MS Defender Integration with DefectDojo
Microsoft Defender is a comprehensive family of cybersecurity solutions that provides threat prevention, detection, and response capabilities across endpoints, identities, applications, email, data, workloads, and cloud environments through unified extended detection and response (XDR) technology. Microsoft Defender leverages advanced threat intelligence from over 78 trillion daily signals and AI-powered protection to help organizations prevent cyberattacks, automate incident response, and strengthen security posture across hybrid and multicloud infrastructures.
Data Granularity: What Gets Imported
The following fields are captured from MS Defender results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "MS Defender",
"engagement": "<engagement-id>",
"file": "results.json"
}