Skip to main content

Integrating Invicti Standard with TFS

This document is for:
Invicti Standard

TFS (Team Foundation Server) is a Microsoft product that covers the entire application development lifecycle, including issue tracking, reporting, project management, and testing capabilities. TFS 2012 and later versions are supported.

This document explains how to configure Invicti Standard to send a detected vulnerability to TFS for comprehensive application development lifecycle management.

TFS Fields

This table lists and explains the TFS fields in the Send to Actions tab.

Button/Section/FieldDescription
AddClick to add an integration.
DeleteClick to delete the integration and clear all fields.
Create Sample IssueOnce all relevant fields have been configured, click to create a sample issue.
ActionThis section contains general fields about the Send To action.
Display NameThis is the name of the configuration that will be shown in menus.
MandatoryThis section contains fields that must be completed.
Project URLThis is the TFS project web address.
UsernameThis is the name of the user. If you are using a personal access token (see below), leave this field blank.
Password or TokenThis is the password of the user or the personal access token. (Since March 2, 2020, Azure DevOps supports only Access Token.)
VulnerabilityThis section contains fields with vulnerability details.
Body TemplateThis is the template file that is used to create description fields.
Title FormatThis is the string format that is used to create the vulnerability title.
OptionalThis section contains optional fields.
DomainThis is the domain of the user.
Work Item TypeThis is the type of the work item.
Assigned ToThis is the user to whom the issue is assigned.
TagsThese are the work item tags, separated by a semicolon (;).
Custom FieldsClick the ellipsis to open the Custom Fields Editor dialog.

How to Integrate Invicti Standard with TFS

Follow these steps to configure the TFS integration in Invicti Standard:

  1. Open Invicti Standard.
  2. From the Home tab on the ribbon, click Options. The Options dialog is displayed.
  3. Click Send To Actions.
Invicti Standard Options dialog showing Send To Actions configuration menu
  1. From the Add dropdown, select TFS. The TFS fields are displayed.
TFS integration configuration form showing mandatory and optional fields for setup
  1. In the Mandatory section, complete the connection details:
    • Project URL
    • Username
    • Password or Token
Authentication Options

If you use a personal access token, leave the Username field empty. If you have alternate credentials, fill in the Username and Password fields. To learn how to create a token, read Authenticate access with personal access tokens external documentation.

  1. In the Vulnerability section, you can change the Body Template and Title Format.
note

Body templates are stored in %userprofile%\Documents\Invicti\Resources\Send To Templates. If you use your own custom templates, store them in this location.

  1. In the Optional settings you can specify:
    • Domain
    • Work Item Type
    • Assigned To
    • Tags
    • Custom Fields
Work Item Configuration

To learn about the Work Item Type field, read Add and manage work type items external documentation. To learn about Custom fields, read Add and manage fields for an inherited process external documentation.

  1. To set custom field values, in the Custom Fields field, click the ellipsis button.
  2. In the Edit Custom Field Value field, enter the relevant value.
TFS custom fields editor dialog for configuring custom field values
  1. Click OK.
  2. Click Create Sample Issue to confirm that Invicti Standard can connect to the configured system. The Send To Action Test confirmation dialog is displayed.
TFS test connection dialog showing Create Sample Issue confirmation and results
  1. In the Send To Action Test dialog, click the Issue number link to open the issue in TFS in the default browser.
TFS test connection dialog showing Create Sample Issue confirmation and results

How to Export Reported Vulnerabilities to Projects in TFS

Prerequisites

Please ensure that you have first configured TFS integration (see How to Integrate Invicti Standard with TFS).

  1. Open Invicti Standard.
  2. From the ribbon, select the File tab. Local Scans are displayed. Double-click the relevant scan to display its results.
Invicti Standard scan results view showing vulnerabilities ready for export to TFS
  1. In the Issues panel, right click the vulnerability you want to export to TFS and select Send to TFS. (Alternatively, from the ribbon, click the Vulnerability tab, then Send to TFS.) A confirmation message and link is displayed at the bottom of the screen.
Invicti Standard scan results view showing vulnerabilities ready for export to TFS
  1. Click the TFS Send to Action is executed for the selected vulnerability link to see the newly-created issue in TFS.
  2. The vulnerability is automatically exported to TFS. You can view it in TFS's Work tab.
Invicti Standard scan results view showing vulnerabilities ready for export to TFS

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?