Automated Proofpoint Daily Threat Digest
Every morning, WebRun opens Proofpoint, reviews the last day's blocked phishing and malware email threats, saves a copy of the threat report to Google Drive, and texts your security lead a short summary through Twilio naming the top targeted employees.
How do I find out which employees Proofpoint is catching the most phishing attempts against?
WebRun reviews Proofpoint every morning for the last day's blocked phishing and malware email threats, saves the report to Google Drive, and texts your security lead a summary through Twilio naming the top targeted employees and threat types. It never quarantines or deletes a message itself, only reports what was blocked.
- Top targeted employees are visible every morning, not buried in a console
- Threat reports are archived daily for trend comparison over time
- No phishing content is ever shared, only counts and targets
Built for security teams · IT admins · email security administrators · CISOs
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.proofpoint.comin a real browser with your saved login - no setup, no API keys. -
1
Proofpoint - review blocked email threats
WebRun opens Proofpoint to review blocked email threats. - Open Proofpoint and review blocked phishing and malware threats from the last 24 hours
- Rank the most targeted employees and the most common threat type
- Note any threat that got close to landing in an inbox
Done when The last day's blocked threats are ranked by employee and type.
-
2
Google Drive - archive the threat report
WebRun opens Google Drive to archive the threat report. - Open the email security folder in Google Drive
- Save a copy of today's threat report with the date
- Keep it alongside prior days for trend comparison
Done when Today's threat report is archived in Google Drive.
-
3
Twilio - text the security lead
WebRun opens Twilio to text the security lead. - Send a text through Twilio to the security lead with today's top targeted employees
- Include the total blocked count and the most common threat type
- Flag anything that nearly reached an inbox
Done when The security lead has today's summary by text.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun quarantine or delete any emails itself?
No. WebRun only reports what Proofpoint already blocked or quarantined. Releasing or deleting a message stays a manual step for your security team.
Does the text include the phishing email's content?
No. It only shares who was targeted, the threat type, and counts, never the content of the phishing message itself.
Who receives the Twilio text?
Only your configured security lead number. WebRun never contacts the targeted employee directly about the attempt.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.