Blink Security Automation — Confidential

fentron — Customer Success Report

Generated 2026-09-10 | fentron-value-report.md
2026-09-10Report Date
692Total Playbooks
221Unique Workflows (12m)
240,814Actions Automated (12m)
$61,938Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

692
Total playbooks built
all non-deleted workflows
519
Active playbooks
currently enabled
221
Unique workflows executed (12m)
distinct workflows that ran
240,814
Actions automated (12m)
completed action steps
1,337.9h
Hours saved (12m)
@ 20s per action
$61,938
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
307
Total cases managed
307 opened in last 12m
3d 11h
MTTR — mean time to resolve
closed cases, last 12m
35
Active AI agents
of 100 total
2,792
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 34,475 WAF security events auto-ingested & normalized from Cloudflare - 9,293 endpoint alerts auto-processed from Microsoft Defender for Endpoint without analyst intervention - 1,644 identity risk events ingested & correlated from Microsoft Entra ID Protection - 996 Sentinel incidents auto-ingested from SIEM into the case management pipeline - 890 email security events ingested & normalized from Exchange Online Protection - 562 alerts triaged autonomously by the AI investigation layer without analyst involvement - 40 Sentinel incidents auto-closed after AI-driven investigation confirmed resolution - 3 CrowdStrike alerts ingested via webhook

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1: SIEM & Alert Ingestion Pipeline19,355 executions
100.0%
10
3 active
Use Case 2: Agentic SOC — AI-Driven Alert Investigation0 executions
0.0%
17
16 active
Use Case 3: Alert Enrichment & IOC Lookup0 executions
0.0%
16
15 active
Use Case 4: Case Management & Incident Lifecycle4 executions
0.0%
6
5 active
Use Case 7: Platform Operations & Monitoring0 executions
0.0%
5
5 active
Total19,359 executions100%
54
44 active

Use Case Growth Over Time

218 unique playbooks  |  5 operational use cases  |  19,360 total executions (12m)  |  2026-05 to 2026-07
Toggle:
Toggle:

03Integration Ecosystem

Use Case 7: Platform Operations & Monitoring
Email
Use Case 3: Alert Enrichment & IOC Lookup
CrowdStrike Agents Microsoft Defender XDR Microsoft Intune NinjaOne Microsoft Entra ID VirusTotal
Use Case 2: Agentic SOC — AI-Driven Alert Investigation
Agents Azure Log Analytics VirusTotal Microsoft Defender XDR
Use Case 4: Case Management & Incident Lifecycle
Agents Microsoft Sentinel
Use Case 1: SIEM & Alert Ingestion Pipeline
Microsoft Defender For Endpoints Cloudflare Microsoft Sentinel Azure Log Analytics CrowdStrike Microsoft Office 365 Management Activity Microsoft Graph

04Key Observations

✓  Strengths

Strengths

Mature, high-volume ingestion pipeline. The Cloudflare WAF polling ingestion is the highest-volume operation in the environment at 34,475 executions across 3 workspaces, running every 5 minutes with consistent throughput across all three instances. The Microsoft Defender for Endpoint ingestion adds another 9,293 executions across 4 workspaces with near-identical counts per instance, indicating a well-load-balanced, stable deployment. The ingestion layer collectively processed over 47,000 events in the last 12 months without analyst involvement.

Operational Agentic SOC deployment. The AI investigation layer is active and in production use across 5 workspaces. The Decision Layer has completed 562 triage decisions; the Expert Agents, Main AI Investigation subflow, and all supporting agent abilities (VIP user context, asset inventory, historical cases, observable enrichments) are executing consistently. The environment has custom agent query tools for Azure Log Analytics and Defender XDR Advanced Hunting, indicating purpose-built threat investigation capabilities integrated directly into the AI layer.

Broad enrichment coverage across 11 sources. The enrichment framework is active across 5 workspaces with VirusTotal, Whois, Entra ID, Defender XDR, Intune, CrowdStrike, and NinjaOne all contributing structured enrichment data to cases. Observable enrichment is tightly integrated into the AI investigation pipeline — the agent queries enrichment data before making close/escalate decisions.

Bidirectional Sentinel integration. Both ingestion (Sentinel Ingestion - V3) and closure sync (Close Sentinel Incident, 40 executions) are active, indicating a live SIEM integration where case resolution state is propagated back to the source SIEM automatically.

Extensive response playbook library ready for activation. Use Cases 5 and 6 represent 48+ configured response playbooks across EDR (MDE + CrowdStrike) and identity (Entra ID + Exchange Online) that are fully deployed and require no additional setup to activate. The "no gated approval" labeling on the highest-impact actions indicates deliberate pre-authorization decisions have already been made.

###

△  Gaps & Growth Opportunities

Gaps and Expansion Opportunities

AI case closure not yet active. The Agentic SOC - Close Case playbook is configured across all workspaces but has 0 executions. The AI layer is completing triage decisions (562 executions) but not yet auto-closing cases on its own — likely being reviewed manually before closing. Activating automated closure for AI-confirmed low-risk cases would complete the autonomous SOC loop.

Response playbooks configured but unused. Neither Use Case 5 (EDR containment) nor Use Case 6 (identity response) have recorded executions in the last 12 months. Given the active ingestion and AI triage pipeline, connecting AI escalate decisions to response actions is the logical next step.

Several alert sources configured but not yet producing volume. CrowdStrike webhook ingestion has 3 executions; FortiGate, Splunk, and webhook-based Cloudflare ingestion are configured at 0 executions. These represent expansion-ready integrations that can be activated without additional playbook development.

Enrichment configured for sources not yet integrated. Okta, Google Workspace, GitHub, Slack, Wiz, Azure Resource logs, FortiAnalyzer, IPDB, and URLScan enrichment playbooks are all configured but idle. As these integrations are connected, enrichment coverage expands automatically.

Two parallel Whois enrichment playbooks active. "Enrich - IP or Domain - Whois" and "Enrich IP or Domain Using Whois" are running concurrently with identical execution counts per workspace — both at 26/18/9 across the same three workspaces. This appears to be a versioning overlap; consolidating to the newer playbook would reduce redundancy.

Integration Ecosystem

Active integrations (11):

Integration Usage
Cloudflare WAF Alert ingestion (polling)
Microsoft Defender for Endpoint Alert ingestion, device enrichment, XDR threat hunting
Microsoft Sentinel Incident ingestion, closure sync
Microsoft Entra ID / Graph API Identity risk ingestion, user enrichment
Microsoft Exchange Online / Office 365 Management Email security alert ingestion
Microsoft Intune Device/hostname enrichment
Microsoft Azure Log Analytics AI agent threat hunting queries
VirusTotal Hash, IP, URL, domain enrichment
CrowdStrike Alert ingestion (webhook), host enrichment, hash enrichment
NinjaOne Device enrichment
Blink Case Management Case CRUD, observable management, historical case lookups

Configured — not yet active (9):

Integration Use Case
Okta User enrichment
Google Workspace User enrichment
Slack User enrichment
GitHub User enrichment
Wiz Entity enrichment
Azure Resource enrichment Resource context
FortiGate / FortiAnalyzer Alert ingestion, enrichment
Splunk Alert ingestion
IPDB, URLScan IP/URL enrichment
Appendices
A Case Management 307 cases (12m) | MTTR 3d 11h

Case Management

Total Cases (all-time)
307
307 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
123
of 307 opened
MTTR
3d 11h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
B-Paid 161 161 85 1d 13h
Fentron SOC 124 124 37 7d 12h
CWM 12 12 0 N/A
Asset Watch 6 6 0 N/A
Agentic SOC V2 2 2 0 N/A
Steller Construction 2 2 1 19d 18h
B AI Agents 35 active | 2,792 tasks (12m)

AI Agents

Active Agents
35
of 100 total
Tasks Executed (12m)
2,792
0 in last 30d
Data Usage (12m)
612,814,901
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink - Decision Maker Fentron SOC 838 0 146,036,821
2 Micro Agent - Historical Case Check Fentron SOC 481 0 38,023,093
3 SOC Agent - Core Investigator Agent Fentron SOC 371 0 77,478,534
4 Agent Blink - Decision Maker B-Paid 367 0 33,116,727
5 Fentron - Enrichment Card Agent Fentron SOC 287 0 246,520,877
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Fentron SOC2,089
B-Paid570
Steller Construction52
CWM50
Asset Watch30
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
10
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Agentic SOC 00
2 Agentic SOC 00
3 Guest User Audit Dashboard 00
4 Agentic SOC 00
5 NinjaOne Dashboard 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 5 use cases | 19,360 executions (12m)

Business KPIs

Metric Value
Total automation executions 52,142
Active use cases 7
Alert sources integrated (active) 11
Alert sources configured (not yet active) 9
Workspaces with active automation 10
In the last 12 months, Blink automated: - 34,475 WAF security events auto-ingested & normalized from Cloudflare - 9,293 endpoint alerts auto-processed from Microsoft Defender for Endpoint without analyst intervention - 1,644 identity risk events ingested & correlated from Microsoft Entra ID Protection - 996 Sentinel incidents auto-ingested from SIEM into the case management pipeline - 890 email security events ingested & normalized from Exchange Online Protection - 562 alerts triaged autonomously by the AI investigation layer without analyst involvement - 40 Sentinel incidents auto-closed after AI-driven investigation confirmed resolution - 3 CrowdStrike alerts ingested via webhook

Use Case Summary

Use Case Category Subcategory Unique Playbook Instances Active Executions
1. SIEM & Alert Ingestion Pipeline SOC SIEM & log pipeline monitoring 12 active + 11 configured 47,301
2. Agentic SOC — AI-Driven Alert Investigation SOC Agentic SOC 16 active + 4 configured 3,249
3. Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 16 active + 18 configured 1,166
4. Case Management & Incident Lifecycle SOC Case mgmt & SOAR 8 active + 5 configured 497
5. EDR Containment & Response SOC EDR containment & response 0 active, 22 configured 0
6. Identity Threat Response SOC Identity threat response 0 active, 26 configured 0
7. Platform Operations & Monitoring Other IT helpdesk & ticket routing 1 active + 5 configured 2

Use Cases

Use Case 1: SIEM & Alert Ingestion Pipeline

Category: SOC | Subcategory: SIEM & log pipeline monitoring

Description: Scheduled and webhook-based polling of multiple security platforms — Cloudflare WAF, Microsoft Defender for Endpoint, Microsoft Sentinel, Entra ID Protection, Exchange Online Protection, and CrowdStrike — normalizes incoming security events and automatically creates cases in the case management system. This pipeline is the entry point for all downstream automation: enrichment, AI investigation, and response actions operate on cases created here.

Active integrations: Cloudflare WAF, Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Entra ID / Graph API, Microsoft Exchange Online / Office 365 Management API, CrowdStrike

Active Playbooks

Playbook Workspace Executions (12mo) Category Subcategory
Cloudflare WAF Ingestion - Polling 9dba09ef 11,522 SOC SIEM & log pipeline monitoring
Cloudflare WAF Ingestion - Polling 30299069 11,477 SOC SIEM & log pipeline monitoring
Cloudflare WAF Ingestion - Polling 97ee93a9 11,476 SOC SIEM & log pipeline monitoring
Microsoft Defender for Endpoint Ingestion 30299069 2,325 SOC SIEM & log pipeline monitoring
Microsoft Defender for Endpoint Ingestion 6ce97eba 2,323 SOC SIEM & log pipeline monitoring
Microsoft Defender for Endpoint Ingestion ecf7f34f 2,323 SOC SIEM & log pipeline monitoring
Microsoft Defender for Endpoint Ingestion a81e6f7f 2,322 SOC SIEM & log pipeline monitoring
Entra ID Protection Ingestion (E5) ecf7f34f 921 SOC SIEM & log pipeline monitoring
Microsoft Sentinel Ingestion - V3 97ee93a9 996 SOC SIEM & log pipeline monitoring
EOP Alert Ingestion (E3) 30299069 890 SOC SIEM & log pipeline monitoring
Entra ID Protection Ingestion (E5) a81e6f7f 723 SOC SIEM & log pipeline monitoring
Ingest - Crowdstrike 6ce97eba 3 SOC SIEM & log pipeline monitoring

Playbook descriptions:

  • Cloudflare WAF Ingestion - Polling: Scheduled polling (every 5 minutes) of Cloudflare WAF zones; normalizes WAF security events and creates cases in case management. Deployed across 3 workspaces totaling 34,475 executions — the highest-volume ingestion pipeline in the environment.
  • Microsoft Defender for Endpoint Ingestion: Event-driven polling of Microsoft Defender for Endpoint for new endpoint alerts; auto-ingests and normalizes into case management. Deployed across 4 workspaces totaling 9,293 executions.
  • Microsoft Sentinel Ingestion - V3: Polling-based ingestion of Microsoft Sentinel incidents into case management (996 executions, 1 workspace).
  • Entra ID Protection Ingestion (E5): Hourly polling of Microsoft Graph API for Entra ID risk detections; ingests identity threat signals and creates correlated cases (1,644 executions across 2 workspaces).
  • EOP Alert Ingestion (E3): Hourly polling of Office 365 Management Activity API for Exchange Online Protection alerts; normalizes email security events (890 executions, 1 workspace).
  • Ingest - Crowdstrike: Webhook-based ingestion of CrowdStrike alert events; retrieves alert details and normalizes into case management (3 executions, 1 workspace).

Configured — Not Yet Active

Playbook Notes
Cloudflare WAF Ingestion - Webhook Webhook-based alternative to the polling ingestion; configured across multiple workspace instances
FortiGate Ingestion - Webhook Configured, 0 executions
Splunk Ingestion Configured, 0 executions

Use Case 2: Agentic SOC — AI-Driven Alert Investigation

Category: SOC | Subcategory: Agentic SOC

Description: A multi-layer AI agent system that autonomously investigates security alerts by orchestrating specialist expert agents. The Decision Layer receives an alert case, dispatches domain-specific expert agents, and queries threat intelligence sources (VirusTotal), log repositories (Azure Log Analytics, Defender XDR Advanced Hunting via KQL), and organizational context (VIP user lists, asset inventory, historical cases, observable enrichments) before rendering a close or escalate decision — without analyst involvement on routine cases. The architecture separates orchestration (Decision Layer), routing (Expert Agents), core AI logic (Main AI Investigation subflow), and tool-specific agent abilities into discrete, reusable playbook layers.

Active integrations: Azure Log Analytics, Microsoft Defender XDR Advanced Hunting (KQL), VirusTotal, Blink Case Management (observables, historical cases, VIP user lists, asset inventory)

Active Playbooks

Playbook Workspace Executions (12mo) Category Subcategory
Agentic SOC - Decision Layer 97ee93a9 345 SOC Agentic SOC
Agentic SOC - Decision Layer 05f4ac12 163 SOC Agentic SOC
Agentic SOC - Decision Layer 30299069 32 SOC Agentic SOC
Agentic SOC - Decision Layer 6ce97eba 18 SOC Agentic SOC
Agentic SOC - Decision Layer a81e6f7f 4 SOC Agentic SOC
Agentic SOC - Expert Agents 97ee93a9 174 SOC Agentic SOC
Agentic SOC - Expert Agents 05f4ac12 82 SOC Agentic SOC
Agentic SOC - Expert Agents 30299069 16 SOC Agentic SOC
Agentic SOC - Expert Agents 6ce97eba 9 SOC Agentic SOC
Agentic SOC - Expert Agents a81e6f7f 2 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation 97ee93a9 174 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation 05f4ac12 82 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation 30299069 16 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation 6ce97eba 9 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation a81e6f7f 2 SOC Agentic SOC
Agent Blink - Query Log Analytics (Fentron Production) 97ee93a9 48 SOC Agentic SOC
Agent Blink - Query Log Analytics (Fentron Production) 05f4ac12 13 SOC Agentic SOC
Agent Blink - Query Defender XDR Hunting 05f4ac12 47 SOC Agentic SOC
Agent Blink - Query Defender XDR Hunting 97ee93a9 8 SOC Agentic SOC
Agent Blink - Search Virus Total (Fentron Production) 6ce97eba 3 SOC Agentic SOC
Agent Blink - Search Virus Total (Fentron Production) ecf7f34f 1 SOC Agentic SOC
Agent Ability - Get VIP Users 97ee93a9 519 SOC Agentic SOC
Agent Ability - Get VIP Users 05f4ac12 245 SOC Agentic SOC
Agent Ability - Get VIP Users 30299069 44 SOC Agentic SOC
Agent Ability - Get VIP Users 6ce97eba 22 SOC Agentic SOC
Agent Ability - Get VIP Users a81e6f7f 6 SOC Agentic SOC
Agent Ability - Get Org Assets 97ee93a9 417 SOC Agentic SOC
Agent Ability - Get Org Assets 05f4ac12 68 SOC Agentic SOC
Agent Ability - Get Org Assets 30299069 7 SOC Agentic SOC
Agent Ability - Get Org Assets 6ce97eba 3 SOC Agentic SOC
Agent Ability - Get Org Assets a81e6f7f 2 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment 97ee93a9 174 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment 05f4ac12 90 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment 30299069 16 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment 6ce97eba 9 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment a81e6f7f 2 SOC Agentic SOC
Agent Ability - Historical Case Checks 97ee93a9 174 SOC Agentic SOC
Agent Ability - Historical Case Checks 05f4ac12 18 SOC Agentic SOC
Agent Ability - Historical Case Checks 30299069 7 SOC Agentic SOC
Agent Ability - Historical Case Checks a81e6f7f 2 SOC Agentic SOC
Agent Ability - Get Core Agent Questions 97ee93a9 140 SOC Agentic SOC
Agent Ability - Get Core Agent Questions a81e6f7f 1 SOC Agentic SOC
Agent Ability - Read Observable Enrichments a81e6f7f 26 SOC Agentic SOC
Agent Ability - Post Enrichment Card a81e6f7f 4 SOC Agentic SOC
Agent Ability - Get Case a81e6f7f 2 SOC Agentic SOC
Agent Ability - Get Malware Questions 97ee93a9 2 SOC Agentic SOC
Agent Ability - Get Phishing Questions 97ee93a9 1 SOC Agentic SOC

Configured — Not Yet Active

Playbook Notes
Agent Blink - Query Log Analytics Configured across additional workspaces with 0 executions
Agent Blink - Query Defender XDR Hunting Configured across additional workspaces with 0 executions
Subflow - Agentic SOC - Main - AI Investigation Configured in unused workspaces
Agentic SOC - Close Case The AI-driven case closure action; configured across all workspaces, not yet executed

Use Case 3: Alert Enrichment & IOC Lookup

Category: SOC | Subcategory: Alert enrichment / IOC lookup

Description: A multi-source enrichment framework that automatically looks up IPs, domains, file hashes, usernames, hostnames, and device identifiers across VirusTotal, Whois, CrowdStrike, Microsoft Defender XDR, Intune, Entra ID, and NinjaOne. A central router dispatches enrichment requests by observable type; results are written back as structured enrichment data to case observables, making all downstream automation — including the AI investigation layer — context-aware from the moment a case opens.

Active integrations: VirusTotal, Whois, Microsoft Entra ID, Microsoft Defender XDR, Microsoft Intune, CrowdStrike, NinjaOne, Blink Case Management

Active Playbooks

Playbook Workspace Executions (12mo) Category Subcategory
Subflow - Enrich Observables - Main Router 05f4ac12 159 SOC Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router 97ee93a9 142 SOC Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router 6ce97eba 82 SOC Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router 30299069 30 SOC Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router a81e6f7f 13 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 97ee93a9 121 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 05f4ac12 102 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 6ce97eba 48 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 30299069 14 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data a81e6f7f 5 SOC Alert enrichment / IOC lookup
CM Ability - VirusTotal Enrichment 97ee93a9 55 SOC Alert enrichment / IOC lookup
CM Ability - VirusTotal Enrichment 05f4ac12 42 SOC Alert enrichment / IOC lookup
CM Ability - VirusTotal Enrichment 6ce97eba 23 SOC Alert enrichment / IOC lookup
CM Ability - VirusTotal Enrichment 30299069 8 SOC Alert enrichment / IOC lookup
CM Ability - VirusTotal Enrichment a81e6f7f 1 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 97ee93a9 26 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 05f4ac12 18 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 6ce97eba 9 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 97ee93a9 26 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 05f4ac12 18 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 6ce97eba 9 SOC Alert enrichment / IOC lookup
CM Ability - Entra ID User Enrichment 05f4ac12 23 SOC Alert enrichment / IOC lookup
CM Ability - Entra ID User Enrichment 97ee93a9 18 SOC Alert enrichment / IOC lookup
CM Ability - Entra ID User Enrichment 30299069 3 SOC Alert enrichment / IOC lookup
CM Ability - Entra ID User Enrichment 6ce97eba 2 SOC Alert enrichment / IOC lookup
CM Ability - Entra ID User Enrichment a81e6f7f 1 SOC Alert enrichment / IOC lookup
Enrich - Defender - XDR User Threat Hunting - E5 97ee93a9 16 SOC Alert enrichment / IOC lookup
Enrich - Defender - XDR User Threat Hunting - E5 05f4ac12 14 SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike 6ce97eba 14 SOC Alert enrichment / IOC lookup
CM Ability - NinjaOne Enrichment 6ce97eba 6 SOC Alert enrichment / IOC lookup
CM Ability - NinjaOne Enrichment 30299069 3 SOC Alert enrichment / IOC lookup
CM Ability - NinjaOne Enrichment 05f4ac12 2 SOC Alert enrichment / IOC lookup
CM Ability - NinjaOne Enrichment 97ee93a9 2 SOC Alert enrichment / IOC lookup
CM Ability - NinjaOne Enrichment a81e6f7f 2 SOC Alert enrichment / IOC lookup
NinjaOne - Get Device By System Name Or DNS Name Or ID 6ce97eba 4 SOC Alert enrichment / IOC lookup
NinjaOne - Get Device By System Name Or DNS Name Or ID 30299069 3 SOC Alert enrichment / IOC lookup
NinjaOne - Get Device By System Name Or DNS Name Or ID 05f4ac12 2 SOC Alert enrichment / IOC lookup
NinjaOne - Get Device By System Name Or DNS Name Or ID 97ee93a9 2 SOC Alert enrichment / IOC lookup
NinjaOne - Get Device By System Name Or DNS Name Or ID a81e6f7f 1 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Intune 6ce97eba 3 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Intune 30299069 3 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Intune 05f4ac12 2 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Intune 97ee93a9 2 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Intune a81e6f7f 1 SOC Alert enrichment / IOC lookup
CM Ability - Intune - Search for User's Device 05f4ac12 3 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Crowdstrike 6ce97eba 3 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Defender XDR Threat Context 97ee93a9 2 SOC Alert enrichment / IOC lookup
Enrich - Hostname - Defender XDR Threat Context 05f4ac12 1 SOC Alert enrichment / IOC lookup
Enrich - Device Agent ID - CrowdStrike 6ce97eba 2 SOC Alert enrichment / IOC lookup
Subflow - Generate Enrichment Cards a81e6f7f 2 SOC Alert enrichment / IOC lookup

Configured — Not Yet Active

Enrich - IP - IPDB, Enrich - IP - VT, Enrich - URL - VT, Enrich - URL - URLScan, Enrich - Hash - VT, Enrich - Username - Okta, Enrich - Username - Google Workspace, Enrich - Username - Microsoft Entra ID, Enrich - Email Address - Slack, Enrich - Agent ID - Crowdstrike, Enrich - CrowdStrike Threatgraph Enrichment, Enrich - Username - Github, Enrich - Wiz Entity Enrichment, Enrich - Azure Resource Activity Log, Enrich - Azure Resource Enrichment, Enrich - FortiAnalyzer Enrichment, Enrich - Observable - Cloudflare Zero Trust Account, Enrich - Observable - Cloudflare Zone

Use Case 4: Case Management & Incident Lifecycle

Category: SOC | Subcategory: Case mgmt & SOAR

Description: Manages the full lifecycle of security cases — bidirectional sync between the case management platform and Microsoft Sentinel (ingesting incidents and closing them back in Sentinel once resolved), fetching and maintaining case observables, and refreshing investigation state to keep the analyst view current. These utilities underpin every other use case: enrichment, AI investigation, and response actions all depend on accurate, up-to-date case data.

Active integrations: Microsoft Sentinel, Blink Case Management

Active Playbooks

Playbook Workspace Executions (12mo) Category Subcategory
Close Sentinel Incident 97ee93a9 27 SOC Case mgmt & SOAR
Close Sentinel Incident 05f4ac12 13 SOC Case mgmt & SOAR
Get Observables by Case ID 97ee93a9 290 SOC Case mgmt & SOAR
Get Observables by Case ID 30299069 12 SOC Case mgmt & SOAR
Get Observables by Case ID 05f4ac12 11 SOC Case mgmt & SOAR
Utility - Refresh investigation 97ee93a9 112 SOC Case mgmt & SOAR
Utility - Refresh investigation 05f4ac12 22 SOC Case mgmt & SOAR
Utility - Refresh investigation 6ce97eba 4 SOC Case mgmt & SOAR
Utility - Refresh investigation 30299069 4 SOC Case mgmt & SOAR
Utility - Refresh investigation a81e6f7f 1 SOC Case mgmt & SOAR
Utility - Refresh investigation list 97ee93a9 1 SOC Case mgmt & SOAR

Configured — Not Yet Active

Playbook Notes
Agentic SOC - Close Case AI-driven case closure; configured across all workspaces, not yet executed
Utility - Close Stale Cases Automated stale case hygiene; configured, not yet executed
Comment On Case Automated case commenting; configured, not yet executed

Use Case 5: EDR Containment & Response

Category: SOC | Subcategory: EDR containment & response

Description: A comprehensive library of one-click and agentic response actions for Microsoft Defender for Endpoint and CrowdStrike Falcon — covering device isolation, file quarantine and block, indicator-based blocking (IP, URL, domain, hash), antivirus scanning, investigation package collection, live response script execution, and device tagging. Configured and deployed across workspaces; ready for execution without additional setup. These actions can be triggered manually by analysts or invoked by the AI investigation layer for approved automated response.

Integrations configured: Microsoft Defender for Endpoint, CrowdStrike Falcon (RTR, quarantine management)

Configured — Not Yet Active

Microsoft Defender for Endpoint:

  • Isolate Device - Full (no gated approval)
  • Isolate Device - Selective (no gated approval)
  • Release Device from Isolation
  • Run Antivirus Scan
  • Collect Investigation Package
  • Restrict App Execution (no gated approval)
  • Remove App-Execution Restriction
  • Stop & Quarantine File (no gated approval)
  • Block File Hash (Custom Indicator)
  • Block IP / URL / Domain (Custom Indicator)
  • Initiate Automated Investigation
  • Run Live Response Script (no gated approval)
  • Set Device Tag
  • Offboard Machine (no gated approval)
  • Disable Device Object (no gated approval)

CrowdStrike:

  • CrowdStrike RTR to a Single Host
  • CrowdStrike RTR to a Batch of Hosts
  • Manage Endpoint Quarantine Status in Crowdstrike
  • quarantine device on CS
  • Agent Blink - Crowdstrike - Isolate/Unisolate
  • Agent Blink - CrowdStrike RTR to a Single Host
  • Agent Ability - Lookup Crowdstrike Host

Use Case 6: Identity Threat Response

Category: SOC | Subcategory: Identity threat response

Description: A full set of on-demand response playbooks for Microsoft Entra ID identity threats — covering account disablement, password reset, session revocation, MFA re-registration enforcement, conditional access group management, OAuth consent revocation, and service principal/application disablement. Also includes Exchange Online email remediation and Defender for Endpoint response abilities callable from the AI agent layer. Configured and deployed across workspaces; no execution in the last 12 months.

Integrations configured: Microsoft Entra ID, Microsoft Exchange Online, Microsoft Defender for Endpoint

Configured — Not Yet Active

Microsoft Entra ID:

  • Disable User Account (no gated approval)
  • Re-enable User Account
  • Revoke User Sign-in Sessions
  • Force Password Reset on Next Sign-in (no gated approval)
  • Issue Temporary Access Pass (no gated approval)
  • Require MFA Re-registration (no gated approval)
  • Delete a Suspicious Authentication Method (no gated approval)
  • Confirm User Compromised
  • Dismiss User Risk
  • Add User to Quarantine / CA-Block Group (no gated approval)
  • Remove User from Group (no gated approval)
  • Revoke OAuth Consent Grant (no gated approval)
  • Disable Service Principal / Application (no gated approval)

Agent response abilities (callable by AI layer):

  • Response Ability - Microsoft Entra ID - Revoke User Session
  • Response Ability - Microsoft Entra ID - User Password Reset
  • Response Ability - Microsoft Entra ID - User Require Re-registration of MFA
  • Response Ability - Microsoft Entra ID - Disable User
  • Response Ability - Microsoft Entra ID - Enable User
  • Response Ability - Microsoft Defender for Endpoint - Start AV Scan
  • Response Ability - Microsoft Defender for Endpoint - Isolate Device
  • Response Ability - Microsoft Defender for Endpoint - Release Machine Isolation
  • Response Ability - Microsoft Exchange Online - Move Email to Deleted
  • Response Ability - Microsoft Exchange Online - Move Email to Spam
  • Response Ability - Remove IOC from Indicators Block List
  • Response Ability - Add IOC into Indicators Block List
  • Response Ability - Microsoft Defender for Endpoint - Stop Process on Endpoint

Use Case 7: Platform Operations & Monitoring

Category: Other | Subcategory: IT helpdesk & ticket routing (error monitoring)

Description: Operational monitoring for the automation platform itself — triggered on workflow errors to send notification emails and surface pipeline failures to the operations team. Additional recovery utilities (for handling unprocessed alerts, missing templates, and non-enriched observables) are configured but not yet active.

Active Playbooks

Playbook Workspace Executions (12mo) Category Subcategory
Email Error Monitoring Channel 9dba09ef 2 Other Error monitoring

Configured — Not Yet Active

Playbook Notes
Error Handling - Send Error Notification Email Multiple workspace instances configured
Recovery - Enrich Non-Enriched Observables Backfill enrichment on observables that missed initial enrichment pass
Recovery - Handle Unprocessed Alerts / Recovery - Handle Unprocessed Alert Alert pipeline recovery utilities
Subflow - Missing Alert Template Notification Alerts ops team when an incoming event lacks a defined normalization template
Utility - Close Stale Cases Automated hygiene for aged-out open cases

Key Observations

Strengths

Mature, high-volume ingestion pipeline. The Cloudflare WAF polling ingestion is the highest-volume operation in the environment at 34,475 executions across 3 workspaces, running every 5 minutes with consistent throughput across all three instances. The Microsoft Defender for Endpoint ingestion adds another 9,293 executions across 4 workspaces with near-identical counts per instance, indicating a well-load-balanced, stable deployment. The ingestion layer collectively processed over 47,000 events in the last 12 months without analyst involvement.

Operational Agentic SOC deployment. The AI investigation layer is active and in production use across 5 workspaces. The Decision Layer has completed 562 triage decisions; the Expert Agents, Main AI Investigation subflow, and all supporting agent abilities (VIP user context, asset inventory, historical cases, observable enrichments) are executing consistently. The environment has custom agent query tools for Azure Log Analytics and Defender XDR Advanced Hunting, indicating purpose-built threat investigation capabilities integrated directly into the AI layer.

Broad enrichment coverage across 11 sources. The enrichment framework is active across 5 workspaces with VirusTotal, Whois, Entra ID, Defender XDR, Intune, CrowdStrike, and NinjaOne all contributing structured enrichment data to cases. Observable enrichment is tightly integrated into the AI investigation pipeline — the agent queries enrichment data before making close/escalate decisions.

Bidirectional Sentinel integration. Both ingestion (Sentinel Ingestion - V3) and closure sync (Close Sentinel Incident, 40 executions) are active, indicating a live SIEM integration where case resolution state is propagated back to the source SIEM automatically.

Extensive response playbook library ready for activation. Use Cases 5 and 6 represent 48+ configured response playbooks across EDR (MDE + CrowdStrike) and identity (Entra ID + Exchange Online) that are fully deployed and require no additional setup to activate. The "no gated approval" labeling on the highest-impact actions indicates deliberate pre-authorization decisions have already been made.

Gaps and Expansion Opportunities

AI case closure not yet active. The Agentic SOC - Close Case playbook is configured across all workspaces but has 0 executions. The AI layer is completing triage decisions (562 executions) but not yet auto-closing cases on its own — likely being reviewed manually before closing. Activating automated closure for AI-confirmed low-risk cases would complete the autonomous SOC loop.

Response playbooks configured but unused. Neither Use Case 5 (EDR containment) nor Use Case 6 (identity response) have recorded executions in the last 12 months. Given the active ingestion and AI triage pipeline, connecting AI escalate decisions to response actions is the logical next step.

Several alert sources configured but not yet producing volume. CrowdStrike webhook ingestion has 3 executions; FortiGate, Splunk, and webhook-based Cloudflare ingestion are configured at 0 executions. These represent expansion-ready integrations that can be activated without additional playbook development.

Enrichment configured for sources not yet integrated. Okta, Google Workspace, GitHub, Slack, Wiz, Azure Resource logs, FortiAnalyzer, IPDB, and URLScan enrichment playbooks are all configured but idle. As these integrations are connected, enrichment coverage expands automatically.

Two parallel Whois enrichment playbooks active. "Enrich - IP or Domain - Whois" and "Enrich IP or Domain Using Whois" are running concurrently with identical execution counts per workspace — both at 26/18/9 across the same three workspaces. This appears to be a versioning overlap; consolidating to the newer playbook would reduce redundancy.

Integration Ecosystem

Active integrations (11):

Integration Usage
Cloudflare WAF Alert ingestion (polling)
Microsoft Defender for Endpoint Alert ingestion, device enrichment, XDR threat hunting
Microsoft Sentinel Incident ingestion, closure sync
Microsoft Entra ID / Graph API Identity risk ingestion, user enrichment
Microsoft Exchange Online / Office 365 Management Email security alert ingestion
Microsoft Intune Device/hostname enrichment
Microsoft Azure Log Analytics AI agent threat hunting queries
VirusTotal Hash, IP, URL, domain enrichment
CrowdStrike Alert ingestion (webhook), host enrichment, hash enrichment
NinjaOne Device enrichment
Blink Case Management Case CRUD, observable management, historical case lookups

Configured — not yet active (9):

Integration Use Case
Okta User enrichment
Google Workspace User enrichment
Slack User enrichment
GitHub User enrichment
Wiz Entity enrichment
Azure Resource enrichment Resource context
FortiGate / FortiAnalyzer Alert ingestion, enrichment
Splunk Alert ingestion
IPDB, URLScan IP/URL enrichment
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.