All integrations

Fleet Integration with DefectDojo

Fleet Integration with DefectDojo

Fleet is an open source device management and endpoint visibility platform built on osquery, developed by Fleet Device Management. It inventories the software installed on macOS, Windows, Linux, and other hosts, enriches that inventory with vulnerability data such as CVSS scores, EPSS probabilities, and CISA Known Exploited Vulnerabilities status, and evaluates policies (osquery queries with a pass or fail result) on every host. Fleet exposes this through its REST API as JSON, and offers a free edition alongside Fleet Premium.

Fleet Integration with DefectDojo

We already had Fleet on our laptops and servers, so we knew which machines ran vulnerable software and which ones failed our baseline policies. What we didn't have was a way to manage that work next to application and cloud findings. Bringing Fleet into DefectDojo gave every host CVE and every failing policy an owner, an SLA, and a status that updates when the next sync shows the machine has been patched. Because DefectDojo keeps one Finding per host, a CVE fixed on 300 machines but still present on four stays visibly open on those four.

Why Fleet Matters

Endpoint and server vulnerabilities often live outside the AppSec program because they come from IT tooling. Fleet closes part of that gap.

  • osquery reads installed software and system state directly from each host, rather than inferring it from the network.
  • Vulnerability data comes with context: CVSS, EPSS, the fixed version when known, and whether the CVE is on CISA's KEV list.
  • Policies express compliance checks (disk encryption on, a firewall enabled, a minimum OS version) as queries that return pass or fail per host.
  • The same platform covers several operating systems, so one source feeds both vulnerability and configuration posture.

Advantages of This Integration

What we gained by sending Fleet data through DefectDojo:

  • Two finding types, kept separate. Software CVEs import as Fleet:Vulnerabilities - Connectors Import and failing policies as Fleet:Policies - Connectors Import, each with its own deduplication keys, mirroring how Fleet models them.
  • Per-host accuracy. A vulnerability's identity is host, software, version, and CVE; a policy's is host and policy. Remediating one machine never hides another that is still exposed.
  • Fixes in the Finding. CVE Findings say which version resolves the issue when Fleet reports one. Policy Findings carry the policy's own resolution text as the mitigation and include the policy query, so a reviewer sees exactly what was checked.
  • Exploit context for prioritization. CVEs on the KEV list are tagged cisa-known-exploited and flagged in the description, and EPSS appears alongside CVSS.
  • One lifecycle. SLAs, assignment, risk acceptance, Jira tickets, and reporting apply to host findings the same way they do to application findings.

How This Integration Works

Option 1: API Connector (DefectDojo Pro). In the DefectDojo Pro UI, configure the Fleet connector with your Fleet server URL in the Location field and a Fleet API token (from Account Settings, Get API token) in the API Token field. The connector only needs read access, and on Fleet Premium you can issue a dedicated API-only user for it. Optional toggles let you skip software vulnerabilities or skip compliance policies if you only want one kind of finding; both are imported by default. You can also set a Minimum Severity. DefectDojo creates a Record for each Fleet team, and hosts that belong to no team go to a synthetic "No team" Record. Teams are a Fleet Premium feature, so on a free Fleet deployment every host lands in that single Record, which is expected.

Option 2: File import. Where DefectDojo cannot reach Fleet's API, save a Fleet host response as JSON. The parsers accept a host list ({"hosts": [...]}), a single host ({"host": {...}}), a bare array of hosts, or a bare host object. For vulnerabilities, export host detail that includes software and vulnerability data; Fleet's single-host endpoint returns it, while the summary host list does not. Import the same file once per scan type if you want both CVEs and policies:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Fleet:Vulnerabilities - Connectors Import" 
  -F "file=@fleet-hosts.json" 
  -F "product_name=corporate-endpoints" 
  -F "engagement_name=Fleet" 
  -F "auto_create_context=true"
universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Fleet:Policies - Connectors Import" 
  --report-path "./fleet-hosts.json" 
  --product-name "corporate-endpoints" 
  --engagement-name "Fleet" 
  --auto-create-context

UI Import works the same way: open the Engagement, choose Import Scan Results, and pick either Fleet scan type.

Data Granularity: What Gets Imported

DefectDojo Field Source in Fleet Data Notes
Title (CVE) CVE, software, version, host For example CVE-ID - openssl 3.0.2 on host-01
Title (policy) Policy name Policies with no name are skipped
Severity (CVE) cvss_score 9.0+ Critical, 7.0+ High, 4.0+ Medium, above 0 Low, 0 Info, unscored Medium
Severity (policy) critical flag High if critical, otherwise Medium
Description CVE summary or policy description Adds software, host, OS, CPE, CVSS, EPSS, KEV; policies add the SQL query
Mitigation resolved_in_version or policy resolution Generic upgrade advice when no fixed version is known
Component Software name and version Vulnerabilities only
Vulnerability ID cve Vulnerabilities only
CVSS v3 score / Publish date cvss_score / cve_published Vulnerabilities only
Endpoint Display name, computer name, hostname, or IP The host itself
Tags Platform, KEV, critical policy Sorted and deduplicated
Unique ID Host, software, version, CVE / host and policy One Finding per host
Finding type Static Inventory and query results, nothing exercised
Deduplication Unique ID from tool, then hash code CVEs: title, severity, component; policies: title, severity, vuln ID

Only failing policies are imported. A passing policy, or one that has not run on the host yet, produces nothing.

Use Cases

Endpoint patch tracking: IT and security share one view of which laptops still run a vulnerable browser or VPN client. SLAs by severity apply per host, and each sync closes Findings on machines that have been updated.

Compliance evidence: Failing policies such as disk encryption or OS version checks become Findings with the policy query attached. An auditor can see which hosts failed, when, and when they were fixed.

KEV-driven response: When a CVE is added to CISA's KEV list, filtering on the cisa-known-exploited tag shows every affected host, already grouped by Fleet team.

Air-gapped server estates: A team with no outbound access exports host detail from Fleet and imports the file. Because the scan types match the connector, switching to the connector later doesn't double the findings.

Operational Tips

  • Use Fleet teams if you have Fleet Premium. They become separate Records, which is what lets you route findings to the right owners.
  • Remember that unscored CVEs import as Medium, not Info. That is deliberate (not scored yet is an unknown), but expect some Medium findings to move once NVD scores arrive.
  • KEV status does not raise severity. If your policy treats KEV CVEs as urgent, build an SLA or filter around the tag.
  • Turn off the policy import on the connector if compliance is managed elsewhere, rather than closing policy findings by hand.
  • For file imports, export host detail with software included. The summary host list has no vulnerability data and imports zero CVE Findings.
  • Hosts whose names DefectDojo can't accept as an endpoint (spaces, paths) are still described in the Finding but get no endpoint, so keep Fleet display names simple.