01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1 — SIEM Event Ingestion & Log Health Monitoring |
| 3.8% | 17 17 active |
| Use Case 2 — Multi-Source SOC Alert Ingestion & Case Management |
| 10.9% | 58 56 active |
| Use Case 3 — Agentic SOC & AI-Driven Investigation |
| 42.8% | 20 19 active |
| Use Case 4 — Alert Enrichment & IOC Lookup |
| 7.0% | 39 39 active |
| Use Case 5 — Proofpoint CASB Alert Triage & Response |
| 11.7% | 7 7 active |
| Use Case 6 — Phishing Detection & URL Analysis | 4,156 executions | 0.9% | 5 5 active |
| Use Case 7 — Threat Intelligence — Flashpoint Compromised Credentials |
| 4.8% | 35 34 active |
| Use Case 8 — EDR Containment & Wide-Area Isolation |
| 2.9% | 22 21 active |
| Use Case 9 — Endpoint Inventory & Insider Threat Monitoring |
| 3.2% | 8 8 active |
| Use Case 10 — USB Exception Request Lifecycle |
| 0.5% | 16 16 active |
| Use Case 11 — DLP & Data Policy Enforcement |
| 2.3% | 21 21 active |
| Use Case 12 — Security Metrics & SOC Reporting |
| 0.8% | 30 25 active |
| Use Case 13 — Network Traffic Analysis | 591 executions | 0.1% | 16 16 active |
| Use Case 14 — Vendor Risk Search — Archer Integration | 0 executions | 0.0% | 1 0 active |
| Use Case 15 — Phishing Simulation Awareness Tracking | 3 executions | 0.0% | 1 1 active |
| Use Case 16 — Vulnerability & Technology CVE Search |
| 0.2% | 4 4 active |
| Use Case 17 — Endpoint Browser History Forensics | 1 executions | 0.0% | 4 4 active |
| Use Case 18 — AI Usage Governance — WitnessAI Validation |
| 0.0% | 4 4 active |
| Use Case 19 — Shadow IT / SaaS App Discovery Reporting | 5 executions | 0.0% | 2 2 active |
| Total | 427,657 executions | 100% | 310 299 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Scale and Coverage. 192,911 total workflow executions across 256 active playbooks over 12 months demonstrates deep, production-grade adoption of automation across the full SOC function. The platform is not being used for proof-of-concept workflows — it is integral to daily operations.
Aviation-Domain Specificity. The SIEM workspace integrates natively with aviation-specific systems including FOMAX (flight operations), Documentum (document management), WebOMS, and per-aircraft-type log health checks. This reflects a mature integration model tailored to Delta's operational environment, not a generic SOC deployment.
Multi-Layered Alert Pipeline. The Exabeam correlation pipeline (ingestion → processing → deduplication → enrichment) executes ~46,000 times per year in the dedicated SIEM workspace, operating as a fully automated high-volume event processor. Combined with SentinelOne, Wiz, Akamai, Expel, and Proofpoint ingestion in the main workspace, the alert pipeline spans all major threat surfaces.
Agentic SOC Investment. The dedicated Agentic SOC workspace with 422 decision layer executions and specialized expert agents (Geoffrey, Tiana, Murgatroyd) represents a forward-looking investment in AI-driven autonomous investigation, reflecting an ambition to reduce analyst alert handling workload rather than just automate mechanical steps.
Credential Threat Response. The Flashpoint credential stealer pipeline with ~5,000+ combined executions across ingestion, processing, and remediation playbooks demonstrates a proactive approach to dark web threat intelligence — automatically correlating published stealer logs to active employees and executing remediation at scale.
USB Lifecycle Governance. 1,877 USB exception removals in 12 months, combined with a full intake-to-recertification lifecycle, indicates consistent enforcement of endpoint access controls that would otherwise require manual audit processes.
###
Gaps & Opportunities
50% Playbook Utilization. 237 of 493 playbooks have zero executions in the last 12 months. The idle SOC enrichment utilities workspace (a6e9c12e) contains 24 zero-execution playbooks integrating CrowdStrike, URLScan, IPDB, and Okta — each pre-built but unused. These represent immediate activation opportunities if the corresponding integrations are in scope.
CrowdStrike and Okta Enrichment Unconfigured. Pre-built enrichment playbooks for CrowdStrike (agent ID lookup) and Okta (user lookup) are present but have never executed. If CrowdStrike or Okta are part of the environment, activating these enrichment paths would add identity and endpoint context to every investigation automatically.
SafeBreach Integration Present but Idle. SafeBreach integration code is referenced in the workflow library but has not executed. Connecting breach-and-attack simulation results to the SOC case pipeline could provide continuous validation of detection coverage.
Duplicate Traffic Analysis Subflows. The network traffic use case contains multiple copy variants (e.g., S1 Traffic - DNS subflow and S1 Traffic - DNS subflow copy) each running ~40 executions. Consolidating to a single authoritative subflow would reduce maintenance overhead.
Testing Workflow in Production. The playbook Vincent Testing - Rob copy in workspace e93903f0 ran 449 times in 12 months — suggesting a development or testing workflow is executing in a production-connected environment. This warrants review to confirm it is not impacting production data or case counts.
GRC Coverage Limited to USB and DLP. Relative to the breadth of the SOC automation portfolio, GRC automation is limited. Opportunities exist to extend into vulnerability management reporting, compliance questionnaire automation, and vendor risk workflows using existing integrations (ServiceNow, Wiz, Exabeam).
Integration Ecosystem
Delta Air Lines has deployed Blink with one of the broadest integration footprints in the platform:
| Category | Integrations |
|---|---|
| EDR / Endpoint | SentinelOne (primary), Qualys, Mandiant |
| SIEM & Log Management | Exabeam, Cribl |
| Monitoring | Zabbix |
| Cloud Security | Wiz, Koi Security |
| Email Security / CASB | Proofpoint (CASB, Threat Protection, ITM) |
| Threat Intelligence | Flashpoint, VirusTotal, AbuseIPDB, URLScan, Cyware (A-ISAC TAXII feed) |
| Identity & Access | Microsoft Entra ID, PingID, SailPoint |
| ITSM & Case Management | ServiceNow, Expel, PagerDuty |
| Collaboration | Mattermost, Slack, Microsoft Teams, Microsoft Outlook |
| Aviation-Specific | FOMAX, WebOMS, Documentum |
| DevOps / GitOps | GitLab, GitHub |
| Network / Infrastructure | Akamai, Arista |
| GRC / Vendor Risk | RSA Archer |
| Unused / Available | CrowdStrike, Okta, SafeBreach |
A Case Management 18,126 cases (12m) | MTTR 23d 15h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Incident Response | 9,787 | 5,207 | 4,896 | 3d 11h |
| AI SOC | 5,877 | 5,877 | 1,105 | 1d 12h |
| Cyber Threat Intelligence | 4,776 | 4,776 | 4,720 | 2d 1h |
| Dev_Case_MGMT_Playground | 2,985 | 0 | 0 | N/A |
| Aircraft Cybersecurity Team | 1,624 | 1,624 | 1,128 | 231d 4h |
| Data Loss Prevention | 436 | 436 | 322 | 20s |
| Cyber Forensics and Investigation | 205 | 190 | 186 | 13d 12h |
| ITM | 16 | 16 | 7 | 33d 12h |
| Case Management Playground | 2 | 0 | 0 | N/A |
B AI Agents 26 active | 34,160 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | SOC Analyst | AI SOC | 7,363 | 5,928 | 1,456,813,963 |
| 2 | Agent Blink - Decision Maker | AI SOC | 4,386 | 0 | 411,126,026 |
| 3 | SOC Agent - Core Investigator Agent | AI SOC | 4,295 | 3,482 | 994,923,244 |
| 4 | Dr. Data | Incident Response | 3,678 | 638 | 143,415,929 |
| 5 | Summarizer | Cyber Threat Intelligence | 3,187 | 1,241 | 125,841,340 |
| Workspace | Tasks (12m) |
|---|---|
| AI SOC | 18,687 |
| Incident Response | 8,004 |
| Cyber Threat Intelligence | 7,423 |
| ACE Project Management | 46 |
| ITM | 0 |
C Self-Service & Webforms 0 app runs | 69 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | KB | 0 | 0 |
| 2 | ITM | 0 | 0 |
| 3 | Akamai Support | 0 | 0 |
| 4 | ITM Import | 0 | 0 |
| 5 | Arista | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | USB Exception Request | 47 | 45 |
| 2 | Cyber Forensics and Investigations Initial Intake Form | 22 | 15 |
| 3 | Akamai Quarterly Custom Header Rotation Confirmation | 0 | 0 |
| 4 | Akamai Certificate Expiration Notice | 0 | 0 |
| 5 | Sender Policy Framework (SPF) Request | 0 | 0 |
D Full Use Case Analysis 19 use cases | 465,292 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| CASB policy violations triaged & investigated | 32,695 | Proofpoint CASB Alerts |
| MDR security cases ingested & auto-processed | 11,559 | SentinelOne WatchTower MDR Case Ingestion |
| SIEM correlation events ingested from Exabeam | 9,139 | Ingestion - Correlation Rule Trigger Events |
| SentinelOne ITM events polled & processed | 5,779 | 1.2_S1_ITM_Poll |
| EDR alerts automatically triaged | 3,854 | SentinelOne Alerts |
| Cloud threat alerts auto-processed | 3,853 | Wiz Threats |
| Compromised credentials ingested from dark web feeds | 3,853 | Flashpoint - Polling - Compromised Credential_Credential Stealer Ingest |
| DLP policy violation cases ingested from Proofpoint | 3,843 | DLP Case Ingestion |
| AI usage governance records validated via WitnessAI | 3,841 | WitnessAI Validation - Polling |
| Endpoint files automatically evaluated for quarantine | 2,290 | S1 File Quarantine Eval |
| Curated threat mention alerts ingested from Flashpoint | 1,920 | Flashpoint - Curated Alerts Ingestion |
| Code repository & DEA threat alerts ingested from Flashpoint | 1,920 | Flashpoint - DEA Alerts Ingestion |
| USB access exceptions automatically revoked | 1,877 | USB Exception Request - Remove Exception |
| Cribl security alerts auto-ingested | 1,686 | Cribl Alert Ingestion |
| Ransomware threat indicators refreshed from Google Threat Intelligence | 960 | GTI Ransomware Table |
| Flashpoint alert rule definitions refreshed for threat monitoring | 960 | Flashpoint - Alert Rules Table |
| Breach forum community mentions monitored via Flashpoint | 959 | Flashpoint - Breach Forums Alerts - Communities |
| Delta-specific ransomware mentions monitored via Flashpoint | 958 | Flashpoint - Delta Specific Ransomware Mentions |
| Delta technology mentions monitored via Flashpoint | 958 | Flashpoint - Delta Technologies |
| Dark web marketplace mentions of Delta monitored via Flashpoint | 958 | Flashpoint - Delta Marketplaces |
| Combo threat mentions (botnet, brute force, data breach) monitored via Flashpoint | 957 | Flashpoint - Combo Alerts |
| Typosquatting & phishing domain mentions monitored via Flashpoint | 957 | Flashpoint - Typosquatting & Phishing Domains |
| Ransomware threat alerts ingested from Flashpoint | 956 | Flashpoint - Ransomware Alerts Ingestion |
| GTI threat intelligence reports ingested and converted to OSINT cases | 794 | GTI - Reports Case Ingestion |
| OSINT threat reports processed into cases via automated subflow | 704 | Subflow - OSINT Case Creation |
| Ransomware intelligence articles ingested and AI-summarized via Flashpoint | 668 | Flashpoint - Ransomware Alerts Ingestion copy |
| Aviation-sector threat intel ingested via A-ISAC CyWare feed | 648 | A-ISAC CyWare Feed Ingestion |
| GTI BleepingComputer reports ingested and converted to OSINT cases | 624 | GTI - BleepingComputer Ingestion |
| GTI SecurityWeek reports ingested and converted to OSINT cases | 623 | GTI - SecurityWeek Report Ingestion |
| GTI HackerNews reports ingested and converted to OSINT cases | 622 | GTI - HackerNews Ingestion |
| ZScaler OSINT reports swept for threat indicators via GTI | 427 | GTI IOC Sweeps - ZScaler Reports |
| CISA OSINT reports swept for threat indicators via GTI | 427 | GTI IOC Sweeps - CISA Reports |
| AI-driven alert triage decisions made autonomously | 422 | Agentic SOC - Decision Layer |
| Check Point OSINT reports swept for threat indicators via GTI | 409 | GTI IOC Sweeps - Check Point Reports |
| MalwareBytes OSINT reports swept for threat indicators via GTI | 409 | GTI IOC Sweeps - MalwareBytes Reports |
| Unit42 OSINT reports swept for threat indicators via GTI | 408 | GTI IOC Sweeps - Unit42 Reports |
| Wiz OSINT reports swept for threat indicators via GTI | 408 | GTI IOC Sweeps - Wiz Reports |
| SentinelOne OSINT reports swept for threat indicators via GTI | 407 | GTI IOC Sweeps - SentinelOne Reports |
| Microsoft OSINT reports swept for threat indicators via GTI | 407 | GTI IOC Sweeps - Microsoft Reports |
| SocketDev OSINT reports swept for threat indicators via GTI | 308 | GTI IOC Sweeps - SocketDev Reports |
| Elastic OSINT reports swept for threat indicators via GTI | 308 | GTI IOC Sweeps - Elastic Reports |
| Talos OSINT reports swept for threat indicators via GTI | 308 | GTI IOC Sweeps - Talos Reports |
| Proofpoint OSINT reports swept for threat indicators via GTI | 308 | GTI IOC Sweeps - Proofpoint Reports |
| Red Canary OSINT reports swept for threat indicators via GTI | 308 | GTI IOC Sweeps - Red Canary Reports |
| CrowdStrike OSINT reports swept for threat indicators via GTI | 308 | GTI IOC Sweeps - CS Reports |
| GTI OSINT reports swept for indicators via automated subflow | 300 | Subflow - OSINT IOC Sweep |
| CVE intelligence lookups resolved via Google Threat Intelligence | 187 | GTI Vuln Intelligence |
| Threat intel articles swept for CVEs and cross-referenced against Qualys/Wiz exposure | 132 | Subflow - CVE Sweep |
| SentinelOne threat indicators swept and investigated via Deep Visibility | 106 | SentinelOne IOC Sweep |
| ACE PM dashboard views served via automated widget updates | 96 | ACE PM View Only |
| Endpoints isolated & quarantined in real time | 81 | client_quarantine |
| Expel security actions ingested for case processing | 76 | Expel Action Ingestion |
| General OSINT reports swept for threat indicators via GTI | 64 | GTI IOC Sweeps - General OSINT |
| WitnessAI host removal actions approved and executed via SentinelOne | 12 | SentinelOne WitnessAI Removal - Approved |
| USB exceptions restored via self-service after hardware rebuild | 8 | USB Exception Migration |
| SentinelOne quarantine actions routed through approval workflow | 8 | S1 Quarantine Hosts - Approval |
Use Case Summary
| # | Use Case | Category | Subcategory | Active Playbooks |
|---|---|---|---|---|
| 1 | SIEM Event Ingestion & Log Health Monitoring | SOC | SIEM & log pipeline monitoring | 17 |
| 2 | Multi-Source SOC Alert Ingestion & Case Management | SOC | Case mgmt & SOAR | 58 |
| 3 | Agentic SOC & AI-Driven Investigation | SOC | Agentic SOC | 20 |
| 4 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 59 |
| 5 | Proofpoint CASB Alert Triage & Response | SOC | Phishing detection & response | 7 |
| 6 | Phishing Detection & URL Analysis | SOC | Phishing detection & response | 5 |
| 7 | Threat Intelligence — Flashpoint Compromised Credentials | SOC | Threat intel ingest & curation, Identity threat response | 53 |
| 8 | EDR Containment & Wide-Area Isolation | SOC | EDR containment & response | 23 |
| 9 | Endpoint Inventory & Insider Threat Monitoring | Other | Endpoint hygiene & MDM ops | 8 |
| 10 | USB Exception Request Lifecycle | GRC | RBAC review & access mgmt | 16 |
| 11 | DLP & Data Policy Enforcement | GRC | DLP triage & exposure resp | 22 |
| 12 | Security Metrics & SOC Reporting | GRC | Security metrics & reporting | 30 |
| 13 | Network Traffic Analysis | SOC | Alert enrichment / IOC lookup | 19 |
| 14 | Vendor Risk Search — Archer Integration | GRC | Vendor risk & TPRM | 1 |
| 15 | Phishing Simulation Awareness Tracking | SOC | Phishing sim & awareness | 1 |
| 16 | Vulnerability & Technology CVE Search | Vulnerability Mgmt | CVE lookup & remediation | 4 |
| 17 | Endpoint Browser History Forensics | SOC | EDR containment & response | 4 |
| 18 | AI Usage Governance — WitnessAI Validation | GRC | AI / HR compliance automation | 6 |
| 19 | Shadow IT / SaaS App Discovery Reporting | Cloud Security | Cloud access & SaaS policy mgmt | 2 |
Use Cases
Use Case 1 — SIEM Event Ingestion & Log Health Monitoring
Category: SOC | Subcategory: SIEM & log pipeline monitoring
Description: Fully automates the Exabeam SIEM event pipeline — ingesting correlation rule trigger events, enriching them with associated log data, deduplicating alerts, and forwarding metrics to Zabbix. Includes scheduled log-health checks across aircraft types and platforms, fleet synchronization, and access token maintenance. Aviation-specific integrations (Documentum, WebOMS, FOMAX) are natively supported.
Business Problem: Manual SIEM data management creates detection gaps and inconsistent alert quality. Operational log health checks require constant analyst attention. Blink automates the full event lifecycle from ingestion through enrichment, ensuring continuous pipeline integrity and providing aviation-domain context enrichment before alerts reach analysts.
Key Integrations: Exabeam, Zabbix, Documentum, HTTP, WebOMS (custom)
Use Case 2 — Multi-Source SOC Alert Ingestion & Case Management
Category: SOC | Subcategory: Case mgmt & SOAR
Description: Central alert intake and full case lifecycle management hub. Automatically ingests security events from SentinelOne WatchTower MDR, Wiz, Akamai, Expel, ServiceNow, Cohesity, Proofpoint, Arista, and Cribl into the CDART case management system. Handles deduplication, priority tagging, analyst assignment via round-robin, escalation routing, daily ops summaries, and automated case closure. Communications are delivered over Mattermost, Slack, and email.
Business Problem: Analysts across multiple source systems spend significant time on manual case creation, routing, and status tracking. Disparate alert sources create visibility gaps and inconsistent triage priority. Blink unifies the alert-to-case pipeline, automates analyst load balancing, and enforces consistent SLA tracking from ingestion to closure.
Key Integrations: SentinelOne, Wiz, Akamai, Expel, ServiceNow, Cohesity, Proofpoint, Mattermost, Slack, PagerDuty, GitLab, Arista, Blink Case Management
Use Case 3 — Agentic SOC & AI-Driven Investigation
Category: SOC | Subcategory: Agentic SOC
Description: A layered AI investigation framework operating within the dedicated Agentic SOC workspace. A decision layer routes incoming alerts to specialized expert AI agents, each capable of querying enrichment data, accessing VIP user lists, performing hash searches, and retrieving asset context. The Murgatroyd AI assistant is additionally available on-demand via Mattermost webhooks, serving as an interactive SOC copilot. Named AI agents Geoffrey, Tiana, and Fairy Godmother represent analyst-persona automation for specific investigation workflows.
Business Problem: Alert volume and investigation depth requirements exceed analyst bandwidth. Rather than simply routing alerts to humans, the Agentic SOC layer performs autonomous first-pass investigation, synthesizes observable enrichment, and delivers structured findings — enabling analysts to focus on escalated cases requiring human judgment.
Key Integrations: Blink Agents, Mattermost, SentinelOne, Microsoft Entra ID, VirusTotal
Use Case 4 — Alert Enrichment & IOC Lookup
Category: SOC | Subcategory: Alert enrichment / IOC lookup
Description: A comprehensive enrichment layer spanning three workspaces that resolves security observables (file hashes, IPs, domains, usernames, device IDs) through VirusTotal, Whois, Microsoft Entra ID, PingID, and SentinelOne. Maintains a live case management user table with device-to-user linkage and MFA device correlation. Supports both automated pipeline enrichment and on-demand analyst lookups.
Business Problem: Raw alerts from EDR, SIEM, and cloud tools contain sparse technical indicators that require extensive manual lookups before an analyst can assess risk or take action. This enrichment layer populates every case with user identity, device ownership, threat intelligence verdicts, and contextual asset data — reducing analyst investigation time per alert.
Key Integrations: VirusTotal, URLScan, AbuseIPDB, SentinelOne, Microsoft Entra ID, PingID, Whois (HTTP)
Use Case 5 — Proofpoint CASB Alert Triage & Response
Category: SOC | Subcategory: Phishing detection & response
Description: The highest-volume automation by execution count. Continuously ingests Proofpoint CASB policy violations, deduplicates, triages by severity, links affected users to their identity records, assigns cases to analysts, and executes remediation actions including account-level policy enforcement. The end-to-end pipeline processes tens of thousands of CASB events per year without analyst involvement.
Business Problem: Proofpoint CASB generates thousands of cloud service policy violations monthly across SaaS platforms. Manual review is unsustainable. Blink auto-triages violations, resolves user identity context, and routes only true positives requiring human action — dramatically reducing mean time to acknowledge (MTTA) for cloud policy events.
Key Integrations: Proofpoint (CASB), SentinelOne, Microsoft Entra ID, Mattermost
| Playbook | Executions (12 mo.) |
|---|---|
| Proofpoint CASB Alerts | 32,695 |
| Process Alert - Proofpoint CASB | 60 |
| CASB Alert Ingest | 57 |
| Assign Proofpoint CASB Cases | 18 |
| Response Subflow Proofpoint - CASB - Remediation | 31 |
| Response Subflow ProofPoint - CASB - User Linking | 31 |
| Subflow 4 - Response | 204 |
Use Case 6 — Phishing Detection & URL Analysis
Category: SOC | Subcategory: Phishing detection & response
Description: Detects phishing clicker events from Proofpoint, retroactively identifies users who accessed malicious URLs, and performs real-time URL category classification to determine threat scope. The domain discovery workflow proactively scans for newly registered lookalike domains.
Business Problem: Phishing clicks require immediate identification of exposed users and rapid scope determination. Retroactive detection finds at-risk users who clicked links before a URL was flagged. Automated URL categorization eliminates manual analyst lookups for every new URL indicator.
Key Integrations: Proofpoint Threat Protection, Mattermost, Blink Case Management
| Playbook | Executions (12 mo.) |
|---|---|
| 1.2_URLCategoryCheck - Poll | 3,853 |
| proofpoint_domain_discover | 40 |
| Retroactive Phishing Clicker Alert | 68 |
| Process Alert - ProofPoint Phishing Clicker | 68 |
| Subflow - Retroactive Phishing Clicker | 29 |
Use Case 7 — Threat Intelligence — Flashpoint Compromised Credentials
Category: SOC | Subcategory: Threat intel ingest & curation, Identity threat response
Description: Continuously polls Flashpoint for newly published compromised credential and credential stealer logs mentioning the organization. Processes both bulk and individual employee records — correlating stealer logs to active employees, linking affected accounts to their identity and device records, and executing remediation including password reset and session revocation. Also ingests Flashpoint ransomware alert rules, dark web marketplace mentions, and typosquatting/phishing domain mentions on an hourly cadence, and distributes a daily OSINT threat article summary and an AI-summarized ransomware intelligence digest to the SOC via email. A dedicated on-demand tool searches live ransomware victim postings by country, group, sector, and keyword. Google Threat Intelligence (GTI), accessed via VirusTotal, supplements this pipeline with an hourly ransomware indicator table refresh and automated ingestion of GTI reports into cases. A dedicated set of hourly GTI IOC sweep playbooks additionally fetches and cleans vendor-published OSINT reports (ZScaler, CISA, Unit42, Wiz, Check Point, SentinelOne, MalwareBytes, Microsoft, SocketDev, Elastic, Talos, Proofpoint, Red Canary, CrowdStrike) for indicator extraction. Aviation ISAC (A-ISAC) threat intel is additionally ingested hourly via a Cyware TAXII 2.1 feed.
Business Problem: Credential stealer malware logs are published daily on dark web marketplaces, placing employees at immediate risk of account takeover. Manual monitoring at scale is impossible. Blink automates the full cycle from dark web detection through employee notification and credential remediation, while also keeping the SOC current on sector-specific and aviation-industry threat intelligence.
Key Integrations: Flashpoint, VirusTotal (GTI), Cyware (TAXII 2.1), SentinelOne, Microsoft Entra ID, PingID, Mattermost, Blink Case Management, Blink Agents
Use Case 8 — EDR Containment & Wide-Area Isolation
Category: SOC | Subcategory: EDR containment & response
Description: Automates SentinelOne endpoint isolation at both individual and enterprise scale. Individual quarantine workflows handle on-demand host containment with S1 agent verification. The Wide-Area Isolation (WAI) capability enables simultaneous isolation of hundreds of hosts using chunked script execution with polling loops — supporting large-scale incident response scenarios. File-level quarantine evaluation is handled continuously via a high-volume scheduled assessment workflow. An hourly scheduled job also gathers newly onboarded SentinelOne agents to keep the WAI in-scope host list current.
Business Problem: Containing compromised endpoints during active incidents requires rapid, large-scale action that manual SentinelOne operations cannot sustain. WAI automation enables the security team to isolate hundreds of hosts within minutes using controlled job chunking, while individual quarantine workflows reduce analyst steps per containment to near zero.
Key Integrations: SentinelOne, Qualys, Mandiant, Mattermost, Blink Case Management
Use Case 9 — Endpoint Inventory & Insider Threat Monitoring
Category: Other | Subcategory: Endpoint hygiene & MDM ops
Description: Maintains a continuously refreshed endpoint inventory by polling SentinelOne's Insider Threat Management (ITM) module on a 10-minute schedule. Tracks all managed devices, correlates user identity data via Entra ID and PingID, and monitors for newly provisioned user accounts. Supports both automated table maintenance and analyst-facing device queries.
Business Problem: Insider threat detection requires real-time visibility into device ownership, user activity patterns, and new account creation. Static snapshots from weekly scans create detection gaps. Blink's continuous ITM polling ensures the device inventory is always current and available for case enrichment and investigation workflows.
Key Integrations: SentinelOne, Microsoft Entra ID, PingID, Microsoft Outlook, MSSQL
| Playbook | Executions (12 mo.) |
|---|---|
| Devices Table | 10,286 |
| 1.2_S1_ITM_Poll | 5,779 |
| Query New Users Subflow | 110 |
| Ability - Move Host to another Host Group | 1 |
| Devices - S1 - Kape Triage Deployment | 1 |
| Query New Users | 6 |
| Drop Table | 6 |
| Akamai Certificate Expiration Notice (ACEN) | 5 |
Use Case 10 — USB Exception Request Lifecycle
Category: GRC | Subcategory: RBAC review & access mgmt
Description: Fully automates the end-to-end USB device exception management process — from employee or contractor intake through manager approval workflows, SentinelOne policy verification, device provisioning, periodic recertification campaigns (AQCHR), and automated removal upon expiration. Automated reminders escalate through manager and director levels when approvals are pending.
Business Problem: USB exception management requires multi-party coordination across employees, managers, directors, and the security team, creating audit trail gaps and inconsistent enforcement. Manual expiration tracking leads to exceptions persisting beyond their approved period. Blink automates the full lifecycle with structured approval chains, audit logging, and time-bound enforcement.
Key Integrations: SentinelOne, Mattermost, Slack, Blink Case Management
Use Case 11 — DLP & Data Policy Enforcement
Category: GRC | Subcategory: DLP triage & exposure resp
Description: Automates DLP policy lifecycle management (activation and deactivation cycles), detects and responds to internal domain-wide password sharing events, processes employee requests for blocked website access, and manages credential reset and session revocation workflows via Entra ID and SailPoint integration. The EDL validation workflow enforces firewall External Dynamic List integrity via GitLab-triggered checks.
Business Problem: DLP policy state changes require rapid, error-free execution across endpoints. Internal password sharing represents a systemic credential hygiene risk that is difficult to detect and respond to at scale. Blocked website requests and identity reset workflows generate high analyst workload when handled manually.
Key Integrations: Proofpoint (DLP/ITM), Microsoft Entra ID, SailPoint, Mattermost, GitLab, Blink Case Management
Use Case 12 — Security Metrics & SOC Reporting
Category: GRC | Subcategory: Security metrics & reporting
Description: Delivers automated security reporting across multiple frequencies and audiences. Daily ops assignment reports are generated and distributed to analysts each morning. Weekly CISO summaries, weekly release notes, and a weekly Mattermost check-in are pushed automatically via an AI announcer agent, and on-call schedules are pushed to Mattermost automatically. Threat intelligence metrics are tracked via ThreatQuotient audit log polling, providing CTI coverage visibility. Timesheet reminders reduce administrative overhead for SOC staff. A webhook-triggered template dispatcher standardizes email formatting for dashboard-driven report requests. A SharePoint-synced CMIR wiki knowledge base is kept current — including event-driven page save/delete/create sync and a nightly scheduled dashboard refresh — AI-summarized on a monthly cadence, and made searchable on demand, while a weekly threat-hunt case summary is emailed to the team.
Business Problem: Security leaders require consistent operational visibility without placing additional reporting burden on the SOC team. Manual report compilation pulls analysts away from investigations. Blink automates all recurring security reporting, ensuring leadership has accurate, timely data without analyst intervention.
Key Integrations: ThreatQuotient, PagerDuty, Mattermost, Slack, ServiceNow, GitLab, Blink Agents
Use Case 13 — Network Traffic Analysis
Category: SOC | Subcategory: Alert enrichment / IOC lookup
Description: Analyzes DNS, URL, and destination-IP network traffic events sourced from both SentinelOne and Exabeam to identify anomalous or malicious patterns. Parallel subflow variants (copy/original) support high-volume, concurrent processing. A SentinelOne Deep Visibility-based destination-IP lookup traces traffic to specific sites and users on demand. Results feed directly into case management for analyst review.
Business Problem: Network traffic events from EDR and SIEM are too voluminous for manual analyst review. Automated DNS and URL traffic correlation surfaces suspicious query patterns and blocked access events, converting raw network telemetry into actionable security findings.
Key Integrations: SentinelOne, Exabeam, Mattermost, Blink Case Management
Use Case 14 — Vendor Risk Search — Archer Integration
Category: GRC | Subcategory: Vendor risk & TPRM
Description: Provides on-demand search of the Archer GRC vendor risk register by search term, returning matching vendor records for use by analysts or other workflows evaluating vendor risk posture.
Business Problem: Assessing vendor risk requires quickly checking whether a vendor already has an existing risk record before onboarding or renewal decisions. Manually searching Archer reports for vendor matches is slow and inconsistent. Blink automates the vendor lookup against the Archer report directly, returning results on demand.
Key Integrations: RSA Archer
| Playbook | Executions (12 mo.) |
|---|---|
| Archer Dev Vendor Search Subflow | 0 |
Use Case 15 — Phishing Simulation Awareness Tracking
Category: SOC | Subcategory: Phishing sim & awareness
Description: Monitors simulated phishing campaign notifications sent to employees via Microsoft Outlook, uses AI-driven parsing to extract the relevant details from each notification, and logs the event to a dedicated tracking table for awareness program reporting.
Business Problem: Measuring phishing awareness program effectiveness requires capturing every simulated phishing notification sent to employees. Manually tracking these notifications across a large workforce is impractical. Blink automatically detects simulated phishing notification emails, extracts relevant details via AI, and records them for awareness metrics reporting.
Key Integrations: Microsoft Outlook, Blink Agents, Blink Case Management
| Playbook | Executions (12 mo.) |
|---|---|
| Phishing Sim Notifications | 3 |
Use Case 16 — Vulnerability & Technology CVE Search
Category: Vulnerability Mgmt | Subcategory: CVE lookup & remediation
Description: On-demand CVE and technology exposure lookup tools spanning Qualys and Wiz. Given a CVE identifier, resolves affected QIDs in Qualys and reports vulnerable host counts with a formatted markdown summary; a parallel Wiz-based workflow queries cloud assets for exposure to a given CVE via GraphQL and summarizes vulnerability findings. A companion Wiz workflow supports technology-based asset searches. A Google Threat Intelligence (GTI) lookup supplements these with on-demand CVE intelligence retrieval.
Business Problem: When a new CVE is disclosed, analysts need a fast answer to "are we exposed, and where?" across both on-prem vulnerability scanning (Qualys) and cloud workloads (Wiz). Manually cross-referencing CVE-to-QID mappings and querying multiple platforms is slow during time-sensitive vulnerability response. Blink automates the lookup and returns a ready-to-share exposure summary on demand.
Key Integrations: Qualys, Wiz, VirusTotal (GTI)
| Playbook | Executions (12 mo.) |
|---|---|
| Wiz CVE Search | 58 |
| Qualys CVE Search | 33 |
| Wiz Technologies Search | 0 |
| GTI Vuln Intelligence | 187 |
Use Case 17 — Endpoint Browser History Forensics
Category: SOC | Subcategory: EDR containment & response
Description: On-demand forensic collection workflow that remotely triggers a browser history pull from a target SentinelOne-managed endpoint for a specified date range, downloads the resulting artifact, parses it with AI-assisted extraction, and produces domain and subdomain lists for investigation. A companion ability saves the retrieved file directly to the case record for evidentiary continuity. A dedicated web form additionally lets employees request VSS (Volume Shadow Copy) snapshots of specific hosts, capturing contact and business-justification details and automatically opening a case for the request.
Business Problem: Investigating a compromised or suspicious endpoint often requires browser history evidence and point-in-time disk snapshots, which are normally manual, per-host SentinelOne console operations. Blink automates the remote collection, retrieval, parsing, and case-linking of browser history artifacts, and structures VSS snapshot requests into an auditable, case-tracked intake process — giving analysts ready-to-use forensic evidence without leaving the case workflow.
Key Integrations: SentinelOne, Blink Case Management, Blink Agents, Blink Web Forms
| Playbook | Executions (12 mo.) |
|---|---|
| Ability - Initiate Browser History Pull | 0 |
| Ability - Grab Browser History Result | 0 |
| Ability - Save File to Case | 0 |
| VSS Snapshot Requests | 1 |
Use Case 18 — AI Usage Governance — WitnessAI Validation
Category: GRC | Subcategory: AI / HR compliance automation
Description: Reconciles SentinelOne-managed hosts against WitnessAI's AI usage governance platform. A scheduled poller checks a validation queue every 15 minutes and triggers on-demand hostname lookups that confirm SentinelOne enrollment status for hosts flagged by WitnessAI.
Business Problem: As generative AI usage grows across the workforce, security teams need to confirm that hosts flagged by AI governance tooling are also covered by endpoint security. Manually cross-referencing WitnessAI-flagged hosts against the SentinelOne device inventory is slow and error-prone. Blink automates the validation loop, continuously reconciling AI usage governance data with endpoint coverage records.
Key Integrations: WitnessAI, SentinelOne
| Playbook | Executions (12 mo.) |
|---|---|
| WitnessAI Validation - Polling | 3,841 |
| SentinelOne WitnessAI Validation - Intake | 0 |
| WitnessAI Deployment/Removal | 4 |
| SentinelOne WitnessAI Deployment | 3 |
| SentinelOne WitnessAI Removal | 1 |
| SentinelOne WitnessAI Removal - Approved | 12 |
Use Case 19 — Shadow IT / SaaS App Discovery Reporting
Category: Cloud Security | Subcategory: Cloud access & SaaS policy mgmt
Description: Generates a weekly report of shadow SaaS applications discovered across the environment, formatting the findings as an HTML table and distributing it via email with a CSV attachment for record-keeping. Koi Security SaaS/browser-extension governance findings are additionally ingested via webhook and posted in real time to Mattermost for immediate visibility.
Business Problem: Unauthorized or unsanctioned SaaS application usage (shadow IT) creates unmanaged risk that is difficult to track without a recurring, consolidated view. Blink automates the weekly compilation and distribution of shadow app findings, and now also surfaces real-time SaaS governance findings from Koi Security, ensuring the security team has consistent visibility without manual report building.
Key Integrations: Email (CSV/HTML reporting), Koi Security, Mattermost
| Playbook | Executions (12 mo.) |
|---|---|
| Shadow App Email | 3 |
| Koi Security Governance Notifications | 0 |
Key Observations
Strengths
Scale and Coverage. 192,911 total workflow executions across 256 active playbooks over 12 months demonstrates deep, production-grade adoption of automation across the full SOC function. The platform is not being used for proof-of-concept workflows — it is integral to daily operations.
Aviation-Domain Specificity. The SIEM workspace integrates natively with aviation-specific systems including FOMAX (flight operations), Documentum (document management), WebOMS, and per-aircraft-type log health checks. This reflects a mature integration model tailored to Delta's operational environment, not a generic SOC deployment.
Multi-Layered Alert Pipeline. The Exabeam correlation pipeline (ingestion → processing → deduplication → enrichment) executes ~46,000 times per year in the dedicated SIEM workspace, operating as a fully automated high-volume event processor. Combined with SentinelOne, Wiz, Akamai, Expel, and Proofpoint ingestion in the main workspace, the alert pipeline spans all major threat surfaces.
Agentic SOC Investment. The dedicated Agentic SOC workspace with 422 decision layer executions and specialized expert agents (Geoffrey, Tiana, Murgatroyd) represents a forward-looking investment in AI-driven autonomous investigation, reflecting an ambition to reduce analyst alert handling workload rather than just automate mechanical steps.
Credential Threat Response. The Flashpoint credential stealer pipeline with ~5,000+ combined executions across ingestion, processing, and remediation playbooks demonstrates a proactive approach to dark web threat intelligence — automatically correlating published stealer logs to active employees and executing remediation at scale.
USB Lifecycle Governance. 1,877 USB exception removals in 12 months, combined with a full intake-to-recertification lifecycle, indicates consistent enforcement of endpoint access controls that would otherwise require manual audit processes.
Gaps & Opportunities
50% Playbook Utilization. 237 of 493 playbooks have zero executions in the last 12 months. The idle SOC enrichment utilities workspace (a6e9c12e) contains 24 zero-execution playbooks integrating CrowdStrike, URLScan, IPDB, and Okta — each pre-built but unused. These represent immediate activation opportunities if the corresponding integrations are in scope.
CrowdStrike and Okta Enrichment Unconfigured. Pre-built enrichment playbooks for CrowdStrike (agent ID lookup) and Okta (user lookup) are present but have never executed. If CrowdStrike or Okta are part of the environment, activating these enrichment paths would add identity and endpoint context to every investigation automatically.
SafeBreach Integration Present but Idle. SafeBreach integration code is referenced in the workflow library but has not executed. Connecting breach-and-attack simulation results to the SOC case pipeline could provide continuous validation of detection coverage.
Duplicate Traffic Analysis Subflows. The network traffic use case contains multiple copy variants (e.g., S1 Traffic - DNS subflow and S1 Traffic - DNS subflow copy) each running ~40 executions. Consolidating to a single authoritative subflow would reduce maintenance overhead.
Testing Workflow in Production. The playbook Vincent Testing - Rob copy in workspace e93903f0 ran 449 times in 12 months — suggesting a development or testing workflow is executing in a production-connected environment. This warrants review to confirm it is not impacting production data or case counts.
GRC Coverage Limited to USB and DLP. Relative to the breadth of the SOC automation portfolio, GRC automation is limited. Opportunities exist to extend into vulnerability management reporting, compliance questionnaire automation, and vendor risk workflows using existing integrations (ServiceNow, Wiz, Exabeam).
Integration Ecosystem
Delta Air Lines has deployed Blink with one of the broadest integration footprints in the platform:
| Category | Integrations |
|---|---|
| EDR / Endpoint | SentinelOne (primary), Qualys, Mandiant |
| SIEM & Log Management | Exabeam, Cribl |
| Monitoring | Zabbix |
| Cloud Security | Wiz, Koi Security |
| Email Security / CASB | Proofpoint (CASB, Threat Protection, ITM) |
| Threat Intelligence | Flashpoint, VirusTotal, AbuseIPDB, URLScan, Cyware (A-ISAC TAXII feed) |
| Identity & Access | Microsoft Entra ID, PingID, SailPoint |
| ITSM & Case Management | ServiceNow, Expel, PagerDuty |
| Collaboration | Mattermost, Slack, Microsoft Teams, Microsoft Outlook |
| Aviation-Specific | FOMAX, WebOMS, Documentum |
| DevOps / GitOps | GitLab, GitHub |
| Network / Infrastructure | Akamai, Arista |
| GRC / Vendor Risk | RSA Archer |
| Unused / Available | CrowdStrike, Okta, SafeBreach |
E New Integrations (detail) 4 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| delta_airlines | apikey-auth | anvilogic_poc | 2026-09-09 |
| delta_airlines | vega | vega_poc | 2026-09-08 |
| delta_airlines | virus-total | vt_darpan | 2026-08-28 |
| delta_airlines | apikey-auth | koipov | 2026-08-20 |