01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Alert Deduplication & Correlation | 0 executions | 0.0% | 1 0 active |
| CVE Intelligence & Weekly Digest | 0 executions | 0.0% | 3 0 active |
| IP Enrichment & Alert Triage | 0 executions | 0.0% | 1 0 active |
| Total | 0 executions | 100% | 5 0 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Vulnerability intelligence automation is the dominant theme. Multiple independently built workflows converge on the same mission: fetching, filtering, and delivering CVE data from NIST NVD. This confirms a clear, recognised pain point that Blink is solving repeatedly across team members.
- Production-quality engineering patterns. Playbooks include retry logic with exponential back-off, paginated API calls, severity-based branching, SIEM audit logging (Coralogix), and email notification routing. These are not toy automations — they reflect real engineering rigour.
- Alert deduplication pipeline in place. The webhook-based deduplication workflow shows intent to manage alert volume systematically — a foundational SOAR capability.
- Threat-intel enrichment wired to downstream actions. The IP enrichment playbook closes the loop: VirusTotal lookup → severity check → email alert or daily digest → SIEM log. End-to-end, not just a lookup.
###
Gaps & Opportunities
- Low execution volume signals a pre-production stage. Most playbooks have 0 executions in the last 12 months, indicating the environment is primarily used for skill evaluation or early-stage development rather than live operations. The next step is connecting these automations to production alert pipelines.
- CVE workflows are fragmented across workspaces. Three separately built CVE digest/report playbooks (CVE Report, CVE Weekly Digest, SecureCo_Automation) solve the same problem with slightly different implementations. Consolidating into a single parameterised playbook would improve maintainability.
- No IAM or endpoint response coverage yet. The current portfolio is entirely focused on vulnerability intelligence and SOC enrichment. Automating identity lifecycle events (onboarding/offboarding, access reviews) and EDR response actions would broaden the automation footprint significantly.
- Alert deduplication is disconnected. The deduplication workflow receives events via a custom webhook but is not yet wired to a live SIEM or alert source. Connecting it to Coralogix or a SOAR platform would immediately reduce analyst noise.
Integration Ecosystem
The organisation's current Blink integration surface spans: Coralogix, Email (SMTP), HTTP / REST API, NIST NVD API, Python, VirusTotal.
The combination of VirusTotal (threat intel), Coralogix (SIEM/logging), NIST NVD (vulnerability feed), and email notification forms a solid SOC enrichment foundation. Extending to EDR platforms (CrowdStrike, SentinelOne), ticketing (Jira, ServiceNow), and identity providers (Okta, Azure AD) would unlock the next tier of automation value.
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 3 use cases | 0 executions (12m)
Business KPIs
Use Case Summary
| Use Case | Category | # Playbooks | Executions |
|---|---|---|---|
| Alert Deduplication & Correlation | SOC | 1 | 0 |
| CVE Intelligence & Weekly Digest | Vulnerability Mgmt | 3 | 0 |
| IP Enrichment & Alert Triage | SOC | 1 | 0 |
Use Cases
Alert Deduplication & Correlation
Webhook-triggered pipeline that ingests incoming alerts, detects duplicate incidents by correlation ID, suppresses redundant noise, and aggregates correlated events into a unified incident record.
Business problem: Alert fatigue from duplicate events wastes analyst time and inflates MTTR. This automation deduplicates at ingestion time, keeping the incident queue clean and actionable.
Integrations: Python
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| dedup using webhook | 0 | SOC | Case mgmt & SOAR |
CVE Intelligence & Weekly Digest
Automated weekly ingestion of newly published CVEs from the NIST NVD, filtered by severity score and technology stack relevance, delivered as a structured email digest.
Business problem: Security engineers spend hours each week manually scanning vulnerability feeds. This automation surfaces only the high-impact CVEs relevant to the organisation's stack and delivers them automatically.
Integrations: Coralogix, Email (SMTP), HTTP / REST API, NIST NVD API, Python
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| CVE Report | 0 | Vulnerability Mgmt | CVE lookup & remediation |
| CVE Weekly Digest | 0 | Vulnerability Mgmt | CVE lookup & remediation |
| SecureCo_Automation_Needhi | 0 | Vulnerability Mgmt | CVE lookup & remediation |
IP Enrichment & Alert Triage
On-demand IP address reputation lookup via VirusTotal, with automated severity-based routing: high-severity alerts trigger immediate email notification, while medium/low alerts are batched into a daily digest. All results are logged to the SIEM for audit.
Business problem: Manual IP lookups across threat-intel platforms slow down alert triage. This automation enriches IPs instantly, routes alerts by severity, and maintains a full audit trail without analyst intervention.
Integrations: Coralogix, Email (SMTP), VirusTotal
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Manual_IP_Enrichment | 0 | SOC | Alert enrichment / IOC lookup |
Key Observations
Strengths
- Vulnerability intelligence automation is the dominant theme. Multiple independently built workflows converge on the same mission: fetching, filtering, and delivering CVE data from NIST NVD. This confirms a clear, recognised pain point that Blink is solving repeatedly across team members.
- Production-quality engineering patterns. Playbooks include retry logic with exponential back-off, paginated API calls, severity-based branching, SIEM audit logging (Coralogix), and email notification routing. These are not toy automations — they reflect real engineering rigour.
- Alert deduplication pipeline in place. The webhook-based deduplication workflow shows intent to manage alert volume systematically — a foundational SOAR capability.
- Threat-intel enrichment wired to downstream actions. The IP enrichment playbook closes the loop: VirusTotal lookup → severity check → email alert or daily digest → SIEM log. End-to-end, not just a lookup.
Gaps & Opportunities
- Low execution volume signals a pre-production stage. Most playbooks have 0 executions in the last 12 months, indicating the environment is primarily used for skill evaluation or early-stage development rather than live operations. The next step is connecting these automations to production alert pipelines.
- CVE workflows are fragmented across workspaces. Three separately built CVE digest/report playbooks (CVE Report, CVE Weekly Digest, SecureCo_Automation) solve the same problem with slightly different implementations. Consolidating into a single parameterised playbook would improve maintainability.
- No IAM or endpoint response coverage yet. The current portfolio is entirely focused on vulnerability intelligence and SOC enrichment. Automating identity lifecycle events (onboarding/offboarding, access reviews) and EDR response actions would broaden the automation footprint significantly.
- Alert deduplication is disconnected. The deduplication workflow receives events via a custom webhook but is not yet wired to a live SIEM or alert source. Connecting it to Coralogix or a SOAR platform would immediately reduce analyst noise.
Integration Ecosystem
The organisation's current Blink integration surface spans: Coralogix, Email (SMTP), HTTP / REST API, NIST NVD API, Python, VirusTotal.
The combination of VirusTotal (threat intel), Coralogix (SIEM/logging), NIST NVD (vulnerability feed), and email notification forms a solid SOC enrichment foundation. Extending to EDR platforms (CrowdStrike, SentinelOne), ticketing (Jira, ServiceNow), and identity providers (Okta, Azure AD) would unlock the next tier of automation value.
Section 1: Business KPIs — Last 12 Months
Section 2: Use Case Summary
| Use Case | Category | # Playbooks | Executions |
|---|---|---|---|
| Alert Deduplication & Correlation | SOC | 1 | 0 |
| CVE Intelligence & Weekly Digest | Vulnerability Mgmt | 3 | 0 |
| IP Enrichment & Alert Triage | SOC | 1 | 0 |
Section 3: Use Cases — Full Detail
Alert Deduplication & Correlation
Webhook-triggered pipeline that ingests incoming alerts, detects duplicate incidents by correlation ID, suppresses redundant noise, and aggregates correlated events into a unified incident record.
Business problem: Alert fatigue from duplicate events wastes analyst time and inflates MTTR. This automation deduplicates at ingestion time, keeping the incident queue clean and actionable.
Integrations: Python
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| dedup using webhook | 0 | SOC | Case mgmt & SOAR |
CVE Intelligence & Weekly Digest
Automated weekly ingestion of newly published CVEs from the NIST NVD, filtered by severity score and technology stack relevance, delivered as a structured email digest.
Business problem: Security engineers spend hours each week manually scanning vulnerability feeds. This automation surfaces only the high-impact CVEs relevant to the organisation's stack and delivers them automatically.
Integrations: Coralogix, Email (SMTP), HTTP / REST API, NIST NVD API, Python
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| CVE Report | 0 | Vulnerability Mgmt | CVE lookup & remediation |
| CVE Weekly Digest | 0 | Vulnerability Mgmt | CVE lookup & remediation |
| SecureCo_Automation_Needhi | 0 | Vulnerability Mgmt | CVE lookup & remediation |
IP Enrichment & Alert Triage
On-demand IP address reputation lookup via VirusTotal, with automated severity-based routing: high-severity alerts trigger immediate email notification, while medium/low alerts are batched into a daily digest. All results are logged to the SIEM for audit.
Business problem: Manual IP lookups across threat-intel platforms slow down alert triage. This automation enriches IPs instantly, routes alerts by severity, and maintains a full audit trail without analyst intervention.
Integrations: Coralogix, Email (SMTP), VirusTotal
| Playbook | Executions | Category | Subcategory |
|---|---|---|---|
| Manual_IP_Enrichment | 0 | SOC | Alert enrichment / IOC lookup |
Section 4: Key Observations
Strengths
- Vulnerability intelligence automation is the dominant theme. Multiple independently built workflows converge on the same mission: fetching, filtering, and delivering CVE data from NIST NVD. This confirms a clear, recognised pain point that Blink is solving repeatedly across team members.
- Production-quality engineering patterns. Playbooks include retry logic with exponential back-off, paginated API calls, severity-based branching, SIEM audit logging (Coralogix), and email notification routing. These are not toy automations — they reflect real engineering rigour.
- Alert deduplication pipeline in place. The webhook-based deduplication workflow shows intent to manage alert volume systematically — a foundational SOAR capability.
- Threat-intel enrichment wired to downstream actions. The IP enrichment playbook closes the loop: VirusTotal lookup → severity check → email alert or daily digest → SIEM log. End-to-end, not just a lookup.
Gaps & Opportunities
- Low execution volume signals a pre-production stage. Most playbooks have 0 executions in the last 12 months, indicating the environment is primarily used for skill evaluation or early-stage development rather than live operations. The next step is connecting these automations to production alert pipelines.
- CVE workflows are fragmented across workspaces. Three separately built CVE digest/report playbooks (CVE Report, CVE Weekly Digest, SecureCo_Automation) solve the same problem with slightly different implementations. Consolidating into a single parameterised playbook would improve maintainability.
- No IAM or endpoint response coverage yet. The current portfolio is entirely focused on vulnerability intelligence and SOC enrichment. Automating identity lifecycle events (onboarding/offboarding, access reviews) and EDR response actions would broaden the automation footprint significantly.
- Alert deduplication is disconnected. The deduplication workflow receives events via a custom webhook but is not yet wired to a live SIEM or alert source. Connecting it to Coralogix or a SOAR platform would immediately reduce analyst noise.
Integration Ecosystem
The organisation's current Blink integration surface spans: Coralogix, Email (SMTP), HTTP / REST API, NIST NVD API, Python, VirusTotal.
The combination of VirusTotal (threat intel), Coralogix (SIEM/logging), NIST NVD (vulnerability feed), and email notification forms a solid SOC enrichment foundation. Extending to EDR platforms (CrowdStrike, SentinelOne), ticketing (Jira, ServiceNow), and identity providers (Okta, Azure AD) would unlock the next tier of automation value.
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.