| ArmorCode status | SOCRadar status |
|---|---|
| Remediated | RESOLVED |
| Triage | INVESTIGATING |
| False Positive | FALSE_POSITIVE |
SOCRadar Attack Surface Management Now Integrates with ArmorCode ASPM
Your team has a process for triaging vulnerabilities. The question is whether findings from your external attack surface ever reach it. An internet-facing asset carrying a critical CVE may be sitting outside the system your application security team reviews each day. When analysts have to move findings between tools and repeat status updates by hand, even a clear vulnerability alert turns into extra work and conflicting records of what still needs attention.
SOCRadar’s external vulnerability findings now flow natively into ArmorCode Application Security Posture Management, and the decisions your analysts make there flow back to SOCRadar.
An ASPM Platform Can Only Manage What It Knows About
ArmorCode is built to consolidate, prioritize, and drive remediation across findings. Discovering what your organization has exposed on the internet is a separate discipline: continuously mapping domains, subdomains, IPs, cloud assets, certificates, and services that belong to you, including the ones no one told the security team about.
Shadow IT, a forgotten staging environment, a subsidiary’s domain, an asset spun up outside the change process: none of these appear in a scanner’s target list because nobody added them. A vulnerability on such an asset goes unaddressed because the asset was never in scope.
Prioritization Depends on Asset Context
Prioritization takes more than collecting alerts. CISA recommends that organizations monitor its Known Exploited Vulnerabilities catalog and prioritize remediation of the vulnerabilities it lists. Acting on guidance like that requires knowing which of your assets are affected, which application each asset belongs to, and what work is already underway.
The coordination problem continues after triage. If an analyst adjusts severity or records that a finding has been remediated in one platform, the source system needs to reflect that decision. Otherwise, a colleague reviewing the original alert repeats an investigation or asks for work that is already done. A useful integration has to carry findings in and decisions back.
Where the Findings Come From: SOCRadar Attack Surface Management
SOCRadar Attack Surface Management continuously discovers your external-facing assets and identifies the vulnerabilities affecting them. For this integration, ASM supplies both halves of what an analyst needs to start work: the vulnerability finding and the affected-asset context around it.
What ASM contributes:
- Discovery of assets across your external attack surface, including ones outside your inventory
- Identification of vulnerabilities affecting those exposed assets
- CVE, CVSS, CWE, and severity detail for triage
- A concrete link between each vulnerability finding and the asset it affects
ASM is one module of the wider SOCRadar Extended Threat Intelligence Platform, which also covers Dark Web monitoring, brand protection and takedown services, supply chain intelligence, and vulnerability intelligence.
Integration with ArmorCode
The integration is native and bidirectional, connecting the two platforms over an API with no middleware or custom scripts.
Findings in: ArmorCode ingests SOCRadar ASM findings on your configured scan schedule, carrying CVE, CVSS, CWE, severity, and affected-asset information. The integration also discovers SOCRadar assets and maps them into ArmorCode’s Group › Subgroup › Environment structure, so external findings arrive inside the organizational model your teams already use.
Decisions back: Status and severity changes made in ArmorCode are pushed back to SOCRadar. Status mappings are:
Severity updates map one-to-one. Synchronization is available only for findings that carry a SOCRadar alarm_id.
The connector is a connection layer that carries findings you are already licensed to receive from SOCRadar into ArmorCode. Enabling it does not grant access to SOCRadar data on its own.
Requires the ASM module and Company API access: Authentication uses your SOCRadar Company API Key and Company ID. For bidirectional updates, you must also configure a fixed Acting User Email belonging to a registered SOCRadar user. If that email is not registered, the push fails silently on the ArmorCode side. When reviewing activity history, note that severity updates sent from ArmorCode appear as Manual in SOCRadar due to a limitation in the SOCRadar severity API; status updates are attributed correctly.
How It Works in Practice
You open ArmorCode after a scheduled import and find a high-severity SOCRadar finding affecting a public-facing application. You review its CVE, CVSS, and CWE detail, then use the affected asset and its Group › Subgroup › Environment mapping to see where it belongs and which team owns it. You start the investigation without first copying the finding into another record.
You set the finding to Triage in ArmorCode; the SOCRadar status becomes INVESTIGATING. If your assessment calls for a severity change, that goes back too. After the application team ships the fix and you validate it, you mark the finding Remediated, and SOCRadar records RESOLVED.
The asset in that scenario matters as much as the workflow. SOCRadar discovered it as part of your external attack surface, which is why the vulnerability reached a triage queue at all.
Take the Next Step
For teams already running ArmorCode, this integration brings SOCRadar’s external vulnerability findings into an established ASPM workflow and keeps status and severity decisions connected to the source findings. Your analysts spend less effort transferring records and more time on the vulnerabilities those records describe.
ArmorCode is one of many destinations SOCRadar feeds. The same intelligence reaches SIEM, SOAR, TIP, ITSM, and vulnerability management tools across the SOCRadar integrations ecosystem, so standardizing on SOCRadar as the source of external findings does not tie you to a single workflow surface.
Enable the connector in ArmorCode under Manage › Security Tools › SOCRadar. Setup takes about 10 minutes; have your Company API Key, Company ID, and registered Acting User Email ready. In the SOCRadar platform, Settings › API & Integrations › Integrations › ArmorCode Integration holds the setup guide, field and status mappings, and troubleshooting. Contact your SOCRadar Customer Success Manager or sales team to confirm ASM module and Company API access.
