Automated Mandiant Threat Intelligence Digest
Every morning, WebRun opens Mandiant Advantage, checks for new threat intelligence relevant to your industry and assets, logs each item to Airtable as a searchable record, and emails your security team the daily digest in Gmail.
How do I get a daily, searchable digest of Mandiant threat intelligence?
WebRun checks Mandiant Advantage every morning for threat intelligence relevant to your organization, logs each item to Airtable as a searchable record with the actor and technique, and emails your security team the daily digest in Gmail. It only reads and logs, so any response stays with your team.
- Relevant threat intelligence reaches the team every morning
- Past intelligence stays searchable by actor and technique
- Any defensive action always stays a human decision
Built for threat intelligence teams · SOC analysts · CISOs · security operations
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.mandiant.comin a real browser with your saved login - no setup, no API keys. -
1
Mandiant - check new threat intelligence
WebRun opens Mandiant to check new threat intelligence. - Open Mandiant Advantage and check threat intelligence published in the last 24 hours
- Filter to items relevant to your industry, region, or watched assets
- Read the threat actor, technique, and summary for each
Done when Every relevant item published in the last 24 hours has been read.
-
2
Airtable - log each item as a record
WebRun opens Airtable to log each item as a record. - Open the threat intelligence base in Airtable
- Log each item as a record with the actor, technique, and summary
- Tag records so past intelligence stays searchable by actor or technique
Done when Every item from this run has a searchable Airtable record.
-
3
Gmail - email the daily digest
WebRun opens Gmail to email the daily digest. - Draft a digest email listing today's relevant threat intelligence
- Send it to your security team's distribution list
- Leave any response or defensive change to the team
Done when The security team has today's digest in their inbox.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will WebRun act on a threat it finds?
No. WebRun only reads and logs threat intelligence. Any defensive change, block, or response stays with your security team.
How does it decide what's relevant?
It reads the filters Mandiant already applies for your industry, region, and watched assets, it does not invent its own relevance scoring.
Can past threat intelligence be searched later?
Yes. Every item is logged as an Airtable record tagged by actor and technique, so the team can search back through prior digests.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.