Security
Built by security practitioners for security practitioners
Discover some of our favorite stories for inspiration towards your next build.
Dive into specific areas of cloud security
Founded by security practitioners, we know the importance of SOAR. Explore some examples of ways customers use Tines to modernize the way they view SOAR.
Featured stories

Analyze a file in VirusTotalUpload a file and search VirusTotal to see if the hash has been scanned before. If not, upload the file to VirusTotal for analysis and receive an email with the results.Tools: VirusTotal
Analyze and triage suspicious emails with various tools
Submit suspicious emails and investigate with a comprehensive analysis of files, URLs, and headers. Add IOCs to various tool blocklists in order to limit impact of phishing campaigns.
Tools
CrowdStrike, EmailRep, Jira Software, NextDNS, URLScan.io, VirusTotal
Created by
Michael Tolan
Loading story...




How it works
Instantly import stories to your tenant where you can adapt them to meet your unique business requirements.
Learners welcome
Step through beginner to advanced topics as you explore our tailored courses on Tines Stories University
Authorize distributed Slack apps and store OAuth tokens using pagesAutomate the OAuth 2.0 authorization flow for distributed Slack apps, collecting bot and user tokens and storing them automatically as Tines credentials for use in other workflows.Tools: Slack, Tines
Manage Infoblox infrastucture with various methodsManage Infoblox IPAM resources with various methods. (1) AI Chat Interface for conversational resource discovery and creation, (2) AI Task Mode with form-driven intelligent resource management that checks for existing resources and creates only what's missing, and (3) Traditional Deterministic Workflow with explicit conditional branching. All methods handle the resource hierarchy of IP Spaces, Address Blocks, and Subnets while preventing duplicate creation.Tools: Infoblox
Sync Insider Threat Matrix records and attach to CasesRetrieve categories from the Insider Threat Matrix website, sync them into a Tines Stories record type, and let analysts attach or detach matching records from Cases.
Audit AWS security and compliance and document in Google SheetsAudit AWS S3 buckets, EC2 security groups, EC2 instances, IAM credentials, and EBS volumes for security and compliance gaps. Export findings to a formatted Google Sheets workpaper for review and documentationTools: AWS

Manage a risk register using AI-driven scoring and recordsSubmit risks via Workbench or an internal Tines Page, score them automatically with AI, and track results in a risk register using records.

Run a CrowdStrike Real Time Response command
This Story will run a given CrowdStrike RTR command against a provided Host ID. All default RTR scripts can be used.
Tools
Loading story...
Tines achieves AWS security competency

Isolate & remediate AWS EC2 instance based on IOCReceive IOC from an external system and report notifications in Jira. Determine if IOC is actionable, if so remediate AWS EC2 instance based on IOC, and update Jira.Tools: AWS, Jira Software, Slack
Alert on AWS Backup changes and record in CodeCommitUse AWS CloudTrail to send AWS Backup events to Slack. Record modifications in AWS CodeCommit for version control of backup plans.Tools: AWS, Slack

Rotate AWS access keys on scheduleRotate access keys in AWS KMS when the key is greater than 90 days old.Tools: AWS

Remediate vulnerabilities identified by AWS Inspector v2Receive vulnerability information from AWS Inspector v2 and create a JIRA ticket with the details. Then, use a prompt within the ticket to remediate specific vulnerabilities (e.g. SSH, RDP open).Tools: AWS, Jira Software
Receive & remediate SNS notifications from AWS ConfigReceive SNS notifications from AWS Config, and report notifications in Jira. Remediate AWS infrastructure based on the notification.Tools: AWS, Jira Software
Submit your story
We’d love to hear your ideas or see what you’ve created.