All templates
For security analysts, SOC teams & IT managers

Close out the threats that were never resolved

Every morning, WebRun signs in to SentinelOne, lists every threat still unresolved with the endpoint, the analyst verdict, the assignee, and how many days it has been open, sends the aging backlog oldest first to your security Telegram channel, and texts the on-call analyst through Twilio when an incident passes your resolution target.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every day at 7:00 AM WebRun
1 SentinelOne list threats still unresolved
2 Telegram send the aging backlog
3 Twilio text the analyst on overdue incidents
Run a sample
In short

How do I track security threats that were detected but never resolved?

WebRun works your security backlog every morning. It lists every unresolved SentinelOne threat with its endpoint, verdict, assignee, and days open, sends the aging list oldest first to Telegram, and texts the on-call analyst through Twilio on anything past target, so nothing stays half handled.

  • The oldest open incident is named every single morning
  • Unassigned threats surface before they age another day
  • Handovers between shifts start from one aging list

Built for security analysts · SOC teams · IT managers · managed service providers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.sentinelone.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    SentinelOne - list threats still unresolved
    sentinelone.com
    WebRun in SentinelOne: list threats still unresolved
    WebRun opens SentinelOne to list threats still unresolved.
    • Sign in to the SentinelOne console and filter threats to anything not in a resolved state
    • Capture each one with the endpoint, the detection date, the analyst verdict where set, the current incident status, and the assignee
    • Work out how many days each has been open and note which have no verdict and which have no assignee at all

    Done when Every unresolved threat has an age, a verdict state, and an owner or a gap where one should be.

  3. 2
    Telegram - send the aging backlog
    telegram.org How to Automate Telegram
    WebRun in Telegram: send the aging backlog
    WebRun opens Telegram to send the aging backlog.
    • Send the security channel today's backlog with the oldest incident first and the age in days on each line
    • Group by assignee so each analyst can see their own queue, and put unassigned incidents in their own block at the top
    • Compare the count against yesterday so the channel can see whether the backlog is growing or shrinking

    Done when The security channel has today's aging backlog grouped by owner.

  4. 3
    Twilio - text the analyst on overdue incidents
    twilio.com How to Automate Twilio
    WebRun in Twilio: text the analyst on overdue incidents
    WebRun opens Twilio to text the analyst on overdue incidents.
    • Text the on-call analyst's own number when an incident passes the resolution target you set, naming the endpoint and the age
    • Send one combined text per run listing the overdue incidents together, rather than a message per threat
    • Leave every action in the console to your analysts. WebRun never resolves, dismisses, quarantines, or reclassifies a threat

    Done when The on-call analyst has been alerted to every incident past its target.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.sentinelone.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Aging backlog · Telegram
OutputWhat each run produces - A daily aging backlog of unresolved threats: endpoint, verdict, assignee, and days open, oldest first.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it resolve or dismiss threats itself?

No. WebRun reads the console and reports the backlog. Resolving, dismissing, quarantining, or reclassifying a threat is always an analyst decision, never an automated one.

How is this different from a daily threat digest?

A digest covers what happened overnight. This covers what is still open: incidents raised days ago that nobody closed, ordered oldest first with the owner named.

Who gets the overdue text?

Only your on-call analyst's own number, and only for incidents past the resolution target you set. One combined text per run keeps it to a single interruption.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.