Automate Ticket Creation, Device Identification, and Threat Triage Easily with Tines

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Jul 09, 2025The Hacker NewsSecurity Operations / Automation

Streamlining Malware Alert Management with Tines

In today’s fast-paced digital landscape, efficient security operations are paramount. To assist security teams in managing their workflows, Tines, a robust workflow orchestration and AI platform, offers a library of over 1,000 pre-built workflows, created by practitioners in the field. These workflows can be imported and deployed for free through Tines’ Community Edition, making advanced security automation accessible to all.

A recent highlight from the Tines library is a specialized workflow designed to handle malware alerts efficiently. This workflow integrates multiple platforms—CrowdStrike, Oomnitza, GitHub, and PagerDuty—to provide a seamless experience for security teams. Developed by Lucas Cantor from Intercom, the workflow simplifies the evaluation of security alerts, allowing for quick escalation based on user input. “It’s designed to reduce noise and add contextual understanding to security issues affecting our endpoints,” Lucas explains.

Identifying the Challenge: Integration Gaps in Security Tools

The challenge faced by security teams is multifaceted. Responding to malware threats, assessing their severity, and reaching out to device owners can be a time-intensive process. The current manual approach often involves:

  • Responding to CrowdStrike events one at a time
  • Enriching alerts with necessary metadata
  • Documenting and notifying device owners through Slack
  • Communicating with on-call teams via PagerDuty

This manual workflow is not only slow but also prone to human error, which can lead to significant security risks.

Automating the Process: A Streamlined Solution

Recognizing these pain points, Lucas’s pre-built workflow automates critical steps in handling malware alerts. This process includes generating a case from the malware alert and ensuring both the device owner and on-call team are promptly informed. Specific benefits of this automated workflow include:

  • Quicker response times for malware alerts
  • Real-time notifications for device owners
  • Clear pathways for remediation and escalation
  • A centralized management system for better oversight

The workflow enhances the speed at which security teams can identify and react to threats, irrespective of their severity.

Workflow Overview: Tools and Functionality

Essential Tools

  • Tines: Workflow orchestration and AI platform (available in free Community Edition)
  • CrowdStrike: Threat intelligence and endpoint detection and response (EDR) platform
  • Oomnitza: IT asset management solution
  • GitHub: Platform for software development and version control
  • PagerDuty: Incident management service
  • Slack: Team collaboration messaging platform

How It Works

Initial Steps

  • Receive an alert from CrowdStrike
  • Identify the device responsible for triggering the alert
  • Create a ticket in GitHub and notify the relevant team in Slack
  • If the device is user-owned and classified as low-priority:
    • Send a message to the owner asking for escalation
  • If the device is user-owned and classified as high-priority:
    • Create a PagerDuty event to alert the on-call analyst
    • Inform the device owner of the issue

Follow-up Actions

  • Monitor user interaction via the Slack message
  • Update the GitHub ticket with the user’s response
  • If the owner escalates the issue:
    • Create a new PagerDuty event to notify the on-call analyst again

Setting Up the Workflow: A Step-by-Step Guide

1. Log into Tines or create a new account.

2. Navigate to the pre-built workflow section and select the option to import. This action will direct you to your new workflow.

3. Configure your credentials:

  • Add five essential credentials to your Tines tenant:
    • CrowdStrike
    • Oomnitza
    • GitHub
    • PagerDuty
    • Slack
  • For guidance, consult the respective credential guides available at explained.tines.com.

4. Configure your actions:

  • Set up your environment variables, including:
    • Slack IT channel alerting webhook
    • CrowdStrike/GitHub severity mapping
  • Ensure CrowdStrike is set to alert the New CrowdStrike Detection webhook when a detection occurs.
  • Configure your SlackBot interactivity URL to link with the relevant webhook.

5. Perform a test of the workflow.

6. Once tested successfully, publish the workflow to operationalize it.

If you’re interested in testing this workflow, consider signing up for a free Tines account to get started.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

NovaCookies Phishing Toolkit Exploits Docusign Notifications to Hijack Microsoft 365 Sessions

Cybersecurity researchers have unveiled a new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies, which is designed to redirect Microsoft 365 sign-ins while capturing authenticated sessions....

Cybercriminals Leak Grand Theft Auto VI Footage, Prompting Legal Action from Take-Two Interactive

Grand Theft Auto VI, anticipated as the game event of the decade, faced a major setback last week when a cybercriminal leaked gameplay footage...

Cybersecurity Patch Window Collapses, Urging New Control Strategies for Risk Management

For decades, cybersecurity defenders have relied on a straightforward model: when a vulnerability is disclosed, security teams assess exposure, test fixes, deploy patches, and...

Tehran-linked hackers shut down UK power plant in recent cyber attack

A recent cyber attack attributed to hackers linked to the Iranian regime has resulted in the shutdown of a small power plant in the...