All integrations

Threagile Integration with DefectDojo

Threagile is an open-source agile threat modeling toolkit that enables security teams and architects to model system architectures with assets, trust boundaries, and data flows in YAML format directly within IDEs, then automatically execute security risk rules and generate threat assessments with mitigation advice based on standard and custom security policies. The platform seamlessly integrates into DevSecOps workflows through command-line execution, Docker containers, or REST API interfaces to produce comprehensive threat analysis reports, risk tracking with current mitigation status, automated data-flow diagrams, and multiple output formats including PDF, Excel, and JSON for continuous threat modeling throughout the software development lifecycle.

Data Granularity: What Gets Imported

The following fields are captured from Threagile results and surfaced in DefectDojo findings:

FieldSourceNotes
TitleFinding name from the scanMatched to the tool's own naming
SeverityCritical / High / Medium / Low / InfoMapped from the tool's own severity scale
DescriptionFinding detail from the reportIncludes what the issue is and why it matters
MitigationRemediation guidanceWhere the tool provides it

Importing Into DefectDojo

Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:

{
  "scan_type": "Threagile",
  "engagement": "<engagement-id>",
  "file": "results.json"
}