PingCastle Integration with DefectDojo
PingCastle Integration with DefectDojo
PingCastle is an Active Directory security assessment tool created by Vincent Le Toux and acquired by Netwrix in 2024. Its health check queries a domain and scores it against a set of risk rules grouped into categories such as stale objects, privileged accounts, trusts, and anomalies, and each triggered rule adds points to the domain's risk score. A health check produces an HTML report for people to read and an XML file with the same data, which DefectDojo imports. PingCastle Enterprise adds a reporting server that collects health check reports submitted by agents across many domains.
PingCastle Integration with DefectDojo
Active Directory is where an attacker goes after the first foothold, and most of what makes it dangerous is configuration we inherited: old delegation settings, admin accounts that never expire, a print spooler running on a domain controller. We run PingCastle because it finds those issues quickly and explains them well. What it does not do is track who fixed what. Importing PingCastle results into DefectDojo gives each triggered risk rule an owner, an SLA, and a place next to the rest of our infrastructure findings, and the DefectDojo Pro connector keeps every monitored domain current.
Why PingCastle Matters
Many Active Directory compromises lean on misconfigurations rather than unpatched software, and those misconfigurations rarely show up in a network vulnerability scan.
- It checks identity-layer risks such as privileged group membership, delegation, password policy, and legacy authentication settings.
- Each rule has a stable identifier, for example
A-DC-SpoolerorP-Delegated, and a rationale explaining what was found. - Domain controller details in the report, including names, IPs, and open RPC interfaces, show where a fix has to be applied.
- A risk score is a good headline for leadership, but it does not tell anyone which rules are still open or who is working them.
Advantages of This Integration
What we gained by routing PingCastle results through DefectDojo:
- Rules become trackable work. Each triggered risk rule is a Finding on the Asset for that domain, with assignment, notes, Jira push, and risk acceptance available.
- Severity that reflects context. Severity starts from the rule's PingCastle points and is raised one level when the rationale names a CVE, when the rule targets domain controllers, or when the category is Exposure.
- Endpoints that point at the right systems. Domain controller specific rules carry each controller's name and IPs as endpoints; other rules carry the domain FQDN.
- Extra detail where it helps. Coercion findings list the open RPC interfaces per domain controller, spooler findings note whether remote spooler exposure was detected, and password length findings include the GPO password policy that was observed.
- Lifecycle on rescans. Reimporting the next health check into the same Test mitigates rules that no longer trigger and adds new ones.
- Connector sync with DefectDojo Pro. The PingCastle connector reads the same health check risk rules from a PingCastle Enterprise reporting server, so file imports and connector findings stay consistent.
How This Integration Works
DefectDojo imports PingCastle results with the PingCastle scan type, which reads the health check XML export.
Option 1: XML file import (Community Edition and DefectDojo Pro).
1. Run a health check. From a domain-joined machine:
PingCastle.exe --healthcheck --server corp.example.com
Keep the XML file the health check writes for the domain. The HTML report is for reading; the XML is what DefectDojo parses.
2. Import the XML. In the UI, open the Engagement, choose Import Scan Results, select PingCastle, and upload the file. Through the API:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=PingCastle"
-F "file=@ad_hc_corp.example.com.xml"
-F "product_name=corp.example.com"
-F "engagement_name=AD Health Check"
-F "auto_create_context=true"
DefectDojo Pro users can use Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "PingCastle"
--report-path "./ad_hc_corp.example.com.xml"
--product-name "corp.example.com"
--engagement-name "AD Health Check"
--auto-create-context
3. Reimport each run. Send later health checks for the same domain to /api/v2/reimport-scan/ against the same Test.
Option 2: PingCastle connector (DefectDojo Pro). If you run PingCastle Enterprise, configure the connector with:
- The reporting server URL in the Location field, the same address your agents submit to with
--api-endpoint. - The PingCastle Enterprise API key in the Secret field, the same key your agents pass with
--api-key. - Optionally, a Minimum Severity.
DefectDojo creates a Record for each Active Directory domain the reporting server monitors, and that domain's latest health check supplies its findings. Map each Record to an Asset.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in PingCastle XML | Notes |
|---|---|---|
| Title | RiskId, Category, Model |
Formatted as [PingCastle] RiskId (Category/Model) |
| Severity | Points, plus context |
0 Info, 1 to 5 Low, 6 to 10 Medium, 11 to 15 High, over 15 Critical, then contextual bumps |
| Description | Domain, RiskId, category, model, points, Rationale |
Domain controller list added for DC rules; extra detail for coercion, spooler, and password length rules |
| Mitigation | Fixed text | "Review and remediate according to PingCastle recommendations." |
| Impact | Fixed text | "Risk identified by PingCastle HealthCheck." |
| Vuln ID from Tool | RiskId |
The PingCastle rule identifier |
| Vulnerability IDs | CVEs in Rationale |
Extracted when the rationale names a CVE |
| Endpoints | Domain controller names and IPs, or DomainFQDN |
DC names and IPs for DC-specific rules, domain FQDN otherwise |
| Date | GenerationDate |
The health check's generation time |
| Deduplication | Legacy algorithm | No per-parser setting; within one report, repeats of a RiskId are merged |
Use Cases
For an AD hardening program: A security team imports the first health check for each domain, assigns Privileged Accounts findings to the identity team and Anomalies findings to infrastructure, and reimports monthly to show the open rule count dropping.
Across many domains with DefectDojo Pro: An organization with PingCastle Enterprise agents in several forests uses the connector so every monitored domain has its own Record and Asset, and leadership sees open identity risk by domain in one report.
After an incident or audit finding: Teams prove that a specific rule, such as print spooler exposure on domain controllers, was remediated by showing the Finding's history from discovery to mitigation.
For coordinating change windows: Domain controller endpoints on each Finding tell the change advisory board exactly which servers a fix touches.
Operational Tips
- Use one Asset per Active Directory domain. Rules and endpoints are domain-specific, and mixing domains in one Test makes reimport results hard to read.
- The mitigation text is generic. Use the rule ID and rationale to look up PingCastle's own guidance for that rule before assigning the work.
- The contextual bumps can raise many domain controller rules by a level. Review severities on the first import and adjust SLAs or individual severities if needed.
- Risk-accept rules that reflect a deliberate design decision, such as an intentional trust, with an expiration date so they are reviewed again.
- Keep the XML from every run, not just the HTML. It is the only format the parser reads.
- For the connector, the API key is the same one agents use, so coordinate key rotation with whoever manages the PingCastle Enterprise agents.