Alerting¶
Every custom rule defines an alert: block describing how the
finding will surface in the Escape platform. The schema is
identical for API and WebApp rules.
Configure how the alert will be displayed in the Escape interface.
This block configures how your alert appears in the Escape interface.
For example you can configure the severity of the alert: HIGH, MEDIUM, LOW or INFO.
Add context to explain why the alert was raised and why it matters.
alert:
severity: HIGH
name: Admin email changed
context: |
The admin email has been changed. The API shouldn't allow this change.
For more information, please contact the security team.
category: ACCESS_CONTROL
Properties¶
Required properties are marked with an asterisk.
| Property | Type | Default | Description |
|---|---|---|---|
category |
CustomRuleCategory |
CUSTOM |
Category of the alert |
compliance |
Compliance |
null |
Compliance standards violated by this alert |
context* |
string |
Context of the alert | |
description |
string |
null |
Description of the alert |
name* |
string |
Name of the alert | |
remediation |
string |
null |
Remediation of the alert |
severity* |
CustomRuleSeverity |
Severity of the alert |
CustomRuleSeverity¶
HIGH, MEDIUM, LOW, INFO
CustomRuleCategory¶
ACCESS_CONTROL, CONFIGURATION, INFORMATION_DISCLOSURE, INJECTION, PROTOCOL, REQUEST_FORGERY, RESOURCE_LIMITATION, SENSITIVE_DATA, SCHEMA, CUSTOM