01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| SOC Alert Pipeline & Automated Triage |
| 24.7% | 8 8 active |
| Observable Enrichment & IOC Lookup |
| 52.6% | 18 18 active |
| Case Management Utilities & Maintenance | 0 executions | 0.0% | 6 6 active |
| Endpoint Containment & Malware Response | 0 executions | 0.0% | 1 1 active |
| Phishing Detection & Response | 0 executions | 0.0% | 1 1 active |
| Identity Threat Detection | 3 executions | 0.0% | 3 3 active |
| Agentic SOC Capabilities | 0 executions | 0.0% | 3 3 active |
| Conditional Access & Network Blocklist Management | 0 executions | 0.0% | 2 2 active |
| SIEM, Log Analytics & Threat Intelligence |
| 3.5% | 6 6 active |
| User Identity Information Lookups | 770 executions | 4.4% | 2 2 active |
| End-of-Life & Vulnerability Tracking | 0 executions | 0.0% | 0 0 active |
| Admin, Demo & Training | 0 executions | 0.0% | 2 1 active |
| Total | 14,871 executions | 100% | 52 51 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- End-to-end SOC automation pipeline is live. The alert lifecycle from Defender XDR ingest → observable extraction → enrichment routing → response dispatch is fully wired and has executed 450+ times in 12 months. This is a production-grade SOAR platform, not a pilot.
- Breadth of enrichment coverage. 10+ threat intelligence and identity sources are integrated into a single routing layer (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Entra ID, Google Workspace, GitHub, Slack, Whois). When the pipeline is fully active, analysts receive pre-enriched cases without touching any external console.
- Agentic SOC foundation in place. Three agent abilities (Teams interaction, user department lookup, Log Analytics queries) indicate BOI is building toward AI-driven autonomous triage — a significant forward-looking investment in the Blink platform.
- Microsoft-native, CrowdStrike-reinforced. The environment is heavily Microsoft-centric (Entra ID, Defender XDR, Azure Log Analytics, Outlook, Teams, Graph), supplemented by CrowdStrike as the EDR. Blink bridges these two ecosystems cleanly across enrichment and response workflows.
- Log Analytics investigation and internal-IP enrichment are now driving real volume. Beyond the core ingest pipeline, analysts are actively using Blink for ad hoc investigation: 337 internal-IP enrichment checks, 149 sign-in-by-IP queries, 124 sign-in-by-user queries, and 86 custom KQL queries in the last 12 months. This shows adoption expanding from the automated pipeline into day-to-day analyst workflows.
###
Gaps & Opportunities
- Most playbooks still show zero executions, though newer investigation playbooks are gaining traction. Of 77 playbooks, the majority remain unused, but the recently added Log Analytics investigation playbooks and the internal-IP enrichment subflow are seeing meaningful adoption. The bulk of the enrichment router's downstream subflows, endpoint containment, phishing response, and identity threat containment playbooks are still built but not yet running at scale. Driving adoption of these — particularly the enrichment router's TI lookups and the Phishing/Malware response subflows — remains the largest near-term value lever.
- Response subflows not yet activated. The Phishing and Malware response subflows exist and are connected to the main response router, but show 0 executions. Enabling these paths would immediately extend automation coverage beyond triage into remediation.
- No scheduled/recurring automations visible. No scheduled jobs (e.g., daily risky user sweeps, stale case closure) are running. The "Utility - Close Stale Cases" and "Risky Users Workflow" playbooks are built for this purpose but inactive.
- Single Defender XDR ingest source. All 424 alert ingestion events flow from one source (Microsoft Defender XDR, AAD Identity Protection category). Expanding ingest connectors to CrowdStrike, Okta, or additional Defender alert categories would broaden detection coverage without requiring new response logic.
Integration Ecosystem
| Integration | Purpose |
|---|---|
| Microsoft Defender XDR | Alert ingestion (primary SOC feed) |
| Microsoft Entra ID / Active Directory | User enrichment, risky user detection, agent ability, account containment (disable/enable) |
| Azure Log Analytics | SIEM log queries, sign-in investigation |
| Microsoft Graph | Conditional Access / Named Locations management |
| Microsoft Outlook | Phishing email retrieval and header analysis |
| Microsoft Teams | Analyst interaction via Agentic SOC |
| CrowdStrike Falcon | Hash/agent enrichment, endpoint isolation, RTR |
| Okta | User enrichment, activity log search |
| VirusTotal | IP, URL, and hash threat intelligence |
| AbuseIPDB | IP reputation scoring |
| URLScan | URL scanning and screenshot capture |
| Intezer | Threat incident intelligence |
| Google Workspace | User profile enrichment |
| GitHub | Developer identity enrichment |
| Slack | Email-to-user identity resolution |
| Blink Case Management | Case/alert/observable lifecycle management |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 1 active | 3 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Sherlock | SOC | 3 | 0 | 128,163 |
| 2 | Agent Blink | SOC | 0 | 0 | 0 |
| 3 | Agent Blink | yaron.king@boi.org.il | 0 | 0 | 0 |
| 4 | New Agent | SOC | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| SOC | 3 |
| yaron.king@boi.org.il | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 11 use cases | 17,460 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts ingested & normalized from Microsoft Defender XDR | 424 | EXAMPLE Ingest - Microsoft Defender XDR |
| Security alerts processed end-to-end through the automated SOC pipeline | 15 | Process Alert |
| Threat incidents retrieved and analyzed from Intezer | 2 | Intezer - Get Incidents |
| Internal IP addresses automatically checked against BOI network ranges during enrichment | 337 | Enrichment - Check BOI Internal IP |
| Sign-in activity investigations run by IP address via Azure Log Analytics | 149 | Response - Sign In Activity By IP Query |
| Sign-in activity investigations run by user via Azure Log Analytics | 124 | Response - Sign in Activity by User - Sentinel Query |
| Custom KQL queries executed on demand against Azure Log Analytics | 86 | Run Log Analytics KQL query |
Use Case Summary
| Use Case | Category | Subcategory | Playbooks | Executions (12 mo) |
|---|---|---|---|---|
| SOC Alert Pipeline & Automated Triage | SOC | Case mgmt & SOAR | 11 | 461 |
| Observable Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 27 | 349 |
| Case Management Utilities & Maintenance | SOC | Case mgmt & SOAR | 7 | 0 |
| Endpoint Containment & Malware Response | SOC | EDR containment & response | 4 | 0 |
| Phishing Detection & Response | SOC | Phishing detection & response | 1 | 0 |
| Identity Threat Detection | SOC | Identity threat response | 4 | 3 |
| Agentic SOC Capabilities | SOC | Agentic SOC | 3 | 0 |
| Conditional Access & Network Blocklist Mgmt | Cloud Security | Cloud access & SaaS policy mgmt | 3 | 0 |
| SIEM, Log Analytics & Threat Intelligence | SOC | SIEM & log pipeline monitoring, Threat intel ingest & curation | 6 | 361 |
| User Identity Information Lookups | IAM | Identity sync & directory mgmt | 6 | 6 |
| End-of-Life & Vulnerability Tracking | Vulnerability Mgmt | CVE lookup & remediation | 1 | 0 |
| Admin, Demo & Training | Other | SaaS / IT administration | 4 | 0 |
| Total | 77 | 1180 |
Use Cases
1. SOC Alert Pipeline & Automated Triage
Category: SOC | Subcategory: Case mgmt & SOAR
Description: End-to-end, event-driven alert processing pipeline. Alerts are ingested from Microsoft Defender XDR, normalized into the case management layer, deduplicated, enriched, and routed to the appropriate response playbook — all without analyst intervention.
Business problem solved: Eliminates manual alert triage triage by automating the full lifecycle from raw event to case creation and response routing, reducing mean time to respond and preventing alert fatigue.
Integrations: Microsoft Defender XDR, Blink Case Management, Azure Log Analytics
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| EXAMPLE Ingest - Microsoft Defender XDR | Event trigger | 424 | SOC › Case mgmt & SOAR, SIEM & log pipeline monitoring |
| Process Alert | Event trigger | 15 | SOC › Case mgmt & SOAR |
| Subflow - Response - Main Router | Subflow | 11 | SOC › Case mgmt & SOAR |
| Subflow - Missing Alert Template Notification | Subflow | 4 | SOC › Case mgmt & SOAR |
| Recovery - Handle Unprocessed Alerts | Recovery | 0 | SOC › Case mgmt & SOAR |
| Simulate Multiple Alerts from Different Sources | Test | 0 | SOC › Case mgmt & SOAR |
| Simulate Crowdstrike Alert | Test | 0 | SOC › Case mgmt & SOAR |
| Error Handling - Send Error Notification Email | Subflow | 0 | SOC › Case mgmt & SOAR |
| USE WITH CARE - Reset Case Management Environment | Admin | 0 | SOC › Case mgmt & SOAR |
| Close Sentinel Incident | On-demand | 6 | SOC › Case mgmt & SOAR |
| Closing BlinkOps + Sentinel Incident | Event trigger | 1 | SOC › Case mgmt & SOAR |
2. Observable Enrichment & IOC Lookup
Category: SOC | Subcategory: Alert enrichment / IOC lookup
Description: A modular enrichment library that automatically queries multiple threat intelligence and identity sources for every observable (IP, hash, URL, email, username, agent ID) extracted from an alert. A central router dispatches to the correct enrichment subflow based on observable type and writes the verdict back to the case.
Business problem solved: Eliminates manual copy-paste lookups across 10+ tools per alert. Analysts receive pre-enriched cases with verdicts from VirusTotal, AbuseIPDB, CrowdStrike, Okta, Entra ID, URLScan, Whois, and more.
Integrations: VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Microsoft Entra ID (Active Directory), Google Workspace, GitHub, Slack, Blink Case Management
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Subflow - Enrich Observables - Main Router | Subflow | 12 | SOC › Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Utility - Update Enrichment | Utility | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - IP - VT | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - URL - VT | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Hash - VT | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | On-demand | 0 | SOC › Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | On-demand | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Username - Github | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Analyze URL with URLScan | On-demand | 0 | SOC › Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | On-demand | 0 | SOC › Alert enrichment / IOC lookup |
| Run Dig Command | Utility | 0 | SOC › Alert enrichment / IOC lookup |
| Recovery - Enrich Non-Enriched Observables | Recovery | 0 | SOC › Alert enrichment / IOC lookup |
| Table Action - Validate Observables Extraction Template | Utility | 0 | SOC › Alert enrichment / IOC lookup |
| Subflow - Post Enrichment Card | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| CM Ability - User Agent Parser | Subflow | 0 | SOC › Alert enrichment / IOC lookup |
| Enrichment - Check BOI Internal IP | Subflow | 337 | SOC › Alert enrichment / IOC lookup |
3. Case Management Utilities & Maintenance
Category: SOC | Subcategory: Case mgmt & SOAR
Description: A set of utility playbooks that manage the structural integrity of the case management data model — linking and unlinking observables to alerts, finding similar cases based on shared observables, and closing stale cases automatically.
Business problem solved: Keeps the case management database accurate and usable over time, preventing case clutter and ensuring observable relationships are correctly maintained for analyst review and similarity detection.
Integrations: Blink Case Management
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Utility - List Observable Alert Relations | Utility | 0 | SOC › Case mgmt & SOAR |
| Utility - List Alert Observable Relations | Utility | 0 | SOC › Case mgmt & SOAR |
| Utility - Find Similar Cases Based on Observables | Utility | 0 | SOC › Case mgmt & SOAR |
| Utility - Set Or Update Observable Relation | Utility | 0 | SOC › Case mgmt & SOAR |
| Utility - Delete Observable Relation | Utility | 0 | SOC › Case mgmt & SOAR |
| Utility - Close Stale Cases | Utility | 0 | SOC › Case mgmt & SOAR |
| Utility - List Observable Alert Relations | Utility | 0 | SOC › Case mgmt & SOAR |
4. Endpoint Containment & Malware Response
Category: SOC | Subcategory: EDR containment & response
Description: Automated endpoint response capabilities using CrowdStrike — including host isolation (quarantine/lift), remote command execution via Real Time Response (RTR) on single or batched hosts, and a malware response workflow that evaluates remediation status and drives next steps.
Business problem solved: Cuts containment time from hours to seconds by enabling automated or one-click endpoint isolation and remote remediation, removing the need for analyst access to the CrowdStrike console for routine response actions.
Integrations: CrowdStrike Falcon (EDR, RTR), Blink Case Management
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | On-demand | 0 | SOC › EDR containment & response |
| CrowdStrike RTR to a Single Host | On-demand | 0 | SOC › EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | On-demand | 0 | SOC › EDR containment & response |
| Response Subflow - Malware | Subflow | 0 | SOC › EDR containment & response |
5. Phishing Detection & Response
Category: SOC | Subcategory: Phishing detection & response
Description: Automated phishing investigation that retrieves the original email, parses headers, detects KnowBe4 simulation markers (X-PHISHTEST), and branches response actions accordingly — distinguishing real phishing attempts from security awareness training exercises.
Business problem solved: Prevents analyst time being wasted on simulated phishing campaigns while ensuring real phishing emails receive immediate, structured investigation and response.
Integrations: Microsoft Outlook
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Response Subflow - Phishing | Subflow | 0 | SOC › Phishing detection & response |
6. Identity Threat Detection
Category: SOC | Subcategory: Identity threat response
Description: Monitors for compromised or high-risk user identities by querying Microsoft Entra ID's risky users list and searching Okta activity logs for suspicious behavior patterns. Drives targeted investigation and response for identity-based threats.
Business problem solved: Provides automated detection of account compromise and anomalous identity activity across two identity providers, enabling timely response before lateral movement occurs.
Integrations: Microsoft Entra ID (Active Directory), Okta
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Risky Users Workflow | On-demand | 0 | SOC › Identity threat response |
| Okta Search for User Activity | On-demand | 0 | SOC › Identity threat response |
| Disable/Enable Entra Account | On-demand | 3 | SOC › Identity threat response |
| Disable/Enable Account and Notify | On-demand | 0 | SOC › Identity threat response |
7. Agentic SOC Capabilities
Category: SOC | Subcategory: Agentic SOC
Description: A suite of reusable agent-callable abilities that expose SOC tools to an AI agent layer — enabling a Blink AI agent to look up a user's department, send interactive questions to analysts via Microsoft Teams, and execute arbitrary Log Analytics queries. These abilities are the building blocks of a conversational, AI-driven SOC.
Business problem solved: Enables AI-driven autonomous investigation by providing a structured, callable interface to security data sources and analyst communication channels — moving toward a SOC model where the agent drives triage and human escalation is the exception.
Integrations: Microsoft Entra ID (Active Directory), Microsoft Teams, Azure Log Analytics
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Agent Ability - Get User Department | Agent ability | 0 | SOC › Agentic SOC |
| Agent Ability - Ask a question via Teams | Agent ability | 0 | SOC › Agentic SOC |
| Agent Ability - Log Analytics Query | Agent ability | 0 | SOC › Agentic SOC |
8. Conditional Access & Network Blocklist Management
Category: Cloud Security | Subcategory: Cloud access & SaaS policy mgmt
Description: Automates the management of Microsoft Entra Conditional Access Named Locations used as IP blocklists. Playbooks sync the current blocklist state, validate whether a CIDR is already present, and add new ranges programmatically — supporting both IPv4 and IPv6.
Business problem solved: Removes the manual, error-prone process of updating Conditional Access Named Locations when new malicious IP ranges need to be blocked. Ensures the blocklist is always current and consistent across environments.
Integrations: Microsoft Graph (Conditional Access Named Locations), Blink Tables
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Add CIDR to Blocklist | On-demand | 0 | Cloud Security › Cloud access & SaaS policy mgmt |
| Add CIDR to Named Location | On-demand | 0 | Cloud Security › Cloud access & SaaS policy mgmt |
| Get and Sync Named Locations Block List | Subflow | 0 | Cloud Security › Cloud access & SaaS policy mgmt |
9. SIEM, Log Analytics & Threat Intelligence
Category: SOC | Subcategory: SIEM & log pipeline monitoring, Threat intel ingest & curation
Description: Queries Azure Log Analytics for sign-in events and executes custom KQL queries on demand, providing analysts with flexible log investigation capabilities. Also integrates with Intezer to retrieve threat intelligence incidents for additional context.
Business problem solved: Gives the SOC on-demand access to log data and external threat intelligence without requiring console access, enabling faster investigation and correlation across data sources.
Integrations: Azure Log Analytics, Intezer
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Intezer - Get Incidents | On-demand | 2 | SOC › Threat intel ingest & curation |
| Query SignIn Logs | On-demand | 0 | SOC › SIEM & log pipeline monitoring |
| Run Log Analytics KQL query | On-demand | 86 | SOC › SIEM & log pipeline monitoring |
| Response - Sign In Activity By IP Query | On-demand | 149 | SOC › SIEM & log pipeline monitoring |
| Response - Sign in Activity by User - Sentinel Query | On-demand | 124 | SOC › SIEM & log pipeline monitoring |
| Response - Keep Alive Query copy | On-demand | 0 | SOC › SIEM & log pipeline monitoring |
10. User Identity Information Lookups
Category: IAM | Subcategory: Identity sync & directory mgmt
Description: Reusable on-demand playbooks to retrieve full user profile details from each identity provider in the environment. Designed for analyst use and as building blocks callable by enrichment and response workflows.
Business problem solved: Provides a single, standardized interface for user identity lookups across five platforms, eliminating the need for analysts to context-switch between consoles during investigations.
Integrations: Microsoft Entra ID (Active Directory), Okta, Google Workspace, GitHub, Slack
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Get User Information Using Microsoft Entra ID | On-demand | 0 | IAM › Identity sync & directory mgmt |
| Get User Information Using Okta | On-demand | 0 | IAM › Identity sync & directory mgmt |
| Get User Information Using Google Workspace | On-demand | 0 | IAM › Identity sync & directory mgmt |
| Get User Information Using Github | On-demand | 0 | IAM › Identity sync & directory mgmt |
| Get User Information on Email Address Using Slack | On-demand | 0 | IAM › Identity sync & directory mgmt |
| Entra ID - Run Query | On-demand | 6 | IAM › Identity sync & directory mgmt |
11. End-of-Life & Vulnerability Tracking
Category: Vulnerability Mgmt | Subcategory: CVE lookup & remediation
Description: Looks up the end-of-life date for any named software product and version, enabling the SOC and vulnerability management teams to identify unsupported software in the environment.
Business problem solved: Automates EOL tracking, which is often done manually via spreadsheets, providing a consistent and repeatable way to flag out-of-support software during incident investigation or asset reviews.
Integrations: endoflife.date API (via HTTP)
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Get End of Life Date for a Product | On-demand | 0 | Vulnerability Mgmt › CVE lookup & remediation |
12. Admin, Demo & Training
Category: Other | Subcategory: SaaS / IT administration
Description: Placeholder, demonstration, and onboarding playbooks used during environment setup and POC activities. Not part of production operations.
| Playbook | Type | Executions | Taxonomy |
|---|---|---|---|
| Getting Started - Hello World | Training | 0 | Other › SaaS / IT administration |
| Demo Shadow IT | Demo | 0 | Other › SaaS / IT administration |
| New Workflow 1 | Placeholder | 0 | Other › SaaS / IT administration |
Key Observations
Strengths
- End-to-end SOC automation pipeline is live. The alert lifecycle from Defender XDR ingest → observable extraction → enrichment routing → response dispatch is fully wired and has executed 450+ times in 12 months. This is a production-grade SOAR platform, not a pilot.
- Breadth of enrichment coverage. 10+ threat intelligence and identity sources are integrated into a single routing layer (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Entra ID, Google Workspace, GitHub, Slack, Whois). When the pipeline is fully active, analysts receive pre-enriched cases without touching any external console.
- Agentic SOC foundation in place. Three agent abilities (Teams interaction, user department lookup, Log Analytics queries) indicate BOI is building toward AI-driven autonomous triage — a significant forward-looking investment in the Blink platform.
- Microsoft-native, CrowdStrike-reinforced. The environment is heavily Microsoft-centric (Entra ID, Defender XDR, Azure Log Analytics, Outlook, Teams, Graph), supplemented by CrowdStrike as the EDR. Blink bridges these two ecosystems cleanly across enrichment and response workflows.
- Log Analytics investigation and internal-IP enrichment are now driving real volume. Beyond the core ingest pipeline, analysts are actively using Blink for ad hoc investigation: 337 internal-IP enrichment checks, 149 sign-in-by-IP queries, 124 sign-in-by-user queries, and 86 custom KQL queries in the last 12 months. This shows adoption expanding from the automated pipeline into day-to-day analyst workflows.
Gaps & Opportunities
- Most playbooks still show zero executions, though newer investigation playbooks are gaining traction. Of 77 playbooks, the majority remain unused, but the recently added Log Analytics investigation playbooks and the internal-IP enrichment subflow are seeing meaningful adoption. The bulk of the enrichment router's downstream subflows, endpoint containment, phishing response, and identity threat containment playbooks are still built but not yet running at scale. Driving adoption of these — particularly the enrichment router's TI lookups and the Phishing/Malware response subflows — remains the largest near-term value lever.
- Response subflows not yet activated. The Phishing and Malware response subflows exist and are connected to the main response router, but show 0 executions. Enabling these paths would immediately extend automation coverage beyond triage into remediation.
- No scheduled/recurring automations visible. No scheduled jobs (e.g., daily risky user sweeps, stale case closure) are running. The "Utility - Close Stale Cases" and "Risky Users Workflow" playbooks are built for this purpose but inactive.
- Single Defender XDR ingest source. All 424 alert ingestion events flow from one source (Microsoft Defender XDR, AAD Identity Protection category). Expanding ingest connectors to CrowdStrike, Okta, or additional Defender alert categories would broaden detection coverage without requiring new response logic.
Integration Ecosystem
| Integration | Purpose |
|---|---|
| Microsoft Defender XDR | Alert ingestion (primary SOC feed) |
| Microsoft Entra ID / Active Directory | User enrichment, risky user detection, agent ability, account containment (disable/enable) |
| Azure Log Analytics | SIEM log queries, sign-in investigation |
| Microsoft Graph | Conditional Access / Named Locations management |
| Microsoft Outlook | Phishing email retrieval and header analysis |
| Microsoft Teams | Analyst interaction via Agentic SOC |
| CrowdStrike Falcon | Hash/agent enrichment, endpoint isolation, RTR |
| Okta | User enrichment, activity log search |
| VirusTotal | IP, URL, and hash threat intelligence |
| AbuseIPDB | IP reputation scoring |
| URLScan | URL scanning and screenshot capture |
| Intezer | Threat incident intelligence |
| Google Workspace | User profile enrichment |
| GitHub | Developer identity enrichment |
| Slack | Email-to-user identity resolution |
| Blink Case Management | Case/alert/observable lifecycle management |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.