All integrations

Holm Security Integration with DefectDojo

Holm Security Integration with DefectDojo

Holm Security is a European vulnerability management vendor whose platform covers system and network scanning, web application scanning, cloud security posture, API security, and phishing simulation. Its network scanning assesses servers, network equipment, cloud infrastructure, and other systems for known vulnerabilities, while its web application scanning tests running applications for issues such as the OWASP Top 10. Findings carry a severity, CVE references, CVSS scores, a solution, and detection details, and are available through Holm's REST API as JSON.

Holm Security Integration with DefectDojo

Holm Security covers both our network ranges and our public web applications, and we bring both into DefectDojo through one integration. Network findings land on the Asset that owns the host, web findings land on the application's Asset, and both sit next to the SAST and dependency results for the same systems. DefectDojo gives each one an owner and an SLA, and keeps track of what changed between scans so nobody has to compare exports by hand.

Why Holm Security Matters

Most organizations need both infrastructure and web application scanning, and running them in one platform keeps coverage consistent.

  • Network scanning finds missing patches, weak configurations, and exposed services across servers and network equipment.
  • Web application scanning exercises running applications, which catches issues static analysis cannot.
  • Findings include Holm's own solution text, impact statement, and vendor reference, which gives engineers what they need to act.
  • Holm reports the same weakness once per host and per listening port, so a second exposed service on the same machine is visible.
  • Without a central platform, those results stay separate from application security findings for the same Assets.

Advantages of This Integration

What DefectDojo adds to Holm Security results:

  • One scan type for file and API. The parser and the DefectDojo Pro connector both report Holm Security Scan, so uploaded exports and connector syncs deduplicate against each other.
  • Per-host, per-port identity. The unique ID is holm-<hid> plus the asset and the port when present, so the same weakness on two ports stays two findings.
  • Static and dynamic kept apart. Web class findings are marked dynamic and tagged web-scan, network class findings are marked static and tagged net-scan, so you can report on each separately.
  • Fixed means closed. Findings with a Holm status of fixed, closed, or resolved import as inactive.
  • Workflow on top. SLAs per severity, assignment, risk acceptance, false positive marking, and Jira pushes apply to Holm findings like any others.

How This Integration Works

All methods use the scan type Holm Security Scan.

Option 1: Import a JSON export. The parser reads Holm's paged vulnerabilities response, with rows under results (or vulnerabilities, or a bare array). Because the scan class belongs to the scan rather than the row, add a top-level "class" (or "asset_class") of web or net to the export. Without it, findings are imported as static with no class tag.

In the UI, open the Engagement, choose Import Scan Results, select Holm Security Scan, and upload the file. To automate it in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Holm Security Scan" 
  -F "file=@holm-web.json" 
  -F "product_name=customer-portal" 
  -F "engagement_name=Holm Web Scans" 
  -F "auto_create_context=true"

Option 2: Universal Importer (DefectDojo Pro).

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Holm Security Scan" 
  --report-path "./holm-net.json" 
  --product-name "datacenter-east" 
  --engagement-name "Holm Network Scans" 
  --auto-create-context

Option 3: The Holm Security connector (DefectDojo Pro). One connector covers both the network and web asset classes. Create an API token in Holm under Security Center, then API. In the connector form:

  1. Enter your region's API host in Location, for example https://se-api.holmsecurity.com for the Swedish region. The host must match the region your account is in.
  2. Enter the token in API Token.
  3. Optionally set a Minimum Severity.

DefectDojo creates a Record for each Holm asset, whether a network or web scan found it, and you map each Record to a DefectDojo Asset.

Data Granularity: What Gets Imported

DefectDojo Field Source in Holm Export Notes
Title vulnerability_name Falls back to the first CVE, then Holm Security finding <hid>
Severity severity name, else severity_level Names map directly; levels 4 Critical, 3 High, 2 Medium, 1 Low, 0 Info
Description Detection information, Holm ID, CVEs, URL, port and protocol, status One labeled line each
Mitigation solution Holm's solution text
Impact vulnerability_impact Holm's impact statement
References vendor_reference
CVSS v3 Score cvss_base, else cvss_score
Vulnerability IDs cve_ids
Endpoint url Host, port, path, and query; not set when there is no URL
Date last_detected, else first_detected
Active status Fixed, closed, or resolved import inactive
Static / Dynamic Top-level class web dynamic, net or absent static
Tags Top-level class web-scan or net-scan
Unique ID / Vuln ID from Tool holm-<hid>[-<asset>][-<port>] / hid
Deduplication Unique ID or hashcode Title, severity, endpoints, vuln ID from tool

The separately reported detected_port is not added to the endpoint. It appears in the unique ID and the description.

Use Cases

Splitting infrastructure and application work: A security team imports network exports into Assets for each data center or VPC and web exports into each application's Asset. Infrastructure teams patch hosts while application teams work their web findings, and both are measured against the same SLAs.

Patch cycle verification: After a monthly patch window, the next connector sync or reimport marks fixed findings inactive, so the team can see what the window actually closed.

Before the connector is approved: A team waiting on approval to share a Holm API token with another system imports JSON exports with the class set. When the connector is enabled later, its findings deduplicate against the uploaded ones because both use the Holm Security Scan type and the same unique IDs.

Reporting by scan type: Because findings are tagged web-scan or net-scan, a security lead can report open web application risk separately from infrastructure risk for the same Asset.

Operational Tips

  • Always set the top-level class on file exports. A web export imported without it is marked static, which skews dynamic versus static reporting.
  • Import network and web exports as separate Tests so reimports of one class do not mitigate findings from the other.
  • Network findings often have no URL, so they have no endpoint. The host details stay in the description, and dedupe still works on the unique ID.
  • Severity names take precedence over the numeric level. If an export has an unfamiliar name, the level is used, so check both when results look off.
  • Use minimum_severity on import, or Minimum Severity on the connector, to keep informational detections out of team queues.
  • Tag imports with the scan schedule or network zone so findings can be filtered by where they came from.