All integrations

Elastic Security Integration with DefectDojo

Elastic Security Integration with DefectDojo

Elastic Security is the security solution from Elastic, built on Elasticsearch and Kibana. Alongside its SIEM detection engine, it includes cloud security features such as Cloud Native Vulnerability Management (CNVM), which finds software CVEs in cloud workloads, and cloud and Kubernetes security posture management, which evaluates resources against benchmark rules. All of this data is stored as documents in Elasticsearch, described with the Elastic Common Schema, and can be retrieved through the Elasticsearch search API as JSON, which DefectDojo imports.

Elastic Security Integration with DefectDojo

We already send our cloud and endpoint telemetry to Elastic, so Elastic Security's vulnerability and posture data was sitting in the same cluster as our logs. What it lacked was a remediation workflow. Bringing it into DefectDojo turns workload CVEs and failed benchmark rules into Findings with owners and SLAs, next to our application scanners, and puts detection alerts into a triage queue with clear handling notes. DefectDojo Pro customers can sync it with the connector. Teams that cannot issue Elasticsearch credentials can export search results and import them as files, and the file parsers match the connector's scan types so the two deduplicate.

Why Elastic Security Matters

Many teams already run Elastic for logging and SIEM, which puts security data close to where it is collected.

  • CNVM reports vulnerable packages in running workloads, which catches drift that image scanning at build time can miss.
  • Posture management checks cloud accounts and Kubernetes clusters against benchmark rules and records the rationale, remediation, and cost of fixing each rule.
  • Detection rules surface suspicious activity, which needs triage even though it is not a fixable defect.
  • Every document carries ECS context about the host, resource, cluster, and cloud account, which tells you who owns the problem.
  • Inside Elastic, these three data types live in different views. A security program still needs one place to assign, track, and report on them.

Advantages of This Integration

What running Elastic Security data through DefectDojo provides:

  • Three scan types, kept apart. CNVM vulnerabilities, posture failures, and detection alerts import under separate scan types with separate deduplication keys, so a burst of alerts never mixes with a CVE backlog.
  • One export, three imports. Each parser claims only its own documents, so the same search response can be uploaded under all three scan types without any document landing twice.
  • File and connector agree. Scan type strings match the connector exactly, and the Elasticsearch document ID is the unique ID, so file imports and connector syncs deduplicate.
  • Only failures for posture. Elastic writes a document for every rule evaluation. Only failed evaluations become findings.
  • Honest handling of detections. Alerts are imported as neither static nor dynamic, and their mitigation is a triage instruction, not a fix.
  • Context for routing. Resource, host, OS, cluster, namespace, and cloud account land in the description, and provider, region, and cluster become tags.

How This Integration Works

Elastic Security data maps to three scan types:

  • Elastic Security:CNVM - Connectors Import for documents carrying a vulnerability.id
  • Elastic Security:Posture - Connectors Import for documents carrying a rule whose result.evaluation is failed
  • Elastic Security:Detections - Connectors Import for alert documents under kibana.alert, or the older top-level signal object

Option 1: File import (Community Edition and DefectDojo Pro). Run a search against the relevant Elastic Security indices and save the Elasticsearch search response, with documents under hits.hits. A bare array of documents, or a single document, is also accepted. Keep each document's _id, which becomes the finding's identity. Import the file once per scan type you want. In the UI, open the Engagement, choose Import Scan Results, pick the scan type, and upload. To automate it:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Elastic Security:CNVM - Connectors Import" 
  -F "file=@elastic-security-export.json" 
  -F "product_name=aws-prod-workloads" 
  -F "engagement_name=Cloud Security" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer, changing the scan type for posture or detections:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Elastic Security:Posture - Connectors Import" 
  --report-path "./elastic-security-export.json" 
  --product-name "aws-prod-workloads" 
  --engagement-name "Cloud Security" 
  --auto-create-context

Option 2: Elastic Security connector (DefectDojo Pro). The connector imports all three finding types from an Elasticsearch cluster. In the DefectDojo Pro UI:

  1. Enter your Elasticsearch cluster URL in the Location field.
  2. Enter an Elasticsearch API key, as the base64 id:api_key value, in the API Key field. An API key is preferred because it can be scoped read-only to the security indices.
  3. If the cluster does not have API keys enabled, leave that field blank and enter a Username and password for HTTP Basic authentication instead.
  4. Optionally set a Minimum Severity.

DefectDojo creates a Record for each cloud account. Findings without a cloud account fall back to the Kubernetes cluster, then the host, and anything identifying none of those goes to a single catch-all Record rather than being dropped.

Data Granularity: What Gets Imported

DefectDojo Field Source in Elastic Documents Notes
Title (CNVM) CVE, package, version, asset Formatted as CVE - package version on asset
Title (Posture) rule.name Unnamed rules are skipped
Title (Detections) Rule name, else alert reason Alerts with neither are skipped
Severity (CNVM) vulnerability.severity, else CVSS base Recognized label wins; otherwise 9.0+ Critical, 7.0+ High, 4.0+ Medium, above 0 Low
Severity (Posture, Detections) Rule or alert severity label Unrecognized or missing labels become Medium
Description Per type, plus ECS asset lines CVE text and CVSS; rationale, benchmark, impact of remediation; reason, risk score, workflow status
Mitigation Fixed version, rule remediation, or triage note CNVM says when no fix is published; detections get a triage instruction
Component Name / Version Package (CNVM) or benchmark (Posture) Not set for detections
CVSS v3 Score vulnerability.score.base CNVM, v3 scores only; v2 scores stay in the description
Vulnerability IDs vulnerability.id CNVM only
Vuln ID from Tool CVE, rule ID, or rule uuid Posture falls back to benchmark rule number
Unique ID from Tool Document _id Detections fall back to alert uuid
Endpoint Host, else resource or pod name Values that are not valid hosts are skipped
Dates @timestamp, published_date Publish date for CNVM
Tags Type, provider, region, cluster, rule tags Detections add event categories
Finding type Static, or neither for detections Detections are observed activity
Deduplication Unique ID, then hashcode CNVM: title, severity, component name. Posture and Detections: title, severity, Vuln ID from Tool

Use Cases

For cloud workload vulnerabilities: A platform team imports CNVM findings into an Asset per cloud account. Each CVE names the package, version, and workload, and the mitigation names the fixed version so the owning team knows which image to rebuild.

For posture and compliance: Failed CIS benchmark rules from posture management become findings with Elastic's remediation text and the documented impact of the fix, so teams can plan changes and auditors can see when each rule passed again.

For detection triage: A security operations team imports detection alerts into a separate Engagement. Repeated firings of the same rule group by rule uuid, and Elastic's workflow status appears in the description while triage happens in DefectDojo.

From a restricted cluster: An organization that cannot grant outside access to Elasticsearch saves search responses internally and imports them. If the connector is approved later, document IDs keep the two sources aligned.

Operational Tips

  • Import the same export three times, once per scan type, when you want all three data types. Each parser skips documents that belong to the others.
  • Keep document _id values in your exports. Without them, identity falls back to asset, CVE, and package or rule, which is less stable.
  • Put detections in their own Engagement. They describe activity, not defects, and should not count toward remediation metrics.
  • The Elastic workflow status for an alert is not mapped onto the finding's status. Close detections in DefectDojo when the investigation is done.
  • Scope the connector's API key read-only to the security indices rather than using a broad user account.
  • Use Minimum Severity on the connector or minimum_severity on import if Info-level CNVM entries would bury actionable CVEs.