Blink Security Automation — Confidential

BDOMDR — Customer Success Report

Generated 2026-09-10 | bdomdr-value-report.md
2026-09-10Report Date
224Total Playbooks
182Unique Workflows (12m)
49,674,124Actions Automated (12m)
$12,776,266Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

224
Total playbooks built
all non-deleted workflows
93
Active playbooks
currently enabled
182
Unique workflows executed (12m)
distinct workflows that ran
49,674,124
Actions automated (12m)
completed action steps
275,967.4h
Hours saved (12m)
@ 20s per action
$12,776,266
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
72,969
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
3
Active AI agents
of 11 total
186
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: *No automated actions were recorded for this period. 93 workflows are deployed across 13 use cases and 5 workspaces, representing a broad automation capability awaiting activation.*

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
ArcSight SOC Alert Pipeline0 executions
0.0%
5
5 active
Zendesk SOC Ticketing0 executions
0.0%
2
2 active
Alert Enrichment & IOC Lookup0 executions
0.0%
10
10 active
EDR Containment & Response0 executions
0.0%
5
5 active
Network & Domain Blocking0 executions
0.0%
3
3 active
Outbound Escalation (Twilio)0 executions
0.0%
2
2 active
ZD ↔ ServiceNow Bidirectional Sync0 executions
0.0%
14
14 active
MDR Staff Onboarding0 executions
0.0%
9
9 active
MDR Staff Offboarding0 executions
0.0%
9
9 active
Asset Inventory & Correlation0 executions
0.0%
5
5 active
Vulnerability Remediation0 executions
0.0%
3
3 active
Attack Surface Management0 executions
0.0%
2
2 active
Platform Utilities & Infrastructure0 executions
0.0%
20
20 active
Total0 executions100%
89
89 active

Use Case Growth Over Time

176 unique playbooks  |  13 operational use cases  |  0 total executions (12m)  |  2023-08 to 2024-11
Toggle:
Toggle:

03Integration Ecosystem

Network & Domain Blocking
Zscaler Internet Access Slack Palo Alto Firewall ServiceNow
EDR Containment & Response
Cortex XDR Slack Gmail Zendesk
Asset Inventory & Correlation
Qualys Cortex XDR ServiceNow
Vulnerability Remediation
ServiceNow Cortex XDR
Platform Utilities & Infrastructure
Microsoft SQL Server Google Sheets MySQL Zendesk String Utilities Email
ArcSight SOC Alert Pipeline
ArcSight ESM
Zendesk SOC Ticketing
Microsoft SQL Server Zendesk
MDR Staff Onboarding
Microsoft Entra ID Elasticsearch Duo LDAP Zendesk AWS Cisco Umbrella
MDR Staff Offboarding
Microsoft Entra ID Duo Zendesk Elasticsearch AWS LDAP Cisco Umbrella
Outbound Escalation (Twilio)
Twilio
Alert Enrichment & IOC Lookup
MySQL Whois AbuseIPDB VirusTotal Cortex XDR Cortex Xpanse Elasticsearch
ZD ↔ ServiceNow Bidirectional Sync
Zendesk ServiceNow
Attack Surface Management
CyCognito Zendesk

04Key Observations

✓  Strengths

Strengths

Architecturally complete SOC ingestion pipeline. The numbered ArcSight sequence (1 → 2 → 3 → 5 → 6) represents a well-designed ingestion-to-escalation flow covering SIEM polling, deduplication, case creation, enrichment, and Zendesk ticketing in a single automation chain. The MSSQL-backed rule and notification databases make the pipeline configurable without touching workflow logic.

Comprehensive MDR employee lifecycle automation. The onboarding and offboarding stacks cover 8 distinct systems each in a single orchestrated flow: AD/LDAP, Entra ID, DUO, Elasticsearch, Zendesk, AWS Workspaces, and dual Cisco Umbrella tenants. This is operationally mature and reflects a security-first identity hygiene posture — every new analyst is fully provisioned, every departure is fully revoked, in one click.

Production-grade bidirectional ITSM sync. The 14-playbook ZD↔ServiceNow V3 integration handles the full ticket lifecycle in both directions — creation, comments, attachments, status, priority, and closure — with multi-tenant ServiceNow support and try/catch error handling throughout. This is a high-complexity integration that typically requires significant custom code; the Blink implementation is fully no-code and multi-customer.

Multi-layer containment capability. The estate covers active response from four vectors simultaneously: endpoint (Cortex XDR isolation), network (Palo Alto IP blocking), DNS/web (Zscaler ZIA domain blocking), and file hash (XDR block list). Few MSSP platforms have pre-built containment automation spanning all four layers.

VIP-aware enrichment. The SOC enrichment chain includes dedicated VIP user checks for both source and destination users — a detail that directly maps to client SLA prioritization requirements and shows depth of operational design.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

No recorded executions — activation audit needed. All 93 workflows show 0 executions in the 12-month window. This is the most significant gap to address before deriving ROI metrics. Root causes to investigate: (a) are scheduled/event triggers enabled and connected to live data sources, (b) are integration connections validated and authenticated, (c) does the telemetry collection window post-date the deployment date.

Remediation workflows are undifferentiated. Remediation 2, 3, and 4 share near-identical structures (ServiceNow + Cortex XDR cross-reference) with names that don't distinguish their scope or trigger conditions. A consolidation pass could reduce these to a single parameterized workflow, improving maintainability and making execution metrics meaningful.

No CSPM automation deployed. Despite a broad SOC and IAM footprint, there are no cloud security posture workflows (AWS Config, Microsoft Defender for Cloud, Prisma). Given the existing AWS integration for Workspaces and EC2 lifecycle management, expanding into cloud configuration compliance monitoring is a natural next step.

Threat intelligence loop is open-ended. VirusTotal enrichment is deployed and VirusTotal verdicts surface in alert context, but there is no automated write-back: a confirmed-malicious verdict from VT does not automatically trigger a ZIA domain block or XDR hash block. Closing this loop would turn enrichment into active defense.

Asset correlation limited to three sources. The Qualys + XDR + ServiceNow correlation is solid, but cloud-native workloads (EC2 instances, serverless) are absent. Adding AWS EC2 inventory — which is already connected for Workspaces — would extend coverage visibility to cloud infrastructure.

Integration Ecosystem

Integration Use Cases
Cortex XDR EDR containment, alert enrichment, asset correlation, vulnerability remediation, IOC management
ServiceNow ITSM sync (ZD↔SNOW), asset correlation, vulnerability remediation, network blocking audit
Zendesk SOC ticketing, ITSM sync, staff lifecycle, SIEM sensor tracking
Microsoft SQL SOC pipeline backbone — rule metadata, dedup logic, on-call routing, notification contacts
ArcSight SIEM event ingestion (Alert and DSM event types)
Zscaler ZIA URL/domain blocking
Palo Alto Networks Firewall IP blocking
Twilio Voice call + SMS escalation
VirusTotal IOC hash/URL verdict with result caching
Elasticsearch (ELK SOC) Evidence-of-incident search, SOC analyst user management
Microsoft Entra ID Staff onboarding / offboarding (cloud identity)
Active Directory (LDAP) Staff onboarding / offboarding (on-prem identity)
DUO MFA provisioning and deprovisioning
Cisco Umbrella DNS policy management (two managed network tenants)
AWS Workspaces virtual desktop + EC2 lifecycle management
Qualys Vulnerability asset inventory
CyCognito External attack surface discovery
Cortex Xpanse ASM alert enrichment and status update
MySQL (ArcSight ESM) User attribute lookup across three ESM instances
Slack EDR response result notifications
Google Sheets Bulk data import utility
SMTP Email notification utility
Appendices
A Case Management 0 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
72,969
0 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 0 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
BDO MDR Master Playbook 72,969 0 0 N/A
B AI Agents 3 active | 186 tasks (12m)

AI Agents

Active Agents
3
of 11 total
Tasks Executed (12m)
186
0 in last 30d
Data Usage (12m)
13,470,017
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Sum Ting Wong BDO MDR - MTE 151 0 10,978,144
2 TPRM Email Analyzer BDO - TPRM 22 0 368,758
3 Agent Bumblebee BDO MDR Master Playbook 13 0 2,123,115
4 Agent Blink CM V9 Elastic POC 0 0 0
5 Agent Blink BDO MDR Prod 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
BDO MDR - MTE151
BDO - TPRM22
BDO MDR Master Playbook13
CM V9 Elastic POC0
BDO MDR Prod0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
2
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Daily status alerts 00
2 SMS Using 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 13 use cases | 0 executions (12m)

Business KPIs

All 93 workflows recorded 0 executions in the reporting window (July 2025 – July 2026). This indicates workflows are deployed but not yet running in production — likely due to trigger activation, integration connection setup, or telemetry collection timing. The KPI table reflects deployment scope rather than realized throughput.

Metric Count Playbook
— — No executions recorded in period
In the last 12 months, Blink automated: *No automated actions were recorded for this period. 93 workflows are deployed across 13 use cases and 5 workspaces, representing a broad automation capability awaiting activation.*

Use Case Summary

# Use Case Category Subcategory Playbooks
1 ArcSight SOC Alert Pipeline SOC SIEM & log pipeline monitoring, Case mgmt & SOAR 5
2 Zendesk SOC Ticketing SOC Case mgmt & SOAR 2
3 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 10
4 EDR Containment & Response SOC EDR containment & response 5
5 Network & Domain Blocking SOC EDR containment & response 3
6 Outbound Escalation (Twilio) SOC Case mgmt & SOAR 2
7 ZD ↔ ServiceNow Bidirectional Sync Other IT helpdesk & ticket routing 14
8 MDR Staff Onboarding IAM Employee onboarding, Full employee lifecycle 9
9 MDR Staff Offboarding IAM Employee offboarding, Full employee lifecycle 9
10 Asset Inventory & Correlation Cloud Security Cloud asset coverage & inventory 5
11 Vulnerability Remediation Vulnerability Mgmt CVE lookup & remediation, Vuln lifecycle prioritize & ticket 5
12 Attack Surface Management Vulnerability Mgmt Threat hunting & detection, Vuln scan lifecycle automation 2
13 Platform Utilities & Infrastructure SOC Case mgmt & SOAR 22
Total 93

Use Cases

1. ArcSight SOC Alert Pipeline

Description: End-to-end ingestion of ArcSight SIEM events into Blink Case Management. The pipeline polls ArcSight Query Viewers for both Alert and DSM event types, deduplicates against existing records using an MSSQL automation-closing database, and creates or links alerts and cases automatically.

Business problem solved: Eliminates manual log review from ArcSight consoles; SOC analysts work from a unified Blink case queue rather than raw SIEM output, with deduplication preventing alert fatigue from repeat events.

Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR

Integrations: ArcSight, Microsoft SQL, Blink Case Management, Blink Tables

Playbook Role Executions (12mo)
1. Master Workflow - Get All New Events - Alert Orchestrator — Alert event type 0
Master Workflow - Get All New Events - DSM Orchestrator — DSM event type 0
3. Master - Ingest and dedup Event in Case Management Dedup & case routing 0
2. Case Management - Create Alert and Create or Link A Case Alert/case creation 0
Arcsight - Get Formatted Query Viewer Results SIEM data fetch (subflow) 0

2. Zendesk SOC Ticketing

Description: Automated creation of Zendesk tickets from SOC alert events, including pre-population of ticket fields: priority mapping from event severity, rule descriptions from MSSQL, ELK evidence-of-incident links, XDR incident correlation, and VIP user flags.

Business problem solved: Removes manual ticket creation from the SOC escalation path; ensures every alert that reaches escalation threshold generates a properly formatted Zendesk ticket without analyst intervention.

Category: SOC | Subcategories: Case mgmt & SOAR

Integrations: Zendesk, Microsoft SQL, Cortex XDR, Elasticsearch

Playbook Role Executions (12mo)
5. Zendesk - Create new Ticket Top-level ticket creation 0
6. Zendesk - Pre-request information for open ZD Field enrichment pre-flight (subflow) 0

3. Alert Enrichment & IOC Lookup

Description: A suite of enrichment subflows invoked during SOC triage to gather context on IPs, file hashes, user identities (source/destination, VIP status), endpoint state, open XDR incidents, and ELK evidence of interest. VirusTotal provides hash and URL verdicts with a result-caching layer.

Business problem solved: Reduces analyst research time per alert by automatically surfacing device context, user risk tier, threat intelligence verdicts, and correlated XDR incident data directly into the case record before an analyst reviews it.

Category: SOC | Subcategories: Alert enrichment / IOC lookup

Integrations: VirusTotal, Cortex XDR, Cortex Xpanse, Elasticsearch, ArcSight, MySQL (ESM-GER-2, ESM-GER-3, ESM-Carl)

Playbook Role Executions (12mo)
Utility - IP Enrichment IP extraction & enrichment 0
VirusTotal - Get IOC Enrichment and refresh cache IOC verdict (VT) with caching 0
ArcSight - Source User Info Source user context 0
ArcSight - Destination User Info Destination user context 0
ArcSight - VIP Source User Info VIP source user check 0
ArcSight - VIP Destination User Info VIP destination user check 0
Cortex XDR - Get Device Info Endpoint device lookup 0
Cortex XDR - Incident Enrichment XDR incident correlation 0
Xpanse - Enrichment and Change Alert Status ASM alert enrichment 0
ELK SOC - Search EOI by Query from DBDB Evidence-of-incident ELK query 0

4. EDR Containment & Response

Description: On-demand and webhook-triggered endpoint containment using Cortex XDR. Supports manual isolation requests, automated isolation via webhook (triggered from Zendesk ticket comments), endpoint scanning, and hash-level blocking and whitelisting across multiple customer XDR connections.

Business problem solved: Compresses endpoint containment from minutes to seconds by removing the manual XDR console step; supports both analyst-initiated actions and automated isolation triggered by external ticketing system events.

Category: SOC | Subcategories: EDR containment & response

Integrations: Cortex XDR, Slack, Zendesk

Playbook Role Executions (12mo)
Isolate Endpoint with Cortex XDR and Send Results via Slack Manual endpoint isolation 0
Scan Endpoint with Cortex XDR and Send Results via Slack Manual endpoint scan 0
Isolate Endpoint with Cortex XDR and Send Results via Slack (Webhook listen trigger) Webhook-triggered isolation 0
Cortex XDR - Add Hash to Block List Hash-level containment 0
Cortex XDR - Ignore IOC Hash Hash whitelist management 0

5. Network & Domain Blocking

Description: Automated enforcement actions across Zscaler ZIA (URL/domain blocking via DenyList) and Palo Alto Networks Firewall (IP blocking across specified network locations). Supports on-demand analyst triggers and creates ServiceNow incidents as a blocking audit trail.

Business problem solved: Closes the gap between threat intelligence identification and network enforcement; a malicious domain or IP can be pushed to perimeter controls without requiring a firewall admin or ZIA console access.

Category: SOC | Subcategories: EDR containment & response

Integrations: Zscaler ZIA, Palo Alto Networks, ServiceNow

Playbook Role Executions (12mo)
Add URL to ZIA URL/domain block in ZIA 0
Block malicious domain Domain block via ZIA DenyList 0
Block IPs - Palo Alto Networks Firewall IP block + ServiceNow audit ticket 0

6. Outbound Escalation (Twilio)

Description: Automated phone and SMS escalation for high-severity SOC events. Looks up the appropriate on-call contact from the MSSQL notification database, then dispatches outbound calls or SMS messages via Twilio based on the alert rule and customer context.

Business problem solved: Ensures critical alerts reach the right personnel immediately without requiring an analyst to manually identify and dial the on-call contact; removes the last manual step in the critical-alert notification chain.

Category: SOC | Subcategories: Case mgmt & SOAR

Integrations: Twilio, Microsoft SQL

Playbook Role Executions (12mo)
Twilio - Send SMS SMS alert notification 0
Twilio - Outbound Call Voice call escalation 0

7. ZD ↔ ServiceNow Bidirectional Sync

Description: A full bidirectional synchronization layer between Zendesk and ServiceNow. Handles ticket creation, comment sync, status and priority sync, attachment sync, and ticket closure in both directions. Supports multiple customer ServiceNow instances via a dynamic connection map stored in Blink Tables; V3 architecture adds try/catch error handling throughout.

Business problem solved: Eliminates manual double-entry and status drift between the MDR's Zendesk instance and managed customers' ServiceNow instances; both systems reflect the same ticket state in real time without any human relay.

Category: Other | Subcategories: IT helpdesk & ticket routing

Integrations: Zendesk, ServiceNow (multi-tenant), Blink Tables

Playbook Role Executions (12mo)
Open from SNOW to ZD V3 SNOW → ZD ticket creation 0
Open From ZD to SNOW V3 ZD → SNOW ticket creation 0
ZD to SNOW comment V3 ZD comment → SNOW 0
SNOW to ZD Comment V3 SNOW comment → ZD 0
ZD to SNOW Close v3 ZD closure → SNOW 0
ZD to SNOW Priority update Priority change sync 0
ZD to SNOW status sync Status sync (on-demand) 0
ZD to SNOW status sync - org Status sync (org-scoped) 0
Upload Attachments ZD to SNOW V3 ZD attachment → SNOW 0
Upload Attachments SNOW to ZD V3 SNOW attachment → ZD 0
Generate creation JSON Ticket payload builder (subflow) 0
Generate creation JSON v3 Ticket payload builder v3 (subflow) 0
Replacing Priority Status ZD-SNOW Priority/status field mapping (subflow) 0
Add To Connection Map Customer SNOW connection setup 0

8. MDR Staff Onboarding

Description: Fully automated onboarding of new MDR staff members across all required platforms. A single orchestrator triggers simultaneous provisioning across Active Directory (LDAP), Microsoft Entra ID (with external guest invite), DUO MFA, Elasticsearch SOC, Zendesk, AWS Workspaces, and Cisco Umbrella across two managed network tenants.

Business problem solved: Reduces new hire platform provisioning from hours of manual work across eight systems to a single triggered workflow; eliminates provisioning gaps that create security blind spots or delayed analyst access.

Category: IAM | Subcategories: Employee onboarding, Full employee lifecycle

Integrations: LDAP/Active Directory, Microsoft Entra ID, DUO, Elasticsearch, Zendesk, AWS, Cisco Umbrella

Playbook Role Executions (12mo)
MDR - Onboarding Staff Member Top-level orchestrator 0
MDR - Create AD User LDAP/AD provisioning 0
Microsoft Entra ID - Create New User Entra ID + external invite 0
DUO - Create User MFA enrollment 0
ELK SOC - Create User Elasticsearch SOC access 0
Zendesk - Create User Zendesk access 0
AWS - Create Workspace AWS virtual desktop provisioning 0
Avolon Umbrella - Create User Cisco Umbrella DNS policy (tenant A) 0
DiscoverIE Umbrella - Create User Cisco Umbrella DNS policy (tenant B) 0

9. MDR Staff Offboarding

Description: Mirrors the onboarding stack in reverse — a single orchestrator triggers deprovisioning and suspension across all MDR platforms simultaneously: AD disable, Entra ID removal, DUO deprovisioning, Elasticsearch access revocation, Zendesk suspension, AWS Workspace deletion, and Cisco Umbrella removal across both tenants.

Business problem solved: Prevents access persistence after termination across eight systems; ensures offboarding is complete and auditable in a single automated pass without relying on manual checklists.

Category: IAM | Subcategories: Employee offboarding, Full employee lifecycle

Integrations: LDAP/Active Directory, Microsoft Entra ID, DUO, Elasticsearch, Zendesk, AWS, Cisco Umbrella

Playbook Role Executions (12mo)
MDR - Offboarding Staff Member Top-level orchestrator 0
MDR - Disable AD User LDAP/AD disable 0
Microsoft Entra ID - Delete User Entra ID removal 0
DUO - Delete User MFA deprovisioning 0
ELK SOC - Delete User Elasticsearch access revocation 0
Zendesk - Suspend User Zendesk suspension 0
AWS - Delete Workspace AWS desktop removal 0
Avolon Umbrella - Delete User Cisco Umbrella removal (tenant A) 0
DiscoverIE Umbrella - Delete User Cisco Umbrella removal (tenant B) 0

10. Asset Inventory & Correlation

Description: Cross-source asset correlation that joins endpoint records from Qualys, Cortex XDR, and ServiceNow into a unified asset table in Blink. SQL queries then surface coverage gaps — assets visible in one source but absent from another — across all three.

Business problem solved: Provides a single reconciled asset inventory without a dedicated CMDB integration; surfaces security coverage gaps where endpoints are known to IT (ServiceNow) but not enrolled in the EDR or vulnerability scanner.

Category: Cloud Security | Subcategories: Cloud asset coverage & inventory

Integrations: Qualys, Cortex XDR, ServiceNow, Blink Tables

Playbook Role Executions (12mo)
Asset Correlation main Top-level orchestrator 0
Asset Correlation Qualys Qualys asset pull (subflow) 0
Asset Correlation - XDR XDR endpoint pull (subflow) 0
Asset Correlation - ServiceNow ServiceNow CMDB pull (subflow) 0
Add or Update Asset Unified asset upsert (subflow) 0

11. Vulnerability Remediation

Description: ServiceNow-triggered remediation workflows that cross-reference CVE data from ServiceNow incidents against endpoint inventory in Cortex XDR. Multiple remediation variants handle different scenarios; a file download utility extracts remediation artifacts from ServiceNow attachments.

Business problem solved: Automates the cross-referencing step in vulnerability remediation — matching CVE findings from ticketed incidents to affected XDR endpoints — so remediation owners receive pre-populated endpoint lists rather than conducting manual asset queries.

Category: Vulnerability Mgmt | Subcategories: CVE lookup & remediation, Vuln lifecycle prioritize & ticket

Integrations: ServiceNow, Cortex XDR

Playbook Role Executions (12mo)
Remediation 2 CVE-to-endpoint matching (variant 2) 0
threats 1 Threat analysis (variant 1) 0
Remediation 3 CVE-to-endpoint matching (variant 3) 0
Remediation 4 CVE-to-endpoint matching (variant 4) 0
Download File File extraction from ServiceNow 0

12. Attack Surface Management

Description: External attack surface discovery and SIEM sensor health monitoring. CyCognito enumerates externally exposed assets, while the DSM workflow detects devices that have stopped reporting to the SIEM and creates Zendesk tickets to track remediation.

Business problem solved: Automates external exposure discovery and SIEM sensor gap detection, catching both unknown external assets and silent sensors before they create coverage blindspots or SLA violations.

Category: Vulnerability Mgmt | Subcategories: Threat hunting & detection, Vuln scan lifecycle automation

Integrations: CyCognito, Zendesk

Playbook Role Executions (12mo)
cycognito External asset discovery 0
DSM - Device Return Reporting SIEM sensor gap detection 0

13. Platform Utilities & Infrastructure

Description: Shared utility subflows and administrative tooling that underpin the SOC pipeline, enrichment chain, and ZD-SNOW sync. Includes MSSQL routing lookups (rule details, notification contacts), text normalization utilities, event-source classifiers, and admin tools for data management and integration setup.

Business problem solved: Provides reusable logic components that keep the main SOC workflows clean and maintainable; centralizes volatile configuration (on-call contacts, rule metadata, severity mappings) in queryable MSSQL tables rather than hardcoded workflow logic.

Category: SOC | Subcategories: Case mgmt & SOAR

Integrations: Microsoft SQL, Elasticsearch, Google Sheets, Zendesk, AWS, SMTP

Playbook Role Executions (12mo)
MS SQL - Get Automation Closing Dedup/closing logic lookup 0
MS SQL - Get Rule Details Alert rule metadata 0
MS SQL - Get Call Notification Call routing lookup 0
MS SQL - Get SMS Notification SMS routing lookup 0
MS SQL - Get Requester from 3A Notification ZD requester lookup 0
Utility - Extract Upper Case User from Event Username normalization 0
Utility - Correct Upper Case Customer Name from Event Tenant name normalization 0
Utility - Create Helper Link ZD helper link generation 0
Utility - Description Formatting Alert description formatting 0
Utility - Set Event Severity to ZD Priority Severity → priority mapping 0
Utility - Mask URLs and Links URL sanitization 0
Utility - Event Source identification Source type classification 0
Account Information by User Name or Email ArcSight ESM user attribute lookup 0
Print Username Debug utility 0
USE WITH CARE - Delete All Table Records Table wipe (admin) 0
USE WITH CARE - Delete All Cases/alerts Table Records Case/alert table wipe (admin) 0
Import CSVs to Table Bulk data import via Google Sheets 0
PKV - Ticket ID Webhook PKV ticket ID extraction via webhook 0
Zendesk - Export All Users per Customer User export (admin) 0
Zendesk - Search Triggers and Automations by string ZD config search (admin) 0
AWS - EC2 Instance Start / Stop / Restart EC2 lifecycle management 0
SMTP - Send Email Email notification utility 0

Key Observations

Strengths

Architecturally complete SOC ingestion pipeline. The numbered ArcSight sequence (1 → 2 → 3 → 5 → 6) represents a well-designed ingestion-to-escalation flow covering SIEM polling, deduplication, case creation, enrichment, and Zendesk ticketing in a single automation chain. The MSSQL-backed rule and notification databases make the pipeline configurable without touching workflow logic.

Comprehensive MDR employee lifecycle automation. The onboarding and offboarding stacks cover 8 distinct systems each in a single orchestrated flow: AD/LDAP, Entra ID, DUO, Elasticsearch, Zendesk, AWS Workspaces, and dual Cisco Umbrella tenants. This is operationally mature and reflects a security-first identity hygiene posture — every new analyst is fully provisioned, every departure is fully revoked, in one click.

Production-grade bidirectional ITSM sync. The 14-playbook ZD↔ServiceNow V3 integration handles the full ticket lifecycle in both directions — creation, comments, attachments, status, priority, and closure — with multi-tenant ServiceNow support and try/catch error handling throughout. This is a high-complexity integration that typically requires significant custom code; the Blink implementation is fully no-code and multi-customer.

Multi-layer containment capability. The estate covers active response from four vectors simultaneously: endpoint (Cortex XDR isolation), network (Palo Alto IP blocking), DNS/web (Zscaler ZIA domain blocking), and file hash (XDR block list). Few MSSP platforms have pre-built containment automation spanning all four layers.

VIP-aware enrichment. The SOC enrichment chain includes dedicated VIP user checks for both source and destination users — a detail that directly maps to client SLA prioritization requirements and shows depth of operational design.

Gaps & Opportunities

No recorded executions — activation audit needed. All 93 workflows show 0 executions in the 12-month window. This is the most significant gap to address before deriving ROI metrics. Root causes to investigate: (a) are scheduled/event triggers enabled and connected to live data sources, (b) are integration connections validated and authenticated, (c) does the telemetry collection window post-date the deployment date.

Remediation workflows are undifferentiated. Remediation 2, 3, and 4 share near-identical structures (ServiceNow + Cortex XDR cross-reference) with names that don't distinguish their scope or trigger conditions. A consolidation pass could reduce these to a single parameterized workflow, improving maintainability and making execution metrics meaningful.

No CSPM automation deployed. Despite a broad SOC and IAM footprint, there are no cloud security posture workflows (AWS Config, Microsoft Defender for Cloud, Prisma). Given the existing AWS integration for Workspaces and EC2 lifecycle management, expanding into cloud configuration compliance monitoring is a natural next step.

Threat intelligence loop is open-ended. VirusTotal enrichment is deployed and VirusTotal verdicts surface in alert context, but there is no automated write-back: a confirmed-malicious verdict from VT does not automatically trigger a ZIA domain block or XDR hash block. Closing this loop would turn enrichment into active defense.

Asset correlation limited to three sources. The Qualys + XDR + ServiceNow correlation is solid, but cloud-native workloads (EC2 instances, serverless) are absent. Adding AWS EC2 inventory — which is already connected for Workspaces — would extend coverage visibility to cloud infrastructure.

Integration Ecosystem

Integration Use Cases
Cortex XDR EDR containment, alert enrichment, asset correlation, vulnerability remediation, IOC management
ServiceNow ITSM sync (ZD↔SNOW), asset correlation, vulnerability remediation, network blocking audit
Zendesk SOC ticketing, ITSM sync, staff lifecycle, SIEM sensor tracking
Microsoft SQL SOC pipeline backbone — rule metadata, dedup logic, on-call routing, notification contacts
ArcSight SIEM event ingestion (Alert and DSM event types)
Zscaler ZIA URL/domain blocking
Palo Alto Networks Firewall IP blocking
Twilio Voice call + SMS escalation
VirusTotal IOC hash/URL verdict with result caching
Elasticsearch (ELK SOC) Evidence-of-incident search, SOC analyst user management
Microsoft Entra ID Staff onboarding / offboarding (cloud identity)
Active Directory (LDAP) Staff onboarding / offboarding (on-prem identity)
DUO MFA provisioning and deprovisioning
Cisco Umbrella DNS policy management (two managed network tenants)
AWS Workspaces virtual desktop + EC2 lifecycle management
Qualys Vulnerability asset inventory
CyCognito External attack surface discovery
Cortex Xpanse ASM alert enrichment and status update
MySQL (ArcSight ESM) User attribute lookup across three ESM instances
Slack EDR response result notifications
Google Sheets Bulk data import utility
SMTP Email notification utility
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.