01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| SOC Case Management & SOAR Platform |
| 98.7% | 12 9 active |
| Automated Alert Enrichment & Observable Intelligence | 0 executions | 0.0% | 23 18 active |
| On-Demand SOC Investigation Toolkit | 0 executions | 0.0% | 14 12 active |
| EDR Containment & Response |
| 0.0% | 4 4 active |
| Expel MDR → Microsoft Defender XDR Alert Sync |
| 0.1% | 1 1 active |
| Threat Hunting Platform |
| 0.1% | 16 16 active |
| Vulnerability Management — Tenable VM & WAS |
| 1.1% | 16 16 active |
| DLP & CSPM Alert Integration |
| 0.0% | 6 4 active |
| MDE Configuration Compliance Reporting |
| 0.0% | 2 2 active |
| Asset Intelligence via Device42 | 0 executions | 0.0% | 5 5 active |
| Endpoint & Identity Self-Service |
| 0.0% | 2 2 active |
| Cloud SaaS App Discovery (MDCA) | 0 executions | 0.0% | 1 1 active |
| Workflow Autodocumentation Platform | 0 executions | 0.0% | 8 8 active |
| GitLab DevOps Automation | 0 executions | 0.0% | 4 4 active |
| Software License & Usage Reporting |
| 0.0% | 2 2 active |
| Total | 133,923 executions | 100% | 116 104 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. High-volume, production-grade SOAR at scale
The Process Alert workflow at 78,197 executions — running every minute, polling for new case management records — demonstrates a fully operationalized SOAR deployment. The supporting scheduled cleanup (482 runs) and recovery flows (16 runs) show mature pipeline hygiene. This is not a pilot; it's a running production SOC platform.
2. Sophisticated vulnerability management pipeline
The Tenable VM and WAS ingestion infrastructure — with chunked download subflows, separate alert creation and update paths, and a dedicated chunk recovery scheduler — handles enterprise-scale vulnerability data robustly. VM_Alert_Creation_Subflow ran 291 times and VM_Alert_Update 233 times, indicating continuous vulnerability lifecycle tracking, not just one-time ingestion.
3. Agentic threat hunting capability
The threat hunting platform is a standout capability. Using Blink AI agents (Xmus Jaxon Flaxon-Waxon) to search and reason over Sumo Logic SIEM data, with deduplicated IOC tracking in a custom table and multiple intake paths (webform, self-service API, URL analysis), this is a production-ready agentic SOC function — not a demo.
4. Broad integration ecosystem
20+ integrations across EDR (CrowdStrike, Defender), identity (Okta, Entra ID, Google Workspace, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), vulnerability (Tenable, Cyera, Prisma Cloud), SIEM (Sumo Logic), CMDB (Device42), and cloud (AWS, Microsoft Graph, MDCA) — covering the full security toolchain.
5. Self-service security operations
Machine lockout, BitLocker PIN reset, and HR travel policy exception workflows exposed via Web Forms represent a mature self-service security model that reduces analyst ticket load while maintaining governance and auditability.
6. GitLab AppSec scanning pipeline now active
Publish Failing Scans (17 executions) and Populate Overview Dashboard (7 executions) show the GitLab project security scanning dashboard — sharing a workspace with the Tenable/AppSec vulnerability pipeline — is now live in production, surfacing failing project scans and refreshing an overview dashboard automatically rather than sitting idle.
###
Gaps & Opportunities
1. Enrichment layer not executing in production
All 14 automated enrichment workflows (Enrich - Hash - VT, Enrich - IP - IPDB, Enrich - Username or Email - Okta, etc.) show 0 executions. The enrichment infrastructure is fully built, but the Process Alert flow may not be routing through it or enrichment is only triggered under specific conditions. Activating enrichment on the live alert stream would add context to all 78,000+ annual alerts.
2. DLP pipeline still inactive; CSPM shows early signs of life
Cyera (3 workflows) remains fully inactive at 0 executions. Prisma Cloud CSPM, previously dormant, now shows initial activity — a new webhook-triggered workflow checking for stale IAM keys ran twice — but the core Prisma Ingestion and CVE enrichment playbooks are still at 0 executions. Activating Cyera and completing the full Prisma ingestion pipeline would extend the SOAR platform's coverage to data security and cloud posture risk beyond this initial IAM key check.
3. Device42 CMDB enrichment not yet running
All 5 Device42 workflows show 0 executions. The cross-reference infrastructure (on-prem + cloud runners, chunked processing) is complete. Running Device42 Ingestion and Enrichment would immediately add asset context to the existing Tenable vulnerability alert inventory.
4. EDR response actions are read-only in practice
CrowdStrike RTR workflows (single host, batch) and endpoint quarantine management show 0 executions. Defender Device Isolation ran once. The containment tooling exists but is not integrated into automated response flows — response may still be manual. Wiring these into the Response Subflow - Malware path would enable true automated containment.
5. Threat hunting pipeline does not complete end-to-end
Hunt Enrichment & Analysis (0 executions) and Hunt Completion - Case Creation (0 executions) show the hunting pipeline is not progressing beyond the search phase. IOC searches are running (IP: 11, FQDN: 6, Filehash: 1) but either findings are not hitting the enrichment trigger condition or the enrichment step is failing silently. Completing the pipeline would convert hunt results into SOAR cases automatically.
6. MDCA AI App Discovery not yet active
MDCA - AI App Refresh (0 executions) represents an unactivated shadow IT / AI governance capability. As AI application governance becomes a compliance priority in healthcare, activating this workflow would provide a governed inventory for AI risk review.
Integration Ecosystem
| Category | Integrations |
|---|---|
| EDR & Endpoint | CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps |
| Identity | Okta, Microsoft Entra ID, Microsoft Graph, Google Workspace, GitHub, Slack |
| Threat Intelligence | VirusTotal, AbuseIPDB, URLScan |
| SIEM | Sumo Logic |
| Vulnerability | Tenable VM, Tenable WAS, Cyera, Prisma Cloud CSPM |
| CMDB / Asset | Device42 |
| Cloud Infrastructure | AWS IAM |
| MDR | Expel |
| Microsoft Outlook | |
| DevOps | GitLab |
| SaaS Applications | Adobe Acrobat Pro, Edifecs SpecBuilder |
| Blink Native | Case Management, AI Agents, Web Forms, Tables, Blink API |
A Case Management 6,181 cases (12m) | MTTR 95d 8h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Vulnerability Management | 6,174 | 6,174 | 1,004 | 95d 23h |
| BCBSMN Sandbox | 247 | 0 | 0 | N/A |
| Threat Detection & Response - Dev | 7 | 7 | 7 | 2d 17h |
B AI Agents 5 active | 1,526 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | TrAIvis | Threat Detection & Response - Dev | 643 | 10 | 570,808,039 |
| 2 | Xmus Jaxon Flaxon-Waxon | Threat Detection & Response - Dev | 301 | 18 | 21,041,641 |
| 3 | Hingle McCringleberry | Threat Detection & Response - Dev | 273 | 14 | 12,484,940 |
| 4 | Dapper Dan | Threat Detection & Response - Dev | 210 | 0 | 12,468,929 |
| 5 | Markdown Man | Threat Detection & Response - Dev | 99 | 0 | 12,620,480 |
| Workspace | Tasks (12m) |
|---|---|
| Threat Detection & Response - Dev | 1,526 |
| BCBSMN Sandbox | 0 |
| Vulnerability Management | 0 |
| Application Security - Dev | 0 |
C Self-Service & Webforms 0 app runs | 12 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | CM Demo | 0 | 0 |
| 2 | SecDevOps | 0 | 0 |
| 3 | Prisma | 0 | 0 |
| 4 | VM Dashboard | 0 | 0 |
| 5 | Tenable_vm_ingestion | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Machine Lockout | 12 | 12 |
| 2 | Automated Threat Hunt | 0 | 0 |
| 3 | Generate Blink Workflow Documentation | 0 | 0 |
| 4 | Generate Blink Workflow Documentation | 0 | 0 |
| 5 | Automated Threat Hunting | 0 | 0 |
D Full Use Case Analysis 15 use cases | 133,932 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-processed through SOAR pipeline | 78,197 | Process Alert |
| Unprocessed alert backlog cleanup cycles executed | 482 | Timed Unprocessed Alerts Cleanup |
| Expel MDR closed alerts synced to Microsoft Defender XDR | 90 | Alert Mgmt - Expel to Defender XDR |
| Security case lifecycle updates orchestrated automatically | 42 | Case Update Orchestrator |
| Tenable VM vulnerability scan batches ingested | 39 | Tenable VM Alert Ingestion |
| Tenable WAS vulnerability scan batches ingested | 39 | Tenable WAS Alert Ingestion |
| Security cases automatically closed | 33 | Case Close |
| Security cases automatically reopened | 21 | Case Reopen |
| GitLab project failing-scan events published | 17 | Publish Failing Scans |
| Automated threat hunts executed against SIEM data | 10 | Hunt Execution |
| Self-service threat hunting sessions initiated | 9 | Self-Service - Threat Hunting |
| Endpoint machine lockouts executed | 9 | Machine Lockout |
| Application vulnerability datasets published to SOAR | 7 | Publish Application Vulnerabilities |
| GitLab overview dashboard refreshes | 7 | Populate Overview Dashboard |
| MDE configuration compliance reports generated | 6 | MDE Configuration Issue Collection |
| Adobe Acrobat Pro usage reports generated | 5 | Adobe Pro Usage Report |
| Edifecs SpecBuilder usage reports generated | 5 | Edifecs SpecBuilder Usage |
| HR travel policy violations/exceptions processed | 3 | Self-Service - HR Travel Policy Violation or Exception |
| BitLocker PIN resets performed | 2 | Run BitLocker PIN Reset |
| CSPM webhook alerts triaged for stale IAM keys | 2 | New Workflow 1 |
| Devices isolated via Microsoft Defender for Endpoint | 1 | Defender Device Isolation |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks |
|---|---|---|---|---|
| 1 | SOC Case Management & SOAR Platform | SOC | Case mgmt & SOAR | 12 |
| 2 | Automated Alert Enrichment & Observable Intelligence | SOC | Alert enrichment / IOC lookup | 23 |
| 3 | On-Demand SOC Investigation Toolkit | SOC | Alert enrichment / IOC lookup | 14 |
| 4 | EDR Containment & Response | SOC | EDR containment & response | 4 |
| 5 | Expel MDR → Microsoft Defender XDR Alert Sync | SOC | Case mgmt & SOAR | 1 |
| 6 | Threat Hunting Platform | SOC / Vulnerability Mgmt | Threat intel ingest & curation, Threat hunting & detection | 16 |
| 7 | Vulnerability Management — Tenable VM & WAS | Vulnerability Mgmt | Vuln scanning ingest & report, Vuln scan lifecycle automation | 16 |
| 8 | DLP & CSPM Alert Integration | GRC / Cloud Security | DLP triage & exposure resp, CSPM ingest & triage | 6 |
| 9 | MDE Configuration Compliance Reporting | GRC / Cloud Security | Security metrics & reporting, Config audit & remediation | 2 |
| 10 | Asset Intelligence via Device42 | Vulnerability Mgmt / Cloud Security | Vuln lifecycle prioritize & ticket, Cloud asset coverage & inventory | 5 |
| 11 | Endpoint & Identity Self-Service | Other | Endpoint hygiene & MDM ops | 4 |
| 12 | Cloud SaaS App Discovery (MDCA) | Cloud Security | Cloud access & SaaS policy mgmt | 1 |
| 13 | Workflow Autodocumentation Platform | Other | SaaS / IT administration | 8 |
| 14 | GitLab DevOps Automation | Other | DevOps & release automation | 4 |
| 15 | Software License & Usage Reporting | Other | SaaS / IT administration | 2 |
| Total | 118 |
Use Cases
1. SOC Case Management & SOAR Platform
Description: A fully automated security operations platform built on Blink's native case management system that ingests, deduplicates, enriches, and triages security alerts — automatically creating, routing, updating, and closing cases. Dedicated response subflows handle phishing and malware scenarios with distinct playbook logic.
Business problem solved: Eliminates manual triage and case management overhead at scale. At 78,000+ alert events per year, the platform ensures no alert is missed, response logic is consistently applied, and unprocessed alerts are automatically recovered.
Integrations: Blink Case Management, Microsoft Outlook, CrowdStrike, Okta
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Process Alert | 78,197 | SOC | Case mgmt & SOAR |
| Timed Unprocessed Alerts Cleanup | 482 | SOC | Case mgmt & SOAR |
| Case Update Orchestrator | 42 | SOC | Case mgmt & SOAR |
| Case Close | 33 | SOC | Case mgmt & SOAR |
| Case Reopen | 21 | SOC | Case mgmt & SOAR |
| Recovery - Handle Unprocessed Alerts | 16 | SOC | Case mgmt & SOAR |
| Response Subflow - Phishing | 0 | SOC | Phishing detection & response |
| Response Subflow - Malware | 0 | SOC | Case mgmt & SOAR |
| Subflow - Response - Main Router | 0 | SOC | Case mgmt & SOAR |
| Subflow - Missing Alert Template Notification | 0 | SOC | Case mgmt & SOAR |
| Table Action - Validate Observables Extraction Template | 0 | SOC | Case mgmt & SOAR |
| Error Handling - Send Error Notification Email | 0 | SOC | Case mgmt & SOAR |
2. Automated Alert Enrichment & Observable Intelligence
Description: A comprehensive multi-source enrichment layer that automatically enriches observables (IPs, hashes, URLs, usernames, email addresses, domains) extracted from incoming alerts, using 9+ threat intelligence and identity integrations. Includes full observable lifecycle management — linking, updating, deduplicating, and recovering unenriched records.
Business problem solved: Ensures every observable attached to a security alert carries full context before analysts review it, reducing investigation time and enabling automated triage decisions downstream.
Integrations: CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Okta, Slack, GitHub, Google Workspace, Microsoft Entra ID, Whois, Blink Case Management
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Enrich - Agent ID - Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username - Github | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 0 | SOC | Alert enrichment / IOC lookup |
| Recovery - Enrich Non-Enriched Observables | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Update Enrichment | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - List Observable Alert Relations | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Delete Observable Relation | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - List Alert Observable Relations | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Set Or Update Observable Relation | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Find Similar Cases Based on Observables | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Close Stale Cases | 0 | SOC | Case mgmt & SOAR |
3. On-Demand SOC Investigation Toolkit
Description: A library of standalone, analyst-facing enrichment and investigation tools designed for interactive or on-demand use during active incident response. Covers user identity lookups, hash reputation, URL analysis, network reconnaissance, and endpoint intelligence across every major identity provider and threat intel source.
Business problem solved: Gives SOC analysts a single Blink-native interface to query any data source without switching tools — reducing context-switching overhead and accelerating investigation timelines.
Integrations: Slack, Okta, CrowdStrike, VirusTotal, URLScan, Google Workspace, Microsoft Entra ID, Microsoft Graph, GitHub, Whois, Bash
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Get User Information on Email Address Using Slack | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Okta | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | 0 | SOC | Alert enrichment / IOC lookup |
| Okta Search for User Activity | 0 | SOC | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | 0 | SOC | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | 0 | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | 0 | SOC | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Github | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | 0 | SOC | Alert enrichment / IOC lookup |
| Get VPN Logins | 0 | SOC | Alert enrichment / IOC lookup |
4. EDR Containment & Response
Description: On-demand endpoint containment workflows for CrowdStrike Falcon and Microsoft Defender for Endpoint, enabling remote triage (RTR) on single hosts or batch fleets, device quarantine management, and Defender device isolation.
Business problem solved: Allows analysts to execute containment actions — isolating compromised endpoints or running remote commands — directly from Blink without switching to EDR consoles, reducing response time during active incidents.
Integrations: CrowdStrike Falcon, Microsoft Defender for Endpoint
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Defender Device Isolation | 1 | SOC | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | 0 | SOC | EDR containment & response |
5. Expel MDR → Microsoft Defender XDR Alert Sync
Description: An event-driven integration that monitors Expel's MDR platform via webhook and automatically propagates closed alert status back to Microsoft Defender XDR — keeping both platforms in sync without manual updates.
Business problem solved: Eliminates the double-work of manually closing alerts in Defender XDR after Expel resolves them, ensuring clean alert queues and accurate platform metrics across the dual-vendor MDR architecture.
Integrations: Expel (webhook), Microsoft Defender XDR
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Alert Mgmt - Expel to Defender XDR | 90 | SOC | Case mgmt & SOAR |
6. Threat Hunting Platform
Description: An end-to-end automated threat hunting capability powered by AI agents and Sumo Logic SIEM data. Analysts submit IOCs (IPs, FQDNs, file hashes, or unstructured text) via webform or API; the platform extracts, deduplicates, searches SIEM data at scale, enriches findings, and creates cases for confirmed hits — all without manual SIEM querying.
Business problem solved: Enables proactive threat detection by operationalizing threat intelligence as hunts against historical SIEM data, with deduplication to avoid re-hunting known IOCs and AI-powered enrichment to contextualize findings.
Integrations: Sumo Logic, URLScan, VirusTotal, Blink AI Agents, Blink Web Forms, Blink Tables
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Hunt Execution | 10 | SOC | Threat intel ingest & curation |
| Self-Service - Threat Hunting | 9 | Vulnerability Mgmt | Threat hunting & detection |
| Hunting Intake - Unstructured Text | 10 | Vulnerability Mgmt | Threat hunting & detection |
| Hunting Intake - Historic IOC Lookup | 10 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt Searching - IP IOCs | 11 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt Searching - FQDN Domain IOCs | 6 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt Searching - Filehash IOCs | 1 | Vulnerability Mgmt | Threat hunting & detection |
| Sumo Logic - Search Subflow | 60 | SOC | SIEM & log pipeline monitoring |
| Hunt Enrichment - Sumo Logic Threat Intel | 1 | SOC | Threat intel ingest & curation |
| General - Fetch URL Content | 1 | SOC | Threat intel ingest & curation |
| Webform - Threat Hunting | 2 | Vulnerability Mgmt | Threat hunting & detection |
| Hunting Intake - URL Analysis | 1 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt Enrichment & Analysis | 0 | SOC | Threat intel ingest & curation |
| Hunt Completion - Case Creation | 0 | SOC | Case mgmt & SOAR |
| URLScan - Scan URL | 0 | SOC | Alert enrichment / IOC lookup |
| VirusTotal - Scan URL | 0 | SOC | Alert enrichment / IOC lookup |
7. Vulnerability Management — Tenable VM & WAS
Description: A fully automated vulnerability ingestion and alert pipeline for Tenable Vulnerability Management (VM) and Web Application Scanning (WAS). Runs daily on a schedule, pulling chunked scan results via paginated API calls, creating and updating SOAR alerts for new and changed vulnerabilities, and recovering from processing failures automatically. Includes a dashboard metrics refresh and an application vulnerability ingestion endpoint via webhook.
Business problem solved: Converts raw Tenable scan output into structured, case-management-ready vulnerability alerts at scale — enabling consistent prioritization, tracking, and lifecycle management without manual data handling.
Integrations: Tenable VM, Tenable WAS, Blink Case Management, Blink Tables, Custom Webhook (AppSec), GitLab
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Tenable VM Alert Ingestion | 39 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Tenable WAS Alert Ingestion | 39 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Tenable - Chunk Processing Recovery | 231 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| VM_Alert_Creation_Subflow | 291 | Vulnerability Mgmt | Vuln scanning ingest & report |
| VM_Alert_Update | 233 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| VM_Chunk_Download_ Subflow | 210 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| WAS_Alert Creation_Subflow | 30 | Vulnerability Mgmt | Vuln scanning ingest & report |
| WAS_Alert_Update | 25 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Query Vulnerability Data | 28 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Dashboard Table Update - Tenable ONLY - v2 | 39 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Daily Trigger | 38 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Publish Application Vulnerabilities | 7 | Vulnerability Mgmt | Vuln scanning ingest & report |
| WAS_Chunk_Download_Subflow | 28 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Refresh Table - Vuln Records and D42 XREF | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Populate Overview Dashboard | 7 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Publish Failing Scans | 17 | Vulnerability Mgmt | Vuln scanning ingest & report |
8. DLP & CSPM Alert Integration
Description: Ingestion pipelines for Cyera (data security posture) and Prisma Cloud (CSPM) that convert DLP findings and cloud misconfigurations into SOAR alerts. The Daily Trigger orchestrates Cyera ingestion alongside Tenable and Device42.
Business problem solved: Surfaces data exposure and cloud posture risks inside the same case management system used for security alerts, enabling unified analyst workflow and consistent SLA tracking across DLP, CSPM, and endpoint security findings.
Integrations: Cyera, Prisma Cloud CSPM
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Cyera Ingestion | 0 | GRC | DLP triage & exposure resp |
| Cyera Alert Creation | 0 | GRC | DLP triage & exposure resp |
| Cyera Alert Update | 0 | GRC | DLP triage & exposure resp |
| Prisma Ingestion | 0 | Cloud Security | CSPM ingest & triage |
| Enrich Prisma CVE Data and Create Alert | 0 | Cloud Security | CSPM ingest & triage |
| New Workflow 1 | 2 | Cloud Security | CSPM ingest & triage |
9. MDE Configuration Compliance Reporting
Description: A weekly scheduled workflow that collects Microsoft Defender for Endpoint configuration assessment data via Microsoft Graph API, stores it in a structured table, and generates an HTML/CSV compliance report delivered by email.
Business problem solved: Provides consistent, automated visibility into MDE configuration health and compliance posture — delivered as a formatted report to the cybersecurity mailbox each week without manual data extraction.
Integrations: Microsoft Graph API, Microsoft Defender for Endpoint, Microsoft Outlook, Blink Tables
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| MDE Configuration Issue Collection | 6 | GRC | Security metrics & reporting |
| Generate MDE Configuration Issues Report | 6 | Cloud Security | Config audit & remediation |
10. Asset Intelligence via Device42
Description: Integrates the Device42 CMDB with the vulnerability management pipeline to cross-reference vulnerable assets with their authoritative CMDB records. Runs via the Daily Trigger alongside Tenable ingestion, using split on-premises and cloud runner flows to handle large asset lists in chunks of 1,000.
Business problem solved: Adds CMDB asset context (owner, environment, criticality) to vulnerability alerts, enabling accurate prioritization based on asset importance rather than raw CVSS scores alone.
Integrations: Device42, Blink Case Management, Blink Tables
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Device42 Ingestion and Enrichment | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Device42 Enhancment | 0 | Cloud Security | Cloud asset coverage & inventory |
| Update Device42 | 0 | Cloud Security | Cloud asset coverage & inventory |
| Cloud Runner - D42 XREF parent flow | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Onprem Runner - D42 XREF subflow | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
11. Endpoint & Identity Self-Service
Description: A set of security-controlled self-service workflows accessible via Blink Web Forms, enabling analysts and authorized staff to execute endpoint and identity actions — machine lockouts, BitLocker PIN resets, and HR travel policy exceptions — with automated Microsoft Graph-based user lookup as a supporting primitive.
Business problem solved: Reduces analyst burden and ticket queue volume for routine security operations actions by making them directly accessible to authorized requestors through a governed, auditable self-service interface.
Integrations: Microsoft Graph, Microsoft Defender for Endpoint, CrowdStrike, Blink Web Forms
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Machine Lockout | 9 | Other | Endpoint hygiene & MDM ops |
| Get User Details | 6 | Other | Endpoint hygiene & MDM ops |
| Self-Service - HR Travel Policy Violation or Exception | 3 | Other | Endpoint hygiene & MDM ops |
| Run BitLocker PIN Reset | 2 | Other | Endpoint hygiene & MDM ops |
12. Cloud SaaS App Discovery (MDCA)
Description: A workflow that refreshes a structured inventory table of AI and cloud applications discovered by Microsoft Defender for Cloud Apps (MDCA), clearing and repopulating the table via paginated API calls.
Business problem solved: Maintains an up-to-date, queryable inventory of sanctioned and unsanctioned cloud applications — foundational for shadow IT governance and AI application risk management programs.
Integrations: Microsoft Defender for Cloud Apps (MDCA)
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| MDCA - AI App Refresh | 0 | Cloud Security | Cloud access & SaaS policy mgmt |
13. Workflow Autodocumentation Platform
Description: An AI-powered documentation platform that automatically generates structured Markdown documentation for any Blink workflow — either on-demand via webform or in bulk for an entire workspace. Supports both AI-assisted (agent-written) and template-based (no-AI) modes, producing publishable .mdx files packaged as downloadable archives.
Business problem solved: Eliminates the manual documentation burden for security engineering teams managing large Blink workflow libraries — ensuring institutional knowledge is captured, up-to-date, and accessible without dedicated documentation effort.
Integrations: Blink API, Blink AI Agents, Blink Web Forms
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Autodocs - Agent Intake Webform | 2 | Other | SaaS / IT administration |
| Single Autodoc Agent | 2 | Other | SaaS / IT administration |
| Single Autodoc Markdown Template | 2 | Other | SaaS / IT administration |
| Get Workflow Data | 2 | Other | SaaS / IT administration |
| Autodocs - Make Markdown Files | 1 | Other | SaaS / IT administration |
| System Autodocs Agent | 0 | Other | SaaS / IT administration |
| Autodocs - NoAI - Make Markdown Files | 0 | Other | SaaS / IT administration |
| System Autodoc Markdown Template | 0 | Other | SaaS / IT administration |
14. GitLab DevOps Automation
Description: Workflows for GitLab-integrated DevOps security operations, including YAML pipeline component parsing, repository approval rule enforcement across project groups, and a subflow for AWS IAM access key rotation with guardrails.
Business problem solved: Automates compliance enforcement within the software development lifecycle — ensuring merge approval policies are applied consistently across GitLab repositories and enabling auditable key rotation without developer intervention.
Integrations: GitLab, AWS IAM
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Repo Approval Rules | 0 | Other | DevOps & release automation |
| Retrieve YAML File and Parse for Components | 0 | Other | DevOps & release automation |
| New Workflow | 0 | Other | DevOps & release automation |
| Subflow - Create New Key | 0 | GRC | RBAC review & access mgmt |
15. Software License & Usage Reporting
Description: Scheduled weekly workflows that collect and report on usage of licensed enterprise software — Adobe Acrobat Pro and Edifecs SpecBuilder — running every Monday.
Business problem solved: Provides consistent, automated visibility into software license utilization, supporting license reclamation and cost-optimization decisions without manual usage audits.
Integrations: Adobe Acrobat Pro, Edifecs SpecBuilder
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Adobe Pro Usage Report | 5 | Other | SaaS / IT administration |
| Edifecs SpecBuilder Usage | 5 | Other | SaaS / IT administration |
Key Observations
Strengths
1. High-volume, production-grade SOAR at scale
The Process Alert workflow at 78,197 executions — running every minute, polling for new case management records — demonstrates a fully operationalized SOAR deployment. The supporting scheduled cleanup (482 runs) and recovery flows (16 runs) show mature pipeline hygiene. This is not a pilot; it's a running production SOC platform.
2. Sophisticated vulnerability management pipeline
The Tenable VM and WAS ingestion infrastructure — with chunked download subflows, separate alert creation and update paths, and a dedicated chunk recovery scheduler — handles enterprise-scale vulnerability data robustly. VM_Alert_Creation_Subflow ran 291 times and VM_Alert_Update 233 times, indicating continuous vulnerability lifecycle tracking, not just one-time ingestion.
3. Agentic threat hunting capability
The threat hunting platform is a standout capability. Using Blink AI agents (Xmus Jaxon Flaxon-Waxon) to search and reason over Sumo Logic SIEM data, with deduplicated IOC tracking in a custom table and multiple intake paths (webform, self-service API, URL analysis), this is a production-ready agentic SOC function — not a demo.
4. Broad integration ecosystem
20+ integrations across EDR (CrowdStrike, Defender), identity (Okta, Entra ID, Google Workspace, GitHub, Slack), threat intel (VirusTotal, AbuseIPDB, URLScan), vulnerability (Tenable, Cyera, Prisma Cloud), SIEM (Sumo Logic), CMDB (Device42), and cloud (AWS, Microsoft Graph, MDCA) — covering the full security toolchain.
5. Self-service security operations
Machine lockout, BitLocker PIN reset, and HR travel policy exception workflows exposed via Web Forms represent a mature self-service security model that reduces analyst ticket load while maintaining governance and auditability.
6. GitLab AppSec scanning pipeline now active
Publish Failing Scans (17 executions) and Populate Overview Dashboard (7 executions) show the GitLab project security scanning dashboard — sharing a workspace with the Tenable/AppSec vulnerability pipeline — is now live in production, surfacing failing project scans and refreshing an overview dashboard automatically rather than sitting idle.
Gaps & Opportunities
1. Enrichment layer not executing in production
All 14 automated enrichment workflows (Enrich - Hash - VT, Enrich - IP - IPDB, Enrich - Username or Email - Okta, etc.) show 0 executions. The enrichment infrastructure is fully built, but the Process Alert flow may not be routing through it or enrichment is only triggered under specific conditions. Activating enrichment on the live alert stream would add context to all 78,000+ annual alerts.
2. DLP pipeline still inactive; CSPM shows early signs of life
Cyera (3 workflows) remains fully inactive at 0 executions. Prisma Cloud CSPM, previously dormant, now shows initial activity — a new webhook-triggered workflow checking for stale IAM keys ran twice — but the core Prisma Ingestion and CVE enrichment playbooks are still at 0 executions. Activating Cyera and completing the full Prisma ingestion pipeline would extend the SOAR platform's coverage to data security and cloud posture risk beyond this initial IAM key check.
3. Device42 CMDB enrichment not yet running
All 5 Device42 workflows show 0 executions. The cross-reference infrastructure (on-prem + cloud runners, chunked processing) is complete. Running Device42 Ingestion and Enrichment would immediately add asset context to the existing Tenable vulnerability alert inventory.
4. EDR response actions are read-only in practice
CrowdStrike RTR workflows (single host, batch) and endpoint quarantine management show 0 executions. Defender Device Isolation ran once. The containment tooling exists but is not integrated into automated response flows — response may still be manual. Wiring these into the Response Subflow - Malware path would enable true automated containment.
5. Threat hunting pipeline does not complete end-to-end
Hunt Enrichment & Analysis (0 executions) and Hunt Completion - Case Creation (0 executions) show the hunting pipeline is not progressing beyond the search phase. IOC searches are running (IP: 11, FQDN: 6, Filehash: 1) but either findings are not hitting the enrichment trigger condition or the enrichment step is failing silently. Completing the pipeline would convert hunt results into SOAR cases automatically.
6. MDCA AI App Discovery not yet active
MDCA - AI App Refresh (0 executions) represents an unactivated shadow IT / AI governance capability. As AI application governance becomes a compliance priority in healthcare, activating this workflow would provide a governed inventory for AI risk review.
Integration Ecosystem
| Category | Integrations |
|---|---|
| EDR & Endpoint | CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps |
| Identity | Okta, Microsoft Entra ID, Microsoft Graph, Google Workspace, GitHub, Slack |
| Threat Intelligence | VirusTotal, AbuseIPDB, URLScan |
| SIEM | Sumo Logic |
| Vulnerability | Tenable VM, Tenable WAS, Cyera, Prisma Cloud CSPM |
| CMDB / Asset | Device42 |
| Cloud Infrastructure | AWS IAM |
| MDR | Expel |
| Microsoft Outlook | |
| DevOps | GitLab |
| SaaS Applications | Adobe Acrobat Pro, Edifecs SpecBuilder |
| Blink Native | Case Management, AI Agents, Web Forms, Tables, Blink API |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.