Triage findings
Deduplication fundamentals and key concepts
How DefectDojo Pro records whether an asset is reachable from outside, whether a Finding is deployed in production, and how both adjust priority
Upload screenshots, reports, or other supporting files to a Finding, Engagement, or Test in DefectDojo OS
Upload screenshots, reports, or other supporting files to a Finding, Engagement, or Test in DefectDojo Pro
Apply metadata changes, tags, notes, and review to many Findings at once in the DefectDojo Pro UI
Track vulnerability information without using a scan tool
Which CVSS versions DefectDojo stores, displays, and accepts on Findings
Group Assets so their Findings deduplicate against each other, per matching kind
Configure how DefectDojo identifies and manages duplicate findings
Configure deduplication in DefectDojo Open Source: algorithms, hash fields, endpoints, and service
Change a Finding’s Status, or add more metadata as you resolve an issue
How to enable Deduplication at the Asset or Engagement level
How DefectDojo Pro enriches Findings with EPSS and CISA KEV data, when it syncs, and how it drives priority
Export findings and engagements as CSV or Excel
Automatically mark new Findings as false positive when a matching Finding was already triaged that way
A quick reference to Finding status: Open, Verified, Accepted..
Deduplicate Software Composition Analysis Findings by component name and version across all Assets
Deduplicate Findings by shared location (URL or dependency) across all Assets
The main workflow and vulnerability tracking system of DefectDojo
Track findings as their locations change across reimports: line shifts, file renames, URL moves, and dependency version bumps no longer close and recreate findings
Request a review from specific people, claim a review so others know it is being handled, and control who is eligible to be asked
How DefectDojo Pro records whether a Finding's vulnerable code is actually reachable, and how that verdict adjusts priority
Leveraging Risk Acceptances in DefectDojo OS
Leveraging Risk Acceptances in DefectDojo Pro
Group Findings that share a root cause -- the same vulnerable component, CVE, infrastructure resource, or weakness at a URL -- so one fix can be traced to every Finding it resolves
Find related Findings on the View Finding page and manually link them as duplicates
Find related Findings on the View Finding page and manually link them as duplicates