Automated CrowdStrike Critical Detection Alerts
Every hour, WebRun checks CrowdStrike Falcon for new high and critical severity detections, logs each one to a Google Sheet with the host, tactic, and status, and emails your on-call inbox the moment a critical severity detection appears.
How do I get notified immediately when CrowdStrike Falcon flags a critical detection?
WebRun checks CrowdStrike Falcon every hour for new detections, logs every one, regardless of severity, to a Google Sheet with the host and tactic, and sends an immediate Gmail alert to your on-call address only when a detection is critical severity. It never takes containment action itself, so response stays with your team.
- Critical detections reach on-call within the hour instead of at the next log review
- Every detection, big or small, is logged so nothing is lost to alert fatigue
- Non-critical activity stays out of your inbox entirely
Built for security operations teams · IT admins · managed detection providers · on-call engineers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
falcon.crowdstrike.comin a real browser with your saved login - no setup, no API keys. -
1
CrowdStrike - check for new detections
WebRun opens CrowdStrike to check for new detections. - Open Falcon and check detections from the last hour
- Note severity, host, and the tactic or technique involved for each
- Separate critical severity detections from high and below
Done when This hour's detections are listed with severity, host, and tactic.
-
2
Google Sheets - log every detection
WebRun opens Google Sheets to log every detection. - Open the detections tracker in Google Sheets
- Add a row for every new detection regardless of severity
- Mark critical rows so they stand out in the sheet
Done when Every detection from this hour has a row in the tracker.
-
3
Gmail - email on-call for critical hits
WebRun opens Gmail to email on-call for critical hits. - Draft and send an email to the on-call address only for critical severity detections
- Include the host, tactic, and a link to the Falcon console
- Send nothing when there is no critical detection this hour
Done when On-call has an email for any critical detection, and nothing otherwise.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun take any containment action in Falcon?
No. WebRun only reads detections and reports them. Isolating a host, killing a process, or any other containment action is left for your security team to trigger in Falcon.
Will I get an email for every detection?
No. Every detection is logged to the Google Sheet, but Gmail only sends when a detection is critical severity, so on-call isn't flooded.
Who receives the email alert?
Only the internal on-call address you set. WebRun never emails outside your organization about a detection.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.