Introducing DefectDojo Connectors

Introducing DefectDojo Connectors

The DefectDojo team is always evolving the platform to support the needs of enterprise security professionals. Security vulnerability data ingestion is one of the key requirements that DefectDojo aims to solve. Connectors are the latest way your vulnerability data can be imported into DefectDojo.

What are DefectDojo Connectors?

Connectors allow DefectDojo to interact directly with third-party security tools’ APIs to retrieve information about “vendor-equivalent products” - the vendor resource closest in nature to a DefectDojo Product - so that their findings can be imported automatically to DefectDojo. By setting a schedule for “Discover” (collecting VEPs) and “Synchronize” (collecting and importing Findings) operations, you can ensure that DefectDojo stays up to date with the latest scans from these tools.

How to configure a DefectDojo Connector

The following fields are required when configuring a new Connector for a given vendor tool:

How do DefectDojo Connectors work?

During “Discover” operations, Connectors create Records that contain the details about vendor-equivalent products, including their names and unique identifiers. Associating these Records with DefectDojo resources is called “mapping”. You can do this manually to ensure that Products are created in a way that’s meaningful to you, or you can enable auto-mapping to have Products created automatically when new Records are created (see the “How does auto-mapping work?” section below for more details).

After Records have been mapped to DefectDojo resources, you can run a “Synchronize” operation to collect Findings from the vendor tool for all mapped Records and [re-]import them into the relevant Test under those Products. As Findings come and go from the vendor tool, their status will be accurately reflected in DefectDojo (for example, if a Finding disappears from the vendor tool, it will be marked inactive in DefectDojo).

How does auto-mapping work?

When auto-mapping is enabled, DefectDojo will automatically create Products based on the name of VEPs contained in new Records. For example, if you have a Product called ProductA in your third-party tool, a Discover operation will create a new Record in DefectDojo containing its metadata, and will automatically create a DefectDojo Product named ProductA, with a Product Type of [Vendor] Connector. It will associate the created Product with the resource ID from the vendor tool in a Mapping so that future Sync operations will know to retrieve Findings for this VEP and where to import them.

About permissions

Users must have the global Maintainer role to:

Users with the global Reader, Writer, and Maintainer roles can:

Glossary

Concepts

Operations

Product record states

Future Connectors

We are excited to introduce Connectors for Snyk and Semgrep and we are working on adding more to the list. For now, we are prioritizing tools our current customers use and in time we hope to have a large list of Connectors for the more popular security tools in use.

Keep following us to get the latest news on where Connectors are headed!