01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1: SIEM & Alert Ingestion Pipeline | 19,355 executions | 100.0% | 10 3 active |
| Use Case 2: Agentic SOC — AI-Driven Alert Investigation | 0 executions | 0.0% | 17 16 active |
| Use Case 3: Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 16 15 active |
| Use Case 4: Case Management & Incident Lifecycle | 4 executions | 0.0% | 6 5 active |
| Use Case 7: Platform Operations & Monitoring | 0 executions | 0.0% | 5 5 active |
| Total | 19,359 executions | 100% | 54 44 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature, high-volume ingestion pipeline. The Cloudflare WAF polling ingestion is the highest-volume operation in the environment at 34,475 executions across 3 workspaces, running every 5 minutes with consistent throughput across all three instances. The Microsoft Defender for Endpoint ingestion adds another 9,293 executions across 4 workspaces with near-identical counts per instance, indicating a well-load-balanced, stable deployment. The ingestion layer collectively processed over 47,000 events in the last 12 months without analyst involvement.
Operational Agentic SOC deployment. The AI investigation layer is active and in production use across 5 workspaces. The Decision Layer has completed 562 triage decisions; the Expert Agents, Main AI Investigation subflow, and all supporting agent abilities (VIP user context, asset inventory, historical cases, observable enrichments) are executing consistently. The environment has custom agent query tools for Azure Log Analytics and Defender XDR Advanced Hunting, indicating purpose-built threat investigation capabilities integrated directly into the AI layer.
Broad enrichment coverage across 11 sources. The enrichment framework is active across 5 workspaces with VirusTotal, Whois, Entra ID, Defender XDR, Intune, CrowdStrike, and NinjaOne all contributing structured enrichment data to cases. Observable enrichment is tightly integrated into the AI investigation pipeline — the agent queries enrichment data before making close/escalate decisions.
Bidirectional Sentinel integration. Both ingestion (Sentinel Ingestion - V3) and closure sync (Close Sentinel Incident, 40 executions) are active, indicating a live SIEM integration where case resolution state is propagated back to the source SIEM automatically.
Extensive response playbook library ready for activation. Use Cases 5 and 6 represent 48+ configured response playbooks across EDR (MDE + CrowdStrike) and identity (Entra ID + Exchange Online) that are fully deployed and require no additional setup to activate. The "no gated approval" labeling on the highest-impact actions indicates deliberate pre-authorization decisions have already been made.
###
Gaps and Expansion Opportunities
AI case closure not yet active. The Agentic SOC - Close Case playbook is configured across all workspaces but has 0 executions. The AI layer is completing triage decisions (562 executions) but not yet auto-closing cases on its own — likely being reviewed manually before closing. Activating automated closure for AI-confirmed low-risk cases would complete the autonomous SOC loop.
Response playbooks configured but unused. Neither Use Case 5 (EDR containment) nor Use Case 6 (identity response) have recorded executions in the last 12 months. Given the active ingestion and AI triage pipeline, connecting AI escalate decisions to response actions is the logical next step.
Several alert sources configured but not yet producing volume. CrowdStrike webhook ingestion has 3 executions; FortiGate, Splunk, and webhook-based Cloudflare ingestion are configured at 0 executions. These represent expansion-ready integrations that can be activated without additional playbook development.
Enrichment configured for sources not yet integrated. Okta, Google Workspace, GitHub, Slack, Wiz, Azure Resource logs, FortiAnalyzer, IPDB, and URLScan enrichment playbooks are all configured but idle. As these integrations are connected, enrichment coverage expands automatically.
Two parallel Whois enrichment playbooks active. "Enrich - IP or Domain - Whois" and "Enrich IP or Domain Using Whois" are running concurrently with identical execution counts per workspace — both at 26/18/9 across the same three workspaces. This appears to be a versioning overlap; consolidating to the newer playbook would reduce redundancy.
Integration Ecosystem
Active integrations (11):
| Integration | Usage |
|---|---|
| Cloudflare WAF | Alert ingestion (polling) |
| Microsoft Defender for Endpoint | Alert ingestion, device enrichment, XDR threat hunting |
| Microsoft Sentinel | Incident ingestion, closure sync |
| Microsoft Entra ID / Graph API | Identity risk ingestion, user enrichment |
| Microsoft Exchange Online / Office 365 Management | Email security alert ingestion |
| Microsoft Intune | Device/hostname enrichment |
| Microsoft Azure Log Analytics | AI agent threat hunting queries |
| VirusTotal | Hash, IP, URL, domain enrichment |
| CrowdStrike | Alert ingestion (webhook), host enrichment, hash enrichment |
| NinjaOne | Device enrichment |
| Blink Case Management | Case CRUD, observable management, historical case lookups |
Configured — not yet active (9):
| Integration | Use Case |
|---|---|
| Okta | User enrichment |
| Google Workspace | User enrichment |
| Slack | User enrichment |
| GitHub | User enrichment |
| Wiz | Entity enrichment |
| Azure Resource enrichment | Resource context |
| FortiGate / FortiAnalyzer | Alert ingestion, enrichment |
| Splunk | Alert ingestion |
| IPDB, URLScan | IP/URL enrichment |
A Case Management 307 cases (12m) | MTTR 3d 11h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| B-Paid | 161 | 161 | 85 | 1d 13h |
| Fentron SOC | 124 | 124 | 37 | 7d 12h |
| CWM | 12 | 12 | 0 | N/A |
| Asset Watch | 6 | 6 | 0 | N/A |
| Agentic SOC V2 | 2 | 2 | 0 | N/A |
| Steller Construction | 2 | 2 | 1 | 19d 18h |
B AI Agents 35 active | 2,792 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink - Decision Maker | Fentron SOC | 838 | 0 | 146,036,821 |
| 2 | Micro Agent - Historical Case Check | Fentron SOC | 481 | 0 | 38,023,093 |
| 3 | SOC Agent - Core Investigator Agent | Fentron SOC | 371 | 0 | 77,478,534 |
| 4 | Agent Blink - Decision Maker | B-Paid | 367 | 0 | 33,116,727 |
| 5 | Fentron - Enrichment Card Agent | Fentron SOC | 287 | 0 | 246,520,877 |
| Workspace | Tasks (12m) |
|---|---|
| Fentron SOC | 2,089 |
| B-Paid | 570 |
| Steller Construction | 52 |
| CWM | 50 |
| Asset Watch | 30 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Agentic SOC | 0 | 0 |
| 2 | Agentic SOC | 0 | 0 |
| 3 | Guest User Audit Dashboard | 0 | 0 |
| 4 | Agentic SOC | 0 | 0 |
| 5 | NinjaOne Dashboard | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 5 use cases | 19,360 executions (12m)
Business KPIs
| Metric | Value |
|---|---|
| Total automation executions | 52,142 |
| Active use cases | 7 |
| Alert sources integrated (active) | 11 |
| Alert sources configured (not yet active) | 9 |
| Workspaces with active automation | 10 |
Use Case Summary
| Use Case | Category | Subcategory | Unique Playbook Instances | Active Executions |
|---|---|---|---|---|
| 1. SIEM & Alert Ingestion Pipeline | SOC | SIEM & log pipeline monitoring | 12 active + 11 configured | 47,301 |
| 2. Agentic SOC — AI-Driven Alert Investigation | SOC | Agentic SOC | 16 active + 4 configured | 3,249 |
| 3. Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 16 active + 18 configured | 1,166 |
| 4. Case Management & Incident Lifecycle | SOC | Case mgmt & SOAR | 8 active + 5 configured | 497 |
| 5. EDR Containment & Response | SOC | EDR containment & response | 0 active, 22 configured | 0 |
| 6. Identity Threat Response | SOC | Identity threat response | 0 active, 26 configured | 0 |
| 7. Platform Operations & Monitoring | Other | IT helpdesk & ticket routing | 1 active + 5 configured | 2 |
Use Cases
Use Case 1: SIEM & Alert Ingestion Pipeline
Category: SOC | Subcategory: SIEM & log pipeline monitoring
Description: Scheduled and webhook-based polling of multiple security platforms — Cloudflare WAF, Microsoft Defender for Endpoint, Microsoft Sentinel, Entra ID Protection, Exchange Online Protection, and CrowdStrike — normalizes incoming security events and automatically creates cases in the case management system. This pipeline is the entry point for all downstream automation: enrichment, AI investigation, and response actions operate on cases created here.
Active integrations: Cloudflare WAF, Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Entra ID / Graph API, Microsoft Exchange Online / Office 365 Management API, CrowdStrike
Active Playbooks
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| Cloudflare WAF Ingestion - Polling | 9dba09ef | 11,522 | SOC | SIEM & log pipeline monitoring |
| Cloudflare WAF Ingestion - Polling | 30299069 | 11,477 | SOC | SIEM & log pipeline monitoring |
| Cloudflare WAF Ingestion - Polling | 97ee93a9 | 11,476 | SOC | SIEM & log pipeline monitoring |
| Microsoft Defender for Endpoint Ingestion | 30299069 | 2,325 | SOC | SIEM & log pipeline monitoring |
| Microsoft Defender for Endpoint Ingestion | 6ce97eba | 2,323 | SOC | SIEM & log pipeline monitoring |
| Microsoft Defender for Endpoint Ingestion | ecf7f34f | 2,323 | SOC | SIEM & log pipeline monitoring |
| Microsoft Defender for Endpoint Ingestion | a81e6f7f | 2,322 | SOC | SIEM & log pipeline monitoring |
| Entra ID Protection Ingestion (E5) | ecf7f34f | 921 | SOC | SIEM & log pipeline monitoring |
| Microsoft Sentinel Ingestion - V3 | 97ee93a9 | 996 | SOC | SIEM & log pipeline monitoring |
| EOP Alert Ingestion (E3) | 30299069 | 890 | SOC | SIEM & log pipeline monitoring |
| Entra ID Protection Ingestion (E5) | a81e6f7f | 723 | SOC | SIEM & log pipeline monitoring |
| Ingest - Crowdstrike | 6ce97eba | 3 | SOC | SIEM & log pipeline monitoring |
Playbook descriptions:
- Cloudflare WAF Ingestion - Polling: Scheduled polling (every 5 minutes) of Cloudflare WAF zones; normalizes WAF security events and creates cases in case management. Deployed across 3 workspaces totaling 34,475 executions — the highest-volume ingestion pipeline in the environment.
- Microsoft Defender for Endpoint Ingestion: Event-driven polling of Microsoft Defender for Endpoint for new endpoint alerts; auto-ingests and normalizes into case management. Deployed across 4 workspaces totaling 9,293 executions.
- Microsoft Sentinel Ingestion - V3: Polling-based ingestion of Microsoft Sentinel incidents into case management (996 executions, 1 workspace).
- Entra ID Protection Ingestion (E5): Hourly polling of Microsoft Graph API for Entra ID risk detections; ingests identity threat signals and creates correlated cases (1,644 executions across 2 workspaces).
- EOP Alert Ingestion (E3): Hourly polling of Office 365 Management Activity API for Exchange Online Protection alerts; normalizes email security events (890 executions, 1 workspace).
- Ingest - Crowdstrike: Webhook-based ingestion of CrowdStrike alert events; retrieves alert details and normalizes into case management (3 executions, 1 workspace).
Configured — Not Yet Active
| Playbook | Notes |
|---|---|
| Cloudflare WAF Ingestion - Webhook | Webhook-based alternative to the polling ingestion; configured across multiple workspace instances |
| FortiGate Ingestion - Webhook | Configured, 0 executions |
| Splunk Ingestion | Configured, 0 executions |
Use Case 2: Agentic SOC — AI-Driven Alert Investigation
Category: SOC | Subcategory: Agentic SOC
Description: A multi-layer AI agent system that autonomously investigates security alerts by orchestrating specialist expert agents. The Decision Layer receives an alert case, dispatches domain-specific expert agents, and queries threat intelligence sources (VirusTotal), log repositories (Azure Log Analytics, Defender XDR Advanced Hunting via KQL), and organizational context (VIP user lists, asset inventory, historical cases, observable enrichments) before rendering a close or escalate decision — without analyst involvement on routine cases. The architecture separates orchestration (Decision Layer), routing (Expert Agents), core AI logic (Main AI Investigation subflow), and tool-specific agent abilities into discrete, reusable playbook layers.
Active integrations: Azure Log Analytics, Microsoft Defender XDR Advanced Hunting (KQL), VirusTotal, Blink Case Management (observables, historical cases, VIP user lists, asset inventory)
Active Playbooks
Configured — Not Yet Active
| Playbook | Notes |
|---|---|
| Agent Blink - Query Log Analytics | Configured across additional workspaces with 0 executions |
| Agent Blink - Query Defender XDR Hunting | Configured across additional workspaces with 0 executions |
| Subflow - Agentic SOC - Main - AI Investigation | Configured in unused workspaces |
| Agentic SOC - Close Case | The AI-driven case closure action; configured across all workspaces, not yet executed |
Use Case 3: Alert Enrichment & IOC Lookup
Category: SOC | Subcategory: Alert enrichment / IOC lookup
Description: A multi-source enrichment framework that automatically looks up IPs, domains, file hashes, usernames, hostnames, and device identifiers across VirusTotal, Whois, CrowdStrike, Microsoft Defender XDR, Intune, Entra ID, and NinjaOne. A central router dispatches enrichment requests by observable type; results are written back as structured enrichment data to case observables, making all downstream automation — including the AI investigation layer — context-aware from the moment a case opens.
Active integrations: VirusTotal, Whois, Microsoft Entra ID, Microsoft Defender XDR, Microsoft Intune, CrowdStrike, NinjaOne, Blink Case Management
Active Playbooks
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| Subflow - Enrich Observables - Main Router | 05f4ac12 | 159 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | 97ee93a9 | 142 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | 6ce97eba | 82 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | 30299069 | 30 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | a81e6f7f | 13 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 97ee93a9 | 121 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 05f4ac12 | 102 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 6ce97eba | 48 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 30299069 | 14 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | a81e6f7f | 5 | SOC | Alert enrichment / IOC lookup |
| CM Ability - VirusTotal Enrichment | 97ee93a9 | 55 | SOC | Alert enrichment / IOC lookup |
| CM Ability - VirusTotal Enrichment | 05f4ac12 | 42 | SOC | Alert enrichment / IOC lookup |
| CM Ability - VirusTotal Enrichment | 6ce97eba | 23 | SOC | Alert enrichment / IOC lookup |
| CM Ability - VirusTotal Enrichment | 30299069 | 8 | SOC | Alert enrichment / IOC lookup |
| CM Ability - VirusTotal Enrichment | a81e6f7f | 1 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 97ee93a9 | 26 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 05f4ac12 | 18 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 6ce97eba | 9 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 97ee93a9 | 26 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 05f4ac12 | 18 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 6ce97eba | 9 | SOC | Alert enrichment / IOC lookup |
| CM Ability - Entra ID User Enrichment | 05f4ac12 | 23 | SOC | Alert enrichment / IOC lookup |
| CM Ability - Entra ID User Enrichment | 97ee93a9 | 18 | SOC | Alert enrichment / IOC lookup |
| CM Ability - Entra ID User Enrichment | 30299069 | 3 | SOC | Alert enrichment / IOC lookup |
| CM Ability - Entra ID User Enrichment | 6ce97eba | 2 | SOC | Alert enrichment / IOC lookup |
| CM Ability - Entra ID User Enrichment | a81e6f7f | 1 | SOC | Alert enrichment / IOC lookup |
| Enrich - Defender - XDR User Threat Hunting - E5 | 97ee93a9 | 16 | SOC | Alert enrichment / IOC lookup |
| Enrich - Defender - XDR User Threat Hunting - E5 | 05f4ac12 | 14 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | 6ce97eba | 14 | SOC | Alert enrichment / IOC lookup |
| CM Ability - NinjaOne Enrichment | 6ce97eba | 6 | SOC | Alert enrichment / IOC lookup |
| CM Ability - NinjaOne Enrichment | 30299069 | 3 | SOC | Alert enrichment / IOC lookup |
| CM Ability - NinjaOne Enrichment | 05f4ac12 | 2 | SOC | Alert enrichment / IOC lookup |
| CM Ability - NinjaOne Enrichment | 97ee93a9 | 2 | SOC | Alert enrichment / IOC lookup |
| CM Ability - NinjaOne Enrichment | a81e6f7f | 2 | SOC | Alert enrichment / IOC lookup |
| NinjaOne - Get Device By System Name Or DNS Name Or ID | 6ce97eba | 4 | SOC | Alert enrichment / IOC lookup |
| NinjaOne - Get Device By System Name Or DNS Name Or ID | 30299069 | 3 | SOC | Alert enrichment / IOC lookup |
| NinjaOne - Get Device By System Name Or DNS Name Or ID | 05f4ac12 | 2 | SOC | Alert enrichment / IOC lookup |
| NinjaOne - Get Device By System Name Or DNS Name Or ID | 97ee93a9 | 2 | SOC | Alert enrichment / IOC lookup |
| NinjaOne - Get Device By System Name Or DNS Name Or ID | a81e6f7f | 1 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Intune | 6ce97eba | 3 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Intune | 30299069 | 3 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Intune | 05f4ac12 | 2 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Intune | 97ee93a9 | 2 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Intune | a81e6f7f | 1 | SOC | Alert enrichment / IOC lookup |
| CM Ability - Intune - Search for User's Device | 05f4ac12 | 3 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Crowdstrike | 6ce97eba | 3 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Defender XDR Threat Context | 97ee93a9 | 2 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Defender XDR Threat Context | 05f4ac12 | 1 | SOC | Alert enrichment / IOC lookup |
| Enrich - Device Agent ID - CrowdStrike | 6ce97eba | 2 | SOC | Alert enrichment / IOC lookup |
| Subflow - Generate Enrichment Cards | a81e6f7f | 2 | SOC | Alert enrichment / IOC lookup |
Configured — Not Yet Active
Enrich - IP - IPDB, Enrich - IP - VT, Enrich - URL - VT, Enrich - URL - URLScan, Enrich - Hash - VT, Enrich - Username - Okta, Enrich - Username - Google Workspace, Enrich - Username - Microsoft Entra ID, Enrich - Email Address - Slack, Enrich - Agent ID - Crowdstrike, Enrich - CrowdStrike Threatgraph Enrichment, Enrich - Username - Github, Enrich - Wiz Entity Enrichment, Enrich - Azure Resource Activity Log, Enrich - Azure Resource Enrichment, Enrich - FortiAnalyzer Enrichment, Enrich - Observable - Cloudflare Zero Trust Account, Enrich - Observable - Cloudflare Zone
Use Case 4: Case Management & Incident Lifecycle
Category: SOC | Subcategory: Case mgmt & SOAR
Description: Manages the full lifecycle of security cases — bidirectional sync between the case management platform and Microsoft Sentinel (ingesting incidents and closing them back in Sentinel once resolved), fetching and maintaining case observables, and refreshing investigation state to keep the analyst view current. These utilities underpin every other use case: enrichment, AI investigation, and response actions all depend on accurate, up-to-date case data.
Active integrations: Microsoft Sentinel, Blink Case Management
Active Playbooks
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| Close Sentinel Incident | 97ee93a9 | 27 | SOC | Case mgmt & SOAR |
| Close Sentinel Incident | 05f4ac12 | 13 | SOC | Case mgmt & SOAR |
| Get Observables by Case ID | 97ee93a9 | 290 | SOC | Case mgmt & SOAR |
| Get Observables by Case ID | 30299069 | 12 | SOC | Case mgmt & SOAR |
| Get Observables by Case ID | 05f4ac12 | 11 | SOC | Case mgmt & SOAR |
| Utility - Refresh investigation | 97ee93a9 | 112 | SOC | Case mgmt & SOAR |
| Utility - Refresh investigation | 05f4ac12 | 22 | SOC | Case mgmt & SOAR |
| Utility - Refresh investigation | 6ce97eba | 4 | SOC | Case mgmt & SOAR |
| Utility - Refresh investigation | 30299069 | 4 | SOC | Case mgmt & SOAR |
| Utility - Refresh investigation | a81e6f7f | 1 | SOC | Case mgmt & SOAR |
| Utility - Refresh investigation list | 97ee93a9 | 1 | SOC | Case mgmt & SOAR |
Configured — Not Yet Active
| Playbook | Notes |
|---|---|
| Agentic SOC - Close Case | AI-driven case closure; configured across all workspaces, not yet executed |
| Utility - Close Stale Cases | Automated stale case hygiene; configured, not yet executed |
| Comment On Case | Automated case commenting; configured, not yet executed |
Use Case 5: EDR Containment & Response
Category: SOC | Subcategory: EDR containment & response
Description: A comprehensive library of one-click and agentic response actions for Microsoft Defender for Endpoint and CrowdStrike Falcon — covering device isolation, file quarantine and block, indicator-based blocking (IP, URL, domain, hash), antivirus scanning, investigation package collection, live response script execution, and device tagging. Configured and deployed across workspaces; ready for execution without additional setup. These actions can be triggered manually by analysts or invoked by the AI investigation layer for approved automated response.
Integrations configured: Microsoft Defender for Endpoint, CrowdStrike Falcon (RTR, quarantine management)
Configured — Not Yet Active
Microsoft Defender for Endpoint:
- Isolate Device - Full (no gated approval)
- Isolate Device - Selective (no gated approval)
- Release Device from Isolation
- Run Antivirus Scan
- Collect Investigation Package
- Restrict App Execution (no gated approval)
- Remove App-Execution Restriction
- Stop & Quarantine File (no gated approval)
- Block File Hash (Custom Indicator)
- Block IP / URL / Domain (Custom Indicator)
- Initiate Automated Investigation
- Run Live Response Script (no gated approval)
- Set Device Tag
- Offboard Machine (no gated approval)
- Disable Device Object (no gated approval)
CrowdStrike:
- CrowdStrike RTR to a Single Host
- CrowdStrike RTR to a Batch of Hosts
- Manage Endpoint Quarantine Status in Crowdstrike
- quarantine device on CS
- Agent Blink - Crowdstrike - Isolate/Unisolate
- Agent Blink - CrowdStrike RTR to a Single Host
- Agent Ability - Lookup Crowdstrike Host
Use Case 6: Identity Threat Response
Category: SOC | Subcategory: Identity threat response
Description: A full set of on-demand response playbooks for Microsoft Entra ID identity threats — covering account disablement, password reset, session revocation, MFA re-registration enforcement, conditional access group management, OAuth consent revocation, and service principal/application disablement. Also includes Exchange Online email remediation and Defender for Endpoint response abilities callable from the AI agent layer. Configured and deployed across workspaces; no execution in the last 12 months.
Integrations configured: Microsoft Entra ID, Microsoft Exchange Online, Microsoft Defender for Endpoint
Configured — Not Yet Active
Microsoft Entra ID:
- Disable User Account (no gated approval)
- Re-enable User Account
- Revoke User Sign-in Sessions
- Force Password Reset on Next Sign-in (no gated approval)
- Issue Temporary Access Pass (no gated approval)
- Require MFA Re-registration (no gated approval)
- Delete a Suspicious Authentication Method (no gated approval)
- Confirm User Compromised
- Dismiss User Risk
- Add User to Quarantine / CA-Block Group (no gated approval)
- Remove User from Group (no gated approval)
- Revoke OAuth Consent Grant (no gated approval)
- Disable Service Principal / Application (no gated approval)
Agent response abilities (callable by AI layer):
- Response Ability - Microsoft Entra ID - Revoke User Session
- Response Ability - Microsoft Entra ID - User Password Reset
- Response Ability - Microsoft Entra ID - User Require Re-registration of MFA
- Response Ability - Microsoft Entra ID - Disable User
- Response Ability - Microsoft Entra ID - Enable User
- Response Ability - Microsoft Defender for Endpoint - Start AV Scan
- Response Ability - Microsoft Defender for Endpoint - Isolate Device
- Response Ability - Microsoft Defender for Endpoint - Release Machine Isolation
- Response Ability - Microsoft Exchange Online - Move Email to Deleted
- Response Ability - Microsoft Exchange Online - Move Email to Spam
- Response Ability - Remove IOC from Indicators Block List
- Response Ability - Add IOC into Indicators Block List
- Response Ability - Microsoft Defender for Endpoint - Stop Process on Endpoint
Use Case 7: Platform Operations & Monitoring
Category: Other | Subcategory: IT helpdesk & ticket routing (error monitoring)
Description: Operational monitoring for the automation platform itself — triggered on workflow errors to send notification emails and surface pipeline failures to the operations team. Additional recovery utilities (for handling unprocessed alerts, missing templates, and non-enriched observables) are configured but not yet active.
Active Playbooks
| Playbook | Workspace | Executions (12mo) | Category | Subcategory |
|---|---|---|---|---|
| Email Error Monitoring Channel | 9dba09ef | 2 | Other | Error monitoring |
Configured — Not Yet Active
| Playbook | Notes |
|---|---|
| Error Handling - Send Error Notification Email | Multiple workspace instances configured |
| Recovery - Enrich Non-Enriched Observables | Backfill enrichment on observables that missed initial enrichment pass |
| Recovery - Handle Unprocessed Alerts / Recovery - Handle Unprocessed Alert | Alert pipeline recovery utilities |
| Subflow - Missing Alert Template Notification | Alerts ops team when an incoming event lacks a defined normalization template |
| Utility - Close Stale Cases | Automated hygiene for aged-out open cases |
Key Observations
Strengths
Mature, high-volume ingestion pipeline. The Cloudflare WAF polling ingestion is the highest-volume operation in the environment at 34,475 executions across 3 workspaces, running every 5 minutes with consistent throughput across all three instances. The Microsoft Defender for Endpoint ingestion adds another 9,293 executions across 4 workspaces with near-identical counts per instance, indicating a well-load-balanced, stable deployment. The ingestion layer collectively processed over 47,000 events in the last 12 months without analyst involvement.
Operational Agentic SOC deployment. The AI investigation layer is active and in production use across 5 workspaces. The Decision Layer has completed 562 triage decisions; the Expert Agents, Main AI Investigation subflow, and all supporting agent abilities (VIP user context, asset inventory, historical cases, observable enrichments) are executing consistently. The environment has custom agent query tools for Azure Log Analytics and Defender XDR Advanced Hunting, indicating purpose-built threat investigation capabilities integrated directly into the AI layer.
Broad enrichment coverage across 11 sources. The enrichment framework is active across 5 workspaces with VirusTotal, Whois, Entra ID, Defender XDR, Intune, CrowdStrike, and NinjaOne all contributing structured enrichment data to cases. Observable enrichment is tightly integrated into the AI investigation pipeline — the agent queries enrichment data before making close/escalate decisions.
Bidirectional Sentinel integration. Both ingestion (Sentinel Ingestion - V3) and closure sync (Close Sentinel Incident, 40 executions) are active, indicating a live SIEM integration where case resolution state is propagated back to the source SIEM automatically.
Extensive response playbook library ready for activation. Use Cases 5 and 6 represent 48+ configured response playbooks across EDR (MDE + CrowdStrike) and identity (Entra ID + Exchange Online) that are fully deployed and require no additional setup to activate. The "no gated approval" labeling on the highest-impact actions indicates deliberate pre-authorization decisions have already been made.
Gaps and Expansion Opportunities
AI case closure not yet active. The Agentic SOC - Close Case playbook is configured across all workspaces but has 0 executions. The AI layer is completing triage decisions (562 executions) but not yet auto-closing cases on its own — likely being reviewed manually before closing. Activating automated closure for AI-confirmed low-risk cases would complete the autonomous SOC loop.
Response playbooks configured but unused. Neither Use Case 5 (EDR containment) nor Use Case 6 (identity response) have recorded executions in the last 12 months. Given the active ingestion and AI triage pipeline, connecting AI escalate decisions to response actions is the logical next step.
Several alert sources configured but not yet producing volume. CrowdStrike webhook ingestion has 3 executions; FortiGate, Splunk, and webhook-based Cloudflare ingestion are configured at 0 executions. These represent expansion-ready integrations that can be activated without additional playbook development.
Enrichment configured for sources not yet integrated. Okta, Google Workspace, GitHub, Slack, Wiz, Azure Resource logs, FortiAnalyzer, IPDB, and URLScan enrichment playbooks are all configured but idle. As these integrations are connected, enrichment coverage expands automatically.
Two parallel Whois enrichment playbooks active. "Enrich - IP or Domain - Whois" and "Enrich IP or Domain Using Whois" are running concurrently with identical execution counts per workspace — both at 26/18/9 across the same three workspaces. This appears to be a versioning overlap; consolidating to the newer playbook would reduce redundancy.
Integration Ecosystem
Active integrations (11):
| Integration | Usage |
|---|---|
| Cloudflare WAF | Alert ingestion (polling) |
| Microsoft Defender for Endpoint | Alert ingestion, device enrichment, XDR threat hunting |
| Microsoft Sentinel | Incident ingestion, closure sync |
| Microsoft Entra ID / Graph API | Identity risk ingestion, user enrichment |
| Microsoft Exchange Online / Office 365 Management | Email security alert ingestion |
| Microsoft Intune | Device/hostname enrichment |
| Microsoft Azure Log Analytics | AI agent threat hunting queries |
| VirusTotal | Hash, IP, URL, domain enrichment |
| CrowdStrike | Alert ingestion (webhook), host enrichment, hash enrichment |
| NinjaOne | Device enrichment |
| Blink Case Management | Case CRUD, observable management, historical case lookups |
Configured — not yet active (9):
| Integration | Use Case |
|---|---|
| Okta | User enrichment |
| Google Workspace | User enrichment |
| Slack | User enrichment |
| GitHub | User enrichment |
| Wiz | Entity enrichment |
| Azure Resource enrichment | Resource context |
| FortiGate / FortiAnalyzer | Alert ingestion, enrichment |
| Splunk | Alert ingestion |
| IPDB, URLScan | IP/URL enrichment |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.