01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Phishing Detection & Response | 0 executions | 0.0% | 2 2 active |
| Threat Intel Ingest & IOC Lookup | 0 executions | 0.0% | 2 1 active |
| Vulnerability Lifecycle Management | 0 executions | 0.0% | 1 0 active |
| Total | 0 executions | 100% | 5 3 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- FS-ISAC TAXII integration is a differentiated capability. Most security teams rely on generic threat intel sources (VirusTotal, Shodan, etc.). A direct TAXII integration with FS-ISAC is specific to the financial services sector and positions the SOC to act on threats before they are broadly published.
- Phishing workflow is architecturally complete. The
Mainflow covers the full response chain: trigger → email retrieval → IOC/attachment extraction → TAXII enrichment → evidence storage → SIEM logging. The logic is ready to operationalize — it has not yet been exercised, not redesigned.
- Coralogix plays a dual role. It serves as both the TAXII gateway and the SIEM logging target, which keeps the integration surface area small and avoids context-switching between platforms during incident response.
- Vulnerability → Jira ticketing is scoped correctly. The prototype filters by severity before creating tickets, avoiding alert noise and ensuring Jira receives actionable, prioritized work items.
###
Gaps
- No automations have executed. All workflows are in pre-operational state. The primary gap is activation and go-live, not design quality. Identifying the blocker to first execution is the critical next step.
- Phishing flow has no analyst routing. Enrichment results are logged to Coralogix but not surfaced in a case management system or sent to analysts via Slack/email/ticketing. Without a notification or escalation path, findings are silently accumulated in the SIEM.
- Vulnerability Management and TAXII ingestion are inactive prototypes. Rapid7 and Jira connections are not yet established in the prototype workspace, and the scheduled TAXII ingestion job (
New Workflow) has never run.
- No coverage in Cloud Security, IAM, or GRC. The current automation footprint is limited to SOC and early-stage Vulnerability Management. Access reviews, cloud configuration monitoring, and compliance workflows are not yet in scope.
Integration Ecosystem
| Integration | Used In | Status |
|---|---|---|
| Google Workspace (Gmail) | Phishing Detection | Active |
| Google Drive | Phishing Detection | Active |
| Coralogix | Phishing Detection · Threat Intel | Active |
| Rapid7 InsightVM | Vulnerability Mgmt | Prototype (not connected) |
| Jira | Vulnerability Mgmt | Prototype (not connected) |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 3 use cases | 0 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| — | — | No executions recorded in the last 12 months |
Use Case Summary
| Use Case | Category | Subcategory | Playbooks | Status |
|---|---|---|---|---|
| Phishing Detection & Response | SOC | Phishing detection & response | 2 | Active — not yet triggered |
| Threat Intel Ingest & IOC Lookup | SOC | Threat intel ingest & curation · Alert enrichment / IOC lookup | 2 | 1 active, 1 prototype |
| Vulnerability Lifecycle Management | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket | 1 | Prototype |
Total operational playbooks: 4 active · 2 prototype · 5 onboarding templates (excluded from analysis)
Use Cases
1. Phishing Detection & Response
Description: End-to-end automation for user-reported phishing emails surfaced via Gmail. When a phishing alert fires, the workflow retrieves the email, parses it for IOCs and attachments, enriches each indicator against the FS-ISAC TAXII threat intelligence database, stores artifacts in Google Drive, and logs all findings to Coralogix for retention and correlation.
Business problem: Manual phishing triage is time-consuming and inconsistent. This automation standardizes the response, reduces analyst toil, and creates a complete evidence trail for every reported email — at machine speed.
Integrations: Google Workspace (Gmail), Google Drive, Coralogix
| Playbook | Category | Subcategory | Type | Executions (12 mo) | Status |
|---|---|---|---|---|---|
| Main | SOC | Phishing detection & response | Event-triggered | 0 | Active |
| Retrieve Gmail Message Based on Message ID in rfc822msgid Format | SOC | Phishing detection & response | Utility subflow | 0 | Active |
2. Threat Intel Ingest & IOC Lookup
Description: Operationalizes FS-ISAC financial-sector threat intelligence through two complementary workflows. An on-demand lookup checks any indicator — MD5/SHA256 hash, IP address, domain, URL, or email address — against the FS-ISAC TAXII database and returns a malicious/clean verdict. A companion prototype ingests all TAXII 2 feeds on a daily schedule and indexes the raw data into Coralogix for persistent search and correlation.
Business problem: Financial institutions face threats tracked specifically by FS-ISAC. By integrating TAXII feeds directly into the SOC workflow, analysts can enrich indicators in real time without switching to a separate portal — and historical feed data accumulates in the SIEM automatically.
Integrations: Coralogix (TAXII gateway + SIEM)
| Playbook | Category | Subcategory | Type | Executions (12 mo) | Status |
|---|---|---|---|---|---|
| Search IOC in FS-ISAC TAXI | SOC | Alert enrichment / IOC lookup · Threat intel ingest & curation | On-demand | 0 | Active |
| New Workflow | SOC | Threat intel ingest & curation | Scheduled (daily, 12:00 UTC) | 0 | Prototype |
3. Vulnerability Lifecycle Management
Description: Prototype workflow that retrieves vulnerability data from Rapid7 InsightVM, filters findings by analyst-selected severity (Critical, Severe, or Moderate), and automatically creates a Jira ticket for each matching vulnerability, pre-populated with CVE identifiers, CVSS v3 score, risk score, description, and labels.
Business problem: The handoff from vulnerability scanner to remediation ticketing is a manual bottleneck. This automation ensures every high-priority finding is tracked in Jira without analyst intervention, reducing time-to-ticket and preventing findings from being dropped.
Integrations: Rapid7 InsightVM, Jira
| Playbook | Category | Subcategory | Type | Executions (12 mo) | Status |
|---|---|---|---|---|---|
| New Workflow 1 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket | On-demand | 0 | Prototype |
Key Observations
Strengths
- FS-ISAC TAXII integration is a differentiated capability. Most security teams rely on generic threat intel sources (VirusTotal, Shodan, etc.). A direct TAXII integration with FS-ISAC is specific to the financial services sector and positions the SOC to act on threats before they are broadly published.
- Phishing workflow is architecturally complete. The
Mainflow covers the full response chain: trigger → email retrieval → IOC/attachment extraction → TAXII enrichment → evidence storage → SIEM logging. The logic is ready to operationalize — it has not yet been exercised, not redesigned.
- Coralogix plays a dual role. It serves as both the TAXII gateway and the SIEM logging target, which keeps the integration surface area small and avoids context-switching between platforms during incident response.
- Vulnerability → Jira ticketing is scoped correctly. The prototype filters by severity before creating tickets, avoiding alert noise and ensuring Jira receives actionable, prioritized work items.
Gaps
- No automations have executed. All workflows are in pre-operational state. The primary gap is activation and go-live, not design quality. Identifying the blocker to first execution is the critical next step.
- Phishing flow has no analyst routing. Enrichment results are logged to Coralogix but not surfaced in a case management system or sent to analysts via Slack/email/ticketing. Without a notification or escalation path, findings are silently accumulated in the SIEM.
- Vulnerability Management and TAXII ingestion are inactive prototypes. Rapid7 and Jira connections are not yet established in the prototype workspace, and the scheduled TAXII ingestion job (
New Workflow) has never run.
- No coverage in Cloud Security, IAM, or GRC. The current automation footprint is limited to SOC and early-stage Vulnerability Management. Access reviews, cloud configuration monitoring, and compliance workflows are not yet in scope.
Integration Ecosystem
| Integration | Used In | Status |
|---|---|---|
| Google Workspace (Gmail) | Phishing Detection | Active |
| Google Drive | Phishing Detection | Active |
| Coralogix | Phishing Detection · Threat Intel | Active |
| Rapid7 InsightVM | Vulnerability Mgmt | Prototype (not connected) |
| Jira | Vulnerability Mgmt | Prototype (not connected) |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.