Security

Built by security practitioners for security practitioners

Discover some of our favorite stories for inspiration towards your next build.

Team
Explore

Dive into specific areas of cloud security

Founded by security practitioners, we know the importance of SOAR. Explore some examples of ways customers use Tines to modernize the way they view SOAR.

📧virustotaljira

Analyze and triage suspicious emails with various tools

Submit suspicious emails and investigate with a comprehensive analysis of files, URLs, and headers. Add IOCs to various tool blocklists in order to limit impact of phishing campaigns.

Created by

Michael Tolan

Import

Loading story...

How it works

Instantly import stories to your tenant where you can adapt them to meet your unique business requirements.

Explore
Import
Adapt
Get started fast

Learners welcome

Step through beginner to advanced topics as you explore our tailored courses on Tines Stories University

Freshly baked

Latest stories

See more

tinestines🔒🔗Sync Insider Threat Matrix records and attach to CasesRetrieve categories from the Insider Threat Matrix website, sync them into a Tines Stories record type, and let analysts attach or detach matching records from Cases.
emailrepslackjiraDetect deepfakes with Reality Defender and triage in JiraAnalyze uploaded files for deepfakes using Reality Defender, enrich results with Twilio phone and EmailRep email intelligence, then create Jira tickets, Cases, and Slack alerts for suspicious submissions.Tools: EmailRep, Reality Defender, Slack, Twilio
awsawstinestines🔎Audit AWS security and compliance and document in Google SheetsAudit AWS S3 buckets, EC2 security groups, EC2 instances, IAM credentials, and EBS volumes for security and compliance gaps. Export findings to a formatted Google Sheets workpaper for review and documentationTools: AWS
⚠️📋🤖Manage a risk register using AI-driven scoring and recordsSubmit risks via Workbench or an internal Tines Page, score them automatically with AI, and track results in a risk register using records.
dratadrataworkramptinestinesSync security awareness training completions from WorkRamp to DrataFetches daily security awareness training completion records from WorkRamp and uploads them as evidence to Drata for users failing the security training compliance check.Tools: BambooHR, Drata, Google, WorkRamp
githubgithubgoogle-sheetstinestinesGenerate a merge audit report for GitHub pull requests in Google SheetsGenerate an audit report of merged GitHub pull requests, capturing each PR's title, author, URL, and merge date for compliance review. Store in a timestamped Google Sheet for easy trackingTools: GitHub, Google Sheets
crowdstrike🕵️⏱

Run a CrowdStrike Real Time Response command

This Story will run a given CrowdStrike RTR command against a provided Host ID. All default RTR scripts can be used.

Import

Loading story...

Partner spotlight

Tines achieves AWS security competency

awsaws🔎⚠️Isolate & remediate AWS EC2 instance based on IOCReceive IOC from an external system and report notifications in Jira. Determine if IOC is actionable, if so remediate AWS EC2 instance based on IOC, and update Jira.Tools: AWS, Jira Software, Slack
awsawsslack🗄️Alert on AWS Backup changes and record in CodeCommitUse AWS CloudTrail to send AWS Backup events to Slack. Record modifications in AWS CodeCommit for version control of backup plans.Tools: AWS, Slack
🔑awsawsdratadrataScheduled rotation & tracking for AWS Access Keys in DrataThis Story automates the key rotation when the key is greater than 90 days, saving the system administrator time and money and helping to maintain security compliance. All of this process is captured as evidence from the Jira ticket and added as evidence in Drata.Tools: AWS, Drata, Jira Software
🔑awsaws🔁Rotate AWS access keys on scheduleRotate access keys in AWS KMS when the key is greater than 90 days old.Tools: AWS
awsaws🧼jiraCleanup inactive users in AWS IAMSearch for inactive or unused AWS IAM users and create a Jira issue with all of the important details if any are found. Prompts enable the deactivation and reactivation of an account if required.Tools: AWS, Jira Software
awsaws📈🧑‍🔧Remediate vulnerabilities identified by AWS Inspector v2Receive vulnerability information from AWS Inspector v2 and create a JIRA ticket with the details. Then, use a prompt within the ticket to remediate specific vulnerabilities (e.g. SSH, RDP open).Tools: AWS, Jira Software
awsaws🔎⚠️Receive & remediate SNS notifications from AWS ConfigReceive SNS notifications from AWS Config, and report notifications in Jira. Remediate AWS infrastructure based on the notification.Tools: AWS, Jira Software
awsawsurlscanemailemailProcess and remediate GuardDuty detections received via AWS Security HubProcess security alerts from AWS Security Hub and gather additional information from AWS GuardDuty. Notify security teams via Slack, automatically stop compromised EC2 instances, submit suspicious URLs to URLScan.io for analysis, and document in Jira.Tools: Amazon GuardDuty, AWS, AWS Security Hub, Jira Software, URLScan.io
anecdotes🪣awsawsFind & remediate public AWS S3 bucket access with AnecdotesQuery Anecdotes for AWS S3 bucket gaps and non-compliant security control evidence. Create an enriched Jira ticket for each result returned. Then, remediate based on the Jira ticket to make the bucket private or allow it to stay public through AWS.Tools: Anecdotes.ai, AWS

Submit your story

We’d love to hear your ideas or see what you’ve created.