MS Defender Parser | DefectDojo Documentation

MS Defender Parser

This parser helps to parse Microsoft Defender Findings and supports two types of imports:

However, if you have a fast changing environment with a huge number of vulnerabilities and endpoints, it is recommended to leave the folder machines/ empty. Then, for stability reasons, the machine info is skipped and only the machineID is added to the finding.

Sample Scan Data

Sample MS Defender Parser scans can be found here.

Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these hashcode fields: