All templates
For security operations teams, IT managers & managed security providers

Make sure critical Darktrace alerts reach a person

Every hour, WebRun opens Darktrace, reads the newest model breaches and incidents, keeps only the ones above your severity line, posts each to the security Slack channel with the device and affected user, and texts the on-call analyst through Twilio.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every hour WebRun
1 Darktrace pull high severity breaches
2 Slack post the incident detail
3 Twilio text the on-call analyst
Run a sample
In short

How do I make sure critical Darktrace alerts reach the on-call analyst?

Every hour WebRun opens Darktrace, reads the newest model breaches, and keeps only the highest severity incidents. WebRun posts each one to Slack with the affected device, the user, and what triggered it, then texts your on-call analyst through Twilio, so a critical alert never waits for someone to open the console.

  • Critical breaches reach a phone within the hour, not the next console login
  • Every alert carries the device, the user, and the trigger in one message
  • Low severity and already acknowledged items never reach the on-call rota

Built for security operations teams · IT managers · managed security providers · on-call analysts

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.darktrace.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Darktrace - pull high severity breaches
    darktrace.com
    WebRun in Darktrace: pull high severity breaches
    WebRun opens Darktrace to pull high severity breaches.
    • Open Darktrace and list model breaches and incidents raised in the last hour
    • Keep only items at or above the severity score you set, and drop anything already acknowledged
    • Capture the affected device, the user, the severity score, and the investigation notes for each

    Done when Every new breach above your severity line is listed with its device and score.

  3. 2
    Slack - post the incident detail
    slack.com How to Automate Slack
    WebRun in Slack: post the incident detail
    WebRun opens Slack to post the incident detail.
    • Post each qualifying breach to the security channel, highest severity first
    • Include the device, the affected user, the severity score, and what triggered the model
    • Link straight back to the incident in Darktrace so the analyst lands on the right page

    Done when Each new high severity breach has a Slack post with its full detail and a link.

  4. 3
    Twilio - text the on-call analyst
    twilio.com How to Automate Twilio
    WebRun in Twilio: text the on-call analyst
    WebRun opens Twilio to text the on-call analyst.
    • Send a short SMS to the on-call number saved during setup, naming the device and severity
    • Text only numbers on your own on-call rota. Messages to anyone outside that list are drafted and held for your approval
    • Never contact an affected end user or a customer. Escalation stays inside the security team

    Done when The on-call analyst has been texted about every critical breach this hour.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.darktrace.com
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Critical alert · Slack
OutputWhat each run produces - Each run produces a Slack post per high severity breach with device, user, and trigger detail, plus an SMS summary to the on-call analyst.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it text people without my approval?

It texts only the on-call numbers you saved during setup. Any message to a number outside that rota is drafted and held for your approval, and it never texts an affected user or a customer.

Can it act on a breach or change anything in Darktrace?

No. WebRun reads the console and reports. It never acknowledges, closes, quarantines, or takes any response action, so every decision stays with your analyst.

How do I stop being paged for noise?

You set the severity line, and WebRun drops anything below it plus anything already acknowledged in Darktrace, so only genuinely new critical items reach the phone.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.