Daily attack surface monitoring with Slack alerts and Jira tickets

By General Input

Scan your domains and IP ranges each weekday for risky exposed services, with a prioritized Slack digest and auto-filed Jira tickets for critical new findings.

Integrations

  • Censys
  • Slack Bot
  • Jira

Type

Agentic Task

Categories

  • Engineering
  • Operations

Every weekday at 8:00am, scan my organization's known internet-facing attack surface with Censys, triage what turns up, post a prioritized digest to our security Slack channel, and open a Jira ticket for each critical, newly appeared exposure. Discovery uses the Censys "Run a Search Query" operation, the digest uses the Slack Bot "Send a Message" operation, and the tickets use the Jira "Create Issue" operation.

Censys is a read-only intelligence source, so there is no webhook or poll to subscribe to. Run this on a weekday 8am cron and do the discovery with an in-workflow CenQL search. The Censys connection must have the Organization ID set, because the search endpoint returns a 422 error without it. Scope every query to my known assets. Expose the target domains and IP ranges as a configurable input (default: example.com and 203.0.113.0/24, which should be replaced with the real domains and CIDR ranges).

Search for risky internet-exposed services within those assets: open databases such as Elasticsearch, MongoDB, and Redis; remote-access services such as RDP on port 3389 and VNC; and exposed admin or login panels. For every match, capture the IP address, port, service and software version, and any labels Censys reports.

Review the matches and prioritize them. Rank by severity (an open, unauthenticated database or an exposed RDP endpoint is critical; a login panel on an expected service is lower), and separately judge whether each exposure looks newly appeared versus expected. Treat intentionally public services as expected and flag anything net-new or out of place. Use a configurable severity threshold to decide what warrants a Jira ticket (default: only critical, net-new exposures).

Post one prioritized digest to our security Slack channel with the Slack Bot "Send a Message" operation (default channel #security, configurable). Lead with a one-line summary of counts by severity and how many are net-new, then list findings grouped by severity, each showing the IP, port, service, and whether it is new or expected. Use Slack mrkdwn formatting.

For each finding that meets the ticket threshold, open a Jira issue with the Jira "Create Issue" operation in our security project (configurable). Put the affected IP, port, service and version, severity, and why it looks net-new into the issue summary and description, and set priority to Highest for criticals. File tickets only for net-new exposures so the board is not flooded with services we intentionally keep online, and always include the IP, port, and service so a human can dedupe.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them