Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 18 additions & 2 deletions cloud/examples/connectjira.mdx
Original file line number Diff line number Diff line change
@@ -1,42 +1,42 @@
---
title: "Create Tickets for Jira"
description: "Create actionable follow up for exploitable vulnerabilities in Jira"

Check warning on line 3 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L3

Did you really mean 'Jira'?
sidebarTitle: "Create Tickets for Jira"

Check warning on line 4 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L4

Did you really mean 'Jira'?
---

## Summary
ProjectDiscovery Cloud Platform has provided you with comprehensive scan results on exploitable vulnerabilities - what's next? You want to get your team involved and have a more seamless pipeline between data visibility, discovery, and follow up.
For your organization this means getting important tasks into Jira!

Check warning on line 9 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L9

Did you really mean 'Jira'?


In this example, we'll walk through setting up this important workflow for a brand new user. You will add assets, configure a Jira integration, and initiate a scan to create a ticket for your team to take action.

Check warning on line 12 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L12

Did you really mean 'Jira'?

### What You'll Do
In this walkthrough we're going to go step-by-step to complete the following actions:

Check warning on line 15 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L15

Did you really mean 'walkthrough'?

- Add Assets
- Configure Jira

Check warning on line 18 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L18

Did you really mean 'Jira'?
- Configure ProjectDiscovery Cloud Platform for Jira ticketing

Check warning on line 19 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L19

Did you really mean 'Jira'?
- Start a scan to test your new integration

### Prerequisites
To complete the integration you will need to have the correct permissions to access account details within Jira. Refer to [Atlassian's documentation](https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/) for additional details.

Check warning on line 23 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L23

Did you really mean 'Jira'?

<Note>If you are not a Jira administrator you may need your organization's Jira administrator for assistance in collecting these details. </Note>

**You will need the following:**

- Jira instance URL

Check warning on line 29 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L29

Did you really mean 'Jira'?
- Jira Account ID

Check warning on line 30 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L30

Did you really mean 'Jira'?
- Jira email

Check warning on line 31 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L31

Did you really mean 'Jira'?
- Jira API Token

Check warning on line 32 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L32

Did you really mean 'Jira'?
- Jira Project name

Check warning on line 33 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L33

Did you really mean 'Jira'?

## Add Assets

For this example we're going to stick with the simplest path and add assets to your PDCP environment by uploading a .TXT file with the domains you want to include for scanning.

If you already have assets in ProjectDiscovery Cloud Platform, you can skip ahead to Connecting Slack. For for other Asset upload options check out the docs on [Adding Assets.](/cloud/assets/adding-assets)

Check warning on line 39 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L39

'for' is repeated!


<Steps>
Expand All @@ -58,26 +58,26 @@

</Steps>

Once your assets, you will need to connect your ProjectDiscovery Cloud Platform to your Jira account.

Check warning on line 61 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L61

Did you really mean 'Jira'?

If you have questions on Assets - check out the [Assets - FAQ](/cloud/assets/overview#faq).

## Connecting Jira

Check warning on line 65 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L65

Did you really mean 'Jira'?
After adding your assets, you will need to connect your ProjectDiscovery Cloud Platform environment to Jira. There are two parts to this, the part you will need to complete in your Jira environment and the details you'll need to add to ProjectDiscovery Cloud Platform.

Check warning on line 66 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L66

Did you really mean 'Jira'?

Check warning on line 66 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L66

Did you really mean 'Jira'?

### Jira Setup

Check warning on line 68 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L68

Did you really mean 'Jira'?

Logged in to Jira as an administrator visit [this link]( https://id.atlassian.com/manage-profile/products) to locate your Jira instance URL.

Check warning on line 70 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L70

Did you really mean 'Jira'?

Check warning on line 70 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L70

Did you really mean 'Jira'?
You can also [use the REST API](https://developer.atlassian.com/cloud/jira/platform/rest/v3/) to obtain these details.

*Note: The format for URLs in Jira will vary depending on your account type (Jira Cloud vs on-prem)*

Check warning on line 73 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L73

Did you really mean 'Jira'?

Check warning on line 73 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L73

Did you really mean 'Jira'?

<Steps>
<Step title="Find your Jira instance URL">

Check warning on line 76 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L76

Did you really mean 'Jira'?
Log in to your Jira account and locate the following information:

Check warning on line 77 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L77

Did you really mean 'Jira'?
- Jira instance URL

Check warning on line 78 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L78

Did you really mean 'Jira'?
- Jira Account ID

Check warning on line 79 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L79

Did you really mean 'Jira'?
- Jira Project Name

Check warning on line 80 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L80

Did you really mean 'Jira'?

*Note: To locate your Jira instant URL - Click your Profile menu in the upper-right, then select **Profile**. In the URL after /people/ is your account ID.*

Expand All @@ -93,21 +93,21 @@
</Step>
</Steps>

Next up, you will be adding these details from Jira to your environment in ProjectDiscovery Cloud Platform!

Check warning on line 96 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L96

Did you really mean 'Jira'?

### ProjectDiscovery Cloud Platform Setup
Before getting started with this part of the setup ensure that you have completed the configuration required in Jira.

Check warning on line 99 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L99

Did you really mean 'Jira'?

<Steps>
<Step title="Launch the Jira integration in PDCP">
Navigate to **Scans → Configurations** and under Ticketing select Connect under the option for Jira.

Check warning on line 103 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L103

Did you really mean 'Jira'?
</Step>
<Step title="Add your config details">
In PDCP complete the information for Jira including:

Check warning on line 106 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L106

Did you really mean 'Jira'?
- A name for your Jira Configuration

Check warning on line 107 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L107

Did you really mean 'Jira'?
- Jira instance URL

Check warning on line 108 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L108

Did you really mean 'Jira'?
- Jira account ID

Check warning on line 109 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L109

Did you really mean 'Jira'?
- Jira Email

Check warning on line 110 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L110

Did you really mean 'Jira'?
- Jira API Token
- *(Optional) Select Enable for all scans option if desired (you can also select this option during scan creation)*
- Select **Next** to continue the Jira integration setup.
Expand All @@ -117,20 +117,36 @@
- Provide the **Jira Issue type** you want to have created.
- Add the Closed status. (Default is "Done" but this field can be edited)
- Choose your preferred options (toggle) for **Severity** and **Deduplication**.
- Add any Custom field details you want to include.
- Refer to [an example on custom fields from ProjectDiscovery](/opensource/nuclei/running#nuclei-reporting) (*scroll to Jira*)
- Add any Custom field details you want to include. Enter one entry per field, each mapping `id`, `name` or `freeform` to a value:

```yaml
customfield_00001:
name: 'Nuclei'
customfield_00002:
freeform: '{{.CVSSMetrics}}'
priority:
id: '{{if eq .Severity "critical"}}10104{{else}}4{{end}}'
```

<Note>
This box is the custom-fields block, so your entries go in directly. If you
paste an example that still has a `custom-fields:` (or `custom_fields:`)
line at the top, that line is ignored and the fields under it are used.
</Note>

- Use `id` or `name` for dropdown fields, and `freeform` for text fields.
- Review Atlassian's documentation on [creating custom fields](https://support.atlassian.com/jira-cloud-administration/docs/create-a-custom-field/), or [locating existing custom field IDs](https://confluence.atlassian.com/jirakb/how-to-find-any-custom-field-s-ids-744522503.html).
</Step>
<Step title="Finalize your configuration for Jira">
Once you're satisfied with your configuration select **Verify** to complete your Jira integration.

Check warning on line 141 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L141

Did you really mean 'Jira'?
</Step>
</Steps>

Now that your configuration is set up, you can create a scan and verify your Jira integration.

Check warning on line 145 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L145

Did you really mean 'Jira'?

## Create a Scan

The final step is to create a scan, verify that your Jira integration is set up correctly, and check for the corresponding ticket in the Jira project you configured.

Check warning on line 149 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L149

Did you really mean 'Jira'?

<Steps>
<Step title="Create a new scan">
Expand All @@ -153,7 +169,7 @@
</Steps>

## What's Next?
This example focuses on the process of integrating with Jira to create tickets for your team based on scan results.

Check warning on line 172 in cloud/examples/connectjira.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

cloud/examples/connectjira.mdx#L172

Did you really mean 'Jira'?

ProjectDiscovery Cloud Platform also supports workflows for alerting for Slack, MS Teams, Email and custom webhooks.

Expand Down
2 changes: 1 addition & 1 deletion opensource/nuclei/running.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

For automation in pipelines, see [Running Nuclei in CI/CD](/opensource/nuclei/ci-cd).

Nuclei supports various input formats to run template against, including urls, hosts, ips, cidrs, asn, openapi, swagger, proxify, burpsuite exported data and more. To learn more on using input specify options, you can refer [nuclei input formats](/opensource/nuclei/input-formats).

Check warning on line 19 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L19

Did you really mean 'urls'?

Check warning on line 19 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L19

Did you really mean 'ips'?

Check warning on line 19 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L19

Did you really mean 'cidrs'?

Check warning on line 19 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L19

Did you really mean 'asn'?

Check warning on line 19 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L19

Did you really mean 'proxify'?

Check warning on line 19 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L19

Did you really mean 'burpsuite'?

These inputs can be given to nuclei using `-l` and `-input-mode` flags.

Expand All @@ -25,13 +25,13 @@
-im, -input-mode string mode of input file (list, burp, jsonl, yaml, openapi, swagger) (default "list")
```

Executing nuclei against a list of inputs (urls, hosts, ips, cidrs, asn) is as simple as running the following command:

Check warning on line 28 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L28

Did you really mean 'urls'?

Check warning on line 28 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L28

Did you really mean 'ips'?

Check warning on line 28 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L28

Did you really mean 'cidrs'?

Check warning on line 28 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L28

Did you really mean 'asn'?

```bash
nuclei -l targets.txt
```

For running other input formats (burp, jsonl, yaml, openapi, swagger), you can use the `-im` flag to specify the input mode.

Check warning on line 34 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L34

Did you really mean 'jsonl'?

```bash
nuclei -l targets.burp -im burp
Expand Down Expand Up @@ -226,7 +226,7 @@
<Accordion title="For GitLab Project" icon="pencil">
```bash
export GITLAB_SERVER_URL=https://gitlab.com
# The GitLab token must have the read_api and read_repository scope

Check warning on line 229 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L229

Did you really mean 'read_api'?

Check warning on line 229 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L229

Did you really mean 'read_repository'?
export GITLAB_TOKEN=XXXXXXXXXX
# Comma separated list of repository IDs (not names)
export GITLAB_REPOSITORY_IDS=12345,67890
Expand Down Expand Up @@ -719,11 +719,11 @@

<Warning>
Do not modify the active **.nuclei-ignore** file. Nuclei can replace it during
a template update. To override the denylist, use [Nuclei

Check warning on line 722 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L722

Did you really mean 'denylist'?
configuration](/opensource/nuclei/running#nuclei-config) or the include flags.
</Warning>

To prioritize certain templates or tags over the [.nuclei-ignore](https://github.com/projectdiscovery/nuclei-templates/blob/master/.nuclei-ignore) file or denylist, you must use the `-include-templates` or `-include-tags` flags. This will ensure that the specified templates or tags take precedence over any `.nuclei-ignore` or denylist entries.

Check warning on line 726 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L726

Did you really mean 'denylist'?

Check warning on line 726 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L726

Did you really mean 'denylist'?

<Note>
Example of running blocked templates
Expand All @@ -735,9 +735,9 @@
</Note>

<Note>
Example of executing a specific template that is in the denylist

Check warning on line 738 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L738

Did you really mean 'denylist'?

Say that you have custom templates globbed (`*`) in the denylist on the Nuclei configuration file.

Check warning on line 740 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L740

Did you really mean 'globbed'?

```yaml
# ...
Expand Down Expand Up @@ -766,7 +766,7 @@

### Scan on internet database

Nuclei supports integration with [uncover module](https://github.com/projectdiscovery/uncover) that supports services like Shodan, Censys, Hunter, Zoomeye, many more to execute Nuclei on these databases.

Check warning on line 769 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L769

Did you really mean 'Shodan'?

Check warning on line 769 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L769

Did you really mean 'Censys'?

Check warning on line 769 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L769

Did you really mean 'Zoomeye'?

Here are uncover options to use -

Expand Down Expand Up @@ -852,7 +852,7 @@

### Template profiles

The `profile` setting accepts a file path or an extensionless community profile ID. For a relative YAML file path, Nuclei checks the current directory first and then `profiles/` in the active template root. For a profile ID, it searches that profile directory and its subdirectories for a matching YAML file.

Check warning on line 855 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L855

Did you really mean 'extensionless'?

A profile can provide targets through a multiline `targets-inline` value. A multiline `list` value also becomes inline targets, while a single-line `list` value remains a file path. Nuclei trims each target and ignores blank lines and lines that start with `#`.

Expand All @@ -860,14 +860,14 @@

### Storage locations

Nuclei keeps configuration, installed data, persistent state, and regenerable cache in separate directories:

Check warning on line 863 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L863

Did you really mean 'regenerable'?

| Purpose | Default location |
| --- | --- |
| User configuration | `$XDG_CONFIG_HOME/nuclei` |
| Public template installation target | `$XDG_DATA_HOME/nuclei/nuclei-templates` |
| Restart-persistent state | `$XDG_STATE_HOME/nuclei` |
| Regenerable cache | `$XDG_CACHE_HOME/nuclei` |

Check warning on line 870 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L870

Did you really mean 'Regenerable'?

`NUCLEI_CONFIG_DIR` remains a compatibility override for the user configuration directory, including `config.yaml`, signing keys, and reporting configuration. It does not change the XDG data, state, or cache locations.

Expand Down Expand Up @@ -1017,9 +1017,9 @@

## Nuclei Reporting

Nuclei comes with reporting module support with the release of v2.3.0 supporting GitHub, GitLab, and Jira integration, this allows nuclei engine to create automatic tickets on the supported platform based on found results.

Check warning on line 1020 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1020

Did you really mean 'Jira'?

| Platform | GitHub | GitLab | Jira | Markdown | SARIF | Elasticsearch | Splunk HEC | MongoDB |

Check warning on line 1022 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1022

Did you really mean 'Jira'?

Check warning on line 1022 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1022

Did you really mean 'Splunk'?
|-------------|:------:|:------:|:----:|:--------:|:-----:|:-------------:|:----------:|:-------:|
| Support | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |

Expand Down Expand Up @@ -1068,7 +1068,7 @@
index-name: nuclei
```

To forward results to Splunk HEC, create a config file with the following content and replace the appropriate values:

Check warning on line 1071 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1071

Did you really mean 'Splunk'?

```yaml
# splunkhec contains configuration options for splunkhec exporter
Expand All @@ -1087,19 +1087,19 @@
token: '$hec_token'
```

To forward results to Jira, create a config file with the following content and replace the appropriate values:

Check warning on line 1090 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1090

Did you really mean 'Jira'?

The Jira reporting options allows for custom fields, as well as using variables from the Nuclei templates in those custom fields.

Check warning on line 1092 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1092

Did you really mean 'Jira'?
The supported variables currently are: `$CVSSMetrics`, `$CVEID`, `$CWEID`, `$Host`, `$Severity`, `$CVSSScore`, `$Name`

In addition, Jira is strict when it comes to custom field entry. If the field is a dropdown, Jira accepts only the case sensitive specific string and the API call is slightly different. To support this, there are three types of customfields.

Check warning on line 1095 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1095

Did you really mean 'Jira'?

Check warning on line 1095 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1095

Did you really mean 'Jira'?

Check warning on line 1095 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1095

Did you really mean 'customfields'?

- `name` is the dropdown value
- `id` is the ID value of the dropdown
- `freeform` is if the customfield the entry of any value

Check warning on line 1099 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1099

Did you really mean 'customfield'?

To avoid duplication, the JQL query run can be slightly modified by the config file.
The `CLOSED_STATUS` can be changed in the Jira template file using the `status-not` variable.

Check warning on line 1102 in opensource/nuclei/running.mdx

View check run for this annotation

Mintlify / Mintlify Validation (projectdiscovery) - vale-spellcheck

opensource/nuclei/running.mdx#L1102

Did you really mean 'Jira'?
`summary ~ TEMPLATE_NAME AND summary ~ HOSTNAME AND status != CLOSED_STATUS`

```yaml
Expand Down Expand Up @@ -1131,7 +1131,7 @@
# freeform can be used if the custom field is just a text entry
# Variables can be used to pull various pieces of data from the finding itself.
# Supported variables: $CVSSMetrics, $CVEID, $CWEID, $Host, $Severity, $CVSSScore, $Name
custom_fields:
custom-fields:
customfield_00001:
name: 'Nuclei'
customfield_00002:
Expand Down
Loading