Blink Security Automation — Confidential

delta_airlines — Customer Success Report

Generated 2026-09-10 | delta_airlines-value-report.md
2026-09-10Report Date
1294Total Playbooks
484Unique Workflows (12m)
48,745,412Actions Automated (12m)
$12,537,400Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

1294
Total playbooks built
all non-deleted workflows
604
Active playbooks
currently enabled
484
Unique workflows executed (12m)
distinct workflows that ran
48,745,412
Actions automated (12m)
completed action steps
270,807.8h
Hours saved (12m)
@ 20s per action
$12,537,400
Money saved (12m)
@ $100K avg salary
45
New active workflows (last 30d)
recently created & enabled
25,708
Total cases managed
18,126 opened in last 12m
23d 15h
MTTR — mean time to resolve
closed cases, last 12m
26
Active AI agents
of 63 total
34,160
AI agent tasks executed (12m)
15,800 in last 30d
In the last 12 months, Blink automated: - 32,695 CASB policy violations triaged and investigated - 11,559 MDR security cases ingested and processed without manual intervention - 9,139 SIEM correlation events automatically enriched and routed - 3,854 EDR alerts auto-triaged across endpoints - 3,853 compromised credentials ingested from dark web threat intelligence feeds - 3,843 DLP policy violation cases ingested from Proofpoint - 3,841 AI usage governance records validated via WitnessAI - 2,290 endpoint files automatically evaluated for quarantine - 1,920 curated threat mention alerts ingested from Flashpoint - 1,920 code repository & DEA threat alerts ingested from Flashpoint - 1,877 USB access exceptions automatically revoked upon expiry - 960 ransomware threat indicators refreshed from Google Threat Intelligence - 960 Flashpoint alert rule definitions refreshed for threat monitoring - 959 breach forum community mentions monitored via Flashpoint - 958 Delta-specific ransomware mentions monitored via Flashpoint - 958 Delta technology mentions monitored via Flashpoint - 958 dark web marketplace mentions of Delta monitored via Flashpoint - 957 combo threat mentions (botnet, brute force, data breach) monitored via Flashpoint - 957 typosquatting & phishing domain mentions monitored via Flashpoint - 956 ransomware threat alerts ingested from Flashpoint - 794 GTI threat intelligence reports ingested and converted to OSINT cases - 704 OSINT threat reports processed into cases via automated subflow - 668 ransomware intelligence articles ingested and AI-summarized via Flashpoint - 648 aviation-sector threat intel ingested via A-ISAC CyWare feed - 624 GTI BleepingComputer reports ingested and converted to OSINT cases - 623 GTI SecurityWeek reports ingested and converted to OSINT cases - 622 GTI HackerNews reports ingested and converted to OSINT cases - 427 ZScaler OSINT reports swept for threat indicators via GTI - 427 CISA OSINT reports swept for threat indicators via GTI - 422 alerts autonomously triaged by the AI-powered Agentic SOC decision layer - 409 Check Point OSINT reports swept for threat indicators via GTI - 409 MalwareBytes OSINT reports swept for threat indicators via GTI - 408 Unit42 OSINT reports swept for threat indicators via GTI - 408 Wiz OSINT reports swept for threat indicators via GTI - 407 SentinelOne OSINT reports swept for threat indicators via GTI - 407 Microsoft OSINT reports swept for threat indicators via GTI - 308 SocketDev OSINT reports swept for threat indicators via GTI - 308 Elastic OSINT reports swept for threat indicators via GTI - 308 Talos OSINT reports swept for threat indicators via GTI - 308 Proofpoint OSINT reports swept for threat indicators via GTI - 308 Red Canary OSINT reports swept for threat indicators via GTI - 308 CrowdStrike OSINT reports swept for threat indicators via GTI - 300 GTI OSINT reports swept for indicators via automated subflow - 187 CVE intelligence lookups resolved via Google Threat Intelligence - 132 threat intel articles swept for CVEs and cross-referenced against Qualys/Wiz exposure - 106 SentinelOne threat indicators swept and investigated via Deep Visibility queries - 96 ACE PM dashboard views served via automated widget updates - 81 endpoints isolated and quarantined in real time - 76 Expel security actions ingested for case processing - 64 General OSINT reports swept for threat indicators via GTI - 12 WitnessAI host removal actions approved and executed via SentinelOne - 8 USB exceptions restored via self-service after hardware rebuild - 8 SentinelOne quarantine actions routed through approval workflow

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1 — SIEM Event Ingestion & Log Health Monitoring
  • 9,139SIEM correlation events ingested from Exabeam
3.8%
17
17 active
Use Case 2 — Multi-Source SOC Alert Ingestion & Case Management
  • 11,559MDR security cases ingested & auto-processed
  • 3,854EDR alerts automatically triaged
  • 3,853Cloud threat alerts auto-processed
10.9%
58
56 active
Use Case 3 — Agentic SOC & AI-Driven Investigation
  • 1,686Cribl security alerts auto-ingested
  • 422AI-driven alert triage decisions made autonomously
42.8%
20
19 active
Use Case 4 — Alert Enrichment & IOC Lookup
  • 106SentinelOne threat indicators swept and investigated via Deep Visibility
7.0%
39
39 active
Use Case 5 — Proofpoint CASB Alert Triage & Response
  • 32,695CASB policy violations triaged & investigated
11.7%
7
7 active
Use Case 6 — Phishing Detection & URL Analysis4,156 executions
0.9%
5
5 active
Use Case 7 — Threat Intelligence — Flashpoint Compromised Credentials
  • 3,853Compromised credentials ingested from dark web feeds
  • 1,920Curated threat mention alerts ingested from Flashpoint
  • 1,920Code repository & DEA threat alerts ingested from Flashpoint
4.8%
35
34 active
Use Case 8 — EDR Containment & Wide-Area Isolation
  • 2,290Endpoint files automatically evaluated for quarantine
  • 81Endpoints isolated & quarantined in real time
  • 8SentinelOne quarantine actions routed through approval workflow
2.9%
22
21 active
Use Case 9 — Endpoint Inventory & Insider Threat Monitoring
  • 5,779SentinelOne ITM events polled & processed
3.2%
8
8 active
Use Case 10 — USB Exception Request Lifecycle
  • 1,877USB access exceptions automatically revoked
  • 8USB exceptions restored via self-service after hardware rebuild
0.5%
16
16 active
Use Case 11 — DLP & Data Policy Enforcement
  • 3,843DLP policy violation cases ingested from Proofpoint
2.3%
21
21 active
Use Case 12 — Security Metrics & SOC Reporting
  • 96ACE PM dashboard views served via automated widget updates
0.8%
30
25 active
Use Case 13 — Network Traffic Analysis591 executions
0.1%
16
16 active
Use Case 14 — Vendor Risk Search — Archer Integration0 executions
0.0%
1
0 active
Use Case 15 — Phishing Simulation Awareness Tracking3 executions
0.0%
1
1 active
Use Case 16 — Vulnerability & Technology CVE Search
  • 187CVE intelligence lookups resolved via Google Threat Intelligence
0.2%
4
4 active
Use Case 17 — Endpoint Browser History Forensics1 executions
0.0%
4
4 active
Use Case 18 — AI Usage Governance — WitnessAI Validation
  • 3,841AI usage governance records validated via WitnessAI
  • 12WitnessAI host removal actions approved and executed via SentinelOne
0.0%
4
4 active
Use Case 19 — Shadow IT / SaaS App Discovery Reporting5 executions
0.0%
2
2 active
Total427,657 executions100%
310
299 active

Use Case Growth Over Time

885 unique playbooks  |  19 operational use cases  |  465,292 total executions (12m)  |  1970-01 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Use Case 3 — Agentic SOC & AI-Driven Investigation
Agents Mattermost SentinelOne
Use Case 4 — Alert Enrichment & IOC Lookup
VirusTotal PingID SentinelOne Microsoft Outlook Microsoft Graph Microsoft Entra ID
Use Case 8 — EDR Containment & Wide-Area Isolation
SentinelOne VirusTotal Agents Microsoft SQL Server Microsoft Teams Email Mattermost Web Form
Use Case 6 — Phishing Detection & URL Analysis
Microsoft Outlook PhishLabs Mattermost Proofpoint Threat Protection Email SentinelOne Microsoft Teams
Use Case 12 — Security Metrics & SOC Reporting
Mattermost PagerDuty Microsoft Outlook String Utilities ThreatQuotient Dashboards Agents Email Microsoft Graph SharePoint
Use Case 9 — Endpoint Inventory & Insider Threat Monitoring
ServiceNow Agents Microsoft Outlook SentinelOne PingID
Use Case 2 — Multi-Source SOC Alert Ingestion & Case Management
Microsoft Outlook Mattermost Agents Email SentinelOne Web Form Expel Wiz GitLab PagerDuty Microsoft Teams ServiceNow Exabeam Proofpoint Threat Protection Dashboards
Use Case 11 — DLP & Data Policy Enforcement
Microsoft Outlook Mattermost Agents Email GitLab Web Form SentinelOne Microsoft Teams Proofpoint
Use Case 5 — Proofpoint CASB Alert Triage & Response
Agents Email Microsoft Outlook Mattermost
Use Case 7 — Threat Intelligence — Flashpoint Compromised Credentials
Email Mattermost Microsoft Outlook SentinelOne Flashpoint Agents
Use Case 1 — SIEM Event Ingestion & Log Health Monitoring
Mattermost Microsoft Graph Microsoft Outlook SSH Exabeam
Use Case 10 — USB Exception Request Lifecycle
Web Form Microsoft Teams SentinelOne Agents Mattermost Email
Use Case 13 — Network Traffic Analysis
Exabeam SentinelOne
Use Case 15 — Phishing Simulation Awareness Tracking
Microsoft Outlook Agents
Use Case 16 — Vulnerability & Technology CVE Search
Qualys Wiz
Use Case 17 — Endpoint Browser History Forensics
SentinelOne Agents
Use Case 19 — Shadow IT / SaaS App Discovery Reporting
Email Mattermost
Use Case 18 — AI Usage Governance — WitnessAI Validation
SentinelOne Mattermost Microsoft Teams

04Key Observations

✓  Strengths

Strengths

Scale and Coverage. 192,911 total workflow executions across 256 active playbooks over 12 months demonstrates deep, production-grade adoption of automation across the full SOC function. The platform is not being used for proof-of-concept workflows — it is integral to daily operations.

Aviation-Domain Specificity. The SIEM workspace integrates natively with aviation-specific systems including FOMAX (flight operations), Documentum (document management), WebOMS, and per-aircraft-type log health checks. This reflects a mature integration model tailored to Delta's operational environment, not a generic SOC deployment.

Multi-Layered Alert Pipeline. The Exabeam correlation pipeline (ingestion → processing → deduplication → enrichment) executes ~46,000 times per year in the dedicated SIEM workspace, operating as a fully automated high-volume event processor. Combined with SentinelOne, Wiz, Akamai, Expel, and Proofpoint ingestion in the main workspace, the alert pipeline spans all major threat surfaces.

Agentic SOC Investment. The dedicated Agentic SOC workspace with 422 decision layer executions and specialized expert agents (Geoffrey, Tiana, Murgatroyd) represents a forward-looking investment in AI-driven autonomous investigation, reflecting an ambition to reduce analyst alert handling workload rather than just automate mechanical steps.

Credential Threat Response. The Flashpoint credential stealer pipeline with ~5,000+ combined executions across ingestion, processing, and remediation playbooks demonstrates a proactive approach to dark web threat intelligence — automatically correlating published stealer logs to active employees and executing remediation at scale.

USB Lifecycle Governance. 1,877 USB exception removals in 12 months, combined with a full intake-to-recertification lifecycle, indicates consistent enforcement of endpoint access controls that would otherwise require manual audit processes.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

50% Playbook Utilization. 237 of 493 playbooks have zero executions in the last 12 months. The idle SOC enrichment utilities workspace (a6e9c12e) contains 24 zero-execution playbooks integrating CrowdStrike, URLScan, IPDB, and Okta — each pre-built but unused. These represent immediate activation opportunities if the corresponding integrations are in scope.

CrowdStrike and Okta Enrichment Unconfigured. Pre-built enrichment playbooks for CrowdStrike (agent ID lookup) and Okta (user lookup) are present but have never executed. If CrowdStrike or Okta are part of the environment, activating these enrichment paths would add identity and endpoint context to every investigation automatically.

SafeBreach Integration Present but Idle. SafeBreach integration code is referenced in the workflow library but has not executed. Connecting breach-and-attack simulation results to the SOC case pipeline could provide continuous validation of detection coverage.

Duplicate Traffic Analysis Subflows. The network traffic use case contains multiple copy variants (e.g., S1 Traffic - DNS subflow and S1 Traffic - DNS subflow copy) each running ~40 executions. Consolidating to a single authoritative subflow would reduce maintenance overhead.

Testing Workflow in Production. The playbook Vincent Testing - Rob copy in workspace e93903f0 ran 449 times in 12 months — suggesting a development or testing workflow is executing in a production-connected environment. This warrants review to confirm it is not impacting production data or case counts.

GRC Coverage Limited to USB and DLP. Relative to the breadth of the SOC automation portfolio, GRC automation is limited. Opportunities exist to extend into vulnerability management reporting, compliance questionnaire automation, and vendor risk workflows using existing integrations (ServiceNow, Wiz, Exabeam).

Integration Ecosystem

Delta Air Lines has deployed Blink with one of the broadest integration footprints in the platform:

Category Integrations
EDR / Endpoint SentinelOne (primary), Qualys, Mandiant
SIEM & Log Management Exabeam, Cribl
Monitoring Zabbix
Cloud Security Wiz, Koi Security
Email Security / CASB Proofpoint (CASB, Threat Protection, ITM)
Threat Intelligence Flashpoint, VirusTotal, AbuseIPDB, URLScan, Cyware (A-ISAC TAXII feed)
Identity & Access Microsoft Entra ID, PingID, SailPoint
ITSM & Case Management ServiceNow, Expel, PagerDuty
Collaboration Mattermost, Slack, Microsoft Teams, Microsoft Outlook
Aviation-Specific FOMAX, WebOMS, Documentum
DevOps / GitOps GitLab, GitHub
Network / Infrastructure Akamai, Arista
GRC / Vendor Risk RSA Archer
Unused / Available CrowdStrike, Okta, SafeBreach
Appendices
A Case Management 18,126 cases (12m) | MTTR 23d 15h

Case Management

Total Cases (all-time)
25,708
18,126 opened in last 12m
Cases Opened (30d)
6,517
3,945 closed in last 30d
Cases Closed (12m)
12,364
of 18,126 opened
MTTR
23d 15h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Incident Response 9,787 5,207 4,896 3d 11h
AI SOC 5,877 5,877 1,105 1d 12h
Cyber Threat Intelligence 4,776 4,776 4,720 2d 1h
Dev_Case_MGMT_Playground 2,985 0 0 N/A
Aircraft Cybersecurity Team 1,624 1,624 1,128 231d 4h
Data Loss Prevention 436 436 322 20s
Cyber Forensics and Investigation 205 190 186 13d 12h
ITM 16 16 7 33d 12h
Case Management Playground 2 0 0 N/A
B AI Agents 26 active | 34,160 tasks (12m)

AI Agents

Active Agents
26
of 63 total
Tasks Executed (12m)
34,160
15,800 in last 30d
Data Usage (12m)
4,309,456,652
2,285,648,931 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 SOC Analyst AI SOC 7,363 5,928 1,456,813,963
2 Agent Blink - Decision Maker AI SOC 4,386 0 411,126,026
3 SOC Agent - Core Investigator Agent AI SOC 4,295 3,482 994,923,244
4 Dr. Data Incident Response 3,678 638 143,415,929
5 Summarizer Cyber Threat Intelligence 3,187 1,241 125,841,340
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
AI SOC18,687
Incident Response8,004
Cyber Threat Intelligence7,423
ACE Project Management46
ITM0
C Self-Service & Webforms 0 app runs | 69 form submissions

Self-Service Applications

Apps
35
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 KB 00
2 ITM 00
3 Akamai Support 00
4 ITM Import 00
5 Arista 00

Webforms

Forms
27
active webforms
Total Submissions
69
all time
Completed
60
fully submitted
Submissions (30d)
58
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 USB Exception Request 4745
2 Cyber Forensics and Investigations Initial Intake Form 2215
3 Akamai Quarterly Custom Header Rotation Confirmation 00
4 Akamai Certificate Expiration Notice 00
5 Sender Policy Framework (SPF) Request 00
D Full Use Case Analysis 19 use cases | 465,292 executions (12m)

Business KPIs

Metric Count Playbook
CASB policy violations triaged & investigated 32,695 Proofpoint CASB Alerts
MDR security cases ingested & auto-processed 11,559 SentinelOne WatchTower MDR Case Ingestion
SIEM correlation events ingested from Exabeam 9,139 Ingestion - Correlation Rule Trigger Events
SentinelOne ITM events polled & processed 5,779 1.2_S1_ITM_Poll
EDR alerts automatically triaged 3,854 SentinelOne Alerts
Cloud threat alerts auto-processed 3,853 Wiz Threats
Compromised credentials ingested from dark web feeds 3,853 Flashpoint - Polling - Compromised Credential_Credential Stealer Ingest
DLP policy violation cases ingested from Proofpoint 3,843 DLP Case Ingestion
AI usage governance records validated via WitnessAI 3,841 WitnessAI Validation - Polling
Endpoint files automatically evaluated for quarantine 2,290 S1 File Quarantine Eval
Curated threat mention alerts ingested from Flashpoint 1,920 Flashpoint - Curated Alerts Ingestion
Code repository & DEA threat alerts ingested from Flashpoint 1,920 Flashpoint - DEA Alerts Ingestion
USB access exceptions automatically revoked 1,877 USB Exception Request - Remove Exception
Cribl security alerts auto-ingested 1,686 Cribl Alert Ingestion
Ransomware threat indicators refreshed from Google Threat Intelligence 960 GTI Ransomware Table
Flashpoint alert rule definitions refreshed for threat monitoring 960 Flashpoint - Alert Rules Table
Breach forum community mentions monitored via Flashpoint 959 Flashpoint - Breach Forums Alerts - Communities
Delta-specific ransomware mentions monitored via Flashpoint 958 Flashpoint - Delta Specific Ransomware Mentions
Delta technology mentions monitored via Flashpoint 958 Flashpoint - Delta Technologies
Dark web marketplace mentions of Delta monitored via Flashpoint 958 Flashpoint - Delta Marketplaces
Combo threat mentions (botnet, brute force, data breach) monitored via Flashpoint 957 Flashpoint - Combo Alerts
Typosquatting & phishing domain mentions monitored via Flashpoint 957 Flashpoint - Typosquatting & Phishing Domains
Ransomware threat alerts ingested from Flashpoint 956 Flashpoint - Ransomware Alerts Ingestion
GTI threat intelligence reports ingested and converted to OSINT cases 794 GTI - Reports Case Ingestion
OSINT threat reports processed into cases via automated subflow 704 Subflow - OSINT Case Creation
Ransomware intelligence articles ingested and AI-summarized via Flashpoint 668 Flashpoint - Ransomware Alerts Ingestion copy
Aviation-sector threat intel ingested via A-ISAC CyWare feed 648 A-ISAC CyWare Feed Ingestion
GTI BleepingComputer reports ingested and converted to OSINT cases 624 GTI - BleepingComputer Ingestion
GTI SecurityWeek reports ingested and converted to OSINT cases 623 GTI - SecurityWeek Report Ingestion
GTI HackerNews reports ingested and converted to OSINT cases 622 GTI - HackerNews Ingestion
ZScaler OSINT reports swept for threat indicators via GTI 427 GTI IOC Sweeps - ZScaler Reports
CISA OSINT reports swept for threat indicators via GTI 427 GTI IOC Sweeps - CISA Reports
AI-driven alert triage decisions made autonomously 422 Agentic SOC - Decision Layer
Check Point OSINT reports swept for threat indicators via GTI 409 GTI IOC Sweeps - Check Point Reports
MalwareBytes OSINT reports swept for threat indicators via GTI 409 GTI IOC Sweeps - MalwareBytes Reports
Unit42 OSINT reports swept for threat indicators via GTI 408 GTI IOC Sweeps - Unit42 Reports
Wiz OSINT reports swept for threat indicators via GTI 408 GTI IOC Sweeps - Wiz Reports
SentinelOne OSINT reports swept for threat indicators via GTI 407 GTI IOC Sweeps - SentinelOne Reports
Microsoft OSINT reports swept for threat indicators via GTI 407 GTI IOC Sweeps - Microsoft Reports
SocketDev OSINT reports swept for threat indicators via GTI 308 GTI IOC Sweeps - SocketDev Reports
Elastic OSINT reports swept for threat indicators via GTI 308 GTI IOC Sweeps - Elastic Reports
Talos OSINT reports swept for threat indicators via GTI 308 GTI IOC Sweeps - Talos Reports
Proofpoint OSINT reports swept for threat indicators via GTI 308 GTI IOC Sweeps - Proofpoint Reports
Red Canary OSINT reports swept for threat indicators via GTI 308 GTI IOC Sweeps - Red Canary Reports
CrowdStrike OSINT reports swept for threat indicators via GTI 308 GTI IOC Sweeps - CS Reports
GTI OSINT reports swept for indicators via automated subflow 300 Subflow - OSINT IOC Sweep
CVE intelligence lookups resolved via Google Threat Intelligence 187 GTI Vuln Intelligence
Threat intel articles swept for CVEs and cross-referenced against Qualys/Wiz exposure 132 Subflow - CVE Sweep
SentinelOne threat indicators swept and investigated via Deep Visibility 106 SentinelOne IOC Sweep
ACE PM dashboard views served via automated widget updates 96 ACE PM View Only
Endpoints isolated & quarantined in real time 81 client_quarantine
Expel security actions ingested for case processing 76 Expel Action Ingestion
General OSINT reports swept for threat indicators via GTI 64 GTI IOC Sweeps - General OSINT
WitnessAI host removal actions approved and executed via SentinelOne 12 SentinelOne WitnessAI Removal - Approved
USB exceptions restored via self-service after hardware rebuild 8 USB Exception Migration
SentinelOne quarantine actions routed through approval workflow 8 S1 Quarantine Hosts - Approval
In the last 12 months, Blink automated: - 32,695 CASB policy violations triaged and investigated - 11,559 MDR security cases ingested and processed without manual intervention - 9,139 SIEM correlation events automatically enriched and routed - 3,854 EDR alerts auto-triaged across endpoints - 3,853 compromised credentials ingested from dark web threat intelligence feeds - 3,843 DLP policy violation cases ingested from Proofpoint - 3,841 AI usage governance records validated via WitnessAI - 2,290 endpoint files automatically evaluated for quarantine - 1,920 curated threat mention alerts ingested from Flashpoint - 1,920 code repository & DEA threat alerts ingested from Flashpoint - 1,877 USB access exceptions automatically revoked upon expiry - 960 ransomware threat indicators refreshed from Google Threat Intelligence - 960 Flashpoint alert rule definitions refreshed for threat monitoring - 959 breach forum community mentions monitored via Flashpoint - 958 Delta-specific ransomware mentions monitored via Flashpoint - 958 Delta technology mentions monitored via Flashpoint - 958 dark web marketplace mentions of Delta monitored via Flashpoint - 957 combo threat mentions (botnet, brute force, data breach) monitored via Flashpoint - 957 typosquatting & phishing domain mentions monitored via Flashpoint - 956 ransomware threat alerts ingested from Flashpoint - 794 GTI threat intelligence reports ingested and converted to OSINT cases - 704 OSINT threat reports processed into cases via automated subflow - 668 ransomware intelligence articles ingested and AI-summarized via Flashpoint - 648 aviation-sector threat intel ingested via A-ISAC CyWare feed - 624 GTI BleepingComputer reports ingested and converted to OSINT cases - 623 GTI SecurityWeek reports ingested and converted to OSINT cases - 622 GTI HackerNews reports ingested and converted to OSINT cases - 427 ZScaler OSINT reports swept for threat indicators via GTI - 427 CISA OSINT reports swept for threat indicators via GTI - 422 alerts autonomously triaged by the AI-powered Agentic SOC decision layer - 409 Check Point OSINT reports swept for threat indicators via GTI - 409 MalwareBytes OSINT reports swept for threat indicators via GTI - 408 Unit42 OSINT reports swept for threat indicators via GTI - 408 Wiz OSINT reports swept for threat indicators via GTI - 407 SentinelOne OSINT reports swept for threat indicators via GTI - 407 Microsoft OSINT reports swept for threat indicators via GTI - 308 SocketDev OSINT reports swept for threat indicators via GTI - 308 Elastic OSINT reports swept for threat indicators via GTI - 308 Talos OSINT reports swept for threat indicators via GTI - 308 Proofpoint OSINT reports swept for threat indicators via GTI - 308 Red Canary OSINT reports swept for threat indicators via GTI - 308 CrowdStrike OSINT reports swept for threat indicators via GTI - 300 GTI OSINT reports swept for indicators via automated subflow - 187 CVE intelligence lookups resolved via Google Threat Intelligence - 132 threat intel articles swept for CVEs and cross-referenced against Qualys/Wiz exposure - 106 SentinelOne threat indicators swept and investigated via Deep Visibility queries - 96 ACE PM dashboard views served via automated widget updates - 81 endpoints isolated and quarantined in real time - 76 Expel security actions ingested for case processing - 64 General OSINT reports swept for threat indicators via GTI - 12 WitnessAI host removal actions approved and executed via SentinelOne - 8 USB exceptions restored via self-service after hardware rebuild - 8 SentinelOne quarantine actions routed through approval workflow

Use Case Summary

# Use Case Category Subcategory Active Playbooks
1 SIEM Event Ingestion & Log Health Monitoring SOC SIEM & log pipeline monitoring 17
2 Multi-Source SOC Alert Ingestion & Case Management SOC Case mgmt & SOAR 58
3 Agentic SOC & AI-Driven Investigation SOC Agentic SOC 20
4 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 59
5 Proofpoint CASB Alert Triage & Response SOC Phishing detection & response 7
6 Phishing Detection & URL Analysis SOC Phishing detection & response 5
7 Threat Intelligence — Flashpoint Compromised Credentials SOC Threat intel ingest & curation, Identity threat response 53
8 EDR Containment & Wide-Area Isolation SOC EDR containment & response 23
9 Endpoint Inventory & Insider Threat Monitoring Other Endpoint hygiene & MDM ops 8
10 USB Exception Request Lifecycle GRC RBAC review & access mgmt 16
11 DLP & Data Policy Enforcement GRC DLP triage & exposure resp 22
12 Security Metrics & SOC Reporting GRC Security metrics & reporting 30
13 Network Traffic Analysis SOC Alert enrichment / IOC lookup 19
14 Vendor Risk Search — Archer Integration GRC Vendor risk & TPRM 1
15 Phishing Simulation Awareness Tracking SOC Phishing sim & awareness 1
16 Vulnerability & Technology CVE Search Vulnerability Mgmt CVE lookup & remediation 4
17 Endpoint Browser History Forensics SOC EDR containment & response 4
18 AI Usage Governance — WitnessAI Validation GRC AI / HR compliance automation 6
19 Shadow IT / SaaS App Discovery Reporting Cloud Security Cloud access & SaaS policy mgmt 2

Use Cases

Use Case 1 — SIEM Event Ingestion & Log Health Monitoring

Category: SOC | Subcategory: SIEM & log pipeline monitoring

Description: Fully automates the Exabeam SIEM event pipeline — ingesting correlation rule trigger events, enriching them with associated log data, deduplicating alerts, and forwarding metrics to Zabbix. Includes scheduled log-health checks across aircraft types and platforms, fleet synchronization, and access token maintenance. Aviation-specific integrations (Documentum, WebOMS, FOMAX) are natively supported.

Business Problem: Manual SIEM data management creates detection gaps and inconsistent alert quality. Operational log health checks require constant analyst attention. Blink automates the full event lifecycle from ingestion through enrichment, ensuring continuous pipeline integrity and providing aviation-domain context enrichment before alerts reach analysts.

Key Integrations: Exabeam, Zabbix, Documentum, HTTP, WebOMS (custom)

Playbook Executions (12 mo.)
Send to Zabbix 14,373
Processing - Correlation Rule Trigger Events 9,146
Ingestion - Correlation Rule Trigger Events 9,139
Processing - Case / Alert Deduplication and Setup 9,129
Enrichment - Correlation Rule Trigger Events 9,126
Enrichment - Get Associated Logs 9,110
Exabeam Access Token Update 321
Log Flow Health - Run Checks 162
Log Flow Health - Discrepancies Check 77
Documentum Query 77
Log Flow Health - Check Server Script Logs 74
Log Flow Health - Start Checks Per Aircraft Type 41
Ingestion - Missing Logs 36
Enrichment - Query WebOMS and Attach Results to Case 19
Fleet List Sync 12
Aircraft Sync - FOMAX 6
Exabeam Ingestion Monitoring 720

Use Case 2 — Multi-Source SOC Alert Ingestion & Case Management

Category: SOC | Subcategory: Case mgmt & SOAR

Description: Central alert intake and full case lifecycle management hub. Automatically ingests security events from SentinelOne WatchTower MDR, Wiz, Akamai, Expel, ServiceNow, Cohesity, Proofpoint, Arista, and Cribl into the CDART case management system. Handles deduplication, priority tagging, analyst assignment via round-robin, escalation routing, daily ops summaries, and automated case closure. Communications are delivered over Mattermost, Slack, and email.

Business Problem: Analysts across multiple source systems spend significant time on manual case creation, routing, and status tracking. Disparate alert sources create visibility gaps and inconsistent triage priority. Blink unifies the alert-to-case pipeline, automates analyst load balancing, and enforces consistent SLA tracking from ingestion to closure.

Key Integrations: SentinelOne, Wiz, Akamai, Expel, ServiceNow, Cohesity, Proofpoint, Mattermost, Slack, PagerDuty, GitLab, Arista, Blink Case Management

Playbook Executions (12 mo.)
SentinelOne WatchTower MDR Case Ingestion 11,559
Pending Request Notification 5,779
SentinelOne Alerts 3,854
Wiz Threats 3,853
Ingest - CM Comms Emails 3,808
Ingest - Akamai CM Comms Email 2,701
CDART Snooze Table Refresh 2,889
Akamai Incidents 963
BlinkOps Cases 963
Ability - Send Mattermost Message 180
Expel Incidents and Investigations 255
Expel Case Closing 189
SNow Case Ingestion 186
Expel Case Ingestion 181
CDART Tool Alerting 121
Assign Slack (Expel) Cases 95
Get Analysts 95
Assign BlinkOps & Travel Security Case 196
Ability - Query Users in Case Management 72
CASB Alert Ingest 57
Cohesity- Security Tooling Alerts 52
round_robin_counter 58
Escalate Case Decision 47
Proofpoint Threat Response Ingestion 39
Get BlinkOps/Travel Security Cases 50
Get Slack (Expel) Cases 44
Get Open Slack (Expel) Cases 27
ServiceNow Case Closing 35
Grab Open Cases 37
New Case Processing - Apply Year, Month, and Quarter fields 429
Validate Case Manager Assignment and Queue 439
SOC Daily Ops Assignments 64
Send Daily Ops Assignments 43
Escalation Response 17
Arista Email Ingestion 15
Auto-Closure 9
Auto-Closure Subflow 8
Action Merge Request 8
2.1_Email IT Technology Governance Upon Case Creation 8
DLP_GRC Submissions - Case Ingestion 8
Arista Historical Cases Report 6
Send to CFI 3
Arista - High/Critical - Processing 4
CFI Initial Intake Form 11
SNow Case Prosessing 154
Manager Listener 48
Ability - Re-run Daily Assignments 0
Ability - Create Case 12
Ability - Get Cases 11
Ability - Case & Observable Types 10
Ability - Create & Link Observables 6
Dashboard-Book of Grudges 728
Imani Testing copy 0
Wiz RedAgent Discovery 6
Add table entry 0
Send Email 44
Expel Action Ingestion 76
Test 1

Use Case 3 — Agentic SOC & AI-Driven Investigation

Category: SOC | Subcategory: Agentic SOC

Description: A layered AI investigation framework operating within the dedicated Agentic SOC workspace. A decision layer routes incoming alerts to specialized expert AI agents, each capable of querying enrichment data, accessing VIP user lists, performing hash searches, and retrieving asset context. The Murgatroyd AI assistant is additionally available on-demand via Mattermost webhooks, serving as an interactive SOC copilot. Named AI agents Geoffrey, Tiana, and Fairy Godmother represent analyst-persona automation for specific investigation workflows.

Business Problem: Alert volume and investigation depth requirements exceed analyst bandwidth. Rather than simply routing alerts to humans, the Agentic SOC layer performs autonomous first-pass investigation, synthesizes observable enrichment, and delivers structured findings — enabling analysts to focus on escalated cases requiring human judgment.

Key Integrations: Blink Agents, Mattermost, SentinelOne, Microsoft Entra ID, VirusTotal

Playbook Executions (12 mo.)
Cribl Alert Ingestion 1,686
Subflow - Enrich Observables - Main Router 1,644
Subflow - Update Enrichment Data 987
Agent Ability - Get VIP Users 458
Agentic SOC - Decision Layer 422
Process Alert 413
Subflow - Response - Main Router 408
Agentic SOC - Expert Agents 212
Subflow - Agentic SOC - Main - AI Investigation 212
Agent Ability - Get Case Observable's Enrichment 210
Ask Murgatroyd Webhook 90
Agent Ability - Endpoint Hash Search 160
Invoke - Geoffrey 44
Invoke - Tiana 27
Invoke - Webster 12
Invoke - Fairy Godmother 55
Refresh investigations on case dataset 0
Load cases taggings from csv 0
Load cases predictions from conclusions 0
Main Evaluation - Evaluate On Cases dataset 0

Use Case 4 — Alert Enrichment & IOC Lookup

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Description: A comprehensive enrichment layer spanning three workspaces that resolves security observables (file hashes, IPs, domains, usernames, device IDs) through VirusTotal, Whois, Microsoft Entra ID, PingID, and SentinelOne. Maintains a live case management user table with device-to-user linkage and MFA device correlation. Supports both automated pipeline enrichment and on-demand analyst lookups.

Business Problem: Raw alerts from EDR, SIEM, and cloud tools contain sparse technical indicators that require extensive manual lookups before an analyst can assess risk or take action. This enrichment layer populates every case with user identity, device ownership, threat intelligence verdicts, and contextual asset data — reducing analyst investigation time per alert.

Key Integrations: VirusTotal, URLScan, AbuseIPDB, SentinelOne, Microsoft Entra ID, PingID, Whois (HTTP)

Playbook Executions (12 mo.)
1.2.1 CM Dedup MFA Devices 843
1.1 Subflow - Enrich User Record 443
1.0 CM Users Table Enrichment - New Record Dedup and Processing 411
1.2.0 Subflow - Find and Enrich MFA Devices 403
1.3.0 Find and Link Devices by Username 402
Subflow 3 - Enrich Observable 210
Enrich - Hash - VT 672
Get User Information Using Microsoft Entra ID 103
Enrich - Username or Email - Microsoft Entra ID 103
Enrich - IP - VT 194
Enrich - SentinelOne Device Agent ID 161
Enrich - Username or Email - PingID 46
VT File Report 48
VT Get Analysis 48
Ability - Get user manager by PPR 52
Ability - Query for user information by name 34
Ability - Search for user host by PPR 33
Ability - Check S1 for host 31
Ability - Query MFA Devices 22
Gather Device Record from S1 223
1.3.1 Device Dedup Enrich 229
SentinelOne Isolation Status 34
Enrich - IP or Domain - Whois 12
Enrich IP or Domain Using Whois 12
Agent Ability - Get Org Assets 42
VT Sandbox 3
Ability - Get manager direct reports 303
Ability - Get User's Manager 18
1.2.1 CM Dedup MFA Devices 2
1.3.2 Find Users based off S1 Username 0
Gather Device Record from S1 0
1.3.1 Device Dedup Enrich 0
1.1 Subflow - Enrich User Record 0
1.3.0 Find and Link Devices by Username 0
1.2.0 Subflow - Find and Enrich MFA Devices 0
1.0 CM Users Table Enrichment - New Record Dedup and Processing 1
Initialize table 0
Ability - Check S1 for host 238
Ability - Get user manager by PPR 130
1.1 Subflow - Enrich User Record 15
SentinelOne IOC Sweep 106
Exabeam IOC Sweep 0
VirusTotal IOC Search 0
Ability - Query for user information by name 167
Ability - Search for user host by PPR 116
ability - query AD for user's registered hosts 28
1.2.1 CM Dedup MFA Devices 404
1.0 CM Users Table Enrichment - New Record Dedup and Processing 228
1.1 Subflow - Enrich User Record 226
1.3.0 Find and Link Devices by Username 226
1.2.0 Subflow - Find and Enrich MFA Devices 226
1.3.1 Device Dedup Enrich 218
Gather Device Record from S1 215
1.3.2 Find Users based off S1 Username 0
S1 - AgentUUID to Hostname 0
Outbound Sync 874
VT Analysis Subflow 4
VT Analysis 3
ability -Batch query AD for user's registered devices 5

Use Case 5 — Proofpoint CASB Alert Triage & Response

Category: SOC | Subcategory: Phishing detection & response

Description: The highest-volume automation by execution count. Continuously ingests Proofpoint CASB policy violations, deduplicates, triages by severity, links affected users to their identity records, assigns cases to analysts, and executes remediation actions including account-level policy enforcement. The end-to-end pipeline processes tens of thousands of CASB events per year without analyst involvement.

Business Problem: Proofpoint CASB generates thousands of cloud service policy violations monthly across SaaS platforms. Manual review is unsustainable. Blink auto-triages violations, resolves user identity context, and routes only true positives requiring human action — dramatically reducing mean time to acknowledge (MTTA) for cloud policy events.

Key Integrations: Proofpoint (CASB), SentinelOne, Microsoft Entra ID, Mattermost

Playbook Executions (12 mo.)
Proofpoint CASB Alerts 32,695
Process Alert - Proofpoint CASB 60
CASB Alert Ingest 57
Assign Proofpoint CASB Cases 18
Response Subflow Proofpoint - CASB - Remediation 31
Response Subflow ProofPoint - CASB - User Linking 31
Subflow 4 - Response 204

Use Case 6 — Phishing Detection & URL Analysis

Category: SOC | Subcategory: Phishing detection & response

Description: Detects phishing clicker events from Proofpoint, retroactively identifies users who accessed malicious URLs, and performs real-time URL category classification to determine threat scope. The domain discovery workflow proactively scans for newly registered lookalike domains.

Business Problem: Phishing clicks require immediate identification of exposed users and rapid scope determination. Retroactive detection finds at-risk users who clicked links before a URL was flagged. Automated URL categorization eliminates manual analyst lookups for every new URL indicator.

Key Integrations: Proofpoint Threat Protection, Mattermost, Blink Case Management

Playbook Executions (12 mo.)
1.2_URLCategoryCheck - Poll 3,853
proofpoint_domain_discover 40
Retroactive Phishing Clicker Alert 68
Process Alert - ProofPoint Phishing Clicker 68
Subflow - Retroactive Phishing Clicker 29

Use Case 7 — Threat Intelligence — Flashpoint Compromised Credentials

Category: SOC | Subcategory: Threat intel ingest & curation, Identity threat response

Description: Continuously polls Flashpoint for newly published compromised credential and credential stealer logs mentioning the organization. Processes both bulk and individual employee records — correlating stealer logs to active employees, linking affected accounts to their identity and device records, and executing remediation including password reset and session revocation. Also ingests Flashpoint ransomware alert rules, dark web marketplace mentions, and typosquatting/phishing domain mentions on an hourly cadence, and distributes a daily OSINT threat article summary and an AI-summarized ransomware intelligence digest to the SOC via email. A dedicated on-demand tool searches live ransomware victim postings by country, group, sector, and keyword. Google Threat Intelligence (GTI), accessed via VirusTotal, supplements this pipeline with an hourly ransomware indicator table refresh and automated ingestion of GTI reports into cases. A dedicated set of hourly GTI IOC sweep playbooks additionally fetches and cleans vendor-published OSINT reports (ZScaler, CISA, Unit42, Wiz, Check Point, SentinelOne, MalwareBytes, Microsoft, SocketDev, Elastic, Talos, Proofpoint, Red Canary, CrowdStrike) for indicator extraction. Aviation ISAC (A-ISAC) threat intel is additionally ingested hourly via a Cyware TAXII 2.1 feed.

Business Problem: Credential stealer malware logs are published daily on dark web marketplaces, placing employees at immediate risk of account takeover. Manual monitoring at scale is impossible. Blink automates the full cycle from dark web detection through employee notification and credential remediation, while also keeping the SOC current on sector-specific and aviation-industry threat intelligence.

Key Integrations: Flashpoint, VirusTotal (GTI), Cyware (TAXII 2.1), SentinelOne, Microsoft Entra ID, PingID, Mattermost, Blink Case Management, Blink Agents

Playbook Executions (12 mo.)
Flashpoint - Polling - Compromised Credential_Credential Stealer Ingest 3,853
Flashpoint - Bulk Credential Stealer Processing 396
Flashpoint - Bulk Compromised Credential Processing 156
Process Alert - Flashpoint Credential 149
Flashpoint - Individual Employee Credential Stealer Processing 147
Response Subflow Flashpoint - Compromised Credentials/Credential Stealer - User Linking 144
Response Subflow Flashpoint - Credential Stealer - Remediation 114
Flashpoint - Individual Employee Compromised Credential Processing 60
Response Subflow Flashpoint - Compromised Credentials - Remediation 22
Flashpoint - Compromised Credentials/Credential Stealer - Monroe Case Processing 5
Flashpoint - Ransomware Alerts Ingestion 956
OSINT Article Morning Email 72
GTI Ransomware Table 960
GTI - Reports Case Ingestion 794
GTI Reports Table 40
Flashpoint - Curated Alerts Ingestion 1,920
Flashpoint - DEA Alerts Ingestion 1,920
Flashpoint - Breach Forums Alerts - Communities 959
Flashpoint - Delta Specific Ransomware Mentions 958
Flashpoint - Delta Technologies 958
Flashpoint - Combo Alerts 957
Flashpoint - Alert Rules Table 960
A-ISAC CyWare Feed Ingestion 648
Flashpoint - Delta Marketplaces 958
Flashpoint - Typosquatting & Phishing Domains 957
Flashpoint - Ransomware Table 33
Flashpoint - Ransomware Alerts Ingestion copy 668
Ransomware Email 6:30am daily 31
Ransomware Email 2pm daily 30
Ransomware Live Victim Search 4
GTI - BleepingComputer Ingestion 624
GTI - SecurityWeek Report Ingestion 623
GTI - HackerNews Ingestion 622
GTI IOC Sweeps - ZScaler Reports 427
GTI IOC Sweeps - CISA Reports 427
GTI IOC Sweeps - Check Point Reports 409
GTI IOC Sweeps - MalwareBytes Reports 409
GTI IOC Sweeps - Unit42 Reports 408
GTI IOC Sweeps - Wiz Reports 408
GTI IOC Sweeps - SentinelOne Reports 407
GTI IOC Sweeps - Microsoft Reports 407
GTI IOC Sweeps - SocketDev Reports 308
GTI IOC Sweeps - Elastic Reports 308
GTI IOC Sweeps - Talos Reports 308
GTI IOC Sweeps - Proofpoint Reports 308
GTI IOC Sweeps - Red Canary Reports 308
GTI IOC Sweeps - CS Reports 308
Subflow - OSINT Case Creation 704
Subflow - OSINT IOC Sweep 300
Subflow - CVE Sweep 132
GTI IOC Sweeps - General OSINT 64
DTR - Case Ingestion 0
DTR - Industry/Company Incident Specific to Aviation/Aerospace 0

Use Case 8 — EDR Containment & Wide-Area Isolation

Category: SOC | Subcategory: EDR containment & response

Description: Automates SentinelOne endpoint isolation at both individual and enterprise scale. Individual quarantine workflows handle on-demand host containment with S1 agent verification. The Wide-Area Isolation (WAI) capability enables simultaneous isolation of hundreds of hosts using chunked script execution with polling loops — supporting large-scale incident response scenarios. File-level quarantine evaluation is handled continuously via a high-volume scheduled assessment workflow. An hourly scheduled job also gathers newly onboarded SentinelOne agents to keep the WAI in-scope host list current.

Business Problem: Containing compromised endpoints during active incidents requires rapid, large-scale action that manual SentinelOne operations cannot sustain. WAI automation enables the security team to isolate hundreds of hosts within minutes using controlled job chunking, while individual quarantine workflows reduce analyst steps per containment to near zero.

Key Integrations: SentinelOne, Qualys, Mandiant, Mattermost, Blink Case Management

Playbook Executions (12 mo.)
S1 File Quarantine Eval 2,290
5_WAI_Exit1_Validation 2,246
Poll Script Completion 1,927
Nick - Check Mandiant Integration in S1 926
4_WAI_Poll For Script Completion 963
Poll CS Process CHeck Script 963
3_WAI_Execute Script Job_200 Hosts 899
2_WAI_Process Chunk Table Add_Update 663
1.2_Quarantine Hosts - In S1 421
client_quarantine 81
client_quarantine_subflow 117
1.1_Quarantine Hosts - Loop - In S1 110
1_WAI_Gather In Scope Devices 81
1.3_Quarantine Hosts - Not in S1 35
1.0_Quarantine Hosts - Ingest Records 28
1.1_Quarantine Hosts - Loop - Not in S1 19
Qualys Host Quarantine Process 3
Gather In Scope New S1 Agents 960
Reattempts 0
WAI_Gather In Scope - On Demand 2
2. Gather Hosts in Scope from Table - Every Hour 646
2. Gather Hosts in Scope from Table - Every Hour copy 0
S1 Quarantine Hosts - Approval 8

Use Case 9 — Endpoint Inventory & Insider Threat Monitoring

Category: Other | Subcategory: Endpoint hygiene & MDM ops

Description: Maintains a continuously refreshed endpoint inventory by polling SentinelOne's Insider Threat Management (ITM) module on a 10-minute schedule. Tracks all managed devices, correlates user identity data via Entra ID and PingID, and monitors for newly provisioned user accounts. Supports both automated table maintenance and analyst-facing device queries.

Business Problem: Insider threat detection requires real-time visibility into device ownership, user activity patterns, and new account creation. Static snapshots from weekly scans create detection gaps. Blink's continuous ITM polling ensures the device inventory is always current and available for case enrichment and investigation workflows.

Key Integrations: SentinelOne, Microsoft Entra ID, PingID, Microsoft Outlook, MSSQL

Playbook Executions (12 mo.)
Devices Table 10,286
1.2_S1_ITM_Poll 5,779
Query New Users Subflow 110
Ability - Move Host to another Host Group 1
Devices - S1 - Kape Triage Deployment 1
Query New Users 6
Drop Table 6
Akamai Certificate Expiration Notice (ACEN) 5

Use Case 10 — USB Exception Request Lifecycle

Category: GRC | Subcategory: RBAC review & access mgmt

Description: Fully automates the end-to-end USB device exception management process — from employee or contractor intake through manager approval workflows, SentinelOne policy verification, device provisioning, periodic recertification campaigns (AQCHR), and automated removal upon expiration. Automated reminders escalate through manager and director levels when approvals are pending.

Business Problem: USB exception management requires multi-party coordination across employees, managers, directors, and the security team, creating audit trail gaps and inconsistent enforcement. Manual expiration tracking leads to exceptions persisting beyond their approved period. Blink automates the full lifecycle with structured approval chains, audit logging, and time-bound enforcement.

Key Integrations: SentinelOne, Mattermost, Slack, Blink Case Management

Playbook Executions (12 mo.)
USB Exception Request - Remove Exception 1,877
USB Exception Request - Intake 60
USB Exception Request - Verify Host in S1 51
AQCHR Reminder Emails 30
USB Exception Request - MD or Dir Reminder Message - Get Records and Chunk 29
USB Exception Request - MD or Dir Reminder Message - Manager OOO 29
USB Exception Request - Manager Reminder Message - Grab Records and Chunk 29
USB Exception Request - Employee/Contractor 26
Check USB Exception Request Status 17
USB Exception Recertification - Receive Response 12
USB Exception Request - Provisioning 9
USB Exception Request - MD or Dir Reminder Message - Send Message 7
USB Exception Request - Manager Reminder Message - Send Message 7
Close Unresponsive AQCHR Cases 1
USB Exception Migration 8
USB Exception Group Check 12

Use Case 11 — DLP & Data Policy Enforcement

Category: GRC | Subcategory: DLP triage & exposure resp

Description: Automates DLP policy lifecycle management (activation and deactivation cycles), detects and responds to internal domain-wide password sharing events, processes employee requests for blocked website access, and manages credential reset and session revocation workflows via Entra ID and SailPoint integration. The EDL validation workflow enforces firewall External Dynamic List integrity via GitLab-triggered checks.

Business Problem: DLP policy state changes require rapid, error-free execution across endpoints. Internal password sharing represents a systemic credential hygiene risk that is difficult to detect and respond to at scale. Blocked website requests and identity reset workflows generate high analyst workload when handled manually.

Key Integrations: Proofpoint (DLP/ITM), Microsoft Entra ID, SailPoint, Mattermost, GitLab, Blink Case Management

Playbook Executions (12 mo.)
Internal Password Shared Domain Wide 55
Automator - Send message to Reset and Revoke 27
Automator - Receive message to Reset and Revoke 26
EDL Validation Send Message 32
Poll DLP Process Activation/Deactivation 16
2.0_Blocked Website Request Form 7
2.0_Blocked Website Request Form Auto Response 7
Users - Entra_Sailpoint - Revoke and Reset 9
DLP Deactivation/Activation 4
Email Redirect Request 3
Ability - PFPT Threat Protection Add to List 3
Users - Entra - Refresh Enrichment 3
Ability - Reset and Revoke 3
Check current EDL List 98
DLP Case Ingestion 3,843
DLP - Outbound Email 323
Response - DLP Outbound Email 223
Send Mattermost Message 39
Response - DLP Outbound Email - Duplicate Alert 23
Utility - View Full Thread 0
Password Reset 4
Revoke Session 1

Use Case 12 — Security Metrics & SOC Reporting

Category: GRC | Subcategory: Security metrics & reporting

Description: Delivers automated security reporting across multiple frequencies and audiences. Daily ops assignment reports are generated and distributed to analysts each morning. Weekly CISO summaries, weekly release notes, and a weekly Mattermost check-in are pushed automatically via an AI announcer agent, and on-call schedules are pushed to Mattermost automatically. Threat intelligence metrics are tracked via ThreatQuotient audit log polling, providing CTI coverage visibility. Timesheet reminders reduce administrative overhead for SOC staff. A webhook-triggered template dispatcher standardizes email formatting for dashboard-driven report requests. A SharePoint-synced CMIR wiki knowledge base is kept current — including event-driven page save/delete/create sync and a nightly scheduled dashboard refresh — AI-summarized on a monthly cadence, and made searchable on demand, while a weekly threat-hunt case summary is emailed to the team.

Business Problem: Security leaders require consistent operational visibility without placing additional reporting burden on the SOC team. Manual report compilation pulls analysts away from investigations. Blink automates all recurring security reporting, ensuring leadership has accurate, timely data without analyst intervention.

Key Integrations: ThreatQuotient, PagerDuty, Mattermost, Slack, ServiceNow, GitLab, Blink Agents

Playbook Executions (12 mo.)
1.3_CTI Metrics Get Audit Log (Event) 33
Pagerduty On-Call MM 40
Send Daily Summary M-F 40
1.0_Master ThreatQuotient Metrics 28
1.1_CTI Metrics Grab Events 28
1.3_CTI Metrics Get Audit Log (Report) 24
1.2_CTI Metrics Loop through Events/Reports 23
Send MM Reminder 52
Weekly CISO MM 6
Morning timesheet reminder MM 5
Afternoon timesheet reminder MM 5
Bridge Monitoring 12
ACE Failing Workflows 23
Dashboard-Send Email Templates 32
Dashboard-Create/Edit Email Template 120
ACE Backlog 1,100
Update HTML Widget - CMIR Wiki Dashboard 283
Search Wiki 26
Weekly Hunt Report Email 3
Pull Data from Sharepoint - CMIR Wiki 1
Update AI Summary - CMIR Wiki 1
Scheduled Update - CMIR Wiki 12
Save Changes/Delete Page/New Page - CMIR Wiki 8
CISO Weekly 2
Weekly Release Notes 1
Mattermost Check-in 0
Send Mattermost Message 3
MM Webhook 0
Create Direct Mattermost Channel 0
ACE PM View Only 96

Use Case 13 — Network Traffic Analysis

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Description: Analyzes DNS, URL, and destination-IP network traffic events sourced from both SentinelOne and Exabeam to identify anomalous or malicious patterns. Parallel subflow variants (copy/original) support high-volume, concurrent processing. A SentinelOne Deep Visibility-based destination-IP lookup traces traffic to specific sites and users on demand. Results feed directly into case management for analyst review.

Business Problem: Network traffic events from EDR and SIEM are too voluminous for manual analyst review. Automated DNS and URL traffic correlation surfaces suspicious query patterns and blocked access events, converting raw network telemetry into actionable security findings.

Key Integrations: SentinelOne, Exabeam, Mattermost, Blink Case Management

Playbook Executions (12 mo.)
Exabeam Traffic Subflow copy 40
S1 Traffic - DNS subflow copy 40
S1 Traffic - DNS subflow 40
Ability - S1 Traffic 33
Ability - Exabeam Traffic 27
Exabeam Traffic Subflow 23
S1 Traffic - DNS 22
S1 Traffic - URL Subflow 25
S1 Traffic - URL 16
Exabeam Traffic 14
Search Exabeam for Traffic 0
Test Connectivity by AppID 0
Exabeam Traffic Subflow copy 0
Ability - Exabeam Traffic 0
S1 Traffic - DNS subflow copy 0
S1 Traffic - DstIP 10
S1 Traffic - DstIP Subflow 10
S1 Traffic - SrcIP Subflow 0
S1 Traffic - SrcIP 0

Use Case 14 — Vendor Risk Search — Archer Integration

Category: GRC | Subcategory: Vendor risk & TPRM

Description: Provides on-demand search of the Archer GRC vendor risk register by search term, returning matching vendor records for use by analysts or other workflows evaluating vendor risk posture.

Business Problem: Assessing vendor risk requires quickly checking whether a vendor already has an existing risk record before onboarding or renewal decisions. Manually searching Archer reports for vendor matches is slow and inconsistent. Blink automates the vendor lookup against the Archer report directly, returning results on demand.

Key Integrations: RSA Archer

Playbook Executions (12 mo.)
Archer Dev Vendor Search Subflow 0

Use Case 15 — Phishing Simulation Awareness Tracking

Category: SOC | Subcategory: Phishing sim & awareness

Description: Monitors simulated phishing campaign notifications sent to employees via Microsoft Outlook, uses AI-driven parsing to extract the relevant details from each notification, and logs the event to a dedicated tracking table for awareness program reporting.

Business Problem: Measuring phishing awareness program effectiveness requires capturing every simulated phishing notification sent to employees. Manually tracking these notifications across a large workforce is impractical. Blink automatically detects simulated phishing notification emails, extracts relevant details via AI, and records them for awareness metrics reporting.

Key Integrations: Microsoft Outlook, Blink Agents, Blink Case Management

Playbook Executions (12 mo.)
Phishing Sim Notifications 3

Use Case 16 — Vulnerability & Technology CVE Search

Category: Vulnerability Mgmt | Subcategory: CVE lookup & remediation

Description: On-demand CVE and technology exposure lookup tools spanning Qualys and Wiz. Given a CVE identifier, resolves affected QIDs in Qualys and reports vulnerable host counts with a formatted markdown summary; a parallel Wiz-based workflow queries cloud assets for exposure to a given CVE via GraphQL and summarizes vulnerability findings. A companion Wiz workflow supports technology-based asset searches. A Google Threat Intelligence (GTI) lookup supplements these with on-demand CVE intelligence retrieval.

Business Problem: When a new CVE is disclosed, analysts need a fast answer to "are we exposed, and where?" across both on-prem vulnerability scanning (Qualys) and cloud workloads (Wiz). Manually cross-referencing CVE-to-QID mappings and querying multiple platforms is slow during time-sensitive vulnerability response. Blink automates the lookup and returns a ready-to-share exposure summary on demand.

Key Integrations: Qualys, Wiz, VirusTotal (GTI)

Playbook Executions (12 mo.)
Wiz CVE Search 58
Qualys CVE Search 33
Wiz Technologies Search 0
GTI Vuln Intelligence 187

Use Case 17 — Endpoint Browser History Forensics

Category: SOC | Subcategory: EDR containment & response

Description: On-demand forensic collection workflow that remotely triggers a browser history pull from a target SentinelOne-managed endpoint for a specified date range, downloads the resulting artifact, parses it with AI-assisted extraction, and produces domain and subdomain lists for investigation. A companion ability saves the retrieved file directly to the case record for evidentiary continuity. A dedicated web form additionally lets employees request VSS (Volume Shadow Copy) snapshots of specific hosts, capturing contact and business-justification details and automatically opening a case for the request.

Business Problem: Investigating a compromised or suspicious endpoint often requires browser history evidence and point-in-time disk snapshots, which are normally manual, per-host SentinelOne console operations. Blink automates the remote collection, retrieval, parsing, and case-linking of browser history artifacts, and structures VSS snapshot requests into an auditable, case-tracked intake process — giving analysts ready-to-use forensic evidence without leaving the case workflow.

Key Integrations: SentinelOne, Blink Case Management, Blink Agents, Blink Web Forms

Playbook Executions (12 mo.)
Ability - Initiate Browser History Pull 0
Ability - Grab Browser History Result 0
Ability - Save File to Case 0
VSS Snapshot Requests 1

Use Case 18 — AI Usage Governance — WitnessAI Validation

Category: GRC | Subcategory: AI / HR compliance automation

Description: Reconciles SentinelOne-managed hosts against WitnessAI's AI usage governance platform. A scheduled poller checks a validation queue every 15 minutes and triggers on-demand hostname lookups that confirm SentinelOne enrollment status for hosts flagged by WitnessAI.

Business Problem: As generative AI usage grows across the workforce, security teams need to confirm that hosts flagged by AI governance tooling are also covered by endpoint security. Manually cross-referencing WitnessAI-flagged hosts against the SentinelOne device inventory is slow and error-prone. Blink automates the validation loop, continuously reconciling AI usage governance data with endpoint coverage records.

Key Integrations: WitnessAI, SentinelOne

Playbook Executions (12 mo.)
WitnessAI Validation - Polling 3,841
SentinelOne WitnessAI Validation - Intake 0
WitnessAI Deployment/Removal 4
SentinelOne WitnessAI Deployment 3
SentinelOne WitnessAI Removal 1
SentinelOne WitnessAI Removal - Approved 12

Use Case 19 — Shadow IT / SaaS App Discovery Reporting

Category: Cloud Security | Subcategory: Cloud access & SaaS policy mgmt

Description: Generates a weekly report of shadow SaaS applications discovered across the environment, formatting the findings as an HTML table and distributing it via email with a CSV attachment for record-keeping. Koi Security SaaS/browser-extension governance findings are additionally ingested via webhook and posted in real time to Mattermost for immediate visibility.

Business Problem: Unauthorized or unsanctioned SaaS application usage (shadow IT) creates unmanaged risk that is difficult to track without a recurring, consolidated view. Blink automates the weekly compilation and distribution of shadow app findings, and now also surfaces real-time SaaS governance findings from Koi Security, ensuring the security team has consistent visibility without manual report building.

Key Integrations: Email (CSV/HTML reporting), Koi Security, Mattermost

Playbook Executions (12 mo.)
Shadow App Email 3
Koi Security Governance Notifications 0

Key Observations

Strengths

Scale and Coverage. 192,911 total workflow executions across 256 active playbooks over 12 months demonstrates deep, production-grade adoption of automation across the full SOC function. The platform is not being used for proof-of-concept workflows — it is integral to daily operations.

Aviation-Domain Specificity. The SIEM workspace integrates natively with aviation-specific systems including FOMAX (flight operations), Documentum (document management), WebOMS, and per-aircraft-type log health checks. This reflects a mature integration model tailored to Delta's operational environment, not a generic SOC deployment.

Multi-Layered Alert Pipeline. The Exabeam correlation pipeline (ingestion → processing → deduplication → enrichment) executes ~46,000 times per year in the dedicated SIEM workspace, operating as a fully automated high-volume event processor. Combined with SentinelOne, Wiz, Akamai, Expel, and Proofpoint ingestion in the main workspace, the alert pipeline spans all major threat surfaces.

Agentic SOC Investment. The dedicated Agentic SOC workspace with 422 decision layer executions and specialized expert agents (Geoffrey, Tiana, Murgatroyd) represents a forward-looking investment in AI-driven autonomous investigation, reflecting an ambition to reduce analyst alert handling workload rather than just automate mechanical steps.

Credential Threat Response. The Flashpoint credential stealer pipeline with ~5,000+ combined executions across ingestion, processing, and remediation playbooks demonstrates a proactive approach to dark web threat intelligence — automatically correlating published stealer logs to active employees and executing remediation at scale.

USB Lifecycle Governance. 1,877 USB exception removals in 12 months, combined with a full intake-to-recertification lifecycle, indicates consistent enforcement of endpoint access controls that would otherwise require manual audit processes.

Gaps & Opportunities

50% Playbook Utilization. 237 of 493 playbooks have zero executions in the last 12 months. The idle SOC enrichment utilities workspace (a6e9c12e) contains 24 zero-execution playbooks integrating CrowdStrike, URLScan, IPDB, and Okta — each pre-built but unused. These represent immediate activation opportunities if the corresponding integrations are in scope.

CrowdStrike and Okta Enrichment Unconfigured. Pre-built enrichment playbooks for CrowdStrike (agent ID lookup) and Okta (user lookup) are present but have never executed. If CrowdStrike or Okta are part of the environment, activating these enrichment paths would add identity and endpoint context to every investigation automatically.

SafeBreach Integration Present but Idle. SafeBreach integration code is referenced in the workflow library but has not executed. Connecting breach-and-attack simulation results to the SOC case pipeline could provide continuous validation of detection coverage.

Duplicate Traffic Analysis Subflows. The network traffic use case contains multiple copy variants (e.g., S1 Traffic - DNS subflow and S1 Traffic - DNS subflow copy) each running ~40 executions. Consolidating to a single authoritative subflow would reduce maintenance overhead.

Testing Workflow in Production. The playbook Vincent Testing - Rob copy in workspace e93903f0 ran 449 times in 12 months — suggesting a development or testing workflow is executing in a production-connected environment. This warrants review to confirm it is not impacting production data or case counts.

GRC Coverage Limited to USB and DLP. Relative to the breadth of the SOC automation portfolio, GRC automation is limited. Opportunities exist to extend into vulnerability management reporting, compliance questionnaire automation, and vendor risk workflows using existing integrations (ServiceNow, Wiz, Exabeam).

Integration Ecosystem

Delta Air Lines has deployed Blink with one of the broadest integration footprints in the platform:

Category Integrations
EDR / Endpoint SentinelOne (primary), Qualys, Mandiant
SIEM & Log Management Exabeam, Cribl
Monitoring Zabbix
Cloud Security Wiz, Koi Security
Email Security / CASB Proofpoint (CASB, Threat Protection, ITM)
Threat Intelligence Flashpoint, VirusTotal, AbuseIPDB, URLScan, Cyware (A-ISAC TAXII feed)
Identity & Access Microsoft Entra ID, PingID, SailPoint
ITSM & Case Management ServiceNow, Expel, PagerDuty
Collaboration Mattermost, Slack, Microsoft Teams, Microsoft Outlook
Aviation-Specific FOMAX, WebOMS, Documentum
DevOps / GitOps GitLab, GitHub
Network / Infrastructure Akamai, Arista
GRC / Vendor Risk RSA Archer
Unused / Available CrowdStrike, Okta, SafeBreach
E New Integrations (detail) 4 added in last 30d

New Integrations Added - Last 30 Days

4 new connections
TenantIntegrationConnection NameAdded
delta_airlines apikey-auth anvilogic_poc 2026-09-09
delta_airlines vega vega_poc 2026-09-08
delta_airlines virus-total vt_darpan 2026-08-28
delta_airlines apikey-auth koipov 2026-08-20