Automated Sophos Alert Triage
Every morning, WebRun signs in to Sophos Central, reads the open alerts across your estate, records the severity, affected device, user, and age of each, opens a Trello triage card for every unresolved detection, and queues a Twilio text to the security lead whenever a high severity alert is still open.
How do I make sure every security alert gets triaged and owned?
WebRun triages your Sophos Central alerts every morning. It reads every open detection with its severity, device, user, and age, opens a dated Trello card for each so nothing sits unowned, and queues a Twilio text to the security lead whenever a high severity alert is still open.
- Every open detection has a card and an owner the same day
- High severity alerts reach the security lead without a dashboard check
- One noisy device is seen as a pattern instead of a wall of cards
Built for IT security teams · managed service providers · system administrators · small security operations teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
central.sophos.comin a real browser with your saved login - no setup, no API keys. -
1
Sophos - read the open alerts
- Sign in to Sophos Central and open the alerts view
- List every alert that is still open, with its severity, description, affected device, and user
- Record how long each alert has been open and whether it repeated on the same device
- Group alerts by device so one machine generating many detections is obvious
- Skip alerts already marked resolved or acknowledged
Done when Every open alert is captured with severity, device, user, and age.
-
2
Trello - open a triage card per alert
WebRun opens Trello to open a triage card per alert. - Open your security board and check the triage list for an existing card for that alert
- Create a card per new open alert, titled with the severity, device, and detection name
- Put the user, the alert age, the repeat count, and the Sophos link in the description
- Label the card by severity and set a due date matching your response target for that level
Done when Every open alert has one dated triage card and no duplicates were created.
-
3
Twilio - queue a text for high severity
WebRun opens Twilio to queue a text for high severity. - Open Twilio and compose a short alert for the security lead when a high severity detection is still open
- Include the detection name, the device, the user, and how long it has been open
- Leave the message queued as a draft for a human to approve and send
Done when A ready-to-send text exists for every high severity alert still open.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it resolve alerts or isolate a device?
No. WebRun reads Sophos Central and reports. Clearing an alert, isolating an endpoint, or changing a policy is always done by a security engineer.
Will it text the security lead automatically?
No. The Twilio message is written and left queued for a human to approve and send, so an out-of-hours page is always a deliberate choice.
How does it handle one noisy device?
Alerts are grouped by device with a repeat count, so a single machine generating many detections shows as one pattern rather than flooding the board.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.