Using ScanSuite

Working with scan results

Reading findings in DefectDojo and exporting them.

DefectDojo is an optional bug tracker. Most teams work findings entirely in ScanSuite's own Vulnerability Management, which has bug tracking built in. This chapter is for teams who also export classic-scanner results to DefectDojo and want to work them there — when results are exported, DefectDojo visualises findings, tracks them, gathers statistics, creates reports and integrates with issue trackers, read and processed in DefectDojo rather than in ScanSuite.

The AI-driven scans do not export to DefectDojo at all: AI Native SAST, dependency reachability, AI DAST and AI Pentest findings are managed in ScanSuite's own Vulnerability Management, with full bug tracking. Secrets and Hidden Paths results are held back by default given the nature of the data. Using DefectDojo means setting it up first — see Set up DefectDojo (Optional).

Opening the results

In ScanSuite, open the product from the Products page and click the DefectDojo pill under its name. The DefectDojo line under a product in the list, and the product in Scan History's Environment column, link to the same engagement:

ScanSuite product page with the DefectDojo pill
The DefectDojo pill on a product's page opens its engagement

You will be redirected to the DefectDojo instance. The first time, you will need to log in with the DefectDojo credentials — see Set up DefectDojo (Optional) for how to retrieve them.

Once logged in, the Product → Engagement view opens directly from the ScanSuite reference, so you do not need to search for it inside DefectDojo:

DefectDojo engagement
The engagement view in DefectDojo

Reading the findings

The engagement contains all successful scan exports, with the option to view a consolidated list of findings or the findings from each individual scan.

DefectDojo consolidated findings
Opening the consolidated view
DefectDojo findings list
All findings with their testing data

Click any finding for its details. These vary by scanner, but most provide the affected file and line number for static findings, the URL for dynamic ones, and further detail in the Description and Mitigation sections.

DefectDojo finding detail
An individual finding

Exporting

Findings can be exported as HTML or CSV:

DefectDojo export options
The HTML and CSV export controls

The HTML report presents all finding details in a scrollable form, which is often a better way to work through results than clicking each one individually.

Issue trackers

DefectDojo provides its own Jira integration for pushing findings into a remediation workflow. That is configured inside DefectDojo, not in ScanSuite.

To learn more about DefectDojo's functionality, settings and troubleshooting, refer to the official documentation.

Last reviewed 2026-09-25