Orca Security Alerts Integration with DefectDojo
Orca Security Alerts Integration with DefectDojo
Orca Security is a cloud security platform that assesses workloads, configurations, and identities across cloud accounts without installing agents. It raises alerts for issues such as vulnerabilities, misconfigurations, malware, and exposed secrets, and gives each alert an OrcaScore from 0 to 10, a category, and the affected cloud resource. DefectDojo imports Orca alerts from the CSV or JSON export on the console's Alerts page, or pulls open alerts through the DefectDojo Pro API connector.
Orca Security Alerts Integration with DefectDojo
We bring Orca Security alerts into DefectDojo because cloud posture findings need owners just as much as code findings do. Orca shows us an unused IAM role or an exposed storage bucket in a given account. DefectDojo turns that alert into a Finding on the right Asset, deduplicates it against the last export, assigns it, and measures it against the SLA for its severity. Our cloud and application findings end up in one backlog with one set of reports.
Why Orca Security Matters
Cloud risk changes faster than release cycles, and a lot of it comes from configuration rather than code.
- Orca covers many alert types from one platform: vulnerabilities, misconfigurations, malware, and secrets.
- Its agentless approach reaches cloud resources that don't run a security agent.
- Each alert names the affected inventory item and cloud account, which is where ownership questions start.
- The OrcaScore ranks alerts on a single numeric scale, which is useful for consistent triage.
- Alerts in a cloud console stay with the cloud team. Getting them into a shared workflow is what makes application and platform owners act on them.
Advantages of This Integration
- Consistent severities. OrcaScore maps onto DefectDojo's Critical through Info scale, and the original score is kept as the severity justification, so nothing about Orca's ranking is lost.
- Deduplication by alert and resource. DefectDojo hashes Orca findings on title and component name (the inventory item), so the same alert on the same resource is matched across exports while the same alert on two resources stays two findings.
- Status follows Orca. Alerts with status
openimport as active and any other status as inactive, so closed alerts in an export don't create open work. - Labels become tags. Orca labels are imported as DefectDojo tags, which makes filtering by source, team, or alert type straightforward.
- Scheduled sync in DefectDojo Pro. The API connector imports open alerts on a schedule and reflects alerts closed in Orca on the next sync, with no export step.
How This Integration Works
DefectDojo imports Orca exports with the Orca Security Alerts scan type. DefectDojo Pro also offers the Orca Security API connector.
1. Option A: export alerts. In the Orca Security console, open the Alerts page, apply the filters you want (scope, severity, status), click Export, and choose CSV or JSON. The parser detects the format itself: a file starting with [ is read as JSON, anything else as CSV.
2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select Orca Security Alerts, and upload the export. For automation, use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Orca Security Alerts"
-F "file=@orca-alerts.json"
-F "product_name=aws-production"
-F "engagement_name=Cloud Posture"
-F "auto_create_context=true"
DefectDojo Pro users can use Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Orca Security Alerts"
--report-path "./orca-alerts.json"
--product-name "aws-production"
--engagement-name "Cloud Posture"
--auto-create-context
3. Option B: connect the API (DefectDojo Pro). Create an Orca API token. In the DefectDojo Pro connector, enter your Orca API host as the Location and the token as the Secret, and optionally set a Minimum Severity. Orca tokens are region-scoped, so the host must belong to the same region as the token; a sync that fails to authenticate with a valid token usually means a region mismatch. The connector creates one Record per connected cloud account and imports only open alerts.
4. Reimport exports. For file-based workflows, reimport each new export into the same Test with /api/v2/reimport-scan/ so alerts that disappear are mitigated.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Orca Export | Notes |
|---|---|---|
| Title | Title |
Truncated at 500 characters; "Orca Security Alert" if empty |
| Severity | OrcaScore |
0 or missing Info, below 4 Low, below 7 Medium, below 9 High, 9 and up Critical |
| Severity Justification | OrcaScore |
Stored as "OrcaScore: X.X" |
| Description | Title, category, source, inventory, cloud account, score, status, dates, labels | Labeled fields; empty values omitted |
| Component Name | Inventory.Name |
The affected cloud resource |
| Service | Source |
Orca resource identifier |
| Date | CreatedAt |
|
| Active | Status |
open is active; other values inactive; missing status active |
| Tags | Labels |
JSON array in both formats; raw string used if the CSV value isn't JSON |
| Mitigation | Not set | Orca exports carry no remediation text |
| Finding type | Static | |
| Deduplication | Hashcode | Title, component name |
The cloud account name appears in the description but is not part of the deduplication hash.
Use Cases
Cloud posture backlog: A platform team exports open alerts weekly and reimports them into one Asset per cloud account. DefectDojo shows which alerts are new since last week, which were resolved, and which are past their SLA.
Account ownership: Separate business units own separate AWS, Azure, or GCP accounts. With one Asset per account, each unit's findings are assigned and reported to the right owner, and a security lead can compare units by open Critical and High alerts.
Connector-driven sync: A DefectDojo Pro customer connects Orca through the API connector, so open alerts are synced on a schedule and alerts closed in Orca drop out of the DefectDojo backlog without an export.
Combined application view: A service running in a cloud account has its SAST and SCA findings on one Asset and its Orca alerts on another. Reporting at the Organization level gives the service owner the full picture of code and cloud risk.
Operational Tips
- Apply filters before exporting. Exporting only the scope and statuses you track keeps closed alerts and out-of-scope accounts from cluttering the Test.
- Keep the same export format between runs. CSV and JSON produce the same fields, but switching formats midstream makes reimport comparisons harder to read.
- Because the hash is title plus resource, renaming a resource in the cloud creates a new finding and mitigates the old one on reimport.
- Orca exports have no remediation text. Add notes or link Orca's guidance in the finding when you assign it, so the owner knows what to change.
- Use
minimum_severityor the connector's Minimum Severity to keep low-scoring informational alerts out of the triage queue. - If a connector sync fails to authenticate, confirm the Location host matches the token's region before regenerating the token.