CFRipper Integration with DefectDojo
CFRipper Integration with DefectDojo
CFRipper is an open source CloudFormation security analyzer developed by Skyscanner and published in its GitHub organization. It audits CloudFormation templates for security misconfiguration, such as wildcard IAM policies, actions that allow privilege escalation, and resources exposed publicly, and assigns each rule a risk value of HIGH, MEDIUM, or LOW. CFRipper runs as a command-line tool or as part of a deployment pipeline, and it can produce text or JSON results; DefectDojo imports the JSON.
CFRipper Integration with DefectDojo
We use CFRipper to catch IAM and exposure problems in CloudFormation before a stack is deployed, and DefectDojo turns its results into tracked work. Each failure becomes a Finding named for the rule and the resource that tripped it, with CFRipper's risk value as the severity and the rule mode (BLOCKING or MONITOR) recorded in the description. When an engineer tightens a policy, the next reimport closes that Finding, and anything still open has an owner and an SLA instead of living in a pipeline log.
Why CFRipper Matters
Most damaging cloud incidents trace back to permissions or exposure, and CloudFormation is where many of those permissions are written.
- CFRipper focuses on security posture, which is different from the syntax and best-practice checks cfn-lint performs.
- Its privilege escalation rule names the specific IAM actions that make a policy dangerous, which gives the reviewer something concrete to remove.
- Rule modes separate rules meant to block a deployment from rules that only monitor, so teams can adopt new checks gradually.
- It reviews templates before they reach AWS, when a fix is a one-line change in a pull request.
Advantages of This Integration
- Findings keyed to rule and resource. Each Finding's title is
<rule>: <resource>, and DefectDojo deduplicates CFRipper results onvuln_id_from_tool(the rule) andcomponent_name(the resource), so the same rule on the same resource is one Finding across every rescan. - Edits don't create duplicates. Neither line numbers nor description text is part of the hash, so rewording a policy or moving a resource in the template doesn't make an open Finding look new.
- Severity straight from CFRipper. HIGH, MEDIUM, and LOW map directly to DefectDojo's High, Medium, and Low, so SLAs follow the risk CFRipper assigned.
- Reimport closes fixed issues. Reimporting into the same Test mitigates failures that disappeared, adds new ones, and reactivates any that come back.
- Shared context. CFRipper Findings sit on the same Asset as cfn-lint and cfn-nag results, so template correctness and security are reviewed together.
How This Integration Works
DefectDojo imports CFRipper output with the CFRipper Scan scan type. The parser reads the failures list of a CFRipper JSON result.
1. Analyze the template and save JSON.
cfripper template.json --format json > cfripper.json
CFRipper can also save results to a folder with --output-folder, which writes one results file per analyzed template, and its --resolve option resolves intrinsic functions before evaluation. Whichever you use, import one template's result object per file, since the parser expects a single object with a failures list.
2. Import the report. In the UI, open the Engagement, choose Import Scan Results, select CFRipper Scan, and upload the file. With the API, in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=CFRipper Scan"
-F "file=@cfripper.json"
-F "product_name=identity-stacks"
-F "engagement_name=IaC Security"
-F "test_title=iam-roles template"
-F "auto_create_context=true"
With Universal Importer in DefectDojo Pro:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "CFRipper Scan"
--report-path "./cfripper.json"
--product-name "identity-stacks"
--engagement-name "IaC Security"
--auto-create-context
3. Reimport per template. Send later results for the same template to /api/v2/reimport-scan/ against its Test so the history stays together.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in CFRipper Report | Notes |
|---|---|---|
| Title | rule and first resource_ids entry |
<rule>: <resource>, or the rule alone when no resource is named |
| Severity | risk_value |
HIGH, MEDIUM, LOW map directly; anything else Medium |
| Description | reason, rule, granularity, resources, resource types, rule mode, actions |
All resource IDs are listed here |
| Component Name | First resource_ids entry |
Logical resource ID, for example MyPolicy |
| Vuln ID from Tool | rule |
For example PrivilegeEscalationRule |
| File Path / Line | Not set | CFRipper's JSON result doesn't carry them |
| CWE | Not set | |
| Finding type | Static | Templates are analyzed, not deployed |
| Deduplication | Hash code | vuln_id_from_tool, component_name |
The parser reads failures only. Entries in CFRipper's exceptions list are not imported.
Use Cases
In a deployment pipeline: Every pull request that touches a template runs CFRipper and reimports the result. A new policy that grants actions such as iam:CreatePolicyVersion or iam:AttachRolePolicy shows up as a High privilege escalation Finding with the offending actions listed, before the stack ships.
For IAM-heavy stacks: An identity team owns the templates that define cross-account roles. Importing CFRipper results into their Asset gives them a running list of wildcard and escalation findings, with notes and risk acceptances recording the exceptions they've approved.
When rolling out new rules: Rules in MONITOR mode still produce failures in the JSON result, so importing them shows how many Findings a rule creates before anyone treats it as blocking. The rule mode is recorded in each Finding's description.
Alongside cfn-lint and cfn-nag: The three tools look at the same templates from different angles. Importing each as its own Test in one Engagement gives reviewers the full picture without merging rule sets.
Operational Tips
- Watch for repeated logical IDs. Because the hash is rule plus resource, two templates in the same Asset that both define
MyPolicyand trip the same rule are treated as duplicates. Keep logical IDs distinct, or setdeduplication_on_engagementand give each template set its own Engagement. - Only the first resource ID is used for the title and component. When a failure lists several resources, check the description before closing it.
- Severity comes from the risk value CFRipper attaches to each failure, not from DefectDojo, so review CFRipper's rule risk values before you set SLAs for this scan type.
- Use
test_title(or Universal Importer's equivalent naming) to name each Test after its template so reports are readable. - Risk-accept intentional findings, such as a deliberately public bucket, with an expiration date and a note, rather than deleting them.
- Pair CFRipper with cfn-lint in the same pipeline step so invalid templates are caught before security rules are evaluated.