# Torq Knowledge Base > Triage. Investigate. Respond. Faster. ## Set Up Torq - [Invite and Manage Workspace Users in Torq](https://kb.torq.io/en/articles/9113722-invite-and-manage-workspace-users-in-torq.md): Learn how to invite and effectively manage users in your Torq workspace. - [Grant Temporary Workspace Access to Torq Support](https://kb.torq.io/en/articles/9094913-grant-temporary-workspace-access-to-torq-support.md): Provide Torq Support with temporary access to your workspace to assist with any issues. - [Create a Torq API key: Enable programmatic access](https://kb.torq.io/en/articles/9145827-create-a-torq-api-key-enable-programmatic-access.md): Follow this guide to create your own Torq API key for authentication. - [Organization Management: Manage Workspaces in Torq](https://kb.torq.io/en/articles/9418412-organization-management-manage-workspaces-in-torq.md): Learn how Organization Managers can access key metrics and information for all the organization's workspaces in a single glance. - [Customize Torq Workspace Logos: Simplify Workspace Differentiation](https://kb.torq.io/en/articles/9112750-customize-torq-workspace-logos-simplify-workspace-differentiation.md): Learn how to assign distinct logos to your Torq workspaces, simplifying workspace recognition and navigation. - [Two-Factor Authentication: Secure Your Workspaces](https://kb.torq.io/en/articles/9701811-two-factor-authentication-secure-your-workspaces.md): Enhance workspace security by enabling two-factor authentication for users logging in with email and password. - [Update your personal settings in Torq](https://kb.torq.io/en/articles/10021471-update-your-personal-settings-in-torq.md): Adjust your Torq settings to tailor your experience. - [Torq Roles and Scopes: Manage Access and Permissions](https://kb.torq.io/en/articles/9145806-torq-roles-and-scopes-manage-access-and-permissions.md): Efficiently manage user access and permissions in your workspace using Torq's role-based access control \(RBAC\) system. - [AI Pricing Model: Monitor and Track AI Credit Consumption](https://kb.torq.io/en/articles/13223383-ai-pricing-model-monitor-and-track-ai-credit-consumption.md): Understand how Torq’s unified AI Credit system powers Socrates, AI Agents, and AI Tasks. - [Manage Cross-Workspace Dashboards](https://kb.torq.io/en/articles/14278518-manage-cross-workspace-dashboards.md): Create and manage dashboards at the organizational level and make them available across selected workspaces. - [Torq API Key Rotation: Full Replacement vs. Expiration Update](https://kb.torq.io/en/articles/14498016-torq-api-key-rotation-full-replacement-vs-expiration-update.md): Learn how to manage Torq API keys securely by choosing between full key replacement and expiration updates. - [Regional Availability: Deployment and Data Residency Options](https://kb.torq.io/en/articles/15516103-regional-availability-deployment-and-data-residency-options.md): Explore how Torq maintains regional availability and supports organizations with data residency requirements. - [Organization-managed Roles: Centralize Access Across Workspaces](https://kb.torq.io/en/articles/15413464-organization-managed-roles-centralize-access-across-workspaces.md): Centralize role management across workspaces to ensure consistent permissions, reduce overhead, and enable seamless use of roles in workflows and integrations. - [Product Spotlight](https://kb.torq.io/en/articles/13741563-product-spotlight.md): Catch up on the latest Torq updates with the Product Spotlight. - [Configure SSO for Torq: Boost Security and Efficiency](https://kb.torq.io/en/articles/9148439-configure-sso-for-torq-boost-security-and-efficiency.md): Learn about Torq's Single Sign-On \(SSO\) capabilities. - [Set Up Torq SSO: Okta SAML 2.0 from App Catalog](https://kb.torq.io/en/articles/9138224-set-up-torq-sso-okta-saml-2-0-from-app-catalog.md): Follow this guide to set up Single Sign-On \(SSO\) with Okta using SAML 2.0 via the Torq app in the Okta App Catalog. - [Set Up Torq SSO: Okta SAML 2.0](https://kb.torq.io/en/articles/9138244-set-up-torq-sso-okta-saml-2-0.md): Follow this guide to set up Single Sign-On \(SSO\) with Okta using the SAML 2.0 protocol. - [Set Up Torq SSO: Okta OpenID Connect](https://kb.torq.io/en/articles/9138228-set-up-torq-sso-okta-openid-connect.md): Follow this guide to set up Single Sign-On \(SSO\) with Okta using the OpenID Connect protocol. - [Set Up Torq SSO: OneLogin SAML 2.0](https://kb.torq.io/en/articles/9138237-set-up-torq-sso-onelogin-saml-2-0.md): Follow this guide to set up Single Sign-On \(SSO\) with OneLogin using the SAML 2.0 protocol. - [Set Up Torq SSO: OneLogin OpenID Connect](https://kb.torq.io/en/articles/9145932-set-up-torq-sso-onelogin-openid-connect.md): Follow this guide to set up Single Sign-On \(SSO\) with OneLogin using the OpenID Connect protocol. - [Set Up Torq SSO: Microsoft Entra ID](https://kb.torq.io/en/articles/9138230-set-up-torq-sso-microsoft-entra-id.md): Follow this guide to set up Single Sign-On \(SSO\) with Entra ID \(formerly Azure AD\). - [Set Up Torq SSO: Auth0 with Entra ID](https://kb.torq.io/en/articles/9145881-set-up-torq-sso-auth0-with-entra-id.md): Follow this guide to set up SSO with Auth0, using Entra ID for secure and streamlined access control. - [Set Up Torq SSO: JumpCloud SAML 2.0](https://kb.torq.io/en/articles/10050568-set-up-torq-sso-jumpcloud-saml-2-0.md): Use JumpCloud's built-in SSO flow with Torq via SAML 2.0. - [Add Torq SSO to Microsoft's My Apps Portal](https://kb.torq.io/en/articles/9830631-add-torq-sso-to-microsoft-s-my-apps-portal.md): Learn how to add an Entra ID Torq SSO app to Microsoft's My Apps portal. - [Single Sign-On Setup \(Generic Guide\)](https://kb.torq.io/en/articles/13842502-single-sign-on-setup-generic-guide.md): Configure SAML or OIDC with any identity provider using Torq’s generic SSO setup instructions. - [Troubleshoot SSO and Login Issues](https://kb.torq.io/en/articles/15244733-troubleshoot-sso-and-login-issues.md): Diagnose and resolve common SSO and sign-in failures in Torq, organized by symptom, with escalation steps when self-recovery isn't enough. ## Integrate Everything - [Integrate Anything. Resolve Everything.](https://kb.torq.io/en/articles/9174097-integrate-anything-resolve-everything.md): Discover how Torq's powerful integration capabilities transform your security operations by seamlessly connecting with any system. - [ANY.RUN](https://kb.torq.io/en/articles/16052149-any-run.md): Integrate ANY.RUN with Torq to automate malware analysis and threat intelligence enrichment across your SOC workflows. - [Every Integration.](https://kb.torq.io/en/articles/10166233-every-integration.md): View a list of Torq's out-of-the-box integrations in one quick glance. - [Setting Up Integrations in Torq: Connecting to Third-Party Services](https://kb.torq.io/en/articles/9305279-setting-up-integrations-in-torq-connecting-to-third-party-services.md): This guide introduces Torq integrations, explaining how to connect seamlessly with third-party services using trigger and step integrations. - [Abnormal Security](https://kb.torq.io/en/articles/10902244-abnormal-security.md): Integrate Abnormal Security with Torq to orchestrate responses to email security events and automatically perform remediation actions. - [AbuseIPDB](https://kb.torq.io/en/articles/9138321-abuseipdb.md): Integrate AbuseIPDB with Torq for secure internet operations. - [Adaptive Shield](https://kb.torq.io/en/articles/9138332-adaptive-shield.md): Learn to integrate Adaptive Shield with Torq for security monitoring and configure API keys, alerts, and workflows. - [AlienVault OTX](https://kb.torq.io/en/articles/9138333-alienvault-otx.md): Integrate AlienVault OTX steps for cyber threat intelligence on domains, files, IPs, and URLs. - [Apiiro](https://kb.torq.io/en/articles/9140079-apiiro.md): Integrate Apiiro with Torq to send events via webhooks for secure app development workflows. - [Armis](https://kb.torq.io/en/articles/9138348-armis.md): Secure IoT with Armis and Torq: integrate Armis for device security with Torq Workflows to manage and monitor enterprise IoT devices. - [Armis OAuth](https://kb.torq.io/en/articles/16179624-armis-oauth.md): Integrate Armis Centrix™ with Torq using OAuth 2.0 client credentials authentication. - [Axonius](https://kb.torq.io/en/articles/9138341-axonius.md): Integrate Axonius with Torq for asset management and trigger automated security Workflows using Axonius events. - [BambooHR](https://kb.torq.io/en/articles/9138353-bamboohr.md): Learn how to obtain a BambooHR API key and set up an integration in Torq for seamless employee data management. - [Box](https://kb.torq.io/en/articles/9140021-box.md): Learn to integrate and use Box steps in Torq for content management, session creation, user tasks, and setting permissions. - [BlackBerry Cylance](https://kb.torq.io/en/articles/9138359-blackberry-cylance.md): Learn how to integrate Cylance with Torq by creating an app, storing credentials, and using Steps in Workflows. - [Britive](https://kb.torq.io/en/articles/9138363-britive.md): Learn how to obtain a Britive API token and integrate it with Torq to automate cloud identity management workflows. - [Check Point Management](https://kb.torq.io/en/articles/9138366-check-point-management.md): Learn how to efficiently use Check Point's all-in-one platform in Torq's automated workflows. - [CircleCI](https://kb.torq.io/en/articles/9138368-circleci.md): Integrate CircleCI with Torq: Learn to create API keys and configure CI/CD actions within your workflows. - [Clutch Security](https://kb.torq.io/en/articles/10260297-clutch-security.md): Integrate Clutch Security with Torq to automate event response workflows using API key configuration. - [Cisco Webex](https://kb.torq.io/en/articles/9138376-cisco-webex.md): Learn to set up Webex bots and integrations to interact with messages and users safely, plus configure Webex steps in Torq workflows. - [Criminal IP](https://kb.torq.io/en/articles/15835062-criminal-ip.md): Integrate Criminal IP with Torq to enrich your workflows with attack surface and threat intelligence data using API key configuration. - [CrowdStrike](https://kb.torq.io/en/articles/9138382-crowdstrike.md): Integrate CrowdStrike with Torq to automate event response workflows using webhooks and API key configurations. - [CrowdStrike Streaming](https://kb.torq.io/en/articles/10050660-crowdstrike-streaming.md): Trigger workflows in Torq based on CrowdStrike streaming API for Falcon events. - [Cyera](https://kb.torq.io/en/articles/10257220-cyera.md): Integrate Cyera with Torq to automate event response workflows using webhooks and API key configurations. - [Datadog](https://kb.torq.io/en/articles/9140026-datadog.md): Integrate Datadog with Torq to automate workflows via event triggers, log searches, and event management within workflows. - [Discord](https://kb.torq.io/en/articles/9521582-discord.md): Learn to integrate Discord with Torq and automate chatbots and workflows. - [Drata](https://kb.torq.io/en/articles/9138390-drata.md): Integrate Drata with Torq for automated security compliance workflows: API key and account ID instructions included. - [Duo](https://kb.torq.io/en/articles/9138392-duo.md): Learn how to retrieve your Duo API hostname and set up Duo step integration for enhanced authentication and security. - [Elastic Security](https://kb.torq.io/en/articles/9138403-elastic-security.md): Leverage Elastic Security's advanced threat detection by integrating with Torq for automated workflow triggers and responses. - [Elasticsearch](https://kb.torq.io/en/articles/9138406-elasticsearch.md): Learn to set up Elasticsearch as a trigger for Torq workflows: Create integrations in Torq and connectors in Kibana for automated actions. - [GitHub](https://kb.torq.io/en/articles/9138417-github.md): Integrate GitHub with Torq to manage issues and repositories. - [GreyNoise](https://kb.torq.io/en/articles/9138418-greynoise.md): Use GreyNoise with Torq to filter out noise in alerts, run queries, and check IP activities with your API key. Optimize security workflows. - [Grip Security](https://kb.torq.io/en/articles/9138420-grip-security.md): Safeguard your SaaS applications with Grip Security's control plane. Follow premade steps or create custom ones—full guide coming soon. - [HashiCorp Terraform Cloud](https://kb.torq.io/en/articles/9138431-hashicorp-terraform-cloud.md): Manage resources in Torq with Terraform Cloud integration: automate workflows, estimate costs, handle OAuth, and more. - [HashiCorp Vault AppRole](https://kb.torq.io/en/articles/9140088-hashicorp-vault-approle.md): Securely manage secrets with HashiCorp Vault's AppRole in Torq—store and control access to sensitive data, ideal for automated workflows. - [HashiCorp Vault](https://kb.torq.io/en/articles/9138448-hashicorp-vault.md): Securely manage secrets with HashiCorp Vault in Torq: setup guide, integration, and workflow steps for KV secrets. - [HiBob](https://kb.torq.io/en/articles/9138452-hibob.md): Integrate with HiBob HR Software to automate onboarding and offboarding and track leave & compensation. - [IMAP](https://kb.torq.io/en/articles/9139711-imap.md): Learn to monitor IMAP mailboxes in Gmail & Microsoft 365 for new emails and set up IMAP integration with our easy guide. - [IBM QRadar](https://kb.torq.io/en/articles/9483059-ibm-qradar.md): Learn how to integrate IBM's QRadar with Torq's automated workflows. - [IPinfo](https://kb.torq.io/en/articles/9139725-ipinfo.md): Integrate IPinfo with Torq to enhance security workflows with geolocation features. - [Jamf](https://kb.torq.io/en/articles/9139680-jamf.md): Integrate Jamf and Jamf Protect with Torq to automate device management and security using built-in steps, triggers, and templates. - [JumpCloud](https://kb.torq.io/en/articles/9139699-jumpcloud.md): Securely manage identities across devices with JumpCloud. Learn to get your API key & integrate with Torq for streamlined access control. - [LimaCharlie](https://kb.torq.io/en/articles/9140031-limacharlie.md): Learn how to leverage LimaCharlie data for Torq workflows by integrating with webhook triggers for events, detects, audits & more. - [Lucid](https://kb.torq.io/en/articles/9414545-lucid.md): Integrate Lucid with Torq's workflows to securely automate tasks and team collaboration. - [monday.com](https://kb.torq.io/en/articles/10066976-monday-com.md): Use monday.com steps in automated Torq workflows and trigger Torq workflows from monday.com actions. - [Netskope](https://kb.torq.io/en/articles/9139753-netskope.md): Secure cloud platform for advanced threat protection with Torq's premade steps for data events and reports. - [New Relic](https://kb.torq.io/en/articles/9140000-new-relic.md): Learn how to integrate New Relic with Torq to trigger workflows via New Relic events. - [Notion](https://kb.torq.io/en/articles/9139755-notion.md): Learn to integrate Notion with Torq to manage tasks and track projects in your workflows. - [OAuth Refresh Token](https://kb.torq.io/en/articles/9139763-oauth-refresh-token.md): Ensure uninterrupted API access with OAuth refresh tokens by automating new token generation before expiration. Set up easily in Torq. - [OAuth 2.0](https://kb.torq.io/en/articles/9140106-oauth-2-0.md): Integrate third-party OAuth 2.0 vendors into workflows. Know your flow, set up tokens, and manage access in Torq. - [Opsin](https://kb.torq.io/en/articles/15834994-opsin.md): Integrate Opsin with Torq to automate governance and access workflows for your GenAI environment using API token configuration. - [Orca Security](https://kb.torq.io/en/articles/9139794-orca-security.md): Integrate Orca Security with Torq to automate workflows that remediate cloud threats using webhook triggers and APIs. - [OpenAI](https://kb.torq.io/en/articles/10903025-openai.md): Integrate OpenAI with Torq to enhance automated workflows with AI. - [PagerDuty](https://kb.torq.io/en/articles/9139797-pagerduty.md): Integrate PagerDuty incidents with Torq for automated workflow triggers, updates, and streamlined communications. - [Proofpoint](https://kb.torq.io/en/articles/10183856-proofpoint.md): Integrate Proofpoint TAP with Torq to enhance security Workflows with advanced threat intelligence and automation. - [Recorded Future](https://kb.torq.io/en/articles/9140057-recorded-future.md): Learn to obtain a Recorded Future API token and integrate intelligence APIs with Torq for enhanced security workflows. - [Salesforce](https://kb.torq.io/en/articles/9140113-salesforce.md): Guide to create Salesforce OAuth credentials for secure, token-based authorization in Torq integrations. - [ServiceNow](https://kb.torq.io/en/articles/9140040-servicenow.md): Integrate ServiceNow with Torq to use ServiceNow steps in your workflows. - [Shodan](https://kb.torq.io/en/articles/9413577-shodan.md): Integrate Shodan with Torq's automated workflows to maximize the Internet Intelligence Platform. - [SMTP](https://kb.torq.io/en/articles/9140074-smtp.md): Use SMTP to easily send emails straight from the app without needing a separate email program. - [Sweet Security](https://kb.torq.io/en/articles/10466661-sweet-security.md): Integrate Sweet Security with Torq to automate incidents and insights across your cloud-native detection platform. - [TheHive](https://kb.torq.io/en/articles/9139993-thehive.md): "Integrate TheHive with Torq for case management and alert creation in workflows—complete guide on setting it up and using API keys." - [Thinkst Canary](https://kb.torq.io/en/articles/9139992-thinkst-canary.md): Learn to set up Torq with Canary alerts to automate and trigger security workflows with our easy integration guide. - [Torq](https://kb.torq.io/en/articles/10313594-torq.md): Create a Torq integration with specific permissions to allow delegated permissions and access within workflows. - [Urlscan.io](https://kb.torq.io/en/articles/10790876-urlscan-io.md): Integrate urlscan.io to use urlscan.io steps in your workflows. - [Veeam Backup and Replication](https://kb.torq.io/en/articles/10624117-veeam-backup-and-replication.md): Integrate Veeam with Torq to run Veeam actions as part of a Torq workflow. - [Veeam ONE](https://kb.torq.io/en/articles/10627419-veeam-one.md): Integrate Veeam ONE with Torq to run Veeam ONE actions as part of a Torq workflow . - [VirusTotal](https://kb.torq.io/en/articles/9140050-virustotal.md): Integrate VirusTotal with Torq to analyze files, domains, IPs, and URLs as part of your Torq workflows. - [Webhooks](https://kb.torq.io/en/articles/9139841-webhooks.md): Set up Torq webhooks to create endpoints for external events and trigger workflows. - [WhatsApp Business](https://kb.torq.io/en/articles/9139983-whatsapp-business.md): Automate WhatsApp Business comms with Torq: Set up Meta app, integrate with Torq workflow & triggers to streamline ChatOps. - [Wiz](https://kb.torq.io/en/articles/9139937-wiz.md): Integrate Wiz with Torq to set up automations for proactive risk management in the cloud. - [Zendesk](https://kb.torq.io/en/articles/9445680-zendesk.md): Integrate Zendesk in Torq's automated workflows in order to manage support tickets, product communities and more. - [Zoom](https://kb.torq.io/en/articles/9139876-zoom.md): Integrate Zoom with Torq: choose the official Torq app for simplicity or a custom app for more control. Admin rights required. - [CrowdStrike \(Legacy\)](https://kb.torq.io/en/articles/10585675-crowdstrike-legacy.md): Integrate CrowdStrike with Torq to automate event response workflows using API key configurations. - [Qualys](https://kb.torq.io/en/articles/11154467-qualys.md): Integrate Qualys to bring vulnerability and compliance data into your workflows. - [Hybrid Analysis](https://kb.torq.io/en/articles/11121952-hybrid-analysis.md) - [Google Maps](https://kb.torq.io/en/articles/11099225-google-maps.md): Integrate Google Maps with Torq to enhance your automated workflows. - [Google Cloud Pub/Sub](https://kb.torq.io/en/articles/11111785-google-cloud-pub-sub.md): Integrate Google Cloud Pub/Sub with Torq to send and receive messages between independent applications. - [Gmail](https://kb.torq.io/en/articles/10391545-gmail.md): Integrate Gmail with Torq to automate email management. - [Google Chat OAuth](https://kb.torq.io/en/articles/11092538-google-chat-oauth.md): Integrate Google Chat OAuth with Torq to authenticate to Google Chat via OAuth 2.0 client credentials. - [Cloudflare](https://kb.torq.io/en/articles/11161716-cloudflare.md): Integrate Cloudflare with Torq to detect and manage threats and enhance content delivery. - [CrowdStrike Identity Protection](https://kb.torq.io/en/articles/11161122-crowdstrike-identity-protection.md): Integrate CrowdStrike IdP with Torq to automate event response workflows using API key configurations. - [Bitbucket](https://kb.torq.io/en/articles/11872833-bitbucket.md): Integrate Bitbucket with Torq to enhance your automated Workflows. - [Anthropic Claude](https://kb.torq.io/en/articles/13052247-anthropic-claude.md): Use Anthropic Claude in Torq by bringing your own subscription. - [Google SecOps Response](https://kb.torq.io/en/articles/13169148-google-secops-response.md): Integrate Google SecOps Response \(formerly Chronicle\) with Torq to enhance your SOC investigations. - [Upwind](https://kb.torq.io/en/articles/13162187-upwind.md): Integrate Upwind with Torq to automate event response workflows using webhooks and API credentials. - [Panorays](https://kb.torq.io/en/articles/13531602-panorays.md): Integrate Panorays with Torq to automate third-party risk management workflows using webhooks and API key configurations.. - [1Password](https://kb.torq.io/en/articles/13754603-1password.md): Integrate 1Password with Torq to automate user lifecycle management workflows. - [Halo](https://kb.torq.io/en/articles/14080073-halo.md): Integrate Halo with Torq to automate IT service management and PSA workflows. - [SailPoint](https://kb.torq.io/en/articles/14792449-sailpoint.md): Integrate SailPoint Identity Security Cloud with Torq to automate identity governance and access response workflows using event trigger subscriptions and OAuth2 API credentials. - [Cyberhaven](https://kb.torq.io/en/articles/14792242-cyberhaven.md): Integrate Cyberhaven with Torq to automate data protection and insider risk response workflows using webhooks and API key configurations. - [LayerX](https://kb.torq.io/en/articles/14845310-layerx.md): LayerX is an agentless AI and browser security platform that can help you protect your organization against AI, SaaS, web, and data leakage risks across any browser, application, device, and identity. - [Atlassian Rovo MCP Server](https://kb.torq.io/en/articles/15163007-atlassian-rovo-mcp-server.md): Integrate Atlassian Rovo MCP Server with Torq to securely connect trusted AI tools. - [Intezer](https://kb.torq.io/en/articles/11774543-intezer.md): Integrate Intezer with Torq to enhance your automated Workflows. - [Vega](https://kb.torq.io/en/articles/15451808-vega.md): Integrate Vega with Torq to turn AI-native detection into autonomous SOC response. - [Sekoia Intelligence](https://kb.torq.io/en/articles/15834955-sekoia-intelligence.md): Integrate Sekoia Intelligence with Torq to enrich your workflows with threat intelligence using API key configuration. - [Google Cloud Platform \(GCP\)](https://kb.torq.io/en/articles/9297304-google-cloud-platform-gcp.md): Integrate GCP with Torq to enhance Torq automated workflows. - [Google Chat](https://kb.torq.io/en/articles/9211240-google-chat.md): Integrate Google Chat with Torq to enable real-time updates and seamless automation within your chat environment. - [Google Sheets](https://kb.torq.io/en/articles/9140011-google-sheets.md): Explore essential Google Sheets functions: generate tokens, search, create, query data & track workflow events with our guide & templates. - [Receive Gmail Push Notifications Using Google Cloud Pub/Sub](https://kb.torq.io/en/articles/9138324-receive-gmail-push-notifications-using-google-cloud-pub-sub.md): Learn how to configure GCP Pub/Sub with Torq to receive Gmail push notifications and streamline your workflow triggers without polling. - [Send Gmail Messages With Images](https://kb.torq.io/en/articles/9138326-send-gmail-messages-with-images.md): Learn to embed images in Gmail by attaching them and using 'Content-ID' in your HTML emails. - [Send Gmail Messages With Attachments](https://kb.torq.io/en/articles/9138329-send-gmail-messages-with-attachments.md): Learn to attach files to Gmail messages by encoding to Base64 using the Encode base64 utility before employing the Gmail Send Message Step. - [Google SecOps \(formerly Google Chronicle\)](https://kb.torq.io/en/articles/9992600-google-secops-formerly-google-chronicle.md): Use Google SecOps \(formerly Google Chronicle\) steps in Torq to access assets, run searches, and automate your security investigations. - [Google Cloud Security Operations Data Connector](https://kb.torq.io/en/articles/13280290-google-cloud-security-operations-data-connector.md): Stream Google SecOps detections into Torq in real time, with faster delivery and simplified setup. - [Palo Alto Networks Prisma Cloud](https://kb.torq.io/en/articles/9138303-palo-alto-networks-prisma-cloud.md): "Protect cloud-native apps with Prisma Cloud. Explore premade steps and templates for seamless security workflow integration." - [Palo Alto Networks Cortex XDR](https://kb.torq.io/en/articles/9138312-palo-alto-networks-cortex-xdr.md): Learn to integrate Cortex XDR with Torq: IOCs, incident management, and API key validation for seamless workflow automation. - [Amazon Web Services \(AWS\)](https://kb.torq.io/en/articles/9138309-amazon-web-services-aws.md): Integrate AWS with Torq to take actions as an approved user for the assets and APIs provided by the Amazon Web Services platform. - [Amazon SNS](https://kb.torq.io/en/articles/9138323-amazon-sns.md): Integrate SNS with Torq to receive alerts and findings from AWS services. - [Amazon GuardDuty](https://kb.torq.io/en/articles/11027603-amazon-guardduty.md): Integrate Amazon GuardDuty with Torq to receive EventBridge events with GuardDuty findings. - [Amazon Security Hub](https://kb.torq.io/en/articles/9138334-amazon-security-hub.md): Centralize AWS security with Security Hub and automate remediation using Torq to streamline and secure your cloud environment. - [AWS SigV4 Authorization: Utilize AWS Calls in HTTP Steps](https://kb.torq.io/en/articles/11079835-aws-sigv4-authorization-utilize-aws-calls-in-http-steps.md): Use AWS SigV4 authorization for secure and automated cloud operations with Torq's custom HTTP request step. - [Assume different roles via the "sts assume-role" command in AWS CLI Steps](https://kb.torq.io/en/articles/9024670-assume-different-roles-via-the-sts-assume-role-command-in-aws-cli-steps.md): Learn how to use the "sts assume-role" command in AWS CLI Steps to assume different roles in Torq Workflows. - [Azure](https://kb.torq.io/en/articles/9138424-azure.md): Integrate Azure with Torq to execute Azure CLI commands in Workflows. - [Azure Key Vault](https://kb.torq.io/en/articles/9138426-azure-key-vault.md): Learn to integrate Azure Key Vault with Torq by obtaining necessary Azure IDs and URIs and setting up secure secret storage. - [Microsoft Defender for Endpoint](https://kb.torq.io/en/articles/9973890-microsoft-defender-for-endpoint.md): Sometimes known as Microsoft Defender for XDR. Integrate Defender for Endpoint with Torq to automate threat detection and more. - [Microsoft 365 Delegated Access](https://kb.torq.io/en/articles/9138305-microsoft-365-delegated-access.md): Enable non-admin Microsoft 365 access with Torq Delegated Access for Excel, OneDrive, Outlook & SharePoint steps. - [Microsoft Forms](https://kb.torq.io/en/articles/9697429-microsoft-forms.md): Integrate Microsoft Forms with Torq to automate your forms. - [Microsoft 365 Graph Subscription](https://kb.torq.io/en/articles/9380201-microsoft-365-graph-subscription.md): Learn to integrate Microsoft Graph in Torq and utilize the Steps in secure automated Workflows. - [Microsoft Sentinel](https://kb.torq.io/en/articles/9297475-microsoft-sentinel.md): Learn to create a Microsoft Sentinel Step integration in Torq, including APP registration in Entra ID \(formerly Azure AD\). - [Microsoft Teams Bot](https://kb.torq.io/en/articles/9138446-microsoft-teams-bot.md): Integrate a Microsoft Teams Bot with Torq to trigger workflows, manage Teams interactions, and enhance team collaboration. - [Microsoft 365 Defender](https://kb.torq.io/en/articles/9989882-microsoft-365-defender.md): Use Microsoft Defender XDR \(Microsoft 365 Defender\) steps in your Torq automated workflows. - [Microsoft Recommended Permissions](https://kb.torq.io/en/articles/10305275-microsoft-recommended-permissions.md): The recommended permissions to provide your Microsoft Integrations - [Microsoft 365](https://kb.torq.io/en/articles/10287213-microsoft-365.md): Learn how to integrate Microsoft 365 products with Torq to automate Workflows, security, production, and more. - [Microsoft Active Directory](https://kb.torq.io/en/articles/10338677-microsoft-active-directory.md): Integrate Microsoft Active Directory with Torq to automate identity access, security, and permissions across your organization. - [Azure Log Analytics](https://kb.torq.io/en/articles/10495751-azure-log-analytics.md): Use Azure Log Analytics steps in your Torq automated workflows. - [Azure OpenAI](https://kb.torq.io/en/articles/11411348-azure-openai.md): Integrate Azure OpenAI with Torq to use Azure OpenAI steps and automate security workflows. - [Azure DevOps](https://kb.torq.io/en/articles/12151066-azure-devops.md): Integrate Azure DevOps with Torq to enhance automated Workflows. - [Send and Refresh Adaptive Cards in Outlook Emails](https://kb.torq.io/en/articles/9024679-send-and-refresh-adaptive-cards-in-outlook-emails.md) - [Trigger a Workflow when a File is Changed in a Microsoft OneDrive Folder](https://kb.torq.io/en/articles/9828706-trigger-a-workflow-when-a-file-is-changed-in-a-microsoft-onedrive-folder.md) - [Trigger a Workflow when a User Account is Changed in Microsoft Entra ID](https://kb.torq.io/en/articles/9829575-trigger-a-workflow-when-a-user-account-is-changed-in-microsoft-entra-id.md) - [Send Emails With Inline Images in Microsoft Outlook](https://kb.torq.io/en/articles/9297456-send-emails-with-inline-images-in-microsoft-outlook.md): Use Torq's Microsoft Outlook Send Message Step to send emails with inline images. - [Revalidate a User’s Identity by Triggering Entra ID Authentication From a Torq Workflow](https://kb.torq.io/en/articles/9024677-revalidate-a-user-s-identity-by-triggering-entra-id-authentication-from-a-torq-workflow.md) - [Microsoft Defender Data Connector](https://kb.torq.io/en/articles/14685235-microsoft-defender-data-connector.md): Learn how to automatically ingest Microsoft Defender alerts and incidents into Torq to enable Auto Triage and trigger response workflows. - [Microsoft Entra ID Data Connector](https://kb.torq.io/en/articles/14889396-microsoft-entra-id-data-connector.md): Ingest Microsoft Entra ID identity, risk, and audit events into Torq to enable automated analysis and Auto Triage. - [Slack Bot](https://kb.torq.io/en/articles/9138337-slack-bot.md): Integrate Slack with Torq's bot to trigger workflows, message channels, run commands, and customize branding—all inside Slack. - [Slack Slash Commands](https://kb.torq.io/en/articles/9138345-slack-slash-commands.md): Integrate Slack Slash Commands with Torq to trigger workflows directly from Slack by setting up a unique endpoint. - [Slack Interaction Payloads](https://kb.torq.io/en/articles/9138361-slack-interaction-payloads.md): Integrate Slack with Torq to trigger workflows from Slack interactions, using a custom endpoint for event notifications. - [Custom Slack Events](https://kb.torq.io/en/articles/9138352-custom-slack-events.md): Integrate Slack with Torq to trigger workflows based on custom Slack events using a unique endpoint for automated notifications. - [Slack Custom App](https://kb.torq.io/en/articles/11151827-slack-custom-app.md): Integrate Custom Slack Apps with Torq to build workflows with Slack messages. - [SentinelOne](https://kb.torq.io/en/articles/9140001-sentinelone.md): Secure assets with SentinelOne's unified AI-driven platform and Torq's automated workflows. - [SentinelOne Data Connector](https://kb.torq.io/en/articles/14635477-sentinelone-data-connector.md): Learn how to automatically ingest SentinelOne threats and alerts into Torq to enable Auto Triage and trigger response workflows. - [Zscaler Internet Access](https://kb.torq.io/en/articles/11017667-zscaler-internet-access.md): Integrate Zscaler ZIA with Torq to enhance threat detection and response efficiency. - [Atlassian](https://kb.torq.io/en/articles/9138342-atlassian.md): Integrate Atlassian with Torq to enhance your workflows with user activation and domain management. - [Jira](https://kb.torq.io/en/articles/9139692-jira.md): Integrate Jira with Torq to monitor projects and processes and update policies and users. - [Confluence](https://kb.torq.io/en/articles/9970578-confluence.md): Integrate Confluence with Torq to securely access Confluence resources on behalf of a user. - [Automatically Mention Users in Jira Comments Using ADF](https://kb.torq.io/en/articles/10001813-automatically-mention-users-in-jira-comments-using-adf.md): Automate user mentions in Jira comments for streamlined communication. - [Splunk](https://kb.torq.io/en/articles/9139999-splunk.md): Integrate Splunk with Torq to trigger workflows from alerts and perform searches. - [Set up delegated access to a Microsoft application using OAuth 2.0](https://kb.torq.io/en/articles/9024678-set-up-delegated-access-to-a-microsoft-application-using-oauth-2-0.md): Learn how to set up delegated access with Microsoft Graph to an Entra ID application using OAuth 2.0 in Torq. - [Okta Data Connector](https://kb.torq.io/en/articles/14889704-okta-data-connector.md): Ingest Okta identity, authentication, and threat events into Torq to power automated analysis. - [Okta](https://kb.torq.io/en/articles/9139783-okta.md): Integrate Okta with Torq to trigger workflows: configure webhooks and event hooks, create test workflows, and set up Okta steps. ## Build Automations - [What is Torq?](https://kb.torq.io/en/articles/9026484-what-is-torq.md): Discover the core components of Torq's security hyperautomation platform: Workflows, triggers, steps, integrations, cases, and more. - [Finding Your Way Around Torq](https://kb.torq.io/en/articles/9267556-finding-your-way-around-torq.md): Discover Torq basics to kickstart your automation journey. - [Automate With AI: Simplify Workflow Creation](https://kb.torq.io/en/articles/9445187-automate-with-ai-simplify-workflow-creation.md): Use AI to generate automated workflows, build logic based on your given prompt, and ease the creation process with AI automated solutions. - [AI in Torq](https://kb.torq.io/en/articles/13424122-ai-in-torq.md): Learn about the different AI capabilities available in Torq. - [Troubleshoot Workflow Failures in Torq](https://kb.torq.io/en/articles/13543992-troubleshoot-workflow-failures-in-torq.md): A practical troubleshooting guide for workflow failures in Torq. - [Workflow States: Testing and Publishing Workflows in Torq](https://kb.torq.io/en/articles/9115762-workflow-states-testing-and-publishing-workflows-in-torq.md): Learn about the different states of Torq workflows and how to transition between them for efficient testing and deployment. - [Export and Import Workflows in Torq](https://kb.torq.io/en/articles/9140014-export-and-import-workflows-in-torq.md): Learn how to export and import workflows in YAML format. - [Version History in Torq: Track Workflow Changes](https://kb.torq.io/en/articles/9127970-version-history-in-torq-track-workflow-changes.md): Learn how to view and restore previous workflow versions, compare changes, and manage iterations efficiently. - [Stop Workflow Executions: A Quick Guide](https://kb.torq.io/en/articles/9116275-stop-workflow-executions-a-quick-guide.md): Learn how to halt ongoing workflow executions. - [Implement a Workflow Approval Flow: Effectively Control Production Changes](https://kb.torq.io/en/articles/9140073-implement-a-workflow-approval-flow-effectively-control-production-changes.md): Use Torq roles to implement an approval flow that ensures workflows are reviewed before publication. - [Get Notifications for Failed Workflows](https://kb.torq.io/en/articles/9128070-get-notifications-for-failed-workflows.md): Learn how to set up notifications for failed workflows, enabling quick identification and resolution of automation issues. - [Tag Workflows for Efficient Organization](https://kb.torq.io/en/articles/9139969-tag-workflows-for-efficient-organization.md): Learn how to organize and categorize your workflows effectively by using tags. - [Grouping Torq Workflows into Sections](https://kb.torq.io/en/articles/9116449-grouping-torq-workflows-into-sections.md): Learn how to group workflows into sections for easier navigation. - [Exporting Torq Workflows to PDF](https://kb.torq.io/en/articles/9140082-exporting-torq-workflows-to-pdf.md): Export workflows to PDF for easy sharing with users outside Torq. - [Annotations: Add Clarity to Your Workflows](https://kb.torq.io/en/articles/13362876-annotations-add-clarity-to-your-workflows.md): Add annotations to workflows to document logic, explain decisions, and improve collaboration directly on the workflow canvas. - [Test Pads: Experiment With Workflow Steps](https://kb.torq.io/en/articles/13832163-test-pads-experiment-with-workflow-steps.md): Add a test pad to the workflow canvas to brainstorm and experiment with steps without impacting the main workflow. - [Workflow Metadata: Enrich Executions with Additional Context](https://kb.torq.io/en/articles/9140008-workflow-metadata-enrich-executions-with-additional-context.md): Access workflow metadata for essential execution details that can be provided as step inputs and used in messages, tickets, logs, etc. - [Workflow Context: Understand Data Access and Utilization in Torq](https://kb.torq.io/en/articles/9175119-workflow-context-understand-data-access-and-utilization-in-torq.md): Use the workflow context to access execution data, including completed step outputs, trigger event information, and more. - [Escape Special Characters in JSON Objects](https://kb.torq.io/en/articles/9174867-escape-special-characters-in-json-objects.md): Learn how to properly escape special characters and white space in JSON objects to successfully pass data between steps in Torq. - [Escape JSON Strings to Use Python in Torq](https://kb.torq.io/en/articles/9113702-escape-json-strings-to-use-python-in-torq.md): Learn how to properly escape JSON strings and take advantage of using Python code in Torq. - [Escape Curly Brackets to Pass Them in Workflow Step Inputs](https://kb.torq.io/en/articles/9140025-escape-curly-brackets-to-pass-them-in-workflow-step-inputs.md): Learn how to escape curly brackets in Torq to correctly pass syntax for systems like JQL or GraphQL, avoiding common JSON or input errors. - [Nest Context Expressions: Dynamic Key References in Torq](https://kb.torq.io/en/articles/9113285-nest-context-expressions-dynamic-key-references-in-torq.md): Dynamically reference keys in Torq workflows using nested context expressions. - [Use Fractional Seconds in Torq: Enhance DateTime Precision](https://kb.torq.io/en/articles/9174908-use-fractional-seconds-in-torq-enhance-datetime-precision.md): Learn how to enhance the precision of datetime values by returning fractional seconds in Torq. - [Advanced JSONPath and Golang Templates](https://kb.torq.io/en/articles/9202746-advanced-jsonpath-and-golang-templates.md): Learn how to efficiently retrieve and manipulate data in Torq with advanced JSONPath and Golang templates. - [Format ASCII Tables for Emails](https://kb.torq.io/en/articles/9140018-format-ascii-tables-for-emails.md): Ensure your ASCII tables retain their alignment and readability in emails. - [Sprig Functions: Add Dynamic Data Logic to Your Workflows](https://kb.torq.io/en/articles/12780103-sprig-functions-add-dynamic-data-logic-to-your-workflows.md): Easily perform dynamic data manipulation and logic operations in your workflows using Torq’s built-in Sprig functions. - [jq Expressions for Run jq Command Step](https://kb.torq.io/en/articles/9024668-jq-expressions-for-run-jq-command-step.md): Use built-in jq expressions in the Run jq Command step to transform JSON data without writing custom code. - [Python Scripting in Torq Workflows](https://kb.torq.io/en/articles/12595926-python-scripting-in-torq-workflows.md): Add custom Python logic to workflows for flexible, advanced automation - [Execute Workflows: Testing and Production Options in Torq](https://kb.torq.io/en/articles/9154312-execute-workflows-testing-and-production-options-in-torq.md): Explore Torq's testing and production workflow execution options. - [Mock Outputs: Simulate Step Executions in Torq](https://kb.torq.io/en/articles/9140030-mock-outputs-simulate-step-executions-in-torq.md): Leverage mock outputs to test workflows and logic with predetermined responses, avoiding unnecessary API calls or production changes. - [Trigger a Workflow with an Integration Trigger: Sync/Async Options](https://kb.torq.io/en/articles/9140015-trigger-a-workflow-with-an-integration-trigger-sync-async-options.md): Learn how to synchronously or asynchronously trigger a specific workflow with an integration trigger in Torq. - [Automate CircleCI Secret Rotation with Torq](https://kb.torq.io/en/articles/9173821-automate-circleci-secret-rotation-with-torq.md): Automate CircleCI secret rotation with Torq for enhanced security. Follow our step-by-step guide to safeguard your software development. - [Slack Chatbots in Torq: Get the Most Out of Slack](https://kb.torq.io/en/articles/9211218-slack-chatbots-in-torq-get-the-most-out-of-slack.md): Learn how to enhance your Torq workflows with versatile Slack integrations by triggering commands, sending messages, and more. - [Microsoft Teams Chatbots in Torq: Get the Most Out of Teams](https://kb.torq.io/en/articles/9211194-microsoft-teams-chatbots-in-torq-get-the-most-out-of-teams.md): Maximize Torq+Teams efficiency: Learn to trigger workflows, send messages, and ask questions directly in Teams. - [Automate Lost or Stolen Device Management with Torq](https://kb.torq.io/en/articles/9175093-automate-lost-or-stolen-device-management-with-torq.md): Learn how to use Torq to secure team member's devices when misplaced. - [Workflow Triggers in Torq: Initiating Workflow Executions](https://kb.torq.io/en/articles/9121101-workflow-triggers-in-torq-initiating-workflow-executions.md): Learn about Torq's workflow triggers and how to use them efficiently. - [Integration Triggers in Torq: Ingest Data](https://kb.torq.io/en/articles/9130865-integration-triggers-in-torq-ingest-data.md): Trigger automated workflows based on events from external systems. - [On-Demand Triggers: Enable User-Initiated Executions](https://kb.torq.io/en/articles/9112879-on-demand-triggers-enable-user-initiated-executions.md): Learn how to set up and customize on-demand triggers in Torq workflows. - [Schedule Triggers in Torq: Predefine Execution Timing](https://kb.torq.io/en/articles/9120989-schedule-triggers-in-torq-predefine-execution-timing.md): Learn how to schedule workflow executions for precise dates and times. - [Trigger Workflows with Torq System Events](https://kb.torq.io/en/articles/9128772-trigger-workflows-with-torq-system-events.md): Learn how to initiate workflows based on internal Torq events. - [Trigger Workflow Executions with Uploaded Files](https://kb.torq.io/en/articles/9121315-trigger-workflow-executions-with-uploaded-files.md): Learn how to trigger workflow executions using uploaded files as inputs. - [Set Up IMAP Trigger Events in Torq](https://kb.torq.io/en/articles/9112767-set-up-imap-trigger-events-in-torq.md): Set up IMAP trigger events in Torq to create workflows triggered by incoming emails. - [Email Trigger](https://kb.torq.io/en/articles/11560283-email-trigger.md): Initiate workflows from incoming emails, no third-party integrations required. - [Explore Torq Steps: Workflow Building Blocks](https://kb.torq.io/en/articles/9122841-explore-torq-steps-workflow-building-blocks.md): Learn about steps in Torq and how to use them efficiently in workflows. - [Creating Custom Steps in Torq: Automate Anything](https://kb.torq.io/en/articles/9183207-creating-custom-steps-in-torq-automate-anything.md): Learn how to create your own new steps to automate any process. - [Set Steps to Automatically Retry: Enhancing Workflow Reliability in Torq](https://kb.torq.io/en/articles/9112337-set-steps-to-automatically-retry-enhancing-workflow-reliability-in-torq.md): Learn how to set steps to automatically retry, saving you the effort of implementing complex retry patterns. - [File Usage in Torq Workflows](https://kb.torq.io/en/articles/9112499-file-usage-in-torq-workflows.md): Learn how to incorporate file usage into Torq workflows, optimizing effciency and flexibility in data handling. - [Return HTTP Responses as Files: Handling Large Outputs and Binary Content](https://kb.torq.io/en/articles/9139557-return-http-responses-as-files-handling-large-outputs-and-binary-content.md): Learn how to handle large outputs and binary content by converting HTTP responses to files in Torq workflows. - [Configure HTTP Mode Steps Failure](https://kb.torq.io/en/articles/9140298-configure-http-mode-steps-failure.md): Configure HTTP requests in Torq workflows to fail when receiving non-success responses. - [Automatically Manage Integrations in Torq](https://kb.torq.io/en/articles/9149256-automatically-manage-integrations-in-torq.md): Automatically create, update, and delete integrations with workflow steps. - [Use AI for Step Parameter Population](https://kb.torq.io/en/articles/9140027-use-ai-for-step-parameter-population.md): Automatically fill specific step input parameters with AI assistance. - [Scripting in Torq Workflows: Bring Your Own Code](https://kb.torq.io/en/articles/9140315-scripting-in-torq-workflows-bring-your-own-code.md): Incorporate scripts into Torq workflows using dedicated steps for Python, JavaScript, PowerShell, and Bash, with support for AI completion. - [Rename Steps: Enhance Workflow Readability in Torq](https://kb.torq.io/en/articles/9393585-rename-steps-enhance-workflow-readability-in-torq.md): Learn how to rename steps and maintain their references in Torq to improve workflow clarity and efficiency. - [Send Emails Directly from Torq](https://kb.torq.io/en/articles/9973813-send-emails-directly-from-torq.md): Send emails directly from Torq using the Send Email step, no third-party integration is required. - [Build a Custom Container Step](https://kb.torq.io/en/articles/9024698-build-a-custom-container-step.md): Learn how to build and configure a custom Docker container as a step in Torq. - [Array Utilities](https://kb.torq.io/en/articles/9140046-array-utilities.md): Explore and manage arrays easily using Torq’s built-in array utility steps - [Cryptographic Utilities](https://kb.torq.io/en/articles/9140087-cryptographic-utilities.md): Ensure data integrity, support secure authentication flows, and simplify security-focused automations. - [Date and Time Utilities](https://kb.torq.io/en/articles/9140151-date-and-time-utilities.md): Calculate, compare, and format timestamps within your workflows using Torq’s built-in date and time utility steps. - [Encoding Utilities](https://kb.torq.io/en/articles/9140176-encoding-utilities.md): Encode, decode, and transform data within your workflows using Torq’s built-in Encoding utility steps. - [String Utilities](https://kb.torq.io/en/articles/9140365-string-utilities.md): Manipulate, format, and clean text in your workflows using Torq’s string utility steps. - [Parameter Utilities](https://kb.torq.io/en/articles/9140425-parameter-utilities.md): Define, store, and reuse parameters across your workflows. - [Math Utilities](https://kb.torq.io/en/articles/9148494-math-utilities.md): Explore the math utility steps in Torq. - [File Utilities](https://kb.torq.io/en/articles/9149269-file-utilities.md): Work with ZIP archives and files in your workflows using Torq’s file utility steps. - [Object Utilities](https://kb.torq.io/en/articles/9149385-object-utilities.md): Explore the object utility steps in Torq. - [Output Utilities](https://kb.torq.io/en/articles/9149670-output-utilities.md): Explore the output utility steps in Torq. - [Extraction Utilities](https://kb.torq.io/en/articles/9155514-extraction-utilities.md): Explore the extraction utility steps in Torq. - [Utils Utilities](https://kb.torq.io/en/articles/9839998-utils-utilities.md): Enrich, compare, and match data within your workflows using Torq’s built-in Utils utility steps. - [Screenshot Utilities](https://kb.torq.io/en/articles/12668675-screenshot-utilities.md): Learn how to use the screenshot capture utility steps in Torq. - [Utility Steps Overview](https://kb.torq.io/en/articles/12629203-utility-steps-overview.md): Torq utility steps perform common data handling and helper operations within workflows. - [Operators in Torq: Workflow Flow Control](https://kb.torq.io/en/articles/9121891-operators-in-torq-workflow-flow-control.md): Learn about Torq's Operators and how to efficiently use them for workflow logic control and definition. - [If Operator: Using Conditions in Torq](https://kb.torq.io/en/articles/12231503-if-operator-using-conditions-in-torq.md): Learn how to use conditions to define and apply different workflow logic. - [Switch Operator: Streamline Conditional Logic with Branches](https://kb.torq.io/en/articles/9110241-switch-operator-streamline-conditional-logic-with-branches.md): Learn how to use Torq's Switch operator to efficiently manage diverse workflow conditions in a neat, organized manner. - [Loop Operator: Automate Iterative Processes with Torq](https://kb.torq.io/en/articles/9144380-loop-operator-automate-iterative-processes-with-torq.md): Learn how to efficiently use loops in Torq workflows. - [Collect Operator: Streamline Loop Results Aggregation in Torq](https://kb.torq.io/en/articles/9128929-collect-operator-streamline-loop-results-aggregation-in-torq.md): Learn how to use the Collect operator to collect the results of a loop in an easily readable array. - [Exit Operator: Configure Output Schemas in Torq](https://kb.torq.io/en/articles/9110185-exit-operator-configure-output-schemas-in-torq.md): Define output schemas in Torq to standardize workflow outputs for consistency in returned data and more predictable, robust workflows. - [Parallel Step Executions: Accelerating SecOps with Torq](https://kb.torq.io/en/articles/9144744-parallel-step-executions-accelerating-secops-with-torq.md): Execute multiple processes in your workflows concurrently, enhancing efficiency and saving time. - [Nested Workflows in Torq: Improve Modularity and Reusability](https://kb.torq.io/en/articles/9139661-nested-workflows-in-torq-improve-modularity-and-reusability.md): Use nested workflows to break large workflows into reusable, modular components that make automation easier to read, maintain, and scale. - [Dynamically Select Nested Workflows: Specify IDs from the Context](https://kb.torq.io/en/articles/9139994-dynamically-select-nested-workflows-specify-ids-from-the-context.md): Dynamically specify nested workflows and their revisions by passing IDs from the workflow context. - [Transform Data Operator: Manipulate Data Seamlessly with Torq](https://kb.torq.io/en/articles/9684949-transform-data-operator-manipulate-data-seamlessly-with-torq.md): Learn how Torq's Transform data operator streamlines JSON manipulation with AI-driven natural language prompts. - [Deduplicate Operator: Identify Unique Values](https://kb.torq.io/en/articles/9996964-deduplicate-operator-identify-unique-values.md): Use the Deduplicate operator to identify unique inputs and minimize noise by managing unique and duplicate values differently. - [AI Task Operator: Execute AI-Powered Tasks Seamlessly](https://kb.torq.io/en/articles/10115626-ai-task-operator-execute-ai-powered-tasks-seamlessly.md): Use the AI Task operator to incorporate AI models into Torq workflows effortlessly. - [Track AI Task Operator Usage](https://kb.torq.io/en/articles/10219449-track-ai-task-operator-usage.md): Understand the AI Task operator's credit system, allocation, and usage tracking. - [Wait Operator: Precisely Pause Workflow Progress with Torq](https://kb.torq.io/en/articles/10115781-wait-operator-precisely-pause-workflow-progress-with-torq.md): Learn how to pause and resume your workflows with the Wait operator to control timing and improve execution flow in Torq - [AI Agents: Bring Adaptive Intelligence into Your Workflows](https://kb.torq.io/en/articles/12065413-ai-agents-bring-adaptive-intelligence-into-your-workflows.md): Add AI Agents to workflows to enable adaptive automation and smarter decisions. - [AI Agent Instructions: Writing a Mission Statement](https://kb.torq.io/en/articles/12065565-ai-agent-instructions-writing-a-mission-statement.md): Learn how to define your AI Agent’s role, goal, and scope in natural language. - [AI Tools: Enhance AI Agent Capabilities](https://kb.torq.io/en/articles/12065486-ai-tools-enhance-ai-agent-capabilities.md): Boost efficiency by giving your AI Agent tools to act smarter and adapt better in workflows. - [Use Case: Automate SOC Triage with AI Agents](https://kb.torq.io/en/articles/12094965-use-case-automate-soc-triage-with-ai-agents.md): Learn how to accelerate SOC triage using AI Agents. - [AI Models: Bring Your Own Subscription \(BYOS\)](https://kb.torq.io/en/articles/13052484-ai-models-bring-your-own-subscription-byos.md): Power Torq AI Agents with your own AI provider subscriptions for greater flexibility, governance, and cost control. - [AI Agent FAQs](https://kb.torq.io/en/articles/12071508-ai-agent-faqs.md): Check out common questions about Torq's AI Agents - [Torq Interact: Send Forms and Create Pages](https://kb.torq.io/en/articles/9095382-torq-interact-send-forms-and-create-pages.md): Torq Interact creates custom web pages, forms, and portals in a secure and automated way to collect or distribute user-facing content. - [Torq Interact: Start an Interaction Flow](https://kb.torq.io/en/articles/10532124-torq-interact-start-an-interaction-flow.md): Learn how to start an Interaction Flow to interact with end users, create forms, pages, and more - [Create a Portal with Torq Interact](https://kb.torq.io/en/articles/9907655-create-a-portal-with-torq-interact.md): Use Torq Interact to create a cross organizational portal interface and combine many Torq Interactions into one easily accessible page. - [Condition Elements in Interact: Create Dynamic Forms and Pages](https://kb.torq.io/en/articles/10117942-condition-elements-in-interact-create-dynamic-forms-and-pages.md): Create complex and dynamic Torq Interactions with condition elements. - [Torq Interact Loading Screen: Real-Time Updates](https://kb.torq.io/en/articles/10531846-torq-interact-loading-screen-real-time-updates.md): Update users on their progress with Torq's Interaction Flow loading screen. - [Reference User Answers in Torq Interact](https://kb.torq.io/en/articles/11137822-reference-user-answers-in-torq-interact.md): Reference user input and responses from Interactions quickly and simply via the workflow context. - [Display Tables in an Interaction: Torq Interact](https://kb.torq.io/en/articles/11042642-display-tables-in-an-interaction-torq-interact.md): Present tables to end-users using Torq Interact and allow real-time data viewing. - [Torq Interact: Access and Execute from the Sidebar](https://kb.torq.io/en/articles/11509009-torq-interact-access-and-execute-from-the-sidebar.md): Configure Torq Interact workflows to appear or send notifications directly in the sidebar, reducing context switching. - [Torq Interact: Access Control](https://kb.torq.io/en/articles/13001783-torq-interact-access-control.md): Use Interact permissions to control exactly who can access and run each Interaction Flow. - [Torq Interact: Row Selection and Editable Table](https://kb.torq.io/en/articles/13868260-torq-interact-row-selection-and-editable-table.md): Learn how to let users select or edit table-type workspace variables directly within Torq Interact. - [Workspace Variables in Torq: Optimal Data Management](https://kb.torq.io/en/articles/9202852-workspace-variables-in-torq-optimal-data-management.md): Learn how to use workspace variables in Torq for streamlined storage and access to workspace-relevant information across workflows. - [Global Variables: Share Data Across Workflow Executions](https://kb.torq.io/en/articles/9202839-global-variables-share-data-across-workflow-executions.md): Learn how to use global variables in Torq to store and access data across multiple workflow executions efficiently. - [Table Workspace Variables: Manage Data Efficiently in Torq](https://kb.torq.io/en/articles/9315614-table-workspace-variables-manage-data-efficiently-in-torq.md): Learn how to use table workspace variables in Torq for efficient data management. - [Custom Secrets: Protect Sensitive Data](https://kb.torq.io/en/articles/9142412-custom-secrets-protect-sensitive-data.md): Securely create and use custom secrets within Torq workflows, ensuring data protection and confidentiality. - [Integrate External Secret Stores with Torq for Enhanced Security](https://kb.torq.io/en/articles/9141592-integrate-external-secret-stores-with-torq-for-enhanced-security.md): Integrate Torq with your key management service to manage secrets for third-party vendor integrations securely and independently. - [Testing Integration Instances: Validate Your Connections](https://kb.torq.io/en/articles/10627995-testing-integration-instances-validate-your-connections.md): Learn how to quickly validate integration connections to ensure reliable workflows and smooth automation setup. - [Integration Builder: Create Custom Integrations](https://kb.torq.io/en/articles/10662506-integration-builder-create-custom-integrations.md): Leverage Torq's custom integration builder to create tailored step and trigger integrations. - [Deploy Self-Hosted Step Runners](https://kb.torq.io/en/articles/9142406-deploy-self-hosted-step-runners.md): Set up and manage self-hosted Step Runners in Torq to execute steps requiring access to private environments. - [Customize Self-Hosted Step Runners: Advanced Deployment Settings](https://kb.torq.io/en/articles/11383457-customize-self-hosted-step-runners-advanced-deployment-settings.md): Learn how to customize the default deployment configuration files for self-hosted Step Runners. - [Troubleshoot Self-Hosted Step Runners](https://kb.torq.io/en/articles/9142427-troubleshoot-self-hosted-step-runners.md): Learn to quickly diagnose and fix issues with Torq's self-hosted Step Runners. - [Deploy Self-Hosted Step Runners on Microsoft Azure Kubernetes Service \(AKS\)](https://kb.torq.io/en/articles/11070775-deploy-self-hosted-step-runners-on-microsoft-azure-kubernetes-service-aks.md): Learn how to deploy Torq Step Runners on a Microsoft AKS cluster. - [Deploy Self-Hosted Step Runners on AWS Elastic Kubernetes Service \(EKS\)](https://kb.torq.io/en/articles/9024696-deploy-self-hosted-step-runners-on-aws-elastic-kubernetes-service-eks.md): Learn how to deploy Torq Step Runners on an AWS EKS cluster. - [Step Runner Version Updates](https://kb.torq.io/en/articles/12616921-step-runner-version-updates.md) - [Automating Case Management with Torq: Key Features](https://kb.torq.io/en/articles/9193768-automating-case-management-with-torq-key-features.md): Get an overview of Torq case management with recommended articles for further exploration. - [Automatically Manage Cases with Torq Workflows](https://kb.torq.io/en/articles/9165031-automatically-manage-cases-with-torq-workflows.md): Learn how to automate Torq case creation, update, and resolution using workflows. - [Cases Triggers: Initiate Workflows with Torq Case Management Events](https://kb.torq.io/en/articles/9138475-cases-triggers-initiate-workflows-with-torq-case-management-events.md): Get to know the events within the case lifecycle that can serve as triggers for Torq workflows. - [Automating Case Timelines in Torq: Track Investigation Progress](https://kb.torq.io/en/articles/9165278-automating-case-timelines-in-torq-track-investigation-progress.md): Learn how to streamline investigations with case timeline automation using automated comments, user mentions, and public comment sharing. - [Automating Observables: Enhance Threat Detection with Torq](https://kb.torq.io/en/articles/9095629-automating-observables-enhance-threat-detection-with-torq.md): Learn how to manage observables automatically with Torq workflows. - [Automating Notes in Torq Cases: Efficiently Store Information](https://kb.torq.io/en/articles/9172631-automating-notes-in-torq-cases-efficiently-store-information.md): Learn how to automatically manage notes in Torq cases. - [Automating Attachments in Torq Cases: Add Context and Information](https://kb.torq.io/en/articles/9172888-automating-attachments-in-torq-cases-add-context-and-information.md): Learn how to automatically manage attachments in Torq cases. - [Automating Cases Links in Torq: See the Bigger Picture](https://kb.torq.io/en/articles/9172977-automating-cases-links-in-torq-see-the-bigger-picture.md): Learn how to automatically manage links in Torq cases. - [Automate Runbooks in Torq Cases: Streamline Investigations with Instructions](https://kb.torq.io/en/articles/9173110-automate-runbooks-in-torq-cases-streamline-investigations-with-instructions.md): Learn how to manage runbooks automatically, and in the centralized Runbooks page. - [Automating Events in Torq Cases: Track Investigation-Related Events](https://kb.torq.io/en/articles/9173349-automating-events-in-torq-cases-track-investigation-related-events.md): Learn how to automatically manage events in Torq cases. - [Assign Tasks to Torq Cases: Interact with Assignees](https://kb.torq.io/en/articles/9140545-assign-tasks-to-torq-cases-interact-with-assignees.md): Learn how to automate interactions with case assignees by assigning tasks directly to cases in Torq. - [Make Workflows Accessible in Torq Cases: Streamline Investigations](https://kb.torq.io/en/articles/9202368-make-workflows-accessible-in-torq-cases-streamline-investigations.md): Learn how to streamline investigations by making specific workflows easily accessible as actions within Torq cases. - [Streamline Case Management Setup: Automated Provisioning in Torq](https://kb.torq.io/en/articles/9140568-streamline-case-management-setup-automated-provisioning-in-torq.md): Learn how to configure case management automatically as part of workspace provisioning. - [Query Cases Step: Retrieve Cases Efficiently in Torq](https://kb.torq.io/en/articles/9140130-query-cases-step-retrieve-cases-efficiently-in-torq.md): Learn how to automatically filter and retrieve cases based on your defined criteria. - [Automating Case Creation in Torq](https://kb.torq.io/en/articles/9863798-automating-case-creation-in-torq.md): Learn how to automatically create cases in Torq using workflow steps. - [Automate Case Reviews: Ensure Investigation Quality in Torq's HyperSOC](https://kb.torq.io/en/articles/10430214-automate-case-reviews-ensure-investigation-quality-in-torq-s-hypersoc.md): Learn about the workflow steps and triggers you can use to automate the case review process. - [Automate Case Access Restriction: Ensure Information Confidentiality](https://kb.torq.io/en/articles/11051856-automate-case-access-restriction-ensure-information-confidentiality.md): Learn about managing and updating case access restrictions in workflows. - [Automatically Manage Custom Case Tabs](https://kb.torq.io/en/articles/14635991-automatically-manage-custom-case-tabs.md): Learn how to automatically create and manage custom tabs for cases. - [Automatically Embed Details in Case Descriptions](https://kb.torq.io/en/articles/15176159-automatically-embed-details-in-case-descriptions.md): Learn how to embed details directly in case descriptions to spotlight critical case details using workflows. - [Saved Views: Quickly Access Relevant Cases](https://kb.torq.io/en/articles/9182528-saved-views-quickly-access-relevant-cases.md): Learn how Torq's views streamline finding and focusing on priority cases and specified case categories. - [Automating Custom Fields in Torq Cases: Track Additional Case Details](https://kb.torq.io/en/articles/9140145-automating-custom-fields-in-torq-cases-track-additional-case-details.md): Learn how to automate custom fields to efficiently capture, manage, and analyze organization-specific case details. - [Custom States in Torq: Customize Investigation Stages](https://kb.torq.io/en/articles/9182550-custom-states-in-torq-customize-investigation-stages.md): Learn how to create custom states to tailor the investigation stages to your organization's needs. - [Custom SLA Timers: Track Case Deadlines Automatically with Torq](https://kb.torq.io/en/articles/9140803-custom-sla-timers-track-case-deadlines-automatically-with-torq.md): Learn how to automate custom case SLAs for tracking deadlines and managing time limits specific to your organization's requirements. - [Customize Case State Transitions with Torq Workflows](https://kb.torq.io/en/articles/9140746-customize-case-state-transitions-with-torq-workflows.md): Learn how to customize case state transitions, ensuring each transition meets specific requirements before execution. - [Cases Settings Page: Configure Torq's HyperSOC](https://kb.torq.io/en/articles/9896839-cases-settings-page-configure-torq-s-hypersoc.md): Learn how to customize Torq's HyperSOC settings. - [Configure SLA Display](https://kb.torq.io/en/articles/11374118-configure-sla-display.md): Display either the time remaining until the SLA target or the time elapsed since it began. - [Socrates: Transform Case Investigations](https://kb.torq.io/en/articles/9734818-socrates-transform-case-investigations.md): Discover how Socrates, Torq's AI SOC analyst, accelerates investigations, offers insights, and streamlines case-management processes. - [Socrates Tools: Empower Socrates to Take Action on Cases](https://kb.torq.io/en/articles/9738837-socrates-tools-empower-socrates-to-take-action-on-cases.md): Learn about the actions Socrates, Torq's AI analyst, can perform and how to expand its out-of-the-box capabilities. - [Transform Your SOC with Responsible AI](https://kb.torq.io/en/articles/9738849-transform-your-soc-with-responsible-ai.md): Discover how Torq's Socrates AI Analyst ensures trust through responsible use and transparency. - [Socrates Auditing: Monitor Your AI Analyst](https://kb.torq.io/en/articles/9743934-socrates-auditing-monitor-your-ai-analyst.md): See where Socrates' actions are audited to ensure transparency. - [Track Socrates Usage](https://kb.torq.io/en/articles/9917812-track-socrates-usage.md): Learn how to track Socrates usage by case count to optimize your license. - [Socrates Actionplans: Optimize Runbooks for Socrates-assigned Cases](https://kb.torq.io/en/articles/12258119-socrates-actionplans-optimize-runbooks-for-socrates-assigned-cases.md): Learn how Socrates Actionplans can be generated from runbooks to enhance AI-driven case management. - [Socrates: Investigate Outside a Case](https://kb.torq.io/en/articles/12751448-socrates-investigate-outside-a-case.md): Ask Socrates Investigator anything - investigate, review, and take action at a workspace level. - [Socrates Builder: Getting Started](https://kb.torq.io/en/articles/14894585-socrates-builder-getting-started.md): Learn how to use Socrates Builder to create, test, and publish production-grade Torq workflows through natural conversation. - [Socrates Builder: Prompting and Iteration Guide](https://kb.torq.io/en/articles/14893688-socrates-builder-prompting-and-iteration-guide.md): Learn how to write effective prompts, iterate on results, and get the most out of your Socrates Builder sessions. - [Socrates Builder: Supported Capabilities and Known Limitations](https://kb.torq.io/en/articles/14894477-socrates-builder-supported-capabilities-and-known-limitations.md): Understand what Socrates Builder can do, including supported workflow operations, workspace awareness, and security considerations. - [Leverage Torq Cases for Identity and Access Management](https://kb.torq.io/en/articles/9138463-leverage-torq-cases-for-identity-and-access-management.md): Learn how to manage suspicious activity alerts with Torq cases for quick resolution and stakeholder updates. - [Sync Torq Cases with External Tickets](https://kb.torq.io/en/articles/9138467-sync-torq-cases-with-external-tickets.md): Learn to sync Torq Cases with external ticketing systems like Jira or ServiceNow for efficient cross-team security event tracking. - [Automatically Set Up a New Workspace: Workspace Provisioning in Torq](https://kb.torq.io/en/articles/9140806-automatically-set-up-a-new-workspace-workspace-provisioning-in-torq.md): Create and activate new Torq workspaces for your organization automatically. - [Explore Torq's RBAC Architecture: An In-Depth Guide](https://kb.torq.io/en/articles/9145815-explore-torq-s-rbac-architecture-an-in-depth-guide.md): Explore Torq's RBAC architecture: workspace segmentation, user roles and scopes, and cross-workspace resource sharing. - [Workspace Timeout Settings](https://kb.torq.io/en/articles/11366219-workspace-timeout-settings.md): Configure inactivity timeout and session expiration settings for enhanced Workspace security in Torq. - [Share Resources Across Torq Workspaces: Streamline Collaboration](https://kb.torq.io/en/articles/9140161-share-resources-across-torq-workspaces-streamline-collaboration.md): Enhance collaboration by sharing resources like integrations and workflows across workspaces within your Torq organization. - [Share Workflows Across Torq Workspaces](https://kb.torq.io/en/articles/9140232-share-workflows-across-torq-workspaces.md): Learn how to share workflows across workspaces in Torq, enabling seamless collaboration while maintaining control over editing privileges. - [Share Integrations Across Torq Workspaces](https://kb.torq.io/en/articles/9140498-share-integrations-across-torq-workspaces.md): Learn how to share integrations across workspaces in Torq to enable seamless collaboration. - [Share Workspace Variables Across Torq Workspaces](https://kb.torq.io/en/articles/9140718-share-workspace-variables-across-torq-workspaces.md): Learn how to share workspace variables across workspaces in Torq to enable seamless collaboration. - [Share Step Runners Across Torq Workspaces](https://kb.torq.io/en/articles/12910610-share-step-runners-across-torq-workspaces.md): Learn how to share Step Runners across workspaces in Torq to enable seamless collaboration. ## Auto Triage - [Torq Auto Triage: Cut Alert Noise, Focus on What Matters](https://kb.torq.io/en/articles/13560462-torq-auto-triage-cut-alert-noise-focus-on-what-matters.md): Learn how Auto Triage evaluates alerts in Torq and how its decisions are configured, reviewed, and refined. - [Alert Streaming: Route Alerts to Auto Triage](https://kb.torq.io/en/articles/13563677-alert-streaming-route-alerts-to-auto-triage.md): Stream security alerts from supported sources into Auto Triage to enable AI-driven triage and configuration-based post-verdict handling. - [Configuration: Manage Alert Sources and Post-Triage Actions](https://kb.torq.io/en/articles/13461687-configuration-manage-alert-sources-and-post-triage-actions.md): Manage which alert sources Auto Triage uses and define how alerts from each source are handled after triage. - [Guidance: Add Context to Triage](https://kb.torq.io/en/articles/13246188-guidance-add-context-to-triage.md): Use Guidance to add context before triage, so Auto-Triage can interpret alerts accurately and reduce noise. - [Rules: Enforce Alert Verdicts and Severities](https://kb.torq.io/en/articles/13246861-rules-enforce-alert-verdicts-and-severities.md): Create and manage rules in Torq to enforce alert severity and verdicts after triage. - [How Torq's Auto Triage Determines Alert Severity and Verdicts](https://kb.torq.io/en/articles/13673175-how-torq-s-auto-triage-determines-alert-severity-and-verdicts.md): Learn how Auto Triage evaluates ingested alerts and determines Torq-assigned severity and verdicts based on risk, context, and historical outcomes. - [Alerts: Monitor, Review and Track Ingested Alerts](https://kb.torq.io/en/articles/13506816-alerts-monitor-review-and-track-ingested-alerts.md): Review verdicts, enriched context and actions taken by Auto Triage on ingested alerts. - [Auto Triage Dashboard: Monitor Triage Outcomes](https://kb.torq.io/en/articles/13673321-auto-triage-dashboard-monitor-triage-outcomes.md): Learn how the Auto Triage dashboard provides visibility into triage outcomes and operational performance. - [Torq AI SOC: From Alert to Resolution](https://kb.torq.io/en/articles/15420937-torq-ai-soc-from-alert-to-resolution.md): Understand how the Torq AI SOC Platform increases capacity and velocity across triage, investigation, containment, and remediation. ## Investigate Cases - [Navigating Torq's Cases Page: Stay on Top of Cases](https://kb.torq.io/en/articles/9164938-navigating-torq-s-cases-page-stay-on-top-of-cases.md): Learn how to track active and resolved cases on the Cases page efficiently. - [Inside a Case: Investigate Cases in Torq](https://kb.torq.io/en/articles/15887130-inside-a-case-investigate-cases-in-torq.md): Learn how to navigate through a case to easily review threat details, track investigations, and take actions. - [Creating Cases in Torq](https://kb.torq.io/en/articles/9140119-creating-cases-in-torq.md): Learn how to create a new case, including the necessary and optional attributes. - [Case Timelines in Torq: Track Investigation Progress](https://kb.torq.io/en/articles/9167040-case-timelines-in-torq-track-investigation-progress.md): Learn how to effectively log and retrieve information using the case timeline. - [Custom Fields in Torq Cases: Track Additional Case Details](https://kb.torq.io/en/articles/9242004-custom-fields-in-torq-cases-track-additional-case-details.md): Learn about custom fields in Torq cases, ensuring all relevant details are considered for a comprehensive review. - [Observables: Enhance Threat Detection with Torq](https://kb.torq.io/en/articles/9202637-observables-enhance-threat-detection-with-torq.md): Learn about observables in Torq and how to use and manage them efficiently. - [Notes in Torq Cases: Efficiently Store Information](https://kb.torq.io/en/articles/9140793-notes-in-torq-cases-efficiently-store-information.md): Learn how to store information within Torq cases efficiently with notes. - [Attachments in Torq Cases: Add Context and Information](https://kb.torq.io/en/articles/9140124-attachments-in-torq-cases-add-context-and-information.md): Learn how to use attachments in Torq cases to enrich context and add information through screenshots, documents, and other files. - [Link Related Cases in Torq: See the Bigger Picture](https://kb.torq.io/en/articles/9140531-link-related-cases-in-torq-see-the-bigger-picture.md): Learn how to link related cases, enabling better identification and tracking of interconnected incidents. - [Runbooks in Torq Cases: Streamline Investigations with Instructions](https://kb.torq.io/en/articles/9140537-runbooks-in-torq-cases-streamline-investigations-with-instructions.md): Learn how to follow runbook instructions in Torq to ensure efficient and standardized investigations. - [Trigger Workflows from Torq Cases: Take Action During Investigations](https://kb.torq.io/en/articles/9140128-trigger-workflows-from-torq-cases-take-action-during-investigations.md): Learn how to use workflows during your case management investigations by triggering them directly from a case. - [Case SLAs in Torq: Track Deadlines](https://kb.torq.io/en/articles/9140665-case-slas-in-torq-track-deadlines.md): Learn about SLA tracking with Torq to ensure timely case resolution. - [Torq's All Workspaces View: Manage Cases Across Multiple Workspaces](https://kb.torq.io/en/articles/9109999-torq-s-all-workspaces-view-manage-cases-across-multiple-workspaces.md): Learn how to handle cases across multiple workspaces without needing constant workspace switching. - [Case Reviewer: Ensure Investigation Quality in Torq's HyperSOC](https://kb.torq.io/en/articles/10428912-case-reviewer-ensure-investigation-quality-in-torq-s-hypersoc.md): Ensure quality and compliance by assigning reviewers to approve or reject case investigations before taking further action. - [Auto-Generate Resolution Details with Socrates AI](https://kb.torq.io/en/articles/10943505-auto-generate-resolution-details-with-socrates-ai.md): Use Socrates to auto-generate case resolution details based on relevant case data. - [Restrict Cases Access: Ensure Information Confidentiality](https://kb.torq.io/en/articles/10748982-restrict-cases-access-ensure-information-confidentiality.md): Ensure information privacy by controlling who has access to specific cases. - [Embedded Details in Case Descriptions](https://kb.torq.io/en/articles/13177251-embedded-details-in-case-descriptions.md): Learn how to embed details directly in case descriptions to spotlight critical case details. - [Custom Case Tabs](https://kb.torq.io/en/articles/13342635-custom-case-tabs.md): Learn how to create and manage custom tabs for cases. ## Gain Insights - [Insights Dashboard: Track Time Saved with Torq](https://kb.torq.io/en/articles/9113853-insights-dashboard-track-time-saved-with-torq.md): Explore Torq's Insights dashboard to track time saved with automation and monitor key workflow statistics. - [Activity Log: Monitor Workflow Executions in Torq](https://kb.torq.io/en/articles/9174359-activity-log-monitor-workflow-executions-in-torq.md): Track workflow executions in the Activity Log, along with single-step executions and events that didn’t trigger workflows. - [Audit Logs: Streamline Auditing with Torq](https://kb.torq.io/en/articles/9174571-audit-logs-streamline-auditing-with-torq.md): Collect and analyze Torq audit logs for enhanced security and compliance. - [Export Torq Activity and Audit Logs to Amazon S3 Automatically](https://kb.torq.io/en/articles/10381189-export-torq-activity-and-audit-logs-to-amazon-s3-automatically.md): Set up automatic audit and activity log exports to Amazon S3, ensuring availability for external tools. - [Cases Dashboards: Drive Data-Backed Decisions](https://kb.torq.io/en/articles/10113343-cases-dashboards-drive-data-backed-decisions.md): Explore how Cases Dashboards deliver customizable data analysis, real-time insights, and personalized data views. - [Targeted Monitoring with Torq: Create Custom Dashboards and Widgets](https://kb.torq.io/en/articles/9997135-targeted-monitoring-with-torq-create-custom-dashboards-and-widgets.md): Create custom dashboards and widgets to efficiently track, analyze, and visualize your data in Torq. - [Cases Dashboards: Monitor HyperSOC Metrics](https://kb.torq.io/en/articles/10342755-cases-dashboards-monitor-hypersoc-metrics.md): Gain actionable insights with Cases Dashboards to enhance task prioritization and optimize SOC operations. - [Cases Dashboards Template: SOC Posture](https://kb.torq.io/en/articles/10146109-cases-dashboards-template-soc-posture.md): Explore the SOC Posture dashboard template. ## Templates - [Accelerate Security Automation with Torq Templates](https://kb.torq.io/en/articles/9297096-accelerate-security-automation-with-torq-templates.md): Discover Torq templates—ready-to-use workflows designed to streamline and enhance your cybersecurity automation efforts. - [Workflow Template: Collect Azure VM and Network Details](https://kb.torq.io/en/articles/9349979-workflow-template-collect-azure-vm-and-network-details.md): Nested workflow used to collect Azure VM and Network info needed in support of remediation workflows. - [Workflow Template: Create a QuickAction for a Case](https://kb.torq.io/en/articles/13050612-workflow-template-create-a-quickaction-for-a-case.md): This workflow creates a QuickAction for a user-supplied case by querying the available workflows in the workspace using keyword search. - [Workflow Template: Convert complex JSON Array Data to CSV](https://kb.torq.io/en/articles/13222876-workflow-template-convert-complex-json-array-data-to-csv.md): Transform complex, nested JSON data into streamlined, flat CSV data. - [Workflow Template: Convert HCL to JSON](https://kb.torq.io/en/articles/13222877-workflow-template-convert-hcl-to-json.md): Convert HashiCorp Configuration Language to JSON using python-hcl2 library - [Workflow Template: Manage containment on a device in CrowdStrike with Socrates](https://kb.torq.io/en/articles/13303232-workflow-template-manage-containment-on-a-device-in-crowdstrike-with-socrates.md): This workflow serves as a Socrates wrapper for the 'Manage containment on a device in CrowdStrike' workflow - [Workflow Template: QuickAction - Get Device Details using CrowdStrike](https://kb.torq.io/en/articles/13303233-workflow-template-quickaction-get-device-details-using-crowdstrike.md): This workflow will take in host device name and return a case note with all the relevant CrowdStrike information including the device ID - [Workflow Template: QuickAction - Manage containment on a device in CrowdStrike](https://kb.torq.io/en/articles/13303240-workflow-template-quickaction-manage-containment-on-a-device-in-crowdstrike.md): This workflow serves as a wrapper for the 'Manage containment on a device in CrowdStrike' workflow - [Workflow Template: QuickAction - Scan Device in CrowdStrike](https://kb.torq.io/en/articles/13333238-workflow-template-quickaction-scan-device-in-crowdstrike.md): Initiate a scan on a CrowdStrike device using a QuickAction button. This serves as a wrapper for the 'Scan Device in CrowdStrike' workflow - [Workflow Template: Scan Device in CrowdStrike with Socrates](https://kb.torq.io/en/articles/13333241-workflow-template-scan-device-in-crowdstrike-with-socrates.md): Initiate a scan on a device in CrowdStrike using Socrates. This workflow serves as a wrapper for the 'Scan Device in CrowdStrike' workflow - [Workflow Template: Delete Torq Cases in Bulk](https://kb.torq.io/en/articles/13722637-workflow-template-delete-torq-cases-in-bulk.md): Delete multiple Torq cases with an interactive confirmation workflow. - [Workflow Template: Export Observables as CSV](https://kb.torq.io/en/articles/13733023-workflow-template-export-observables-as-csv.md): Gather and export your selected observable type in CSV format. - [Workflow Template: Disable Public Sharing for Files in Google Drive with Reco.ai](https://kb.torq.io/en/articles/13758665-workflow-template-disable-public-sharing-for-files-in-google-drive-with-reco-ai.md): Limit business critical exposure by removing public access to Google Drive files discovered by Reco to be containing sensitive information. - [Workflow Template: AI task/HyperAgent Resource Check](https://kb.torq.io/en/articles/13842460-workflow-template-ai-task-hyperagent-resource-check.md): Provides an inventory for AI task and HyperAgent step usage in a given workspace. Results are presented as an interactive table. - [Workflow Template: File Prevalence Check on MS Defender for Endpoint](https://kb.torq.io/en/articles/14274212-workflow-template-file-prevalence-check-on-ms-defender-for-endpoint.md): Checks whether a file \(by SHA1 hash\) is widely distributed across the org before allowing automated remediation. - [Workflow Template: QuickAction - Remediation Menu for MS Defender for Endpoint](https://kb.torq.io/en/articles/14397145-workflow-template-quickaction-remediation-menu-for-ms-defender-for-endpoint.md): Enables a Case Analyst to perform Scan, Isolation and Release from Isolation actions from a single menu triggered by an Interact menu. - [Workflow Template: Automated Employee Offboarding](https://kb.torq.io/en/articles/14801963-workflow-template-automated-employee-offboarding.md): Automatically disable all SailPoint-managed accounts when an identity is terminated, with ServiceNow ticketing and Slack notification. - [Workflow Template: Create an Orion Case using a Field Mapper](https://kb.torq.io/en/articles/14816515-workflow-template-create-an-orion-case-using-a-field-mapper.md): Automatically create a fully formatted Torq case from an Orion Security alert with mapped fields, observables, and markdown tables. - [Workflow Template: XML to JSON - Practice Your Skills](https://kb.torq.io/en/articles/15357944-workflow-template-xml-to-json-practice-your-skills.md): Practice your automation skills by transforming XML data and performing calculations over it. - [Workflow Template: Enrich File Hash with VirusTotal via Observable Enrichment Data](https://kb.torq.io/en/articles/15429291-workflow-template-enrich-file-hash-with-virustotal-via-observable-enrichment-data.md): Enrich Hash with VirusTotal using observables enrichment data as a cache - [Workflow Template: Poll Microsoft Outlook on a Schedule for New Messages](https://kb.torq.io/en/articles/15515478-workflow-template-poll-microsoft-outlook-on-a-schedule-for-new-messages.md): Poll new messages from outlook, return parsed content as a JSON document and attachments as tqfiles. - [Workflow Template: Synchronize Torq Case Runbooks from a GitHub Repository](https://kb.torq.io/en/articles/10263117-workflow-template-synchronize-torq-case-runbooks-from-a-github-repository.md): Create or update Torq runbooks based on a GitHub repository when a commit has been made in the repository holding the runbooks. - [Workflow Template: Create Torq Cases from Proofpoint Clicks Permitted](https://kb.torq.io/en/articles/10263119-workflow-template-create-torq-cases-from-proofpoint-clicks-permitted.md): On a schedule check for clicks permitted in Proofpoint and enrich the URLs in VirusTotal and open a Torq Case for each finding. - [Workflow Template: Torq Automation Analyst - Fix this Workflow](https://kb.torq.io/en/articles/10263128-workflow-template-torq-automation-analyst-fix-this-workflow.md): This workflow is used as part of the Torq Automation Analyst Course to learn about troubleshooting and fixing errors in a workflow. - [Workflow Template: Torq Automation Expert - Pagination](https://kb.torq.io/en/articles/10263132-workflow-template-torq-automation-expert-pagination.md): This workflow is used as part of the Torq Automation Expert Course to test your skills at using pagination to gather data in a workflow. - [Workflow Template: Torq Automation Analyst - Generate Token and HTTP GET Data](https://kb.torq.io/en/articles/10263135-workflow-template-torq-automation-analyst-generate-token-and-http-get-data.md): This workflow is used as part of the Torq Automation Analyst Course to learn about using basic HTTP steps in a workflow. - [Workflow Template: Torq Automation Analyst - XML to JSON](https://kb.torq.io/en/articles/10263138-workflow-template-torq-automation-analyst-xml-to-json.md): This workflow is used as part of the Torq Automation Analyst Course to learn how to transform, select and filter data in Torq workflows. - [Workflow Template: Torq Automation Expert - Fix This Workflow](https://kb.torq.io/en/articles/10263139-workflow-template-torq-automation-expert-fix-this-workflow.md): This workflow is used as part of the Torq Automation Expert Course that checks your skills at addressing and fixing errors in a workflow. - [Workflow Template: Crowdstrike Falcon Sandbox - File Analysis with Cache](https://kb.torq.io/en/articles/10263143-workflow-template-crowdstrike-falcon-sandbox-file-analysis-with-cache.md): Submit a file to Falcon Sandbox for malware analysis. - [Workflow Template: Start Configuration Backup in Veeam Backup & Replication](https://kb.torq.io/en/articles/10697060-workflow-template-start-configuration-backup-in-veeam-backup-replication.md): Initiates a configuration backup of system settings, job configurations, and other essential data in Veeam Backup & Replication. - [Workflow Template: Change Sweet Security incident statuses via Slack Integration](https://kb.torq.io/en/articles/10697061-workflow-template-change-sweet-security-incident-statuses-via-slack-integration.md): Notify SOC and users of Sweet Security alerts, enriching incidents with responses. - [Workflow Template: Silverfort Risk and Incidents to Torq Observables and Cases](https://kb.torq.io/en/articles/10697066-workflow-template-silverfort-risk-and-incidents-to-torq-observables-and-cases.md): This workflow will receive a webhook from Silverfort and create or update Torq cases based on Silverfort Incident and risk changes. - [Workflow Template: Get Triggered Alarms from Veeam ONE](https://kb.torq.io/en/articles/10697071-workflow-template-get-triggered-alarms-from-veeam-one.md): This workflow lists multiple security-related Veeam ONE alarms in Warning or Error status - [Workflow Template: VirusTotal IOC Lookup with Summary of Results from AI Task](https://kb.torq.io/en/articles/11058525-workflow-template-virustotal-ioc-lookup-with-summary-of-results-from-ai-task.md): Used as a nested workflow, receive an IP address, domain or file hash and query VirusTotal and analyze details with AI Task for a summary. - [Workflow Template: What do we have? Environment Audit Report](https://kb.torq.io/en/articles/11671901-workflow-template-what-do-we-have-environment-audit-report.md): Gathers an account's resources list, including triggers, workflows, integration API keys, and secrets, to generate HTML and PDF reports. - [Workflow Template: QuickAction - Isolate or Release a Device on MS Defender Endpoint](https://kb.torq.io/en/articles/11684938-workflow-template-quickaction-isolate-or-release-a-device-on-ms-defender-endpoint.md): Isolate or release a remote device from isolation when a quick action button is pressed. - [Workflow Template: QuickAction - Scan Device on MS Defender for Endpoint](https://kb.torq.io/en/articles/11684941-workflow-template-quickaction-scan-device-on-ms-defender-for-endpoint.md): Start a full malware scan on a remote device when a quick action button is pressed. - [Workflow Template: Extract Multiple Observables with AI Task](https://kb.torq.io/en/articles/11702698-workflow-template-extract-multiple-observables-with-ai-task.md): Use AI Task operator to extract multiple types of observables from a raw text. - [Workflow Template: Where Used? Resource Usage Report](https://kb.torq.io/en/articles/11767202-workflow-template-where-used-resource-usage-report.md): Provides 'where used' functionality in Torq, enabling users to query integrations, runners, secrets, steps, or workspace variables. - [Workflow Template: Attach a password protected archive to a Torq Case](https://kb.torq.io/en/articles/11828671-workflow-template-attach-a-password-protected-archive-to-a-torq-case.md): Attach a suspicious or malicious file to a case within a password-protected archive for secure handling and analysis. - [Workflow Template: Poll for new Veeam ONE Alarm and Open a Torq Case](https://kb.torq.io/en/articles/11828672-workflow-template-poll-for-new-veeam-one-alarm-and-open-a-torq-case.md): Creates a case in Torq when security-related alarms in Veeam ONE are triggered in a Warning or Error state. - [Workflow Template: Poll for new Veeam Backup & Replication Events and Open a Case](https://kb.torq.io/en/articles/11847347-workflow-template-poll-for-new-veeam-backup-replication-events-and-open-a-case.md): Creates a case in Torq for malware events detected by Veeam Backup & Replication. - [Workflow Template: Rerun Failed Workflow Executions On Demand](https://kb.torq.io/en/articles/11847351-workflow-template-rerun-failed-workflow-executions-on-demand.md): Search the Activity Log for the failed workflow executions and their triggering events and reruns all the failed workflow executions - [Workflow Template: QuickAction - Create a PDF Report for a Torq Case](https://kb.torq.io/en/articles/12062084-workflow-template-quickaction-create-a-pdf-report-for-a-torq-case.md): Creates a PDF Summary Report of a Torq Case as a response to a QuickAction button. - [Workflow Template: QuickAction - Upload a File from a URL to a Case](https://kb.torq.io/en/articles/12146480-workflow-template-quickaction-upload-a-file-from-a-url-to-a-case.md): Uploads a password protected archive from a URL as a response to a QuickAction button. - [Workflow Template: Notify on Runner's Health Status Change via Slack](https://kb.torq.io/en/articles/12274888-workflow-template-notify-on-runner-s-health-status-change-via-slack.md): Get a Slack notification every time a Step Runner's health status changes. - [Workflow Template: Notify on Runner's Health Status Change via Teams](https://kb.torq.io/en/articles/12274892-workflow-template-notify-on-runner-s-health-status-change-via-teams.md): Get a Teams notification every time a Step Runner's health status changes. - [Workflow Template: Simple SumoLogic Query with Optional Return Field Filters](https://kb.torq.io/en/articles/12338562-workflow-template-simple-sumologic-query-with-optional-return-field-filters.md): Filter your search for specific messages or records in Sumo Logic and return only the relevant fields. - [Workflow Template: Send a Slack message when a workspace table variable is deleted](https://kb.torq.io/en/articles/12537809-workflow-template-send-a-slack-message-when-a-workspace-table-variable-is-deleted.md): Send a Slack message to subscribers when a workspace table variable is deleted. - [Workflow Template: Send a Teams message when a workspace table variable is deleted](https://kb.torq.io/en/articles/12537813-workflow-template-send-a-teams-message-when-a-workspace-table-variable-is-deleted.md): Send a Microsoft Teams message to subscribers when a workspace table variable is deleted. - [Workflow Template: Reduce large Slack message to multiple 3000 character messages](https://kb.torq.io/en/articles/12584527-workflow-template-reduce-large-slack-message-to-multiple-3000-character-messages.md): This workflow takes in a large message and breaks it into multiple "chunks" compatible with the 3000 character limit in the Slack API. - [Workflow Template: Synchronize Torq Case Tags to Microsoft Sentinel Incidents](https://kb.torq.io/en/articles/12584530-workflow-template-synchronize-torq-case-tags-to-microsoft-sentinel-incidents.md): Synchronize Torq Case Tags to a Sentinel Incident driven by a "Tags Updated" Trigger. - [Workflow Template: Synchronize Torq Case Comment to ServiceNow Note](https://kb.torq.io/en/articles/12584532-workflow-template-synchronize-torq-case-comment-to-servicenow-note.md): Synchronize Torq Case Comment to ServiceNow Note driven by a "Comment added" Trigger. - [Workflow Template: Synchronize Torq Case Severity to Microsoft Sentinel Incidents](https://kb.torq.io/en/articles/12584535-workflow-template-synchronize-torq-case-severity-to-microsoft-sentinel-incidents.md): Synchronize Torq Case Severity to a Sentinel Incident driven by a "Severity changed" Trigger. - [Workflow Template: Synchronize Torq Case Assignee to Microsoft Sentinel Incidents](https://kb.torq.io/en/articles/12584536-workflow-template-synchronize-torq-case-assignee-to-microsoft-sentinel-incidents.md): Synchronize Torq Case Assignee to a Sentinel Incident driven by a "Assigned to teammate" Trigger. - [Workflow Template: Synchronize Torq Case State Change to ServiceNow](https://kb.torq.io/en/articles/12584538-workflow-template-synchronize-torq-case-state-change-to-servicenow.md): Synchronize Torq Case Change of State to ServiceNow driven by a "State changed" Trigger. - [Workflow Template: Synchronize Torq Case Attachment to ServiceNow](https://kb.torq.io/en/articles/12584542-workflow-template-synchronize-torq-case-attachment-to-servicenow.md): Synchronize Torq Case attachment to ServiceNow driven by a "Attachment added" Trigger. - [Workflow Template: Synchronize Torq Case State Change to Microsoft Sentinel Incident](https://kb.torq.io/en/articles/12584545-workflow-template-synchronize-torq-case-state-change-to-microsoft-sentinel-incident.md): Synchronize Torq Case Change of State to a Sentinel Incident driven by a "State changed" Trigger. - [Workflow Template: Synchronize Torq Case Assignee to ServiceNow](https://kb.torq.io/en/articles/12584546-workflow-template-synchronize-torq-case-assignee-to-servicenow.md): Synchronize Torq Case Assignee to ServiceNow driven by a "Assigned to teammate" Trigger. - [Workflow Template: Synchronize Torq Case Severity to ServiceNow Urgency and Impact](https://kb.torq.io/en/articles/12584547-workflow-template-synchronize-torq-case-severity-to-servicenow-urgency-and-impact.md): Synchronize Torq Case Severity to ServiceNow driven by a "Severity changed" Trigger. - [Workflow Template: Synchronize Torq Case Severity to Jira](https://kb.torq.io/en/articles/12593644-workflow-template-synchronize-torq-case-severity-to-jira.md): Synchronize Torq Case Severity to Jira driven by a "Severity changed" Trigger. - [Workflow Template: Synchronize Torq Case State Change to Jira](https://kb.torq.io/en/articles/12593645-workflow-template-synchronize-torq-case-state-change-to-jira.md): Synchronize Torq Case Change of State to a Jira ticket driven by a "State changed" Trigger. - [Workflow Template: Synchronize Torq Case Comment to Microsoft Sentinel Incidents](https://kb.torq.io/en/articles/12593647-workflow-template-synchronize-torq-case-comment-to-microsoft-sentinel-incidents.md): Synchronize Torq Case Comment to a Sentinel Incident driven by a "Comment added" Trigger. - [Workflow Template: Synchronize Torq Case Assignee to Jira](https://kb.torq.io/en/articles/12593649-workflow-template-synchronize-torq-case-assignee-to-jira.md): Synchronize Torq Case Assignee to Jira driven by a "Assigned to teammate" Trigger. - [Workflow Template: Synchronize Torq Case Attachment to Jira](https://kb.torq.io/en/articles/12593650-workflow-template-synchronize-torq-case-attachment-to-jira.md): Synchronize Torq Case attachment to Jira driven by a "Attachment added" Trigger. - [Workflow Template: Synchronize Torq Case Comment to Jira](https://kb.torq.io/en/articles/12593652-workflow-template-synchronize-torq-case-comment-to-jira.md): Synchronize Torq Case Comment to Jira driven by a "Comment added" Trigger. - [Workflow Template: QuickAction - Scan Device on SentinelOne](https://kb.torq.io/en/articles/12847087-workflow-template-quickaction-scan-device-on-sentinelone.md): Quickly start a Full Disk Scan a Device with SentinelOne Agent using a single QuickAction button. - [Workflow Template: Alert on Google Login Activity Outside of Allowed Regions](https://kb.torq.io/en/articles/9349980-workflow-template-alert-on-google-login-activity-outside-of-allowed-regions.md): Retrieve Google Login Activity for logins and compare against specific allowed regions. If a violation occurs notify a Slack channel. - [Workflow Template: Silent Push - IP Address Enrichment with Cache](https://kb.torq.io/en/articles/9349983-workflow-template-silent-push-ip-address-enrichment-with-cache.md): Receives an IP Address from a parent workflow and query Silent Push for enrichment. - [Workflow Template: VirusTotal IOC Lookup with Summary of Results from OpenAI](https://kb.torq.io/en/articles/9349984-workflow-template-virustotal-ioc-lookup-with-summary-of-results-from-openai.md): Used as a nested workflow, receive an IP address, domain or file hash and query VirusTotal and send the details to OpenAI for a summary. - [Workflow Template: Query Okta System Logs by Actor Activity](https://kb.torq.io/en/articles/9349986-workflow-template-query-okta-system-logs-by-actor-activity.md): Query the Okta System Logs by specific Actor and provide results and an optional summary of EventType and outcome result for the logs. - [Workflow Template: Shodan - Domain Enrichment with Cache](https://kb.torq.io/en/articles/9349988-workflow-template-shodan-domain-enrichment-with-cache.md): Receives a Domain from a parent workflow and query Shodan for enrichment. - [Workflow Template: Enrich New Cybereason MalOps File Hash Detail](https://kb.torq.io/en/articles/9349989-workflow-template-enrich-new-cybereason-malops-file-hash-detail.md): For each new MalOp that is detected, attempt to enrich the file hash intelligence from VirusTotal and Recorded Future in the MalOp Comments - [Workflow Template: Interactive Email Conversation using Google Workspace](https://kb.torq.io/en/articles/9349990-workflow-template-interactive-email-conversation-using-google-workspace.md): Example of using Google Workspace email as part of an interactive email conversation. This could also be added as a nested workflow. - [Workflow Template: Collect Torq Global Variables with Pagination](https://kb.torq.io/en/articles/9349991-workflow-template-collect-torq-global-variables-with-pagination.md): Workflow that uses pagination to gather all Torq global variables and provide them into a single array. - [Workflow Template: Verify Permissions to Execute Workflows \(Google Cloud Identity\)](https://kb.torq.io/en/articles/9349992-workflow-template-verify-permissions-to-execute-workflows-google-cloud-identity.md): Workflow that can be used to verify users have permissions to run a specific workflow by Id or name also check group membership. - [Workflow Template: Process New NIST NVD Vulnerabilities](https://kb.torq.io/en/articles/9349993-workflow-template-process-new-nist-nvd-vulnerabilities.md): Pull latest CVEs from the NIST NVD Database and update a Slack channel. Additional steps can be added to search for CVEs in other platforms - [Workflow Template: Slack Slash Command - Hello World](https://kb.torq.io/en/articles/9349994-workflow-template-slack-slash-command-hello-world.md): Example of an interactive experience with Slack Slash Commands and replying back to the channel with information from the event. - [Workflow Template: Add Malicious IPs to Network Block Zone from Okta System Logs](https://kb.torq.io/en/articles/9349996-workflow-template-add-malicious-ips-to-network-block-zone-from-okta-system-logs.md): On a schedule pull Okta system logs for specific event types, extract any IPv4 address and if found malicious update the block zone in Okta. - [Workflow Template: Collect Torq Audit or Activity Logs](https://kb.torq.io/en/articles/9349997-workflow-template-collect-torq-audit-or-activity-logs.md): Nested workflow that collects Torq workflow Activity logs or user Audit logs and returns the logs to the parent workflow. - [Workflow Template: Handle Nessus Scan Results \(Nessus\)](https://kb.torq.io/en/articles/9349999-workflow-template-handle-nessus-scan-results-nessus.md): Daily notification of specific pre-defined Nessus scans. Send results to Slack channel as defined. - [Workflow Template: Gather CircleCI Environment Variables from Bitbucket Repos](https://kb.torq.io/en/articles/9350000-workflow-template-gather-circleci-environment-variables-from-bitbucket-repos.md): Query Bitbucket for workspace repositories and gather CircleCI Environment Variables that are configured in the project. - [Workflow Template: Verify Permissions to Execute Specific Workflows \(Okta\)](https://kb.torq.io/en/articles/9350001-workflow-template-verify-permissions-to-execute-specific-workflows-okta.md): Workflow that can be used to verify users have permissions to run a specific workflow by Id or name also check group membership in Okta. - [Workflow Template: Send an email with VirusTotal Stats](https://kb.torq.io/en/articles/9350002-workflow-template-send-an-email-with-virustotal-stats.md): Send a simple email including VirusTotal engine stats in a HTML table format for a particular HASH lookup. - [Workflow Template: Assign New Alerts from Hunters.ai](https://kb.torq.io/en/articles/9350004-workflow-template-assign-new-alerts-from-hunters-ai.md): Retrieve alerts from Hunters XDR, suggest to assign using Slack. - [Workflow Template: Jira Issue Reminder and Escalation via Slack or Teams](https://kb.torq.io/en/articles/9350005-workflow-template-jira-issue-reminder-and-escalation-via-slack-or-teams.md): Send reminder and escalation messages via Slack or Microsoft Teams on a Jira issue status on a specific polling interval. - [Workflow Template: Append data to an Array \(Torq\)](https://kb.torq.io/en/articles/9350006-workflow-template-append-data-to-an-array-torq.md): Append JSON data to an array using the Append to Array step. Example JSON data is provided to append to a new array. - [Workflow Template: Open a PagerDuty Incident on Host Detection \(CrowdStrike\)](https://kb.torq.io/en/articles/9350007-workflow-template-open-a-pagerduty-incident-on-host-detection-crowdstrike.md): Receive an event from CrowdStrike, if event is critical or high, open an incident with PagerDuty and enrich the IOC details with VirusTotal - [Workflow Template: Upload a File in Teams to a SharePoint Folder](https://kb.torq.io/en/articles/9350009-workflow-template-upload-a-file-in-teams-to-a-sharepoint-folder.md): Create either a CSV, JSON or PDF file in Microsoft Teams and post an adaptive card with a link to the file in the Teams Channel - [Workflow Template: Compliance - Generate report on non-compliant devices \(Intune\)](https://kb.torq.io/en/articles/9350010-workflow-template-compliance-generate-report-on-non-compliant-devices-intune.md): Pull non-compliant devices list from Microsoft Intune and go over them. Retrieve an associated user from each device, and create a list. - [Workflow Template: Merge JSON data using JQ based on a common Key/Value](https://kb.torq.io/en/articles/9350011-workflow-template-merge-json-data-using-jq-based-on-a-common-key-value.md): Simple example using JQ to merge two JSON files using JQ using the key Email\_Address as the match between the two datasets. - [Workflow Template: Check Point R81 Management Workflow](https://kb.torq.io/en/articles/9350012-workflow-template-check-point-r81-management-workflow.md): An example workflow that outlines the needed steps to make changes to the Check Point Management Server and install policy against a gateway - [Workflow Template: Slack Mention to Analyze Suspicious URLs and IPs with VirusTotal](https://kb.torq.io/en/articles/9350014-workflow-template-slack-mention-to-analyze-suspicious-urls-and-ips-with-virustotal.md): Receive a suspicious list of URLs and/or IPs from Slack, scan using VirusTotal, and report back to the Slack thread the results. - [Workflow Template: Create a Torq Case from a QRadar Offense](https://kb.torq.io/en/articles/9350015-workflow-template-create-a-torq-case-from-a-qradar-offense.md): Used as a nested workflow to open a Torq case from details in a QRadar Offense and optionally include QRadar events into the case details. - [Workflow Template: Retrieve Daily Unencrypted Bucket Summary \(AWS Macie\)](https://kb.torq.io/en/articles/9350017-workflow-template-retrieve-daily-unencrypted-bucket-summary-aws-macie.md): On a daily schedule retrieve data from Amazon Macie on specific criteria and deliver to a Slack user or Channel. - [Workflow Template: Remove Public Links from Google Drive Detected by BigID](https://kb.torq.io/en/articles/9350018-workflow-template-remove-public-links-from-google-drive-detected-by-bigid.md): On an alert from BigID where files with sensitive information are found publicly shared, loop over each finding and remove the public share. - [Workflow Template: Jira Issue Creation, Update, and Assignment](https://kb.torq.io/en/articles/9350020-workflow-template-jira-issue-creation-update-and-assignment.md): Example workflow using the most common steps in the lifecycle of a Jira issue including issue assignment and example JQL query. - [Workflow Template: Scan URLs with VirusTotal and Provide Summary Verdict](https://kb.torq.io/en/articles/9350021-workflow-template-scan-urls-with-virustotal-and-provide-summary-verdict.md): Receive an array of URLs to scan with VirusTotal and provide a summary per URL of any malicious or suspicious count more than 1. - [Workflow Template: Recorded Future - Domain Enrichment with Cache](https://kb.torq.io/en/articles/9350023-workflow-template-recorded-future-domain-enrichment-with-cache.md): Receive a domain from a parent workflow and query Recorded Future for its reputation. - [Workflow Template: Clear Okta sessions for specific users via Slack](https://kb.torq.io/en/articles/9350024-workflow-template-clear-okta-sessions-for-specific-users-via-slack.md): Receive a Slack command to clear all sessions for one or more users. - [Workflow Template: Enable GCP Bucket Versioning on a Wiz Alert](https://kb.torq.io/en/articles/9350026-workflow-template-enable-gcp-bucket-versioning-on-a-wiz-alert.md): Receive an issue from Wiz on a GCP storage bucket with versioning disabled, lookup the channel, ask the channel to enable versioning. - [Workflow Template: Google Workspace Calendar Offboarding](https://kb.torq.io/en/articles/9350027-workflow-template-google-workspace-calendar-offboarding.md): Receive message from Slack with an email address, find meetings where user is the originator/creator of the meetings and delete if approved. - [Workflow Template: Analyze Files and URLs \(Recorded Future Sandbox\)](https://kb.torq.io/en/articles/9350028-workflow-template-analyze-files-and-urls-recorded-future-sandbox.md): Analyze Files and URLs and in Recoded Future Sandbox using nested functions with cache. - [Workflow Template: AlienVault URL Enrichment with Cache](https://kb.torq.io/en/articles/9350030-workflow-template-alienvault-url-enrichment-with-cache.md): Nested workflow that will take a URL as input and query AlienVault's General and URL List for details and return analysis information. - [Workflow Template: Daily Report to Slack on Inactive Okta Users](https://kb.torq.io/en/articles/9350031-workflow-template-daily-report-to-slack-on-inactive-okta-users.md): Poll the list of Okta users and list all users that have not logged in for the past 30 days and report the list to a Slack channel - [Workflow Template: Search for CVE in Wiz and Snyk via Slack Mention](https://kb.torq.io/en/articles/9350032-workflow-template-search-for-cve-in-wiz-and-snyk-via-slack-mention.md): When triggered via Slack, search in Wiz and Snyk for a specific CVE. Send findings to the Slack channel via a snippet. - [Workflow Template: Gather CircleCI Global Environment Variables with Creation Date](https://kb.torq.io/en/articles/9350034-workflow-template-gather-circleci-global-environment-variables-with-creation-date.md): Gather Global Environment Variables from CircleCI and provide results organized by context and included creation date and context id. - [Workflow Template: Upload New Threat Intelligence IOCs to Cybereason](https://kb.torq.io/en/articles/9350035-workflow-template-upload-new-threat-intelligence-iocs-to-cybereason.md): Receives arrays of Domains, Hashes and IP Addresses IOC's and upload them to Cybereason. - [Workflow Template: Add/Remove Entra ID User from Global Address List \(ex-Azure AD\)](https://kb.torq.io/en/articles/9350037-workflow-template-add-remove-entra-id-user-from-global-address-list-ex-azure-ad.md): Receives user name / email from a Slack command and adds/removes the specified user from the Global Address List in Entra ID - [Workflow Template: Compliance - Find unmanaged devices in Intune and Carbon Black](https://kb.torq.io/en/articles/9350038-workflow-template-compliance-find-unmanaged-devices-in-intune-and-carbon-black.md): Compare lists of managed devices in Microsoft Intune and Carbon Black. List gaps \(i.e., devices present only in one of the solutions\) - [Workflow Template: Send Slack Block Message and Perform Operations in Parallel](https://kb.torq.io/en/articles/9350039-workflow-template-send-slack-block-message-and-perform-operations-in-parallel.md): Example workflow to send a Slack Block kit message and run another operation in parallel and wait for a Users response back to the message. - [Workflow Template: Send Torq Audit or Activity Logs to Azure Blob Storage](https://kb.torq.io/en/articles/9350040-workflow-template-send-torq-audit-or-activity-logs-to-azure-blob-storage.md): On a schedule configured in Workflow Context, Torq workflow Audit Logs will be collected in a Nested Workflow and sent to an Azure Blob - [Workflow Template: IP Penalty Box with Timeout via Slack \(Cloudflare\)](https://kb.torq.io/en/articles/9350041-workflow-template-ip-penalty-box-with-timeout-via-slack-cloudflare.md): Adds specific IPv4 or IPv6 address to a penalty box in Cloudflare by creating and removing IP Access Rules driven by Slack. - [Workflow Template: Create IOCs on Malicious Files from a CrowdStrike Incident](https://kb.torq.io/en/articles/9350043-workflow-template-create-iocs-on-malicious-files-from-a-crowdstrike-incident.md): For each new EDR incident, validate the files involved with threat intelligence, and add to the global block list if found to be malicious - [Workflow Template: Find all Okta Active Users with Pagination](https://kb.torq.io/en/articles/9350045-workflow-template-find-all-okta-active-users-with-pagination.md): Pagination example with Okta to find all active users and place the results into a single array of users. - [Workflow Template: Retrieve Daily Scan Summary and Notify on Findings \(Aqua\)](https://kb.torq.io/en/articles/9350046-workflow-template-retrieve-daily-scan-summary-and-notify-on-findings-aqua.md): Pull Scan Summary information on findings in Aqua and deliver a short report to a Slack channel on the Findings on Warnings and Failures. - [Workflow Template: Check for New Carbon Black Alerts and Notify](https://kb.torq.io/en/articles/9350047-workflow-template-check-for-new-carbon-black-alerts-and-notify.md): This workflow periodically checks for new Carbon Black alerts and notifies end user of the alert and asks for verification of the activity - [Workflow Template: Basic Global Variable Use in a Workflow](https://kb.torq.io/en/articles/9350048-workflow-template-basic-global-variable-use-in-a-workflow.md): Basic Create/Read/Update/Append/Delete steps for use with Global Variables. This can provide ephemeral data storage between workflows. - [Workflow Template: Create Attachment in Jira with JSON Data](https://kb.torq.io/en/articles/9350051-workflow-template-create-attachment-in-jira-with-json-data.md): Example of how to add an attachment with JSON data to a Jira issue. - [Workflow Template: Retrieve New Exploited Vulnerabilities from CISA update via Teams](https://kb.torq.io/en/articles/9350053-workflow-template-retrieve-new-exploited-vulnerabilities-from-cisa-update-via-teams.md): On a daily schedule poll the latest CISA vulnerabilities and update a Teams channel on any new CVEs and include references from NIST - [Workflow Template: Ask a Question over Slack or Microsoft Teams](https://kb.torq.io/en/articles/9350054-workflow-template-ask-a-question-over-slack-or-microsoft-teams.md): This workflow can be used where both Slack and Microsoft Teams are used by different parts of their organizations to ask a question. - [Workflow Template: Count Number of Executions for Action \(Torq\)](https://kb.torq.io/en/articles/9350055-workflow-template-count-number-of-executions-for-action-torq.md): Workflow to be used as a nested workflow that will keep track of the number of executions of a given action and maximum executions per day. - [Workflow Template: JSON Filtering with JQ](https://kb.torq.io/en/articles/9350056-workflow-template-json-filtering-with-jq.md): Simple filtering of VirusTotal IP Lookup JSON data. Use these examples to learn how easy it is to filter or create a new JSON output. - [Workflow Template: Collect Azure Network Security Group Details](https://kb.torq.io/en/articles/9350057-workflow-template-collect-azure-network-security-group-details.md): Nested workflow that will collect and format Azure NSG info to identify rule priority needed to block a given port and protocol - [Workflow Template: Interactive Email Conversation \(Microsoft 365\)](https://kb.torq.io/en/articles/9350060-workflow-template-interactive-email-conversation-microsoft-365.md): Example of using Microsoft 365 email as part of an interactive email conversation. This could also be added as a nested workflow. - [Workflow Template: Approve Group Membership for New User \(JumpCloud\)](https://kb.torq.io/en/articles/9350061-workflow-template-approve-group-membership-for-new-user-jumpcloud.md): Ask via Slack for approval from a specific department approver list when a new user is added and add user to the departments JumpCloud group - [Workflow Template: Create Jira and Asana Tickets from Astrix Alert](https://kb.torq.io/en/articles/9350062-workflow-template-create-jira-and-asana-tickets-from-astrix-alert.md): Based on a high risk finding from Astrix initiate a cases with Asana and Jira. - [Workflow Template: Microsoft 365 Adaptive Card Email Conversation](https://kb.torq.io/en/articles/9350064-workflow-template-microsoft-365-adaptive-card-email-conversation.md): Example workflow to send an adaptive card questionnaire via Microsoft 365. Responses are delivered via a webhook back to a Torq workflow. - [Workflow Template: Generate Table in ADF Format for Jira Comments](https://kb.torq.io/en/articles/9350067-workflow-template-generate-table-in-adf-format-for-jira-comments.md): Template to be used as a nested workflow to generate a simple table from an array for Jira in ADF format. - [Workflow Template: Workflow Notification Tracking in Google Sheets](https://kb.torq.io/en/articles/9350069-workflow-template-workflow-notification-tracking-in-google-sheets.md): Workflow that will receive notifications of failed workflows and save the details in a Google Sheet. Entries older than 7 days are removed. - [Workflow Template: Webex Hello World Chat Bot](https://kb.torq.io/en/articles/9350070-workflow-template-webex-hello-world-chat-bot.md): Easy starter template to create an interactive messaging experience for Webex users. - [Workflow Template: Search for CVE Findings in Orca Triggered by Slack](https://kb.torq.io/en/articles/9350071-workflow-template-search-for-cve-findings-in-orca-triggered-by-slack.md): Receive a mention via Slack for "orca-cve", kick off a search in Orca for the specific CVE and update the thread in Slack with the results. - [Workflow Template: Create IOCs on Malicious Files from a CrowdStrike Alert](https://kb.torq.io/en/articles/9350073-workflow-template-create-iocs-on-malicious-files-from-a-crowdstrike-alert.md): For each new EDR alert, validate the files involved with threat intelligence, add to global block list if found to be malicious - [Workflow Template: Approve Group Membership for New User Creation \(Okta\)](https://kb.torq.io/en/articles/9350075-workflow-template-approve-group-membership-for-new-user-creation-okta.md): Ask via Slack for approval from specific department approvers when a new user is added to Okta. - [Workflow Template: Get AWS Access Key Information for User \(AWS\)](https://kb.torq.io/en/articles/9350076-workflow-template-get-aws-access-key-information-for-user-aws.md): Workflow that provides a summary of the Access Keys for a user including number of keys, status, last used and if the key is still in use. - [Workflow Template: Retrieve New Exploited Vulnerabilities from CISA](https://kb.torq.io/en/articles/9350077-workflow-template-retrieve-new-exploited-vulnerabilities-from-cisa.md): On a daily schedule poll the latest CISA vulnerabilities and update a Slack channel on any new CVEs and include references from NIST - [Workflow Template: Send Torq Audit and Activity Logs to Snowflake](https://kb.torq.io/en/articles/9350079-workflow-template-send-torq-audit-and-activity-logs-to-snowflake.md): Pull audit and activity logs from the Torq API and store them in Snowflake on a schedule of every 10 minutes. - [Workflow Template: Reset Direct Manager reference for an Entra ID user \(ex-Azure AD\)](https://kb.torq.io/en/articles/9350080-workflow-template-reset-direct-manager-reference-for-an-entra-id-user-ex-azure-ad.md): Trigger on Teams command, find user in Entra ID, and reset the reference to the direct manager in the directory. - [Workflow Template: Trigger specific scan, update results to Slack \(Tenable\)](https://kb.torq.io/en/articles/9350081-workflow-template-trigger-specific-scan-update-results-to-slack-tenable.md): Triggers a specific pre-defined Tenable Cloud scan, waits for completion, updates on every vulnerable host with severity findings above 0. - [Workflow Template: Retrieve and Normalize data on a Domain](https://kb.torq.io/en/articles/9350082-workflow-template-retrieve-and-normalize-data-on-a-domain.md): Workflow to lookup threat intelligence data from a number of sources and aggregate domain and threat data, normalize a score for a domain - [Workflow Template: Send Torq Audit and Activity Logs to S3 Bucket on a Schedule](https://kb.torq.io/en/articles/9350083-workflow-template-send-torq-audit-and-activity-logs-to-s3-bucket-on-a-schedule.md): Based on a configured time, workflow will upload Torq Audit and/or Activity logs to AWS S3 Buckets. - [Workflow Template: Rename new iOS device to User / Serial Number \(Jamf\)](https://kb.torq.io/en/articles/9350089-workflow-template-rename-new-ios-device-to-user-serial-number-jamf.md): For each new iOS device enrolled in Jamf, if the User Name was not set, change it to unique serial number. Otherwise rename to the User Name - [Workflow Template: Cache VirusTotal Threat Intelligence Findings on an IOC](https://kb.torq.io/en/articles/9350090-workflow-template-cache-virustotal-threat-intelligence-findings-on-an-ioc.md): Receive an IOC from a parent workflow, check the global variable for previous results, if not, query VirusTotal and save results - [Workflow Template: Microsoft Teams - Hello World](https://kb.torq.io/en/articles/9350092-workflow-template-microsoft-teams-hello-world.md): Simple example of Microsoft Teams messages using Adaptive Cards, collecting interactive responses and providing them back to the user. - [Workflow Template: Check Point SmartTasks Notification to Slack](https://kb.torq.io/en/articles/9350096-workflow-template-check-point-smarttasks-notification-to-slack.md): Notification to Slack on status of a policy install or session details of additions, modification, or deletions when a session is published. - [Workflow Template: Nested Check-Out of AWS Credentials via Britive \(Britive\)](https://kb.torq.io/en/articles/9350098-workflow-template-nested-check-out-of-aws-credentials-via-britive-britive.md): Example nested workflow using Britive to Check-Out AWS credentials to be used in a workflow. Check-In the creds using the trans-id provided - [Workflow Template: ITSM - Notify Slack user on closed/resolve incidents \(ServiceNow\)](https://kb.torq.io/en/articles/9350100-workflow-template-itsm-notify-slack-user-on-closed-resolve-incidents-servicenow.md): Receive a Slack message on resolved or closed tickets within ServiceNow. Enrich the message with details from the ticket and closing users. - [Workflow Template: Verify User's Group Membership in Okta via Slack Command](https://kb.torq.io/en/articles/9350102-workflow-template-verify-user-s-group-membership-in-okta-via-slack-command.md): Receive a Slack command with the users email and optional group and provide the group membership including a match if a group is provided. - [Workflow Template: Ask Users to Confirm Failed JumpCloud Login Attempts](https://kb.torq.io/en/articles/9350103-workflow-template-ask-users-to-confirm-failed-jumpcloud-login-attempts.md): Daily pull of failed logins from JumpCloud, reach out to users with failed logins over Slack and confirm they were the tying to login. - [Workflow Template: Send Message over Slack or Microsoft Teams](https://kb.torq.io/en/articles/9350105-workflow-template-send-message-over-slack-or-microsoft-teams.md): This workflow can be used where both Slack and Microsoft Teams are used by different parts of their organizations to send a message. - [Workflow Template: Upload Latest Recorded Future IOCs to Cybereason](https://kb.torq.io/en/articles/9350110-workflow-template-upload-latest-recorded-future-iocs-to-cybereason.md): Pull latest Hashes, IPs and Domains above a specific risk score from Recorded Future and add to the Cybereason reputation list. - [Workflow Template: Suspend Okta Users that are Inactive for More than 30 Days](https://kb.torq.io/en/articles/9350111-workflow-template-suspend-okta-users-that-are-inactive-for-more-than-30-days.md): On a scheduled interval check for users that have not logged in for more than 30 days. Ask a Slack channel for approval to suspend the users - [Workflow Template: Teams Mention to Analyze Suspicious URLs and IPs with VirusTotal](https://kb.torq.io/en/articles/9350112-workflow-template-teams-mention-to-analyze-suspicious-urls-and-ips-with-virustotal.md): Receive a suspicious list of URLs and/or IPs from Microsoft Teams, scan using VirusTotal, and send results back to the Teams conversation. - [Workflow Template: Enrich Hashes, CVEs and IP Addresses with Recorded Future](https://kb.torq.io/en/articles/9350113-workflow-template-enrich-hashes-cves-and-ip-addresses-with-recorded-future.md): Receive a message with one or more CVEs, SHA256 hashes or suspicious IP addresses from Slack and enrich the data with Recorded Future. - [Workflow Template: Collect all Public IP Addresses for an AWS Account](https://kb.torq.io/en/articles/9350114-workflow-template-collect-all-public-ip-addresses-for-an-aws-account.md): Collect all public IP addresses for a given AWS account and provide a simple summary list of IPs and a JSON list by region and service. - [Workflow Template: Slack Mentions - Hello World](https://kb.torq.io/en/articles/9350115-workflow-template-slack-mentions-hello-world.md): Slack Bot workflow to reply to either mentions or direct conversations with the bot - [Workflow Template: Nested Slack Block Generator from an Array](https://kb.torq.io/en/articles/9350116-workflow-template-nested-slack-block-generator-from-an-array.md): Workflow meant to be used as a nested workflow to build a Slack block from an array. This block can be used in the Slack Block Form step. - [Workflow Template: Group IoCs From Text Input](https://kb.torq.io/en/articles/9350117-workflow-template-group-iocs-from-text-input.md): This function takes a text and returns groups of hashes, URLs, domains and IP addresses - [Workflow Template: Process New Cloud Vulnerability DB Issues \(Open CVDB\)](https://kb.torq.io/en/articles/9350120-workflow-template-process-new-cloud-vulnerability-db-issues-open-cvdb.md): Pull latest vulnerabilities from the Open Cloud Vulnerability Database and send an alert to a Slack Channel - [Workflow Template: Open or Update a Jira Issue on an Uptycs Alert](https://kb.torq.io/en/articles/9350121-workflow-template-open-or-update-a-jira-issue-on-an-uptycs-alert.md): Open a parent or child issue in Jira when a medium/high severity event is found. Ask a Slack channel if additional information is required. - [Workflow Template: Just-In-Time Access to Group Membership in Active Directory](https://kb.torq.io/en/articles/9350123-workflow-template-just-in-time-access-to-group-membership-in-active-directory.md): Trigger on a Slack command where a user asks for temporary access to a group in Active Directory with approval from a Slack channel. - [Workflow Template: Okta event on MFA addition with user Verification \(Okta\)](https://kb.torq.io/en/articles/9350124-workflow-template-okta-event-on-mfa-addition-with-user-verification-okta.md): Receive event from Okta when a user adds a MFA method, lookup source IP with VirusTotal or ask user if this was intended, if not open issue. - [Workflow Template: Upload HIPAA Training Evidence in Drata](https://kb.torq.io/en/articles/9350130-workflow-template-upload-hipaa-training-evidence-in-drata.md): Identify users that are HIPAA training non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Identify and Label Confluence Content with PII from BigID](https://kb.torq.io/en/articles/9350131-workflow-template-identify-and-label-confluence-content-with-pii-from-bigid.md): On a trigger from BigID, label all content in Confluence with a specific tag and notify a Slack channel and open a Jira issue with findings. - [Workflow Template: Gather CircleCI Environment Variables from GitHub Org Repos](https://kb.torq.io/en/articles/9350132-workflow-template-gather-circleci-environment-variables-from-github-org-repos.md): Query GitHub for Organization Repositories and gather CircleCI Environment Variables that are configured in the project. - [Workflow Template: Verify Permissions to Execute Workflows - EntraID \(ex-Azure AD\)](https://kb.torq.io/en/articles/9350133-workflow-template-verify-permissions-to-execute-workflows-entraid-ex-azure-ad.md): Workflow that can be used to verify users have permissions to run a specific workflow by Id or name and also check group membership. - [Workflow Template: Upload Hard Drive Encryption Evidence in Drata](https://kb.torq.io/en/articles/9350136-workflow-template-upload-hard-drive-encryption-evidence-in-drata.md): Identify devices that are HD encryption non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Send a Microsoft Teams Notification upon Mention in a Torq Case](https://kb.torq.io/en/articles/9350137-workflow-template-send-a-microsoft-teams-notification-upon-mention-in-a-torq-case.md): When a user is mentioned in a Torq Case comment, send the user a notification in Microsoft Teams with the text and a hyperlink to the case. - [Workflow Template: Label Google Drive Files Containing PII Identified by BigID](https://kb.torq.io/en/articles/9350138-workflow-template-label-google-drive-files-containing-pii-identified-by-bigid.md): On trigger from BigID from findings of files in Google Drive that contain PII, assign a Google Drive label and field to the file. - [Workflow Template: Reset Entra ID \(ex-Azure AD\) MFA Methods and Password on a User](https://kb.torq.io/en/articles/9350142-workflow-template-reset-entra-id-ex-azure-ad-mfa-methods-and-password-on-a-user.md): This workflow can be used as a nested workflow to reset a users password, remove all MFA methods for the user and clears any user sessions. - [Workflow Template: Add MFA on IdP Evidence in Drata](https://kb.torq.io/en/articles/9350144-workflow-template-add-mfa-on-idp-evidence-in-drata.md): Identify users that are MFA non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Fetch New QRadar Offenses with Pagination](https://kb.torq.io/en/articles/9350145-workflow-template-fetch-new-qradar-offenses-with-pagination.md): A nested workflow to pull all new open QRadar offenses and use pagination to return all results. - [Workflow Template: SSL Certificate Expiration Check](https://kb.torq.io/en/articles/9350146-workflow-template-ssl-certificate-expiration-check.md): From a List of domains or subdomains, check expiration dates from their certificates - [Workflow Template: Find all Okta Active Devices with Pagination](https://kb.torq.io/en/articles/9350147-workflow-template-find-all-okta-active-devices-with-pagination.md): Workflow that can be used as a nested workflow to gather all active Okta devices into a single array using pagination. - [Workflow Template: Extract Multiple Observables](https://kb.torq.io/en/articles/9350148-workflow-template-extract-multiple-observables.md): Extracts different types of observables such as File Hashes, IP Addresses, IP Range, Email Addresses, Filenames, Hostnames, URLs, and CVEs. - [Workflow Template: Upload Screensaver Lock Evidence in Drata](https://kb.torq.io/en/articles/9350149-workflow-template-upload-screensaver-lock-evidence-in-drata.md): Identify devices that are screen lock non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Identify PII Information Shared in a Slack Workspace via BigID](https://kb.torq.io/en/articles/9350150-workflow-template-identify-pii-information-shared-in-a-slack-workspace-via-bigid.md): On a trigger from BigID for PII information found in a Slack Workspace, send detailed findings to a specific Slack channel or admin. - [Workflow Template: Simple Loops with Torq](https://kb.torq.io/en/articles/9350154-workflow-template-simple-loops-with-torq.md): Example of using a loop over JSON data and loop over a range in a workflow. Results are collected with the "Collect" operator - [Workflow Template: Add Anti-Virus Evidence in Drata](https://kb.torq.io/en/articles/9350155-workflow-template-add-anti-virus-evidence-in-drata.md): Identify devices that are anti-virus non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Upload Auto-Updates Evidence in Drata](https://kb.torq.io/en/articles/9350156-workflow-template-upload-auto-updates-evidence-in-drata.md): Identify devices that are anti-update non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Add Password Manager Evidence in Drata](https://kb.torq.io/en/articles/9350157-workflow-template-add-password-manager-evidence-in-drata.md): Identify devices that are password manager non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Send Torq Audit or Activity logs to Sumo Logic on a Schedule](https://kb.torq.io/en/articles/9350158-workflow-template-send-torq-audit-or-activity-logs-to-sumo-logic-on-a-schedule.md): Workflow that can be used to send either Torq audit or activity logs to Sumo Logic on a scheduled interval. - [Workflow Template: Handle Wiz Alert for AWS Admin Principals Inactive Over 90 Days](https://kb.torq.io/en/articles/9350159-workflow-template-handle-wiz-alert-for-aws-admin-principals-inactive-over-90-days.md): On alert from Wiz on an AWS admin principal that is inactive over 90 days, ask a Slack channel for approval to deactivate the IAM account. - [Workflow Template: Export a Torq Case in Word Document Format](https://kb.torq.io/en/articles/9350162-workflow-template-export-a-torq-case-in-word-document-format.md): Export a Torq Case including the general details, timeline, observables, attachments and custom fields into a Microsoft Word file. - [Workflow Template: Collect Asynchronous Responses from Slack Block Messages](https://kb.torq.io/en/articles/9350164-workflow-template-collect-asynchronous-responses-from-slack-block-messages.md): Workflow that can be used to record asynchronous responses to Slack Block Kit messages that contain buttons for a user response. - [Workflow Template: Convert Newline Delimited JSON to Standard JSON](https://kb.torq.io/en/articles/9350165-workflow-template-convert-newline-delimited-json-to-standard-json.md): Converts Newline Delimited JSON formatted data into standard JSON format. - [Workflow Template: Upload Background Check Evidence in Drata](https://kb.torq.io/en/articles/9350166-workflow-template-upload-background-check-evidence-in-drata.md): Remediate failed resources that require background check evidence by attaching necessary provided URL on workflow initiation. - [Workflow Template: Assign or Remove Licenses on Users for Microsoft via Graph API](https://kb.torq.io/en/articles/9350167-workflow-template-assign-or-remove-licenses-on-users-for-microsoft-via-graph-api.md): Used as a nested workflow to assign or remove licenses to Microsoft 365 users. The workflow takes the SKU on input for assignment. - [Workflow Template: Upload Security Training Evidence in Drata](https://kb.torq.io/en/articles/9350168-workflow-template-upload-security-training-evidence-in-drata.md): Identify users that are security training non-compliant within Drata and upload evidence file provided to workflow. - [Workflow Template: Get Failing Resources for a Test in Drata](https://kb.torq.io/en/articles/9350169-workflow-template-get-failing-resources-for-a-test-in-drata.md): Provide insight into failed resources based on information collected from the Drata platform. - [Workflow Template: Check if IPv4 Address is Part of an AWS IP Network Block](https://kb.torq.io/en/articles/9350171-workflow-template-check-if-ipv4-address-is-part-of-an-aws-ip-network-block.md): On a mention from Slack, extract an ip address and try to match it to a network block in use at AWS. Provide the result back to the thread. - [Workflow Template: Offboard SaaS User from Grip on Trigger from Hibob](https://kb.torq.io/en/articles/9350176-workflow-template-offboard-saas-user-from-grip-on-trigger-from-hibob.md): On trigger from Hibob, offboard the user from Grip and report the status back to a default Slack channel or the users Manager via Slack. - [Workflow Template: Attach a Screenshot to a ServiceNow Incident or Jira Issue](https://kb.torq.io/en/articles/9350177-workflow-template-attach-a-screenshot-to-a-servicenow-incident-or-jira-issue.md): Workflow that can be used as a nested workflow to attach a screenshot of a URL to either a Jira Issue or ServiceNow Incident - [Workflow Template: Search for Unused or Inactive Roles in AWS IAM](https://kb.torq.io/en/articles/9350179-workflow-template-search-for-unused-or-inactive-roles-in-aws-iam.md): Queries AWS for the IAM Roles and groups roles by Last Used and Never Used after a defined amount of days. - [Workflow Template: Verify User's Group Membership in Ping via Slack Command](https://kb.torq.io/en/articles/9350180-workflow-template-verify-user-s-group-membership-in-ping-via-slack-command.md): Receive a Slack command with an optional group and provide the group membership including a match if a group is provided. - [Workflow Template: Collect Information on Case Closing Action](https://kb.torq.io/en/articles/9350182-workflow-template-collect-information-on-case-closing-action.md): Shows a form whenever a Case is change to CLOSED status. - [Workflow Template: URLScan URL Enrichment with Cache](https://kb.torq.io/en/articles/9350187-workflow-template-urlscan-url-enrichment-with-cache.md): Receive a URL to analyze with URLScan and provide a summary of the URL with malicious, phishing, score and screenshot details if available. - [Workflow Template: Subscribe Gmail address to watch a PUB SUB pre-defined topic](https://kb.torq.io/en/articles/9350189-workflow-template-subscribe-gmail-address-to-watch-a-pub-sub-pre-defined-topic.md): Maintains a valid subscription to a topic by checking daily its expiration date and renewing it when necessary. - [Workflow Template: Send Torq Audit and Activity Logs to Singularity XDR](https://kb.torq.io/en/articles/9350190-workflow-template-send-torq-audit-and-activity-logs-to-singularity-xdr.md): Based on a configured time, workflow audit and activity logs will be sent to SingularityXDR - [Workflow Template: Google File Label Lifecycle](https://kb.torq.io/en/articles/9350193-workflow-template-google-file-label-lifecycle.md): This workflow showcases the published steps to support the Google file label lifecycle process. - [Workflow Template: Issue a Push Challenge with Okta and Wait for a Response](https://kb.torq.io/en/articles/9350198-workflow-template-issue-a-push-challenge-with-okta-and-wait-for-a-response.md): Receive an Okta user and factor ID from a parent workflow and send a push challenge to the user and wait for and return the response. - [Workflow Template: AlienVault File Hash Enrichment with Cache](https://kb.torq.io/en/articles/9350199-workflow-template-alienvault-file-hash-enrichment-with-cache.md): Nested workflow that will take a File Hash as input and query AlienVault's General and Analysis sections for details and return the results. - [Workflow Template: Google Chat Hello World](https://kb.torq.io/en/articles/9350200-workflow-template-google-chat-hello-world.md): This workflow demonstrates the use of the Google Chat Steps and the ability to interact with end users and create Google Chat Spaces. - [Workflow Template: Pangea - Domain Enrichment with Cache](https://kb.torq.io/en/articles/9350201-workflow-template-pangea-domain-enrichment-with-cache.md): Receives a Domain from a parent workflow and query Pangea for its reputation. - [Workflow Template: Decode QR Codes in Torq Case Attachments](https://kb.torq.io/en/articles/9350202-workflow-template-decode-qr-codes-in-torq-case-attachments.md): Decode QR codes that are found in Torq Case Attachments by using a quick action or Run a Workflow on a Torq Case. - [Workflow Template: Notify on Open and In-Progress Torq Cases Approaching the SLA](https://kb.torq.io/en/articles/9350205-workflow-template-notify-on-open-and-in-progress-torq-cases-approaching-the-sla.md): Scheduled workflow that will send a notification to Slack or Microsoft Teams on Torq cases that are approaching or past the defined SLA. - [Workflow Template: Recorded Future Sandbox - File Analysis with Cache](https://kb.torq.io/en/articles/9350206-workflow-template-recorded-future-sandbox-file-analysis-with-cache.md): Submits a File to Recorded Future Sandbox for full analysis. - [Workflow Template: Generate Graph of Simple JSON Data using Python](https://kb.torq.io/en/articles/9350208-workflow-template-generate-graph-of-simple-json-data-using-python.md): Functional workflow that will data JSON data and generate a base64 encoded PNG graph of the data that was passed to the workflow. - [Workflow Template: Notify a Slack Channel on Case Creation](https://kb.torq.io/en/articles/9350209-workflow-template-notify-a-slack-channel-on-case-creation.md): Workflow that will notify a specific Slack channel for every new Torq case that is created. - [Workflow Template: Query Logs on Singularity XDR with Pagination](https://kb.torq.io/en/articles/9350210-workflow-template-query-logs-on-singularity-xdr-with-pagination.md): This workflow serves as a function that executes a query in Singularity XDR. - [Workflow Template: Send Torq Audit or Activity Logs on a Schedule to Splunk](https://kb.torq.io/en/articles/9350211-workflow-template-send-torq-audit-or-activity-logs-on-a-schedule-to-splunk.md): Workflow that can be used to send Torq audit and/or activity logs to Splunk on a schedule every 10 minutes. - [Workflow Template: Simple Splunk Query with Optional Return Field Filters](https://kb.torq.io/en/articles/9350212-workflow-template-simple-splunk-query-with-optional-return-field-filters.md): A simple Splunk query that can use optional field filters to filter the dataset returned. Can be used as a nested workflow to simplify use. - [Workflow Template: Find AWS Instance Information by Private IP Address in Wiz](https://kb.torq.io/en/articles/9350213-workflow-template-find-aws-instance-information-by-private-ip-address-in-wiz.md): On mention from Microsoft Teams, look for instances with the private IP Address and gather information on the instance and send to Teams. - [Workflow Template: Verify Entra ID \(ex-Azure AD\) Audit Sign-Ins from Allowed Regions](https://kb.torq.io/en/articles/9350214-workflow-template-verify-entra-id-ex-azure-ad-audit-sign-ins-from-allowed-regions.md): Retrieve Entra ID Audit logs for Sign-Ins and compare against specific allowed regions. If a violation occurs notify a Slack channel. - [Workflow Template: Run Antivirus Scan on a device on Microsoft Defender for Endpoint](https://kb.torq.io/en/articles/9350215-workflow-template-run-antivirus-scan-on-a-device-on-microsoft-defender-for-endpoint.md): Run a Quick or Full Antivirus Scan on a device by its machineId or device name. - [Workflow Template: Retrieve and Normalize data on a File Hash](https://kb.torq.io/en/articles/9350217-workflow-template-retrieve-and-normalize-data-on-a-file-hash.md): Workflow to lookup threat intelligence data from a number of sources and aggregate threat data, normalize a score for the provided file hash - [Workflow Template: Generate a Report for Torq Cases in Microsoft Docx Format](https://kb.torq.io/en/articles/9350218-workflow-template-generate-a-report-for-torq-cases-in-microsoft-docx-format.md): A nested workflow that generates a report on Torq cases, analyst activity, and case MTTR reporting with output as a Microsoft Word document. - [Workflow Template: Create Microsoft Graph Subscriptions and Renewals](https://kb.torq.io/en/articles/9350220-workflow-template-create-microsoft-graph-subscriptions-and-renewals.md): Create one or more Microsoft Graph subscriptions to a Microsoft 365 trigger. The subscriptions are extended and renewed daily. - [Workflow Template: Find all Hosts Impacted by an Open CVE in CrowdStrike](https://kb.torq.io/en/articles/9350221-workflow-template-find-all-hosts-impacted-by-an-open-cve-in-crowdstrike.md): Find all hosts in CrowdStrike that are impacted by a specific CVE and output the list of hostnames and remediation information provided. - [Workflow Template: Send a Microsoft Teams Notification to Assignee in a Torq Case](https://kb.torq.io/en/articles/9350222-workflow-template-send-a-microsoft-teams-notification-to-assignee-in-a-torq-case.md): Send a notification to the new assignee on a Torq Case via Microsoft Teams with a summary of the case and a direct hyperlink to the case. - [Workflow Template: Search for Vulnerabilities by Hostname in Tenable](https://kb.torq.io/en/articles/9350223-workflow-template-search-for-vulnerabilities-by-hostname-in-tenable.md): Pull information from a hostname in Tenable and output the information back to the parent workflow or an optional Slack user or channel. - [Workflow Template: Send Torq Audit and Activity Logs to Elasticsearch](https://kb.torq.io/en/articles/9350224-workflow-template-send-torq-audit-and-activity-logs-to-elasticsearch.md): Pull the logs from Torq on a schedule and send to Elasticsearch in a batch transaction. - [Workflow Template: Create Microsoft Graph Subscription and Renew Daily](https://kb.torq.io/en/articles/9350225-workflow-template-create-microsoft-graph-subscription-and-renew-daily.md): Create a Microsoft Graph subscription to a Torq Microsoft 365 trigger. The subscription is renewed daily and extends the expiration date. - [Workflow Template: Suspend Contractor Accounts in Okta with inactivity for 7 days](https://kb.torq.io/en/articles/9350229-workflow-template-suspend-contractor-accounts-in-okta-with-inactivity-for-7-days.md): Check daily for active accounts where the profile userType is "Contractor". Suspend the account if no login occurred in the past 7 days. - [Workflow Template: VirusTotal Domain Enrichment with Cache](https://kb.torq.io/en/articles/9350230-workflow-template-virustotal-domain-enrichment-with-cache.md): Nested workflow that will take a Domain as input and query VirusTotal for the domain and return analysis information to the parent workflow. - [Workflow Template: Isolate or Unisolate device on Microsoft Defender for Endpoint](https://kb.torq.io/en/articles/9350231-workflow-template-isolate-or-unisolate-device-on-microsoft-defender-for-endpoint.md): Nested workflow to Isolate or Unisolate a device by its machineId or device name. - [Workflow Template: Recorded Future - URL Enrichment with Cache](https://kb.torq.io/en/articles/9350232-workflow-template-recorded-future-url-enrichment-with-cache.md): Receive an URL from a parent workflow and query Recorded Future for its reputation. - [Workflow Template: Fetch File Information by Hash from Microsoft Defender](https://kb.torq.io/en/articles/9350234-workflow-template-fetch-file-information-by-hash-from-microsoft-defender.md): Collects threat information about a file by fileId \(SHA1 Hash\) in a time frame. - [Workflow Template: VirusTotal URL Enrichment with Cache](https://kb.torq.io/en/articles/9350235-workflow-template-virustotal-url-enrichment-with-cache.md): Nested workflow that will take a URL as input and query VirusTotal for details and return analysis information on the URL. - [Workflow Template: Torq Case Example Descriptions for Different Case Types](https://kb.torq.io/en/articles/9350236-workflow-template-torq-case-example-descriptions-for-different-case-types.md): A workflow with many mock examples of Torq Case descriptions for Torq integration partners and formatting examples to use with Torq Cases. - [Workflow Template: Recorded Future - IoC Enrichment](https://kb.torq.io/en/articles/9350237-workflow-template-recorded-future-ioc-enrichment.md): Extracts multiple observables from raw text and performs enrichment for each observable on RecordedFuture. - [Workflow Template: AlienVault Combined Observable Enrichment](https://kb.torq.io/en/articles/9350238-workflow-template-alienvault-combined-observable-enrichment.md): Extract multiple observables from raw text and performs enrichment for each observable in AlienVault returns analysis information. - [Workflow Template: Collect Information on Case Closure by Permitted Analysts](https://kb.torq.io/en/articles/9350241-workflow-template-collect-information-on-case-closure-by-permitted-analysts.md): Collect information when a Torq Case is changed to a CLOSED status and verifies that the analyst is permitted to close cases. - [Workflow Template: Gather QRadar Events for a Given Offense](https://kb.torq.io/en/articles/9350242-workflow-template-gather-qradar-events-for-a-given-offense.md): For a given QRadar Offense pull all events for a specific time window and provide the list of events back to a parent workflow. - [Workflow Template: AlienVault Domain Enrichment with Cache](https://kb.torq.io/en/articles/9350244-workflow-template-alienvault-domain-enrichment-with-cache.md): Nested workflow that will take a Domain as input and query AlienVault's General, Malware and GEO sections and return analysis information. - [Workflow Template: Notify a Teams Channel on Case Creation](https://kb.torq.io/en/articles/9350246-workflow-template-notify-a-teams-channel-on-case-creation.md): Workflow that will notify a specific Microsoft Teams channel for every new Torq case that is created. - [Workflow Template: Send Slack Notification upon Mention in a Torq Case](https://kb.torq.io/en/articles/9350247-workflow-template-send-slack-notification-upon-mention-in-a-torq-case.md): When a user is mentioned in a Torq Case comment, send the user a notification in Slack with the text and a hyperlink to the case. - [Workflow Template: Prepare Case Properties by Case Type](https://kb.torq.io/en/articles/9350248-workflow-template-prepare-case-properties-by-case-type.md): When a new Torq case is created, based on the case type, create custom fields and quick action on the newly created case. - [Workflow Template: Generate a Screenshot of a URL and Describe the Image via OpenAI](https://kb.torq.io/en/articles/9350249-workflow-template-generate-a-screenshot-of-a-url-and-describe-the-image-via-openai.md): Generate a screenshot of a specific URL and ask OpenAI to review the image and provide input if it could be part of a phishing attempt. - [Workflow Template: Retrieve and Normalize data on an IP Address](https://kb.torq.io/en/articles/9350250-workflow-template-retrieve-and-normalize-data-on-an-ip-address.md): Workflow to lookup threat intelligence data from a number of sources and aggregate geo data, threat data and normalize a score for the IP - [Workflow Template: VirusTotal File Hash Enrichment with Cache](https://kb.torq.io/en/articles/9350251-workflow-template-virustotal-file-hash-enrichment-with-cache.md): Nested workflow that will take a File Hash as input and query VirusTotal for analysis and if the hash is found, return the results. - [Workflow Template: Handle Panther Okta Alerts on User Action Detection](https://kb.torq.io/en/articles/9350252-workflow-template-handle-panther-okta-alerts-on-user-action-detection.md): On a new Panther alert from Okta, ask the user if the action was intended and if so mark the alert resolved. If not, open a Torq case. - [Workflow Template: Pangea - Email Enrichment with Cache](https://kb.torq.io/en/articles/9350253-workflow-template-pangea-email-enrichment-with-cache.md): Receives an Email from a parent workflow and query Pangea for its reputation. - [Workflow Template: VirusTotal IPv4 Address Enrichment with Cache](https://kb.torq.io/en/articles/9350254-workflow-template-virustotal-ipv4-address-enrichment-with-cache.md): Workflow that will take an IPv4 address as input and query VirusTotal and return the analysis information to the parent workflow. - [Workflow Template: AlienVault IPv4 Address Enrichment with Cache](https://kb.torq.io/en/articles/9350255-workflow-template-alienvault-ipv4-address-enrichment-with-cache.md): Workflow that will take an IPv4 as input and query AlienVault's General, Malware and Reputation sections and return analysis information. - [Workflow Template: Enrich SentinelOne Threat Finding and Run Singularity XDR Search](https://kb.torq.io/en/articles/9350256-workflow-template-enrich-sentinelone-threat-finding-and-run-singularity-xdr-search.md): For each new threat detected by SentinelOne, query Threat Intelligence data from VirusTotal and RecordedFuture and add notes to the threat - [Workflow Template: Pangea - File Hash Enrichment with Cache](https://kb.torq.io/en/articles/9350257-workflow-template-pangea-file-hash-enrichment-with-cache.md): Receives a File Hash from a parent workflow and query Pangea for its reputation. - [Workflow Template: Submit a File for Analysis to VirusTotal with Cache](https://kb.torq.io/en/articles/9350258-workflow-template-submit-a-file-for-analysis-to-virustotal-with-cache.md): Submit a file to VirusTotal for analysis and provide a simple cache for the analysis results. Use URLs or Torq file links to the file. - [Workflow Template: Search Observables by Grouped UDM Fields in Chronicle](https://kb.torq.io/en/articles/9350259-workflow-template-search-observables-by-grouped-udm-fields-in-chronicle.md): Receives Observables as hash, IP address, domain, username or email and performs a query to Chronicle SIEM using Grouped UDM fields. - [Workflow Template: Return Specific Default or Overriding Workspace Variable](https://kb.torq.io/en/articles/9350263-workflow-template-return-specific-default-or-overriding-workspace-variable.md): This workflow will return a variable from two workspace variables with priority if found in the Overriding Workspace Variable then Default. - [Workflow Template: Request File Download From CrowdStrike Using Real Time Response](https://kb.torq.io/en/articles/9350264-workflow-template-request-file-download-from-crowdstrike-using-real-time-response.md): Nested workflow that will take the CrowdStrike Device ID and a file path and will provide a download link to pass to a Sandbox vendor - [Workflow Template: On Case Closure Set a Custom Field and Tag with Resolution Reason](https://kb.torq.io/en/articles/9350265-workflow-template-on-case-closure-set-a-custom-field-and-tag-with-resolution-reason.md): When a Torq Case is closed or resolved, add a specific custom field and tag to the case the will contain the resolution reason of the case. - [Workflow Template: Send a Slack Notification to Assignee in a Torq Case](https://kb.torq.io/en/articles/9350266-workflow-template-send-a-slack-notification-to-assignee-in-a-torq-case.md): Send a notification to a new assignee on a Torq Case via Slack with a summary of the case and a direct hyperlink to the case. - [Workflow Template: Validate Gem Alert Events in Slack](https://kb.torq.io/en/articles/9350267-workflow-template-validate-gem-alert-events-in-slack.md): Communicate with a user through Slack to validate a security alert. - [Workflow Template: Run LiveResponses on Microsoft Defender for Endpoint](https://kb.torq.io/en/articles/9350268-workflow-template-run-liveresponses-on-microsoft-defender-for-endpoint.md): Execute Live Responses on an Endpoint and collects the results of each command. - [Workflow Template: Torq Interact Multi-User Communication Example](https://kb.torq.io/en/articles/9350269-workflow-template-torq-interact-multi-user-communication-example.md): This demo illustrates how to utilize Torq Interact to handle communications with one or more users. - [Workflow Template: Scan URLs with URLScan and Provide a Summary](https://kb.torq.io/en/articles/9350271-workflow-template-scan-urls-with-urlscan-and-provide-a-summary.md): Receive an array of URLs to scan with URLScan and provide a summary per URL with malicious, phishing, score, and screenshot URL if available - [Workflow Template: VirusTotal Combined Observable Enrichment](https://kb.torq.io/en/articles/9350272-workflow-template-virustotal-combined-observable-enrichment.md): Extract multiple observables from raw text and performs enrichment for each observable in VirusTotal and returns analysis information. - [Workflow Template: AbuseIPDB IPv4 Address Enrichment with Cache](https://kb.torq.io/en/articles/9350273-workflow-template-abuseipdb-ipv4-address-enrichment-with-cache.md): Workflow that will take an IPv4 address as input and query AbuseIPDB for details about the address including the Abuse Confidence Score. - [Workflow Template: Send a Question to Slack Users and Collect Responses](https://kb.torq.io/en/articles/9350274-workflow-template-send-a-question-to-slack-users-and-collect-responses.md): Send a question to a number of Slack users and collect the responses in a global variable with a wait of up to 31 days to collect results. - [Workflow Template: Recorded Future - File Hash Enrichment with Cache](https://kb.torq.io/en/articles/9350275-workflow-template-recorded-future-file-hash-enrichment-with-cache.md): Receive a file hash from a parent workflow and query Recorded Future for its reputation. - [Workflow Template: Send a Microsoft Outlook Email to Assignee in a Torq Case](https://kb.torq.io/en/articles/9350276-workflow-template-send-a-microsoft-outlook-email-to-assignee-in-a-torq-case.md): Workflow that will notify the user by sending an email via Microsoft Outlook for every new Torq case that is assigned to the user. - [Workflow Template: Pangea - IP Address Enrichment with Cache](https://kb.torq.io/en/articles/9350277-workflow-template-pangea-ip-address-enrichment-with-cache.md): Receives an IP Address from a parent workflow and query Pangea for its reputation. - [Workflow Template: Silent Push - Domain Enrichment with Cache](https://kb.torq.io/en/articles/9350278-workflow-template-silent-push-domain-enrichment-with-cache.md): Receives an Domain from a parent workflow and query Silent Push for enrichment. - [Workflow Template: Generate a Screenshot and Attach to a Torq Case on URL Addition](https://kb.torq.io/en/articles/9350279-workflow-template-generate-a-screenshot-and-attach-to-a-torq-case-on-url-addition.md): When a new URL is added as an observable, attempt to generate a screenshot and if successful add it as an attachment to a Torq case. - [Workflow Template: Download a File from a SentinelOne Threat ID](https://kb.torq.io/en/articles/9350280-workflow-template-download-a-file-from-a-sentinelone-threat-id.md): Fetch a file from a SentinelOne Threat ID and encrypt it with the provided password with a link to download. - [Workflow Template: URL Analysis with Cache \(Recorded Future Sandbox\)](https://kb.torq.io/en/articles/9350281-workflow-template-url-analysis-with-cache-recorded-future-sandbox.md): Submits an URL to Recorded Future Sandbox for full analysis. - [Workflow Template: Pangea - URL Enrichment with Cache](https://kb.torq.io/en/articles/9350282-workflow-template-pangea-url-enrichment-with-cache.md): Receives an URL from a parent workflow and query Pangea for its reputation. - [Workflow Template: Recorded Future - IP Address Enrichment with Cache](https://kb.torq.io/en/articles/9350283-workflow-template-recorded-future-ip-address-enrichment-with-cache.md): Receive an IP address from a parent workflow and query Recorded Future for its reputation. - [Workflow Template: Shodan - IP Address Enrichment with Cache](https://kb.torq.io/en/articles/9350284-workflow-template-shodan-ip-address-enrichment-with-cache.md): Receives an IP Address from a parent workflow and query Shodan for enrichment. - [Workflow Template: Search in Torq Audit Logs Based on Query](https://kb.torq.io/en/articles/9350285-workflow-template-search-in-torq-audit-logs-based-on-query.md): Search for audit event based on action, email, actor type, actor\_name or resource name. - [Workflow Template: Generate a Dynamic PowerPoint Document based on Slide Data](https://kb.torq.io/en/articles/9350286-workflow-template-generate-a-dynamic-powerpoint-document-based-on-slide-data.md): Workflow that can be used as a guide on how to generate a dynamic PowerPoint document with the Python python-pptx library. - [Workflow Template: Submit a File for Analysis to VMRay with Cache](https://kb.torq.io/en/articles/9350288-workflow-template-submit-a-file-for-analysis-to-vmray-with-cache.md): Submit a file to VMRay for analysis and provide a simple cache for the analysis results. Use public URLs or Torq file links to the file. - [Workflow Template: Gather Torq Audit or Activity Logs](https://kb.torq.io/en/articles/9838973-workflow-template-gather-torq-audit-or-activity-logs.md): Nested workflow that collects Torq workflow Activity logs or user Audit logs and returns the logs to the parent workflow. - [Workflow Template: Fetch Cyberint Alerts on a Schedule](https://kb.torq.io/en/articles/9838984-workflow-template-fetch-cyberint-alerts-on-a-schedule.md): Fetch alerts from Cyberint on a schedule. An optional loop is available in the workflow to do additional actions as needed. - [Workflow Template: Table Workspace Variable Example Workflow](https://kb.torq.io/en/articles/9838985-workflow-template-table-workspace-variable-example-workflow.md): This Workflows is an example on how to use a table as a workspace variable to perform common CRUD tasks. - [Workflow Template: Open Jira Issues and Enrich Event on Sysdig Kubernetes Detections](https://kb.torq.io/en/articles/9838987-workflow-template-open-jira-issues-and-enrich-event-on-sysdig-kubernetes-detections.md): Detect, enrich, alert and auto-assign incidents using Kubernetes namespaces using Sysdig Runtime Threat Intelligence and Detection. - [Workflow Template: List All Groups with Pagination on Entra ID \(ex-Azure AD\)](https://kb.torq.io/en/articles/9847507-workflow-template-list-all-groups-with-pagination-on-entra-id-ex-azure-ad.md): This function will collect all groups on Entra ID \(ex AzureAD\) using pagination. - [Workflow Template: List All Users with Pagination on Entra ID \(ex-Azure AD\)](https://kb.torq.io/en/articles/9847510-workflow-template-list-all-users-with-pagination-on-entra-id-ex-azure-ad.md): This function will collect all users on Entra ID \(ex AzureAD\) using pagination. - [Workflow Template: Fetch Incidents from Cortex XDR on a Schedule](https://kb.torq.io/en/articles/9890752-workflow-template-fetch-incidents-from-cortex-xdr-on-a-schedule.md): On a schedule, fetch new incidents from Cortex XDR using pagination. - [Workflow Template: Create Tables on Snowflake for Torq Audit and Activity Logs](https://kb.torq.io/en/articles/9905431-workflow-template-create-tables-on-snowflake-for-torq-audit-and-activity-logs.md): Create tables in snowflake database to store Torq audit and activity logs. - [Workflow Template: Step Failure with Runner Configured Notification to Slack](https://kb.torq.io/en/articles/9919492-workflow-template-step-failure-with-runner-configured-notification-to-slack.md): Send a notification to a Slack channel when a step failure occurs where a runner is configured. A link to the execution id is also provided - [Workflow Template: Step Failure with Runner Configured Notification to Teams](https://kb.torq.io/en/articles/9924288-workflow-template-step-failure-with-runner-configured-notification-to-teams.md): Send a notification to a Teams channel when a step failure occurs where a runner is configured. A link to the execution id is also provided - [Workflow Template: Step Failure with Runner Configured Notification to Email](https://kb.torq.io/en/articles/9928981-workflow-template-step-failure-with-runner-configured-notification-to-email.md): Send an email notification via Gmail/Outlook when a step failure occurs where a runner is configured. A link to the execution is provided. - [Workflow Template: Notify by Email when a Workflow Failure is Triggered](https://kb.torq.io/en/articles/9928984-workflow-template-notify-by-email-when-a-workflow-failure-is-triggered.md): Send an email notification via Gmail/Outlook when a workflow failure is detected. A link to the workflow execution is provided. - [Workflow Template: Notify Reviewer via Slack when Workflow is Submitted for Review](https://kb.torq.io/en/articles/9928985-workflow-template-notify-reviewer-via-slack-when-workflow-is-submitted-for-review.md): When a workflow submission is requested send a message to each reviewer in Slack and include a link to the submission. - [Workflow Template: Notify a Slack Channel when a Workflow Failure is Triggered](https://kb.torq.io/en/articles/9928987-workflow-template-notify-a-slack-channel-when-a-workflow-failure-is-triggered.md): Send a notification to a Slack channel when a workflow failure is detected. A link to the execution log is provided in the message. - [Workflow Template: Notify a Microsoft Team when a Workflow Failure is Triggered](https://kb.torq.io/en/articles/9928988-workflow-template-notify-a-microsoft-team-when-a-workflow-failure-is-triggered.md): Send a notification to a Microsoft Team when a workflow failure is detected. A link to the execution log is provided in the message. - [Workflow Template: Notify Reviewer via Teams when Workflow is Submitted for Review](https://kb.torq.io/en/articles/9928992-workflow-template-notify-reviewer-via-teams-when-workflow-is-submitted-for-review.md): When a workflow submission is requested send a message to each reviewer in Teams and include a link to the submission. - [Workflow Template: Notify a Slack Channel for a New Share Request](https://kb.torq.io/en/articles/9932260-workflow-template-notify-a-slack-channel-for-a-new-share-request.md): When a new resource is shared with the workspace send a message with the details to a Slack channel with a link to the request. - [Workflow Template: Notify a Microsoft Teams Channel for a New Share Request](https://kb.torq.io/en/articles/9932261-workflow-template-notify-a-microsoft-teams-channel-for-a-new-share-request.md): When a new resource is shared with the workspace send a message with the details to a Teams channel with a link to the request. - [Workflow Template: Watch Microsoft Security Response Center RSS Feed](https://kb.torq.io/en/articles/9973285-workflow-template-watch-microsoft-security-response-center-rss-feed.md): An example workflow to check an RSS feed daily for changes using the Microsoft Security Response Center RSS feed as a sample. - [Workflow Template: File Conversion using a Torq Interact Workflow](https://kb.torq.io/en/articles/9978674-workflow-template-file-conversion-using-a-torq-interact-workflow.md): This workflow is an example of how to use Torq Interact with the file upload and download parameters. - [Workflow Template: Add a Weekday or Weekend Tag on Creation of a Torq Case](https://kb.torq.io/en/articles/10031567-workflow-template-add-a-weekday-or-weekend-tag-on-creation-of-a-torq-case.md): This workflow will add a tag for either Weekday or Weekend to a new Torq case based on the local creation time of the case. - [Workflow Template: Wiz GraphQL Query for AWS Instances with Open SSH Access](https://kb.torq.io/en/articles/9349978-workflow-template-wiz-graphql-query-for-aws-instances-with-open-ssh-access.md): Simple example using the GraphQL functionality with Wiz to run a query. Use the API Console in Wiz to find GraphQL statements to use. - [Workflow Template: Hello World \(Discord\)](https://kb.torq.io/en/articles/9350192-workflow-template-hello-world-discord.md): This is a simple example of using Discord to create an interactive workflow using an Ask Question step. - [Workflow Template: Enable AWS S3 Bucket Versioning on Orca Alert](https://kb.torq.io/en/articles/9349981-workflow-template-enable-aws-s3-bucket-versioning-on-orca-alert.md): Receive an Orca alert on an AWS S3 bucket with versioning disabled, lookup owner tag, ask owner or channel to enable versioning. - [Workflow Template: Offboarding Remediation with Adaptive Shield](https://kb.torq.io/en/articles/9349982-workflow-template-offboarding-remediation-with-adaptive-shield.md): Triggered from a Slack mention to leverage Adaptive Shield's insight into SaaS applications to remediate offboarded user's access - [Workflow Template: Just-in-time access to Group Membership in PingOne](https://kb.torq.io/en/articles/9349985-workflow-template-just-in-time-access-to-group-membership-in-pingone.md): Trigger on a Slack command where a user asks for temporary access to resources based on group membership via PingOne with approval. - [Workflow Template: Remediate Wiz Alert on Azure VM with Open SSH Access \(Teams\)](https://kb.torq.io/en/articles/9349987-workflow-template-remediate-wiz-alert-on-azure-vm-with-open-ssh-access-teams.md): Whenever an alert is raised on an Azure VM having an open access \(from the internet\) to SSH on port 22, orchestrate remediation. - [Workflow Template: Compliance - Provide temporary Device Admin to Mac users \(JAMF\)](https://kb.torq.io/en/articles/9349998-workflow-template-compliance-provide-temporary-device-admin-to-mac-users-jamf.md): Receive a request over Slack for temporary assignment of admin permissions. Get approval from Security channel, update policy on Jamf. - [Workflow Template: Enable AWS S3 Bucket Encryption on Alert from Wiz](https://kb.torq.io/en/articles/9350003-workflow-template-enable-aws-s3-bucket-encryption-on-alert-from-wiz.md): Receive a Wiz issue on an AWS S3 bucket with encryption disabled, lookup owner tag, ask owner or channel to enable AWS256 encryption. - [Workflow Template: Enable AWS S3 Bucket Versioning on Alert from Wiz](https://kb.torq.io/en/articles/9350013-workflow-template-enable-aws-s3-bucket-versioning-on-alert-from-wiz.md): Receive an alert from Wiz on an AWS S3 bucket with versioning disabled, lookup owner tag, ask owner or channel to enable versioning. - [Workflow Template: Handle Suspicious AWS Console Logins \(AWS SNS\)](https://kb.torq.io/en/articles/9350016-workflow-template-handle-suspicious-aws-console-logins-aws-sns.md): Check source IP of the login session, verify with user if suspicious or malicious. If acknowledged - log a ticket. Otherwise - remediate. - [Workflow Template: Disable and Contain a Specific User in Entra ID \(ex-Azure AD\)](https://kb.torq.io/en/articles/9350019-workflow-template-disable-and-contain-a-specific-user-in-entra-id-ex-azure-ad.md): Workflow and nested workflow that can be used to disable a specific user in Entra ID when an account is compromised. - [Workflow Template: Update Jira Status/User on Device with CVE Tag \(Armis\)](https://kb.torq.io/en/articles/9350022-workflow-template-update-jira-status-user-on-device-with-cve-tag-armis.md): Query Armis for devices with a specific tag where a vulnerability was found in a previous workflow and update Jira and user on the status. - [Workflow Template: Disable a Specific User in Google Cloud Identity](https://kb.torq.io/en/articles/9350025-workflow-template-disable-a-specific-user-in-google-cloud-identity.md): Workflow and nested workflow that can be used to disable a specific user in Google Cloud Identity when an account is compromised. - [Workflow Template: Handle AWS Security Group with Open SSH Access on Orca Alert](https://kb.torq.io/en/articles/9350033-workflow-template-handle-aws-security-group-with-open-ssh-access-on-orca-alert.md): Whenever an Orca alert is raised on an AWS security group with an open access \(from the internet\) to SSH, orchestrate remediation. - [Workflow Template: Enable AWS S3 Bucket Encryption on Alert \(PrismaCloud\)](https://kb.torq.io/en/articles/9350042-workflow-template-enable-aws-s3-bucket-encryption-on-alert-prismacloud.md): Receive PrismaCloud alert on an AWS S3 bucket with encryption disabled, lookup owner tag, ask owner or channel to enable AES256 encryption. - [Workflow Template: Analyze Files in Netskope Sandbox with Cache](https://kb.torq.io/en/articles/9350044-workflow-template-analyze-files-in-netskope-sandbox-with-cache.md): Submit a file using a Webform to Netskope Sandbox for malware analysis. - [Workflow Template: Handle AWS S3 Bucket Allows HTTP Requests on Wiz Alert](https://kb.torq.io/en/articles/9350050-workflow-template-handle-aws-s3-bucket-allows-http-requests-on-wiz-alert.md): Receive an issue from Wiz on an AWS S3 bucket no being compliant, apply a default AWS S3 bucket policy to remediate. - [Workflow Template: Add Phishing Domain to CloudFlare ZeroTrust \(IntSights\)](https://kb.torq.io/en/articles/9350052-workflow-template-add-phishing-domain-to-cloudflare-zerotrust-intsights.md): Poll alerts in IntSights for High level Phishing issues. Ask a Slack channel if the domain should be added to the CloudFlare Zero Trust List - [Workflow Template: Remediate AWS VPC Created without Flow Logs with Orca](https://kb.torq.io/en/articles/9350059-workflow-template-remediate-aws-vpc-created-without-flow-logs-with-orca.md): Receive an alert on an AWS VPC created without Flow Logs. Reach out to the owner, suggest remediation and define Flow Logs in AWS. - [Workflow Template: Remediate AWS EC2 Instance with Open SSH Access from Wiz Alert](https://kb.torq.io/en/articles/9350063-workflow-template-remediate-aws-ec2-instance-with-open-ssh-access-from-wiz-alert.md): Whenever an alert is raised on an AWS EC2 Instance having an open access \(from the internet\) for SSH, orchestrate remediation. - [Workflow Template: Block Domain Finding on PerceptionPoint \(IntSights\)](https://kb.torq.io/en/articles/9350065-workflow-template-block-domain-finding-on-perceptionpoint-intsights.md): Poll alerts in IntSights for High level Phishing issues. Ask a Slack channel if the domain should be blocked in PerceptionPoint's blocklist - [Workflow Template: Open a TheHive case triggered by SentinelOne findings](https://kb.torq.io/en/articles/9350066-workflow-template-open-a-thehive-case-triggered-by-sentinelone-findings.md): Retrieve latest threats from SentinelOne and enrich using third party vendors, open a case at TheHIVE with observables, tasks and TTPs. - [Workflow Template: Request Justification of Integration from Astrix Finding](https://kb.torq.io/en/articles/9350072-workflow-template-request-justification-of-integration-from-astrix-finding.md): Add business context to new Astrix high-risk integrations by asking the owner to elaborate on the purpose of the integration by email. - [Workflow Template: Detected RDP session from Server to External IP \(Armis\)](https://kb.torq.io/en/articles/9350074-workflow-template-detected-rdp-session-from-server-to-external-ip-armis.md): Receive an event from Armis on a Network Policy Violation, lookup source/destination/user information and open Jira ticket and alert user. - [Workflow Template: Add/Del \(IPs/Ranges/Subnets\) from Okta BlockedIpZone \(Okta\)](https://kb.torq.io/en/articles/9350084-workflow-template-add-del-ips-ranges-subnets-from-okta-blockedipzone-okta.md): Receive Slack command to add/del ip/range/subnet from the Okta BlockedIPZone, verify IP's and get approval from admin to update. - [Workflow Template: Hunt for specific CVE and Attempt Remediation \(Armis\)](https://kb.torq.io/en/articles/9350086-workflow-template-hunt-for-specific-cve-and-attempt-remediation-armis.md): Query Armis for specific CVE to look for threat, query information from Armis and Jamf, place device into Jamf patch group and notify user. - [Workflow Template: Just-in-time access to Group Membership in AzureAD by TEAMS](https://kb.torq.io/en/articles/9350085-workflow-template-just-in-time-access-to-group-membership-in-azuread-by-teams.md): Triggers on a Teams command where a user asks for temporary access to applications based on group membership via Azure AD with approval. - [Workflow Template: Just in Time AWS Access with Slack Approval Flow \(Britive\)](https://kb.torq.io/en/articles/9350087-workflow-template-just-in-time-aws-access-with-slack-approval-flow-britive.md): Request temporary access to AWS via Britive using Slack. Approval via a Slack channel and up to 8 hours of access with reminders every hour - [Workflow Template: Advanced Upload of the Latest Recorded Future IOCs to Cybereason](https://kb.torq.io/en/articles/9350088-workflow-template-advanced-upload-of-the-latest-recorded-future-iocs-to-cybereason.md): Pull latest Hashes, IPs and Domains above a specific risk score from Recorded Future and add to the Cybereason reputation list. - [Workflow Template: Request User Account Unlock in JumpCloud](https://kb.torq.io/en/articles/9350093-workflow-template-request-user-account-unlock-in-jumpcloud.md): Request an unlock of the users account in JumpCloud by sending a Slack Slash command and verifying the user and lock status. - [Workflow Template: Jira Enrichment for Hashes Found in Issue Description](https://kb.torq.io/en/articles/9350094-workflow-template-jira-enrichment-for-hashes-found-in-issue-description.md): Enrich hashes found in Jira issue description when a new comment is added to the issue with a specific keyword. Triggered by Jira automation - [Workflow Template: Add and Remove URLs from the Global Blacklist \(Zscaler\)](https://kb.torq.io/en/articles/9350095-workflow-template-add-and-remove-urls-from-the-global-blacklist-zscaler.md): Triggers from Slack message for check url or remove url for the Global Blacklist for Zscaler. On a check url, the URL category is provided. - [Workflow Template: Isolate an AWS EC2 Instance by using tags](https://kb.torq.io/en/articles/9350099-workflow-template-isolate-an-aws-ec2-instance-by-using-tags.md): When applying a specific Key:Value tag on an EC2 instance, apply a isolation security group and remove IAM Instance Role and apply new role - [Workflow Template: Enable Encryption on AWS S3 Bucket on Alert from Orca](https://kb.torq.io/en/articles/9350101-workflow-template-enable-encryption-on-aws-s3-bucket-on-alert-from-orca.md): Receive an Orca alert on an AWS S3 bucket with encryption disabled, lookup owner tag, ask owner or channel to enable AES256 encryption. - [Workflow Template: Request Just-in-Time Access to SSO Applications in JumpCloud](https://kb.torq.io/en/articles/9350104-workflow-template-request-just-in-time-access-to-sso-applications-in-jumpcloud.md): Trigger on a Slack command where a user asks for temporary access to applications based on group membership via JumpCloud with approval. - [Workflow Template: Handle Orca Alert for IAM Role with Admin Permissions](https://kb.torq.io/en/articles/9350107-workflow-template-handle-orca-alert-for-iam-role-with-admin-permissions.md): Receive an Orca alert on excessive policies / permissions attached to an IAM Role. Update owner or channel via Slack. - [Workflow Template: Request AWS Credentials Based on Jira Assignment \(Britive\)](https://kb.torq.io/en/articles/9350108-workflow-template-request-aws-credentials-based-on-jira-assignment-britive.md): Receive a mention via Slack for Jira-Access with a Jira issue key. Provide access to the AWS account ID listed in the Jira issue via Slack. - [Workflow Template: Notify Project Owners of 5 or more Critical Issues in Snyk](https://kb.torq.io/en/articles/9350122-workflow-template-notify-project-owners-of-5-or-more-critical-issues-in-snyk.md): Poll the projects for an organization in Snyk and create Jira issues when a project is found to have 5 or more critical issues. - [Workflow Template: Handle IAC Configuration Issues in Snyk and Notify Owner](https://kb.torq.io/en/articles/9350125-workflow-template-handle-iac-configuration-issues-in-snyk-and-notify-owner.md): Get latest configuration issues from projects in an organization, open a Jira issue if one does not exist and notify the project owner. - [Workflow Template: Enable AWS S3 Bucket Versioning on Lacework Alert](https://kb.torq.io/en/articles/9350126-workflow-template-enable-aws-s3-bucket-versioning-on-lacework-alert.md): On an alert received from Lacework for S3 bucket versioning, pull the event, ask Slack user or channel to enable versioning. - [Workflow Template: Handle High Level CNC Threat Detected on Network \(Armis\)](https://kb.torq.io/en/articles/9350127-workflow-template-handle-high-level-cnc-threat-detected-on-network-armis.md): Receive alert from Armis on a CNC DNS query, pull details about the device, open Jira issue, and alert the channel or user via Slack/Email - [Workflow Template: Remediate Wiz Alert on Azure VM with Open SSH Access \(Slack\)](https://kb.torq.io/en/articles/9350128-workflow-template-remediate-wiz-alert-on-azure-vm-with-open-ssh-access-slack.md): Whenever an alert is raised on an Azure VM having an open access \(from the internet\) to SSH on port 22, orchestrate remediation. - [Workflow Template: Remediate Alerts from Rules to External Address Adaptive Shield](https://kb.torq.io/en/articles/9350129-workflow-template-remediate-alerts-from-rules-to-external-address-adaptive-shield.md): Remediate Adaptive Shield alerts generated from Outlook inboxes with email rules that forward email to external addresses using Slack - [Workflow Template: Okta Exposed Passwords in Failed Login Attempts](https://kb.torq.io/en/articles/9350134-workflow-template-okta-exposed-passwords-in-failed-login-attempts.md): Uncover possible exfiltrated credentials in Okta when a user accidentally inputs a password in the email field and is stored as clear text. - [Workflow Template: Disable and Contain a Specific Compromised User in Okta](https://kb.torq.io/en/articles/9350135-workflow-template-disable-and-contain-a-specific-compromised-user-in-okta.md): Workflow and nested workflow that can be used to disable a specific user in Okta when an account is found to be compromised. - [Workflow Template: Handle AWS S3 Bucket Should Enforce HTTPS Alert from Orca](https://kb.torq.io/en/articles/9350139-workflow-template-handle-aws-s3-bucket-should-enforce-https-alert-from-orca.md): Receive an Orca alert on an AWS S3 Bucket not being compliant, apply a default S3 bucket policy to remediate. - [Workflow Template: Create Exclusions on Multiple SentinelOne Sites](https://kb.torq.io/en/articles/9350143-workflow-template-create-exclusions-on-multiple-sentinelone-sites.md): Creates Exclusions for a list of path, browser or filetype Items. Exclusions can be created in one site or in multiple sites. - [Workflow Template: Notify on Google Drive Files Containing PII Identified by BigID](https://kb.torq.io/en/articles/9350151-workflow-template-notify-on-google-drive-files-containing-pii-identified-by-bigid.md): On a trigger from BigID on findings of files in Google Drive that contain PII, notify the file owner via Slack and open Jira issues. - [Workflow Template: Delete an IAM User Account](https://kb.torq.io/en/articles/9350170-workflow-template-delete-an-iam-user-account.md): This workflow automates the procedure to delete or detach items from an user before deleting an IAM User Account. - [Workflow Template: Detect impossible travels in Okta logins](https://kb.torq.io/en/articles/9350172-workflow-template-detect-impossible-travels-in-okta-logins.md): Analyzes users' successful logins from different locations within a short timeframe to detect possible Impossible Travel escenarios. - [Workflow Template: Microsoft Teams Driven User Account Management Action Menu](https://kb.torq.io/en/articles/9350173-workflow-template-microsoft-teams-driven-user-account-management-action-menu.md): Displays a menu for User Management related activities such as Reset Password, Enable/Disable a User or Get User Information. - [Workflow Template: Whitelist SHA1 Hashes on Multiple SentinelOne Sites](https://kb.torq.io/en/articles/9350178-workflow-template-whitelist-sha1-hashes-on-multiple-sentinelone-sites.md): Whitelist a list of Hashes in one or multiple sites, if no Site list is provided, Hashes are added to all active sites. - [Workflow Template: Handle Wiz Alert for Public Azure Container with Sensitive Data](https://kb.torq.io/en/articles/9350181-workflow-template-handle-wiz-alert-for-public-azure-container-with-sensitive-data.md): On trigger from Wiz alert for an Azure Container containing sensitive data, ask a Slack channel or container owner to limit public access - [Workflow Template: Blacklist SHA1 Hashes on Multiple SentinelOne Sites](https://kb.torq.io/en/articles/9350183-workflow-template-blacklist-sha1-hashes-on-multiple-sentinelone-sites.md): Blacklists a list of Hashes in one site or multiple sites, if no Site list is provided, Hashes are added to all active sites. - [Workflow Template: Just-in-time access to Group Membership in AzureAD](https://kb.torq.io/en/articles/9350184-workflow-template-just-in-time-access-to-group-membership-in-azuread.md): Trigger on a Slack command where a user asks for temporary access to applications based on group membership via Azure AD with approval. - [Workflow Template: Handle Wiz Alert for Public AWS S3 Bucket with Sensitive Data](https://kb.torq.io/en/articles/9350185-workflow-template-handle-wiz-alert-for-public-aws-s3-bucket-with-sensitive-data.md): On trigger from Wiz finding for a AWS S3 bucket containing sensitive data, ask a Slack channel or bucket owner to limit public access. - [Workflow Template: Just-in-Time \(JIT\) access to Okta SSO Applications by Slack](https://kb.torq.io/en/articles/9350186-workflow-template-just-in-time-jit-access-to-okta-sso-applications-by-slack.md): Slack mention of "JIT-Access" allowing users to ask for a temporary access to applications via Okta SSO, with an approval flow via Slack - [Workflow Template: Handle Gem Alert for NSG With Ingress From Any \(0.0.0.0/0\)](https://kb.torq.io/en/articles/9350188-workflow-template-handle-gem-alert-for-nsg-with-ingress-from-any-0-0-0-0-0.md): Workflow triggers when a rule with open access to the internet is created for a security group. - [Workflow Template: Enrich SentinelOne Incident with Threat Intelligence from Intezer](https://kb.torq.io/en/articles/9350191-workflow-template-enrich-sentinelone-incident-with-threat-intelligence-from-intezer.md): Trigger from a Singularity Webhook on a new threat and provide threat enrichment from Intezer with optional Live Agent Endpoint Scan - [Workflow Template: Threat Hunt for a Specified SHA1 Signature in SingularityXDR](https://kb.torq.io/en/articles/9350196-workflow-template-threat-hunt-for-a-specified-sha1-signature-in-singularityxdr.md): Receive a file signature from Slack and hunt for the signature in Singularity XDR, notify owners of the endpoint, kick off scan of devices. - [Workflow Template: Analyze URLs and Files in Triage Sandbox](https://kb.torq.io/en/articles/9350203-workflow-template-analyze-urls-and-files-in-triage-sandbox.md): This workflow submit URLs to Hatching Triage Sandbox for analysis. - [Workflow Template: Create Att&ck Layer from TTP List](https://kb.torq.io/en/articles/9350204-workflow-template-create-att-ck-layer-from-ttp-list.md): Receives a list of TTPs and returns an Att&ck layer in JSON and SVG formats. - [Workflow Template: Download a File from a SentinelOne Endpoint](https://kb.torq.io/en/articles/9350207-workflow-template-download-a-file-from-a-sentinelone-endpoint.md): Downloads a file from a Sentinel One agent given an AgentID a file path and a password. File does not need to be part of an Incident. - [Workflow Template: Analyze URLs and Files in Recorded Future Sandbox](https://kb.torq.io/en/articles/9350233-workflow-template-analyze-urls-and-files-in-recorded-future-sandbox.md): This workflow submit URLs to Recorded Future Sandbox for analysis. - [Workflow Template: Just-in-time \(JIT\) access to Okta Groups via Slack](https://kb.torq.io/en/articles/9350245-workflow-template-just-in-time-jit-access-to-okta-groups-via-slack.md): Slack mention of JIT-Group allowing users to ask for a temporary access to Okta groups with approval flow via a Slack channel - [Workflow Template: Handle Gem Alert for EC2 Instance "Write" Actions on IAM Entities](https://kb.torq.io/en/articles/9350270-workflow-template-handle-gem-alert-for-ec2-instance-write-actions-on-iam-entities.md): Creates an snapshot of each EC2 volume when a EC2InstanceWriteActionsOnIAM alert from Gem Security is triggered. - [Workflow Template: Handle Gem Alert for Root Usage](https://kb.torq.io/en/articles/9350287-workflow-template-handle-gem-alert-for-root-usage.md): Receives an alert for a recent usage of Root credentials and validates it with the user trough Slack - [Workflow Template: Just-in-time access to Group Membership in Entra ID by TEAMS](https://kb.torq.io/en/articles/9838688-workflow-template-just-in-time-access-to-group-membership-in-entra-id-by-teams.md): Triggers on a Teams command where a user asks for temporary access to applications based on group membership via Entra ID with approval. - [Workflow Template: Just-in-time access to Group Membership in Entra ID \(ex-Azure AD\)](https://kb.torq.io/en/articles/9838963-workflow-template-just-in-time-access-to-group-membership-in-entra-id-ex-azure-ad.md): Trigger on a Slack command where a user asks for temporary access to applications based on group membership via Entra ID with approval. - [Workflow Template: Notify when a Thinkst Canary Token is triggered](https://kb.torq.io/en/articles/9941516-workflow-template-notify-when-a-thinkst-canary-token-is-triggered.md): Triggers upon a Thinkst Canary token activation, sends a Slack notification, and opens a case with relevant data, including a static map. - [Workflow Template: Create Cases from Crowdstrike Detections found in Splunk](https://kb.torq.io/en/articles/9955192-workflow-template-create-cases-from-crowdstrike-detections-found-in-splunk.md): Query Splunk for new Crowdstrike detections and create Torq cases for events that are detected including host and user details. - [Workflow Template: Create Cases from SentinelOne Events found in Azure Sentinel](https://kb.torq.io/en/articles/9968947-workflow-template-create-cases-from-sentinelone-events-found-in-azure-sentinel.md): Search on a schedule for SentinelOnes detections in Azure Sentinel and open a Torq case for each alert and threat. - [Workflow Template: Create Torq Cases from SentinelOne Threats Reported in Chronicle](https://kb.torq.io/en/articles/10005543-workflow-template-create-torq-cases-from-sentinelone-threats-reported-in-chronicle.md): On a schedule query Google Chronicle for new SentinelOne threats and open a Torq case with the relevant agent and threat details - [Workflow Template: Query for user MFA fraud reports on Entra ID](https://kb.torq.io/en/articles/10025892-workflow-template-query-for-user-mfa-fraud-reports-on-entra-id.md): On schedule, query the Entra ID audit logs for fraud reports from users who declined an MFA request on the Microsoft Authenticator App. - [Workflow Template: Initial Microsoft Defender for Endpoint Case Creation](https://kb.torq.io/en/articles/11684937-workflow-template-initial-microsoft-defender-for-endpoint-case-creation.md): Fetch alert details by supplying an alert id and create a case using the field mapping nested workflow. - [Workflow Template: Poll for New Microsoft Defender for Endpoint Events for Cases](https://kb.torq.io/en/articles/11684945-workflow-template-poll-for-new-microsoft-defender-for-endpoint-events-for-cases.md): Automatically pull new Microsoft Defender for Endpoint alerts on a schedule, then create cases with a field mapper. - [Workflow Template: Use AI to Create Torq Case from Anvilogic Alerts](https://kb.torq.io/en/articles/11684948-workflow-template-use-ai-to-create-torq-case-from-anvilogic-alerts.md): Use Anvilogic Copilot, to analyze Anvilogic alerts and create cases in Torq. - [Workflow Template: AI Event Triage with Anvilogic Copilot](https://kb.torq.io/en/articles/11684949-workflow-template-ai-event-triage-with-anvilogic-copilot.md): Use Anvilogic Copilot, to analyze a Threat Identifier’s Event of Interest \(EOI\). - [Workflow Template: Initial Intezer Case Creation](https://kb.torq.io/en/articles/11767199-workflow-template-initial-intezer-case-creation.md): Takes a raw JSON alert as an input to create an Intezer case using the field mapping nested workflow. - [Workflow Template: Create Intezer Case from Trigger Alert](https://kb.torq.io/en/articles/11767201-workflow-template-create-intezer-case-from-trigger-alert.md): Receives alerts from Intezer trigger and creates a case via a field mapper. It adds QuickAction notes and an initial Runbook. - [Workflow Template: Poll Microsoft Outlook on a Schedule for New Messages for Cases](https://kb.torq.io/en/articles/11767206-workflow-template-poll-microsoft-outlook-on-a-schedule-for-new-messages-for-cases.md): Automatically pull new messages from Outlook on a schedule, extract its components, enrich observables and create cases with a field mapper. - [Workflow Template: Poll for new SentinelOne Threats and Open a Torq Case](https://kb.torq.io/en/articles/11767207-workflow-template-poll-for-new-sentinelone-threats-and-open-a-torq-case.md): Automatically pull new SentinelOne alerts on a schedule, then create cases using the field mapping nested workflow. - [Workflow Template: Poll for new CrowdStrike Alerts and Open a Torq Case](https://kb.torq.io/en/articles/11767211-workflow-template-poll-for-new-crowdstrike-alerts-and-open-a-torq-case.md): Automatically pull new CrowdStrike alerts on a schedule, then deduplicate alerts and create cases with a field mapper. - [Workflow Template: Initial CrowdStrike Case Creation](https://kb.torq.io/en/articles/11767212-workflow-template-initial-crowdstrike-case-creation.md): Receives an alert event from CrowdStrike and creates a case with Torq using the field mapping nested workflow. - [Workflow Template: Initial SentinelOne Case Creation](https://kb.torq.io/en/articles/11767216-workflow-template-initial-sentinelone-case-creation.md): Receives an alert event from SentinelOne and creates a case with Torq using the field mapping nested workflow. - [Workflow Template: Create Case from Microsoft Sentinel Incident](https://kb.torq.io/en/articles/11782343-workflow-template-create-case-from-microsoft-sentinel-incident.md): Receives alerts from Microsoft Sentinel Trigger and creates a case via a field mapper. - [Workflow Template: QuickAction - Fetch a File from Device on MS Defender Endpoint](https://kb.torq.io/en/articles/12057849-workflow-template-quickaction-fetch-a-file-from-device-on-ms-defender-endpoint.md): Fetch a file from a device on MS Defender Endpoint when a quick action button is pressed. - [Workflow Template: Create a PDF Report for a Torq Case](https://kb.torq.io/en/articles/12062087-workflow-template-create-a-pdf-report-for-a-torq-case.md): Creates a PDF Summary Report for a Torq Case. - [Workflow Template: QuickAction - Run a command on a device with MS Defender Endpoint](https://kb.torq.io/en/articles/12065479-workflow-template-quickaction-run-a-command-on-a-device-with-ms-defender-endpoint.md): Execute commands on a remote endpoint using LiveResponse. - [Workflow Template: Analyze Attachment Files in Sandbox \(QuickAction\)](https://kb.torq.io/en/articles/12146476-workflow-template-analyze-attachment-files-in-sandbox-quickaction.md): Send multiple Password-Protected Attachments to multiple Sandbox Engines to be analyzed. - [Workflow Template: QuickAction - Connect or Disconnect a SentinelOne Agent](https://kb.torq.io/en/articles/12847083-workflow-template-quickaction-connect-or-disconnect-a-sentinelone-agent.md): Quickly connect or disconnect SentinelOne agents using a single QuickAction command. - [Workflow Template: Runner inspect and regenerate](https://kb.torq.io/en/articles/12941775-workflow-template-runner-inspect-and-regenerate.md): Analyzes the output from docker inspect and generates a new installation command which includes both standard and customized parameters. - [Workflow Template: QuickAction - Run a RemoteScript on a device with SentinelOne](https://kb.torq.io/en/articles/12941776-workflow-template-quickaction-run-a-remotescript-on-a-device-with-sentinelone.md): Execute a RemoteScript on a remote device as a response to a QuickAction button. - [Workflow Template: Run remote script on devices with SentinelOne Agent](https://kb.torq.io/en/articles/12950712-workflow-template-run-remote-script-on-devices-with-sentinelone-agent.md): This Function enables the builder to enhance the remediation and threat hunting features by executing remote scripts on devices. - [Workflow Template: Sync Torq case with ServiceNow ticket via webhook](https://kb.torq.io/en/articles/12980625-workflow-template-sync-torq-case-with-servicenow-ticket-via-webhook.md): This workflow keeps cases synchronized between ServiceNow and Torq by mirroring changes made in ServiceNow to a corresponding Torq case - [Workflow Template: Socrates Tool - List Remote Scripts in SentinelOne](https://kb.torq.io/en/articles/12990513-workflow-template-socrates-tool-list-remote-scripts-in-sentinelone.md): List the available remote scripts for a specific platform in SentinelOne so that Socrates can choose the best script to perform RemoteOps. - [Workflow Template: Socrates Tool - Run a RemoteScript on a device with SentinelOne](https://kb.torq.io/en/articles/12990516-workflow-template-socrates-tool-run-a-remotescript-on-a-device-with-sentinelone.md): Enable Socrates to run remote scripts by analyzing their parameters and automatically generating the required values. - [Workflow Template: Socrates Tool - Scan Device on SentinelOne](https://kb.torq.io/en/articles/13001233-workflow-template-socrates-tool-scan-device-on-sentinelone.md): Enable Socrates to start a Full Disk Scan action on the device under investigation. - [Workflow Template: Socrates Tool - Attach a Password-protected File to a Case](https://kb.torq.io/en/articles/13019332-workflow-template-socrates-tool-attach-a-password-protected-file-to-a-case.md): This workflow provides Socrates with the ability to download any file from an URL and attach it to a case as a password protected file. - [Workflow Template: Decode Safe Links](https://kb.torq.io/en/articles/13165675-workflow-template-decode-safe-links.md): Decodes a list of Proofpoint, Barracuda, and Microsoft SafeLink URLs. - [Workflow Template: Socrates Tool - Decode Safe Links](https://kb.torq.io/en/articles/13184003-workflow-template-socrates-tool-decode-safe-links.md): Decode Proofpoint, Barracuda, and Microsoft SafeLink URL and query it against observables. - [Workflow Template: Query Jira Issues with pagination](https://kb.torq.io/en/articles/13242601-workflow-template-query-jira-issues-with-pagination.md): Search for Jira issues using Jira Query Language, handle paginated results, and transform the raw data into a clean, standardized format. - [Workflow Template: Download File From Host Using CrowdStrike RTR with Socrates](https://kb.torq.io/en/articles/13303287-workflow-template-download-file-from-host-using-crowdstrike-rtr-with-socrates.md): This workflow will take in a file path and device ID optionally and return a temporary URL to download the file - [Workflow Template: Manage containment on a device in CrowdStrike](https://kb.torq.io/en/articles/13303335-workflow-template-manage-containment-on-a-device-in-crowdstrike.md): This workflow is meant to be used as a nested workflow that will either contain or lift containment on a device in CrowdStrike - [Workflow Template: QuickAction - Download File From Host Using CrowdStrike RTR](https://kb.torq.io/en/articles/13303385-workflow-template-quickaction-download-file-from-host-using-crowdstrike-rtr.md): This workflow takes in a file path and returns a temporary URL to download the file using the CrowdStrike Real Time Response API. - [Workflow Template: Scan Device in CrowdStrike](https://kb.torq.io/en/articles/13303402-workflow-template-scan-device-in-crowdstrike.md): This workflow will initiate a scan for a machine associated to a CrowdStrike case. - [Workflow Template: QuickAction - Run Command on CrowdStrike Host](https://kb.torq.io/en/articles/13333244-workflow-template-quickaction-run-command-on-crowdstrike-host.md): Run common commands against the host of an associated case using CrowdStrike Real Time Response. - [Workflow Template: Track Supplier-Risk-Score Daily](https://kb.torq.io/en/articles/13584416-workflow-template-track-supplier-risk-score-daily.md): Uses the Panorays platform to track drops in suppliers risk score and notifies the security team using slack. - [Workflow Template: Vendor Gap Detection](https://kb.torq.io/en/articles/13615751-workflow-template-vendor-gap-detection.md): Extracts vendors from Torq cases and checks Panorays to see if they are in the company’s supplier list. - [Workflow Template: Manage Cloud-Resource-Tags in AWS](https://kb.torq.io/en/articles/13615755-workflow-template-manage-cloud-resource-tags-in-aws.md): Tag AWS Resources when and Issue is found by Cyera. - [Workflow Template: Create Security-Cases from Cyera](https://kb.torq.io/en/articles/13615759-workflow-template-create-security-cases-from-cyera.md): Create Torq case from Cyera issues via webhook. - [Workflow Template: Sync Torq to Jira via webhook](https://kb.torq.io/en/articles/13682255-workflow-template-sync-torq-to-jira-via-webhook.md): This workflow monitors a Jira issue board and keeps your cases in Torq synchronized with changes in Jira. - [Workflow Template: Moving Sensitive Data from Ghost accounts](https://kb.torq.io/en/articles/13682258-workflow-template-moving-sensitive-data-from-ghost-accounts.md): Addresses the discovery of sensitive data within "ghost" or unauthorized/unmanaged OneDrive accounts. - [Workflow Template: Remove public access to sensitive files in Google Drive](https://kb.torq.io/en/articles/13712298-workflow-template-remove-public-access-to-sensitive-files-in-google-drive.md): Remove public access permission from exposed files in Google Drive detected by Cyera. - [Workflow Template: War-Room Orchestrator HyperAgent](https://kb.torq.io/en/articles/14057228-workflow-template-war-room-orchestrator-hyperagent.md): Automates initial Incident Response coordination by opening an Slack Channel for confirmed true positive security cases. - [Workflow Template: Automated Investigation Environment Provisioning](https://kb.torq.io/en/articles/14133555-workflow-template-automated-investigation-environment-provisioning.md): Automatically provision a Replica Cyber investigation environment when a new Torq case is created. - [Workflow Template: Automated Workload Quarantine on Security Event](https://kb.torq.io/en/articles/14133557-workflow-template-automated-workload-quarantine-on-security-event.md): Automatically quarantine threatening IPs when Illumio error events exceed a configured threshold, with policy provisioning and Slack alerts. - [Workflow Template: Analyze URL with HyperAgent](https://kb.torq.io/en/articles/14133564-workflow-template-analyze-url-with-hyperagent.md): HyperAgent scans suspicious URLs for phishing: decodes, defangs, checks infrastructure, inspects content, scores risk with OCSF output. - [Workflow Template: QuickAction - Query Device Timeline on MS Defender for Endpoint](https://kb.torq.io/en/articles/14334512-workflow-template-quickaction-query-device-timeline-on-ms-defender-for-endpoint.md): Enables security analysts to search and investigate device timeline events across 8 Defender Advanced Hunting tables. - [Workflow Template: Microsoft Defender for Endpoint Triage HyperAgent](https://kb.torq.io/en/articles/14468411-workflow-template-microsoft-defender-for-endpoint-triage-hyperagent.md): Automates MS Defender triage by running multi-step threat hunting on evidence and correlation between alerts, incidents and torq cases. - [Workflow Template: Initial CrowdStrike Streaming Case Creation](https://kb.torq.io/en/articles/14468412-workflow-template-initial-crowdstrike-streaming-case-creation.md): Receives an alert event from CrowdStrike Streaming integration to create a case with Torq using the field mapping nested workflow. - [Workflow Template: AI Case Summary Generator](https://kb.torq.io/en/articles/14608237-workflow-template-ai-case-summary-generator.md): Generates a structured AI narrative from case details for routing to downstream tools. - [Workflow Template: Suspend User on Cyberhaven Incident](https://kb.torq.io/en/articles/14685448-workflow-template-suspend-user-on-cyberhaven-incident.md): Suspend users in Okta when Cyberhaven incidents hit severity or cumulative thresholds, with risk group tagging and Slack alerts. - [Workflow Template: Dormant Account Remediation HyperAgent for EntraID](https://kb.torq.io/en/articles/14717183-workflow-template-dormant-account-remediation-hyperagent-for-entraid.md): Detects and remediates dormant user accounts in Entra ID through a two-agent workflow with Slack-based approval and full case tracking. - [Workflow Template: Initial SentinelOne Case Creation from DataConnector](https://kb.torq.io/en/articles/14851797-workflow-template-initial-sentinelone-case-creation-from-dataconnector.md): Creates a case from Threats and Alerts received from the SentinelOne DataConnector. - [Workflow Template: Enrich Case with Threat Intelligence Data - ANY.RUN TI Lookup](https://kb.torq.io/en/articles/15027756-workflow-template-enrich-case-with-threat-intelligence-data-any-run-ti-lookup.md): Look up case observables \(IPs, URLs, hostnames, hashes\) in ANY.RUN TI and enrich the Torq Case with verdicts and reputation. - [Workflow Template: Analyze Files with ANY.RUN Sandbox](https://kb.torq.io/en/articles/15027760-workflow-template-analyze-files-with-any-run-sandbox.md): Submit a file download URL to ANY.RUN Sandbox for analysis and receive a structured JSON report with verdict, IoCs, and summary. - [Workflow Template: Analyze URLs with ANY.RUN Sandbox](https://kb.torq.io/en/articles/15027767-workflow-template-analyze-urls-with-any-run-sandbox.md): Submit a URL to ANY.RUN Sandbox for analysis and receive a structured JSON report with verdict, IoCs, and enrichment summary. - [Workflow Template: Enrich Case with File Analysis in ANY.RUN Sandbox](https://kb.torq.io/en/articles/15027772-workflow-template-enrich-case-with-file-analysis-in-any-run-sandbox.md): Detonate a file attachment from a Torq Case in ANY.RUN Sandbox and enrich the case with verdict, IoCs, HTML report, and notes. - [Workflow Template: Enrich Case with URL Analysis in ANY.RUN Sandbox](https://kb.torq.io/en/articles/15027776-workflow-template-enrich-case-with-url-analysis-in-any-run-sandbox.md): Detonate a URL observable from a Torq Case in ANY.RUN Sandbox and enrich the case with verdict, IoCs, HTML report, and notes. - [Workflow Template: Working with Excel files \(not M365\)](https://kb.torq.io/en/articles/15201433-workflow-template-working-with-excel-files-not-m365.md): Natively work with Excel Files in Torq by importing or exporting data. - [Workflow Template: Initial MS Defender Incident Case Creation from Data Connector](https://kb.torq.io/en/articles/15258632-workflow-template-initial-ms-defender-incident-case-creation-from-data-connector.md): Natively create Torq Cases from Microsoft Defender XDR incidents via a data connector trigger. - [Workflow Template: Initial MS Defender Alert Case Creation from Data Connector](https://kb.torq.io/en/articles/15271220-workflow-template-initial-ms-defender-alert-case-creation-from-data-connector.md): Natively create Torq Cases from Microsoft Defender XDR alerts via a data connector trigger. - [Workflow Template: Search/Update/Delete Dynamic Resolution Reasons in Torq Cases](https://kb.torq.io/en/articles/15357947-workflow-template-search-update-delete-dynamic-resolution-reasons-in-torq-cases.md): This workflow is the primary mechanism for cleaning up and maintaining your Dynamic Resolution Reason list. - [Workflow Template: Endpoint Persistence Threat Hunting via Microsoft Defender XDR](https://kb.torq.io/en/articles/15561052-workflow-template-endpoint-persistence-threat-hunting-via-microsoft-defender-xdr.md): Runs Threat Hunting KQL queries in Microsoft Defender XDR to detect host-based persistence techniques across endpoints. - [Workflow Template: Query CrowdStrike Next-Gen SIEM](https://kb.torq.io/en/articles/15942563-workflow-template-query-crowdstrike-next-gen-siem.md): Run an ad-hoc CQL search against CrowdStrike Next-Gen SIEM and return the matching events. - [Workflow Template: Create a Torq Case from a Field Mapping JSON](https://kb.torq.io/en/articles/16011156-workflow-template-create-a-torq-case-from-a-field-mapping-json.md): Create a case in Torq using this workflow to take as input a JSON that includes fields and tables to describe an event. - [Workflow Template: Create Process Tree from Microsoft Defender XDR Endpoint Alert](https://kb.torq.io/en/articles/16196327-workflow-template-create-process-tree-from-microsoft-defender-xdr-endpoint-alert.md): Run multiple Threat Hunting Queries to collect data around an alert and build an HTML report with a process tree and related events. - [Workflow Template: QuickAction - Fetch a File from Device on SentinelOne](https://kb.torq.io/en/articles/12889236-workflow-template-quickaction-fetch-a-file-from-device-on-sentinelone.md): Fetch a file from a device on SentinelOne when a quick action button is pressed. - [Workflow Template: Monitor and Handle Gmail Mailbox for Phishing \(Gmail\)](https://kb.torq.io/en/articles/9350029-workflow-template-monitor-and-handle-gmail-mailbox-for-phishing-gmail.md): Monitor a Gmail inbox and scan each message for URL's and attachments to scan with VirusTotal. Label each message with the result. - [Workflow Template: Remove Outlook Forwarding or Redirect Rules on Mention in Teams](https://kb.torq.io/en/articles/9350068-workflow-template-remove-outlook-forwarding-or-redirect-rules-on-mention-in-teams.md): On mention from Microsoft Teams, check the email mailbox for domains that are not permitted for forwarding or redirection of emails. - [Workflow Template: Monitor and Handle Mailbox Folder for Phishing via IMAP](https://kb.torq.io/en/articles/9350078-workflow-template-monitor-and-handle-mailbox-folder-for-phishing-via-imap.md): Monitor and handle emails in an Inbox folder and scan the URLs and attachments via VirusTotal. Report back via Slack and send email result. - [Workflow Template: Request Elevation of Local Admin Privileges in JumpCloud](https://kb.torq.io/en/articles/9350118-workflow-template-request-elevation-of-local-admin-privileges-in-jumpcloud.md): Request an elevation of admin permissions to a system by sending a Slack Slash command and verifying the system and duration of access. - [Workflow Template: Monitor an Outlook Mailbox for Phishing with Recorded Future](https://kb.torq.io/en/articles/9350119-workflow-template-monitor-an-outlook-mailbox-for-phishing-with-recorded-future.md): Scan messages arriving to a specific folder in Outlook with Recorded Future for malicious urls and files. Update category on email results. - [Workflow Template: CVE Search in Wiz, Snyk and Armis with Jira Issue Tracking](https://kb.torq.io/en/articles/9350197-workflow-template-cve-search-in-wiz-snyk-and-armis-with-jira-issue-tracking.md): On mention from Slack, search for CVE in Wiz, Snyk, and Armis. Report on findings in Slack and open and update Jira parent and child issues - [Workflow Template: Monitor an Outlook Mailbox for Phishing via Graph Subscription](https://kb.torq.io/en/articles/9350227-workflow-template-monitor-an-outlook-mailbox-for-phishing-via-graph-subscription.md): Analyze a message arriving to a mailbox in Outlook with VirusTotal for malicious and suspicious URLs and files. Update label on message. - [Workflow Template: AWS Bedrock Usage Examples](https://kb.torq.io/en/articles/9350243-workflow-template-aws-bedrock-usage-examples.md): This workflow demonstrates usage examples of a number of models available through Amazon Bedrock. - [Workflow Template: Monitor and Handle a Gmail Mailbox for Phishing Using OAuth2](https://kb.torq.io/en/articles/9350261-workflow-template-monitor-and-handle-a-gmail-mailbox-for-phishing-using-oauth2.md): Scan messages in a Gmail mailbox with a specific label with VirusTotal for malicious URLs and files. Update label and send email on results - [Workflow Template: Monitor an Outlook Mailbox for Phishing with VirusTotal](https://kb.torq.io/en/articles/9350289-workflow-template-monitor-an-outlook-mailbox-for-phishing-with-virustotal.md): Scan messages arriving to a specific folder in Outlook with VirusTotal for malicious URLs and files. Update the label on email results. - [Workflow Template: Create Case from Microsoft XDR Incident](https://kb.torq.io/en/articles/13615761-workflow-template-create-case-from-microsoft-xdr-incident.md): Creates a parent incident case while each alert generates its own separate case. - [Workflow Template: Export Actionplan with Tools](https://kb.torq.io/en/articles/14816504-workflow-template-export-actionplan-with-tools.md): Exports Socrates Actionplans and runbooks, including associated workflows and agentic tools, from a development to a production workspace. - [Workflow Template: Export Actionplan with Tools \(to Child Workspace\)](https://kb.torq.io/en/articles/14816509-workflow-template-export-actionplan-with-tools-to-child-workspace.md): Exports Socrates Actionplans and runbooks, including associated workflows and agentic tools internally from a parent to a child workspace.