01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| ServiceNow Case Synchronization |
| 74.8% | 4 3 active |
| Agentic SOC — Autonomous AI Case Investigation |
| 16.0% | 43 43 active |
| Phishing & Email Threat Response |
| 2.1% | 6 6 active |
| SIEM & XDR Alert Ingestion | 5,743 executions | 2.8% | 10 10 active |
| Alert & Observable Enrichment Library | 3,732 executions | 1.8% | 40 40 active |
| Case & Alert Lifecycle Management |
| 1.4% | 24 24 active |
| Identity Threat Response — Risky User Detection & Remediation |
| 1.0% | 19 19 active |
| Vulnerability Scanning, Asset Sync & Ticketing (Tenable) |
| 0.1% | 10 10 active |
| Security Metrics & Reporting |
| 0.0% | 1 1 active |
| Platform Testing & Environment Scaffolding | 0 executions | 0.0% | 15 11 active |
| EDR Containment & Response Actions | 0 executions | 0.0% | 10 10 active |
| IT Request Routing — ServiceNow to Monday.com | 0 executions | 0.0% | 1 1 active |
| Total | 206,194 executions | 100% | 183 178 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Agentic SOC is the deepest single investment in the automation footprint. At 43 playbooks — the largest library by playbook count — the AI investigation agent has its own callable tool library of 26+ "Agent Ability" actions spanning Splunk, ServiceNow, Tenable, Tanium, and case-management context, plus a dedicated model-evaluation harness (labeled-dataset scoring and re-run tooling) used to continuously tune investigation accuracy against ground truth. This is a materially more mature Agentic SOC deployment than a typical single-playbook AI-triage integration.
- ServiceNow synchronization is the automation backbone. At 127K+ executions, real-time case-to-ticket sync is by a wide margin the most-executed automation, meaning ServiceNow reliably reflects live case status for every team outside the SOC without manual re-entry.
- Broad, structured enrichment coverage. A 40-tool enrichment library normalizes hashes, IPs, URLs, hostnames, and identities across VirusTotal, CrowdStrike, Okta, Microsoft Entra ID, URLScan.io, AbuseIPDB, GitHub, Slack, and Google Workspace behind a single routing layer, so analysts and the AI agent get a consistent verdict regardless of observable type.
- Healthcare-specific asset context. The Claroty Medigate integration (hostname-to-medical-device lookup) gives investigations clinical/IoMT context that generic SOC tooling doesn't provide — directly relevant to a hospital's unique attack surface.
- Identity remediation is a complete, one-call toolkit. Session revocation, MFA reset, account suspension/reactivation, and forced password reset are all built as standalone, callable actions alongside Entra ID risky-user monitoring and Defender XDR identity-alert ingestion, giving the identity response pipeline everything it needs end-to-end.
###
Gaps & Opportunities
- EDR containment library is fully built but unused. All 10 CrowdStrike/Defender/Tanium containment playbooks (host isolation, quarantine, RTR, antivirus scan) show zero executions in the trailing 12 months — the capability exists but isn't yet wired into the automatic response path from the AI investigation or identity-threat workflows.
- Identity remediation actions are idle. The core remediation calls (Force Password Reset, Suspend User Account, Revoke User Sessions, Reset User MFA Methods, Confirm Compromise Risky User, Entra disable/revoke-session actions) all show zero executions, while detection-side workflows (risky-user monitoring, Defender XDR identity alerts) are active — suggesting confirmed risky-user cases are currently being remediated manually rather than through the automated action library already in place.
- Workspace duplication adds maintenance overhead. Core playbooks (case sync, alert ingestion, enrichment) are deployed nearly identically across 8 separate workspaces under the same tenant. Consolidating to a clear dev/staging/production boundary — or fully retiring unused copies — would reduce the surface area that needs to stay in sync when a playbook is updated.
- 23 platform-testing and scaffolding workflows carry effectively zero production executions, including unconfigured onboarding templates (Hello World, Intake Form, Feedback Form, empty "New Workflow" placeholders). These are reasonable to keep for sandbox testing but are candidates for archival to keep the production automation inventory clean.
- No dedicated GRC/compliance automation beyond dashboard reporting. Access review, audit-evidence collection, or compliance-questionnaire workflows aren't yet represented — a natural next step given the identity and case-management foundation already in place.
Integration Ecosystem
| Integration | Role in the Automation Footprint |
|---|---|
| ServiceNow | System of record for tickets/incidents; two-way sync with Blink Case Management |
| Splunk | Primary SIEM — alert ingestion, AI-agent threat hunting, risk-based alerting, pipeline health checks |
| Microsoft Defender XDR / Defender for Endpoint | XDR and endpoint alert ingestion, identity alerts, endpoint containment actions |
| Tenable | Vulnerability scanning, asset inventory sync, high/critical finding ticketing |
| Tanium | Endpoint posture queries for AI investigation and containment actions |
| CrowdStrike | EDR enrichment (hash/agent/ThreatGraph lookups) and RTR/quarantine containment actions |
| Microsoft Entra ID | Risky-user identity signals, account enrichment, session/account remediation |
| Okta | Identity enrichment and user activity search |
| VirusTotal / URLScan.io / AbuseIPDB | Threat intelligence enrichment for hashes, URLs, and IPs |
| Proofpoint TAP | Phishing threat and Very Attacked People (VAP) ingestion |
| Claroty Medigate | Medical device / clinical asset context — hospital-specific enrichment |
| GitHub / Slack / Google Workspace | Supplementary identity enrichment across collaboration and dev tooling |
| Monday.com | Downstream task tracking for security engineering fulfillment work |
| Blink Case Management / Blink Tables / Blink AI Agents | Blink-native case lifecycle, data storage, and AI agent orchestration |
A Case Management 1,466 cases (12m) | MTTR 5d 11h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| AI SOC | 701 | 701 | 564 | 8h 26m |
| Case Management V9 | 446 | 446 | 393 | 14d 5h |
| Dev Workspace | 319 | 319 | 100 | 1h 41m |
B AI Agents 6 active | 3,669 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | SOC Analyst | AI SOC | 1,875 | 930 | 445,828,827 |
| 2 | SOC Agent - Suspicious Network Activity Agent | AI SOC | 825 | 423 | 223,073,188 |
| 3 | Micro Agent - Historical Case Check | AI SOC | 788 | 526 | 43,929,805 |
| 4 | SOC Agent - Compliance & Endpoint Agent | AI SOC | 160 | 109 | 51,749,392 |
| 5 | SOC Agent - Reconnaissance Agent | AI SOC | 16 | 15 | 6,180,439 |
| Workspace | Tasks (12m) |
|---|---|
| AI SOC | 3,669 |
| Case Management V9 | 0 |
| Dev Workspace | 0 |
| Case Management | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Tenable | 0 | 0 |
| 2 | Very Attacked Person List | 0 | 0 |
| 3 | SOC Overview | 0 | 0 |
| 4 | AI SOC Automation Map | 0 | 0 |
| 5 | Children's National - Automation View | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Access Help Request | 0 | 0 |
| 2 | Blink Automation Feedback Form | 0 | 0 |
| 3 | New Automation Request | 0 | 0 |
| 4 | please fill in form | 0 | 0 |
| 5 | New Automation Intake Form | 0 | 0 |
D Full Use Case Analysis 12 use cases | 206,194 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security case updates synchronized to ServiceNow in real time | 127,195 | Sync Case with ServiceNow |
| Raw security alerts triaged into structured investigation cases | 1,533 | Process Alert |
| Cases investigated end-to-end by the autonomous AI SOC agent | 860 | Agentic SOC - Decision Layer |
| Proofpoint-flagged phishing & Very Attacked People threats investigated & responded to | 676 | Response Subflow - Proofpoint TAP |
| High/critical vulnerability tickets auto-generated in ServiceNow from Tenable findings | 166 | Webhook for Tennable VM Ticket Generation |
| Risky-user identity threats investigated & remediated | 132 | Response Subflow - Risky User Detections |
| MSSP-reported incidents ingested as new cases from ServiceNow | 30 | ServiceNow MSSP |
| SOC performance dashboard refreshes delivered to stakeholders | 21 | AI SOC 360 - Build Dashboard |
Use Case Summary
| # | Use Case | Category | Playbook Count | Executions (12mo) |
|---|---|---|---|---|
| 1 | ServiceNow Case Synchronization | SOC | 6 | 131,137 |
| 2 | Agentic SOC — Autonomous AI Case Investigation | SOC | 43 | 32,651 |
| 3 | Phishing & Email Threat Response | SOC | 10 | 5,569 |
| 4 | SIEM & XDR Alert Ingestion | SOC | 12 | 4,913 |
| 5 | Alert & Observable Enrichment Library | SOC | 138 | 4,802 |
| 6 | Case & Alert Lifecycle Management | SOC | 56 | 4,431 |
| 7 | Identity Threat Response — Risky User Detection & Remediation | SOC | 19 | 2,062 |
| 8 | Vulnerability Scanning, Asset Sync & Ticketing (Tenable) | Vulnerability Mgmt | 13 | 257 |
| 9 | Security Metrics & Reporting | GRC | 1 | 21 |
| 10 | Platform Testing & Environment Scaffolding | Other | 23 | 1 |
| 11 | EDR Containment & Response Actions | SOC | 21 | 0 |
| 12 | IT Request Routing — ServiceNow to Monday.com | Other | 1 | 0 |
Use Cases
1. ServiceNow Case Synchronization
Category: SOC
Subcategories: Case mgmt & SOAR
Description:
Keeps every security case created in Blink Case Management mirrored in ServiceNow in near real time, with an hourly reconciliation pass, and ingests MSSP-reported incidents from ServiceNow back in as new Blink cases.
Business problem solved:
SOC and hospital IT operate from different systems of record — without continuous two-way sync, ServiceNow tickets go stale and stakeholders outside the SOC lose visibility into case status, while MSSP-flagged incidents would otherwise require manual re-entry. This pipeline makes ServiceNow the reliable, always-current record of case status across the organization.
Integrations: ServiceNow · Blink Case Management
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Sync Case with ServiceNow | 101,630 | Pushes every case create/update to its mirrored ServiceNow ticket in real time. |
| Sync Case with ServiceNow | 25,565 | Pushes every case create/update to its mirrored ServiceNow ticket in real time. |
| Hourly Sync | 1,920 | Scheduled hourly reconciliation that re-syncs all open cases against their ServiceNow tickets. |
| Hourly Sync | 1,920 | Scheduled hourly reconciliation that re-syncs all open cases against their ServiceNow tickets. |
| On Case Closure | 72 | Confirms the linked ServiceNow incident is closed when a Blink case is closed. |
| ServiceNow MSSP | 30 | Ingests new MSSP-reported incidents from ServiceNow as Blink cases with an auto-generated summary. |
2. Agentic SOC — Autonomous AI Case Investigation
Category: SOC
Subcategories: Agentic SOC, Threat hunting & detection
Description:
An AI agent investigates incoming cases end-to-end using a library of over 30 callable tools — pulling case and asset context, hunting across Splunk, checking Tenable/Tanium/ServiceNow records, and following documented investigation guidelines — then produces a triage recommendation, with a labeled-dataset evaluation harness used to score and tune investigation accuracy.
Business problem solved:
Tier-1 triage historically consumed the majority of analyst time on repetitive, multi-system data-gathering before a human could even begin judging an alert. This use case gives every case a first-pass AI investigation using the same toolset a human analyst would use, freeing analysts to focus on judgment calls and true positives rather than data collection.
Integrations: Splunk · ServiceNow · Tenable · Tanium · Blink Case Management · Blink AI Agents
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Agent Ability - Run Splunk Search | 7,887 | Executes an ad hoc Splunk search on the agent's behalf — the most heavily used investigation tool in the library. |
| Agent Ability - Get Case By Case ID | 4,421 | Looks up a case by ID so the agent can pull it into context. |
| Utility - Log Investigation Activity | 2,497 | Records each AI investigation step to the case's activity log for auditability. |
| Utility - Read Agentic Output | 2,282 | Reads structured output from a completed agent investigation step. |
| Agent Ability - Get Org Assets | 1,756 | Retrieves organizational asset inventory to establish investigation context. |
| Agent Ability - Get VIP Users | 1,285 | Flags whether an entity in the case is a VIP user, raising investigation priority. |
| Agent Ability - Hunt Indicator Activity (Splunk) | 1,216 | Hunts Splunk for prior activity involving a given indicator. |
| Agent Ability - Get Change Records (ServiceNow) | 1,166 | Pulls related ServiceNow change records so the agent can rule out planned maintenance as a cause. |
| Agent Ability - Get Splunk Risk Contributors | 1,038 | Pulls Splunk risk-based-alerting contributors for an entity. |
| Agent Ability - Hunt Outbound Contact (Splunk) | 1,036 | Hunts Splunk for outbound network contact from an entity. |
| Utility - Sanitize Case From Prior Investigation | 863 | Clears stale investigation artifacts before re-running AI investigation. |
| Utility - Truncate Case & Alert | 863 | Trims oversized case/alert payloads so they fit within the agent's context limits. |
| Agentic SOC - Decision Layer | 860 | Top-level orchestrator that runs a case through AI investigation and issues the final triage decision. |
| Subflow - Agentic SOC - Main - AI Investigation | 860 | Runs the core AI investigation loop, calling agent tools to build the case narrative. |
| Agent Ability - Get Case Observable's Enrichment | 845 | Surfaces existing enrichment data for a case's observables to the agent. |
| Agentic SOC - Expert Agents | 842 | Invokes specialized micro-agents for domain-specific analysis within an investigation. |
| Agent Ability - Get Investigation Guidelines | 839 | Supplies the agent with the documented investigation playbook for the alert type. |
| Agent Ability - Historical Case Checks | 725 | Checks for related historical cases and appends findings to the case record. |
| Agent Ability - Get Case | 464 | Retrieves the full case record for the AI agent to reason over. |
| Agent Ability - Hunt Authentication Activity (Splunk) | 390 | Hunts Splunk authentication logs for an entity's login activity. |
| Subflow - Post-Investigation Finalisation | 270 | Finalizes case documentation once the AI investigation completes. |
| Utility - Refresh investigation | 205 | Re-triggers AI investigation on a case, e.g. after new evidence arrives. |
| Agent Ability - Get Endpoint Posture (Tanium) | 20 | Queries Tanium for real-time endpoint posture on an entity under investigation. |
| Agent Ability - Query Observables by Content | 9 | Searches existing observables by content to surface related evidence. |
| Utility - Read Investigation Activity | 6 | Reads back logged investigation activity for a case. |
| Agent Ability - Get Splunk Schema | 3 | Returns available Splunk index/field schema so the agent can construct valid searches. |
| Agent Ability - Get Observable Reputations From Case Management Settings | 1 | Returns configured reputation thresholds the agent uses to judge observable verdicts. |
| Agent Ability - Get Identity Governance (SailPoint) | 1 | Queries Splunk-indexed SailPoint identity governance data for an entity. |
| Agent Ability - Resolve Asset (Tenable) | 1 | Resolves an entity to its Tenable asset record for vulnerability context. |
| Agent Ability - Recommendation for case | 0 | Generates the agent's triage/response recommendation for a case. |
| SubFlow - Context Enrichment | 0 | Builds an observable profile to enrich investigation context. |
| Agentic SOC - Close Case | 0 | Closes a case automatically once the AI agent reaches a high-confidence disposition. |
| Agent Ability - Get Vendor Logo List | 0 | Supplies known vendor branding data used to spot phishing brand impersonation. |
| Agent Ability - Get Observable Relation Types From Case Management Settings | 0 | Returns the configured observable relationship types the agent can use when linking evidence. |
| Load cases taggings from csv | 0 | Loads analyst-labeled case tags used as ground truth for model evaluation. |
| Load cases predictions from conclusions | 0 | Loads AI-generated case predictions for evaluation against ground truth. |
| Main Evaluation - Evaluate On Cases dataset | 0 | Scores AI investigation accuracy against a labeled case dataset. |
| Agent Ability - Get Observable Types From Case Management Settings | 0 | Returns the configured observable types available to the agent. |
| Refresh investigations on case dataset | 0 | Re-runs AI investigation across the evaluation dataset after a model or prompt change. |
| Agent Ability - Get Alert | 0 | Retrieves full alert detail for the case under investigation. |
| Agent Ability - Get Org Technological Stack | 0 | Supplies the agent with the org's technology stack for investigation context. |
| Agent Ability - Get Email Threat Context (Proofpoint) | 0 | Queries Splunk-indexed Proofpoint email data for threat context on an entity. |
| Agent Ability - Profile Entity Baseline (Splunk) | 0 | Builds a Splunk-based behavioral baseline for an entity to spot deviation. |
3. Phishing & Email Threat Response
Category: SOC
Subcategories: Phishing detection & response
Description:
Ingests phishing threats and Very Attacked People (VAP) signals from Proofpoint TAP on a schedule and routes each confirmed alert through a dedicated investigation-and-response subflow.
Business problem solved:
Email remains the leading initial-access vector, and hospital staff are frequent phishing targets. This pipeline gives every Proofpoint-flagged threat a consistent, automated response path instead of relying on ad hoc analyst handling, and feeds the VAP list into Splunk so high-value targets are weighted appropriately elsewhere in the detection stack.
Integrations: Proofpoint TAP · Splunk · Blink Case Management
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Proofpoint TAP Alert Ingestion | 3,839 | Scheduled poll that pulls new Proofpoint TAP threat alerts into the case pipeline. |
| Proofpoint TAP Alert Ingestion | 1,054 | Scheduled poll that pulls new Proofpoint TAP threat alerts into the case pipeline. |
| Response Subflow - Proofpoint TAP | 530 | Investigates and actions a Proofpoint TAP alert end-to-end. |
| Response Subflow - Proofpoint TAP | 146 | Investigates and actions a Proofpoint TAP alert end-to-end. |
| Response Subflow - Phishing | 0 | Runs the phishing-specific investigation and remediation steps for a case. |
| Response Subflow - Phishing | 0 | Runs the phishing-specific investigation and remediation steps for a case. |
| Pull VAP List and Add to Table | 0 | Pulls Proofpoint's Very Attacked People (VAP) list and stores it in Blink Tables. |
| Phishing Alerts (Proofpoint) | 0 | Event trigger that ingests a phishing alert flagged by Proofpoint TAP. |
| VAP List to Splunk | 0 | Forwards the Very Attacked People list to Splunk for correlation with other alerting. |
| Response Subflow - Phishing | 0 | Runs the phishing-specific investigation and remediation steps for a case. |
4. SIEM & XDR Alert Ingestion
Category: SOC
Subcategories: SIEM & log pipeline monitoring
Description:
Polls Splunk and Microsoft Defender XDR/Endpoint for new alerts, opens linked ServiceNow tickets for cross-team follow-up, and separately watches the pipeline's own health — certificate expiry, missing data feeds — so gaps are caught early.
Business problem solved:
A detection pipeline is only as good as its uptime and its ability to route findings to the right team. These workflows bring new SIEM/XDR alerts into the case queue and ticket queues, while dedicated health-check workflows monitor the pipeline itself so silent failures (an expired certificate, a stalled Workday feed) don't become blind spots.
Integrations: Splunk · Microsoft Defender XDR · Microsoft Defender for Endpoint · ServiceNow · Blink Case Management
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Ingest - CNMC Splunk | 3,110 | Scheduled poll that pulls new Splunk-correlated alerts into the case pipeline. |
| DEMO Ingest Workflow (custom splunk events) | 960 | Scheduled test ingestion of custom Splunk events used to validate the pipeline. |
| New Defender Alert | 607 | Event trigger on new Microsoft Defender XDR alerts. |
| Ingest - CNMC Defender for Endpoint | 208 | Event trigger that pulls new Microsoft Defender for Endpoint alerts into the case pipeline. |
| Splunk Triggered Event | 18 | Generic Splunk-triggered event handler that opens a ServiceNow ticket. |
| Splunk Query - Upcoming Certificate Expiration | 10 | Checks Splunk for certificates approaching expiry and alerts the team. |
| Response Subflow - Malware | 0 | Runs malware-specific investigation and remediation steps for a case. |
| Response Subflow - Malware | 0 | Runs malware-specific investigation and remediation steps for a case. |
| Splunk Alert | 0 | Generic event trigger for a Splunk-sourced alert. |
| Response Subflow - Malware | 0 | Runs malware-specific investigation and remediation steps for a case. |
| Automated Defender Actions | 0 | Turns a Defender XDR incident into linked ServiceNow tickets for both the SecOps and IAM teams. |
| Splunk Query - Workday Data Not Being Ingested | 0 | Monitors for a break in the Workday-to-Splunk data feed. |
5. Alert & Observable Enrichment Library
Category: SOC
Subcategories: Alert enrichment / IOC lookup
Description:
A large modular library that enriches every observable type extracted from a case — hashes, IPs, URLs, hostnames, usernames — against threat intel, identity, and asset sources, with a central router dispatching each observable to the correct enrichment workflow and writing results back to the case.
Business problem solved:
Analysts previously had to manually pivot across a dozen separate consoles — VirusTotal, CrowdStrike, Okta, Entra ID, URLScan, AbuseIPDB, GitHub, Slack, Google Workspace, Claroty — to build context on a single indicator. This library returns a structured verdict for any observable type through one consistent interface, including hospital-specific context such as whether a hostname belongs to a clinical medical device.
Integrations: VirusTotal · CrowdStrike · Okta · Microsoft Entra ID · URLScan.io · AbuseIPDB · GitHub · Slack · Google Workspace · Claroty Medigate · Microsoft Defender for Endpoint · Tanium · Blink Case Management
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Subflow - Enrich Observables - Main Router | 1,885 | Central dispatcher that routes each observable to its type-specific enrichment workflow. |
| Subflow - Enrich Observables - Main Router | 707 | Central dispatcher that routes each observable to its type-specific enrichment workflow. |
| Subflow - Update Enrichment Data | 523 | Writes enrichment results back to the case's observable record. |
| Subflow - Enrich Observables - Main Router | 333 | Central dispatcher that routes each observable to its type-specific enrichment workflow. |
| Utility - Extract Decoded PowerShell | 273 | Decodes obfuscated or encoded PowerShell command lines for analysis. |
| Get Machine Info - Microsoft Defender | 139 | Resolves a hostname to Microsoft Defender device details. |
| Get Machine Info - Tanium Lookup | 137 | Resolves a hostname to Tanium-managed endpoint details. |
| Get Machine Info - Medigate Hostname Lookup | 137 | Resolves a hostname to Claroty Medigate medical-device asset details. |
| IP2Hostname Lookup | 137 | Resolves an IP address to its hostname. |
| Enrich - IP - VT | 111 | Checks an IP's reputation via VirusTotal. |
| Enrich IP or Domain Using Whois | 98 | Runs a Whois lookup on an IP or domain for registration context. |
| Enrich - IP or Domain - Whois | 98 | Runs a Whois lookup on an IP or domain for registration context. |
| Enrich - Hash - VT | 73 | Checks a file hash's reputation in VirusTotal. |
| Enrich - Hostname - Microsoft Defender for Endpoint | 73 | Pulls Microsoft Defender for Endpoint device context for a hostname. |
| Enrich - Hostname - Claroty Medical Device Context | 27 | Looks up whether a hostname belongs to a clinical medical device via Claroty Medigate. |
| Get User Information Using Microsoft Entra ID | 17 | Resolves a user identity to Microsoft Entra ID account details. |
| Enrich - Username or Email - Microsoft Entra ID | 17 | Resolves a username or email to Microsoft Entra ID account context, including risky-user status. |
| Enrich - Check If Observable inside Organization | 15 | Flags whether an observable (IP/host) belongs to the organization's own network. |
| Recovery - Enrich Non-Enriched Observables | 2 | Catches observables that were never enriched and reruns enrichment. |
| Enrich - Agent ID - Crowdstrike | 0 | Resolves a CrowdStrike agent ID to device and user context. |
| Enrich - Agent ID - Crowdstrike | 0 | Resolves a CrowdStrike agent ID to device and user context. |
| Enrich - URL - URLScan | 0 | Submits a URL to URLScan.io for enrichment. |
| Enrich - URL - URLScan | 0 | Submits a URL to URLScan.io for enrichment. |
| Enrich - Hash - VT | 0 | Checks a file hash's reputation in VirusTotal. |
| Enrich - Hash - VT | 0 | Checks a file hash's reputation in VirusTotal. |
| Enrich - IP - IPDB | 0 | Checks an IP's abuse reputation via AbuseIPDB. |
| Enrich - IP - IPDB | 0 | Checks an IP's abuse reputation via AbuseIPDB. |
| Enrich - Username or Email - Okta | 0 | Resolves a username or email to Okta account context. |
| Enrich - Username or Email - Okta | 0 | Resolves a username or email to Okta account context. |
| Enrich - IP - VT | 0 | Checks an IP's reputation via VirusTotal. |
| Enrich - IP - VT | 0 | Checks an IP's reputation via VirusTotal. |
| Subflow - Enrich Observables - Main Router | 0 | Central dispatcher that routes each observable to its type-specific enrichment workflow. |
| Subflow - Update Enrichment Data | 0 | Writes enrichment results back to the case's observable record. |
| Subflow - Update Enrichment Data | 0 | Writes enrichment results back to the case's observable record. |
| Enrich - URL - VT | 0 | Checks a URL's reputation via VirusTotal. |
| Enrich - URL - VT | 0 | Checks a URL's reputation via VirusTotal. |
| Get User Information Using Google Workspace | 0 | Resolves a user identity to Google Workspace account details. |
| Get User Information Using Google Workspace | 0 | Resolves a user identity to Google Workspace account details. |
| Enrich IP or Domain Using Whois | 0 | Runs a Whois lookup on an IP or domain for registration context. |
| Enrich IP or Domain Using Whois | 0 | Runs a Whois lookup on an IP or domain for registration context. |
| Get User Information Using Github | 0 | Resolves a user identity to GitHub account details. |
| Get User Information Using Github | 0 | Resolves a user identity to GitHub account details. |
| Get User Information Using Microsoft Entra ID | 0 | Resolves a user identity to Microsoft Entra ID account details. |
| Get User Information Using Microsoft Entra ID | 0 | Resolves a user identity to Microsoft Entra ID account details. |
| Enrich - Hash - Crowdstrike | 0 | Checks a file hash's detection history in CrowdStrike. |
| Enrich - Hash - Crowdstrike | 0 | Checks a file hash's detection history in CrowdStrike. |
| Enrich - IP or Domain - Whois | 0 | Runs a Whois lookup on an IP or domain for registration context. |
| Enrich - IP or Domain - Whois | 0 | Runs a Whois lookup on an IP or domain for registration context. |
| Enrich - Username or Email - Google Workspace | 0 | Resolves a username or email to Google Workspace account context. |
| Enrich - Username or Email - Google Workspace | 0 | Resolves a username or email to Google Workspace account context. |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Resolves a username or email to Microsoft Entra ID account context, including risky-user status. |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Resolves a username or email to Microsoft Entra ID account context, including risky-user status. |
| Utility - Update Enrichment | 0 | Updates an observable's stored enrichment data. |
| Recovery - Enrich Non-Enriched Observables | 0 | Catches observables that were never enriched and reruns enrichment. |
| Enrich - Username - Github | 0 | Resolves a username to GitHub identity and activity context. |
| Enrich - Email Address - Slack | 0 | Resolves an email address to Slack user identity for context. |
| Get User Information on Email Address Using Slack | 0 | Resolves an email address to Slack user profile. |
| Get User Information Using Okta | 0 | Resolves a user identity to Okta account details. |
| Get Hash Info Using Crowdstrike | 0 | Returns CrowdStrike detection details for a file hash. |
| Run Dig Command | 0 | Runs a DNS dig query on a domain or IP for enrichment. |
| Get End of Life Date for a Product | 0 | Looks up a software product's end-of-life date to inform risk assessment. |
| Secure URL Screenshot Capture | 0 | Captures a sandboxed screenshot of a suspicious URL for analyst review. |
| Analyze URL with URLScan | 0 | Submits a URL to URLScan.io for sandboxed analysis and returns the verdict. |
| Okta Search for User Activity | 0 | Searches Okta system logs for a user's recent activity. |
| Get Hash Info Using VirusTotal | 0 | Returns VirusTotal detection details for a file hash. |
| Get Machine Info - Medigate Hostname Lookup | 0 | Resolves a hostname to Claroty Medigate medical-device asset details. |
| Get Machine Info - Tanium Lookup | 0 | Resolves a hostname to Tanium-managed endpoint details. |
| Get Machine Info - Microsoft Defender | 0 | Resolves a hostname to Microsoft Defender device details. |
| IP2Hostname Lookup | 0 | Resolves an IP address to its hostname. |
| Utility - Update Enrichment | 0 | Updates an observable's stored enrichment data. |
| Recovery - Enrich Non-Enriched Observables | 0 | Catches observables that were never enriched and reruns enrichment. |
| Enrich - Email Address - Slack | 0 | Resolves an email address to Slack user identity for context. |
| Enrich - Username - Github | 0 | Resolves a username to GitHub identity and activity context. |
| Get User Information Using Okta | 0 | Resolves a user identity to Okta account details. |
| Get Hash Info Using Crowdstrike | 0 | Returns CrowdStrike detection details for a file hash. |
| Analyze URL with URLScan | 0 | Submits a URL to URLScan.io for sandboxed analysis and returns the verdict. |
| Secure URL Screenshot Capture | 0 | Captures a sandboxed screenshot of a suspicious URL for analyst review. |
| Get User Information on Email Address Using Slack | 0 | Resolves an email address to Slack user profile. |
| Get Hash Info Using VirusTotal | 0 | Returns VirusTotal detection details for a file hash. |
| Run Dig Command | 0 | Runs a DNS dig query on a domain or IP for enrichment. |
| Okta Search for User Activity | 0 | Searches Okta system logs for a user's recent activity. |
| Get End of Life Date for a Product | 0 | Looks up a software product's end-of-life date to inform risk assessment. |
| Get End of Life Date for a Product | 0 | Looks up a software product's end-of-life date to inform risk assessment. |
| Okta Search for User Activity | 0 | Searches Okta system logs for a user's recent activity. |
| Run Dig Command | 0 | Runs a DNS dig query on a domain or IP for enrichment. |
| Enrich IP or Domain Using Whois | 0 | Runs a Whois lookup on an IP or domain for registration context. |
| Get Hash Info Using VirusTotal | 0 | Returns VirusTotal detection details for a file hash. |
| Get User Information Using Microsoft Entra ID | 0 | Resolves a user identity to Microsoft Entra ID account details. |
| Get User Information Using Github | 0 | Resolves a user identity to GitHub account details. |
| Get User Information on Email Address Using Slack | 0 | Resolves an email address to Slack user profile. |
| Get User Information Using Google Workspace | 0 | Resolves a user identity to Google Workspace account details. |
| Secure URL Screenshot Capture | 0 | Captures a sandboxed screenshot of a suspicious URL for analyst review. |
| Analyze URL with URLScan | 0 | Submits a URL to URLScan.io for sandboxed analysis and returns the verdict. |
| Get Hash Info Using Crowdstrike | 0 | Returns CrowdStrike detection details for a file hash. |
| Get User Information Using Okta | 0 | Resolves a user identity to Okta account details. |
| Subflow - Update Enrichment Data | 0 | Writes enrichment results back to the case's observable record. |
| Enrich - URL - VT | 0 | Checks a URL's reputation via VirusTotal. |
| Enrich - Username - Github | 0 | Resolves a username to GitHub identity and activity context. |
| Enrich - IP - VT | 0 | Checks an IP's reputation via VirusTotal. |
| Enrich - URL - URLScan | 0 | Submits a URL to URLScan.io for enrichment. |
| Enrich - IP - IPDB | 0 | Checks an IP's abuse reputation via AbuseIPDB. |
| Enrich - Email Address - Slack | 0 | Resolves an email address to Slack user identity for context. |
| Enrich - Username or Email - Google Workspace | 0 | Resolves a username or email to Google Workspace account context. |
| Enrich - Agent ID - Crowdstrike | 0 | Resolves a CrowdStrike agent ID to device and user context. |
| Enrich - Username or Email - Okta | 0 | Resolves a username or email to Okta account context. |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Resolves a username or email to Microsoft Entra ID account context, including risky-user status. |
| Get Machine Info - Medigate Hostname Lookup | 0 | Resolves a hostname to Claroty Medigate medical-device asset details. |
| Get Machine Info - Microsoft Defender | 0 | Resolves a hostname to Microsoft Defender device details. |
| Get Machine Info - Tanium Lookup | 0 | Resolves a hostname to Tanium-managed endpoint details. |
| IP2Hostname Lookup | 0 | Resolves an IP address to its hostname. |
| Enrich - IP or Domain - Whois | 0 | Runs a Whois lookup on an IP or domain for registration context. |
| Enrich - Hash - VT | 0 | Checks a file hash's reputation in VirusTotal. |
| Enrich - Hash - Crowdstrike | 0 | Checks a file hash's detection history in CrowdStrike. |
| Utility - Update Enrichment | 0 | Updates an observable's stored enrichment data. |
| Recovery - Enrich Non-Enriched Observables | 0 | Catches observables that were never enriched and reruns enrichment. |
| Enrich - Router Default Case | 0 | Fallback handler for observable types with no dedicated enrichment path. |
| Enrich - Username or Email - Okta | 0 | Resolves a username or email to Okta account context. |
| Get User Information Using Google Workspace | 0 | Resolves a user identity to Google Workspace account details. |
| Enrich - Username or Email - Google Workspace | 0 | Resolves a username or email to Google Workspace account context. |
| Get Hash Info Using Crowdstrike | 0 | Returns CrowdStrike detection details for a file hash. |
| Enrich - URL - VT | 0 | Checks a URL's reputation via VirusTotal. |
| Enrich - Crowdstrike Threatgraph Enrichment | 0 | Pulls CrowdStrike ThreatGraph relationship data for an indicator. |
| Enrich - IP - IPDB | 0 | Checks an IP's abuse reputation via AbuseIPDB. |
| Enrich - URL - URLScan | 0 | Submits a URL to URLScan.io for enrichment. |
| Get User Information Using Okta | 0 | Resolves a user identity to Okta account details. |
| Get User Information Using Github | 0 | Resolves a user identity to GitHub account details. |
| Run Dig Command | 0 | Runs a DNS dig query on a domain or IP for enrichment. |
| Secure URL Screenshot Capture | 0 | Captures a sandboxed screenshot of a suspicious URL for analyst review. |
| Utility - Update Enrichment | 0 | Updates an observable's stored enrichment data. |
| Analyze URL with URLScan | 0 | Submits a URL to URLScan.io for sandboxed analysis and returns the verdict. |
| Enrich - Username - Github | 0 | Resolves a username to GitHub identity and activity context. |
| Okta Search for User Activity | 0 | Searches Okta system logs for a user's recent activity. |
| Enrich - Agent ID - Crowdstrike | 0 | Resolves a CrowdStrike agent ID to device and user context. |
| Get Hash Info Using VirusTotal | 0 | Returns VirusTotal detection details for a file hash. |
| Get End of Life Date for a Product | 0 | Looks up a software product's end-of-life date to inform risk assessment. |
| Enrich - Hash - Crowdstrike | 0 | Checks a file hash's detection history in CrowdStrike. |
| Enrich - Email Address - Slack | 0 | Resolves an email address to Slack user identity for context. |
| Get User Information on Email Address Using Slack | 0 | Resolves an email address to Slack user profile. |
6. Case & Alert Lifecycle Management
Category: SOC
Subcategories: Case mgmt & SOAR
Description:
Core SOAR plumbing that ingests raw alerts into structured cases, manages observable relationships and deduplication, routes each case to the correct response subflow, and provides recovery and cleanup for the case-and-alert data model.
Business problem solved:
Without a structured case-management backbone, every alert type would need its own bespoke tracking and orphaned or malformed alerts would silently fall through the cracks. This layer standardizes case creation, routing, and hygiene so every alert gets a consistent, auditable lifecycle regardless of source.
Integrations: Blink Case Management · Blink Tables
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Utility - Build Case Feed | 1,040 | Assembles the consolidated activity feed shown on a case. |
| Subflow - Response - Main Router | 703 | Routes a case to the correct threat-specific response subflow based on alert type. |
| Process Alert | 680 | Primary event-driven handler that turns an incoming alert into a structured case. |
| Subflow - Response - Main Router | 676 | Routes a case to the correct threat-specific response subflow based on alert type. |
| Process Alert | 562 | Primary event-driven handler that turns an incoming alert into a structured case. |
| Process Alert | 291 | Primary event-driven handler that turns an incoming alert into a structured case. |
| Subflow - Response - Main Router | 290 | Routes a case to the correct threat-specific response subflow based on alert type. |
| Recovery - Handle Unprocessed Alert | 148 | Catches and reprocesses an alert that failed to create a case on first pass. |
| Utility - Set Case Status | 16 | Updates a case's status field. |
| Utility - List Cases | 12 | Returns a filtered list of cases. |
| Utility - Probe Query Shape | 5 | Diagnostic utility validating case-management query structure during development. |
| Utility - Automation View Export | 3 | Exports the current automation inventory/view for reporting. |
| Utility - Probe Async Inputs | 2 | Diagnostic utility validating asynchronous input handling in case-management queries. |
| Subflow - Missing Alert Template Notification | 1 | Notifies the team when an alert type has no configured template, preventing silent drops. |
| Utility - Observable Inventory | 1 | Returns the current observable inventory for a case. |
| Utility - Probe Input Binding | 1 | Diagnostic utility validating input-binding behavior in case-management queries. |
| Subflow - Missing Alert Template Notification | 0 | Notifies the team when an alert type has no configured template, preventing silent drops. |
| Subflow - Missing Alert Template Notification | 0 | Notifies the team when an alert type has no configured template, preventing silent drops. |
| Subflow - Response - Main Router | 0 | Routes a case to the correct threat-specific response subflow based on alert type. |
| Utility - List Observable Alert Relations | 0 | Lists alerts linked to a given observable. |
| Utility - Set Or Update Observable Relation | 0 | Creates or updates a relationship between two observables. |
| Utility - Delete Observable Relation | 0 | Removes an observable relationship from a case. |
| Utility - List Alert Observable Relations | 0 | Lists observable relationships tied to an alert. |
| Table Action - Validate Observables Extraction Template | 0 | Validates that an observable-extraction template is correctly configured. |
| Utility - Close Stale Cases | 0 | Automatically closes cases that have gone stale past a defined threshold. |
| Utility - Find Similar Cases Based on Observables | 0 | Finds related open or prior cases sharing observables, supporting deduplication. |
| Recovery - Handle Unprocessed Alerts | 0 | Catches and reprocesses alerts that failed to create a case on first pass. |
| Process Alert | 0 | Primary event-driven handler that turns an incoming alert into a structured case. |
| Utility - Find Similar Cases Based on Observables | 0 | Finds related open or prior cases sharing observables, supporting deduplication. |
| Utility - Delete Observable Relation | 0 | Removes an observable relationship from a case. |
| Table Action - Validate Observables Extraction Template | 0 | Validates that an observable-extraction template is correctly configured. |
| Utility - List Alert Observable Relations | 0 | Lists observable relationships tied to an alert. |
| Utility - Close Stale Cases | 0 | Automatically closes cases that have gone stale past a defined threshold. |
| Utility - Set Or Update Observable Relation | 0 | Creates or updates a relationship between two observables. |
| Utility - List Observable Alert Relations | 0 | Lists alerts linked to a given observable. |
| Recovery - Handle Unprocessed Alerts | 0 | Catches and reprocesses alerts that failed to create a case on first pass. |
| Subflow - Missing Alert Template Notification | 0 | Notifies the team when an alert type has no configured template, preventing silent drops. |
| Utility - Close Stale Cases | 0 | Automatically closes cases that have gone stale past a defined threshold. |
| Utility - Delete Observable Relation | 0 | Removes an observable relationship from a case. |
| Utility - Set Or Update Observable Relation | 0 | Creates or updates a relationship between two observables. |
| Utility - List Observable Alert Relations | 0 | Lists alerts linked to a given observable. |
| Utility - List Alert Observable Relations | 0 | Lists observable relationships tied to an alert. |
| Utility - Find Similar Cases Based on Observables | 0 | Finds related open or prior cases sharing observables, supporting deduplication. |
| Table Action - Validate Observables Extraction Template | 0 | Validates that an observable-extraction template is correctly configured. |
| Recovery - Handle Unprocessed Alerts | 0 | Catches and reprocesses alerts that failed to create a case on first pass. |
| Utility - Delete Observable Relation | 0 | Removes an observable relationship from a case. |
| Comment On Case | 0 | Posts an automated comment to a case record. |
| Table Action - Validate Observables Extraction Template | 0 | Validates that an observable-extraction template is correctly configured. |
| Utility - Find Similar Cases Based on Observables | 0 | Finds related open or prior cases sharing observables, supporting deduplication. |
| Utility - Set Or Update Observable Relation | 0 | Creates or updates a relationship between two observables. |
| Utility - Close Stale Cases | 0 | Automatically closes cases that have gone stale past a defined threshold. |
| Get Observables by Case ID | 0 | Retrieves all observables linked to a case. |
| Utility - List Alert Observable Relations | 0 | Lists observable relationships tied to an alert. |
| Utility - Add Observable Extraction Rule | 0 | Registers a new rule for extracting observables from alert payloads. |
| Query Observable | 0 | Looks up an observable record by identifier. |
| Utility - List Observable Alert Relations | 0 | Lists alerts linked to a given observable. |
7. Identity Threat Response — Risky User Detection & Remediation
Category: SOC
Subcategories: Identity threat response
Description:
Monitors Microsoft Entra ID risky-user signals and Defender XDR identity alerts (including anomalous logins), routes them to analyst disposition (confirm compromised / confirm safe / dismiss), and provides one-call remediation — session revocation, MFA reset, account suspension, forced password reset — once compromise is confirmed.
Business problem solved:
Identity compromise is one of the fastest-moving threats in a hospital environment, where account takeover can expose patient data. Manually cross-referencing risky-user lists and manually executing remediation steps costs precious response time; this use case closes the loop from detection to remediation in a single, auditable pipeline.
Integrations: Microsoft Entra ID · Microsoft Defender XDR · Splunk · VirusTotal · Microsoft Defender for Endpoint · ServiceNow
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Ingest Microsoft XDR Identity Alerts | 960 | Scheduled poll for new Microsoft Defender XDR identity alerts, such as risky sign-ins. |
| Risky User List Monitoring | 960 | Scheduled poll of the Entra ID risky-user list for new entries. |
| Response Subflow - Risky User Detections | 132 | Investigates and actions a flagged risky-user detection end-to-end. |
| New Password Rotation Needed | 9 | Opens a ServiceNow ticket when Splunk flags a credential due for rotation. |
| On Defender XDR Alert (Anomalous Login) | 1 | Investigates an anomalous-login Defender XDR alert with Splunk and VirusTotal enrichment, then emails the finding. |
| Response Subflow - Microsoft XDR Identity Alerts | 0 | Runs the response steps for an identity alert surfaced via Microsoft XDR. |
| Clean up Risk User List | 0 | Scheduled cleanup of stale entries from the tracked risky-user list. |
| Revoke User Sessions | 0 | Revokes all active sessions for a specified user. |
| User to PrincipleID | 0 | Resolves a username to its identity provider principal ID for downstream remediation actions. |
| Reset User MFA Methods | 0 | Resets a user's registered MFA methods. |
| Suspend User Account | 0 | Suspends a user account pending investigation. |
| Reactivate User Account | 0 | Reactivates a previously suspended user account. |
| Force Password Reset | 0 | Forces a password reset for a compromised or at-risk account. |
| Risky User Clean Up | 0 | Clears resolved entries from the risky-user tracking table. |
| Dismiss Risky User | 0 | Dismisses a risky-user alert without further action. |
| Confirm Safe Risky User | 0 | Analyst-confirmed disposition that a flagged risky user is a false positive. |
| Confirm Compromise Risky User | 0 | Analyst-confirmed disposition that a flagged risky user is compromised, triggering remediation. |
| Action - Disable User (Entra) | 0 | Disables a compromised user account in Microsoft Entra ID. |
| Action - Revoke Sessions (Entra) | 0 | Revokes all active sessions for a user in Microsoft Entra ID. |
8. Vulnerability Scanning, Asset Sync & Ticketing (Tenable)
Category: Vulnerability Mgmt
Subcategories: Vuln scanning, ingest & report, Vuln lifecycle, prioritize, ticket
Description:
Syncs asset inventory and vulnerability findings from Tenable into Blink Tables, supports on-demand self-service scans, and automatically opens ServiceNow tickets for qualifying high/critical findings.
Business problem solved:
Manually triaging vulnerability scan output and opening a ticket for every finding doesn't scale. This pipeline gives the security team a running asset/vulnerability data store and auto-generates remediation tickets for the findings that matter most, while giving requesters a self-service path to trigger targeted scans.
Integrations: Tenable · ServiceNow · Splunk · Blink Tables
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Webhook for Tennable VM Ticket Generation | 84 | Opens a ServiceNow ticket automatically when Tenable reports a qualifying vulnerability. |
| Webhook for Tennable VM Ticket Generation | 82 | Opens a ServiceNow ticket automatically when Tenable reports a qualifying vulnerability. |
| Sync - Org Assets | 34 | Scheduled sync of the organization's asset inventory from Tenable. |
| Enrich - Hostname - Tenable Vulnerabilities | 26 | Pulls known vulnerabilities for a hostname from Tenable. |
| Enrich - IP Address - Asset Identity (Tenable) | 21 | Resolves an IP address to its Tenable asset identity. |
| Vuln Scanner - Table Creation | 5 | Provisions the Blink Tables used to store Tenable scan results. |
| Vuln Scanner - Table Creation | 5 | Provisions the Blink Tables used to store Tenable scan results. |
| Tenable Device Details by IPv4 | 0 | Looks up full Tenable asset detail for a given IP address. |
| Tenable Device Details by IPv4 | 0 | Looks up full Tenable asset detail for a given IP address. |
| Create Table and Schema from JSON | 0 | Provisions a new Blink Table and schema from a JSON definition, used to stand up vulnerability data stores. |
| Self Service Tenable Scan | 0 | On-demand self-service trigger for a targeted Tenable vulnerability scan. |
| Poll for Complete Tenable Scan and Email Results | 0 | Waits for a Tenable scan to finish and emails the report to the requester. |
| Vulnerability Submissions for High and Critical | 0 | Webhook trigger for newly submitted high/critical vulnerability findings from Splunk. |
9. Security Metrics & Reporting
Category: GRC
Subcategories: Security metrics & reporting
Description:
Refreshes the AI SOC 360 dashboard on a daily schedule, giving stakeholders an always-current view of SOC automation performance and case metrics.
Business problem solved:
Without a live dashboard, leadership visibility into SOC throughput and AI-agent performance depends on manual reporting; this workflow keeps a stakeholder-facing view continuously refreshed.
Integrations: Blink Case Management
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| AI SOC 360 - Build Dashboard | 21 | Daily scheduled refresh of the AI SOC performance and case-metrics dashboard. |
10. Platform Testing & Environment Scaffolding
Category: Other
Subcategories: DevOps & release automation
Description:
Non-production workflows used to validate integration connectivity, simulate alerts for pipeline testing, reset the case-management sandbox, and scaffold new automations, plus a handful of unconfigured onboarding templates.
Business problem solved:
Safely testing new detections and integrations requires alert simulators and disposable environments that don't touch production case data; these workflows support that without representing security automation in their own right.
Integrations: CrowdStrike · ServiceNow · Tanium · Tenable
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| ZZ CONN TEST | 1 | Validates Tanium and Tenable connection health. |
| Error Handling - Send Error Notification Email | 0 | Sends an email notification when an automation encounters an unhandled error. |
| Error Handling - Send Error Notification Email | 0 | Sends an email notification when an automation encounters an unhandled error. |
| Getting Started - Hello World | 0 | Default starter workflow created during platform onboarding. |
| Test | 0 | Placeholder workflow used for ad hoc platform testing. |
| Simulate Multiple Alerts from Different Sources | 0 | Generates a batch of synthetic multi-source alerts for pipeline load-testing. |
| USE WITH CARE - Reset Case Management Environment | 0 | Bulk-resets case management test data in a non-production workspace. |
| Simulate Crowdstrike Alert | 0 | Generates a synthetic CrowdStrike alert to test the case-creation pipeline. |
| Simulate Crowdstrike Alert | 0 | Generates a synthetic CrowdStrike alert to test the case-creation pipeline. |
| Simulate Multiple Alerts from Different Sources | 0 | Generates a batch of synthetic multi-source alerts for pipeline load-testing. |
| USE WITH CARE - Reset Case Management Environment | 0 | Bulk-resets case management test data in a non-production workspace. |
| ServiceNow End 2 End Testing | 0 | Validates ServiceNow connectivity and record creation end-to-end in a test instance. |
| Hello World | 0 | Default starter workflow created during platform onboarding. |
| Example Subflow | 0 | Template subflow left over from platform onboarding, not used in production. |
| New Workflow 1 | 0 | Empty placeholder workflow, not used in production. |
| New Workflow | 0 | Empty placeholder workflow, not used in production. |
| Intake Form | 0 | Web-form intake scaffold, not yet wired into a production process. |
| Feedback Form | 0 | Web-form intake scaffold, not yet wired into a production process. |
| USE WITH CARE - Reset Case Management Environment | 0 | Bulk-resets case management test data in a non-production workspace. |
| Simulate Multiple Alerts from Different Sources | 0 | Generates a batch of synthetic multi-source alerts for pipeline load-testing. |
| Simulate Crowdstrike Alert | 0 | Generates a synthetic CrowdStrike alert to test the case-creation pipeline. |
| Error Handling - Send Error Notification Email | 0 | Sends an email notification when an automation encounters an unhandled error. |
| Error Handling - Send Error Notification Email | 0 | Sends an email notification when an automation encounters an unhandled error. |
11. EDR Containment & Response Actions
Category: SOC
Subcategories: EDR containment & response
Description:
A ready-to-invoke library of endpoint containment actions spanning CrowdStrike, Microsoft Defender for Endpoint, and Tanium — host isolation and release, hash/IOC quarantine, antivirus scans, and remote live-response queries.
Business problem solved:
When a device is confirmed compromised, the speed of containment directly limits blast radius. This library gives analysts and the AI agent a standardized, one-call path to isolate a host or quarantine a hash instead of navigating each EDR console by hand — built and ready, currently awaiting activation into the response pipeline.
Integrations: CrowdStrike · Microsoft Defender for Endpoint · Tanium
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Get Question Result with Tanium and Send Results via Email | 0 | Runs a Tanium question against endpoints and emails the results. |
| Get Sensor with Tanium and Send Results via Email | 0 | Runs a Tanium sensor query against endpoints and emails the results. |
| CrowdStrike RTR to a Single Host | 0 | Runs a CrowdStrike Real Time Response command on a single host. |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs a CrowdStrike Real Time Response command across a batch of hosts. |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Quarantines or releases a file/host in CrowdStrike. |
| Isolate Host - MS Defender for Endpoint | 0 | Network-isolates a compromised host via Microsoft Defender for Endpoint. |
| Release Host - MS Defender for Endpoint | 0 | Releases a host from network isolation in Microsoft Defender for Endpoint. |
| CrowdStrike RTR to a Single Host | 0 | Runs a CrowdStrike Real Time Response command on a single host. |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs a CrowdStrike Real Time Response command across a batch of hosts. |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Quarantines or releases a file/host in CrowdStrike. |
| Release Host - MS Defender for Endpoint | 0 | Releases a host from network isolation in Microsoft Defender for Endpoint. |
| Isolate Host - MS Defender for Endpoint | 0 | Network-isolates a compromised host via Microsoft Defender for Endpoint. |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Quarantines or releases a file/host in CrowdStrike. |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs a CrowdStrike Real Time Response command across a batch of hosts. |
| CrowdStrike RTR to a Single Host | 0 | Runs a CrowdStrike Real Time Response command on a single host. |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs a CrowdStrike Real Time Response command across a batch of hosts. |
| CrowdStrike RTR to a Single Host | 0 | Runs a CrowdStrike Real Time Response command on a single host. |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Quarantines or releases a file/host in CrowdStrike. |
| Action - Isolate Host (Defender) | 0 | Network-isolates a host via Microsoft Defender. |
| Action - Release Host Isolation (Defender) | 0 | Releases a previously isolated host in Microsoft Defender. |
| Action - Run Antivirus Scan (Defender) | 0 | Triggers an on-demand antivirus scan via Microsoft Defender. |
12. IT Request Routing — ServiceNow to Monday.com
Category: Other
Subcategories: IT helpdesk & ticket routing
Description:
Converts new Splunk-related ServiceNow request items (RITMs) assigned to the security operations team into Monday.com tasks, so the security engineering team can track fulfillment work in its own tool.
Business problem solved:
Security engineering fulfillment work is tracked in Monday.com while requests originate in ServiceNow; this bridges the two systems so request items don't require manual re-entry.
Integrations: ServiceNow · Monday.com
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Create Monday Tasks from Service now RITMs | 0 | Converts new Splunk-related ServiceNow request items into Monday.com tasks for the security engineering team. |
Key Observations
Strengths
- Agentic SOC is the deepest single investment in the automation footprint. At 43 playbooks — the largest library by playbook count — the AI investigation agent has its own callable tool library of 26+ "Agent Ability" actions spanning Splunk, ServiceNow, Tenable, Tanium, and case-management context, plus a dedicated model-evaluation harness (labeled-dataset scoring and re-run tooling) used to continuously tune investigation accuracy against ground truth. This is a materially more mature Agentic SOC deployment than a typical single-playbook AI-triage integration.
- ServiceNow synchronization is the automation backbone. At 127K+ executions, real-time case-to-ticket sync is by a wide margin the most-executed automation, meaning ServiceNow reliably reflects live case status for every team outside the SOC without manual re-entry.
- Broad, structured enrichment coverage. A 40-tool enrichment library normalizes hashes, IPs, URLs, hostnames, and identities across VirusTotal, CrowdStrike, Okta, Microsoft Entra ID, URLScan.io, AbuseIPDB, GitHub, Slack, and Google Workspace behind a single routing layer, so analysts and the AI agent get a consistent verdict regardless of observable type.
- Healthcare-specific asset context. The Claroty Medigate integration (hostname-to-medical-device lookup) gives investigations clinical/IoMT context that generic SOC tooling doesn't provide — directly relevant to a hospital's unique attack surface.
- Identity remediation is a complete, one-call toolkit. Session revocation, MFA reset, account suspension/reactivation, and forced password reset are all built as standalone, callable actions alongside Entra ID risky-user monitoring and Defender XDR identity-alert ingestion, giving the identity response pipeline everything it needs end-to-end.
Gaps & Opportunities
- EDR containment library is fully built but unused. All 10 CrowdStrike/Defender/Tanium containment playbooks (host isolation, quarantine, RTR, antivirus scan) show zero executions in the trailing 12 months — the capability exists but isn't yet wired into the automatic response path from the AI investigation or identity-threat workflows.
- Identity remediation actions are idle. The core remediation calls (Force Password Reset, Suspend User Account, Revoke User Sessions, Reset User MFA Methods, Confirm Compromise Risky User, Entra disable/revoke-session actions) all show zero executions, while detection-side workflows (risky-user monitoring, Defender XDR identity alerts) are active — suggesting confirmed risky-user cases are currently being remediated manually rather than through the automated action library already in place.
- Workspace duplication adds maintenance overhead. Core playbooks (case sync, alert ingestion, enrichment) are deployed nearly identically across 8 separate workspaces under the same tenant. Consolidating to a clear dev/staging/production boundary — or fully retiring unused copies — would reduce the surface area that needs to stay in sync when a playbook is updated.
- 23 platform-testing and scaffolding workflows carry effectively zero production executions, including unconfigured onboarding templates (Hello World, Intake Form, Feedback Form, empty "New Workflow" placeholders). These are reasonable to keep for sandbox testing but are candidates for archival to keep the production automation inventory clean.
- No dedicated GRC/compliance automation beyond dashboard reporting. Access review, audit-evidence collection, or compliance-questionnaire workflows aren't yet represented — a natural next step given the identity and case-management foundation already in place.
Integration Ecosystem
| Integration | Role in the Automation Footprint |
|---|---|
| ServiceNow | System of record for tickets/incidents; two-way sync with Blink Case Management |
| Splunk | Primary SIEM — alert ingestion, AI-agent threat hunting, risk-based alerting, pipeline health checks |
| Microsoft Defender XDR / Defender for Endpoint | XDR and endpoint alert ingestion, identity alerts, endpoint containment actions |
| Tenable | Vulnerability scanning, asset inventory sync, high/critical finding ticketing |
| Tanium | Endpoint posture queries for AI investigation and containment actions |
| CrowdStrike | EDR enrichment (hash/agent/ThreatGraph lookups) and RTR/quarantine containment actions |
| Microsoft Entra ID | Risky-user identity signals, account enrichment, session/account remediation |
| Okta | Identity enrichment and user activity search |
| VirusTotal / URLScan.io / AbuseIPDB | Threat intelligence enrichment for hashes, URLs, and IPs |
| Proofpoint TAP | Phishing threat and Very Attacked People (VAP) ingestion |
| Claroty Medigate | Medical device / clinical asset context — hospital-specific enrichment |
| GitHub / Slack / Google Workspace | Supplementary identity enrichment across collaboration and dev tooling |
| Monday.com | Downstream task tracking for security engineering fulfillment work |
| Blink Case Management / Blink Tables / Blink AI Agents | Blink-native case lifecycle, data storage, and AI agent orchestration |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| CNH | 2lo_auth | identityiq_test | 2026-08-27 |