Blink Security Automation — Confidential

CNH — Customer Success Report

Generated 2026-09-10 | cnh-value-report.md
2026-09-10Report Date
544Total Playbooks
288Unique Workflows (12m)
3,572,100Actions Automated (12m)
$918,750Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

544
Total playbooks built
all non-deleted workflows
343
Active playbooks
currently enabled
288
Unique workflows executed (12m)
distinct workflows that ran
3,572,100
Actions automated (12m)
completed action steps
19,845.0h
Hours saved (12m)
@ 20s per action
$918,750
Money saved (12m)
@ $100K avg salary
26
New active workflows (last 30d)
recently created & enabled
1,466
Total cases managed
1,466 opened in last 12m
5d 11h
MTTR — mean time to resolve
closed cases, last 12m
6
Active AI agents
of 17 total
3,669
AI agent tasks executed (12m)
2,005 in last 30d
In the last 12 months, Blink automated: - 127,195 Security case updates synchronized to ServiceNow in real time - 1,533 Raw security alerts triaged into structured investigation cases - 860 Cases investigated end-to-end by the autonomous AI SOC agent - 676 Proofpoint-flagged phishing & Very Attacked People threats investigated & responded to - 166 High/critical vulnerability tickets auto-generated in ServiceNow from Tenable findings - 132 Risky-user identity threats investigated & remediated - 30 MSSP-reported incidents ingested as new cases from ServiceNow - 21 SOC performance dashboard refreshes delivered to stakeholders

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
ServiceNow Case Synchronization
  • 127,195Security case updates synchronized to ServiceNow in real time
  • 30MSSP-reported incidents ingested as new cases from ServiceNow
74.8%
4
3 active
Agentic SOC — Autonomous AI Case Investigation
  • 860Cases investigated end-to-end by the autonomous AI SOC agent
16.0%
43
43 active
Phishing & Email Threat Response
  • 676Proofpoint-flagged phishing & Very Attacked People threats investigated & responded to
2.1%
6
6 active
SIEM & XDR Alert Ingestion5,743 executions
2.8%
10
10 active
Alert & Observable Enrichment Library3,732 executions
1.8%
40
40 active
Case & Alert Lifecycle Management
  • 1,533Raw security alerts triaged into structured investigation cases
1.4%
24
24 active
Identity Threat Response — Risky User Detection & Remediation
  • 132Risky-user identity threats investigated & remediated
1.0%
19
19 active
Vulnerability Scanning, Asset Sync & Ticketing (Tenable)
  • 166High/critical vulnerability tickets auto-generated in ServiceNow from Tenable findings
0.1%
10
10 active
Security Metrics & Reporting
  • 21SOC performance dashboard refreshes delivered to stakeholders
0.0%
1
1 active
Platform Testing & Environment Scaffolding0 executions
0.0%
15
11 active
EDR Containment & Response Actions0 executions
0.0%
10
10 active
IT Request Routing — ServiceNow to Monday.com0 executions
0.0%
1
1 active
Total206,194 executions100%
183
178 active

Use Case Growth Over Time

311 unique playbooks  |  12 operational use cases  |  206,194 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Agentic SOC — Autonomous AI Case Investigation
Agents Splunk ServiceNow
Alert & Observable Enrichment Library
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Google Workspace GitHub Microsoft Entra ID Microsoft Defender For Endpoints Claroty xDome Tanium Slack String Utilities Extraction Utilities
Phishing & Email Threat Response
Microsoft Outlook Proofpoint TAP Splunk Microsoft Defender XDR ServiceNow
Case & Alert Lifecycle Management
Email
Platform Testing & Environment Scaffolding
Email VirusTotal ServiceNow CrowdStrike Okta Tenable Kandji Claroty xDome Tanium
Vulnerability Scanning, Asset Sync & Ticketing (Tenable)
Tenable Email ServiceNow
EDR Containment & Response Actions
Tanium Email CrowdStrike Microsoft Defender For Endpoints
Identity Threat Response — Risky User Detection & Remediation
Splunk Microsoft Defender For Endpoints VirusTotal Microsoft Defender XDR Email ServiceNow Microsoft Entra ID
SIEM & XDR Alert Ingestion
ServiceNow Microsoft Defender XDR Splunk Microsoft Defender for Endpoint
ServiceNow Case Synchronization
ServiceNow Email
IT Request Routing — ServiceNow to Monday.com
ServiceNow Monday
Security Metrics & Reporting
Dashboards

04Key Observations

✓  Strengths

Strengths

  • Agentic SOC is the deepest single investment in the automation footprint. At 43 playbooks — the largest library by playbook count — the AI investigation agent has its own callable tool library of 26+ "Agent Ability" actions spanning Splunk, ServiceNow, Tenable, Tanium, and case-management context, plus a dedicated model-evaluation harness (labeled-dataset scoring and re-run tooling) used to continuously tune investigation accuracy against ground truth. This is a materially more mature Agentic SOC deployment than a typical single-playbook AI-triage integration.
  • ServiceNow synchronization is the automation backbone. At 127K+ executions, real-time case-to-ticket sync is by a wide margin the most-executed automation, meaning ServiceNow reliably reflects live case status for every team outside the SOC without manual re-entry.
  • Broad, structured enrichment coverage. A 40-tool enrichment library normalizes hashes, IPs, URLs, hostnames, and identities across VirusTotal, CrowdStrike, Okta, Microsoft Entra ID, URLScan.io, AbuseIPDB, GitHub, Slack, and Google Workspace behind a single routing layer, so analysts and the AI agent get a consistent verdict regardless of observable type.
  • Healthcare-specific asset context. The Claroty Medigate integration (hostname-to-medical-device lookup) gives investigations clinical/IoMT context that generic SOC tooling doesn't provide — directly relevant to a hospital's unique attack surface.
  • Identity remediation is a complete, one-call toolkit. Session revocation, MFA reset, account suspension/reactivation, and forced password reset are all built as standalone, callable actions alongside Entra ID risky-user monitoring and Defender XDR identity-alert ingestion, giving the identity response pipeline everything it needs end-to-end.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • EDR containment library is fully built but unused. All 10 CrowdStrike/Defender/Tanium containment playbooks (host isolation, quarantine, RTR, antivirus scan) show zero executions in the trailing 12 months — the capability exists but isn't yet wired into the automatic response path from the AI investigation or identity-threat workflows.
  • Identity remediation actions are idle. The core remediation calls (Force Password Reset, Suspend User Account, Revoke User Sessions, Reset User MFA Methods, Confirm Compromise Risky User, Entra disable/revoke-session actions) all show zero executions, while detection-side workflows (risky-user monitoring, Defender XDR identity alerts) are active — suggesting confirmed risky-user cases are currently being remediated manually rather than through the automated action library already in place.
  • Workspace duplication adds maintenance overhead. Core playbooks (case sync, alert ingestion, enrichment) are deployed nearly identically across 8 separate workspaces under the same tenant. Consolidating to a clear dev/staging/production boundary — or fully retiring unused copies — would reduce the surface area that needs to stay in sync when a playbook is updated.
  • 23 platform-testing and scaffolding workflows carry effectively zero production executions, including unconfigured onboarding templates (Hello World, Intake Form, Feedback Form, empty "New Workflow" placeholders). These are reasonable to keep for sandbox testing but are candidates for archival to keep the production automation inventory clean.
  • No dedicated GRC/compliance automation beyond dashboard reporting. Access review, audit-evidence collection, or compliance-questionnaire workflows aren't yet represented — a natural next step given the identity and case-management foundation already in place.

Integration Ecosystem

Integration Role in the Automation Footprint
ServiceNow System of record for tickets/incidents; two-way sync with Blink Case Management
Splunk Primary SIEM — alert ingestion, AI-agent threat hunting, risk-based alerting, pipeline health checks
Microsoft Defender XDR / Defender for Endpoint XDR and endpoint alert ingestion, identity alerts, endpoint containment actions
Tenable Vulnerability scanning, asset inventory sync, high/critical finding ticketing
Tanium Endpoint posture queries for AI investigation and containment actions
CrowdStrike EDR enrichment (hash/agent/ThreatGraph lookups) and RTR/quarantine containment actions
Microsoft Entra ID Risky-user identity signals, account enrichment, session/account remediation
Okta Identity enrichment and user activity search
VirusTotal / URLScan.io / AbuseIPDB Threat intelligence enrichment for hashes, URLs, and IPs
Proofpoint TAP Phishing threat and Very Attacked People (VAP) ingestion
Claroty Medigate Medical device / clinical asset context — hospital-specific enrichment
GitHub / Slack / Google Workspace Supplementary identity enrichment across collaboration and dev tooling
Monday.com Downstream task tracking for security engineering fulfillment work
Blink Case Management / Blink Tables / Blink AI Agents Blink-native case lifecycle, data storage, and AI agent orchestration
Appendices
A Case Management 1,466 cases (12m) | MTTR 5d 11h

Case Management

Total Cases (all-time)
1,466
1,466 opened in last 12m
Cases Opened (30d)
738
466 closed in last 30d
Cases Closed (12m)
1,057
of 1,466 opened
MTTR
5d 11h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
AI SOC 701 701 564 8h 26m
Case Management V9 446 446 393 14d 5h
Dev Workspace 319 319 100 1h 41m
B AI Agents 6 active | 3,669 tasks (12m)

AI Agents

Active Agents
6
of 17 total
Tasks Executed (12m)
3,669
2,005 in last 30d
Data Usage (12m)
771,771,611
532,567,542 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 SOC Analyst AI SOC 1,875 930 445,828,827
2 SOC Agent - Suspicious Network Activity Agent AI SOC 825 423 223,073,188
3 Micro Agent - Historical Case Check AI SOC 788 526 43,929,805
4 SOC Agent - Compliance & Endpoint Agent AI SOC 160 109 51,749,392
5 SOC Agent - Reconnaissance Agent AI SOC 16 15 6,180,439
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
AI SOC3,669
Case Management V90
Dev Workspace0
Case Management0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
7
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Tenable 00
2 Very Attacked Person List 00
3 SOC Overview 00
4 AI SOC Automation Map 00
5 Children's National - Automation View 00

Webforms

Forms
5
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Access Help Request 00
2 Blink Automation Feedback Form 00
3 New Automation Request 00
4 please fill in form 00
5 New Automation Intake Form 00
D Full Use Case Analysis 12 use cases | 206,194 executions (12m)

Business KPIs

Metric Count Playbook
Security case updates synchronized to ServiceNow in real time 127,195 Sync Case with ServiceNow
Raw security alerts triaged into structured investigation cases 1,533 Process Alert
Cases investigated end-to-end by the autonomous AI SOC agent 860 Agentic SOC - Decision Layer
Proofpoint-flagged phishing & Very Attacked People threats investigated & responded to 676 Response Subflow - Proofpoint TAP
High/critical vulnerability tickets auto-generated in ServiceNow from Tenable findings 166 Webhook for Tennable VM Ticket Generation
Risky-user identity threats investigated & remediated 132 Response Subflow - Risky User Detections
MSSP-reported incidents ingested as new cases from ServiceNow 30 ServiceNow MSSP
SOC performance dashboard refreshes delivered to stakeholders 21 AI SOC 360 - Build Dashboard
In the last 12 months, Blink automated: - 127,195 Security case updates synchronized to ServiceNow in real time - 1,533 Raw security alerts triaged into structured investigation cases - 860 Cases investigated end-to-end by the autonomous AI SOC agent - 676 Proofpoint-flagged phishing & Very Attacked People threats investigated & responded to - 166 High/critical vulnerability tickets auto-generated in ServiceNow from Tenable findings - 132 Risky-user identity threats investigated & remediated - 30 MSSP-reported incidents ingested as new cases from ServiceNow - 21 SOC performance dashboard refreshes delivered to stakeholders

Use Case Summary

# Use Case Category Playbook Count Executions (12mo)
1 ServiceNow Case Synchronization SOC 6 131,137
2 Agentic SOC — Autonomous AI Case Investigation SOC 43 32,651
3 Phishing & Email Threat Response SOC 10 5,569
4 SIEM & XDR Alert Ingestion SOC 12 4,913
5 Alert & Observable Enrichment Library SOC 138 4,802
6 Case & Alert Lifecycle Management SOC 56 4,431
7 Identity Threat Response — Risky User Detection & Remediation SOC 19 2,062
8 Vulnerability Scanning, Asset Sync & Ticketing (Tenable) Vulnerability Mgmt 13 257
9 Security Metrics & Reporting GRC 1 21
10 Platform Testing & Environment Scaffolding Other 23 1
11 EDR Containment & Response Actions SOC 21 0
12 IT Request Routing — ServiceNow to Monday.com Other 1 0

Use Cases

1. ServiceNow Case Synchronization

Category: SOC

Subcategories: Case mgmt & SOAR

Description:

Keeps every security case created in Blink Case Management mirrored in ServiceNow in near real time, with an hourly reconciliation pass, and ingests MSSP-reported incidents from ServiceNow back in as new Blink cases.

Business problem solved:

SOC and hospital IT operate from different systems of record — without continuous two-way sync, ServiceNow tickets go stale and stakeholders outside the SOC lose visibility into case status, while MSSP-flagged incidents would otherwise require manual re-entry. This pipeline makes ServiceNow the reliable, always-current record of case status across the organization.

Integrations: ServiceNow · Blink Case Management

Playbooks

Playbook Executions Role
Sync Case with ServiceNow 101,630 Pushes every case create/update to its mirrored ServiceNow ticket in real time.
Sync Case with ServiceNow 25,565 Pushes every case create/update to its mirrored ServiceNow ticket in real time.
Hourly Sync 1,920 Scheduled hourly reconciliation that re-syncs all open cases against their ServiceNow tickets.
Hourly Sync 1,920 Scheduled hourly reconciliation that re-syncs all open cases against their ServiceNow tickets.
On Case Closure 72 Confirms the linked ServiceNow incident is closed when a Blink case is closed.
ServiceNow MSSP 30 Ingests new MSSP-reported incidents from ServiceNow as Blink cases with an auto-generated summary.

2. Agentic SOC — Autonomous AI Case Investigation

Category: SOC

Subcategories: Agentic SOC, Threat hunting & detection

Description:

An AI agent investigates incoming cases end-to-end using a library of over 30 callable tools — pulling case and asset context, hunting across Splunk, checking Tenable/Tanium/ServiceNow records, and following documented investigation guidelines — then produces a triage recommendation, with a labeled-dataset evaluation harness used to score and tune investigation accuracy.

Business problem solved:

Tier-1 triage historically consumed the majority of analyst time on repetitive, multi-system data-gathering before a human could even begin judging an alert. This use case gives every case a first-pass AI investigation using the same toolset a human analyst would use, freeing analysts to focus on judgment calls and true positives rather than data collection.

Integrations: Splunk · ServiceNow · Tenable · Tanium · Blink Case Management · Blink AI Agents

Playbooks

Playbook Executions Role
Agent Ability - Run Splunk Search 7,887 Executes an ad hoc Splunk search on the agent's behalf — the most heavily used investigation tool in the library.
Agent Ability - Get Case By Case ID 4,421 Looks up a case by ID so the agent can pull it into context.
Utility - Log Investigation Activity 2,497 Records each AI investigation step to the case's activity log for auditability.
Utility - Read Agentic Output 2,282 Reads structured output from a completed agent investigation step.
Agent Ability - Get Org Assets 1,756 Retrieves organizational asset inventory to establish investigation context.
Agent Ability - Get VIP Users 1,285 Flags whether an entity in the case is a VIP user, raising investigation priority.
Agent Ability - Hunt Indicator Activity (Splunk) 1,216 Hunts Splunk for prior activity involving a given indicator.
Agent Ability - Get Change Records (ServiceNow) 1,166 Pulls related ServiceNow change records so the agent can rule out planned maintenance as a cause.
Agent Ability - Get Splunk Risk Contributors 1,038 Pulls Splunk risk-based-alerting contributors for an entity.
Agent Ability - Hunt Outbound Contact (Splunk) 1,036 Hunts Splunk for outbound network contact from an entity.
Utility - Sanitize Case From Prior Investigation 863 Clears stale investigation artifacts before re-running AI investigation.
Utility - Truncate Case & Alert 863 Trims oversized case/alert payloads so they fit within the agent's context limits.
Agentic SOC - Decision Layer 860 Top-level orchestrator that runs a case through AI investigation and issues the final triage decision.
Subflow - Agentic SOC - Main - AI Investigation 860 Runs the core AI investigation loop, calling agent tools to build the case narrative.
Agent Ability - Get Case Observable's Enrichment 845 Surfaces existing enrichment data for a case's observables to the agent.
Agentic SOC - Expert Agents 842 Invokes specialized micro-agents for domain-specific analysis within an investigation.
Agent Ability - Get Investigation Guidelines 839 Supplies the agent with the documented investigation playbook for the alert type.
Agent Ability - Historical Case Checks 725 Checks for related historical cases and appends findings to the case record.
Agent Ability - Get Case 464 Retrieves the full case record for the AI agent to reason over.
Agent Ability - Hunt Authentication Activity (Splunk) 390 Hunts Splunk authentication logs for an entity's login activity.
Subflow - Post-Investigation Finalisation 270 Finalizes case documentation once the AI investigation completes.
Utility - Refresh investigation 205 Re-triggers AI investigation on a case, e.g. after new evidence arrives.
Agent Ability - Get Endpoint Posture (Tanium) 20 Queries Tanium for real-time endpoint posture on an entity under investigation.
Agent Ability - Query Observables by Content 9 Searches existing observables by content to surface related evidence.
Utility - Read Investigation Activity 6 Reads back logged investigation activity for a case.
Agent Ability - Get Splunk Schema 3 Returns available Splunk index/field schema so the agent can construct valid searches.
Agent Ability - Get Observable Reputations From Case Management Settings 1 Returns configured reputation thresholds the agent uses to judge observable verdicts.
Agent Ability - Get Identity Governance (SailPoint) 1 Queries Splunk-indexed SailPoint identity governance data for an entity.
Agent Ability - Resolve Asset (Tenable) 1 Resolves an entity to its Tenable asset record for vulnerability context.
Agent Ability - Recommendation for case 0 Generates the agent's triage/response recommendation for a case.
SubFlow - Context Enrichment 0 Builds an observable profile to enrich investigation context.
Agentic SOC - Close Case 0 Closes a case automatically once the AI agent reaches a high-confidence disposition.
Agent Ability - Get Vendor Logo List 0 Supplies known vendor branding data used to spot phishing brand impersonation.
Agent Ability - Get Observable Relation Types From Case Management Settings 0 Returns the configured observable relationship types the agent can use when linking evidence.
Load cases taggings from csv 0 Loads analyst-labeled case tags used as ground truth for model evaluation.
Load cases predictions from conclusions 0 Loads AI-generated case predictions for evaluation against ground truth.
Main Evaluation - Evaluate On Cases dataset 0 Scores AI investigation accuracy against a labeled case dataset.
Agent Ability - Get Observable Types From Case Management Settings 0 Returns the configured observable types available to the agent.
Refresh investigations on case dataset 0 Re-runs AI investigation across the evaluation dataset after a model or prompt change.
Agent Ability - Get Alert 0 Retrieves full alert detail for the case under investigation.
Agent Ability - Get Org Technological Stack 0 Supplies the agent with the org's technology stack for investigation context.
Agent Ability - Get Email Threat Context (Proofpoint) 0 Queries Splunk-indexed Proofpoint email data for threat context on an entity.
Agent Ability - Profile Entity Baseline (Splunk) 0 Builds a Splunk-based behavioral baseline for an entity to spot deviation.

3. Phishing & Email Threat Response

Category: SOC

Subcategories: Phishing detection & response

Description:

Ingests phishing threats and Very Attacked People (VAP) signals from Proofpoint TAP on a schedule and routes each confirmed alert through a dedicated investigation-and-response subflow.

Business problem solved:

Email remains the leading initial-access vector, and hospital staff are frequent phishing targets. This pipeline gives every Proofpoint-flagged threat a consistent, automated response path instead of relying on ad hoc analyst handling, and feeds the VAP list into Splunk so high-value targets are weighted appropriately elsewhere in the detection stack.

Integrations: Proofpoint TAP · Splunk · Blink Case Management

Playbooks

Playbook Executions Role
Proofpoint TAP Alert Ingestion 3,839 Scheduled poll that pulls new Proofpoint TAP threat alerts into the case pipeline.
Proofpoint TAP Alert Ingestion 1,054 Scheduled poll that pulls new Proofpoint TAP threat alerts into the case pipeline.
Response Subflow - Proofpoint TAP 530 Investigates and actions a Proofpoint TAP alert end-to-end.
Response Subflow - Proofpoint TAP 146 Investigates and actions a Proofpoint TAP alert end-to-end.
Response Subflow - Phishing 0 Runs the phishing-specific investigation and remediation steps for a case.
Response Subflow - Phishing 0 Runs the phishing-specific investigation and remediation steps for a case.
Pull VAP List and Add to Table 0 Pulls Proofpoint's Very Attacked People (VAP) list and stores it in Blink Tables.
Phishing Alerts (Proofpoint) 0 Event trigger that ingests a phishing alert flagged by Proofpoint TAP.
VAP List to Splunk 0 Forwards the Very Attacked People list to Splunk for correlation with other alerting.
Response Subflow - Phishing 0 Runs the phishing-specific investigation and remediation steps for a case.

4. SIEM & XDR Alert Ingestion

Category: SOC

Subcategories: SIEM & log pipeline monitoring

Description:

Polls Splunk and Microsoft Defender XDR/Endpoint for new alerts, opens linked ServiceNow tickets for cross-team follow-up, and separately watches the pipeline's own health — certificate expiry, missing data feeds — so gaps are caught early.

Business problem solved:

A detection pipeline is only as good as its uptime and its ability to route findings to the right team. These workflows bring new SIEM/XDR alerts into the case queue and ticket queues, while dedicated health-check workflows monitor the pipeline itself so silent failures (an expired certificate, a stalled Workday feed) don't become blind spots.

Integrations: Splunk · Microsoft Defender XDR · Microsoft Defender for Endpoint · ServiceNow · Blink Case Management

Playbooks

Playbook Executions Role
Ingest - CNMC Splunk 3,110 Scheduled poll that pulls new Splunk-correlated alerts into the case pipeline.
DEMO Ingest Workflow (custom splunk events) 960 Scheduled test ingestion of custom Splunk events used to validate the pipeline.
New Defender Alert 607 Event trigger on new Microsoft Defender XDR alerts.
Ingest - CNMC Defender for Endpoint 208 Event trigger that pulls new Microsoft Defender for Endpoint alerts into the case pipeline.
Splunk Triggered Event 18 Generic Splunk-triggered event handler that opens a ServiceNow ticket.
Splunk Query - Upcoming Certificate Expiration 10 Checks Splunk for certificates approaching expiry and alerts the team.
Response Subflow - Malware 0 Runs malware-specific investigation and remediation steps for a case.
Response Subflow - Malware 0 Runs malware-specific investigation and remediation steps for a case.
Splunk Alert 0 Generic event trigger for a Splunk-sourced alert.
Response Subflow - Malware 0 Runs malware-specific investigation and remediation steps for a case.
Automated Defender Actions 0 Turns a Defender XDR incident into linked ServiceNow tickets for both the SecOps and IAM teams.
Splunk Query - Workday Data Not Being Ingested 0 Monitors for a break in the Workday-to-Splunk data feed.

5. Alert & Observable Enrichment Library

Category: SOC

Subcategories: Alert enrichment / IOC lookup

Description:

A large modular library that enriches every observable type extracted from a case — hashes, IPs, URLs, hostnames, usernames — against threat intel, identity, and asset sources, with a central router dispatching each observable to the correct enrichment workflow and writing results back to the case.

Business problem solved:

Analysts previously had to manually pivot across a dozen separate consoles — VirusTotal, CrowdStrike, Okta, Entra ID, URLScan, AbuseIPDB, GitHub, Slack, Google Workspace, Claroty — to build context on a single indicator. This library returns a structured verdict for any observable type through one consistent interface, including hospital-specific context such as whether a hostname belongs to a clinical medical device.

Integrations: VirusTotal · CrowdStrike · Okta · Microsoft Entra ID · URLScan.io · AbuseIPDB · GitHub · Slack · Google Workspace · Claroty Medigate · Microsoft Defender for Endpoint · Tanium · Blink Case Management

Playbooks

Playbook Executions Role
Subflow - Enrich Observables - Main Router 1,885 Central dispatcher that routes each observable to its type-specific enrichment workflow.
Subflow - Enrich Observables - Main Router 707 Central dispatcher that routes each observable to its type-specific enrichment workflow.
Subflow - Update Enrichment Data 523 Writes enrichment results back to the case's observable record.
Subflow - Enrich Observables - Main Router 333 Central dispatcher that routes each observable to its type-specific enrichment workflow.
Utility - Extract Decoded PowerShell 273 Decodes obfuscated or encoded PowerShell command lines for analysis.
Get Machine Info - Microsoft Defender 139 Resolves a hostname to Microsoft Defender device details.
Get Machine Info - Tanium Lookup 137 Resolves a hostname to Tanium-managed endpoint details.
Get Machine Info - Medigate Hostname Lookup 137 Resolves a hostname to Claroty Medigate medical-device asset details.
IP2Hostname Lookup 137 Resolves an IP address to its hostname.
Enrich - IP - VT 111 Checks an IP's reputation via VirusTotal.
Enrich IP or Domain Using Whois 98 Runs a Whois lookup on an IP or domain for registration context.
Enrich - IP or Domain - Whois 98 Runs a Whois lookup on an IP or domain for registration context.
Enrich - Hash - VT 73 Checks a file hash's reputation in VirusTotal.
Enrich - Hostname - Microsoft Defender for Endpoint 73 Pulls Microsoft Defender for Endpoint device context for a hostname.
Enrich - Hostname - Claroty Medical Device Context 27 Looks up whether a hostname belongs to a clinical medical device via Claroty Medigate.
Get User Information Using Microsoft Entra ID 17 Resolves a user identity to Microsoft Entra ID account details.
Enrich - Username or Email - Microsoft Entra ID 17 Resolves a username or email to Microsoft Entra ID account context, including risky-user status.
Enrich - Check If Observable inside Organization 15 Flags whether an observable (IP/host) belongs to the organization's own network.
Recovery - Enrich Non-Enriched Observables 2 Catches observables that were never enriched and reruns enrichment.
Enrich - Agent ID - Crowdstrike 0 Resolves a CrowdStrike agent ID to device and user context.
Enrich - Agent ID - Crowdstrike 0 Resolves a CrowdStrike agent ID to device and user context.
Enrich - URL - URLScan 0 Submits a URL to URLScan.io for enrichment.
Enrich - URL - URLScan 0 Submits a URL to URLScan.io for enrichment.
Enrich - Hash - VT 0 Checks a file hash's reputation in VirusTotal.
Enrich - Hash - VT 0 Checks a file hash's reputation in VirusTotal.
Enrich - IP - IPDB 0 Checks an IP's abuse reputation via AbuseIPDB.
Enrich - IP - IPDB 0 Checks an IP's abuse reputation via AbuseIPDB.
Enrich - Username or Email - Okta 0 Resolves a username or email to Okta account context.
Enrich - Username or Email - Okta 0 Resolves a username or email to Okta account context.
Enrich - IP - VT 0 Checks an IP's reputation via VirusTotal.
Enrich - IP - VT 0 Checks an IP's reputation via VirusTotal.
Subflow - Enrich Observables - Main Router 0 Central dispatcher that routes each observable to its type-specific enrichment workflow.
Subflow - Update Enrichment Data 0 Writes enrichment results back to the case's observable record.
Subflow - Update Enrichment Data 0 Writes enrichment results back to the case's observable record.
Enrich - URL - VT 0 Checks a URL's reputation via VirusTotal.
Enrich - URL - VT 0 Checks a URL's reputation via VirusTotal.
Get User Information Using Google Workspace 0 Resolves a user identity to Google Workspace account details.
Get User Information Using Google Workspace 0 Resolves a user identity to Google Workspace account details.
Enrich IP or Domain Using Whois 0 Runs a Whois lookup on an IP or domain for registration context.
Enrich IP or Domain Using Whois 0 Runs a Whois lookup on an IP or domain for registration context.
Get User Information Using Github 0 Resolves a user identity to GitHub account details.
Get User Information Using Github 0 Resolves a user identity to GitHub account details.
Get User Information Using Microsoft Entra ID 0 Resolves a user identity to Microsoft Entra ID account details.
Get User Information Using Microsoft Entra ID 0 Resolves a user identity to Microsoft Entra ID account details.
Enrich - Hash - Crowdstrike 0 Checks a file hash's detection history in CrowdStrike.
Enrich - Hash - Crowdstrike 0 Checks a file hash's detection history in CrowdStrike.
Enrich - IP or Domain - Whois 0 Runs a Whois lookup on an IP or domain for registration context.
Enrich - IP or Domain - Whois 0 Runs a Whois lookup on an IP or domain for registration context.
Enrich - Username or Email - Google Workspace 0 Resolves a username or email to Google Workspace account context.
Enrich - Username or Email - Google Workspace 0 Resolves a username or email to Google Workspace account context.
Enrich - Username or Email - Microsoft Entra ID 0 Resolves a username or email to Microsoft Entra ID account context, including risky-user status.
Enrich - Username or Email - Microsoft Entra ID 0 Resolves a username or email to Microsoft Entra ID account context, including risky-user status.
Utility - Update Enrichment 0 Updates an observable's stored enrichment data.
Recovery - Enrich Non-Enriched Observables 0 Catches observables that were never enriched and reruns enrichment.
Enrich - Username - Github 0 Resolves a username to GitHub identity and activity context.
Enrich - Email Address - Slack 0 Resolves an email address to Slack user identity for context.
Get User Information on Email Address Using Slack 0 Resolves an email address to Slack user profile.
Get User Information Using Okta 0 Resolves a user identity to Okta account details.
Get Hash Info Using Crowdstrike 0 Returns CrowdStrike detection details for a file hash.
Run Dig Command 0 Runs a DNS dig query on a domain or IP for enrichment.
Get End of Life Date for a Product 0 Looks up a software product's end-of-life date to inform risk assessment.
Secure URL Screenshot Capture 0 Captures a sandboxed screenshot of a suspicious URL for analyst review.
Analyze URL with URLScan 0 Submits a URL to URLScan.io for sandboxed analysis and returns the verdict.
Okta Search for User Activity 0 Searches Okta system logs for a user's recent activity.
Get Hash Info Using VirusTotal 0 Returns VirusTotal detection details for a file hash.
Get Machine Info - Medigate Hostname Lookup 0 Resolves a hostname to Claroty Medigate medical-device asset details.
Get Machine Info - Tanium Lookup 0 Resolves a hostname to Tanium-managed endpoint details.
Get Machine Info - Microsoft Defender 0 Resolves a hostname to Microsoft Defender device details.
IP2Hostname Lookup 0 Resolves an IP address to its hostname.
Utility - Update Enrichment 0 Updates an observable's stored enrichment data.
Recovery - Enrich Non-Enriched Observables 0 Catches observables that were never enriched and reruns enrichment.
Enrich - Email Address - Slack 0 Resolves an email address to Slack user identity for context.
Enrich - Username - Github 0 Resolves a username to GitHub identity and activity context.
Get User Information Using Okta 0 Resolves a user identity to Okta account details.
Get Hash Info Using Crowdstrike 0 Returns CrowdStrike detection details for a file hash.
Analyze URL with URLScan 0 Submits a URL to URLScan.io for sandboxed analysis and returns the verdict.
Secure URL Screenshot Capture 0 Captures a sandboxed screenshot of a suspicious URL for analyst review.
Get User Information on Email Address Using Slack 0 Resolves an email address to Slack user profile.
Get Hash Info Using VirusTotal 0 Returns VirusTotal detection details for a file hash.
Run Dig Command 0 Runs a DNS dig query on a domain or IP for enrichment.
Okta Search for User Activity 0 Searches Okta system logs for a user's recent activity.
Get End of Life Date for a Product 0 Looks up a software product's end-of-life date to inform risk assessment.
Get End of Life Date for a Product 0 Looks up a software product's end-of-life date to inform risk assessment.
Okta Search for User Activity 0 Searches Okta system logs for a user's recent activity.
Run Dig Command 0 Runs a DNS dig query on a domain or IP for enrichment.
Enrich IP or Domain Using Whois 0 Runs a Whois lookup on an IP or domain for registration context.
Get Hash Info Using VirusTotal 0 Returns VirusTotal detection details for a file hash.
Get User Information Using Microsoft Entra ID 0 Resolves a user identity to Microsoft Entra ID account details.
Get User Information Using Github 0 Resolves a user identity to GitHub account details.
Get User Information on Email Address Using Slack 0 Resolves an email address to Slack user profile.
Get User Information Using Google Workspace 0 Resolves a user identity to Google Workspace account details.
Secure URL Screenshot Capture 0 Captures a sandboxed screenshot of a suspicious URL for analyst review.
Analyze URL with URLScan 0 Submits a URL to URLScan.io for sandboxed analysis and returns the verdict.
Get Hash Info Using Crowdstrike 0 Returns CrowdStrike detection details for a file hash.
Get User Information Using Okta 0 Resolves a user identity to Okta account details.
Subflow - Update Enrichment Data 0 Writes enrichment results back to the case's observable record.
Enrich - URL - VT 0 Checks a URL's reputation via VirusTotal.
Enrich - Username - Github 0 Resolves a username to GitHub identity and activity context.
Enrich - IP - VT 0 Checks an IP's reputation via VirusTotal.
Enrich - URL - URLScan 0 Submits a URL to URLScan.io for enrichment.
Enrich - IP - IPDB 0 Checks an IP's abuse reputation via AbuseIPDB.
Enrich - Email Address - Slack 0 Resolves an email address to Slack user identity for context.
Enrich - Username or Email - Google Workspace 0 Resolves a username or email to Google Workspace account context.
Enrich - Agent ID - Crowdstrike 0 Resolves a CrowdStrike agent ID to device and user context.
Enrich - Username or Email - Okta 0 Resolves a username or email to Okta account context.
Enrich - Username or Email - Microsoft Entra ID 0 Resolves a username or email to Microsoft Entra ID account context, including risky-user status.
Get Machine Info - Medigate Hostname Lookup 0 Resolves a hostname to Claroty Medigate medical-device asset details.
Get Machine Info - Microsoft Defender 0 Resolves a hostname to Microsoft Defender device details.
Get Machine Info - Tanium Lookup 0 Resolves a hostname to Tanium-managed endpoint details.
IP2Hostname Lookup 0 Resolves an IP address to its hostname.
Enrich - IP or Domain - Whois 0 Runs a Whois lookup on an IP or domain for registration context.
Enrich - Hash - VT 0 Checks a file hash's reputation in VirusTotal.
Enrich - Hash - Crowdstrike 0 Checks a file hash's detection history in CrowdStrike.
Utility - Update Enrichment 0 Updates an observable's stored enrichment data.
Recovery - Enrich Non-Enriched Observables 0 Catches observables that were never enriched and reruns enrichment.
Enrich - Router Default Case 0 Fallback handler for observable types with no dedicated enrichment path.
Enrich - Username or Email - Okta 0 Resolves a username or email to Okta account context.
Get User Information Using Google Workspace 0 Resolves a user identity to Google Workspace account details.
Enrich - Username or Email - Google Workspace 0 Resolves a username or email to Google Workspace account context.
Get Hash Info Using Crowdstrike 0 Returns CrowdStrike detection details for a file hash.
Enrich - URL - VT 0 Checks a URL's reputation via VirusTotal.
Enrich - Crowdstrike Threatgraph Enrichment 0 Pulls CrowdStrike ThreatGraph relationship data for an indicator.
Enrich - IP - IPDB 0 Checks an IP's abuse reputation via AbuseIPDB.
Enrich - URL - URLScan 0 Submits a URL to URLScan.io for enrichment.
Get User Information Using Okta 0 Resolves a user identity to Okta account details.
Get User Information Using Github 0 Resolves a user identity to GitHub account details.
Run Dig Command 0 Runs a DNS dig query on a domain or IP for enrichment.
Secure URL Screenshot Capture 0 Captures a sandboxed screenshot of a suspicious URL for analyst review.
Utility - Update Enrichment 0 Updates an observable's stored enrichment data.
Analyze URL with URLScan 0 Submits a URL to URLScan.io for sandboxed analysis and returns the verdict.
Enrich - Username - Github 0 Resolves a username to GitHub identity and activity context.
Okta Search for User Activity 0 Searches Okta system logs for a user's recent activity.
Enrich - Agent ID - Crowdstrike 0 Resolves a CrowdStrike agent ID to device and user context.
Get Hash Info Using VirusTotal 0 Returns VirusTotal detection details for a file hash.
Get End of Life Date for a Product 0 Looks up a software product's end-of-life date to inform risk assessment.
Enrich - Hash - Crowdstrike 0 Checks a file hash's detection history in CrowdStrike.
Enrich - Email Address - Slack 0 Resolves an email address to Slack user identity for context.
Get User Information on Email Address Using Slack 0 Resolves an email address to Slack user profile.

6. Case & Alert Lifecycle Management

Category: SOC

Subcategories: Case mgmt & SOAR

Description:

Core SOAR plumbing that ingests raw alerts into structured cases, manages observable relationships and deduplication, routes each case to the correct response subflow, and provides recovery and cleanup for the case-and-alert data model.

Business problem solved:

Without a structured case-management backbone, every alert type would need its own bespoke tracking and orphaned or malformed alerts would silently fall through the cracks. This layer standardizes case creation, routing, and hygiene so every alert gets a consistent, auditable lifecycle regardless of source.

Integrations: Blink Case Management · Blink Tables

Playbooks

Playbook Executions Role
Utility - Build Case Feed 1,040 Assembles the consolidated activity feed shown on a case.
Subflow - Response - Main Router 703 Routes a case to the correct threat-specific response subflow based on alert type.
Process Alert 680 Primary event-driven handler that turns an incoming alert into a structured case.
Subflow - Response - Main Router 676 Routes a case to the correct threat-specific response subflow based on alert type.
Process Alert 562 Primary event-driven handler that turns an incoming alert into a structured case.
Process Alert 291 Primary event-driven handler that turns an incoming alert into a structured case.
Subflow - Response - Main Router 290 Routes a case to the correct threat-specific response subflow based on alert type.
Recovery - Handle Unprocessed Alert 148 Catches and reprocesses an alert that failed to create a case on first pass.
Utility - Set Case Status 16 Updates a case's status field.
Utility - List Cases 12 Returns a filtered list of cases.
Utility - Probe Query Shape 5 Diagnostic utility validating case-management query structure during development.
Utility - Automation View Export 3 Exports the current automation inventory/view for reporting.
Utility - Probe Async Inputs 2 Diagnostic utility validating asynchronous input handling in case-management queries.
Subflow - Missing Alert Template Notification 1 Notifies the team when an alert type has no configured template, preventing silent drops.
Utility - Observable Inventory 1 Returns the current observable inventory for a case.
Utility - Probe Input Binding 1 Diagnostic utility validating input-binding behavior in case-management queries.
Subflow - Missing Alert Template Notification 0 Notifies the team when an alert type has no configured template, preventing silent drops.
Subflow - Missing Alert Template Notification 0 Notifies the team when an alert type has no configured template, preventing silent drops.
Subflow - Response - Main Router 0 Routes a case to the correct threat-specific response subflow based on alert type.
Utility - List Observable Alert Relations 0 Lists alerts linked to a given observable.
Utility - Set Or Update Observable Relation 0 Creates or updates a relationship between two observables.
Utility - Delete Observable Relation 0 Removes an observable relationship from a case.
Utility - List Alert Observable Relations 0 Lists observable relationships tied to an alert.
Table Action - Validate Observables Extraction Template 0 Validates that an observable-extraction template is correctly configured.
Utility - Close Stale Cases 0 Automatically closes cases that have gone stale past a defined threshold.
Utility - Find Similar Cases Based on Observables 0 Finds related open or prior cases sharing observables, supporting deduplication.
Recovery - Handle Unprocessed Alerts 0 Catches and reprocesses alerts that failed to create a case on first pass.
Process Alert 0 Primary event-driven handler that turns an incoming alert into a structured case.
Utility - Find Similar Cases Based on Observables 0 Finds related open or prior cases sharing observables, supporting deduplication.
Utility - Delete Observable Relation 0 Removes an observable relationship from a case.
Table Action - Validate Observables Extraction Template 0 Validates that an observable-extraction template is correctly configured.
Utility - List Alert Observable Relations 0 Lists observable relationships tied to an alert.
Utility - Close Stale Cases 0 Automatically closes cases that have gone stale past a defined threshold.
Utility - Set Or Update Observable Relation 0 Creates or updates a relationship between two observables.
Utility - List Observable Alert Relations 0 Lists alerts linked to a given observable.
Recovery - Handle Unprocessed Alerts 0 Catches and reprocesses alerts that failed to create a case on first pass.
Subflow - Missing Alert Template Notification 0 Notifies the team when an alert type has no configured template, preventing silent drops.
Utility - Close Stale Cases 0 Automatically closes cases that have gone stale past a defined threshold.
Utility - Delete Observable Relation 0 Removes an observable relationship from a case.
Utility - Set Or Update Observable Relation 0 Creates or updates a relationship between two observables.
Utility - List Observable Alert Relations 0 Lists alerts linked to a given observable.
Utility - List Alert Observable Relations 0 Lists observable relationships tied to an alert.
Utility - Find Similar Cases Based on Observables 0 Finds related open or prior cases sharing observables, supporting deduplication.
Table Action - Validate Observables Extraction Template 0 Validates that an observable-extraction template is correctly configured.
Recovery - Handle Unprocessed Alerts 0 Catches and reprocesses alerts that failed to create a case on first pass.
Utility - Delete Observable Relation 0 Removes an observable relationship from a case.
Comment On Case 0 Posts an automated comment to a case record.
Table Action - Validate Observables Extraction Template 0 Validates that an observable-extraction template is correctly configured.
Utility - Find Similar Cases Based on Observables 0 Finds related open or prior cases sharing observables, supporting deduplication.
Utility - Set Or Update Observable Relation 0 Creates or updates a relationship between two observables.
Utility - Close Stale Cases 0 Automatically closes cases that have gone stale past a defined threshold.
Get Observables by Case ID 0 Retrieves all observables linked to a case.
Utility - List Alert Observable Relations 0 Lists observable relationships tied to an alert.
Utility - Add Observable Extraction Rule 0 Registers a new rule for extracting observables from alert payloads.
Query Observable 0 Looks up an observable record by identifier.
Utility - List Observable Alert Relations 0 Lists alerts linked to a given observable.

7. Identity Threat Response — Risky User Detection & Remediation

Category: SOC

Subcategories: Identity threat response

Description:

Monitors Microsoft Entra ID risky-user signals and Defender XDR identity alerts (including anomalous logins), routes them to analyst disposition (confirm compromised / confirm safe / dismiss), and provides one-call remediation — session revocation, MFA reset, account suspension, forced password reset — once compromise is confirmed.

Business problem solved:

Identity compromise is one of the fastest-moving threats in a hospital environment, where account takeover can expose patient data. Manually cross-referencing risky-user lists and manually executing remediation steps costs precious response time; this use case closes the loop from detection to remediation in a single, auditable pipeline.

Integrations: Microsoft Entra ID · Microsoft Defender XDR · Splunk · VirusTotal · Microsoft Defender for Endpoint · ServiceNow

Playbooks

Playbook Executions Role
Ingest Microsoft XDR Identity Alerts 960 Scheduled poll for new Microsoft Defender XDR identity alerts, such as risky sign-ins.
Risky User List Monitoring 960 Scheduled poll of the Entra ID risky-user list for new entries.
Response Subflow - Risky User Detections 132 Investigates and actions a flagged risky-user detection end-to-end.
New Password Rotation Needed 9 Opens a ServiceNow ticket when Splunk flags a credential due for rotation.
On Defender XDR Alert (Anomalous Login) 1 Investigates an anomalous-login Defender XDR alert with Splunk and VirusTotal enrichment, then emails the finding.
Response Subflow - Microsoft XDR Identity Alerts 0 Runs the response steps for an identity alert surfaced via Microsoft XDR.
Clean up Risk User List 0 Scheduled cleanup of stale entries from the tracked risky-user list.
Revoke User Sessions 0 Revokes all active sessions for a specified user.
User to PrincipleID 0 Resolves a username to its identity provider principal ID for downstream remediation actions.
Reset User MFA Methods 0 Resets a user's registered MFA methods.
Suspend User Account 0 Suspends a user account pending investigation.
Reactivate User Account 0 Reactivates a previously suspended user account.
Force Password Reset 0 Forces a password reset for a compromised or at-risk account.
Risky User Clean Up 0 Clears resolved entries from the risky-user tracking table.
Dismiss Risky User 0 Dismisses a risky-user alert without further action.
Confirm Safe Risky User 0 Analyst-confirmed disposition that a flagged risky user is a false positive.
Confirm Compromise Risky User 0 Analyst-confirmed disposition that a flagged risky user is compromised, triggering remediation.
Action - Disable User (Entra) 0 Disables a compromised user account in Microsoft Entra ID.
Action - Revoke Sessions (Entra) 0 Revokes all active sessions for a user in Microsoft Entra ID.

8. Vulnerability Scanning, Asset Sync & Ticketing (Tenable)

Category: Vulnerability Mgmt

Subcategories: Vuln scanning, ingest & report, Vuln lifecycle, prioritize, ticket

Description:

Syncs asset inventory and vulnerability findings from Tenable into Blink Tables, supports on-demand self-service scans, and automatically opens ServiceNow tickets for qualifying high/critical findings.

Business problem solved:

Manually triaging vulnerability scan output and opening a ticket for every finding doesn't scale. This pipeline gives the security team a running asset/vulnerability data store and auto-generates remediation tickets for the findings that matter most, while giving requesters a self-service path to trigger targeted scans.

Integrations: Tenable · ServiceNow · Splunk · Blink Tables

Playbooks

Playbook Executions Role
Webhook for Tennable VM Ticket Generation 84 Opens a ServiceNow ticket automatically when Tenable reports a qualifying vulnerability.
Webhook for Tennable VM Ticket Generation 82 Opens a ServiceNow ticket automatically when Tenable reports a qualifying vulnerability.
Sync - Org Assets 34 Scheduled sync of the organization's asset inventory from Tenable.
Enrich - Hostname - Tenable Vulnerabilities 26 Pulls known vulnerabilities for a hostname from Tenable.
Enrich - IP Address - Asset Identity (Tenable) 21 Resolves an IP address to its Tenable asset identity.
Vuln Scanner - Table Creation 5 Provisions the Blink Tables used to store Tenable scan results.
Vuln Scanner - Table Creation 5 Provisions the Blink Tables used to store Tenable scan results.
Tenable Device Details by IPv4 0 Looks up full Tenable asset detail for a given IP address.
Tenable Device Details by IPv4 0 Looks up full Tenable asset detail for a given IP address.
Create Table and Schema from JSON 0 Provisions a new Blink Table and schema from a JSON definition, used to stand up vulnerability data stores.
Self Service Tenable Scan 0 On-demand self-service trigger for a targeted Tenable vulnerability scan.
Poll for Complete Tenable Scan and Email Results 0 Waits for a Tenable scan to finish and emails the report to the requester.
Vulnerability Submissions for High and Critical 0 Webhook trigger for newly submitted high/critical vulnerability findings from Splunk.

9. Security Metrics & Reporting

Category: GRC

Subcategories: Security metrics & reporting

Description:

Refreshes the AI SOC 360 dashboard on a daily schedule, giving stakeholders an always-current view of SOC automation performance and case metrics.

Business problem solved:

Without a live dashboard, leadership visibility into SOC throughput and AI-agent performance depends on manual reporting; this workflow keeps a stakeholder-facing view continuously refreshed.

Integrations: Blink Case Management

Playbooks

Playbook Executions Role
AI SOC 360 - Build Dashboard 21 Daily scheduled refresh of the AI SOC performance and case-metrics dashboard.

10. Platform Testing & Environment Scaffolding

Category: Other

Subcategories: DevOps & release automation

Description:

Non-production workflows used to validate integration connectivity, simulate alerts for pipeline testing, reset the case-management sandbox, and scaffold new automations, plus a handful of unconfigured onboarding templates.

Business problem solved:

Safely testing new detections and integrations requires alert simulators and disposable environments that don't touch production case data; these workflows support that without representing security automation in their own right.

Integrations: CrowdStrike · ServiceNow · Tanium · Tenable

Playbooks

Playbook Executions Role
ZZ CONN TEST 1 Validates Tanium and Tenable connection health.
Error Handling - Send Error Notification Email 0 Sends an email notification when an automation encounters an unhandled error.
Error Handling - Send Error Notification Email 0 Sends an email notification when an automation encounters an unhandled error.
Getting Started - Hello World 0 Default starter workflow created during platform onboarding.
Test 0 Placeholder workflow used for ad hoc platform testing.
Simulate Multiple Alerts from Different Sources 0 Generates a batch of synthetic multi-source alerts for pipeline load-testing.
USE WITH CARE - Reset Case Management Environment 0 Bulk-resets case management test data in a non-production workspace.
Simulate Crowdstrike Alert 0 Generates a synthetic CrowdStrike alert to test the case-creation pipeline.
Simulate Crowdstrike Alert 0 Generates a synthetic CrowdStrike alert to test the case-creation pipeline.
Simulate Multiple Alerts from Different Sources 0 Generates a batch of synthetic multi-source alerts for pipeline load-testing.
USE WITH CARE - Reset Case Management Environment 0 Bulk-resets case management test data in a non-production workspace.
ServiceNow End 2 End Testing 0 Validates ServiceNow connectivity and record creation end-to-end in a test instance.
Hello World 0 Default starter workflow created during platform onboarding.
Example Subflow 0 Template subflow left over from platform onboarding, not used in production.
New Workflow 1 0 Empty placeholder workflow, not used in production.
New Workflow 0 Empty placeholder workflow, not used in production.
Intake Form 0 Web-form intake scaffold, not yet wired into a production process.
Feedback Form 0 Web-form intake scaffold, not yet wired into a production process.
USE WITH CARE - Reset Case Management Environment 0 Bulk-resets case management test data in a non-production workspace.
Simulate Multiple Alerts from Different Sources 0 Generates a batch of synthetic multi-source alerts for pipeline load-testing.
Simulate Crowdstrike Alert 0 Generates a synthetic CrowdStrike alert to test the case-creation pipeline.
Error Handling - Send Error Notification Email 0 Sends an email notification when an automation encounters an unhandled error.
Error Handling - Send Error Notification Email 0 Sends an email notification when an automation encounters an unhandled error.

11. EDR Containment & Response Actions

Category: SOC

Subcategories: EDR containment & response

Description:

A ready-to-invoke library of endpoint containment actions spanning CrowdStrike, Microsoft Defender for Endpoint, and Tanium — host isolation and release, hash/IOC quarantine, antivirus scans, and remote live-response queries.

Business problem solved:

When a device is confirmed compromised, the speed of containment directly limits blast radius. This library gives analysts and the AI agent a standardized, one-call path to isolate a host or quarantine a hash instead of navigating each EDR console by hand — built and ready, currently awaiting activation into the response pipeline.

Integrations: CrowdStrike · Microsoft Defender for Endpoint · Tanium

Playbooks

Playbook Executions Role
Get Question Result with Tanium and Send Results via Email 0 Runs a Tanium question against endpoints and emails the results.
Get Sensor with Tanium and Send Results via Email 0 Runs a Tanium sensor query against endpoints and emails the results.
CrowdStrike RTR to a Single Host 0 Runs a CrowdStrike Real Time Response command on a single host.
CrowdStrike RTR to a Batch of Hosts 0 Runs a CrowdStrike Real Time Response command across a batch of hosts.
Manage Endpoint Quarantine Status in Crowdstrike 0 Quarantines or releases a file/host in CrowdStrike.
Isolate Host - MS Defender for Endpoint 0 Network-isolates a compromised host via Microsoft Defender for Endpoint.
Release Host - MS Defender for Endpoint 0 Releases a host from network isolation in Microsoft Defender for Endpoint.
CrowdStrike RTR to a Single Host 0 Runs a CrowdStrike Real Time Response command on a single host.
CrowdStrike RTR to a Batch of Hosts 0 Runs a CrowdStrike Real Time Response command across a batch of hosts.
Manage Endpoint Quarantine Status in Crowdstrike 0 Quarantines or releases a file/host in CrowdStrike.
Release Host - MS Defender for Endpoint 0 Releases a host from network isolation in Microsoft Defender for Endpoint.
Isolate Host - MS Defender for Endpoint 0 Network-isolates a compromised host via Microsoft Defender for Endpoint.
Manage Endpoint Quarantine Status in Crowdstrike 0 Quarantines or releases a file/host in CrowdStrike.
CrowdStrike RTR to a Batch of Hosts 0 Runs a CrowdStrike Real Time Response command across a batch of hosts.
CrowdStrike RTR to a Single Host 0 Runs a CrowdStrike Real Time Response command on a single host.
CrowdStrike RTR to a Batch of Hosts 0 Runs a CrowdStrike Real Time Response command across a batch of hosts.
CrowdStrike RTR to a Single Host 0 Runs a CrowdStrike Real Time Response command on a single host.
Manage Endpoint Quarantine Status in Crowdstrike 0 Quarantines or releases a file/host in CrowdStrike.
Action - Isolate Host (Defender) 0 Network-isolates a host via Microsoft Defender.
Action - Release Host Isolation (Defender) 0 Releases a previously isolated host in Microsoft Defender.
Action - Run Antivirus Scan (Defender) 0 Triggers an on-demand antivirus scan via Microsoft Defender.

12. IT Request Routing — ServiceNow to Monday.com

Category: Other

Subcategories: IT helpdesk & ticket routing

Description:

Converts new Splunk-related ServiceNow request items (RITMs) assigned to the security operations team into Monday.com tasks, so the security engineering team can track fulfillment work in its own tool.

Business problem solved:

Security engineering fulfillment work is tracked in Monday.com while requests originate in ServiceNow; this bridges the two systems so request items don't require manual re-entry.

Integrations: ServiceNow · Monday.com

Playbooks

Playbook Executions Role
Create Monday Tasks from Service now RITMs 0 Converts new Splunk-related ServiceNow request items into Monday.com tasks for the security engineering team.

Key Observations

Strengths

  • Agentic SOC is the deepest single investment in the automation footprint. At 43 playbooks — the largest library by playbook count — the AI investigation agent has its own callable tool library of 26+ "Agent Ability" actions spanning Splunk, ServiceNow, Tenable, Tanium, and case-management context, plus a dedicated model-evaluation harness (labeled-dataset scoring and re-run tooling) used to continuously tune investigation accuracy against ground truth. This is a materially more mature Agentic SOC deployment than a typical single-playbook AI-triage integration.
  • ServiceNow synchronization is the automation backbone. At 127K+ executions, real-time case-to-ticket sync is by a wide margin the most-executed automation, meaning ServiceNow reliably reflects live case status for every team outside the SOC without manual re-entry.
  • Broad, structured enrichment coverage. A 40-tool enrichment library normalizes hashes, IPs, URLs, hostnames, and identities across VirusTotal, CrowdStrike, Okta, Microsoft Entra ID, URLScan.io, AbuseIPDB, GitHub, Slack, and Google Workspace behind a single routing layer, so analysts and the AI agent get a consistent verdict regardless of observable type.
  • Healthcare-specific asset context. The Claroty Medigate integration (hostname-to-medical-device lookup) gives investigations clinical/IoMT context that generic SOC tooling doesn't provide — directly relevant to a hospital's unique attack surface.
  • Identity remediation is a complete, one-call toolkit. Session revocation, MFA reset, account suspension/reactivation, and forced password reset are all built as standalone, callable actions alongside Entra ID risky-user monitoring and Defender XDR identity-alert ingestion, giving the identity response pipeline everything it needs end-to-end.

Gaps & Opportunities

  • EDR containment library is fully built but unused. All 10 CrowdStrike/Defender/Tanium containment playbooks (host isolation, quarantine, RTR, antivirus scan) show zero executions in the trailing 12 months — the capability exists but isn't yet wired into the automatic response path from the AI investigation or identity-threat workflows.
  • Identity remediation actions are idle. The core remediation calls (Force Password Reset, Suspend User Account, Revoke User Sessions, Reset User MFA Methods, Confirm Compromise Risky User, Entra disable/revoke-session actions) all show zero executions, while detection-side workflows (risky-user monitoring, Defender XDR identity alerts) are active — suggesting confirmed risky-user cases are currently being remediated manually rather than through the automated action library already in place.
  • Workspace duplication adds maintenance overhead. Core playbooks (case sync, alert ingestion, enrichment) are deployed nearly identically across 8 separate workspaces under the same tenant. Consolidating to a clear dev/staging/production boundary — or fully retiring unused copies — would reduce the surface area that needs to stay in sync when a playbook is updated.
  • 23 platform-testing and scaffolding workflows carry effectively zero production executions, including unconfigured onboarding templates (Hello World, Intake Form, Feedback Form, empty "New Workflow" placeholders). These are reasonable to keep for sandbox testing but are candidates for archival to keep the production automation inventory clean.
  • No dedicated GRC/compliance automation beyond dashboard reporting. Access review, audit-evidence collection, or compliance-questionnaire workflows aren't yet represented — a natural next step given the identity and case-management foundation already in place.

Integration Ecosystem

Integration Role in the Automation Footprint
ServiceNow System of record for tickets/incidents; two-way sync with Blink Case Management
Splunk Primary SIEM — alert ingestion, AI-agent threat hunting, risk-based alerting, pipeline health checks
Microsoft Defender XDR / Defender for Endpoint XDR and endpoint alert ingestion, identity alerts, endpoint containment actions
Tenable Vulnerability scanning, asset inventory sync, high/critical finding ticketing
Tanium Endpoint posture queries for AI investigation and containment actions
CrowdStrike EDR enrichment (hash/agent/ThreatGraph lookups) and RTR/quarantine containment actions
Microsoft Entra ID Risky-user identity signals, account enrichment, session/account remediation
Okta Identity enrichment and user activity search
VirusTotal / URLScan.io / AbuseIPDB Threat intelligence enrichment for hashes, URLs, and IPs
Proofpoint TAP Phishing threat and Very Attacked People (VAP) ingestion
Claroty Medigate Medical device / clinical asset context — hospital-specific enrichment
GitHub / Slack / Google Workspace Supplementary identity enrichment across collaboration and dev tooling
Monday.com Downstream task tracking for security engineering fulfillment work
Blink Case Management / Blink Tables / Blink AI Agents Blink-native case lifecycle, data storage, and AI agent orchestration
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
CNH 2lo_auth identityiq_test 2026-08-27