Blink Security Automation — Confidential

bcbs-mn — Customer Success Report

Generated 2026-09-10 | bcbs-mn-value-report.md
2026-09-10Report Date
344Total Playbooks
85Unique Workflows (12m)
5,152,416Actions Automated (12m)
$1,325,210Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

344
Total playbooks built
all non-deleted workflows
124
Active playbooks
currently enabled
85
Unique workflows executed (12m)
distinct workflows that ran
5,152,416
Actions automated (12m)
completed action steps
28,624.5h
Hours saved (12m)
@ 20s per action
$1,325,210
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
6,428
Total cases managed
6,181 opened in last 12m
95d 8h
MTTR — mean time to resolve
closed cases, last 12m
5
Active AI agents
of 10 total
1,526
AI agent tasks executed (12m)
42 in last 30d
In the last 12 months, Blink automated: - 78,197 security alerts processed end-to-end through the SOAR pipeline — from ingestion through enrichment, deduplication, case creation, and automated response - 482 unprocessed alert backlog cleanup cycles executed automatically, preventing alert queue buildup - 90 Expel MDR closed alerts automatically synchronized back to Microsoft Defender XDR - 78 Tenable vulnerability scan datasets ingested and converted into actionable SOAR alerts (VM + WAS combined) - 24 GitLab AppSec pipeline events processed automatically (17 failing-scan publications, 7 overview dashboard refreshes) - 75 security case lifecycle updates automated — 42 orchestrated, 33 closed, 21 reopened - 19 threat hunting sessions executed against Sumo Logic SIEM data, covering IP, domain, and file hash IOCs - 2 CSPM webhook alerts automatically triaged for stale IAM key hygiene (Prisma Cloud) - 6 Microsoft Defender for Endpoint configuration compliance reports generated and distributed weekly - 10 software license usage reports generated automatically (Adobe Acrobat Pro, Edifecs SpecBuilder) - 14 endpoint security actions executed via self-service (machine lockouts, BitLocker PIN resets, device isolation)

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SOC Case Management & SOAR Platform
  • 78,197Security alerts auto-processed through SOAR pipeline
  • 482Unprocessed alert backlog cleanup cycles executed
  • 42Security case lifecycle updates orchestrated automatically
98.7%
12
9 active
Automated Alert Enrichment & Observable Intelligence0 executions
0.0%
23
18 active
On-Demand SOC Investigation Toolkit0 executions
0.0%
14
12 active
EDR Containment & Response
  • 1Devices isolated via Microsoft Defender for Endpoint
0.0%
4
4 active
Expel MDR → Microsoft Defender XDR Alert Sync
  • 90Expel MDR closed alerts synced to Microsoft Defender XDR
0.1%
1
1 active
Threat Hunting Platform
  • 10Automated threat hunts executed against SIEM data
  • 9Self-service threat hunting sessions initiated
0.1%
16
16 active
Vulnerability Management — Tenable VM & WAS
  • 39Tenable VM vulnerability scan batches ingested
  • 39Tenable WAS vulnerability scan batches ingested
  • 17GitLab project failing-scan events published
1.1%
16
16 active
DLP & CSPM Alert Integration
  • 2CSPM webhook alerts triaged for stale IAM keys
0.0%
6
4 active
MDE Configuration Compliance Reporting
  • 6MDE configuration compliance reports generated
0.0%
2
2 active
Asset Intelligence via Device420 executions
0.0%
5
5 active
Endpoint & Identity Self-Service
  • 9Endpoint machine lockouts executed
  • 3HR travel policy violations/exceptions processed
  • 2BitLocker PIN resets performed
0.0%
2
2 active
Cloud SaaS App Discovery (MDCA)0 executions
0.0%
1
1 active
Workflow Autodocumentation Platform0 executions
0.0%
8
8 active
GitLab DevOps Automation0 executions
0.0%
4
4 active
Software License & Usage Reporting
  • 5Adobe Acrobat Pro usage reports generated
  • 5Edifecs SpecBuilder usage reports generated
0.0%
2
2 active
Total133,923 executions100%
116
104 active

Use Case Growth Over Time

247 unique playbooks  |  15 operational use cases  |  133,932 total executions (12m)  |  2024-09 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Automated Alert Enrichment & Observable Intelligence
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Slack
SOC Case Management & SOAR Platform
Microsoft Outlook Email
EDR Containment & Response
CrowdStrike Microsoft Defender For Endpoints
On-Demand SOC Investigation Toolkit
Slack Okta CrowdStrike VirusTotal URLScan Google Workspace GitHub Microsoft Entra ID String Utilities Extraction Utilities Microsoft Graph Email
GitLab DevOps Automation
GitLab AWS Jira Slack Email CyberArk Dashboards Prisma Cloud CSPM
DLP & CSPM Alert Integration
Microsoft Defender For Endpoints Email GitLab Prisma Cloud CSPM Cyera AWS CyberArk Tenable TeamDynamix Microsoft Outlook Microsoft OneNote
Vulnerability Management — Tenable VM & WAS
Tenable Dashboards
Endpoint & Identity Self-Service
Web Form Sumo Logic Microsoft Outlook Microsoft Graph
Threat Hunting Platform
Sumo Logic Web Form Agents Microsoft Outlook URLScan VirusTotal
Asset Intelligence via Device42
Device 42
Expel MDR → Microsoft Defender XDR Alert Sync
Microsoft Defender For Endpoints Microsoft Outlook
MDE Configuration Compliance Reporting
Microsoft Graph Microsoft Outlook
Workflow Autodocumentation Platform
Agents Web Form Microsoft Outlook
Cloud SaaS App Discovery (MDCA)
Microsoft Graph
Software License & Usage Reporting
Microsoft Graph Email

04Key Observations

✓  Strengths

Strengths

1. High-volume, production-grade SOAR at scale

The Process Alert workflow at 78,197 executions — running every minute, polling for new case management records — demonstrates a fully operationalized SOAR deployment. The supporting scheduled cleanup (482 runs) and recovery flows (16 runs) show mature pipeline hygiene. This is not a pilot; it's a running production SOC platform.

2. Sophisticated vulnerability management pipeline

The Tenable VM and WAS ingestion infrastructure — with chunked download subflows, separate alert creation and update paths, and a dedicated chunk recovery scheduler — handles enterprise-scale vulnerability data robustly. VM_Alert_Creation_Subflow ran 291 times and VM_Alert_Update 233 times, indicating continuous vulnerability lifecycle tracking, not just one-time ingestion.

3. Agentic threat hunting capability

The threat hunting platform is a standout capability. Using Blink AI agents (Xmus Jaxon Flaxon-Waxon) to search and reason over Sumo Logic SIEM data, with deduplicated IOC tracking in a custom table and multiple intake paths (webform, self-service API, URL analysis), this is a production-ready agentic SOC function — not a demo.

4. Broad integration ecosystem

20+ integrations across EDR (CrowdStrike, Defender), identity (Okta, Entra ID, Google Workspace, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), vulnerability (Tenable, Cyera, Prisma Cloud), SIEM (Sumo Logic), CMDB (Device42), and cloud (AWS, Microsoft Graph, MDCA) — covering the full security toolchain.

5. Self-service security operations

Machine lockout, BitLocker PIN reset, and HR travel policy exception workflows exposed via Web Forms represent a mature self-service security model that reduces analyst ticket load while maintaining governance and auditability.

6. GitLab AppSec scanning pipeline now active

Publish Failing Scans (17 executions) and Populate Overview Dashboard (7 executions) show the GitLab project security scanning dashboard — sharing a workspace with the Tenable/AppSec vulnerability pipeline — is now live in production, surfacing failing project scans and refreshing an overview dashboard automatically rather than sitting idle.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

1. Enrichment layer not executing in production

All 14 automated enrichment workflows (Enrich - Hash - VT, Enrich - IP - IPDB, Enrich - Username or Email - Okta, etc.) show 0 executions. The enrichment infrastructure is fully built, but the Process Alert flow may not be routing through it or enrichment is only triggered under specific conditions. Activating enrichment on the live alert stream would add context to all 78,000+ annual alerts.

2. DLP pipeline still inactive; CSPM shows early signs of life

Cyera (3 workflows) remains fully inactive at 0 executions. Prisma Cloud CSPM, previously dormant, now shows initial activity — a new webhook-triggered workflow checking for stale IAM keys ran twice — but the core Prisma Ingestion and CVE enrichment playbooks are still at 0 executions. Activating Cyera and completing the full Prisma ingestion pipeline would extend the SOAR platform's coverage to data security and cloud posture risk beyond this initial IAM key check.

3. Device42 CMDB enrichment not yet running

All 5 Device42 workflows show 0 executions. The cross-reference infrastructure (on-prem + cloud runners, chunked processing) is complete. Running Device42 Ingestion and Enrichment would immediately add asset context to the existing Tenable vulnerability alert inventory.

4. EDR response actions are read-only in practice

CrowdStrike RTR workflows (single host, batch) and endpoint quarantine management show 0 executions. Defender Device Isolation ran once. The containment tooling exists but is not integrated into automated response flows — response may still be manual. Wiring these into the Response Subflow - Malware path would enable true automated containment.

5. Threat hunting pipeline does not complete end-to-end

Hunt Enrichment & Analysis (0 executions) and Hunt Completion - Case Creation (0 executions) show the hunting pipeline is not progressing beyond the search phase. IOC searches are running (IP: 11, FQDN: 6, Filehash: 1) but either findings are not hitting the enrichment trigger condition or the enrichment step is failing silently. Completing the pipeline would convert hunt results into SOAR cases automatically.

6. MDCA AI App Discovery not yet active

MDCA - AI App Refresh (0 executions) represents an unactivated shadow IT / AI governance capability. As AI application governance becomes a compliance priority in healthcare, activating this workflow would provide a governed inventory for AI risk review.

Integration Ecosystem

Category Integrations
EDR & Endpoint CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps
Identity Okta, Microsoft Entra ID, Microsoft Graph, Google Workspace, GitHub, Slack
Threat Intelligence VirusTotal, AbuseIPDB, URLScan
SIEM Sumo Logic
Vulnerability Tenable VM, Tenable WAS, Cyera, Prisma Cloud CSPM
CMDB / Asset Device42
Cloud Infrastructure AWS IAM
MDR Expel
Email Microsoft Outlook
DevOps GitLab
SaaS Applications Adobe Acrobat Pro, Edifecs SpecBuilder
Blink Native Case Management, AI Agents, Web Forms, Tables, Blink API
Appendices
A Case Management 6,181 cases (12m) | MTTR 95d 8h

Case Management

Total Cases (all-time)
6,428
6,181 opened in last 12m
Cases Opened (30d)
270
32 closed in last 30d
Cases Closed (12m)
1,011
of 6,181 opened
MTTR
95d 8h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Vulnerability Management 6,174 6,174 1,004 95d 23h
BCBSMN Sandbox 247 0 0 N/A
Threat Detection & Response - Dev 7 7 7 2d 17h
B AI Agents 5 active | 1,526 tasks (12m)

AI Agents

Active Agents
5
of 10 total
Tasks Executed (12m)
1,526
42 in last 30d
Data Usage (12m)
629,424,029
1,819,363 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 TrAIvis Threat Detection & Response - Dev 643 10 570,808,039
2 Xmus Jaxon Flaxon-Waxon Threat Detection & Response - Dev 301 18 21,041,641
3 Hingle McCringleberry Threat Detection & Response - Dev 273 14 12,484,940
4 Dapper Dan Threat Detection & Response - Dev 210 0 12,468,929
5 Markdown Man Threat Detection & Response - Dev 99 0 12,620,480
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Threat Detection & Response - Dev1,526
BCBSMN Sandbox0
Vulnerability Management0
Application Security - Dev0
C Self-Service & Webforms 0 app runs | 12 form submissions

Self-Service Applications

Apps
26
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 CM Demo 00
2 SecDevOps 00
3 Prisma 00
4 VM Dashboard 00
5 Tenable_vm_ingestion 00

Webforms

Forms
6
active webforms
Total Submissions
12
all time
Completed
12
fully submitted
Submissions (30d)
8
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Machine Lockout 1212
2 Automated Threat Hunt 00
3 Generate Blink Workflow Documentation 00
4 Generate Blink Workflow Documentation 00
5 Automated Threat Hunting 00
D Full Use Case Analysis 15 use cases | 133,932 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-processed through SOAR pipeline 78,197 Process Alert
Unprocessed alert backlog cleanup cycles executed 482 Timed Unprocessed Alerts Cleanup
Expel MDR closed alerts synced to Microsoft Defender XDR 90 Alert Mgmt - Expel to Defender XDR
Security case lifecycle updates orchestrated automatically 42 Case Update Orchestrator
Tenable VM vulnerability scan batches ingested 39 Tenable VM Alert Ingestion
Tenable WAS vulnerability scan batches ingested 39 Tenable WAS Alert Ingestion
Security cases automatically closed 33 Case Close
Security cases automatically reopened 21 Case Reopen
GitLab project failing-scan events published 17 Publish Failing Scans
Automated threat hunts executed against SIEM data 10 Hunt Execution
Self-service threat hunting sessions initiated 9 Self-Service - Threat Hunting
Endpoint machine lockouts executed 9 Machine Lockout
Application vulnerability datasets published to SOAR 7 Publish Application Vulnerabilities
GitLab overview dashboard refreshes 7 Populate Overview Dashboard
MDE configuration compliance reports generated 6 MDE Configuration Issue Collection
Adobe Acrobat Pro usage reports generated 5 Adobe Pro Usage Report
Edifecs SpecBuilder usage reports generated 5 Edifecs SpecBuilder Usage
HR travel policy violations/exceptions processed 3 Self-Service - HR Travel Policy Violation or Exception
BitLocker PIN resets performed 2 Run BitLocker PIN Reset
CSPM webhook alerts triaged for stale IAM keys 2 New Workflow 1
Devices isolated via Microsoft Defender for Endpoint 1 Defender Device Isolation
In the last 12 months, Blink automated: - 78,197 security alerts processed end-to-end through the SOAR pipeline — from ingestion through enrichment, deduplication, case creation, and automated response - 482 unprocessed alert backlog cleanup cycles executed automatically, preventing alert queue buildup - 90 Expel MDR closed alerts automatically synchronized back to Microsoft Defender XDR - 78 Tenable vulnerability scan datasets ingested and converted into actionable SOAR alerts (VM + WAS combined) - 24 GitLab AppSec pipeline events processed automatically (17 failing-scan publications, 7 overview dashboard refreshes) - 75 security case lifecycle updates automated — 42 orchestrated, 33 closed, 21 reopened - 19 threat hunting sessions executed against Sumo Logic SIEM data, covering IP, domain, and file hash IOCs - 2 CSPM webhook alerts automatically triaged for stale IAM key hygiene (Prisma Cloud) - 6 Microsoft Defender for Endpoint configuration compliance reports generated and distributed weekly - 10 software license usage reports generated automatically (Adobe Acrobat Pro, Edifecs SpecBuilder) - 14 endpoint security actions executed via self-service (machine lockouts, BitLocker PIN resets, device isolation)

Use Case Summary

# Use Case Category Subcategory Playbooks
1 SOC Case Management & SOAR Platform SOC Case mgmt & SOAR 12
2 Automated Alert Enrichment & Observable Intelligence SOC Alert enrichment / IOC lookup 23
3 On-Demand SOC Investigation Toolkit SOC Alert enrichment / IOC lookup 14
4 EDR Containment & Response SOC EDR containment & response 4
5 Expel MDR → Microsoft Defender XDR Alert Sync SOC Case mgmt & SOAR 1
6 Threat Hunting Platform SOC / Vulnerability Mgmt Threat intel ingest & curation, Threat hunting & detection 16
7 Vulnerability Management — Tenable VM & WAS Vulnerability Mgmt Vuln scanning ingest & report, Vuln scan lifecycle automation 16
8 DLP & CSPM Alert Integration GRC / Cloud Security DLP triage & exposure resp, CSPM ingest & triage 6
9 MDE Configuration Compliance Reporting GRC / Cloud Security Security metrics & reporting, Config audit & remediation 2
10 Asset Intelligence via Device42 Vulnerability Mgmt / Cloud Security Vuln lifecycle prioritize & ticket, Cloud asset coverage & inventory 5
11 Endpoint & Identity Self-Service Other Endpoint hygiene & MDM ops 4
12 Cloud SaaS App Discovery (MDCA) Cloud Security Cloud access & SaaS policy mgmt 1
13 Workflow Autodocumentation Platform Other SaaS / IT administration 8
14 GitLab DevOps Automation Other DevOps & release automation 4
15 Software License & Usage Reporting Other SaaS / IT administration 2
Total 118

Use Cases

1. SOC Case Management & SOAR Platform

Description: A fully automated security operations platform built on Blink's native case management system that ingests, deduplicates, enriches, and triages security alerts — automatically creating, routing, updating, and closing cases. Dedicated response subflows handle phishing and malware scenarios with distinct playbook logic.

Business problem solved: Eliminates manual triage and case management overhead at scale. At 78,000+ alert events per year, the platform ensures no alert is missed, response logic is consistently applied, and unprocessed alerts are automatically recovered.

Integrations: Blink Case Management, Microsoft Outlook, CrowdStrike, Okta

Playbook Executions (12mo) Category Subcategory
Process Alert 78,197 SOC Case mgmt & SOAR
Timed Unprocessed Alerts Cleanup 482 SOC Case mgmt & SOAR
Case Update Orchestrator 42 SOC Case mgmt & SOAR
Case Close 33 SOC Case mgmt & SOAR
Case Reopen 21 SOC Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts 16 SOC Case mgmt & SOAR
Response Subflow - Phishing 0 SOC Phishing detection & response
Response Subflow - Malware 0 SOC Case mgmt & SOAR
Subflow - Response - Main Router 0 SOC Case mgmt & SOAR
Subflow - Missing Alert Template Notification 0 SOC Case mgmt & SOAR
Table Action - Validate Observables Extraction Template 0 SOC Case mgmt & SOAR
Error Handling - Send Error Notification Email 0 SOC Case mgmt & SOAR

2. Automated Alert Enrichment & Observable Intelligence

Description: A comprehensive multi-source enrichment layer that automatically enriches observables (IPs, hashes, URLs, usernames, email addresses, domains) extracted from incoming alerts, using 9+ threat intelligence and identity integrations. Includes full observable lifecycle management — linking, updating, deduplicating, and recovering unenriched records.

Business problem solved: Ensures every observable attached to a security alert carries full context before analysts review it, reducing investigation time and enabling automated triage decisions downstream.

Integrations: CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Slack, GitHub, Google Workspace, Microsoft Entra ID, Whois, Blink Case Management

Playbook Executions (12mo) Category Subcategory
Enrich - Agent ID - Crowdstrike 0 SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - VT 0 SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta 0 SOC Alert enrichment / IOC lookup
Enrich - IP - VT 0 SOC Alert enrichment / IOC lookup
Enrich - URL - VT 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike 0 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 0 SOC Alert enrichment / IOC lookup
Enrich - Username - Github 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID 0 SOC Alert enrichment / IOC lookup
Enrich - Email Address - Slack 0 SOC Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router 0 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 0 SOC Alert enrichment / IOC lookup
Recovery - Enrich Non-Enriched Observables 0 SOC Alert enrichment / IOC lookup
Utility - Update Enrichment 0 SOC Alert enrichment / IOC lookup
Utility - List Observable Alert Relations 0 SOC Alert enrichment / IOC lookup
Utility - Delete Observable Relation 0 SOC Alert enrichment / IOC lookup
Utility - List Alert Observable Relations 0 SOC Alert enrichment / IOC lookup
Utility - Set Or Update Observable Relation 0 SOC Alert enrichment / IOC lookup
Utility - Find Similar Cases Based on Observables 0 SOC Alert enrichment / IOC lookup
Utility - Close Stale Cases 0 SOC Case mgmt & SOAR

3. On-Demand SOC Investigation Toolkit

Description: A library of standalone, analyst-facing enrichment and investigation tools designed for interactive or on-demand use during active incident response. Covers user identity lookups, hash reputation, URL analysis, network reconnaissance, and endpoint intelligence across every major identity provider and threat intel source.

Business problem solved: Gives SOC analysts a single Blink-native interface to query any data source without switching tools — reducing context-switching overhead and accelerating investigation timelines.

Integrations: Slack, Okta, CrowdStrike, VirusTotal, URLScan, Google Workspace, Microsoft Entra ID, Microsoft Graph, GitHub, Whois, Bash

Playbook Executions (12mo) Category Subcategory
Get User Information on Email Address Using Slack 0 SOC Alert enrichment / IOC lookup
Get User Information Using Okta 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal 0 SOC Alert enrichment / IOC lookup
Okta Search for User Activity 0 SOC Alert enrichment / IOC lookup
Analyze URL with URLScan 0 SOC Alert enrichment / IOC lookup
Get End of Life Date for a Product 0 SOC Alert enrichment / IOC lookup
Get User Information Using Google Workspace 0 SOC Alert enrichment / IOC lookup
Run Dig Command 0 SOC Alert enrichment / IOC lookup
Secure URL Screenshot Capture 0 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 0 SOC Alert enrichment / IOC lookup
Get User Information Using Github 0 SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID 0 SOC Alert enrichment / IOC lookup
Get VPN Logins 0 SOC Alert enrichment / IOC lookup

4. EDR Containment & Response

Description: On-demand endpoint containment workflows for CrowdStrike Falcon and Microsoft Defender for Endpoint, enabling remote triage (RTR) on single hosts or batch fleets, device quarantine management, and Defender device isolation.

Business problem solved: Allows analysts to execute containment actions — isolating compromised endpoints or running remote commands — directly from Blink without switching to EDR consoles, reducing response time during active incidents.

Integrations: CrowdStrike Falcon, Microsoft Defender for Endpoint

Playbook Executions (12mo) Category Subcategory
Defender Device Isolation 1 SOC EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike 0 SOC EDR containment & response
CrowdStrike RTR to a Single Host 0 SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts 0 SOC EDR containment & response

5. Expel MDR → Microsoft Defender XDR Alert Sync

Description: An event-driven integration that monitors Expel's MDR platform via webhook and automatically propagates closed alert status back to Microsoft Defender XDR — keeping both platforms in sync without manual updates.

Business problem solved: Eliminates the double-work of manually closing alerts in Defender XDR after Expel resolves them, ensuring clean alert queues and accurate platform metrics across the dual-vendor MDR architecture.

Integrations: Expel (webhook), Microsoft Defender XDR

Playbook Executions (12mo) Category Subcategory
Alert Mgmt - Expel to Defender XDR 90 SOC Case mgmt & SOAR

6. Threat Hunting Platform

Description: An end-to-end automated threat hunting capability powered by AI agents and Sumo Logic SIEM data. Analysts submit IOCs (IPs, FQDNs, file hashes, or unstructured text) via webform or API; the platform extracts, deduplicates, searches SIEM data at scale, enriches findings, and creates cases for confirmed hits — all without manual SIEM querying.

Business problem solved: Enables proactive threat detection by operationalizing threat intelligence as hunts against historical SIEM data, with deduplication to avoid re-hunting known IOCs and AI-powered enrichment to contextualize findings.

Integrations: Sumo Logic, URLScan, VirusTotal, Blink AI Agents, Blink Web Forms, Blink Tables

Playbook Executions (12mo) Category Subcategory
Hunt Execution 10 SOC Threat intel ingest & curation
Self-Service - Threat Hunting 9 Vulnerability Mgmt Threat hunting & detection
Hunting Intake - Unstructured Text 10 Vulnerability Mgmt Threat hunting & detection
Hunting Intake - Historic IOC Lookup 10 Vulnerability Mgmt Threat hunting & detection
Hunt Searching - IP IOCs 11 Vulnerability Mgmt Threat hunting & detection
Hunt Searching - FQDN Domain IOCs 6 Vulnerability Mgmt Threat hunting & detection
Hunt Searching - Filehash IOCs 1 Vulnerability Mgmt Threat hunting & detection
Sumo Logic - Search Subflow 60 SOC SIEM & log pipeline monitoring
Hunt Enrichment - Sumo Logic Threat Intel 1 SOC Threat intel ingest & curation
General - Fetch URL Content 1 SOC Threat intel ingest & curation
Webform - Threat Hunting 2 Vulnerability Mgmt Threat hunting & detection
Hunting Intake - URL Analysis 1 Vulnerability Mgmt Threat hunting & detection
Hunt Enrichment & Analysis 0 SOC Threat intel ingest & curation
Hunt Completion - Case Creation 0 SOC Case mgmt & SOAR
URLScan - Scan URL 0 SOC Alert enrichment / IOC lookup
VirusTotal - Scan URL 0 SOC Alert enrichment / IOC lookup

7. Vulnerability Management — Tenable VM & WAS

Description: A fully automated vulnerability ingestion and alert pipeline for Tenable Vulnerability Management (VM) and Web Application Scanning (WAS). Runs daily on a schedule, pulling chunked scan results via paginated API calls, creating and updating SOAR alerts for new and changed vulnerabilities, and recovering from processing failures automatically. Includes a dashboard metrics refresh and an application vulnerability ingestion endpoint via webhook.

Business problem solved: Converts raw Tenable scan output into structured, case-management-ready vulnerability alerts at scale — enabling consistent prioritization, tracking, and lifecycle management without manual data handling.

Integrations: Tenable VM, Tenable WAS, Blink Case Management, Blink Tables, Custom Webhook (AppSec), GitLab

Playbook Executions (12mo) Category Subcategory
Tenable VM Alert Ingestion 39 Vulnerability Mgmt Vuln scanning ingest & report
Tenable WAS Alert Ingestion 39 Vulnerability Mgmt Vuln scanning ingest & report
Tenable - Chunk Processing Recovery 231 Vulnerability Mgmt Vuln scan lifecycle automation
VM_Alert_Creation_Subflow 291 Vulnerability Mgmt Vuln scanning ingest & report
VM_Alert_Update 233 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
VM_Chunk_Download_ Subflow 210 Vulnerability Mgmt Vuln scan lifecycle automation
WAS_Alert Creation_Subflow 30 Vulnerability Mgmt Vuln scanning ingest & report
WAS_Alert_Update 25 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Query Vulnerability Data 28 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Dashboard Table Update - Tenable ONLY - v2 39 Vulnerability Mgmt Vuln scan lifecycle automation
Daily Trigger 38 Vulnerability Mgmt Vuln scan lifecycle automation
Publish Application Vulnerabilities 7 Vulnerability Mgmt Vuln scanning ingest & report
WAS_Chunk_Download_Subflow 28 Vulnerability Mgmt Vuln scan lifecycle automation
Refresh Table - Vuln Records and D42 XREF 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Populate Overview Dashboard 7 Vulnerability Mgmt Vuln scanning ingest & report
Publish Failing Scans 17 Vulnerability Mgmt Vuln scanning ingest & report

8. DLP & CSPM Alert Integration

Description: Ingestion pipelines for Cyera (data security posture) and Prisma Cloud (CSPM) that convert DLP findings and cloud misconfigurations into SOAR alerts. The Daily Trigger orchestrates Cyera ingestion alongside Tenable and Device42.

Business problem solved: Surfaces data exposure and cloud posture risks inside the same case management system used for security alerts, enabling unified analyst workflow and consistent SLA tracking across DLP, CSPM, and endpoint security findings.

Integrations: Cyera, Prisma Cloud CSPM

Playbook Executions (12mo) Category Subcategory
Cyera Ingestion 0 GRC DLP triage & exposure resp
Cyera Alert Creation 0 GRC DLP triage & exposure resp
Cyera Alert Update 0 GRC DLP triage & exposure resp
Prisma Ingestion 0 Cloud Security CSPM ingest & triage
Enrich Prisma CVE Data and Create Alert 0 Cloud Security CSPM ingest & triage
New Workflow 1 2 Cloud Security CSPM ingest & triage

9. MDE Configuration Compliance Reporting

Description: A weekly scheduled workflow that collects Microsoft Defender for Endpoint configuration assessment data via Microsoft Graph API, stores it in a structured table, and generates an HTML/CSV compliance report delivered by email.

Business problem solved: Provides consistent, automated visibility into MDE configuration health and compliance posture — delivered as a formatted report to the cybersecurity mailbox each week without manual data extraction.

Integrations: Microsoft Graph API, Microsoft Defender for Endpoint, Microsoft Outlook, Blink Tables

Playbook Executions (12mo) Category Subcategory
MDE Configuration Issue Collection 6 GRC Security metrics & reporting
Generate MDE Configuration Issues Report 6 Cloud Security Config audit & remediation

10. Asset Intelligence via Device42

Description: Integrates the Device42 CMDB with the vulnerability management pipeline to cross-reference vulnerable assets with their authoritative CMDB records. Runs via the Daily Trigger alongside Tenable ingestion, using split on-premises and cloud runner flows to handle large asset lists in chunks of 1,000.

Business problem solved: Adds CMDB asset context (owner, environment, criticality) to vulnerability alerts, enabling accurate prioritization based on asset importance rather than raw CVSS scores alone.

Integrations: Device42, Blink Case Management, Blink Tables

Playbook Executions (12mo) Category Subcategory
Device42 Ingestion and Enrichment 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Device42 Enhancment 0 Cloud Security Cloud asset coverage & inventory
Update Device42 0 Cloud Security Cloud asset coverage & inventory
Cloud Runner - D42 XREF parent flow 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Onprem Runner - D42 XREF subflow 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket

11. Endpoint & Identity Self-Service

Description: A set of security-controlled self-service workflows accessible via Blink Web Forms, enabling analysts and authorized staff to execute endpoint and identity actions — machine lockouts, BitLocker PIN resets, and HR travel policy exceptions — with automated Microsoft Graph-based user lookup as a supporting primitive.

Business problem solved: Reduces analyst burden and ticket queue volume for routine security operations actions by making them directly accessible to authorized requestors through a governed, auditable self-service interface.

Integrations: Microsoft Graph, Microsoft Defender for Endpoint, CrowdStrike, Blink Web Forms

Playbook Executions (12mo) Category Subcategory
Machine Lockout 9 Other Endpoint hygiene & MDM ops
Get User Details 6 Other Endpoint hygiene & MDM ops
Self-Service - HR Travel Policy Violation or Exception 3 Other Endpoint hygiene & MDM ops
Run BitLocker PIN Reset 2 Other Endpoint hygiene & MDM ops

12. Cloud SaaS App Discovery (MDCA)

Description: A workflow that refreshes a structured inventory table of AI and cloud applications discovered by Microsoft Defender for Cloud Apps (MDCA), clearing and repopulating the table via paginated API calls.

Business problem solved: Maintains an up-to-date, queryable inventory of sanctioned and unsanctioned cloud applications — foundational for shadow IT governance and AI application risk management programs.

Integrations: Microsoft Defender for Cloud Apps (MDCA)

Playbook Executions (12mo) Category Subcategory
MDCA - AI App Refresh 0 Cloud Security Cloud access & SaaS policy mgmt

13. Workflow Autodocumentation Platform

Description: An AI-powered documentation platform that automatically generates structured Markdown documentation for any Blink workflow — either on-demand via webform or in bulk for an entire workspace. Supports both AI-assisted (agent-written) and template-based (no-AI) modes, producing publishable .mdx files packaged as downloadable archives.

Business problem solved: Eliminates the manual documentation burden for security engineering teams managing large Blink workflow libraries — ensuring institutional knowledge is captured, up-to-date, and accessible without dedicated documentation effort.

Integrations: Blink API, Blink AI Agents, Blink Web Forms

Playbook Executions (12mo) Category Subcategory
Autodocs - Agent Intake Webform 2 Other SaaS / IT administration
Single Autodoc Agent 2 Other SaaS / IT administration
Single Autodoc Markdown Template 2 Other SaaS / IT administration
Get Workflow Data 2 Other SaaS / IT administration
Autodocs - Make Markdown Files 1 Other SaaS / IT administration
System Autodocs Agent 0 Other SaaS / IT administration
Autodocs - NoAI - Make Markdown Files 0 Other SaaS / IT administration
System Autodoc Markdown Template 0 Other SaaS / IT administration

14. GitLab DevOps Automation

Description: Workflows for GitLab-integrated DevOps security operations, including YAML pipeline component parsing, repository approval rule enforcement across project groups, and a subflow for AWS IAM access key rotation with guardrails.

Business problem solved: Automates compliance enforcement within the software development lifecycle — ensuring merge approval policies are applied consistently across GitLab repositories and enabling auditable key rotation without developer intervention.

Integrations: GitLab, AWS IAM

Playbook Executions (12mo) Category Subcategory
Repo Approval Rules 0 Other DevOps & release automation
Retrieve YAML File and Parse for Components 0 Other DevOps & release automation
New Workflow 0 Other DevOps & release automation
Subflow - Create New Key 0 GRC RBAC review & access mgmt

15. Software License & Usage Reporting

Description: Scheduled weekly workflows that collect and report on usage of licensed enterprise software — Adobe Acrobat Pro and Edifecs SpecBuilder — running every Monday.

Business problem solved: Provides consistent, automated visibility into software license utilization, supporting license reclamation and cost-optimization decisions without manual usage audits.

Integrations: Adobe Acrobat Pro, Edifecs SpecBuilder

Playbook Executions (12mo) Category Subcategory
Adobe Pro Usage Report 5 Other SaaS / IT administration
Edifecs SpecBuilder Usage 5 Other SaaS / IT administration

Key Observations

Strengths

1. High-volume, production-grade SOAR at scale

The Process Alert workflow at 78,197 executions — running every minute, polling for new case management records — demonstrates a fully operationalized SOAR deployment. The supporting scheduled cleanup (482 runs) and recovery flows (16 runs) show mature pipeline hygiene. This is not a pilot; it's a running production SOC platform.

2. Sophisticated vulnerability management pipeline

The Tenable VM and WAS ingestion infrastructure — with chunked download subflows, separate alert creation and update paths, and a dedicated chunk recovery scheduler — handles enterprise-scale vulnerability data robustly. VM_Alert_Creation_Subflow ran 291 times and VM_Alert_Update 233 times, indicating continuous vulnerability lifecycle tracking, not just one-time ingestion.

3. Agentic threat hunting capability

The threat hunting platform is a standout capability. Using Blink AI agents (Xmus Jaxon Flaxon-Waxon) to search and reason over Sumo Logic SIEM data, with deduplicated IOC tracking in a custom table and multiple intake paths (webform, self-service API, URL analysis), this is a production-ready agentic SOC function — not a demo.

4. Broad integration ecosystem

20+ integrations across EDR (CrowdStrike, Defender), identity (Okta, Entra ID, Google Workspace, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), vulnerability (Tenable, Cyera, Prisma Cloud), SIEM (Sumo Logic), CMDB (Device42), and cloud (AWS, Microsoft Graph, MDCA) — covering the full security toolchain.

5. Self-service security operations

Machine lockout, BitLocker PIN reset, and HR travel policy exception workflows exposed via Web Forms represent a mature self-service security model that reduces analyst ticket load while maintaining governance and auditability.

6. GitLab AppSec scanning pipeline now active

Publish Failing Scans (17 executions) and Populate Overview Dashboard (7 executions) show the GitLab project security scanning dashboard — sharing a workspace with the Tenable/AppSec vulnerability pipeline — is now live in production, surfacing failing project scans and refreshing an overview dashboard automatically rather than sitting idle.

Gaps & Opportunities

1. Enrichment layer not executing in production

All 14 automated enrichment workflows (Enrich - Hash - VT, Enrich - IP - IPDB, Enrich - Username or Email - Okta, etc.) show 0 executions. The enrichment infrastructure is fully built, but the Process Alert flow may not be routing through it or enrichment is only triggered under specific conditions. Activating enrichment on the live alert stream would add context to all 78,000+ annual alerts.

2. DLP pipeline still inactive; CSPM shows early signs of life

Cyera (3 workflows) remains fully inactive at 0 executions. Prisma Cloud CSPM, previously dormant, now shows initial activity — a new webhook-triggered workflow checking for stale IAM keys ran twice — but the core Prisma Ingestion and CVE enrichment playbooks are still at 0 executions. Activating Cyera and completing the full Prisma ingestion pipeline would extend the SOAR platform's coverage to data security and cloud posture risk beyond this initial IAM key check.

3. Device42 CMDB enrichment not yet running

All 5 Device42 workflows show 0 executions. The cross-reference infrastructure (on-prem + cloud runners, chunked processing) is complete. Running Device42 Ingestion and Enrichment would immediately add asset context to the existing Tenable vulnerability alert inventory.

4. EDR response actions are read-only in practice

CrowdStrike RTR workflows (single host, batch) and endpoint quarantine management show 0 executions. Defender Device Isolation ran once. The containment tooling exists but is not integrated into automated response flows — response may still be manual. Wiring these into the Response Subflow - Malware path would enable true automated containment.

5. Threat hunting pipeline does not complete end-to-end

Hunt Enrichment & Analysis (0 executions) and Hunt Completion - Case Creation (0 executions) show the hunting pipeline is not progressing beyond the search phase. IOC searches are running (IP: 11, FQDN: 6, Filehash: 1) but either findings are not hitting the enrichment trigger condition or the enrichment step is failing silently. Completing the pipeline would convert hunt results into SOAR cases automatically.

6. MDCA AI App Discovery not yet active

MDCA - AI App Refresh (0 executions) represents an unactivated shadow IT / AI governance capability. As AI application governance becomes a compliance priority in healthcare, activating this workflow would provide a governed inventory for AI risk review.

Integration Ecosystem

Category Integrations
EDR & Endpoint CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps
Identity Okta, Microsoft Entra ID, Microsoft Graph, Google Workspace, GitHub, Slack
Threat Intelligence VirusTotal, AbuseIPDB, URLScan
SIEM Sumo Logic
Vulnerability Tenable VM, Tenable WAS, Cyera, Prisma Cloud CSPM
CMDB / Asset Device42
Cloud Infrastructure AWS IAM
MDR Expel
Email Microsoft Outlook
DevOps GitLab
SaaS Applications Adobe Acrobat Pro, Edifecs SpecBuilder
Blink Native Case Management, AI Agents, Web Forms, Tables, Blink API
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.