DefectDojo integration
Send Konvu's triaged findings to DefectDojo with exploitability evidence.
Integration details
Primary category
AppSec Posture Management
Sync direction
DefectDojo ↔ Konvu
Findings are ingested from DefectDojo into Konvu. What Konvu writes back to DefectDojo depends on the integration.
Status
Coming soon
What is DefectDojo?
DefectDojo is an open-source vulnerability management platform that aggregates security tool output, deduplicates findings across scanners, tracks remediation metrics, and provides vulnerability lifecycle management.
Why connect DefectDojo to Konvu
- Konvu's triage layer adds exploitability analysis to DefectDojo's aggregated findings, clarifying which deduplicated vulnerabilities warrant action.
- Evidence trails enhance DefectDojo's metrics with proof of why findings were prioritized or dismissed for audit purposes.
- Combined workflow allows teams to use DefectDojo's deduplication while leveraging Konvu's deeper exploitability analysis.
How it works
Scan
DefectDojo produces findings from scans or assessments.
Ingest & enrich
Konvu ingests those findings and enriches them with code, configuration, and deployment context.
Assess exploitability
Konvu determines exploitability and recommended action with evidence attached.
Record decisions
Konvu records each verdict with its evidence. What it can write back to DefectDojo depends on the integration.
Quick setup
When DefectDojo is available, you’ll configure it from the integrations list in Konvu.
- 1Go to /configuration/integrations in Konvu and choose DefectDojo.
- 2Authorize access and confirm the data sources you want to sync.
- 3Save the configuration to start syncing.
Sync direction
DefectDojo ↔ Konvu
Findings are ingested from DefectDojo into Konvu. What Konvu writes back to DefectDojo depends on the integration.
Join the waitlist
We’ll let you know when the DefectDojo integration is ready. Leave your email to get updates.
More integrations
View allArnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Apiiro
Layer exploitability evidence onto Apiiro's risk-based code-to-cloud findings.
- ASPM
ArmorCode
Enrich ArmorCode's aggregated findings with Konvu's exploitability analysis.
- ASPM
Cycode
Augment Cycode's pipeline and posture findings with exploitability analysis.
- ASPM
JupiterOne
Connect JupiterOne asset relationships with Konvu's vulnerability exploitability analysis.
- ASPM
AWS Inspector
Check whether the vulnerabilities AWS Inspector finds in your ECR container images are exploitable.
- Cloud Security