All integrations

Gobuster Integration with DefectDojo

Gobuster Integration with DefectDojo

Gobuster is an open source brute-forcing tool written in Go, created and maintained by OJ Reeves. Given a wordlist, it enumerates web paths, DNS subdomains, virtual hosts, and several other targets, depending on the mode. Its dir mode requests each wordlist entry against a web server and prints one line per path that exists, with the HTTP status, the response size, and any redirect target. DefectDojo imports the plain text output file that dir mode writes.

Gobuster Integration with DefectDojo

Gobuster is our quick check for what a web server will hand out if you ask for it by name, and DefectDojo is how we keep that list from being thrown away after each run. Every discovered path becomes a Finding with its status and size, every redirect to an absolute URL gives us an endpoint, and triage decisions stick on the next run because DefectDojo deduplicates on the title and endpoint. When a deployment quietly exposes a new directory, it shows up as a new Finding rather than a line buried in a terminal log.

Why Gobuster Matters

Crawlers only find what is linked. The paths that cause trouble are usually the ones nobody linked: an admin panel, a backup archive, a staging directory left behind.

  • Gobuster is a single binary with no runtime dependencies, which makes it easy to drop into a pipeline or a pentest toolkit.
  • It is fast and concurrent, so large wordlists against a single host finish in a reasonable time.
  • Its output is simple and predictable, which makes it easy to review and easy to parse.
  • A raw output file has no memory. Without somewhere to put the results, nobody knows whether /backup is new this week or has been reachable for months.

Advantages of This Integration

What we get from importing Gobuster output into DefectDojo:

  • Deduplication across reruns. The Gobuster Scan type uses the hash code algorithm on title and endpoints. Response sizes are kept in the description, which is deliberately left out of the hash, so an unchanged site doesn't produce new Findings each run.
  • Clean input, even from a noisy run. The parser skips Gobuster's banner and progress lines if they end up in the file, and collapses duplicate wordlist entries into a single Finding.
  • A lifecycle for exposed paths. Reimporting into the same Test mitigates paths that stopped responding, adds new ones, and reactivates any that return after a deployment.
  • Triage with history. Paths that matter get a raised severity, an owner, notes, or a Jira ticket. Paths that are expected get marked false positive once, and that decision carries forward.
  • Context next to other findings. Discovered paths sit on the same Asset as DAST and pentest results, so a scanner finding on /admin and the Gobuster hit that found it are in one place.

How This Integration Works

DefectDojo imports Gobuster results with the Gobuster Scan scan type. Only dir mode output is parsed.

1. Run Gobuster in dir mode with an output file. Use -q to keep the banner and progress footer out of the file:

gobuster dir -u https://target.example.com -w wordlist.txt -q -o gobuster.txt

Gobuster has no JSON output for dir mode, so the printed line is the format DefectDojo reads. A hit looks like admin (Status: 301) [Size: 169] [--> https://target.example.com/admin/].

2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select Gobuster Scan, and upload gobuster.txt. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Gobuster Scan" 
  -F "file=@gobuster.txt" 
  -F "product_name=marketing-site" 
  -F "engagement_name=Content Discovery" 
  -F "test_title=target.example.com" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Gobuster Scan" 
  --report-path "./gobuster.txt" 
  --product-name "marketing-site" 
  --engagement-name "Content Discovery" 
  --auto-create-context

3. Reimport on a schedule. Send later output for the same host to /api/v2/reimport-scan/ against the same Test so each path's open and closed history stays together.

Data Granularity: What Gets Imported

DefectDojo Field Source in Gobuster Output Notes
Title Status and path Formatted as HTTP 301: /admin; a leading slash is added
Severity None Always Info; Gobuster reports paths that exist, not what is wrong
Endpoint Redirect target Only when the hit redirects to an absolute URL
Description Path and status Every Finding
Description [Size: n] Response size at scan time
Description [--> target] Redirect destination
Description Fixed note States that Gobuster's output does not record the scanned host
Finding type Dynamic Gobuster probes a running service
Deduplication Hash code Title and endpoints

Lines from Gobuster's dns and vhost modes, which print Found: name, are not imported. Those modes produce subdomain and virtual host inventory rather than findings.

Use Cases

Pre-launch checks: Before a new site goes live, the team runs Gobuster against staging with a wordlist of common admin, backup, and configuration paths. Anything that responds lands in DefectDojo for a security engineer to escalate or dismiss.

Recurring external exposure checks: A security team runs Gobuster weekly against its public web hosts, reimporting into one Test per host. New Findings after a release are often the first sign that a debug route or old directory shipped to production.

Penetration test evidence: A tester imports Gobuster output into the client's Engagement next to manual findings. The client gets a reviewable list of discovered paths attached to the right Asset instead of a pasted log.

Confirming cleanup: A team removing legacy content reimports after each change. Paths that stop responding are mitigated, which documents the cleanup without anyone maintaining a spreadsheet.

Operational Tips

  • Keep one host per Test, and name the Test after the host (for example with test_title). Gobuster's output doesn't record the scanned host, so non-redirecting hits have no endpoint, and the Test name is what tells readers where the path lives.
  • Don't mix hosts in one Asset without separate Tests or Engagements. Hits without an endpoint deduplicate on title alone, so /admin on two hosts can look like the same Finding.
  • Always run with -q. The parser skips banner and progress lines it recognizes, but a clean file avoids surprises.
  • Every Finding is Info. Decide which path patterns your team escalates (version control directories, backups, admin interfaces) and raise severity during triage.
  • Filter soft-404 responses in Gobuster before importing. A server that answers every request with the same status will otherwise produce one Finding per wordlist entry.
  • Don't use minimum_severity above Info for this scan type. Since every Finding is Info, it would drop the entire report.