Deepfence ThreatMapper Integration with DefectDojo
Deepfence ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) that hunts for vulnerabilities, malware, exposed secrets, and compliance misconfigurations across production environments including Kubernetes, Docker, AWS Fargate, and virtual machines, ranking threats based on their risk-of-exploit and proximity to attack surfaces. ThreatMapper generates runtime Software Bill of Materials (SBOM) for workloads and hosts, provides topology visualization through ThreatGraph, and enables organizations to prioritize security remediation efforts by identifying which vulnerabilities pose the greatest risk to cloud-native applications.
Data Granularity: What Gets Imported
The following fields are captured from Deepfence ThreatMapper results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "Deepfence ThreatMapper",
"engagement": "<engagement-id>",
"file": "results.json"
}