firmwalker Integration with DefectDojo
firmwalker Integration with DefectDojo
firmwalker is an open source Bash script, published on GitHub as craigz28/firmwalker, that searches an extracted firmware filesystem for files and strings worth a closer look. It checks for password and shadow files, Unix MD5 password hashes, SSL and SSH material, database and configuration files, shell scripts, web servers, notable binaries, and patterns such as IP addresses, URLs, and email addresses inside files. It writes its results to a plain text report, which DefectDojo imports.
firmwalker Integration with DefectDojo
When we take apart a device image, firmwalker is one of the first things we run on the extracted filesystem, and DefectDojo is where we keep what it found. The text report is a good starting map but a poor record: it has no notion of owner, status, or which build it came from. Imported into DefectDojo, each hit becomes a Finding with a file path, grouped under the Asset for that device, so reviewers can mark what is expected in this image, escalate what isn't, and compare the next firmware drop against this one.
Why firmwalker Matters
Firmware ships an entire filesystem, and the risky parts are usually leftovers: a private key from the build system, a default account in a shadow file, a debug script nobody removed.
- It covers a broad checklist of file names and content patterns in one pass, which is hard to replicate by hand on every image.
- It works on any filesystem you can extract, regardless of the device vendor or architecture.
- It reports paths, so a reviewer can go straight to the file in the extracted tree.
- It is honest about what it does. It shows where to look, and leaves the judgement to the reviewer.
Advantages of This Integration
Running firmwalker output through DefectDojo gives that judgement a place to live:
- One Finding per observation. Each section-and-hit pair becomes a Finding. A file matched by several overlapping patterns within one section is a single Finding that lists every pattern, so firmwalker's repeated searches don't turn into noise.
- File paths where they exist. Hits that look like paths populate the File Path field. Values found inside files (addresses, URLs, emails) are kept in the description instead of being forced into a path.
- Clean runs stay clean. The parser skips the Firmware Directory section and the
etc/ssldirectory listing, so a clean image doesn't import as one Finding and listing timestamps don't create churn. - Triage that carries forward. Expected files can be marked false positive or risk-accepted, and deduplication keeps those decisions attached when the next build is scanned.
- Firmware next to everything else. firmwalker Findings sit alongside binary analysis, SCA, and pentest results for the same device Asset, under the same SLA and reporting rules.
How This Integration Works
DefectDojo imports firmwalker results with the Firmwalker Scan scan type.
1. Extract the firmware and run firmwalker. Point the script at the root of the extracted filesystem and give it a report file name:
./firmwalker.sh /path/to/extracted/firmware firmwalker.txt
2. Import the text report. In the UI, open the Engagement, choose Import Scan Results, select Firmwalker Scan, and upload firmwalker.txt. For automation, use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Firmwalker Scan"
-F "file=@firmwalker.txt"
-F "product_name=edge-gateway"
-F "engagement_name=Firmware 2.3.1"
-F "auto_create_context=true"
DefectDojo Pro users can run the same step with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Firmwalker Scan"
--report-path "./firmwalker.txt"
--product-name "edge-gateway"
--engagement-name "Firmware 2.3.1"
--auto-create-context
3. Reimport for each new build. Sending the next build's report to /api/v2/reimport-scan/ against the same Test mitigates hits that disappeared and adds new ones.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in firmwalker Report | Notes |
|---|---|---|
| Title | Hit and section name | For example /etc/shadow (password files); the "Search for" prefix is removed |
| Severity | None | Always Info; firmwalker reports where to look, not what is wrong |
| File Path | The hit, when it starts with / |
Not set for addresses, URLs, and emails |
| Description | Section, path or value | States which search found it |
| Description | Matched text | For grep-style hits, the text after the first colon |
| Description | Patterns that matched | Every subsection pattern that matched the same hit |
| Finding type | Static | firmwalker reads an extracted image, not a running device |
| Deduplication | Hash code | Title, CWE, line, file path, description |
firmwalker's own output is passed through as written. Its file searches print paths relative to the firmware root, while its Unix-MD5 hash section prints the absolute path it was given, so the same file can appear with two different path styles.
Use Cases
Reviewing a new device before deployment: A security team receives firmware for an industrial gateway, extracts it, and runs firmwalker. The import gives them a reviewable list of credential files, keys, and scripts, each with a path, and they raise the severity of the ones that shouldn't be in a production image.
Comparing firmware releases: A product team reimports each new build into the same Test. When a private key or debug script appears in a release that didn't have it before, it shows up as a new Finding instead of being buried in a long text file.
Supporting a hardware penetration test: A tester imports firmwalker results into the client's Engagement alongside manual findings, so the client sees exactly which files were flagged and can assign each to the firmware owner.
Operational Tips
- Every Finding imports at Info. Agree on escalation rules for the sections that usually matter (private keys, shadow files with hashes, SSH host keys) and raise severity during triage.
- Restrict access to these Findings. Hits from the hash and pattern searches include the matched text, which can include password hashes or other sensitive strings from the image.
- Keep the extraction step consistent between builds. Because the description and file path are part of the hash, a different extraction root or path style produces new Findings for unchanged files.
- Use one Test per device model and reimport each build into it, tagging imports with the firmware version (for example
tags=fw-2.3.1). - Mark files that are expected in your image (a public CA bundle, a standard init script) as false positives once, so reviewers can focus on what changed.
- Pair firmwalker with a binary or SCA tool for the same image. firmwalker finds files of interest, not vulnerable component versions.