Events and Filters Reference
A notification rule reacts to one event. This page lists every event you can choose in the CREATE NEW NOTIFICATION RULE popup, and the filters each one offers in the Filters step.
Where to Find It
Sidebar: NOTIFICATION CENTER · https://platform.deepinfo.com/app/platform/notification/rules
Select CREATE NEW RULE. The events are the tiles under NOTIFICATION TYPE in step 1, Event Type. The filters for the selected event are the chips in step 3, Filters. See Create a notification rule.
Events
The groups below are this guide's, to make the list easier to scan; the popup shows the tiles in the same order, without group names.
The Event column gives the tile name. The rules list (SCOPE column), the TYPE filter and the rule drawer use the name in the second column. The TYPE filter shows it in capitals, for example NEW ASSET ADDED.
Assets Entering Your Inventory or Discovery
| Event | Name in the rules list | Filters |
|---|---|---|
| New Asset Added | New Asset Added | Asset Type, Asset Tags, Creation Method |
| New Asset Discovered | New Asset Discovered | Asset Type, Rule, Rule Type |
Changes to Your Assets
| Event | Name in the rules list | Filters |
|---|---|---|
| Whois Changed | Asset Whois Changed | Asset, Asset Type, Asset Tags, Whois Data Changes |
| DNS Changed | Asset DNS Changed | Asset, Asset Type, Asset Tags, DNS Data Changes |
| SSL Changed | Asset SSL Certificate Changed | Asset, Asset Type, Asset Tags, SSL Data Changes |
| New Open Port | New Open Port Detected | Asset, Asset Type, Asset Tags, Port Protocol, Port Number |
Issues and Vulnerabilities
| Event | Name in the rules list | Filters |
|---|---|---|
| New Issue | New Issue Detected | Asset, Asset Tags, Asset Type, Severity |
| Issue Reappeared | Reappeared Issue Detected | Asset, Asset Tags, Asset Type, Severity |
| New Vulnerability | New Vulnerability Detected | Asset, Asset Tags, Asset Type, CVE ID, EPSS, Base Score, Base Severity |
| Vulnerability Reappeared | Reappeared Vulnerability Detected | Asset, Asset Tags, Asset Type, CVE ID, EPSS, Base Score, Base Severity |
Security Scores
| Event | Name in the rules list | Filters |
|---|---|---|
| Asset Score Decreased | Asset Security Score Decreased | Asset, Asset Tags, Unit, By |
| Asset Score Changed | Asset Security Score Changed | Asset, Asset Type, Asset Tags, Score |
| Domain Score Decreased | Domain Security Score Decreased | Asset, Asset Tags, Unit, By |
| Domain Score Changed | Domain Security Score Changed | Asset, Asset Tags, Score |
Lookalike Domains (Brand Risk Protection, BRP)
| Event | Name in the rules list | Filters |
|---|---|---|
| New Suspicious Domain | New Suspicious Domain | Fraudulent Type, Rule |
| New Fraudulent Domain | New Fraudulent Domain Detected | Fraudulent Type, Rule |
See Review suspicious domains.
Leaked Credentials (Cyber Threat Intelligence, CTI)
| Event | Name in the rules list | Filters |
|---|---|---|
| New Employee Credential Detected | New Employee Credential Detected | Username Type |
| New Client Credential Detected | New Client Credential Detected | Username Type |
| New Payment Credential Detected | New Payment Credential Detected | Card Brand, BIN |
See Cyber Threat Intelligence (CTI).
Security News (CTI)
| Event | Name in the rules list | Filters |
|---|---|---|
| New Cybersecurity News | New Cybersecurity News | Title, Source, Publish Date From, Publish Date To, Tags, Country, Industry, Organization, CVE Vendor, CVE Product, CVE ID, Featured, Threat Actor, Related Issue Types |
What Each Filter Takes
Every filter is optional. A filter you leave empty does not restrict the rule. To set one, open its chip, choose a value and select APPLY (see Create a notification rule).
Asset Filters
| Filter | Value |
|---|---|
| Asset | An asset from your inventory. |
| Asset Type | Domain, Subdomain, IP Address or Website. |
| Asset Tags | One or more of your asset tags. |
| Creation Method | How the asset entered your inventory: Manually Added, Manually Approved or Auto Approved. |
Discovery Filters (New Asset Discovered)
| Filter | Value |
|---|---|
| Rule Type | Smart Discovery, Smart Monitoring or Custom. |
| Rule | The rule that discovered the asset: Subdomain, Same Whois Registrant Email, Same Whois Registrant Email Apex, Same Whois Registrant Email Historical, Same Whois Registrant Organization, Same Whois Registrant Phone, Same Whois NS, Same DNS A, Same DNS NS, Same DNS MX, Same SSL Subject Organization, Same SSL Certificate, DNS A, DNS CNAME, SSL Certificate SAN or HTTP Redirection. |
These are short names of Deepinfo's smart discovery and smart monitoring rules. See Review discovered assets.
Change Filters (Whois, DNS and SSL Changed)
| Filter | Value |
|---|---|
| Whois Data Changes | The WHOIS fields whose change should trigger the rule, ticked in a list of fields, for example the registrar, the name servers or the expiry date. |
| DNS Data Changes | The DNS record fields whose change should trigger the rule, ticked in a list. |
| SSL Data Changes | The certificate fields whose change should trigger the rule, ticked in a list, for example the issuer or the validity end date. |
Port Filters (New Open Port)
| Filter | Value |
|---|---|
| Port Protocol | TCP, UDP or both. |
| Port Number | One or more port numbers, from 1 to 65535. Use +Add Value for each extra port. |
Issue and Vulnerability Filters
| Filter | Value |
|---|---|
| Severity | Critical, High, Medium, Low or Information. |
| CVE ID | A CVE ID. |
| EPSS | The CVE's EPSS value. |
| Base Score | The CVE's CVSS base score. |
| Base Severity | Critical, High, Medium or Low. |
Score Filters
| Filter | Value |
|---|---|
| Unit | Absolute (the default) or Percentage. With Absolute, you are notified when the score falls below the value in By. With Percentage, you are notified when the score changes by the percentage in By. |
| By | The threshold. It starts at 800. |
| Score | A score range, FROM and TO. |
BRP Filters
| Filter | Value |
|---|---|
| Fraudulent Type | Domain or Subdomain. |
| Rule | One of your BRP custom rules, the detection rule that found the domain. See Set up detection rules. |
Credential Filters
| Filter | Value |
|---|---|
| Username Type | Email or Username: whether the leaked login is an e-mail address or a user name. |
| Card Brand | Visa, Mastercard, Amex, Discover or UnionPay. |
| BIN | The card's bank identification number. |
News Filters
New Cybersecurity News offers the filters Title, Source, Publish Date From, Publish Date To, Tags, Country, Industry, Organization, CVE Vendor, CVE Product, CVE ID, Featured, Threat Actor and Related Issue Types.
How a Rule Shows Its Filters
Click a rule in the list to open its drawer. The RULES block lists each filter as a label and a value, for example SCORE UNIT: and BY:, FROM: and TO:, or EPSS SCORE: and BASE SCORE:. A rule without filters shows -. See Manage notification rules.
Good to Know
- Filters cannot be changed after the rule is saved. To change them, duplicate the rule. See Manage notification rules.
- Every event has filters, so the Filters step always appears in the popup.
- Only e-mail is available for every event.
Do This With the API
- Create a notification rule, where the event is the rule's
scope - List sent notification e-mails, which you can filter by event