Reported phishing emails eat up a lot of my team’s time and I’d like to automate the first pass. How would I build a phishing report triage and response workflow in 3B? I’m curious what the typical steps look like, from receiving the report through to taking action. A sketch of the usual pattern would give me a solid starting point.
There are examples in the Tines blog and examples gallery on phishing. However, one of the very best ways to start automating your team’s phishing process is to take your existing run book and use that as an input to 3B. We’ve found that to be a really effective way of building these out.
And that doesn’t just apply to phishing workflows. Try it with any of your other runbooks for things like vulnerability management, incident escalation, password resets, and account lockouts, etc.