All integrations

AccuKnox Integration with DefectDojo

AccuKnox Integration with DefectDojo

AccuKnox is a Zero Trust cloud native application protection platform (CNAPP) that covers code-to-cloud security. Through a single findings endpoint it reports container image vulnerabilities, infrastructure as code issues, cloud security posture (CSPM) misconfigurations, and runtime findings. DefectDojo accepts AccuKnox data two ways: a JSON findings export imported as a file, or the DefectDojo Pro AccuKnox connector, which pulls the same data over the AccuKnox API.

AccuKnox Integration with DefectDojo

We connected AccuKnox to DefectDojo because AccuKnox told us what was wrong across our clusters and cloud accounts, but our application teams already worked their backlog in DefectDojo. Each AccuKnox row becomes a Finding under the right Asset, with its AccuKnox status translated into DefectDojo state and its finding class kept as a tag. The file parser and the Pro connector use the same scan type, so a team that starts with exports and later switches on the connector ends up with one set of findings, not two.

Why AccuKnox Matters

AccuKnox looks at cloud workloads from several angles at once, which is useful and also messy, since each angle produces a different kind of row.

  • It covers container images, IaC, cloud posture, and runtime behavior from one platform, so cloud teams don't need four separate exports.
  • Its findings carry triage state from AccuKnox itself (in progress, accepted risk, fixed), which matters when security and platform teams already work inside the AccuKnox console.
  • Cloud posture and runtime issues usually belong to platform engineers, while image CVEs belong to service owners. Sorting that out needs a place where findings can be filtered by class and assigned.
  • Without a vulnerability management layer, nobody can compare AccuKnox results with the SAST, SCA, and DAST results for the same application.

Advantages of This Integration

  • One identity for file and API data. The parser's scan type is AccuKnox - Connectors Import, the exact string the Pro connector reports, so uploads and connector Syncs deduplicate against each other.
  • Status carried through. Only fixed, accepted risk, and duplicate close a finding in DefectDojo. Working states such as in progress or waiting for 3rd party stay open, so active work is never hidden.
  • Suppressions recorded, not lost. A row ignored in AccuKnox imports as out of scope instead of being dropped, which keeps an audit trail of what was suppressed.
  • Filtering by finding class. The AccuKnox data type (for example container_image, iac, cloud_posture, runtime) and the asset type are written as tags, so each team can work only its own slice.
  • SLAs and reporting. AccuKnox risk factors map onto Critical through Info, so cloud findings follow the same SLA rules and metrics as every other scanner.

How This Integration Works

Option 1: File import. This path exists for organizations that can't grant AccuKnox API credentials, such as air-gapped networks or teams waiting on a security review. Save the JSON response from AccuKnox's findings endpoint. The parser reads rows under results and also accepts findings, data, rows, or a bare array.

AccuKnox does not publish column names for every data type, and they differ between container, IaC, cloud posture, and runtime rows. The parser probes a list of candidate keys for each field (for example name, title, finding_name, or vulnerability_name for the title) and also tries each candidate with AccuKnox's vulnerability__ column prefix.

In the UI, open an Engagement, choose Import Scan Results, select AccuKnox - Connectors Import, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=AccuKnox - Connectors Import" 
  -F "file=@accuknox-findings.json" 
  -F "product_name=cloud-platform" 
  -F "engagement_name=AccuKnox" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import from a pipeline with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "AccuKnox - Connectors Import" 
  --report-path "./accuknox-findings.json" 
  --product-name "cloud-platform" 
  --engagement-name "AccuKnox" 
  --auto-create-context

Option 2: AccuKnox connector (DefectDojo Pro). In the DefectDojo Pro UI, add the AccuKnox connector, enter your AccuKnox CSPM host as the Location, and paste an AccuKnox access key as the Secret. A key created by a user with the Viewer role is enough. You can optionally add your Tenant ID (workspace ID) and a Minimum Severity. The connector imports CSPM findings across the tenant, creates a Record for each connected cloud account, and adds a tenant-level catch-all Record for findings that match no account. Access keys expire, so an authentication error on a connector that used to work usually means the key needs replacing.

Data Granularity: What Gets Imported

DefectDojo Field Source in AccuKnox Data Notes
Title name, title, finding_name, or vulnerability_name Falls back to AccuKnox finding plus the ID
Severity risk_factor or severity Critical, High, Medium, Low map directly; anything else is Info
Date date_discovered, first_seen, or created_at Several date formats accepted
Description Description text plus details Adds finding class, AccuKnox status, asset, asset type, first and last seen
Mitigation solution, remediation, recommendation, or fix Copied as text
Component Name / Version Package name and version columns Populated for package-based findings
Service asset_name, resource_name, asset, or resource The affected asset
Vulnerability IDs CVE column, else the title CVE IDs extracted and deduplicated
Unique ID from Tool finding_id, id, or uuid AccuKnox's finding ID
Vuln ID from Tool data_type AccuKnox's finding class
Tags Data type and asset type For filtering by class
Status flags AccuKnox status and ignored flag Fixed, accepted risk, duplicate close; ignored rows become out of scope
Verified AccuKnox status potential or blank status imports as unverified
Finding type Static All rows are marked static
Deduplication Unique ID or hashcode Unique ID from tool, falling back to title, severity, description

Use Cases

Air-gapped or restricted environments: A regulated team can't let an external platform call the AccuKnox API. They export findings on a schedule, move the file across the boundary, and import it. If the connector is approved later, the shared scan type means history carries over.

Splitting cloud work by owner: A platform team takes cloud_posture and runtime findings while service teams take container_image CVEs. Filtering on the tags the parser writes gives each group its own queue inside the same Asset.

Keeping AccuKnox triage in sync: When engineers mark rows fixed or accepted risk in AccuKnox, the next import reflects it in DefectDojo, so security leads report from one place without asking teams to update two tools.

Cloud account reporting: With the Pro connector creating a Record per cloud account, leadership can see open posture issues by account next to application findings for the services running there.

Operational Tips

  • Pick one Test per AccuKnox export scope and reimport into it, so findings that leave the export are mitigated and returning ones are reactivated.
  • Rows with an empty or unrecognized risk factor import as Info. If the export has lots of those, check whether your AccuKnox data type uses a column the parser doesn't probe.
  • Rows marked potential (or with no status) arrive unverified. Filter on verified status if you only want confirmed findings in SLA reporting.
  • Use minimum_severity on file imports, or the connector's Minimum Severity setting, to keep Low posture noise out of the first rollout.
  • Ignored rows import as out of scope. Review them periodically, since a suppression made in AccuKnox now shows up in DefectDojo reporting.
  • If you plan to move from file imports to the connector, keep the same Asset structure so deduplication can match the two sources.