Rapplex Integration with DefectDojo
Rapplex Integration with DefectDojo
Rapplex is a commercial web application security scanner that crawls a target website and tests it for vulnerabilities such as SQL injection and cross-site scripting. It is available as a cloud service or for on-premise use, with a plugin-based architecture and a Web API for managing scans programmatically. Each scan runs under a scan policy that sets crawl scope and the security checks applied per injection point, and results can be exported as a JSON report grouped by severity.
Rapplex Integration with DefectDojo
We run Rapplex against our web applications on a schedule, and we import every report into DefectDojo because a DAST finding is only useful if someone owns it until it is fixed. Each Rapplex issue becomes a Finding on the application's Asset, with the affected URL as an endpoint, the CWE from Rapplex's classification, the remediation guidance, and the exact HTTP request and response that proved it. When the next scan no longer reproduces an issue, reimporting closes it, and we keep the history of when it was found and fixed.
Why Rapplex Matters
Dynamic scanning tests the application as it actually runs, including configuration, frameworks, and the code paths a crawler can reach. It finds issues that only exist in the deployed system.
- Rapplex crawls and attacks the live application, so findings reflect behavior rather than code patterns.
- Each issue includes the request and response that triggered it, which makes reproduction straightforward.
- Issue definitions carry classifications such as CWE, OWASP, and PCI references, along with a summary and remediation section.
- Scan policies control scope and checks, so the same configuration can be rerun for comparable results.
- On its own, a scan report is a point-in-time list. It cannot tell you which issues were already accepted or are past their SLA.
Advantages of This Integration
What running Rapplex through DefectDojo gives us:
- Evidence attached to every Finding. The HTTP request and response from Rapplex are stored on the Finding, so a developer can see the proof without access to the scanner.
- Endpoints for each issue. The affected URL becomes an endpoint on the Finding, which shows where in the application an issue lives and how many places share it.
- CWE-based reporting. The CWE from Rapplex's classifications is mapped onto the Finding, so web findings can be reported alongside SAST results by weakness type.
- Deduplication across scans. DefectDojo hashes the title, endpoints, and severity, so the same issue at the same URL in the next scan matches the existing Finding.
- Lifecycle on reimport. Reimporting into the same Test mitigates issues that no longer appear and reactivates any that return.
- Standard workflow. Findings receive severity-based SLAs, owners, risk acceptance, and Jira tickets like any other result.
How This Integration Works
DefectDojo imports Rapplex reports with the Rapplex Scan scan type.
1. Export a JSON report. After a scan completes, export its report from Rapplex in JSON format. The report contains scan metadata (target, start date, scan policy) and a Severities object grouping issues under Critical, High, Medium, Low, and Information.
2. Import the file. In the UI, open the Engagement, choose Import Scan Results, select Rapplex Scan, and upload the report. Through the API, available in Community Edition and DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Rapplex Scan"
-F "file=@rapplex-report.json"
-F "product_name=customer-portal"
-F "engagement_name=Weekly DAST"
-F "auto_create_context=true"
DefectDojo Pro users can import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Rapplex Scan"
--report-path "./rapplex-report.json"
--product-name "customer-portal"
--engagement-name "Weekly DAST"
--auto-create-context
3. Reimport each scan. Send later reports for the same target to /api/v2/reimport-scan/ against the same Test, so findings move between active and mitigated as the application changes.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Rapplex Report | Notes |
|---|---|---|
| Title | Issue Title |
For example SQL Injection |
| Severity | Severity group Name |
Critical, High, Medium, Low map directly; Information becomes Info |
| Description | Definition Sections.Summary |
The issue summary from Rapplex |
| Mitigation | Definition Sections.Remediation |
Rapplex remediation guidance |
| References | Definition Sections.References |
Converted from HTML to text |
| CWE | Definition Classifications |
The entry whose foundation is CWE |
| Endpoint | Issue Url |
The affected URL |
| Request / Response | HttpRequest, HttpResponse |
Stored as the Finding's request and response pair |
| Date | Report StartedDate |
The scan start date |
| Active | Fixed | Imported as active |
| Deduplication | Hashcode | Title, endpoints, severity |
Other classifications in the report, such as OWASP, PCI, and WASC references, are not mapped to separate fields.
Use Cases
Scheduled DAST of production: A weekly Rapplex scan of a customer-facing site is reimported into one Test. New issues appear as new Findings with SLAs, and fixed ones are mitigated automatically.
Pre-release testing: A staging deployment is scanned before each release and imported into the release Engagement, giving the release owner a clear list of open web issues and their evidence.
Developer handoff: Instead of sharing scanner access, the security team assigns Findings in DefectDojo. Developers get the URL, the request and response, and the remediation text in one place.
Combined application view: Rapplex results sit on the same Asset as SAST and SCA findings, so CWE-based reporting shows whether a weakness found in code is also exploitable in the running application.
Operational Tips
- Keep the scan policy stable for a given target. Changing crawl scope or checks changes what is found and can look like a wave of new or fixed Findings.
- Severity is part of the dedupe hash. If Rapplex reclassifies an issue's severity between versions, it will import as a new Finding.
- The parser expects
StartedDatein Rapplex's day/month/year format. If you edit or generate reports by hand, keep that format. - Use
minimum_severity=Lowif Information-level issues add noise to the queue. - Treat stored HTTP responses as sensitive. They can include session data or application content, so limit access to the Asset accordingly.
- Tag imports with the environment (staging, production) when both are scanned into the same Asset.