As of 2.6+, you can create a new scanner source in order to upload vulnerability reports from other 3rd parties or non-natively-supported scanning tools. These require the use of the .threadfix file format in order to upload, but you must first create the scanner identifier in ThreadFix. If you don't create the scanner, you'll receive the following error when trying to upload a .threadfix file with an unknown source: "Could not determine the scan type.
"
The maximum number of custom scanners and Pen Test Teams is ten (10) total between the two.
To create a new scanner, follow the steps below:
- Go to Global → Administration → System Settings on the left sidebar
- From within the Scanner Settings tab, click the 'Create New Scanner' button
- Complete necessary details and click the "Create Scanner" button
- Log out and back in to ThreadFix...although the new scanner will not immediately appear be allowed for import, logging out and back in to ThreadFix will reflect that it is, in fact, allowed...you may now upload a .threadfix scan file with the new scanner as the source.