01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Core SOC Platform & Case Management |
| 23.6% | 17 16 active |
| SIEM & EDR Alert Ingestion |
| 16.0% | 11 8 active |
| Identity Threat Response — Azure AD Risky Users |
| 14.0% | 11 10 active |
| Alert Enrichment & IOC Investigation |
| 0.0% | 19 19 active |
| DLP Incident Triage |
| 4.1% | 3 3 active |
| Threat Intelligence Curation — H-ISAC |
| 0.0% | 2 1 active |
| EDR Containment & Response |
| 0.0% | 4 4 active |
| Training / Development Workspace | 33,545 executions | 38.4% | 28 27 active |
| Total | 83,978 executions | 100% | 95 88 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep SOC automation at scale. The platform is running at production volume — 25,633 cases closed, 9,322 alerts processed end-to-end, and 6,395 IRP playbooks auto-triggered over 12 months. This represents a fully operational Agentic SOC, not a pilot.
Dual-source alert coverage. Both Rapid7 InsightIDR (SIEM) and CrowdStrike (EPP + IDP) are fully integrated and ingesting in real time. The split between OMI and ACC variants suggests the environment supports a multi-tenant or segmented network model, each with its own alert pipeline.
Identity threat response at continuous coverage. Two parallel polling workflows (OMI and ACC) check Azure AD for risky users every 5 minutes around the clock. With 395 identity events actioned over 12 months, this is one of the highest-value response loops in the environment — particularly critical given the prevalence of identity-based attacks in healthcare.
Dedicated DLP workspace. The DLP incident pipeline is fully operational (2,755 incidents ingested across two intake paths — the original webhook feed plus a newer Outlook-based ACH intake at 474 executions — with 2,231 processed). The DLP workspace carries a complete mirror of the enrichment and response subflow library, providing the same depth of investigation capability as the main SOC workspace.
Healthcare-specific threat intelligence automation. H-ISAC bulletin processing is live and tracked. Processing sector-specific threat intel automatically — without analyst mailbox monitoring — is a differentiator for healthcare security programs operating under regulatory scrutiny.
Sandbox analysis capability is now active. ANY.RUN integration has moved beyond configuration into live use: Run New Analysis - URL-Domains auto-triggers on new URL/Domain observables (19 detonations in the last 12 months) and Get Analysis Report-Auto retrieves and attaches results to cases automatically, enabling detonation-based analysis without analyst intervention.
###
Gaps & Opportunities
Enrichment library has low utilization. The full enrichment library (VirusTotal, AbuseIPDB, URLScan, hash lookups, user lookups across 5+ directories) shows near-zero direct executions, despite high alert volume. This likely indicates enrichment subflows are triggered correctly as part of the main pipeline (via the router) but may not be firing consistently — worth validating that the Subflow - Enrich Observables router is being called for all alert types.
EDR containment playbooks are deployed but unused. CrowdStrike endpoint quarantine, batch RTR, and Palo Alto IOC blocking have 0–2 executions. These are high-value containment actions. If they haven't been tested in a live scenario, a tabletop exercise or controlled red team drill would validate readiness before a real incident requires them.
Identity response resolution rate. Of risky user events detected, 337 were dismissed (false positives) and 57 resolved via case closure — but zero were confirmed as actual compromises via the Confirm Risky User Compromise playbook. This is either a sign of a clean environment or that compromise confirmations are being handled outside Blink (e.g., direct console actions). Closing this loop through Blink would improve audit traceability.
Phishing detection & response not yet active. Response Subflow - Phishing is deployed (in both SOC and DLP workspaces) but has 0 executions. Given that phishing remains a top initial access vector in healthcare, activating automated KnowBe4 simulation filtering and analyst-initiated phishing response workflows would close a visible gap.
Stale case management utility unused. Utility - Close Stale Cases (auto-closes cases inactive for a month) has 0 executions. With 25,633 cases processed, enabling scheduled stale-case cleanup would reduce backlog noise and keep the case queue meaningful.
Integration Ecosystem
| Integration | Coverage Area |
|---|---|
| Rapid7 InsightIDR | SIEM alert ingestion, investigation sync |
| CrowdStrike (EPP + IDP) | EDR alert ingestion, hash/agent enrichment, endpoint isolation, RTR |
| Microsoft Entra ID / Azure AD | Risky user detection, user enrichment, compromise/dismissal writeback |
| Palo Alto Networks | Network-layer IOC blocking |
| Okta | User enrichment, activity search |
| Google Workspace | User enrichment |
| VirusTotal | Hash, IP, URL reputation |
| AbuseIPDB | IP reputation |
| URLScan | URL analysis |
| ANY.RUN | Sandbox detonation (URL + file) |
| WHOIS | IP/domain registration lookup |
| Slack | User enrichment by email |
| GitHub | User identity enrichment |
| Outlook | H-ISAC feed ingestion, error notifications |
| H-ISAC | Healthcare sector threat intelligence |
A Case Management 151,761 cases (12m) | MTTR 7h 49m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management | 132,864 | 132,864 | 128,314 | 4h 20m |
| IT Security Data Protection | 14,737 | 14,737 | 9,240 | 2d 8h |
| Harshal.Surwade@owens-minor.com | 4,151 | 4,151 | 2 | 41m |
| DEMO: ENGINEERING | 9 | 9 | 9 | 4s |
| Nitin.L@owens-minor.com | 3 | 0 | 0 | N/A |
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink | Case Management | 0 | 0 | 0 |
| 2 | Agent Blink | Nitin.L@owens-minor.com | 0 | 0 | 0 |
| 3 | Agent Blink | IT Security Data Protection | 0 | 0 | 0 |
| 4 | Agent Blink | Harshal.Surwade@owens-minor.com | 0 | 0 | 0 |
| 5 | Agent Blink | DEMO: ENGINEERING | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Case Management | 0 |
| Nitin.L@owens-minor.com | 0 |
| IT Security Data Protection | 0 |
| Harshal.Surwade@owens-minor.com | 0 |
| DEMO: ENGINEERING | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Alerts Dashboard | 0 | 0 |
| 2 | Test | 0 | 0 |
| 3 | production: metric dashboard | 0 | 0 |
| 4 | EBR Dashboard | 0 | 0 |
| 5 | Migration Dashboard | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 8 use cases | 87,377 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security cases resolved & closed | 25,633 | Set To Close in UI |
| Security alerts processed end-to-end | 9,322 | Process Alert (SOC) + Process Alert (DLP) |
| Incident response playbooks auto-triggered | 6,395 | Incident Playbook - Generic IRP |
| Rapid7 InsightIDR investigations auto-ingested | 5,778 | Ingest - Rapid7 Insight IDR Alerts |
| Rapid7 investigation links updated on cases | 4 | Update R7 Investigation Link |
| Analyst case notifications dispatched | 3,129 | New Case Notification |
| DLP incidents automatically ingested & triaged | 2,755 | Ingest DLP Incident + Ingest DLP Incident - ACH |
| Rapid7 investigations auto-assigned to case owner | 1,514 | Assign User To Rapid7 Investigation |
| Risky user events reviewed & actioned | 395 | Dismiss Risky User-Case + Risky User Case Closed - Update Azure + Confirm User Safe-Case |
| CrowdStrike EDR/IDP alerts ingested | 265 | Ingest CS-EPP-OMI + Ingest CS-EPP-ACC + Ingest CS-IDP-OMI + Ingest CS-IDP-ACC |
| H-ISAC threat intelligence bulletins processed | 43 | H-ISAC Intel Notifications |
| Cases escalated to next team | 32 | Escalate Case to Next Team |
| Sandbox URL/domain analyses auto-submitted (ANY.RUN) | 19 | Run New Analysis - URL-Domains |
| Lateral movement incidents investigated | 5 | Incident Playbook - Lateral Movement |
| Malicious IOCs blocked on Palo Alto | 2 | Block IOC on Palo Alto |
Use Case Summary
| # | Use Case | Category | Playbooks | Total Executions (12mo) |
|---|---|---|---|---|
| 1 | Core SOC Platform & Case Management | SOC | 22 | 65,090 |
| 2 | SIEM & EDR Alert Ingestion | SOC | 12 | 7,561 |
| 3 | Identity Threat Response — Azure AD Risky Users | SOC | 11 | 23,436 |
| 4 | Alert Enrichment & IOC Investigation | SOC | 36 | 37 |
| 5 | DLP Incident Triage | GRC | 26 | 4,986 |
| 6 | Threat Intelligence Curation — H-ISAC | SOC | 2 | 43 |
| 7 | EDR Containment & Response | SOC | 6 | 2 |
| — | Training / Development Workspace | — | 31 | 11,522 |
| Total | 146 |
Use Cases
1. Core SOC Platform & Case Management
Description: The central orchestration layer for Accendra's security operations. Blink powers the full alert-to-case lifecycle — ingesting observables, executing response playbooks, managing case state, notifying analysts, and closing cases — replacing a manual SOAR workflow with fully automated orchestration.
Business problem solved: Manual triage and case management across multiple security tools creates analyst fatigue, inconsistent documentation, and slow response times. This use case eliminates repetitive mechanical work so analysts focus on investigation and decision-making.
Integrations: Blink Case Management, Rapid7 InsightIDR, CrowdStrike, Outlook/Email
2. SIEM & EDR Alert Ingestion
Description: Automated connectors that pull and normalize security alerts from Rapid7 InsightIDR (SIEM) and CrowdStrike Endpoint Protection/Identity Detection (EDR/IDP) into the Blink case management platform, ensuring every alert is captured, deduplicated, and queued for processing.
Business problem solved: Without automated ingestion, analysts must manually poll SIEM and EDR consoles for new alerts — a slow, error-prone process that introduces coverage gaps. Blink's connectors provide continuous, zero-touch alert capture across all integrated platforms.
Integrations: Rapid7 InsightIDR, CrowdStrike EPP, CrowdStrike IDP, IBM Resilient (legacy migration)
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Ingest - Rapid7 Insight IDR Alerts | 5,778 | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR |
| Assign User To Rapid7 Investigation | 1,514 | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR |
| Update R7 Investigation Link | 4 | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR |
| Ingest - CrowdStrike-EPP-OMI | 156 | SOC | SIEM & log pipeline monitoring, EDR containment & response |
| Ingest - CrowdStrike-EPP - ACC | 77 | SOC | SIEM & log pipeline monitoring, EDR containment & response |
| Ingest - CrowdStrike-IDP-OMI | 20 | SOC | SIEM & log pipeline monitoring, Identity threat response |
| Ingest - CrowdStrike-IDP -ACC | 12 | SOC | SIEM & log pipeline monitoring, Identity threat response |
| Update Rapid7 Insight IDR Alerts | 0 | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR |
| Update Rapid7 Insight IDR - pull investigations polling | 0 | SOC | SIEM & log pipeline monitoring |
| Ingest Legacy Resilient Incidents-updateErrored | 0 | SOC | Case mgmt & SOAR |
| Ingest Legacy Resilient Incidents-1 | 0 | SOC | Case mgmt & SOAR |
| Ingest - CrowdStrike-EPP/IDP legacy1 | 0 | SOC | SIEM & log pipeline monitoring, EDR containment & response |
3. Identity Threat Response — Azure AD Risky Users
Description: Continuous 5-minute polling of Azure Active Directory for risky user events, with automated case creation and structured analyst resolution workflows. When a risky user is flagged, Blink creates a case, notifies the analyst, and surfaces three response actions: dismiss (false positive), confirm compromise, or confirm safe — each syncing the outcome back to Azure AD.
Business problem solved: Identity-based attacks are among the most common initial access vectors in healthcare environments. Automating Azure AD risky user triage ensures near-real-time detection coverage and consistent response, even across off-hours, without requiring analysts to monitor the Azure portal continuously.
Integrations: Microsoft Azure Active Directory (Entra ID), Blink Case Management
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Ingest Risky Alerts Polling-OMI | 11,521* | SOC | Identity threat response |
| Ingest Risky Alerts Polling-ACC | 11,520* | SOC | Identity threat response |
| Dismiss Risky User-Case | 337 | SOC | Identity threat response |
| Risky User Case Closed by User - Update Azure | 57 | SOC | Identity threat response |
| Confirm User Safe-Case | 1 | SOC | Identity threat response |
| Confirm Risky User Compromise-Case | 0 | SOC | Identity threat response |
| Update Risky Alert Case | 0 | SOC | Identity threat response |
| Dismiss Risky User-Alert | 0 | SOC | Identity threat response |
| Confirm User Safe-Alert | 0 | SOC | Identity threat response |
| Confirm Risky User Compromise-Alert | 0 | SOC | Identity threat response |
| Ingest Risky Alerts copy | 0 | SOC | Identity threat response |
*\* Polling infrastructure — each execution is a 5-minute schedule tick, not an individual alert event.*
4. Alert Enrichment & IOC Investigation
Description: A comprehensive library of on-demand and subflow enrichment playbooks that automatically gather threat context on observables — IP addresses, file hashes, URLs, domains, email addresses, and user identities — across threat intelligence platforms and identity directories. Enrichments are triggered automatically as part of the main alert processing pipeline.
Business problem solved: Investigating a security alert manually requires an analyst to run lookups across 8+ tools for every observable. Blink's enrichment library automates this context-gathering in seconds, ensuring analysts arrive at each case with full context already populated.
Integrations: VirusTotal, AbuseIPDB, URLScan, ANY.RUN, WHOIS, CrowdStrike, Okta, Microsoft Entra ID / Azure AD, Google Workspace, Slack, GitHub
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Subflow - Enrich Observables - Main Router | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich Observable | 3 | SOC | Alert enrichment / IOC lookup |
| Subflow - Response - Main Router | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | 1 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 2 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 2 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username - Github | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | 0 | SOC | Alert enrichment / IOC lookup, Identity threat response |
| Get User Information Using Google Workspace | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Github | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Okta | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | 0 | SOC | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | 0 | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | 0 | SOC | Alert enrichment / IOC lookup |
| Okta Search for User Activity | 0 | SOC | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | 0 | SOC | Alert enrichment / IOC lookup |
| Run New Analysis - URL | 1 | SOC | Alert enrichment / IOC lookup |
| Run New Analysis - URL-Domains | 19 | SOC | Alert enrichment / IOC lookup |
| Run New Analysis - File | 0 | SOC | Alert enrichment / IOC lookup |
| Run New Analysis - File copy | 0 | SOC | Alert enrichment / IOC lookup |
| Get Analysis Report | 0 | SOC | Alert enrichment / IOC lookup |
| Get Analysis Report-Auto | 4 | SOC | Alert enrichment / IOC lookup |
| Error Handling - Send Error Notification Email | 0 | SOC | Case mgmt & SOAR |
5. DLP Incident Triage
Description: A dedicated workspace for automated ingestion and initial processing of data loss prevention incidents. Incoming DLP events are automatically structured into cases, observables are extracted, and the full enrichment + response subflow library is available for analyst-driven investigation.
Business problem solved: DLP platforms generate high volumes of incidents that vary widely in severity. Blink automates the ingestion and first-pass triage so analysts work from a normalized, enriched case view rather than raw DLP console events.
Integrations: DLP platform (via webhook), Microsoft Entra ID, Okta, Google Workspace, CrowdStrike, VirusTotal, AbuseIPDB, URLScan, WHOIS, Outlook
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Ingest DLP Incident | 2,281 | GRC | DLP triage & exposure resp |
| Ingest DLP Incident - ACH | 474 | GRC | DLP triage & exposure resp |
| Process Alert (DLP workspace) | 2,231 | GRC | DLP triage & exposure resp |
| send Email | 0 | GRC | DLP triage & exposure resp |
| Utility - Find Similar Cases Based on Observables | 0 | GRC | DLP triage & exposure resp |
| Subflow - Update Enrichment Data | 0 | GRC | DLP triage & exposure resp |
| Get User Information Using Google Workspace | 0 | GRC | DLP triage & exposure resp |
| Get User Information Using Microsoft Entra ID | 0 | GRC | DLP triage & exposure resp |
| Enrich IP or Domain Using Whois | 0 | GRC | DLP triage & exposure resp |
| Response Subflow - Malware | 0 | GRC | DLP triage & exposure resp |
| Response Subflow - Phishing | 0 | GRC | DLP triage & exposure resp |
| Enrich - Hash - VT | 0 | GRC | DLP triage & exposure resp |
| Enrich - URL - URLScan | 0 | GRC | DLP triage & exposure resp |
| Enrich - URL - VT | 0 | GRC | DLP triage & exposure resp |
| Enrich - IP or Domain - Whois | 0 | GRC | DLP triage & exposure resp |
| Enrich - IP - VT | 0 | GRC | DLP triage & exposure resp |
| Enrich - Username or Email - Microsoft Entra ID | 0 | GRC | DLP triage & exposure resp |
| Enrich - IP - IPDB | 0 | GRC | DLP triage & exposure resp |
| Enrich - Username or Email - Okta | 0 | GRC | DLP triage & exposure resp |
| Enrich - Agent ID - Crowdstrike | 0 | GRC | DLP triage & exposure resp |
| Error Handling - Send Error Notification Email | 0 | GRC | DLP triage & exposure resp |
| Enrich - Hash - Crowdstrike | 0 | GRC | DLP triage & exposure resp |
| Enrich - Username or Email - Google Workspace | 0 | GRC | DLP triage & exposure resp |
| Subflow - Response - Main Router | 0 | GRC | DLP triage & exposure resp |
| Subflow - Enrich Observables - Main Router | 0 | GRC | DLP triage & exposure resp |
| Subflow - Missing Alert Template Notification | 0 | GRC | DLP triage & exposure resp |
6. Threat Intelligence Curation — H-ISAC
Description: Automated monitoring of the Health Information Sharing and Analysis Center (H-ISAC) threat intelligence email feed. Blink parses incoming bulletins from Outlook, extracts relevant threat data, and creates structured case attachments so intelligence is immediately available to analysts — without manual email review.
Business problem solved: Healthcare sector threat intelligence (ransomware campaigns, nation-state TTPs targeting medical orgs) arrives via email feeds that are easy to miss or process inconsistently. Blink ensures every H-ISAC bulletin is captured, timestamped, and linked to cases for analyst consumption.
Integrations: Outlook, H-ISAC TLP feed, Blink Case Management
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| H-ISAC Intel Notifications | 43 | SOC | Threat intel ingest & curation |
| Verify H-ISAC Feed | 0 | SOC | Threat intel ingest & curation |
7. EDR Containment & Response
Description: A library of pre-built containment and remediation playbooks for use during active incidents. Covers CrowdStrike endpoint isolation (quarantine/lift), remote response command execution against single or batches of hosts, Palo Alto IOC blocking, and response subflows for phishing and malware alert types.
Business problem solved: During a live incident, every minute without containment increases blast radius. Blink delivers one-click endpoint isolation and network-level IOC blocking, removing the need for analysts to navigate separate consoles under pressure.
Integrations: CrowdStrike (RTR, host isolation), Palo Alto Networks
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | 0 | SOC | EDR containment & response |
| Block IOC on Palo Alto | 2 | SOC | EDR containment & response |
| Response Subflow - Phishing | 0 | SOC | EDR containment & response, Phishing detection & response |
| Response Subflow - Malware | 0 | SOC | EDR containment & response |
Training / Development Workspace
The following playbooks reside in a dedicated training workspace (ca4b0c4a). They are development and analyst training copies of production playbooks and are excluded from production KPI counts. "New Workflow 2" (11,521 executions) appears to be a scheduled polling workflow running in parallel to production identity polling.
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| New Workflow 2 | 11,521 | SOC | Identity threat response |
| Crowdstrike - IDP-OMI-Training | 0 | SOC | SIEM & log pipeline monitoring |
| Process Alert | 1 | SOC | Agentic SOC, Case mgmt & SOAR |
| test workflow | 0 | SOC | Case mgmt & SOAR |
| CS-EPP-Test | 0 | SOC | EDR containment & response |
| Process Alerts | 0 | SOC | Case mgmt & SOAR |
| Utility - Find Similar Cases Based on Observables | 0 | SOC | Case mgmt & SOAR |
| Subflow - Update Enrichment Data | 0 | SOC | Case mgmt & SOAR |
| Get User Information Using Google Workspace | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 0 | SOC | Alert enrichment / IOC lookup |
| Response Subflow - Malware | 0 | SOC | EDR containment & response |
| Response Subflow - Phishing | 0 | SOC | Phishing detection & response |
| Enrich - Username or Email - Google Workspace | 0 | SOC | Alert enrichment / IOC lookup |
| Error Handling - Send Error Notification Email | 0 | SOC | Case mgmt & SOAR |
| Enrich - IP or Domain - Whois | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Response - Main Router | 0 | SOC | Case mgmt & SOAR |
| Subflow - Enrich Observables - Main Router | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | 0 | SOC | Case mgmt & SOAR |
Key Observations
Strengths
Deep SOC automation at scale. The platform is running at production volume — 25,633 cases closed, 9,322 alerts processed end-to-end, and 6,395 IRP playbooks auto-triggered over 12 months. This represents a fully operational Agentic SOC, not a pilot.
Dual-source alert coverage. Both Rapid7 InsightIDR (SIEM) and CrowdStrike (EPP + IDP) are fully integrated and ingesting in real time. The split between OMI and ACC variants suggests the environment supports a multi-tenant or segmented network model, each with its own alert pipeline.
Identity threat response at continuous coverage. Two parallel polling workflows (OMI and ACC) check Azure AD for risky users every 5 minutes around the clock. With 395 identity events actioned over 12 months, this is one of the highest-value response loops in the environment — particularly critical given the prevalence of identity-based attacks in healthcare.
Dedicated DLP workspace. The DLP incident pipeline is fully operational (2,755 incidents ingested across two intake paths — the original webhook feed plus a newer Outlook-based ACH intake at 474 executions — with 2,231 processed). The DLP workspace carries a complete mirror of the enrichment and response subflow library, providing the same depth of investigation capability as the main SOC workspace.
Healthcare-specific threat intelligence automation. H-ISAC bulletin processing is live and tracked. Processing sector-specific threat intel automatically — without analyst mailbox monitoring — is a differentiator for healthcare security programs operating under regulatory scrutiny.
Sandbox analysis capability is now active. ANY.RUN integration has moved beyond configuration into live use: Run New Analysis - URL-Domains auto-triggers on new URL/Domain observables (19 detonations in the last 12 months) and Get Analysis Report-Auto retrieves and attaches results to cases automatically, enabling detonation-based analysis without analyst intervention.
Gaps & Opportunities
Enrichment library has low utilization. The full enrichment library (VirusTotal, AbuseIPDB, URLScan, hash lookups, user lookups across 5+ directories) shows near-zero direct executions, despite high alert volume. This likely indicates enrichment subflows are triggered correctly as part of the main pipeline (via the router) but may not be firing consistently — worth validating that the Subflow - Enrich Observables router is being called for all alert types.
EDR containment playbooks are deployed but unused. CrowdStrike endpoint quarantine, batch RTR, and Palo Alto IOC blocking have 0–2 executions. These are high-value containment actions. If they haven't been tested in a live scenario, a tabletop exercise or controlled red team drill would validate readiness before a real incident requires them.
Identity response resolution rate. Of risky user events detected, 337 were dismissed (false positives) and 57 resolved via case closure — but zero were confirmed as actual compromises via the Confirm Risky User Compromise playbook. This is either a sign of a clean environment or that compromise confirmations are being handled outside Blink (e.g., direct console actions). Closing this loop through Blink would improve audit traceability.
Phishing detection & response not yet active. Response Subflow - Phishing is deployed (in both SOC and DLP workspaces) but has 0 executions. Given that phishing remains a top initial access vector in healthcare, activating automated KnowBe4 simulation filtering and analyst-initiated phishing response workflows would close a visible gap.
Stale case management utility unused. Utility - Close Stale Cases (auto-closes cases inactive for a month) has 0 executions. With 25,633 cases processed, enabling scheduled stale-case cleanup would reduce backlog noise and keep the case queue meaningful.
Integration Ecosystem
| Integration | Coverage Area |
|---|---|
| Rapid7 InsightIDR | SIEM alert ingestion, investigation sync |
| CrowdStrike (EPP + IDP) | EDR alert ingestion, hash/agent enrichment, endpoint isolation, RTR |
| Microsoft Entra ID / Azure AD | Risky user detection, user enrichment, compromise/dismissal writeback |
| Palo Alto Networks | Network-layer IOC blocking |
| Okta | User enrichment, activity search |
| Google Workspace | User enrichment |
| VirusTotal | Hash, IP, URL reputation |
| AbuseIPDB | IP reputation |
| URLScan | URL analysis |
| ANY.RUN | Sandbox detonation (URL + file) |
| WHOIS | IP/domain registration lookup |
| Slack | User enrichment by email |
| GitHub | User identity enrichment |
| Outlook | H-ISAC feed ingestion, error notifications |
| H-ISAC | Healthcare sector threat intelligence |
E New Integrations (detail) 6 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Accendra | microsoft-teams | my_microsoft_teams_connection_3 | 2026-09-18 |
| Accendra | microsoft-teams | my_microsoft_teams_connection_2 | 2026-09-18 |
| Accendra | microsoft-graph | my_microsoft_graph_connection | 2026-09-18 |
| Accendra | microsoft-teams | blinkops | 2026-09-18 |
| Accendra | microsoft-teams | my_microsoft_teams_connection_1 | 2026-09-18 |
| Accendra | microsoft-teams | my_microsoft_teams_connection | 2026-09-18 |