01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| MSSP Platform Operations & Customer Onboarding |
| 82.1% | 5 5 active |
| Playbook Deployment & Release Automation | 427 executions | 17.3% | 6 6 active |
| EDR Endpoint Containment |
| 0.1% | 3 3 active |
| Identity Threat Response |
| 0.4% | 6 6 active |
| Total | 2,462 executions | 100% | 20 20 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Production-scale multi-tenant MSSP architecture. The deployment model is architected for scale: a single master workspace manages provisioning and rollout to 558 customer workspaces, each with a consistent, standardized set of response playbooks. The automated onboarding pipeline (76 customers provisioned in 12 months) and hourly workspace sync demonstrate a mature, automated operations layer.
Dual-vector identity containment coverage. The identity response suite covers both cloud (Entra ID) and on-premises (Active Directory via LimaCharlie sensor) attack surfaces in a single coordinated playbook (disable_user_and_revoke_session_v4). This eliminates the risk of revoking cloud sessions while leaving on-prem credentials intact — a critical
gap in many MDR response programs.
EDR containment at machine speed. File deletion and process termination actions are wired directly to LimaCharlie's reliable task API, enabling sub-minute endpoint response across the entire customer base. These playbooks are deployed and armed in 558 customer environments.
Robust release engineering pipeline. The deployment automation (staging ingestion, multi-customer rollout, version overwrite, failure recovery) mirrors enterprise DevOps practices. This infrastructure enables Blumira to continuously improve and ship response playbooks across their entire customer base without manual per-workspace work.
Gaps & Opportunities
Response playbook activation rate is low relative to scale. 558 customer workspaces have response playbooks deployed, yet only a handful of EDR and identity containment actions have fired. Playbooks for entra_disable_user, limacharlie_disable_ad_user, and limacharlie_disable_local_user have zero executions. If these are expected to fire on detections, the integration wiring from Blumira's SIEM/detection layer into Blink should be reviewed.
No alert enrichment or IOC lookup automation. There are no workflows for threat intelligence enrichment, indicator lookups, or automated alert triage. Adding enrichment playbooks (VirusTotal, Shodan, threat intel feeds) before containment actions would improve decision quality and reduce false-positive containment.
No case management or ticketing integration. Containment actions fire silently — there is no SOAR-style case creation, ticket update (e.g., Jira, ServiceNow), or analyst notification wired to response outcomes. Adding post-action notifications and case updates would improve SOC visibility and audit trail.
Cloud security and vulnerability management are absent. No playbooks exist for CSPM triage, cloud misconfiguration remediation, or vulnerability scan ingestion. As Blumira expands its MDR offering, these are natural adjacencies.
Integration Ecosystem
| Integration | Usage |
|---|---|
| LimaCharlie EDR | Endpoint containment — file deletion, process termination, AD user disable, local user disable |
| Microsoft Entra ID / Azure AD | Cloud identity containment — user disable, session revocation |
| Active Directory (on-prem) | On-prem identity containment via LimaCharlie domain controller sensor |
| Blink Platform API | Cross-workspace orchestration — staging-to-production promotion, multi-customer deployment |
| Slack | Ops alerting — onboarding failure notifications |
| HTTP / REST | Internal data tables — customer registry, deployment logs, workspace inventory |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 4 use cases | 2,462 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Customer environments activated on the MDR platform | 76 | customer_blink_onboarding |
| Malicious files removed from customer endpoints | 14 | limacharlie_delete_file |
| Compromised accounts disabled and sessions terminated | 7 | disable_user_and_revoke_session_v4 |
| Active threat process trees terminated on endpoints | 3 | limacharlie_kill_process_tree |
| Malicious processes terminated on customer endpoints | 1 | limacharlie_kill_process |
| Entra ID sessions force-revoked for at-risk users | 3 | entra_revoke_session |
Use Case Summary
| # | Use Case | Category | Total Playbooks | Active (Executions > 0) |
|---|---|---|---|---|
| 1 | MSSP Platform Operations & Customer Onboarding | Other | 5 | 4 |
| 2 | Playbook Deployment & Release Automation | Other | 6 | 0 |
| 3 | EDR Endpoint Containment | SOC | 3 | 3 |
| 4 | Identity Threat Response | SOC | 6 | 2 |
| Total | 20 | 9 |
Use Cases
1. MSSP Platform Operations & Customer Onboarding
Description: Automates the full lifecycle of onboarding new customer environments onto the Blumira MDR platform. Each run provisions a new customer workspace in Blink, configures integrations, and validates credentials — turning a multi-step manual process into a single automated flow.
Business problem solved: Blumira delivers MDR services to hundreds of customers. Manual provisioning of each customer's Blink response environment is operationally expensive and error-prone. Automation ensures consistent, repeatable onboarding with built-in error alerting and real-time workspace inventory.
Taxonomy: Other → Customer registry & FinOps auto, SaaS / IT administration
| Playbook | Executions (12 mo) | Notes |
|---|---|---|
| customer_blink_onboarding | 76 | Top-level onboarding orchestrator; creates customer workspace, configures integrations |
| validate_credentials | 168 (182 instances) | Validates customer integration credentials; deployed per customer workspace |
| SCHEDULED Update Cust Workspaces Global Variable | 962 | Hourly scheduler that refreshes the live customer workspace inventory |
| Subflow - Update Customer Workspaces Global Variable | 961 | Subflow: fetches workspace records and updates the global variable |
| Customer Onboarding Failure Notification | 0 | Triggers on onboarding errors; sends Slack alert to ops team |
Key integrations: Blink platform API (cross-workspace), HTTP/REST (internal data tables), Slack
2. Playbook Deployment & Release Automation
Description: A CI/CD pipeline for managing the lifecycle of response playbooks across all 558+ customer workspaces. Covers ingestion of new playbooks from a staging environment, multi-tenant deployment (ad hoc or bulk), version management, and failure recovery.
Business problem solved: As Blumira develops and improves response playbooks, distributing updates to hundreds of customer workspaces manually is unsustainable. This pipeline automates promotion from staging to production, deployment to selected or all customers, and safe version overwriting — with error recovery to prevent partial deployments from leaving workspaces in an inconsistent state.
Taxonomy: Other → DevOps & release automation
| Playbook | Executions (12 mo) | Notes |
|---|---|---|
| Ingest Staging Push Request | 0 | Webhook-triggered; promotes a workflow from staging to production and submits for approval |
| Deploy - All Customers | 0 | Deploys a workflow version to every customer workspace |
| Deploy - Ad Hoc | 0 | Deploys a workflow to a targeted subset of customer workspaces |
| Deploy - Overwrite Existing Versions | 0 | Force-overwrites an already-deployed version across affected customer workspaces |
| Fail Forward - Workflow Deployment Ad Hoc | 0 | Retries and recovers failed deployments for individual customer workspaces |
| Mason_E2E_testing | 0 | End-to-end platform testing automation (9 test instances deployed) |
Key integrations: Blink platform API (staging and production cross-connect), HTTP/REST (deployment log tables)
3. EDR Endpoint Containment
Description: Automated endpoint response actions executed via LimaCharlie EDR on behalf of customer environments when threats are detected. Actions include terminating malicious processes and removing hostile files — all orchestrated without analyst intervention.
Business problem solved: When Blumira's detection engine identifies active malware or a compromised process on a customer endpoint, immediate containment is critical. These playbooks perform surgical EDR actions (file deletion, process termination) automatically and at machine speed, reducing dwell time and limiting blast radius before a human analyst reviews the incident.
Taxonomy: SOC → EDR containment & response
| Playbook | Executions (12 mo) | Deployed Instances | Notes |
|---|---|---|---|
| limacharlie_delete_file | 14 | 566 | Deletes a specified file from an endpoint via LimaCharlie reliable task |
| limacharlie_kill_process_tree | 3 | 566 | Terminates a full process tree on an endpoint (parent + child processes) |
| limacharlie_kill_process | 1 | 566 | Terminates a single process on an endpoint via LimaCharlie reliable task |
Key integrations: LimaCharlie EDR (sensor-level actions via reliable task API)
4. Identity Threat Response
Description: Automated identity containment actions covering both cloud identity (Microsoft Entra ID / Azure AD) and on-premises Active Directory via LimaCharlie's endpoint-resident sensor. Actions include disabling accounts, killing active sessions, and revoking cloud authentication tokens — all deployable across 558 customer workspaces.
Business problem solved: Identity-based attacks — account takeover, lateral movement via compromised credentials — require immediate containment. These playbooks automatically disable the compromised account and revoke all active sessions (cloud and on-prem) the moment a threat is confirmed, drastically cutting the window of attacker access without waiting for analyst intervention.
Taxonomy: SOC → Identity threat response
| Playbook | Executions (12 mo) | Deployed Instances | Notes |
|---|---|---|---|
| disable_user_and_revoke_session_v4 | 7 | 566 | Full containment: disables AD account via LimaCharlie sensor + revokes Entra session |
| entra_revoke_session | 3 | 567 | Revokes all active Microsoft Entra ID / Azure AD sessions for a user |
| entra_disable_user | 0 | 567 | Disables a user account in Entra ID; available, not yet activated |
| limacharlie_disable_ad_user | 0 | 566 | Disables an on-premises Active Directory user via LimaCharlie domain controller runner |
| limacharlie_disable_local_user | 0 | 567 | Disables a local system account on an endpoint via LimaCharlie sensor |
| disable_user_and_revoke_session | 0 | 1 | Prior version (v3); superseded by v4 |
Key integrations: Microsoft Entra ID / Azure AD (Graph API), LimaCharlie EDR (domain controller & endpoint sensor), Active Directory (on-prem via LimaCharlie reliable task)
Key Observations
Strengths
Production-scale multi-tenant MSSP architecture. The deployment model is architected for scale: a single master workspace manages provisioning and rollout to 558 customer workspaces, each with a consistent, standardized set of response playbooks. The automated onboarding pipeline (76 customers provisioned in 12 months) and hourly workspace sync demonstrate a mature, automated operations layer.
Dual-vector identity containment coverage. The identity response suite covers both cloud (Entra ID) and on-premises (Active Directory via LimaCharlie sensor) attack surfaces in a single coordinated playbook (disable_user_and_revoke_session_v4). This eliminates the risk of revoking cloud sessions while leaving on-prem credentials intact — a critical gap in many MDR response programs.
EDR containment at machine speed. File deletion and process termination actions are wired directly to LimaCharlie's reliable task API, enabling sub-minute endpoint response across the entire customer base. These playbooks are deployed and armed in 558 customer environments.
Robust release engineering pipeline. The deployment automation (staging ingestion, multi-customer rollout, version overwrite, failure recovery) mirrors enterprise DevOps practices. This infrastructure enables Blumira to continuously improve and ship response playbooks across their entire customer base without manual per-workspace work.
Gaps & Opportunities
Response playbook activation rate is low relative to scale. 558 customer workspaces have response playbooks deployed, yet only a handful of EDR and identity containment actions have fired. Playbooks for entra_disable_user, limacharlie_disable_ad_user, and limacharlie_disable_local_user have zero executions. If these are expected to fire on detections, the integration wiring from Blumira's SIEM/detection layer into Blink should be reviewed.
No alert enrichment or IOC lookup automation. There are no workflows for threat intelligence enrichment, indicator lookups, or automated alert triage. Adding enrichment playbooks (VirusTotal, Shodan, threat intel feeds) before containment actions would improve decision quality and reduce false-positive containment.
No case management or ticketing integration. Containment actions fire silently — there is no SOAR-style case creation, ticket update (e.g., Jira, ServiceNow), or analyst notification wired to response outcomes. Adding post-action notifications and case updates would improve SOC visibility and audit trail.
Cloud security and vulnerability management are absent. No playbooks exist for CSPM triage, cloud misconfiguration remediation, or vulnerability scan ingestion. As Blumira expands its MDR offering, these are natural adjacencies.
Integration Ecosystem
| Integration | Usage |
|---|---|
| LimaCharlie EDR | Endpoint containment — file deletion, process termination, AD user disable, local user disable |
| Microsoft Entra ID / Azure AD | Cloud identity containment — user disable, session revocation |
| Active Directory (on-prem) | On-prem identity containment via LimaCharlie domain controller sensor |
| Blink Platform API | Cross-workspace orchestration — staging-to-production promotion, multi-customer deployment |
| Slack | Ops alerting — onboarding failure notifications |
| HTTP / REST | Internal data tables — customer registry, deployment logs, workspace inventory |
E New Integrations (detail) 17 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| blumira-production | active-directory | active_directory_05b86b85_6024_4128_a694_a7dc2d43b83c | 2026-09-09 |
| blumira-production | active-directory | active_directory_369258dc_75c2_4aa7_a4a4_f9ffb5af3efe | 2026-09-08 |
| blumira-production | active-directory | active_directory_953373d4_008d_436b_8ba4_e354ae8fece0 | 2026-09-01 |
| blumira-production | active-directory | active_directory_9e542b25_4c34_48ce_8f18_17bf24a83a11 | 2026-08-28 |
| blumira-production | active-directory | active_directory_ea66909a_7761_4b89_8cbb_c782eede5480 | 2026-08-27 |
| blumira-production | active-directory | active_directory_ae2b14c4_b191_4577_8176_a458317a7600 | 2026-08-26 |
| blumira-production | active-directory | active_directory_0e4e29d2_d435_4146_bf06_27cd9bce8ce6 | 2026-08-23 |
| blumira-production | active-directory | active_directory_d4b44f74_b1b0_472d_a869_ba82fef61452 | 2026-08-23 |
| blumira-production | active-directory | active_directory_fff02da6_7661_434d_9f83_9660f330ff2e | 2026-08-23 |
| blumira-production | active-directory | active_directory_ccc873ac_db1a_4c02_9914_3cc3d51581f8 | 2026-08-23 |
| blumira-production | active-directory | active_directory_2ee4a2cb_e670_4946_a85d_e841b4ae9094 | 2026-08-20 |
| blumira-production | active-directory | active_directory_07854c6f_50d4_4565_8284_5a16544797aa | 2026-08-17 |
| blumira-production | active-directory | active_directory_47825bf4_8a5b_47ed_83c2_9026ad2d951e | 2026-08-17 |
| blumira-production | active-directory | active_directory_660ee8fb_960c_4f72_a027_a69631618e98 | 2026-08-17 |
| blumira-production | active-directory | active_directory_09a45435_5266_49ff_b6a8_dc6b764f1459 | 2026-08-17 |
| blumira-production | active-directory | active_directory_1f70bbe5_3561_41b3_819c_153331170b8c | 2026-08-13 |
| blumira-production | active-directory | active_directory_a811a0c5_e599_4624_9d49_710667103d8b | 2026-08-13 |