01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Multi-Source Alert Ingestion & SOC Automation |
| 45.6% | 24 24 active |
| Phishing & Email Threat Response |
| 8.7% | 21 21 active |
| Endpoint Security & Application Control |
| 12.5% | 22 22 active |
| Case Management & SOAR Orchestration | 5,352 executions | 4.6% | 23 22 active |
| Threat Intelligence & IOC Blocking |
| 0.1% | 13 13 active |
| Firewall & Network Infrastructure |
| 0.9% | 15 15 active |
| Vulnerability & Asset Management |
| 1.3% | 27 27 active |
| Security Metrics & Executive Reporting | 150 executions | 0.1% | 6 6 active |
| Compliance & Access Governance | 256 executions | 0.2% | 9 9 active |
| Data Loss Prevention & Data Security |
| 0.1% | 6 5 active |
| JIT Access Management (Apono) | 89 executions | 0.1% | 6 6 active |
| Total | 86,501 executions | 100% | 172 170 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. Exceptional alert ingestion breadth.
AWAC has automated intake for 10+ distinct alert sources, covering endpoint (Intezer, CrowdStrike), email (Proofpoint TAP), network (Cribl, Imperva), ransomware (Halcyon), data (Varonis), and specialized sources (Appono, MASNET, Unit 42). With over 118,000 executions across the ingestion layer, the SOC is operating a fully automated alert intake pipeline at scale. The Intezer integration alone (60,910 executions) represents one of the highest single-workflow execution volumes in the environment.
2. Mature SOC orchestration fabric.
The case management and SOAR layer is deeply built out, with 26,000+ executions synchronizing state between Blink Case Management, Jira, and ServiceNow in near real-time. The AI-assisted Migration - Add Comment Agent workflow signals early adoption of agentic patterns within core SOAR workflows. This bidirectional sync infrastructure is a significant operational asset.
3. ThreatLocker at production scale.
The application control workflows — server block polling (5,777 runs), automated containment responses (1,635), hash lookups (448), and approval request handling (342) — represent a mature, high-frequency endpoint control automation that would otherwise require constant manual attention from security operations.
4. Continuous compliance control framework.
The compliance workspace (857728f8) implements a scheduled execution engine that continuously runs and validates Vanta and Azure controls. Combined with Okta user verification and GitHub branch protection enforcement, AWAC has moved from periodic compliance audits to continuous automated validation.
5. AI/Agentic adoption in production.
Three Agent TIA (Threat Intelligence & Analysis) workflows for domain blocking, hash blocking, and IP blocking demonstrate early production deployment of agentic automation. The MASNET Ingestion workflow also uses AI agent patterns for complex multi-system orchestration. This positions AWAC ahead of the curve on agentic SOC capabilities.
6. Cortex XDR emerging as a second production EDR pipeline.
Cortex XDR Blocked Processed Alert polls every 5 minutes and has already logged 8,474 executions, plus a growing set of Cortex XDR containment actions (hash blocking, endpoint isolation, agentic hash-block approval). This runs alongside the existing CrowdStrike pipeline, giving AWAC redundant, cross-vendor EDR alert coverage.
7. First IAM use case: Apono JIT access governance.
New workflows continuously sync Apono access flows, groups, bundles, and integrations into Blink tables, and route ServiceNow-initiated Apono access requests to the security engineering team via Teams. This is AWAC's first automated IAM capability and a natural foundation for expanding into broader access-review and provisioning automation.
###
Gaps & Opportunities
1. CrowdStrike and Cortex XDR EDR response not yet fully automated.
Workflows for CrowdStrike RTR to a Single Host, CrowdStrike RTR to a Batch of Hosts, and Manage Endpoint Quarantine Status in Crowdstrike have 0 executions. CrowdStrike alert ingestion is automated (267 + 11,547 + 11,546 executions) but the response layer — RTR commands, host isolation, containment — is not yet triggered automatically. The newer Isolate Machine in Cortex and Response Subflow - Crowdstrike workflows are similarly built but still at 0 executions. Closing this loop across both EDR platforms would deliver significant MTTR reduction.
2. Tenable integration built but inactive.
Tenable Self Service Vulnerability Scan, Tenable IE to Jira, and Tenable Vulnerability Management all have 0 executions. Given the mature Nucleus pipeline, these may represent a parallel capability that was not fully activated. Tenable self-service via Teams is particularly high-value for enabling non-SOC teams to initiate scans on demand.
3. Firewall rule audit suite not running.
Three Firewall Rule Audit workflows (Aggregate Data, Enrich with Agent Data, Send Email) are built but have 0 executions. A scheduled firewall rule audit would provide ongoing hygiene visibility and support compliance requirements.
4. Varonis SaaS Alerts and Zero Networks inactive.
Varonis SaaS Alerts and both Zero Networks microsegmentation workflows have 0 executions. If Zero Networks is deployed in the environment, automated rule cleanup and disablement workflows could significantly reduce the manual burden of microsegmentation policy management.
5. Fragmented workflow copies.
The environment contains multiple "copy" variants of core workflows (Sync List, Tenant Block Domain, Add Users to Team, etc.) with 0 executions. These represent technical debt and risk of divergence. A consolidation pass would reduce maintenance overhead and eliminate confusion about which workflow is canonical.
Integration Ecosystem
AWAC operates one of the most diverse integration ecosystems in the Blink customer base, spanning 20+ distinct security and IT platforms:
| Domain | Integrations |
|---|---|
| Endpoint / EDR | CrowdStrike Falcon, Palo Alto Cortex XDR, ThreatLocker, Halcyon, Microsoft Defender for Endpoint |
| Email Security | Proofpoint TAP, Tessian, Agari, Phishlabs, Microsoft Outlook / O365 |
| SIEM / Log Pipeline | CrowdStrike Next-Gen SIEM, Cribl |
| SOAR / Ticketing | Blink Case Management, Jira, ServiceNow, OpsGenie |
| Network / Firewall | Palo Alto Networks (Panorama, NGFW, SSPM, Cortex XDR, Unit 42), Imperva, Zero Networks |
| Vulnerability Mgmt | Axonius, Nucleus, NetSPI, Tenable |
| Data Security | Varonis |
| Identity | Okta, Microsoft Entra ID, Google Workspace, Apono |
| Threat Intel | Intezer, VirusTotal, URLScan, AbuseIPDB, MASNET, Appono |
| Compliance | Vanta, GitHub, Azure AD |
| Collaboration | Microsoft Teams, Slack |
| Learning | Litmos |
A Case Management 14,089 cases (12m) | MTTR 4d 6h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| AW Production | 14,087 | 14,087 | 13,920 | 4d 6h |
| Case Management | 2 | 2 | 0 | N/A |
B AI Agents 14 active | 5,215 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Domain Analyzer | AW Production | 1,954 | 19 | 147,733,143 |
| 2 | Agent Pete | AW Production | 1,436 | 416 | 150,705,493 |
| 3 | Agent Phil | AW Production | 798 | 54 | 16,340,901 |
| 4 | Agent DiL Pickle | AW Production | 262 | 27 | 19,404,854 |
| 5 | Agent Fred | AW Production | 239 | 0 | 5,762,604 |
| Workspace | Tasks (12m) |
|---|---|
| AW Production | 5,215 |
| Case Management | 0 |
| AW Vulnerability Management | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Domain Blocks | 0 | 0 |
| 2 | sdfd | 0 | 0 |
| 3 | Security - Main | 0 | 0 |
| 4 | CISO Dashboard - WIP | 0 | 0 |
| 5 | MttX PoC Board | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Threatlocker Learning Mode Self Service Request | 0 | 0 |
D Full Use Case Analysis 11 use cases | 116,552 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Malware & endpoint alerts auto-triaged via Intezer | 60,910 | On New Intezer Alert |
| SIEM alerts ingested & routed from Cribl | 12,061 | Cribl Alerting |
| Email threats automatically ingested from Proofpoint TAP | 11,548 | Proofpoint TAP Ingestion |
| CrowdStrike SIEM critical-app events monitored | 11,547 | Crowdstrike Next-Gen SIEM Airlock alert Critical Apps |
| CrowdStrike SIEM executive-endpoint events monitored | 11,546 | Crowdstrike Next-Gen SIEM Airlock alert Executive Endpoints |
| Cortex XDR blocked-execution alerts processed | 8,474 | Cortex XDR Blocked Processed Alert |
| Security alerts orchestrated through case management | 5,085 | Process Alert |
| Application control block events detected via ThreatLocker | 5,777 | Threatlocker - Server Block Polling |
| Delivered phishing emails auto-remediated via Proofpoint TAP (v2) | 4,832 | Response Subflow - Proofpoint TAP v2 Email Delivered |
| Data access control alerts ingested from Varonis | 3,358 | Varonis Opsgenie DAC |
| ThreatLocker containment actions executed | 1,635 | Response - Threatlocker Server Block |
| Vulnerability controls deactivated & remediated | 2,123 | Vulnerability Deactivation Deactivate Array |
| Proofpoint URL clicks reviewed | 962 | Proofpoint URL Click Review |
| Palo Alto firewall connections continuously monitored | 948 | Firewall Connection to Panorama Monitor |
| Ransomware alerts ingested from Halcyon | 721 | Halcyon Alert Ingestion |
| Application control approval requests handled | 342 | Threatlocker Approval request notifications |
| Phishing site takedown alerts processed | 281 | Phishlabs Alert |
| CrowdStrike endpoint alerts triaged | 267 | 6. Ingest and triage a Crowdstrike Alert |
| Microsoft Defender alerts enriched & triaged | 253 | Microsoft Defender for Security Alert Triage |
| Vulnerability controls automatically validated | 222 | Generic Vulnerability Control Validation |
| Phishing incidents automatically remediated | 193 | Remediate Phishlabs Incident |
| Palo Alto Unit 42 threat escalations processed | 164 | Unit 42 Escalation Alert |
| Phishlabs MX record response actions processed (v2) | 83 | Response Subflow - Phishlabs MX Records v2 |
| Malicious emails quarantined | 73 | Quarantine Email |
| Malicious domains blocked in Palo Alto EDLs | 70 | Tenant Block Domain and Add to EDL |
Use Case Summary
| # | Use Case | Category | Playbooks | Total Executions (12M) |
|---|---|---|---|---|
| 1 | Multi-Source Alert Ingestion & SOC Automation | SOC | 23 | 126,850 |
| 2 | Phishing & Email Threat Response | SOC | 21 | 9,503 |
| 3 | Endpoint Security & Application Control | SOC | 24 | 8,610 |
| 4 | Case Management & SOAR Orchestration | SOC | 23 | 26,318 |
| 5 | Threat Intelligence & IOC Blocking | SOC | 12 | 284 |
| 6 | Firewall & Network Infrastructure | Other | 18 | 1,112 |
| 7 | Vulnerability & Asset Management | Vulnerability Mgmt | 27 | 3,117 |
| 8 | Security Metrics & Executive Reporting | GRC | 7 | 152 |
| 9 | Compliance & Access Governance | GRC | 9 | 291 |
| 10 | Data Loss Prevention & Data Security | GRC | 8 | 3,876 |
| 11 | JIT Access Management (Apono) | IAM | 6 | 65 |
Use Cases
1. Multi-Source Alert Ingestion & SOC Automation
Category: SOC | Subcategories: Agentic SOC, SIEM & log pipeline monitoring, Alert enrichment / IOC lookup
Description: Automated ingestion, enrichment, and routing of security alerts from nine distinct sources — Intezer, CrowdStrike (Next-Gen SIEM), Cribl, Proofpoint TAP, Halcyon, Microsoft Defender, Palo Alto Unit 42, and specialist tools — ensuring every signal enters the case management pipeline without manual triage.
Business problem: Security teams receive thousands of daily alerts across disconnected platforms. Without automation, alert intake is a manual bottleneck that delays triage, increases analyst burnout, and raises dwell time. These workflows eliminate the intake layer entirely, normalizing and routing alerts at machine speed.
Integrations: Intezer, CrowdStrike (Next-Gen SIEM / Falcon), Cribl, Proofpoint TAP, Halcyon, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, Palo Alto Cortex XDR / Unit 42, OpsGenie, Microsoft Outlook, Appono, Imperva, MASNET
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| On New Intezer Alert | 60,910 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Cribl Alerting | 12,061 | SOC | SIEM & log pipeline monitoring |
| Proofpoint TAP Ingestion | 11,548 | SOC | SIEM & log pipeline monitoring, Alert enrichment / IOC lookup |
| Crowdstrike Next-Gen SIEM Airlock alert Critical Apps | 11,547 | SOC | SIEM & log pipeline monitoring |
| Crowdstrike Next-Gen SIEM Airlock alert Executive Endpoints | 11,546 | SOC | SIEM & log pipeline monitoring |
| Process Alert | 5,085 | SOC | Agentic SOC, Case mgmt & SOAR |
| Halcyon Alert Ingestion | 721 | SOC | Alert enrichment / IOC lookup |
| Microsoft Defender for Security Alert Triage | 253 | SOC | Alert enrichment / IOC lookup |
| Unit 42 Escalation Alert | 164 | SOC | Alert enrichment / IOC lookup |
| 6. Ingest and triage a Crowdstrike Alert | 267 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Proofpoint TAP Opsgenie Alert | 22 | SOC | Alert enrichment / IOC lookup |
| O365 Alerts Opsgenie Alert | 17 | SOC | Alert enrichment / IOC lookup |
| Crowdstrike OpsGenie Alert | 15 | SOC | Alert enrichment / IOC lookup |
| MASNET Ingestion | 13 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Alert ingestion Appono | 10 | SOC | Alert enrichment / IOC lookup |
| Imperva DDOS Alert Ingestion | 7 | SOC | Alert enrichment / IOC lookup |
| Exec Failed Logon Scheduled Query | 6 | SOC | SIEM & log pipeline monitoring |
| Crowdstrike IOMs Report Webhook | 6 | SOC | Alert enrichment / IOC lookup |
| Microsoft Defender Alerts | 0 | SOC | Alert enrichment / IOC lookup |
| Microsoft Defender for Cloud Opsgenie Alert | 0 | SOC | Alert enrichment / IOC lookup |
| AWS Load Balancer - Create an Alert | 0 | SOC | Alert enrichment / IOC lookup |
| Varonis Escalation Alerts | 1 | SOC | Alert enrichment / IOC lookup |
| SS Keywords - Crowdstrike | 0 | SOC | SIEM & log pipeline monitoring |
| Cortex XDR Blocked Processed Alert | 8,474 | SOC | SIEM & log pipeline monitoring, Alert enrichment / IOC lookup |
| Microsoft Defender for Security Alert Triage copy | 45 | SOC | Alert enrichment / IOC lookup |
| Response Subflow - MASNET | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
| Unit 42 Threathunting Alert | 3 | SOC | Alert enrichment / IOC lookup |
2. Phishing & Email Threat Response
Category: SOC | Subcategories: Phishing detection & response, Alert enrichment / IOC lookup
Description: End-to-end automation covering phishing site takedowns via Phishlabs, Proofpoint TAP threat blocking, domain discovery, URL click analysis, and email quarantine — from first detection through remediation without analyst intervention.
Business problem: Phishing remains the leading initial access vector. Manual investigation of phishing alerts, site takedown coordination, and email quarantine actions introduces delays measured in hours; automated response collapses that to minutes.
Integrations: Phishlabs, Proofpoint TAP, Agari Phishing Response, Microsoft Outlook, CrowdStrike (hash/URL analysis), VirusTotal, Intezer
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Proofpoint URL Click Review | 962 | SOC | Phishing detection & response |
| Phishlabs Alert | 281 | SOC | Phishing detection & response |
| Response Subflow - Phishlabs | 215 | SOC | Phishing detection & response |
| Remediate Phishlabs Incident | 193 | SOC | Phishing detection & response |
| Response Subflow - Proofpoint TAP | 2,541 | SOC | Phishing detection & response |
| Proofpoint TAP Response - Block Threat | 86 | SOC | Phishing detection & response |
| Quarantine Email | 73 | SOC | Phishing detection & response |
| Response Subflow - Phishlabs MX Records | 68 | SOC | Phishing detection & response |
| Grep Search Attachment | 65 | SOC | Phishing detection & response |
| Regex Search Attachment | 58 | SOC | Phishing detection & response |
| Enrich - Agari | 56 | SOC | Alert enrichment / IOC lookup |
| Proofpoint Domain Discover | 32 | SOC | Phishing detection & response |
| Response Workflow - Proofpoint Domain Discover | 29 | SOC | Phishing detection & response |
| Response Subflow - Phishlabs v2 | 3 | SOC | Phishing detection & response |
| Whitelist Proofpoint TAP Threat | 1 | SOC | Phishing detection & response |
| Get Email | 0 | SOC | Phishing detection & response |
| Get Email Details | 0 | SOC | Phishing detection & response |
| Get Threat Details | 0 | SOC | Alert enrichment / IOC lookup |
| Response Subflow - Proofpoint TAP v2 Email Delivered | 4,832 | SOC | Phishing detection & response |
| Response Subflow - Phishlabs MX Records v2 | 83 | SOC | Phishing detection & response |
| Response Subflow - Proofpoint TAP v2 Click Permitted | 0 | SOC | Phishing detection & response |
| Enrich - Agari Enrich ID | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - Cortex | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Intezer - URL copy | 0 | SOC | Alert enrichment / IOC lookup |
| Response Subflow - Domain Discover V2 | 0 | SOC | Phishing detection & response |
3. Endpoint Security & Application Control
Category: SOC | Subcategories: EDR containment & response, Alert enrichment / IOC lookup
Description: Automated application control enforcement via ThreatLocker — detecting server block events, handling approval requests, looking up application hashes, and executing containment actions — plus Halcyon ransomware containment and CrowdStrike EDR enrichment and remote response capabilities.
Business problem: Application control and ransomware containment require sub-minute response times that manual processes cannot reliably deliver. Automated detection and response closes the gap between alert and action, preventing lateral movement and protecting critical server infrastructure.
Integrations: ThreatLocker, Halcyon, CrowdStrike Falcon (RTR, Indicators, Identity), Palo Alto Cortex XDR, Microsoft Entra ID, Microsoft Teams (approval flows)
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Threatlocker - Server Block Polling | 5,777 | SOC | EDR containment & response |
| Response - Threatlocker Server Block | 1,635 | SOC | EDR containment & response |
| Threatlocker Hash - Find matching applications | 448 | SOC | EDR containment & response |
| Threatlocker Approval request notifications | 342 | SOC | EDR containment & response |
| Response Subflow - Halcyon | 265 | SOC | EDR containment & response |
| Enrich CS Identity Alert | 48 | SOC | Alert enrichment / IOC lookup, Identity threat response |
| Enrich and store CS event | 23 | SOC | Alert enrichment / IOC lookup |
| Retro CS Enrichment | 19 | SOC | Alert enrichment / IOC lookup |
| Block Hash/Hashes in CS | 3 | SOC | EDR containment & response |
| Agent TIA - Block Hashes in Crowdstrike | 1 | SOC | EDR containment & response, Agentic SOC |
| Agent TIA - Block IP Addresses | 1 | SOC | EDR containment & response, Agentic SOC |
| CrowdStrike RTR to a Single Host | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | 0 | SOC | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | SOC | EDR containment & response |
| ThreatLocker Handle Application Control Approval Request | 0 | SOC | EDR containment & response |
| Threatlocker SelfService Learning Mode Request | 0 | SOC | EDR containment & response |
| Agent TIA - Block Hashes in Cortex | 1 | SOC | EDR containment & response, Agentic SOC |
| Block Hash/Hashes in Cortex | 5 | SOC | EDR containment & response |
| Isolate Machine in Cortex | 0 | SOC | EDR containment & response |
| Response Subflow - Crowdstrike | 0 | SOC | EDR containment & response |
| Response Subflow - Cortex XDR Blocked Executions | 28 | SOC | EDR containment & response |
| Threatlocker Request Form | 13 | SOC | EDR containment & response |
| Revoke User Entra Sessions | 1 | SOC | Identity threat response |
| Reset User Password Entra | 0 | SOC | Identity threat response |
4. Case Management & SOAR Orchestration
Category: SOC | Subcategories: Case mgmt & SOAR
Description: Bi-directional synchronization between Blink Case Management, Jira, and ServiceNow — keeping tickets, comments, status, and assignments consistent across platforms — plus event-driven notifications to Microsoft Teams and AI-assisted comment routing, forming the connective tissue of the SOC workflow.
Business problem: SOC teams lose significant time context-switching between ticketing systems and manually updating status across tools. These workflows keep all platforms in sync automatically, ensure no update is missed, and reduce MTTD/MTTR by eliminating manual cross-system coordination.
Integrations: Jira, ServiceNow, Blink Case Management, Microsoft Teams, OpsGenie
5. Threat Intelligence & IOC Blocking
Category: SOC | Subcategories: Threat intel ingest & curation, Alert enrichment / IOC lookup
Description: Automated IOC blocking and EDL management — enabling analysts and AI agents to block malicious domains, URLs, IPs, and file hashes across Palo Alto Networks EDLs and CrowdStrike indicators, with full audit trails and self-service list synchronization.
Business problem: Manual IOC blocking is a slow, error-prone process that leaves windows of exposure between threat identification and enforcement. These workflows reduce blocking latency to seconds and maintain consistent enforcement across all firewall and EDR control points.
Integrations: Palo Alto Networks (EDL management, Panorama), CrowdStrike Falcon (indicators), Palo Alto Cortex XDR, Microsoft Teams (approval), VirusTotal, PowerShell
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Sync List | 125 | SOC | Threat intel ingest & curation |
| Tenant Block Domain and Add to EDL | 70 | SOC | Threat intel ingest & curation |
| Tenant Block Domain (No Add to EDL) | 46 | SOC | Threat intel ingest & curation |
| Tenant List Remove Domain Entry | 21 | SOC | Threat intel ingest & curation |
| Tenant Block Multiple Domain and Add to EDL | 6 | SOC | Threat intel ingest & curation |
| Update an EDL List | 7 | SOC | Threat intel ingest & curation |
| Block Hash/Hashes in CS | 3 | SOC | Threat intel ingest & curation |
| Agent TIA - Block Domains | 0 | SOC | Threat intel ingest & curation, Agentic SOC |
| Block Domain | 0 | SOC | Threat intel ingest & curation |
| Block URL | 0 | SOC | Threat intel ingest & curation |
| Block Hash/Hashes in Cortex | 5 | SOC | Threat intel ingest & curation |
| URL Lookup Response | 0 | SOC | Threat intel ingest & curation |
6. Firewall & Network Infrastructure
Category: Other | Subcategories: IT/OT & network infra monitoring
Description: Continuous monitoring of Palo Alto Networks firewall health and connectivity via Panorama, automated firmware version caching and lifecycle tracking, SaaS Security Posture Management (SSPM) ingestion, MTTR tracking, and on-demand firewall update and audit workflows.
Business problem: Firewall drift, unmonitored connectivity failures, and delayed firmware updates create exploitable security gaps. Automated daily monitoring and lifecycle workflows ensure real-time visibility into the network perimeter without dedicated manual checks.
Integrations: Palo Alto Networks (Panorama, NGFW API, Cortex XDR, SSPM), Backup systems, Microsoft Outlook
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Firewall Connection to Panorama Monitor | 948 | Other | IT/OT & network infra monitoring |
| Cache versions | 40 | Other | IT/OT & network infra monitoring |
| Firewall DC Connection Monitoring | 40 | Other | IT/OT & network infra monitoring |
| Palo Alto SSPM Ingestion | 6 | Other | IT/OT & network infra monitoring |
| Palo Alto Wildfire Alerts | 0 | Other | IT/OT & network infra monitoring |
| Update Individual FW | 0 | Other | IT/OT & network infra monitoring |
| Upgrade FW Group - Production | 0 | Other | IT/OT & network infra monitoring |
| Backup FW config to Blink | 0 | Other | IT/OT & network infra monitoring |
| Palo Firewall Audit | 0 | Other | IT/OT & network infra monitoring |
| Firewall Rule Audit - Aggregate Data | 0 | Other | IT/OT & network infra monitoring |
| Firewall Rule Audit - Enrich With Agent Data | 0 | Other | IT/OT & network infra monitoring |
| Firewall Rule Audit - Send Collect and Send Email | 0 | Other | IT/OT & network infra monitoring |
| Zero Networks delete rules by rule ids | 0 | Other | IT/OT & network infra monitoring |
| ZN disable rules | 0 | Other | IT/OT & network infra monitoring |
| Cache versions (FW workspace) | 40 | Other | IT/OT & network infra monitoring |
| Update Individual FW (FW workspace) | 0 | Other | IT/OT & network infra monitoring |
| Query Panorama | 0 | Other | IT/OT & network infra monitoring, Agentic SOC |
| List Panorama Device Groups | 0 | Other | IT/OT & network infra monitoring |
7. Vulnerability & Asset Management
Category: Vulnerability Mgmt | Subcategories: Vuln scanning ingest & report, Vuln lifecycle prioritize & ticket, CVE lookup & remediation
Description: Automated collection and normalization of vulnerability data from Axonius (asset inventory, patching compliance, EOL tracking), NetSPI (penetration testing findings), Nucleus (vulnerability management platform), and Tenable — combined with automated control validation, vulnerability deactivation, and CrowdStrike Reduced Functionality Mode (RFM) remediation tracking.
Business problem: Vulnerability backlogs grow faster than teams can manually track, validate, and remediate. These workflows automate the entire lifecycle from scan ingestion to control validation and ticket creation, ensuring no finding ages out of the remediation pipeline.
Integrations: Axonius, Nucleus, NetSPI, Tenable, CrowdStrike (Spotlight / RFM), Jira, Vanta, Microsoft Teams (self-service)
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Vulnerability Deactivation Deactivate Array | 2,123 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Generic Vulnerability Control Validation | 222 | Vulnerability Mgmt | CVE lookup & remediation |
| Nucleus Stats | 41 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Axonius EOL Dashboard Playbook | 42 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Axonius GP Version Dashboard Playbook | 41 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Axonius Tables User by Region count | 41 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Working netspi | 41 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Nucleus Dashboard Sync | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| NetSPI Nucleus Ingestion | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Axonius Server Patching Compliance | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Axonius Endpoint Patching Compliance | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Retreive NetSpi Stats | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Crowdstrike RFM | 40 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Crowdstrike RFM Ticket Creation | 40 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Axonius Agent Coverage Queries | 23 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Search Axonius for Vulnerable Software | 14 | Vulnerability Mgmt | CVE lookup & remediation |
| Generic Deactivation Array | 16 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Tenable Self Service Vulnerability Scan | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Tenable IE to Jira | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Tenable Vulnerability Management | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Query Nucleus | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Agentic SOC |
| Count Axonius Devices | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Agentic SOC |
| Get Axonius Device Details | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Agentic SOC |
| Query Tenable | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation, Agentic SOC |
| Query NetSPI GET | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Agentic SOC |
| Query NetSPI | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Agentic SOC |
| Count NetSPI | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Agentic SOC |
8. Security Metrics & Executive Reporting
Category: GRC | Subcategories: Security metrics & reporting
Description: Automated daily and weekly collection of security KPIs into dashboards covering Proofpoint email threats, CrowdStrike detection posture, MTTR (Mean Time to Resolve/Remediate) tracking, and scheduled export and delivery of executive reports.
Business problem: Manual preparation of security metrics for CISO and board-level reporting consumes analyst time and produces inconsistent data. Automated pipelines deliver accurate, real-time dashboards and scheduled reports without human intervention.
Integrations: Proofpoint TAP, CrowdStrike, Nucleus, Cortex XDR, Palo Alto Networks, Blink Case Management, Microsoft Outlook
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| ProofPoint Dash | 40 | GRC | Security metrics & reporting |
| Crowdstrike Dashboard Sync | 40 | GRC | Security metrics & reporting |
| Palo Alto MTTR | 38 | GRC | Security metrics & reporting |
| Retrieve retrospective MttX for a workflow | 18 | GRC | Security metrics & reporting |
| MttX Scheduler | 6 | GRC | Security metrics & reporting |
| Export the Dashboard and Send it to Uriel | 6 | GRC | Security metrics & reporting |
| Query CISO Tables | 0 | GRC | Security metrics & reporting |
9. Compliance & Access Governance
Category: GRC | Subcategories: RBAC review & access mgmt, DevSecOps compliance
Description: Automated compliance control execution and validation using a scheduled framework that runs Vanta and Azure-based controls, Okta user verification, GitHub branch protection enforcement, and Litmos learning management — forming a continuous compliance posture engine rather than point-in-time audits.
Business problem: Compliance programs that depend on periodic manual reviews create gaps between audit cycles. A continuous automated control execution framework ensures controls are validated daily, findings surface immediately, and evidence is collected automatically.
Integrations: Okta, Vanta, Azure Active Directory, GitHub, Litmos (learning management), Axonius
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Scheduled Executer | 40 | GRC | DevSecOps compliance |
| Okta External User Verification | 40 | GRC | RBAC review & access mgmt |
| Axonius Litmos charts Import | 40 | GRC | DevSecOps compliance |
| Execute a Control and Update Next Run | 146 | GRC | DevSecOps compliance |
| Generic Control Validation | 18 | GRC | DevSecOps compliance |
| Github Ensure Branch Protection Enforced | 7 | GRC | DevSecOps compliance |
| Azure Live Asset Validation | 0 | GRC | RBAC review & access mgmt |
| Get Group Members from AD | 0 | GRC | RBAC review & access mgmt |
| Query Vanta | 0 | GRC | DevSecOps compliance, Agentic SOC |
10. Data Loss Prevention & Data Security
Category: GRC | Subcategories: DLP triage & exposure resp
Description: Automated ingestion and response for data loss events from Tessian (email-based DLP) and Varonis (data access control), including event enrichment, case creation, and response playbook execution — ensuring every data exfiltration signal is captured and triaged without analyst manual intake.
Business problem: DLP tools generate high volumes of noisy alerts that are frequently ignored or worked in batch. Automated intake and triage ensures consistent investigation of data access anomalies and email-based exfiltration attempts, reducing the risk of undetected insider threats or data breaches.
Integrations: Tessian, Varonis, OpsGenie, Blink Case Management
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Varonis Opsgenie DAC | 3,358 | GRC | DLP triage & exposure resp |
| Tessian DLP Ingest | 27 | GRC | DLP triage & exposure resp |
| Response Subflow - Tessian | 27 | GRC | DLP triage & exposure resp |
| Varonis SaaS Alerts | 0 | GRC | DLP triage & exposure resp |
| Users With Compromised Password | 0 | GRC | DLP triage & exposure resp |
| Response Subflow - Varonis Escalation Alerts | 0 | GRC | DLP triage & exposure resp |
11. JIT Access Management (Apono)
Category: IAM | Subcategories: JIT & temporary access, Access review & group mgmt, Identity sync & directory mgmt
Description: Automated synchronization of Apono just-in-time (JIT) access data — access flows, bundles, scopes, groups, users, integrations, and attributes — into Blink tables for governance visibility, plus ServiceNow-triggered fulfillment of Apono access requests routed to the security engineering team via Microsoft Teams.
Business problem: JIT access platforms generate rich but siloed data that is hard to review without manual exports. These workflows keep Apono access-flow and group data continuously synced for governance review, and automatically route new access requests from ServiceNow to the right approvers, eliminating manual request triage.
Integrations: Apono, ServiceNow, Microsoft Teams
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Apono Groups | 29 | IAM | Access review & group mgmt |
| Apono Access Flow Summary | 20 | IAM | JIT & temporary access, Identity sync & directory mgmt |
| New Apono Request in ServiceNow | 3 | IAM | JIT & temporary access |
| Apono Integrations | 0 | IAM | Identity sync & directory mgmt |
| Apono Table Sync | 10 | IAM | Identity sync & directory mgmt, JIT & temporary access |
| Apono Azure, Entra Admin Request | 3 | IAM | JIT & temporary access |
Key Observations
Strengths
1. Exceptional alert ingestion breadth.
AWAC has automated intake for 10+ distinct alert sources, covering endpoint (Intezer, CrowdStrike), email (Proofpoint TAP), network (Cribl, Imperva), ransomware (Halcyon), data (Varonis), and specialized sources (Appono, MASNET, Unit 42). With over 118,000 executions across the ingestion layer, the SOC is operating a fully automated alert intake pipeline at scale. The Intezer integration alone (60,910 executions) represents one of the highest single-workflow execution volumes in the environment.
2. Mature SOC orchestration fabric.
The case management and SOAR layer is deeply built out, with 26,000+ executions synchronizing state between Blink Case Management, Jira, and ServiceNow in near real-time. The AI-assisted Migration - Add Comment Agent workflow signals early adoption of agentic patterns within core SOAR workflows. This bidirectional sync infrastructure is a significant operational asset.
3. ThreatLocker at production scale.
The application control workflows — server block polling (5,777 runs), automated containment responses (1,635), hash lookups (448), and approval request handling (342) — represent a mature, high-frequency endpoint control automation that would otherwise require constant manual attention from security operations.
4. Continuous compliance control framework.
The compliance workspace (857728f8) implements a scheduled execution engine that continuously runs and validates Vanta and Azure controls. Combined with Okta user verification and GitHub branch protection enforcement, AWAC has moved from periodic compliance audits to continuous automated validation.
5. AI/Agentic adoption in production.
Three Agent TIA (Threat Intelligence & Analysis) workflows for domain blocking, hash blocking, and IP blocking demonstrate early production deployment of agentic automation. The MASNET Ingestion workflow also uses AI agent patterns for complex multi-system orchestration. This positions AWAC ahead of the curve on agentic SOC capabilities.
6. Cortex XDR emerging as a second production EDR pipeline.
Cortex XDR Blocked Processed Alert polls every 5 minutes and has already logged 8,474 executions, plus a growing set of Cortex XDR containment actions (hash blocking, endpoint isolation, agentic hash-block approval). This runs alongside the existing CrowdStrike pipeline, giving AWAC redundant, cross-vendor EDR alert coverage.
7. First IAM use case: Apono JIT access governance.
New workflows continuously sync Apono access flows, groups, bundles, and integrations into Blink tables, and route ServiceNow-initiated Apono access requests to the security engineering team via Teams. This is AWAC's first automated IAM capability and a natural foundation for expanding into broader access-review and provisioning automation.
Gaps & Opportunities
1. CrowdStrike and Cortex XDR EDR response not yet fully automated.
Workflows for CrowdStrike RTR to a Single Host, CrowdStrike RTR to a Batch of Hosts, and Manage Endpoint Quarantine Status in Crowdstrike have 0 executions. CrowdStrike alert ingestion is automated (267 + 11,547 + 11,546 executions) but the response layer — RTR commands, host isolation, containment — is not yet triggered automatically. The newer Isolate Machine in Cortex and Response Subflow - Crowdstrike workflows are similarly built but still at 0 executions. Closing this loop across both EDR platforms would deliver significant MTTR reduction.
2. Tenable integration built but inactive.
Tenable Self Service Vulnerability Scan, Tenable IE to Jira, and Tenable Vulnerability Management all have 0 executions. Given the mature Nucleus pipeline, these may represent a parallel capability that was not fully activated. Tenable self-service via Teams is particularly high-value for enabling non-SOC teams to initiate scans on demand.
3. Firewall rule audit suite not running.
Three Firewall Rule Audit workflows (Aggregate Data, Enrich with Agent Data, Send Email) are built but have 0 executions. A scheduled firewall rule audit would provide ongoing hygiene visibility and support compliance requirements.
4. Varonis SaaS Alerts and Zero Networks inactive.
Varonis SaaS Alerts and both Zero Networks microsegmentation workflows have 0 executions. If Zero Networks is deployed in the environment, automated rule cleanup and disablement workflows could significantly reduce the manual burden of microsegmentation policy management.
5. Fragmented workflow copies.
The environment contains multiple "copy" variants of core workflows (Sync List, Tenant Block Domain, Add Users to Team, etc.) with 0 executions. These represent technical debt and risk of divergence. A consolidation pass would reduce maintenance overhead and eliminate confusion about which workflow is canonical.
Integration Ecosystem
AWAC operates one of the most diverse integration ecosystems in the Blink customer base, spanning 20+ distinct security and IT platforms:
| Domain | Integrations |
|---|---|
| Endpoint / EDR | CrowdStrike Falcon, Palo Alto Cortex XDR, ThreatLocker, Halcyon, Microsoft Defender for Endpoint |
| Email Security | Proofpoint TAP, Tessian, Agari, Phishlabs, Microsoft Outlook / O365 |
| SIEM / Log Pipeline | CrowdStrike Next-Gen SIEM, Cribl |
| SOAR / Ticketing | Blink Case Management, Jira, ServiceNow, OpsGenie |
| Network / Firewall | Palo Alto Networks (Panorama, NGFW, SSPM, Cortex XDR, Unit 42), Imperva, Zero Networks |
| Vulnerability Mgmt | Axonius, Nucleus, NetSPI, Tenable |
| Data Security | Varonis |
| Identity | Okta, Microsoft Entra ID, Google Workspace, Apono |
| Threat Intel | Intezer, VirusTotal, URLScan, AbuseIPDB, MASNET, Appono |
| Compliance | Vanta, GitHub, Azure AD |
| Collaboration | Microsoft Teams, Slack |
| Learning | Litmos |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.