AppSecNews
ASPM Open source Established Verified profile

DefectDojo

by DefectDojo (originally an OWASP project)

An open source vulnerability management system that imports scanner output through a large parser library, deduplicates findings and tracks them to closure.

Visit defectdojo.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run DefectDojo in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What it does

DefectDojo is a Django application that acts as a central store for security findings. Its defining asset is the parser library: a long list of importers for scanner output formats covering SAST, DAST, SCA, container, cloud, network and mobile tools, plus generic CSV and JSON formats for anything unsupported. You push a scan report in through the UI, the API or a CI step, and it is normalized into a common finding model attached to a product and an engagement.

The important machinery is deduplication and reimport. Findings are matched across scans using configurable algorithms, so the same issue seen in fifty consecutive builds stays one record with a history rather than fifty. Reimport updates an existing test in place, closing fixed findings and opening new ones. Around that sit the workflow pieces: risk acceptance with expiry, false positive marking, SLA clocks, product hierarchies, Jira synchronization and metrics. It also models manual work, so penetration test results live in the same backlog as automated scans.

Where it fits

This is the security team's system of record, fed from CI and from manual testing. Developers rarely log into it, they see Jira tickets. It presumes you already have scanners producing output and a person willing to own configuration: product hierarchy, deduplication settings, SLA definitions and parser choices all need deliberate setup. Running it yourself means running a database, a queue and a web application.

Strengths

  • The parser catalog is broad enough that almost any tool you run can be ingested without custom work.
  • Deduplication and reimport semantics are well thought out and handle the repeated-scan problem properly.
  • Open source under a permissive license, so you can self-host, read the code, and keep your findings data entirely in your own environment.
  • Models manual testing engagements alongside automated scans, which most commercial aggregation tools handle poorly.

Limitations

  • The interface is dense and dated, with nested concepts (product types, products, engagements, tests, findings) to learn before it makes sense.
  • It aggregates and tracks but offers little prioritization intelligence. There is no reachability analysis or runtime context, so ranking comes down to what your scanners reported and what you configure.
  • Self-hosting, upgrades, database growth and parser breakage after scanner format changes are all yours to handle, and that load is not trivial at scale.

Who it suits

The default choice for teams that want vulnerability consolidation without a commercial contract and have the engineering capacity to run and tune it. It fits security functions valuing data ownership and extensibility over polish. It is a poor fit for teams wanting prioritization intelligence out of the box, or with no appetite to operate another stateful service.

Used DefectDojo? Recommend it under your own name and title.

Recommend this tool