Cloudflare Insights Integration with DefectDojo
Cloudflare Insights Integration with DefectDojo
Cloudflare Security Insights are part of Cloudflare Security Center, which reviews the accounts and zones you run on Cloudflare and flags security posture issues. Examples include DNS records that aren't proxied and expose origin IP addresses, a missing DMARC record, DNSSEC not enabled, a missing security.txt file, or certificate problems. Each insight carries a severity, an issue class and type, the affected subject (usually a hostname or zone), and recommended action. Insights can be exported from the dashboard as CSV or retrieved as JSON through the Cloudflare API.
Cloudflare Insights Integration with DefectDojo
We put most of our public domains behind Cloudflare, so Security Center insights are often the first sign that someone added an unproxied DNS record or let an email authentication record lapse. Importing those insights into DefectDojo gives them owners. Each insight becomes a Finding with the affected host as its endpoint and Cloudflare's recommended action as the mitigation, and it sits on the same Asset as the DAST and infrastructure findings for that domain. Insights that are resolved or dismissed in Cloudflare come in inactive, so the open list matches what still needs work.
Why Cloudflare Insights Matter
Edge and DNS configuration drift is easy to miss because nothing breaks when it happens.
- An unproxied record can reveal an origin server's IP address and let traffic bypass Cloudflare's protections entirely.
- Missing DMARC or DNSSEC configuration weakens email and domain integrity without any visible symptom.
- Security Center checks every zone the account holds, including old or forgotten domains no one is actively watching.
- Cloudflare shows insights in its own dashboard. Tracking them in DefectDojo puts them under the same SLAs and reporting as the rest of your vulnerability data.
Advantages of This Integration
- Status carried over. CSV rows with a status of Resolved, Mitigated, Closed, or Fixed import as inactive, and JSON insights marked
dismissedimport as inactive, so Cloudflare-side decisions are respected. - Hosts as endpoints. The parser extracts the hostname from each insight's subject and attaches it as an endpoint, which lets you filter and report posture issues by domain.
- Remediation in the Finding. Cloudflare's recommended action (CSV) or resolve text (JSON) becomes the Finding's mitigation, so the fix travels with the ticket when you push it to Jira.
- Severity normalized. Cloudflare's Low, Moderate, High, and Critical map to Low, Medium, High, and Critical, so insights fall under your existing SLA rules.
- Two ways in. Use file imports where you can't share API credentials, or let the DefectDojo Pro connector sync insights on a schedule and mitigate them automatically once they are resolved or dismissed in Cloudflare.
How This Integration Works
File imports use the Cloudflare Insights scan type and support UI Import, API Import, and Universal Importer. DefectDojo Pro also offers an API connector.
Option 1: Import a CSV or JSON file. Export Security Insights from the Cloudflare dashboard as CSV, or save insights retrieved from the Cloudflare API as JSON. The parser treats a file starting with [ as JSON, so a JSON file must be a top-level array of insight objects; if your API response wraps the list in an envelope, extract the array first. CSV files need the severity, issue_class, subject, issue_type, status, and recommended_action columns, with insight, detection_method, and risk read when present.
Import through the UI by choosing Import Scan Results on the Engagement, or with the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Cloudflare Insights"
-F "file=@cloudflare-insights.csv"
-F "product_name=public-domains"
-F "engagement_name=Edge Posture"
-F "auto_create_context=true"
With Universal Importer in DefectDojo Pro:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Cloudflare Insights"
--report-path "./cloudflare-insights.csv"
--product-name "public-domains"
--engagement-name "Edge Posture"
--auto-create-context
Option 2: Use the API Connector (Pro). Create a Cloudflare API token (not the legacy Global API Key) under My Profile, API Tokens. The "Read all resources" template works; for least privilege, grant Zone, Zone, Read for all zones plus account-level read access for Security Center. In DefectDojo Pro, add the Cloudflare connector, enter https://api.cloudflare.com/client/v4 as the Location, paste the token into Secret, and optionally set a Minimum Severity. The connector discovers the accounts and zones the token can access, creates a Record for each zone with open insights plus an account-level Record for insights not tied to a zone, and imports only open (active, non-dismissed) insights. Insights you resolve or dismiss in Cloudflare are mitigated in DefectDojo on the next sync.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Cloudflare Export | Notes |
|---|---|---|
| Title | issue_type and subject |
<issue_type>: <subject>, or whichever exists |
| Severity | severity |
Low, Moderate (Medium), High, Critical; anything else Info |
| Description | Issue class, issue type, risk | CSV adds status, insight, and detection method |
| Mitigation | recommended_action (CSV), resolve_text (JSON) |
Cloudflare's suggested fix |
| Endpoint | subject |
Hostname extracted; port and path dropped |
| Active | status (CSV), dismissed (JSON) |
Resolved, Mitigated, Closed, Fixed, or dismissed import inactive |
| References | Fixed text | Set to "Not provided!" |
| Finding type | Dynamic | Insights describe live configuration |
| Deduplication | Legacy algorithm | No per-parser configuration; endpoints must match for dynamic findings |
The table above describes the file parser. The connector maps each zone to a Record and imports open insights, as described in the connector documentation.
Use Cases
For domain portfolio reviews: An organization with dozens of zones imports insights into an Asset for its public domains. Security leads see every unproxied record and missing email authentication setting by hostname, and assign each to the team that owns the domain.
After DNS changes: A team adds records for a new service. The next connector sync or file import shows whether any new record exposes an origin, and the Finding names the host to fix.
For restricted environments: A team that can't hand DefectDojo a Cloudflare API token exports the CSV from the dashboard each week and imports it. Resolved rows come in inactive, so the open count reflects real work.
For email security hygiene: Missing DMARC or related records become tracked Findings with Cloudflare's recommended action attached, which gives the messaging team a clear list instead of a dashboard they don't check.
Operational Tips
- Choose one path per Cloudflare account, file imports or the connector, so the same insight isn't tracked twice.
- Keep imports for one account in one Test and reimport, so insights that disappear from the export are mitigated.
- Insights with severities the parser doesn't recognize import as Info. Check a first import to confirm severities land where you expect.
- The References field reads "Not provided!" for every Finding. Add links in notes if your team needs them.
- If you strip status columns from the CSV, every row imports as active. Keep the
statuscolumn intact. - Use the connector's Minimum Severity, or
minimum_severityon file imports, to hold back low-priority configuration suggestions while you work through higher-severity issues.