01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| ArcSight SOC Alert Pipeline | 0 executions | 0.0% | 5 5 active |
| Zendesk SOC Ticketing | 0 executions | 0.0% | 2 2 active |
| Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 10 10 active |
| EDR Containment & Response | 0 executions | 0.0% | 5 5 active |
| Network & Domain Blocking | 0 executions | 0.0% | 3 3 active |
| Outbound Escalation (Twilio) | 0 executions | 0.0% | 2 2 active |
| ZD ↔ ServiceNow Bidirectional Sync | 0 executions | 0.0% | 14 14 active |
| MDR Staff Onboarding | 0 executions | 0.0% | 9 9 active |
| MDR Staff Offboarding | 0 executions | 0.0% | 9 9 active |
| Asset Inventory & Correlation | 0 executions | 0.0% | 5 5 active |
| Vulnerability Remediation | 0 executions | 0.0% | 3 3 active |
| Attack Surface Management | 0 executions | 0.0% | 2 2 active |
| Platform Utilities & Infrastructure | 0 executions | 0.0% | 20 20 active |
| Total | 0 executions | 100% | 89 89 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Architecturally complete SOC ingestion pipeline. The numbered ArcSight sequence (1 → 2 → 3 → 5 → 6) represents a well-designed ingestion-to-escalation flow covering SIEM polling, deduplication, case creation, enrichment, and Zendesk ticketing in a single automation chain. The MSSQL-backed rule and notification databases make the pipeline configurable without touching workflow logic.
Comprehensive MDR employee lifecycle automation. The onboarding and offboarding stacks cover 8 distinct systems each in a single orchestrated flow: AD/LDAP, Entra ID, DUO, Elasticsearch, Zendesk, AWS Workspaces, and dual Cisco Umbrella tenants. This is operationally mature and reflects a security-first identity hygiene posture — every new analyst is fully provisioned, every departure is fully revoked, in one click.
Production-grade bidirectional ITSM sync. The 14-playbook ZD↔ServiceNow V3 integration handles the full ticket lifecycle in both directions — creation, comments, attachments, status, priority, and closure — with multi-tenant ServiceNow support and try/catch error handling throughout. This is a high-complexity integration that typically requires significant custom code; the Blink implementation is fully no-code and multi-customer.
Multi-layer containment capability. The estate covers active response from four vectors simultaneously: endpoint (Cortex XDR isolation), network (Palo Alto IP blocking), DNS/web (Zscaler ZIA domain blocking), and file hash (XDR block list). Few MSSP platforms have pre-built containment automation spanning all four layers.
VIP-aware enrichment. The SOC enrichment chain includes dedicated VIP user checks for both source and destination users — a detail that directly maps to client SLA prioritization requirements and shows depth of operational design.
###
Gaps & Opportunities
No recorded executions — activation audit needed. All 93 workflows show 0 executions in the 12-month window. This is the most significant gap to address before deriving ROI metrics. Root causes to investigate: (a) are scheduled/event triggers enabled and connected to live data sources, (b) are integration connections validated and authenticated, (c) does the telemetry collection window post-date the deployment date.
Remediation workflows are undifferentiated. Remediation 2, 3, and 4 share near-identical structures (ServiceNow + Cortex XDR cross-reference) with names that don't distinguish their scope or trigger conditions. A consolidation pass could reduce these to a single parameterized workflow, improving maintainability and making execution metrics meaningful.
No CSPM automation deployed. Despite a broad SOC and IAM footprint, there are no cloud security posture workflows (AWS Config, Microsoft Defender for Cloud, Prisma). Given the existing AWS integration for Workspaces and EC2 lifecycle management, expanding into cloud configuration compliance monitoring is a natural next step.
Threat intelligence loop is open-ended. VirusTotal enrichment is deployed and VirusTotal verdicts surface in alert context, but there is no automated write-back: a confirmed-malicious verdict from VT does not automatically trigger a ZIA domain block or XDR hash block. Closing this loop would turn enrichment into active defense.
Asset correlation limited to three sources. The Qualys + XDR + ServiceNow correlation is solid, but cloud-native workloads (EC2 instances, serverless) are absent. Adding AWS EC2 inventory — which is already connected for Workspaces — would extend coverage visibility to cloud infrastructure.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| Cortex XDR | EDR containment, alert enrichment, asset correlation, vulnerability remediation, IOC management |
| ServiceNow | ITSM sync (ZD↔SNOW), asset correlation, vulnerability remediation, network blocking audit |
| Zendesk | SOC ticketing, ITSM sync, staff lifecycle, SIEM sensor tracking |
| Microsoft SQL | SOC pipeline backbone — rule metadata, dedup logic, on-call routing, notification contacts |
| ArcSight | SIEM event ingestion (Alert and DSM event types) |
| Zscaler ZIA | URL/domain blocking |
| Palo Alto Networks | Firewall IP blocking |
| Twilio | Voice call + SMS escalation |
| VirusTotal | IOC hash/URL verdict with result caching |
| Elasticsearch (ELK SOC) | Evidence-of-incident search, SOC analyst user management |
| Microsoft Entra ID | Staff onboarding / offboarding (cloud identity) |
| Active Directory (LDAP) | Staff onboarding / offboarding (on-prem identity) |
| DUO | MFA provisioning and deprovisioning |
| Cisco Umbrella | DNS policy management (two managed network tenants) |
| AWS | Workspaces virtual desktop + EC2 lifecycle management |
| Qualys | Vulnerability asset inventory |
| CyCognito | External attack surface discovery |
| Cortex Xpanse | ASM alert enrichment and status update |
| MySQL (ArcSight ESM) | User attribute lookup across three ESM instances |
| Slack | EDR response result notifications |
| Google Sheets | Bulk data import utility |
| SMTP | Email notification utility |
A Case Management 0 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| BDO MDR Master Playbook | 72,969 | 0 | 0 | N/A |
B AI Agents 3 active | 186 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Sum Ting Wong | BDO MDR - MTE | 151 | 0 | 10,978,144 |
| 2 | TPRM Email Analyzer | BDO - TPRM | 22 | 0 | 368,758 |
| 3 | Agent Bumblebee | BDO MDR Master Playbook | 13 | 0 | 2,123,115 |
| 4 | Agent Blink | CM V9 Elastic POC | 0 | 0 | 0 |
| 5 | Agent Blink | BDO MDR Prod | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| BDO MDR - MTE | 151 |
| BDO - TPRM | 22 |
| BDO MDR Master Playbook | 13 |
| CM V9 Elastic POC | 0 |
| BDO MDR Prod | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Daily status alerts | 0 | 0 |
| 2 | SMS Using | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 13 use cases | 0 executions (12m)
Business KPIs
All 93 workflows recorded 0 executions in the reporting window (July 2025 – July 2026). This indicates workflows are deployed but not yet running in production — likely due to trigger activation, integration connection setup, or telemetry collection timing. The KPI table reflects deployment scope rather than realized throughput.
| Metric | Count | Playbook |
|---|---|---|
| — | — | No executions recorded in period |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks |
|---|---|---|---|---|
| 1 | ArcSight SOC Alert Pipeline | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR | 5 |
| 2 | Zendesk SOC Ticketing | SOC | Case mgmt & SOAR | 2 |
| 3 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 10 |
| 4 | EDR Containment & Response | SOC | EDR containment & response | 5 |
| 5 | Network & Domain Blocking | SOC | EDR containment & response | 3 |
| 6 | Outbound Escalation (Twilio) | SOC | Case mgmt & SOAR | 2 |
| 7 | ZD ↔ ServiceNow Bidirectional Sync | Other | IT helpdesk & ticket routing | 14 |
| 8 | MDR Staff Onboarding | IAM | Employee onboarding, Full employee lifecycle | 9 |
| 9 | MDR Staff Offboarding | IAM | Employee offboarding, Full employee lifecycle | 9 |
| 10 | Asset Inventory & Correlation | Cloud Security | Cloud asset coverage & inventory | 5 |
| 11 | Vulnerability Remediation | Vulnerability Mgmt | CVE lookup & remediation, Vuln lifecycle prioritize & ticket | 5 |
| 12 | Attack Surface Management | Vulnerability Mgmt | Threat hunting & detection, Vuln scan lifecycle automation | 2 |
| 13 | Platform Utilities & Infrastructure | SOC | Case mgmt & SOAR | 22 |
| Total | 93 |
Use Cases
1. ArcSight SOC Alert Pipeline
Description: End-to-end ingestion of ArcSight SIEM events into Blink Case Management. The pipeline polls ArcSight Query Viewers for both Alert and DSM event types, deduplicates against existing records using an MSSQL automation-closing database, and creates or links alerts and cases automatically.
Business problem solved: Eliminates manual log review from ArcSight consoles; SOC analysts work from a unified Blink case queue rather than raw SIEM output, with deduplication preventing alert fatigue from repeat events.
Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR
Integrations: ArcSight, Microsoft SQL, Blink Case Management, Blink Tables
| Playbook | Role | Executions (12mo) |
|---|---|---|
| 1. Master Workflow - Get All New Events - Alert | Orchestrator — Alert event type | 0 |
| Master Workflow - Get All New Events - DSM | Orchestrator — DSM event type | 0 |
| 3. Master - Ingest and dedup Event in Case Management | Dedup & case routing | 0 |
| 2. Case Management - Create Alert and Create or Link A Case | Alert/case creation | 0 |
| Arcsight - Get Formatted Query Viewer Results | SIEM data fetch (subflow) | 0 |
2. Zendesk SOC Ticketing
Description: Automated creation of Zendesk tickets from SOC alert events, including pre-population of ticket fields: priority mapping from event severity, rule descriptions from MSSQL, ELK evidence-of-incident links, XDR incident correlation, and VIP user flags.
Business problem solved: Removes manual ticket creation from the SOC escalation path; ensures every alert that reaches escalation threshold generates a properly formatted Zendesk ticket without analyst intervention.
Category: SOC | Subcategories: Case mgmt & SOAR
Integrations: Zendesk, Microsoft SQL, Cortex XDR, Elasticsearch
| Playbook | Role | Executions (12mo) |
|---|---|---|
| 5. Zendesk - Create new Ticket | Top-level ticket creation | 0 |
| 6. Zendesk - Pre-request information for open ZD | Field enrichment pre-flight (subflow) | 0 |
3. Alert Enrichment & IOC Lookup
Description: A suite of enrichment subflows invoked during SOC triage to gather context on IPs, file hashes, user identities (source/destination, VIP status), endpoint state, open XDR incidents, and ELK evidence of interest. VirusTotal provides hash and URL verdicts with a result-caching layer.
Business problem solved: Reduces analyst research time per alert by automatically surfacing device context, user risk tier, threat intelligence verdicts, and correlated XDR incident data directly into the case record before an analyst reviews it.
Category: SOC | Subcategories: Alert enrichment / IOC lookup
Integrations: VirusTotal, Cortex XDR, Cortex Xpanse, Elasticsearch, ArcSight, MySQL (ESM-GER-2, ESM-GER-3, ESM-Carl)
| Playbook | Role | Executions (12mo) |
|---|---|---|
| Utility - IP Enrichment | IP extraction & enrichment | 0 |
| VirusTotal - Get IOC Enrichment and refresh cache | IOC verdict (VT) with caching | 0 |
| ArcSight - Source User Info | Source user context | 0 |
| ArcSight - Destination User Info | Destination user context | 0 |
| ArcSight - VIP Source User Info | VIP source user check | 0 |
| ArcSight - VIP Destination User Info | VIP destination user check | 0 |
| Cortex XDR - Get Device Info | Endpoint device lookup | 0 |
| Cortex XDR - Incident Enrichment | XDR incident correlation | 0 |
| Xpanse - Enrichment and Change Alert Status | ASM alert enrichment | 0 |
| ELK SOC - Search EOI by Query from DBDB | Evidence-of-incident ELK query | 0 |
4. EDR Containment & Response
Description: On-demand and webhook-triggered endpoint containment using Cortex XDR. Supports manual isolation requests, automated isolation via webhook (triggered from Zendesk ticket comments), endpoint scanning, and hash-level blocking and whitelisting across multiple customer XDR connections.
Business problem solved: Compresses endpoint containment from minutes to seconds by removing the manual XDR console step; supports both analyst-initiated actions and automated isolation triggered by external ticketing system events.
Category: SOC | Subcategories: EDR containment & response
Integrations: Cortex XDR, Slack, Zendesk
| Playbook | Role | Executions (12mo) |
|---|---|---|
| Isolate Endpoint with Cortex XDR and Send Results via Slack | Manual endpoint isolation | 0 |
| Scan Endpoint with Cortex XDR and Send Results via Slack | Manual endpoint scan | 0 |
| Isolate Endpoint with Cortex XDR and Send Results via Slack (Webhook listen trigger) | Webhook-triggered isolation | 0 |
| Cortex XDR - Add Hash to Block List | Hash-level containment | 0 |
| Cortex XDR - Ignore IOC Hash | Hash whitelist management | 0 |
5. Network & Domain Blocking
Description: Automated enforcement actions across Zscaler ZIA (URL/domain blocking via DenyList) and Palo Alto Networks Firewall (IP blocking across specified network locations). Supports on-demand analyst triggers and creates ServiceNow incidents as a blocking audit trail.
Business problem solved: Closes the gap between threat intelligence identification and network enforcement; a malicious domain or IP can be pushed to perimeter controls without requiring a firewall admin or ZIA console access.
Category: SOC | Subcategories: EDR containment & response
Integrations: Zscaler ZIA, Palo Alto Networks, ServiceNow
| Playbook | Role | Executions (12mo) |
|---|---|---|
| Add URL to ZIA | URL/domain block in ZIA | 0 |
| Block malicious domain | Domain block via ZIA DenyList | 0 |
| Block IPs - Palo Alto Networks Firewall | IP block + ServiceNow audit ticket | 0 |
6. Outbound Escalation (Twilio)
Description: Automated phone and SMS escalation for high-severity SOC events. Looks up the appropriate on-call contact from the MSSQL notification database, then dispatches outbound calls or SMS messages via Twilio based on the alert rule and customer context.
Business problem solved: Ensures critical alerts reach the right personnel immediately without requiring an analyst to manually identify and dial the on-call contact; removes the last manual step in the critical-alert notification chain.
Category: SOC | Subcategories: Case mgmt & SOAR
Integrations: Twilio, Microsoft SQL
| Playbook | Role | Executions (12mo) |
|---|---|---|
| Twilio - Send SMS | SMS alert notification | 0 |
| Twilio - Outbound Call | Voice call escalation | 0 |
7. ZD ↔ ServiceNow Bidirectional Sync
Description: A full bidirectional synchronization layer between Zendesk and ServiceNow. Handles ticket creation, comment sync, status and priority sync, attachment sync, and ticket closure in both directions. Supports multiple customer ServiceNow instances via a dynamic connection map stored in Blink Tables; V3 architecture adds try/catch error handling throughout.
Business problem solved: Eliminates manual double-entry and status drift between the MDR's Zendesk instance and managed customers' ServiceNow instances; both systems reflect the same ticket state in real time without any human relay.
Category: Other | Subcategories: IT helpdesk & ticket routing
Integrations: Zendesk, ServiceNow (multi-tenant), Blink Tables
| Playbook | Role | Executions (12mo) |
|---|---|---|
| Open from SNOW to ZD V3 | SNOW → ZD ticket creation | 0 |
| Open From ZD to SNOW V3 | ZD → SNOW ticket creation | 0 |
| ZD to SNOW comment V3 | ZD comment → SNOW | 0 |
| SNOW to ZD Comment V3 | SNOW comment → ZD | 0 |
| ZD to SNOW Close v3 | ZD closure → SNOW | 0 |
| ZD to SNOW Priority update | Priority change sync | 0 |
| ZD to SNOW status sync | Status sync (on-demand) | 0 |
| ZD to SNOW status sync - org | Status sync (org-scoped) | 0 |
| Upload Attachments ZD to SNOW V3 | ZD attachment → SNOW | 0 |
| Upload Attachments SNOW to ZD V3 | SNOW attachment → ZD | 0 |
| Generate creation JSON | Ticket payload builder (subflow) | 0 |
| Generate creation JSON v3 | Ticket payload builder v3 (subflow) | 0 |
| Replacing Priority Status ZD-SNOW | Priority/status field mapping (subflow) | 0 |
| Add To Connection Map | Customer SNOW connection setup | 0 |
8. MDR Staff Onboarding
Description: Fully automated onboarding of new MDR staff members across all required platforms. A single orchestrator triggers simultaneous provisioning across Active Directory (LDAP), Microsoft Entra ID (with external guest invite), DUO MFA, Elasticsearch SOC, Zendesk, AWS Workspaces, and Cisco Umbrella across two managed network tenants.
Business problem solved: Reduces new hire platform provisioning from hours of manual work across eight systems to a single triggered workflow; eliminates provisioning gaps that create security blind spots or delayed analyst access.
Category: IAM | Subcategories: Employee onboarding, Full employee lifecycle
Integrations: LDAP/Active Directory, Microsoft Entra ID, DUO, Elasticsearch, Zendesk, AWS, Cisco Umbrella
| Playbook | Role | Executions (12mo) |
|---|---|---|
| MDR - Onboarding Staff Member | Top-level orchestrator | 0 |
| MDR - Create AD User | LDAP/AD provisioning | 0 |
| Microsoft Entra ID - Create New User | Entra ID + external invite | 0 |
| DUO - Create User | MFA enrollment | 0 |
| ELK SOC - Create User | Elasticsearch SOC access | 0 |
| Zendesk - Create User | Zendesk access | 0 |
| AWS - Create Workspace | AWS virtual desktop provisioning | 0 |
| Avolon Umbrella - Create User | Cisco Umbrella DNS policy (tenant A) | 0 |
| DiscoverIE Umbrella - Create User | Cisco Umbrella DNS policy (tenant B) | 0 |
9. MDR Staff Offboarding
Description: Mirrors the onboarding stack in reverse — a single orchestrator triggers deprovisioning and suspension across all MDR platforms simultaneously: AD disable, Entra ID removal, DUO deprovisioning, Elasticsearch access revocation, Zendesk suspension, AWS Workspace deletion, and Cisco Umbrella removal across both tenants.
Business problem solved: Prevents access persistence after termination across eight systems; ensures offboarding is complete and auditable in a single automated pass without relying on manual checklists.
Category: IAM | Subcategories: Employee offboarding, Full employee lifecycle
Integrations: LDAP/Active Directory, Microsoft Entra ID, DUO, Elasticsearch, Zendesk, AWS, Cisco Umbrella
| Playbook | Role | Executions (12mo) |
|---|---|---|
| MDR - Offboarding Staff Member | Top-level orchestrator | 0 |
| MDR - Disable AD User | LDAP/AD disable | 0 |
| Microsoft Entra ID - Delete User | Entra ID removal | 0 |
| DUO - Delete User | MFA deprovisioning | 0 |
| ELK SOC - Delete User | Elasticsearch access revocation | 0 |
| Zendesk - Suspend User | Zendesk suspension | 0 |
| AWS - Delete Workspace | AWS desktop removal | 0 |
| Avolon Umbrella - Delete User | Cisco Umbrella removal (tenant A) | 0 |
| DiscoverIE Umbrella - Delete User | Cisco Umbrella removal (tenant B) | 0 |
10. Asset Inventory & Correlation
Description: Cross-source asset correlation that joins endpoint records from Qualys, Cortex XDR, and ServiceNow into a unified asset table in Blink. SQL queries then surface coverage gaps — assets visible in one source but absent from another — across all three.
Business problem solved: Provides a single reconciled asset inventory without a dedicated CMDB integration; surfaces security coverage gaps where endpoints are known to IT (ServiceNow) but not enrolled in the EDR or vulnerability scanner.
Category: Cloud Security | Subcategories: Cloud asset coverage & inventory
Integrations: Qualys, Cortex XDR, ServiceNow, Blink Tables
| Playbook | Role | Executions (12mo) |
|---|---|---|
| Asset Correlation main | Top-level orchestrator | 0 |
| Asset Correlation Qualys | Qualys asset pull (subflow) | 0 |
| Asset Correlation - XDR | XDR endpoint pull (subflow) | 0 |
| Asset Correlation - ServiceNow | ServiceNow CMDB pull (subflow) | 0 |
| Add or Update Asset | Unified asset upsert (subflow) | 0 |
11. Vulnerability Remediation
Description: ServiceNow-triggered remediation workflows that cross-reference CVE data from ServiceNow incidents against endpoint inventory in Cortex XDR. Multiple remediation variants handle different scenarios; a file download utility extracts remediation artifacts from ServiceNow attachments.
Business problem solved: Automates the cross-referencing step in vulnerability remediation — matching CVE findings from ticketed incidents to affected XDR endpoints — so remediation owners receive pre-populated endpoint lists rather than conducting manual asset queries.
Category: Vulnerability Mgmt | Subcategories: CVE lookup & remediation, Vuln lifecycle prioritize & ticket
Integrations: ServiceNow, Cortex XDR
| Playbook | Role | Executions (12mo) |
|---|---|---|
| Remediation 2 | CVE-to-endpoint matching (variant 2) | 0 |
| threats 1 | Threat analysis (variant 1) | 0 |
| Remediation 3 | CVE-to-endpoint matching (variant 3) | 0 |
| Remediation 4 | CVE-to-endpoint matching (variant 4) | 0 |
| Download File | File extraction from ServiceNow | 0 |
12. Attack Surface Management
Description: External attack surface discovery and SIEM sensor health monitoring. CyCognito enumerates externally exposed assets, while the DSM workflow detects devices that have stopped reporting to the SIEM and creates Zendesk tickets to track remediation.
Business problem solved: Automates external exposure discovery and SIEM sensor gap detection, catching both unknown external assets and silent sensors before they create coverage blindspots or SLA violations.
Category: Vulnerability Mgmt | Subcategories: Threat hunting & detection, Vuln scan lifecycle automation
Integrations: CyCognito, Zendesk
| Playbook | Role | Executions (12mo) |
|---|---|---|
| cycognito | External asset discovery | 0 |
| DSM - Device Return Reporting | SIEM sensor gap detection | 0 |
13. Platform Utilities & Infrastructure
Description: Shared utility subflows and administrative tooling that underpin the SOC pipeline, enrichment chain, and ZD-SNOW sync. Includes MSSQL routing lookups (rule details, notification contacts), text normalization utilities, event-source classifiers, and admin tools for data management and integration setup.
Business problem solved: Provides reusable logic components that keep the main SOC workflows clean and maintainable; centralizes volatile configuration (on-call contacts, rule metadata, severity mappings) in queryable MSSQL tables rather than hardcoded workflow logic.
Category: SOC | Subcategories: Case mgmt & SOAR
Integrations: Microsoft SQL, Elasticsearch, Google Sheets, Zendesk, AWS, SMTP
Key Observations
Strengths
Architecturally complete SOC ingestion pipeline. The numbered ArcSight sequence (1 → 2 → 3 → 5 → 6) represents a well-designed ingestion-to-escalation flow covering SIEM polling, deduplication, case creation, enrichment, and Zendesk ticketing in a single automation chain. The MSSQL-backed rule and notification databases make the pipeline configurable without touching workflow logic.
Comprehensive MDR employee lifecycle automation. The onboarding and offboarding stacks cover 8 distinct systems each in a single orchestrated flow: AD/LDAP, Entra ID, DUO, Elasticsearch, Zendesk, AWS Workspaces, and dual Cisco Umbrella tenants. This is operationally mature and reflects a security-first identity hygiene posture — every new analyst is fully provisioned, every departure is fully revoked, in one click.
Production-grade bidirectional ITSM sync. The 14-playbook ZD↔ServiceNow V3 integration handles the full ticket lifecycle in both directions — creation, comments, attachments, status, priority, and closure — with multi-tenant ServiceNow support and try/catch error handling throughout. This is a high-complexity integration that typically requires significant custom code; the Blink implementation is fully no-code and multi-customer.
Multi-layer containment capability. The estate covers active response from four vectors simultaneously: endpoint (Cortex XDR isolation), network (Palo Alto IP blocking), DNS/web (Zscaler ZIA domain blocking), and file hash (XDR block list). Few MSSP platforms have pre-built containment automation spanning all four layers.
VIP-aware enrichment. The SOC enrichment chain includes dedicated VIP user checks for both source and destination users — a detail that directly maps to client SLA prioritization requirements and shows depth of operational design.
Gaps & Opportunities
No recorded executions — activation audit needed. All 93 workflows show 0 executions in the 12-month window. This is the most significant gap to address before deriving ROI metrics. Root causes to investigate: (a) are scheduled/event triggers enabled and connected to live data sources, (b) are integration connections validated and authenticated, (c) does the telemetry collection window post-date the deployment date.
Remediation workflows are undifferentiated. Remediation 2, 3, and 4 share near-identical structures (ServiceNow + Cortex XDR cross-reference) with names that don't distinguish their scope or trigger conditions. A consolidation pass could reduce these to a single parameterized workflow, improving maintainability and making execution metrics meaningful.
No CSPM automation deployed. Despite a broad SOC and IAM footprint, there are no cloud security posture workflows (AWS Config, Microsoft Defender for Cloud, Prisma). Given the existing AWS integration for Workspaces and EC2 lifecycle management, expanding into cloud configuration compliance monitoring is a natural next step.
Threat intelligence loop is open-ended. VirusTotal enrichment is deployed and VirusTotal verdicts surface in alert context, but there is no automated write-back: a confirmed-malicious verdict from VT does not automatically trigger a ZIA domain block or XDR hash block. Closing this loop would turn enrichment into active defense.
Asset correlation limited to three sources. The Qualys + XDR + ServiceNow correlation is solid, but cloud-native workloads (EC2 instances, serverless) are absent. Adding AWS EC2 inventory — which is already connected for Workspaces — would extend coverage visibility to cloud infrastructure.
Integration Ecosystem
| Integration | Use Cases |
|---|---|
| Cortex XDR | EDR containment, alert enrichment, asset correlation, vulnerability remediation, IOC management |
| ServiceNow | ITSM sync (ZD↔SNOW), asset correlation, vulnerability remediation, network blocking audit |
| Zendesk | SOC ticketing, ITSM sync, staff lifecycle, SIEM sensor tracking |
| Microsoft SQL | SOC pipeline backbone — rule metadata, dedup logic, on-call routing, notification contacts |
| ArcSight | SIEM event ingestion (Alert and DSM event types) |
| Zscaler ZIA | URL/domain blocking |
| Palo Alto Networks | Firewall IP blocking |
| Twilio | Voice call + SMS escalation |
| VirusTotal | IOC hash/URL verdict with result caching |
| Elasticsearch (ELK SOC) | Evidence-of-incident search, SOC analyst user management |
| Microsoft Entra ID | Staff onboarding / offboarding (cloud identity) |
| Active Directory (LDAP) | Staff onboarding / offboarding (on-prem identity) |
| DUO | MFA provisioning and deprovisioning |
| Cisco Umbrella | DNS policy management (two managed network tenants) |
| AWS | Workspaces virtual desktop + EC2 lifecycle management |
| Qualys | Vulnerability asset inventory |
| CyCognito | External attack surface discovery |
| Cortex Xpanse | ASM alert enrichment and status update |
| MySQL (ArcSight ESM) | User attribute lookup across three ESM instances |
| Slack | EDR response result notifications |
| Google Sheets | Bulk data import utility |
| SMTP | Email notification utility |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.