01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1 — SOC Case Management & Alert Triage | 15,009 executions | 29.2% | 11 11 active |
| Use Case 2 — IOC Enrichment & Threat Hunting | 7,108 executions | 13.8% | 15 15 active |
| Use Case 3 — Threat Intelligence Ingestion & Curation | 2,182 executions | 4.3% | 11 11 active |
| Use Case 4 — Vulnerability Management Data Lake Pipeline | 2,633 executions | 5.1% | 35 34 active |
| Use Case 5 — Vulnerability Lifecycle: Prioritization, Ticketing & Reporting | 1,721 executions | 3.4% | 39 38 active |
| Use Case 6 — Employee Offboarding & IAM Response | 5,652 executions | 11.0% | 9 9 active |
| Use Case 7 — Identity Threat Response (EDR Containment) | 885 executions | 1.7% | 14 14 active |
| Use Case 8 — Cloud Asset Coverage & Inventory | 6,807 executions | 13.3% | 30 29 active |
| Use Case 9 — SaaS Application Governance | 0 executions | 0.0% | 0 0 active |
| Use Case 10 — GRC & Security Reporting | 7 executions | 0.0% | 3 3 active |
| Use Case 11 — AI Agent Governance & Inventory | 432 executions | 0.8% | 13 1 active |
| Total | 42,436 executions | 100% | 180 165 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep, production-grade Vulnerability Management program. NIQ has built one of the most sophisticated VM automation programs in the Blink customer base. The ADLS pipeline ingests vulnerabilities from three scanner families (Defender, Rapid7, Wiz) across multiple business unit instances (NIQ + GFK), normalizes to OCSF, enriches with KEV/EPSS/NVD context, correlates cross-source, and drives Jira remediation ticket creation — all automated. The daily cadence of KEV, EPSS, and NVD dimension builds (38–40 executions each) and Defender/R7/Wiz ingestion runs (127–1,348 executions) demonstrates genuine production reliance.
High-volume SOC automation is operational and running. The Case Orchestrator and Observable Orchestrator together processed nearly 7,700 items in the past 12 months. The enrichment chain (Observable Router → per-tool Hunt subflows → Update Observable Findings at 4,154 executions) is clearly handling real alert volume, not just testing.
Agentic security capabilities are deployed. NIQ has production AI agents for three distinct functions: TI Analyst Agent (threat intelligence interrogation), VM Analyst Agent (natural language vulnerability datalake queries), and a VM Operator Agent with full pipeline tooling. This positions NIQ ahead of most customers in deploying agentic security workflows.
Breadth of integration ecosystem. NIQ's automation spans: Microsoft Defender XDR, SentinelOne, Wiz, Rapid7 InsightVM, Microsoft Entra ID, Microsoft Intune, Zscaler ZIA/SSPM, SailPoint, AlienVault OTX, Cycode, ServiceNow, Jira, Azure Synapse / ADLS, CISA KEV, EPSS, NVD — a mature, enterprise-scale integration footprint.
Cross-business-unit coverage. The VM pipeline explicitly handles both the NIQ and GFK entities with separate scanner connections, reflecting a post-merger integration use case where automation bridges organizational boundaries.
New: AI Agent Governance program stood up. NIQ has launched a dedicated workspace and pipeline (Use Case 11) to inventory and risk-score AI agents across Microsoft Defender/M365 and Wiz — reconciling both sources into a unified inventory, computing exposure and shared-connection risk metrics, and publishing governance dashboards. The AI Agent Chunk Writer alone processed 375 records in its first period, indicating active, ongoing discovery rather than a one-time pilot. This positions NIQ ahead of the curve on a fast-emerging AI-agent attack surface.
New: second asset ingestion pipeline stood up with EOL-OS and metrics capabilities. A new workspace mirrors the core asset-inventory subflows (shared inventory writer, ingestion health writer, cleanup, coverage reporting) and adds two new capabilities not previously present: end-of-life OS detection and asset metrics computation. It also extends source coverage with Spektion and Microsoft Active Directory connectors, and has since added parallel Get-Assets connectors for SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium — effectively rebuilding the full source breadth of the original pipeline within the new architecture. The inventory writer alone processed 940 records, indicating active parallel rollout rather than a dormant fork. The pipeline has since gained its own user-ingestion orchestrator, ASM Analyst Agent abilities, device/host lookup subflows, and error-notification handling — mirroring the original pipeline's full operator toolset, though these newest additions have not yet accrued executions.
VM scanner coverage expanded significantly. Beyond Defender, Rapid7, and Wiz, NIQ has added Spektion, Tanium, and SecurityScorecard as new vulnerability/software-risk data sources, each with its own ingestion, writer, and hunting playbooks already producing meaningful volume (Spektion and Tanium software hunts each running in the 200+ execution range, on par with the original three scanners).
###
Gaps and Opportunities
Response playbooks built but not yet executing. Several high-value response actions have 0 executions: IOC blocking (Defender for Endpoint, SentinelOne, Zscaler), device isolation (Defender, SentinelOne), and user credential reset (Entra). The approval workflow infrastructure exists and is running (693 IOC response trigger events fired). The gap suggests response is still requiring manual confirmation at a high rate, or the blocking/isolation capabilities are staged for broader rollout. Activating automated response for confirmed malicious IOCs would significantly reduce dwell time.
WF0–WF7 table-based VM pipeline has 0 executions. The older workspace (06f7470e) containing WF0–WF8 workflows shows zero execution across all workflows. All active VM pipeline execution is occurring in the newer workspace (b76c3ccc). The older workspace appears to be a superseded iteration — these playbooks could be archived to reduce maintenance overhead.
User Response Actions workflow has 0 executions. The Response - User Response Actions event-based workflow (which responds to compromised user table records) fired 0 times, while the Device Response Actions workflow fired 14. This asymmetry suggests the user response workflow may not be connected to the active case management tables.
Software CVE hunt executions appear pooled across wrapper playbooks. The Blink VM integration wrapper playbooks (Hunt - Software - SentinelOne - Blink Vulnerability Management, Hunt - Software - Wiz - Blink Vulnerability Management, Hunt - Software - Cycode - Blink Vulnerability Management) each show 1,044 executions — likely the same hunt batch running across all three sources in parallel. The underlying direct hunt playbooks (Hunt - Software - SentinelOne, Hunt - Software - Wiz at 1,044 and Hunt - Software - Cycode at 1,109) show consistent counts, confirming a live software hunt program.
ASM workspace (2a845363) has no active playbooks. The Attack Surface Management workspace contains several drafted workflows (Coverage Gap - Alert and Ticket, Ingestion Health Monitor, ASM Agent) with 0 executions. This appears to be an emerging capability being developed rather than production automation.
Integration Ecosystem Summary
| Tool | Category | Role in Automation |
|---|---|---|
| Microsoft Defender XDR / MDE | EDR / VM | IOC hunting, device containment, vulnerability ingestion |
| SentinelOne | EDR | IOC hunting, device isolation, scan initiation, software inventory |
| Wiz | CSPM / VM | Cloud vulnerability ingestion, SBOM hunting, TI notifications |
| Rapid7 InsightVM Cloud | VM Scanner | Vulnerability ingestion (NIQ + GFK entities) |
| Microsoft Entra ID | IAM | User enrichment, device attribution, MFA revocation, batch lookups |
| Microsoft Intune | MDM | Device enrichment, offboarding device management |
| SailPoint | IAM / HR | Termination and activation event source |
| Zscaler ZIA / SSPM | Network / SaaS | IOC URL blocking, SaaS app governance |
| ServiceNow | CMDB / ITSM | CMDB asset ingestion, ticket routing |
| Jira | Ticketing | Remediation ticket creation and assignment |
| Azure Synapse / ADLS | Data Platform | Vulnerability datalake, SLA metrics, analytics |
| AlienVault OTX | Threat Intel | IOC enrichment |
| Cycode | AppSec / VM | Software CVE hunting |
| CISA KEV / EPSS / NVD | Threat Intel | Vulnerability prioritization dimensions |
| Microsoft Outlook | TI notification ingestion, reporting delivery | |
| Microsoft Teams | Collaboration | Response approval requests |
| Spektion | Software Risk / VM | Software CVE hunting, software risk inventory ingestion |
| Tanium | Endpoint Mgmt / VM | Software CVE hunting, software inventory ingestion |
| SecurityScorecard | Security Ratings / VM | Vulnerability and patching-cadence issue ingestion |
| Microsoft Graph / M365 | AI Agent Governance | AI agent discovery and activity ingestion for governance |
| Microsoft Active Directory | IAM / Asset Inventory | On-prem asset and identity source for inventory |
A Case Management 3,974 cases (12m) | MTTR 3d 16h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| User Offboarding | 3,667 | 3,667 | 3,651 | 3d 18h |
| Threat Intelligence | 307 | 307 | 307 | 2d 10h |
B AI Agents 16 active | 1,502 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Observable Identification Agent | Threat Intelligence | 777 | 111 | 63,340,392 |
| 2 | Case Summarization Agent | Threat Intelligence | 423 | 83 | 25,802,900 |
| 3 | Executive Summary Writer | Vulnerability Management | 96 | 43 | 11,414,741 |
| 4 | VM Analyst | Vulnerability Management | 77 | 4 | 4,861,410 |
| 5 | Software Asset Management Agent | Vulnerability Management | 23 | 0 | 2,149,632 |
| Workspace | Tasks (12m) |
|---|---|
| Threat Intelligence | 1,235 |
| Vulnerability Management | 261 |
| Evan.Obal@nielseniq.com | 6 |
| User Offboarding | 0 |
| vincent.sheahan@blinkops.com | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Agentic ADLS Vulnerability Metrics | 0 | 0 |
| 2 | Introduction to Attack Surface Management | 0 | 0 |
| 3 | Spektion AI Software Dashboard | 0 | 0 |
| 4 | Threat Intelligence Overview | 0 | 0 |
| 5 | Threat Intelligence Performance Monitoring | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Automation Test | 0 | 0 |
| 2 | Interactive Software Hunting | 0 | 0 |
| 3 | Threat Intelligence Enhancement Request | 0 | 0 |
| 4 | Threat Intelligence Enhancement Request | 0 | 0 |
D Full Use Case Analysis 10 use cases | 51,330 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Observable findings automatically updated & enriched | 4,154 | Subflow - Update Observable Findings |
| Security cases auto-orchestrated through SOC pipeline | 3,844 | Case Orchestrator |
| Observables automatically triaged & enriched | 3,843 | Observable Orchestrator |
| Entra email batch lookups executed for remediation owners | 3,739 | Entra Email Lookup Batch |
| Asset inventory records written to shared inventory | 3,126 | Subflow - Shared Inventory Writer |
| Asset inventory records written via new asset ingestion pipeline | 940 | Subflow - Shared Inventory Writer (new asset pipeline) |
| Ingestion health records logged for new asset pipeline | 17 | Subflow - Shared Ingestion Health Writer (new asset pipeline) |
| Observable processing status updates | 3,177 | Subflow - Update Observable Processing Status |
| Case processing status updates | 2,676 | Subflow - Update Case Processing Status |
| Wiz threat intelligence notifications ingested | 1,922 | Ingest - Wiz - GraphQL TI Notification |
| Observable enrichment data updated | 1,874 | Subflow - Update Enrichment Data |
| Microsoft Defender vulnerability records ingested to data lake | 1,348 | ADLS Ingest Defender |
| Software CVE hunts executed across SentinelOne | 1,044 | Hunt - Software - SentinelOne |
| Software CVE hunts executed across Wiz | 1,044 | Hunt - Software - Wiz |
| Software CVE hunts executed via Cycode | 1,109 | Hunt - Software - Cycode |
| Employee offboarding workflows processed | 961 | Termination Event Ingestion |
| Security alerts fully processed through SOAR pipeline | 947 | Process Alert |
| VIP user enrichment lookups executed | 971 | Enrich - VIP User |
| Observable enrichment routed automatically | 971 | Subflow - Enrich Observables - Main Router |
| IOC response actions triggered on malicious observables | 693 | Response - IOC Response Actions |
| Hunt findings for IOCs across Microsoft Defender XDR | 392 | Hunt - IOC - Microsoft Defender XDR |
| Hunt findings for IOCs across SentinelOne | 392 | Hunt - IOC - SentinelOne |
| IOC router decisions for enrichment & hunting | 1,960 | Router - Enrich & Hunt Observables |
| Offboarding action sequences completed | 460 | Response Subflow - Offboarding |
| Intune device enrichments executed | 970 | Enrich - Intune Devices |
| Entity response data records updated | 769 | Subflow - Update Response Data |
| Employee activation events logged from SailPoint | 77 | Sailpoint Webhook Number 2 (Employee Activations) |
| Rapid7 vulnerability records ingested to data lake | 127 | ADLS Ingest Rapid7 |
| CVE hunts across Blink Vulnerability Management | 154 | Hunt - CVE - Blink Vulnerability Management |
| Wiz vulnerability records ingested to data lake | 354 | ADLS Ingest Wiz |
| MFA revocation subflow executions | 314 | Subflow - Revoke MFA |
| Response approval requests sent | 211 | Subflow - Response - Main Router |
| Threat intel notifications normalized by AI agent | 125 | Subflow - Intelligence Normalization Agent |
| Zscaler 3rd-party app governance reports generated | 40 | Zscaler 3rd Party App Governance - Query Apps Present In Environment |
| Weekly threat intelligence reports delivered | 5 | Weekly Threat Intelligence Reporting |
| Software CVE hunts executed via Microsoft Defender TVM | 215 | Hunt - Software - Defender TVM |
| Software CVE hunts executed via Spektion | 215 | Hunt - Software - Spektion |
| Software CVE hunts executed via Tanium | 205 | Hunt - Software - Tanium |
| Identity isolation eligibility checks executed for active users | 241 | Subflow - Isolation Logic - KQL for active user |
| AI agent inventory records written to unified AI-agent governance datastore | 375 | AI Agent Chunk Writer |
| Wiz cloud issue records ingested & written | 98 | Wiz Issue Writer |
| Microsoft Defender vulnerability delta records ingested | 93 | Defender Delta Ingest |
| Spektion software inventory records ingested & written | 65 | Spektion Software Writer |
| Wiz wide-exposure vulnerability records ingested to data lake | 55 | ADLS Ingest Wiz Wide Exposure |
| Daily offboarding metrics computed & published | 40 | Compute Offboarding Metrics |
| Microsoft Defender vulnerability recommendations retrieved | 22 | Get Defender VM Reccomendations |
| Extension IOC hunts executed across SentinelOne | 23 | Hunt - Extension - SentinelOne |
| AI agent governance reporting dashboards refreshed | 24 | MS Defender AI Agent Reporting Dashboard |
| Wiz cloud security issues ingested | 14 | Wiz Issues Ingestion |
| Critical open-vulnerability assets tagged for prioritization | 12 | Critical Open Vuln Assets |
| ASM host lookups resolved via ServiceNow CMDB integration | 4 | Utility - ASM Host Lookup |
Use Case Summary
| Use Case | Category | Active Playbooks | Total Executions (12 mo) |
|---|---|---|---|
| SOC Case Management & Alert Triage | SOC | 13 | ~15,000+ |
| IOC Enrichment & Threat Hunting | SOC | 15 | ~8,200 |
| Threat Intelligence Ingestion & Curation | SOC | 11 | ~2,250 |
| Vulnerability Management Data Lake Pipeline | Vulnerability Mgmt | 35 | ~2,650 |
| Vulnerability Lifecycle, Prioritization & Ticketing | Vulnerability Mgmt | 35 | ~1,450 |
| Employee Offboarding & IAM Response | IAM | 8 | ~1,650 |
| Cloud Asset Coverage & Inventory | Cloud Security | 61 | ~4,273 |
| Identity Response Actions | SOC | 10 | ~600 |
| SaaS App Governance | Cloud Security | 2 | ~40 |
| GRC Reporting | GRC | 3 | ~46 |
| AI Agent Governance & Inventory | Cloud Security | 13 | ~420 |
Use Cases
Use Case 1 — SOC Case Management & Alert Triage
Description: End-to-end automated SOC pipeline that ingests security alerts, extracts and deduplicates observables, runs enrichment, and routes cases through approval workflows. Enables a lean SOC team to handle high alert volumes with consistent, repeatable triage logic.
Business Problem Solved: Security analysts spend the majority of their time on repetitive alert processing tasks. This use case removes that burden by automatically normalizing alerts, extracting indicators, deduplicating cases, running enrichment in parallel, and escalating only when human judgment is genuinely required.
Integrations: Blink Case Management, Microsoft Teams, Blink API
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Case Orchestrator | 3,844 | SOC | Case mgmt & SOAR |
| Observable Orchestrator | 3,843 | SOC | Case mgmt & SOAR |
| Process Alert | 947 | SOC | Case mgmt & SOAR |
| Subflow - Update Observable Findings | 4,154 | SOC | Case mgmt & SOAR |
| Subflow - Update Observable Processing Status | 3,177 | SOC | Case mgmt & SOAR |
| Subflow - Update Case Processing Status | 2,676 | SOC | Case mgmt & SOAR |
| Subflow - Request Response Approval | 14 | SOC | Case mgmt & SOAR |
| Daily Response Approval Polling | 28 | SOC | Case mgmt & SOAR |
| Subflow - Response - Main Router | 211 | SOC | Case mgmt & SOAR |
| Action Subflow - Router | 249 | SOC | Case mgmt & SOAR |
| Process Alert (workspace 49940165) | 124 | SOC | Case mgmt & SOAR |
| Error Handling - Error Notification | 142 | SOC | Case mgmt & SOAR |
| Auto Close Cases from D3 | 11 | SOC | Case mgmt & SOAR |
Use Case 2 — IOC Enrichment & Threat Hunting
Description: Automated enrichment and hunting pipeline for Indicators of Compromise (IOCs). When an observable is identified, Blink routes it to the appropriate enrichment sources and hunting tools, then triggers automated response if a malicious verdict is reached. Covers IPs, domains, hashes, CVEs, and software packages across multiple security products.
Business Problem Solved: Manual IOC lookup and hunting across siloed tools (Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode) is slow and inconsistent. This use case automates the full investigation chain from detection to containment decision.
Integrations: Microsoft Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode, Zscaler ZIA, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Router - Enrich & Hunt Observables | 1,960 | SOC | Alert enrichment / IOC lookup |
| IOC Response Actions | 693 | SOC | Alert enrichment / IOC lookup |
| Hunt - IOC - Microsoft Defender XDR | 392 | SOC | Alert enrichment / IOC lookup |
| Hunt - IOC - SentinelOne | 392 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | 971 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 1,874 | SOC | Alert enrichment / IOC lookup |
| Subflow - Add Hunt Finding Record | 46 | SOC | Alert enrichment / IOC lookup |
| Enrich - IOC - Alienvault OTX | 46 | SOC | Alert enrichment / IOC lookup |
| Hunt - CVE - Blink Vulnerability Management | 154 | SOC | Alert enrichment / IOC lookup |
| Observable Re-hunting | 60 | SOC | Alert enrichment / IOC lookup |
| Hunt - SaaS - Zscaler SSPM | 33 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich User | 14 | SOC | Alert enrichment / IOC lookup |
| Hunt - Extension - SentinelOne | 23 | SOC | Alert enrichment / IOC lookup |
| Hunt - Software - Spektion - Blink Vulnerability Management | 215 | SOC | Alert enrichment / IOC lookup |
| Hunt - Software - Tanium - Blink Vulnerability Management | 201 | SOC | Alert enrichment / IOC lookup |
| Subflow - Attach Bulk Hunt Results to Existing Case | 4 | SOC | Alert enrichment / IOC lookup |
| Response - IOC Response Actions - On-demand | 1 | SOC | Alert enrichment / IOC lookup |
Use Case 3 — Threat Intelligence Ingestion & Curation
Description: Automated ingestion of threat intelligence from multiple sources including CISA RSS feeds, Rapid7 advisories, Wiz GraphQL queries, shared mailbox scanning, and manual webpage ingestion. An AI agent normalizes and structures the raw intelligence into actionable case management records. Weekly reporting delivers consolidated threat landscape summaries to the security team.
Business Problem Solved: Monitoring multiple disparate threat intel feeds manually is time-intensive and inconsistent. This use case ensures no advisory is missed, normalizes heterogeneous formats, and surfaces actionable intelligence automatically to the CTSO team.
Integrations: CISA RSS, Rapid7 RSS, Wiz, Microsoft Outlook, SailPoint
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Ingest - Wiz - GraphQL TI Notification | 1,922 | SOC | Threat intel ingest & curation |
| Subflow - Intelligence Normalization Agent | 125 | SOC | Threat intel ingest & curation, Agentic SOC |
| Ingest - Shared Mailbox - CTSO TI Notification | 12 | SOC | Threat intel ingest & curation |
| Ingest - RSS - CISA TI Notification | 51 | SOC | Threat intel ingest & curation |
| Ingest - RSS - Rapid7 TI Notification | 5 | SOC | Threat intel ingest & curation |
| Ingest - Manual Webpage - TI Notification | 13 | SOC | Threat intel ingest & curation |
| Weekly Threat Intelligence Reporting | 5 | SOC | Threat intel ingest & curation |
| TI Analyst Agent | 5 | SOC | Agentic SOC, Threat intel ingest & curation |
| Response Global Variable Update | 6 | SOC | Threat intel ingest & curation |
| Populate TI Products | 6 | SOC | Threat intel ingest & curation |
| Ingest - Shared Mailbox - BlueVoyant SOC Trends Report | 4 | SOC | Threat intel ingest & curation |
| Ingest - RSS - RSS Ingestion Validation | 40 | SOC | Threat intel ingest & curation |
| Monthly Threat Intelligence Reporting | 1 | SOC | Threat intel ingest & curation |
Use Case 4 — Vulnerability Management Data Lake Pipeline
Description: Enterprise-scale vulnerability data ingestion pipeline that pulls findings from Microsoft Defender, Rapid7 InsightVM, Wiz, and ServiceNow CMDB into an Azure Data Lake Storage (ADLS) / Synapse environment. Supports daily ingestion, cursor-based pagination, data normalization to OCSF schema, KEV/EPSS/NVD dimension tables, and automated phantom purge for stale records. Enables a single source of truth for the VM program across multiple business units and scanner sources.
Business Problem Solved: NIQ runs Defender, Rapid7, and Wiz across separate business units (NIQ and GFK). Without automation, reconciling vulnerability data across scanners and feeding it into a datalake for analytics would require substantial manual engineering work. This pipeline automates the entire ingestion-normalization-enrichment-analytics chain.
Integrations: Microsoft Defender for Endpoints, Rapid7 InsightVM Cloud, Wiz, ServiceNow CMDB, Azure Data Lake Storage / Azure Synapse, CISA KEV, EPSS, NVD
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| ADLS Orch Main | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Defender | 1,348 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Rapid7 | 127 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Wiz | 354 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest CMDB | 4 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Defender | 50 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch R7 | 120 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Wiz | 33 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Wiz Resolved | 4 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch CMDB | 4 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Dim Builder KEV | 40 | Vulnerability Mgmt | Vuln scanning ingest & report, CVE lookup & remediation |
| ADLS Dim Builder EPSS | 40 | Vulnerability Mgmt | Vuln scanning ingest & report, CVE lookup & remediation |
| ADLS Dim Builder NVD | 38 | Vulnerability Mgmt | Vuln scanning ingest & report, CVE lookup & remediation |
| ADLS R7 Vuln Dim Orch | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS R7 Vuln Dim Worker | 127 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Wiz Inactive Asset Tombstone | 30 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Wiz Resolved Rejected Backfill | 56 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Wiz Phantom Orchestrator | 11 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| ADLS Monthly Capture | 1 | Vulnerability Mgmt | Security metrics & reporting |
| Spektion Software Ingestion | 21 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Wiz Tombstone Orchestrator | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| ADLS Wiz Open Snapshot Orchestrator | 28 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Wiz Open Snapshot v2 | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Spektion Software Writer | 65 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Get Defender VM Reccomendations | 22 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Issues Ingestion | 14 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Issue Writer | 98 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Portfolio Metrics Ingestion | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Top Risk Drivers | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Security Scorecard Vuln Ingestion | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Wiz Wide Exposure | 55 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Wiz Wide Exposure | 31 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Defender Delta Ingest | 93 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Defender Delta Orchestrator | 21 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Tanium Software Ingestion | 1 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Tanium Software Writer | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
Use Case 5 — Vulnerability Lifecycle: Prioritization, Ticketing & Reporting
Description: Downstream processing of vulnerability data for SLA evaluation, cross-source asset correlation, remediation candidate generation, Jira ticket assignment, and executive reporting. Includes AI-powered analyst agents for natural language querying of the vulnerability datalake and on-demand CVE search capability.
Business Problem Solved: After ingestion, vulnerability data must be correlated across multiple scanners and business units, enriched with SLA context, prioritized by CVSS/EPSS/KEV, and routed to the right ticket owners. This use case automates that entire chain, ensuring no critical finding sits unowned.
Integrations: Azure Synapse, Jira, Wiz, Rapid7 InsightVM, Microsoft Defender, Blink Case Management, AI Agents
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| WF0 - VM Orchestrator | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| WF1 - VM Source Ingestion & Normalize | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| WF2 - Severity & SLA Evaluation | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF3 - Cross-Source Asset Correlation | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF4 - Correlate & Build Remediation Candidates (ws 06f7470e) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF4 - Correlate & Build Remediation Candidates (ws b76c3ccc) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF5 - Remediation Task Assignment (ws 06f7470e) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF5 - Remediation Task Assignment (ws b76c3ccc) | 1 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF6 - Dashboard Metrics Rollup | 0 | Vulnerability Mgmt | Security metrics & reporting |
| WF7 - VM Reporting (ws 06f7470e) | 0 | Vulnerability Mgmt | Security metrics & reporting |
| WF7 - Remediation Progress Tracking (ws b76c3ccc) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF8 - Software Hunting | 0 | Vulnerability Mgmt | Threat hunting & detection |
| WF9 VM Analyst Agent Ability | 0 | Vulnerability Mgmt | Threat hunting & detection |
| VM Analyst Agent | 2 | Vulnerability Mgmt | Agentic SOC, Threat hunting & detection |
| VM Operator Agent | 0 | Vulnerability Mgmt | Agentic SOC |
| WF - VM Analysis | 0 | Vulnerability Mgmt | Threat hunting & detection |
| WF - Software Analysis | 2 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt - CVE - Blink Vulnerability Management (ws b76c3ccc) | 178 | Vulnerability Mgmt | CVE lookup & remediation |
| Hunt - Software - SentinelOne | 1,044 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt - Software - Wiz | 1,044 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt - Software - Cycode | 1,109 | Vulnerability Mgmt | Threat hunting & detection |
| ADLS CVE Search | 12 | Vulnerability Mgmt | CVE lookup & remediation |
| ADLS Report Builder | 1 | Vulnerability Mgmt | Security metrics & reporting |
| ADLS Report Request | 1 | Vulnerability Mgmt | Security metrics & reporting |
| ADLS SQL Builder Portal | 1 | Vulnerability Mgmt | Threat hunting & detection |
| Ad Hoc Synapse Query | 25 | Vulnerability Mgmt | Threat hunting & detection |
| Entra Email Lookup Orchestrator | 40 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Entra Email Lookup Batch | 3,739 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Entra Email Lookup Worker | 44 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| VM Severity Counts | 0 | Vulnerability Mgmt | Security metrics & reporting |
| Spektion HTML Report Generator | 21 | Vulnerability Mgmt | Security metrics & reporting |
| VM Analyst Agent - Ability - Ask TI Analyst Agent | 5 | Vulnerability Mgmt | Agentic SOC, Threat hunting & detection |
| Hunt - Software - Defender TVM | 215 | Vulnerability Mgmt | Threat hunting & detection |
| Get VM Metrics Tables | 0 | Vulnerability Mgmt | Security metrics & reporting |
| VM Dashboard Metrics Agent | 0 | Vulnerability Mgmt | Agentic SOC, Security metrics & reporting |
| Render & Save VM Dashboard | 0 | Vulnerability Mgmt | Security metrics & reporting |
| ADLS VM KPI Weekly Snapshot | 5 | Vulnerability Mgmt | Security metrics & reporting |
| Hunt - Software - Spektion | 215 | Vulnerability Mgmt | Threat hunting & detection |
| MDVM Recommendations Report Generator | 11 | Vulnerability Mgmt | Security metrics & reporting |
| Get and summarize VM and Risk Metrics | 44 | Vulnerability Mgmt | Agentic SOC, Security metrics & reporting |
| MDVM Patch and Zero-Day Digest | 44 | Vulnerability Mgmt | Security metrics & reporting |
| Spektion Software Report Digest | 44 | Vulnerability Mgmt | Security metrics & reporting |
| VM Metrics Digest | 44 | Vulnerability Mgmt | Security metrics & reporting |
| Wiz SLA Metrics Flow | 40 | Vulnerability Mgmt | Security metrics & reporting |
| Hunt - Software - Tanium | 205 | Vulnerability Mgmt | Threat hunting & detection |
| Wiz External Facing Disposition | 13 | Vulnerability Mgmt | Security metrics & reporting |
| Get AI Software from the Spektion Software table | 22 | Vulnerability Mgmt | Security metrics & reporting |
| Ad Hoc Synapse Query copy | 0 | Vulnerability Mgmt | Threat hunting & detection |
| Defender AD HOC Metrics | 0 | Vulnerability Mgmt | Security metrics & reporting |
| Critical Open Vuln Assets | 12 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| VM KPI Dashboard Refresh | 7 | Vulnerability Mgmt | Security metrics & reporting |
| Wiz Risk Metrics Builder | 0 | Vulnerability Mgmt | Agentic SOC, Security metrics & reporting |
| Rapid7 Vulnerability Instances - FTP Assets | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Security metrics & reporting |
Use Case 6 — Employee Offboarding & IAM Response
Description: Automated offboarding pipeline triggered by SailPoint termination events. Blink processes each departing employee by revoking user sessions, resetting passwords, revoking MFA methods, wiping or unenrolling devices from Intune, and closing the associated case. A scheduled workflow handles edge cases and batches unresolved offboarding events to a downstream ITSM system (D3).
Business Problem Solved: Employee offboarding is a high-risk, time-sensitive IAM process. Missing a device wipe or leaving sessions active post-termination creates significant data leakage exposure. This use case automates the full sequence and provides audit trails for compliance.
Integrations: SailPoint, Microsoft Entra ID, Microsoft Intune, SentinelOne, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Termination Event Ingestion | 961 | IAM | Employee offboarding |
| Response Subflow - Offboarding | 460 | IAM | Employee offboarding |
| Offboarding - Send Batched Edge Case to D3 | 13 | IAM | Employee offboarding |
| Sailpoint Webhook Number 2 (Employee Activations) | 77 | IAM | Employee onboarding, Identity lifecycle automation |
| Offboarding User not found Email | 40 | IAM | Employee offboarding |
| Subflow - Revoke MFA | 314 | IAM | Password & credential lifecycle |
| Enrich - Intune Devices | 970 | IAM | Identity lifecycle automation |
| Enrich - VIP User | 971 | IAM | Identity lifecycle automation |
| Compute Offboarding Metrics | 40 | IAM | Employee offboarding |
Use Case 7 — Identity Threat Response (EDR Containment)
Description: Automated response actions for compromised identities and devices. Covers IOC blocking across Microsoft Defender for Endpoint and SentinelOne, user session revocation and password reset, device isolation and scan initiation, and URL blocking via Zscaler ZIA. All actions are gated through an approval workflow before execution.
Business Problem Solved: When a malicious observable is confirmed, response execution latency is critical. Manual containment across multiple tools (MDE, S1, Zscaler) introduces unacceptable delay. This use case automates the full response chain with human-in-the-loop approval where required.
Integrations: Microsoft Defender for Endpoint, SentinelOne, Microsoft Entra ID, Zscaler ZIA
Use Case 8 — Cloud Asset Coverage & Inventory
Description: Multi-source asset inventory aggregation pipeline that collects device and software inventory from Microsoft Defender, SentinelOne, Wiz, Rapid7, Entra ID, Intune, Zscaler, Jamf, and ServiceNow. Assets are correlated across sources and written to a shared inventory table for vulnerability correlation and coverage gap analysis.
Business Problem Solved: Without a unified asset inventory, vulnerability remediation cannot be accurately scoped. This use case continuously syncs asset records from all deployed security tools and identifies coverage gaps where EDR is missing.
Integrations: Microsoft Defender for Endpoints, SentinelOne, Wiz, Rapid7, Microsoft Entra ID, Intune, Zscaler, Jamf, ServiceNow, Spektion, Microsoft Active Directory
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Asset Ingestion Orchestrator | 8 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Inventory Writer | 3,126 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Defender for Endpoints | 13 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - SentinelOne | 5 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Wiz | 3 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Ingestion Health Writer | 60 | Cloud Security | Cloud asset coverage & inventory |
| Populate Product Connections Global Variable | 5 | Cloud Security | Cloud asset coverage & inventory |
| Wiz Inventory Snapshot | 17 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Coverage HTML Report Generator | 6 | Cloud Security | Cloud asset coverage & inventory |
| User Ingestion Orchestrator | 5 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Users - Microsoft Entra AD | 5 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Inventory Cleanup | 5 | Cloud Security | Cloud asset coverage & inventory |
| ServiceNow CMDB Host Lookup | 7 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Reference Query Table Examples | 3 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Table Schema | 2 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Tables | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - ASM SQL Query | 8 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent | 0 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Refresh Table Views | 9 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Tag Assets | 11 | Cloud Security | Cloud asset coverage & inventory |
| Asset Ingestion Re-processing | 4 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Format Connection List | 8 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Post-Ingestion | 5 | Cloud Security | Cloud asset coverage & inventory |
| Defender Host Lookup | 2 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Active Directory | 0 | Cloud Security | Cloud asset coverage & inventory |
| Query - Device - ASM | 6 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Spektion | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Gather End of Life OS Details | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Metrics Computation | 2 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Post-Ingestion | 3 | Cloud Security | Cloud asset coverage & inventory |
| Scratchpad | 0 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Ingestion Health Writer (new asset pipeline) | 17 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Inventory Writer (new asset pipeline) | 940 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Wiz (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Active Directory (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| ServiceNow CMDB Host Lookup (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Inventory Cleanup (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Coverage HTML Report Generator (new asset pipeline) | 2 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Table Schema (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Asset Ingestion Orchestrator (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Format Connection List (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - SentinelOne (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Zscaler (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Entra AD (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - ServiceNow (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Defender for Endpoint (new asset pipeline) | 2 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Rapid7 InsightVM (new asset pipeline) | 3 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Intune (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Jamf (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Tanium (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Refresh Table Views (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Tag Assets (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - ASM SQL Query (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Users - Microsoft Entra AD (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Query - Device - ASM (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Tables (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| User Ingestion Orchestrator (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Defender Host Lookup (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| On Error Notification (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Reference Query Table Examples (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Utility - ASM Host Lookup | 4 | Cloud Security | Cloud asset coverage & inventory |
Use Case 9 — SaaS Application Governance
Description: Scheduled governance automation that queries Zscaler ZIA for third-party SaaS applications present in the environment, generates compliance views, and feeds findings into a reporting pipeline. Surfaces shadow IT and unauthorized application usage.
Business Problem Solved: Unmanaged SaaS applications represent a data leakage and compliance risk. This use case automates the detection and cataloging of all SaaS applications traversing the network perimeter.
Integrations: Zscaler ZIA, Microsoft Outlook
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Zscaler 3rd Party App Governance - Query Apps Present In Environment (scheduled) | 40 | Cloud Security | Cloud access & SaaS policy mgmt |
| Zscaler 3rd Party App Governance - Query Apps Present In Environment (on-demand) | 0 | Cloud Security | Cloud access & SaaS policy mgmt |
Use Case 10 — GRC & Security Reporting
Description: Automated security metrics and executive reporting workflows including weekly threat intelligence reports and Blink automation reporting. Provides consistent, timely security status updates to stakeholders without manual report assembly.
Business Problem Solved: Preparing security metrics reports manually is error-prone and time-consuming. Automation ensures reports are generated on schedule with up-to-date data from live case management and vulnerability systems.
Integrations: Blink Case Management, Email
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Weekly Threat Intelligence Reporting | 5 | GRC | Security metrics & reporting |
| Unowned Assets Report | 0 | GRC | Security metrics & reporting |
| Monthly Threat Intelligence Reporting | 1 | GRC | Security metrics & reporting |
Use Case 11 — AI Agent Governance & Inventory
Description: A new automation program that discovers, correlates, and monitors AI agents deployed across the enterprise — pulling agent telemetry from Microsoft Defender (Security Copilot / M365 agent activity via Microsoft Graph) and Wiz (cloud-deployed AI agents), reconciling both sources into a unified AI-agent inventory with identity links, and computing governance/risk metrics (exposure, connected hubs, tool/MCP counts, shared-connection risk). Dashboards surface capability analytics and priority governance gaps.
Business Problem Solved: AI agents (Copilot extensions, cloud-hosted agents, MCP-connected tools) are proliferating faster than security teams can track them, creating an ungoverned identity and data-access surface. This use case builds the asset inventory and risk-scoring layer needed to bring AI agents under the same governance rigor as traditional endpoints and cloud resources.
Integrations: Microsoft Defender, Microsoft Graph (M365), Wiz, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Ingest M365 Agent Data | 8 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Chunk Writer | 375 | Cloud Security | Cloud asset coverage & inventory |
| MS Defender AI Agent Reporting Dashboard | 24 | Cloud Security | Cloud asset coverage & inventory |
| Wiz Agent Data Writer | 0 | Cloud Security | Cloud asset coverage & inventory |
| Wiz AI Agent Ingestion | 4 | Cloud Security | Cloud asset coverage & inventory |
| Wiz AI Agent Metrics Dashboard | 1 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Unified Inventory Builder | 0 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Metric Observation Builder | 1 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Unified Metrics Dashboard | 1 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Unified Inventory IO Worker | 1 | Cloud Security | Cloud asset coverage & inventory |
| Get Spektion AI Software from VM Workspace | 1 | Cloud Security | Cloud asset coverage & inventory |
| Defender AI Agent Capability Analytics | 1 | Cloud Security | Config audit & remediation |
| Defender AI Agent Component Metrics Builder | 0 | Cloud Security | Config audit & remediation |
Key Observations
Strengths
Deep, production-grade Vulnerability Management program. NIQ has built one of the most sophisticated VM automation programs in the Blink customer base. The ADLS pipeline ingests vulnerabilities from three scanner families (Defender, Rapid7, Wiz) across multiple business unit instances (NIQ + GFK), normalizes to OCSF, enriches with KEV/EPSS/NVD context, correlates cross-source, and drives Jira remediation ticket creation — all automated. The daily cadence of KEV, EPSS, and NVD dimension builds (38–40 executions each) and Defender/R7/Wiz ingestion runs (127–1,348 executions) demonstrates genuine production reliance.
High-volume SOC automation is operational and running. The Case Orchestrator and Observable Orchestrator together processed nearly 7,700 items in the past 12 months. The enrichment chain (Observable Router → per-tool Hunt subflows → Update Observable Findings at 4,154 executions) is clearly handling real alert volume, not just testing.
Agentic security capabilities are deployed. NIQ has production AI agents for three distinct functions: TI Analyst Agent (threat intelligence interrogation), VM Analyst Agent (natural language vulnerability datalake queries), and a VM Operator Agent with full pipeline tooling. This positions NIQ ahead of most customers in deploying agentic security workflows.
Breadth of integration ecosystem. NIQ's automation spans: Microsoft Defender XDR, SentinelOne, Wiz, Rapid7 InsightVM, Microsoft Entra ID, Microsoft Intune, Zscaler ZIA/SSPM, SailPoint, AlienVault OTX, Cycode, ServiceNow, Jira, Azure Synapse / ADLS, CISA KEV, EPSS, NVD — a mature, enterprise-scale integration footprint.
Cross-business-unit coverage. The VM pipeline explicitly handles both the NIQ and GFK entities with separate scanner connections, reflecting a post-merger integration use case where automation bridges organizational boundaries.
New: AI Agent Governance program stood up. NIQ has launched a dedicated workspace and pipeline (Use Case 11) to inventory and risk-score AI agents across Microsoft Defender/M365 and Wiz — reconciling both sources into a unified inventory, computing exposure and shared-connection risk metrics, and publishing governance dashboards. The AI Agent Chunk Writer alone processed 375 records in its first period, indicating active, ongoing discovery rather than a one-time pilot. This positions NIQ ahead of the curve on a fast-emerging AI-agent attack surface.
New: second asset ingestion pipeline stood up with EOL-OS and metrics capabilities. A new workspace mirrors the core asset-inventory subflows (shared inventory writer, ingestion health writer, cleanup, coverage reporting) and adds two new capabilities not previously present: end-of-life OS detection and asset metrics computation. It also extends source coverage with Spektion and Microsoft Active Directory connectors, and has since added parallel Get-Assets connectors for SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium — effectively rebuilding the full source breadth of the original pipeline within the new architecture. The inventory writer alone processed 940 records, indicating active parallel rollout rather than a dormant fork. The pipeline has since gained its own user-ingestion orchestrator, ASM Analyst Agent abilities, device/host lookup subflows, and error-notification handling — mirroring the original pipeline's full operator toolset, though these newest additions have not yet accrued executions.
VM scanner coverage expanded significantly. Beyond Defender, Rapid7, and Wiz, NIQ has added Spektion, Tanium, and SecurityScorecard as new vulnerability/software-risk data sources, each with its own ingestion, writer, and hunting playbooks already producing meaningful volume (Spektion and Tanium software hunts each running in the 200+ execution range, on par with the original three scanners).
Gaps and Opportunities
Response playbooks built but not yet executing. Several high-value response actions have 0 executions: IOC blocking (Defender for Endpoint, SentinelOne, Zscaler), device isolation (Defender, SentinelOne), and user credential reset (Entra). The approval workflow infrastructure exists and is running (693 IOC response trigger events fired). The gap suggests response is still requiring manual confirmation at a high rate, or the blocking/isolation capabilities are staged for broader rollout. Activating automated response for confirmed malicious IOCs would significantly reduce dwell time.
WF0–WF7 table-based VM pipeline has 0 executions. The older workspace (06f7470e) containing WF0–WF8 workflows shows zero execution across all workflows. All active VM pipeline execution is occurring in the newer workspace (b76c3ccc). The older workspace appears to be a superseded iteration — these playbooks could be archived to reduce maintenance overhead.
User Response Actions workflow has 0 executions. The Response - User Response Actions event-based workflow (which responds to compromised user table records) fired 0 times, while the Device Response Actions workflow fired 14. This asymmetry suggests the user response workflow may not be connected to the active case management tables.
Software CVE hunt executions appear pooled across wrapper playbooks. The Blink VM integration wrapper playbooks (Hunt - Software - SentinelOne - Blink Vulnerability Management, Hunt - Software - Wiz - Blink Vulnerability Management, Hunt - Software - Cycode - Blink Vulnerability Management) each show 1,044 executions — likely the same hunt batch running across all three sources in parallel. The underlying direct hunt playbooks (Hunt - Software - SentinelOne, Hunt - Software - Wiz at 1,044 and Hunt - Software - Cycode at 1,109) show consistent counts, confirming a live software hunt program.
ASM workspace (2a845363) has no active playbooks. The Attack Surface Management workspace contains several drafted workflows (Coverage Gap - Alert and Ticket, Ingestion Health Monitor, ASM Agent) with 0 executions. This appears to be an emerging capability being developed rather than production automation.
Integration Ecosystem Summary
| Tool | Category | Role in Automation |
|---|---|---|
| Microsoft Defender XDR / MDE | EDR / VM | IOC hunting, device containment, vulnerability ingestion |
| SentinelOne | EDR | IOC hunting, device isolation, scan initiation, software inventory |
| Wiz | CSPM / VM | Cloud vulnerability ingestion, SBOM hunting, TI notifications |
| Rapid7 InsightVM Cloud | VM Scanner | Vulnerability ingestion (NIQ + GFK entities) |
| Microsoft Entra ID | IAM | User enrichment, device attribution, MFA revocation, batch lookups |
| Microsoft Intune | MDM | Device enrichment, offboarding device management |
| SailPoint | IAM / HR | Termination and activation event source |
| Zscaler ZIA / SSPM | Network / SaaS | IOC URL blocking, SaaS app governance |
| ServiceNow | CMDB / ITSM | CMDB asset ingestion, ticket routing |
| Jira | Ticketing | Remediation ticket creation and assignment |
| Azure Synapse / ADLS | Data Platform | Vulnerability datalake, SLA metrics, analytics |
| AlienVault OTX | Threat Intel | IOC enrichment |
| Cycode | AppSec / VM | Software CVE hunting |
| CISA KEV / EPSS / NVD | Threat Intel | Vulnerability prioritization dimensions |
| Microsoft Outlook | TI notification ingestion, reporting delivery | |
| Microsoft Teams | Collaboration | Response approval requests |
| Spektion | Software Risk / VM | Software CVE hunting, software risk inventory ingestion |
| Tanium | Endpoint Mgmt / VM | Software CVE hunting, software inventory ingestion |
| SecurityScorecard | Security Ratings / VM | Vulnerability and patching-cadence issue ingestion |
| Microsoft Graph / M365 | AI Agent Governance | AI agent discovery and activity ingestion for governance |
| Microsoft Active Directory | IAM / Asset Inventory | On-prem asset and identity source for inventory |
1. Business KPIs — Last 12 Months
| Metric | Count | Playbook |
|---|---|---|
| Observable findings automatically updated & enriched | 4,154 | Subflow - Update Observable Findings |
| Security cases auto-orchestrated through SOC pipeline | 3,844 | Case Orchestrator |
| Observables automatically triaged & enriched | 3,843 | Observable Orchestrator |
| Entra email batch lookups executed for remediation owners | 3,739 | Entra Email Lookup Batch |
| Asset inventory records written to shared inventory | 3,126 | Subflow - Shared Inventory Writer |
| Asset inventory records written via new asset ingestion pipeline | 940 | Subflow - Shared Inventory Writer (new asset pipeline) |
| Ingestion health records logged for new asset pipeline | 17 | Subflow - Shared Ingestion Health Writer (new asset pipeline) |
| Observable processing status updates | 3,177 | Subflow - Update Observable Processing Status |
| Case processing status updates | 2,676 | Subflow - Update Case Processing Status |
| Wiz threat intelligence notifications ingested | 1,922 | Ingest - Wiz - GraphQL TI Notification |
| Observable enrichment data updated | 1,874 | Subflow - Update Enrichment Data |
| Microsoft Defender vulnerability records ingested to data lake | 1,348 | ADLS Ingest Defender |
| Software CVE hunts executed across SentinelOne | 1,044 | Hunt - Software - SentinelOne |
| Software CVE hunts executed across Wiz | 1,044 | Hunt - Software - Wiz |
| Software CVE hunts executed via Cycode | 1,109 | Hunt - Software - Cycode |
| Employee offboarding workflows processed | 961 | Termination Event Ingestion |
| Security alerts fully processed through SOAR pipeline | 947 | Process Alert |
| VIP user enrichment lookups executed | 971 | Enrich - VIP User |
| Observable enrichment routed automatically | 971 | Subflow - Enrich Observables - Main Router |
| IOC response actions triggered on malicious observables | 693 | Response - IOC Response Actions |
| Hunt findings for IOCs across Microsoft Defender XDR | 392 | Hunt - IOC - Microsoft Defender XDR |
| Hunt findings for IOCs across SentinelOne | 392 | Hunt - IOC - SentinelOne |
| IOC router decisions for enrichment & hunting | 1,960 | Router - Enrich & Hunt Observables |
| Offboarding action sequences completed | 460 | Response Subflow - Offboarding |
| Intune device enrichments executed | 970 | Enrich - Intune Devices |
| Entity response data records updated | 769 | Subflow - Update Response Data |
| Employee activation events logged from SailPoint | 77 | Sailpoint Webhook Number 2 (Employee Activations) |
| Rapid7 vulnerability records ingested to data lake | 127 | ADLS Ingest Rapid7 |
| CVE hunts across Blink Vulnerability Management | 154 | Hunt - CVE - Blink Vulnerability Management |
| Wiz vulnerability records ingested to data lake | 354 | ADLS Ingest Wiz |
| MFA revocation subflow executions | 314 | Subflow - Revoke MFA |
| Response approval requests sent | 211 | Subflow - Response - Main Router |
| Threat intel notifications normalized by AI agent | 125 | Subflow - Intelligence Normalization Agent |
| Zscaler 3rd-party app governance reports generated | 40 | Zscaler 3rd Party App Governance - Query Apps Present In Environment |
| Weekly threat intelligence reports delivered | 5 | Weekly Threat Intelligence Reporting |
| Software CVE hunts executed via Microsoft Defender TVM | 215 | Hunt - Software - Defender TVM |
| Software CVE hunts executed via Spektion | 215 | Hunt - Software - Spektion |
| Software CVE hunts executed via Tanium | 205 | Hunt - Software - Tanium |
| Identity isolation eligibility checks executed for active users | 241 | Subflow - Isolation Logic - KQL for active user |
| AI agent inventory records written to unified AI-agent governance datastore | 375 | AI Agent Chunk Writer |
| Wiz cloud issue records ingested & written | 98 | Wiz Issue Writer |
| Microsoft Defender vulnerability delta records ingested | 93 | Defender Delta Ingest |
| Spektion software inventory records ingested & written | 65 | Spektion Software Writer |
| Wiz wide-exposure vulnerability records ingested to data lake | 55 | ADLS Ingest Wiz Wide Exposure |
| Daily offboarding metrics computed & published | 40 | Compute Offboarding Metrics |
| Microsoft Defender vulnerability recommendations retrieved | 22 | Get Defender VM Reccomendations |
| Extension IOC hunts executed across SentinelOne | 23 | Hunt - Extension - SentinelOne |
| AI agent governance reporting dashboards refreshed | 24 | MS Defender AI Agent Reporting Dashboard |
| Wiz cloud security issues ingested | 14 | Wiz Issues Ingestion |
| Critical open-vulnerability assets tagged for prioritization | 12 | Critical Open Vuln Assets |
| ASM host lookups resolved via ServiceNow CMDB integration | 4 | Utility - ASM Host Lookup |
2. Use Case Summary
| Use Case | Category | Active Playbooks | Total Executions (12 mo) |
|---|---|---|---|
| SOC Case Management & Alert Triage | SOC | 13 | ~15,000+ |
| IOC Enrichment & Threat Hunting | SOC | 15 | ~8,200 |
| Threat Intelligence Ingestion & Curation | SOC | 11 | ~2,250 |
| Vulnerability Management Data Lake Pipeline | Vulnerability Mgmt | 35 | ~2,650 |
| Vulnerability Lifecycle, Prioritization & Ticketing | Vulnerability Mgmt | 35 | ~1,450 |
| Employee Offboarding & IAM Response | IAM | 8 | ~1,650 |
| Cloud Asset Coverage & Inventory | Cloud Security | 61 | ~4,273 |
| Identity Response Actions | SOC | 10 | ~600 |
| SaaS App Governance | Cloud Security | 2 | ~40 |
| GRC Reporting | GRC | 3 | ~46 |
| AI Agent Governance & Inventory | Cloud Security | 13 | ~420 |
3. Use Cases
Use Case 1 — SOC Case Management & Alert Triage
Description: End-to-end automated SOC pipeline that ingests security alerts, extracts and deduplicates observables, runs enrichment, and routes cases through approval workflows. Enables a lean SOC team to handle high alert volumes with consistent, repeatable triage logic.
Business Problem Solved: Security analysts spend the majority of their time on repetitive alert processing tasks. This use case removes that burden by automatically normalizing alerts, extracting indicators, deduplicating cases, running enrichment in parallel, and escalating only when human judgment is genuinely required.
Integrations: Blink Case Management, Microsoft Teams, Blink API
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Case Orchestrator | 3,844 | SOC | Case mgmt & SOAR |
| Observable Orchestrator | 3,843 | SOC | Case mgmt & SOAR |
| Process Alert | 947 | SOC | Case mgmt & SOAR |
| Subflow - Update Observable Findings | 4,154 | SOC | Case mgmt & SOAR |
| Subflow - Update Observable Processing Status | 3,177 | SOC | Case mgmt & SOAR |
| Subflow - Update Case Processing Status | 2,676 | SOC | Case mgmt & SOAR |
| Subflow - Request Response Approval | 14 | SOC | Case mgmt & SOAR |
| Daily Response Approval Polling | 28 | SOC | Case mgmt & SOAR |
| Subflow - Response - Main Router | 211 | SOC | Case mgmt & SOAR |
| Action Subflow - Router | 249 | SOC | Case mgmt & SOAR |
| Process Alert (workspace 49940165) | 124 | SOC | Case mgmt & SOAR |
| Error Handling - Error Notification | 142 | SOC | Case mgmt & SOAR |
| Auto Close Cases from D3 | 11 | SOC | Case mgmt & SOAR |
Use Case 2 — IOC Enrichment & Threat Hunting
Description: Automated enrichment and hunting pipeline for Indicators of Compromise (IOCs). When an observable is identified, Blink routes it to the appropriate enrichment sources and hunting tools, then triggers automated response if a malicious verdict is reached. Covers IPs, domains, hashes, CVEs, and software packages across multiple security products.
Business Problem Solved: Manual IOC lookup and hunting across siloed tools (Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode) is slow and inconsistent. This use case automates the full investigation chain from detection to containment decision.
Integrations: Microsoft Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode, Zscaler ZIA, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Router - Enrich & Hunt Observables | 1,960 | SOC | Alert enrichment / IOC lookup |
| IOC Response Actions | 693 | SOC | Alert enrichment / IOC lookup |
| Hunt - IOC - Microsoft Defender XDR | 392 | SOC | Alert enrichment / IOC lookup |
| Hunt - IOC - SentinelOne | 392 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | 971 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 1,874 | SOC | Alert enrichment / IOC lookup |
| Subflow - Add Hunt Finding Record | 46 | SOC | Alert enrichment / IOC lookup |
| Enrich - IOC - Alienvault OTX | 46 | SOC | Alert enrichment / IOC lookup |
| Hunt - CVE - Blink Vulnerability Management | 154 | SOC | Alert enrichment / IOC lookup |
| Observable Re-hunting | 60 | SOC | Alert enrichment / IOC lookup |
| Hunt - SaaS - Zscaler SSPM | 33 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich User | 14 | SOC | Alert enrichment / IOC lookup |
| Hunt - Extension - SentinelOne | 23 | SOC | Alert enrichment / IOC lookup |
| Hunt - Software - Spektion - Blink Vulnerability Management | 215 | SOC | Alert enrichment / IOC lookup |
| Hunt - Software - Tanium - Blink Vulnerability Management | 201 | SOC | Alert enrichment / IOC lookup |
| Subflow - Attach Bulk Hunt Results to Existing Case | 4 | SOC | Alert enrichment / IOC lookup |
| Response - IOC Response Actions - On-demand | 1 | SOC | Alert enrichment / IOC lookup |
Use Case 3 — Threat Intelligence Ingestion & Curation
Description: Automated ingestion of threat intelligence from multiple sources including CISA RSS feeds, Rapid7 advisories, Wiz GraphQL queries, shared mailbox scanning, and manual webpage ingestion. An AI agent normalizes and structures the raw intelligence into actionable case management records. Weekly reporting delivers consolidated threat landscape summaries to the security team.
Business Problem Solved: Monitoring multiple disparate threat intel feeds manually is time-intensive and inconsistent. This use case ensures no advisory is missed, normalizes heterogeneous formats, and surfaces actionable intelligence automatically to the CTSO team.
Integrations: CISA RSS, Rapid7 RSS, Wiz, Microsoft Outlook, SailPoint
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Ingest - Wiz - GraphQL TI Notification | 1,922 | SOC | Threat intel ingest & curation |
| Subflow - Intelligence Normalization Agent | 125 | SOC | Threat intel ingest & curation, Agentic SOC |
| Ingest - Shared Mailbox - CTSO TI Notification | 12 | SOC | Threat intel ingest & curation |
| Ingest - RSS - CISA TI Notification | 51 | SOC | Threat intel ingest & curation |
| Ingest - RSS - Rapid7 TI Notification | 5 | SOC | Threat intel ingest & curation |
| Ingest - Manual Webpage - TI Notification | 13 | SOC | Threat intel ingest & curation |
| Weekly Threat Intelligence Reporting | 5 | SOC | Threat intel ingest & curation |
| TI Analyst Agent | 5 | SOC | Agentic SOC, Threat intel ingest & curation |
| Response Global Variable Update | 6 | SOC | Threat intel ingest & curation |
| Populate TI Products | 6 | SOC | Threat intel ingest & curation |
| Ingest - Shared Mailbox - BlueVoyant SOC Trends Report | 4 | SOC | Threat intel ingest & curation |
| Ingest - RSS - RSS Ingestion Validation | 40 | SOC | Threat intel ingest & curation |
| Monthly Threat Intelligence Reporting | 1 | SOC | Threat intel ingest & curation |
Use Case 4 — Vulnerability Management Data Lake Pipeline
Description: Enterprise-scale vulnerability data ingestion pipeline that pulls findings from Microsoft Defender, Rapid7 InsightVM, Wiz, and ServiceNow CMDB into an Azure Data Lake Storage (ADLS) / Synapse environment. Supports daily ingestion, cursor-based pagination, data normalization to OCSF schema, KEV/EPSS/NVD dimension tables, and automated phantom purge for stale records. Enables a single source of truth for the VM program across multiple business units and scanner sources.
Business Problem Solved: NIQ runs Defender, Rapid7, and Wiz across separate business units (NIQ and GFK). Without automation, reconciling vulnerability data across scanners and feeding it into a datalake for analytics would require substantial manual engineering work. This pipeline automates the entire ingestion-normalization-enrichment-analytics chain.
Integrations: Microsoft Defender for Endpoints, Rapid7 InsightVM Cloud, Wiz, ServiceNow CMDB, Azure Data Lake Storage / Azure Synapse, CISA KEV, EPSS, NVD
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| ADLS Orch Main | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Defender | 1,348 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Rapid7 | 127 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Wiz | 354 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest CMDB | 4 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Defender | 50 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch R7 | 120 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Wiz | 33 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Wiz Resolved | 4 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch CMDB | 4 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Dim Builder KEV | 40 | Vulnerability Mgmt | Vuln scanning ingest & report, CVE lookup & remediation |
| ADLS Dim Builder EPSS | 40 | Vulnerability Mgmt | Vuln scanning ingest & report, CVE lookup & remediation |
| ADLS Dim Builder NVD | 38 | Vulnerability Mgmt | Vuln scanning ingest & report, CVE lookup & remediation |
| ADLS R7 Vuln Dim Orch | 40 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS R7 Vuln Dim Worker | 127 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Wiz Inactive Asset Tombstone | 30 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Wiz Resolved Rejected Backfill | 56 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Wiz Phantom Orchestrator | 11 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| ADLS Monthly Capture | 1 | Vulnerability Mgmt | Security metrics & reporting |
| Spektion Software Ingestion | 21 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Wiz Tombstone Orchestrator | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| ADLS Wiz Open Snapshot Orchestrator | 28 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Wiz Open Snapshot v2 | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Spektion Software Writer | 65 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Get Defender VM Reccomendations | 22 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Issues Ingestion | 14 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Issue Writer | 98 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Portfolio Metrics Ingestion | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Wiz Top Risk Drivers | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Security Scorecard Vuln Ingestion | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Ingest Wiz Wide Exposure | 55 | Vulnerability Mgmt | Vuln scanning ingest & report |
| ADLS Orch Wiz Wide Exposure | 31 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Defender Delta Ingest | 93 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Defender Delta Orchestrator | 21 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Tanium Software Ingestion | 1 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Tanium Software Writer | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
Use Case 5 — Vulnerability Lifecycle: Prioritization, Ticketing & Reporting
Description: Downstream processing of vulnerability data for SLA evaluation, cross-source asset correlation, remediation candidate generation, Jira ticket assignment, and executive reporting. Includes AI-powered analyst agents for natural language querying of the vulnerability datalake and on-demand CVE search capability.
Business Problem Solved: After ingestion, vulnerability data must be correlated across multiple scanners and business units, enriched with SLA context, prioritized by CVSS/EPSS/KEV, and routed to the right ticket owners. This use case automates that entire chain, ensuring no critical finding sits unowned.
Integrations: Azure Synapse, Jira, Wiz, Rapid7 InsightVM, Microsoft Defender, Blink Case Management, AI Agents
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| WF0 - VM Orchestrator | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| WF1 - VM Source Ingestion & Normalize | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| WF2 - Severity & SLA Evaluation | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF3 - Cross-Source Asset Correlation | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF4 - Correlate & Build Remediation Candidates (ws 06f7470e) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF4 - Correlate & Build Remediation Candidates (ws b76c3ccc) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF5 - Remediation Task Assignment (ws 06f7470e) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF5 - Remediation Task Assignment (ws b76c3ccc) | 1 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF6 - Dashboard Metrics Rollup | 0 | Vulnerability Mgmt | Security metrics & reporting |
| WF7 - VM Reporting (ws 06f7470e) | 0 | Vulnerability Mgmt | Security metrics & reporting |
| WF7 - Remediation Progress Tracking (ws b76c3ccc) | 0 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| WF8 - Software Hunting | 0 | Vulnerability Mgmt | Threat hunting & detection |
| WF9 VM Analyst Agent Ability | 0 | Vulnerability Mgmt | Threat hunting & detection |
| VM Analyst Agent | 2 | Vulnerability Mgmt | Agentic SOC, Threat hunting & detection |
| VM Operator Agent | 0 | Vulnerability Mgmt | Agentic SOC |
| WF - VM Analysis | 0 | Vulnerability Mgmt | Threat hunting & detection |
| WF - Software Analysis | 2 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt - CVE - Blink Vulnerability Management (ws b76c3ccc) | 178 | Vulnerability Mgmt | CVE lookup & remediation |
| Hunt - Software - SentinelOne | 1,044 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt - Software - Wiz | 1,044 | Vulnerability Mgmt | Threat hunting & detection |
| Hunt - Software - Cycode | 1,109 | Vulnerability Mgmt | Threat hunting & detection |
| ADLS CVE Search | 12 | Vulnerability Mgmt | CVE lookup & remediation |
| ADLS Report Builder | 1 | Vulnerability Mgmt | Security metrics & reporting |
| ADLS Report Request | 1 | Vulnerability Mgmt | Security metrics & reporting |
| ADLS SQL Builder Portal | 1 | Vulnerability Mgmt | Threat hunting & detection |
| Ad Hoc Synapse Query | 25 | Vulnerability Mgmt | Threat hunting & detection |
| Entra Email Lookup Orchestrator | 40 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Entra Email Lookup Batch | 3,739 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Entra Email Lookup Worker | 44 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| VM Severity Counts | 0 | Vulnerability Mgmt | Security metrics & reporting |
| Spektion HTML Report Generator | 21 | Vulnerability Mgmt | Security metrics & reporting |
| VM Analyst Agent - Ability - Ask TI Analyst Agent | 5 | Vulnerability Mgmt | Agentic SOC, Threat hunting & detection |
| Hunt - Software - Defender TVM | 215 | Vulnerability Mgmt | Threat hunting & detection |
| Get VM Metrics Tables | 0 | Vulnerability Mgmt | Security metrics & reporting |
| VM Dashboard Metrics Agent | 0 | Vulnerability Mgmt | Agentic SOC, Security metrics & reporting |
| Render & Save VM Dashboard | 0 | Vulnerability Mgmt | Security metrics & reporting |
| ADLS VM KPI Weekly Snapshot | 5 | Vulnerability Mgmt | Security metrics & reporting |
| Hunt - Software - Spektion | 215 | Vulnerability Mgmt | Threat hunting & detection |
| MDVM Recommendations Report Generator | 11 | Vulnerability Mgmt | Security metrics & reporting |
| Get and summarize VM and Risk Metrics | 44 | Vulnerability Mgmt | Agentic SOC, Security metrics & reporting |
| MDVM Patch and Zero-Day Digest | 44 | Vulnerability Mgmt | Security metrics & reporting |
| Spektion Software Report Digest | 44 | Vulnerability Mgmt | Security metrics & reporting |
| VM Metrics Digest | 44 | Vulnerability Mgmt | Security metrics & reporting |
| Wiz SLA Metrics Flow | 40 | Vulnerability Mgmt | Security metrics & reporting |
| Hunt - Software - Tanium | 205 | Vulnerability Mgmt | Threat hunting & detection |
| Wiz External Facing Disposition | 13 | Vulnerability Mgmt | Security metrics & reporting |
| Get AI Software from the Spektion Software table | 22 | Vulnerability Mgmt | Security metrics & reporting |
| Ad Hoc Synapse Query copy | 0 | Vulnerability Mgmt | Threat hunting & detection |
| Defender AD HOC Metrics | 0 | Vulnerability Mgmt | Security metrics & reporting |
| Critical Open Vuln Assets | 12 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| VM KPI Dashboard Refresh | 7 | Vulnerability Mgmt | Security metrics & reporting |
| Wiz Risk Metrics Builder | 0 | Vulnerability Mgmt | Agentic SOC, Security metrics & reporting |
| Rapid7 Vulnerability Instances - FTP Assets | 0 | Vulnerability Mgmt | Vuln scanning ingest & report, Security metrics & reporting |
Use Case 6 — Employee Offboarding & IAM Response
Description: Automated offboarding pipeline triggered by SailPoint termination events. Blink processes each departing employee by revoking user sessions, resetting passwords, revoking MFA methods, wiping or unenrolling devices from Intune, and closing the associated case. A scheduled workflow handles edge cases and batches unresolved offboarding events to a downstream ITSM system (D3).
Business Problem Solved: Employee offboarding is a high-risk, time-sensitive IAM process. Missing a device wipe or leaving sessions active post-termination creates significant data leakage exposure. This use case automates the full sequence and provides audit trails for compliance.
Integrations: SailPoint, Microsoft Entra ID, Microsoft Intune, SentinelOne, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Termination Event Ingestion | 961 | IAM | Employee offboarding |
| Response Subflow - Offboarding | 460 | IAM | Employee offboarding |
| Offboarding - Send Batched Edge Case to D3 | 13 | IAM | Employee offboarding |
| Sailpoint Webhook Number 2 (Employee Activations) | 77 | IAM | Employee onboarding, Identity lifecycle automation |
| Offboarding User not found Email | 40 | IAM | Employee offboarding |
| Subflow - Revoke MFA | 314 | IAM | Password & credential lifecycle |
| Enrich - Intune Devices | 970 | IAM | Identity lifecycle automation |
| Enrich - VIP User | 971 | IAM | Identity lifecycle automation |
| Compute Offboarding Metrics | 40 | IAM | Employee offboarding |
Use Case 7 — Identity Threat Response (EDR Containment)
Description: Automated response actions for compromised identities and devices. Covers IOC blocking across Microsoft Defender for Endpoint and SentinelOne, user session revocation and password reset, device isolation and scan initiation, and URL blocking via Zscaler ZIA. All actions are gated through an approval workflow before execution.
Business Problem Solved: When a malicious observable is confirmed, response execution latency is critical. Manual containment across multiple tools (MDE, S1, Zscaler) introduces unacceptable delay. This use case automates the full response chain with human-in-the-loop approval where required.
Integrations: Microsoft Defender for Endpoint, SentinelOne, Microsoft Entra ID, Zscaler ZIA
Use Case 8 — Cloud Asset Coverage & Inventory
Description: Multi-source asset inventory aggregation pipeline that collects device and software inventory from Microsoft Defender, SentinelOne, Wiz, Rapid7, Entra ID, Intune, Zscaler, Jamf, and ServiceNow. Assets are correlated across sources and written to a shared inventory table for vulnerability correlation and coverage gap analysis.
Business Problem Solved: Without a unified asset inventory, vulnerability remediation cannot be accurately scoped. This use case continuously syncs asset records from all deployed security tools and identifies coverage gaps where EDR is missing.
Integrations: Microsoft Defender for Endpoints, SentinelOne, Wiz, Rapid7, Microsoft Entra ID, Intune, Zscaler, Jamf, ServiceNow, Spektion, Microsoft Active Directory
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Asset Ingestion Orchestrator | 8 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Inventory Writer | 3,126 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Defender for Endpoints | 13 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - SentinelOne | 5 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Wiz | 3 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Ingestion Health Writer | 60 | Cloud Security | Cloud asset coverage & inventory |
| Populate Product Connections Global Variable | 5 | Cloud Security | Cloud asset coverage & inventory |
| Wiz Inventory Snapshot | 17 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Coverage HTML Report Generator | 6 | Cloud Security | Cloud asset coverage & inventory |
| User Ingestion Orchestrator | 5 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Users - Microsoft Entra AD | 5 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Inventory Cleanup | 5 | Cloud Security | Cloud asset coverage & inventory |
| ServiceNow CMDB Host Lookup | 7 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Reference Query Table Examples | 3 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Table Schema | 2 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Tables | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - ASM SQL Query | 8 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent | 0 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Refresh Table Views | 9 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Tag Assets | 11 | Cloud Security | Cloud asset coverage & inventory |
| Asset Ingestion Re-processing | 4 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Format Connection List | 8 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Post-Ingestion | 5 | Cloud Security | Cloud asset coverage & inventory |
| Defender Host Lookup | 2 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Active Directory | 0 | Cloud Security | Cloud asset coverage & inventory |
| Query - Device - ASM | 6 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Spektion | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Gather End of Life OS Details | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Metrics Computation | 2 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Post-Ingestion | 3 | Cloud Security | Cloud asset coverage & inventory |
| Scratchpad | 0 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Ingestion Health Writer (new asset pipeline) | 17 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Shared Inventory Writer (new asset pipeline) | 940 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Wiz (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Active Directory (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| ServiceNow CMDB Host Lookup (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Inventory Cleanup (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Asset Coverage HTML Report Generator (new asset pipeline) | 2 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Table Schema (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Asset Ingestion Orchestrator (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Format Connection List (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - SentinelOne (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Zscaler (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Entra AD (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - ServiceNow (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Microsoft Defender for Endpoint (new asset pipeline) | 2 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Rapid7 InsightVM (new asset pipeline) | 3 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Intune (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Jamf (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Assets - Tanium (new asset pipeline) | 1 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Refresh Table Views (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Utility - Tag Assets (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - ASM SQL Query (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Subflow - Get Users - Microsoft Entra AD (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Query - Device - ASM (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Get ASM Tables (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| User Ingestion Orchestrator (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Defender Host Lookup (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| On Error Notification (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| ASM Analyst Agent - Ability - Reference Query Table Examples (new asset pipeline) | 0 | Cloud Security | Cloud asset coverage & inventory |
| Utility - ASM Host Lookup | 4 | Cloud Security | Cloud asset coverage & inventory |
Use Case 9 — SaaS Application Governance
Description: Scheduled governance automation that queries Zscaler ZIA for third-party SaaS applications present in the environment, generates compliance views, and feeds findings into a reporting pipeline. Surfaces shadow IT and unauthorized application usage.
Business Problem Solved: Unmanaged SaaS applications represent a data leakage and compliance risk. This use case automates the detection and cataloging of all SaaS applications traversing the network perimeter.
Integrations: Zscaler ZIA, Microsoft Outlook
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Zscaler 3rd Party App Governance - Query Apps Present In Environment (scheduled) | 40 | Cloud Security | Cloud access & SaaS policy mgmt |
| Zscaler 3rd Party App Governance - Query Apps Present In Environment (on-demand) | 0 | Cloud Security | Cloud access & SaaS policy mgmt |
Use Case 10 — GRC & Security Reporting
Description: Automated security metrics and executive reporting workflows including weekly threat intelligence reports and Blink automation reporting. Provides consistent, timely security status updates to stakeholders without manual report assembly.
Business Problem Solved: Preparing security metrics reports manually is error-prone and time-consuming. Automation ensures reports are generated on schedule with up-to-date data from live case management and vulnerability systems.
Integrations: Blink Case Management, Email
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Weekly Threat Intelligence Reporting | 5 | GRC | Security metrics & reporting |
| Unowned Assets Report | 0 | GRC | Security metrics & reporting |
| Monthly Threat Intelligence Reporting | 1 | GRC | Security metrics & reporting |
Use Case 11 — AI Agent Governance & Inventory
Description: A new automation program that discovers, correlates, and monitors AI agents deployed across the enterprise — pulling agent telemetry from Microsoft Defender (Security Copilot / M365 agent activity via Microsoft Graph) and Wiz (cloud-deployed AI agents), reconciling both sources into a unified AI-agent inventory with identity links, and computing governance/risk metrics (exposure, connected hubs, tool/MCP counts, shared-connection risk). Dashboards surface capability analytics and priority governance gaps.
Business Problem Solved: AI agents (Copilot extensions, cloud-hosted agents, MCP-connected tools) are proliferating faster than security teams can track them, creating an ungoverned identity and data-access surface. This use case builds the asset inventory and risk-scoring layer needed to bring AI agents under the same governance rigor as traditional endpoints and cloud resources.
Integrations: Microsoft Defender, Microsoft Graph (M365), Wiz, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|
| Ingest M365 Agent Data | 8 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Chunk Writer | 375 | Cloud Security | Cloud asset coverage & inventory |
| MS Defender AI Agent Reporting Dashboard | 24 | Cloud Security | Cloud asset coverage & inventory |
| Wiz Agent Data Writer | 0 | Cloud Security | Cloud asset coverage & inventory |
| Wiz AI Agent Ingestion | 4 | Cloud Security | Cloud asset coverage & inventory |
| Wiz AI Agent Metrics Dashboard | 1 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Unified Inventory Builder | 0 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Metric Observation Builder | 1 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Unified Metrics Dashboard | 1 | Cloud Security | Cloud asset coverage & inventory |
| AI Agent Unified Inventory IO Worker | 1 | Cloud Security | Cloud asset coverage & inventory |
| Get Spektion AI Software from VM Workspace | 1 | Cloud Security | Cloud asset coverage & inventory |
| Defender AI Agent Capability Analytics | 1 | Cloud Security | Config audit & remediation |
| Defender AI Agent Component Metrics Builder | 0 | Cloud Security | Config audit & remediation |
4. Key Observations
Strengths
Deep, production-grade Vulnerability Management program. NIQ has built one of the most sophisticated VM automation programs in the Blink customer base. The ADLS pipeline ingests vulnerabilities from three scanner families (Defender, Rapid7, Wiz) across multiple business unit instances (NIQ + GFK), normalizes to OCSF, enriches with KEV/EPSS/NVD context, correlates cross-source, and drives Jira remediation ticket creation — all automated. The daily cadence of KEV, EPSS, and NVD dimension builds (38–40 executions each) and Defender/R7/Wiz ingestion runs (127–1,348 executions) demonstrates genuine production reliance.
High-volume SOC automation is operational and running. The Case Orchestrator and Observable Orchestrator together processed nearly 7,700 items in the past 12 months. The enrichment chain (Observable Router → per-tool Hunt subflows → Update Observable Findings at 4,154 executions) is clearly handling real alert volume, not just testing.
Agentic security capabilities are deployed. NIQ has production AI agents for three distinct functions: TI Analyst Agent (threat intelligence interrogation), VM Analyst Agent (natural language vulnerability datalake queries), and a VM Operator Agent with full pipeline tooling. This positions NIQ ahead of most customers in deploying agentic security workflows.
Breadth of integration ecosystem. NIQ's automation spans: Microsoft Defender XDR, SentinelOne, Wiz, Rapid7 InsightVM, Microsoft Entra ID, Microsoft Intune, Zscaler ZIA/SSPM, SailPoint, AlienVault OTX, Cycode, ServiceNow, Jira, Azure Synapse / ADLS, CISA KEV, EPSS, NVD — a mature, enterprise-scale integration footprint.
Cross-business-unit coverage. The VM pipeline explicitly handles both the NIQ and GFK entities with separate scanner connections, reflecting a post-merger integration use case where automation bridges organizational boundaries.
New: AI Agent Governance program stood up. NIQ has launched a dedicated workspace and pipeline (Use Case 11) to inventory and risk-score AI agents across Microsoft Defender/M365 and Wiz — reconciling both sources into a unified inventory, computing exposure and shared-connection risk metrics, and publishing governance dashboards. The AI Agent Chunk Writer alone processed 375 records in its first period, indicating active, ongoing discovery rather than a one-time pilot. This positions NIQ ahead of the curve on a fast-emerging AI-agent attack surface.
New: second asset ingestion pipeline stood up with EOL-OS and metrics capabilities. A new workspace mirrors the core asset-inventory subflows (shared inventory writer, ingestion health writer, cleanup, coverage reporting) and adds two new capabilities not previously present: end-of-life OS detection and asset metrics computation. It also extends source coverage with Spektion and Microsoft Active Directory connectors, and has since added parallel Get-Assets connectors for SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium — effectively rebuilding the full source breadth of the original pipeline within the new architecture. The inventory writer alone processed 940 records, indicating active parallel rollout rather than a dormant fork. The pipeline has since gained its own user-ingestion orchestrator, ASM Analyst Agent abilities, device/host lookup subflows, and error-notification handling — mirroring the original pipeline's full operator toolset, though these newest additions have not yet accrued executions.
VM scanner coverage expanded significantly. Beyond Defender, Rapid7, and Wiz, NIQ has added Spektion, Tanium, and SecurityScorecard as new vulnerability/software-risk data sources, each with its own ingestion, writer, and hunting playbooks already producing meaningful volume (Spektion and Tanium software hunts each running in the 200+ execution range, on par with the original three scanners).
Gaps and Opportunities
Response playbooks built but not yet executing. Several high-value response actions have 0 executions: IOC blocking (Defender for Endpoint, SentinelOne, Zscaler), device isolation (Defender, SentinelOne), and user credential reset (Entra). The approval workflow infrastructure exists and is running (693 IOC response trigger events fired). The gap suggests response is still requiring manual confirmation at a high rate, or the blocking/isolation capabilities are staged for broader rollout. Activating automated response for confirmed malicious IOCs would significantly reduce dwell time.
WF0–WF7 table-based VM pipeline has 0 executions. The older workspace (06f7470e) containing WF0–WF8 workflows shows zero execution across all workflows. All active VM pipeline execution is occurring in the newer workspace (b76c3ccc). The older workspace appears to be a superseded iteration — these playbooks could be archived to reduce maintenance overhead.
User Response Actions workflow has 0 executions. The Response - User Response Actions event-based workflow (which responds to compromised user table records) fired 0 times, while the Device Response Actions workflow fired 14. This asymmetry suggests the user response workflow may not be connected to the active case management tables.
Software CVE hunt executions appear pooled across wrapper playbooks. The Blink VM integration wrapper playbooks (Hunt - Software - SentinelOne - Blink Vulnerability Management, Hunt - Software - Wiz - Blink Vulnerability Management, Hunt - Software - Cycode - Blink Vulnerability Management) each show 1,044 executions — likely the same hunt batch running across all three sources in parallel. The underlying direct hunt playbooks (Hunt - Software - SentinelOne, Hunt - Software - Wiz at 1,044 and Hunt - Software - Cycode at 1,109) show consistent counts, confirming a live software hunt program.
ASM workspace (2a845363) has no active playbooks. The Attack Surface Management workspace contains several drafted workflows (Coverage Gap - Alert and Ticket, Ingestion Health Monitor, ASM Agent) with 0 executions. This appears to be an emerging capability being developed rather than production automation.
Integration Ecosystem Summary
| Tool | Category | Role in Automation |
|---|---|---|
| Microsoft Defender XDR / MDE | EDR / VM | IOC hunting, device containment, vulnerability ingestion |
| SentinelOne | EDR | IOC hunting, device isolation, scan initiation, software inventory |
| Wiz | CSPM / VM | Cloud vulnerability ingestion, SBOM hunting, TI notifications |
| Rapid7 InsightVM Cloud | VM Scanner | Vulnerability ingestion (NIQ + GFK entities) |
| Microsoft Entra ID | IAM | User enrichment, device attribution, MFA revocation, batch lookups |
| Microsoft Intune | MDM | Device enrichment, offboarding device management |
| SailPoint | IAM / HR | Termination and activation event source |
| Zscaler ZIA / SSPM | Network / SaaS | IOC URL blocking, SaaS app governance |
| ServiceNow | CMDB / ITSM | CMDB asset ingestion, ticket routing |
| Jira | Ticketing | Remediation ticket creation and assignment |
| Azure Synapse / ADLS | Data Platform | Vulnerability datalake, SLA metrics, analytics |
| AlienVault OTX | Threat Intel | IOC enrichment |
| Cycode | AppSec / VM | Software CVE hunting |
| CISA KEV / EPSS / NVD | Threat Intel | Vulnerability prioritization dimensions |
| Microsoft Outlook | TI notification ingestion, reporting delivery | |
| Microsoft Teams | Collaboration | Response approval requests |
| Spektion | Software Risk / VM | Software CVE hunting, software risk inventory ingestion |
| Tanium | Endpoint Mgmt / VM | Software CVE hunting, software inventory ingestion |
| SecurityScorecard | Security Ratings / VM | Vulnerability and patching-cadence issue ingestion |
| Microsoft Graph / M365 | AI Agent Governance | AI agent discovery and activity ingestion for governance |
| Microsoft Active Directory | IAM / Asset Inventory | On-prem asset and identity source for inventory |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| NIQ | winrm | winrm_connection | 2026-08-11 |