Compliance Integrations / Drata

Drata Integration

Push scan results to Drata's Evidence Library as structured compliance evidence. API key setup, per-scan sync, all Drata plans.

Overview

AttackerView connects to Drata to automatically push vulnerability evidence to your compliance controls. After each scan completes, AttackerView generates a structured evidence document and uploads it to the relevant controls in Drata's Evidence Library.

The integration works on all Drata plans and uses Drata's Evidence Library API. No custom connection setup or schema configuration required on Drata's side.

Prerequisites

  • An active AttackerView account on the Watchtower plan or higher
  • A Drata account with API access enabled
  • A Drata API key (generated in Drata's Connections settings)
  • At least one domain added to AttackerView

Setup

The setup uses an API key from Drata. The whole process takes about a minute.

Step 1: Generate a Drata API key

  1. Log into your Drata account
  2. Go to Settings then API Keys (or Connections, depending on your Drata version)
  3. Click Generate API Key
  4. Copy the key. You'll paste it into AttackerView next.

Step 2: Connect in AttackerView

  1. Go to Settings in your AttackerView dashboard
  2. Under Compliance Integrations, click Add Drata
  3. Paste your Drata API key
  4. Select your region (North America, Europe, or Asia-Pacific)
  5. Click Save

Existing scan results are synced within a minute of connecting. After that, evidence is pushed automatically whenever findings change.

Region selection

Drata operates in three regional data centers. Select the one that matches your Drata account:

RegionDashboard URLSelect in AttackerView
North Americaapp.drata.comNorth America
Europeapp.eu.drata.comEurope
Asia-Pacificapp.apac.drata.comAsia-Pacific

If you're not sure which region you're on, check the URL when you log into Drata.

What gets synced

After each scan completes, AttackerView generates a structured JSON evidence document for the scanned domain and uploads it to Drata. The document contains:

{
  "source": "AttackerView",
  "version": "1.0",
  "generatedAt": "2026-02-28T12:00:00Z",
  "domain": "example.com",
  "scanId": "scan_abc123",
  "scanCompletedAt": "2026-02-28T11:55:00Z",
  "summary": {
    "totalFindings": 12,
    "bySeverity": { "critical": 1, "high": 3, "medium": 4, "low": 4 }
  },
  "findings": [
    {
      "id": "av:example.com:tls-cert-expiring",
      "title": "TLS Certificate Expiring Soon",
      "severity": "medium",
      "status": "open",
      "category": "TLS",
      "target": "https://example.com",
      "evidence": "Certificate expires in 12 days",
      "firstSeenAt": "2026-02-01T00:00:00Z",
      "lastSeenAt": "2026-02-28T11:55:00Z",
      "compliance": {
        "soc2": ["CC6.1"],
        "iso27001": ["A.8.24"],
        "pciDss": []
      },
      "remediationUrl": "https://app.attackerview.com/app/d/..."
    }
  ]
}

This document is uploaded to every Drata control tagged with a matching compliance framework. For example, a finding with SOC 2 compliance tags gets attached as evidence to all Drata controls tagged "SOC 2".

Sync behavior

Drata evidence is synced in two ways:

Initial sync

When you first connect Drata, all existing open findings across your domains are pushed within a minute. You don't need to run a new scan to get your current results into Drata.

Ongoing sync

After the initial sync, evidence is pushed whenever findings change. This includes:

  • Manual scans triggered from the dashboard
  • API-triggered scans from your CI/CD pipeline
  • Watchtower monitoring scans (sentinel, patrol, and recon)
  • Retests of individual findings

Each push is scoped to the domain that was scanned. Evidence accumulates in Drata's Evidence Library over time, giving auditors a history of scan results.

Control mapping

AttackerView tags each finding with compliance frameworks (SOC 2, ISO 27001, PCI DSS, HIPAA). For PCI DSS these are supporting evidence for your assessor, not an ASV scan. When evidence is pushed to Drata, it's attached to every Drata control tagged with the matching framework. For example, a finding tagged SOC 2 gets uploaded to all controls in your Drata workspace that carry the "SOC 2" framework tag. No manual mapping needed.

See the full framework and control reference for details.

What your auditor sees

Evidence appears in Drata's Evidence Library linked to the relevant DCF controls. Each uploaded document includes:

  • Structured JSON with all finding details, human-readable in Drata's evidence viewer
  • Scan timestamp for evidence freshness
  • Summary counts by severity for quick assessment
  • Deep links back to AttackerView for each finding's full detail and remediation guidance

Over time, Drata accumulates a history of evidence uploads that demonstrates continuous monitoring and remediation to auditors.

Disconnecting

Go to Settings and remove the Drata integration. This deletes the stored API key from AttackerView and stops all evidence pushes. Evidence already uploaded to Drata is retained per Drata's data retention policies.

If you need to change your API key or region, remove the integration and add it again with the new values.

Troubleshooting

Authentication errors

Your API key may have been revoked or expired in Drata. Generate a new key in Drata's API settings and update it in AttackerView. If the error persists, verify you've selected the correct region.

Evidence isn't appearing in Drata

Existing findings are synced within a minute of connecting. If nothing appeared, check Settings for any error messages on the integration. Common causes: wrong region selected, or API key was revoked.

Wrong region selected

If you selected the wrong region, evidence uploads will fail with connection errors. Remove the integration and re-add it with the correct region. Check your Drata dashboard URL to confirm which region you're on.

Evidence appears but isn't linked to controls

AttackerView maps findings to Drata controls based on compliance framework references. If a finding doesn't have compliance tags (e.g., informational findings), it won't be linked to specific controls. The evidence document will still be available in Drata's general Evidence Library.

FAQ

Does this work on all Drata plans?

Yes. The integration uses Drata's Evidence Library API, which is available on all plans. It does not require Drata's Advanced or Enterprise plan.

Can I use Vanta and Drata at the same time?

Yes. Each integration operates independently. The same findings appear in both platforms.

What happens if I downgrade from a paid plan?

The integration is paused, not deleted. Evidence pushes stop until you re-upgrade. Data already in Drata is retained. Re-upgrading resumes automatic evidence pushes.

Does Drata send data back to AttackerView?

No. The integration is one-directional. AttackerView pushes evidence to Drata. Drata does not send webhooks or data back.

How is this different from the Vanta integration?

Vanta uses OAuth and syncs all findings every few minutes as structured vulnerability records. Drata uses an API key and receives evidence documents per-domain after each scan. Vanta auto-creates compliance tests; Drata maps evidence to existing controls. See the comparison table for a full breakdown.

See also