Skip to main content
ContraForce keeps your team informed with configurable email notifications. Receive alerts when new incidents are detected, Gamebooks complete, or when issues require attention—all customizable by severity and workspace.
Notification capabilities vary by module. The XDR + SIEM module offers full customization, while the XDR-only module has limited notification options.

Notification Overview

Incident Alerts

Get notified when new security incidents are detected

Gamebook Activity

Receive updates when Gamebook actions complete

Severity Filtering

Choose which severity levels trigger notifications

Notification Capabilities by Module

Notification features depend on which ContraForce module you’ve deployed:
FeatureXDR ModuleXDR + SIEM Module
Sentinel incident notifications
Defender XDR incident notifications
Gamebook completion notifications
Severity-based filtering
Per-workspace customization
Distribution group support
XDR Module Users: ContraForce does not generate email notifications for new Defender XDR incidents. Use Microsoft Defender’s built-in notification settings for Defender alerts. ContraForce notifications are sent only for Gamebook activity.
Deploying ContraForce does not interrupt or override your existing Microsoft Defender notification configuration.

Email Notification Details

Sender Address

All ContraForce notifications are sent from:
Add this address to your email allowlist to ensure notifications aren’t blocked by spam filters.

Email Content

Incident notification emails include:
FieldDescription
TitleIncident name/description
DescriptionSummary of the security event
SeverityHigh, Medium, Low, or Informational
Incident IDUnique identifier for tracking
MITRE TacticsAssociated attack techniques
EntitiesAffected users, devices, IPs, etc.
View Incident ButtonDirect link to open the incident in ContraForce

Example Email

Example ContraForce notification email
The View Incident button takes you directly to the incident in the ContraForce Portal, where you can investigate and respond.

Configuring Notifications

Accessing Notification Settings

1

Open Settings

Click Settings in the navigation menu
2

Select Notifications

Click the Notifications tab
3

Configure Preferences

Adjust settings by workspace and severity
Direct link: Settings > Notifications

Severity-Based Filtering

For XDR + SIEM deployments, you can customize which severity levels trigger notifications:
Notification severity settings
High severity incidents typically indicate active threats requiring immediate response.Recommendation: Always enable

Per-Workspace Configuration

Configure different notification preferences for each customer workspace:
  1. Navigate to Settings > Notifications
  2. Select the Workspace you want to configure
  3. Enable or disable severity levels for that workspace
  4. Save changes
Use per-workspace configuration to match notification settings to each customer’s SLA. High-priority customers might need all severities enabled, while others might only need High alerts.

Distribution Group Notifications

Send notifications to a team distribution list instead of individual users.

Use Cases

SOC Team Inbox

Route all alerts to a shared SOC mailbox for team visibility

On-Call Rotation

Send to a distribution group that routes to the current on-call analyst

Ticketing Integration

Route to an email address that auto-creates tickets in your ITSM

Customer Notifications

Keep customers informed by CCing their security team

Setting Up Distribution Groups

Distribution group notifications require setup assistance from the ContraForce team:
1

Identify Email Address

Determine the distribution group email address you want to use
2

Contact ContraForce

Provide the email address during onboarding or contact [email protected]
3

Engineering Setup

The ContraForce Engineering team configures the distribution group
4

Verify

Test that notifications are reaching the distribution group
Distribution group setup is typically completed during onboarding. If you need to add or change distribution groups later, contact support.

Gamebook Notifications

Gamebook notifications are available for all modules (XDR and XDR + SIEM).

When You’ll Receive Notifications

EventNotification Sent
Gamebook execution started
Gamebook completed successfully
Gamebook failed
Gamebook requires approval
Gamebook approved

Gamebook Email Content

Gamebook notifications include:
  • Gamebook name
  • Target incident
  • Actions executed
  • Execution status (Success/Failed)
  • Workspace name
  • Link to view details

Notification Best Practices

Begin with High severity notifications enabled for all workspaces. Add Medium and Low severities gradually based on team capacity to avoid alert fatigue.
Route notifications to a shared mailbox so the entire SOC team has visibility. This prevents missed alerts when individuals are unavailable.
Set up email folder rules to automatically categorize ContraForce notifications by workspace or severity for easier triage.
Route notifications to an email address that creates tickets in your ITSM (ServiceNow, Jira, etc.) for automatic tracking and SLA management.
Regularly review notification settings. If you’re experiencing alert fatigue, consider disabling lower severity levels or refining detection rules.
Add [email protected] to your email allowlist to prevent notifications from being caught by spam filters.

Integrating Notifications with Other Tools

Email-to-Ticket Integration

Many ITSM platforms support email-based ticket creation:
PlatformMethod
ServiceNowConfigure inbound email actions
Jira Service ManagementUse email request channel
AutotaskSet up email-to-ticket rules
ConnectWiseConfigure email connector
For tighter integration, consider using the ContraForce Partner API or native integrations like ServiceNow or Jira.

Microsoft Teams / Slack

For real-time team notifications:
  1. Create an email-enabled channel in Teams or Slack
  2. Use that email address as a distribution group in ContraForce
  3. Notifications appear directly in your chat platform

Troubleshooting

Common Issues

IssuePossible CauseSolution
Not receiving notificationsSpam filter blockingAdd sender to allowlist
Not receiving notificationsWrong module deployedVerify you have XDR + SIEM module
Not receiving notificationsSeverity disabledCheck notification settings
Missing workspaces in settingsPermissions issueVerify you have admin access
Distribution group not workingNot configuredContact ContraForce support
Too many notificationsAll severities enabledDisable Informational and Low

Testing Notifications

To verify notifications are working:
  1. Ensure notification settings are enabled for the workspace
  2. Wait for a new incident to be detected (or ask ContraForce to send a test)
  3. Check your inbox (including spam/junk folders)
  4. Verify the email contains expected content

Frequently Asked Questions

All notifications are sent from [email protected]
ContraForce does not send email notifications for Defender XDR incidents directly. Use Microsoft Defender’s built-in notification settings for those alerts. ContraForce sends notifications for Sentinel incidents (XDR + SIEM module) and Gamebook activity (all modules).
Contact [email protected] with the email address you want to use. The ContraForce Engineering team will configure it for your account.
Email templates are standardized and cannot be customized. For custom notification formatting, consider routing emails to a ticketing system that can reformat them.
Notifications are sent in near real-time when incidents are detected and processed by ContraForce. Typical delay is under 5 minutes.
ContraForce currently supports email notifications only. For SMS or push, route email notifications to a service like PagerDuty or Opsgenie.


Questions about notifications? Contact us at [email protected].