Overview
Arnica is a code security posture management (CSPM) platform focused on developer-centric risk signals: hardcoded secrets, risky code changes, overprivileged tokens, and supply chain threats. The Pwnbook integration pulls Arnica findings into your organization for consolidated review.Prerequisites
- An Arnica account
- An Arnica API token with read access
- Your Arnica organization ID
- Admin or Owner access in Pwnbook to configure the integration
Credentials required
Setup
1
Generate an Arnica API token
- Log in to your Arnica account.
- Go to Settings → Integrations → API Access.
- Click Generate Token.
- Give the token a descriptive name (e.g.,
pwnbook). - Assign Read permissions.
- Copy the token.
2
Find your organization ID
Your Arnica organization ID is displayed in the URL or in Settings → Organization Details.
3
Configure the integration in Pwnbook
- Go to Organization Settings → Marketplace → Arnica.
- Click Configure.
- Enter your API Token and Organization ID.
- Click Save & Test.
What gets synced
Viewing findings in Pwnbook
Arnica findings appear under Security Findings → Arnica in your organization. You can filter by severity, finding type, and repository. Findings can be tracked through remediation and assigned to tasks.Disconnecting
To remove the Arnica integration:- Go to Organization Settings → Marketplace → Arnica.
- Click Disconnect.
- Confirm.