Blink Security Automation — Confidential

Accendra — Customer Success Report

Generated 2026-10-05 | accendra-value-report.md
2026-10-05Report Date
309Total Playbooks
92Unique Workflows (12m)
8,712,938Actions Automated (12m)
$2,240,982Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

309
Total playbooks built
all non-deleted workflows
142
Active playbooks
currently enabled
92
Unique workflows executed (12m)
distinct workflows that ran
8,712,938
Actions automated (12m)
completed action steps
48,405.2h
Hours saved (12m)
@ 20s per action
$2,240,982
Money saved (12m)
@ $100K avg salary
1
New active workflows (last 30d)
recently created & enabled
151,764
Total cases managed
151,761 opened in last 12m
7h 49m
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 6 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 25,633 security cases resolved & closed without manual process overhead - 9,322 SIEM/EDR and DLP alerts processed end-to-end by automation - 6,395 incident response playbooks automatically triggered on incoming alerts - 5,778 Rapid7 InsightIDR investigations auto-ingested and queued for analyst action - 2,755 data loss prevention incidents automatically captured and triaged - 1,514 Rapid7 investigations automatically assigned to the correct case owner - 395 risky user identity events reviewed and actioned — dismissals, closures, and confirmations - 43 H-ISAC sector threat intelligence bulletins automatically processed and attached to cases

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Core SOC Platform & Case Management
  • 25,633Security cases resolved & closed
  • 6,395Incident response playbooks auto-triggered
  • 3,129Analyst case notifications dispatched
23.6%
17
16 active
SIEM & EDR Alert Ingestion
  • 5,778Rapid7 InsightIDR investigations auto-ingested
  • 1,514Rapid7 investigations auto-assigned to case owner
  • 4Rapid7 investigation links updated on cases
16.0%
11
8 active
Identity Threat Response — Azure AD Risky Users
  • 395Risky user events reviewed & actioned
14.0%
11
10 active
Alert Enrichment & IOC Investigation
  • 19Sandbox URL/domain analyses auto-submitted (ANY.RUN)
0.0%
19
19 active
DLP Incident Triage
  • 2,755DLP incidents automatically ingested & triaged
4.1%
3
3 active
Threat Intelligence Curation — H-ISAC
  • 43H-ISAC threat intelligence bulletins processed
0.0%
2
1 active
EDR Containment & Response
  • 2Malicious IOCs blocked on Palo Alto
0.0%
4
4 active
Training / Development Workspace33,545 executions
38.4%
28
27 active
Total83,978 executions100%
95
88 active

Use Case Growth Over Time

198 unique playbooks  |  8 operational use cases  |  87,377 total executions (12m)  |  2024-09 to 2026-10
Toggle:
Toggle:

03Integration Ecosystem

Training / Development Workspace
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Microsoft Outlook Email Google Workspace Microsoft Entra ID Azure Rapid7 InsightIDR
Alert Enrichment & IOC Investigation
GitHub Slack Okta Extraction Utilities String Utilities VirusTotal CrowdStrike URLScan Any Run
Threat Intelligence Curation — H-ISAC
Microsoft Outlook Azure
SIEM & EDR Alert Ingestion
CrowdStrike Rapid7 InsightIDR Azure Microsoft Entra ID Microsoft Outlook
EDR Containment & Response
CrowdStrike SSH
Identity Threat Response — Azure AD Risky Users
Microsoft Entra ID Azure
Core SOC Platform & Case Management
Rapid7 InsightIDR CrowdStrike Email
DLP Incident Triage
Microsoft Outlook Microsoft Entra ID

04Key Observations

✓  Strengths

Strengths

Deep SOC automation at scale. The platform is running at production volume — 25,633 cases closed, 9,322 alerts processed end-to-end, and 6,395 IRP playbooks auto-triggered over 12 months. This represents a fully operational Agentic SOC, not a pilot.

Dual-source alert coverage. Both Rapid7 InsightIDR (SIEM) and CrowdStrike (EPP + IDP) are fully integrated and ingesting in real time. The split between OMI and ACC variants suggests the environment supports a multi-tenant or segmented network model, each with its own alert pipeline.

Identity threat response at continuous coverage. Two parallel polling workflows (OMI and ACC) check Azure AD for risky users every 5 minutes around the clock. With 395 identity events actioned over 12 months, this is one of the highest-value response loops in the environment — particularly critical given the prevalence of identity-based attacks in healthcare.

Dedicated DLP workspace. The DLP incident pipeline is fully operational (2,755 incidents ingested across two intake paths — the original webhook feed plus a newer Outlook-based ACH intake at 474 executions — with 2,231 processed). The DLP workspace carries a complete mirror of the enrichment and response subflow library, providing the same depth of investigation capability as the main SOC workspace.

Healthcare-specific threat intelligence automation. H-ISAC bulletin processing is live and tracked. Processing sector-specific threat intel automatically — without analyst mailbox monitoring — is a differentiator for healthcare security programs operating under regulatory scrutiny.

Sandbox analysis capability is now active. ANY.RUN integration has moved beyond configuration into live use: Run New Analysis - URL-Domains auto-triggers on new URL/Domain observables (19 detonations in the last 12 months) and Get Analysis Report-Auto retrieves and attaches results to cases automatically, enabling detonation-based analysis without analyst intervention.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Enrichment library has low utilization. The full enrichment library (VirusTotal, AbuseIPDB, URLScan, hash lookups, user lookups across 5+ directories) shows near-zero direct executions, despite high alert volume. This likely indicates enrichment subflows are triggered correctly as part of the main pipeline (via the router) but may not be firing consistently — worth validating that the Subflow - Enrich Observables router is being called for all alert types.

EDR containment playbooks are deployed but unused. CrowdStrike endpoint quarantine, batch RTR, and Palo Alto IOC blocking have 0–2 executions. These are high-value containment actions. If they haven't been tested in a live scenario, a tabletop exercise or controlled red team drill would validate readiness before a real incident requires them.

Identity response resolution rate. Of risky user events detected, 337 were dismissed (false positives) and 57 resolved via case closure — but zero were confirmed as actual compromises via the Confirm Risky User Compromise playbook. This is either a sign of a clean environment or that compromise confirmations are being handled outside Blink (e.g., direct console actions). Closing this loop through Blink would improve audit traceability.

Phishing detection & response not yet active. Response Subflow - Phishing is deployed (in both SOC and DLP workspaces) but has 0 executions. Given that phishing remains a top initial access vector in healthcare, activating automated KnowBe4 simulation filtering and analyst-initiated phishing response workflows would close a visible gap.

Stale case management utility unused. Utility - Close Stale Cases (auto-closes cases inactive for a month) has 0 executions. With 25,633 cases processed, enabling scheduled stale-case cleanup would reduce backlog noise and keep the case queue meaningful.

Integration Ecosystem

Integration Coverage Area
Rapid7 InsightIDR SIEM alert ingestion, investigation sync
CrowdStrike (EPP + IDP) EDR alert ingestion, hash/agent enrichment, endpoint isolation, RTR
Microsoft Entra ID / Azure AD Risky user detection, user enrichment, compromise/dismissal writeback
Palo Alto Networks Network-layer IOC blocking
Okta User enrichment, activity search
Google Workspace User enrichment
VirusTotal Hash, IP, URL reputation
AbuseIPDB IP reputation
URLScan URL analysis
ANY.RUN Sandbox detonation (URL + file)
WHOIS IP/domain registration lookup
Slack User enrichment by email
GitHub User identity enrichment
Outlook H-ISAC feed ingestion, error notifications
H-ISAC Healthcare sector threat intelligence
Appendices
A Case Management 151,761 cases (12m) | MTTR 7h 49m

Case Management

Total Cases (all-time)
151,764
151,761 opened in last 12m
Cases Opened (30d)
5,305
4,293 closed in last 30d
Cases Closed (12m)
137,565
of 151,761 opened
MTTR
7h 49m
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management 132,864 132,864 128,314 4h 20m
IT Security Data Protection 14,737 14,737 9,240 2d 8h
Harshal.Surwade@owens-minor.com 4,151 4,151 2 41m
DEMO: ENGINEERING 9 9 9 4s
Nitin.L@owens-minor.com 3 0 0 N/A
B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 6 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink Case Management 0 0 0
2 Agent Blink Nitin.L@owens-minor.com 0 0 0
3 Agent Blink IT Security Data Protection 0 0 0
4 Agent Blink Harshal.Surwade@owens-minor.com 0 0 0
5 Agent Blink DEMO: ENGINEERING 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Case Management 0
Nitin.L@owens-minor.com0
IT Security Data Protection0
Harshal.Surwade@owens-minor.com0
DEMO: ENGINEERING0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
14
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Alerts Dashboard 00
2 Test 00
3 production: metric dashboard 00
4 EBR Dashboard 00
5 Migration Dashboard 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 8 use cases | 87,377 executions (12m)

Business KPIs

Metric Count Playbook
Security cases resolved & closed 25,633 Set To Close in UI
Security alerts processed end-to-end 9,322 Process Alert (SOC) + Process Alert (DLP)
Incident response playbooks auto-triggered 6,395 Incident Playbook - Generic IRP
Rapid7 InsightIDR investigations auto-ingested 5,778 Ingest - Rapid7 Insight IDR Alerts
Rapid7 investigation links updated on cases 4 Update R7 Investigation Link
Analyst case notifications dispatched 3,129 New Case Notification
DLP incidents automatically ingested & triaged 2,755 Ingest DLP Incident + Ingest DLP Incident - ACH
Rapid7 investigations auto-assigned to case owner 1,514 Assign User To Rapid7 Investigation
Risky user events reviewed & actioned 395 Dismiss Risky User-Case + Risky User Case Closed - Update Azure + Confirm User Safe-Case
CrowdStrike EDR/IDP alerts ingested 265 Ingest CS-EPP-OMI + Ingest CS-EPP-ACC + Ingest CS-IDP-OMI + Ingest CS-IDP-ACC
H-ISAC threat intelligence bulletins processed 43 H-ISAC Intel Notifications
Cases escalated to next team 32 Escalate Case to Next Team
Sandbox URL/domain analyses auto-submitted (ANY.RUN) 19 Run New Analysis - URL-Domains
Lateral movement incidents investigated 5 Incident Playbook - Lateral Movement
Malicious IOCs blocked on Palo Alto 2 Block IOC on Palo Alto
In the last 12 months, Blink automated: - 25,633 security cases resolved & closed without manual process overhead - 9,322 SIEM/EDR and DLP alerts processed end-to-end by automation - 6,395 incident response playbooks automatically triggered on incoming alerts - 5,778 Rapid7 InsightIDR investigations auto-ingested and queued for analyst action - 2,755 data loss prevention incidents automatically captured and triaged - 1,514 Rapid7 investigations automatically assigned to the correct case owner - 395 risky user identity events reviewed and actioned — dismissals, closures, and confirmations - 43 H-ISAC sector threat intelligence bulletins automatically processed and attached to cases

Use Case Summary

# Use Case Category Playbooks Total Executions (12mo)
1 Core SOC Platform & Case Management SOC 22 65,090
2 SIEM & EDR Alert Ingestion SOC 12 7,561
3 Identity Threat Response — Azure AD Risky Users SOC 11 23,436
4 Alert Enrichment & IOC Investigation SOC 36 37
5 DLP Incident Triage GRC 26 4,986
6 Threat Intelligence Curation — H-ISAC SOC 2 43
7 EDR Containment & Response SOC 6 2
— Training / Development Workspace — 31 11,522
Total 146
Note: The Identity Threat Response total includes 23,041 scheduled polling executions (5-minute interval); individual business actions (dismissals, closures) total 395.

Use Cases

1. Core SOC Platform & Case Management

Description: The central orchestration layer for Accendra's security operations. Blink powers the full alert-to-case lifecycle — ingesting observables, executing response playbooks, managing case state, notifying analysts, and closing cases — replacing a manual SOAR workflow with fully automated orchestration.

Business problem solved: Manual triage and case management across multiple security tools creates analyst fatigue, inconsistent documentation, and slow response times. This use case eliminates repetitive mechanical work so analysts focus on investigation and decision-making.

Integrations: Blink Case Management, Rapid7 InsightIDR, CrowdStrike, Outlook/Email

Playbook Executions (12mo) Category Subcategory
Process Alert 7,091 SOC Agentic SOC, Case mgmt & SOAR
Incident Playbook - Generic IRP 6,395 SOC Agentic SOC, Case mgmt & SOAR
Incident Playbook - Lateral Movement - Administrator Impersonation 5 SOC Agentic SOC, Case mgmt & SOAR
Post Comment to UI 10,575 SOC Case mgmt & SOAR
Assign user to Incident in UI 7,282 SOC Case mgmt & SOAR
Set Status in UI 4,948 SOC Case mgmt & SOAR
Set To Close in UI 25,633 SOC Case mgmt & SOAR
New Case Notification 3,129 SOC Case mgmt & SOAR
Escalate Case to Next Team 32 SOC Case mgmt & SOAR
Set the priority of an investigation 1 SOC Case mgmt & SOAR
Subflow - Update Enrichment Data 2 SOC Case mgmt & SOAR
Subflow - Missing Alert Template Notification 1 SOC Case mgmt & SOAR
Utility - Close Stale Cases 0 SOC Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables 0 SOC Case mgmt & SOAR
Utility - Delete Observable Relation 0 SOC Case mgmt & SOAR
Utility - Set Or Update Observable Relation 0 SOC Case mgmt & SOAR
Utility - List Alert Observable Relations 0 SOC Case mgmt & SOAR
Utility - Update Enrichment 0 SOC Case mgmt & SOAR
Utility - List Observable Alert Relations 0 SOC Case mgmt & SOAR
Table Action - Validate Observables Extraction Template 0 SOC Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts 0 SOC Case mgmt & SOAR
Recovery - Enrich Non-Enriched Observables 0 SOC Case mgmt & SOAR

2. SIEM & EDR Alert Ingestion

Description: Automated connectors that pull and normalize security alerts from Rapid7 InsightIDR (SIEM) and CrowdStrike Endpoint Protection/Identity Detection (EDR/IDP) into the Blink case management platform, ensuring every alert is captured, deduplicated, and queued for processing.

Business problem solved: Without automated ingestion, analysts must manually poll SIEM and EDR consoles for new alerts — a slow, error-prone process that introduces coverage gaps. Blink's connectors provide continuous, zero-touch alert capture across all integrated platforms.

Integrations: Rapid7 InsightIDR, CrowdStrike EPP, CrowdStrike IDP, IBM Resilient (legacy migration)

Playbook Executions (12mo) Category Subcategory
Ingest - Rapid7 Insight IDR Alerts 5,778 SOC SIEM & log pipeline monitoring, Case mgmt & SOAR
Assign User To Rapid7 Investigation 1,514 SOC SIEM & log pipeline monitoring, Case mgmt & SOAR
Update R7 Investigation Link 4 SOC SIEM & log pipeline monitoring, Case mgmt & SOAR
Ingest - CrowdStrike-EPP-OMI 156 SOC SIEM & log pipeline monitoring, EDR containment & response
Ingest - CrowdStrike-EPP - ACC 77 SOC SIEM & log pipeline monitoring, EDR containment & response
Ingest - CrowdStrike-IDP-OMI 20 SOC SIEM & log pipeline monitoring, Identity threat response
Ingest - CrowdStrike-IDP -ACC 12 SOC SIEM & log pipeline monitoring, Identity threat response
Update Rapid7 Insight IDR Alerts 0 SOC SIEM & log pipeline monitoring, Case mgmt & SOAR
Update Rapid7 Insight IDR - pull investigations polling 0 SOC SIEM & log pipeline monitoring
Ingest Legacy Resilient Incidents-updateErrored 0 SOC Case mgmt & SOAR
Ingest Legacy Resilient Incidents-1 0 SOC Case mgmt & SOAR
Ingest - CrowdStrike-EPP/IDP legacy1 0 SOC SIEM & log pipeline monitoring, EDR containment & response

3. Identity Threat Response — Azure AD Risky Users

Description: Continuous 5-minute polling of Azure Active Directory for risky user events, with automated case creation and structured analyst resolution workflows. When a risky user is flagged, Blink creates a case, notifies the analyst, and surfaces three response actions: dismiss (false positive), confirm compromise, or confirm safe — each syncing the outcome back to Azure AD.

Business problem solved: Identity-based attacks are among the most common initial access vectors in healthcare environments. Automating Azure AD risky user triage ensures near-real-time detection coverage and consistent response, even across off-hours, without requiring analysts to monitor the Azure portal continuously.

Integrations: Microsoft Azure Active Directory (Entra ID), Blink Case Management

Playbook Executions (12mo) Category Subcategory
Ingest Risky Alerts Polling-OMI 11,521* SOC Identity threat response
Ingest Risky Alerts Polling-ACC 11,520* SOC Identity threat response
Dismiss Risky User-Case 337 SOC Identity threat response
Risky User Case Closed by User - Update Azure 57 SOC Identity threat response
Confirm User Safe-Case 1 SOC Identity threat response
Confirm Risky User Compromise-Case 0 SOC Identity threat response
Update Risky Alert Case 0 SOC Identity threat response
Dismiss Risky User-Alert 0 SOC Identity threat response
Confirm User Safe-Alert 0 SOC Identity threat response
Confirm Risky User Compromise-Alert 0 SOC Identity threat response
Ingest Risky Alerts copy 0 SOC Identity threat response

*\* Polling infrastructure — each execution is a 5-minute schedule tick, not an individual alert event.*

4. Alert Enrichment & IOC Investigation

Description: A comprehensive library of on-demand and subflow enrichment playbooks that automatically gather threat context on observables — IP addresses, file hashes, URLs, domains, email addresses, and user identities — across threat intelligence platforms and identity directories. Enrichments are triggered automatically as part of the main alert processing pipeline.

Business problem solved: Investigating a security alert manually requires an analyst to run lookups across 8+ tools for every observable. Blink's enrichment library automates this context-gathering in seconds, ensuring analysts arrive at each case with full context already populated.

Integrations: VirusTotal, AbuseIPDB, URLScan, ANY.RUN, WHOIS, CrowdStrike, Okta, Microsoft Entra ID / Azure AD, Google Workspace, Slack, GitHub

Playbook Executions (12mo) Category Subcategory
Subflow - Enrich Observables - Main Router 0 SOC Alert enrichment / IOC lookup
Enrich Observable 3 SOC Alert enrichment / IOC lookup
Subflow - Response - Main Router 0 SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike 1 SOC Alert enrichment / IOC lookup
Enrich - Hash - VT 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike 0 SOC Alert enrichment / IOC lookup
Enrich - IP - VT 0 SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB 0 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 2 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 2 SOC Alert enrichment / IOC lookup
Enrich - URL - VT 0 SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace 0 SOC Alert enrichment / IOC lookup
Enrich - Username - Github 0 SOC Alert enrichment / IOC lookup
Enrich - Email Address - Slack 0 SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID 0 SOC Alert enrichment / IOC lookup, Identity threat response
Get User Information Using Google Workspace 0 SOC Alert enrichment / IOC lookup
Get User Information Using Github 0 SOC Alert enrichment / IOC lookup
Get User Information Using Okta 0 SOC Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike 0 SOC Alert enrichment / IOC lookup
Analyze URL with URLScan 0 SOC Alert enrichment / IOC lookup
Secure URL Screenshot Capture 0 SOC Alert enrichment / IOC lookup
Run Dig Command 0 SOC Alert enrichment / IOC lookup
Okta Search for User Activity 0 SOC Alert enrichment / IOC lookup
Get End of Life Date for a Product 0 SOC Alert enrichment / IOC lookup
Run New Analysis - URL 1 SOC Alert enrichment / IOC lookup
Run New Analysis - URL-Domains 19 SOC Alert enrichment / IOC lookup
Run New Analysis - File 0 SOC Alert enrichment / IOC lookup
Run New Analysis - File copy 0 SOC Alert enrichment / IOC lookup
Get Analysis Report 0 SOC Alert enrichment / IOC lookup
Get Analysis Report-Auto 4 SOC Alert enrichment / IOC lookup
Error Handling - Send Error Notification Email 0 SOC Case mgmt & SOAR

5. DLP Incident Triage

Description: A dedicated workspace for automated ingestion and initial processing of data loss prevention incidents. Incoming DLP events are automatically structured into cases, observables are extracted, and the full enrichment + response subflow library is available for analyst-driven investigation.

Business problem solved: DLP platforms generate high volumes of incidents that vary widely in severity. Blink automates the ingestion and first-pass triage so analysts work from a normalized, enriched case view rather than raw DLP console events.

Integrations: DLP platform (via webhook), Microsoft Entra ID, Okta, Google Workspace, CrowdStrike, VirusTotal, AbuseIPDB, URLScan, WHOIS, Outlook

Playbook Executions (12mo) Category Subcategory
Ingest DLP Incident 2,281 GRC DLP triage & exposure resp
Ingest DLP Incident - ACH 474 GRC DLP triage & exposure resp
Process Alert (DLP workspace) 2,231 GRC DLP triage & exposure resp
send Email 0 GRC DLP triage & exposure resp
Utility - Find Similar Cases Based on Observables 0 GRC DLP triage & exposure resp
Subflow - Update Enrichment Data 0 GRC DLP triage & exposure resp
Get User Information Using Google Workspace 0 GRC DLP triage & exposure resp
Get User Information Using Microsoft Entra ID 0 GRC DLP triage & exposure resp
Enrich IP or Domain Using Whois 0 GRC DLP triage & exposure resp
Response Subflow - Malware 0 GRC DLP triage & exposure resp
Response Subflow - Phishing 0 GRC DLP triage & exposure resp
Enrich - Hash - VT 0 GRC DLP triage & exposure resp
Enrich - URL - URLScan 0 GRC DLP triage & exposure resp
Enrich - URL - VT 0 GRC DLP triage & exposure resp
Enrich - IP or Domain - Whois 0 GRC DLP triage & exposure resp
Enrich - IP - VT 0 GRC DLP triage & exposure resp
Enrich - Username or Email - Microsoft Entra ID 0 GRC DLP triage & exposure resp
Enrich - IP - IPDB 0 GRC DLP triage & exposure resp
Enrich - Username or Email - Okta 0 GRC DLP triage & exposure resp
Enrich - Agent ID - Crowdstrike 0 GRC DLP triage & exposure resp
Error Handling - Send Error Notification Email 0 GRC DLP triage & exposure resp
Enrich - Hash - Crowdstrike 0 GRC DLP triage & exposure resp
Enrich - Username or Email - Google Workspace 0 GRC DLP triage & exposure resp
Subflow - Response - Main Router 0 GRC DLP triage & exposure resp
Subflow - Enrich Observables - Main Router 0 GRC DLP triage & exposure resp
Subflow - Missing Alert Template Notification 0 GRC DLP triage & exposure resp

6. Threat Intelligence Curation — H-ISAC

Description: Automated monitoring of the Health Information Sharing and Analysis Center (H-ISAC) threat intelligence email feed. Blink parses incoming bulletins from Outlook, extracts relevant threat data, and creates structured case attachments so intelligence is immediately available to analysts — without manual email review.

Business problem solved: Healthcare sector threat intelligence (ransomware campaigns, nation-state TTPs targeting medical orgs) arrives via email feeds that are easy to miss or process inconsistently. Blink ensures every H-ISAC bulletin is captured, timestamped, and linked to cases for analyst consumption.

Integrations: Outlook, H-ISAC TLP feed, Blink Case Management

Playbook Executions (12mo) Category Subcategory
H-ISAC Intel Notifications 43 SOC Threat intel ingest & curation
Verify H-ISAC Feed 0 SOC Threat intel ingest & curation

7. EDR Containment & Response

Description: A library of pre-built containment and remediation playbooks for use during active incidents. Covers CrowdStrike endpoint isolation (quarantine/lift), remote response command execution against single or batches of hosts, Palo Alto IOC blocking, and response subflows for phishing and malware alert types.

Business problem solved: During a live incident, every minute without containment increases blast radius. Blink delivers one-click endpoint isolation and network-level IOC blocking, removing the need for analysts to navigate separate consoles under pressure.

Integrations: CrowdStrike (RTR, host isolation), Palo Alto Networks

Playbook Executions (12mo) Category Subcategory
Manage Endpoint Quarantine Status in Crowdstrike 0 SOC EDR containment & response
CrowdStrike RTR to a Single Host 0 SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts 0 SOC EDR containment & response
Block IOC on Palo Alto 2 SOC EDR containment & response
Response Subflow - Phishing 0 SOC EDR containment & response, Phishing detection & response
Response Subflow - Malware 0 SOC EDR containment & response

Training / Development Workspace

The following playbooks reside in a dedicated training workspace (ca4b0c4a). They are development and analyst training copies of production playbooks and are excluded from production KPI counts. "New Workflow 2" (11,521 executions) appears to be a scheduled polling workflow running in parallel to production identity polling.

Playbook Executions (12mo) Category Subcategory
New Workflow 2 11,521 SOC Identity threat response
Crowdstrike - IDP-OMI-Training 0 SOC SIEM & log pipeline monitoring
Process Alert 1 SOC Agentic SOC, Case mgmt & SOAR
test workflow 0 SOC Case mgmt & SOAR
CS-EPP-Test 0 SOC EDR containment & response
Process Alerts 0 SOC Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables 0 SOC Case mgmt & SOAR
Subflow - Update Enrichment Data 0 SOC Case mgmt & SOAR
Get User Information Using Google Workspace 0 SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID 0 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 0 SOC Alert enrichment / IOC lookup
Response Subflow - Malware 0 SOC EDR containment & response
Response Subflow - Phishing 0 SOC Phishing detection & response
Enrich - Username or Email - Google Workspace 0 SOC Alert enrichment / IOC lookup
Error Handling - Send Error Notification Email 0 SOC Case mgmt & SOAR
Enrich - IP or Domain - Whois 0 SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB 0 SOC Alert enrichment / IOC lookup
Enrich - IP - VT 0 SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - VT 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta 0 SOC Alert enrichment / IOC lookup
Enrich - URL - VT 0 SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan 0 SOC Alert enrichment / IOC lookup
Subflow - Response - Main Router 0 SOC Case mgmt & SOAR
Subflow - Enrich Observables - Main Router 0 SOC Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification 0 SOC Case mgmt & SOAR

Key Observations

Strengths

Deep SOC automation at scale. The platform is running at production volume — 25,633 cases closed, 9,322 alerts processed end-to-end, and 6,395 IRP playbooks auto-triggered over 12 months. This represents a fully operational Agentic SOC, not a pilot.

Dual-source alert coverage. Both Rapid7 InsightIDR (SIEM) and CrowdStrike (EPP + IDP) are fully integrated and ingesting in real time. The split between OMI and ACC variants suggests the environment supports a multi-tenant or segmented network model, each with its own alert pipeline.

Identity threat response at continuous coverage. Two parallel polling workflows (OMI and ACC) check Azure AD for risky users every 5 minutes around the clock. With 395 identity events actioned over 12 months, this is one of the highest-value response loops in the environment — particularly critical given the prevalence of identity-based attacks in healthcare.

Dedicated DLP workspace. The DLP incident pipeline is fully operational (2,755 incidents ingested across two intake paths — the original webhook feed plus a newer Outlook-based ACH intake at 474 executions — with 2,231 processed). The DLP workspace carries a complete mirror of the enrichment and response subflow library, providing the same depth of investigation capability as the main SOC workspace.

Healthcare-specific threat intelligence automation. H-ISAC bulletin processing is live and tracked. Processing sector-specific threat intel automatically — without analyst mailbox monitoring — is a differentiator for healthcare security programs operating under regulatory scrutiny.

Sandbox analysis capability is now active. ANY.RUN integration has moved beyond configuration into live use: Run New Analysis - URL-Domains auto-triggers on new URL/Domain observables (19 detonations in the last 12 months) and Get Analysis Report-Auto retrieves and attaches results to cases automatically, enabling detonation-based analysis without analyst intervention.

Gaps & Opportunities

Enrichment library has low utilization. The full enrichment library (VirusTotal, AbuseIPDB, URLScan, hash lookups, user lookups across 5+ directories) shows near-zero direct executions, despite high alert volume. This likely indicates enrichment subflows are triggered correctly as part of the main pipeline (via the router) but may not be firing consistently — worth validating that the Subflow - Enrich Observables router is being called for all alert types.

EDR containment playbooks are deployed but unused. CrowdStrike endpoint quarantine, batch RTR, and Palo Alto IOC blocking have 0–2 executions. These are high-value containment actions. If they haven't been tested in a live scenario, a tabletop exercise or controlled red team drill would validate readiness before a real incident requires them.

Identity response resolution rate. Of risky user events detected, 337 were dismissed (false positives) and 57 resolved via case closure — but zero were confirmed as actual compromises via the Confirm Risky User Compromise playbook. This is either a sign of a clean environment or that compromise confirmations are being handled outside Blink (e.g., direct console actions). Closing this loop through Blink would improve audit traceability.

Phishing detection & response not yet active. Response Subflow - Phishing is deployed (in both SOC and DLP workspaces) but has 0 executions. Given that phishing remains a top initial access vector in healthcare, activating automated KnowBe4 simulation filtering and analyst-initiated phishing response workflows would close a visible gap.

Stale case management utility unused. Utility - Close Stale Cases (auto-closes cases inactive for a month) has 0 executions. With 25,633 cases processed, enabling scheduled stale-case cleanup would reduce backlog noise and keep the case queue meaningful.

Integration Ecosystem

Integration Coverage Area
Rapid7 InsightIDR SIEM alert ingestion, investigation sync
CrowdStrike (EPP + IDP) EDR alert ingestion, hash/agent enrichment, endpoint isolation, RTR
Microsoft Entra ID / Azure AD Risky user detection, user enrichment, compromise/dismissal writeback
Palo Alto Networks Network-layer IOC blocking
Okta User enrichment, activity search
Google Workspace User enrichment
VirusTotal Hash, IP, URL reputation
AbuseIPDB IP reputation
URLScan URL analysis
ANY.RUN Sandbox detonation (URL + file)
WHOIS IP/domain registration lookup
Slack User enrichment by email
GitHub User identity enrichment
Outlook H-ISAC feed ingestion, error notifications
H-ISAC Healthcare sector threat intelligence
E New Integrations (detail) 6 added in last 30d

New Integrations Added - Last 30 Days

6 new connections
TenantIntegrationConnection NameAdded
Accendra microsoft-teams my_microsoft_teams_connection_3 2026-09-18
Accendra microsoft-teams my_microsoft_teams_connection_2 2026-09-18
Accendra microsoft-graph my_microsoft_graph_connection 2026-09-18
Accendra microsoft-teams blinkops 2026-09-18
Accendra microsoft-teams my_microsoft_teams_connection_1 2026-09-18
Accendra microsoft-teams my_microsoft_teams_connection 2026-09-18