Skip to main content

Detectify

Detectify is a leading external attack surface management and web application security platform that continuously monitors and tests websites, web applications, and external digital assets for security vulnerabilities and misconfigurations. The platform specializes in automated security testing, vulnerability scanning, and attack surface monitoring to help organizations identify and remediate security weaknesses before they can be exploited by attackers.

CategoryVulnerability management
DirectionQuery source
Sign-inAPI Token & Secret
Query languagesSQLite
Websitedetectify.com

Before you start​

Huntbase signs in to Detectify with API Token & Secret. Create the credential in Detectify first, then keep it to hand for the Connect step.

  1. In Detectify, open Team settings from the user menu and go to the API-keys tab. You need team admin permissions to see it.
  2. Click Generate API key and optionally enter a name and description.
  3. Enable the required message signature to get a secret key for the API Secret field.
  4. Set the key's permissions, then copy the key and the secret.
Watch out for
  • The secret key isn't created by default. Enable the message signature on the key after you create it.

For the vendor's own instructions, see Detectify API key documentation.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Detectify​

  1. Go to Connections and click New connection, or click New connection on the Detectify product page.
  2. On Product, pick Detectify and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Detectify lives:

FieldRequiredNotes
Base URLYesThe Detectify API base URL, https://api.detectify.com/rest.

Credentials​

The only Method is API Token & Secret. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
API TokenYesSecret — not shown again after you save it.
API SecretYesThe secret key from the key's message signature setting. Detectify only offers signing with a secret key on the Professional plan. Secret — not shown again after you save it.
API Token (v3)YesA key for Detectify API v3, created on the same API-keys tab. The connection needs a key for each API version because each version exposes different data. Secret — not shown again after you save it.

Query it​

Once connected, Detectify can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
SQLiteSQL across this source and every other connected source.

Next steps​