Import Data from SecurityScorecard
Import SecurityScorecard findings into Mondoo alongside your own scan results.
Mondoo can import data from SecurityScorecard and combine it with your Mondoo findings. SecurityScorecard evaluates your external attack surface by domain across risk factors such as network security, DNS health, patching cadence, and application security. The unified view gives you Mondoo's security visualization, prioritization, and ticketing on top of that external posture data.
Prerequisites
- Editor or Owner access to the Mondoo space
- A SecurityScorecard account
- An API token from that account
Generate a SecurityScorecard API token
- Log into SecurityScorecard.
- Go to My Settings > API.
- Generate an API token and copy it. You need it in the next section.
To learn more, see the SecurityScorecard API documentation.
A SecurityScorecard API token can reach every domain your SecurityScorecard account can see. The domain you enter in Mondoo controls which portfolio slice gets imported, not what the token can access.
Add a SecurityScorecard integration
In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL. On the Install Integration page, find the integration you want by browsing a category or searching by name:
-
Under Third-Party Data, select SecurityScorecard.
-
In Integration Name, enter a name for the integration.
-
Fill in:
- Domain. The domain to import from your SecurityScorecard portfolio, for example
example.com. - API Token. The token you generated in SecurityScorecard.
- Domain. The domain to import from your SecurityScorecard portfolio, for example
-
Leave Create new assets for unique detections enabled so Mondoo adds an asset for every domain SecurityScorecard discovers that doesn't already exist in this space. Disable it to only attach findings to assets you already track.
-
Select Create Integration.
What Mondoo imports
Mondoo imports the domains and subdomains SecurityScorecard has discovered for your configured domain as assets. IP addresses that don't map to a known domain are imported as standalone assets. SecurityScorecard's findings are security issues and misconfigurations (such as weak TLS ciphers or missing DMARC records) rather than CVEs. They attach to the matching asset.
To see the imported assets, navigate to the space and select Inventory > Assets. Assess and improve your security to review and prioritize the findings alongside the rest of your inventory.
Manage this integration
To open an existing integration, navigate to the space, select Integrations in the side navigation, choose SecurityScorecard, then select the integration.
From the integration detail page, you can:
- Edit settings. Select the edit (pencil) icon to update the integration name, domain, or asset-creation preference. Leave API Token blank to keep the current token, or enter a new one to rotate it.
- Trigger an immediate import. Select Run.
- Remove the integration. Select the trash icon and confirm.
After you connect
Once the import finishes, your SecurityScorecard findings appear in Mondoo alongside its own. Assess and improve your security to review and prioritize them.