mitre / heimdall2

Heimdall Enterprise Server 2 lets you view, store, and compare automated security control scan results.
Other
204 stars 61 forks source link

Aquasec-trivy to HDF Converter #3506

Open georgedias opened 2 years ago

georgedias commented 2 years ago

Problem CReATE Aquasec Trivy scans not able to be convert to ASF format. The current Trivy to ASF is highly specialized for an AWS Security Finding Format and it is not recognizing the Aquasec Trivy format.

Solution Create a new HDF to Trivy to HDF converter that properly translates the Aquasec Trivy format output.

Impact to Workflow CReATE team are not able to automate pushing the scans to Heimdall.

Aquasec Trivy samples aquasec-trivy-scans.zip

georgedias commented 2 years ago

After deliberation on how to resolve this issue, decision was made that the best solution is to add a HDF template to the Aquasec-Trivy packages where the template is include with the Aquasec distribution package.