Skip to main content
Use the Webhook Connection of Censys Attack Surface Management (ASM) to send newly found risks on your attack surface to Flashduty On-call. Each risk instance (one risk type on one asset) maps to one Flashduty alert. The Censys webhook only sends a notification when a risk is found and sends nothing when the risk closes, so alerts do not recover automatically.

In Flashduty On-call


You can obtain an integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select Censys and click Save
  4. Open the generated integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert events
  2. Select Censys and enter an integration name
  3. Configure the default route and select a channel; you can add more rules under Route after the integration is created
  4. Click Save and copy the generated Push URL

In Censys ASM


Webhook Connection is available only at the Advanced and Enterprise access levels of Censys ASM. If your firewall or gateway restricts source IPs, allow the Censys egress addresses 52.5.142.59, 34.226.132.221, and 52.54.43.157.
1

Add a Webhook Connection

  1. Sign in to the Censys ASM console and click Integrations
  2. Find Webhook Connection and click Set Up
  3. On the Authentication page, paste the full Flashduty push URL into Webhook URL; the URL must include integration_key
  4. Choose Authentication type from the options Censys offers. Flashduty authenticates with the integration_key in the URL and does not check other credentials
  5. Click Connect, then Next Step
2

Choose the risk severities to send

  1. On the Default Set Up page, review the defaults (the fields on that page cannot be edited) and click Next Step
  2. On the Filters page, select the risk severities to send
  3. Click Submit, then Close
3

Turn on auto-close

Censys sends no notification when a risk closes. Turn on auto-close in the channel that receives these alerts, with a suggested duration of 7 days, or close an alert manually once the risk is fixed.
4

Verify

The Censys webhook documentation describes no test button. When ASM finds a new risk on your attack surface it sends an event; confirm the matching alert appears in Flashduty.

Alert Key


Flashduty computes the Alert Key from event.data.risk_id (the risk type ID) and event.data.impacted_asset (the affected asset, such as Host: 1.1.1.1). Censys defines a risk instance as one risk type on one asset, but does not state that risk_id and impacted_asset stay unchanged across deliveries. The same risk type on the same asset gets the same Alert Key, so repeated deliveries merge into one alert; the same risk type on different assets, or different risk types on one asset, produce separate alerts. Changes to the risk name, description, severity, first and last seen times, or the event ID do not change the Alert Key. An event without risk_id or impacted_asset is rejected. An event whose event.type is not risk_instance_opened creates no alert; Flashduty acknowledges it and returns success.

Status and severity


Every event is a trigger. Flashduty sets the severity from risk_severity:

Labels


The alert title is the risk description (risk_description, or the risk name when empty) followed by the affected asset.

Troubleshooting


  • Webhook Connection is missing: check that the Censys ASM access level is Advanced or Enterprise
  • The integration does not work: Censys requires the receiver to accept the top-level event field; the Flashduty push URL needs no extra handling
  • Flashduty returns an invalid-parameter error: check that the URL is complete and includes integration_key
  • Alerts never close: Censys sends no risk-closed notification; turn on the channel’s auto-close
For field details, see Censys Webhooks for ASM.