Beagle Security Integration with DefectDojo
Beagle Security Integration with DefectDojo
Beagle Security is a SaaS platform for automated penetration testing of web applications and APIs, a form of dynamic application security testing (DAST). It runs tests against verified applications and produces a report per test session, with findings scored on an OWASP-style severity label or, for tenants configured that way, by CVSS. DefectDojo imports Beagle's JSON test reports, and DefectDojo Pro can pull results directly with the Beagle Security connector.
Beagle Security Integration with DefectDojo
We picked Beagle Security to run regular automated tests against our customer-facing web apps without staffing a manual test for every release. The reports were useful, but each one was a standalone document. Bringing Beagle into DefectDojo turns each finding on each affected URL into its own Finding, attached to the application's Asset, with Beagle's Fixed status carried over. Our web findings now share SLAs, ownership, and Jira tickets with everything else, and the next test session updates the same records.
Why Beagle Security Matters
Dynamic testing finds issues the way an attacker would: by sending requests to a running application and looking at the responses.
- It exercises the deployed application, so it catches configuration and runtime issues that source analysis can't see.
- It reports where each issue was observed (an HTTP method and URL), which tells developers exactly which route to fix.
- Findings carry CWE references and, where configured, CVSS vectors and scores, which makes them comparable with other scanners.
- The same issue often appears on many URLs with different fix states. That level of detail needs tracking beyond a PDF or a one-off report.
Advantages of This Integration
- One finding per occurrence. A finding Beagle observed on three URLs becomes three DefectDojo findings, so each route can be fixed and closed on its own.
- Fixed status carried over. An occurrence Beagle marks
Fixedimports as inactive and mitigated. Every other status counts as open. - Endpoint-aware deduplication. The hashcode fields for this scan type include
endpoints, and the parser always records the tested URL, so repeat imports match per route. - File and API agree. The parser uses the connector's scan type,
Beagle Security - Connectors Import. When no application token is in the export, the hash over title, severity, and endpoints is what matches file imports with connector Syncs. - Severity kept honest. An unrecognized severity label imports as Info, and the original label is kept as a tag, so nothing is silently re-graded.
How This Integration Works
Option 1: File import. Use this path when you can't grant DefectDojo Beagle API credentials. Beagle returns a report as a JSON string inside an envelope ({"result": "{...}"}), and the parser accepts either that envelope or the report body itself. Beagle documents its report-level keys but not every per-finding field name, so the parser reads each field from a set of aliases, matched case-insensitively, and locates the finding array by name or by shape.
In the UI, open an Engagement, choose Import Scan Results, select Beagle Security - Connectors Import, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Beagle Security - Connectors Import"
-F "file=@beagle-report.json"
-F "product_name=customer-portal"
-F "engagement_name=Beagle DAST"
-F "auto_create_context=true"
DefectDojo Pro users can use Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Beagle Security - Connectors Import"
--report-path "./beagle-report.json"
--product-name "customer-portal"
--engagement-name "Beagle DAST"
--auto-create-context
Option 2: Beagle Security connector (DefectDojo Pro). In the DefectDojo Pro UI, add the Beagle Security connector, enter https://api.beaglesecurity.com/rest/v2 as the Location, paste a Beagle personal access token as the Secret, and optionally set a Minimum Severity. The connector creates a Record for each verified application in your Beagle project tree (unverified applications are not imported). Findings come from each application's most recent finished test session, so a test still in progress doesn't replace existing results. Beagle tokens expire, and an expired token returns an HTML error page rather than a JSON error, so check the token first if a working connector starts failing.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Beagle Report | Notes |
|---|---|---|
| Title | Finding name (name, title, and other aliases) |
Falls back to the CWE, then a generic label |
| Severity | Severity label, or CVSS number | critical, high, medium, low, info map directly; CVSS 9.0 Critical, 7.0 High, 4.0 Medium, else Low |
| Date | generated_date, else approved_date |
Same date for every finding in a report; today if neither parses |
| Description | Finding text plus method, URL, Beagle status, CWE | Labeled lines |
| Mitigation | Remediation aliases (remediation, solution, and others) |
Copied as text |
| CWE | cwe and aliases |
Accepts CWE-215, 215, or a list |
| CVSS v3 Vector / Score | cvss_vector, cvss_score, and aliases |
Set when present |
| Param | Occurrence Method |
The HTTP method |
| Endpoint | Occurrence Url, else report url |
Always recorded when the host is valid |
| Vuln ID from Tool | Finding name | Beagle's signature identity |
| Unique ID from Tool | SHA-256 of application token, name, method, URL | Only when the export carries the application token |
| Tags | beagle-security plus severity label |
Keeps unrecognized labels visible |
| Active / Mitigated | Occurrence status |
Fixed is mitigated; anything else is open |
| Finding type | Dynamic | Tests against a running application |
| Deduplication | Unique ID or hashcode | Unique ID from tool, falling back to title, severity, endpoints |
A finding with no occurrences still produces one finding, aimed at the application's own URL.
Use Cases
Release testing: The team runs a Beagle test after each production release. The connector syncs the finished session, and DefectDojo shows which issues are new on which routes and which were fixed.
Developer handoff: Because each occurrence is its own finding with method and URL, a security engineer can assign route-level findings to the team that owns that part of the application and push them to Jira.
Compliance reporting: Regular automated tests plus DefectDojo history give auditors a record of when each web finding was discovered, who owned it, and when it closed.
Restricted environments: A team that can't let DefectDojo call Beagle's API exports the report JSON and imports it. The shared scan type and endpoint-based hash let a later connector rollout line up with those findings.
Operational Tips
- Only verified applications are imported by the connector. Verify each application in Beagle before expecting a Record in DefectDojo.
- If your tenant scores reports with CVSS instead of labels, severities are graded from the score using the 9.0, 7.0, and 4.0 floors.
- Watch the tags for unexpected severity labels. An unrecognized label imports as Info, and the tag shows what Beagle actually said.
- A file import doesn't include the Beagle test-session ID in the description, because the report body doesn't carry it. Connector findings do.
- Reimport each new report into the same Test so fixed occurrences are mitigated and new routes are added.
- Use
minimum_severity, or the connector's Minimum Severity, to start with the findings most likely to matter.