Automated Duo Security MFA Spam Alerts
Every hour, WebRun checks Duo Security's authentication log for users with repeated failed pushes or denied logins in a short window, a common sign of MFA push spam, texts your security on-call through Twilio, and archives the activity log to Google Drive for the record.
How do I catch MFA push spam attacks against Duo Security before someone approves one by mistake?
WebRun checks Duo Security's authentication log every hour for users with repeated failed or denied MFA pushes, a common sign of push spam attacks. It texts your security on-call through Twilio and archives the flagged log entries to Google Drive. It never locks an account or resets anyone's MFA device on its own.
- Push spam bursts reach on-call within the hour they start
- Every flagged burst is archived for later incident review
- Normal single failed logins never trigger a false alarm
Built for security operations teams · IT admins · on-call engineers · identity teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
admin.duosecurity.comin a real browser with your saved login - no setup, no API keys. -
1
Duo Security - check for repeated denied logins
WebRun opens Duo Security to check for repeated denied logins. - Open Duo Security and review the authentication log for the past hour
- Flag any user with several failed or denied pushes in a short window
- Note the user, device, and approximate time for each flagged burst
Done when This hour's log has been checked and any suspicious burst is documented.
-
2
Twilio - text security on-call
WebRun opens Twilio to text security on-call. - Send a text through Twilio to security on-call for each flagged user
- Name the user and the number of denied attempts
- Send nothing when no burst is found this hour
Done when On-call has a text for any flagged burst, and nothing otherwise.
-
3
Google Drive - archive the activity log
WebRun opens Google Drive to archive the activity log. - Open the authentication incidents folder in Google Drive
- Save a copy of the flagged activity log entries with the date
- Keep it alongside prior entries for later review
Done when This hour's flagged entries, if any, are archived in Google Drive.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun lock the account or block the user?
No. WebRun only reads the authentication log and alerts on-call. Locking an account or resetting a user's MFA device is a manual step your security team takes in Duo.
Who gets the Twilio text?
Only your configured security on-call number. WebRun never texts the flagged user or anyone outside your security team.
Will normal failed logins trigger an alert?
No. It only alerts on a burst of repeated failed or denied pushes in a short window, not a single mistyped code.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.