DefectDojo’s Getting started with a new security platform can feel like a project in itself. Adding new scans, setting up reporting, and making sense of myriad new features is an involved and time-consuming process, especially without disrupting your current workflows. I was prepared for the same difficulties when I began using DefectDojo, but I’ve been pleasantly surprised to learn that they take a different approach: instead of asking you to change your processes to adapt to their tools, their tools adapt to your existing processes.
The Asset Hierarchy is incredibly flexible and easy to set up, and their centralized approach lets you bring findings from your entire suite of scanners into a single vulnerability management workflow, making it easier to identify duplicate findings, prioritize what matters, and track your remediation progress.
And you don’t need to set up everything all at once. You can get DefectDojo up and running in just 10 minutes, creating your first Asset and importing scan results before turning your raw security findings into actionable work. This tutorial will walk you through those first 10 minutes and show you how you can grow from there.
NOTE: The information below assumes that DefectDojo has already been installed. Guidelines for installation can be found here.
The primary strength of DefectDojo lies in its ability to contextualize and compartmentalize individual vulnerabilities. Before importing a scan, it helps to understand the structure DefectDojo uses to reflect your security data.
The most important consideration when structuring your hierarchy is mapping DefectDojo's objects to the boundaries that matter in your own environment. One organization might treat each service as an Asset, with separate Engagements for SAST, SCA, and penetration testing; another might use Assets to represent individual software versions within a larger product line. However you choose to model your data, DefectDojo’s hierarchy is flexible enough to adapt to your organization's unique system architecture. Further information about the Asset hierarchy can be found here (Community Edition) and here (Pro).
You have your scanner results ready, so let’s give them a home.
To reflect your hierarchy manually, start by creating an Organization. Organizations generally represent established and lasting boundaries within your security program, such as business domain, customer, or security/development team.
Now create an Asset within that Organization to represent the application, API, or service whose security findings you want to manage. From there, you can import your scan results into an Engagement and Test.
For automated imports, you can also generate the required hierarchy through the auto-create context feature, saving you the manual work of building your hierarchy. In Open-Source DefectDojo, this functionality is available through the REST API. If enabled when uploading a scan, connect it to the Organization and Asset you want it to belong to, and if they don’t exist yet, DefectDojo will generate a hierarchy for you, right down to the Engagement and Test. It’s one of the many ways that DefectDojo reduces friction and adapts to your instance.
With your hierarchy established, it’s time to turn your scan results into action-ready insights.
If you already have the results of a completed scan, importing it into DefectDojo through the UI is the quickest way to get started. UI imports and the REST API are available in both Open-Source and Pro. As your workflow grows, DefectDojo Pro can also connect directly to your security tools to automate how findings enter the platform, such as through the REST API, Universal Importer, Connectors, and Smart Upload. A comparison of the different import methods can be found here.
Whatever the method, DefectDojo natively integrates with 500+ security tools, allowing you to add results from every tool across your security stack, including SAST, DAST, and SCA.
Now that your findings are in DefectDojo, it will tell you what needs attention.
Upon upload, DefectDojo automatically enriches each Finding with a variety of information to determine your most critical vulnerabilities so you know what to tackle first.
Depending on the available data, DefectDojo enriches Findings with information such as EPSS score, EPSS percentile, CWE, and CVSSv3/CVSSv4 scoring.
Importantly, an Asset with a Very Low business criticality, few user records, and minimal revenue will have lower priority and risk calculations for the same Findings as those within an Asset with Very High business criticality, extensive user records, and high revenue. The more information you provide when creating an Asset, the more accurate DefectDojo’s assessment will be. Additional information about priority and risk calculations can be found here.
Scanner formatting may vary, but DefectDojo helps you make sense of the noise. With this data in hand, you can start focusing your efforts where they’re needed most.
Finding vulnerabilities is one thing, but ensuring they actually get fixed is where DefectDojo shines. Findings can be filtered, deduplicated, prioritized, grouped, assigned for remediation, and tracked over time, giving your team a clearer picture of what needs attention and how your security posture is changing.
A single report may include thousands of findings, and knowing which require attention is essential for efficient remediation.
Use filtering and prioritization based on severity, status, assignee, and other attributes to assess the results of a single scan or your entire security system. Native deduplication will also minimize the time spent chasing identical vulnerabilities revealed by multiple scans or tools.
Once you can see your scan results, you can move on to delegation. Findings can be assigned to individual users, tracked through the remediation process, and updated as their status changes.
DefectDojo can push Findings directly to Jira or GitHub Issues, placing each issue exactly where developers know to look for it. It creates the ticket, syncs the comments, and automatically closes the ticket once the fix is confirmed in subsequent scans. Instead of manually sending reports or chasing updates over email, developers can work directly from the systems they already use.
DefectDojo answers the who, what, and where, but also: by when does this need to be fixed? Accordingly, SLA (Service Level Agreement) logic is incorporated directly onto each Finding and can be customized to represent your organization’s particular remediation policies.
Notifications can be triggered and Jira tickets escalated automatically if a vulnerability exceeds the permitted SLA window. And when a fix isn’t possible, the Risk Acceptance workflow creates an audit trail of accountability.
This way, you know what needs doing, by whom, and by when. More information about SLA configuration can be found here.
DefectDojo's reporting and insight capabilities give you a high-level view of your security posture, from individual Tests to your broader portfolio. Share analytics with security teams, developers, and other stakeholders to communicate trends, progress, and areas of risk without having to synthesize the information from individual reports. The result is more time spent acting and less time sorting through the minutiae.
In just 10 minutes, you’ve turned your scanner report into a roadmap for remediation, the first of many steps as you tailor a vulnerability management workflow that grows with your security program. Whether you’re working with a single security tool or managing an entire application portfolio, you can scale this workflow across tools, applications, and findings as your security program evolves, translating minutes of effort into hours saved.
Ready to go further? Explore the DefectDojo documentation to build your own workflow, or request a demo to see how DefectDojo Pro can help you automate at scale.