Holm Security Integration with DefectDojo
Holm Security Integration with DefectDojo
Holm Security is a European vulnerability management vendor whose platform covers system and network scanning, web application scanning, cloud security posture, API security, and phishing simulation. Its network scanning assesses servers, network equipment, cloud infrastructure, and other systems for known vulnerabilities, while its web application scanning tests running applications for issues such as the OWASP Top 10. Findings carry a severity, CVE references, CVSS scores, a solution, and detection details, and are available through Holm's REST API as JSON.
Holm Security Integration with DefectDojo
Holm Security covers both our network ranges and our public web applications, and we bring both into DefectDojo through one integration. Network findings land on the Asset that owns the host, web findings land on the application's Asset, and both sit next to the SAST and dependency results for the same systems. DefectDojo gives each one an owner and an SLA, and keeps track of what changed between scans so nobody has to compare exports by hand.
Why Holm Security Matters
Most organizations need both infrastructure and web application scanning, and running them in one platform keeps coverage consistent.
- Network scanning finds missing patches, weak configurations, and exposed services across servers and network equipment.
- Web application scanning exercises running applications, which catches issues static analysis cannot.
- Findings include Holm's own solution text, impact statement, and vendor reference, which gives engineers what they need to act.
- Holm reports the same weakness once per host and per listening port, so a second exposed service on the same machine is visible.
- Without a central platform, those results stay separate from application security findings for the same Assets.
Advantages of This Integration
What DefectDojo adds to Holm Security results:
- One scan type for file and API. The parser and the DefectDojo Pro connector both report
Holm Security Scan, so uploaded exports and connector syncs deduplicate against each other. - Per-host, per-port identity. The unique ID is
holm-<hid>plus the asset and the port when present, so the same weakness on two ports stays two findings. - Static and dynamic kept apart. Web class findings are marked dynamic and tagged
web-scan, network class findings are marked static and taggednet-scan, so you can report on each separately. - Fixed means closed. Findings with a Holm status of fixed, closed, or resolved import as inactive.
- Workflow on top. SLAs per severity, assignment, risk acceptance, false positive marking, and Jira pushes apply to Holm findings like any others.
How This Integration Works
All methods use the scan type Holm Security Scan.
Option 1: Import a JSON export. The parser reads Holm's paged vulnerabilities response, with rows under results (or vulnerabilities, or a bare array). Because the scan class belongs to the scan rather than the row, add a top-level "class" (or "asset_class") of web or net to the export. Without it, findings are imported as static with no class tag.
In the UI, open the Engagement, choose Import Scan Results, select Holm Security Scan, and upload the file. To automate it in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Holm Security Scan"
-F "file=@holm-web.json"
-F "product_name=customer-portal"
-F "engagement_name=Holm Web Scans"
-F "auto_create_context=true"
Option 2: Universal Importer (DefectDojo Pro).
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Holm Security Scan"
--report-path "./holm-net.json"
--product-name "datacenter-east"
--engagement-name "Holm Network Scans"
--auto-create-context
Option 3: The Holm Security connector (DefectDojo Pro). One connector covers both the network and web asset classes. Create an API token in Holm under Security Center, then API. In the connector form:
- Enter your region's API host in Location, for example
https://se-api.holmsecurity.comfor the Swedish region. The host must match the region your account is in. - Enter the token in API Token.
- Optionally set a Minimum Severity.
DefectDojo creates a Record for each Holm asset, whether a network or web scan found it, and you map each Record to a DefectDojo Asset.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Holm Export | Notes |
|---|---|---|
| Title | vulnerability_name |
Falls back to the first CVE, then Holm Security finding <hid> |
| Severity | severity name, else severity_level |
Names map directly; levels 4 Critical, 3 High, 2 Medium, 1 Low, 0 Info |
| Description | Detection information, Holm ID, CVEs, URL, port and protocol, status | One labeled line each |
| Mitigation | solution |
Holm's solution text |
| Impact | vulnerability_impact |
Holm's impact statement |
| References | vendor_reference |
|
| CVSS v3 Score | cvss_base, else cvss_score |
|
| Vulnerability IDs | cve_ids |
|
| Endpoint | url |
Host, port, path, and query; not set when there is no URL |
| Date | last_detected, else first_detected |
|
| Active | status |
Fixed, closed, or resolved import inactive |
| Static / Dynamic | Top-level class | web dynamic, net or absent static |
| Tags | Top-level class | web-scan or net-scan |
| Unique ID / Vuln ID from Tool | holm-<hid>[-<asset>][-<port>] / hid |
|
| Deduplication | Unique ID or hashcode | Title, severity, endpoints, vuln ID from tool |
The separately reported detected_port is not added to the endpoint. It appears in the unique ID and the description.
Use Cases
Splitting infrastructure and application work: A security team imports network exports into Assets for each data center or VPC and web exports into each application's Asset. Infrastructure teams patch hosts while application teams work their web findings, and both are measured against the same SLAs.
Patch cycle verification: After a monthly patch window, the next connector sync or reimport marks fixed findings inactive, so the team can see what the window actually closed.
Before the connector is approved: A team waiting on approval to share a Holm API token with another system imports JSON exports with the class set. When the connector is enabled later, its findings deduplicate against the uploaded ones because both use the Holm Security Scan type and the same unique IDs.
Reporting by scan type: Because findings are tagged web-scan or net-scan, a security lead can report open web application risk separately from infrastructure risk for the same Asset.
Operational Tips
- Always set the top-level class on file exports. A web export imported without it is marked static, which skews dynamic versus static reporting.
- Import network and web exports as separate Tests so reimports of one class do not mitigate findings from the other.
- Network findings often have no URL, so they have no endpoint. The host details stay in the description, and dedupe still works on the unique ID.
- Severity names take precedence over the numeric level. If an export has an unfamiliar name, the level is used, so check both when results look off.
- Use
minimum_severityon import, or Minimum Severity on the connector, to keep informational detections out of team queues. - Tag imports with the scan schedule or network zone so findings can be filtered by where they came from.