Bring your Kenna findings to DefectDojo Pro

DefectDojo Pro works with Kenna Security (Cisco Vulnerability Management). Connect it with an API key and your open vulnerabilities, with their asset details, import into DefectDojo. The connector reads from your live Kenna tenant, so plan the move while you still have access.

What comes over

One record per risk meter

Each top-level Kenna risk meter becomes a DefectDojo record, so your data arrives split the way your team already splits it. Child meters are covered by their parent.

Every open vulnerability in the meter

Findings come through Kenna's asynchronous data export, so a large meter comes over whole instead of stopping at the search API's 100,000-result limit.

Asset context on each finding

The connector joins each vulnerability to its Kenna asset for hostname, IP address or URL.

No duplicates on re-sync

Kenna's vulnerability ID is stored as the finding's unique ID. Each sync updates the findings you already have, and findings that are no longer open in Kenna are closed.

Kenna's scoring, kept as context

Kenna's risk score, threat score and threat-intelligence flags are written to each finding's severity justification and tags. DefectDojo severity comes from the scanner severity Kenna normalizes, with CVSS as the fallback.

Triage decisions, kept visible

Vulnerabilities marked risk accepted or false positive in Kenna import as active findings tagged kenna-risk-accepted or kenna-false-positive, so your team can review them in DefectDojo.

What does not come over: closed vulnerabilities, Kenna's application security findings, and Kenna dashboards, reports or tickets. For those scanners, connect the tools directly using DefectDojo's 500+ integrations.

Setup

1

In Kenna

Create an API key under Settings > API Keys and note your API host. It matches the host you use to sign in to Kenna.

2

In DefectDojo Pro

Add the Kenna Security (Cisco Vulnerability Management) connector. Paste the API key, confirm the API host (the default is https://api.kennasecurity.com) and pick a minimum severity.

3

Discover

Discover your risk meters. DefectDojo lists each top-level meter as a record.

4

Map and sync

Map each record to a DefectDojo asset and run a sync. Later syncs keep the findings current until you switch your scanners over directly.

Why now

Cisco has published the end-of-life schedule for Cisco Vulnerability Management (formerly Kenna.VM, Kenna.VI and AppSec):

MilestoneDate
End-of-saleMarch 10, 2026
Last day to renew or change a subscriptionJune 11, 2026
Last date of supportJune 30, 2028

Source: Cisco end-of-life notice

The connector pulls from your live Kenna tenant through the Kenna API. Once your Kenna access ends, there is nothing left for it to read. Starting early also gives you time to run both tools side by side and connect your scanners to DefectDojo directly.

Pricing and next step

Pay as you go

$100/month plus $0.15 per finding processed. No annual commitment. Sensei AI billed per use.

Pre-pay annually

Pre-pay annually and save 48%+. Sensei AI included.

Community Edition

Community Edition, the open source platform that came out of the OWASP community, stays free.

FAQ

What do I need to connect Kenna?

A Kenna API key (Settings > API Keys) and your Kenna API host. The API host matches the host you sign in to. DefectDojo sends the key as Kenna's X-Risk-Token header.

Do closed or historical vulnerabilities come over?

No. The connector requests open vulnerabilities only. On each sync, findings that are no longer open in Kenna are closed in DefectDojo.

Does Kenna's risk score become my DefectDojo score?

No. Kenna's 0 to 100 risk score, threat score and threat-intelligence flags are kept on each finding as context in the severity justification and tags. Severity is set from the scanner severity Kenna normalizes, with CVSS v3 as the fallback, and DefectDojo Pro's own priority and risk triage applies from there.

What happens to findings marked risk accepted or false positive in Kenna?

They import as active findings with the tag kenna-risk-accepted or kenna-false-positive and a note in the severity justification. They stay visible so a decision reversed in Kenna is not hidden in DefectDojo.

What about child risk meters and overlapping meters?

Child meters are not separate records. Their assets are included in the parent meter's record. If an asset sits in two top-level meters, its vulnerabilities appear in both records.

What happens when our Kenna access ends?

Findings you have already imported stay in DefectDojo. The connector stops syncing because there is no tenant to read. Connect your scanners to DefectDojo directly (500+ integrations) before that date so new findings keep flowing.