All integrations

Nozomi Networks Integration with DefectDojo

Nozomi Networks Integration with DefectDojo

Nozomi Networks builds security and visibility products for operational technology (OT), industrial control systems (ICS), and IoT environments. Its Vantage platform builds an inventory of devices such as PLCs, HMIs, and RTUs largely from passive network monitoring, and matches each device's vendor, product, and firmware against published CVEs. DefectDojo imports those per-device vulnerabilities from a Vantage node_cves JSON export, or through the DefectDojo Pro API connector.

Nozomi Networks Integration with DefectDojo

We bring Nozomi Networks Vantage vulnerabilities into DefectDojo because our plant floor shouldn't sit outside the vulnerability program. Vantage knows which controllers run which firmware and which CVEs apply. DefectDojo is where those CVEs get an owner, a remediation target, and a record that auditors can follow. Many of our OT networks are isolated, so a file import is often the only way the data can leave them, and the parser and the connector produce matching findings when a site can use the API.

Why Nozomi Networks Matters

OT vulnerability management runs on different rules from IT. You often can't scan a controller, and you can't patch it on a Tuesday.

  • Vantage builds its device inventory passively, which suits environments where active probing is not acceptable.
  • Each vulnerability record carries full asset context: device label, type, vendor, product, firmware, operating system, and network zone.
  • Records include the hotfix that resolves the CVE, which gives maintenance windows a concrete target.
  • Grouping by zone matches how OT networks are segmented and how change control is usually organized.

Advantages of This Integration

  • One finding per device and CVE. The component is the device's product and its version is the firmware, so the same CVE on two different devices stays two findings with their own owners and deadlines.
  • Resolved records stay closed. The parser skips rows Vantage marks resolved: true, matching the connector's query, so a manual export can't reopen something Nozomi has already closed.
  • File and API imports agree. Both use the Nozomi Vantage Scan scan type and identify findings by Vantage's record ID, so deduplication holds across the two paths.
  • Severity from CVSS. Vantage sends a CVSS base score instead of a severity word, and DefectDojo maps it to Critical through Info, so OT CVEs fall under the same SLA policy as IT ones.
  • Filtering for OT teams. Vendor, device type, product, and zone become tags, which makes it easy to pull every open finding for one cell zone or one controller model.

How This Integration Works

DefectDojo imports Nozomi data with the Nozomi Vantage Scan scan type, from a file or through the API Connector (Pro).

1. Option A: export node_cves to JSON. Save the response of a Vantage node_cves query, which has the shape {"result": [...]}. A bare array, or an object naming the list results or data, also works. Each record is denormalized and carries its own asset context, so one file is enough. Filtering the query to unresolved records keeps the file small, though the parser skips resolved ones either way.

2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select Nozomi Vantage Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Nozomi Vantage Scan" 
  -F "file=@nozomi-node-cves.json" 
  -F "product_name=plant-north" 
  -F "engagement_name=OT Vulnerabilities" 
  -F "auto_create_context=true"

DefectDojo Pro users can use Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Nozomi Vantage Scan" 
  --report-path "./nozomi-node-cves.json" 
  --product-name "plant-north" 
  --engagement-name "OT Vulnerabilities" 
  --auto-create-context

3. Option B: connect the API (DefectDojo Pro). Create a Vantage access key under Administration, Security, Access Keys. In the DefectDojo Pro connector, enter https://api.vantage.nozominetworks.io as the Location, then the key name and key token, and optionally set a Minimum Severity. DefectDojo exchanges the key for a short-lived session token on each sync. The connector creates one Record per network zone and imports vulnerabilities only (not alert-log events), limited to those Vantage still reports as unresolved, so a vulnerability resolved in Vantage is reflected on the next sync.

4. Reimport on a schedule. For file imports, reimport each new export into the same Test with /api/v2/reimport-scan/ so CVEs that disappear are mitigated.

Data Granularity: What Gets Imported

DefectDojo Field Source in Vantage Export Notes
Title cve, node_label "CVE on device"; CVE alone if no label; generic title if no CVE
Severity cve_score 9+ Critical, 7+ High, 4+ Medium, above 0 Low, 0 or missing Info
CVSS v3 Score cve_score Quoted scores are accepted
Description Asset, type, vendor, product, firmware, OS, zone, weakness Followed by the CVE summary
Mitigation latest_hotfix, minimum_hotfix "Apply hotfix X", else "Apply at least hotfix Y"
Component Name / Version node_product_name, node_firmware_version Device product and firmware
References cve_references One per line
CWE cwe_id Accepts "CWE-787" or a bare number
Vulnerability IDs / Vuln ID from Tool cve
Unique ID from Tool Record id Falls back to CVE plus asset_id
Tags Vendor, device type, product, zone
Active Always true Resolved rows are skipped, not imported inactive
Finding type Static Passive inventory matching; nothing is probed
Deduplication Unique ID or hashcode Unique ID first, then title, severity, component name

The likelihood field in the Vantage response is not imported.

Use Cases

Isolated sites: A plant network with no outbound path exports node_cves to a file, moves it through the approved transfer process, and imports it into the plant's Asset. The site's open CVEs then appear in the same reports as the corporate network.

Maintenance window planning: Before a scheduled shutdown, the OT engineering lead filters the Asset by zone and device type, sorts by severity, and builds the work list from the hotfix named in each finding's Mitigation field.

Risk acceptance for legacy controllers: Some controllers can't be patched until a hardware refresh. The team risk-accepts those findings in DefectDojo with an expiration date and a note on compensating controls, so they come back for review instead of vanishing.

Joint IT and OT reporting: A CISO reporting to the board shows OT vulnerabilities by zone next to IT findings by business unit, from one DefectDojo dashboard, with SLA status for both.

Operational Tips

  • Map Assets to sites or zones in a way that matches who owns remediation. The connector's one-Record-per-zone model is a good default for file imports too.
  • Unscored CVEs import as Info. Review Info findings periodically rather than filtering them out, because in OT the asset context alone can matter.
  • Set SLAs for OT realistically. Patching often waits for planned downtime, so a separate SLA configuration for OT Assets avoids constant breach noise.
  • Use risk acceptance with expiry for devices awaiting replacement, and record the compensating control in a note.
  • Tag imports with the site name so multi-site organizations can report per facility.
  • If a CVE appears closed in DefectDojo, check that it was resolved in Vantage. Resolved records are skipped on import, and reimport mitigates whatever is missing from the new file.