# Getting Started


# Introducing SecAlerts

Start receiving alerts to software vulnerabilities using the most comprehensive up-to-date data available.

SecAlerts provides you with world-first access to the most comprehensive and immediate security intelligence database available.

### Real-Time Security Intelligence

At SecAlerts, we understand the critical importance of staying ahead of potential security threats and vulnerabilities. That's why we provide you with world-first access to a cutting-edge security intelligence database, constantly updated in real-time.

### Comprehensive and Immediate Data

Our mission is simple: to empower your organisation with the information you need to safeguard your digital assets effectively. SecAlerts gathers data from primary sources, including vendor advisories, package managers, and news forums. By going directly to the source, we eliminate waiting times for information, ensuring your business remains protected 24/7.

### Key Features at a Glance

* **Timely Alerts**: Receive alerts on potential security threats, CVEs, and vulnerabilities as soon as they are detected.
* **Comprehensive Database**: Access a wealth of information and insights on emerging security risks.
* **Real-Time Updates**: Stay informed with data that is continuously refreshed, providing you with the latest information.
* **Proactive Security**: Take proactive measures to protect your organisation's digital assets.


# Terminology

In the world of cybersecurity and software vulnerability management, specific terms and concepts are essential to understand. This glossary will provide you with a clear understanding of key terms used within the SecAlerts platform and the broader field of cybersecurity.

### Alerts

**Alerts** are notifications triggered by SecAlerts to inform users about specific security events or vulnerabilities. Alerts can be configured to provide real-time updates on software vulnerabilities, CVEs, and security threats.

### CVE (Common Vulnerabilities and Exposures)

**CVE**, which stands for Common Vulnerabilities and Exposures, is a standardized identifier for known software vulnerabilities. CVEs are used to uniquely identify and track security vulnerabilities across different systems and platforms.

### CVSS (Common Vulnerability Scoring System)

**CVSS**, or Common Vulnerability Scoring System, is a framework used to assess and quantify the severity of software vulnerabilities. CVSS scores help organisations prioritise and address vulnerabilities based on their potential impact and exploitability.

### Notification Channels (Channels)

**Notification Channels**, often referred to simply as "Channels," are delivery methods for alerts and notifications within SecAlerts. These channels can include email, Slack, and other communication platforms, allowing users to receive alerts through their preferred means of communication.

### Organization

An **Organisation** in SecAlerts refers to a user's dedicated workspace or account, where software vulnerabilities and security alerts are managed. Organisations have their settings, users, and access controls.

### Properties

**Properties** allow users to segment their SecAlerts account into distinct groups, each with its own set of alerts and access controls. Properties are useful for organising and managing software vulnerabilities for different entities within an organisation, or different companies or divisions.

### Scan

A **Scan** in SecAlerts is a process of collecting software information from a local network and sending it to SecAlerts for analysis. Scans help users keep track of software assets and vulnerabilities within their organisation.

### Software Stack (Stack)

A **Software Stack**, often referred to simply as a "Stack," is a grouping of software assets into a logical collection. Stacks can be used to organise software, create alerts that include specific software collections, and streamline vulnerability management.

### SSO (Single Sign-On)

**SSO**, or Single Sign-On, is an authentication process that allows users to access multiple applications or services with a single set of credentials. SecAlerts offers SSO integration to enhance security and user convenience.

### User Roles

SecAlerts offers several **User Roles**:

* **Owner**: Owners have the highest level of access and control within an organisation's SecAlerts account.
* **Admin**: Admin users can access all properties and configure settings within the organisation's SecAlerts account.
* **Member**: Members have restricted access and can only access properties to which they have been granted access by Admin or Owner users.

### Users

"Users" refer to individuals or accounts that have access to the SecAlerts platform. Users play various roles within the platform and have specific permissions and responsibilities based on their assigned roles.

### Vulnerability

A **Vulnerability** refers to a weakness or flaw in software or hardware that can be exploited by malicious actors to compromise the security of a system. SecAlerts helps users identify and address vulnerabilities to enhance cybersecurity.

This glossary provides a foundation for understanding the key terms and concepts used within the SecAlerts platform. If you encounter any additional terms or have questions about specific terminology, please refer to our support documentation or contact our support team for further assistance.


# Stacks

In this guide, we will explore how to effectively manage Software Stacks (or just Stacks for short) within SecAlerts. Stacks allow you to group your software into logical collections, making it easier to create alerts that include entire stacks or even multiple stacks.

### Key Features

Stacks offer several key features to help you organise and manage your software assets:

1. **Custom Alerts**: Create alerts that include entire Stacks or combinations of Stacks, streamlining your alert configuration.
2. **Flexible Software Addition**: Add software to Stacks manually, via import from CSV, XLS, or XLSX files, or through automated cURL scripts for network scanning.

### Creating and Managing Software Stacks

To create and manage Software Stacks in your SecAlerts account, follow these steps:

1. Log in to your SecAlerts account.
2. Navigate to the  "Stacks" section.
3. Click on "Create New Stack".
4. Provide a **Descriptive Name** for the Stack to easily identify its purpose.
5. To add software to your Stack, you have several options:
   * **By Name**: Click "Edit" link and manually enter the software and version details under "Add New Material" section. You can add the software name as free text and we will match it as best we can. You can audit the list later. Add a specific version you would like to track, you can use \* as a wildcard to track all.
   * **Spreadsheet**: Click "Edit" link and use the importer to upload software information from CSV, XLS, or XLSX files.
   * **Local Scan**: Execute this script to scan your local network for software versions and send the results to the Stack.

### Utilising Stacks in Alerts

Software Stacks simplify the process of creating alerts that include specific software collections. Here's how to use Stacks in your Alerts:

1. When creating or editing an Alert in SecAlerts, select the desired Software Stack(s) from the available options.
2. Configure the Alert settings and triggers as needed.
3. Save the Alert to activate it with the chosen Software Stack(s).

### Conclusion

Stacks provide a structured approach to organising and managing your software assets. Whether you want to create alerts based on specific software collections or simply maintain a comprehensive inventory, Software Stacks offer flexibility and ease of use.


# Channels

Choose where you want alerts to go within your organisation.

In this guide, we will explore how to create and manage Notification Channels (referred to as "Channels" for short) within SecAlerts. Channels allow you to group delivery methods for notifications, which can be easily selected as destinations in your Alerts.

### Key Features of Channels

Channels offer several key features for efficient communication and alert management:

1. **Descriptive Naming**: Assign descriptive names to your Channels for easy identification in a list of other channels.
2. **Email and Slack Delivery Methods**: Choose from Email and Slack as your delivery methods for notifications. Additional integrations will be available in the future, if you require specific integration [contact us](mailto:info@secalerts.co).
3. **Multiple Email Recipients**: If you select Email as a delivery method, you can add as many email addresses as needed or send to a company distribution list.
4. **Seamless Slack Integration**: For Slack delivery, easily authorise the connection to Slack through the "Add to Slack" link.

### Creating and Managing Notification Channels

To create and manage Notification Channels in your SecAlerts account, follow these steps:

1. Log in to your SecAlerts account.
2. Navigate to the "Channels" section.
3. Click on the "Create New Notification Channel".
4. Provide a **Descriptive Name** for the Channel to easily identify its purpose.
5. Select your preferred delivery method:
   * **Email**: Click on the "Add Email" link to add one or more email addresses where notifications should be sent.
   * **Slack**: Click on the "Add to Slack" link to authorise the connection to your Slack workspace. Complete the setup by following the prompts and authorising the connection if necessary.
6. Click the "Create New Channel" button to save the Channel configuration.

### Using Notification Channels in Alerts

Once you have created your Notification Channels, you can utilise them as destinations in your Alerts:

1. When creating or editing an Alert in SecAlerts, select the desired Channel(s) from the available options.
2. Configure the Alert settings and triggers as needed.
3. Save the Alert to activate it with the chosen Notification Channel(s).

### Conclusion

SecAlerts Notification Channels provide a flexible and efficient way to manage the delivery methods of your notifications. Whether you prefer email notifications or use Slack for team communication, you can tailor your notification settings to match your organisation's needs. By following the steps outlined in this documentation, you can create, manage, and utilize Notification Channels effectively.


# Alerts

Bringing Stacks and Channels together and filter out the noise for your teams.

In this guide, we will explore how to create, configure, and manage alerts within SecAlerts. Alerts are a critical component of SecAlerts, enabling you to send notifications to specific individuals or teams within your organisation based on predefined criteria.

### Key Features

Alerts provide a range of features to help you effectively manage your notification and alerting processes:

1. **Descriptive Naming**: Assign descriptive names to your alerts for easy identification in a list of other alerts.
2. **Software Stacks**: Associate alerts with specific Software Stacks to filter and customize the data included in the alerts.
3. **Filtering**: Define criteria for the data you want to receive in the alert, including specific software versions, CVSS scores, vulnerability types, and more.
4. **Notification Channels**: Select the channel(s) through which alerts will be sent.
5. **Frequency Control**: Choose how often alerts should be sent, including options like Instant, Daily, Weekly, Fortnightly, or Monthly.

### Creating and Configuring Alerts

To create and configure alerts in your SecAlerts account, follow these steps:

1. Log in to your SecAlerts  account.
2. Navigate to the "Alerts" section.
3. Select "Create New Alert" to manually create an alert. This method allows you to configure Stacks, Filters, and other settings in detail.
4. Providing a **Descriptive Name** for the alert to identify it easily in a list of other alerts.
5. *Before creating an alert, you will need to create at least one Stack and one Channel.*
6. Configure the Stacks and Filters:
   * **Stacks**: Choose the Software Stacks that you want to associate with the alert. You can add multiple Stacks.
   * **Filters**: Define specific criteria for the data you want to include in the alert, such as software versions, CVSS scores, vulnerability types, and more.
7. Use the toggle to specify whether you want vulnerabilities that have been published since the last alert or both published and modified vulnerabilities since the last alert.
8. In the next section, select the Notification Channels through which the alert will be sent. You can add multiple channels to a single alert.
9. Choose the frequency at which alerts should be sent: Instant, Daily, Weekly, Fortnightly, or Monthly.
10. Click the "Update Alert" button to save the alert configuration.

### Managing Alerts

After creating alerts, you can manage and track them using the following features:

* **Edit**: Use the "Edit" link to make changes to the alert configuration.
* **History**: Review the history of triggered alerts to track past notifications and actions.

### Conclusion

Alerts are a fundamental tool for keeping your organisation informed about software vulnerabilities that matter most. By following the steps outlined in this documentation, you can create, configure, and manage alerts to suit your organization's specific needs and stay ahead of potential security risks.


# Scans

In this guide, we will explore how to effectively use Scans, which allow you to collect software information from your local network and send it to SecAlerts for analysis. Scans are a powerful tool to help onboard your software assets to SecAlerts.

### Key Features

Scans offer several key features to assist you in managing your software assets:

1. **Independent**: Scans are independent of Stacks, allowing you to collect software data without needing to organise it immediately into Stacks.
2. **Script Generation**: You can generate cURL scripts to execute scans from your local environment.
3. **Query Code**: Access the Query feature to view and customise the query code related to the scan results.
4. **Audit Functionality**: Review and select software detected by the Scan to add them to relevant Stacks.

### Creating and Managing Scans

To create and manage Scans in your SecAlerts account, follow these steps:

1. Log in to your SecAlerts account.
2. Navigate to the "Scans" section.
3. Click on the "Copy" link to copy the curl script.
4. Run the curl script locally.
5. Return to the "Scans' section and refresh the page, you should now see a new scan in the list.
6. You can now choose to:
   1. **Merge** the scan results into an existing stack
   2. **Replace** an existing stack
   3. **Create a new stack** with the scan results
   4. **Delete** the scan.

### Viewing Scan Results and Actions

After performing a Scan, you can access the results and take actions as needed:

* **Merge** the scan results into an existing stack
* **Replace** an existing stack
* **Create a new stack** with the scan results
* **Delete** the scan.

Once you have added or created a new Stack with the scan data, you can audit the software that was collected by navigating to Stacks and choosing the Audit option on the Stack.

### Managing Scan Data

SecAlerts strives to provide comprehensive software data through scans, but the resulting list of software can be extensive. Here are some ways to manage Scan data effectively:

* **Prioritisation**: Focus on the most critical or relevant software assets first when reviewing scan results.
* **Custom Stacks**: Create custom Stacks to categorise and organise software assets based on your organization's needs.
* **Regular Scanning**: Schedule regular scans to keep your software inventory up to date and monitor changes over time.

### Conclusion

SecAlerts Scans are a valuable resource for collecting software information from your local network and sending it to SecAlerts for analysis. By following the steps outlined in this documentation, you can create, manage, and utilize Scans to enhance your organization's software asset management and security practices.


# Properties

In this guide, we will explore how to effectively manage properties within your SecAlerts account. Properties allow you to organise alerts, stacks, and channels into distinct groups, and apply custom branding to email alerts for each property. This functionality is particularly valuable for segmenting different companies, divisions, or teams, providing them with their own branding and administrative control over alerts.

### Key Features

Properties offer a range of powerful features to enhance your organisational structure and branding:

1. **Alert Organisation**: Group alerts, stacks, and channels into separate properties to keep information organised and manageable.
2. **Access Control**: Define which users have access to specific properties, allowing you to delegate administrative responsibilities effectively.
3. **Custom Branding**: Apply unique branding to email alerts for each property, ensuring a personalised and consistent experience for users.

### Creating and Managing Properties

To create and manage properties within your SecAlerts account, follow these steps:

1. Log in to your SecAlerts account as an Owner or Admin.
2. Navigate to the "Properties" section in the dashboard.
3. Click on the "Create New Property".
4. Provide the following information for the new property:
   * **Property Name**: Enter a descriptive name for the property (e.g., Company A, Division 1).
   * **Branding**: Customise email alerts with branding elements, such as logos and colors, specific to this property.
5. Save the property settings by clicking 'Create New Property' button.
6. Click on the 'View Access' link to define which users should have access to this property and set their access capability.

### Property Use Cases

SecAlerts Properties serve various purposes within your organization:

#### 1. **Segmentation by Company or Division**

* Separate alerts, stacks, and channels for different companies, divisions, or subsidiaries within your organisation.
* Apply distinct branding to maintain a unique identity for each entity.

#### 2. **Delegated Administration**

* Empower specific teams or individuals with administrative control over their designated properties.
* Reduce administrative burden on central IT or security teams.

#### 3. **Custom Branding**

* Enhance the user experience by delivering email alerts with branding elements that reflect the identity of each property.
* Build trust and recognition among users.

### Conclusion

Properties is a valuable feature for organisations that need to segment their alerts, channels, and users for effective organisation, control, and branding.


# Users

In this guide, we will explore how to effectively manage users within your organisation's SecAlerts account, including inviting users and defining their roles to control access to specific properties.

### User Roles

SecAlerts offers three distinct user roles, each with specific privileges:

1. **Owner**: Owners have the highest level of access and control within an organisation's SecAlerts account. They are equivalent to Admins in terms of access privileges and settings configuration. There must be at least one owner for every organization.
2. **Admin**: Admin users have the authority to access all properties and configure settings within the organisation's SecAlerts account. They play a critical role in managing the account and its users.
3. **Member**: Members have restricted access compared to Admins. They can only access properties to which they have been granted access by Admin or Owner users. Members are primarily focused on monitoring and responding to alerts within their designated properties.

### Inviting Users

To invite users to your organisation and specify their roles, follow these steps:

1. Log in to your SecAlerts account as an Owner or Admin.
2. Navigate to the "Users" section.
3. Click on the "Invite" button.
4. Provide the following information for the user you wish to invite:
   * **Email Address**: Enter the email address associated with the user's SecAlerts account.
   * **Role**: Select the appropriate role for the user (Admin or Member).
5. Click the "Invite" button.

The invited user will receive an email notification with an invitation link. Once they accept the invitation, they will gain access to the organisation's SecAlerts account with the specified role.

### Managing User Access

After users have accepted invitations, you can further manage their access within the organisation:

* **Property Access**: Admins or Owners can grant access to specific properties for Member users. This allows you to control which areas of your organisation's SecAlerts account each user can access.
* **User Removal**: As an Admin or Owner, you can remove users from the organisation if they no longer need access. This action will revoke their access to all properties within the organization.

### Conclusion

Effectively managing users and their roles within your SecAlerts organisation is crucial for maintaining security and ensuring that the right individuals have the appropriate level of access. By following the steps outlined in this documentation, you can invite users, assign roles, and control property access to tailor your organization's SecAlerts experience to your specific needs.

<br>


# Organisation & SSO

In this guide, we will explore how to effectively manage your organisation's SecAlerts account and enable Single Sign-On (SSO) for enhanced security and convenience.

### Organisation Management

As the administrator of your SecAlerts organisation, you have access to all the essential tools and settings to manage your account efficiently. You can update the overall administrator of you account on this page.&#x20;

### Single Sign-On (SSO) Setup

#### Overview

Single Sign-On (SSO) integration allows your organisation to centralise user authentication and access control. With SSO, users can access SecAlerts using their existing corporate credentials, simplifying login and improving security.

#### SSO Setup Instructions

To set up Single Sign-On (SSO) for your SecAlerts organisation, follow these steps:

1. Log in to your SecAlerts account as an administrator.
2. Navigate to the "Organisation" section.
3. Locate and select "SSO Settings" link.
4. Enable SSO by toggling the appropriate setting.
5. Fill out the required SSO settings, which include:
   * X509 Certificate
   * Entity ID
   * Signin URL
   * Signout URL
6. Save your SSO settings by clicking the Update SSO Settings button.
7. Test the SSO integration to ensure it is working correctly.

#### Benefits of SSO Integration

Enabling SSO within your organization's SecAlerts account offers several benefits:

* **Streamlined Access**: Users can log in to SecAlerts with their existing corporate credentials, reducing the need for additional usernames and passwords.
* **Enhanced Security**: Centralised authentication ensures that access is tightly controlled and aligned with your organization's security policies.
* **Improved User Experience**: SSO simplifies the login process, making it more convenient for users to access SecAlerts.
* **Reduced Password Management**: Users can reset passwords and manage access through your organisation's identity provider, reducing the burden on your IT team.

### Conclusion

Effective organizsation management and the implementation of Single Sign-On (SSO) are vital steps to enhance security, streamline access, and simplify user management within your SecAlerts account. By following the provided instructions and taking advantage of the SSO integration, you can ensure that your organization benefits from a secure and efficient experience with SecAlerts.

<br>


# Event Log

Keep track of what is happening in your account

In this guide, we will introduce you to SecAlerts' Event Log, a powerful tool that acts as a forensic record of all activities and events occurring within your account. The Event Log provides critical information such as date and time of occurrences, event descriptions, associated applications or processes, specific event codes, and other relevant details like IP addresses and user names. This comprehensive record is invaluable for maintaining security, monitoring system health, and facilitating forensic investigations.

### Key Features of SecAlerts Event Log

The Event Log offers a wide range of features to help you maintain a clear and comprehensive record of activities within your SecAlerts account:

1. **Timestamps**: Every event in the log is timestamped with the date and time of occurrence, ensuring accurate chronology.
2. **Event Descriptions**: Events are accompanied by descriptions that provide context for each entry.
3. **Application or Process**: The Event Log specifies the application or process involved in each event, making it easier to identify the source.
4. **Event Codes**: Specific event codes are assigned to categorise and identify different types of events, aiding in quick reference and search.
5. **Additional Information**: The log includes other relevant information such as IP addresses and user names associated with the events, providing a holistic view of each occurrence.

### Accessing the Event Log

Accessing the Event Log is straightforward. Here's how to do it:

1. Log in to your SecAlerts account.
2. Navigate to the "Event Log" section in the dashboard.
3. Here, you will find a comprehensive list of events, sorted chronologically with the most recent events at the top.

### Common Use Cases for the Event Log

The SecAlerts Event Log serves multiple essential purposes, including:

#### 1. Security Monitoring

* Monitor changes to security settings.
* Track login activities and IP addresses.

#### 2. Compliance and Auditing

* Maintain records for compliance with regulatory requirements.
* Generate audit trails for security assessments.

#### 3. Troubleshooting

* Identify and diagnose issues by reviewing recent events.
* Correlate events with system or application performance problems.

#### 4. Forensic Investigations

* Investigate security incidents by analysing event details.
* Reconstruct sequences of events to understand the scope of an incident.

#### 5. Historical Reference

* Maintain a historical record of account activities for reference and analysis.

### Conclusion

The SecAlerts Event Log is a crucial component of your account's security infrastructure. It provides a detailed, organised, and easily accessible record of all activities and events, enhancing your ability to monitor and secure your account effectively. Whether you are focused on security, compliance, troubleshooting, or forensic investigations, the Event Log is an invaluable resource that empowers you to stay informed and take proactive measures to protect your account and data.


# Integrations

In this guide, we will provide detailed information on how to set up and use the various integrations offered by SecAlerts. These integrations are designed to enhance your security incident response and communication processes, making it easier to stay informed about security alerts and incidents in your organisation.

SecAlerts offers the following integrations:

1. [**Email Integration**](#1.-email-integration)
2. [**Slack Integration**](#2.-slack-integration)
3. [**API Integration**](#3.-api-integration) **(Coming soon)**
4. [**Webhook Integration**](#4.-webhook-integration) **(Coming soon)**

### 1. Email Integration

#### Overview

SecAlerts' Email Integration allows you to receive security alerts and notifications directly in your email inbox. This integration is suitable for users who prefer to monitor alerts through their email client.

#### Setup Instructions

To set up the Email Integration, follow these steps:

1. Log in to your SecAlerts account.
2. Navigate to the "Channels" section.
3. Create a new Channel or edit an existing one.
4. Under 'Notification Type' choose Email.

<figure><img src="/files/dZ2mPdfNVPr5oyzQm9sZ" alt=""><figcaption></figcaption></figure>

3. You can now click the 'Add Email' link to add as many email recipients you need to receive the alerts.

<figure><img src="/files/htpCV1jFg8UvHb3u0QDY" alt=""><figcaption></figcaption></figure>

4. Now press the Edit Channel button to save the changes.

SecAlerts will now send security alerts and notifications to the specified email address whenever you use that channel in an Alert.

### 2. Slack Integration

#### Overview

The Slack Integration allows you to receive real-time security alerts and incident notifications directly in your Slack channels. This integration is ideal for teams that use Slack for communication and collaboration.

#### Setup Instructions

To set up the Slack Integration, follow these steps:

1. Log in to your SecAlerts account.
2. Navigate to the "Channels" section.
3. Create a new channel or edit an existing one
4. Under 'Notification Type' choose "Slack".
5. Authorize SecAlerts to access your Slack workspace.
6. Configure which Slack channels or direct messages should receive the alerts.
7. Press Edit Channel to save your settings.

SecAlerts will now send security alerts and incident notifications to your specified Slack channels or DMs whenever you use that channel in an Alert.

### 3. API Integration

#### Overview

The API Integration allows you to programmatically retrieve and interact with security alerts and incident data from SecAlerts. This integration is suitable for organisations that want to integrate SecAlerts into their custom applications or workflows.

#### 21/9/2023 - Our API will soon be available, if you want like early access, contact us.

### 4. Webhook Integration

#### Overview

The Webhook Integration enables you to push security alerts and incident data to external systems or custom endpoints using HTTP webhooks. This integration is versatile and can be used to integrate SecAlerts with various third-party tools and services.

#### 21/9/2023 - The Webhook will soon be available, if you would like early access, contact us.


