All integrations

Black Duck Continuous Dynamic Integration with DefectDojo

Black Duck Continuous Dynamic Integration with DefectDojo

Black Duck Continuous Dynamic is a dynamic application security testing (DAST) platform from Black Duck, run through the Continuous Dynamic portal. It was sold as WhiteHat Sentinel Dynamic before Synopsys acquired WhiteHat Security, and it became part of Black Duck when Synopsys's software integrity business was spun out under that name. The platform tests running web applications, which it tracks as sites, and combines continuous scanning with verification and manual assessment by security engineers. It can also test APIs from a supplied specification. DefectDojo Pro reads its findings through an Upstream Connector that calls the Continuous Dynamic API.

Black Duck Continuous Dynamic Integration with DefectDojo

We run Black Duck Continuous Dynamic against our customer-facing sites and use the DefectDojo Pro connector so those DAST results sit next to everything else we know about each application. The connector creates a Record for every site on our account, with no per-site configuration, and syncs findings into the mapped Asset on a schedule. Instead of logging into a separate portal to see what changed, application owners see new and closed web findings in DefectDojo with SLA dates and the URLs that were attacked.

Why Black Duck Continuous Dynamic Matters

Dynamic testing finds the problems that only show up when an application is running: injection flaws reachable through real parameters, broken session handling, and server misconfigurations.

  • It tests deployed sites from the outside, the way an attacker would reach them, so findings reflect what is exposed.
  • Results come with attack vectors, the specific requests that demonstrated the issue, which shortens the path to reproducing and fixing it.
  • Risk ratings and custom risk let a program rank web findings against everything else in its backlog.
  • DAST findings for a site rarely line up with code findings for the same application unless something brings them together.

Advantages of This Integration

What the connector adds to a DefectDojo Pro instance:

  • One Record per site, automatically. Discover finds every site on the account, and Auto-Map can create an Asset for each without manual setup.
  • Complete findings. DefectDojo requests attack vectors, risk scores, and descriptions from the API, so findings arrive with the same detail the WhiteHat Sentinel file parser expects.
  • Endpoints from attack vectors. Each attack vector's request URL becomes an endpoint (or Location) on the Finding, so you can see every affected URL.
  • Status carried over. Vulnerabilities that are no longer open arrive mitigated, with the closed date, and ones marked invalid in the platform arrive as false positives.
  • Lifecycle on every sync. Sync runs a reimport against the existing Test, adding new findings and marking those that are no longer reported as inactive.
  • Common workflow. Findings go through the same SLA rules, risk acceptance, assignment, and Jira or Downstream Connector pushes as every other tool.

How This Integration Works

The connector is a DefectDojo Pro feature, configured under Connect > Upstream.

1. Get an API key. In Continuous Dynamic, open Account > API Keys and create a key. Black Duck treats this key as equivalent to a username and password, so store it in a secrets manager and limit who can see it.

2. Configure the connector. Enter https://sentinel.whitehatsec.com in the Location field and the key in the API Key field. Optionally set a Minimum Severity to limit which findings are imported.

3. Discover and Sync. Discover creates a Record for each site on the account. Map each Record to an Asset, or enable Auto-Map to have DefectDojo create matching Assets. Sync then imports findings into a Test inside the Global Connectors Engagement on that Asset, and repeats on a schedule.

A note on the scan type. Findings from this connector use the WhiteHat Sentinel scan type. DefectDojo reuses that established mapping because the product was WhiteHat Sentinel Dynamic before the acquisition. Seeing WhiteHat Sentinel on these Tests is expected, not a misconfiguration.

Data Granularity: What Gets Imported

The connector reuses the WhiteHat Sentinel mapping. The fields below are how the WhiteHat Sentinel parser in DefectDojo turns a vulnerability into a Finding.

DefectDojo Field Source in Continuous Dynamic Data Notes
Title Vulnerability class For example the class name of the web vulnerability
Severity Custom risk, else risk 0 and 1 become Info, 2 Low, 3 Medium, 4 High, 5 and 6 Critical
Description Vulnerability description HTML paragraph tags removed; the references part is split off
Steps to Reproduce Description prepend text When present
Mitigation Solution, plus solution prepend HTML tags stripped
References Site and finding link, plus reference links Built from the site and vulnerability IDs
CWE Scanner tags on the first attack vector First tag that starts with CWE-
Endpoints / Locations Attack vector request URLs One per attack vector
Active / Mitigated Status and closed date Only open stays active; others are mitigated with the closed timestamp
False Positive Status invalid sets the false positive flag
Date / Last Reviewed Found date / last retested Dates carried from the platform
Unique ID from Tool Vulnerability ID Also used to collapse repeats within one payload
Verified / Type Fixed Verified, and marked dynamic

Deduplication follows the settings for the WhiteHat Sentinel scan type, whose default hashcode fields are title, CWE, line, file path, and description.

Use Cases

Web portfolio reporting: A team with dozens of public sites maps each Record to the Asset for that application. Security leads can then compare open web findings and SLA breaches across the portfolio without exporting anything from the DAST portal.

Correlating DAST with code findings: When the same Asset also receives SAST and SCA results, a web vulnerability found at runtime sits beside the code findings for that application, which helps an engineer decide whether the root cause is in the code, a dependency, or the deployment.

Remediation handoff: New High and Critical findings are pushed to Jira or another Downstream Connector, with the attacked URLs attached as endpoints. When the platform retests and closes the vulnerability, the next sync brings the closed status into DefectDojo.

Audit evidence: Each finding carries its found date, closure date, and SLA status, which documents how quickly exposed web issues were handled.

Operational Tips

  • Expect the WhiteHat Sentinel scan type on these Tests, and build filters and dashboards with that name rather than the current product name.
  • Treat the API key like a password. If it is rotated, update the connector right away; the Connector Health Warning notification can tell you when syncs start failing.
  • Set Minimum Severity if Info findings would bury your team. Risk values 0 and 1 both map to Info.
  • Custom risk takes priority over the platform's default risk, so adjustments your team made in Continuous Dynamic carry into DefectDojo severity.
  • Map several sites to one Asset when they are front ends of the same application, so SLAs and reporting reflect the application rather than each hostname.
  • If a field lands somewhere you don't want, Connector Field Mappings let you rearrange or normalize values for the scan type without waiting for a release.