DefectDojo
Leading open source vulnerability management and Application Security posture platform.
Why consider DefectDojo?
DefectDojo is an open-source Application Security (AppSec) orchestration and vulnerability management platform written in Python and Django by OWASP. DefectDojo consolidates findings from over 150 security scanners (SAST, DAST, SCA), deduplicating issues and tracking remediation SLAs.
Learn DefectDojo by building
Practical setup notes, real use cases, and copy-ready examples in one focused guide.
In this guide2 sections
Overview of DefectDojo
DefectDojo correlates vulnerability reports across automated CI/CD pipeline scans and penetration tests.
Docker Quickstart
./dc-up-d.shDefectDojo is licensed under the BSD-3-Clause License.
Related tools
More options with a similar category or technology profile.
boringproxy
Simple, self-hosted reverse proxy and tunnel manager for exposing private web services securely.
OWASP ModSecurity
Open-source Web Application Firewall (WAF) engine providing cross-platform HTTP security inspection.
OpenCTI
Open-source platform for managing cyber threat intelligence knowledge and STIX2 relationships.
Maltrail
Malicious traffic detection system utilizing public blacklists and heuristic traffic behavior analysis.