PTART Integration with DefectDojo
PTART Integration with DefectDojo
PTART (Pentest and Security Auditing Reporting Tool) is an open source reporting application developed by the Michelin CERT and published on GitHub as certmichelin/PTART. Penetration testers use it to record assessments and the individual findings ("hits") they produce, with severity, CVSS vectors, CWEs, remediation advice, screenshots, and attachments, and to run retest campaigns that record whether each finding was fixed. Reports can be exported from the PTART web interface as JSON.
PTART Integration with DefectDojo
Our testers write up engagements in PTART because it keeps evidence and remediation advice together while the work is happening. Once the report is done, we import the JSON export into DefectDojo so every hit becomes a Finding on the tested Asset, with the tester's CVSS vector, CWEs, screenshots, and fix complexity carried over. From there a pentest result gets an owner and an SLA like anything a scanner reports, and when the retest campaign finishes, its fix verdicts land in DefectDojo too.
Why PTART Matters
Manual testing finds the issues automation misses, but the output usually lives in a document that is hard to track once the engagement ends. PTART structures that output.
- Each hit is a discrete record with a severity, a CVSS vector, CWEs, and remediation text, not a paragraph in a PDF.
- Screenshots and attachments stay tied to the finding they prove.
- Retest campaigns record Fixed, Not Fixed, Partially Fixed, Not Applicable, or Not Tested per original hit.
- A report on its own still ends when the engagement ends. Nobody gets reminded that a High finding is past due.
Advantages of This Integration
What importing PTART into DefectDojo gives a security team:
- Pentest findings next to scanner findings. Hits land on the same Asset as SAST, SCA, and DAST results, so risk reporting covers manual testing too.
- Evidence preserved. Screenshots and attachments from each hit are imported as files on the Finding, so developers see the proof without opening another system.
- Scoring carried over. The tester's CVSS vector is parsed into the CVSS fields, and every listed CWE is stored, with the most specific one as the primary CWE.
- Retest results tracked. Retest hits linked to an original hit import as Findings titled with their fix status, so the outcome of the retest is visible in DefectDojo.
- Stable identity. Deduplication uses the PTART hit ID, so reimporting an updated report matches existing Findings instead of duplicating them.
- Engagement context. The Test is named after the report, and its description is built from the executive summary, engagement overview, and conclusion.
How This Integration Works
DefectDojo imports PTART exports with the PTART Report scan type.
1. Export the report. In the PTART web interface, export the report as JSON. The export includes the report metadata, every assessment with its hits, and any retest campaigns.
2. Import the file. In the UI, open the Engagement for the pentest, choose Import Scan Results, select PTART Report, and upload the JSON. To automate it with the API, available in Community Edition and DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=PTART Report"
-F "file=@ptart-report.json"
-F "product_name=customer-portal"
-F "engagement_name=2026 External Pentest"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "PTART Report"
--report-path "./ptart-report.json"
--product-name "customer-portal"
--engagement-name "2026 External Pentest"
--auto-create-context
3. Reimport after the retest. When the retest campaign is recorded in PTART, export again and reimport into the same Test. The parser merges assessments and retest campaigns from the file into one set of Findings, and the hit IDs keep the original findings matched.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in PTART Report | Notes |
|---|---|---|
| Title | Hit id and title |
ID: title; retest hits append the fix status, such as (Fixed) |
| Severity | Hit severity |
1 Critical, 2 High, 3 Medium, 4 Low, anything else Info |
| Description | Hit body |
Retest hits use the retest body |
| Mitigation | Hit remediation |
From the original hit for retests |
| Effort for Fixing | fix_complexity |
1 High, 2 Medium, 3 Low |
| CVSS | cvss_vector |
Parsed into the CVSS v3 or v4 fields |
| CWE | cwes |
All stored; the last (most specific) becomes the primary CWE |
| Component Name | Assessment title |
Retests use Retest: <campaign name> |
| Endpoint / Location | Hit asset |
https:// is added when no scheme is given |
| Files | screenshots, attachments |
Retest hits carry their own screenshots |
| References | references |
Each as name: url |
| Tags | labels |
For example OWASP Top 10 categories |
| Date | Hit added |
Retests use the campaign start date |
| Unique ID From Tool | Hit id |
Retest hits use the retest hit ID |
| Deduplication | Unique ID from tool | Algorithm configured for this scan type |
At the Test level, the report name becomes the Test title (with "Report" appended), and the executive summary, engagement overview, and conclusion form the Test description.
Use Cases
After an internal pentest: The CERT finishes an engagement in PTART and imports it into the Engagement for that application. Each hit is assigned to the owning team with an SLA based on its severity.
Running retests: Once fixes ship, testers run a retest campaign in PTART and reimport. Retest Findings titled Fixed or Not Fixed show leadership which issues were verified closed and which remain.
Audit evidence: Because screenshots, CVSS vectors, and remediation text travel with the Finding, an auditor can trace a pentest finding from discovery to verified fix without a separate document trail.
Combining manual and automated testing: Teams that also scan the same application with DAST tools can compare what the testers found against what scanners reported, all on one Asset.
Operational Tips
- Keep hit IDs stable in PTART. They drive deduplication, so a re-created hit with a new ID will import as a new Finding.
- Retest hits without a link to an original hit are skipped, so make sure every retest entry references the hit it verifies.
- Original hits and retest hits are separate Findings. Close the original in DefectDojo when the retest Finding says Fixed, or use your normal verification workflow.
- Use the imported labels as tags to filter by OWASP category or by whatever taxonomy your testers apply.
- Set SLAs per severity so pentest Findings follow the same timelines as scanner results.
- Large screenshots increase report size. If an import is slow, check how much image data the export carries.