# Events and Filters Reference

Look up every notification event, the name each one has in the rules list, and the filters each event offers with their values.

Source: https://docs.deepinfo.com/guide/notifications/events-and-filters/

Last updated: 2026-09-26

---
A notification rule reacts to one event. This page lists every event you can choose in the
**CREATE NEW NOTIFICATION RULE** popup, and the filters each one offers in the **Filters** step.

## Where to Find It

**Sidebar:** **NOTIFICATION CENTER** · [https://platform.deepinfo.com/app/platform/notification/rules](https://platform.deepinfo.com/app/platform/notification/rules)

Select **CREATE NEW RULE**. The events are the tiles under **NOTIFICATION TYPE** in step 1, **Event Type**.
The filters for the selected event are the chips in step 3, **Filters**. See
[Create a notification rule](/guide/notifications/create-a-rule/).

## Events

The groups below are this guide's, to make the list easier to scan; the popup shows the tiles in the same
order, without group names.

The **Event** column gives the tile name. The rules list (**SCOPE** column), the **TYPE** filter and the rule
drawer use the name in the second column. The **TYPE** filter shows it in capitals, for example
**NEW ASSET ADDED**.

### Assets Entering Your Inventory or Discovery

| Event | Name in the rules list | Filters |
|---|---|---|
| **New Asset Added** | **New Asset Added** | **Asset Type**, **Asset Tags**, **Creation Method** |
| **New Asset Discovered** | **New Asset Discovered** | **Asset Type**, **Rule**, **Rule Type** |

### Changes to Your Assets

| Event | Name in the rules list | Filters |
|---|---|---|
| **Whois Changed** | **Asset Whois Changed** | **Asset**, **Asset Type**, **Asset Tags**, **Whois Data Changes** |
| **DNS Changed** | **Asset DNS Changed** | **Asset**, **Asset Type**, **Asset Tags**, **DNS Data Changes** |
| **SSL Changed** | **Asset SSL Certificate Changed** | **Asset**, **Asset Type**, **Asset Tags**, **SSL Data Changes** |
| **New Open Port** | **New Open Port Detected** | **Asset**, **Asset Type**, **Asset Tags**, **Port Protocol**, **Port Number** |

### Issues and Vulnerabilities

| Event | Name in the rules list | Filters |
|---|---|---|
| **New Issue** | **New Issue Detected** | **Asset**, **Asset Tags**, **Asset Type**, **Severity** |
| **Issue Reappeared** | **Reappeared Issue Detected** | **Asset**, **Asset Tags**, **Asset Type**, **Severity** |
| **New Vulnerability** | **New Vulnerability Detected** | **Asset**, **Asset Tags**, **Asset Type**, **CVE ID**, **EPSS**, **Base Score**, **Base Severity** |
| **Vulnerability Reappeared** | **Reappeared Vulnerability Detected** | **Asset**, **Asset Tags**, **Asset Type**, **CVE ID**, **EPSS**, **Base Score**, **Base Severity** |

### Security Scores

| Event | Name in the rules list | Filters |
|---|---|---|
| **Asset Score Decreased** | **Asset Security Score Decreased** | **Asset**, **Asset Tags**, **Unit**, **By** |
| **Asset Score Changed** | **Asset Security Score Changed** | **Asset**, **Asset Type**, **Asset Tags**, **Score** |
| **Domain Score Decreased** | **Domain Security Score Decreased** | **Asset**, **Asset Tags**, **Unit**, **By** |
| **Domain Score Changed** | **Domain Security Score Changed** | **Asset**, **Asset Tags**, **Score** |

See [How security scores work](/guide/easm/security-score/).

### Lookalike Domains (Brand Risk Protection, BRP)

| Event | Name in the rules list | Filters |
|---|---|---|
| **New Suspicious Domain** | **New Suspicious Domain** | **Fraudulent Type**, **Rule** |
| **New Fraudulent Domain** | **New Fraudulent Domain Detected** | **Fraudulent Type**, **Rule** |

See [Review suspicious domains](/guide/brp/review-suspicious-domains/).

### Leaked Credentials (Cyber Threat Intelligence, CTI)

| Event | Name in the rules list | Filters |
|---|---|---|
| **New Employee Credential Detected** | **New Employee Credential Detected** | **Username Type** |
| **New Client Credential Detected** | **New Client Credential Detected** | **Username Type** |
| **New Payment Credential Detected** | **New Payment Credential Detected** | **Card Brand**, **BIN** |

See [Cyber Threat Intelligence (CTI)](/guide/cti/).

### Security News (CTI)

| Event | Name in the rules list | Filters |
|---|---|---|
| **New Cybersecurity News** | **New Cybersecurity News** | **Title**, **Source**, **Publish Date From**, **Publish Date To**, **Tags**, **Country**, **Industry**, **Organization**, **CVE Vendor**, **CVE Product**, **CVE ID**, **Featured**, **Threat Actor**, **Related Issue Types** |

## What Each Filter Takes

Every filter is optional. A filter you leave empty does not restrict the rule. To set one, open its chip,
choose a value and select **APPLY** (see
[Create a notification rule](/guide/notifications/create-a-rule/#set-a-filter)).

### Asset Filters

| Filter | Value |
|---|---|
| **Asset** | An asset from your inventory. |
| **Asset Type** | **Domain**, **Subdomain**, **IP Address** or **Website**. |
| **Asset Tags** | One or more of your asset tags. |
| **Creation Method** | How the asset entered your inventory: **Manually Added**, **Manually Approved** or **Auto Approved**. |

### Discovery Filters (New Asset Discovered)

| Filter | Value |
|---|---|
| **Rule Type** | **Smart Discovery**, **Smart Monitoring** or **Custom**. |
| **Rule** | The rule that discovered the asset: **Subdomain**, **Same Whois Registrant Email**, **Same Whois Registrant Email Apex**, **Same Whois Registrant Email Historical**, **Same Whois Registrant Organization**, **Same Whois Registrant Phone**, **Same Whois NS**, **Same DNS A**, **Same DNS NS**, **Same DNS MX**, **Same SSL Subject Organization**, **Same SSL Certificate**, **DNS A**, **DNS CNAME**, **SSL Certificate SAN** or **HTTP Redirection**. |

These are short names of Deepinfo's smart discovery and smart monitoring rules. See
[Review discovered assets](/guide/easm/discovery/).

### Change Filters (Whois, DNS and SSL Changed)

| Filter | Value |
|---|---|
| **Whois Data Changes** | The WHOIS fields whose change should trigger the rule, ticked in a list of fields, for example the registrar, the name servers or the expiry date. |
| **DNS Data Changes** | The DNS record fields whose change should trigger the rule, ticked in a list. |
| **SSL Data Changes** | The certificate fields whose change should trigger the rule, ticked in a list, for example the issuer or the validity end date. |

### Port Filters (New Open Port)

| Filter | Value |
|---|---|
| **Port Protocol** | **TCP**, **UDP** or both. |
| **Port Number** | One or more port numbers, from 1 to 65535. Use **+Add Value** for each extra port. |

### Issue and Vulnerability Filters

| Filter | Value |
|---|---|
| **Severity** | **Critical**, **High**, **Medium**, **Low** or **Information**. |
| **CVE ID** | A CVE ID. |
| **EPSS** | The CVE's EPSS value. |
| **Base Score** | The CVE's CVSS base score. |
| **Base Severity** | **Critical**, **High**, **Medium** or **Low**. |

### Score Filters

| Filter | Value |
|---|---|
| **Unit** | **Absolute** (the default) or **Percentage**. With **Absolute**, you are notified when the score falls below the value in **By**. With **Percentage**, you are notified when the score changes by the percentage in **By**. |
| **By** | The threshold. It starts at 800. |
| **Score** | A score range, **FROM** and **TO**. |

### BRP Filters

| Filter | Value |
|---|---|
| **Fraudulent Type** | **Domain** or **Subdomain**. |
| **Rule** | One of your BRP custom rules, the detection rule that found the domain. See [Set up detection rules](/guide/brp/detection-rules/). |

### Credential Filters

| Filter | Value |
|---|---|
| **Username Type** | **Email** or **Username**: whether the leaked login is an e-mail address or a user name. |
| **Card Brand** | **Visa**, **Mastercard**, **Amex**, **Discover** or **UnionPay**. |
| **BIN** | The card's bank identification number. |

### News Filters

**New Cybersecurity News** offers the filters **Title**, **Source**, **Publish Date From**,
**Publish Date To**, **Tags**, **Country**, **Industry**, **Organization**, **CVE Vendor**, **CVE Product**,
**CVE ID**, **Featured**, **Threat Actor** and **Related Issue Types**.

## How a Rule Shows Its Filters

Click a rule in the list to open its drawer. The **RULES** block lists each filter as a label and a value,
for example **SCORE UNIT:** and **BY:**, **FROM:** and **TO:**, or **EPSS SCORE:** and **BASE SCORE:**.
A rule without filters shows **-**. See
[Manage notification rules](/guide/notifications/manage-rules/#see-a-rules-settings).

## Good to Know

- **Filters cannot be changed after the rule is saved.** To change them, duplicate the rule. See
  [Manage notification rules](/guide/notifications/manage-rules/).
- **Every event has filters,** so the **Filters** step always appears in the popup.
- **Only e-mail is available** for every event.

## Do This With the API

- [Create a notification rule](/reference/platform/notification-rule-create/), where the event is the rule's
  `scope`
- [List sent notification e-mails](/reference/platform/notification-email-list/), which you can filter by event
