Streamlining Malware Alert Management with Tines
In today’s fast-paced digital landscape, efficient security operations are paramount. To assist security teams in managing their workflows, Tines, a robust workflow orchestration and AI platform, offers a library of over 1,000 pre-built workflows, created by practitioners in the field. These workflows can be imported and deployed for free through Tines’ Community Edition, making advanced security automation accessible to all.
A recent highlight from the Tines library is a specialized workflow designed to handle malware alerts efficiently. This workflow integrates multiple platforms—CrowdStrike, Oomnitza, GitHub, and PagerDuty—to provide a seamless experience for security teams. Developed by Lucas Cantor from Intercom, the workflow simplifies the evaluation of security alerts, allowing for quick escalation based on user input. “It’s designed to reduce noise and add contextual understanding to security issues affecting our endpoints,” Lucas explains.
Identifying the Challenge: Integration Gaps in Security Tools
The challenge faced by security teams is multifaceted. Responding to malware threats, assessing their severity, and reaching out to device owners can be a time-intensive process. The current manual approach often involves:
- Responding to CrowdStrike events one at a time
- Enriching alerts with necessary metadata
- Documenting and notifying device owners through Slack
- Communicating with on-call teams via PagerDuty
This manual workflow is not only slow but also prone to human error, which can lead to significant security risks.
Automating the Process: A Streamlined Solution
Recognizing these pain points, Lucas’s pre-built workflow automates critical steps in handling malware alerts. This process includes generating a case from the malware alert and ensuring both the device owner and on-call team are promptly informed. Specific benefits of this automated workflow include:
- Quicker response times for malware alerts
- Real-time notifications for device owners
- Clear pathways for remediation and escalation
- A centralized management system for better oversight
The workflow enhances the speed at which security teams can identify and react to threats, irrespective of their severity.
Workflow Overview: Tools and Functionality
Essential Tools
- Tines: Workflow orchestration and AI platform (available in free Community Edition)
- CrowdStrike: Threat intelligence and endpoint detection and response (EDR) platform
- Oomnitza: IT asset management solution
- GitHub: Platform for software development and version control
- PagerDuty: Incident management service
- Slack: Team collaboration messaging platform
How It Works
Initial Steps
- Receive an alert from CrowdStrike
- Identify the device responsible for triggering the alert
- Create a ticket in GitHub and notify the relevant team in Slack
- If the device is user-owned and classified as low-priority:
- Send a message to the owner asking for escalation
- If the device is user-owned and classified as high-priority:
- Create a PagerDuty event to alert the on-call analyst
- Inform the device owner of the issue
Follow-up Actions
- Monitor user interaction via the Slack message
- Update the GitHub ticket with the user’s response
- If the owner escalates the issue:
- Create a new PagerDuty event to notify the on-call analyst again
Setting Up the Workflow: A Step-by-Step Guide
1. Log into Tines or create a new account.
2. Navigate to the pre-built workflow section and select the option to import. This action will direct you to your new workflow.
3. Configure your credentials:
- Add five essential credentials to your Tines tenant:
- CrowdStrike
- Oomnitza
- GitHub
- PagerDuty
- Slack
- For guidance, consult the respective credential guides available at explained.tines.com.
4. Configure your actions:
- Set up your environment variables, including:
- Slack IT channel alerting webhook
- CrowdStrike/GitHub severity mapping
- Ensure CrowdStrike is set to alert the New CrowdStrike Detection webhook when a detection occurs.
- Configure your SlackBot interactivity URL to link with the relevant webhook.
5. Perform a test of the workflow.
6. Once tested successfully, publish the workflow to operationalize it.
If you’re interested in testing this workflow, consider signing up for a free Tines account to get started.


