Triage findings

About Deduplication →

Deduplication fundamentals and key concepts

Asset Exposure →

How DefectDojo Pro records whether an asset is reachable from outside, whether a Finding is deployed in production, and how both adjust priority

Attaching Files →

Upload screenshots, reports, or other supporting files to a Finding, Engagement, or Test in DefectDojo OS

Attaching Files →

Upload screenshots, reports, or other supporting files to a Finding, Engagement, or Test in DefectDojo Pro

Bulk Editing Findings →

Apply metadata changes, tags, notes, and review to many Findings at once in the DefectDojo Pro UI

Creating Findings Manually →

Track vulnerability information without using a scan tool

CVSS Version Support →

Which CVSS versions DefectDojo stores, displays, and accepts on Findings

Dedupe Pools →

Group Assets so their Findings deduplicate against each other, per matching kind

Deduplication Tuning →

Configure how DefectDojo identifies and manages duplicate findings

Deduplication Tuning →

Configure deduplication in DefectDojo Open Source: algorithms, hash fields, endpoints, and service

Editing Findings →

Change a Finding’s Status, or add more metadata as you resolve an issue

Enabling Deduplication →

How to enable Deduplication at the Asset or Engagement level

EPSS / KEV →

How DefectDojo Pro enriches Findings with EPSS and CISA KEV data, when it syncs, and how it drives priority

Export Findings →

Export findings and engagements as CSV or Excel

False Positive History →

Automatically mark new Findings as false positive when a matching Finding was already triaged that way

Finding Status Definitions →

A quick reference to Finding status: Open, Verified, Accepted..

Global Component Deduplication →

Deduplicate Software Composition Analysis Findings by component name and version across all Assets

Global Locations Deduplication →

Deduplicate Findings by shared location (URL or dependency) across all Assets

Introduction to Findings →

The main workflow and vulnerability tracking system of DefectDojo

Location Drift Matching →

Track findings as their locations change across reimports: line shifts, file renames, URL moves, and dependency version bumps no longer close and recreate findings

Peer Review & Claiming →

Request a review from specific people, claim a review so others know it is being handled, and control who is eligible to be asked

Reachability →

How DefectDojo Pro records whether a Finding's vulnerable code is actually reachable, and how that verdict adjusts priority

Risk Acceptances →

Leveraging Risk Acceptances in DefectDojo OS

Risk Acceptances →

Leveraging Risk Acceptances in DefectDojo Pro

Root Cause Correlation →

Group Findings that share a root cause -- the same vulnerable component, CVE, infrastructure resource, or weakness at a URL -- so one fix can be traced to every Finding it resolves

Similar Findings →

Find related Findings on the View Finding page and manually link them as duplicates

Similar Findings →

Find related Findings on the View Finding page and manually link them as duplicates