Set up Alerts

Alerts let Method notify an external system when something happens in the platform, such as a new Finding being created or a Target reaching a given stage.

An Alert has two parts:

  • External channel: the destination an Alert is sent to. Method supports Microsoft Teams, Slack, and generic HTTP webhooks.
  • Alert rule: the condition that fires an Alert and the channel it notifies. You add rules after connecting at least one channel.

Open Alerts

In the Admin panel, open Alerts under the Setup group. The page has two sections: External channels, where you configure destinations, and Alert rules, where you define what triggers an Alert. Until you connect a channel, the Alert rules section prompts you to add one first.

The Admin navigation menu with Alerts selected under the Setup group, alongside Seed Data, Cloud, and Integrations
Opening Alerts from the Admin menu

Choose a channel type

Connect at least one external channel, then add Alert rules that route to it. Each channel type has its own setup:


Create an Alert rule

Once a channel is connected, go to Alert rules and click New. In Configure Alert, pick the event the rule fires on, set its criteria, and click Save. Method supports two event types.

Animated walkthrough of the Alerts page: clicking New under Alert rules, configuring the criteria in the Configure Alert form, and saving the rule
Creating an Alert rule from the Alerts page

Targeting stages

Fire an Alert when a Target reaches a stage:

  1. Select a stage (Targeted, Researched, Exploited, or Remediated), several stages, or all stages.
  2. Select an Environment, several Environments, or all Environments.
  3. Select the channel that receives the Alert.
A saved Alert rule reading Send Alert when a target reaches Exploited in All Environments to Cyber Security Team Channel, routed to a Slack channel, under the Alert rules section
A saved Target-stage Alert rule routed to a channel

New Findings

Fire an Alert when a new Finding is created:

  1. Select a Finding type, several Finding types, or all Finding types.
  2. Select an Environment, several Environments, or all Environments.
  3. Select a severity, or receive all severities.
  4. Select the channel that receives the Alert.
A saved Alert rule reading Send Alert for new Findings of Cloud Bucket in All Environments of CRITICAL to Cyber Security Team Channel, routed to a Slack channel, under the Alert rules section
A saved New Findings Alert rule routed to a channel