All templates

Automated Mandiant Threat Intelligence Digest

Every morning, WebRun opens Mandiant Advantage, checks for new threat intelligence relevant to your industry and assets, logs each item to Airtable as a searchable record, and emails your security team the daily digest in Gmail.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 Mandiant check new threat intelligence
2 Airtable log each item as a record
3 Gmail email the daily digest
In short

How do I get a daily, searchable digest of Mandiant threat intelligence?

WebRun checks Mandiant Advantage every morning for threat intelligence relevant to your organization, logs each item to Airtable as a searchable record with the actor and technique, and emails your security team the daily digest in Gmail. It only reads and logs, so any response stays with your team.

  • Relevant threat intelligence reaches the team every morning
  • Past intelligence stays searchable by actor and technique
  • Any defensive action always stays a human decision

Built for threat intelligence teams · SOC analysts · CISOs · security operations

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.mandiant.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Mandiant - check new threat intelligence
    mandiant.com
    WebRun in Mandiant: check new threat intelligence
    WebRun opens Mandiant to check new threat intelligence.
    • Open Mandiant Advantage and check threat intelligence published in the last 24 hours
    • Filter to items relevant to your industry, region, or watched assets
    • Read the threat actor, technique, and summary for each

    Done when Every relevant item published in the last 24 hours has been read.

  3. 2
    Airtable - log each item as a record
    airtable.com
    WebRun in Airtable: log each item as a record
    WebRun opens Airtable to log each item as a record.
    • Open the threat intelligence base in Airtable
    • Log each item as a record with the actor, technique, and summary
    • Tag records so past intelligence stays searchable by actor or technique

    Done when Every item from this run has a searchable Airtable record.

  4. 3
    Gmail - email the daily digest
    gmail.com
    WebRun in Gmail: email the daily digest
    WebRun opens Gmail to email the daily digest.
    • Draft a digest email listing today's relevant threat intelligence
    • Send it to your security team's distribution list
    • Leave any response or defensive change to the team

    Done when The security team has today's digest in their inbox.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.mandiant.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Threat intel digest · Gmail
OutputWhat each run produces - A daily digest of relevant threat intelligence, logged as searchable Airtable records.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will WebRun act on a threat it finds?

No. WebRun only reads and logs threat intelligence. Any defensive change, block, or response stays with your security team.

How does it decide what's relevant?

It reads the filters Mandiant already applies for your industry, region, and watched assets, it does not invent its own relevance scoring.

Can past threat intelligence be searched later?

Yes. Every item is logged as an Airtable record tagged by actor and technique, so the team can search back through prior digests.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.