Blink Security Automation — Confidential

buckle — Customer Success Report

Generated 2026-09-10 | buckle-value-report.md
2026-09-10Report Date
407Total Playbooks
124Unique Workflows (12m)
827,040Actions Automated (12m)
$212,716Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

407
Total playbooks built
all non-deleted workflows
300
Active playbooks
currently enabled
124
Unique workflows executed (12m)
distinct workflows that ran
827,040
Actions automated (12m)
completed action steps
4,594.7h
Hours saved (12m)
@ 20s per action
$212,716
Money saved (12m)
@ $100K avg salary
45
New active workflows (last 30d)
recently created & enabled
988
Total cases managed
988 opened in last 12m
2d 22h
MTTR — mean time to resolve
closed cases, last 12m
6
Active AI agents
of 12 total
158
AI agent tasks executed (12m)
3 in last 30d
In the last 12 months, Blink automated: - 2,390 SIEM alerts auto-ingested and routed from LogRhythm - 1,944 vulnerable-password incidents detected and automatically remediated - 800 SOC alerts processed end-to-end — observables extracted, enriched, deduplicated, and routed for response - 597 privileged-account status checks performed automatically during alert response - 446 case closures automatically synced back to source detection tools - 431 Microsoft Defender alerts auto-triaged without analyst intervention - 372 account takeover incidents investigated and contained automatically - 251 user password resets automatically executed, with forced reset enforced on next login - 59 third-party CrowdStrike alerts auto-ingested and routed via webhook - 53 scheduled traveling-user access expiration jobs enforced (CA014 conditional access policy) - 47 Fastly WAF allowlist and IP-list updates applied on-demand via Slack - 35 lateral movement detections automatically investigated and contained

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
LogRhythm SIEM Ingestion & Automated Response
  • 2,390SIEM alerts auto-ingested and routed from LogRhythm
  • 1,944Vulnerable-password incidents detected and auto-remediated
  • 119LogRhythm alert drilldown fields enriched
6.5%
4
4 active
Agentic SOC — Multi-Source Alert Processing & Case Management
  • 800SOC alerts processed end-to-end (extract, enrich, deduplicate, respond)
  • 699Automated alert response routings dispatched
  • 597Privileged-account status checks performed during automated alert response
73.5%
13
12 active
Alert Enrichment & IOC Lookup175 executions
0.4%
21
21 active
Account Takeover & Identity Threat Investigation
  • 29Ad-hoc MFA verification prompts sent to users
  • 16AD department directory lookups performed for user investigations and audits
  • 9Device lookups performed via Microsoft Graph/Intune for endpoint support and investigation
0.4%
44
42 active
EDR Containment & Identity Lockdown272 executions
0.7%
13
13 active
WAF & Web Filtering Policy Management
  • 47Fastly WAF allowlist and IP-list updates applied via Slack
0.1%
6
4 active
JIT Temporary Access — Conditional Access Exception (CA014)
  • 53Scheduled traveling-user access expiration jobs enforced (CA014)
  • 3Users added to CA014 travel exception group
0.1%
3
2 active
Identity Lifecycle & Employee Provisioning0 executions
0.0%
19
19 active
Email Notification Delivery0 executions
0.0%
2
2 active
Total32,550 executions100%
125
119 active

Use Case Growth Over Time

251 unique playbooks  |  9 operational use cases  |  39,826 total executions (12m)  |  2024-09 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
Google Workspace GitHub Microsoft Entra ID CrowdStrike Okta URLScan Slack VirusTotal Abnormal
EDR Containment & Identity Lockdown
CrowdStrike Slack Microsoft Entra ID Active Directory On-Prem
LogRhythm SIEM Ingestion & Automated Response
Email CrowdStrike LogRhythm Slack Cribl
WAF & Web Filtering Policy Management
Slack Microsoft Entra ID Microsoft Graph
Account Takeover & Identity Threat Investigation
Microsoft Entra ID Agents Slack Microsoft Graph Active Directory On-Prem Microsoft Intune Email
Identity Lifecycle & Employee Provisioning
UKG Pro HCM Microsoft Entra ID Slack LDAP Active Directory On-Prem Microsoft Teams Email Dashboards
JIT Temporary Access — Conditional Access Exception (CA014)
Microsoft Entra ID Slack
Agentic SOC — Multi-Source Alert Processing & Case Management
CrowdStrike LogRhythm Microsoft Defender XDR Vectra Detect Microsoft Entra ID Abnormal
Email Notification Delivery
Email Slack

04Key Observations

✓  Strengths

Strengths

Deep, production-grade SOAR platform. The LogRhythm + Blink Case Management stack is the clearest indicator of mature automation: 2,390 SIEM events ingested, 1,944 vulnerability responses executed, and 800 alerts processed through a full extract-enrich-deduplicate-respond pipeline. This is not exploratory automation — it is core SOC infrastructure.

Multi-source EDR integration running at scale. CrowdStrike (Falcon webhook) and Microsoft Defender (polling, every 5 minutes) feed into the same SOAR pipeline, giving a unified case management view across both EDR products. The 446 case closures synced back to source tools confirm the bidirectional integration loop is closed.

Account takeover response is the heaviest automated response path. 372 ATO incident responses were dispatched through the automated response router, each triggering IP geolocation (IPWhois), user login history retrieval, and NIC history lookups — indicating the ATO playbook is the primary threat scenario being actioned at scale.

WAF management via Slack is a genuine force multiplier. 47 Fastly NGWAF allowlist and IP-list changes were applied on-demand through a Slack-triggered workflow with built-in IP validation. This gives tier-1 staff the ability to make controlled WAF changes during incidents without console access.

MFA-gated containment is built and ready. Every endpoint isolation playbook (isolate by username, hostname, device ID) requires MFA confirmation via Entra before executing — a security control that prevents misuse. These playbooks have 0 executions, meaning the capability exists as a rapid-response tool that has not yet been needed in production.

CA014 JIT access runs autonomously. The traveling-user exception workflow — web form intake, group membership, nightly expiration — ran 40 times in 12 months with no IT intervention. The lifecycle is fully self-contained.

Password reset automation scaled sharply. A newly deployed instance of Reset Password + force reset on next login accounted for 242 of the 251 combined executions across all three workspace instances of this playbook — making credential reset one of the highest-volume identity remediation actions on the platform, alongside the LogRhythm vulnerable-password response path.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Phishing and malware response playbooks are built but inactive. Both Response Subflow — Phishing and Response Subflow — Malware have 0 executions despite being wired into the SOAR router. If phishing/malware alerts are reaching the platform, the alert template mappings may not be routing to these playbooks. If they are not reaching the platform, there is an untapped ingestion opportunity (e.g., ProofPoint, MSFT Defender for Office 365).

Enrichment library has broad coverage but low utilization for non-Whois sources. The enrichment library spans VirusTotal, AbuseIPDB, URLScan, Okta, Google Workspace, and GitHub — but these all show 0 executions. Only Whois (36 execs), Microsoft Entra ID (62 execs), CrowdStrike (9 execs), and IPWhois (372 execs) are active. Expanding the observable extraction templates to include URL and hash types would activate the existing VirusTotal and URLScan playbooks automatically.

UKG-driven employee lifecycle automation has not yet launched. The full UKG Pro HCM → Entra ID pipeline now spans both onboarding (hire date trigger, email check, account creation, manager assignment, group provisioning) and offboarding (termination trigger, group snapshot, account disable, session revocation), but all of these playbooks still show 0 executions. Activating this would eliminate manual account creation and deactivation steps across IT and HR.

Endpoint isolation capability exists but has not been needed. The 14-playbook EDR containment toolkit (with MFA gating, Slack confirmation, and multi-vector isolation) represents a mature IR capability. With 0 executions, it either reflects a low-compromise environment or a workflow not yet integrated into the SOC's incident response runbook. Wiring it into the SOAR response router for lateral movement and ATO cases would automate containment that currently requires manual CrowdStrike console actions.

Agentic user risk assessment is growing but still underused relative to alert volume. The Blink AI Agent ("Risky Ricky") now appears in three playbooks (two Help Desk lockout assessments, Determine User risk) totaling 4 production executions. With 2,390 LogRhythm events and 372 ATO responses running through the platform, adding AI-assisted risk scoring to the ATO response path would significantly improve triage quality at scale.

Integration Ecosystem

Category Integrations
SIEM / Logging LogRhythm
EDR CrowdStrike Falcon
SIEM / XDR Microsoft Defender for Endpoint, Microsoft XDR
Identity Microsoft Entra ID, Active Directory (on-prem via LDAP/WinRM), Okta
Threat Intel VirusTotal, AbuseIPDB, URLScan, IPWhois.io
Email Security Abnormal Security
Web Security Fastly NGWAF, Zscaler ZIA
HRIS UKG Pro HCM
Communication Slack
Email On-prem SMTP relay
Cloud Identity Microsoft Graph, Google Workspace, GitHub
Case Management Blink Case Management (native)
Network Tools WhoIs (bash), Dig (bash), PowerShell (WinRM)
AI / Agents Blink AI Agents (Risky Ricky — user risk reviewer)
Appendices
A Case Management 988 cases (12m) | MTTR 2d 22h

Case Management

Total Cases (all-time)
988
988 opened in last 12m
Cases Opened (30d)
107
95 closed in last 30d
Cases Closed (12m)
972
of 988 opened
MTTR
2d 22h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management 984 984 972 2d 22h
POC Workspace 4 4 0 N/A
B AI Agents 6 active | 158 tasks (12m)

AI Agents

Active Agents
6
of 12 total
Tasks Executed (12m)
158
3 in last 30d
Data Usage (12m)
7,791,032
192,194 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Risky Ricky phil.brader@buckle.com 67 1 2,687,035
2 Risky Ricky Infosec - Production 51 0 2,797,467
3 Agent Risky Ricky Corporate IT Helpdesk 24 2 1,595,699
4 Risky Ricky POC Workspace 12 0 621,724
5 Arnold phil.brader@buckle.com 3 0 59,482
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
phil.brader@buckle.com70
Infosec - Production51
Corporate IT Helpdesk25
POC Workspace12
Case Management0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
4
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Case Management 00
2 Case Dashboard 00
3 HelpDesk Usage 00
4 Identity Lifecycle Command Center 00

Webforms

Forms
4
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Traveling User: Add user with UPN. you must also include start and end dates of Travel. User will be removed at midnight on the last day of travel. 00
2 Traveling User: Add user with UPN. you must also include start and end dates of Travel. User will be removed at midnight on the last day of travel. 00
3 New User Onboarding Demo 00
4 Traveling User: Add user with UPN. You must include start and end dates of Travel. User will be added to the CA014 conditional exception group and then removed at midnight on the last day of travel. 00
D Full Use Case Analysis 9 use cases | 39,826 executions (12m)

Business KPIs

Metric Count Playbook
SIEM alerts auto-ingested and routed from LogRhythm 2,390 Ingested Message from LogRhythm
Vulnerable-password incidents detected and auto-remediated 1,944 LogRhythm — User with vulnerable password found
SOC alerts processed end-to-end (extract, enrich, deduplicate, respond) 800 Process Alert
Automated alert response routings dispatched 699 Subflow — Response Main Router
Privileged-account status checks performed during automated alert response 597 Check if UPN is privileged account
Cases closed and synced back to source tools 446 Close Alerts in External Tools
Microsoft Defender alerts auto-triaged and routed 431 Defender Alerts
Account takeover incidents investigated and contained 372 Response Subflow — ATO
User password resets executed with forced reset enforced on next login 251 Reset Password + force reset on next login, Reset Password + force reset on next login, Reset Password + force reset on next login, Reset Password + force reset on next login
Observables automatically enriched across threat intel sources 130 Subflow — Enrich Observables Main Router
LogRhythm alert drilldown fields enriched 119 Enrich LogRhythm Drilldown field
Missing alert template notifications dispatched to team 100 Subflow — Missing Alert Template Notification
Third-party CrowdStrike alerts auto-ingested and routed via webhook 59 Third Party Alerts via CS
Scheduled traveling-user access expiration jobs enforced (CA014) 53 Scheduled: Remove user from CA014, Scheduled: Remove user from CA014
CrowdStrike endpoint detections automatically ingested 51 Crowdstrike Ingestion
Fastly WAF allowlist and IP-list updates applied via Slack 47 Update Fastly Allowlist, Update Fastly NG WAF Corp IP list, Update Fastly NG WAF Allowlist
Lateral movement detections responded to 35 Response Subflow — Lateral Movement
Ad-hoc MFA verification prompts sent to users 29 Send Ad-Hoc Entra MFA prompt via UPN, Send Ad-Hoc Entra MFA prompt via UPN
AD department directory lookups performed for user investigations and audits 16 List all users in a department
Device lookups performed via Microsoft Graph/Intune for endpoint support and investigation 9 Device Information
Cribl search job results compiled into CSV reports and emailed 9 Cribl report sender, Cribl report sender
Password reset emails sent to users on demand 6 Send password reset email
Identity investigation searches performed via Microsoft Graph (ASN, service principal, OAuth grants) 6 Search by ASN, Search for activity on a service principal, Search oauth grants by user
Full AD user-attribute retrievals performed for investigation and support 5 List All of a User Attributes from AD
Account lockouts resolved via automated AD unlock 4 Unlock User in AD
User-registered device inventories retrieved for identity investigation 4 Get Users Registered Devices
Users added to CA014 travel exception group 3 Add User to Travel Exception
Sign-in logs retrieved for users blocked by a Conditional Access Policy 1 Get users blocked by a CAP last 12 hours
In the last 12 months, Blink automated: - 2,390 SIEM alerts auto-ingested and routed from LogRhythm - 1,944 vulnerable-password incidents detected and automatically remediated - 800 SOC alerts processed end-to-end — observables extracted, enriched, deduplicated, and routed for response - 597 privileged-account status checks performed automatically during alert response - 446 case closures automatically synced back to source detection tools - 431 Microsoft Defender alerts auto-triaged without analyst intervention - 372 account takeover incidents investigated and contained automatically - 251 user password resets automatically executed, with forced reset enforced on next login - 59 third-party CrowdStrike alerts auto-ingested and routed via webhook - 53 scheduled traveling-user access expiration jobs enforced (CA014 conditional access policy) - 47 Fastly WAF allowlist and IP-list updates applied on-demand via Slack - 35 lateral movement detections automatically investigated and contained

Use Case Summary

# Use Case Category Subcategories Playbooks Executions (12 mo)
1 LogRhythm SIEM Ingestion & Automated Response SOC SIEM & log pipeline monitoring, Case mgmt & SOAR 6 4,462
2 Agentic SOC — Multi-Source Alert Processing & Case Management SOC Case mgmt & SOAR, Agentic SOC, EDR containment & response, Identity threat response 32 3,811
3 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 35 563
4 Account Takeover & Identity Threat Investigation SOC Identity threat response, Agentic SOC 74 433
5 EDR Containment & Identity Lockdown SOC EDR containment & response, Identity threat response 14 0
6 WAF & Web Filtering Policy Management Cloud Security Cloud access & SaaS policy mgmt 9 47
7 JIT Temporary Access — Conditional Access Exception (CA014) IAM JIT & temporary access 4 56
8 Identity Lifecycle & Employee Provisioning IAM Employee onboarding, Employee offboarding, Identity lifecycle automation 21 0
9 Email Notification Delivery Other SaaS / IT administration 3 0
Total 198 9,372

Use Cases

1. LogRhythm SIEM Ingestion & Automated Response

Description: Ingests every alert fired from LogRhythm via webhook, enriches each event's drilldown fields against Microsoft Entra ID, CrowdStrike, and Okta, and auto-executes response playbooks (e.g., forced password reset for vulnerable-credential detections) — all without analyst touch.

Business problem solved: LogRhythm generates high-alert volume that previously required manual triage; Blink intercepts every event, enriches it in real time, and acts on high-confidence detections automatically.

Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR

Key integrations: LogRhythm (webhook), Microsoft Entra ID, CrowdStrike, Okta, Microsoft Graph, WinRM (AD password reset)

Playbook Executions (12 mo)
Ingested Message from LogRhythm 2,390
LogRhythm — User with vulnerable password found 1,944
Enrich LogRhythm Drilldown field 119
Log message to Cribl 0
Cribl report sender 7
Cribl report sender 2

2. Agentic SOC — Multi-Source Alert Processing & Case Management

Description: A full Blink-native SOAR platform that ingests alerts from CrowdStrike and Microsoft Defender, extracts and deduplicates observables, enriches IOCs across threat intel sources, routes each alert to the appropriate response playbook (ATO, lateral movement, phishing, malware), and syncs case closures back to source tools — running continuously on a 1-minute polling interval.

Business problem solved: The security team needed a vendor-agnostic case management and response orchestration layer that ties together CrowdStrike, Defender, and LogRhythm signals without relying on a dedicated SIEM-native SOAR product.

Category: SOC | Subcategories: Case mgmt & SOAR, Agentic SOC, EDR containment & response, Identity threat response

Key integrations: CrowdStrike, Microsoft Defender/XDR, Microsoft Entra ID, Microsoft Outlook, Slack, Blink Case Management

Playbook Executions (12 mo)
Process Alert 800
Subflow — Response Main Router 699
Close Alerts in External Tools 446
Defender Alerts 431
Response Subflow — ATO 372
Subflow — Enrich Observables Main Router 130
Subflow — Missing Alert Template Notification 100
Subflow — Update Enrichment Data 58
Third Party Alerts via CS 59
Crowdstrike Ingestion 51
Response Subflow — Lateral Movement 35
Enrich Cases with Observable Data as Cards 11
Attach CS Host info to Case 13
Get/Create Observable ID 7
Attach IP's whois info to case 1
Response Subflow — Phishing 0
Response Subflow — Malware 0
Table Action — Validate Observables Extraction Template 0
Attach User's recent Entra logins to case 0
Attach Hostname's NIC History to Case 0
Recovery — Handle Unprocessed Alerts 0
Recovery — Enrich Non-Enriched Observables 0
Utility — Close Stale Cases 0
Utility — Find Similar Cases Based on Observables 0
Utility — List Alert Observable Relations 0
Utility — List Observable Alert Relations 0
Utility — Set Or Update Observable Relation 0
Utility — Delete Observable Relation 0
Utility — Update Enrichment 0
Check if UPN is privileged account 597
Check if UPN is privileged account 0
receive_cs_webhook_to_update_case 1

3. Alert Enrichment & IOC Lookup

Description: A library of on-demand enrichment playbooks that automatically look up every observable type (IP, hash, URL, email, username, domain, agent ID, hostname) across a wide array of threat intelligence and identity sources. These playbooks are called by the SOAR engine during alert processing and are also available standalone.

Business problem solved: Manually cross-referencing observables across eight or more tools during triage added hours per incident; this library enables instant, automated enrichment of every observable the moment it enters a case.

Category: SOC | Subcategories: Alert enrichment / IOC lookup

Key integrations: CrowdStrike, VirusTotal, AbuseIPDB, URLScan, WhoIs (bash), IPWhois.io, Microsoft Entra ID, Okta, Google Workspace, GitHub, Slack, Dig (bash), Abnormal Security

Playbook Executions (12 mo)
IPWhois.io — Single IP Lookup 372
Enrich — IP or Domain — Whois 18
Enrich IP or Domain Using Whois 18
Get User Information Using Microsoft Entra ID 31
Enrich — Username or Email — Microsoft Entra ID 31
Retrieve NIC History by deviceID 43
Retrieve Host Information by deviceID 11
Retrieve User Login History by deviceID 11
Enrich — Hash — Crowdstrike 7
Enrich - Abnormal 7
Enrich — Agent ID — Crowdstrike 2
Get Device ID via hostname 1
Enrich — Hash — VT 0
Enrich — IP — IPDB 0
Enrich — IP — VT 0
Enrich — URL — VT 0
Enrich — URL — URLScan 0
Enrich — Username or Email — Okta 0
Enrich — Username or Email — Google Workspace 0
Enrich — Username — Github 0
Enrich — Email Address — Slack 0
Get User Information Using Google Workspace 0
Get User Information Using Github 0
Get User Information Using Okta 0
Get User Information on Email Address Using Slack 0
Get Hash Info Using VirusTotal 0
Get Hash Info Using Crowdstrike 0
Analyze URL with URLScan 0
Okta Search for User Activity 0
Get End of Life Date for a Product 0
Secure URL Screenshot Capture 0
Retrieve NIC History by Hostname 0
Retrieve Host Information by Hostname 0
Retrieve User Login History by Hostname 0
Run Dig Command 0

4. Account Takeover & Identity Threat Investigation

Description: An analyst-facing toolkit for investigating suspected account compromises, including AI-assisted user risk assessment (Blink AI Agent "Risky Ricky"), ad-hoc MFA challenges sent via Entra, login history retrieval, and a Slack-native help-desk integration for real-time lockout triage.

Business problem solved: Help desk staff and security analysts needed a fast, structured way to assess whether a locked-out or suspicious user account represented a genuine compromise versus a benign lockout — without pulling data from multiple consoles manually.

Category: SOC | Subcategories: Identity threat response, Agentic SOC

Key integrations: Microsoft Entra ID, Microsoft Graph, Slack, Blink AI Agents, PowerShell/WinRM, Okta

Playbook Executions (12 mo)
Send Ad-Hoc Entra MFA prompt via UPN 24
Send Ad-Hoc Entra MFA prompt via Email 24
Get UPN from email address 24
Get Entra TAP for a User 11
Reset Password + force reset on next login 9
Find Group by Name 8
Entra Login details 6
List Users Entra Auth Methods 5
Send Ad-Hoc Entra MFA prompt via UPN 5
Unlock User in AD 4
Help Desk - User Lockout Risky User Assessment 3
User MFA Check 2
Get TAP from Entra 2
Help Desk — User Lockout Risky User Assessment 1
Login details 1
More user details 0
Slack: Help Desk — User Lockout Risky User Assessment 0
Determine User risk 0
Get UPN's recent login activity 0
Get User AD Groups 0
Get User Groups from UPN 0
Translate Email to UPN 0
Helpdesk 0
Send Ad-Hoc Entra MFA prompt via UPN 0
List all users in a department 16
Device Information 9
List All of a User Attributes from AD 5
Get Users Registered Devices 4
List Users Information From Entra 3
Get email addresses of users in Entra Group 3
List AD Groups for user 2
List Entra Groups for user 1
Retrieve device information and Bitlocker Key 1
List Users Entra License 1
Get email addresses of users in Entra Group 0
Get user licenses 0
Enroll Ipad in Intune 0
List Risky Users 0
Reset Password + force reset on next login 242
Laps Password for Device 4
List Entra Groups for user 0
Device Information 0
List Users Information From Entra 0
List Users AD Groups 0
List all users in a department 0
List Risky Users 0
Help Desk - User Lockout Risky User Assessment 0
List User Groups from UPN 0
Unlock User in AD 0
List All of a User Attributes from AD 0
List Users Entra Auth Methods 0
Retrieve device information and Bitlocker Key 0
Get Entra TAP for a User 0
Entra Login details 0
Get Users Registered Devices 0
List Users Entra License 0
List AD Groups for user 0
Laps Password for Device 0
Find Group by Name 0
Enroll Ipad in Intune 0
Send password reset email 0
Assign user to a Device 0
Send password reset email 6
Reset Password + force reset on next login 0
List Users Information From Entra 0
List Users Entra Auth Methods 0
List Users Entra License 0
Interactive Agent 0
Dismiss Risky user status 0
Search by ASN 1
Search for activity on a service principal 2
Search oauth grants by user 3
Get users blocked by a CAP last 12 hours 1
Delete users MFA devices registered in last 5 days 0

5. EDR Containment & Identity Lockdown

Description: A complete endpoint containment toolkit built on CrowdStrike Falcon RTR, supporting endpoint isolation and de-isolation by username, hostname, device ID, or transaction ID — with MFA-gated confirmation via Slack before any destructive action. Also includes identity lockdown capabilities (disable account, reset password, revoke sessions) for use during active incidents.

Business problem solved: Incident responders needed a repeatable, auditable, MFA-protected workflow for isolating compromised endpoints across the retail environment without direct CrowdStrike console access during fast-moving incidents.

Category: SOC | Subcategories: EDR containment & response, Identity threat response

Key integrations: CrowdStrike Falcon, Microsoft Entra ID, Slack, WinRM (AD operations)

Playbook Executions (12 mo)
Isolate hosts via username 0
Isolate Hosts via Hostname 0
Isolate host via DeviceID 0
Remove Isolation via DeviceID 0
Remove Isolation via Hostname 0
Remove Isolation via Username 0
Remove Isolation via transaction ID 0
CrowdStrike RTR to a Single Host 0
CrowdStrike RTR to a Batch of Hosts 0
Manage Endpoint Quarantine Status in Crowdstrike 0
Crowdstrike — Setup Pentera Exclusions 0
Disable User Access 0
Restore User Access 0
Reset Password + force reset on next login 0

6. WAF & Web Filtering Policy Management

Description: On-demand and Slack-triggered workflows that allow the security team to update Fastly NGWAF allowlists (corp-level and site-level) and manage Zscaler ZIA URL blocklists — with IP validation built in before any change is committed.

Business problem solved: Security engineers needed a safe, auditable way to update WAF allowlists for legitimate business traffic (e.g., POS systems, traveling staff) and block malicious URLs during active incidents, without granting direct console access to tier-1 responders.

Category: Cloud Security | Subcategories: Cloud access & SaaS policy mgmt

Key integrations: Fastly NGWAF, Zscaler ZIA, Slack

Playbook Executions (12 mo)
Update Fastly Allowlist 26
Update Fastly NG WAF Corp IP list 13
Update Fastly NG WAF Allowlist 8
Update Fastly NG WAF Site Allowlist 0
Get Fastly NGWAF Corps 0
Get Fastly NGWAF Sites 0
Add URL to Blocklist — Zscaler Three 0
Remove URL from Blocklist — Zscaler Three 0
Activate ZIA Changes — Zscaler Three 0

7. JIT Temporary Access — Conditional Access Exception (CA014)

Description: A self-service web form allows authorized users to request temporary exemption from Conditional Access policy CA014 for a specific travel window; the user is automatically added to the exception group and a nightly scheduled job removes them at midnight on the last day of travel.

Business problem solved: Traveling employees frequently triggered CA014 blocks when authenticating from non-standard locations, requiring manual IT intervention; this process automates the full request-to-expiration lifecycle with zero IT involvement.

Category: IAM | Subcategories: JIT & temporary access

Key integrations: Microsoft Entra ID, Slack, Blink Tables, Blink Web Form

Playbook Executions (12 mo)
Scheduled: Remove user from CA014 40
Add User to CA014 0
Add User to Travel Exception 3
Scheduled: Remove user from CA014 13

8. Identity Lifecycle & Employee Provisioning

Description: End-to-end employee lifecycle management driven by UKG Pro HCM: retrieves new-hire and termination records, checks email address availability in Entra ID, creates Entra admin accounts with manager assignment, provisions and deprovisions group memberships, disables accounts and revokes sessions on departure, and syncs user attribute changes (department, title, manager) through LDAP and WinRM.

Business problem solved: IT operations needed to eliminate manual account creation and deactivation steps for new hires, internal transfers, and departures, reducing provisioning/deprovisioning time and ensuring attribute and access consistency across on-prem Active Directory, Entra ID, and HR records.

Category: IAM | Subcategories: Employee onboarding, Employee offboarding, Identity lifecycle automation

Key integrations: UKG Pro HCM, Microsoft Entra ID, Microsoft Graph, LDAP, WinRM, Slack

Playbook Executions (12 mo)
UKG Pro — Get Users by Last Hire Date 0
UKG New Hire to User Creation Subflow 0
Entra Admin Account Creation 0
Azure Email Check — Blink Copy 0
User update Manager 0
UKG Integration Tests 0
Provision Employee From UKG 0
Deprovision Employee 0
Activate Started Employee 0
Admin Seed Identity Lifecycle Tables 0
Example 3: Subflow - Create user in local AD 0
Refresh Identity Dashboard 0
Sync UKG Employee Changes 0
Update UKG Contact Info 0
Assign Groups From Mapping 0
Deprovision Entra ID Account 0
Find Entra Account and Suggest Username 0
Get Employee From UKG Pro 0
Get Lifecycle Status 0
Provision Entra ID Account 0
Write Contact Info Back To UKG 0

9. Email Notification Delivery

Description: An on-demand utility that sends HTML-formatted email content through the organization's on-premises SMTP relay, supporting configurable sender, recipient, and subject parameters with file-based HTML content.

Business problem solved: Other automations and manual processes needed a standardized way to deliver formatted HTML reports and notifications through the internal mail relay without duplicating SMTP logic in every playbook.

Category: Other | Subcategories: SaaS / IT administration

Key integrations: On-prem SMTP server

Playbook Executions (12 mo)
Send html email file via on-prem SMTP server 0
Send html email file via on-prem SMTP server 0
Notify On-Call Infosec Analyst 0

Key Observations

Strengths

Deep, production-grade SOAR platform. The LogRhythm + Blink Case Management stack is the clearest indicator of mature automation: 2,390 SIEM events ingested, 1,944 vulnerability responses executed, and 800 alerts processed through a full extract-enrich-deduplicate-respond pipeline. This is not exploratory automation — it is core SOC infrastructure.

Multi-source EDR integration running at scale. CrowdStrike (Falcon webhook) and Microsoft Defender (polling, every 5 minutes) feed into the same SOAR pipeline, giving a unified case management view across both EDR products. The 446 case closures synced back to source tools confirm the bidirectional integration loop is closed.

Account takeover response is the heaviest automated response path. 372 ATO incident responses were dispatched through the automated response router, each triggering IP geolocation (IPWhois), user login history retrieval, and NIC history lookups — indicating the ATO playbook is the primary threat scenario being actioned at scale.

WAF management via Slack is a genuine force multiplier. 47 Fastly NGWAF allowlist and IP-list changes were applied on-demand through a Slack-triggered workflow with built-in IP validation. This gives tier-1 staff the ability to make controlled WAF changes during incidents without console access.

MFA-gated containment is built and ready. Every endpoint isolation playbook (isolate by username, hostname, device ID) requires MFA confirmation via Entra before executing — a security control that prevents misuse. These playbooks have 0 executions, meaning the capability exists as a rapid-response tool that has not yet been needed in production.

CA014 JIT access runs autonomously. The traveling-user exception workflow — web form intake, group membership, nightly expiration — ran 40 times in 12 months with no IT intervention. The lifecycle is fully self-contained.

Password reset automation scaled sharply. A newly deployed instance of Reset Password + force reset on next login accounted for 242 of the 251 combined executions across all three workspace instances of this playbook — making credential reset one of the highest-volume identity remediation actions on the platform, alongside the LogRhythm vulnerable-password response path.

Gaps & Opportunities

Phishing and malware response playbooks are built but inactive. Both Response Subflow — Phishing and Response Subflow — Malware have 0 executions despite being wired into the SOAR router. If phishing/malware alerts are reaching the platform, the alert template mappings may not be routing to these playbooks. If they are not reaching the platform, there is an untapped ingestion opportunity (e.g., ProofPoint, MSFT Defender for Office 365).

Enrichment library has broad coverage but low utilization for non-Whois sources. The enrichment library spans VirusTotal, AbuseIPDB, URLScan, Okta, Google Workspace, and GitHub — but these all show 0 executions. Only Whois (36 execs), Microsoft Entra ID (62 execs), CrowdStrike (9 execs), and IPWhois (372 execs) are active. Expanding the observable extraction templates to include URL and hash types would activate the existing VirusTotal and URLScan playbooks automatically.

UKG-driven employee lifecycle automation has not yet launched. The full UKG Pro HCM → Entra ID pipeline now spans both onboarding (hire date trigger, email check, account creation, manager assignment, group provisioning) and offboarding (termination trigger, group snapshot, account disable, session revocation), but all of these playbooks still show 0 executions. Activating this would eliminate manual account creation and deactivation steps across IT and HR.

Endpoint isolation capability exists but has not been needed. The 14-playbook EDR containment toolkit (with MFA gating, Slack confirmation, and multi-vector isolation) represents a mature IR capability. With 0 executions, it either reflects a low-compromise environment or a workflow not yet integrated into the SOC's incident response runbook. Wiring it into the SOAR response router for lateral movement and ATO cases would automate containment that currently requires manual CrowdStrike console actions.

Agentic user risk assessment is growing but still underused relative to alert volume. The Blink AI Agent ("Risky Ricky") now appears in three playbooks (two Help Desk lockout assessments, Determine User risk) totaling 4 production executions. With 2,390 LogRhythm events and 372 ATO responses running through the platform, adding AI-assisted risk scoring to the ATO response path would significantly improve triage quality at scale.

Integration Ecosystem

Category Integrations
SIEM / Logging LogRhythm
EDR CrowdStrike Falcon
SIEM / XDR Microsoft Defender for Endpoint, Microsoft XDR
Identity Microsoft Entra ID, Active Directory (on-prem via LDAP/WinRM), Okta
Threat Intel VirusTotal, AbuseIPDB, URLScan, IPWhois.io
Email Security Abnormal Security
Web Security Fastly NGWAF, Zscaler ZIA
HRIS UKG Pro HCM
Communication Slack
Email On-prem SMTP relay
Cloud Identity Microsoft Graph, Google Workspace, GitHub
Case Management Blink Case Management (native)
Network Tools WhoIs (bash), Dig (bash), PowerShell (WinRM)
AI / Agents Blink AI Agents (Risky Ricky — user risk reviewer)
E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
buckle cribl buckle_cribl 2026-08-28
buckle apikey-auth buckle_crowdstrike_http_webhook 2026-08-26