All integrations

Ostorlab Integration with DefectDojo

Ostorlab Integration with DefectDojo

Ostorlab is a security testing platform that scans mobile applications, web targets, and network assets from one service. Mobile apps are analyzed from their packages, while web, domain, and network targets are tested as running systems, and each vulnerability carries a risk rating, a description, a recommendation, references, and location metadata. The company also maintains open source scanning tooling on GitHub. DefectDojo imports Ostorlab results from a JSON export of a scan, or through the DefectDojo Pro API connector.

Ostorlab Integration with DefectDojo

We use Ostorlab for both our mobile apps and our external web footprint, and DefectDojo is where those results get worked. Ostorlab's console is good at showing one scan. DefectDojo gives each finding an Asset, an owner, and an SLA, and decides per scan whether the work came from static or dynamic analysis. The file parser and the connector use the same scan type and the same finding identity, so we can start with exports and move to the API sync without creating duplicates.

Why Ostorlab Matters

Teams with mobile apps and public web services often end up with separate tools and separate backlogs for each. Ostorlab covers both classes of asset.

  • One platform scans Android and iOS apps, web applications, domains, and hosts.
  • Findings include a recommendation and references, so remediation guidance comes with each issue.
  • Location metadata records where in the target the issue was found, whether that's a URL, a file, or a code location.
  • Ostorlab reports passed checks too (rated SECURE), which helps coverage but has to be filtered before anything becomes a finding.

Advantages of This Integration

  • Passed checks stay out. Vulnerabilities rated SECURE are skipped, so a passing check never appears as a finding.
  • Static or dynamic by asset type. Mobile packages and uploaded files import as static findings, while web, network, and domain targets import as dynamic, decided from the scan's asset type.
  • CVE IDs pulled from the text. Ostorlab has no CVE field, so the parser extracts CVE, GHSA, GO, and RHSA identifiers from the technical detail, title, description, summary, and references, which makes these findings searchable by advisory.
  • File and API imports agree. Both paths use the Ostorlab Scan scan type and the identity ostorlab-<scan id>-<vulnerability id>, and deduplication checks that unique ID first.
  • Endpoints for web and network scans. The affected asset's name or host becomes a DefectDojo endpoint, so web findings are tied to the host they were found on.

How This Integration Works

DefectDojo imports Ostorlab data with the Ostorlab Scan scan type, from a file or through the API Connector (Pro).

1. Option A: export a scan to JSON. Ostorlab exposes scan results through its GraphQL API. Save the response for one scan, including the scan's id, assetType, and createdTime along with its vulnerabilities. In Ostorlab's response shape the vulnerabilities sit under a doubled key (vulnerabilities.vulnerabilities); unwrapped forms and a bare array of vulnerabilities are accepted too. Without the scan context, findings still import, but every finding is treated as dynamic and the identity uses scan 0.

2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select Ostorlab Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Ostorlab Scan" 
  -F "file=@ostorlab-scan.json" 
  -F "product_name=retail-android-app" 
  -F "engagement_name=Mobile Release 8.1" 
  -F "auto_create_context=true"

DefectDojo Pro users can use Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Ostorlab Scan" 
  --report-path "./ostorlab-scan.json" 
  --product-name "retail-android-app" 
  --engagement-name "Mobile Release 8.1" 
  --auto-create-context

3. Option B: connect the API (DefectDojo Pro). Create an Ostorlab API key under Settings, then API Keys. In the DefectDojo Pro connector, enter https://api.ostorlab.co as the Location (DefectDojo adds the GraphQL path itself) and the key in the API Key field, and optionally set a Minimum Severity. The connector creates one Record per scanned asset, which can be an app bundle ID, a domain, or a host, and imports vulnerabilities from every scan of that asset.

4. Keep each target in one place. For file imports, import each scan of the same target into the same Asset so results from successive scans can be compared.

Data Granularity: What Gets Imported

DefectDojo Field Source in Ostorlab Export Notes
Title detail.title Falls back to "Ostorlab finding" plus the vulnerability ID
Severity detail.riskRating CRITICAL, HIGH, MEDIUM, LOW map directly; POTENTIALLY is Low; HARDENING, IMPORTANT, INFO, unknown are Info
Description Description, short description, technical detail, location metadata Each metadata entry labeled with its own type
Mitigation detail.recommendation
CVSS v3 Vector detail.cvssV3Vector Vector only; Ostorlab provides no numeric score
References detail.references "title: url" per line
Vulnerability IDs Text of detail, title, description, summary, references CVE, GHSA, GO, RHSA; sorted
Vuln ID from Tool detail.title
Unique ID from Tool Scan ID and vulnerability ID ostorlab-<scan>-<vuln>
Endpoint Affected asset name or host Skipped for mobile scans and hosts DefectDojo can't accept
Date Scan createdTime
Tags Risk rating, asset type
Static / Dynamic Scan assetType Android, iOS, app, file, store types are static; others dynamic
Active Always true SECURE ratings are not imported
Deduplication Unique ID or hashcode Unique ID first, then title, severity, component name

Ostorlab reports no component, so the component name in the hash is always empty and the fallback hash is effectively title plus severity.

Use Cases

Mobile release checks: Each release build is scanned in Ostorlab and the export imported into the app's Asset. Static findings are tagged with the asset type, so the mobile team can filter to its own app's results and work them under the same SLAs as backend findings.

External web footprint: Scans of public domains and hosts import as dynamic findings with endpoints. A security engineer can look at a host in DefectDojo and see every Ostorlab finding against it, next to results from other web scanners.

Connector-based portfolio: A DefectDojo Pro customer with dozens of apps and domains connects Ostorlab through the API connector. Each scanned asset becomes a Record, and findings flow in on a schedule without anyone exporting files.

Advisory-driven response: When a new CVE is announced, the team searches DefectDojo by that ID. Because the parser pulls identifiers out of Ostorlab's text and references, matching Ostorlab findings show up in the search along with SCA results.

Operational Tips

  • Always include the scan object in exports. Without its asset type, mobile findings are recorded as dynamic, and without its ID every file shares scan 0 in its identities.
  • Identity includes the scan ID, so the same issue in two scans of an app is two records. Expect DefectDojo's hashcode fallback (title and severity) to do the matching across scans, and review duplicates after the first few imports.
  • Ostorlab's IMPORTANT rating imports as Info. If your team treats IMPORTANT as actionable, adjust severity on those findings or review the Info queue regularly.
  • POTENTIALLY means Ostorlab couldn't fully confirm the issue. Those import as Low, so verify them before assigning remediation.
  • Use minimum_severity or the connector's Minimum Severity to keep HARDENING and INFO items out of the main queue.
  • Keep mobile apps and web targets in separate Assets. Their remediation owners and SLA expectations usually differ.