All templates

Automated Proofpoint Daily Threat Digest

Every morning, WebRun opens Proofpoint, reviews the last day's blocked phishing and malware email threats, saves a copy of the threat report to Google Drive, and texts your security lead a short summary through Twilio naming the top targeted employees.

Runs on WebRun · Strict Lockdown policy
Every day at 7:00 AM WebRunorchestrates each step
1 Proofpoint review blocked email threats
2 Google Drive archive the threat report
3 Twilio text the security lead
In short

How do I find out which employees Proofpoint is catching the most phishing attempts against?

WebRun reviews Proofpoint every morning for the last day's blocked phishing and malware email threats, saves the report to Google Drive, and texts your security lead a summary through Twilio naming the top targeted employees and threat types. It never quarantines or deletes a message itself, only reports what was blocked.

  • Top targeted employees are visible every morning, not buried in a console
  • Threat reports are archived daily for trend comparison over time
  • No phishing content is ever shared, only counts and targets

Built for security teams · IT admins · email security administrators · CISOs

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.proofpoint.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Proofpoint - review blocked email threats
    proofpoint.com
    WebRun in Proofpoint: review blocked email threats
    WebRun opens Proofpoint to review blocked email threats.
    • Open Proofpoint and review blocked phishing and malware threats from the last 24 hours
    • Rank the most targeted employees and the most common threat type
    • Note any threat that got close to landing in an inbox

    Done when The last day's blocked threats are ranked by employee and type.

  3. 2
    Google Drive - archive the threat report
    drive.google.com
    WebRun in Google Drive: archive the threat report
    WebRun opens Google Drive to archive the threat report.
    • Open the email security folder in Google Drive
    • Save a copy of today's threat report with the date
    • Keep it alongside prior days for trend comparison

    Done when Today's threat report is archived in Google Drive.

  4. 3
    Twilio - text the security lead
    twilio.com
    WebRun in Twilio: text the security lead
    WebRun opens Twilio to text the security lead.
    • Send a text through Twilio to the security lead with today's top targeted employees
    • Include the total blocked count and the most common threat type
    • Flag anything that nearly reached an inbox

    Done when The security lead has today's summary by text.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.proofpoint.com
ScheduleRuns automatically on this cadence
Every day at 7:00 AM
DeliveryHow each run's result reaches you
Threat digest · Twilio
OutputWhat each run produces - A daily summary of blocked phishing and malware threats by employee, archived in Google Drive.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does WebRun quarantine or delete any emails itself?

No. WebRun only reports what Proofpoint already blocked or quarantined. Releasing or deleting a message stays a manual step for your security team.

Does the text include the phishing email's content?

No. It only shares who was targeted, the threat type, and counts, never the content of the phishing message itself.

Who receives the Twilio text?

Only your configured security lead number. WebRun never contacts the targeted employee directly about the attempt.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.