Skip to content
Discussion options

You must be logged in to vote

Hi sorry forgot to answer, just stumbled over this question again.

I don't think there is a (open source) alternative to DefectDojo which comes close to the quality and level of integrations as Defect Dojo has when it comes to the vulnerability management.

The "main" alternative to DefectDojo in the secureCodeBox is Elasticsearch / Kibana. Which is pretty good to save and analyse a large number of infrastructure level findings (like network, ssh, tls scan results) as these are pretty reliable / the false positive rate is pretty low. You can scan your whole networks / infrastructure every day and dump all results into elasticseach and always just look at the results from the last 24hours.

W…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by rfelber
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants