All integrations

Deepfence ThreatMapper Integration with DefectDojo

Deepfence ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) that hunts for vulnerabilities, malware, exposed secrets, and compliance misconfigurations across production environments including Kubernetes, Docker, AWS Fargate, and virtual machines, ranking threats based on their risk-of-exploit and proximity to attack surfaces. ThreatMapper generates runtime Software Bill of Materials (SBOM) for workloads and hosts, provides topology visualization through ThreatGraph, and enables organizations to prioritize security remediation efforts by identifying which vulnerabilities pose the greatest risk to cloud-native applications.

Data Granularity: What Gets Imported

The following fields are captured from Deepfence ThreatMapper results and surfaced in DefectDojo findings:

FieldSourceNotes
TitleFinding name from the scanMatched to the tool's own naming
SeverityCritical / High / Medium / Low / InfoMapped from the tool's own severity scale
DescriptionFinding detail from the reportIncludes what the issue is and why it matters
MitigationRemediation guidanceWhere the tool provides it

Importing Into DefectDojo

Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:

{
  "scan_type": "Deepfence ThreatMapper",
  "engagement": "<engagement-id>",
  "file": "results.json"
}