All templates

Automated CrowdStrike Critical Detection Alerts

Every hour, WebRun checks CrowdStrike Falcon for new high and critical severity detections, logs each one to a Google Sheet with the host, tactic, and status, and emails your on-call inbox the moment a critical severity detection appears.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 CrowdStrike check for new detections
2 Google Sheets log every detection
3 Gmail email on-call for critical hits
In short

How do I get notified immediately when CrowdStrike Falcon flags a critical detection?

WebRun checks CrowdStrike Falcon every hour for new detections, logs every one, regardless of severity, to a Google Sheet with the host and tactic, and sends an immediate Gmail alert to your on-call address only when a detection is critical severity. It never takes containment action itself, so response stays with your team.

  • Critical detections reach on-call within the hour instead of at the next log review
  • Every detection, big or small, is logged so nothing is lost to alert fatigue
  • Non-critical activity stays out of your inbox entirely

Built for security operations teams · IT admins · managed detection providers · on-call engineers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens falcon.crowdstrike.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    CrowdStrike - check for new detections
    crowdstrike.com
    WebRun in CrowdStrike: check for new detections
    WebRun opens CrowdStrike to check for new detections.
    • Open Falcon and check detections from the last hour
    • Note severity, host, and the tactic or technique involved for each
    • Separate critical severity detections from high and below

    Done when This hour's detections are listed with severity, host, and tactic.

  3. 2
    Google Sheets - log every detection
    google.com
    WebRun in Google Sheets: log every detection
    WebRun opens Google Sheets to log every detection.
    • Open the detections tracker in Google Sheets
    • Add a row for every new detection regardless of severity
    • Mark critical rows so they stand out in the sheet

    Done when Every detection from this hour has a row in the tracker.

  4. 3
    Gmail - email on-call for critical hits
    gmail.com
    WebRun in Gmail: email on-call for critical hits
    WebRun opens Gmail to email on-call for critical hits.
    • Draft and send an email to the on-call address only for critical severity detections
    • Include the host, tactic, and a link to the Falcon console
    • Send nothing when there is no critical detection this hour

    Done when On-call has an email for any critical detection, and nothing otherwise.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
falcon.crowdstrike.com
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Critical detection alert · Gmail
OutputWhat each run produces - Every detection logged to a running Google Sheet, with an immediate email only for critical severity hits.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does WebRun take any containment action in Falcon?

No. WebRun only reads detections and reports them. Isolating a host, killing a process, or any other containment action is left for your security team to trigger in Falcon.

Will I get an email for every detection?

No. Every detection is logged to the Google Sheet, but Gmail only sends when a detection is critical severity, so on-call isn't flooded.

Who receives the email alert?

Only the internal on-call address you set. WebRun never emails outside your organization about a detection.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.