All integrations

cfn-nag Integration with DefectDojo

cfn-nag Integration with DefectDojo

cfn-nag is an open source tool from Stelligent that looks for security problems in AWS CloudFormation templates. Distributed as a Ruby gem, it applies a rule set that flags patterns such as security groups open to the world, IAM policies with wildcard actions or resources, unencrypted queues and buckets, and rules without descriptions. Its cfn_nag_scan command scans a directory of templates and can write results as JSON, which DefectDojo imports.

cfn-nag Integration with DefectDojo

We added cfn-nag to our template pipeline because a CloudFormation stack can be perfectly valid and still open an SSH port to the internet, and DefectDojo is where those violations get tracked to closure. The parser splits each violation into one Finding per offending resource, so when an engineer encrypts one of two queues, that resource's Finding closes and the other stays open. Rule IDs, file paths, and line numbers come through on every Finding, and the platform team sees security debt per stack rather than per CI log.

Why cfn-nag Matters

Infrastructure as code moves security decisions into pull requests, which is good only if someone reviews them with the right questions in mind.

  • cfn-nag encodes common AWS misconfigurations as rules, so reviewers don't have to spot a 0.0.0.0/0 ingress rule or a * IAM action by eye.
  • It separates hard failures from warnings. A FAIL is a rule the template breaks; a WARN depends on intent, such as an open ingress rule that is fine on a load balancer and not on an instance.
  • Its rules don't overlap with cfn-lint. Running both checks templates for correctness and for security.
  • Catching these issues before deployment is cheaper than finding them later in an account-level posture review.

Advantages of This Integration

  • One Finding per resource. A single cfn-nag violation can cover several resources through parallel logical_resource_ids and line_numbers lists. The parser pairs them by index and creates a Finding for each resource, and each Finding's description names the sibling resources the rule also fired on.
  • Severity that preserves cfn-nag's intent. FAIL becomes High and WARN becomes Medium, so the two aren't flattened and SLAs can treat them differently.
  • Deduplication across runs. cfn-nag Findings use the hash code algorithm over the legacy default fields (title, cwe, line, file_path, description). The description includes the resource name, which keeps two Findings for the same rule distinct.
  • Closure through reimport. Reimporting the latest scan into the same Test mitigates fixed resources, adds new violations, and reactivates any that return.
  • Workflow. Findings can be assigned to the stack owner, risk-accepted for intentional exceptions, and pushed to Jira.

How This Integration Works

DefectDojo imports cfn-nag output with the cfn-nag Scan scan type.

1. Scan a template directory and save JSON. cfn_nag_scan takes a directory, not a single file:

gem install cfn-nag
cfn_nag_scan --input-path ./templates --output-format json > cfn-nag.json

The report's filename is whatever path cfn-nag was given. The parser removes a leading ./ and changes nothing else, so scan with a relative path if you want portable paths in DefectDojo. Like cfn-lint, cfn-nag exits non-zero when it finds anything, so make sure your CI uploads the report even when the scan step fails.

2. Import the report. In the UI, open the Engagement, choose Import Scan Results, select cfn-nag Scan, and upload the file. With the API, available in Community Edition and DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=cfn-nag Scan" 
  -F "file=@cfn-nag.json" 
  -F "product_name=network-stacks" 
  -F "engagement_name=IaC Security" 
  -F "auto_create_context=true"

DefectDojo Pro users can use Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "cfn-nag Scan" 
  --report-path "./cfn-nag.json" 
  --product-name "network-stacks" 
  --engagement-name "IaC Security" 
  --auto-create-context

3. Reimport on each merge. Send later reports to /api/v2/reimport-scan/ against the same Test so fixed resources close automatically.

Data Granularity: What Gets Imported

DefectDojo Field Source in cfn-nag Report Notes
Title violations[].message Rule wording, identical for every resource it fires on
Severity violations[].type FAIL to High, WARN to Medium; anything else Medium
Description Message, resource, rule ID, rule name, result, element types Lists other resources the rule also reported
Component Name logical_resource_ids[i] One Finding per resource
Line line_numbers[i] Paired by index; falls back to the first line
File Path filename Leading ./ removed
Vuln ID from Tool violations[].id For example F38, W48
CWE None cfn-nag reports no CWE
Finding type Static Templates are analyzed, not deployed
Deduplication Hash code Legacy default fields: title, cwe, line, file_path, description

A violation that names no resource still becomes one Finding, anchored to the first line cfn-nag gave, so nothing in the report is silently dropped.

Use Cases

In a pull request pipeline: Each change to a template directory triggers cfn_nag_scan and a reimport. A new wildcard IAM policy appears as a new High Finding before merge, and fixing it closes the Finding on the next run.

For shared networking stacks: A platform team owns VPC and security group templates used by many services. Importing cfn-nag results into an Asset for those stacks gives them a clear list of open-ingress warnings, with notes recording which are intentional, such as public load balancers.

With cfn-lint and CFRipper: All three tools can be imported as separate Tests in the same Engagement. cfn-lint covers correctness, while cfn-nag and CFRipper apply different security rule sets, and the Asset view shows all of it together.

For audit preparation: Findings for encryption and IAM rules carry their discovery and mitigation dates, which gives auditors a record of how long template-level security issues stayed open.

Operational Tips

  • Review WARN Findings with context. A rule like W2 (CIDR open to world on ingress) is legitimate on a load balancer, so risk-accept it with a note instead of letting it age against an SLA.
  • Scan from the same directory with the same relative path every time. File path is a hash field, so a changed path makes every Finding look new.
  • Because line numbers are part of the hash, editing a template above a flagged resource can shift lines and create a new Finding while reimport mitigates the old one. Expect some churn on heavily edited templates.
  • Tag imports with the repository or stack name when one Asset covers several template directories.
  • Use minimum_severity=High on import if you only want FAIL results to enter triage at first, then lower it once the backlog is under control.
  • Keep cfn-nag suppressions in the templates themselves for exceptions that should never be reported, and use DefectDojo risk acceptance for exceptions that need periodic review.