InsightCloudSec Integration with DefectDojo
InsightCloudSec Integration with DefectDojo
InsightCloudSec is Rapid7's cloud security posture product, formerly known as DivvyCloud. It connects to public cloud accounts such as AWS, Microsoft Azure, and Google Cloud, inventories their resources, and evaluates them against checks it calls insights, which flag misconfigurations like publicly exposed storage, permissive network rules, or missing encryption. Results live in the InsightCloudSec console and its API, which is what the DefectDojo Pro connector reads.
InsightCloudSec Integration with DefectDojo
We connected InsightCloudSec to DefectDojo Pro because cloud posture findings were the one category of risk that never showed up in the same place as everything else. The InsightCloudSec connector pulls failing insights from the Rapid7 API on a schedule and files them under a Record for each onboarded cloud account. Once those Records map to DefectDojo Assets, a misconfigured bucket sits next to the container CVEs and code findings for the same team, with an SLA clock, an owner, and a status history we can report on. Nobody exports a CSV or runs an import script.
Why InsightCloudSec Matters
Cloud configuration changes constantly, and the riskiest changes are often made by people who are not on the security team.
- It evaluates the live configuration of cloud resources, so it catches drift introduced through a console click or an emergency change that bypassed infrastructure as code review.
- Its insights are written against specific resource types, so each failure points to a concrete resource rather than a general recommendation.
- It covers multiple cloud providers from one place, which matters when different business units chose different clouds.
- On its own, a list of failing insights does not tell you who owns the fix, how long it has been open, or whether last month's failures were ever resolved. That tracking is what DefectDojo adds.
A note before you start: InsightCloudSec is a separate Rapid7 product from InsightVM and InsightAppSec, and each has its own DefectDojo connector. Pick the InsightCloudSec tile for cloud posture data.
Advantages of This Integration
What changes once InsightCloudSec findings flow through DefectDojo Pro:
- No manual export step. The connector runs Discover and Sync on a schedule you choose (every 6, 12, or 24 hours), so posture findings arrive without anyone exporting reports.
- One Record per cloud account. Each onboarded cloud account becomes a Record that you map to a DefectDojo Asset, which lines findings up with the team that owns the account.
- Per-resource findings. The connector creates one finding for each insight and failing resource pair, so a single policy failing on 40 resources produces 40 findings that can be assigned, accepted, or closed individually.
- Lifecycle on every sync. Each Sync compares the latest data with what is already in DefectDojo, adds new findings, and marks findings that no longer appear as inactive. A fixed resource drops out without anyone closing it by hand.
- Shared SLAs and reporting. Cloud posture findings fall under the same severity-based SLA rules, risk acceptance workflow, and metrics as findings from your scanners and pentests.
- Downstream ticketing. Findings on a mapped Asset can be pushed to your issue tracker through DefectDojo Pro's Downstream Connectors or Jira integration, so cloud owners get tickets in the tools they already watch.
How This Integration Works
Connectors are a DefectDojo Pro feature. Community Edition users can still import scan files from many tools, but there is no InsightCloudSec file parser, so this connector is the supported path.
1. Create an API key in InsightCloudSec. Generate a key from the API Keys page in your InsightCloudSec user profile. A dedicated service account for DefectDojo makes it easier to tell connector activity apart from people. DefectDojo never writes the key to its logs.
2. Add the connector in DefectDojo Pro. In the Pro UI, open Connect > Upstream, find InsightCloudSec under Available Connectors, and click Add Configuration. Fill in:
- Location:
https://cloudsec.insight.rapid7.comfor the Rapid7-hosted service. Self-hosted InsightCloudSec deployments use their own host. - API Key: the key from step 1.
- Minimum Severity (optional): a floor below which findings are not imported.
- Label: a name that tells this configuration apart, for example by environment.
Then set the Discovery and Synchronization schedules, choose whether to enable Auto-Mapping, and submit. DefectDojo checks what the credentials can see and warns you if the account reports no data.
3. Discover your cloud accounts. The Discover operation creates a Record for each onboarded cloud account. With Auto-Mapping on, each Record is matched to an existing Asset with the same name or a new Asset is created. With it off, Records wait in the Unmapped list until you assign them.
4. Sync findings. For every mapped Record, Sync imports the account's findings into an Engagement named Global Connectors under the mapped Asset, with a separate Test for this connector. Later syncs update that same Test.
Data Granularity: What Gets Imported
The connector documentation describes the structure of what is imported rather than a field-by-field mapping, so the table below sticks to what is documented.
| DefectDojo Object or Field | Source in InsightCloudSec | Notes |
|---|---|---|
| Record | Onboarded cloud account | Mapped to a DefectDojo Asset manually or by Auto-Mapping |
| Finding | Insight and failing resource pair | One finding per resource that fails a given insight |
| Grouping | Cloud account of the failing resource | Findings land under the Record for that account |
| Severity filter | Minimum Severity setting | Findings below the floor are not imported |
| Engagement | Created by DefectDojo | Named Global Connectors, under the mapped Asset |
| Test | Created by DefectDojo | One Test for this connector per Asset, updated on each sync |
| Status changes | Sync comparison | New findings added, absent findings marked inactive |
| Field adjustments | Connector Field Mappings | Rearrange or combine fields the connector sends, per scan type |
If you need a different Title or a composite unique identifier, Connector Field Mappings (under Connect > Field Mappings) can rearrange values the connector already sends. They cannot add data the connector does not send.
Use Cases
Giving cloud owners a queue: A platform team maps each AWS and Azure account Record to the Asset owned by the team that runs it. Each team sees its own failing insights alongside its application findings, with SLA dates, instead of a central security team forwarding screenshots.
Tracking posture over time: Because each Sync marks resolved findings inactive, leadership can see how many posture findings were opened and closed in a quarter per account, using DefectDojo metrics rather than spreadsheets built from exports.
Consolidating a multi-account estate: An organization with dozens of sandbox accounts can leave those Records unmapped or set them to Ignored, and map only production accounts. Discover keeps the full list visible so new accounts are not missed.
Combining with other cloud tools: If you also import cloud findings from another source, both can map to the same Asset. Each connector writes to its own Test inside the Global Connectors Engagement, so the data stays separable.
Operational Tips
- Start with a Minimum Severity of Medium or High if your InsightCloudSec policies are broad, then lower it once teams have worked through the backlog.
- Remember the one-finding-per-resource model. A noisy insight across hundreds of resources will create hundreds of findings, so tune or scope the insight in InsightCloudSec before blaming the import.
- Use Ignored, not Delete, for cloud account Records you never want imported. Deleted Records come back on the next Discover if the account still exists.
- When remapping an account to a different Asset, the default Move option carries existing findings, notes, and risk acceptances with it. Start fresh closes them on the old Asset and imports a new set.
- Turn on the Connector Health Warning notification (under Connections in your notification settings) so a revoked or expired API key is reported instead of silently stopping imports.
- If a sync reports success but imports nothing, check what the API key's user can see in InsightCloudSec. A missing grant on the tool side is the usual cause.