Detectify Integration with DefectDojo
Detectify Integration with DefectDojo
Detectify is a Swedish security company whose platform combines external attack surface management (EASM) with dynamic application security testing. Its Surface Monitoring product watches internet-facing hosts and subdomains, while Application Scanning and API Scanning test running web applications and APIs. Findings are available through the Detectify API, and a JSON export of its vulnerabilities endpoint is what DefectDojo imports from a file.
Detectify Integration with DefectDojo
We run Detectify against everything we expose to the internet, and DefectDojo is where those results get owners and deadlines. Detectify tells us a host has a problem. DefectDojo tells us which team owns that host, whether the issue was there last week, and whether it is past its SLA. With DefectDojo Pro the connector pulls findings from all three Detectify products into one place. Teams that cannot issue API keys can upload an export instead, and because both paths use the same scan type, the findings deduplicate rather than doubling up.
Why Detectify Matters
The perimeter changes constantly: new subdomains, forgotten staging sites, third-party services pointed at company DNS. Detectify is built to keep up with that.
- It covers discovery and testing together, so a newly found host can be tested without someone filing a request.
- It tests running targets, which catches misconfigurations and exposures that never appear in source code.
- Findings include Detectify's description of the risk, references, CWE, and CVSS data where available.
- Detectify tracks its own status for each finding (patched, false positive, accepted risk), which is useful context to carry into a central platform.
Advantages of This Integration
What changes when Detectify results go through DefectDojo:
- One scan type for file and API. The parser uses Detectify Scan, the exact string the Detectify connector reports, so a team can upload exports today and enable the connector later without duplicate findings.
- Closed items stay closed. Findings Detectify marks
patchedorfalse_positiveare not imported, so resolved work does not reappear in the open queue. - Accepted risk is preserved. Findings with status
accepted_riskare imported and flagged as risk accepted, keeping the record that someone made that decision. - Stable deduplication. Each finding carries Detectify's UUID as its unique ID, which matches findings across imports and syncs.
- Endpoints for every finding. DefectDojo records the affected URL or host, so findings can be grouped by endpoint and routed to the owning team.
- SLAs and ticketing. Detectify severities map directly to DefectDojo severities, so the same SLA rules, Jira integration, and reporting apply as for every other scanner.
How This Integration Works
Both routes use the Detectify Scan scan type. Note that it does not follow the Vendor - Connectors Import naming used by many other connector scan types, so copy it exactly.
Option 1: File import (Community Edition and DefectDojo Pro). Save the JSON response from Detectify's vulnerabilities API endpoint. The parser accepts the API's vulnerabilities envelope or a bare array of vulnerabilities. In the UI, open the Engagement, choose Import Scan Results, select Detectify Scan, and upload the file. To automate it:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Detectify Scan"
-F "file=@detectify-vulnerabilities.json"
-F "product_name=public-web"
-F "engagement_name=External Attack Surface"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Detectify Scan"
--report-path "./detectify-vulnerabilities.json"
--product-name "public-web"
--engagement-name "External Attack Surface"
--auto-create-context
Send later exports to /api/v2/reimport-scan/ for the same Test so findings missing from the new export are mitigated.
Option 2: Detectify connector (DefectDojo Pro). The connector covers Application Scanning, Surface Monitoring, and API Scanning in one configuration. Create an API key in Detectify under Team settings, API keys. In the DefectDojo Pro UI:
- Enter
https://api.detectify.com/restin the Location field. - Enter the Detectify API key in the API Key field.
- Optionally enter the base64 secret paired with the key in the API Secret field so DefectDojo signs its requests. This is a Detectify Professional plan feature; leave it blank for key-only authentication, which works on all plans.
- Optionally set a Minimum Severity.
DefectDojo creates a Record for each Detectify asset, carrying its vulnerabilities from all three products, and you map each Record to a DefectDojo Asset.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Detectify Data | Notes |
|---|---|---|
| Title | title, else definition title |
Falls back to the finding UUID |
| Severity | severity |
critical, high, medium, low map directly; information, info, informational, and unrecognized values become Info |
| Description | Host, location, scan source, status, definition description | Labeled lines followed by Detectify's explanation |
| Impact | Definition risk |
Detectify's description of what an attacker gains |
| Mitigation | Reference links | Detectify supplies no remediation prose, so the finding points to its references |
| References | Reference names and links | Rendered as a list |
| CWE | cwe |
Reported by Detectify as an integer |
| CVSS v3 | CVSS 3.1 block, else 3.0 | Score and vector; the 2.0 block is ignored |
| Vulnerability IDs | CVEs found in titles, descriptions, risk text, references | Detectify has no dedicated CVE field |
| Endpoint | Request URL, else host and path, else location | Recorded per finding |
| Vuln ID from Tool | Definition title | Detectify's stable rule name |
| Unique ID from Tool | uuid |
Primary deduplication identity |
| Risk Accepted | status of accepted_risk |
Imported and flagged |
| Tags | Detectify tags and scan_source |
Filter by which product found it |
| Finding type | Dynamic | All findings |
| Deduplication | Unique ID, then hashcode | Fallback hash: title, severity, component name |
Findings with status patched or false_positive are skipped, and repeated UUIDs within one file are imported once.
Use Cases
For external attack surface tracking: A security team syncs Detectify through the connector and maps each Detectify asset to the Asset for the team that owns it. New exposures land with an owner already assigned, and the team reviews the delta instead of the full list.
In a restricted environment: An organization still completing a vendor review exports findings from inside its network and imports the JSON. Once approval comes through, it enables the connector and the UUIDs line up with the earlier uploads.
For web application releases: Application Scanning results for a customer portal sit next to SAST and SCA findings on the same Asset, so a release review covers both code issues and what Detectify saw on the running site.
For audit evidence: Accepted risks imported from Detectify keep their flag in DefectDojo, so an auditor can see which external issues were accepted rather than fixed, alongside discovery and closure dates for the rest.
Operational Tips
- Copy the scan type exactly as Detectify Scan. A guessed
Detectify - Connectors Importwill not match the connector, and the two sources will not deduplicate. - Map Detectify assets to DefectDojo Assets by owning team. Endpoints on each finding make it easy to confirm the mapping.
- Use the
scan_sourcetag to separate Surface Monitoring results from Application Scanning and API Scanning in dashboards and SLA reports. - Review accepted risks imported from Detectify and add an expiration date in DefectDojo so they come back for review.
- Because Detectify supplies only reference links in Mitigation, add remediation notes to recurring findings so the next engineer has more to go on.
- Set
minimum_severityon file import, or Minimum Severity on the connector, if informational surface findings would crowd out actionable ones.