Threat intelligence enrichment
Gain the context you need, faster
Automatically enrich alerts with intelligence from across tools for better insight, more thorough investigation, and faster remediation.
Featured stories


Analyze an IP in many services at onceAnalyze an IP address across some of the most popular IP reputation and enrichment services, and consolidate results using the best data.Tools: AbuseIPDB, APIVoid, GreyNoise, Jira Software, Pulsedive, VirusTotal

Analyze domains through multiple sources
Investigate suspicious domains and identify false positives by leveraging threat intelligence tools, including URLhaus, VirusTotal, and URLScan, to gather more context and respond faster.
Tools
Loading story...
How it works
Instantly import stories to your tenant where you can adapt them to meet your unique business requirements.
Learners welcome
Step through beginner to advanced topics as you explore our tailored courses on Tines Stories University

Manage indicators of compromise in SentinelOne with Tines pagesManage Indicators of Compromise (IOC) using Tines Pages. Add or remove IOC's from SentinelOne.Tools: SentinelOne
Search alphaMountain for URL threat intelligence via SlackSearch for URLs or domains in alphaMountain via a Slack slash command. Return a threat score and flagged categories instantly, including a link to investigate deeper on ThreatYeti.Tools: alphaMountain, Slack
Analyze a hash in VirusTotalSurface VirusTotal behaviors, comments, graphs, and more to fully enrich hash analysis.Tools: VirusTotal
Sync Insider Threat Matrix records and attach to CasesRetrieve categories from the Insider Threat Matrix website, sync them into a Tines Stories record type, and let analysts attach or detach matching records from Cases.
Manage indicators of compromise in SentinelOne with Tines pagesManage Indicators of Compromise (IOC) using Tines Pages. Add or remove IOC's from SentinelOne.Tools: SentinelOne
Search for IOCs in MISP default feedsSearch, analyze, and transform data from MISP's default feeds to be viewed in a Tines Page.
Streamline threat intelligence gathering, enabling rapid threat identification and enhancing security responses through real-time data from MISP.Tools: MCP, MISP
Search alphaMountain for URL threat intelligence via SlackSearch for URLs or domains in alphaMountain via a Slack slash command. Return a threat score and flagged categories instantly, including a link to investigate deeper on ThreatYeti.Tools: alphaMountain, Slack
Integrate Anomali Threat Intelligence with Sublime Security's email detection signaturesCollect data on threat actors from Anomali ThreatStream, then either create or update detection signature security rules in Sublime Security based on the presence of observables and whether rules already exist. If further results appear, repeat the collection and rule management process after a delay.Tools: Anomali ThreatStream, Sublime SecurityHow Sophos frees up one analyst per week
“Thanks to Tines, the first time an analyst looks at the case, they already have all the information they need.”
Submit your story
We’d love to hear your ideas or see what you’ve created.