Home / Companies / Tines / Blog / Post Details
Content Deep Dive

Managing CrowdStrike detections, analyzing behaviors, & containing user devices

Blog post from Tines

Post Details
Company
Date Published
Author
Martin Moroney
Word Count
1,525
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

Incident Response teams face the challenge of alert fatigue due to the high volume of alerts from various sources like SIEM, EDR, and abuse inboxes. To address this, automation plays a crucial role, and integrating alerts into a centralized Case Management System can be a significant first step. Tines, a platform that integrates with tools like Jira, The Hive, and ServiceNow, facilitates this process by automatically creating cases from alerts. In an extension of a previous integration with CrowdStrike, Tines now enables the creation of Jira tickets for new detections, allowing analysts to perform response actions such as containing a device at the click of a button. By setting up permissions carefully, Tines can read and update detection statuses, enrich Jira tickets with detailed information from CrowdStrike, and use VirusTotal to assess the severity of threats. This approach helps streamline incident management by reducing manual tasks, allowing analysts to make quicker decisions based on enriched data, and offering the potential for further automation and integration with other threat intelligence sources.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 1,155 290 91 +44%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.