Masscan Integration with DefectDojo
Masscan Integration with DefectDojo
Masscan is an open source TCP and UDP port scanner written by Robert Graham and published on GitHub. It is built to sweep large address ranges quickly by sending packets asynchronously at a configurable rate, and it reports which ports on which hosts answered. Masscan can write its results in several formats, including XML and JSON; DefectDojo imports the JSON written with -oJ.
Masscan Integration with DefectDojo
We use Masscan for the wide sweep: every external range we own, on a schedule, to see what is listening. A raw Masscan file tells you what answered on one run, but it does not tell you what changed since last week. Importing the JSON into DefectDojo turns each open port into an Info Finding with a proper host and port endpoint on the Asset that owns the range, and reimporting the next sweep shows which ports closed and which ones are new.
Why Masscan Matters
Most exposure problems start with something listening that nobody expected: a forgotten admin port, a test service left on a public address, a database bound to the wrong interface. Masscan is good at finding those across large networks.
- It is designed for speed across large ranges, which makes regular full sweeps practical.
- Its output is minimal and predictable: host, port, protocol, status, and probe details.
- It answers the first question in exposure management, which is what is actually reachable, before anyone asks what is vulnerable.
- Masscan does not judge whether a port should be open. That decision needs context about the host, which is exactly what a vulnerability management platform holds.
Advantages of This Integration
What we get from running Masscan output through DefectDojo:
- Ports as endpoints. Each open port becomes an endpoint built from the host and port, so it can be searched and reported on with the rest of the Asset's endpoints.
- Clean deduplication. DefectDojo hashes Masscan findings on title and endpoints. The description (timestamp, TTL, probe reason) is left out on purpose, so a rescan of an unchanged network does not import every port again.
- Change detection through reimport. Reimporting a new sweep into the same Test mitigates ports that closed, adds newly opened ones, and reactivates any that came back. The new ones are what we review first.
- Duplicate records collapsed. A port answered by more than one probe can appear twice in a Masscan file. The parser keys on host, port, and protocol, so it imports once.
- Ownership. Findings sit on the Asset responsible for the range, where they can be assigned, annotated, or pushed to Jira when a port needs closing.
- Exposure next to vulnerabilities. Open ports sit beside DAST and infrastructure scanner findings for the same Asset, which helps when deciding which services deserve deeper testing.
How This Integration Works
DefectDojo reads Masscan results with the Masscan Scan scan type.
1. Write a JSON report. Use -oJ to write JSON. Only scan address ranges you own or are authorized to test:
masscan -p80,443,8080 203.0.113.0/24 --rate 1000 -oJ masscan.json
2. Import it. In the UI, open the Engagement, choose Import Scan Results, select Masscan Scan, and upload the file. For automation, use the API, available in Community Edition and DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Masscan Scan"
-F "file=@masscan.json"
-F "product_name=external-perimeter"
-F "engagement_name=Weekly Port Sweep"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Masscan Scan"
--report-path "./masscan.json"
--product-name "external-perimeter"
--engagement-name "Weekly Port Sweep"
--auto-create-context
3. Reimport each sweep. Send later scans of the same range to /api/v2/reimport-scan/ against the same Test so closed ports are mitigated and newly opened ones stand out.
The parser handles two Masscan habits. A scan that finds nothing writes an empty file rather than an empty JSON array, and that parses to zero findings. Some Masscan versions leave a trailing comma before the closing bracket, and the parser tolerates it. Ports Masscan reports as closed are not imported.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Masscan Report | Notes |
|---|---|---|
| Title | Port, protocol, host IP | "Open port: 443/tcp on 203.0.113.10" |
| Severity | Fixed | Always Info; an open port is an observation, not a weakness |
| Description | Host, port and protocol, reason, TTL, timestamp | Reason is typically syn-ack for a SYN scan |
| Endpoint | ip and port |
Host and port only, with no scheme |
| Status filter | status |
Only open ports are imported |
| Finding type | Dynamic | All Masscan findings are marked dynamic |
| Deduplication | Hashcode | Title, endpoints |
The parser reads open ports only. It does not import banner or service data, and Masscan reports no vulnerability data, so no CVE, CWE, or mitigation fields are set.
Use Cases
For external attack surface monitoring: A security team sweeps its public address space weekly and reimports into one Test per range. Each week the new Info findings are the ports that opened since the last sweep, which is a short list to check against change tickets.
Before deeper testing: A pentest or DAST program uses the imported endpoints to decide where to point slower, more detailed tools, and records the results against the same Asset.
During cloud migrations: While workloads move between networks, regular Masscan imports show whether old addresses have actually gone quiet and whether new ones expose only what was planned.
For audit evidence: Open ports with discovery and mitigation dates give a timeline of what was exposed and for how long, without rebuilding it from old scan files.
Operational Tips
- Keep one Test per range or network segment and reimport into it. A new Test per scan works, but you lose the opened and closed history.
- Every Masscan Finding is Info, so SLAs keyed to severity will not fire on them. Review new findings after each reimport, or raise the severity manually on a port that should never be exposed.
- Keep the port list and rate consistent between runs. Scanning fewer ports one week makes ports look closed and mitigates their findings on reimport.
- Masscan's speed can drop responses on congested links. If ports flap between open and mitigated across sweeps, lower the rate before assuming the service changed.
- Tag imports with the range or scan profile (for example
tags=external,top-ports) so different sweep types stay easy to filter. - Pair Masscan with a scanner that identifies services. Masscan tells you a port is open; it does not tell you what is behind it.