Uptycs Integration with DefectDojo
Uptycs Integration with DefectDojo
Uptycs is a security platform from Uptycs Inc. that collects osquery-based telemetry from endpoints, servers, containers, and cloud workloads and makes it queryable through a SQL-style query engine. Among its capabilities is vulnerability detection for installed packages, reported per host with the affected package, version, CVE list, CVSS score, operating system, and asset group. DefectDojo can pull that data through the DefectDojo Pro Uptycs connector, or import it from a JSON export of the vulnerabilities query.
Uptycs Integration with DefectDojo
Uptycs already tells us which hosts carry vulnerable packages. DefectDojo is where that list gets owners, SLAs, and history, alongside the findings from our application and container scanners. The Uptycs data arrives as one Finding per CVE per host, graded from Uptycs's CVSS score and tagged with the host's operating system and asset group. We run the DefectDojo Pro connector where we can grant API credentials, and import a JSON export in the one network where we cannot. Both paths use the same Uptycs Scan scan type and the same finding identity, so the two sources deduplicate against each other instead of producing duplicate copies.
Why Uptycs Matters
Host vulnerability data is only useful if it reaches the people who patch hosts. Uptycs gives broad visibility into installed software across a mixed fleet.
- Its osquery-based agent sees installed packages on each host, which is the basis for matching CVEs.
- Results are organized by asset group, which usually lines up with the teams or environments that own the machines.
- Each vulnerable package row lists every CVE that affects it, with a CVSS score for prioritization.
- The same platform covers endpoints, servers, and cloud workloads, so one feed spans much of the infrastructure estate.
Advantages of This Integration
- One Finding per CVE per host. Uptycs reports one row per vulnerable package. DefectDojo splits that row into a Finding for each CVE, because each is separately fixable and triaged. A row with no CVE still becomes one package Finding.
- Hosts stay separate. The unique ID is
uptycs-<asset id>-<package>-<CVE>, so the same CVE on two machines remains two Findings: two hosts to patch. - Connector and file imports agree. File imports mirror the connector's finding conversion and use the same scan type, so data from either path deduplicates against the other.
- Severity from CVSS. Uptycs sends a score but no severity word, so DefectDojo applies standard CVSS bands, and SLAs follow from there.
- Fleet filtering with tags. Each Finding is tagged with the host's OS and asset group, which makes per-environment reports and SLA views straightforward.
- Records per asset group. The connector creates a Record for each Uptycs asset group, so ownership in DefectDojo can follow your Uptycs grouping.
How This Integration Works
Uptycs data comes in under the Uptycs Scan scan type, either from the connector or from a file.
Option 1: DefectDojo Pro connector. Configure the Uptycs connector in the DefectDojo Pro UI. You need three values from Uptycs: your customer ID (shown in the API key file), an API key ID (from Configuration, User, API Keys), and the matching API secret, which DefectDojo uses to sign a token for each request and never logs.
- Enter your Uptycs stack URL in Location, for example
https://your-stack.uptycs.io. - Enter the customer ID in Customer ID, the API key ID in Key, and the secret in Secret.
- Optionally set a Minimum Severity to limit which findings are imported.
The connector syncs on a schedule, reading vulnerabilities through the Uptycs query engine, and creates a Record for each asset group. The imported set is whatever that query returns for your tenant.
Option 2: Import a JSON export. For environments that cannot grant Uptycs API credentials, such as air-gapped networks or teams waiting on a security review, save the response of the Uptycs vulnerabilities query as a JSON file. The parser expects an object with an items list; a bare array, or an object with rows, data, or results, also works. Then import it in the UI (Import Scan Results, Uptycs Scan) or through the API, available in Community Edition and DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Uptycs Scan"
-F "file=@uptycs-vulns.json"
-F "product_name=linux-fleet"
-F "engagement_name=Host Vulnerabilities"
-F "auto_create_context=true"
DefectDojo Pro users can use Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Uptycs Scan"
--report-path "./uptycs-vulns.json"
--product-name "linux-fleet"
--engagement-name "Host Vulnerabilities"
--auto-create-context
For recurring exports, reimport to /api/v2/reimport-scan/ against the same Test so patched CVEs are mitigated.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Uptycs Data | Notes |
|---|---|---|
| Title | CVE and package_name |
<CVE> in <package>, or Vulnerable package <package> with no CVE |
| Severity | cvss_score |
9 or more Critical, 7 High, 4 Medium, above 0 Low, unscored Info |
| CVSS v3 Score | cvss_score |
Quoted scores are accepted |
| Description | Row details | Package and version, host, OS, asset group, and other CVEs when the row lists several |
| Component Name / Version | package_name, package_version |
The vulnerable package |
| Vulnerability IDs | cve_list |
One CVE per Finding; array or comma-separated string |
| Vulnerability ID from tool | CVE | Set when the row names a CVE |
| Unique ID from tool | Asset ID, package, CVE | uptycs-<asset id>-<package>-<CVE> |
| Tags | os, upt_asset_group_name |
For filtering a fleet |
| Records (connector) | Asset groups | One Record per asset group |
| Finding type | Static | Installed package inventory, nothing exercised |
| Deduplication | Unique ID from tool or hashcode | Hashcode fields: title, severity, Component Name |
Use Cases
Patch SLA tracking: An infrastructure team lets the connector sync Uptycs on its schedule. Each host's CVEs become Findings with SLAs by severity, and reimports or syncs mitigate them as packages are patched, giving a measurable time to remediate per asset group.
Air-gapped environments: A regulated network exports the Uptycs vulnerabilities query to JSON and imports it through the UI or API. Because file and connector findings share a scan type and identity, those hosts can move to the connector later and their Findings deduplicate rather than doubling up.
Fleet reporting: Tags for OS and asset group let security leads report open Critical and High CVEs by environment, such as production Linux versus developer laptops.
One view per service: Host CVEs sit beside container, code, and dependency findings for the same Asset, so an application owner sees the whole stack in one place.
Operational Tips
- All CVEs split from one Uptycs row share that row's severity, because Uptycs provides one CVSS score per package row, not per CVE. Review individual CVEs if exact grading matters.
- Rows with an empty or missing CVSS score import as Info. If many appear, check the query that produced the export before trusting severity counts.
- Use the connector's Minimum Severity, or
minimum_severityon file imports, to keep low-scored package findings out if they would swamp the queue. - Pick one path per environment where you can. Both paths deduplicate, but a single source keeps sync timing and history simple to explain.
- Filter by the asset group tag to assign findings to the team that owns those hosts.
- A row with no package name and no CVE produces the title
Vulnerable package package. Treat those as a data quality issue in the export.