All templates

Automated Duo Security MFA Spam Alerts

Every hour, WebRun checks Duo Security's authentication log for users with repeated failed pushes or denied logins in a short window, a common sign of MFA push spam, texts your security on-call through Twilio, and archives the activity log to Google Drive for the record.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 Duo Security check for repeated denied logins
2 Twilio text security on-call
3 Google Drive archive the activity log
In short

How do I catch MFA push spam attacks against Duo Security before someone approves one by mistake?

WebRun checks Duo Security's authentication log every hour for users with repeated failed or denied MFA pushes, a common sign of push spam attacks. It texts your security on-call through Twilio and archives the flagged log entries to Google Drive. It never locks an account or resets anyone's MFA device on its own.

  • Push spam bursts reach on-call within the hour they start
  • Every flagged burst is archived for later incident review
  • Normal single failed logins never trigger a false alarm

Built for security operations teams · IT admins · on-call engineers · identity teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens admin.duosecurity.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Duo Security - check for repeated denied logins
    duo.com
    WebRun in Duo Security: check for repeated denied logins
    WebRun opens Duo Security to check for repeated denied logins.
    • Open Duo Security and review the authentication log for the past hour
    • Flag any user with several failed or denied pushes in a short window
    • Note the user, device, and approximate time for each flagged burst

    Done when This hour's log has been checked and any suspicious burst is documented.

  3. 2
    Twilio - text security on-call
    twilio.com
    WebRun in Twilio: text security on-call
    WebRun opens Twilio to text security on-call.
    • Send a text through Twilio to security on-call for each flagged user
    • Name the user and the number of denied attempts
    • Send nothing when no burst is found this hour

    Done when On-call has a text for any flagged burst, and nothing otherwise.

  4. 3
    Google Drive - archive the activity log
    drive.google.com
    WebRun in Google Drive: archive the activity log
    WebRun opens Google Drive to archive the activity log.
    • Open the authentication incidents folder in Google Drive
    • Save a copy of the flagged activity log entries with the date
    • Keep it alongside prior entries for later review

    Done when This hour's flagged entries, if any, are archived in Google Drive.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
admin.duosecurity.com
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
MFA spam alert · Twilio
OutputWhat each run produces - An hourly check of Duo's authentication log, with a Twilio text and an archived record only when a suspicious burst is found.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does WebRun lock the account or block the user?

No. WebRun only reads the authentication log and alerts on-call. Locking an account or resetting a user's MFA device is a manual step your security team takes in Duo.

Who gets the Twilio text?

Only your configured security on-call number. WebRun never texts the flagged user or anyone outside your security team.

Will normal failed logins trigger an alert?

No. It only alerts on a burst of repeated failed or denied pushes in a short window, not a single mistyped code.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.