What is DefectDojo?
DefectDojo is a security tool that automates application security vulnerability management. DefectDojo streamlines the application security testing process by offering features such as importing third party security findings, merging and de-duping, integration with Jira, templating, report generation and security metrics.
What does DefectDojo do?
While traceability and metrics are the ultimate end goal, DefectDojo is a bug tracker at its core. Taking advantage of DefectDojo’s Product:Engagement model, enables traceability among multiple projects and test cycles, and allows for fine-grained reporting.
How does DefectDojo work?
DefectDojo is based on a model that allows the ultimate flexibility in your test tracking needs.
- Working in DefectDojo starts with a
- Each Product Type can have one of more
- Each Product can have one or more
- Each Engagement can have one more
- Each Test can have one or more
The code is open source, and available on github.
A demo installation can be found over at PythonAnywhere.
Our documentation is organized in the following sections:
- About DefectDojo
- Getting Started
- Arachni Scanner
- AppSpider (Rapid7)
- Burp XML
- Contrast Scanner
- Dependency Check
- Generic Findings Import
- Nessus (Tenable)
- Nexpose XML 2.0 (Rapid7)
- Node Security Platform
- NPM Audit
- OpenVAS CSV
- PHP Symfony Security Checker
- SKF Scan
- SSL Labs
- Visual Code Grepper (VCG)
- Zed Attack Proxy
- Usage Examples
- Upgrading to DefectDojo Version 1.5.0
- Upgrading to DefectDojo Version 1.3.1
- Upgrading to DefectDojo Version 1.2.9
- Upgrading to DefectDojo Version 1.2.8
- Upgrading to DefectDojo Version 1.2.4
- Upgrading to DefectDojo Version 1.2.3
- July 6th 2017 - New location for system settings
- Upgrading to DefectDojo Version 1.2.2
- Upgrading to Django 1.1.5
- Upgrading to Django 1.11
- Running in Production