All integrations

Detectify Integration with DefectDojo

Detectify Integration with DefectDojo

Detectify is a Swedish security company whose platform combines external attack surface management (EASM) with dynamic application security testing. Its Surface Monitoring product watches internet-facing hosts and subdomains, while Application Scanning and API Scanning test running web applications and APIs. Findings are available through the Detectify API, and a JSON export of its vulnerabilities endpoint is what DefectDojo imports from a file.

Detectify Integration with DefectDojo

We run Detectify against everything we expose to the internet, and DefectDojo is where those results get owners and deadlines. Detectify tells us a host has a problem. DefectDojo tells us which team owns that host, whether the issue was there last week, and whether it is past its SLA. With DefectDojo Pro the connector pulls findings from all three Detectify products into one place. Teams that cannot issue API keys can upload an export instead, and because both paths use the same scan type, the findings deduplicate rather than doubling up.

Why Detectify Matters

The perimeter changes constantly: new subdomains, forgotten staging sites, third-party services pointed at company DNS. Detectify is built to keep up with that.

  • It covers discovery and testing together, so a newly found host can be tested without someone filing a request.
  • It tests running targets, which catches misconfigurations and exposures that never appear in source code.
  • Findings include Detectify's description of the risk, references, CWE, and CVSS data where available.
  • Detectify tracks its own status for each finding (patched, false positive, accepted risk), which is useful context to carry into a central platform.

Advantages of This Integration

What changes when Detectify results go through DefectDojo:

  • One scan type for file and API. The parser uses Detectify Scan, the exact string the Detectify connector reports, so a team can upload exports today and enable the connector later without duplicate findings.
  • Closed items stay closed. Findings Detectify marks patched or false_positive are not imported, so resolved work does not reappear in the open queue.
  • Accepted risk is preserved. Findings with status accepted_risk are imported and flagged as risk accepted, keeping the record that someone made that decision.
  • Stable deduplication. Each finding carries Detectify's UUID as its unique ID, which matches findings across imports and syncs.
  • Endpoints for every finding. DefectDojo records the affected URL or host, so findings can be grouped by endpoint and routed to the owning team.
  • SLAs and ticketing. Detectify severities map directly to DefectDojo severities, so the same SLA rules, Jira integration, and reporting apply as for every other scanner.

How This Integration Works

Both routes use the Detectify Scan scan type. Note that it does not follow the Vendor - Connectors Import naming used by many other connector scan types, so copy it exactly.

Option 1: File import (Community Edition and DefectDojo Pro). Save the JSON response from Detectify's vulnerabilities API endpoint. The parser accepts the API's vulnerabilities envelope or a bare array of vulnerabilities. In the UI, open the Engagement, choose Import Scan Results, select Detectify Scan, and upload the file. To automate it:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Detectify Scan" 
  -F "file=@detectify-vulnerabilities.json" 
  -F "product_name=public-web" 
  -F "engagement_name=External Attack Surface" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Detectify Scan" 
  --report-path "./detectify-vulnerabilities.json" 
  --product-name "public-web" 
  --engagement-name "External Attack Surface" 
  --auto-create-context

Send later exports to /api/v2/reimport-scan/ for the same Test so findings missing from the new export are mitigated.

Option 2: Detectify connector (DefectDojo Pro). The connector covers Application Scanning, Surface Monitoring, and API Scanning in one configuration. Create an API key in Detectify under Team settings, API keys. In the DefectDojo Pro UI:

  1. Enter https://api.detectify.com/rest in the Location field.
  2. Enter the Detectify API key in the API Key field.
  3. Optionally enter the base64 secret paired with the key in the API Secret field so DefectDojo signs its requests. This is a Detectify Professional plan feature; leave it blank for key-only authentication, which works on all plans.
  4. Optionally set a Minimum Severity.

DefectDojo creates a Record for each Detectify asset, carrying its vulnerabilities from all three products, and you map each Record to a DefectDojo Asset.

Data Granularity: What Gets Imported

DefectDojo Field Source in Detectify Data Notes
Title title, else definition title Falls back to the finding UUID
Severity severity critical, high, medium, low map directly; information, info, informational, and unrecognized values become Info
Description Host, location, scan source, status, definition description Labeled lines followed by Detectify's explanation
Impact Definition risk Detectify's description of what an attacker gains
Mitigation Reference links Detectify supplies no remediation prose, so the finding points to its references
References Reference names and links Rendered as a list
CWE cwe Reported by Detectify as an integer
CVSS v3 CVSS 3.1 block, else 3.0 Score and vector; the 2.0 block is ignored
Vulnerability IDs CVEs found in titles, descriptions, risk text, references Detectify has no dedicated CVE field
Endpoint Request URL, else host and path, else location Recorded per finding
Vuln ID from Tool Definition title Detectify's stable rule name
Unique ID from Tool uuid Primary deduplication identity
Risk Accepted status of accepted_risk Imported and flagged
Tags Detectify tags and scan_source Filter by which product found it
Finding type Dynamic All findings
Deduplication Unique ID, then hashcode Fallback hash: title, severity, component name

Findings with status patched or false_positive are skipped, and repeated UUIDs within one file are imported once.

Use Cases

For external attack surface tracking: A security team syncs Detectify through the connector and maps each Detectify asset to the Asset for the team that owns it. New exposures land with an owner already assigned, and the team reviews the delta instead of the full list.

In a restricted environment: An organization still completing a vendor review exports findings from inside its network and imports the JSON. Once approval comes through, it enables the connector and the UUIDs line up with the earlier uploads.

For web application releases: Application Scanning results for a customer portal sit next to SAST and SCA findings on the same Asset, so a release review covers both code issues and what Detectify saw on the running site.

For audit evidence: Accepted risks imported from Detectify keep their flag in DefectDojo, so an auditor can see which external issues were accepted rather than fixed, alongside discovery and closure dates for the rest.

Operational Tips

  • Copy the scan type exactly as Detectify Scan. A guessed Detectify - Connectors Import will not match the connector, and the two sources will not deduplicate.
  • Map Detectify assets to DefectDojo Assets by owning team. Endpoints on each finding make it easy to confirm the mapping.
  • Use the scan_source tag to separate Surface Monitoring results from Application Scanning and API Scanning in dashboards and SLA reports.
  • Review accepted risks imported from Detectify and add an expiration date in DefectDojo so they come back for review.
  • Because Detectify supplies only reference links in Mitigation, add remediation notes to recurring findings so the next engineer has more to go on.
  • Set minimum_severity on file import, or Minimum Severity on the connector, if informational surface findings would crowd out actionable ones.