django-DefectDojo icon indicating copy to clipboard operation
django-DefectDojo copied to clipboard

Wiz tool support (https://www.wiz.io/)

Open barucijah opened this issue 1 year ago • 1 comments

Is your feature request related to a problem? Please describe I would like to import my report from WIZ to the DefectDojo https://www.wiz.io/

Describe the solution you'd like Create a new feature that will support the WIZ tool. https://www.wiz.io/

Describe alternatives you've considered A clear and concise description of any alternative solutions or features you have considered. An alternative for the support of the new tools could be creating a feature that will enable users to define their template, something like a generic template which will match their tool report.

barucijah avatar Feb 21 '24 14:02 barucijah

@barucijah, could you please add an anonymized report example to be able to build the parser in DefectDojo?

manuel-sommer avatar Feb 21 '24 19:02 manuel-sommer

Hi @manuel-sommer, I was waiting for the report example. I have 2 types of reports standard format and one which uses OCSF format. Please feel free to use one of those one of those 2. Payment_Issues__OCSF_2024_03_01T14_40_51Z.csv Payment_Issues_2024_03_01T14_36_46Z.csv

barucijah avatar Mar 04 '24 10:03 barucijah

Hi @barucijah, just a question: Regarding the ocsf output. Does the parser save the output file format, or can you choose the file format? Then, it would be easier to distinguish between both file types.

manuel-sommer avatar Mar 04 '24 15:03 manuel-sommer

@barucijah , you can review the PR

manuel-sommer avatar Mar 04 '24 15:03 manuel-sommer

Hi @barucijah, just a question: Regarding the ocsf output. Does the parser save the output file format, or can you choose the file format? Then, it would be easier to distinguish between both file types.

I can choose the file format. image

barucijah avatar Mar 04 '24 15:03 barucijah

If you choose OCSF, then the file type is .ocsf or .csv (how you uploaded it)? Furthermore: It is a dynamic scanner, right?

manuel-sommer avatar Mar 04 '24 15:03 manuel-sommer

Both file types are in the .csv format. Yes, it is dynamic scanner.

barucijah avatar Mar 04 '24 15:03 barucijah

Ok, so you chose "Standard"

manuel-sommer avatar Mar 04 '24 15:03 manuel-sommer

It is up to you, which one you consider easier to parse. I am fine with both file formats, as the reports are giving similar results.

barucijah avatar Mar 04 '24 15:03 barucijah

Please close this issue as PR has been merged.

manuel-sommer avatar Apr 01 '24 12:04 manuel-sommer