01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Network Threat Containment via Palo Alto FW EDL | 0 executions | 0.0% | 6 6 active |
| Endpoint Detection & Response | 0 executions | 0.0% | 3 3 active |
| Identity & Access Management | 0 executions | 0.0% | 1 1 active |
| Notification Infrastructure | 0 executions | 0.0% | 3 3 active |
| Data & Table Management | 0 executions | 0.0% | 2 2 active |
| Development / Uncategorized | 0 executions | 0.0% | 1 1 active |
| Total | 0 executions | 100% | 16 16 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Well-scoped network containment pipeline. The EDL automation is the most complete use case — covering single and bulk IP blocking, whitelist management, and full bi-directional Zendesk integration (event in, ticket comment out, SMS notification). This is a meaningful SOC automation that eliminates manual firewall edits under incident pressure.
- Zendesk as SOC ticketing hub. The webhook-triggered architecture cleanly routes Zendesk incidents to automated response actions, establishing a solid SOAR pattern that can be extended to additional response types without reworking the entry point.
- Approval gates on sensitive actions. Endpoint isolation (
Cortex XDR - Isolate Endpoint) and user enable/disable (Microsoft Entra ID - Enable or Disable User) both require anapproveinput, indicating deliberate human-in-the-loop design for high-impact actions — a sign of mature automation governance.
- Reusable notification layer. SMS and email flows are built as independent, callable utilities rather than embedded per-playbook. This keeps notification logic DRY and makes future changes (e.g., swapping SMTP providers) a single-point update.
- Whitelist-aware containment. IP blocking and user disable actions both check against Blink Tables whitelists before acting, preventing automation from accidentally blocking legitimate infrastructure or users.
###
Gaps
- Zero production executions. No workflow has recorded any execution in the last 12 months. The full library is configured but dormant — activating these automations is the single highest-priority action to realize business value from this investment.
- Staging/production workspace drift. Several playbooks are duplicated across two workspaces (
assuta_cortex_xdrvs.assuta_staging-assuta_cortex_xdr). Without a structured promotion process, these copies will diverge over time, creating a maintenance and correctness risk. A clear staging → production promotion path should be established.
- No event-driven or scheduled automation. Every playbook except the Zendesk webhook is
on_demand. There are no alert-driven, schedule-driven, or SIEM-connected automations, which means no autonomous SOC response without a human manually triggering a workflow.
- Narrow IAM scope. The IAM use case covers only Entra ID account enable/disable and session revocation. Missing: full employee offboarding orchestration, access reviews, role assignments, JIT/temporary access, and Active Directory-native lifecycle management.
- No vulnerability management or GRC coverage. The library has no vulnerability scanning, compliance monitoring, audit reporting, or regulatory workflow automation — categories that commonly represent high-volume, high-value automation opportunities.
- No alert enrichment or threat intel lookups. Despite having Cortex XDR integrated, there are no workflows for automatic alert enrichment, IOC lookup, or threat intelligence ingestion — steps that typically precede containment decisions.
Integration Ecosystem
| Integration | Role in Current Workflows |
|---|---|
| Cortex XDR | Endpoint isolation, malware scan, AD user management via script, endpoint lookup |
| Microsoft Entra ID | User account enable/disable, session revocation |
| Palo Alto Firewall (EDL via SMB) | IP block list management |
| Zendesk | Incident routing (webhook trigger), ticket commenting |
| SMTP | Email notification delivery |
| Google Sheets / Workspace | Reference data import |
| Blink Tables | IP whitelists, user allow-lists, routing reference data |
| SMS | Urgent alert notification for blocked IPs |
| Active Directory | User management (via Cortex XDR script execution) |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 6 use cases | 0 executions (12m)
Business KPIs
*No execution-based metrics are available for this period.*
Use Case Summary
| Use Case | Category | Subcategories | Playbooks |
|---|---|---|---|
| Network Threat Containment via Palo Alto FW EDL | SOC | Case mgmt & SOAR, Threat intel ingest & curation | 6 |
| Endpoint Detection & Response | SOC | EDR containment & response | 5 |
| Identity & Access Management | IAM | Identity lifecycle automation, Password & credential lifecycle | 3 |
| Notification Infrastructure | Other | IT helpdesk & ticket routing | 3 |
| Data & Table Management | Other | SaaS / IT administration | 2 |
| Development / Uncategorized | Other | SaaS / IT administration | 1 |
Total: 20 playbooks across 6 use cases (includes duplicates across staging and production workspaces)
Use Cases
1. Network Threat Containment via Palo Alto FW EDL
Description: Automates the blocking of malicious IP addresses at the Palo Alto firewall by maintaining an External Dynamic List (EDL), triggered both manually and through Zendesk incident tickets. Includes whitelist validation and bi-directional Zendesk ticket updates.
Business problem: Security analysts must act quickly when malicious IPs are identified — manual firewall rule edits are slow and error-prone. This pipeline automates containment from the moment an incident is raised in Zendesk, with notification via SMS and a documented audit trail back into the ticket.
Integrations: Palo Alto Firewall (EDL via SMB), Zendesk, Blink Tables, SMS
| Playbook | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|
| Zendesk Webhook | 0 | SOC | Case mgmt & SOAR |
| PaloAlto FW - Add single IP to EDL - Incidents From Zendesk | 0 | SOC | Case mgmt & SOAR, Threat intel ingest & curation |
| PaloAlto FW - Add multi IPs to EDL - Incidents From Zendesk | 0 | SOC | Case mgmt & SOAR, Threat intel ingest & curation |
| PaloAlto FW - Add IPs to EDL file | 0 | SOC | Threat intel ingest & curation |
| PaloAlto FW - Remove manually IPs from EDL file | 0 | SOC | Threat intel ingest & curation |
| Adding IP manually into White-list IP's | 0 | SOC | Threat intel ingest & curation |
2. Endpoint Detection & Response
Description: Automates endpoint containment and investigation via Cortex XDR — covering endpoint isolation with email notification, malware scanning, AD endpoint lookup, and enabling/disabling AD user accounts directly from the XDR platform via script execution.
Business problem: When a threat is detected on an endpoint, analysts must contain it before lateral movement occurs. Manual isolation and AD account management introduce critical delay; these playbooks automate the full response chain with approval gates for high-impact actions and status reporting back to the team.
Integrations: Cortex XDR, Active Directory (via XDR Script Library), SMTP
| Playbook | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|
| Cortex XDR - Isolate Endpoint and Notify by Email | 0 | SOC | EDR containment & response |
| Cortex XDR - Malware Scan | 0 | SOC | EDR containment & response |
| Cortex XDR - Run Script - Enable or Disable AD User | 0 | SOC | EDR containment & response |
| Cortex XDR - Run Script - Get AD Endpoint *(production)* | 0 | SOC | EDR containment & response |
| Cortex XDR - Run Script - Get AD Endpoint *(staging)* | 0 | SOC | EDR containment & response |
3. Identity & Access Management
Description: Automates user account lifecycle actions in Microsoft Entra ID — enabling and disabling accounts with whitelist-based validation, plus revoking all active sessions for a user — both with approval gates.
Business problem: During incidents or offboarding, time-sensitive identity actions (account disable, session invalidation) must execute immediately and consistently. Manual portal operations introduce lag and skip validation steps; these playbooks enforce input validation, whitelist checks, and structured approval before any account action is taken.
Integrations: Microsoft Entra ID, Blink Tables
| Playbook | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|
| Microsoft Entra ID - Enable or Disable User *(production)* | 0 | IAM | Identity lifecycle automation |
| Microsoft Entra ID - Enable or Disable User *(staging)* | 0 | IAM | Identity lifecycle automation |
| Microsoft Entra ID - Revoke User Session | 0 | IAM | Password & credential lifecycle |
4. Notification Infrastructure
Description: Reusable notification subflows providing email delivery (SMTP and table-driven) and bulk SMS, used as building blocks by security response playbooks throughout the library.
Business problem: Security workflows need consistent, multi-channel alerting — email to stakeholders for audit trails, SMS for urgent time-sensitive escalations. These utilities standardize notification delivery and avoid duplicating integration logic across playbooks.
Integrations: SMTP, SMS provider, Blink Tables
| Playbook | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|
| Assuta - Send Email from Table | 0 | Other | IT helpdesk & ticket routing |
| SMTP - Send Email | 0 | Other | IT helpdesk & ticket routing |
| Send - SMS to list of destinations | 0 | Other | IT helpdesk & ticket routing |
5. Data & Table Management
Description: Utility playbooks for managing Blink table content — importing structured data from Google Sheets and inspecting table state — used to keep reference data (IP whitelists, user allow-lists) current for downstream security workflows.
Business problem: Security workflows depend on Blink Tables for dynamic reference data that changes over time (e.g., IP whitelists, approved user lists). These playbooks allow the security team to refresh that data from upstream sources without manual intervention in the Blink UI.
Integrations: Google Sheets, Google Workspace, Blink Tables
| Playbook | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|
| Import CSVs to Table | 0 | Other | SaaS / IT administration |
| Show Table Content | 0 | Other | SaaS / IT administration |
6. Development / Uncategorized
Description: Unfinished or test playbooks not yet promoted to a production use case.
| Playbook | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|
| New Workflow | 0 | Other | SaaS / IT administration |
Key Observations
Strengths
- Well-scoped network containment pipeline. The EDL automation is the most complete use case — covering single and bulk IP blocking, whitelist management, and full bi-directional Zendesk integration (event in, ticket comment out, SMS notification). This is a meaningful SOC automation that eliminates manual firewall edits under incident pressure.
- Zendesk as SOC ticketing hub. The webhook-triggered architecture cleanly routes Zendesk incidents to automated response actions, establishing a solid SOAR pattern that can be extended to additional response types without reworking the entry point.
- Approval gates on sensitive actions. Endpoint isolation (
Cortex XDR - Isolate Endpoint) and user enable/disable (Microsoft Entra ID - Enable or Disable User) both require anapproveinput, indicating deliberate human-in-the-loop design for high-impact actions — a sign of mature automation governance.
- Reusable notification layer. SMS and email flows are built as independent, callable utilities rather than embedded per-playbook. This keeps notification logic DRY and makes future changes (e.g., swapping SMTP providers) a single-point update.
- Whitelist-aware containment. IP blocking and user disable actions both check against Blink Tables whitelists before acting, preventing automation from accidentally blocking legitimate infrastructure or users.
Gaps
- Zero production executions. No workflow has recorded any execution in the last 12 months. The full library is configured but dormant — activating these automations is the single highest-priority action to realize business value from this investment.
- Staging/production workspace drift. Several playbooks are duplicated across two workspaces (
assuta_cortex_xdrvs.assuta_staging-assuta_cortex_xdr). Without a structured promotion process, these copies will diverge over time, creating a maintenance and correctness risk. A clear staging → production promotion path should be established.
- No event-driven or scheduled automation. Every playbook except the Zendesk webhook is
on_demand. There are no alert-driven, schedule-driven, or SIEM-connected automations, which means no autonomous SOC response without a human manually triggering a workflow.
- Narrow IAM scope. The IAM use case covers only Entra ID account enable/disable and session revocation. Missing: full employee offboarding orchestration, access reviews, role assignments, JIT/temporary access, and Active Directory-native lifecycle management.
- No vulnerability management or GRC coverage. The library has no vulnerability scanning, compliance monitoring, audit reporting, or regulatory workflow automation — categories that commonly represent high-volume, high-value automation opportunities.
- No alert enrichment or threat intel lookups. Despite having Cortex XDR integrated, there are no workflows for automatic alert enrichment, IOC lookup, or threat intelligence ingestion — steps that typically precede containment decisions.
Integration Ecosystem
| Integration | Role in Current Workflows |
|---|---|
| Cortex XDR | Endpoint isolation, malware scan, AD user management via script, endpoint lookup |
| Microsoft Entra ID | User account enable/disable, session revocation |
| Palo Alto Firewall (EDL via SMB) | IP block list management |
| Zendesk | Incident routing (webhook trigger), ticket commenting |
| SMTP | Email notification delivery |
| Google Sheets / Workspace | Reference data import |
| Blink Tables | IP whitelists, user allow-lists, routing reference data |
| SMS | Urgent alert notification for blocked IPs |
| Active Directory | User management (via Cortex XDR script execution) |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.