Overview
Veracode helps organizations identify and manage application security risks through SCA (Software Composition Analysis), SAST (Static Application Security Testing), and DAST (Dynamic Application Security Testing). By consolidating results from these methods, Veracode delivers centralized visibility into vulnerabilities, license compliance issues, and code flaws across the development lifecycle.
The Balbix integration automatically ingests Veracode application inventory and findings, normalizes the data, and enriches it with context for accurate prioritization.
Balbix leverages AI to aggregate, normalize, and deduplicate data ingested from across your IT and security ecosystem. This unified view of inventory and exposures enriched with operational and business context, enables deployment gap analysis, risk-based exposure management, and cyber risk quantification. These insights help organizations drive faster, more informed, and more scalable risk reduction.
Integration Summary
Integration Type | Fetch: An inbound API integration that retrieves application security data from Veracode using the Veracode REST APIs (commercial region base URL |
Types of Assets Fetched | Application profiles from the Veracode portfolio, including associated sandboxes and policy context via the Applications API. For web apps and APIs scanned dynamically, links between Dynamic Analysis results and application profiles are supported via the Dynamic Analysis linking capability. |
Types of Data Fetched | Vulnerability findings across scan types via the Findings API: Static Analysis, Dynamic Analysis, Software Composition Analysis (SCA), and Manual Penetration Testing. Data typically includes CWE, severity, status, mitigation state, and timestamps (created, first observed, last seen, closed). Third‑party component inventory and SCA findings via the SCA REST API, including component names, versions, advisories, policy status, and SBOM‑related information. |
Prerequisites
Follow the procedure documented in https://docs.veracode.com/r/REST_APIs_Quickstart to generate credentials for the Balbix connector.
Field Mappings
Imported Field | Balbix Field | Comments |
|---|---|---|
API: /appsec/v1/applications | ||
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
| |
|
|
|
|
|
|
API: /appsec/v2/applications/{app_guid}/findings?scan_type=SCA | ||
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
API: /appsec/v2/applications/{app_guid}/findings?scan_type=STATIC | ||
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
Set up your Veracode connector
Follow this procedure to add a Veracode connector: