Skip to content

Alerting

Every custom rule defines an alert: block describing how the finding will surface in the Escape platform. The schema is identical for API and WebApp rules.

Configure how the alert will be displayed in the Escape interface.

This block configures how your alert appears in the Escape interface. For example you can configure the severity of the alert: HIGH, MEDIUM, LOW or INFO.

Add context to explain why the alert was raised and why it matters.

alert:
  severity: HIGH
  name: Admin email changed
  context: |
    The admin email has been changed. The API shouldn't allow this change.
    For more information, please contact the security team.
  category: ACCESS_CONTROL

Properties

Required properties are marked with an asterisk.

Property Type Default Description
category CustomRuleCategory CUSTOM Category of the alert
compliance Compliance null Compliance standards violated by this alert
context* string Context of the alert
description string null Description of the alert
name* string Name of the alert
remediation string null Remediation of the alert
severity* CustomRuleSeverity Severity of the alert

CustomRuleSeverity

HIGH, MEDIUM, LOW, INFO

CustomRuleCategory

ACCESS_CONTROL, CONFIGURATION, INFORMATION_DISCLOSURE, INJECTION, PROTOCOL, REQUEST_FORGERY, RESOURCE_LIMITATION, SENSITIVE_DATA, SCHEMA, CUSTOM