Lacework (FortiCNAPP) Integration with DefectDojo
Lacework (FortiCNAPP) Integration with DefectDojo
Lacework is a cloud-native application protection platform (CNAPP) that Fortinet acquired in August 2024 and now offers as FortiCNAPP. Among its capabilities, it assesses container images and running hosts for vulnerabilities in operating system and application packages, rating each CVE by severity and reporting whether a fix is available. Lacework exposes this data through its v2 API and command line tool, which return JSON. DefectDojo imports the container and host vulnerability data, either from a saved JSON export or through the DefectDojo Pro connector.
Lacework (FortiCNAPP) Integration with DefectDojo
Lacework tells us which images and hosts carry vulnerable packages. DefectDojo is where those vulnerabilities get owners, due dates, and a place next to our code and pentest findings. With the DefectDojo Pro connector syncing on a schedule, each container and host CVE becomes a Finding, tagged with the image or host it came from and mitigated automatically when Lacework reports it fixed. For an environment that can't grant API access, the same data imports from a file under the same scan type, so switching to the connector later doesn't duplicate anything.
Why Lacework (FortiCNAPP) Matters
Vulnerabilities in base images and hosts make up a large share of most organizations' open CVEs, and they are owned by different people than application code.
- Lacework covers both container images and running hosts, so one source describes the package exposure of the whole workload.
- It reports a fixed version where one exists, which tells teams whether the work is an upgrade or a risk decision.
- Its severity ratings are on a familiar Critical to Low scale.
- Lacework's own console is organized around cloud resources. DefectDojo adds the application and team ownership view that remediation tracking needs.
Advantages of This Integration
What we gained by routing Lacework through DefectDojo:
- Static and dynamic findings kept apart. Container image vulnerabilities import as static findings and host vulnerabilities as dynamic findings, matching how each was discovered.
- Fixed means closed. A row Lacework reports as
FixedorResolvedis imported as inactive and mitigated rather than left open. - File and API findings merge. File imports use the connector's scan type, Lacework - Connectors Import, and the same identity rules, so the two paths produce one set of findings.
- Precise identity. Deduplication uses a unique ID of image (or host), CVE, package, and version first, and falls back to a hash of title, severity, and component name.
- Asset grouping that fits your org. The connector can put findings on one Asset per account, per resource type, or per container image repository and host.
How This Integration Works
There are two ways to get Lacework data into DefectDojo.
Option 1: Lacework / FortiCNAPP connector (DefectDojo Pro). The connector uses the Lacework v2 API to import host and container vulnerabilities for the whole Lacework account. To set it up:
- Create an API key (key ID and secret) in the Lacework console under Settings, then API keys.
- Enter your Lacework account URL in the Location field, for example
https://YOUR-ACCOUNT.lacework.net. A bare account name also works. - Enter the API Key ID and API Secret. The connector exchanges them for a short-lived access token on each sync, and none of these values are logged.
- Optionally, set a Minimum Severity.
- Optionally, choose an Asset Grouping under Import Filters: Account (the default, one Record), Resource type (Container images and Hosts), or Resource (one Record per image repository and per host).
With a finer grouping, the account Record becomes a parent Asset with no findings of its own, and each vulnerability is imported once on its repository or host Asset. Only repositories and hosts with an active vulnerability at or above the minimum severity become Records. Lacework machine tags reach host Assets as tags prefixed lacework:.
Option 2: File import (Community Edition and DefectDojo Pro). This path is for organizations that can't grant Lacework API credentials. Save the rows of a Lacework container or host vulnerability query as JSON. The DefectDojo documentation gives these Lacework CLI commands as examples:
lacework vulnerability container list-assessments --json > lacework.json
lacework vulnerability host list-cves --json > lacework.json
The parser accepts a bare JSON array of rows or the query envelope that wraps them under data. Each row needs the vulnerability fields described below (vulnId, featureKey, and an imageId or host details), so check a sample export before automating it. Then import with the Lacework - Connectors Import scan type, through the UI or the API:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Lacework - Connectors Import"
-F "file=@lacework.json"
-F "product_name=platform-workloads"
-F "engagement_name=Lacework"
-F "auto_create_context=true"
DefectDojo Pro users can run Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Lacework - Connectors Import"
--report-path "./lacework.json"
--product-name "platform-workloads"
--engagement-name "Lacework"
--auto-create-context
Data Granularity: What Gets Imported
The table below describes the file parser, which mirrors the connector's mapping.
| DefectDojo Field | Source in Lacework Row | Notes |
|---|---|---|
| Title | vulnId, package, version |
<CVE> - <package> (<version>) |
| Severity | severity |
critical, high, medium, low map across; anything else Info |
| Description | CVE, severity, image or host, registry, digest, package, namespace, installed version | Host rows also include the CVE description |
| Mitigation | fixInfo |
Upgrade <package> to <fixed version>, only when a fix is available and a fixed version is given |
| References | cveProps.link |
Host rows only |
| Vulnerability IDs | vulnId |
The CVE ID |
| Component Name / Version | featureKey name and version |
Hosts use version_installed |
| Tags | Image, registry, or host | image:, registry:, source:container or host:, source:host |
| Unique ID from Tool | Image or host, CVE, package, version | Joined with pipe characters; a host without a hostname uses mid-<machine id> |
| Active / Mitigated | status |
Fixed or Resolved rows import inactive and mitigated |
| Finding type | Static or dynamic | Container rows static, host rows dynamic |
| Deduplication | Unique ID or hashcode | Unique ID first, else title, severity, component name |
Duplicate rows with the same unique ID in one file are collapsed into a single Finding.
Use Cases
For container platform teams: The connector uses Resource grouping, so each image repository becomes its own Asset. The team that owns a base image sees its CVEs, with the fixed version in the mitigation, and rebuilt images close Findings as Lacework reports them fixed.
For host patching: Host vulnerabilities land on per-host Assets carrying Lacework machine tags such as an environment tag. Patch teams filter by those tags to plan maintenance windows for production hosts first.
In a restricted environment: A team waiting on approval for API access imports JSON exports in the meantime. When the connector is approved, it syncs into the same scan type and the existing Findings are matched rather than duplicated.
For combined risk reporting: Lacework findings sit alongside SAST, SCA, and pentest results, so a security lead can report open Critical vulnerabilities for an application, from code down to the hosts it runs on.
Operational Tips
- Start with Account grouping to see volume, then move to Resource grouping. Enable Auto Map on the connection when you change grouping so findings move to the new Assets without a gap.
- Set a Minimum Severity on the connector. It also decides which repositories and hosts become Records under finer grouping.
- Expect Records for fully fixed repositories and hosts to stay for 14 days while their findings close, then be marked MISSING.
- Use SLAs by severity, but remember Findings without a fixed version have no mitigation text. Consider time-limited risk acceptance for those.
- Use the
image:andhost:tags to filter and report when one Asset holds findings for many resources. - Don't mix file imports and the connector for the same account on different Assets. Keep them on the same Asset so findings merge.