Get alerted when firewall threats cross your threshold
Every morning, WebRun opens WatchGuard Cloud, checks blocked threats and failed login attempts across your Firebox appliances, posts the daily summary to Slack, and escalates to Telegram when the blocked threat count crosses your threshold.
- No credit card
- Under $0.01 per run
- Cancel anytime
How do I get alerted when WatchGuard firewall threats cross a threshold?
WebRun checks WatchGuard Cloud every morning for blocked threats and failed login attempts across your Firebox appliances, posts the daily summary to Slack, and escalates to Telegram when the blocked threat count crosses your threshold. It only reads firewall activity, so rule changes stay with your team.
- Blocked threats and failed logins are summarized every morning
- Escalation only fires once your threshold is actually crossed
- Firewall rule changes always stay with your IT team
Built for IT admins · network security teams · MSPs · security operations
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.watchguard.comin a real browser with your saved login - no setup, no API keys. -
1
WatchGuard - check blocked threats and logins
WebRun opens WatchGuard to check blocked threats and logins. - Open WatchGuard Cloud and check blocked threats and failed login attempts from the last 24 hours
- Read the threat type and source for each blocked event
- Count the total blocked threats for the day
Done when Every blocked threat and failed login from the last 24 hours has been read.
-
2
Slack - post the daily summary
WebRun opens Slack to post the daily summary. - Post the daily summary of blocked threats and failed logins to the IT Slack channel
- Break it down by threat type and source
- Leave investigating any individual event to the IT team
Done when Today's summary has been posted to Slack.
-
3
Telegram - escalate past the threshold
WebRun opens Telegram to escalate past the threshold. - If the blocked threat count is above your set threshold, escalate to the on call Telegram channel
- Keep the escalation to the count and top threat type
- Stay silent when the count is under threshold to avoid noise
Done when IT has been escalated to whenever the threat count crosses the threshold.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will WebRun change a firewall rule or block an address itself?
No. WebRun only reads blocked threats and failed logins that WatchGuard has already handled. Changing a rule or policy stays with your IT team.
What sets the escalation threshold?
You set the blocked threat count that should trigger a Telegram escalation. WebRun only escalates once that count is reached or crossed.
Does it ever unblock or allow a previously blocked source?
No. WebRun never changes what WatchGuard has blocked or allowed. It only reports on activity that already happened.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.