# Threagile

### File Types

DefectDojo parser accepts a .json file.

JSON reports are created from the Threagile tool (default name `risks.json`) using the following command:

```shell
docker run --rm -it -v "$(pwd)":/app/work threagile/threagile -verbose -model /app/work/threagile.yaml -output /app/work
```

### Acceptable JSON Format

Parser expects an array of findings. All properties are strings. Required fields are the following

- “category”
- “title”
- “severity”
- “synthetic_id”
- “exploitation_impact”

`category` field is used to set both the title of the Finding as well as the CWE.
`most_relevant_technical_asset` field is used to determine the component.

```json
[
    {
        "category": "unguarded-direct-datastore-access",
        "risk_status": "unchecked",
        "severity": "elevated",
        "exploitation_likelihood": "likely",
        "exploitation_impact": "medium",
        "title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>Energon</b> via <b>EnergonToPolicyRegoFileStorage</b>",
        "synthetic_id": "unguarded-direct-datastore-access@energon-ta>energontopolicyregofilestorage@energon-ta@policies-rego-storage-ta",
        "most_relevant_data_asset": "",
        "most_relevant_technical_asset": "policies-rego-storage-ta",
        "most_relevant_trust_boundary": "",
        "most_relevant_shared_runtime": "",
        "most_relevant_communication_link": "energon-ta>energontopolicyregofilestorage",
        "data_breach_probability": "improbable",
        "data_breach_technical_assets": [
            "policies-rego-storage-ta"
        ]
    },
    {
        "category": "unguarded-direct-datastore-access",
        "risk_status": "in-discussion",
        "severity": "elevated",
        "exploitation_likelihood": "likely",
        "exploitation_impact": "medium",
        "title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>IAMSidecar</b> via <b>IAMBachendAPIPoliciesRegoFileStorage</b>",
        "synthetic_id": "unguarded-direct-datastore-access@iam-sidecar-ta>iambachendapipoliciesregofilestorage@iam-sidecar-ta@policies-rego-storage-ta",
        "most_relevant_data_asset": "",
        "most_relevant_technical_asset": "policies-rego-storage-ta",
        "most_relevant_trust_boundary": "",
        "most_relevant_shared_runtime": "",
        "most_relevant_communication_link": "iam-sidecar-ta>iambachendapipoliciesregofilestorage",
        "data_breach_probability": "improbable",
        "data_breach_technical_assets": [
            "policies-rego-storage-ta"
        ]
    },
    {
        "category": "unguarded-direct-datastore-access",
        "risk_status": "accepted",
        "severity": "elevated",
        "exploitation_likelihood": "likely",
        "exploitation_impact": "medium",
        "title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>IDMSidecar</b> via <b>IAMSidecarPoliciesRegoFileStorage</b>",
        "synthetic_id": "unguarded-direct-datastore-access@idm-sidecar-ta>iamsidecarpoliciesregofilestorage@idm-sidecar-ta@policies-rego-storage-ta",
        "most_relevant_data_asset": "",
        "most_relevant_technical_asset": "policies-rego-storage-ta",
        "most_relevant_trust_boundary": "",
        "most_relevant_shared_runtime": "",
        "most_relevant_communication_link": "idm-sidecar-ta>iamsidecarpoliciesregofilestorage",
        "data_breach_probability": "improbable",
        "data_breach_technical_assets": [
            "policies-rego-storage-ta"
        ]
    },
    ...
]
```

### Sample Scan Data

Sample Threagile scans can be found [here](https://github.com/DefectDojo/django-DefectDojo/tree/master/unittests/scans/threagile).

### Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these [hashcode fields](https://docs.defectdojo.com/en/working_with_findings/finding_deduplication/about_deduplication/):

- title
- cwe
- severity
