Import Method Comparison | DefectDojo Documentation

Import Method Comparison

One of the things we understand at DefectDojo is that every company’s security needs are completely different. There is no one-size-fits-all approach. As your organization changes, having a flexible approach is key, and DefectDojo allows you to connect your security tools in a flexible way to match those changes.

Scan Upload Methods

When DefectDojo receives a vulnerability report from a security tool, it will create Findings based on the vulnerabilities contained within that report. DefectDojo acts as the central repository for these Findings where they can be triaged, remediated, or otherwise addressed by you and your team.

There are two main ways that DefectDojo can upload Finding reports.

DefectDojo Pro Methods

DefectDojo Pro users have an additional three methods to handle reports and data:

Comparing Upload Methods

UI Import API Connectors(Pro) Smart Upload(Pro)
Supported Scan Types All: see Supported Tools All: see Supported Tools Akamai API Security, Anchore, AWS Security Hub, BurpSuite, Checkmarx ONE, Dependency-Track, IriusRisk, JFrog Xray, Probely, Semgrep, SonarQube, Snyk, Tenable, Wiz Nexpose, NMap, OpenVas, Qualys, Tenable
Automation? Available via API: /reimport /import endpoints Triggered from CLI Tools or external code Connectors is an inherently automated feature Available via API: /smart_upload_import endpoint

Product Hierarchy and organization

Each of these methods can create Product Hierarchy on the spot. Product Hierarchy refers to DefectDojo’s Product Types, Products, Engagements or Tests: objects in DefectDojo which help organize your data into relevant context.