Datadog Cloud Security Integration with DefectDojo
Datadog Cloud Security Integration with DefectDojo
Datadog Cloud Security is part of Datadog's security product line. It evaluates cloud accounts and workloads already monitored by Datadog and reports security findings of several kinds, including cloud misconfigurations against compliance rules, library and code vulnerabilities, identity risks, attack paths, and API security issues. Every finding carries Datadog's environment-adjusted severity, the affected resource, the rule that raised it, and its cloud account and region. Findings are available as JSON from Datadog's security findings API.
Datadog Cloud Security Integration with DefectDojo
Our cloud teams already use Datadog for monitoring, so Cloud Security was the natural source for cloud posture and workload findings. We import those findings into DefectDojo because remediation, SLAs, and reporting for every other tool already run there. Each Datadog finding becomes a DefectDojo Finding with its rule ID, CVEs, CVSS data, affected package, service, and cloud placement tags, and anything already muted, resolved, or passing in Datadog stays out of the queue.
Why Datadog Cloud Security Matters
Cloud risk spans configuration, identity, and the software running on workloads, and Datadog reports all three from one place.
- It covers misconfigurations, vulnerabilities, identity risks, and attack paths through a single findings stream.
- Its severity is adjusted for the environment, rather than being a rule's static default.
- Findings carry the cloud provider, region, account, and resource type, which is what you need to route them to an owner.
- It builds on the Datadog agent and integrations a team may already run, so coverage follows existing monitoring.
- A posture dashboard shows current state. It does not apply your SLAs or put cloud findings next to application and pentest results.
Advantages of This Integration
What running Datadog Cloud Security through DefectDojo adds:
- File and connector findings stay in sync. The file parser uses the same scan type as the connector, Datadog Cloud Security, and the same deduplication settings, so moving from file uploads to the connector does not create duplicates.
- Datadog's identity, then a hash. Deduplication uses Datadog's finding ID first, then falls back to title, severity, and component name.
- Triage carries over. Findings with a status of muted, resolved, or auto_closed, findings muted through Datadog workflow, and compliance rules that evaluated as pass are all skipped. A failing evaluation is imported.
- Static and dynamic decided per finding. Runtime code vulnerabilities, API security, attack path, workload activity, and identity risk findings are dynamic; everything else is static.
- The right severity. DefectDojo uses Datadog's adjusted
severity, not itsbase_severity, so the import reflects Datadog's environment context. - Filtering by cloud placement. Tags record finding type, cloud provider, region, account, and resource type, alongside Datadog's own tags in their original order.
How This Integration Works
There are two supported ways to get Datadog Cloud Security findings into DefectDojo. Both use the Datadog Cloud Security scan type.
Option 1: JSON file import (Community Edition and DefectDojo Pro). This path is for organizations that cannot give DefectDojo Datadog API credentials, such as air-gapped networks or teams awaiting a security review. Export findings as JSON from Datadog's posture management findings endpoint (/api/v2/posture_management/findings). The parser accepts the response with rows under data, a bare array of rows, or a single row. In the UI, open the Engagement, choose Import Scan Results, select Datadog Cloud Security, and upload the file. To automate it:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Datadog Cloud Security"
-F "file=@datadog-findings.json"
-F "product_name=aws-prod"
-F "engagement_name=Cloud Security"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Datadog Cloud Security"
--report-path "./datadog-findings.json"
--product-name "aws-prod"
--engagement-name "Cloud Security"
--auto-create-context
Option 2: Datadog connector (DefectDojo Pro). The connector imports Cloud Security findings from the Datadog security findings API on a schedule. You need two credentials from Datadog: an API key from Organization Settings, API Keys, and an application key from Organization Settings, Application Keys, with the security_monitoring_findings_read scope. Then configure:
- Your Datadog site in the Location field, for example
https://api.datadoghq.com. Organizations on the EU, US3, US5, or AP1 sites must use their own site hostname. - The API key in the API Key field.
- The application key in the Application Key field.
- Optionally, a Minimum Severity to limit what is imported.
DefectDojo creates a Record for each cloud account that has findings, so no per-resource configuration is needed. The connector respects Datadog's rate limits, backing off and retrying rather than failing the sync. Neither key is logged by DefectDojo.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Datadog Finding | Notes |
|---|---|---|
| Title | title |
Falls back to rule name, then finding type |
| Severity | severity |
critical, high, medium, low map directly; anything else Info |
| Description | description plus details |
Overview, then rule, finding type, resource, compliance evaluation, advisory and summary |
| Date | first_seen_at |
Unix milliseconds; falls back to detection_changed_at |
| CVSS v3 | severity_details.base |
Falls back to adjusted; vector and score taken from the same block |
| Vulnerability IDs | Advisory CVE and aliases, plus IDs in title and description | CVE, GHSA, GO, and RHSA formats recognized |
| Vulnerability ID from tool | rule.id |
The Datadog rule identifier |
| Component Name / Version | package.name, package.version |
For library findings |
| Service | service: tag |
Read from Datadog's tags |
| Tags | Finding type, cloud provider, region, account, resource type, Datadog tags | Deduplicated, order preserved |
| Unique ID from tool | Row id |
Falls back to finding_id |
| Finding type | finding_type |
Runtime types dynamic, others static |
| Deduplication | Unique ID or hashcode | Unique ID from tool, then title, severity, component_name |
The finding itself is nested twice in Datadog's response (data[].attributes.attributes). The outer attributes carry the row's tags and timestamp, and the parser reads both.
Use Cases
Cloud posture with SLAs: A platform team enables the connector, and each cloud account with findings becomes a Record mapped to the owning team's Asset. Misconfigurations arrive with Datadog's adjusted severity and fall under the same SLA rules as application vulnerabilities.
Vulnerabilities in running services: Library vulnerability findings carry the package, version, CVEs, and the service from Datadog's tags, so a service owner can filter their findings and see which packages need upgrading.
Restricted environments: A team whose security review has not cleared API credentials for DefectDojo exports findings from Datadog on a trusted host and uploads the JSON. When the connector is approved, the findings already imported deduplicate against synced ones.
Audit evidence: Failing compliance evaluations are tracked as findings with discovery dates and remediation history, which supports evidence requests without screenshots from a dashboard.
Operational Tips
- Give the application key only the
security_monitoring_findings_readscope the connector needs. - Set the Location to your own Datadog site. Organizations on EU, US3, US5, or AP1 must use their site's hostname rather than
api.datadoghq.com. - Mute findings in Datadog when they are accepted there. Muted findings are skipped on import, so the decision is not made twice.
- Use the tags to route work: filter on
account:,region:, orfinding_type:to separate identity risks from misconfigurations. - Start with a Minimum Severity of High on the connector, or
minimum_severity=Highon file import, if the first sync is large. - Keep file uploads on the Datadog Cloud Security scan type. It does not follow the "Vendor - Connectors Import" naming used by some other connectors, and a different scan type would stop file and connector findings from deduplicating.