="https://lh4.googleusercontent.com/qHSoMdXvuegjmy6PjnaL_VT7KS1nAcnVxK8Xr1aPpdvqARHuURTOQiMLS9bDioIzxyTvVq8k8567K1-CzSbblN_8vDj9IGK4pfssqE0M319kno0KPGxweQKjR7QjIM-B6f7Ez1uGqC48wxlP7EVKBB4ttRD4zbmn4BNb2bSS6OUbRgLOezBFbEDmRQ" alt=""><figcaption></figcaption></figure>


# How to Enable Multi-Factor Authentication

{% embed url="<https://youtu.be/3yhp1Wy-PcM>" %}

### Prerequisite

* You need to be a SuperAdmin

### Step 1: Go to Org Settings

Click on the settings icon, in the headers tab, next to the notifications icon. Click on org settings. Keep the toggle on for MFA and save the settings

<figure><img src="https://lh6.googleusercontent.com/HTUx_1a5M_dc4mMQrBMloZfmRgnxHNP3vXzdn8YDSpL7lDBO_3pH2GgRXqrqvTxNJ6czHPqBKMEBtiNE-HaDNV-dca488PoUjqdaRYCzd3zz0rWOmIgWWdgczvk_tpf828TfEsMqyZKILJ4AtBdIaY2lpl-CjKL6ImV2OwqFE-cFfjMPNiEKSL36kw" alt=""><figcaption></figcaption></figure>

### Step 2: It’s Activated for all the team members

That’s it. Now all of your team members need to provide the OTP from their registered email address to get access to your organization.

<figure><img src="https://lh6.googleusercontent.com/iMAj326oZ4skACp9W2yc4mZ9Vo1z8WGHbtcFX_vF-5eHkReEDQS1fCOc7hQcIA3PHqhaGyNmqNNkMtFLSdbxDKu0gGcGgcGGN5tIDxdnuCRclV25xy7SywyeUdCvYl2VYUM6bA1C_cpQFX2_rSEcnn_7kMrZee4tT-0_yMve8KWmP1LEbyFNswGoSA" alt=""><figcaption></figcaption></figure>


# AUTO PR

{% embed url="<https://youtu.be/CSjCJMzcRO4>" %}

### Prerequisite

* Must have an online scan either from UI or CLI.

### Step 1: Patch the vulnerable dependencies

Once SCA scan is done, we can patch the vulnerable dependencies directly from UI if Source Control (Github/ Gitlab/ Bitbucket) is configured and you know that repo.

Open the SCA results and click on any dependency that is present in the manager file. For this example, we will take pom.xml

<figure><img src="https://lh6.googleusercontent.com/3Mc52zzQSfhGeVkFISBj94vwvcgBzGqMXS1Vk1eOS_ba20GcO87OYwHCFPJx0QxH0fnf0XyQJoUwopgQA7vd8sAfgRBPqXzEm28T67_15GcYcO3RZMCh3kd4GqmyqF91e9No0hXVWssilL57qhQfM4xp0-oaHPkhh5dBivqhjpbTuoXzO7QdBB5XviDj5Q" alt=""><figcaption></figcaption></figure>

And now click on Fox this vulnerability, if success full we get,

<figure><img src="https://lh4.googleusercontent.com/4pkYA6Iuu2QRSOReHWVFjqyNUF1GXuVV-5UXrYJfh217NEJmwO3X_vcTfT2ZfHkY4yl631zBnvIc0TL8tdPKKRvrqNC0HssouqvTvAXETjgEQqGSrH7yXQmJJjQpbNvYn6B1cKImHgmOKGk5Kv-aclw2-LYMZkjAfUVuOsedz56NjLBxbwdB54TxN8bMcg" alt=""><figcaption></figcaption></figure>

### Step 2: GitHub Check

On Github, we check if a pull request is generated or not.

<figure><img src="https://lh6.googleusercontent.com/v9whLJLmbCPYBwt7nBluuGPd2OJg_vFor9ZJbE7up-JPkeUd17-ULm5Vaq4n61-rhI1UnUel0ZN1gTkRgC2okdPvUQhK3rXM36Cl-2HRxz4m-o5vlvXXeQ6GyZZ0kVHIJNxElwzgO5wtiWKi3aWfjwb9KwpCyDGelTiZADIsvZUyKhbrIvphLiRg9VxwUw" alt=""><figcaption></figcaption></figure>

PR is requested, which can be merged.


# Remediation using SAST Recommendations

{% embed url="<https://youtu.be/cpQ_vHOljoc>" %}

Recommendation service helps you understand the impact or root cause of any detected vulnerabilities, recommendation service also correlates detected findings or vulnerabilities with OWASP top 10 rankings to give you more context and information on detected vulnerabilities. Recommendation service gives you two kinds of recommendations for any detected vulnerabilities.<br>

1. **Descriptive** - This kind of recommendation helps you understand vulnerabilities and some methods to protect your application from such vulnerabilities by following some basic rules or good practices. This kind of recommendation is not focused on any specific tech stack or programming language. The descriptive recommendation shows you the following details&#x20;

* OWASP Ranking&#x20;
* CWE Information&#x20;
* Some example bad codes&#x20;
* Attack Scenarios&#x20;
* Attack prevention techniques&#x20;

&#x20;2\. **Code Snippets** - This kind of recommendation gives you examples of code snippets in different programming languages, where our recommendation services show you vulnerable codes and fixes for those vulnerabilities.

### Step 1 : Select “Recommendations” for recommendations.

To understand how a recommendation service works. You can run a SAST scan for any supported programming language and then open the report. You’ll see a “Recommendations” button in the footer section of each finding.

Click on **“Recommendations”** and you’ll see this kind of popup with detailed recommendations.\ <br>

<figure><img src="https://lh4.googleusercontent.com/TwBrXAA4qk2nL0tl931OBncp2jQGfFc8ApaLScTLHMhxtjpqVZr0kvy6aYOuSzBm9n77ZZds2FyLXEHD4FOI20PXtwhixbUmLsEU3CT0cbFeYIANpMkW5t_Xtyg6eYNn137Ff8RZBe6CaRexIEIhr3MSlt5_fSM5WarIkNwrm1NHTFfC7dMvwMoL2JpPvw" alt=""><figcaption></figcaption></figure>

Here you can see a detailed description of CWE-22 and if you scroll down, you’ll also see more detailed attack prevention techniques.<br>

<figure><img src="https://lh4.googleusercontent.com/d7jaz_9MWQz7XxFbp5aDgOzCV3ocNwaDjBKVeOYcGs4S2N4kGPYGuWVLacjG7A7lIAZBaXGJCLN9ER0qOklZ1_iBngSGa8aFkdDvSxmtmwLi01dHFcEske9-DFBU6dIOiCHFFa4H9wB3QXWD3PHFiviQpM-kTtgdGeGly6y6zX2I6-TIU4UUk03ax6XVog" alt=""><figcaption></figcaption></figure>

### Step 2: Code Recommendations

The next part is code recommendations. As you can see, there are some code recommendations here. You’ll also notice an arrow icon on top of code recommendations, that gives you an option to see code suggestions in different available languages like javascript, java, python, php, ruby, etc.

<figure><img src="https://lh3.googleusercontent.com/6t_bTwRtLne2DNtH7jBkPBhsVmOEGKrUuyA6r9GiWU5X5wrw0swU4DZn0fkYjNzDSpl_6G3ISwY-YNGK3z4DhCXq35LDoXXdVvbhsCeGcDHwwDFDLyogrniwieMEr1dMQ25gG2wOkeAqlc12Bb_X-JptDbZkK5EAHolsf2RHRGVUR_7H9Pemdcw27uC3Pw" alt=""><figcaption></figcaption></figure>


# Global Allowed List and Local allowed list - Documentation

{% embed url="<https://youtu.be/8soqRPBf7tE>" %}

## Global Allowed List&#x20;

Global Allowed List helps you suppress those SAST rules that you don’t need. Using this Global Allowed list, you can remove false positives from all future scans related to that specific tech stack. Global allowed list can be turned on and off using SAST Rules, to use this feature follow below steps.

### Step 1: Login to your CloudDefense Instance and click on “Compliance”

<figure><img src="https://lh3.googleusercontent.com/5tF52cMP27DbTGRzQJeC5Gza4fSXgK6fvg1hH70mM8efnoW0vSusOPCaXXO7thnwsEFR6g9wb9b0A--pyISSTBYeLytg-0HIDqeT7iwzmj_WJBqg1TD8IW4xmL2lyfAceiEBxbWCwuLdSZKZl1gcfogB24GLddWc3xqQZHzYcNJjsFwLGXmLFUT3" alt=""><figcaption></figcaption></figure>

### Step 2: Click on SAST Rules option <br>

<figure><img src="https://lh4.googleusercontent.com/GVN07BNbyqU7wpd7IOFd6FnrVjgfSAM8KyWmpzH7p4cT0tkFmwzNR4W6klKQFy8xb7bak0J7gAjlyN_O4s_t4yLg99W4UK34WNgTywddTuPQTYKO8ggcqs1PdGUqOahckuu_0lOiSbdFz4CwExZkfS8ktoD4lbsKnza-8uudhmO5PAqHGLN4X-OF" alt=""><figcaption></figcaption></figure>

Here you can see a toggle button for each SAST rule related to “Java” (you can switch language from the dropdown above).

<figure><img src="https://lh5.googleusercontent.com/IxkkYL9vR5X9UpD5FHvh0rRAHTKbEM2e3HtavuaiUwcQFqMr4atF04VCIBt-vgGnA0wxyh-myLk2j2OR5k_tf4oaskpz3h-EJYtbJIGKGm6A7OLET75tqQDqLtxKwtmdu-Q3oC4gFk1QOCztjI-1gfp85OK9YmPr9msbthcqlnlpvGrHAShz4JuG" alt=""><figcaption></figcaption></figure>

Use these toggle buttons to remove any findings from any project related to this specific programming language. You can also change the default severity for this rule with your own custom severity, and CloudDefense will use that severity instead of the default one.

## Local Allowed List

Local Allowed List works like Global allowed list, there is only one small difference between global and local allowed list and that is from where these rules are applied or how this works. When you use a local allowed list, you make these changes only at the application level, so all changes will be reflected for that specific application, whereas a global allowed list affects all of your applications.

To use local allowed list follow below option

1. Login to your CloudDefense Instance&#x20;
2. Choose any scanned application

<figure><img src="https://lh6.googleusercontent.com/dRuJPlh32lA3WtB8EkEJLqHWEa8kAYchvC3WpFlwbNjl2nQjxmB9PHT6fxHA8f4kt_DocA6kAKre7sHjtGBeklHJgZI1s6k5Qfx132ihVBkaoiMD69aWyGjpOLAYlI1gnxw9LNeE7wlmBtGxFZ1F63Y87QEA2kfDvjf2wVUwGW08x_AhGHMbHWwo" alt=""><figcaption></figcaption></figure>

3\. Now expand this list and click on “Code Analysis”

<figure><img src="https://lh4.googleusercontent.com/A1a_H1TrEG9kvI4Mk4fm2pit6hVmS45O14lZBekkvcY97mxi8hWbL0BLv3FK1Bku4e5MUPDo_RYYSBzWyHJMY6lzJiB-FrBocC5OrSUJF7v9I5VjtutlTg8EHjbJP5Zedt-Iq5Mifzzc69yC9C4a0Ld7UqCiSecYI2oZa30GLUchM5TaLoNabImK" alt=""><figcaption></figcaption></figure>

4\. Now you can see reported findings like this, and you can also see a button “Add to allowed list”

<figure><img src="https://lh6.googleusercontent.com/d9q4kTuZqeYN5s7sRt0vYPZlfRrDvH7LrvmEbxbDRCSk6GGG-Y5TgflSZikUT88nrSlUBD0NXmxrMR46YYP7UJRj8fF-cVlOCDxBLBXu1buqWDwIvH5Di6dC3HrYN5oEpR8v12Own-S5BZ1m8jBorZeOCEgi6vZvVSH1z6XwBycFZ5b6OwWGbkRN" alt=""><figcaption></figcaption></figure>

5\. Click on “Add to allowed list”, and that specific issue will be removed from your scan results.&#x20;

6\. Now, what if you want to see those suppressed findings again? Simply toggle that “Allowed vulnerabilities” button on top.

<br>

<figure><img src="https://lh4.googleusercontent.com/XeQh5hWC0YjUFKdzOXn6_OMs30h-kYe9xKSdAaomHcQCYuC4Ec3f7rDAYXBne5WhBmztHWmZOqb_SaZ-kZ-jKBudtf_WghVIN1rshVVeBKLHrYWmQSVMZi4S6KCvL4Plnou457F06203yLCfoZS-ayXLMHsDsWD9foBs9K1YmN8p7jvRermdscQ_" alt=""><figcaption></figcaption></figure>


# File Exclude

{% embed url="<https://youtu.be/c6a16ORxXkU>" %}

### Prerequisite

* Must have an online scan either from UI or CLI.

### Step 1 : Scan UI

Once scans are finished, we can go to the UI. There is a feature to exclude file paths from the project tree if developers don’t want to scan those via Exclude File Path. To do that, start a scan in UI.

<figure><img src="https://lh3.googleusercontent.com/GK_hI4UqypemAe-XIL4X6MWMY5gPL4D5XXBAK2EqY4jV79ZdAny0ZZGzMCK9uCWlsY9RXnvRIx9Y9FuvHlkpPnfbGMFgUgwyU1O9hNCxwOyatE8ubEaZFdmc85RmSpGAQU4jA02UyhDSByJZlTBtHbsWQ61_jCYccmoX8WJI_OkucMZMHD6AbZa2Ary0sw" alt=""><figcaption></figcaption></figure>

Once the scan finishes.The interface will be as follows

<figure><img src="https://lh5.googleusercontent.com/IEnING-EkZ8Wa--c8XvAW_dOYRULHxKrB_ZtD-exzwLPDigqIgTAes9Kir51m2Xecchy9nii_khBJWeA5pE3i7Gh50ZTM6YNxwfOarKXgL0KdCpSUP0CRteY4nNAJ2HmxFN4RUNvP2uB0J1W15pP2xHRIAoa6W4dty-fyDMCrJwKn9MySwFFKlb_VhyWEQ" alt=""><figcaption></figcaption></figure>

### Step 2 : Exclude Path

We now exclude a path which is similar to the following picture.

<figure><img src="https://lh4.googleusercontent.com/5ImbQpJo-S2-WIZvyOGAHJw35KAQyqYmfDqRIIJvP8s0p7rAHTn-_e9o2p8HKHZ4Jos0c37vJmTKRIJ3oov2_33qnAyzxGnpX186GocoixtEdnCiC7lgxH_2IROGADfpx7IJtxXxkhduB52P9jCEMtwxkOGR6c0DRX0MC30DK9u-LrBG0X9BasZtlUtugg" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh5.googleusercontent.com/U_VdLcx4KMRCa57t9ZhclhzL6aajfGbRMjHdMMhdnRkIt4_2pbijdOCisGNF0yDCqlR8qZN7cXbwY87ohD7T8yAkXP_RC7SS24ADmsC3B2Zku3HAA4oiuOCrRi84c1wGsOW1J1D68i5ESUwrhvDLqV1RgbHHMBfWO2BjZBdvkl1blrTlhNHqPYT-XGbOQw" alt=""><figcaption></figcaption></figure>

### Step 3: Re-run Scan

Now re-ran the scan to see if /apps/ path is excluded from next scan

<figure><img src="https://lh6.googleusercontent.com/JuoV9lHzi1FICQCkr9mWYJw_BtH7Z6nQ3-7nNnfgSi4t6-A3acT_--wAcO3j4rTXiix4VqMjR1yKYEAKCWjDqjn6XEie-U8c_X90uh56iHBGvgiWraXphfL9n2O6IN34uwLuqqB904YnjSrRWTE6yiiNo8Q1uMkq4e2FZyfEcmXz-TLH3bXGngy973D_4Q" alt=""><figcaption></figcaption></figure>

Now we cannot get any thing from the path (/apps/) which we excluded.


# Cloud Defense CLI

CloudDefense's CLI helps you find and fix known vulnerabilities in your dependencies, both on local projects and as part of your CI/CD system.

{% embed url="<https://youtu.be/R6TkGQ9iPrc>" %}

### Installation&#x20;

Please follow instructions specific to your operating system.&#x20;

### How to update CLI?&#x20;

By just rerunning the command updates the client to latest version.&#x20;

#### Mac&#x20;

Run the following command which will install `cdefense` tool.

Prefix with `sudo` if you see any permission error when running this command&#x20;

`curl\https://raw.githubusercontent.com/CloudDefenseAI/cd/master/latest/cd-latest-mac-x64.tar.gz > /tmp/cd-latest-mac-x64.tar.gz && tar -C /usr/local/bin -xzf /tmp/cd-latest-mac-x64.tar.gz && chmod +x /usr/local/bin/cdefense`&#x20;

**Linux**&#x20;

Run the following command which will install `cdefense` tool.

`sudo curl\https://raw.githubusercontent.com/CloudDefenseAI/cd/master/latest/cd-latest-linux-x64.tar.gz > /tmp/cd-latest-linux-x64.tar.gz && tar -C /usr/local/bin -xzf /tmp/cd-latest-linux-x64.tar.gz && chmod +x /usr/local/bin/cdefense`&#x20;

**Windows**&#x20;

Download the following tar file and unzip it​ `https://github.com/CloudDefenseAI/cd/raw/master/latest/cd-latest-windows.exe.tar.gz`&#x20;

### Usage&#x20;

Run the following command to get started.&#x20;

**cdefense help**&#x20;

NAME:&#x20;

Cloud Defense CLI Scanner - CLI for scanning and detecting vulnerabilities in any language&#x20;

USAGE:&#x20;

cdefense \[global options] command \[command options] \[arguments...]&#x20;

VERSION:&#x20;

1.0.1&#x20;

COMMANDS:&#x20;

scan, s SCA scan of a given project and post to Cloud Defense server sast, a SAST scan of a given project and post to Cloud Defense server help, h Shows a list of commands or help for one command&#x20;

GLOBAL OPTIONS:&#x20;

\--help, -h show help (default: false) --version, -v print the version (default: false)&#x20;

### Examples&#x20;

#### SCA

#### Example of python SCA scan

`cdefense scan --lang=python --api-key=<YOUR_API_KEY> --path=/d/temp/vulpy/requirements.txt --project-name="my-python-project" ​`

#### Example of java SCA scan

`cdefense scan --lang=java --api-key=<YOUR_API_KEY> --path=/d/temp/java-goof --verbose --project-name="My Java Project" ​`

#### Example of php SCA scan

`cdefense scan --lang=php --api-key=<YOUR_API_KEY> --path=/d/temp/php-helloworld-app --project-name="my-php-project" ​`

#### Example of NodeJS SCA scan

`cdefense scan --lang=node --api-key=<YOUR_API_KEY> --path=/d/temp/nodejs-system --project-name="my-nodejs-project"`&#x20;

### SAST

#### Example of python SAST scan

`cdefense sast --lang=python --api-key=<YOUR_API_KEY> --path=/d/temp/vulpy/requirements.txt --project-name="my-python-project" ​`

#### Example of java SAST scan

`cdefense sast --lang=java --api-key=<YOUR_API_KEY> --path=/d/temp/java-goof --verbose --project-name="my-java-project" ​`

#### Example of php SAST scan

`cdefense sast --lang=php --api-key=<YOUR_API_KEY> --path=/d/temp/php-helloworld-app --project-name="my-php-project" ​`

#### Example of NodeJS SAST scan

`cdefense sast --lang=node --api-key=<YOUR_API_KEY> --path=/d/`

### FULL SCAN

#### Example of full scan

`cdefense online —api-key=<YOU_API_KEY> —repository-url=`


# Install CloudDefense Helm on a Kubernetes Cluster

{% embed url="<https://youtu.be/iCSK1XLL-Xk>" %}

### &#x20;Prerequisite

A kubernetes cluster whose nodes have to linux/amd64 architecture&#x20;

### Development Environment

* Helm (v3 or above)&#x20;
* Kubernetes Cluster (kubectl)&#x20;
  * Minimum Requirement - 1 Node (2 vCPU 8 GB RAM)&#x20;
  * Recommended Requirements - 2 Nodes (2 vCPUs 16 GB RAM)&#x20;

### Production Environment

* Helm (v3 or above)&#x20;
* Managed Postgres Instance for ex. AWS RDS (db.r5.large)&#x20;
* Kubernetes Cluster (kubectl) On Demand Nodes in Node Groups with Labels

Node Groups Node Type

Node Groups Node Type

| Node Groups | Node Type              | Level     | Min Nodes | Max Nodes |
| ----------- | ---------------------- | --------- | --------- | --------- |
| external    | t3.medium (2vCPU 4GB)  | on-demand | 1         | 4         |
| auth        | t3.medium (2vCPUs 4GB) | on-demand | 1         | 4         |
| api         | c5.large (2vCPUs 4GB)  | on-demand | 1         | 4         |
| web         | t3.medium (2vCPUs 2GB) | on-demand | 1         | 4         |
| job         | C6i.large (2vCPUs 4GB) | spot      | 1         | 4         |

### Install Cluster Auto-Scaler

### Install Kafka

Download the kafka helm repo (bitnami)

````
```
helm repo add bitnami https://charts.bitnami.com/bitnami
`
````

Install kafka helm

````
            values.yaml

```
nodeSelector:
  label: external
```

```
helm install kafka bitnami/kafka -f values.yaml -–debug
```
````

### Install CloudDefense Helm

1. clone <https://github.com/CloudDefenseAI/charts> create roles, role binding and service accounts

````
```
kubectl apply -f cdefense/rbac
```
````

2\. create secrets

````
```
kubectl apply -f cdefense/secrets
```
````

3\. add helm repo

````
```
helm repo add cdefense https://clouddefenseai.github.io/charts/
```
````

4\. Install cdefense

````
```
helm install cdefense cdefense/cdefense --debug 
```
````

4\. update/upgrade

````
```
helm upgrade cdefense cdefense/cdefense
```
````

## Configure CloudDefense Helm for SSO

In order to sign in with different identity providers (for ex. github), create ID and secrets

### Step 1: Create id, secrets for github

1. go to [github developer settings](https://github.com/settings/developers)&#x20;
2. Create a New OAuth App&#x20;
3. Homepage URL is the base\_url&#x20;
4. Authorization callback URL is https\://{base\_url}/auth/realms/cdefense/broker/github/endpoint

<figure><img src="https://lh3.googleusercontent.com/FOY_a11iPhYToQmgxQotgI52cNB8tYKl3gxdDaNPe4SopXf6YvjbCjVX2YrVbj1UUglAyjzfUCViKMFToJt7n5JHkjjfq3HvD5HMEJejHFels6BMjSM25ZvVOCwjPrL1rZDRdXDvi0wkYN3aClA1JMRJ4cXWdNzKG2Pgz6hLZBrc62K9Whc3YOwEDlP2JA" alt=""><figcaption></figcaption></figure>

### Create id, secrets for gitlab

<figure><img src="https://lh6.googleusercontent.com/EDQoSyrv2RL5se3EJJPwUBJe__c7ijPOqi0WV5uaoxgPAa4p9DGDAVx9F_6fI8QD_aKx0oDAuW_zcSkvxFUYEWTeHm1VPmtLMQcqOgmqwEi_LirLUhxeARgP4u8DPQL24UHfENuS47JoQxENP1C3UK8w9TlqrxVCfRsk0_DRURRblQneYYdXmLtikH6CFw" alt=""><figcaption></figcaption></figure>

### Create id, secrets for bitbucket

<figure><img src="https://lh5.googleusercontent.com/slYSJDmyCgEx3FG18w4lWygN9jOab-NNdwvNygLzYeW0GBqLnbGodnv6ocaFu9D-KjFhaLhhE4OZ4f95FFc7hb4wI60-UIRg5twRxBnb0IcuQQhGbrDVrdl9FN4AqrrWgkBap8pIlKYukaP0D6d8LLyinpgcAgi2x-z5gZhOQhhzfJvXGfMr-6eq2MKAKA" alt=""><figcaption></figcaption></figure>

### Create id, secrets of Microsoft

Create secrets on kubernetes cluster

1. Create a secret for authservice or use a yaml file

```
apiVersion: v1
kind: Secret
metadata:
  name: authservice-secrets
type: Opaque
stringData:
  SENDGRID_KEY: 
  GOOGLE_CLIENT_ID: 
  GOOGLE_CLIENT_SECRET: 
  GITHUB_CLIENT_ID: 
  GITHUB_CLIENT_SECRET: 
  GITLAB_APPLICATION_ID: 
  GITLAB_APPLICATION_SECRET: 
  BITBUCKET_KEY: 
  BITBUCKET_SECRET: 
  MICROSOFT_CLIENT_ID: 
  MICROSOFT_CLIENT_SECRET: 
```

2\. Restart authservice pod

```
kubectl apply -f authservice-secrets.yaml
```

### Configure CloudDefense Helm for Importing Repositories

Debugging and Troubleshooting

Pod Description Steps


# Install CloudDefense suite on a Kubernetes cluster

{% embed url="<https://youtu.be/Hs1fPgiJmJI>" %}

### Pre-requisites

There are three main pre-requisites for a production grade cdefense installation on-premises

1. A managed Postgres instance (for AWS RDS db.r5.large)
   1. enable automated backups
2. A kubernetes cluster (/examples/eks) with at least two nodegroups
   1. node group for jobs
      1. each node has { label: job }
   2. node group for all else
      1. (optional) each node has { label: cdefense }
3. A cluster auto-scaler

### Install kafka

* Download the kafka helm repo (bitnami)

  ```
  helm repo add bitnami https://charts.bitnami.com/bitnami
  ```
* (optional) create/edit `values.yaml`

  ```
  nodeSelector:
    label: external
  ```
* Install kafka helm

  ```
  helm install kafka bitnami/kafka -f values.yaml
  ```

### Install cdefense

* add cdefense helm repo

  ```
  helm repo add cdefense https://clouddefenseai.github.io/charts/  
  ```
* update repos

  ```
  helm repo update
  ```
* clone the repo

  ```
  git clone https://github.com/CloudDefenseAI/charts
  ```
* create roles, role binding and service accounts

  ```
  kubectl apply -f charts/cdefense/rbac
  ```
* create secrets

  ```
  kubectl apply -f charts/cdefense/secrets
  ```
* Install cdefense helm

  ```
  helm install cdefense cdefense --debug
  ```

  or

  ```
  helm upgrade cdefense cdefense/cdefense --debug
  ```

### Configure Social Authentication

In order to sign in with different identity providers (for ex. github), create ID and secrets

#### Github

* go to [github developer settings](https://github.com/settings/developers)
* create a New OAuth App
* Homepage URL is the base\_url
* Authorization callback URL is [https://{base\_url}/auth/realms/cdefense/broker/github/endpoint](https://%7Bbase_url%7D/auth/realms/cdefense/broker/github/endpoint)

<figure><img src="https://github.com/CloudDefenseAI/charts/raw/main/images/github-auth.png" alt=""><figcaption></figcaption></figure>

#### create secrets for authservice

* create a secret for authservice

  ```
  apiVersion: v1
  kind: Secret
  metadata:
    name: authservice-secrets
    type: Opaque
  stringData:
    SENDGRID_KEY: 
    GOOGLE_CLIENT_ID: 
    GOOGLE_CLIENT_SECRET: 
    GITHUB_CLIENT_ID: 
    GITHUB_CLIENT_SECRET: 
    GITLAB_APPLICATION_ID: 
    GITLAB_APPLICATION_SECRET: 
    BITBUCKET_KEY: 
    BITBUCKET_SECRET: 
    MICROSOFT_CLIENT_ID: 
    MICROSOFT_CLIENT_SECRET: 
  ```

  ```
  kubectl apply -f authservice-secrets.yaml
  ```
* restart authservice pod

### How to change location of logs

* update value.yaml

  ```
  api:
    logs: 
      region: <REGION>
      bucket: <BUCKET>
  ```

#### in case of private bucket

* Edit the scan-server-secrets.yaml file

  ```
    AWS_SCAN_S3_ACCESS_KEY: <AWS_SCAN_S3_ACCESS_KEY>
    AWS_SCAN_S3_SECRET_KEY: <AWS_SCAN_S3_SECRET_KEY>
  ```

  ```
  kubectl apply -f scan-server-secrets.yaml
  ```
* or update secrets on cluster

  * encode values as base64 strings

  ```
  AWS_SCAN_S3_ACCESS_KEY=<AWS_ACCESS_KEY>
  BASE64_AWS_SCAN_S3_ACCESS_KEY=$(echo $AWS_SCAN_S3_ACCESS_KEY | base64)
  ```

  ```
  AWS_SCAN_S3_SECRET_KEY=<AWS_SECRET_KEY>
  BASE64_AWS_SCAN_S3_ACCESS_KEY=$(echo $AWS_SCAN_S3_SECRET_KEY | base64)
  ```

  * edit scan-server-secrets

  ```
  kubectl edit secret scan-server-secrets
  ```

  ```
    AWS_SCAN_S3_ACCESS_KEY: <BASE64_AWS_SCAN_S3_ACCESS_KEY>
    AWS_SCAN_S3_SECRET_KEY: <BASE64_AWS_SCAN_S3_SECRET_KEY>
  ```
* save and restart api pod

  ```
  kubectl delete pod api-<some-string>
  ```

<br>


# Team Management

{% embed url="<https://youtu.be/HKE-34RrUYs>" %}

CloudDefense allows you to create team under team management tab. The admin can invite both new and existing users as team member and can give access to selected features. For example, let's create the first team. Clicking on the “Teams” tab will navigate you to the team management screen (Tab is available only for admins). To create a new team the only thing is required - a team name. The description is optional.

<figure><img src="https://lh4.googleusercontent.com/L_SuNLTLeaR1I6aPVIC0crqcqBXztR_nAJzLlyP_g43ipe0lmQdM3I9tlWKLNaF3asmWmoyEoBXz9NhBZ0tejllcVsj3FPezY08V3M7cFR2KUD9U8It_vbKe1pyYVrWDUzTKpn8zHl3WP43rAIFAFXvlVoquxZR144zwczqn3R10J6uWeWoeNuANTQ" alt=""><figcaption></figcaption></figure>

After filling the data - click on the create button. Now your team is created. (Frontend is a demo team created for your convenience.)

<figure><img src="https://lh6.googleusercontent.com/Jp3dxgUy7Druk2rpKpdPn-tDwE5p1JCKUmclj5TXBiLRottOfORSpkjcwlSgXlDIfVCGb1A_n362pOGw15eZq7YF8ZPmSYAquIeqLW_IK8rrzCnzFIh5UCpqCJP2dGntrLhUOkgtGhkT8cNjKBUx9-6QUEeJaWWqKUTj_3D8h7S8N4Z_OQtf0zuqfg" alt=""><figcaption></figcaption></figure>

What do the counts at the top menu? Let's figure it out (For your convenience we numbered from 1 to 4).

These counts are a small summary of your organization's team management, represented in number format. About all of them in details:

<mark style="color:green;">Note</mark>\* All of the counts are calculated depending on your role and your access to the teams/applications. F.e *Super Admin* (who is allowed to manage all the teams/applications) will see the counts overall whole organization while TeamAdmin (who is allowed to manage the teams he participates in) will see only counts accessible to him.

1. **Teams**: Displays the number of teams created in your organization or accessible to you.&#x20;
2. **Admins:** Displays the number of admins in the teams which are accessible to you.
3. **Employees:** Displays the number of employees in your organization (For SuperAdmin) or in the teams, you manage (For TeamAdmin)
4. **Applications:** Displays all the applications which can be added to the team.

Clicking on the team you will be navigated to the team details page, where you can:

1. **Delete team** - Delete team button;
2. **See the Team Stats** (how many users, teams, admins are in the specific team) - Team counts
3. **Manage the team name and description** - Team Configuration;&#x20;
4. **Add users** to the team (new and existing) - Team Users;
5. **Add applications to the team** so AppUsers can see them in the list - Team Applications;

We will figure out how all the steps mentioned above work a little bit later, but now let's check how the screen of the team details looks like after first time landing on it:

<figure><img src="https://lh4.googleusercontent.com/1OmBCdhfv0JEIo227MA1-pdgKYnefOvgp84PbwiCgOgPa0qR5AMpessrOGHZYZ00KuXxxkunDNTvpOk13sAUzG8frcLqh0M2FOJtXlzmEzYh9V6cbYcq5YZxEiao6SQ7NXKs1fipiax7wTf9vgLHtYmEk17yvG5pwPEDNcIiEwac1ithvPWhGSKLAA" alt=""><figcaption></figcaption></figure>

### Actions Items on Team Management:

#### Delete team

To delete a team, you have to click on the trash icon in the top bar. If you can delete team, you will see the confirmation modal, after confirming action team will be successfully deleted. What means that you can delete the team? It means that you should have access to it and the team should be ‘empty’ (No applications or users wired with the team). If team is not ‘empty’ - you will see next modal with the action required:

<figure><img src="https://lh4.googleusercontent.com/bplFX7L_X6hvFDFfGlZ1I692cVtIY9I1zULr1iGcw530lKhc21GVBMgsmU2jp-AxtwXAyIptI5jEyE69jy0bWzFzMjT7L3-uQC2SNt3FR20lIWjSyKkmmZr_UmpN-5McyehcH4xQevyVJ9TE5hXcdqyMsO3oW8Hgvf12ml5uqV14uNShD4F_vX-z2Q" alt=""><figcaption></figcaption></figure>

#### Team Stats

For all users on this page, counts are displayed the same, and they show data of the specific team which you have chosen.

#### Manage the team name and description

If you want to change the name or description of the team, simply change it in the inputs and hit on the update button.

#### Add users to the team

You can add existing users or new users to the team. To add user, click the ‘adding users button’ in the team users section. You will be redirected to the next screen:<br>

<figure><img src="https://lh4.googleusercontent.com/NIi5dWiOHB0Qw7nsCpm_cCEdnZcDvvY_Bz9GutQPBGkKY1GRbHb6pzBQ8RKHY6sOWsQfxD5YncUBOangbJoqTz65aWQtQHCLFX4yYtjtuGybVEsC4Zr6WPjO_MtiUMaAB1hN9VY_hPB_0K-ogSQestNony9y1jEGZrYmwtg-xSE8LNOZL5p6ZhgS_A" alt=""><figcaption></figcaption></figure>

If you want to add user which is already in your organization, he can be the part of other teams, you can search his account by entering email or part of the email in the input. If user(s) were found, you can select the one you want to add and click on the ‘*plus*’ icon.&#x20;

If you want to add new user to your organization, click on the ‘*New User*’ tab.

<figure><img src="https://lh4.googleusercontent.com/yCOl3ZB31CkUPoc3pLCU3S15DKxZX2-azDUGubUFlgY6UFFj1xsypJy1jbUQ6pR9oib8hBGykX6yXv1yhhQa5ehCM00zX4fPgeF4ZwaID9L5HvmfDOMcL7nE5s3W8EiL08X1IdycY8EdUC56o7UbwrOfi96OwWu9hUT0PJPoU7cmuKNExnZlU0eGaA" alt=""><figcaption></figcaption></figure>

***User roles description:***

* **Super Admin**: Super Admin has access to all the functions available under a particular team. They can change the role of existing team members if required.
* **Team Admin**: Team admins have the access to control the activity of team members only.
* **App User**: The app user role allows the assigned member to test the basic scans using the application that you have inserted. Other team administrative functions are not available in the app user interface.

Fill in the form with the email address and select its role. After inviting, user will be notified by email and automatically added to your organization and the team you wanted to add to with the <mark style="color:orange;">pending</mark> status.

<figure><img src="https://lh5.googleusercontent.com/fTk3QNDwpJ58UPhofekpraHLZiJhkL-ZbPedP3IDNwnVIE2a5EPiYuv1E3hzKX5T2HTIDUVKu0MHNxU9gMiO5tS7zmdoSx5PeSZPrCyPoIIF62GGA_mGOJpv_QajWRySxSWcTzyBb_yPKtq6q9-iOuU_trME1Wu_-2GYB14uu7j11Jj7JhljMlXk4g" alt=""><figcaption></figcaption></figure>

\*<mark style="color:green;">Note</mark> One user can be added to multiple teams. But currently, the user role in all of the teams will be the same. F.e if you invite user ‘**<test@gmail.com>**’ to the **A team** and assign **TeamAdmin role**, adding this user to the **B team**, meaning that the user will be **TeamAdmin in both teams**. Demoting in the A team will affect the B team as well.

There are 3 different actions that you can perform on users in the team management. Menu with the actions is available after hitting the ‘menu’ icon (3 dots) on the right side of every user entry;

* **Deactivate user** - You can deactivate a user from your organization. Users will not be able to login to your org anymore if you deactivate them. You will see such users with the ‘<mark style="color:red;">deactivated</mark>’ status;
* **Remove user from the team** - You can remove users from the selected team but keeps in the organization;
* **Resend user invite** - This resends the invite to the user, if he has not accepted it in time.

#### Add applications to the team:

You can add applications to the team, and make them visible to team participants. To add an application to the team click on the ‘adding application button’ in application section.

<figure><img src="https://lh6.googleusercontent.com/70_3ifrTq-Tl1vbfUojbUDF2vA1bdKcK_IsxTPmvVjqvdFwE-cIQPHI56Ycok4AmUvYgt7O824nLSuR6oHgJHGxD-r9od8yop8_jvc7Ax0EYbblq3jpaKtp7AIqZN3WJDQyz_FGAT_-94f_8VMJw29BJrOtCPygdXSfkmPvIcDhhTB9TXQGEEURC7w" alt=""><figcaption></figcaption></figure>

You will be redirected to the page with the all available applications tabled.

<figure><img src="https://lh4.googleusercontent.com/G0HPTen2kMEzyF55EuopFVfiloN0D02JqXW58ddLJZurcxoWzYJjagCsTVgrafK3jmL8kpOrn8DTfbdkmgBq9kFiYObwgNHklZZrzPM-n5xMktl01T1sY-eMdfEsyanituH2LwTHTmwN2le-TPjnczY1-TQmEFgr-j6Rtoa85FRJfvkxS-c_zJiqwQ" alt=""><figcaption></figcaption></figure>

\*<mark style="color:green;">Note:</mark> One application can be added only to one team currently. In the list above only applications which can be added will be displayed. F.e I have 2 teams A and B (they are empty) and 2 applications ‘App1’ and ‘App2’. I want to add App1 to team A. In the table I will see both applications. After adding App1 to team A i want to add App2 to team B. In the table I will see only 1 application which is App2 since App1 is already in another team.


# User Management

{% embed url="<https://youtu.be/xn9UGVJ6vDI>" %}

User management tab allows the super admins to view the status of all the invited team members for each team in a single dashboard. Under this tab,only super admins can add new users,change the existing member’s role, remove or deactivate the existing members if necessary. About every action detailed below.

<figure><img src="https://lh6.googleusercontent.com/aL98D_6NRd6pbQW-BhxlaLSzC3YkrsIAwi7ZrvboLveVtHOEVEhgEFA0uqDrTdjfB1CCE66korD-iVyXKfbXkpzgxWP3TGThtGb_TeQv_aFQwunAQaYWZ97eR_v-4EcfxaYT3ZU4TJYmORvij32LcU8962ZUtY7WKqiYwfqc_i9GC8UYDH0QOI_u5w" alt=""><figcaption></figcaption></figure>

Landing on the ‘User Management’ page SuperAdmin can manage all the users.

First we can see the slider at the top which switches all users list and deactivated users list. Then we have an opportunity to change the user role. There are 2 states, when you are allowed to change the role and not. If you are not allowed to change the user's role the role is grayed out.

### **User roles description:**

* **Super Admin**: Super Admin has access to all the functions available under a particular team. They can change the role of existing team members if required.
* **Team Admin**: Team admins have the access to control the activity of team members only.
* **App User**: The app user role allows the assigned member to test the basic scans using the application that you have inserted. Other team administrative functions are not available in the app user interface.

#### Possible reasons why you cannot change user role:

* User is the owner of the organization (**Owner** - the person who created the organization, only the owner can manage SuperAdmins, and nobody can change data about the owner. If you want to change the organization owner, contact support).&#x20;
* User has the same role as you (You can only change users roles who is less privileges than you).&#x20;
* User has not accepted the invite yet (status pending).&#x20;
* User is <mark style="color:red;">deactivated</mark>.

There are 3 different actions that you can perform on users in the team management. Menu with the actions is available after hitting the ‘menu’ icon (3 dots) on the right side of every user entry;

* **Deactivate user** - You can deactivate a user from your organization. Users will not be able to login to your org anymore if you deactivate them. You will see such users with the ‘<mark style="color:red;">deactivated</mark>’ status;
* **Remove user from the team** - You can remove users from the selected team but keeps in the organization;
* **Resend user invite** - This resends the invite to the user, if he has not accepted it in time.

### Invite Users to the Organization

Click on the ‘plus’ icon in the section and you will be redirected to the adding user screen.

<figure><img src="https://lh4.googleusercontent.com/m7yny9_uPO5wQnsir9GvyYTujQulhfxWtxL5GNXsL96g_2DFxkZti1KF34Crrhydu6eYh63OKJlqXk1GDzyyymGpVo3lqaaNCPWcleF2xNY8Is_7-3cqzvAoppXpX7nLMGFKek-G7RcwsFOWsy_T31lIF-MU8nN52wFa9ZALB90-D_jZ9MLnfmS6PQ" alt=""><figcaption></figcaption></figure>

To add users you have to fill 3 fields: Insert user email, choose the user role, choose the team. All steps are required. If you don't have a team, before adding a user you should create it.

[Click here](#user-roles-description) to know more about User Roles

After inviting, the user will be notified by email and automatically added to your organization and the team you wanted to add to with the pending status.


# App Management

{% embed url="<https://youtu.be/ZqfNJbWgHMc>" %}

Application management allows the SuperAdmin to manage the existing inserted repositories from the applications such as of Github, Gitlab, Azure, Bitbucket, DAST, API etc from all users in organization.&#x20;

In the application management section, you can find all applications in your organization and team to which this application relates to. You can quickly move the application through the teams by selecting the team in the dropdown.

<figure><img src="https://lh3.googleusercontent.com/2FPOKJJrBfCHFyI_JpxLJIfreL6zzihLbeYgfjDiNcexoW7eckahymwpzcAMtnMQNjkrAmLE3gRSLne1PAf12KVpXf-VK9T2Q2-lQinfwuT-7X77jdGZ_pNZsLXybQn_U65sfOg4Mmcw2wZBy5yNUhZ_Kg1beMekD3DYSp985DqecXdj6KhYOal-qw" alt=""><figcaption></figcaption></figure>

One application can be assigned to only one team. You can always change the team of an application.


# LogIn/Signup process

{% embed url="<https://youtu.be/pn4_1Ng9olk>" %}

To login or Signup with CloudDefense,please refer following steps as mentioned.

### Step 1: Enter into Console Interface

CloudDefense login/signup option begins from the console interface which you can find by [clicking here](https://console.clouddefenseai.com/). The interface will look like the following picture.

<figure><img src="https://lh5.googleusercontent.com/ujF8GpTy6em2NvlnXruAcw4x5djtBkRkr_rEmd5SvN6qCJyebQmxD5fLPhMS4SmKeHTEhqQBZnYPa4CZoyPBLNMbuJpvUcXXXOVhLutCQXFd775quvZqyGKkAhrZxyTsj7z_hQJm6Dx9732bAD6EHGRmNR2_CS6mXlGP43Riyhxv9Lviy7s8ia3RKw" alt=""><figcaption></figcaption></figure>

### **Step 2: Sign Up to CloudDefense Console**

If you are using CloudDefense Console first time, please make sure to sign-up with any one of the available account you fro&#x6D;**:**&#x20;

* [GitHub](https://github.com/)&#x20;
* [Gitlab](https://gitlab.com/),
* [Google](https://www.google.com/),&#x20;
* [Bitbucket](https://bitbucket.org/),&#x20;
* [Microsoft](https://www.microsoft.com/)&#x20;
* [Email ](https://mail.google.com/)

Once you are done with the sign up procedure you will find the following interface.

<figure><img src="https://lh5.googleusercontent.com/3TQzg9Ltl3bUzs9p4DwyvxeBrgwuKI-6VFHfvkVOOkWvxe0a36bBFX16n15MRiIt9wnjt0i89aoCLOj-YirA2dlZEIrr-ZF-yAMWrlj62MnRTz9kw5oqVul1MAd2i9mC-zVKC-j4eGhlRVu3-2jrcVWADZ49BfwoKVVSizP54L2Jf3-rCyJVX5wP7w" alt=""><figcaption></figcaption></figure>

You won't need to sign up again if you've already registered with the CloudDefense Console interface. Simply log in using the account you previously created.

You may also log in using your corporate email if your organization already has an SSO (single sign-on) account with CloudDefense.


