Intruder Integration with DefectDojo
Intruder Integration with DefectDojo
Intruder is a cloud-based vulnerability scanning service from Intruder, a UK company. It scans an organization's targets, such as internet-facing hosts, internal infrastructure, web applications, and cloud environments, and reports issues with a severity, a description, and remediation advice. Intruder separates an issue (the weakness itself) from its occurrences (each target and port where it was found), and records triage by snoozing occurrences with a reason. Issues and occurrences are available through the Intruder REST API as JSON.
Intruder Integration with DefectDojo
We use Intruder to keep scanning our perimeter and infrastructure without running scanners ourselves. What we needed was a place to work those results alongside everything else. Bringing Intruder into DefectDojo turns every occurrence into a Finding on the Asset that owns that target, with its own CVSS score, owner, and SLA. Occurrences our team already snoozed in Intruder as false positives or accepted risks come across in that state, so nobody triages them twice.
Why Intruder Matters
Exposed services and unpatched hosts are still one of the most common ways in, and the set of exposed targets changes all the time.
- Intruder scans on a schedule as a service, so coverage doesn't depend on someone remembering to run a tool.
- It reports each occurrence separately, so one weakness on ten hosts is ten pieces of work, each fixable on its own timeline.
- Occurrence-level CVSS scores reflect that the same weakness can be more serious on one target than another.
- Snooze reasons (false positive, accepted risk, mitigating controls) record triage decisions that should carry forward.
- Without a central platform, these results stay apart from application and cloud findings for the same systems.
Advantages of This Integration
What DefectDojo adds to Intruder results:
- The occurrence is the finding. Each occurrence becomes its own Finding with its target as the endpoint, so work can be assigned per host.
- Triage carries over. A snoozed false positive imports as an inactive false positive. Accepted risk and mitigating controls import as risk accepted. Other snooze reasons import inactive without either flag.
- Matched file and API findings. The parser and the DefectDojo Pro connector share the scan type
Intruder API Import, so uploaded exports and connector syncs deduplicate against each other. - Deduplication with a guard. The hash covers the occurrence ID, title, and severity, so a reused ID with different content is not mistaken for the same finding.
- CVE coverage. Vulnerability IDs come from the occurrence and from any CVE, GHSA, GO, or RHSA identifiers in the issue title or description.
- Standard workflow. SLAs per severity, assignment, notes, Jira pushes, and metrics all apply.
How This Integration Works
All methods use the scan type Intruder API Import.
Option 1: Import a JSON export. The parser reads Intruder's issues response, with rows under results (or issues, or a bare array). Intruder's issue object only links to its occurrences, so the export must include them, either as a top-level occurrences object keyed by issue ID or as an occurrences array nested on each issue. An issue with no occurrences produces no findings.
In the UI, open the Engagement, choose Import Scan Results, select Intruder API Import, and upload the file. To automate it in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Intruder API Import"
-F "file=@intruder-issues.json"
-F "product_name=external-perimeter"
-F "engagement_name=Intruder Scans"
-F "auto_create_context=true"
Option 2: Universal Importer (DefectDojo Pro).
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Intruder API Import"
--report-path "./intruder-issues.json"
--product-name "external-perimeter"
--engagement-name "Intruder Scans"
--auto-create-context
Option 3: The Intruder connector (DefectDojo Pro). The connector pulls the whole account's posture through the Intruder REST API. Create an API access token in Intruder under My account, then API Access Tokens (you need your account password, and the token is shown only once). In the connector form, leave Location as https://api.intruder.io/ and enter the token in Secret. Each Intruder target is discovered as a Record that you map to a DefectDojo Asset, and each occurrence of an issue on that target becomes a Finding.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Intruder Export | Notes |
|---|---|---|
| Title | Issue title |
Shared by every occurrence of the issue |
| Severity | Issue severity |
critical, high, medium, low map directly; anything else Info |
| Description | Target or display address, port, protocol, first seen, exploit likelihood, extra info, issue description | Extra info listed in sorted key order |
| Mitigation | Issue remediation |
|
| CVSS v3 Score | Occurrence cvss_score, else issue |
Occurrence value preferred |
| Vulnerability IDs | Occurrence cves, plus identifiers in title and description |
CVE, GHSA, GO, RHSA |
| Endpoint | Occurrence target and port |
Port 0 is dropped; non-host targets are not recorded |
| Tags | intruder, target:<target> |
|
| Date | Occurrence first_seen_at |
|
| Status flags | Occurrence snoozed and snooze_reason |
Active, false positive, or risk accepted |
| Unique ID / Vuln ID from Tool | Occurrence ID / issue ID | |
| Finding type | Dynamic | Intruder scans live hosts and services |
| Deduplication | Hashcode | Unique ID from tool, title, severity |
Use Cases
Per-host ownership: A security team maps each Intruder target Record to the Asset that owns the host. Infrastructure teams see only occurrences on their machines, each with its own SLA clock.
Prioritizing by target exposure: Because CVSS comes from the occurrence, the same issue can score higher on an internet-facing host than on an internal one. Teams sort by score within a severity to decide what to patch first.
Keeping triage in one place: Analysts who prefer Intruder's interface snooze false positives and accepted risks there. The connector brings those decisions into DefectDojo, so open counts and SLA reports stay accurate without re-triage.
Before the connector is approved: A team that cannot yet share an Intruder token with another system imports exports that include occurrences. When the connector is enabled, its findings deduplicate against the uploaded ones.
Operational Tips
- Always include occurrences in file exports. Without them, the file parses to zero findings.
- Snooze reasons other than false positive, accepted risk, and mitigating controls import as inactive without a status flag. Review those occasionally so nothing is closed for an unclear reason.
- Targets that are labels rather than hostnames or IPs are not recorded as endpoints. Use the
target:tag or the description to find them. - Use
minimum_severityon import if informational issues would crowd out work your teams need to do. - Reimport exports into the same Test so occurrences that Intruder no longer reports are mitigated.
- Filter on the
intrudertag to report on Intruder findings across all Assets.