Core capabilities
Find the right starting point for your team
Our core capabilities highlight the most popular stories in Tines by function. It’s a great place to find inspiration for what to build first.
Security operations
Founded in security, we understand how workflows and automation streamline incident response processes to allow you to focus on more complex strategic tasks.

Analyze URLs in URLScanExtract a domain from a selected URL and submit it to URLScan for analysis.
Automatically retrieve the results, including information regarding potential brand impersonations, tags and a screenshot of the webpage.
Utilize a "Known Good" resource in order to bypass domains and retrieve results faster.Tools: URLScan.io
Create unique ServiceNow tickets from Splunk alertsFind the best approach for you!
Consolidate multiple Splunk alerts with the same IP address into ServiceNow tickets using three different methods. Unique alerts lead to new incident tickets, child incident tickets, or comments on existing records.
These methods can be easily updated for any alert source and case management system.Tools: ServiceNow, Splunk
Analyze a hash in VirusTotalSurface VirusTotal behaviors, comments, graphs, and more to fully enrich hash analysis.Tools: VirusTotal

Analyze a file in Hybrid AnalysisUse Hybrid Analysis to analyze files safely in a sandbox environment. Search, submit, and retrieve results.Tools: Hybrid AnalysisEndpoint security
Leverage workflows to identify true positive alerts from your endpoint detection tools. Integrate threat intelligence to those workflows to prevent ongoing campaigns or known attacks.

Run a CrowdStrike Real Time Response commandThis Story will run a given CrowdStrike RTR command against a provided Host ID. All default RTR scripts can be used.Tools: CrowdStrike

Investigate EDR alerts from Carbon BlackGet EDR alerts for applications and services that Carbon Black has started or stopped on a system. Enrich application information using VirusTotal, generate a ticket in Jira and record the details, then isolate a machine if deemed malicious.Tools: Jira Software, PagerDuty, VirusTotal
Identify and remediate malicious SentinelOne threats with VirusTotalQuery SentinelOne for unresolved threats, verify their maliciousness, and take remedial action. Notify users via email and gather the information in Jira.Tools: Jira Software, SentinelOne, VirusTotal
Vulnerability management
Vulnerability management is an ongoing process that can contain repetitive tasks. Automation can streamline the creation, updating, and closure of vulnerability reports and tickets, simplifying the ticket management process.


Generate new vulnerability scan reports with QualysSubmit requests for new scan reports via a Tines Page. Receive Qualys results in an email attachment.Tools: Qualys
Fetch and record CrowdStrike Spotlight vulnerabilities with JiraPull all open CrowdStrike Spotlight vulnerabilities and filter the vulnerabilities by CVE. Then create issues in Jira for CVEs that have not been seen before or reopen closed issues if new machines have been impacted by a CVE. Automox can also be used to initiate patches for identified vulnerabilities.Tools: Automox, CrowdStrike, Jira Software



Close Jira tickets if JupiterOne vulnerabilities are resolvedQuery JupiterOne for open vulnerabilities. If the specified vulnerability is no longer present in JupiterOne, mark the Jira ticket status as done.Tools: Jira Software, JupiterOneData loss prevention (DLP)
Incorporating automated workflows into Data Loss Prevention (DLP) helps you detect exposed or sensitive data and set access restrictions to this data. By creating solutions around these tools you can both detect possible issues and speed up remediation times of DLP incidents.

Manage AWS Macie findings with Tines casesCreate a Tines case for active AWS Macie findings. Create an action to allow users to retrieve the affected resource using Tines pages.Tools: AWS, Tines
Manage departing employee watchlists in Code42Manage a departing employee watchlist in Code42 to be aware of insider risk behaviors. This story was created by Code42.Tools: Code42


Remove public access permissions in Google DriveScan your domain's Google Drive folders for any files that have been made public-facing and remove these extra permissions to limit possible data exposure.Tools: Google, Google Drive
Monitor large downloads by employees in Netskope and create Jira issuesRetrieve large download warnings in Netskope and generate a Jira issue for watchlisted employees. Effectively monitor for potential insider threat activity.Tools: Jira Software, NetskopeCloud security
Workflow automation allows you to rapidly deploy security measures, consistently enforce policy measures, and efficiently detect threats. By implementing workflow automation into your cloud security practices you'll save your team time and ensure compliance while significantly reducing the risk of a data breach or security incident.

Track AWS GuardDuty alerts in Jira and remediateEnrich AWS alerts with more context using GuardDuty, then take action to isolate new connections, lock attackers down, review credential usage, or re-apply restrictions, all while managing a case in Jira with this Story.Tools: Amazon GuardDuty, AWS, Jira Software

Monitor and deactivate long-lasting AWS IAM keysMonitor AWS IAM access keys and deactivate any that are older than 30 days. Notify users if their keys are scheduled to be deactivated.Tools: AWS
Retrieve Google Security Command Center findings and create issues in JiraRetrieve GCP Security Command Center findings and create issues in Jira. Provide a remediation prompt for a public GCP bucket finding to revoke access.Tools: Google, Jira SoftwareIdentity and access management (IAM)
Apply workflow automation for IAM processes like user identity management and verification, real-time access changes, and responding to unauthorized access. In doing so, you're able to implement a more efficient, secure, and compliant process for managing digital identities and access.


Send push notifications in Duo SecurityUse Duo Security to send custom push notifications to users, providing a trusted and secure method to get verification from users.Tools: Duo Security
Reset a user's password in OktaReset a user's password in Okta to respond quickly to compromised credentials.Tools: Okta



Application Security (AppSec)
App sec teams leverage automation to consistently detect, track, escalate, and patch vulnerabilities.If the vulnerability is unknown, you can use the workflow builder to map the patch as you build it for future use. This reinforces your software security posture as part of your software development lifecycle without introducing unnecessary friction.




Manage AWS Inspector findings with ServiceNowRetrieve AWS Inspector findings regularly and create ServiceNow incidents for new findings. Close incidents when findings have been remediated.Tools: AWS, ServiceNow
Compliance
Successful compliance programs require data collection, user training, and policy enforcement, all of which can be assisted with by automation. Automated tools can continuously gather and analyse data, ensuring up-to-date compliance reporting. From these reports, actions can be taken on non-compliance issues, from alerting users to their actions, or lack thereof, or by allowing compliance officers to enforce actions.


Report on inactive Okta accounts using Tines cases and deactivateRoutinely scan Okta environments for potential inactive accounts and report using Tines Cases. Deactivate accounts within the Case if necessary.Tools: Okta
Provide compliance information after signing an MNDA in Docusign eSignatureManage requests for compliance information with a simple simple MNDA signing flow. Once approved, requesters will receive a file in their inbox and a your team will be notified in Slack.Tools: DocuSign, Slack
Upload compliance evidence to DrataAdd evidence files to each employee's profile in Drata to keep records up to date and satisfy compliance requirements.Tools: Drata
Send KnowBe4 training reminders via SlackThis Story checks KnowBe4 enrollments for users who should be notified about different stages in their training.Tools: Knowbe4, SlackAsset Management
Workflow automation in Asset Management streamlines the process of tracking and securing digital assets. By automatically cataloging and monitoring all digital components, from hardware to software, it ensures that every asset is accounted for throughout its lifecycle. This proactive approach not only saves time but also enhances the overall security posture by maintaining a reliable, current, and secure asset inventory.
Add devices in Kandji to Google SheetsRetrieve all devices added to Kandji and add them to a newly created spreadsheet in Google Sheets. This enables monitoring and review of device history, facilitating further action if necessary.Tools: Google, Kandji
Sync assets between Kandji and runZero while updating ownershipSync assets seamlessly between Kandji and runZero for enhanced organization and management. The process involves listing devices, extracting data, and updating asset ownership for streamlined operations.Tools: Kandji, runZero
Lookup devices in Lansweeper using a Slack commandUse Slack commands to look up devices in Lansweeper by IP address or name. Get basic and custom attributes, with a button to open the device in Lansweeper for more info.Tools: Lansweeper, SlackEmployee onboarding and offboarding
With workflow automation, builders significantly reduce the manual hours spent managing onboarding and offboarding processes. Through Tines, you can swiftly handle routine tasks (i.e. creating accounts, assigning access rights, etc.) and reduce friction with other teams waiting for access provisioning. This not only speeds up the process, but also reduces the risk of human error or delays and, in the case of offboarding, mitigates risk of unauthorized access. This makes for a smooth and efficient process for the organization and employees.


Remove a user account in Microsoft Entra ID, BambooHR, AWS, and SlackRemove a user from multiple platforms at once. Useful if a user leaves an organization and needs to be offboarded quickly. An issue will be created in Jira as an audit trail during removal.Tools: AWS, BambooHR, Jira Software, Microsoft Azure, Slack
Create many new Microsoft Entra ID users using Tines pagesCreate new users in Microsoft Entra ID using Tines Pages. Upload a CSV file of users or manually specify each user individually.Tools: Microsoft, Microsoft Azure

Move Google Docs and Calendar to another user in Google WorkspaceTransfer Google Calendar and Docs to another user in a Google Workspace. Helpful for moving data of a departing employee to their supervisor or to another repository of historical documents.Tools: Google
Add new employees to BambooHR and manage system accessRun a daily report against BambooHR to pull details of all employees recently hired. Creates a new user in Okta, Slack, Google Workspace and Azure (Microsoft Entra ID) as necessary.
Messages are sent into Slack to alert HR / IT for when new users are added.Tools: BambooHR, Google, Microsoft Azure, Okta, SlackThreat Intelligence
Incorporating workflow automation in your threat intelligence processes allows you to disseminate threat intelligence insights faster. Automation helps you gather and analyze data across resources. Once remediation steps are identified, it helps you respond to those threats consistently and tracks the process in an auditable way. This not only supplements the accuracy of threat detection, but also allows you to focus on strategic risk management.


Query GreyNoise for CVEs and update blocklistQuery the GreyNoise API to get a list of malicious IPs and update a blocklist that can be read by firewalls and other services.Tools: GreyNoise

Analyze an IP in many services at onceAnalyze an IP address across some of the most popular IP reputation and enrichment services, and consolidate results using the best data.Tools: AbuseIPDB, APIVoid, GreyNoise, Jira Software, Pulsedive, VirusTotal
Query Censys for known Command & Control IPs add as IoCs in CrowdStrikeContinuously scan Censys for known Covenant Command and Control (C2) servers, adding them as individual IoCs in CrowdStrike. Maintain an up-to-date list of IPs within CrowdStrike by removing outdated servers and adding newly discovered ones.Tools: Censys, CrowdStrike

Patch Management
Assets and vulnerabilities can be detected and managed using various tools. By running automated patching on vulnerable assets, an endpoint and networks can be protected against common attacks. Furthermore, automation can be used to manage and remediate and issues that arise during the patching process.

Update vulnerable hosts using ManageEngine Endpoint Central and FleetRetrieve a list of hosts with vulnerable software from Fleet. Initiate a patch scan for the hosts using Endpoint CentralTools: Fleet, Manage Engine
Update Linux system packages using Ansible TowerUse Ansible Tower to list Linux system packages and update them on a regular basis. Send packages that could be updated to Slack for approval.Tools: Ansible, Slack
Fetch and record CrowdStrike Spotlight vulnerabilities with JiraPull all open CrowdStrike Spotlight vulnerabilities and filter the vulnerabilities by CVE. Then create issues in Jira for CVEs that have not been seen before or reopen closed issues if new machines have been impacted by a CVE. Automox can also be used to initiate patches for identified vulnerabilities.Tools: Automox, CrowdStrike, Jira Software
Find and reboot devices with failed Microsoft Intune updatesRetrieve devices with failed updates in Microsoft Intune. Perform a reboot of those devices, which can often fix a failed update.Tools: Microsoft, Microsoft AzureUser access requests
Handle user access requests at scale with workflow automation. This ensures access requests are routed appropriately for approval, permissions are provisioned or revoked in real-time, and access changes are adequately documented for audits. This reduces manual intervention, accelerates response times, and reinforces your security policies.
Review apps in Lumos for inactive approvers and notify SlackEvery day, review apps in Lumos for apps with inactive admins/approvers. Send message to Slack channel to update app permissions & remove old users.Tools: Lumos, Slack
Sync on-call engineers from PagerDuty to Bowtie access groupsDynamically update access groups in Bowtie to only contain engineers who are on-call in PagerDuty. Provide access to additional support only when necessary.Tools: Bowtie, PagerDuty
Grant temporary application accessReceive Slack requests to grant a user access to a specific application for a specified period of time and deactivate the user's account immediately afterwards.Tools: Jira Software, Okta, Slack, Tines