01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| LogRhythm SIEM Ingestion & Automated Response |
| 6.5% | 4 4 active |
| Agentic SOC — Multi-Source Alert Processing & Case Management |
| 73.5% | 13 12 active |
| Alert Enrichment & IOC Lookup | 175 executions | 0.4% | 21 21 active |
| Account Takeover & Identity Threat Investigation |
| 0.4% | 44 42 active |
| EDR Containment & Identity Lockdown | 272 executions | 0.7% | 13 13 active |
| WAF & Web Filtering Policy Management |
| 0.1% | 6 4 active |
| JIT Temporary Access — Conditional Access Exception (CA014) |
| 0.1% | 3 2 active |
| Identity Lifecycle & Employee Provisioning | 0 executions | 0.0% | 19 19 active |
| Email Notification Delivery | 0 executions | 0.0% | 2 2 active |
| Total | 32,550 executions | 100% | 125 119 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep, production-grade SOAR platform. The LogRhythm + Blink Case Management stack is the clearest indicator of mature automation: 2,390 SIEM events ingested, 1,944 vulnerability responses executed, and 800 alerts processed through a full extract-enrich-deduplicate-respond pipeline. This is not exploratory automation — it is core SOC infrastructure.
Multi-source EDR integration running at scale. CrowdStrike (Falcon webhook) and Microsoft Defender (polling, every 5 minutes) feed into the same SOAR pipeline, giving a unified case management view across both EDR products. The 446 case closures synced back to source tools confirm the bidirectional integration loop is closed.
Account takeover response is the heaviest automated response path. 372 ATO incident responses were dispatched through the automated response router, each triggering IP geolocation (IPWhois), user login history retrieval, and NIC history lookups — indicating the ATO playbook is the primary threat scenario being actioned at scale.
WAF management via Slack is a genuine force multiplier. 47 Fastly NGWAF allowlist and IP-list changes were applied on-demand through a Slack-triggered workflow with built-in IP validation. This gives tier-1 staff the ability to make controlled WAF changes during incidents without console access.
MFA-gated containment is built and ready. Every endpoint isolation playbook (isolate by username, hostname, device ID) requires MFA confirmation via Entra before executing — a security control that prevents misuse. These playbooks have 0 executions, meaning the capability exists as a rapid-response tool that has not yet been needed in production.
CA014 JIT access runs autonomously. The traveling-user exception workflow — web form intake, group membership, nightly expiration — ran 40 times in 12 months with no IT intervention. The lifecycle is fully self-contained.
Password reset automation scaled sharply. A newly deployed instance of Reset Password + force reset on next login accounted for 242 of the 251 combined executions across all three workspace instances of this playbook — making credential reset one of the highest-volume identity remediation actions on the platform, alongside the LogRhythm vulnerable-password response path.
###
Gaps & Opportunities
Phishing and malware response playbooks are built but inactive. Both Response Subflow — Phishing and Response Subflow — Malware have 0 executions despite being wired into the SOAR router. If phishing/malware alerts are reaching the platform, the alert template mappings may not be routing to these playbooks. If they are not reaching the platform, there is an untapped ingestion opportunity (e.g., ProofPoint, MSFT Defender for Office 365).
Enrichment library has broad coverage but low utilization for non-Whois sources. The enrichment library spans VirusTotal, AbuseIPDB, URLScan, Okta, Google Workspace, and GitHub — but these all show 0 executions. Only Whois (36 execs), Microsoft Entra ID (62 execs), CrowdStrike (9 execs), and IPWhois (372 execs) are active. Expanding the observable extraction templates to include URL and hash types would activate the existing VirusTotal and URLScan playbooks automatically.
UKG-driven employee lifecycle automation has not yet launched. The full UKG Pro HCM → Entra ID pipeline now spans both onboarding (hire date trigger, email check, account creation, manager assignment, group provisioning) and offboarding (termination trigger, group snapshot, account disable, session revocation), but all of these playbooks still show 0 executions. Activating this would eliminate manual account creation and deactivation steps across IT and HR.
Endpoint isolation capability exists but has not been needed. The 14-playbook EDR containment toolkit (with MFA gating, Slack confirmation, and multi-vector isolation) represents a mature IR capability. With 0 executions, it either reflects a low-compromise environment or a workflow not yet integrated into the SOC's incident response runbook. Wiring it into the SOAR response router for lateral movement and ATO cases would automate containment that currently requires manual CrowdStrike console actions.
Agentic user risk assessment is growing but still underused relative to alert volume. The Blink AI Agent ("Risky Ricky") now appears in three playbooks (two Help Desk lockout assessments, Determine User risk) totaling 4 production executions. With 2,390 LogRhythm events and 372 ATO responses running through the platform, adding AI-assisted risk scoring to the ATO response path would significantly improve triage quality at scale.
Integration Ecosystem
| Category | Integrations |
|---|---|
| SIEM / Logging | LogRhythm |
| EDR | CrowdStrike Falcon |
| SIEM / XDR | Microsoft Defender for Endpoint, Microsoft XDR |
| Identity | Microsoft Entra ID, Active Directory (on-prem via LDAP/WinRM), Okta |
| Threat Intel | VirusTotal, AbuseIPDB, URLScan, IPWhois.io |
| Email Security | Abnormal Security |
| Web Security | Fastly NGWAF, Zscaler ZIA |
| HRIS | UKG Pro HCM |
| Communication | Slack |
| On-prem SMTP relay | |
| Cloud Identity | Microsoft Graph, Google Workspace, GitHub |
| Case Management | Blink Case Management (native) |
| Network Tools | WhoIs (bash), Dig (bash), PowerShell (WinRM) |
| AI / Agents | Blink AI Agents (Risky Ricky — user risk reviewer) |
A Case Management 988 cases (12m) | MTTR 2d 22h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management | 984 | 984 | 972 | 2d 22h |
| POC Workspace | 4 | 4 | 0 | N/A |
B AI Agents 6 active | 158 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Risky Ricky | phil.brader@buckle.com | 67 | 1 | 2,687,035 |
| 2 | Risky Ricky | Infosec - Production | 51 | 0 | 2,797,467 |
| 3 | Agent Risky Ricky | Corporate IT Helpdesk | 24 | 2 | 1,595,699 |
| 4 | Risky Ricky | POC Workspace | 12 | 0 | 621,724 |
| 5 | Arnold | phil.brader@buckle.com | 3 | 0 | 59,482 |
| Workspace | Tasks (12m) |
|---|---|
| phil.brader@buckle.com | 70 |
| Infosec - Production | 51 |
| Corporate IT Helpdesk | 25 |
| POC Workspace | 12 |
| Case Management | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Case Management | 0 | 0 |
| 2 | Case Dashboard | 0 | 0 |
| 3 | HelpDesk Usage | 0 | 0 |
| 4 | Identity Lifecycle Command Center | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Traveling User: Add user with UPN. you must also include start and end dates of Travel. User will be removed at midnight on the last day of travel. | 0 | 0 |
| 2 | Traveling User: Add user with UPN. you must also include start and end dates of Travel. User will be removed at midnight on the last day of travel. | 0 | 0 |
| 3 | New User Onboarding Demo | 0 | 0 |
| 4 | Traveling User: Add user with UPN. You must include start and end dates of Travel. User will be added to the CA014 conditional exception group and then removed at midnight on the last day of travel. | 0 | 0 |
D Full Use Case Analysis 9 use cases | 39,826 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| SIEM alerts auto-ingested and routed from LogRhythm | 2,390 | Ingested Message from LogRhythm |
| Vulnerable-password incidents detected and auto-remediated | 1,944 | LogRhythm — User with vulnerable password found |
| SOC alerts processed end-to-end (extract, enrich, deduplicate, respond) | 800 | Process Alert |
| Automated alert response routings dispatched | 699 | Subflow — Response Main Router |
| Privileged-account status checks performed during automated alert response | 597 | Check if UPN is privileged account |
| Cases closed and synced back to source tools | 446 | Close Alerts in External Tools |
| Microsoft Defender alerts auto-triaged and routed | 431 | Defender Alerts |
| Account takeover incidents investigated and contained | 372 | Response Subflow — ATO |
| User password resets executed with forced reset enforced on next login | 251 | Reset Password + force reset on next login, Reset Password + force reset on next login, Reset Password + force reset on next login, Reset Password + force reset on next login |
| Observables automatically enriched across threat intel sources | 130 | Subflow — Enrich Observables Main Router |
| LogRhythm alert drilldown fields enriched | 119 | Enrich LogRhythm Drilldown field |
| Missing alert template notifications dispatched to team | 100 | Subflow — Missing Alert Template Notification |
| Third-party CrowdStrike alerts auto-ingested and routed via webhook | 59 | Third Party Alerts via CS |
| Scheduled traveling-user access expiration jobs enforced (CA014) | 53 | Scheduled: Remove user from CA014, Scheduled: Remove user from CA014 |
| CrowdStrike endpoint detections automatically ingested | 51 | Crowdstrike Ingestion |
| Fastly WAF allowlist and IP-list updates applied via Slack | 47 | Update Fastly Allowlist, Update Fastly NG WAF Corp IP list, Update Fastly NG WAF Allowlist |
| Lateral movement detections responded to | 35 | Response Subflow — Lateral Movement |
| Ad-hoc MFA verification prompts sent to users | 29 | Send Ad-Hoc Entra MFA prompt via UPN, Send Ad-Hoc Entra MFA prompt via UPN |
| AD department directory lookups performed for user investigations and audits | 16 | List all users in a department |
| Device lookups performed via Microsoft Graph/Intune for endpoint support and investigation | 9 | Device Information |
| Cribl search job results compiled into CSV reports and emailed | 9 | Cribl report sender, Cribl report sender |
| Password reset emails sent to users on demand | 6 | Send password reset email |
| Identity investigation searches performed via Microsoft Graph (ASN, service principal, OAuth grants) | 6 | Search by ASN, Search for activity on a service principal, Search oauth grants by user |
| Full AD user-attribute retrievals performed for investigation and support | 5 | List All of a User Attributes from AD |
| Account lockouts resolved via automated AD unlock | 4 | Unlock User in AD |
| User-registered device inventories retrieved for identity investigation | 4 | Get Users Registered Devices |
| Users added to CA014 travel exception group | 3 | Add User to Travel Exception |
| Sign-in logs retrieved for users blocked by a Conditional Access Policy | 1 | Get users blocked by a CAP last 12 hours |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks | Executions (12 mo) |
|---|---|---|---|---|---|
| 1 | LogRhythm SIEM Ingestion & Automated Response | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR | 6 | 4,462 |
| 2 | Agentic SOC — Multi-Source Alert Processing & Case Management | SOC | Case mgmt & SOAR, Agentic SOC, EDR containment & response, Identity threat response | 32 | 3,811 |
| 3 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 35 | 563 |
| 4 | Account Takeover & Identity Threat Investigation | SOC | Identity threat response, Agentic SOC | 74 | 433 |
| 5 | EDR Containment & Identity Lockdown | SOC | EDR containment & response, Identity threat response | 14 | 0 |
| 6 | WAF & Web Filtering Policy Management | Cloud Security | Cloud access & SaaS policy mgmt | 9 | 47 |
| 7 | JIT Temporary Access — Conditional Access Exception (CA014) | IAM | JIT & temporary access | 4 | 56 |
| 8 | Identity Lifecycle & Employee Provisioning | IAM | Employee onboarding, Employee offboarding, Identity lifecycle automation | 21 | 0 |
| 9 | Email Notification Delivery | Other | SaaS / IT administration | 3 | 0 |
| Total | 198 | 9,372 |
Use Cases
1. LogRhythm SIEM Ingestion & Automated Response
Description: Ingests every alert fired from LogRhythm via webhook, enriches each event's drilldown fields against Microsoft Entra ID, CrowdStrike, and Okta, and auto-executes response playbooks (e.g., forced password reset for vulnerable-credential detections) — all without analyst touch.
Business problem solved: LogRhythm generates high-alert volume that previously required manual triage; Blink intercepts every event, enriches it in real time, and acts on high-confidence detections automatically.
Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR
Key integrations: LogRhythm (webhook), Microsoft Entra ID, CrowdStrike, Okta, Microsoft Graph, WinRM (AD password reset)
| Playbook | Executions (12 mo) |
|---|---|
| Ingested Message from LogRhythm | 2,390 |
| LogRhythm — User with vulnerable password found | 1,944 |
| Enrich LogRhythm Drilldown field | 119 |
| Log message to Cribl | 0 |
| Cribl report sender | 7 |
| Cribl report sender | 2 |
2. Agentic SOC — Multi-Source Alert Processing & Case Management
Description: A full Blink-native SOAR platform that ingests alerts from CrowdStrike and Microsoft Defender, extracts and deduplicates observables, enriches IOCs across threat intel sources, routes each alert to the appropriate response playbook (ATO, lateral movement, phishing, malware), and syncs case closures back to source tools — running continuously on a 1-minute polling interval.
Business problem solved: The security team needed a vendor-agnostic case management and response orchestration layer that ties together CrowdStrike, Defender, and LogRhythm signals without relying on a dedicated SIEM-native SOAR product.
Category: SOC | Subcategories: Case mgmt & SOAR, Agentic SOC, EDR containment & response, Identity threat response
Key integrations: CrowdStrike, Microsoft Defender/XDR, Microsoft Entra ID, Microsoft Outlook, Slack, Blink Case Management
3. Alert Enrichment & IOC Lookup
Description: A library of on-demand enrichment playbooks that automatically look up every observable type (IP, hash, URL, email, username, domain, agent ID, hostname) across a wide array of threat intelligence and identity sources. These playbooks are called by the SOAR engine during alert processing and are also available standalone.
Business problem solved: Manually cross-referencing observables across eight or more tools during triage added hours per incident; this library enables instant, automated enrichment of every observable the moment it enters a case.
Category: SOC | Subcategories: Alert enrichment / IOC lookup
Key integrations: CrowdStrike, VirusTotal, AbuseIPDB, URLScan, WhoIs (bash), IPWhois.io, Microsoft Entra ID, Okta, Google Workspace, GitHub, Slack, Dig (bash), Abnormal Security
4. Account Takeover & Identity Threat Investigation
Description: An analyst-facing toolkit for investigating suspected account compromises, including AI-assisted user risk assessment (Blink AI Agent "Risky Ricky"), ad-hoc MFA challenges sent via Entra, login history retrieval, and a Slack-native help-desk integration for real-time lockout triage.
Business problem solved: Help desk staff and security analysts needed a fast, structured way to assess whether a locked-out or suspicious user account represented a genuine compromise versus a benign lockout — without pulling data from multiple consoles manually.
Category: SOC | Subcategories: Identity threat response, Agentic SOC
Key integrations: Microsoft Entra ID, Microsoft Graph, Slack, Blink AI Agents, PowerShell/WinRM, Okta
5. EDR Containment & Identity Lockdown
Description: A complete endpoint containment toolkit built on CrowdStrike Falcon RTR, supporting endpoint isolation and de-isolation by username, hostname, device ID, or transaction ID — with MFA-gated confirmation via Slack before any destructive action. Also includes identity lockdown capabilities (disable account, reset password, revoke sessions) for use during active incidents.
Business problem solved: Incident responders needed a repeatable, auditable, MFA-protected workflow for isolating compromised endpoints across the retail environment without direct CrowdStrike console access during fast-moving incidents.
Category: SOC | Subcategories: EDR containment & response, Identity threat response
Key integrations: CrowdStrike Falcon, Microsoft Entra ID, Slack, WinRM (AD operations)
6. WAF & Web Filtering Policy Management
Description: On-demand and Slack-triggered workflows that allow the security team to update Fastly NGWAF allowlists (corp-level and site-level) and manage Zscaler ZIA URL blocklists — with IP validation built in before any change is committed.
Business problem solved: Security engineers needed a safe, auditable way to update WAF allowlists for legitimate business traffic (e.g., POS systems, traveling staff) and block malicious URLs during active incidents, without granting direct console access to tier-1 responders.
Category: Cloud Security | Subcategories: Cloud access & SaaS policy mgmt
Key integrations: Fastly NGWAF, Zscaler ZIA, Slack
7. JIT Temporary Access — Conditional Access Exception (CA014)
Description: A self-service web form allows authorized users to request temporary exemption from Conditional Access policy CA014 for a specific travel window; the user is automatically added to the exception group and a nightly scheduled job removes them at midnight on the last day of travel.
Business problem solved: Traveling employees frequently triggered CA014 blocks when authenticating from non-standard locations, requiring manual IT intervention; this process automates the full request-to-expiration lifecycle with zero IT involvement.
Category: IAM | Subcategories: JIT & temporary access
Key integrations: Microsoft Entra ID, Slack, Blink Tables, Blink Web Form
| Playbook | Executions (12 mo) |
|---|---|
| Scheduled: Remove user from CA014 | 40 |
| Add User to CA014 | 0 |
| Add User to Travel Exception | 3 |
| Scheduled: Remove user from CA014 | 13 |
8. Identity Lifecycle & Employee Provisioning
Description: End-to-end employee lifecycle management driven by UKG Pro HCM: retrieves new-hire and termination records, checks email address availability in Entra ID, creates Entra admin accounts with manager assignment, provisions and deprovisions group memberships, disables accounts and revokes sessions on departure, and syncs user attribute changes (department, title, manager) through LDAP and WinRM.
Business problem solved: IT operations needed to eliminate manual account creation and deactivation steps for new hires, internal transfers, and departures, reducing provisioning/deprovisioning time and ensuring attribute and access consistency across on-prem Active Directory, Entra ID, and HR records.
Category: IAM | Subcategories: Employee onboarding, Employee offboarding, Identity lifecycle automation
Key integrations: UKG Pro HCM, Microsoft Entra ID, Microsoft Graph, LDAP, WinRM, Slack
9. Email Notification Delivery
Description: An on-demand utility that sends HTML-formatted email content through the organization's on-premises SMTP relay, supporting configurable sender, recipient, and subject parameters with file-based HTML content.
Business problem solved: Other automations and manual processes needed a standardized way to deliver formatted HTML reports and notifications through the internal mail relay without duplicating SMTP logic in every playbook.
Category: Other | Subcategories: SaaS / IT administration
Key integrations: On-prem SMTP server
| Playbook | Executions (12 mo) |
|---|---|
| Send html email file via on-prem SMTP server | 0 |
| Send html email file via on-prem SMTP server | 0 |
| Notify On-Call Infosec Analyst | 0 |
Key Observations
Strengths
Deep, production-grade SOAR platform. The LogRhythm + Blink Case Management stack is the clearest indicator of mature automation: 2,390 SIEM events ingested, 1,944 vulnerability responses executed, and 800 alerts processed through a full extract-enrich-deduplicate-respond pipeline. This is not exploratory automation — it is core SOC infrastructure.
Multi-source EDR integration running at scale. CrowdStrike (Falcon webhook) and Microsoft Defender (polling, every 5 minutes) feed into the same SOAR pipeline, giving a unified case management view across both EDR products. The 446 case closures synced back to source tools confirm the bidirectional integration loop is closed.
Account takeover response is the heaviest automated response path. 372 ATO incident responses were dispatched through the automated response router, each triggering IP geolocation (IPWhois), user login history retrieval, and NIC history lookups — indicating the ATO playbook is the primary threat scenario being actioned at scale.
WAF management via Slack is a genuine force multiplier. 47 Fastly NGWAF allowlist and IP-list changes were applied on-demand through a Slack-triggered workflow with built-in IP validation. This gives tier-1 staff the ability to make controlled WAF changes during incidents without console access.
MFA-gated containment is built and ready. Every endpoint isolation playbook (isolate by username, hostname, device ID) requires MFA confirmation via Entra before executing — a security control that prevents misuse. These playbooks have 0 executions, meaning the capability exists as a rapid-response tool that has not yet been needed in production.
CA014 JIT access runs autonomously. The traveling-user exception workflow — web form intake, group membership, nightly expiration — ran 40 times in 12 months with no IT intervention. The lifecycle is fully self-contained.
Password reset automation scaled sharply. A newly deployed instance of Reset Password + force reset on next login accounted for 242 of the 251 combined executions across all three workspace instances of this playbook — making credential reset one of the highest-volume identity remediation actions on the platform, alongside the LogRhythm vulnerable-password response path.
Gaps & Opportunities
Phishing and malware response playbooks are built but inactive. Both Response Subflow — Phishing and Response Subflow — Malware have 0 executions despite being wired into the SOAR router. If phishing/malware alerts are reaching the platform, the alert template mappings may not be routing to these playbooks. If they are not reaching the platform, there is an untapped ingestion opportunity (e.g., ProofPoint, MSFT Defender for Office 365).
Enrichment library has broad coverage but low utilization for non-Whois sources. The enrichment library spans VirusTotal, AbuseIPDB, URLScan, Okta, Google Workspace, and GitHub — but these all show 0 executions. Only Whois (36 execs), Microsoft Entra ID (62 execs), CrowdStrike (9 execs), and IPWhois (372 execs) are active. Expanding the observable extraction templates to include URL and hash types would activate the existing VirusTotal and URLScan playbooks automatically.
UKG-driven employee lifecycle automation has not yet launched. The full UKG Pro HCM → Entra ID pipeline now spans both onboarding (hire date trigger, email check, account creation, manager assignment, group provisioning) and offboarding (termination trigger, group snapshot, account disable, session revocation), but all of these playbooks still show 0 executions. Activating this would eliminate manual account creation and deactivation steps across IT and HR.
Endpoint isolation capability exists but has not been needed. The 14-playbook EDR containment toolkit (with MFA gating, Slack confirmation, and multi-vector isolation) represents a mature IR capability. With 0 executions, it either reflects a low-compromise environment or a workflow not yet integrated into the SOC's incident response runbook. Wiring it into the SOAR response router for lateral movement and ATO cases would automate containment that currently requires manual CrowdStrike console actions.
Agentic user risk assessment is growing but still underused relative to alert volume. The Blink AI Agent ("Risky Ricky") now appears in three playbooks (two Help Desk lockout assessments, Determine User risk) totaling 4 production executions. With 2,390 LogRhythm events and 372 ATO responses running through the platform, adding AI-assisted risk scoring to the ATO response path would significantly improve triage quality at scale.
Integration Ecosystem
| Category | Integrations |
|---|---|
| SIEM / Logging | LogRhythm |
| EDR | CrowdStrike Falcon |
| SIEM / XDR | Microsoft Defender for Endpoint, Microsoft XDR |
| Identity | Microsoft Entra ID, Active Directory (on-prem via LDAP/WinRM), Okta |
| Threat Intel | VirusTotal, AbuseIPDB, URLScan, IPWhois.io |
| Email Security | Abnormal Security |
| Web Security | Fastly NGWAF, Zscaler ZIA |
| HRIS | UKG Pro HCM |
| Communication | Slack |
| On-prem SMTP relay | |
| Cloud Identity | Microsoft Graph, Google Workspace, GitHub |
| Case Management | Blink Case Management (native) |
| Network Tools | WhoIs (bash), Dig (bash), PowerShell (WinRM) |
| AI / Agents | Blink AI Agents (Risky Ricky — user risk reviewer) |
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| buckle | cribl | buckle_cribl | 2026-08-28 |
| buckle | apikey-auth | buckle_crowdstrike_http_webhook | 2026-08-26 |