Skip to main content

Contrast Security

Application Security

The Contrast Security connector integrates with the Contrast Security Interactive Application Security Testing (IAST) platform. It synchronizes application inventory, open-source library (SCA) data, instrumented servers, and the vulnerabilities discovered by Contrast agents. Vulnerability findings are split into a finding (Vulnerability) and a shared definition (Vulnerability Definition) so that severity, recommendation, and weakness metadata can be normalized across occurrences.

The connector iterates over every organization available to the configured credentials and pulls the following data:

  • Applications monitored by Contrast.
  • Libraries (open-source dependencies) detected across applications and servers.
  • Servers running a Contrast agent.
  • Vulnerabilities (traces) and their Vulnerability Definitions, optionally enriched with analysis, consequence, and remediation details.

Data retrieved from Contrast Security

Connector ObjectRequiredMaps to Data Model
ApplicationYesApplication
LibraryYesPackage
ServerYesHost
VulnerabilityYesVulnerability
Vulnerability DefinitionYesVulnerability Definition

Model relationships

note

For detailed steps on how to view the data retrieved from Contrast Security in the Brinqa Platform, see How to view your data.