All integrations

NowSecure Integration with DefectDojo

NowSecure Integration with DefectDojo

NowSecure is a mobile application security testing platform for iOS and Android apps. A NowSecure assessment runs both static analysis of the app binary and dynamic analysis of the running app, and reports each check with its category, severity, CVSS data, and remediation guidance for developers. DefectDojo imports NowSecure findings from a JSON export of an assessment, or pulls them through the DefectDojo Pro API connector.

NowSecure Integration with DefectDojo

We run NowSecure against every mobile build, and we send the results to DefectDojo so mobile findings get the same SLAs and ownership as our web and backend findings. NowSecure already does the hard part of testing the app. What it can't do is put an insecure data storage issue in the iOS app next to the API vulnerability that makes it exploitable, or tell us whether that issue has been open for three releases. DefectDojo does that, and because the parser and the connector share a scan type, we can import exports today and switch to the API sync without duplicating anything.

Why NowSecure Matters

Mobile apps ship to devices you don't control, which changes what counts as a vulnerability.

  • One assessment covers both what is inside the app package and how the app behaves when it runs, so a single result set spans code-level and runtime issues.
  • Each finding records whether static or dynamic analysis found it, which helps developers reproduce it.
  • Findings carry CVSS vectors and a developer recommendation, so the fix guidance travels with the issue.
  • NowSecure reports every check it ran, including passes. Filtering that down to real problems is the first job of any integration.

Advantages of This Integration

  • Only real findings import. The parser keeps rows where NowSecure says the check affected the app and skips hidden rows, so passed checks and findings suppressed in NowSecure stay out of DefectDojo.
  • Static and dynamic tracked per finding. Each Finding's static or dynamic flag comes from NowSecure's own analysis type, so DefectDojo filters and metrics reflect how each issue was found.
  • File imports and API sync match. Both paths use the NowSecure scan type and identify findings as nowsecure-<check id> (plus NowSecure's vulnerability ID when it is not zero), so deduplication works across them.
  • Mobile risk next to backend risk. Findings land on the Asset for the app, where they share SLA rules, Jira integration, and reporting with every other scanner.
  • CVE filtering. CVE, GHSA, GO, and RHSA identifiers mentioned in the title, description, or detail are extracted into vulnerability IDs.

How This Integration Works

DefectDojo imports NowSecure results with the NowSecure scan type, from a file or through the API Connector (Pro).

1. Option A: export an assessment to JSON. The parser accepts the findings array that NowSecure's findings endpoint returns, or an object with that array under findings and the assessment object under assessment. Include the assessment if you can: it supplies the assessment date and the platform. Without it, findings are dated on the import day and have no platform tag.

2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select NowSecure, and upload the export. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=NowSecure" 
  -F "file=@nowsecure-assessment.json" 
  -F "product_name=mobile-banking-ios" 
  -F "engagement_name=Release 5.2" 
  -F "auto_create_context=true"

Or, in DefectDojo Pro, with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "NowSecure" 
  --report-path "./nowsecure-assessment.json" 
  --product-name "mobile-banking-ios" 
  --engagement-name "Release 5.2" 
  --auto-create-context

3. Option B: connect the API (DefectDojo Pro). Generate a NowSecure Platform API token under Profile, then Tokens. In the DefectDojo Pro connector, enter https://lab-api.nowsecure.com as the Location and paste the token, and optionally set a Minimum Severity. The connector creates one Record per mobile app on the account, holding the findings from that app's latest assessment, so results describe the current build rather than piling up across assessments.

4. Reimport for each build. With file imports, reimport each new assessment into the app's Test with /api/v2/reimport-scan/ so resolved issues are mitigated and new ones are added.

Data Granularity: What Gets Imported

DefectDojo Field Source in NowSecure Export Notes
Title title Falls back to "NowSecure: check id"
Severity severity critical, high, medium, low map directly; info, empty, or unknown become Info
Description Category, check ID, analysis type, description, detail Prose sections follow the labeled fields
Mitigation recommendations.developer Empty if NowSecure gives none
CVSS v3 Vector / Score cvss_vector, cvss Score is always set, so unscored findings show 0.0
Vulnerability IDs Title, description, detail text CVE, GHSA, GO, RHSA identifiers, sorted
Vuln ID from Tool check_id
Unique ID from Tool Check ID and vulnerability ID Format nowsecure-<check>[-<id>]
Date assessment.created Import date if the assessment is missing
Tags Category, analysis type, platform Platform comes from the assessment
Static / Dynamic analysis_type static or dynamic; anything else uses DefectDojo's default (dynamic)
Active Always true Only affected, non-hidden rows are imported
Deduplication Unique ID or hashcode Unique ID first, then title, severity, component name

Use Cases

Release gating for mobile apps: Each release candidate is assessed in NowSecure and imported into the app's Asset. Before the store submission, the release manager checks DefectDojo for open Critical and High findings and any SLA breaches, rather than reading the assessment report end to end.

Separate iOS and Android Assets: A team publishing both platforms keeps one Asset per app. The platform tag from the assessment, plus the category tag, lets the security lead compare the two builds and spot issues that only one platform has.

Developer handoff: Findings carry NowSecure's developer recommendation in the Mitigation field. Pushing a finding to Jira hands the mobile team the issue, its CVSS vector, and the fix guidance in one ticket.

Portfolio view: An organization with a dozen mobile apps uses the connector to keep each app's latest assessment in DefectDojo and reports mobile risk alongside web and API risk for the same business unit.

Operational Tips

  • Export the assessment object with the findings. Without it you lose the real assessment date and the platform tag, and SLA clocks start from the import date.
  • Filter on the static and dynamic flags when assigning work. Static issues usually route to the developers who own the code, while dynamic ones can involve backend teams too.
  • An unscored finding shows a CVSS v3 score of 0.0. Sort by severity, not by CVSS score, when triaging NowSecure results.
  • Findings hidden in NowSecure never import, so make suppression decisions in one place. If you suppress in NowSecure, don't also expect a DefectDojo risk acceptance history for that item.
  • Use minimum_severity or the connector's Minimum Severity to keep Info checks out of the triage queue.
  • Remember the connector imports only each app's latest assessment. If you need history per build, keep the Tests from earlier file imports or rely on the Finding history DefectDojo records.