Blink Security Automation — Confidential

awac — Customer Success Report

Generated 2026-09-10 | awac-value-report.md
2026-09-10Report Date
586Total Playbooks
207Unique Workflows (12m)
7,759,919Actions Automated (12m)
$1,995,864Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

586
Total playbooks built
all non-deleted workflows
359
Active playbooks
currently enabled
207
Unique workflows executed (12m)
distinct workflows that ran
7,759,919
Actions automated (12m)
completed action steps
43,110.7h
Hours saved (12m)
@ 20s per action
$1,995,864
Money saved (12m)
@ $100K avg salary
14
New active workflows (last 30d)
recently created & enabled
14,089
Total cases managed
14,089 opened in last 12m
4d 6h
MTTR — mean time to resolve
closed cases, last 12m
14
Active AI agents
of 23 total
5,215
AI agent tasks executed (12m)
609 in last 30d
In the last 12 months, Blink automated: - 60,910 malware alerts automatically triaged via Intezer - 34,155 CrowdStrike SIEM events monitored across critical apps and executive endpoints - 12,061 SIEM alerts ingested and routed from Cribl - 11,548 email threats automatically enriched from Proofpoint TAP - 8,474 Cortex XDR blocked-execution alerts processed - 7,412 ThreatLocker application control events detected and contained - 5,085 security alerts orchestrated through case management - 4,832 delivered phishing emails auto-remediated via Proofpoint TAP (v2 response flow) - 3,358 data access control anomalies automatically ingested from Varonis - 2,123 vulnerability controls deactivated and closed - 948 Palo Alto firewall connections continuously monitored - 721 ransomware alerts ingested and triaged from Halcyon - 474 phishing incidents triaged and remediated via Phishlabs - 70 malicious domains blocked in Palo Alto EDLs - 65 Apono JIT access-flow records synced and access requests routed

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Multi-Source Alert Ingestion & SOC Automation
  • 60,910Malware & endpoint alerts auto-triaged via Intezer
  • 12,061SIEM alerts ingested & routed from Cribl
  • 11,548Email threats automatically ingested from Proofpoint TAP
45.6%
24
24 active
Phishing & Email Threat Response
  • 4,832Delivered phishing emails auto-remediated via Proofpoint TAP (v2)
  • 962Proofpoint URL clicks reviewed
  • 281Phishing site takedown alerts processed
8.7%
21
21 active
Endpoint Security & Application Control
  • 5,777Application control block events detected via ThreatLocker
  • 1,635ThreatLocker containment actions executed
  • 342Application control approval requests handled
12.5%
22
22 active
Case Management & SOAR Orchestration5,352 executions
4.6%
23
22 active
Threat Intelligence & IOC Blocking
  • 70Malicious domains blocked in Palo Alto EDLs
0.1%
13
13 active
Firewall & Network Infrastructure
  • 948Palo Alto firewall connections continuously monitored
0.9%
15
15 active
Vulnerability & Asset Management
  • 2,123Vulnerability controls deactivated & remediated
  • 222Vulnerability controls automatically validated
1.3%
27
27 active
Security Metrics & Executive Reporting150 executions
0.1%
6
6 active
Compliance & Access Governance256 executions
0.2%
9
9 active
Data Loss Prevention & Data Security
  • 3,358Data access control alerts ingested from Varonis
0.1%
6
5 active
JIT Access Management (Apono)89 executions
0.1%
6
6 active
Total86,501 executions100%
172
170 active

Use Case Growth Over Time

448 unique playbooks  |  11 operational use cases  |  116,552 total executions (12m)  |  2024-01 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Multi-Source Alert Ingestion & SOC Automation
ServiceNow Opsgenie Microsoft Defender For Cloud Microsoft Teams Jira Microsoft Entra ID CrowdStrike Email Proofpoint TAP Nucleus Microsoft Outlook Agents Cortex XDR
Threat Intelligence & IOC Blocking
CrowdStrike Azure Jira Microsoft Teams Cortex XDR ServiceNow Proofpoint TAP Palo Alto Firewall
Case Management & SOAR Orchestration
Jira Microsoft Teams ServiceNow Agents
Vulnerability & Asset Management
Microsoft Teams Jira Tenable Microsoft Entra ID Axonius Nucleus CrowdStrike Vanta NetSPI
Firewall & Network Infrastructure
Palo Alto Firewall Opsgenie Microsoft Teams Nucleus Agents Jira
Data Loss Prevention & Data Security
Opsgenie Jira Microsoft Teams Microsoft Entra ID Microsoft Outlook Agents ServiceNow
Endpoint Security & Application Control
Jira CrowdStrike Microsoft Entra ID ServiceNow Threatlocker Microsoft Teams Web Form Agents Cortex XDR PhishLabs Open Web Monitoring Opsgenie
Security Metrics & Executive Reporting
CrowdStrike Dashboards Email Cortex XDR
Compliance & Access Governance
Axonius Microsoft Entra ID Microsoft Teams Email Vanta GitHub
Phishing & Email Threat Response
Proofpoint TAP Microsoft Outlook Email Agents Microsoft Teams Agari Phishing Response PhishLabs Open Web Monitoring PhishLabs Incident Data Opsgenie CrowdStrike ServiceNow Intezer VirusTotal
JIT Access Management (Apono)
ServiceNow Microsoft Teams

04Key Observations

✓  Strengths

Strengths

1. Exceptional alert ingestion breadth.

AWAC has automated intake for 10+ distinct alert sources, covering endpoint (Intezer, CrowdStrike), email (Proofpoint TAP), network (Cribl, Imperva), ransomware (Halcyon), data (Varonis), and specialized sources (Appono, MASNET, Unit 42). With over 118,000 executions across the ingestion layer, the SOC is operating a fully automated alert intake pipeline at scale. The Intezer integration alone (60,910 executions) represents one of the highest single-workflow execution volumes in the environment.

2. Mature SOC orchestration fabric.

The case management and SOAR layer is deeply built out, with 26,000+ executions synchronizing state between Blink Case Management, Jira, and ServiceNow in near real-time. The AI-assisted Migration - Add Comment Agent workflow signals early adoption of agentic patterns within core SOAR workflows. This bidirectional sync infrastructure is a significant operational asset.

3. ThreatLocker at production scale.

The application control workflows — server block polling (5,777 runs), automated containment responses (1,635), hash lookups (448), and approval request handling (342) — represent a mature, high-frequency endpoint control automation that would otherwise require constant manual attention from security operations.

4. Continuous compliance control framework.

The compliance workspace (857728f8) implements a scheduled execution engine that continuously runs and validates Vanta and Azure controls. Combined with Okta user verification and GitHub branch protection enforcement, AWAC has moved from periodic compliance audits to continuous automated validation.

5. AI/Agentic adoption in production.

Three Agent TIA (Threat Intelligence & Analysis) workflows for domain blocking, hash blocking, and IP blocking demonstrate early production deployment of agentic automation. The MASNET Ingestion workflow also uses AI agent patterns for complex multi-system orchestration. This positions AWAC ahead of the curve on agentic SOC capabilities.

6. Cortex XDR emerging as a second production EDR pipeline.

Cortex XDR Blocked Processed Alert polls every 5 minutes and has already logged 8,474 executions, plus a growing set of Cortex XDR containment actions (hash blocking, endpoint isolation, agentic hash-block approval). This runs alongside the existing CrowdStrike pipeline, giving AWAC redundant, cross-vendor EDR alert coverage.

7. First IAM use case: Apono JIT access governance.

New workflows continuously sync Apono access flows, groups, bundles, and integrations into Blink tables, and route ServiceNow-initiated Apono access requests to the security engineering team via Teams. This is AWAC's first automated IAM capability and a natural foundation for expanding into broader access-review and provisioning automation.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

1. CrowdStrike and Cortex XDR EDR response not yet fully automated.

Workflows for CrowdStrike RTR to a Single Host, CrowdStrike RTR to a Batch of Hosts, and Manage Endpoint Quarantine Status in Crowdstrike have 0 executions. CrowdStrike alert ingestion is automated (267 + 11,547 + 11,546 executions) but the response layer — RTR commands, host isolation, containment — is not yet triggered automatically. The newer Isolate Machine in Cortex and Response Subflow - Crowdstrike workflows are similarly built but still at 0 executions. Closing this loop across both EDR platforms would deliver significant MTTR reduction.

2. Tenable integration built but inactive.

Tenable Self Service Vulnerability Scan, Tenable IE to Jira, and Tenable Vulnerability Management all have 0 executions. Given the mature Nucleus pipeline, these may represent a parallel capability that was not fully activated. Tenable self-service via Teams is particularly high-value for enabling non-SOC teams to initiate scans on demand.

3. Firewall rule audit suite not running.

Three Firewall Rule Audit workflows (Aggregate Data, Enrich with Agent Data, Send Email) are built but have 0 executions. A scheduled firewall rule audit would provide ongoing hygiene visibility and support compliance requirements.

4. Varonis SaaS Alerts and Zero Networks inactive.

Varonis SaaS Alerts and both Zero Networks microsegmentation workflows have 0 executions. If Zero Networks is deployed in the environment, automated rule cleanup and disablement workflows could significantly reduce the manual burden of microsegmentation policy management.

5. Fragmented workflow copies.

The environment contains multiple "copy" variants of core workflows (Sync List, Tenant Block Domain, Add Users to Team, etc.) with 0 executions. These represent technical debt and risk of divergence. A consolidation pass would reduce maintenance overhead and eliminate confusion about which workflow is canonical.

Integration Ecosystem

AWAC operates one of the most diverse integration ecosystems in the Blink customer base, spanning 20+ distinct security and IT platforms:

Domain Integrations
Endpoint / EDR CrowdStrike Falcon, Palo Alto Cortex XDR, ThreatLocker, Halcyon, Microsoft Defender for Endpoint
Email Security Proofpoint TAP, Tessian, Agari, Phishlabs, Microsoft Outlook / O365
SIEM / Log Pipeline CrowdStrike Next-Gen SIEM, Cribl
SOAR / Ticketing Blink Case Management, Jira, ServiceNow, OpsGenie
Network / Firewall Palo Alto Networks (Panorama, NGFW, SSPM, Cortex XDR, Unit 42), Imperva, Zero Networks
Vulnerability Mgmt Axonius, Nucleus, NetSPI, Tenable
Data Security Varonis
Identity Okta, Microsoft Entra ID, Google Workspace, Apono
Threat Intel Intezer, VirusTotal, URLScan, AbuseIPDB, MASNET, Appono
Compliance Vanta, GitHub, Azure AD
Collaboration Microsoft Teams, Slack
Learning Litmos
Appendices
A Case Management 14,089 cases (12m) | MTTR 4d 6h

Case Management

Total Cases (all-time)
14,089
14,089 opened in last 12m
Cases Opened (30d)
695
645 closed in last 30d
Cases Closed (12m)
13,920
of 14,089 opened
MTTR
4d 6h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
AW Production 14,087 14,087 13,920 4d 6h
Case Management 2 2 0 N/A
B AI Agents 14 active | 5,215 tasks (12m)

AI Agents

Active Agents
14
of 23 total
Tasks Executed (12m)
5,215
609 in last 30d
Data Usage (12m)
357,197,169
103,215,923 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Domain Analyzer AW Production 1,954 19 147,733,143
2 Agent Pete AW Production 1,436 416 150,705,493
3 Agent Phil AW Production 798 54 16,340,901
4 Agent DiL Pickle AW Production 262 27 19,404,854
5 Agent Fred AW Production 239 0 5,762,604
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
AW Production5,215
Case Management0
AW Vulnerability Management0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
11
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Domain Blocks 00
2 sdfd 00
3 Security - Main 00
4 CISO Dashboard - WIP 00
5 MttX PoC Board 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Threatlocker Learning Mode Self Service Request 00
D Full Use Case Analysis 11 use cases | 116,552 executions (12m)

Business KPIs

Metric Count Playbook
Malware & endpoint alerts auto-triaged via Intezer 60,910 On New Intezer Alert
SIEM alerts ingested & routed from Cribl 12,061 Cribl Alerting
Email threats automatically ingested from Proofpoint TAP 11,548 Proofpoint TAP Ingestion
CrowdStrike SIEM critical-app events monitored 11,547 Crowdstrike Next-Gen SIEM Airlock alert Critical Apps
CrowdStrike SIEM executive-endpoint events monitored 11,546 Crowdstrike Next-Gen SIEM Airlock alert Executive Endpoints
Cortex XDR blocked-execution alerts processed 8,474 Cortex XDR Blocked Processed Alert
Security alerts orchestrated through case management 5,085 Process Alert
Application control block events detected via ThreatLocker 5,777 Threatlocker - Server Block Polling
Delivered phishing emails auto-remediated via Proofpoint TAP (v2) 4,832 Response Subflow - Proofpoint TAP v2 Email Delivered
Data access control alerts ingested from Varonis 3,358 Varonis Opsgenie DAC
ThreatLocker containment actions executed 1,635 Response - Threatlocker Server Block
Vulnerability controls deactivated & remediated 2,123 Vulnerability Deactivation Deactivate Array
Proofpoint URL clicks reviewed 962 Proofpoint URL Click Review
Palo Alto firewall connections continuously monitored 948 Firewall Connection to Panorama Monitor
Ransomware alerts ingested from Halcyon 721 Halcyon Alert Ingestion
Application control approval requests handled 342 Threatlocker Approval request notifications
Phishing site takedown alerts processed 281 Phishlabs Alert
CrowdStrike endpoint alerts triaged 267 6. Ingest and triage a Crowdstrike Alert
Microsoft Defender alerts enriched & triaged 253 Microsoft Defender for Security Alert Triage
Vulnerability controls automatically validated 222 Generic Vulnerability Control Validation
Phishing incidents automatically remediated 193 Remediate Phishlabs Incident
Palo Alto Unit 42 threat escalations processed 164 Unit 42 Escalation Alert
Phishlabs MX record response actions processed (v2) 83 Response Subflow - Phishlabs MX Records v2
Malicious emails quarantined 73 Quarantine Email
Malicious domains blocked in Palo Alto EDLs 70 Tenant Block Domain and Add to EDL
In the last 12 months, Blink automated: - 60,910 malware alerts automatically triaged via Intezer - 34,155 CrowdStrike SIEM events monitored across critical apps and executive endpoints - 12,061 SIEM alerts ingested and routed from Cribl - 11,548 email threats automatically enriched from Proofpoint TAP - 8,474 Cortex XDR blocked-execution alerts processed - 7,412 ThreatLocker application control events detected and contained - 5,085 security alerts orchestrated through case management - 4,832 delivered phishing emails auto-remediated via Proofpoint TAP (v2 response flow) - 3,358 data access control anomalies automatically ingested from Varonis - 2,123 vulnerability controls deactivated and closed - 948 Palo Alto firewall connections continuously monitored - 721 ransomware alerts ingested and triaged from Halcyon - 474 phishing incidents triaged and remediated via Phishlabs - 70 malicious domains blocked in Palo Alto EDLs - 65 Apono JIT access-flow records synced and access requests routed

Use Case Summary

# Use Case Category Playbooks Total Executions (12M)
1 Multi-Source Alert Ingestion & SOC Automation SOC 23 126,850
2 Phishing & Email Threat Response SOC 21 9,503
3 Endpoint Security & Application Control SOC 24 8,610
4 Case Management & SOAR Orchestration SOC 23 26,318
5 Threat Intelligence & IOC Blocking SOC 12 284
6 Firewall & Network Infrastructure Other 18 1,112
7 Vulnerability & Asset Management Vulnerability Mgmt 27 3,117
8 Security Metrics & Executive Reporting GRC 7 152
9 Compliance & Access Governance GRC 9 291
10 Data Loss Prevention & Data Security GRC 8 3,876
11 JIT Access Management (Apono) IAM 6 65

Use Cases

1. Multi-Source Alert Ingestion & SOC Automation

Category: SOC | Subcategories: Agentic SOC, SIEM & log pipeline monitoring, Alert enrichment / IOC lookup

Description: Automated ingestion, enrichment, and routing of security alerts from nine distinct sources — Intezer, CrowdStrike (Next-Gen SIEM), Cribl, Proofpoint TAP, Halcyon, Microsoft Defender, Palo Alto Unit 42, and specialist tools — ensuring every signal enters the case management pipeline without manual triage.

Business problem: Security teams receive thousands of daily alerts across disconnected platforms. Without automation, alert intake is a manual bottleneck that delays triage, increases analyst burnout, and raises dwell time. These workflows eliminate the intake layer entirely, normalizing and routing alerts at machine speed.

Integrations: Intezer, CrowdStrike (Next-Gen SIEM / Falcon), Cribl, Proofpoint TAP, Halcyon, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, Palo Alto Cortex XDR / Unit 42, OpsGenie, Microsoft Outlook, Appono, Imperva, MASNET

Playbook Executions Category Subcategory
On New Intezer Alert 60,910 SOC Agentic SOC, Alert enrichment / IOC lookup
Cribl Alerting 12,061 SOC SIEM & log pipeline monitoring
Proofpoint TAP Ingestion 11,548 SOC SIEM & log pipeline monitoring, Alert enrichment / IOC lookup
Crowdstrike Next-Gen SIEM Airlock alert Critical Apps 11,547 SOC SIEM & log pipeline monitoring
Crowdstrike Next-Gen SIEM Airlock alert Executive Endpoints 11,546 SOC SIEM & log pipeline monitoring
Process Alert 5,085 SOC Agentic SOC, Case mgmt & SOAR
Halcyon Alert Ingestion 721 SOC Alert enrichment / IOC lookup
Microsoft Defender for Security Alert Triage 253 SOC Alert enrichment / IOC lookup
Unit 42 Escalation Alert 164 SOC Alert enrichment / IOC lookup
6. Ingest and triage a Crowdstrike Alert 267 SOC Agentic SOC, Alert enrichment / IOC lookup
Proofpoint TAP Opsgenie Alert 22 SOC Alert enrichment / IOC lookup
O365 Alerts Opsgenie Alert 17 SOC Alert enrichment / IOC lookup
Crowdstrike OpsGenie Alert 15 SOC Alert enrichment / IOC lookup
MASNET Ingestion 13 SOC Agentic SOC, Alert enrichment / IOC lookup
Alert ingestion Appono 10 SOC Alert enrichment / IOC lookup
Imperva DDOS Alert Ingestion 7 SOC Alert enrichment / IOC lookup
Exec Failed Logon Scheduled Query 6 SOC SIEM & log pipeline monitoring
Crowdstrike IOMs Report Webhook 6 SOC Alert enrichment / IOC lookup
Microsoft Defender Alerts 0 SOC Alert enrichment / IOC lookup
Microsoft Defender for Cloud Opsgenie Alert 0 SOC Alert enrichment / IOC lookup
AWS Load Balancer - Create an Alert 0 SOC Alert enrichment / IOC lookup
Varonis Escalation Alerts 1 SOC Alert enrichment / IOC lookup
SS Keywords - Crowdstrike 0 SOC SIEM & log pipeline monitoring
Cortex XDR Blocked Processed Alert 8,474 SOC SIEM & log pipeline monitoring, Alert enrichment / IOC lookup
Microsoft Defender for Security Alert Triage copy 45 SOC Alert enrichment / IOC lookup
Response Subflow - MASNET 0 SOC Agentic SOC, Alert enrichment / IOC lookup
Unit 42 Threathunting Alert 3 SOC Alert enrichment / IOC lookup

2. Phishing & Email Threat Response

Category: SOC | Subcategories: Phishing detection & response, Alert enrichment / IOC lookup

Description: End-to-end automation covering phishing site takedowns via Phishlabs, Proofpoint TAP threat blocking, domain discovery, URL click analysis, and email quarantine — from first detection through remediation without analyst intervention.

Business problem: Phishing remains the leading initial access vector. Manual investigation of phishing alerts, site takedown coordination, and email quarantine actions introduces delays measured in hours; automated response collapses that to minutes.

Integrations: Phishlabs, Proofpoint TAP, Agari Phishing Response, Microsoft Outlook, CrowdStrike (hash/URL analysis), VirusTotal, Intezer

Playbook Executions Category Subcategory
Proofpoint URL Click Review 962 SOC Phishing detection & response
Phishlabs Alert 281 SOC Phishing detection & response
Response Subflow - Phishlabs 215 SOC Phishing detection & response
Remediate Phishlabs Incident 193 SOC Phishing detection & response
Response Subflow - Proofpoint TAP 2,541 SOC Phishing detection & response
Proofpoint TAP Response - Block Threat 86 SOC Phishing detection & response
Quarantine Email 73 SOC Phishing detection & response
Response Subflow - Phishlabs MX Records 68 SOC Phishing detection & response
Grep Search Attachment 65 SOC Phishing detection & response
Regex Search Attachment 58 SOC Phishing detection & response
Enrich - Agari 56 SOC Alert enrichment / IOC lookup
Proofpoint Domain Discover 32 SOC Phishing detection & response
Response Workflow - Proofpoint Domain Discover 29 SOC Phishing detection & response
Response Subflow - Phishlabs v2 3 SOC Phishing detection & response
Whitelist Proofpoint TAP Threat 1 SOC Phishing detection & response
Get Email 0 SOC Phishing detection & response
Get Email Details 0 SOC Phishing detection & response
Get Threat Details 0 SOC Alert enrichment / IOC lookup
Response Subflow - Proofpoint TAP v2 Email Delivered 4,832 SOC Phishing detection & response
Response Subflow - Phishlabs MX Records v2 83 SOC Phishing detection & response
Response Subflow - Proofpoint TAP v2 Click Permitted 0 SOC Phishing detection & response
Enrich - Agari Enrich ID 0 SOC Alert enrichment / IOC lookup
Enrich - URL - Cortex 0 SOC Alert enrichment / IOC lookup
Enrich - Intezer - URL copy 0 SOC Alert enrichment / IOC lookup
Response Subflow - Domain Discover V2 0 SOC Phishing detection & response

3. Endpoint Security & Application Control

Category: SOC | Subcategories: EDR containment & response, Alert enrichment / IOC lookup

Description: Automated application control enforcement via ThreatLocker — detecting server block events, handling approval requests, looking up application hashes, and executing containment actions — plus Halcyon ransomware containment and CrowdStrike EDR enrichment and remote response capabilities.

Business problem: Application control and ransomware containment require sub-minute response times that manual processes cannot reliably deliver. Automated detection and response closes the gap between alert and action, preventing lateral movement and protecting critical server infrastructure.

Integrations: ThreatLocker, Halcyon, CrowdStrike Falcon (RTR, Indicators, Identity), Palo Alto Cortex XDR, Microsoft Entra ID, Microsoft Teams (approval flows)

Playbook Executions Category Subcategory
Threatlocker - Server Block Polling 5,777 SOC EDR containment & response
Response - Threatlocker Server Block 1,635 SOC EDR containment & response
Threatlocker Hash - Find matching applications 448 SOC EDR containment & response
Threatlocker Approval request notifications 342 SOC EDR containment & response
Response Subflow - Halcyon 265 SOC EDR containment & response
Enrich CS Identity Alert 48 SOC Alert enrichment / IOC lookup, Identity threat response
Enrich and store CS event 23 SOC Alert enrichment / IOC lookup
Retro CS Enrichment 19 SOC Alert enrichment / IOC lookup
Block Hash/Hashes in CS 3 SOC EDR containment & response
Agent TIA - Block Hashes in Crowdstrike 1 SOC EDR containment & response, Agentic SOC
Agent TIA - Block IP Addresses 1 SOC EDR containment & response, Agentic SOC
CrowdStrike RTR to a Single Host 0 SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts 0 SOC EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike 0 SOC EDR containment & response
ThreatLocker Handle Application Control Approval Request 0 SOC EDR containment & response
Threatlocker SelfService Learning Mode Request 0 SOC EDR containment & response
Agent TIA - Block Hashes in Cortex 1 SOC EDR containment & response, Agentic SOC
Block Hash/Hashes in Cortex 5 SOC EDR containment & response
Isolate Machine in Cortex 0 SOC EDR containment & response
Response Subflow - Crowdstrike 0 SOC EDR containment & response
Response Subflow - Cortex XDR Blocked Executions 28 SOC EDR containment & response
Threatlocker Request Form 13 SOC EDR containment & response
Revoke User Entra Sessions 1 SOC Identity threat response
Reset User Password Entra 0 SOC Identity threat response

4. Case Management & SOAR Orchestration

Category: SOC | Subcategories: Case mgmt & SOAR

Description: Bi-directional synchronization between Blink Case Management, Jira, and ServiceNow — keeping tickets, comments, status, and assignments consistent across platforms — plus event-driven notifications to Microsoft Teams and AI-assisted comment routing, forming the connective tissue of the SOC workflow.

Business problem: SOC teams lose significant time context-switching between ticketing systems and manually updating status across tools. These workflows keep all platforms in sync automatically, ensure no update is missed, and reduce MTTD/MTTR by eliminating manual cross-system coordination.

Integrations: Jira, ServiceNow, Blink Case Management, Microsoft Teams, OpsGenie

Playbook Executions Category Subcategory
Sync Jira with Case Management 11,388 SOC Case mgmt & SOAR
Migration - Add Comment 4,004 SOC Case mgmt & SOAR
Jira Notify Security Jira Webhook Event 2,642 SOC Case mgmt & SOAR
Sync ALL - Tickets 1,925 SOC Case mgmt & SOAR
Sync ServiceNow with Case Management 1,911 SOC Case mgmt & SOAR
ServiceNow - Find Ticket 1,093 SOC Case mgmt & SOAR
Migration - Create Ticket 857 SOC Case mgmt & SOAR
Cybersecurity Jira Issue Subflow with Add participants 744 SOC Case mgmt & SOAR
Migration - Add Comment Agent 673 SOC Case mgmt & SOAR, Agentic SOC
New ServiceNow Incidents 543 SOC Case mgmt & SOAR
Migration - Update Status 149 SOC Case mgmt & SOAR
Add Halcyon Asset list to ServiceNow ticket 103 SOC Case mgmt & SOAR
ServiceNow - Clean Up Tracked Incidents 83 SOC Case mgmt & SOAR
New SCTASKs 45 SOC Case mgmt & SOAR
Create Cybersecurity Jira Issue 0 SOC Case mgmt & SOAR
Mass Close Jira Tickets 0 SOC Case mgmt & SOAR
Search Case Management 0 SOC Case mgmt & SOAR, Agentic SOC
Query ServiceNow 0 SOC Case mgmt & SOAR, Agentic SOC
Find Security Team Member 0 SOC Case mgmt & SOAR
Response Subflow - Utility - Assign User to ServiceNow Request 1 SOC Case mgmt & SOAR
Response Subflow - Utility - Generic Alert Handle 0 SOC Case mgmt & SOAR, Agentic SOC
Response Subflow - Utility - Handle Ticket Assignment 1 SOC Case mgmt & SOAR
Response Subflow - Utility - Handle Ticket Closure 0 SOC Case mgmt & SOAR

5. Threat Intelligence & IOC Blocking

Category: SOC | Subcategories: Threat intel ingest & curation, Alert enrichment / IOC lookup

Description: Automated IOC blocking and EDL management — enabling analysts and AI agents to block malicious domains, URLs, IPs, and file hashes across Palo Alto Networks EDLs and CrowdStrike indicators, with full audit trails and self-service list synchronization.

Business problem: Manual IOC blocking is a slow, error-prone process that leaves windows of exposure between threat identification and enforcement. These workflows reduce blocking latency to seconds and maintain consistent enforcement across all firewall and EDR control points.

Integrations: Palo Alto Networks (EDL management, Panorama), CrowdStrike Falcon (indicators), Palo Alto Cortex XDR, Microsoft Teams (approval), VirusTotal, PowerShell

Playbook Executions Category Subcategory
Sync List 125 SOC Threat intel ingest & curation
Tenant Block Domain and Add to EDL 70 SOC Threat intel ingest & curation
Tenant Block Domain (No Add to EDL) 46 SOC Threat intel ingest & curation
Tenant List Remove Domain Entry 21 SOC Threat intel ingest & curation
Tenant Block Multiple Domain and Add to EDL 6 SOC Threat intel ingest & curation
Update an EDL List 7 SOC Threat intel ingest & curation
Block Hash/Hashes in CS 3 SOC Threat intel ingest & curation
Agent TIA - Block Domains 0 SOC Threat intel ingest & curation, Agentic SOC
Block Domain 0 SOC Threat intel ingest & curation
Block URL 0 SOC Threat intel ingest & curation
Block Hash/Hashes in Cortex 5 SOC Threat intel ingest & curation
URL Lookup Response 0 SOC Threat intel ingest & curation

6. Firewall & Network Infrastructure

Category: Other | Subcategories: IT/OT & network infra monitoring

Description: Continuous monitoring of Palo Alto Networks firewall health and connectivity via Panorama, automated firmware version caching and lifecycle tracking, SaaS Security Posture Management (SSPM) ingestion, MTTR tracking, and on-demand firewall update and audit workflows.

Business problem: Firewall drift, unmonitored connectivity failures, and delayed firmware updates create exploitable security gaps. Automated daily monitoring and lifecycle workflows ensure real-time visibility into the network perimeter without dedicated manual checks.

Integrations: Palo Alto Networks (Panorama, NGFW API, Cortex XDR, SSPM), Backup systems, Microsoft Outlook

Playbook Executions Category Subcategory
Firewall Connection to Panorama Monitor 948 Other IT/OT & network infra monitoring
Cache versions 40 Other IT/OT & network infra monitoring
Firewall DC Connection Monitoring 40 Other IT/OT & network infra monitoring
Palo Alto SSPM Ingestion 6 Other IT/OT & network infra monitoring
Palo Alto Wildfire Alerts 0 Other IT/OT & network infra monitoring
Update Individual FW 0 Other IT/OT & network infra monitoring
Upgrade FW Group - Production 0 Other IT/OT & network infra monitoring
Backup FW config to Blink 0 Other IT/OT & network infra monitoring
Palo Firewall Audit 0 Other IT/OT & network infra monitoring
Firewall Rule Audit - Aggregate Data 0 Other IT/OT & network infra monitoring
Firewall Rule Audit - Enrich With Agent Data 0 Other IT/OT & network infra monitoring
Firewall Rule Audit - Send Collect and Send Email 0 Other IT/OT & network infra monitoring
Zero Networks delete rules by rule ids 0 Other IT/OT & network infra monitoring
ZN disable rules 0 Other IT/OT & network infra monitoring
Cache versions (FW workspace) 40 Other IT/OT & network infra monitoring
Update Individual FW (FW workspace) 0 Other IT/OT & network infra monitoring
Query Panorama 0 Other IT/OT & network infra monitoring, Agentic SOC
List Panorama Device Groups 0 Other IT/OT & network infra monitoring

7. Vulnerability & Asset Management

Category: Vulnerability Mgmt | Subcategories: Vuln scanning ingest & report, Vuln lifecycle prioritize & ticket, CVE lookup & remediation

Description: Automated collection and normalization of vulnerability data from Axonius (asset inventory, patching compliance, EOL tracking), NetSPI (penetration testing findings), Nucleus (vulnerability management platform), and Tenable — combined with automated control validation, vulnerability deactivation, and CrowdStrike Reduced Functionality Mode (RFM) remediation tracking.

Business problem: Vulnerability backlogs grow faster than teams can manually track, validate, and remediate. These workflows automate the entire lifecycle from scan ingestion to control validation and ticket creation, ensuring no finding ages out of the remediation pipeline.

Integrations: Axonius, Nucleus, NetSPI, Tenable, CrowdStrike (Spotlight / RFM), Jira, Vanta, Microsoft Teams (self-service)

Playbook Executions Category Subcategory
Vulnerability Deactivation Deactivate Array 2,123 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Generic Vulnerability Control Validation 222 Vulnerability Mgmt CVE lookup & remediation
Nucleus Stats 41 Vulnerability Mgmt Vuln scanning ingest & report
Axonius EOL Dashboard Playbook 42 Vulnerability Mgmt Vuln scanning ingest & report
Axonius GP Version Dashboard Playbook 41 Vulnerability Mgmt Vuln scanning ingest & report
Axonius Tables User by Region count 41 Vulnerability Mgmt Vuln scanning ingest & report
Working netspi 41 Vulnerability Mgmt Vuln scanning ingest & report
Nucleus Dashboard Sync 40 Vulnerability Mgmt Vuln scanning ingest & report
NetSPI Nucleus Ingestion 40 Vulnerability Mgmt Vuln scanning ingest & report
Axonius Server Patching Compliance 40 Vulnerability Mgmt Vuln scanning ingest & report
Axonius Endpoint Patching Compliance 40 Vulnerability Mgmt Vuln scanning ingest & report
Retreive NetSpi Stats 40 Vulnerability Mgmt Vuln scanning ingest & report
Crowdstrike RFM 40 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Crowdstrike RFM Ticket Creation 40 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Axonius Agent Coverage Queries 23 Vulnerability Mgmt Vuln scanning ingest & report
Search Axonius for Vulnerable Software 14 Vulnerability Mgmt CVE lookup & remediation
Generic Deactivation Array 16 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Tenable Self Service Vulnerability Scan 0 Vulnerability Mgmt Vuln scan lifecycle automation
Tenable IE to Jira 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Tenable Vulnerability Management 0 Vulnerability Mgmt Vuln scan lifecycle automation
Query Nucleus 0 Vulnerability Mgmt Vuln scanning ingest & report, Agentic SOC
Count Axonius Devices 0 Vulnerability Mgmt Vuln scanning ingest & report, Agentic SOC
Get Axonius Device Details 0 Vulnerability Mgmt Vuln scanning ingest & report, Agentic SOC
Query Tenable 0 Vulnerability Mgmt Vuln scan lifecycle automation, Agentic SOC
Query NetSPI GET 0 Vulnerability Mgmt Vuln scanning ingest & report, Agentic SOC
Query NetSPI 0 Vulnerability Mgmt Vuln scanning ingest & report, Agentic SOC
Count NetSPI 0 Vulnerability Mgmt Vuln scanning ingest & report, Agentic SOC

8. Security Metrics & Executive Reporting

Category: GRC | Subcategories: Security metrics & reporting

Description: Automated daily and weekly collection of security KPIs into dashboards covering Proofpoint email threats, CrowdStrike detection posture, MTTR (Mean Time to Resolve/Remediate) tracking, and scheduled export and delivery of executive reports.

Business problem: Manual preparation of security metrics for CISO and board-level reporting consumes analyst time and produces inconsistent data. Automated pipelines deliver accurate, real-time dashboards and scheduled reports without human intervention.

Integrations: Proofpoint TAP, CrowdStrike, Nucleus, Cortex XDR, Palo Alto Networks, Blink Case Management, Microsoft Outlook

Playbook Executions Category Subcategory
ProofPoint Dash 40 GRC Security metrics & reporting
Crowdstrike Dashboard Sync 40 GRC Security metrics & reporting
Palo Alto MTTR 38 GRC Security metrics & reporting
Retrieve retrospective MttX for a workflow 18 GRC Security metrics & reporting
MttX Scheduler 6 GRC Security metrics & reporting
Export the Dashboard and Send it to Uriel 6 GRC Security metrics & reporting
Query CISO Tables 0 GRC Security metrics & reporting

9. Compliance & Access Governance

Category: GRC | Subcategories: RBAC review & access mgmt, DevSecOps compliance

Description: Automated compliance control execution and validation using a scheduled framework that runs Vanta and Azure-based controls, Okta user verification, GitHub branch protection enforcement, and Litmos learning management — forming a continuous compliance posture engine rather than point-in-time audits.

Business problem: Compliance programs that depend on periodic manual reviews create gaps between audit cycles. A continuous automated control execution framework ensures controls are validated daily, findings surface immediately, and evidence is collected automatically.

Integrations: Okta, Vanta, Azure Active Directory, GitHub, Litmos (learning management), Axonius

Playbook Executions Category Subcategory
Scheduled Executer 40 GRC DevSecOps compliance
Okta External User Verification 40 GRC RBAC review & access mgmt
Axonius Litmos charts Import 40 GRC DevSecOps compliance
Execute a Control and Update Next Run 146 GRC DevSecOps compliance
Generic Control Validation 18 GRC DevSecOps compliance
Github Ensure Branch Protection Enforced 7 GRC DevSecOps compliance
Azure Live Asset Validation 0 GRC RBAC review & access mgmt
Get Group Members from AD 0 GRC RBAC review & access mgmt
Query Vanta 0 GRC DevSecOps compliance, Agentic SOC

10. Data Loss Prevention & Data Security

Category: GRC | Subcategories: DLP triage & exposure resp

Description: Automated ingestion and response for data loss events from Tessian (email-based DLP) and Varonis (data access control), including event enrichment, case creation, and response playbook execution — ensuring every data exfiltration signal is captured and triaged without analyst manual intake.

Business problem: DLP tools generate high volumes of noisy alerts that are frequently ignored or worked in batch. Automated intake and triage ensures consistent investigation of data access anomalies and email-based exfiltration attempts, reducing the risk of undetected insider threats or data breaches.

Integrations: Tessian, Varonis, OpsGenie, Blink Case Management

Playbook Executions Category Subcategory
Varonis Opsgenie DAC 3,358 GRC DLP triage & exposure resp
Tessian DLP Ingest 27 GRC DLP triage & exposure resp
Response Subflow - Tessian 27 GRC DLP triage & exposure resp
Varonis SaaS Alerts 0 GRC DLP triage & exposure resp
Users With Compromised Password 0 GRC DLP triage & exposure resp
Response Subflow - Varonis Escalation Alerts 0 GRC DLP triage & exposure resp

11. JIT Access Management (Apono)

Category: IAM | Subcategories: JIT & temporary access, Access review & group mgmt, Identity sync & directory mgmt

Description: Automated synchronization of Apono just-in-time (JIT) access data — access flows, bundles, scopes, groups, users, integrations, and attributes — into Blink tables for governance visibility, plus ServiceNow-triggered fulfillment of Apono access requests routed to the security engineering team via Microsoft Teams.

Business problem: JIT access platforms generate rich but siloed data that is hard to review without manual exports. These workflows keep Apono access-flow and group data continuously synced for governance review, and automatically route new access requests from ServiceNow to the right approvers, eliminating manual request triage.

Integrations: Apono, ServiceNow, Microsoft Teams

Playbook Executions Category Subcategory
Apono Groups 29 IAM Access review & group mgmt
Apono Access Flow Summary 20 IAM JIT & temporary access, Identity sync & directory mgmt
New Apono Request in ServiceNow 3 IAM JIT & temporary access
Apono Integrations 0 IAM Identity sync & directory mgmt
Apono Table Sync 10 IAM Identity sync & directory mgmt, JIT & temporary access
Apono Azure, Entra Admin Request 3 IAM JIT & temporary access

Key Observations

Strengths

1. Exceptional alert ingestion breadth.

AWAC has automated intake for 10+ distinct alert sources, covering endpoint (Intezer, CrowdStrike), email (Proofpoint TAP), network (Cribl, Imperva), ransomware (Halcyon), data (Varonis), and specialized sources (Appono, MASNET, Unit 42). With over 118,000 executions across the ingestion layer, the SOC is operating a fully automated alert intake pipeline at scale. The Intezer integration alone (60,910 executions) represents one of the highest single-workflow execution volumes in the environment.

2. Mature SOC orchestration fabric.

The case management and SOAR layer is deeply built out, with 26,000+ executions synchronizing state between Blink Case Management, Jira, and ServiceNow in near real-time. The AI-assisted Migration - Add Comment Agent workflow signals early adoption of agentic patterns within core SOAR workflows. This bidirectional sync infrastructure is a significant operational asset.

3. ThreatLocker at production scale.

The application control workflows — server block polling (5,777 runs), automated containment responses (1,635), hash lookups (448), and approval request handling (342) — represent a mature, high-frequency endpoint control automation that would otherwise require constant manual attention from security operations.

4. Continuous compliance control framework.

The compliance workspace (857728f8) implements a scheduled execution engine that continuously runs and validates Vanta and Azure controls. Combined with Okta user verification and GitHub branch protection enforcement, AWAC has moved from periodic compliance audits to continuous automated validation.

5. AI/Agentic adoption in production.

Three Agent TIA (Threat Intelligence & Analysis) workflows for domain blocking, hash blocking, and IP blocking demonstrate early production deployment of agentic automation. The MASNET Ingestion workflow also uses AI agent patterns for complex multi-system orchestration. This positions AWAC ahead of the curve on agentic SOC capabilities.

6. Cortex XDR emerging as a second production EDR pipeline.

Cortex XDR Blocked Processed Alert polls every 5 minutes and has already logged 8,474 executions, plus a growing set of Cortex XDR containment actions (hash blocking, endpoint isolation, agentic hash-block approval). This runs alongside the existing CrowdStrike pipeline, giving AWAC redundant, cross-vendor EDR alert coverage.

7. First IAM use case: Apono JIT access governance.

New workflows continuously sync Apono access flows, groups, bundles, and integrations into Blink tables, and route ServiceNow-initiated Apono access requests to the security engineering team via Teams. This is AWAC's first automated IAM capability and a natural foundation for expanding into broader access-review and provisioning automation.

Gaps & Opportunities

1. CrowdStrike and Cortex XDR EDR response not yet fully automated.

Workflows for CrowdStrike RTR to a Single Host, CrowdStrike RTR to a Batch of Hosts, and Manage Endpoint Quarantine Status in Crowdstrike have 0 executions. CrowdStrike alert ingestion is automated (267 + 11,547 + 11,546 executions) but the response layer — RTR commands, host isolation, containment — is not yet triggered automatically. The newer Isolate Machine in Cortex and Response Subflow - Crowdstrike workflows are similarly built but still at 0 executions. Closing this loop across both EDR platforms would deliver significant MTTR reduction.

2. Tenable integration built but inactive.

Tenable Self Service Vulnerability Scan, Tenable IE to Jira, and Tenable Vulnerability Management all have 0 executions. Given the mature Nucleus pipeline, these may represent a parallel capability that was not fully activated. Tenable self-service via Teams is particularly high-value for enabling non-SOC teams to initiate scans on demand.

3. Firewall rule audit suite not running.

Three Firewall Rule Audit workflows (Aggregate Data, Enrich with Agent Data, Send Email) are built but have 0 executions. A scheduled firewall rule audit would provide ongoing hygiene visibility and support compliance requirements.

4. Varonis SaaS Alerts and Zero Networks inactive.

Varonis SaaS Alerts and both Zero Networks microsegmentation workflows have 0 executions. If Zero Networks is deployed in the environment, automated rule cleanup and disablement workflows could significantly reduce the manual burden of microsegmentation policy management.

5. Fragmented workflow copies.

The environment contains multiple "copy" variants of core workflows (Sync List, Tenant Block Domain, Add Users to Team, etc.) with 0 executions. These represent technical debt and risk of divergence. A consolidation pass would reduce maintenance overhead and eliminate confusion about which workflow is canonical.

Integration Ecosystem

AWAC operates one of the most diverse integration ecosystems in the Blink customer base, spanning 20+ distinct security and IT platforms:

Domain Integrations
Endpoint / EDR CrowdStrike Falcon, Palo Alto Cortex XDR, ThreatLocker, Halcyon, Microsoft Defender for Endpoint
Email Security Proofpoint TAP, Tessian, Agari, Phishlabs, Microsoft Outlook / O365
SIEM / Log Pipeline CrowdStrike Next-Gen SIEM, Cribl
SOAR / Ticketing Blink Case Management, Jira, ServiceNow, OpsGenie
Network / Firewall Palo Alto Networks (Panorama, NGFW, SSPM, Cortex XDR, Unit 42), Imperva, Zero Networks
Vulnerability Mgmt Axonius, Nucleus, NetSPI, Tenable
Data Security Varonis
Identity Okta, Microsoft Entra ID, Google Workspace, Apono
Threat Intel Intezer, VirusTotal, URLScan, AbuseIPDB, MASNET, Appono
Compliance Vanta, GitHub, Azure AD
Collaboration Microsoft Teams, Slack
Learning Litmos
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.