Blink Security Automation — Confidential

boi — Customer Success Report

Generated 2026-09-10 | boi-value-report.md
2026-09-10Report Date
86Total Playbooks
22Unique Workflows (12m)
94,850Actions Automated (12m)
$24,396Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

86
Total playbooks built
all non-deleted workflows
54
Active playbooks
currently enabled
22
Unique workflows executed (12m)
distinct workflows that ran
94,850
Actions automated (12m)
completed action steps
526.9h
Hours saved (12m)
@ 20s per action
$24,396
Money saved (12m)
@ $100K avg salary
3
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 4 total
3
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 424 security alerts automatically ingested and normalized from Microsoft Defender XDR - 15 security alerts fully processed end-to-end through the automated SOC pipeline — observables extracted, deduplicated, enriched, and routed for response - 2 threat incidents retrieved from Intezer for automated analysis - 337 IP addresses automatically checked against internal BOI network ranges during observable enrichment - 273 sign-in activity investigations run against Azure Log Analytics (149 by IP, 124 by user) to support analyst response - 86 custom KQL queries executed on demand against Azure Log Analytics

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SOC Alert Pipeline & Automated Triage
  • 424Security alerts ingested & normalized from Microsoft Defender XDR
  • 15Security alerts processed end-to-end through the automated SOC pipeline
24.7%
8
8 active
Observable Enrichment & IOC Lookup
  • 337Internal IP addresses automatically checked against BOI network ranges during enrichment
52.6%
18
18 active
Case Management Utilities & Maintenance0 executions
0.0%
6
6 active
Endpoint Containment & Malware Response0 executions
0.0%
1
1 active
Phishing Detection & Response0 executions
0.0%
1
1 active
Identity Threat Detection3 executions
0.0%
3
3 active
Agentic SOC Capabilities0 executions
0.0%
3
3 active
Conditional Access & Network Blocklist Management0 executions
0.0%
2
2 active
SIEM, Log Analytics & Threat Intelligence
  • 149Sign-in activity investigations run by IP address via Azure Log Analytics
  • 124Sign-in activity investigations run by user via Azure Log Analytics
  • 86Custom KQL queries executed on demand against Azure Log Analytics
3.5%
6
6 active
User Identity Information Lookups770 executions
4.4%
2
2 active
End-of-Life & Vulnerability Tracking0 executions
0.0%
0
0 active
Admin, Demo & Training0 executions
0.0%
2
1 active
Total14,871 executions100%
52
51 active

Use Case Growth Over Time

72 unique playbooks  |  11 operational use cases  |  17,460 total executions (12m)  |  2026-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Conditional Access & Network Blocklist Management
Microsoft Entra ID
Identity Threat Detection
Microsoft Entra ID Okta Email
SIEM, Log Analytics & Threat Intelligence
Azure Log Analytics Intezer
Agentic SOC Capabilities
Microsoft Entra ID Microsoft Teams Azure Log Analytics
Admin, Demo & Training
Agents
Observable Enrichment & IOC Lookup
CrowdStrike Okta AbuseIPDB VirusTotal URLScan Slack
User Identity Information Lookups
Google Workspace Microsoft Entra ID GitHub Okta Slack
SOC Alert Pipeline & Automated Triage
Email Microsoft Sentinel
Phishing Detection & Response
Microsoft Outlook
Endpoint Containment & Malware Response
CrowdStrike

04Key Observations

✓  Strengths

Strengths

  • End-to-end SOC automation pipeline is live. The alert lifecycle from Defender XDR ingest → observable extraction → enrichment routing → response dispatch is fully wired and has executed 450+ times in 12 months. This is a production-grade SOAR platform, not a pilot.
  • Breadth of enrichment coverage. 10+ threat intelligence and identity sources are integrated into a single routing layer (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Entra ID, Google Workspace, GitHub, Slack, Whois). When the pipeline is fully active, analysts receive pre-enriched cases without touching any external console.
  • Agentic SOC foundation in place. Three agent abilities (Teams interaction, user department lookup, Log Analytics queries) indicate BOI is building toward AI-driven autonomous triage — a significant forward-looking investment in the Blink platform.
  • Microsoft-native, CrowdStrike-reinforced. The environment is heavily Microsoft-centric (Entra ID, Defender XDR, Azure Log Analytics, Outlook, Teams, Graph), supplemented by CrowdStrike as the EDR. Blink bridges these two ecosystems cleanly across enrichment and response workflows.
  • Log Analytics investigation and internal-IP enrichment are now driving real volume. Beyond the core ingest pipeline, analysts are actively using Blink for ad hoc investigation: 337 internal-IP enrichment checks, 149 sign-in-by-IP queries, 124 sign-in-by-user queries, and 86 custom KQL queries in the last 12 months. This shows adoption expanding from the automated pipeline into day-to-day analyst workflows.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • Most playbooks still show zero executions, though newer investigation playbooks are gaining traction. Of 77 playbooks, the majority remain unused, but the recently added Log Analytics investigation playbooks and the internal-IP enrichment subflow are seeing meaningful adoption. The bulk of the enrichment router's downstream subflows, endpoint containment, phishing response, and identity threat containment playbooks are still built but not yet running at scale. Driving adoption of these — particularly the enrichment router's TI lookups and the Phishing/Malware response subflows — remains the largest near-term value lever.
  • Response subflows not yet activated. The Phishing and Malware response subflows exist and are connected to the main response router, but show 0 executions. Enabling these paths would immediately extend automation coverage beyond triage into remediation.
  • No scheduled/recurring automations visible. No scheduled jobs (e.g., daily risky user sweeps, stale case closure) are running. The "Utility - Close Stale Cases" and "Risky Users Workflow" playbooks are built for this purpose but inactive.
  • Single Defender XDR ingest source. All 424 alert ingestion events flow from one source (Microsoft Defender XDR, AAD Identity Protection category). Expanding ingest connectors to CrowdStrike, Okta, or additional Defender alert categories would broaden detection coverage without requiring new response logic.

Integration Ecosystem

Integration Purpose
Microsoft Defender XDR Alert ingestion (primary SOC feed)
Microsoft Entra ID / Active Directory User enrichment, risky user detection, agent ability, account containment (disable/enable)
Azure Log Analytics SIEM log queries, sign-in investigation
Microsoft Graph Conditional Access / Named Locations management
Microsoft Outlook Phishing email retrieval and header analysis
Microsoft Teams Analyst interaction via Agentic SOC
CrowdStrike Falcon Hash/agent enrichment, endpoint isolation, RTR
Okta User enrichment, activity log search
VirusTotal IP, URL, and hash threat intelligence
AbuseIPDB IP reputation scoring
URLScan URL scanning and screenshot capture
Intezer Threat incident intelligence
Google Workspace User profile enrichment
GitHub Developer identity enrichment
Slack Email-to-user identity resolution
Blink Case Management Case/alert/observable lifecycle management
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 1 active | 3 tasks (12m)

AI Agents

Active Agents
1
of 4 total
Tasks Executed (12m)
3
0 in last 30d
Data Usage (12m)
128,163
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Sherlock SOC 3 0 128,163
2 Agent Blink SOC 0 0 0
3 Agent Blink yaron.king@boi.org.il 0 0 0
4 New Agent SOC 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
SOC3
yaron.king@boi.org.il0
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 11 use cases | 17,460 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts ingested & normalized from Microsoft Defender XDR 424 EXAMPLE Ingest - Microsoft Defender XDR
Security alerts processed end-to-end through the automated SOC pipeline 15 Process Alert
Threat incidents retrieved and analyzed from Intezer 2 Intezer - Get Incidents
Internal IP addresses automatically checked against BOI network ranges during enrichment 337 Enrichment - Check BOI Internal IP
Sign-in activity investigations run by IP address via Azure Log Analytics 149 Response - Sign In Activity By IP Query
Sign-in activity investigations run by user via Azure Log Analytics 124 Response - Sign in Activity by User - Sentinel Query
Custom KQL queries executed on demand against Azure Log Analytics 86 Run Log Analytics KQL query
In the last 12 months, Blink automated: - 424 security alerts automatically ingested and normalized from Microsoft Defender XDR - 15 security alerts fully processed end-to-end through the automated SOC pipeline — observables extracted, deduplicated, enriched, and routed for response - 2 threat incidents retrieved from Intezer for automated analysis - 337 IP addresses automatically checked against internal BOI network ranges during observable enrichment - 273 sign-in activity investigations run against Azure Log Analytics (149 by IP, 124 by user) to support analyst response - 86 custom KQL queries executed on demand against Azure Log Analytics

Use Case Summary

Use Case Category Subcategory Playbooks Executions (12 mo)
SOC Alert Pipeline & Automated Triage SOC Case mgmt & SOAR 11 461
Observable Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 27 349
Case Management Utilities & Maintenance SOC Case mgmt & SOAR 7 0
Endpoint Containment & Malware Response SOC EDR containment & response 4 0
Phishing Detection & Response SOC Phishing detection & response 1 0
Identity Threat Detection SOC Identity threat response 4 3
Agentic SOC Capabilities SOC Agentic SOC 3 0
Conditional Access & Network Blocklist Mgmt Cloud Security Cloud access & SaaS policy mgmt 3 0
SIEM, Log Analytics & Threat Intelligence SOC SIEM & log pipeline monitoring, Threat intel ingest & curation 6 361
User Identity Information Lookups IAM Identity sync & directory mgmt 6 6
End-of-Life & Vulnerability Tracking Vulnerability Mgmt CVE lookup & remediation 1 0
Admin, Demo & Training Other SaaS / IT administration 4 0
Total 77 1180

Use Cases

1. SOC Alert Pipeline & Automated Triage

Category: SOC | Subcategory: Case mgmt & SOAR

Description: End-to-end, event-driven alert processing pipeline. Alerts are ingested from Microsoft Defender XDR, normalized into the case management layer, deduplicated, enriched, and routed to the appropriate response playbook — all without analyst intervention.

Business problem solved: Eliminates manual alert triage triage by automating the full lifecycle from raw event to case creation and response routing, reducing mean time to respond and preventing alert fatigue.

Integrations: Microsoft Defender XDR, Blink Case Management, Azure Log Analytics

Playbook Type Executions Taxonomy
EXAMPLE Ingest - Microsoft Defender XDR Event trigger 424 SOC › Case mgmt & SOAR, SIEM & log pipeline monitoring
Process Alert Event trigger 15 SOC › Case mgmt & SOAR
Subflow - Response - Main Router Subflow 11 SOC › Case mgmt & SOAR
Subflow - Missing Alert Template Notification Subflow 4 SOC › Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts Recovery 0 SOC › Case mgmt & SOAR
Simulate Multiple Alerts from Different Sources Test 0 SOC › Case mgmt & SOAR
Simulate Crowdstrike Alert Test 0 SOC › Case mgmt & SOAR
Error Handling - Send Error Notification Email Subflow 0 SOC › Case mgmt & SOAR
USE WITH CARE - Reset Case Management Environment Admin 0 SOC › Case mgmt & SOAR
Close Sentinel Incident On-demand 6 SOC › Case mgmt & SOAR
Closing BlinkOps + Sentinel Incident Event trigger 1 SOC › Case mgmt & SOAR

2. Observable Enrichment & IOC Lookup

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Description: A modular enrichment library that automatically queries multiple threat intelligence and identity sources for every observable (IP, hash, URL, email, username, agent ID) extracted from an alert. A central router dispatches to the correct enrichment subflow based on observable type and writes the verdict back to the case.

Business problem solved: Eliminates manual copy-paste lookups across 10+ tools per alert. Analysts receive pre-enriched cases with verdicts from VirusTotal, AbuseIPDB, CrowdStrike, Okta, Entra ID, URLScan, Whois, and more.

Integrations: VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Microsoft Entra ID (Active Directory), Google Workspace, GitHub, Slack, Blink Case Management

Playbook Type Executions Taxonomy
Subflow - Enrich Observables - Main Router Subflow 12 SOC › Alert enrichment / IOC lookup
Subflow - Update Enrichment Data Subflow 0 SOC › Alert enrichment / IOC lookup
Utility - Update Enrichment Utility 0 SOC › Alert enrichment / IOC lookup
Enrich - IP - VT Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - IP - IPDB Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - URL - VT Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - URL - URLScan Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - Hash - VT Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike Subflow 0 SOC › Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal On-demand 0 SOC › Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike On-demand 0 SOC › Alert enrichment / IOC lookup
Enrich - Username or Email - Okta Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - Email Address - Slack Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - Username - Github Subflow 0 SOC › Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike Subflow 0 SOC › Alert enrichment / IOC lookup
Analyze URL with URLScan On-demand 0 SOC › Alert enrichment / IOC lookup
Secure URL Screenshot Capture On-demand 0 SOC › Alert enrichment / IOC lookup
Run Dig Command Utility 0 SOC › Alert enrichment / IOC lookup
Recovery - Enrich Non-Enriched Observables Recovery 0 SOC › Alert enrichment / IOC lookup
Table Action - Validate Observables Extraction Template Utility 0 SOC › Alert enrichment / IOC lookup
Subflow - Post Enrichment Card Subflow 0 SOC › Alert enrichment / IOC lookup
CM Ability - User Agent Parser Subflow 0 SOC › Alert enrichment / IOC lookup
Enrichment - Check BOI Internal IP Subflow 337 SOC › Alert enrichment / IOC lookup

3. Case Management Utilities & Maintenance

Category: SOC | Subcategory: Case mgmt & SOAR

Description: A set of utility playbooks that manage the structural integrity of the case management data model — linking and unlinking observables to alerts, finding similar cases based on shared observables, and closing stale cases automatically.

Business problem solved: Keeps the case management database accurate and usable over time, preventing case clutter and ensuring observable relationships are correctly maintained for analyst review and similarity detection.

Integrations: Blink Case Management

Playbook Type Executions Taxonomy
Utility - List Observable Alert Relations Utility 0 SOC › Case mgmt & SOAR
Utility - List Alert Observable Relations Utility 0 SOC › Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables Utility 0 SOC › Case mgmt & SOAR
Utility - Set Or Update Observable Relation Utility 0 SOC › Case mgmt & SOAR
Utility - Delete Observable Relation Utility 0 SOC › Case mgmt & SOAR
Utility - Close Stale Cases Utility 0 SOC › Case mgmt & SOAR
Utility - List Observable Alert Relations Utility 0 SOC › Case mgmt & SOAR

4. Endpoint Containment & Malware Response

Category: SOC | Subcategory: EDR containment & response

Description: Automated endpoint response capabilities using CrowdStrike — including host isolation (quarantine/lift), remote command execution via Real Time Response (RTR) on single or batched hosts, and a malware response workflow that evaluates remediation status and drives next steps.

Business problem solved: Cuts containment time from hours to seconds by enabling automated or one-click endpoint isolation and remote remediation, removing the need for analyst access to the CrowdStrike console for routine response actions.

Integrations: CrowdStrike Falcon (EDR, RTR), Blink Case Management

Playbook Type Executions Taxonomy
Manage Endpoint Quarantine Status in Crowdstrike On-demand 0 SOC › EDR containment & response
CrowdStrike RTR to a Single Host On-demand 0 SOC › EDR containment & response
CrowdStrike RTR to a Batch of Hosts On-demand 0 SOC › EDR containment & response
Response Subflow - Malware Subflow 0 SOC › EDR containment & response

5. Phishing Detection & Response

Category: SOC | Subcategory: Phishing detection & response

Description: Automated phishing investigation that retrieves the original email, parses headers, detects KnowBe4 simulation markers (X-PHISHTEST), and branches response actions accordingly — distinguishing real phishing attempts from security awareness training exercises.

Business problem solved: Prevents analyst time being wasted on simulated phishing campaigns while ensuring real phishing emails receive immediate, structured investigation and response.

Integrations: Microsoft Outlook

Playbook Type Executions Taxonomy
Response Subflow - Phishing Subflow 0 SOC › Phishing detection & response

6. Identity Threat Detection

Category: SOC | Subcategory: Identity threat response

Description: Monitors for compromised or high-risk user identities by querying Microsoft Entra ID's risky users list and searching Okta activity logs for suspicious behavior patterns. Drives targeted investigation and response for identity-based threats.

Business problem solved: Provides automated detection of account compromise and anomalous identity activity across two identity providers, enabling timely response before lateral movement occurs.

Integrations: Microsoft Entra ID (Active Directory), Okta

Playbook Type Executions Taxonomy
Risky Users Workflow On-demand 0 SOC › Identity threat response
Okta Search for User Activity On-demand 0 SOC › Identity threat response
Disable/Enable Entra Account On-demand 3 SOC › Identity threat response
Disable/Enable Account and Notify On-demand 0 SOC › Identity threat response

7. Agentic SOC Capabilities

Category: SOC | Subcategory: Agentic SOC

Description: A suite of reusable agent-callable abilities that expose SOC tools to an AI agent layer — enabling a Blink AI agent to look up a user's department, send interactive questions to analysts via Microsoft Teams, and execute arbitrary Log Analytics queries. These abilities are the building blocks of a conversational, AI-driven SOC.

Business problem solved: Enables AI-driven autonomous investigation by providing a structured, callable interface to security data sources and analyst communication channels — moving toward a SOC model where the agent drives triage and human escalation is the exception.

Integrations: Microsoft Entra ID (Active Directory), Microsoft Teams, Azure Log Analytics

Playbook Type Executions Taxonomy
Agent Ability - Get User Department Agent ability 0 SOC › Agentic SOC
Agent Ability - Ask a question via Teams Agent ability 0 SOC › Agentic SOC
Agent Ability - Log Analytics Query Agent ability 0 SOC › Agentic SOC

8. Conditional Access & Network Blocklist Management

Category: Cloud Security | Subcategory: Cloud access & SaaS policy mgmt

Description: Automates the management of Microsoft Entra Conditional Access Named Locations used as IP blocklists. Playbooks sync the current blocklist state, validate whether a CIDR is already present, and add new ranges programmatically — supporting both IPv4 and IPv6.

Business problem solved: Removes the manual, error-prone process of updating Conditional Access Named Locations when new malicious IP ranges need to be blocked. Ensures the blocklist is always current and consistent across environments.

Integrations: Microsoft Graph (Conditional Access Named Locations), Blink Tables

Playbook Type Executions Taxonomy
Add CIDR to Blocklist On-demand 0 Cloud Security › Cloud access & SaaS policy mgmt
Add CIDR to Named Location On-demand 0 Cloud Security › Cloud access & SaaS policy mgmt
Get and Sync Named Locations Block List Subflow 0 Cloud Security › Cloud access & SaaS policy mgmt

9. SIEM, Log Analytics & Threat Intelligence

Category: SOC | Subcategory: SIEM & log pipeline monitoring, Threat intel ingest & curation

Description: Queries Azure Log Analytics for sign-in events and executes custom KQL queries on demand, providing analysts with flexible log investigation capabilities. Also integrates with Intezer to retrieve threat intelligence incidents for additional context.

Business problem solved: Gives the SOC on-demand access to log data and external threat intelligence without requiring console access, enabling faster investigation and correlation across data sources.

Integrations: Azure Log Analytics, Intezer

Playbook Type Executions Taxonomy
Intezer - Get Incidents On-demand 2 SOC › Threat intel ingest & curation
Query SignIn Logs On-demand 0 SOC › SIEM & log pipeline monitoring
Run Log Analytics KQL query On-demand 86 SOC › SIEM & log pipeline monitoring
Response - Sign In Activity By IP Query On-demand 149 SOC › SIEM & log pipeline monitoring
Response - Sign in Activity by User - Sentinel Query On-demand 124 SOC › SIEM & log pipeline monitoring
Response - Keep Alive Query copy On-demand 0 SOC › SIEM & log pipeline monitoring

10. User Identity Information Lookups

Category: IAM | Subcategory: Identity sync & directory mgmt

Description: Reusable on-demand playbooks to retrieve full user profile details from each identity provider in the environment. Designed for analyst use and as building blocks callable by enrichment and response workflows.

Business problem solved: Provides a single, standardized interface for user identity lookups across five platforms, eliminating the need for analysts to context-switch between consoles during investigations.

Integrations: Microsoft Entra ID (Active Directory), Okta, Google Workspace, GitHub, Slack

Playbook Type Executions Taxonomy
Get User Information Using Microsoft Entra ID On-demand 0 IAM › Identity sync & directory mgmt
Get User Information Using Okta On-demand 0 IAM › Identity sync & directory mgmt
Get User Information Using Google Workspace On-demand 0 IAM › Identity sync & directory mgmt
Get User Information Using Github On-demand 0 IAM › Identity sync & directory mgmt
Get User Information on Email Address Using Slack On-demand 0 IAM › Identity sync & directory mgmt
Entra ID - Run Query On-demand 6 IAM › Identity sync & directory mgmt

11. End-of-Life & Vulnerability Tracking

Category: Vulnerability Mgmt | Subcategory: CVE lookup & remediation

Description: Looks up the end-of-life date for any named software product and version, enabling the SOC and vulnerability management teams to identify unsupported software in the environment.

Business problem solved: Automates EOL tracking, which is often done manually via spreadsheets, providing a consistent and repeatable way to flag out-of-support software during incident investigation or asset reviews.

Integrations: endoflife.date API (via HTTP)

Playbook Type Executions Taxonomy
Get End of Life Date for a Product On-demand 0 Vulnerability Mgmt › CVE lookup & remediation

12. Admin, Demo & Training

Category: Other | Subcategory: SaaS / IT administration

Description: Placeholder, demonstration, and onboarding playbooks used during environment setup and POC activities. Not part of production operations.

Playbook Type Executions Taxonomy
Getting Started - Hello World Training 0 Other › SaaS / IT administration
Demo Shadow IT Demo 0 Other › SaaS / IT administration
New Workflow 1 Placeholder 0 Other › SaaS / IT administration

Key Observations

Strengths

  • End-to-end SOC automation pipeline is live. The alert lifecycle from Defender XDR ingest → observable extraction → enrichment routing → response dispatch is fully wired and has executed 450+ times in 12 months. This is a production-grade SOAR platform, not a pilot.
  • Breadth of enrichment coverage. 10+ threat intelligence and identity sources are integrated into a single routing layer (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Entra ID, Google Workspace, GitHub, Slack, Whois). When the pipeline is fully active, analysts receive pre-enriched cases without touching any external console.
  • Agentic SOC foundation in place. Three agent abilities (Teams interaction, user department lookup, Log Analytics queries) indicate BOI is building toward AI-driven autonomous triage — a significant forward-looking investment in the Blink platform.
  • Microsoft-native, CrowdStrike-reinforced. The environment is heavily Microsoft-centric (Entra ID, Defender XDR, Azure Log Analytics, Outlook, Teams, Graph), supplemented by CrowdStrike as the EDR. Blink bridges these two ecosystems cleanly across enrichment and response workflows.
  • Log Analytics investigation and internal-IP enrichment are now driving real volume. Beyond the core ingest pipeline, analysts are actively using Blink for ad hoc investigation: 337 internal-IP enrichment checks, 149 sign-in-by-IP queries, 124 sign-in-by-user queries, and 86 custom KQL queries in the last 12 months. This shows adoption expanding from the automated pipeline into day-to-day analyst workflows.

Gaps & Opportunities

  • Most playbooks still show zero executions, though newer investigation playbooks are gaining traction. Of 77 playbooks, the majority remain unused, but the recently added Log Analytics investigation playbooks and the internal-IP enrichment subflow are seeing meaningful adoption. The bulk of the enrichment router's downstream subflows, endpoint containment, phishing response, and identity threat containment playbooks are still built but not yet running at scale. Driving adoption of these — particularly the enrichment router's TI lookups and the Phishing/Malware response subflows — remains the largest near-term value lever.
  • Response subflows not yet activated. The Phishing and Malware response subflows exist and are connected to the main response router, but show 0 executions. Enabling these paths would immediately extend automation coverage beyond triage into remediation.
  • No scheduled/recurring automations visible. No scheduled jobs (e.g., daily risky user sweeps, stale case closure) are running. The "Utility - Close Stale Cases" and "Risky Users Workflow" playbooks are built for this purpose but inactive.
  • Single Defender XDR ingest source. All 424 alert ingestion events flow from one source (Microsoft Defender XDR, AAD Identity Protection category). Expanding ingest connectors to CrowdStrike, Okta, or additional Defender alert categories would broaden detection coverage without requiring new response logic.

Integration Ecosystem

Integration Purpose
Microsoft Defender XDR Alert ingestion (primary SOC feed)
Microsoft Entra ID / Active Directory User enrichment, risky user detection, agent ability, account containment (disable/enable)
Azure Log Analytics SIEM log queries, sign-in investigation
Microsoft Graph Conditional Access / Named Locations management
Microsoft Outlook Phishing email retrieval and header analysis
Microsoft Teams Analyst interaction via Agentic SOC
CrowdStrike Falcon Hash/agent enrichment, endpoint isolation, RTR
Okta User enrichment, activity log search
VirusTotal IP, URL, and hash threat intelligence
AbuseIPDB IP reputation scoring
URLScan URL scanning and screenshot capture
Intezer Threat incident intelligence
Google Workspace User profile enrichment
GitHub Developer identity enrichment
Slack Email-to-user identity resolution
Blink Case Management Case/alert/observable lifecycle management
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.