February Office Hours: Getting Started with DefectDojo TY Page
February Office Hours: Getting Started with DefectDojo
Transcript
00:00 Welcome & What You’ll Learn: Getting Started with DefectDojo
00:48 Meet the Speaker: Matt Tesauro’s AppSec & OWASP Background
01:46 The Big Picture: Why Security Must Move at Assembly-Line Speed
02:47 The Pain Today: Excel, Manual Triage, and Tool Sprawl
03:26 The Solution: DefectDojo as Your Single Source of Truth
04:58 Central Hub Workflow: Normalize, De-dupe, Auto-Triage, Then Ship to Jira
05:59 Why DefectDojo (Not the Acronym): Automation-Friendly Vulnerability Management
08:27 Real-World Impact: Prioritization That Cuts 30,000 Findings Down to 80
10:50 Fits Any Maturity Level: From New AppSec Programs to PR-Gating Automation
11:49 Understanding the Dojo Data Model: Product Types, Products, Engagements & Findings
12:55 New Labels + Locations: Evolving the Model for Performance and Clarity
14:28 Open Source vs Pro: DIY Community Edition vs “You’re Just Done”
16:00 What’s New/Next: MCP + LLMs with Clean, Normalized Vulnerability Data
19:08 New Integrations & Asset Hierarchy: Better Destinations and Better Visibility
20:52 Smarter Prioritization: Custom Weights, Risk Buckets, and Asset-Specific Rules
22:45 Connectors + Universal Import/Parse: Automate Ingest from Vendor APIs & CI/CD
24:49 Coming Soon: Modernized UI for DefectDojo Community Edition
25:28 Wrap-Up: Automate the Drudgery, Report Holistically, and Scale to Millions
27:00 Q&A Invitation and Closing
Welcome & What You’ll Learn: Getting Started with DefectDojo
Yeah. We're gonna talk about how to get started with Dojo. I got started with Dojo a long time ago, but in case you're new, I can give you years of experience on how to make the most outta Dojo. So today what we're gonna do, I'm gonna do a very quick intro and a little bit of a rather quick kind of big picture discussion.
We're gonna talk about the problem, we're gonna talk about the solution, we'll talk about why DefectDojo, I think is a major part of that solution. I wanna spend a little time talking about what's new or what's next new or about to be new and released with DefectDojo. And then I'll have a little quick wrap up.
Meet the Speaker: Matt Tesaro’s AppSec & OWASP Background
So intro. So who am I? Like, like Chris said, I'm Matt Tesauro. I, I like to consider myself a reformed programmer and AppSec engineer. I'm currently the CTO and co-founder of DefectDojo, Inc. I've been 18 years, well over 18 years now. Woo. With the OAS community doing a bunch of different things, including this DefectDojo.
I created the AppSec Pipeline with Aaron Weaver. I did OWASP, WTE. I have 26 years of using Linux and Free and Libra Open Source software. I I, the last time I used Windows for real was Windows 2000. I'm a Linux person, so that's just what I use and what I know and love. I'm currently a go fan boy.
The Big Picture: Why Security Must Move at Assembly-Line Speed
Let's talk about the big picture. So who's this dapper looking gentleman sitting out in the grass contemplating life or whatever he's doing? Not for people who don't know. That's Henry Ford and Henry Ford maybe sat in grass and contemplated life and said, you know, this automobile thing, we're making them one at a time by hand.
And then rolling them out of the, the custom coach house and doing the next one. That really doesn't work. What if I did them in this factory thing and he started assembly lines and just radically changed how automobiles were produced. I, I've been saying this for a while now, and I still agree with it.
I think we need to con, we need to figure out how to make security work faster. I don't think the other side of the house is gonna slow down, to be quite honest. I don't think AI is gonna make it slow down. So even if it's slop or if it's not slop, we have to deal with it and we have to deal with it at speed.
The Pain Today: Excel, Manual Triage, and Tool Sprawl
The problem and what does the problem look like today for a lot of people? It looks like this. You're using Excel, which is excel's a fine tool. It does some pretty cool things, and if you're a ninja with it, you can do some nutty things, but we're.
Excel seems to show its weaknesses or its its constraints, is when I suddenly add a whole bunch of tooling that has these s flaky ways to represent vulnerabilities, and I'm trying to mash them all together and make sense of them. This is a very manual labor intensive process. It's risky. It's just hard to do at scale.
The Solution: DefectDojo as Your Single Source of Truth
So how do we solve this? Well, I mean, big surprise, I think DefectDojo is how you solve that and that's how I solved it years ago when we created DefectDojo. 'cause I had that very problem. And I needed to make sense of all these different tools.
And what I really wanted was a single source of truth, right? Because I get a SaaS scanner and the SaaS says, are my applications look this way? But then I get a container scanner, and my container scanner says, well, your containers look this other way. And then I get, I don't know, a SEA tool, and suddenly my libraries look this third way.
And I just wanna wait to tell the, my stakeholders the, like the product teams, Hey, this is the state of security of your thing.
Central Hub Workflow: Normalize, De-dupe, Auto-Triage, Then Ship to Jira
What you wanna get to, hopefully, eventually, is something like this. Where DefectDojo is sitting at the center, I have CICD running that's pushing results into DefectDojo. I have various and sundry other scanners that are running and pushing things to DefectDojo. That's where the normalization, the D dupe, the auto triage happens.