All integrations

Intruder Integration with DefectDojo

Intruder Integration with DefectDojo

Intruder is a cloud-based vulnerability scanning service from Intruder, a UK company. It scans an organization's targets, such as internet-facing hosts, internal infrastructure, web applications, and cloud environments, and reports issues with a severity, a description, and remediation advice. Intruder separates an issue (the weakness itself) from its occurrences (each target and port where it was found), and records triage by snoozing occurrences with a reason. Issues and occurrences are available through the Intruder REST API as JSON.

Intruder Integration with DefectDojo

We use Intruder to keep scanning our perimeter and infrastructure without running scanners ourselves. What we needed was a place to work those results alongside everything else. Bringing Intruder into DefectDojo turns every occurrence into a Finding on the Asset that owns that target, with its own CVSS score, owner, and SLA. Occurrences our team already snoozed in Intruder as false positives or accepted risks come across in that state, so nobody triages them twice.

Why Intruder Matters

Exposed services and unpatched hosts are still one of the most common ways in, and the set of exposed targets changes all the time.

  • Intruder scans on a schedule as a service, so coverage doesn't depend on someone remembering to run a tool.
  • It reports each occurrence separately, so one weakness on ten hosts is ten pieces of work, each fixable on its own timeline.
  • Occurrence-level CVSS scores reflect that the same weakness can be more serious on one target than another.
  • Snooze reasons (false positive, accepted risk, mitigating controls) record triage decisions that should carry forward.
  • Without a central platform, these results stay apart from application and cloud findings for the same systems.

Advantages of This Integration

What DefectDojo adds to Intruder results:

  • The occurrence is the finding. Each occurrence becomes its own Finding with its target as the endpoint, so work can be assigned per host.
  • Triage carries over. A snoozed false positive imports as an inactive false positive. Accepted risk and mitigating controls import as risk accepted. Other snooze reasons import inactive without either flag.
  • Matched file and API findings. The parser and the DefectDojo Pro connector share the scan type Intruder API Import, so uploaded exports and connector syncs deduplicate against each other.
  • Deduplication with a guard. The hash covers the occurrence ID, title, and severity, so a reused ID with different content is not mistaken for the same finding.
  • CVE coverage. Vulnerability IDs come from the occurrence and from any CVE, GHSA, GO, or RHSA identifiers in the issue title or description.
  • Standard workflow. SLAs per severity, assignment, notes, Jira pushes, and metrics all apply.

How This Integration Works

All methods use the scan type Intruder API Import.

Option 1: Import a JSON export. The parser reads Intruder's issues response, with rows under results (or issues, or a bare array). Intruder's issue object only links to its occurrences, so the export must include them, either as a top-level occurrences object keyed by issue ID or as an occurrences array nested on each issue. An issue with no occurrences produces no findings.

In the UI, open the Engagement, choose Import Scan Results, select Intruder API Import, and upload the file. To automate it in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Intruder API Import" 
  -F "file=@intruder-issues.json" 
  -F "product_name=external-perimeter" 
  -F "engagement_name=Intruder Scans" 
  -F "auto_create_context=true"

Option 2: Universal Importer (DefectDojo Pro).

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Intruder API Import" 
  --report-path "./intruder-issues.json" 
  --product-name "external-perimeter" 
  --engagement-name "Intruder Scans" 
  --auto-create-context

Option 3: The Intruder connector (DefectDojo Pro). The connector pulls the whole account's posture through the Intruder REST API. Create an API access token in Intruder under My account, then API Access Tokens (you need your account password, and the token is shown only once). In the connector form, leave Location as https://api.intruder.io/ and enter the token in Secret. Each Intruder target is discovered as a Record that you map to a DefectDojo Asset, and each occurrence of an issue on that target becomes a Finding.

Data Granularity: What Gets Imported

DefectDojo Field Source in Intruder Export Notes
Title Issue title Shared by every occurrence of the issue
Severity Issue severity critical, high, medium, low map directly; anything else Info
Description Target or display address, port, protocol, first seen, exploit likelihood, extra info, issue description Extra info listed in sorted key order
Mitigation Issue remediation
CVSS v3 Score Occurrence cvss_score, else issue Occurrence value preferred
Vulnerability IDs Occurrence cves, plus identifiers in title and description CVE, GHSA, GO, RHSA
Endpoint Occurrence target and port Port 0 is dropped; non-host targets are not recorded
Tags intruder, target:<target>
Date Occurrence first_seen_at
Status flags Occurrence snoozed and snooze_reason Active, false positive, or risk accepted
Unique ID / Vuln ID from Tool Occurrence ID / issue ID
Finding type Dynamic Intruder scans live hosts and services
Deduplication Hashcode Unique ID from tool, title, severity

Use Cases

Per-host ownership: A security team maps each Intruder target Record to the Asset that owns the host. Infrastructure teams see only occurrences on their machines, each with its own SLA clock.

Prioritizing by target exposure: Because CVSS comes from the occurrence, the same issue can score higher on an internet-facing host than on an internal one. Teams sort by score within a severity to decide what to patch first.

Keeping triage in one place: Analysts who prefer Intruder's interface snooze false positives and accepted risks there. The connector brings those decisions into DefectDojo, so open counts and SLA reports stay accurate without re-triage.

Before the connector is approved: A team that cannot yet share an Intruder token with another system imports exports that include occurrences. When the connector is enabled, its findings deduplicate against the uploaded ones.

Operational Tips

  • Always include occurrences in file exports. Without them, the file parses to zero findings.
  • Snooze reasons other than false positive, accepted risk, and mitigating controls import as inactive without a status flag. Review those occasionally so nothing is closed for an unclear reason.
  • Targets that are labels rather than hostnames or IPs are not recorded as endpoints. Use the target: tag or the description to find them.
  • Use minimum_severity on import if informational issues would crowd out work your teams need to do.
  • Reimport exports into the same Test so occurrences that Intruder no longer reports are mitigated.
  • Filter on the intruder tag to report on Intruder findings across all Assets.