new_vuln), and failed scans or asset discoveries (failed_stopped). Scan start and finish notifications (running, finished) and new-asset notifications (new_asset) are accepted and dropped without creating an alert.
ProjectDiscovery sends no “fixed” or “resolved” notification, so these alerts do not recover on their own. Turn on auto-close in the channel that receives them (see below).
In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select ProjectDiscovery and click Save
- Open the new integration card and copy the push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select ProjectDiscovery and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated push URL
In ProjectDiscovery Cloud
1
Add a webhook alerting configuration
- Sign in to ProjectDiscovery Cloud and go to Settings → Integrations → Alerting
- Select Webhook and enter a Config Name (for example
Flashduty) - Paste the full Flashduty push URL into Webhook URL (it must be an HTTPS URL)
- Authentication is optional. Flashduty authenticates with the
integration_keyin the push URL, so leave it empty
2
Choose the events
Select New Vulnerability and the failure events under Scan / Asset Finished / Failed. You can leave the other events off; if you turn them on, Flashduty still returns success and ignores them. To filter by severity, set a severity filter; the counts and vulnerability lists in the notification then only include matching findings.
3
Save and attach to scans
Save the alerting configuration and enable it on the scans or asset discovery jobs you want to be notified about.
Clicking Verify when you create the webhook sends
{"type":"verify","message":"This is a test message from PDCP to verify alerting configuration! Please ignore."}. Flashduty returns success and opens a separate Info alert titled “ProjectDiscovery test notification” that you close by hand.Payload
ProjectDiscovery POSTs notifications as
application/json, and Flashduty parses them directly with no template. Scan notifications carry scan_name and scan_id; asset discovery notifications carry enumeration_name and enumeration_id.
Alert title:
<name>: new vulnerabilities for new vulnerabilities, <name> failed for failures.
Alert Key
Flashduty uses
scan_id (enumeration_id for asset discovery) as the Alert Key. ProjectDiscovery documents it as the unique identifier of the execution. Notifications with the same ID merge into one alert, and different scans or discoveries create different alerts. Changing the name, counts or time does not change the Alert Key.
If a new-vulnerability or failure notification has no matching ID, Flashduty returns a parameter error naming the missing field.
Status and severity
For
new_vuln, the highest severity in rescan_vulns_list decides; when the list is empty, the highest bucket of severity_breakdown with a count above 0 is used. A failed scan is a coverage gap rather than an outage, so it is a Warning.
Auto-close
ProjectDiscovery sends no recovery notification, so these alerts stay active. Turn on auto-close in the channel that receives them, with a suggested duration of 24 hours; adjust it to your scan frequency.
About signatures
The ProjectDiscovery webhook supports an optional custom authentication header. Flashduty does not verify it and relies on the
integration_key in the push URL, so keep the push URL secret.
FAQ
Why does a finished scan not create an alert?
Why does a finished scan not create an alert?
finished, running and new_asset only report job state or asset changes, not problems to act on. Flashduty returns success and drops them. Only new vulnerabilities and failures create alerts.Are vulnerabilities from the first scan reported?
Are vulnerabilities from the first scan reported?
ProjectDiscovery sends
new_vuln only for rescans, so the results of a first scan are not sent through this notification.The vulnerability list is incomplete
The vulnerability list is incomplete
rescan_vulns_list holds at most 15 entries per notification. View the full list in the ProjectDiscovery console or API.Troubleshooting
- ProjectDiscovery reports a failed delivery: check that the Webhook URL is the full HTTPS push URL including
integration_key - Flashduty returns a parameter error: check that the body is a ProjectDiscovery JSON notification and that
new_vulnandfailed_stoppedcarryscan_idorenumeration_id - An alert does not close: this is expected; turn on auto-close