Wallarm Integration with DefectDojo
Wallarm Integration with DefectDojo
Wallarm is an API security platform that protects web applications and APIs and detects vulnerabilities in them. It observes live API traffic and validates suspected weaknesses against the running service, recording each vulnerability with its type, affected domain, method, path, parameter, and a threat level. DefectDojo reads Wallarm vulnerabilities from a JSON export of the vulnerabilities API response, and DefectDojo Pro can also sync them through an API connector.
Wallarm Integration with DefectDojo
We run Wallarm in front of our public APIs, and it finds real issues in traffic that our pre-release scanners never exercise. The trouble was that those vulnerabilities stayed in the Wallarm console while every other application finding was tracked in DefectDojo. Importing Wallarm data puts API vulnerabilities on the right Asset with the affected domain as an endpoint, a severity that follows Wallarm's threat level, and the same SLA and ticketing rules as the rest of our backlog.
Why Wallarm Matters
API weaknesses often show up only when real clients use real endpoints, which is where Wallarm watches.
- It sees production API traffic, including endpoints that are undocumented or forgotten.
- It validates vulnerabilities against the running service, so findings reflect behavior rather than code patterns.
- It records the domain, method, path, and parameter for each issue, which tells developers exactly where to look.
- It keeps its own status for each vulnerability, including closed and false positive.
Advantages of This Integration
Running Wallarm vulnerabilities through DefectDojo gives you:
- Only actionable rows. Vulnerabilities Wallarm already marks
closedorfalsepositiveare skipped on import. Everything else is imported, including rows with no status. - Severity from either threat format. Wallarm sends the threat level as a number or a word depending on which API answered. DefectDojo handles both, so nothing silently drops to Info.
- Endpoints you can filter on. The affected domain becomes an endpoint, with the path appended when Wallarm reports an absolute one.
- CVE extraction. CVE, GHSA, GO, and RHSA identifiers found in the title, type, template, description, and additional text are pulled into vulnerability IDs.
- File and connector deduplicate. The parser mirrors the DefectDojo Pro connector and uses the same scan type, so moving from file exports to the connector does not create duplicates.
- Shared workflow. API vulnerabilities get SLAs, owners, Jira tickets, and reporting alongside SAST and DAST results.
How This Integration Works
DefectDojo supports Wallarm with the Wallarm API Security scan type, by file (UI Import, API Import, Universal Importer in DefectDojo Pro) or through the DefectDojo Pro API connector.
1. Get a vulnerabilities export. The parser reads the JSON response of Wallarm's vulnerabilities endpoint (/v1/objects/vuln), with rows under body. A bare array of rows also works. Save the response to a file from a host that can reach your Wallarm cloud. This route is meant for environments that cannot grant Wallarm API credentials to DefectDojo.
2. Import the file. In the UI, open an Engagement, choose Import Scan Results, select Wallarm API Security, and upload the JSON. Through the API, in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Wallarm API Security"
-F "file=@wallarm-vulns.json"
-F "product_name=public-api"
-F "engagement_name=Runtime API Security"
-F "auto_create_context=true"
With Universal Importer in DefectDojo Pro:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Wallarm API Security"
--report-path "./wallarm-vulns.json"
--product-name "public-api"
--engagement-name "Runtime API Security"
--auto-create-context
3. Or use the connector (DefectDojo Pro). Create an API token in Wallarm under Console, Settings, API tokens. A Read Only role is sufficient. In the DefectDojo Pro UI, add the Wallarm connector, enter your Wallarm cloud URL in Location (the EU or US cloud API host), paste the token into API Token, and optionally set a Minimum Severity. Each affected domain becomes a Record carrying the API security vulnerabilities that affect it.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Wallarm Export | Notes |
|---|---|---|
| Title | title |
Falls back to "Wallarm: type", then the vulnerability ID |
| Severity | threat |
Numeric: 5 or more Critical, 4 High, 3 Medium, 2 Low, 1 or 0 Info. Words map directly; unknown becomes Info |
| Description | Location and prose fields | Type, domain, method, path, parameter, detection method, then description and additional text |
| Mitigation | exploit_example |
Wallarm's reproduction example, not remediation advice |
| Endpoint | domain and path |
Path appended only when it starts with a slash |
| Date | validate_time |
Unix seconds; absent leaves the default date |
| Vulnerability IDs | Text fields | Identifiers extracted, sorted, case-insensitive duplicates dropped |
| Vuln ID from Tool | type |
Wallarm's vulnerability type |
| Unique ID from Tool | id |
wallarm-<id>, falling back to wid, then domain plus path |
| Tags | type, status |
|
| Finding type | Dynamic | Active, observed against the running service |
| Deduplication | Unique ID or hashcode | Unique ID from tool, falling back to title, severity, component_name |
The parser does not set a component, so the hashcode fallback in practice compares title and severity. The unique ID is what normally matches findings across imports.
Use Cases
Runtime findings next to pre-release scans: A team running SAST and DAST in CI also imports Wallarm. When a production API issue appears, it lands in the same Asset as the code findings, and engineers can see whether earlier testing missed it.
Ownership by domain: Each Wallarm domain maps to the team that runs it. Importing into per-domain Assets, or using the connector's per-domain Records, sends API vulnerabilities to the people who can fix them.
Restricted environments: Where DefectDojo cannot hold Wallarm credentials, a scheduled job saves the vulnerabilities response and uploads it. The findings match what the connector would create.
API risk reporting: Security leadership tracks open API vulnerabilities by severity and age, using the same metrics and SLA views as other application findings.
Operational Tips
- Confirm the numeric threat ladder against your tenant. DefectDojo treats 5 as most severe, mirroring the connector, and the DefectDojo docs note this is worth checking against live data.
- Treat Mitigation as a reproduction aid. It holds Wallarm's exploit example, so route remediation guidance through notes or your Jira template.
- Close or mark false positives in Wallarm when you can. Those rows are skipped on the next import, keeping both systems in agreement.
- A Wallarm
paththat is not absolute is a parameter location, not a URL path. It stays in the description but is left out of the endpoint. - Rows without an
idorwidfall back to domain plus path for identity, so two vulnerability types on one path can collide. Prefer exports that include IDs. - If you use both the file route and the connector, send both to the same Asset so their findings deduplicate.