Noir Integration with DefectDojo
Noir Integration with DefectDojo
Noir is an open source static analysis tool that reads an application's source code and extracts the endpoints it exposes: paths, HTTP methods, parameters, and the source files that define them. It started as a personal project of the developer known as hahwul in 2023, joined the OWASP Foundation in 2024, and is maintained under the owasp-noir GitHub organization. Noir is written in Crystal and supports many web frameworks, with output formats that include JSON, YAML, OpenAPI, and SARIF. DefectDojo imports its JSON report.
Noir Integration with DefectDojo
We run Noir because you can't test or protect routes you don't know exist, and our API documentation never matches the code. Noir reads the source and lists every route it can find. Imported into DefectDojo, that list becomes a reviewable inventory on the Asset, refreshed on every build, where new endpoints stand out instead of hiding in a diff. The routes Noir tags as security-relevant, like admin paths or parameters that take file paths, come in one step above informational so someone actually looks at them.
Why Noir Matters
Most security tools tell you what is wrong. Noir tells you what is there, which is the question you need answered first.
- It derives the endpoint list from code, so undocumented and forgotten routes appear alongside the ones in the API spec.
- Each endpoint carries its method, parameters, and the file and line where it is defined, which makes ownership and review concrete.
- Noir tags endpoints it considers sensitive, giving reviewers a short list to start with.
- Its output can seed dynamic testing, so knowing the full surface improves DAST coverage too.
- On its own, a Noir report is a point-in-time list. Without somewhere to keep it, nobody notices when the surface grows.
Advantages of This Integration
- A living endpoint inventory. Each discovered route becomes a Finding on the Asset, so the attack surface is recorded per application and searchable across the portfolio.
- New routes surface on reimport. Reimporting into the same Test adds endpoints that appeared since the last run and mitigates ones that were removed, so changes in the surface are visible in the Test history.
- Stable deduplication. DefectDojo hashes Noir findings on
vuln_id_from_tool(method plus URL) and file path, so the same route defined in the same file is matched across scans. - Review workflow for sensitive routes. Tagged endpoints import as Low. They can be assigned to an application owner, annotated with notes, or risk-accepted once reviewed.
- Context for other findings. With the route inventory on the same Asset as SAST and DAST results, a reviewer can check a reported vulnerability against what the application actually exposes.
How This Integration Works
DefectDojo imports Noir results with the Noir Scan scan type.
1. Generate a JSON report. Run Noir against the source directory and write JSON:
noir -b . -f json > noir.json
The parser reads the endpoints array. Other sections of the report, such as passive scan results, are not imported.
2. Import it. In the UI, open the Engagement, choose Import Scan Results, select Noir Scan, and upload the file. For automation, use the API, available in Community Edition and DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Noir Scan"
-F "file=@noir.json"
-F "product_name=orders-api"
-F "engagement_name=Attack Surface"
-F "auto_create_context=true"
DefectDojo Pro users can run Universal Importer from the pipeline:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Noir Scan"
--report-path "./noir.json"
--product-name "orders-api"
--engagement-name "Attack Surface"
--auto-create-context
3. Reimport on every build. Send later reports to /api/v2/reimport-scan/ against the same Test so the inventory tracks the code as it changes.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Noir Report | Notes |
|---|---|---|
| Title | method and url |
For example POST /api/login |
| Severity | tags |
Low when the endpoint has any Noir tag, otherwise Info |
| Description | Method, URL, technology, protocol, parameters, tags, source location | Each parameter listed with its Noir parameter type |
| File Path | First details.code_paths entry |
Where the route is defined |
| Line | Line of that code path | |
| Vuln ID from Tool | method and url |
Same value as the title |
| Finding type | Static | Derived from source code |
| Deduplication | Hashcode | vuln_id_from_tool, file_path |
Noir findings are inventory, not vulnerabilities, so the parser sets no CWE, CVE, mitigation, or references. Tag names and their descriptions appear in the description so reviewers can see why an endpoint was flagged.
Use Cases
Pre-release review: Before each release, a CI job runs Noir and reimports the result. The security reviewer filters the Test for new Low findings and checks each newly tagged route, such as an admin path or an upload handler, before it ships.
API inventory for compliance: A team asked to prove it knows every externally reachable route can point to the Noir findings on each Asset, with the file and line for each one, instead of maintaining a separate spreadsheet.
Scoping a penetration test: Ahead of an external test, the security team exports the endpoint inventory from DefectDojo and gives testers a complete route list per application, including routes missing from the published API spec.
Tracking surface growth: Across 40 services, a security lead uses DefectDojo metrics to see which applications added the most endpoints in a quarter and directs review time there.
Operational Tips
- Keep Noir in its own Engagement or Test (for example "Attack Surface") so inventory findings don't inflate vulnerability counts in your main security Engagement.
- Set SLAs with Info and Low in mind. Most Noir findings are Info by design, and you probably don't want an SLA clock on route inventory.
- Don't use
minimum_severity=Lowunless you only want tagged endpoints. Filtering out Info hides the untagged inventory, which is half the value. - Risk-accept or close tagged endpoints after review, with a note explaining why the route is expected. The next reimport will match them by method, URL, and file path.
- Moving a route to a different file changes its hash, because file path is part of deduplication. Expect one mitigated and one new finding after a refactor.
- Tag imports with the commit or release (
tags=release-2.3) so you can tell when an endpoint first appeared. - Run Noir from the repository root (or point
-bat the service directory in a monorepo) so file paths stay consistent between runs. A different base path produces different file paths and therefore different hashes. - Pair Noir with a DAST tool on the same Asset. When the dynamic scanner reports nothing for a route Noir found, that gap is worth a ticket of its own.