All templates
For security teams, network engineers & SOC analysts

Know who changed your firewall rules

Every morning, WebRun signs in to Check Point, reviews the policy and configuration changes made in the last 24 hours, notes who made each one and what it touched, sends the list to your security Telegram channel, and files a dated change record in your Microsoft Teams channel for the audit trail.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every day at 7:00 AM WebRun
1 Check Point review policy changes
2 Telegram alert the security channel
3 Microsoft Teams file the change record
Run a sample
In short

How do I track who changed our firewall policy overnight?

WebRun signs in to Check Point every morning and reviews every policy and configuration change made in the last 24 hours, noting who made it and what it touched. It posts the list to your security Telegram channel and files a dated copy in Microsoft Teams, so no firewall edit goes unreviewed.

  • Every overnight policy edit is reviewed by 7am
  • Access-widening changes are flagged before they sit for a week
  • Teams holds a clean dated change log for audits

Built for security teams · network engineers · SOC analysts · compliance officers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.checkpoint.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Check Point - review policy changes
    checkpoint.com
    WebRun in Check Point: review policy changes
    WebRun opens Check Point to review policy changes.
    • Sign in to your Check Point management console
    • Open the audit or change history for the last 24 hours
    • Capture each change: who made it, what object or rule it touched, and when
    • Flag anything that widened access, disabled a rule, or changed an admin account

    Done when Every change in the last 24 hours has been captured with its author.

  3. 2
    Telegram - alert the security channel
    telegram.org How to Automate Telegram
    WebRun in Telegram: alert the security channel
    WebRun opens Telegram to alert the security channel.
    • Post the change list to your security Telegram channel
    • Put the access-widening and rule-disabling changes at the top
    • Say plainly when there were no changes overnight

    Done when The security channel has this morning's change list.

  4. 3
    Microsoft Teams - file the change record
    microsoft.com How to Automate Microsoft Teams
    WebRun in Microsoft Teams: file the change record
    WebRun opens Microsoft Teams to file the change record.
    • Post the same list as a dated record in your Teams compliance channel
    • Keep the format identical each day so the channel reads as a clean change log
    • Tag the on-call engineer when a flagged change has no ticket reference

    Done when Today's dated change record is filed in Teams.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.checkpoint.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Policy change log · Telegram
OutputWhat each run produces - A daily record of Check Point policy and configuration changes: the author, the object touched, the timestamp, and a flag on anything that widened access.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Can it change or roll back a firewall rule?

No. WebRun reads your Check Point change history and reports it. It never edits a rule, installs a policy, or reverts a change. Every remediation stays a human decision.

What counts as a change worth flagging?

Anything that widens access, disables a rule, or touches an admin account is pushed to the top of the list. You can add your own flag conditions when you turn the template on.

Does it work with more than one management domain?

Yes. Point it at each management domain or console you use and WebRun walks them in turn, then merges everything into one dated log.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.