Automated Alert Triage with AI Agents and Confluence SOPs
Summary
Hide ▲
Show ▼
Security workflow orchestration and AI platform Tines has released a pre-built workflow for automating alert triage and Standard Operating Procedures (SOP) execution. The workflow leverages AI agents to analyze alerts, locate relevant SOPs in Confluence, and perform remediation steps. It integrates with various security tools and notifies on-call teams via Slack. The workflow aims to streamline security alert handling, reduce mean time to remediation (MTTR), and ensure consistent application of security procedures. It was developed by Michael Tolan and Peter Wrenn, security researchers at Tines.
Timeline
-
19.09.2025 14:00 1 articles · 13d ago
Tines releases automated alert triage workflow
Tines has released a pre-built workflow that automates alert triage and SOP execution using AI agents and Confluence. The workflow integrates with various security tools and notifies on-call teams via Slack. It aims to streamline security alert handling, reduce MTTR, and ensure consistent application of security procedures.
Show sources
- How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines — thehackernews.com — 19.09.2025 14:00
Information Snippets
-
The Tines library features over 1,000 pre-built workflows shared by security practitioners.
First reported: 19.09.2025 14:001 source, 1 articleShow sources
- How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines — thehackernews.com — 19.09.2025 14:00
-
The workflow automates the identification and execution of SOPs from Confluence.
First reported: 19.09.2025 14:001 source, 1 articleShow sources
- How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines — thehackernews.com — 19.09.2025 14:00
-
AI agents analyze alerts, locate relevant SOPs, and perform remediation steps.
First reported: 19.09.2025 14:001 source, 1 articleShow sources
- How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines — thehackernews.com — 19.09.2025 14:00
-
The workflow integrates with tools like CrowdStrike, AbuseIPDB, EmailRep, Okta, Slack, Tavily, URLScan.io, and VirusTotal.
First reported: 19.09.2025 14:001 source, 1 articleShow sources
- How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines — thehackernews.com — 19.09.2025 14:00
-
The workflow reduces MTTR, ensures consistent security procedures, and provides comprehensive documentation.
First reported: 19.09.2025 14:001 source, 1 articleShow sources
- How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines — thehackernews.com — 19.09.2025 14:00
-
The workflow notifies on-call teams via Slack, providing visibility into alert details and actions taken.
First reported: 19.09.2025 14:001 source, 1 articleShow sources
- How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines — thehackernews.com — 19.09.2025 14:00
Similar Happenings
Automation of Pentest Delivery Enhances Security Operations
Automation is transforming pentest delivery by addressing inefficiencies in traditional reporting methods. This shift enables real-time insights, faster remediation, and standardized operations. Pentesting remains crucial for identifying security weaknesses, but outdated workflows introduce delays and inefficiencies. Automation platforms like PlexTrac streamline the process by delivering findings in real time, integrating with existing tools, and standardizing remediation workflows. This approach helps security teams act on findings immediately, accelerate remediation, and reduce manual work. Organizations adopting Continuous Threat Exposure Management (CTEM) and increasing the frequency of offensive testing benefit significantly from automated delivery. It helps cut through the noise and deliver results in real time, improving handoffs and visibility across the vulnerability lifecycle. Service providers and enterprises can gain a competitive advantage by automating delivery, integrating directly into client workflows, and driving operational maturity. Additionally, automation in pentest delivery helps in reducing the mean time to remediation (MTTR). The article highlights seven key workflows for automating pentest delivery, including creating tickets for remediation, auto-closing informational findings, sending real-time alerts for critical findings, requesting proofreading of draft findings, sending alerts when findings are ready for retest, auto-assigning findings to users, and sending finding updates to client portals. These workflows help accelerate delivery, reduce friction, and build a foundation for a modern, scalable approach to penetration test delivery.