Black Kite
Connect Black Kite to Guard to automatically import third-party cyber-risk assets and vulnerability findings.
The Black Kite integration allows Guard to automatically ingest assets and vulnerability findings from a connected Black Kite organisation. Guard imports only the companies you name as your own, so third parties your tenant monitors are not imported.
How it works
Guard authenticates to the Black Kite API using OAuth2 client credentials scoped to your tenant. On each sync, Guard:
- Enumerates companies in the connected Black Kite organisation and keeps only those that match your configured ecosystem names or company domains.
- Imports each in-scope company's active subdomains as assets.
- Maps per-category vulnerability findings to risks, using the CVSS score for severity when one is present.
- Imports fraudulent and look-alike domain findings as risks.
Each Guard account uses its own OAuth2 client credential.
Prerequisites
- A Black Kite account with access to the organisation you want to import.
- An OAuth2 client ID and client secret generated in Black Kite under Integrations > Black Kite API, scoped to the tenant you want to import.
- The name of the Black Kite ecosystem that groups your own companies (for example, "Our Enterprise"), the domains of the companies you want to import, or both.
Connect Black Kite to Guard
- In Guard, navigate to Integrations > Security Ratings > Black Kite.
- Enter your Black Kite Client ID and Client Secret.
- Enter Ecosystem Name(s), Company Domains, or both, as comma-separated lists. At least one is required.
- Select Connect.
Guard validates the credentials and confirms that your ecosystem names or company domains match at least one company in the tenant, then begins the initial import. Subsequent syncs run automatically.
What is imported
Disconnecting the integration
To remove the integration, navigate to Integrations > Security Ratings > Black Kite and select Disconnect. Existing assets and risks that were imported are not automatically deleted.
Still need help? Ask the team