01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| SIEM & Log Ingestion Pipeline |
| 98.4% | 5 2 active |
| EDR Containment & Endpoint Response | 0 executions | 0.0% | 6 6 active |
| Identity Containment & Session Revocation | 0 executions | 0.0% | 8 8 active |
| Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 1 1 active |
| Password & Credential Lifecycle |
| 0.1% | 2 2 active |
| Customer Deployment & Onboarding Automation |
| 1.5% | 6 6 active |
| Total | 1,954 executions | 100% | 28 25 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. High-volume, fully automated log pipeline. The SIEM log ingestion pipeline runs continuously without analyst intervention, having executed over 70,000 times in the past 12 months. The minute-level polling cadence and per-vendor collection architecture demonstrate a mature, production-grade log ingestion system that sustains Blumira's core SIEM value proposition for its customers.
2. Comprehensive EDR containment toolkit deployed at scale. Six LimaCharlie-based containment actions — covering process kill, process tree termination, file deletion, and both local and AD user disable — are deployed uniformly across 13+ customer workspaces. This gives the SOC immediate automated containment reach across the entire customer base without per-customer configuration.
3. Defense-in-depth identity response architecture. The identity containment library covers multiple layers: cloud identity session revocation (Entra ID), endpoint-level user disable (LimaCharlie AD/local), and credential pre-flight validation — providing automated response across the full identity stack when a user is compromised.
4. Automated platform operations. Blumira uses Blink to automate its own platform operations — onboarding new customers, deploying playbook updates to all workspaces, and maintaining the connection registry. This reduces the operational burden of managing a multi-tenant Blink environment at scale and is a strong proof point of internal adoption.
###
Gaps & Opportunities
1. EDR and identity response playbooks are staged but inactive. Despite a well-designed containment library, none of the response playbooks have been invoked in the past 12 months. These appear configured and ready but not yet wired into automated alert-driven triggers. Connecting these to Blumira's detection alerts would immediately activate automated response value without building new workflows.
2. No alert-driven SOAR orchestration layer. The environment lacks a top-level case management or alert triage workflow — a workflow that fires on a new Blumira detection, enriches it, and routes to the appropriate response playbook. Adding this orchestration layer would close the detect-to-respond loop and unlock the full value of the containment library already built.
3. Version proliferation in identity response. Four variants of the disable-and-revoke pattern (v1, v2, v3, copy) coexist alongside the atomized sub-actions (entra_disable_user, entra_revoke_session). Consolidating to a single canonical version with explicit deprecation of older variants would reduce maintenance overhead and analyst confusion.
4. No vulnerability management or GRC workflows. The environment covers SOC response and IAM containment but has no workflows addressing vulnerability scanning ingestion, compliance reporting, or risk automation. These are natural expansion areas given the existing identity and EDR integrations.
5. Test and development artifacts remain in customer workspaces. Nine test and development playbooks (Getting Started - Hello World, Mason_E2E_testing, Test Prowler, etc.) are active across multiple workspaces. Isolating these in a dedicated development workspace would keep the production catalog clean and avoid confusion in the customer-facing environment.
Integration Ecosystem
| Integration | Use Case | Category |
|---|---|---|
| Microsoft O365 Management Activity API | SIEM log ingestion | SOC |
| Okta | SIEM log ingestion | SOC |
| LimaCharlie EDR | EDR containment, identity disable | SOC |
| Microsoft Entra ID / Azure AD | Identity containment, password lifecycle | SOC / IAM |
| Microsoft Graph API | Identity containment, credential validation | SOC / IAM |
| VirusTotal | IOC / IP enrichment | SOC |
| Recorded Future | IOC / IP enrichment | SOC |
| Blink API | Internal deployment & onboarding ops | Other |
| Blink Tables | Customer registry, log pipeline state | Other |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 6 use cases | 1,954 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security log ingestion routing cycles completed | 57,820 | Parent - Log Ingestion Router |
| Microsoft 365 audit log batches collected | 11,068 | microsoft-o365-management-activity-get-logs |
| Okta identity log batches collected | 947 | okta-get-logs |
| Ad-hoc customer workspace deployments automated | 23 | Deploy - Ad Hoc |
| Customer environments provisioned end-to-end | 8 | customer_blink_onboarding |
| M365 tenant credentials validated | 8 | validate_credentials |
Use Case Summary
| Use Case | Category | Subcategory | Unique Playbooks | Total Executions |
|---|---|---|---|---|
| SIEM & Log Ingestion Pipeline | SOC | SIEM & log pipeline monitoring | 5 | 71,766 |
| EDR Containment & Endpoint Response | SOC | EDR containment & response | 6 | 0 |
| Identity Containment & Session Revocation | SOC | Identity threat response | 8 | 0 |
| Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 1 | 0 |
| Password & Credential Lifecycle | IAM | Password & credential lifecycle | 2 | 8 |
| Customer Deployment & Onboarding Automation | Other | DevOps & release automation | 6 | 31 |
Use Cases
1. SIEM & Log Ingestion Pipeline
Category: SOC | Subcategory: SIEM & log pipeline monitoring
Description: A fully automated, continuous log ingestion pipeline that collects and routes security events from Microsoft 365 and Okta into Blumira's SIEM platform. A scheduled router workflow executes every minute, reads the active log-source connection registry, and dispatches per-vendor collection playbooks to pull the latest audit events.
Business problem solved: Ensures uninterrupted security telemetry from cloud identity and productivity platforms without manual intervention — sustaining SIEM coverage, alert fidelity, and detection freshness at scale.
Integrations: Blink API (connection registry), Microsoft O365 Management Activity API, Okta, Blink internal tables
| Playbook | Executions (12 mo) | Automation Type |
|---|---|---|
| Parent - Log Ingestion Router | 57,820 | Scheduled (every minute) |
| microsoft-o365-management-activity-get-logs | 11,068 | On-demand (called by router) |
| okta-get-logs | 947 | On-demand (called by router) |
| SCHEDULED Update Cust Workspaces Global Variable | 965 | Scheduled (hourly) |
| Subflow - Update Customer Workspaces Global Variable | 966 | Subflow |
2. EDR Containment & Endpoint Response
Category: SOC | Subcategory: EDR containment & response
Description: A library of LimaCharlie EDR containment actions — kill malicious processes or entire process trees, delete suspected malware files, and disable compromised user accounts at the endpoint level (both local accounts and Active Directory accounts). These playbooks are deployed uniformly across 10+ customer workspaces, ready for one-click or automated invocation from Blumira's detection platform.
Business problem solved: When Blumira detects an active threat on a customer endpoint, analysts can execute surgical containment actions through Blink without switching tools or logging into the EDR console directly — reducing mean time to contain (MTTC).
Integrations: LimaCharlie EDR (sensor management, reliable task execution), Active Directory (via LimaCharlie)
| Playbook | Executions (12 mo) | Automation Type |
|---|---|---|
| limacharlie_kill_process | 0 | On-demand |
| limacharlie_kill_process_tree | 0 | On-demand |
| limacharlie_delete_file | 0 | On-demand |
| limacharlie_disable_local_user | 0 | On-demand |
| limacharlie_disable_local_user_v5 | 0 | On-demand |
| limacharlie_disable_ad_user | 0 | On-demand |
*These playbooks are deployed across 13+ customer workspaces. All instances show 0 executions — they are configured and staged for response but have not been invoked in production in the last 12 months.*
3. Identity Containment & Session Revocation
Category: SOC | Subcategory: Identity threat response
Description: A suite of identity containment playbooks that disable compromised accounts, revoke active sessions, and terminate access in Microsoft Entra ID (formerly Azure AD). Multiple versions reflect iterative development of the core disable-and-revoke pattern; newer versions incorporate LimaCharlie endpoint-side disabling alongside cloud identity actions.
Business problem solved: When a user account is compromised or a suspicious authenticated session is detected, analysts can immediately disable the account and invalidate all active tokens — preventing lateral movement, persistent access, and further damage within minutes of detection.
Integrations: Microsoft Entra ID / Azure AD, Microsoft Graph API, LimaCharlie EDR (for endpoint-side disable)
| Playbook | Executions (12 mo) | Automation Type |
|---|---|---|
| disable_user_and_revoke_session | 0 | On-demand |
| disable_user_and_revoke_session_v2 | 0 | On-demand |
| disable_user_and_revoke_session_v3 | 0 | On-demand |
| 1-DisableUserandRevokeSession-v1 | 0 | On-demand |
| DisableUserAndRevokeSession-v2 | 0 | On-demand |
| entra_disable_user | 0 | On-demand |
| entra_revoke_session | 0 | On-demand |
| disable_user_and_revoke_session copy | 0 | On-demand |
*The atomic sub-actions (entra_disable_user, entra_revoke_session) are deployed across 15+ customer workspaces as composable building blocks for the combined disable-and-revoke workflows.*
4. Alert Enrichment & IOC Lookup
Category: SOC | Subcategory: Alert enrichment / IOC lookup
Description: Automated IP address reputation enrichment that queries VirusTotal and Recorded Future in parallel, then branches on the verdict to flag whether the IP is malicious. Designed as a callable enrichment step within broader alert triage workflows.
Business problem solved: Eliminates manual context switching and lookup time during alert triage by delivering automated, multi-source threat intelligence verdicts directly within the response flow.
Integrations: VirusTotal, Recorded Future
| Playbook | Executions (12 mo) | Automation Type |
|---|---|---|
| VT-RF CheckIP | 0 | On-demand |
5. Password & Credential Lifecycle
Category: IAM | Subcategory: Password & credential lifecycle
Description: Automated M365 tenant credential validation and forced password reset. validate_credentials verifies that a tenant's client ID and connection configuration are valid before executing downstream containment actions. entra_reset_password forces an immediate password change on a targeted Entra ID user account.
Business problem solved: Ensures automated identity response actions execute against validated, live tenant credentials — preventing silent failures in containment workflows due to stale or misconfigured connection settings.
Integrations: Microsoft Entra ID, Microsoft Graph API
| Playbook | Executions (12 mo) | Automation Type |
|---|---|---|
| validate_credentials | 8 | On-demand |
| entra_reset_password | 0 | On-demand |
*validate_credentials is deployed across 17 customer workspaces as a pre-flight check called by identity response workflows.*
6. Customer Deployment & Onboarding Automation
Category: Other | Subcategory: DevOps & release automation, Customer registry & FinOps auto
Description: Internal automation managing the full lifecycle of deploying Blink playbooks to customer workspaces and provisioning new customer environments. Covers staged deployment (staging environment), targeted ad-hoc deployments to specific customer workspaces, bulk deployment to all customers, and end-to-end customer onboarding that creates and validates new tenant setups.
Business problem solved: Eliminates manual, error-prone deployment of security automation playbooks across a large and growing customer base — enabling Blumira's team to ship and update response capabilities to all customers at scale, without per-customer manual steps.
Integrations: Blink API, Blink Tables (customer workspace registry), HTTP (internal APIs)
| Playbook | Executions (12 mo) | Automation Type |
|---|---|---|
| customer_blink_onboarding | 8 | On-demand |
| Deploy - Ad Hoc | 23 | On-demand |
| Deploy - Staging | 0 | On-demand |
| Deploy - Overwrite Existing Versions | 0 | On-demand |
| Deploy - All Customers | 0 | On-demand |
| Fail Forward - Workflow Deployment Ad Hoc | 0 | On-demand |
Key Observations
Strengths
1. High-volume, fully automated log pipeline. The SIEM log ingestion pipeline runs continuously without analyst intervention, having executed over 70,000 times in the past 12 months. The minute-level polling cadence and per-vendor collection architecture demonstrate a mature, production-grade log ingestion system that sustains Blumira's core SIEM value proposition for its customers.
2. Comprehensive EDR containment toolkit deployed at scale. Six LimaCharlie-based containment actions — covering process kill, process tree termination, file deletion, and both local and AD user disable — are deployed uniformly across 13+ customer workspaces. This gives the SOC immediate automated containment reach across the entire customer base without per-customer configuration.
3. Defense-in-depth identity response architecture. The identity containment library covers multiple layers: cloud identity session revocation (Entra ID), endpoint-level user disable (LimaCharlie AD/local), and credential pre-flight validation — providing automated response across the full identity stack when a user is compromised.
4. Automated platform operations. Blumira uses Blink to automate its own platform operations — onboarding new customers, deploying playbook updates to all workspaces, and maintaining the connection registry. This reduces the operational burden of managing a multi-tenant Blink environment at scale and is a strong proof point of internal adoption.
Gaps & Opportunities
1. EDR and identity response playbooks are staged but inactive. Despite a well-designed containment library, none of the response playbooks have been invoked in the past 12 months. These appear configured and ready but not yet wired into automated alert-driven triggers. Connecting these to Blumira's detection alerts would immediately activate automated response value without building new workflows.
2. No alert-driven SOAR orchestration layer. The environment lacks a top-level case management or alert triage workflow — a workflow that fires on a new Blumira detection, enriches it, and routes to the appropriate response playbook. Adding this orchestration layer would close the detect-to-respond loop and unlock the full value of the containment library already built.
3. Version proliferation in identity response. Four variants of the disable-and-revoke pattern (v1, v2, v3, copy) coexist alongside the atomized sub-actions (entra_disable_user, entra_revoke_session). Consolidating to a single canonical version with explicit deprecation of older variants would reduce maintenance overhead and analyst confusion.
4. No vulnerability management or GRC workflows. The environment covers SOC response and IAM containment but has no workflows addressing vulnerability scanning ingestion, compliance reporting, or risk automation. These are natural expansion areas given the existing identity and EDR integrations.
5. Test and development artifacts remain in customer workspaces. Nine test and development playbooks (Getting Started - Hello World, Mason_E2E_testing, Test Prowler, etc.) are active across multiple workspaces. Isolating these in a dedicated development workspace would keep the production catalog clean and avoid confusion in the customer-facing environment.
Integration Ecosystem
| Integration | Use Case | Category |
|---|---|---|
| Microsoft O365 Management Activity API | SIEM log ingestion | SOC |
| Okta | SIEM log ingestion | SOC |
| LimaCharlie EDR | EDR containment, identity disable | SOC |
| Microsoft Entra ID / Azure AD | Identity containment, password lifecycle | SOC / IAM |
| Microsoft Graph API | Identity containment, credential validation | SOC / IAM |
| VirusTotal | IOC / IP enrichment | SOC |
| Recorded Future | IOC / IP enrichment | SOC |
| Blink API | Internal deployment & onboarding ops | Other |
| Blink Tables | Customer registry, log pipeline state | Other |
E New Integrations (detail) 3 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| blumira-development | active-directory | active_directory_a31fbabf_248f_47bb_a7ea_ce38712b3104 | 2026-08-21 |
| blumira-development | active-directory | active_directory_8055b737_5acf_4236_a55a_7c16a95f7461 | 2026-08-21 |
| blumira-development | active-directory | active_directory_32cda33c_b961_405d_b4ef_8de974932851 | 2026-08-20 |