Automated Wiz Critical Exposure Alerts
Every hour, WebRun checks Wiz for newly discovered critical severity findings, such as toxic combinations of exposure, permissions, and vulnerability, sends a Telegram alert naming the affected resource, and escalates by Twilio text if the same finding is still open at the next check.
How do I get alerted immediately when Wiz finds a critical cloud exposure?
WebRun checks Wiz every hour for newly discovered critical severity cloud findings, including toxic combinations, sends a Telegram alert naming the resource and account, and escalates by Twilio text if the finding is still open an hour later. It never changes a cloud configuration itself, only detects and alerts on it.
- Critical cloud findings reach the team within the hour they're discovered
- Unresolved findings escalate automatically instead of aging quietly
- Low and medium severity noise never triggers an alert
Built for cloud security teams · DevSecOps teams · platform engineers · CISOs
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
app.wiz.ioin a real browser with your saved login - no setup, no API keys. -
1
Wiz - check for new critical findings
WebRun opens Wiz to check for new critical findings. - Open Wiz and check for findings discovered in the last hour
- Filter to critical severity, including toxic combinations
- Note the affected resource, cloud account, and finding type
Done when Any new critical finding this hour is listed with resource and account.
-
2
Telegram - alert the cloud security team
WebRun opens Telegram to alert the cloud security team. - Send a Telegram alert naming the resource, account, and finding type
- Include a link to the finding in Wiz
- Send nothing when no new critical finding this hour
Done when Every new critical finding has a Telegram alert.
-
3
Twilio - escalate if still open
WebRun opens Twilio to escalate if still open. - Send a text through Twilio only if the same finding is still open at the next hourly check
- Name the resource and how long it has been open
- Stop escalating once the finding is resolved
Done when Any finding still open after an hour has triggered a Twilio escalation.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun fix the misconfiguration itself?
No. WebRun only detects and alerts on the finding. Changing a cloud configuration or permission is a manual step your engineering team takes.
Will I get an alert for every low severity finding?
No. It only alerts on critical severity findings, including toxic combinations Wiz flags as most urgent, not routine low or medium findings.
Who receives the escalation text?
Only your configured cloud security on-call number. WebRun never contacts anyone outside your security team.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.