All integrations

ClamAV Integration with DefectDojo

ClamAV Integration with DefectDojo

ClamAV is an open source antivirus engine maintained by Cisco Talos. Its clamscan command-line scanner matches files against malware signature databases, including ClamAV's own official signatures and any third-party or locally written databases you add. clamscan prints one line per scanned file followed by a scan summary, and that plain-text output is what DefectDojo imports.

ClamAV Integration with DefectDojo

We run ClamAV against build artifacts, upload directories, and file shares, and DefectDojo is where its detections get investigated rather than lost in job logs. Each signature match becomes a High Finding with CWE-506 (embedded malicious code), the file path, and the signature name, attached to the Asset that owns the scanned location. Rescans deduplicate against what we already know, so a single detection stays a single Finding with its triage notes, and a real hit can be assigned and pushed to Jira for follow-up.

Why ClamAV Matters

Malware can reach places security teams don't usually scan: release artifacts, customer uploads, shared storage, and container filesystems.

  • ClamAV is free, open source, and scriptable, so it fits into CI jobs and scheduled scans without licensing work.
  • It names the signature it matched. A detection is evidence of a specific match, not a heuristic guess.
  • You can extend it with your own signature databases, which lets teams look for indicators specific to their own environment.
  • clamscan output is ephemeral. Without a platform recording it, there's no record of which files were flagged, when, and what was decided.

Advantages of This Integration

  • Only detections become Findings. clamscan prints OK, Empty file, and ERROR lines for files that aren't detections, plus a summary block. The parser keeps only FOUND lines, so a clean scan imports as zero Findings despite its long output.
  • One Finding per signature per file. With --allmatch, a file matching several signatures produces a Finding for each, and repeated lines for the same file and signature collapse into one within the report.
  • Signature provenance kept. ClamAV adds .UNOFFICIAL to signatures from any database other than its own. The parser keeps the suffix and calls it out in the description, which tells a reviewer how much weight to give the detection.
  • Stable deduplication. The scan summary, with its engine version and scan date, isn't carried into Findings, so rescanning an unchanged file matches the existing Finding instead of creating a new one.
  • Triage with a record. False detections can be marked false positive with a note, and confirmed ones can be escalated to Critical, assigned, and tracked to removal.

How This Integration Works

DefectDojo imports clamscan output with the ClamAV Scan scan type.

1. Scan and save the output.

clamscan -r --allmatch /path/to/scan > clamav.txt

-r scans recursively. --allmatch keeps scanning a file after the first match, so every signature it matches is reported. Without it, a file matching several signatures shows only one.

2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select ClamAV Scan, and upload the text file. From a pipeline or scheduled job, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=ClamAV Scan" 
  -F "file=@clamav.txt" 
  -F "product_name=release-artifacts" 
  -F "engagement_name=Malware Scans" 
  -F "auto_create_context=true"

DefectDojo Pro users can use Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "ClamAV Scan" 
  --report-path "./clamav.txt" 
  --product-name "release-artifacts" 
  --engagement-name "Malware Scans" 
  --auto-create-context

3. Reimport on a schedule. For a location you scan repeatedly, send later results to /api/v2/reimport-scan/ against the same Test so removed files are mitigated and new detections are added.

Data Granularity: What Gets Imported

DefectDojo Field Source in clamscan Output Notes
Title Signature and path from a FOUND line Malware detected: <signature> in <path>
Severity Fixed Always High; adjust per artifact during triage
CWE Fixed 506, Embedded Malicious Code
Description File path and signature Adds a note when the signature ends in .UNOFFICIAL
Mitigation Fixed guidance Remove the file, find how it got there, or record a false positive
File Path Scanned path Paths with spaces and colons are handled
Vuln ID from Tool Signature name ClamAV's own name for the detection
Finding type Static clamscan reads files rather than probing a service
Deduplication Hash code Legacy default fields: title, cwe, line, file_path, description

OK, Empty file, and ERROR lines, as well as the SCAN SUMMARY block, are not imported.

Use Cases

In a release pipeline: Before artifacts are published, a CI step runs clamscan over the build output and imports the result. A detection blocks nothing by itself, but it appears as a High Finding on the release Asset that someone must resolve or mark false positive, with the decision recorded.

For upload storage: A team that accepts files from customers runs a nightly clamscan over the upload bucket's synced copy and reimports into one Test. New detections appear as new Findings, and files that were deleted are mitigated on the next run.

For custom indicators: A security team writes local signatures for indicators from a recent incident and scans file shares with them. Because those signatures carry the .UNOFFICIAL suffix, analysts can tell at a glance which Findings came from the custom database.

For audit evidence: Dated Tests show that malware scanning ran on a given location and what it found, which answers auditor questions without collecting log files.

Operational Tips

  • Always pass --allmatch if you want complete results per file. Without it, extra signatures on an already-flagged file never reach DefectDojo.
  • Keep scan paths consistent. The file path is in both the title and the hash, so scanning the same files through a different mount point creates new Findings.
  • Triage severity by artifact. A hit in a production release is a different event from a test fixture, so raise confirmed detections to Critical where it fits.
  • Record false positives in DefectDojo rather than excluding paths from the scan, so the decision is visible and reviewable.
  • Use tags such as the scanned location or job name when several scan targets share an Asset.
  • Watch scans that produce many ERROR lines. Unreadable files aren't imported as Findings, so a permissions problem can make coverage look better than it is.