Exposure Alerts

How to choose which risk exposures and port categories notify you, from Settings → Notifications.

Exposure Alerts

Exposure Alerts notifies when selected exposures are detected. The card copy is: Get notified when exposures are detected.

Edit requires manage-settings. It opens Exposure Alert Settings. Configuration is stored as one exposure_settings object.

Summary on the card

LineMeaning
Risk ExposuresEnabled risk types, or None. Count of types with notifications on.
Port CategoriesEnabled category names (first three, then +N more).
CustomShown only when custom ports or protocols exist.
Severity OverridesShown only when exposure-group severity overrides exist.

Risk exposures (opt-in)

NameMeaning
Web Logins (SSO)Login pages with an SSO provider (Okta, Azure AD, and similar).
Web Logins (Generic)Login forms without SSO — admin panels, basic auth.
LLM ChatbotsExposed AI/LLM endpoints (Ollama, OpenAI-compatible, and similar).
MCP ServersExposed Model Context Protocol servers.

Port categories

CategoryExamplesRecommended
Remote Access ServicesSSH, RDP, VNC, TelnetYes
Databases Exposed to InternetMySQL, PostgreSQL, MongoDB, Redis, MSSQL, Oracle, Elasticsearch, Cassandra, CouchDB, MemcachedYes
File Sharing & SMB ServicesSMB, NetBIOS, FTP, NFS, TFTPYes
Management InterfacesSSH, RDP, Telnet, SNMP, VNC, WinRM, IPMIYes
Telecom ProtocolsRADIUS, SIP, GTP, Diameter, SIGTRAN, H.323No

The modal also has Custom Ports and Custom Protocols (tag input plus a notify toggle per item) and per-group severity overrides: Exposure, Info, Low, Medium, High, Critical.