AccuKnox Integration with DefectDojo
AccuKnox Integration with DefectDojo
AccuKnox is a Zero Trust cloud native application protection platform (CNAPP) that covers code-to-cloud security. Through a single findings endpoint it reports container image vulnerabilities, infrastructure as code issues, cloud security posture (CSPM) misconfigurations, and runtime findings. DefectDojo accepts AccuKnox data two ways: a JSON findings export imported as a file, or the DefectDojo Pro AccuKnox connector, which pulls the same data over the AccuKnox API.
AccuKnox Integration with DefectDojo
We connected AccuKnox to DefectDojo because AccuKnox told us what was wrong across our clusters and cloud accounts, but our application teams already worked their backlog in DefectDojo. Each AccuKnox row becomes a Finding under the right Asset, with its AccuKnox status translated into DefectDojo state and its finding class kept as a tag. The file parser and the Pro connector use the same scan type, so a team that starts with exports and later switches on the connector ends up with one set of findings, not two.
Why AccuKnox Matters
AccuKnox looks at cloud workloads from several angles at once, which is useful and also messy, since each angle produces a different kind of row.
- It covers container images, IaC, cloud posture, and runtime behavior from one platform, so cloud teams don't need four separate exports.
- Its findings carry triage state from AccuKnox itself (in progress, accepted risk, fixed), which matters when security and platform teams already work inside the AccuKnox console.
- Cloud posture and runtime issues usually belong to platform engineers, while image CVEs belong to service owners. Sorting that out needs a place where findings can be filtered by class and assigned.
- Without a vulnerability management layer, nobody can compare AccuKnox results with the SAST, SCA, and DAST results for the same application.
Advantages of This Integration
- One identity for file and API data. The parser's scan type is
AccuKnox - Connectors Import, the exact string the Pro connector reports, so uploads and connector Syncs deduplicate against each other. - Status carried through. Only
fixed,accepted risk, andduplicateclose a finding in DefectDojo. Working states such asin progressorwaiting for 3rd partystay open, so active work is never hidden. - Suppressions recorded, not lost. A row ignored in AccuKnox imports as out of scope instead of being dropped, which keeps an audit trail of what was suppressed.
- Filtering by finding class. The AccuKnox data type (for example
container_image,iac,cloud_posture,runtime) and the asset type are written as tags, so each team can work only its own slice. - SLAs and reporting. AccuKnox risk factors map onto Critical through Info, so cloud findings follow the same SLA rules and metrics as every other scanner.
How This Integration Works
Option 1: File import. This path exists for organizations that can't grant AccuKnox API credentials, such as air-gapped networks or teams waiting on a security review. Save the JSON response from AccuKnox's findings endpoint. The parser reads rows under results and also accepts findings, data, rows, or a bare array.
AccuKnox does not publish column names for every data type, and they differ between container, IaC, cloud posture, and runtime rows. The parser probes a list of candidate keys for each field (for example name, title, finding_name, or vulnerability_name for the title) and also tries each candidate with AccuKnox's vulnerability__ column prefix.
In the UI, open an Engagement, choose Import Scan Results, select AccuKnox - Connectors Import, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=AccuKnox - Connectors Import"
-F "file=@accuknox-findings.json"
-F "product_name=cloud-platform"
-F "engagement_name=AccuKnox"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import from a pipeline with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "AccuKnox - Connectors Import"
--report-path "./accuknox-findings.json"
--product-name "cloud-platform"
--engagement-name "AccuKnox"
--auto-create-context
Option 2: AccuKnox connector (DefectDojo Pro). In the DefectDojo Pro UI, add the AccuKnox connector, enter your AccuKnox CSPM host as the Location, and paste an AccuKnox access key as the Secret. A key created by a user with the Viewer role is enough. You can optionally add your Tenant ID (workspace ID) and a Minimum Severity. The connector imports CSPM findings across the tenant, creates a Record for each connected cloud account, and adds a tenant-level catch-all Record for findings that match no account. Access keys expire, so an authentication error on a connector that used to work usually means the key needs replacing.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in AccuKnox Data | Notes |
|---|---|---|
| Title | name, title, finding_name, or vulnerability_name |
Falls back to AccuKnox finding plus the ID |
| Severity | risk_factor or severity |
Critical, High, Medium, Low map directly; anything else is Info |
| Date | date_discovered, first_seen, or created_at |
Several date formats accepted |
| Description | Description text plus details | Adds finding class, AccuKnox status, asset, asset type, first and last seen |
| Mitigation | solution, remediation, recommendation, or fix |
Copied as text |
| Component Name / Version | Package name and version columns | Populated for package-based findings |
| Service | asset_name, resource_name, asset, or resource |
The affected asset |
| Vulnerability IDs | CVE column, else the title | CVE IDs extracted and deduplicated |
| Unique ID from Tool | finding_id, id, or uuid |
AccuKnox's finding ID |
| Vuln ID from Tool | data_type |
AccuKnox's finding class |
| Tags | Data type and asset type | For filtering by class |
| Status flags | AccuKnox status and ignored flag |
Fixed, accepted risk, duplicate close; ignored rows become out of scope |
| Verified | AccuKnox status | potential or blank status imports as unverified |
| Finding type | Static | All rows are marked static |
| Deduplication | Unique ID or hashcode | Unique ID from tool, falling back to title, severity, description |
Use Cases
Air-gapped or restricted environments: A regulated team can't let an external platform call the AccuKnox API. They export findings on a schedule, move the file across the boundary, and import it. If the connector is approved later, the shared scan type means history carries over.
Splitting cloud work by owner: A platform team takes cloud_posture and runtime findings while service teams take container_image CVEs. Filtering on the tags the parser writes gives each group its own queue inside the same Asset.
Keeping AccuKnox triage in sync: When engineers mark rows fixed or accepted risk in AccuKnox, the next import reflects it in DefectDojo, so security leads report from one place without asking teams to update two tools.
Cloud account reporting: With the Pro connector creating a Record per cloud account, leadership can see open posture issues by account next to application findings for the services running there.
Operational Tips
- Pick one Test per AccuKnox export scope and reimport into it, so findings that leave the export are mitigated and returning ones are reactivated.
- Rows with an empty or unrecognized risk factor import as Info. If the export has lots of those, check whether your AccuKnox data type uses a column the parser doesn't probe.
- Rows marked
potential(or with no status) arrive unverified. Filter on verified status if you only want confirmed findings in SLA reporting. - Use
minimum_severityon file imports, or the connector's Minimum Severity setting, to keep Low posture noise out of the first rollout. - Ignored rows import as out of scope. Review them periodically, since a suppression made in AccuKnox now shows up in DefectDojo reporting.
- If you plan to move from file imports to the connector, keep the same Asset structure so deduplication can match the two sources.