SECOPS

Confirmed Exfil Containment and Remediation Tracker

When an analyst confirms an egress event as exfiltration, this blocks the destination at Cloudflare, files a tracked remediation ticket in Linear.

CategorySecOps
Enginesim
Difficultyintermediate
Triggerwebhook
Steps5
Setup~15 min

How it runs

The automated pipeline, trigger to output.

  • TriggerWebhook: investigation confirmed exfilHTTP webhook
  • LogicValidate verdict, extract destination + IOCs
  • ActionApply Cloudflare block rule on destinationCloudflareCloudflare
  • ActionOpen Linear remediation ticketLinearLinear
  • OutputNotify incident channel on MS TeamsMicrosoft Teams

What it does

Acts on a confirmed verdict: once an analyst marks an egress investigation as true-positive exfiltration, it pushes a block rule for the malicious destination at Cloudflare, opens a Linear remediation ticket pre-populated with the case and IOCs, and alerts the incident channel.

When to use it

Use it as the response stage after triage, when you want confirmed exfil to trigger consistent containment and a tracked remediation owner instead of ad-hoc manual steps. Pairs with the investigation-dossier and IOC-ledger workflows.

How it works

  1. 1A webhook trigger fires when an investigation is marked confirmed exfiltration.
  2. 2A logic step validates the verdict payload and extracts the destination and IOC set.
  3. 3A Cloudflare action applies a block/firewall rule against the malicious destination.
  4. 4A Linear action opens a remediation ticket with the case summary, IOCs, and assigned owner.
  5. 5An MS Teams output notifies the incident channel with containment status and the ticket link.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect HTTP webhookTrigger any URL on agent actions.
  2. 2
    Connect CloudflareWorkers, Pages, R2, KV — the edge stack.
  3. 3
    Connect LinearIssues, projects, cycles, triage.
  4. 4
    Connect Microsoft TeamsChannels, chats, files.
  5. 5
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  6. 6
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  7. 7
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.