Halo Security Integration with DefectDojo
Halo Security Integration with DefectDojo
Halo Security is an external security platform that combines attack surface management, external vulnerability scanning, and manual penetration testing, with PCI ASV scanning and dark web monitoring among its services. It monitors an organization's internet-facing targets, such as hosts, IP addresses, and web applications, and reports issues per target with a severity level, a status, and details such as category, CVEs, and whether the issue affects PCI compliance. Issues are available through the Halo Security API as JSON.
Halo Security Integration with DefectDojo
Halo Security watches our perimeter, and DefectDojo is where the fixes get assigned and measured. We bring Halo Security issues into DefectDojo so each exposed host's problems sit on the Asset that owns that host, next to the internal scan and application findings for the same system. Status decisions made in Halo come across intact: a confirmed issue is verified, a fixed one is mitigated, and an acknowledged false positive stays out of the open count.
Why Halo Security Matters
The internet-facing perimeter is where opportunistic attackers start, and it drifts every time a team adds a host or opens a port.
- It continuously monitors targets from the outside, which shows what is actually reachable rather than what the inventory says.
- Issues are reported per target, so the same weakness on two hosts is two separate pieces of work with their own status.
- PCI-relevant issues are flagged, which helps teams that need to keep ASV scans clean.
- Halo's status values (new, investigating, confirmed, fixing, fixed, acknowledged) record triage that should not be redone elsewhere.
- Without a central platform, perimeter issues live apart from the internal and application findings for the same services.
Advantages of This Integration
What changes when Halo Security issues run through DefectDojo:
- One finding per issue per host. The unique ID is
<issue id>:<target id>, so an issue affecting two hosts becomes two findings that can be closed independently. - Status carries over.
confirmedandfixingimport as active and verified,fixedas mitigated,ack_false_positiveas a false positive, andack_acceptable_riskas risk accepted. - Matched file and connector findings. The parser and the DefectDojo Pro connector share the scan type
Halo Security - Connectors Import, so an export uploaded today and a connector sync later deduplicate against each other. - PCI tagging. Issues Halo flags as affecting PCI compliance get a
pcitag and a description line, which makes PCI scope easy to filter. - The rest of the platform. SLAs per severity, assignment, notes, Jira pushes, and metrics apply to perimeter findings like any others.
How This Integration Works
All three methods use the scan type Halo Security - Connectors Import.
Option 1: Import a JSON export. The parser reads Halo's issue-list response with rows under list (a bare array also works). Halo splits each issue across two API calls: the list row has the issue, target, and status, while the description, category, CVEs, and PCI flag only exist on the per-issue detail. Include the details in the export, either as a top-level details object keyed by issue ID, a top-level details array, or a detail object on each row. Without them, findings import with no description.
Upload the file in the UI (Engagement, Import Scan Results, Halo Security - Connectors Import), or use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Halo Security - Connectors Import"
-F "file=@halo-issues.json"
-F "product_name=public-web"
-F "engagement_name=External Monitoring"
-F "auto_create_context=true"
Option 2: Universal Importer (DefectDojo Pro).
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Halo Security - Connectors Import"
--report-path "./halo-issues.json"
--product-name "public-web"
--engagement-name "External Monitoring"
--auto-create-context
Option 3: The Halo Security connector (DefectDojo Pro). The connector needs a single Halo Security API key, with no secret pair or OAuth flow. Enter https://api.halosecurity.com/api/v1 in Location, the key in Secret, and optionally a Minimum Severity. DefectDojo creates a Record for each monitored target, carrying the account's active issues for that target, enriched from Halo's issue catalogue. Map each Record to the DefectDojo Asset that owns the host.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Halo Security Export | Notes |
|---|---|---|
| Title | Issue name |
Falls back to the detail's name, then Halo Security issue <id> |
| Severity | Integer severity |
5 Critical, 4 High, 3 Medium, 2 Low, 1 or 0 Info; row value first, detail as fallback |
| Description | Detail description, target, status, category, PCI, assignee, scans since found | Assignee omitted when Halo says Nobody |
| Status flags | Row status |
Active, verified, mitigated, false positive, or risk accepted per status |
| Endpoint | Target address | Host, port, and scheme when usable as a host |
| Vulnerability IDs | Detail cve_ids |
CVE identifiers, deduplicated |
| Tags | Category, pci, status |
PCI tag only for PCI-flagged issues |
| Date | Import date | Halo's list response has no discovery date |
| Unique ID / Vuln ID from Tool | <issue id>:<target id> / issue ID |
|
| Finding type | Dynamic | Halo probes live hosts |
| Deduplication | Unique ID or hashcode | Title, severity, endpoints |
Use Cases
Perimeter remediation by owner: A security team maps each Halo target to the Asset owned by the team that runs it. A web team sees only the issues on the hosts it runs, and each one counts against the SLA for its severity.
PCI scope tracking: Filtering on the pci tag gives a list of open perimeter issues that affect PCI compliance, with owners and due dates, ahead of the next ASV scan.
When credentials can't leave the network yet: A team blocked on an API key approval imports exported issues and details. Once the connector is approved, its findings deduplicate against the uploaded ones.
Verifying fixes: After a patch window, the next sync or reimport brings Halo's fixed status across, so closed findings in DefectDojo reflect Halo's own confirmation rather than a ticket being marked done.
Operational Tips
- Always include issue details in file exports. Rows without them produce findings with a title and status but no prose, category, or CVEs.
- Remember the severity scale runs upward: 5 is Critical. If you transform exports with your own script, do not treat it as a priority number.
- New and investigating issues import as active but not verified. Filter on verified findings if you only want confirmed work in a sprint.
- Findings are dated with the import date because Halo's list response has no discovery date. Use the first import as the effective discovery point for SLA tracking.
- The dedupe hash includes endpoints. A target that cannot be parsed as a host is not recorded as an endpoint, so check the description for those cases.
- Reimport each export into the same Test so issues that Halo stops reporting are mitigated.