Elastic Security Integration with DefectDojo
Elastic Security Integration with DefectDojo
Elastic Security is the security solution from Elastic, built on Elasticsearch and Kibana. Alongside its SIEM detection engine, it includes cloud security features such as Cloud Native Vulnerability Management (CNVM), which finds software CVEs in cloud workloads, and cloud and Kubernetes security posture management, which evaluates resources against benchmark rules. All of this data is stored as documents in Elasticsearch, described with the Elastic Common Schema, and can be retrieved through the Elasticsearch search API as JSON, which DefectDojo imports.
Elastic Security Integration with DefectDojo
We already send our cloud and endpoint telemetry to Elastic, so Elastic Security's vulnerability and posture data was sitting in the same cluster as our logs. What it lacked was a remediation workflow. Bringing it into DefectDojo turns workload CVEs and failed benchmark rules into Findings with owners and SLAs, next to our application scanners, and puts detection alerts into a triage queue with clear handling notes. DefectDojo Pro customers can sync it with the connector. Teams that cannot issue Elasticsearch credentials can export search results and import them as files, and the file parsers match the connector's scan types so the two deduplicate.
Why Elastic Security Matters
Many teams already run Elastic for logging and SIEM, which puts security data close to where it is collected.
- CNVM reports vulnerable packages in running workloads, which catches drift that image scanning at build time can miss.
- Posture management checks cloud accounts and Kubernetes clusters against benchmark rules and records the rationale, remediation, and cost of fixing each rule.
- Detection rules surface suspicious activity, which needs triage even though it is not a fixable defect.
- Every document carries ECS context about the host, resource, cluster, and cloud account, which tells you who owns the problem.
- Inside Elastic, these three data types live in different views. A security program still needs one place to assign, track, and report on them.
Advantages of This Integration
What running Elastic Security data through DefectDojo provides:
- Three scan types, kept apart. CNVM vulnerabilities, posture failures, and detection alerts import under separate scan types with separate deduplication keys, so a burst of alerts never mixes with a CVE backlog.
- One export, three imports. Each parser claims only its own documents, so the same search response can be uploaded under all three scan types without any document landing twice.
- File and connector agree. Scan type strings match the connector exactly, and the Elasticsearch document ID is the unique ID, so file imports and connector syncs deduplicate.
- Only failures for posture. Elastic writes a document for every rule evaluation. Only failed evaluations become findings.
- Honest handling of detections. Alerts are imported as neither static nor dynamic, and their mitigation is a triage instruction, not a fix.
- Context for routing. Resource, host, OS, cluster, namespace, and cloud account land in the description, and provider, region, and cluster become tags.
How This Integration Works
Elastic Security data maps to three scan types:
- Elastic Security:CNVM - Connectors Import for documents carrying a
vulnerability.id - Elastic Security:Posture - Connectors Import for documents carrying a
rulewhoseresult.evaluationis failed - Elastic Security:Detections - Connectors Import for alert documents under
kibana.alert, or the older top-levelsignalobject
Option 1: File import (Community Edition and DefectDojo Pro). Run a search against the relevant Elastic Security indices and save the Elasticsearch search response, with documents under hits.hits. A bare array of documents, or a single document, is also accepted. Keep each document's _id, which becomes the finding's identity. Import the file once per scan type you want. In the UI, open the Engagement, choose Import Scan Results, pick the scan type, and upload. To automate it:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Elastic Security:CNVM - Connectors Import"
-F "file=@elastic-security-export.json"
-F "product_name=aws-prod-workloads"
-F "engagement_name=Cloud Security"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer, changing the scan type for posture or detections:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Elastic Security:Posture - Connectors Import"
--report-path "./elastic-security-export.json"
--product-name "aws-prod-workloads"
--engagement-name "Cloud Security"
--auto-create-context
Option 2: Elastic Security connector (DefectDojo Pro). The connector imports all three finding types from an Elasticsearch cluster. In the DefectDojo Pro UI:
- Enter your Elasticsearch cluster URL in the Location field.
- Enter an Elasticsearch API key, as the base64
id:api_keyvalue, in the API Key field. An API key is preferred because it can be scoped read-only to the security indices. - If the cluster does not have API keys enabled, leave that field blank and enter a Username and password for HTTP Basic authentication instead.
- Optionally set a Minimum Severity.
DefectDojo creates a Record for each cloud account. Findings without a cloud account fall back to the Kubernetes cluster, then the host, and anything identifying none of those goes to a single catch-all Record rather than being dropped.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Elastic Documents | Notes |
|---|---|---|
| Title (CNVM) | CVE, package, version, asset | Formatted as CVE - package version on asset |
| Title (Posture) | rule.name |
Unnamed rules are skipped |
| Title (Detections) | Rule name, else alert reason | Alerts with neither are skipped |
| Severity (CNVM) | vulnerability.severity, else CVSS base |
Recognized label wins; otherwise 9.0+ Critical, 7.0+ High, 4.0+ Medium, above 0 Low |
| Severity (Posture, Detections) | Rule or alert severity label | Unrecognized or missing labels become Medium |
| Description | Per type, plus ECS asset lines | CVE text and CVSS; rationale, benchmark, impact of remediation; reason, risk score, workflow status |
| Mitigation | Fixed version, rule remediation, or triage note | CNVM says when no fix is published; detections get a triage instruction |
| Component Name / Version | Package (CNVM) or benchmark (Posture) | Not set for detections |
| CVSS v3 Score | vulnerability.score.base |
CNVM, v3 scores only; v2 scores stay in the description |
| Vulnerability IDs | vulnerability.id |
CNVM only |
| Vuln ID from Tool | CVE, rule ID, or rule uuid | Posture falls back to benchmark rule number |
| Unique ID from Tool | Document _id |
Detections fall back to alert uuid |
| Endpoint | Host, else resource or pod name | Values that are not valid hosts are skipped |
| Dates | @timestamp, published_date |
Publish date for CNVM |
| Tags | Type, provider, region, cluster, rule tags | Detections add event categories |
| Finding type | Static, or neither for detections | Detections are observed activity |
| Deduplication | Unique ID, then hashcode | CNVM: title, severity, component name. Posture and Detections: title, severity, Vuln ID from Tool |
Use Cases
For cloud workload vulnerabilities: A platform team imports CNVM findings into an Asset per cloud account. Each CVE names the package, version, and workload, and the mitigation names the fixed version so the owning team knows which image to rebuild.
For posture and compliance: Failed CIS benchmark rules from posture management become findings with Elastic's remediation text and the documented impact of the fix, so teams can plan changes and auditors can see when each rule passed again.
For detection triage: A security operations team imports detection alerts into a separate Engagement. Repeated firings of the same rule group by rule uuid, and Elastic's workflow status appears in the description while triage happens in DefectDojo.
From a restricted cluster: An organization that cannot grant outside access to Elasticsearch saves search responses internally and imports them. If the connector is approved later, document IDs keep the two sources aligned.
Operational Tips
- Import the same export three times, once per scan type, when you want all three data types. Each parser skips documents that belong to the others.
- Keep document
_idvalues in your exports. Without them, identity falls back to asset, CVE, and package or rule, which is less stable. - Put detections in their own Engagement. They describe activity, not defects, and should not count toward remediation metrics.
- The Elastic workflow status for an alert is not mapped onto the finding's status. Close detections in DefectDojo when the investigation is done.
- Scope the connector's API key read-only to the security indices rather than using a broad user account.
- Use Minimum Severity on the connector or
minimum_severityon import if Info-level CNVM entries would bury actionable CVEs.