Probely Integration with DefectDojo
Probely Integration with DefectDojo
Probely is a dynamic application security testing (DAST) scanner for web applications and APIs, founded in Porto, Portugal, and acquired by Snyk in November 2024. Snyk now lists it in its product lineup as Snyk API & Web. Probely crawls and tests running targets for vulnerabilities such as injection flaws, cross-site scripting, and security misconfigurations, and records each finding with a CVSS score, evidence, and fix guidance. Findings are available through the Probely REST API as JSON, which DefectDojo can import as a file or pull with the DefectDojo Pro connector.
Probely Integration with DefectDojo
We use Probely because it scans our web apps and APIs on a schedule without someone babysitting the crawler. The findings were good, but they lived in Probely's console while our SAST and SCA results lived in DefectDojo, and nobody had a single view of a service's risk. Bringing Probely findings into DefectDojo put them on the same Asset as everything else, with owners, SLAs, and Jira tickets. With the DefectDojo Pro connector, new findings arrive without anyone exporting anything.
Why Probely Matters
Static tools see code. DAST sees what an attacker sees: the deployed application, its configuration, and how it responds to hostile input.
- It tests running web applications and APIs, which catches issues introduced by deployment configuration that code scanning cannot see.
- Each finding includes evidence and the request details, such as the path, method, and parameter, which helps developers reproduce it.
- CVSS vectors and scores come with each finding, so severity is grounded in a standard model.
- Probely tracks a state per finding, including fixed, accepted, and retesting, which signals where remediation stands.
- Without a central platform, DAST results sit in a separate console from code and dependency findings for the same service.
Advantages of This Integration
What we gained by routing Probely findings through DefectDojo:
- File and API data agree. The parser mirrors the DefectDojo Pro connector field for field and uses the same scan type, so a team can upload exports today and enable the connector later without duplicating findings.
- Closed findings stay closed. Findings Probely marks as fixed, invalid, or accepted are not imported. Findings under retest are imported, because someone is still working them.
- Endpoint-aware deduplication. The parser records the scanned origin (scheme, host, and port) for every finding, and DefectDojo hashes on title, description, severity, vuln ID from tool, unique ID from tool, endpoints, CWE, and mitigation.
- CVSS carried through. The CVSS vector and score are stored on the Finding, along with a severity justification that states the score.
- Remediation workflow. Findings can be assigned, given SLAs, risk-accepted, marked false positive, or pushed to Jira alongside SAST and SCA results for the same Asset.
How This Integration Works
DefectDojo handles Probely data with the Probely API Import scan type. The name is the same for file imports and the connector, which is what lets the two deduplicate against each other.
Option 1: JSON file import (Community Edition and DefectDojo Pro). This route is for teams that cannot give DefectDojo Probely API credentials, for example on restricted networks or during a security review. Save the response from Probely's findings API endpoint for the target as a JSON file. The parser accepts the API's results envelope or a bare array of findings.
In the UI, open the Engagement, choose Import Scan Results, select Probely API Import, and upload the file. To automate it:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Probely API Import"
-F "file=@probely-findings.json"
-F "product_name=customer-portal"
-F "engagement_name=DAST"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Probely API Import"
--report-path "./probely-findings.json"
--product-name "customer-portal"
--engagement-name "DAST"
--auto-create-context
Reimport later exports into the same Test with /api/v2/reimport-scan/ so resolved findings are mitigated.
Option 2: Probely connector (DefectDojo Pro). The connector fetches findings from the Probely REST API. Configure it in the DefectDojo Pro UI with:
- The API server address for your region in the Location field, either
https://api.us.probely.com/orhttps://api.eu.probely.com/. - A valid Probely API key in the Secret field. API keys are created in Probely under the User menu, API Keys.
As with other DefectDojo Pro connectors, it syncs on a schedule and maps what it pulls to Records, which you link to the DefectDojo Assets that own each target.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Probely Finding | Notes |
|---|---|---|
| Title | definition.name |
The vulnerability definition's name |
| Severity | severity |
30 High, 20 Medium, 10 Low, anything else Info; there is no Critical |
| Severity Justification | severity, cvss_score, cvss_vector |
A sentence stating the severity and base CVSS score |
| Description | path, insertion point and parameter, method, definition.desc, evidence |
Insertion points rendered as labels such as "URL Query" |
| Mitigation | fix and extra |
Joined with a newline |
| CVSS v3 | cvss_vector, cvss_score |
Vector and score |
| CWE | definition.cwe_id |
Parsed when present; left at 0 otherwise |
| Endpoint | url |
Reduced to scheme, host, and port |
| Unique ID from Tool | id |
The Probely finding ID |
| Vuln ID from Tool | definition.id |
The vulnerability definition ID |
| Finding type | Dynamic | All Probely findings are dynamic |
| Deduplication | Hashcode | Title, description, severity, vuln ID, unique ID, endpoints, CWE, mitigation |
Findings with a state of fixed, invalid, or accepted are skipped.
Use Cases
For scheduled DAST: A team scans its staging and production web apps in Probely weekly. The DefectDojo Pro connector brings new findings onto each app's Asset, where they are assigned and tracked against SLAs next to SAST and SCA results.
On restricted networks: An organization that cannot let DefectDojo reach the Probely API exports findings to JSON, imports them by file, and switches to the connector later without duplicates because both use the same scan type.
For API security programs: API targets scanned by Probely land on the Asset for each API, so the API owner sees dynamic findings in the same queue as dependency and code issues.
When verifying fixes: After a fix ships and Probely confirms it, the next sync or reimport no longer includes the finding, and DefectDojo records the mitigation.
Operational Tips
- Plan for the missing Critical tier. Probely's highest severity maps to High, so set your High SLA with that in mind.
- Description and mitigation are part of the deduplication hash. If Probely's evidence or fix text changes for a finding, it can appear as a new Finding, so review new findings after a scanner update.
- Keep the scan type exact:
Probely API Import. It does not follow the naming pattern other connector scan types use, and a different name will not deduplicate against connector findings. - Pick the regional API host that matches your Probely account when configuring the connector.
- Use a dedicated Probely API key for DefectDojo so connector activity is easy to identify and the key can be rotated on its own.
- Findings under retest stay active in DefectDojo. Close them by letting the next sync or reimport reflect Probely's fixed state, not by editing them by hand.