Zscaler EASM
Import the internet-facing assets, open ports, certificates, and findings from Zscaler External Attack Surface Management into Guard.
The Zscaler External Attack Surface Management (EASM) integration imports what Zscaler EASM has discovered about your internet-facing attack surface into the Praetorian Guard Platform (PGP). Guard reads the assets, services, certificates, and findings for each EASM organization through Zscaler OneAPI and adds them to Guard as assets, ports, and risks. This guide walks you through creating a OneAPI client and connecting it to Guard.
What the integration does
Each time the integration runs, Guard signs in to Zscaler OneAPI and, for each organization in your EASM tenant:
- Reads the organization's internet-facing assets. Assets that EASM marks as stale are skipped.
- For each asset, reads its services. Guard adds the service's IP address as an asset, recorded together with the asset's hostname. For each TCP, UDP, or SCTP service, Guard also adds the open port on that IP address. An EASM asset with no service IP address is not imported.
- For each asset, reads its SSL/TLS certificates and adds each certificate's subject common name as an asset.
- Reads the organization's findings. Findings that EASM marks as stale are skipped. Guard adds each remaining finding as a risk on the asset it affects, when that asset is a domain or IP address:
- The risk is named after the finding.
- Its severity follows the EASM risk level: critical, high, medium, and low map to the same severity in Guard, and any other level becomes informational.
- Its first-seen and last-seen dates come from EASM.
- Its proof is the finding's scan evidence from EASM, or the finding's description when there is no evidence.
Imported risks start in the Detected state for you to triage.
Guard also drops assets it should not scan:
- Loopback, link-local, multicast, and unspecified addresses.
- IP addresses in public cloud provider ranges, and domains that resolve to a public cloud provider.
- Private IP addresses, such as
10.0.0.0/8or192.168.0.0/16, and domains that do not resolve in public DNS. - Any single IP address, public or private, that does not answer a single ping within half a second. IP ranges are not pinged.
To import private and non-responding assets, contact Praetorian support.
The integration only reads from Zscaler. It does not change EASM findings, organizations, or settings.
Prerequisites
- A Zscaler EASM tenant that signs in through Zidentity. Guard connects through Zscaler OneAPI, which requires Zidentity.
- A Zidentity administrator account that can create API clients.
- The Zidentity vanity domain for your tenant: the
acmepart ofacme.zslogin.net. - Permission to add integrations in Guard.
Step 1: Create a OneAPI client in Zidentity
- In the Zidentity admin portal, create an API client.
- On the client's Resources tab, assign a read-only EASM API role.
- Save the client, then copy the Client ID and Client Secret and store them safely.
One API client can serve several Zscaler products. To also import ZIA, ZPA, or ZDX data through the same integration, assign an API role for each of those products too.
Step 2: Connect Zscaler in Guard
- In Guard, go to Integrations and open Cyber Asset Attack Surface Management → Zscaler.
- Enter:
- Client ID: the OneAPI client ID from step 1.
- Client Secret: the OneAPI client secret from step 1.
- Vanity Domain: your Zidentity hostname prefix, for example
acme. You can also enter the full host,acme.zslogin.net.
- Keep EASM (External Attack Surface Management) selected. ZIA and ZDX are also selected by default. Clear any product your API client has no role for.
- Click Connect.
Before saving, Guard requests an access token from Zidentity and reads your EASM organizations. Guard checks every product you selected, and stops at the first one that fails, shows the error, and does not save the integration. Guard repeats these checks at the start of every run, so if the client later loses access to one selected product, no product imports until you restore the access or clear that product.
You can add more than one Zscaler integration, for example one per tenant.
Verify the integration
After the first run, go to Vulnerabilities and filter by an asset that has an open finding in Zscaler EASM. The finding should appear as a risk with the same name. On Assets, the asset's IP address should show the open ports EASM reported.
Troubleshooting
If you need help with this integration, contact support@praetorian.com.