What are notifications?
Notifications let you receive alerts when scan results match specific conditions. Instead of checking every scan manually, you set up rules and only hear about what matters.How notifications work
1
Create a notification rule
Define what conditions should trigger an alert.
2
Choose a trigger type
Select what type of scan results to monitor (vulnerability, ports, scan status, etc.).
3
Set conditions
Specify the exact criteria (e.g., risk level is at least High).
4
Select destinations
Choose where to send the notification (email, Slack, webhook, etc.).
Trigger types
Notifications can be triggered based on different types of scan results:Condition examples
Vulnerability conditions
Scan status conditions
Port Scanner conditions
Subdomains conditions
URL Fuzzer conditions
Password Auditor conditions
Domains conditions
Technology conditions
Notification destinations
Send to your account email or custom addresses.
Slack
Send to a Slack channel.
Microsoft Teams
Send to a Teams channel via webhook.
Discord
Send to a Discord channel via webhook.
Webhook
Send to any HTTP endpoint.
Nucleus
Send findings to Nucleus for vulnerability management.
Creating a notification
1
Go to Notifications
Click Notifications in the sidebar.
2
Add a notification
Click Add and enter a name.
3
Select a trigger type
Choose what to monitor, for example, Vulnerability or Port Scanner.
4
Set conditions
Add one or more conditions, for example, Risk level is at least High.
5
Select destinations
Under Notification actions, choose where to send alerts: your default email, additional addresses, or an integration like Slack, Teams, Discord, Webhook, or Nucleus.
6
Save
Click Save. The notification activates immediately.
Workspace scope
Notifications are scoped to your current workspace. Each workspace can have its own set of notification rules. The notifications configured on this page are applied to all scans running in the current workspace, whether started manually, scheduled, or via API. A notification will be sent if a scan result matches any of the defined notification rules in the workspace.Enabling and disabling
You can enable or disable notifications without deleting them:- Enabled: Notification will trigger when conditions match
- Disabled: Notification is saved but won’t trigger
Diff notifications
Diff notifications alert you when results change from a previous scan:- New vulnerabilities: alert when new findings appear
- New ports: alert when new ports are discovered
- New subdomains: alert when new subdomains are found
Best practices
Start with high-severity alerts
Start with high-severity alerts
Begin by setting up notifications for critical and high severity findings. Add more granular rules as needed.
Use meaningful names
Use meaningful names
Name notifications descriptively, for example “Critical vulns - Production”.
Combine conditions wisely
Combine conditions wisely
Use multiple conditions to reduce noise. For example, “Risk level at least High” AND “Finding name contains SQL”.
Use diff notifications
Use diff notifications
For scheduled scans, use diff notifications to only alert on changes instead of every finding.