All integrations

runZero Integration with DefectDojo

runZero Integration with DefectDojo

runZero, formerly known as Rumble, is an asset discovery and exposure management platform founded by HD Moore. It finds and fingerprints devices on a network through active scanning, passive discovery, and integrations with other systems, then organizes the results into an inventory with each asset's type, operating system, addresses, and services. runZero groups assets into sites and offers an Export API, which the DefectDojo Pro connector reads.

runZero Integration with DefectDojo

We rely on runZero to tell us what is actually on our networks, including the devices nobody registered. Connecting it to DefectDojo Pro means our vulnerability management hierarchy starts from that same inventory. The runZero connector creates a Record for every asset, groups them into Organizations by runZero site, and keeps the list reconciled with each sync. When we turn on vulnerability import, runZero's findings land on those same assets with CVE, CVSS, and service details, so the scanner results we already import from other tools have a place to go and the gaps in coverage are visible.

Why runZero Matters

Vulnerability programs fail quietly on the assets they do not know about. An inventory built from discovery, not from what people remembered to register, closes that gap.

  • runZero identifies devices by fingerprinting what it sees on the network, which catches unmanaged hardware, IoT, and operational technology that agent-based tools miss.
  • Its inventory carries type, OS, addresses, and tags per asset, which gives each DefectDojo Asset useful context from the start.
  • Sites reflect how networks are actually segmented, so grouping by site gives a sensible Organization structure.
  • Without a connector, a DefectDojo Asset list has to be maintained by hand and falls behind as soon as the network changes.

Advantages of This Integration

What the runZero connector does for a DefectDojo Pro instance:

  • Inventory-first hierarchy. Each runZero asset becomes a Record, and its site becomes its Organization, so DefectDojo's structure matches what runZero discovered.
  • Full reconciliation. Assets are synced from a full export that DefectDojo reconciles, adding new assets and flagging those that have disappeared. Removed assets are marked Missing for triage rather than silently deleted.
  • Context on every Record. The asset's site, type, OS, addresses, and tags are attached as attributes.
  • Optional vulnerability findings. With Import Vulnerabilities enabled, runZero vulnerabilities arrive as findings on their asset, carrying severity, CVSS score, CVE, the affected service, and remediation.
  • Severity floor for findings. A Minimum Severity setting limits which vulnerability findings are imported.
  • A home for other tools' data. Scanner imports and finding connectors can target the Assets runZero created, so findings from network scanners land on inventory items your team recognizes.

How This Integration Works

Connectors are part of DefectDojo Pro, and runZero has no DefectDojo file parser, so this connector is the supported path. runZero is primarily an asset connector, with findings import as an option.

1. Create an Export Token in runZero. In the runZero console, open Account, then API, and create an organization Export Token. It is prefixed XT, scoped to a single organization (the organization is encoded in the token), and read-only. DefectDojo sends it as a Bearer token and never logs it. The DefectDojo connector documentation notes that a community or starter tier of runZero is available.

2. Add the connector in DefectDojo Pro. Open Connect > Upstream in the Pro UI and find runZero under Available Connectors. The Asset filter in the page header will show it alongside other asset connectors. Click Add Configuration and enter:

  • Location: your runZero console URL, for example https://console.runzero.com. It must be HTTPS.
  • Secret: the Export Token.
  • Import Vulnerabilities (optional): set to true to also import vulnerabilities as findings. Leave blank to sync assets only.
  • Minimum Severity (optional): limits which vulnerability findings are imported. It applies only when vulnerabilities are imported.
  • Label: a name for this configuration.

Set the Discovery and Synchronization schedules (every 6, 12, or 24 hours), decide whether to enable Auto-Mapping, and submit.

3. Discover and map. Discover exports your organization's inventory and creates a Record for each asset. With Auto-Mapping on, DefectDojo creates or matches an Asset for each Record under the Organization for its site. Without it, Records wait in the Unmapped list for you to map or ignore.

4. Sync. Each Sync reconciles the asset list again. When vulnerability import is enabled, Sync also imports findings for mapped Records into the Global Connectors Engagement on each Asset, in a Test for this connector.

Data Granularity: What Gets Imported

DefectDojo Object or Field Source in runZero Notes
Record runZero asset One Record per asset in the organization's export
Record name Asset name or address Display name comes from the asset's name or address
Organization runZero site Each asset is grouped under its site
Record attributes Site, type, OS, addresses, tags Attached to the Record
Record state Presence in the full export Assets no longer exported are flagged Missing
Finding runZero vulnerability Only when Import Vulnerabilities is true
Finding severity runZero severity Filtered by Minimum Severity
Finding CVSS score runZero CVSS score Mapped onto the finding
Finding CVE runZero CVE Mapped onto the finding
Finding endpoint Affected service Formatted as protocol://address:port
Finding remediation runZero remediation Mapped onto the finding

Use Cases

Building the Asset list for a new deployment: A team starting with DefectDojo Pro connects runZero first, with vulnerability import off. Within one Discover run, DefectDojo has an Asset per discovered device, grouped by site, ready for scanner results to be mapped onto.

Finding coverage gaps: Assets created by runZero that never receive findings from any scanner are a quick way to spot hosts outside scan scope. The inventory makes the absence visible.

Tracking network exposure: With Import Vulnerabilities enabled, runZero's findings appear on each asset with the affected service as an endpoint, so exposed services on specific ports can be assigned, tracked against SLAs, and pushed to an issue tracker.

Handling decommissioned hardware: When a device drops out of the runZero export, its Record is flagged Missing. The team confirms the device is gone and deletes the Record, while any findings already recorded for it stay in DefectDojo as history.

Operational Tips

  • Start with assets only. Leave Import Vulnerabilities blank for the first few syncs so you can check the site-to-Organization structure before findings arrive.
  • Decide on Auto-Mapping with your inventory size in mind. One Record per asset with Auto-Mapping on means one DefectDojo Asset per device.
  • Use Ignored for asset classes you never want in DefectDojo, such as guest devices. Deleted Records come back on the next Discover if the asset is still exported.
  • Remember the token is organization-scoped. If you run several runZero organizations, add one connector configuration per token, each with its own label.
  • Minimum Severity affects vulnerability findings only. It does not filter which assets are synced.
  • Turn on the Connector Health Warning notification so an expired or revoked Export Token is reported instead of silently freezing the inventory.