All templates

Automated Sophos Alert Triage

Every morning, WebRun signs in to Sophos Central, reads the open alerts across your estate, records the severity, affected device, user, and age of each, opens a Trello triage card for every unresolved detection, and queues a Twilio text to the security lead whenever a high severity alert is still open.

Runs on WebRun · Strict Lockdown policy
Every day at 8:00 AM WebRunorchestrates each step
1 Sophos read the open alerts
2 Trello open a triage card per alert
3 Twilio queue a text for high severity
In short

How do I make sure every security alert gets triaged and owned?

WebRun triages your Sophos Central alerts every morning. It reads every open detection with its severity, device, user, and age, opens a dated Trello card for each so nothing sits unowned, and queues a Twilio text to the security lead whenever a high severity alert is still open.

  • Every open detection has a card and an owner the same day
  • High severity alerts reach the security lead without a dashboard check
  • One noisy device is seen as a pattern instead of a wall of cards

Built for IT security teams · managed service providers · system administrators · small security operations teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens central.sophos.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Sophos - read the open alerts
    • Sign in to Sophos Central and open the alerts view
    • List every alert that is still open, with its severity, description, affected device, and user
    • Record how long each alert has been open and whether it repeated on the same device
    • Group alerts by device so one machine generating many detections is obvious
    • Skip alerts already marked resolved or acknowledged

    Done when Every open alert is captured with severity, device, user, and age.

  3. 2
    Trello - open a triage card per alert
    trello.com
    WebRun in Trello: open a triage card per alert
    WebRun opens Trello to open a triage card per alert.
    • Open your security board and check the triage list for an existing card for that alert
    • Create a card per new open alert, titled with the severity, device, and detection name
    • Put the user, the alert age, the repeat count, and the Sophos link in the description
    • Label the card by severity and set a due date matching your response target for that level

    Done when Every open alert has one dated triage card and no duplicates were created.

  4. 3
    Twilio - queue a text for high severity
    twilio.com
    WebRun in Twilio: queue a text for high severity
    WebRun opens Twilio to queue a text for high severity.
    • Open Twilio and compose a short alert for the security lead when a high severity detection is still open
    • Include the detection name, the device, the user, and how long it has been open
    • Leave the message queued as a draft for a human to approve and send

    Done when A ready-to-send text exists for every high severity alert still open.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
central.sophos.com
ScheduleRuns automatically on this cadence
Every day at 8:00 AM
DeliveryHow each run's result reaches you
Alert triage list · Trello
OutputWhat each run produces - A morning triage list of open Sophos alerts with severity, detection name, device, user, age, repeat count, and the Trello card for each.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it resolve alerts or isolate a device?

No. WebRun reads Sophos Central and reports. Clearing an alert, isolating an endpoint, or changing a policy is always done by a security engineer.

Will it text the security lead automatically?

No. The Twilio message is written and left queued for a human to approve and send, so an out-of-hours page is always a deliberate choice.

How does it handle one noisy device?

Alerts are grouped by device with a repeat count, so a single machine generating many detections shows as one pattern rather than flooding the board.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.