All templates
For IT administrators, security analysts & managed service providers

Get one clear brief on yesterday's security incidents

Every morning, WebRun opens Microsoft Defender, reads the incidents and alerts raised in the last 24 hours with their severity, status, and affected users or devices, sends your security group a short WhatsApp brief ranked by severity, and books a Google Calendar review block whenever a high severity incident is still unresolved.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every day at 7:30 AM WebRun
1 Microsoft Defender read overnight incidents
2 WhatsApp send the ranked brief
3 Google Calendar book a review on high severity
Run a sample
In short

How do I get a daily summary of security incidents?

WebRun opens Microsoft Defender every morning and reads the incidents and alerts raised in the last 24 hours with severity, status, and owner. It sends your security group a ranked WhatsApp brief and books a Google Calendar review block whenever a high severity incident is still open.

  • One ranked brief replaces scrolling the incident queue
  • Unassigned incidents get an owner first thing
  • A review is booked automatically when something high severity is open

Built for IT administrators · security analysts · managed service providers · compliance leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens security.microsoft.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Microsoft Defender - read overnight incidents
    security.microsoft.com
    WebRun in Microsoft Defender: read overnight incidents
    WebRun opens Microsoft Defender to read overnight incidents.
    • Open Microsoft Defender and go to the Incidents and alerts queue
    • Capture every incident raised in the last 24 hours with severity, status, and assigned owner
    • Note the affected users, devices, or mailboxes on each one
    • Flag anything still unassigned or unresolved from previous days
    • Read only. Never resolve, close, reassign, or take a response action on an incident

    Done when Every incident from the last 24 hours is listed with severity, status, and owner.

  3. 2
    WhatsApp - send the ranked brief
    whatsapp.com How to Automate WhatsApp
    WebRun in WhatsApp: send the ranked brief
    WebRun opens WhatsApp to send the ranked brief.
    • Send a short brief to your internal security group on WhatsApp
    • Lead with the count by severity and the single most serious open incident
    • List unassigned incidents so ownership is settled first thing
    • Name affected users only by role or initials, never with full account detail
    • Keep it to your own team group. Never message an affected employee

    Done when The security team has this morning's ranked incident brief on WhatsApp.

  4. 3
    Google Calendar - book a review on high severity
    calendar.google.com How to Automate Google Calendar
    WebRun in Google Calendar: book a review on high severity
    WebRun opens Google Calendar to book a review on high severity.
    • Check whether any high severity incident is still open
    • If so, book a 30 minute incident review this morning with the security owners
    • Put the incident IDs and their severity in the event description
    • Skip the booking entirely on mornings with nothing high severity open

    Done when A review is on the calendar for any morning with an open high severity incident.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
security.microsoft.com
ScheduleRuns automatically on this cadence
Every day at 7:30 AM
DeliveryHow each run's result reaches you
Incident brief · WhatsApp
OutputWhat each run produces - A WhatsApp brief of the last 24 hours of Defender incidents ranked by severity, plus a calendar review block on mornings with an open high severity incident.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Can it resolve or close an incident?

No. WebRun reads the Microsoft Defender queue only. It never closes an incident, isolates a device, blocks a user, or runs a response action. Every containment decision stays with your security team.

Is it safe to send security details over WhatsApp?

The brief names incident IDs, severity, and status, and refers to affected people by role or initials rather than full account detail. Keep the group internal, and use the Defender console itself for anything sensitive.

What if nothing happened overnight?

You still get a short brief saying the queue was clear, so a quiet morning is confirmed rather than mistaken for a run that failed to happen.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.