Integration: RocketCyber and Bitdefender GravityZone
RocketCyber
NAVIGATION Integrations > Endpoint Security > Bitdefender Monitor
PERMISSIONS Provider Owner or Organization Owner role (required for App Store and Integrations access)
Bitdefender GravityZone
NAVIGATION Welcome menu > My Account > API Keys
PERMISSIONS GravityZone account with Manage Networks, Manage Users, Manage Company, and View and analyze data rights
The RocketCyber and Bitdefender integration imports threat data from your Bitdefender GravityZone Control Center into RocketCyber, giving you visibility into Bitdefender GravityZone detections alongside your other security telemetry.
Mapping routes future Bitdefender detections to the correct RocketCyber organization automatically; it won't change any existing results. You can skip this if you're only using Bitdefender for a single organization, or if you're comfortable routing all detections to one RocketCyber org.
Prerequisites
Before configuring the integration:
-
A GravityZone account with Manage Networks, Manage Users, Manage Company, and View and analyze data rights
-
A RocketCyber user with the Provider Owner or Organization Owner role
-
The Bitdefender Monitor app enabled in the RocketCyber App Store
-
At least one company with managed endpoints (Bitdefender agents installed and checking in) in GravityZone. If GravityZone shows "You have no managed endpoints yet," there's no threat data yet for RocketCyber to pull or map; this isn't a RocketCyber configuration issue.
How to...
-
Go to your RocketCyber dashboard.
-
Click App Store in the side navigation menu.
-
Find the Bitdefender Monitor tile and click its toggle so it turns green, indicating the app is active.
Once enabled, the app also appears as a tile on the Dashboard, with Review and Configure buttons.
Clicking Configure from the Dashboard no longer opens a credential form directly; it displays a message directing you to the Integrations tab, where all setup now takes place.
-
Log in to the Bitdefender GravityZone Control Center.
-
Click the Welcome menu in the upper-right corner and select My Account.
-
Scroll to the API Keys section and click Add.
-
Enter a description for the key and select the APIs needed for threat data access. Your GravityZone account must have Manage Networks, Manage Users, Manage Company, and View and analyze data rights for the key to work correctly. Click Save.
-
Click the new API Key to copy it. Copy and store it somewhere safe right away; Bitdefender GravityZone only displays the full key once, in this window. Once you close it, the key can't be viewed again anywhere in GravityZone, and you'll need to generate a new one if it's lost.
-
In RocketCyber, go to Integrations in the side navigation menu.
-
Select the Endpoint Security tab.
-
Select the Bitdefender Monitor sub-tab.
-
Enter your Bitdefender GravityZone API access token in the Bitdefender access token field.
-
Confirm the BitDefender URL field (defaults to https://cloud.gravityzone.bitdefender.com/api).
-
Optional: click Credential Test to verify the token before proceeding.
-
Click Authenticate.
-
After authenticating, the screen shows Pull Tenants, Save Map, and Clear Existing Credential, along with a banner: "Complete setting up your credential by clicking Save Map."
-
Click Pull Tenants to retrieve your GravityZone companies, then match them to the corresponding RocketCyber organizations in the mapping fields that appear.
-
Click Save Map to complete setup.
NOTE Pull Tenants depends on Bitdefender GravityZone data being present. If your Bitdefender GravityZone account has no companies with managed endpoints yet, Pull Tenants may return nothing to map. Confirm agents are installed and checking in before troubleshooting this as a RocketCyber issue.
NOTE About organization mapping across apps: Some Endpoint Security integrations (formerly including SentinelOne and Webroot) historically required manually entering a unique site ID or keycode into a mapping chart at the Provider level, before connecting the app. That mechanism has been retired: SentinelOne and Bitdefender Monitor are both now configured under Integrations > Endpoint Security using the same credential/URL/Authenticate flow described above.
Once authenticated and mapped, Bitdefender GravityZone threat data will begin flowing into your RocketCyber dashboard.
FAQ
A Bitdefender GravityZone API Access Token, generated from an account with Manage Networks, Manage Users, Manage Company, and View and analyze data rights.
Bitdefender GravityZone only displays the full key once, at the moment it's created. If you navigate away or close the page without copying it, you won't be able to retrieve it again; you'll need to generate a new API key and repeat the setup steps.
This most likely means your Bitdefender GravityZone account has no companies with managed endpoints yet. GravityZone will show a "You have no managed endpoints yet" message in this case. Install and activate at least one Bitdefender agent, then try Pull Tenants again.
No, for Bitdefender Monitor, mapping is done after authenticating, using Pull Tenants and Save Map. This differs from the older manual-mapping process used by some legacy integrations, which required mapping to be set up in advance.
Clicking Configure from the Dashboard now redirects you to Integrations > Endpoint Security > Bitdefender Monitor, where all setup is handled.














