Picus Security Integration with DefectDojo
Picus Security Integration with DefectDojo
Picus Security is a commercial Breach and Attack Simulation (BAS) platform. It runs simulated attack actions against an environment through agents and reports, for each action, whether existing security controls prevented it, logged it, and raised an alert. Simulations are grouped by attack vector such as Email, Endpoint, Network, and Web, and each action is mapped to MITRE ATT&CK tactics and techniques. Results can be exported from the Picus console as CSV or retrieved through the Picus REST API.
Picus Security Integration with DefectDojo
We run Picus to answer a question scanners cannot: if an attacker tried this technique today, would our controls stop it? The answer arrives as thousands of simulated actions, and the useful part is the small set that were not blocked. Importing Picus results into DefectDojo turns each unblocked action into an active Finding with an owner and an SLA, keeps the blocked ones as inactive history, and updates the status on the next run once a control starts doing its job.
Why Picus Security Matters
Security controls drift. A rule gets disabled during troubleshooting, an agent stops reporting, or a new technique slips past a signature nobody updated. BAS tests the controls themselves rather than the software behind them.
- Each simulated action reports prevention, logging, and alerting separately, so a team can tell whether a control failed to block, failed to record, or failed to notify.
- Actions are mapped to MITRE ATT&CK, which lets detection engineers talk about gaps in a shared vocabulary.
- Running simulations repeatedly shows whether controls hold up after configuration changes.
- Picus results describe control gaps, not code defects, so they need a different owner than scanner findings. Without tracking, a failed simulation is easy to note and hard to follow through on.
Advantages of This Integration
What changed when Picus results started landing in DefectDojo:
- Only open gaps are active. The parser sets a Finding active when the prevention result is "Not Blocked" and inactive otherwise, so the triage queue holds real control gaps while the full simulation history is preserved.
- Run-to-run continuity. Deduplication uses the Picus action ID, which stays the same across simulation runs. Reimporting the next run updates existing findings instead of duplicating them, so an action that becomes blocked is reflected on the original Finding.
- Remediation guidance on the Finding. The mitigation field carries a recommendation, the prevent, log, and alert results, and Picus links for mitigation guidance, detection content, payload output, and action logs when the export includes them.
- ATT&CK-based filtering. MITRE tactic, technique, sub-technique, and attack category become tags, so a detection team can pull every open gap for one technique.
- SLAs for control gaps. Severity comes from the threat's severity in Picus, so control gaps fall under the same SLA rules as other findings.
- API sync with DefectDojo Pro. The Picus Security connector pulls results directly from Picus, with no CSV exports.
How This Integration Works
DefectDojo imports Picus results with the PICUS Scan scan type.
Option 1: CSV import (Community Edition and DefectDojo Pro). In the Picus console, open the simulation whose results you want and export them as CSV. Picus exports one CSV per attack vector, all with the same columns, so the same scan type handles every file. If the export arrives as a ZIP or RAR archive, extract it first: DefectDojo imports one file at a time and does not unpack archives.
In the UI, open the Engagement, choose Import Scan Results, select PICUS Scan, and upload each CSV. To automate it:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=PICUS Scan"
-F "file=@picus-endpoint.csv"
-F "product_name=corp-endpoints"
-F "engagement_name=BAS Endpoint"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "PICUS Scan"
--report-path "./picus-endpoint.csv"
--product-name "corp-endpoints"
--engagement-name "BAS Endpoint"
--auto-create-context
After the next simulation run, reimport the new CSV into the same Test with /api/v2/reimport-scan/ so each action matches its earlier Finding.
Option 2: Picus Security connector (DefectDojo Pro). Configure the connector in the DefectDojo Pro UI:
- Enter
https://api.picussecurity.comin the Location field. - Paste a Picus REST API refresh token into the Refresh Token field. Generate it in the Picus app under Settings, Rest API Token. Use the six-month refresh token, not the two-hour access token, which will stop working the same day.
- Optionally, set a Minimum Severity.
DefectDojo creates one Record per Picus agent group, so each Record represents one environment under test, and its findings come from the most recent run of every simulation bound to that group. Map each Record to an Asset. The refresh token expires after six months and the connector cannot renew it, so schedule a rotation.
Data Granularity: What Gets Imported
The table describes the CSV import.
| DefectDojo Field | Source in Picus CSV | Notes |
|---|---|---|
| Title | threatName and actionName |
"threatName - actionName"; truncated at 500 characters |
| Severity | threatSeverity |
Critical, High, Medium, Low, Info; unrecognized values become Info |
| Active | threatPreventionResult |
Active only when "Not Blocked" |
| Description | Threat, action, category, MITRE, results, platforms, payload, IDs | Built as a Markdown table; empty fields omitted |
| Mitigation | Prevention, logging, alerting results, Picus links, signature | Recommendation plus control posture and triage references |
| Component Name | affectedProducts |
The affected product reported by the simulation |
| Vuln ID from Tool | actionId |
Stable across runs; drives deduplication |
| Vulnerability IDs | cve |
Comma-separated CVEs split into a list |
| CWE | cwe |
Set when the value is numeric |
| Tags | MITRE tactic, technique, sub-technique, attackCategory |
Added when present |
| Finding type | Dynamic | Simulation results reflect runtime behavior |
| Deduplication | Hashcode | Vuln ID from tool (the Picus action ID) |
Detection integration, protocol-level, file hash, and some signature columns stay in the CSV and are not mapped.
Use Cases
After control changes: A team rolls out a new EDR policy, reruns the Endpoint simulations, and reimports. Findings for actions that are now blocked go inactive, and the remaining active ones become the follow-up list for the endpoint team.
For detection engineering: Tags on MITRE technique let detection engineers filter active findings where prevention failed and alerting also failed, and push those to Jira as detection content work.
Across environments with DefectDojo Pro: Each Picus agent group maps to its own Asset through the connector, so security leaders can compare control coverage between, for example, headquarters and a regional office.
For audit evidence: Control validation results carry their discovery date, owner, and closure history in DefectDojo, which helps show that identified gaps were acted on.
Operational Tips
- Import each attack vector's CSV separately into its own Test. That keeps Email, Endpoint, Network, and Web results grouped and makes reimport matching clean.
- Keep different environments in different Assets, or enable
deduplication_on_engagement. The action ID is the only hash field, so the same action from two environments would otherwise match. - Severity reflects the threat scenario, not whether the action succeeded. Read severity together with the Active flag when prioritizing.
- Use the control posture block in the mitigation field to route work: a prevention failure belongs to the control owner, while a logging or alerting failure often belongs to the SOC.
- Rotate the connector's refresh token before its six-month expiry, and set a calendar reminder when you configure it.
- Use
minimum_severityon CSV imports, or the connector's Minimum Severity, if low-severity threat scenarios add noise.