All integrations

Kingfisher Integration with DefectDojo

Kingfisher Integration with DefectDojo

Kingfisher is an open source secret scanner from MongoDB, written in Rust and released under the Apache 2.0 license. It searches local files and directories, Git repositories and their history, and a range of other sources for credentials such as cloud keys, API tokens, and private keys. Where a provider allows it, Kingfisher actively validates a match to find out whether the credential still works. It can write results as human-readable text, JSON, JSONL, SARIF, and other formats, and DefectDojo imports its JSON report.

Kingfisher Integration with DefectDojo

We picked Kingfisher for secret scanning because it tells us which leaked credentials are still live, and we send its JSON reports to DefectDojo so that answer turns into assigned work. A raw scan of a large repository can list hundreds of matches. In DefectDojo each match becomes a Finding on the Asset that owns the code, a validated credential lands as Critical, and repeat scans of the same repository don't pile up duplicate copies of the same key. Rotation becomes something we can track to closure instead of a list someone reads once.

Why Kingfisher Matters

Secrets in source code are one of the shortest paths from a public mistake to a real incident. The hard part is rarely finding candidate strings. It is deciding which ones need someone's attention today.

  • Active validation separates a working credential from a revoked one, so the team can rotate live keys first.
  • It scans Git history, not only the current tree, which matters because a secret deleted in a later commit is still recoverable.
  • Each match carries a confidence level, which gives a sensible ordering even when a provider can't be validated.
  • Being open source and self-run, it fits teams that won't send repository contents to a hosted scanning service.

Advantages of This Integration

What running Kingfisher through DefectDojo adds:

  • Severity that reflects exposure. Kingfisher has no severity field. The DefectDojo parser marks a match Critical when validation confirmed a live credential and otherwise maps confidence (high, medium, low) to High, Medium, and Low.
  • Deduplication across scans. Findings are hashed on title, file path, and line, so rescanning a repository on every push doesn't create a new Finding for a secret that is already tracked.
  • A lifecycle for rotation. Reimporting into the same Test mitigates matches that disappeared (for example, after a history rewrite) and reactivates any that come back.
  • Ownership and SLAs. Each Finding sits on an Asset, can be assigned to the owning team, and runs against the SLA for its severity, so a live cloud key gets a much shorter clock than a low-confidence match.
  • Less sensitive data spread around. The parser records the rule, confidence, validation status, entropy, language, and path, but it does not copy the matched snippet or the provider's validation response into the Finding.

How This Integration Works

DefectDojo imports Kingfisher output with the Kingfisher Scan scan type. The parser reads the findings array from a Kingfisher JSON report.

1. Produce a JSON report. Run Kingfisher against a repository or directory and save JSON output:

kingfisher scan /path/to/repo --format json > kingfisher.json

2. Import it. In the UI, open the Engagement, choose Import Scan Results, select Kingfisher Scan, and upload the file. For automation, the API works in Community Edition and DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Kingfisher Scan" 
  -F "file=@kingfisher.json" 
  -F "product_name=payments-api" 
  -F "engagement_name=Secret Scanning" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import from a pipeline with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Kingfisher Scan" 
  --report-path "./kingfisher.json" 
  --product-name "payments-api" 
  --engagement-name "Secret Scanning" 
  --auto-create-context

3. Reimport on a schedule. For a repository you scan repeatedly, send later reports to /api/v2/reimport-scan/ against the same Test so remediated secrets are closed and the history stays in one place.

Data Granularity: What Gets Imported

DefectDojo Field Source in Kingfisher Report Notes
Title rule.name For example, the credential type the rule detects
Severity validation.status and confidence Live credential is Critical; otherwise high, medium, low map to High, Medium, Low
Description Rule, confidence, validation status, entropy, language, path Labeled lines; the matched snippet is not included
Mitigation Fixed text Revoke and rotate the credential, then remove it from source history
File Path finding.path Trailing whitespace Kingfisher sometimes adds is stripped
Line finding.line Line of the match
Vulnerability ID from Tool rule.id Kingfisher's rule identifier
Unique ID from Tool finding.fingerprint Kingfisher's stable identity for the match
Finding type Static All Kingfisher findings are marked static
Deduplication Hashcode Title, file path, line

A credential that validation reports as inactive keeps the severity its confidence gives it. It is still a secret committed to source, just not a usable one.

Use Cases

In a CI/CD pipeline: Each merge to the main branch runs Kingfisher and reimports the report into a Test for that repository. Only new matches show up as new Findings, and a pipeline step can query DefectDojo for new Critical findings to stop a release that would ship a live key.

During incident response: After a suspected leak, the security team scans the affected repositories, including history, and imports the results. Validated credentials sort to the top as Critical, so the rotation list writes itself, and each rotation is recorded against a Finding with an owner.

Across a large organization: A platform team scans dozens of repositories nightly and imports each into the owning Asset. Security leads get one view of open secrets by team, with SLA status, instead of a separate scan log per repository.

For audit evidence: Findings carry discovery dates, status changes, and notes, so an auditor can see how quickly live credentials were rotated without anyone rebuilding the timeline from chat threads.

Operational Tips

  • Set short SLAs for Critical. In this parser, Critical means Kingfisher confirmed the credential works, which is the case that most needs to be fixed fast.
  • Keep validation enabled where your policy allows it. Without a validation result, severity falls back to confidence, and a live key would import as High or lower.
  • Rotate first, then clean history. Removing a secret from the latest commit doesn't close the exposure, and the parser's mitigation text says the same.
  • Use one Test per repository and reimport into it, so the open-to-mitigated history reflects actual cleanup.
  • Use minimum_severity if low-confidence matches create too much noise for a first rollout, and lower it once the backlog is under control.
  • Mark confirmed test fixtures and dummy values as false positives in DefectDojo rather than deleting them, so the decision is recorded and the hash keeps them from reappearing as new.
  • Tag imports with the repository or branch name so findings can be filtered when the same Asset covers several repositories.