Rapid Response Email Notifications
Access Levels: Advanced | Enterprise
In Attack Surface Management (ASM), you can set up a rapid response email to notify you of new Rapid Response risks in your workspace so you can quickly remediate the issue.
Rapid Response is a monitoring and research service run by the Censys Research team. It is dedicated to hunting for vulnerable devices and writing risk fingerprints that will flag those devices in our platform. The service notifies you about new critical vulnerabilities that meet the Rapid Response initiation criteria, configuration exposures, and threats relevant to Censys-observed assets. Within about 24 hours of a new issue's release, Censys fingerprints specific, affected asset versions to grasp the issue's scope in a timely manner.
When a new Rapid Response risk is identified, an email is sent as often as once per hour. If multiple Rapid Response risks are found in your workspace, all the risks are listed in the email. All emails contain information about all current identified Rapid Response risks.

An example Rapid Response email.
For information on the queries used in Rapid Response risk detection, see Policy for sharing Censys Rapid Response queries.
NotePlease see the Risk Email Notifications setup guide for email notifications about new, non-Rapid Response risks.
Risk identifiers
The messages include the following identifiers for new risks:
- 
A new Risk label is created in my workspace: When a Rapid Response label is added, you can be notified of it. This occurs when Censys can only link the risk to a vendor and product but not to a specific version. 
- 
Censys deploy a new Rapid Response Risk: Censys deployed a new Rapid Response risk to your workspace. This means that all your assets are being checked for an indicator of this risk. This process is usually completed within a few hours.   
- 
My workspace contains a new Rapid Response Risk: Censys deployed one, and one or more of your assets within your ASM workspace contain indicators for this risk. - 
You will receive an alert on a risk within 30 days of its deployment. If the risk was released more than 30 days ago, this integration will not trigger an alert.   
 
- 
Prerequisites
You will need the email address where you want Rapid Response emails sent to. You can create a separate email for these messages or add multiple email addresses.
Configure the integration in Censys ASM
- 
Go to the Censys ASM web console and click Integrations. 
- 
Locate Rapid Response Email and click Set Up.   
- 
On the Authentication page, configure the following: - 
Destination Email Addresses: Enter the email address(es) where you want Rapid Response messages to be sent. 
- 
Send an email when: Select the alerts you want to be notified of. See Risk identifiers for more information about the risks. 
- 
Show Assets: Select whether to show assets, such as IP addresses and domains, in the email.   
 
- 
- 
Click Connect. 
- 
Click Submit, then click Close. 
Modify the integration
If you need to make changes to your integration settings or if you need to disconnect the integration:
- 
Go to the Censys ASM web console and click Integrations. 
- 
Locate Rapid Response Email and click Manage.   
- 
On the Authentication page, click Edit Setup. Then, at the bottom of the page, click Disconnect. - You must disconnect the integration in order to make configuration changes.
 
- 
Go through the setup wizard, as described in the section above, and make any necessary changes. 
Updated about 2 months ago
