Using ScanSuite

Custom Rules

Your own Semgrep and Nuclei rules, generating a Nuclei rule with AI, and the suppression rules triage creates.

ScanSuite supports custom scanning rules for both static analysis (Semgrep) and dynamic analysis (Nuclei).

Creating a rule

Select the rule type — Nuclei or Semgrep — paste the rule text, and click Upload:

Custom rule creation
Creating a custom rule

Viewing and editing

Select an existing rule from the drop-down menu to review or change it.

Generating a Nuclei rule with AI

A Nuclei rule can be generated from a vulnerability proof-of-concept description. Paste the description, including the parts of the HTTP request and response used for detection, and click Gen with AI:

AI rule generation
The Gen with AI control, which drafts a Nuclei rule from a description

The rule is generated and pasted into the same field. Review it, amend if necessary, and click Upload.

Review generated rules before uploading. A rule that matches too broadly turns into noise on every subsequent scan, and a rule that matches nothing fails silently.

An AI provider must be configured for this — see AI providers and cost.

Semgrep rules

Semgrep rules are managed the same way, but AI rule generation is not yet supported for them.

Running the rules

To run a scan against the saved rules, choose the Custom Rules scanner in the relevant scan section — it is available for static, web and infrastructure scans.

Suppression rules

A suppression rule stops AI SAST reporting one vulnerability class in a file, a folder or a whole repository. You create one while ruling out a finding: on the Vulnerabilities page, False positive… offers Don't report this class here again — see Vulnerability Management. The rule applies to later scans before a candidate costs a model call.

The Suppression rules section of this page lists every rule:

Suppression rules list
Suppression rules created from false-positive decisions
ColumnWhat it shows
ProductThe product the rule applies to.
ClassThe vulnerability class it suppresses.
WhereThe file, folder or repository, and which of the three it is.
ReasonThe reason given when the finding was ruled out.
CreatedWhen and by whom, and the date it expires if it has one.
AppliedHow many times it has suppressed a candidate; hover for when it last did.

Retire ends a rule: the class is reported again where the rule covered it. A rule past its expiry date stops applying on its own. A product's rules are also listed on the Settings tab of its page.

In ScanSuite Teams, creating and retiring suppression rules needs permission to configure scans.

Last reviewed 2026-09-25