Alerts Overview
BreachSpider can send alerts when a newly published CVE matches your watchlist or your environments. This page describes exactly what the alert engine does today, so you know what to rely on and what to check yourself.
How Alerts Work
The alert engine runs every 15 minutes. On each run it looks at CVEs that BreachSpider first saw in the last 72 hours and that have a CVSS score, and sends an alert when one of them matches:
- A watchlist item (a vendor or product you watch) at or above the item's severity threshold, and with a CVSS score of at least 7.0. Watchlist options such as "known-exploited only" and "unpatched only" are applied.
- An asset in one of your environments, when the match is high confidence and the finding is not acknowledged.
Each CVE is alerted at most once per member per channel. A CVE that was already alerted is not sent again, even if its details change later.
What does not trigger an alert
Rely on the dashboard and the Strike List, not on alerts, for these:
- A CVE added to the CISA KEV catalog after BreachSpider first saw it. The known-exploited flag is synced daily and shown on the CVE and your findings, but it does not send a new alert.
- Changes to an existing CVE, such as a new public exploit, a higher EPSS score, or a new patch.
- CVEs first seen more than 72 hours before the run, including matches created later when you import or edit assets.
- CVEs without a CVSS score.
Alerts are a convenience, not a guarantee of notification. Review your findings regularly.
Where Alerts Are Delivered
| Destination | Status |
|---|---|
| Delivered. One summary email per run, listing the matching CVEs, sent to members with email alerts enabled. See Email Alerts. | |
| Webhooks | Delivered. Every active webhook in your organization receives each alert as a signed JSON cve.alert event. Discord webhook URLs receive a Discord-formatted message instead. See Webhooks. |
| Microsoft Teams, Slack, PagerDuty | Connections can be saved and tested, but the alert engine does not currently send alerts to them. |
| Jira, ServiceNow | Ticket rules can be saved and tested, but tickets are not created automatically. See Tickets. |
Alert rules and per-environment recipients can also be saved, but the alert engine does not currently apply them. Webhooks receive alerts for every environment, whatever environment a webhook is set to.
Configuring Alerts
Alert configuration is under Integrations in the left sidebar:
- Email: turn email alerts on or off for your account, and set watchlist severity thresholds.
- Webhooks: add, test, disable, and rotate the secret of outbound webhooks.
- Connections, Alert Rules, Recipients: can be configured and tested; see the status table above.
Testing
Connections, webhooks, and rules have a Test button that sends a sample message to the destination. A successful test confirms the destination is reachable. It does not mean the alert engine will deliver to that destination; see the status table above.