Blink Security Automation — Confidential

NIQ — Customer Success Report

Generated 2026-09-10 | niq-value-report.md
2026-09-10Report Date
449Total Playbooks
317Unique Workflows (12m)
4,248,581Actions Automated (12m)
$1,092,742Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

449
Total playbooks built
all non-deleted workflows
313
Active playbooks
currently enabled
317
Unique workflows executed (12m)
distinct workflows that ran
4,248,581
Actions automated (12m)
completed action steps
23,603.2h
Hours saved (12m)
@ 20s per action
$1,092,742
Money saved (12m)
@ $100K avg salary
52
New active workflows (last 30d)
recently created & enabled
3,974
Total cases managed
3,974 opened in last 12m
3d 16h
MTTR — mean time to resolve
closed cases, last 12m
16
Active AI agents
of 29 total
1,502
AI agent tasks executed (12m)
257 in last 30d
In the last 12 months, Blink automated: - 7,687 security cases and observables auto-orchestrated through the SOC pipeline without analyst intervention - 6,053 IOC enrichments, hunts, and response actions executed across Microsoft Defender XDR, SentinelOne, and Wiz - 3,767 software CVE hunts performed across SentinelOne, Wiz, Cycode, Microsoft Defender TVM, Spektion, and Tanium - 1,922 Wiz threat intelligence notifications automatically ingested and processed - 1,977 vulnerability records continuously ingested from Defender, Rapid7, and Wiz into the enterprise data lake - 961 employee termination events automatically processed end-to-end - 940 VIP user enrichments and Intune device enrichments executed automatically - 417 AI agent governance actions executed — a new unified inventory, ingestion, and risk-metrics program spanning Microsoft Defender, M365 Graph, and Wiz AI-agent telemetry - 246 identity isolation eligibility checks and weekly isolation-rate calculations computed for EDR containment decisions - 940 asset inventory records processed through a newly stood-up second asset ingestion pipeline — now expanded with SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium connectors (alongside the original Spektion and Active Directory sources) plus new EOL-OS tracking and asset metrics computation

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1 — SOC Case Management & Alert Triage15,009 executions
29.2%
11
11 active
Use Case 2 — IOC Enrichment & Threat Hunting7,108 executions
13.8%
15
15 active
Use Case 3 — Threat Intelligence Ingestion & Curation2,182 executions
4.3%
11
11 active
Use Case 4 — Vulnerability Management Data Lake Pipeline2,633 executions
5.1%
35
34 active
Use Case 5 — Vulnerability Lifecycle: Prioritization, Ticketing & Reporting1,721 executions
3.4%
39
38 active
Use Case 6 — Employee Offboarding & IAM Response5,652 executions
11.0%
9
9 active
Use Case 7 — Identity Threat Response (EDR Containment)885 executions
1.7%
14
14 active
Use Case 8 — Cloud Asset Coverage & Inventory6,807 executions
13.3%
30
29 active
Use Case 9 — SaaS Application Governance0 executions
0.0%
0
0 active
Use Case 10 — GRC & Security Reporting7 executions
0.0%
3
3 active
Use Case 11 — AI Agent Governance & Inventory432 executions
0.8%
13
1 active
Total42,436 executions100%
180
165 active

Use Case Growth Over Time

369 unique playbooks  |  10 operational use cases  |  51,330 total executions (12m)  |  1970-01 to 2026-09
Toggle:
Toggle:

03Integration Ecosystem

Use Case 8 — Cloud Asset Coverage & Inventory
Agents Wiz SentinelOne ServiceNow Spektion Dashboards Microsoft Entra ID Microsoft Defender for Endpoint
Use Case 2 — IOC Enrichment & Threat Hunting
Microsoft Entra ID AlienVault OTX Microsoft Defender XDR Microsoft Defender for Endpoint SentinelOne Agents
Use Case 1 — SOC Case Management & Alert Triage
Email Microsoft Teams Agents
Use Case 7 — Identity Threat Response (EDR Containment)
Microsoft Defender for Endpoint Microsoft Intune Microsoft Entra ID SentinelOne Zscaler Internet Access Microsoft Defender XDR
Use Case 5 — Vulnerability Lifecycle: Prioritization, Ticketing & Reporting
Wiz Rapid7 InsightVM Cloud Microsoft Defender For Endpoints SentinelOne Microsoft Entra ID Agents Email Cycode Dashboards Microsoft Defender XDR Tanium
Use Case 3 — Threat Intelligence Ingestion & Curation
Agents Wiz Microsoft Outlook RSS
Use Case 6 — Employee Offboarding & IAM Response
Email Microsoft Entra ID Microsoft Intune Microsoft Defender for Endpoint Dashboards
Use Case 10 — GRC & Security Reporting
Email Dashboards
Use Case 4 — Vulnerability Management Data Lake Pipeline
Microsoft Defender for Endpoint Rapid7 InsightVM Cloud Wiz ServiceNow Spektion SecurityScorecard Tanium
Use Case 11 — AI Agent Governance & Inventory
Microsoft Graph Dashboards Wiz

04Key Observations

✓  Strengths

Strengths

Deep, production-grade Vulnerability Management program. NIQ has built one of the most sophisticated VM automation programs in the Blink customer base. The ADLS pipeline ingests vulnerabilities from three scanner families (Defender, Rapid7, Wiz) across multiple business unit instances (NIQ + GFK), normalizes to OCSF, enriches with KEV/EPSS/NVD context, correlates cross-source, and drives Jira remediation ticket creation — all automated. The daily cadence of KEV, EPSS, and NVD dimension builds (38–40 executions each) and Defender/R7/Wiz ingestion runs (127–1,348 executions) demonstrates genuine production reliance.

High-volume SOC automation is operational and running. The Case Orchestrator and Observable Orchestrator together processed nearly 7,700 items in the past 12 months. The enrichment chain (Observable Router → per-tool Hunt subflows → Update Observable Findings at 4,154 executions) is clearly handling real alert volume, not just testing.

Agentic security capabilities are deployed. NIQ has production AI agents for three distinct functions: TI Analyst Agent (threat intelligence interrogation), VM Analyst Agent (natural language vulnerability datalake queries), and a VM Operator Agent with full pipeline tooling. This positions NIQ ahead of most customers in deploying agentic security workflows.

Breadth of integration ecosystem. NIQ's automation spans: Microsoft Defender XDR, SentinelOne, Wiz, Rapid7 InsightVM, Microsoft Entra ID, Microsoft Intune, Zscaler ZIA/SSPM, SailPoint, AlienVault OTX, Cycode, ServiceNow, Jira, Azure Synapse / ADLS, CISA KEV, EPSS, NVD — a mature, enterprise-scale integration footprint.

Cross-business-unit coverage. The VM pipeline explicitly handles both the NIQ and GFK entities with separate scanner connections, reflecting a post-merger integration use case where automation bridges organizational boundaries.

New: AI Agent Governance program stood up. NIQ has launched a dedicated workspace and pipeline (Use Case 11) to inventory and risk-score AI agents across Microsoft Defender/M365 and Wiz — reconciling both sources into a unified inventory, computing exposure and shared-connection risk metrics, and publishing governance dashboards. The AI Agent Chunk Writer alone processed 375 records in its first period, indicating active, ongoing discovery rather than a one-time pilot. This positions NIQ ahead of the curve on a fast-emerging AI-agent attack surface.

New: second asset ingestion pipeline stood up with EOL-OS and metrics capabilities. A new workspace mirrors the core asset-inventory subflows (shared inventory writer, ingestion health writer, cleanup, coverage reporting) and adds two new capabilities not previously present: end-of-life OS detection and asset metrics computation. It also extends source coverage with Spektion and Microsoft Active Directory connectors, and has since added parallel Get-Assets connectors for SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium — effectively rebuilding the full source breadth of the original pipeline within the new architecture. The inventory writer alone processed 940 records, indicating active parallel rollout rather than a dormant fork. The pipeline has since gained its own user-ingestion orchestrator, ASM Analyst Agent abilities, device/host lookup subflows, and error-notification handling — mirroring the original pipeline's full operator toolset, though these newest additions have not yet accrued executions.

VM scanner coverage expanded significantly. Beyond Defender, Rapid7, and Wiz, NIQ has added Spektion, Tanium, and SecurityScorecard as new vulnerability/software-risk data sources, each with its own ingestion, writer, and hunting playbooks already producing meaningful volume (Spektion and Tanium software hunts each running in the 200+ execution range, on par with the original three scanners).

###

△  Gaps & Growth Opportunities

Gaps and Opportunities

Response playbooks built but not yet executing. Several high-value response actions have 0 executions: IOC blocking (Defender for Endpoint, SentinelOne, Zscaler), device isolation (Defender, SentinelOne), and user credential reset (Entra). The approval workflow infrastructure exists and is running (693 IOC response trigger events fired). The gap suggests response is still requiring manual confirmation at a high rate, or the blocking/isolation capabilities are staged for broader rollout. Activating automated response for confirmed malicious IOCs would significantly reduce dwell time.

WF0–WF7 table-based VM pipeline has 0 executions. The older workspace (06f7470e) containing WF0–WF8 workflows shows zero execution across all workflows. All active VM pipeline execution is occurring in the newer workspace (b76c3ccc). The older workspace appears to be a superseded iteration — these playbooks could be archived to reduce maintenance overhead.

User Response Actions workflow has 0 executions. The Response - User Response Actions event-based workflow (which responds to compromised user table records) fired 0 times, while the Device Response Actions workflow fired 14. This asymmetry suggests the user response workflow may not be connected to the active case management tables.

Software CVE hunt executions appear pooled across wrapper playbooks. The Blink VM integration wrapper playbooks (Hunt - Software - SentinelOne - Blink Vulnerability Management, Hunt - Software - Wiz - Blink Vulnerability Management, Hunt - Software - Cycode - Blink Vulnerability Management) each show 1,044 executions — likely the same hunt batch running across all three sources in parallel. The underlying direct hunt playbooks (Hunt - Software - SentinelOne, Hunt - Software - Wiz at 1,044 and Hunt - Software - Cycode at 1,109) show consistent counts, confirming a live software hunt program.

ASM workspace (2a845363) has no active playbooks. The Attack Surface Management workspace contains several drafted workflows (Coverage Gap - Alert and Ticket, Ingestion Health Monitor, ASM Agent) with 0 executions. This appears to be an emerging capability being developed rather than production automation.

Integration Ecosystem Summary

Tool Category Role in Automation
Microsoft Defender XDR / MDE EDR / VM IOC hunting, device containment, vulnerability ingestion
SentinelOne EDR IOC hunting, device isolation, scan initiation, software inventory
Wiz CSPM / VM Cloud vulnerability ingestion, SBOM hunting, TI notifications
Rapid7 InsightVM Cloud VM Scanner Vulnerability ingestion (NIQ + GFK entities)
Microsoft Entra ID IAM User enrichment, device attribution, MFA revocation, batch lookups
Microsoft Intune MDM Device enrichment, offboarding device management
SailPoint IAM / HR Termination and activation event source
Zscaler ZIA / SSPM Network / SaaS IOC URL blocking, SaaS app governance
ServiceNow CMDB / ITSM CMDB asset ingestion, ticket routing
Jira Ticketing Remediation ticket creation and assignment
Azure Synapse / ADLS Data Platform Vulnerability datalake, SLA metrics, analytics
AlienVault OTX Threat Intel IOC enrichment
Cycode AppSec / VM Software CVE hunting
CISA KEV / EPSS / NVD Threat Intel Vulnerability prioritization dimensions
Microsoft Outlook Email TI notification ingestion, reporting delivery
Microsoft Teams Collaboration Response approval requests
Spektion Software Risk / VM Software CVE hunting, software risk inventory ingestion
Tanium Endpoint Mgmt / VM Software CVE hunting, software inventory ingestion
SecurityScorecard Security Ratings / VM Vulnerability and patching-cadence issue ingestion
Microsoft Graph / M365 AI Agent Governance AI agent discovery and activity ingestion for governance
Microsoft Active Directory IAM / Asset Inventory On-prem asset and identity source for inventory
Appendices
A Case Management 3,974 cases (12m) | MTTR 3d 16h

Case Management

Total Cases (all-time)
3,974
3,974 opened in last 12m
Cases Opened (30d)
865
849 closed in last 30d
Cases Closed (12m)
3,958
of 3,974 opened
MTTR
3d 16h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
User Offboarding 3,667 3,667 3,651 3d 18h
Threat Intelligence 307 307 307 2d 10h
B AI Agents 16 active | 1,502 tasks (12m)

AI Agents

Active Agents
16
of 29 total
Tasks Executed (12m)
1,502
257 in last 30d
Data Usage (12m)
123,958,455
22,246,361 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Observable Identification Agent Threat Intelligence 777 111 63,340,392
2 Case Summarization Agent Threat Intelligence 423 83 25,802,900
3 Executive Summary Writer Vulnerability Management 96 43 11,414,741
4 VM Analyst Vulnerability Management 77 4 4,861,410
5 Software Asset Management Agent Vulnerability Management 23 0 2,149,632
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Threat Intelligence1,235
Vulnerability Management261
Evan.Obal@nielseniq.com6
User Offboarding0
vincent.sheahan@blinkops.com0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
33
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Agentic ADLS Vulnerability Metrics 00
2 Introduction to Attack Surface Management 00
3 Spektion AI Software Dashboard 00
4 Threat Intelligence Overview 00
5 Threat Intelligence Performance Monitoring 00

Webforms

Forms
4
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Automation Test 00
2 Interactive Software Hunting 00
3 Threat Intelligence Enhancement Request 00
4 Threat Intelligence Enhancement Request 00
D Full Use Case Analysis 10 use cases | 51,330 executions (12m)

Business KPIs

Metric Count Playbook
Observable findings automatically updated & enriched 4,154 Subflow - Update Observable Findings
Security cases auto-orchestrated through SOC pipeline 3,844 Case Orchestrator
Observables automatically triaged & enriched 3,843 Observable Orchestrator
Entra email batch lookups executed for remediation owners 3,739 Entra Email Lookup Batch
Asset inventory records written to shared inventory 3,126 Subflow - Shared Inventory Writer
Asset inventory records written via new asset ingestion pipeline 940 Subflow - Shared Inventory Writer (new asset pipeline)
Ingestion health records logged for new asset pipeline 17 Subflow - Shared Ingestion Health Writer (new asset pipeline)
Observable processing status updates 3,177 Subflow - Update Observable Processing Status
Case processing status updates 2,676 Subflow - Update Case Processing Status
Wiz threat intelligence notifications ingested 1,922 Ingest - Wiz - GraphQL TI Notification
Observable enrichment data updated 1,874 Subflow - Update Enrichment Data
Microsoft Defender vulnerability records ingested to data lake 1,348 ADLS Ingest Defender
Software CVE hunts executed across SentinelOne 1,044 Hunt - Software - SentinelOne
Software CVE hunts executed across Wiz 1,044 Hunt - Software - Wiz
Software CVE hunts executed via Cycode 1,109 Hunt - Software - Cycode
Employee offboarding workflows processed 961 Termination Event Ingestion
Security alerts fully processed through SOAR pipeline 947 Process Alert
VIP user enrichment lookups executed 971 Enrich - VIP User
Observable enrichment routed automatically 971 Subflow - Enrich Observables - Main Router
IOC response actions triggered on malicious observables 693 Response - IOC Response Actions
Hunt findings for IOCs across Microsoft Defender XDR 392 Hunt - IOC - Microsoft Defender XDR
Hunt findings for IOCs across SentinelOne 392 Hunt - IOC - SentinelOne
IOC router decisions for enrichment & hunting 1,960 Router - Enrich & Hunt Observables
Offboarding action sequences completed 460 Response Subflow - Offboarding
Intune device enrichments executed 970 Enrich - Intune Devices
Entity response data records updated 769 Subflow - Update Response Data
Employee activation events logged from SailPoint 77 Sailpoint Webhook Number 2 (Employee Activations)
Rapid7 vulnerability records ingested to data lake 127 ADLS Ingest Rapid7
CVE hunts across Blink Vulnerability Management 154 Hunt - CVE - Blink Vulnerability Management
Wiz vulnerability records ingested to data lake 354 ADLS Ingest Wiz
MFA revocation subflow executions 314 Subflow - Revoke MFA
Response approval requests sent 211 Subflow - Response - Main Router
Threat intel notifications normalized by AI agent 125 Subflow - Intelligence Normalization Agent
Zscaler 3rd-party app governance reports generated 40 Zscaler 3rd Party App Governance - Query Apps Present In Environment
Weekly threat intelligence reports delivered 5 Weekly Threat Intelligence Reporting
Software CVE hunts executed via Microsoft Defender TVM 215 Hunt - Software - Defender TVM
Software CVE hunts executed via Spektion 215 Hunt - Software - Spektion
Software CVE hunts executed via Tanium 205 Hunt - Software - Tanium
Identity isolation eligibility checks executed for active users 241 Subflow - Isolation Logic - KQL for active user
AI agent inventory records written to unified AI-agent governance datastore 375 AI Agent Chunk Writer
Wiz cloud issue records ingested & written 98 Wiz Issue Writer
Microsoft Defender vulnerability delta records ingested 93 Defender Delta Ingest
Spektion software inventory records ingested & written 65 Spektion Software Writer
Wiz wide-exposure vulnerability records ingested to data lake 55 ADLS Ingest Wiz Wide Exposure
Daily offboarding metrics computed & published 40 Compute Offboarding Metrics
Microsoft Defender vulnerability recommendations retrieved 22 Get Defender VM Reccomendations
Extension IOC hunts executed across SentinelOne 23 Hunt - Extension - SentinelOne
AI agent governance reporting dashboards refreshed 24 MS Defender AI Agent Reporting Dashboard
Wiz cloud security issues ingested 14 Wiz Issues Ingestion
Critical open-vulnerability assets tagged for prioritization 12 Critical Open Vuln Assets
ASM host lookups resolved via ServiceNow CMDB integration 4 Utility - ASM Host Lookup
In the last 12 months, Blink automated: - 7,687 security cases and observables auto-orchestrated through the SOC pipeline without analyst intervention - 6,053 IOC enrichments, hunts, and response actions executed across Microsoft Defender XDR, SentinelOne, and Wiz - 3,767 software CVE hunts performed across SentinelOne, Wiz, Cycode, Microsoft Defender TVM, Spektion, and Tanium - 1,922 Wiz threat intelligence notifications automatically ingested and processed - 1,977 vulnerability records continuously ingested from Defender, Rapid7, and Wiz into the enterprise data lake - 961 employee termination events automatically processed end-to-end - 940 VIP user enrichments and Intune device enrichments executed automatically - 417 AI agent governance actions executed — a new unified inventory, ingestion, and risk-metrics program spanning Microsoft Defender, M365 Graph, and Wiz AI-agent telemetry - 246 identity isolation eligibility checks and weekly isolation-rate calculations computed for EDR containment decisions - 940 asset inventory records processed through a newly stood-up second asset ingestion pipeline — now expanded with SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium connectors (alongside the original Spektion and Active Directory sources) plus new EOL-OS tracking and asset metrics computation

Use Case Summary

Use Case Category Active Playbooks Total Executions (12 mo)
SOC Case Management & Alert Triage SOC 13 ~15,000+
IOC Enrichment & Threat Hunting SOC 15 ~8,200
Threat Intelligence Ingestion & Curation SOC 11 ~2,250
Vulnerability Management Data Lake Pipeline Vulnerability Mgmt 35 ~2,650
Vulnerability Lifecycle, Prioritization & Ticketing Vulnerability Mgmt 35 ~1,450
Employee Offboarding & IAM Response IAM 8 ~1,650
Cloud Asset Coverage & Inventory Cloud Security 61 ~4,273
Identity Response Actions SOC 10 ~600
SaaS App Governance Cloud Security 2 ~40
GRC Reporting GRC 3 ~46
AI Agent Governance & Inventory Cloud Security 13 ~420

Use Cases

Use Case 1 — SOC Case Management & Alert Triage

Description: End-to-end automated SOC pipeline that ingests security alerts, extracts and deduplicates observables, runs enrichment, and routes cases through approval workflows. Enables a lean SOC team to handle high alert volumes with consistent, repeatable triage logic.

Business Problem Solved: Security analysts spend the majority of their time on repetitive alert processing tasks. This use case removes that burden by automatically normalizing alerts, extracting indicators, deduplicating cases, running enrichment in parallel, and escalating only when human judgment is genuinely required.

Integrations: Blink Case Management, Microsoft Teams, Blink API

Playbook Executions (12 mo) Category Subcategory
Case Orchestrator 3,844 SOC Case mgmt & SOAR
Observable Orchestrator 3,843 SOC Case mgmt & SOAR
Process Alert 947 SOC Case mgmt & SOAR
Subflow - Update Observable Findings 4,154 SOC Case mgmt & SOAR
Subflow - Update Observable Processing Status 3,177 SOC Case mgmt & SOAR
Subflow - Update Case Processing Status 2,676 SOC Case mgmt & SOAR
Subflow - Request Response Approval 14 SOC Case mgmt & SOAR
Daily Response Approval Polling 28 SOC Case mgmt & SOAR
Subflow - Response - Main Router 211 SOC Case mgmt & SOAR
Action Subflow - Router 249 SOC Case mgmt & SOAR
Process Alert (workspace 49940165) 124 SOC Case mgmt & SOAR
Error Handling - Error Notification 142 SOC Case mgmt & SOAR
Auto Close Cases from D3 11 SOC Case mgmt & SOAR

Use Case 2 — IOC Enrichment & Threat Hunting

Description: Automated enrichment and hunting pipeline for Indicators of Compromise (IOCs). When an observable is identified, Blink routes it to the appropriate enrichment sources and hunting tools, then triggers automated response if a malicious verdict is reached. Covers IPs, domains, hashes, CVEs, and software packages across multiple security products.

Business Problem Solved: Manual IOC lookup and hunting across siloed tools (Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode) is slow and inconsistent. This use case automates the full investigation chain from detection to containment decision.

Integrations: Microsoft Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode, Zscaler ZIA, Blink Case Management

Playbook Executions (12 mo) Category Subcategory
Router - Enrich & Hunt Observables 1,960 SOC Alert enrichment / IOC lookup
IOC Response Actions 693 SOC Alert enrichment / IOC lookup
Hunt - IOC - Microsoft Defender XDR 392 SOC Alert enrichment / IOC lookup
Hunt - IOC - SentinelOne 392 SOC Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router 971 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 1,874 SOC Alert enrichment / IOC lookup
Subflow - Add Hunt Finding Record 46 SOC Alert enrichment / IOC lookup
Enrich - IOC - Alienvault OTX 46 SOC Alert enrichment / IOC lookup
Hunt - CVE - Blink Vulnerability Management 154 SOC Alert enrichment / IOC lookup
Observable Re-hunting 60 SOC Alert enrichment / IOC lookup
Hunt - SaaS - Zscaler SSPM 33 SOC Alert enrichment / IOC lookup
Subflow - Enrich User 14 SOC Alert enrichment / IOC lookup
Hunt - Extension - SentinelOne 23 SOC Alert enrichment / IOC lookup
Hunt - Software - Spektion - Blink Vulnerability Management 215 SOC Alert enrichment / IOC lookup
Hunt - Software - Tanium - Blink Vulnerability Management 201 SOC Alert enrichment / IOC lookup
Subflow - Attach Bulk Hunt Results to Existing Case 4 SOC Alert enrichment / IOC lookup
Response - IOC Response Actions - On-demand 1 SOC Alert enrichment / IOC lookup

Use Case 3 — Threat Intelligence Ingestion & Curation

Description: Automated ingestion of threat intelligence from multiple sources including CISA RSS feeds, Rapid7 advisories, Wiz GraphQL queries, shared mailbox scanning, and manual webpage ingestion. An AI agent normalizes and structures the raw intelligence into actionable case management records. Weekly reporting delivers consolidated threat landscape summaries to the security team.

Business Problem Solved: Monitoring multiple disparate threat intel feeds manually is time-intensive and inconsistent. This use case ensures no advisory is missed, normalizes heterogeneous formats, and surfaces actionable intelligence automatically to the CTSO team.

Integrations: CISA RSS, Rapid7 RSS, Wiz, Microsoft Outlook, SailPoint

Playbook Executions (12 mo) Category Subcategory
Ingest - Wiz - GraphQL TI Notification 1,922 SOC Threat intel ingest & curation
Subflow - Intelligence Normalization Agent 125 SOC Threat intel ingest & curation, Agentic SOC
Ingest - Shared Mailbox - CTSO TI Notification 12 SOC Threat intel ingest & curation
Ingest - RSS - CISA TI Notification 51 SOC Threat intel ingest & curation
Ingest - RSS - Rapid7 TI Notification 5 SOC Threat intel ingest & curation
Ingest - Manual Webpage - TI Notification 13 SOC Threat intel ingest & curation
Weekly Threat Intelligence Reporting 5 SOC Threat intel ingest & curation
TI Analyst Agent 5 SOC Agentic SOC, Threat intel ingest & curation
Response Global Variable Update 6 SOC Threat intel ingest & curation
Populate TI Products 6 SOC Threat intel ingest & curation
Ingest - Shared Mailbox - BlueVoyant SOC Trends Report 4 SOC Threat intel ingest & curation
Ingest - RSS - RSS Ingestion Validation 40 SOC Threat intel ingest & curation
Monthly Threat Intelligence Reporting 1 SOC Threat intel ingest & curation

Use Case 4 — Vulnerability Management Data Lake Pipeline

Description: Enterprise-scale vulnerability data ingestion pipeline that pulls findings from Microsoft Defender, Rapid7 InsightVM, Wiz, and ServiceNow CMDB into an Azure Data Lake Storage (ADLS) / Synapse environment. Supports daily ingestion, cursor-based pagination, data normalization to OCSF schema, KEV/EPSS/NVD dimension tables, and automated phantom purge for stale records. Enables a single source of truth for the VM program across multiple business units and scanner sources.

Business Problem Solved: NIQ runs Defender, Rapid7, and Wiz across separate business units (NIQ and GFK). Without automation, reconciling vulnerability data across scanners and feeding it into a datalake for analytics would require substantial manual engineering work. This pipeline automates the entire ingestion-normalization-enrichment-analytics chain.

Integrations: Microsoft Defender for Endpoints, Rapid7 InsightVM Cloud, Wiz, ServiceNow CMDB, Azure Data Lake Storage / Azure Synapse, CISA KEV, EPSS, NVD

Playbook Executions (12 mo) Category Subcategory
ADLS Orch Main 40 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Defender 1,348 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Rapid7 127 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Wiz 354 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest CMDB 4 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Defender 50 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch R7 120 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Wiz 33 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Wiz Resolved 4 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch CMDB 4 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Dim Builder KEV 40 Vulnerability Mgmt Vuln scanning ingest & report, CVE lookup & remediation
ADLS Dim Builder EPSS 40 Vulnerability Mgmt Vuln scanning ingest & report, CVE lookup & remediation
ADLS Dim Builder NVD 38 Vulnerability Mgmt Vuln scanning ingest & report, CVE lookup & remediation
ADLS R7 Vuln Dim Orch 40 Vulnerability Mgmt Vuln scanning ingest & report
ADLS R7 Vuln Dim Worker 127 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Wiz Inactive Asset Tombstone 30 Vulnerability Mgmt Vuln scan lifecycle automation
Wiz Resolved Rejected Backfill 56 Vulnerability Mgmt Vuln scan lifecycle automation
Wiz Phantom Orchestrator 11 Vulnerability Mgmt Vuln scan lifecycle automation
ADLS Monthly Capture 1 Vulnerability Mgmt Security metrics & reporting
Spektion Software Ingestion 21 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Wiz Tombstone Orchestrator 0 Vulnerability Mgmt Vuln scan lifecycle automation
ADLS Wiz Open Snapshot Orchestrator 28 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Wiz Open Snapshot v2 0 Vulnerability Mgmt Vuln scanning ingest & report
Spektion Software Writer 65 Vulnerability Mgmt Vuln scanning ingest & report
Get Defender VM Reccomendations 22 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Issues Ingestion 14 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Issue Writer 98 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Portfolio Metrics Ingestion 0 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Top Risk Drivers 0 Vulnerability Mgmt Vuln scanning ingest & report
Security Scorecard Vuln Ingestion 0 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Wiz Wide Exposure 55 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Wiz Wide Exposure 31 Vulnerability Mgmt Vuln scanning ingest & report
Defender Delta Ingest 93 Vulnerability Mgmt Vuln scanning ingest & report
Defender Delta Orchestrator 21 Vulnerability Mgmt Vuln scanning ingest & report
Tanium Software Ingestion 1 Vulnerability Mgmt Vuln scanning ingest & report
Tanium Software Writer 0 Vulnerability Mgmt Vuln scanning ingest & report

Use Case 5 — Vulnerability Lifecycle: Prioritization, Ticketing & Reporting

Description: Downstream processing of vulnerability data for SLA evaluation, cross-source asset correlation, remediation candidate generation, Jira ticket assignment, and executive reporting. Includes AI-powered analyst agents for natural language querying of the vulnerability datalake and on-demand CVE search capability.

Business Problem Solved: After ingestion, vulnerability data must be correlated across multiple scanners and business units, enriched with SLA context, prioritized by CVSS/EPSS/KEV, and routed to the right ticket owners. This use case automates that entire chain, ensuring no critical finding sits unowned.

Integrations: Azure Synapse, Jira, Wiz, Rapid7 InsightVM, Microsoft Defender, Blink Case Management, AI Agents

Playbook Executions (12 mo) Category Subcategory
WF0 - VM Orchestrator 0 Vulnerability Mgmt Vuln scan lifecycle automation
WF1 - VM Source Ingestion & Normalize 0 Vulnerability Mgmt Vuln scanning ingest & report
WF2 - Severity & SLA Evaluation 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF3 - Cross-Source Asset Correlation 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF4 - Correlate & Build Remediation Candidates (ws 06f7470e) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF4 - Correlate & Build Remediation Candidates (ws b76c3ccc) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF5 - Remediation Task Assignment (ws 06f7470e) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF5 - Remediation Task Assignment (ws b76c3ccc) 1 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF6 - Dashboard Metrics Rollup 0 Vulnerability Mgmt Security metrics & reporting
WF7 - VM Reporting (ws 06f7470e) 0 Vulnerability Mgmt Security metrics & reporting
WF7 - Remediation Progress Tracking (ws b76c3ccc) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF8 - Software Hunting 0 Vulnerability Mgmt Threat hunting & detection
WF9 VM Analyst Agent Ability 0 Vulnerability Mgmt Threat hunting & detection
VM Analyst Agent 2 Vulnerability Mgmt Agentic SOC, Threat hunting & detection
VM Operator Agent 0 Vulnerability Mgmt Agentic SOC
WF - VM Analysis 0 Vulnerability Mgmt Threat hunting & detection
WF - Software Analysis 2 Vulnerability Mgmt Threat hunting & detection
Hunt - CVE - Blink Vulnerability Management (ws b76c3ccc) 178 Vulnerability Mgmt CVE lookup & remediation
Hunt - Software - SentinelOne 1,044 Vulnerability Mgmt Threat hunting & detection
Hunt - Software - Wiz 1,044 Vulnerability Mgmt Threat hunting & detection
Hunt - Software - Cycode 1,109 Vulnerability Mgmt Threat hunting & detection
ADLS CVE Search 12 Vulnerability Mgmt CVE lookup & remediation
ADLS Report Builder 1 Vulnerability Mgmt Security metrics & reporting
ADLS Report Request 1 Vulnerability Mgmt Security metrics & reporting
ADLS SQL Builder Portal 1 Vulnerability Mgmt Threat hunting & detection
Ad Hoc Synapse Query 25 Vulnerability Mgmt Threat hunting & detection
Entra Email Lookup Orchestrator 40 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Entra Email Lookup Batch 3,739 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Entra Email Lookup Worker 44 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
VM Severity Counts 0 Vulnerability Mgmt Security metrics & reporting
Spektion HTML Report Generator 21 Vulnerability Mgmt Security metrics & reporting
VM Analyst Agent - Ability - Ask TI Analyst Agent 5 Vulnerability Mgmt Agentic SOC, Threat hunting & detection
Hunt - Software - Defender TVM 215 Vulnerability Mgmt Threat hunting & detection
Get VM Metrics Tables 0 Vulnerability Mgmt Security metrics & reporting
VM Dashboard Metrics Agent 0 Vulnerability Mgmt Agentic SOC, Security metrics & reporting
Render & Save VM Dashboard 0 Vulnerability Mgmt Security metrics & reporting
ADLS VM KPI Weekly Snapshot 5 Vulnerability Mgmt Security metrics & reporting
Hunt - Software - Spektion 215 Vulnerability Mgmt Threat hunting & detection
MDVM Recommendations Report Generator 11 Vulnerability Mgmt Security metrics & reporting
Get and summarize VM and Risk Metrics 44 Vulnerability Mgmt Agentic SOC, Security metrics & reporting
MDVM Patch and Zero-Day Digest 44 Vulnerability Mgmt Security metrics & reporting
Spektion Software Report Digest 44 Vulnerability Mgmt Security metrics & reporting
VM Metrics Digest 44 Vulnerability Mgmt Security metrics & reporting
Wiz SLA Metrics Flow 40 Vulnerability Mgmt Security metrics & reporting
Hunt - Software - Tanium 205 Vulnerability Mgmt Threat hunting & detection
Wiz External Facing Disposition 13 Vulnerability Mgmt Security metrics & reporting
Get AI Software from the Spektion Software table 22 Vulnerability Mgmt Security metrics & reporting
Ad Hoc Synapse Query copy 0 Vulnerability Mgmt Threat hunting & detection
Defender AD HOC Metrics 0 Vulnerability Mgmt Security metrics & reporting
Critical Open Vuln Assets 12 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
VM KPI Dashboard Refresh 7 Vulnerability Mgmt Security metrics & reporting
Wiz Risk Metrics Builder 0 Vulnerability Mgmt Agentic SOC, Security metrics & reporting
Rapid7 Vulnerability Instances - FTP Assets 0 Vulnerability Mgmt Vuln scanning ingest & report, Security metrics & reporting

Use Case 6 — Employee Offboarding & IAM Response

Description: Automated offboarding pipeline triggered by SailPoint termination events. Blink processes each departing employee by revoking user sessions, resetting passwords, revoking MFA methods, wiping or unenrolling devices from Intune, and closing the associated case. A scheduled workflow handles edge cases and batches unresolved offboarding events to a downstream ITSM system (D3).

Business Problem Solved: Employee offboarding is a high-risk, time-sensitive IAM process. Missing a device wipe or leaving sessions active post-termination creates significant data leakage exposure. This use case automates the full sequence and provides audit trails for compliance.

Integrations: SailPoint, Microsoft Entra ID, Microsoft Intune, SentinelOne, Blink Case Management

Playbook Executions (12 mo) Category Subcategory
Termination Event Ingestion 961 IAM Employee offboarding
Response Subflow - Offboarding 460 IAM Employee offboarding
Offboarding - Send Batched Edge Case to D3 13 IAM Employee offboarding
Sailpoint Webhook Number 2 (Employee Activations) 77 IAM Employee onboarding, Identity lifecycle automation
Offboarding User not found Email 40 IAM Employee offboarding
Subflow - Revoke MFA 314 IAM Password & credential lifecycle
Enrich - Intune Devices 970 IAM Identity lifecycle automation
Enrich - VIP User 971 IAM Identity lifecycle automation
Compute Offboarding Metrics 40 IAM Employee offboarding

Use Case 7 — Identity Threat Response (EDR Containment)

Description: Automated response actions for compromised identities and devices. Covers IOC blocking across Microsoft Defender for Endpoint and SentinelOne, user session revocation and password reset, device isolation and scan initiation, and URL blocking via Zscaler ZIA. All actions are gated through an approval workflow before execution.

Business Problem Solved: When a malicious observable is confirmed, response execution latency is critical. Manual containment across multiple tools (MDE, S1, Zscaler) introduces unacceptable delay. This use case automates the full response chain with human-in-the-loop approval where required.

Integrations: Microsoft Defender for Endpoint, SentinelOne, Microsoft Entra ID, Zscaler ZIA

Playbook Executions (12 mo) Category Subcategory
Response - IOC Response Actions 693 SOC EDR containment & response
Response - Device Response Actions 14 SOC EDR containment & response
Attribution - Device 38 SOC EDR containment & response
Attribution - User 9 SOC Identity threat response
Subflow - Enrich Device 31 SOC EDR containment & response
Response - Revoke User Sessions and Reset Password - Microsoft Entra ID 0 SOC Identity threat response
Response - Isolate Device - Microsoft Defender for Endpoints 0 SOC EDR containment & response
Response - Isolate Device - SentinelOne 0 SOC EDR containment & response
Response - Block IOC - Microsoft Defender for Endpoint 0 SOC EDR containment & response
Response - Block Hash - SentinelOne 0 SOC EDR containment & response
Response - Block URL - Zscaler ZIA 0 SOC EDR containment & response
Response - Run Device Scan - Microsoft Defender for Endpoints 0 SOC EDR containment & response
Response - Run Device Scan - SentinelOne 0 SOC EDR containment & response
Subflow - Isolation Logic - KQL for active user 241 SOC EDR containment & response
Calculate weekly isolation rate 5 SOC EDR containment & response
Subflow - Send D3 Response Action Notification 0 SOC EDR containment & response
Response - Device Response Actions - On-demand 1 SOC EDR containment & response
Response - User Response Actions - On-demand 1 SOC Identity threat response

Use Case 8 — Cloud Asset Coverage & Inventory

Description: Multi-source asset inventory aggregation pipeline that collects device and software inventory from Microsoft Defender, SentinelOne, Wiz, Rapid7, Entra ID, Intune, Zscaler, Jamf, and ServiceNow. Assets are correlated across sources and written to a shared inventory table for vulnerability correlation and coverage gap analysis.

Business Problem Solved: Without a unified asset inventory, vulnerability remediation cannot be accurately scoped. This use case continuously syncs asset records from all deployed security tools and identifies coverage gaps where EDR is missing.

Integrations: Microsoft Defender for Endpoints, SentinelOne, Wiz, Rapid7, Microsoft Entra ID, Intune, Zscaler, Jamf, ServiceNow, Spektion, Microsoft Active Directory

Playbook Executions (12 mo) Category Subcategory
Asset Ingestion Orchestrator 8 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Inventory Writer 3,126 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Defender for Endpoints 13 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - SentinelOne 5 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Wiz 3 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Ingestion Health Writer 60 Cloud Security Cloud asset coverage & inventory
Populate Product Connections Global Variable 5 Cloud Security Cloud asset coverage & inventory
Wiz Inventory Snapshot 17 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Coverage HTML Report Generator 6 Cloud Security Cloud asset coverage & inventory
User Ingestion Orchestrator 5 Cloud Security Cloud asset coverage & inventory
Subflow - Get Users - Microsoft Entra AD 5 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Inventory Cleanup 5 Cloud Security Cloud asset coverage & inventory
ServiceNow CMDB Host Lookup 7 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Reference Query Table Examples 3 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Table Schema 2 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Tables 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - ASM SQL Query 8 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent 0 Cloud Security Cloud asset coverage & inventory
Utility - Refresh Table Views 9 Cloud Security Cloud asset coverage & inventory
Utility - Tag Assets 11 Cloud Security Cloud asset coverage & inventory
Asset Ingestion Re-processing 4 Cloud Security Cloud asset coverage & inventory
Subflow - Format Connection List 8 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Post-Ingestion 5 Cloud Security Cloud asset coverage & inventory
Defender Host Lookup 2 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Active Directory 0 Cloud Security Cloud asset coverage & inventory
Query - Device - ASM 6 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Spektion 1 Cloud Security Cloud asset coverage & inventory
Subflow - Gather End of Life OS Details 1 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Metrics Computation 2 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Post-Ingestion 3 Cloud Security Cloud asset coverage & inventory
Scratchpad 0 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Ingestion Health Writer (new asset pipeline) 17 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Inventory Writer (new asset pipeline) 940 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Wiz (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Active Directory (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
ServiceNow CMDB Host Lookup (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Inventory Cleanup (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Coverage HTML Report Generator (new asset pipeline) 2 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Table Schema (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Asset Ingestion Orchestrator (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Format Connection List (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - SentinelOne (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Zscaler (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Entra AD (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - ServiceNow (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Defender for Endpoint (new asset pipeline) 2 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Rapid7 InsightVM (new asset pipeline) 3 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Intune (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Jamf (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Tanium (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Utility - Refresh Table Views (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Utility - Tag Assets (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - ASM SQL Query (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Subflow - Get Users - Microsoft Entra AD (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Query - Device - ASM (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Tables (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
User Ingestion Orchestrator (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Defender Host Lookup (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
On Error Notification (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Reference Query Table Examples (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Utility - ASM Host Lookup 4 Cloud Security Cloud asset coverage & inventory

Use Case 9 — SaaS Application Governance

Description: Scheduled governance automation that queries Zscaler ZIA for third-party SaaS applications present in the environment, generates compliance views, and feeds findings into a reporting pipeline. Surfaces shadow IT and unauthorized application usage.

Business Problem Solved: Unmanaged SaaS applications represent a data leakage and compliance risk. This use case automates the detection and cataloging of all SaaS applications traversing the network perimeter.

Integrations: Zscaler ZIA, Microsoft Outlook

Playbook Executions (12 mo) Category Subcategory
Zscaler 3rd Party App Governance - Query Apps Present In Environment (scheduled) 40 Cloud Security Cloud access & SaaS policy mgmt
Zscaler 3rd Party App Governance - Query Apps Present In Environment (on-demand) 0 Cloud Security Cloud access & SaaS policy mgmt

Use Case 10 — GRC & Security Reporting

Description: Automated security metrics and executive reporting workflows including weekly threat intelligence reports and Blink automation reporting. Provides consistent, timely security status updates to stakeholders without manual report assembly.

Business Problem Solved: Preparing security metrics reports manually is error-prone and time-consuming. Automation ensures reports are generated on schedule with up-to-date data from live case management and vulnerability systems.

Integrations: Blink Case Management, Email

Playbook Executions (12 mo) Category Subcategory
Weekly Threat Intelligence Reporting 5 GRC Security metrics & reporting
Unowned Assets Report 0 GRC Security metrics & reporting
Monthly Threat Intelligence Reporting 1 GRC Security metrics & reporting

Use Case 11 — AI Agent Governance & Inventory

Description: A new automation program that discovers, correlates, and monitors AI agents deployed across the enterprise — pulling agent telemetry from Microsoft Defender (Security Copilot / M365 agent activity via Microsoft Graph) and Wiz (cloud-deployed AI agents), reconciling both sources into a unified AI-agent inventory with identity links, and computing governance/risk metrics (exposure, connected hubs, tool/MCP counts, shared-connection risk). Dashboards surface capability analytics and priority governance gaps.

Business Problem Solved: AI agents (Copilot extensions, cloud-hosted agents, MCP-connected tools) are proliferating faster than security teams can track them, creating an ungoverned identity and data-access surface. This use case builds the asset inventory and risk-scoring layer needed to bring AI agents under the same governance rigor as traditional endpoints and cloud resources.

Integrations: Microsoft Defender, Microsoft Graph (M365), Wiz, Blink Case Management

Playbook Executions (12 mo) Category Subcategory
Ingest M365 Agent Data 8 Cloud Security Cloud asset coverage & inventory
AI Agent Chunk Writer 375 Cloud Security Cloud asset coverage & inventory
MS Defender AI Agent Reporting Dashboard 24 Cloud Security Cloud asset coverage & inventory
Wiz Agent Data Writer 0 Cloud Security Cloud asset coverage & inventory
Wiz AI Agent Ingestion 4 Cloud Security Cloud asset coverage & inventory
Wiz AI Agent Metrics Dashboard 1 Cloud Security Cloud asset coverage & inventory
AI Agent Unified Inventory Builder 0 Cloud Security Cloud asset coverage & inventory
AI Agent Metric Observation Builder 1 Cloud Security Cloud asset coverage & inventory
AI Agent Unified Metrics Dashboard 1 Cloud Security Cloud asset coverage & inventory
AI Agent Unified Inventory IO Worker 1 Cloud Security Cloud asset coverage & inventory
Get Spektion AI Software from VM Workspace 1 Cloud Security Cloud asset coverage & inventory
Defender AI Agent Capability Analytics 1 Cloud Security Config audit & remediation
Defender AI Agent Component Metrics Builder 0 Cloud Security Config audit & remediation

Key Observations

Strengths

Deep, production-grade Vulnerability Management program. NIQ has built one of the most sophisticated VM automation programs in the Blink customer base. The ADLS pipeline ingests vulnerabilities from three scanner families (Defender, Rapid7, Wiz) across multiple business unit instances (NIQ + GFK), normalizes to OCSF, enriches with KEV/EPSS/NVD context, correlates cross-source, and drives Jira remediation ticket creation — all automated. The daily cadence of KEV, EPSS, and NVD dimension builds (38–40 executions each) and Defender/R7/Wiz ingestion runs (127–1,348 executions) demonstrates genuine production reliance.

High-volume SOC automation is operational and running. The Case Orchestrator and Observable Orchestrator together processed nearly 7,700 items in the past 12 months. The enrichment chain (Observable Router → per-tool Hunt subflows → Update Observable Findings at 4,154 executions) is clearly handling real alert volume, not just testing.

Agentic security capabilities are deployed. NIQ has production AI agents for three distinct functions: TI Analyst Agent (threat intelligence interrogation), VM Analyst Agent (natural language vulnerability datalake queries), and a VM Operator Agent with full pipeline tooling. This positions NIQ ahead of most customers in deploying agentic security workflows.

Breadth of integration ecosystem. NIQ's automation spans: Microsoft Defender XDR, SentinelOne, Wiz, Rapid7 InsightVM, Microsoft Entra ID, Microsoft Intune, Zscaler ZIA/SSPM, SailPoint, AlienVault OTX, Cycode, ServiceNow, Jira, Azure Synapse / ADLS, CISA KEV, EPSS, NVD — a mature, enterprise-scale integration footprint.

Cross-business-unit coverage. The VM pipeline explicitly handles both the NIQ and GFK entities with separate scanner connections, reflecting a post-merger integration use case where automation bridges organizational boundaries.

New: AI Agent Governance program stood up. NIQ has launched a dedicated workspace and pipeline (Use Case 11) to inventory and risk-score AI agents across Microsoft Defender/M365 and Wiz — reconciling both sources into a unified inventory, computing exposure and shared-connection risk metrics, and publishing governance dashboards. The AI Agent Chunk Writer alone processed 375 records in its first period, indicating active, ongoing discovery rather than a one-time pilot. This positions NIQ ahead of the curve on a fast-emerging AI-agent attack surface.

New: second asset ingestion pipeline stood up with EOL-OS and metrics capabilities. A new workspace mirrors the core asset-inventory subflows (shared inventory writer, ingestion health writer, cleanup, coverage reporting) and adds two new capabilities not previously present: end-of-life OS detection and asset metrics computation. It also extends source coverage with Spektion and Microsoft Active Directory connectors, and has since added parallel Get-Assets connectors for SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium — effectively rebuilding the full source breadth of the original pipeline within the new architecture. The inventory writer alone processed 940 records, indicating active parallel rollout rather than a dormant fork. The pipeline has since gained its own user-ingestion orchestrator, ASM Analyst Agent abilities, device/host lookup subflows, and error-notification handling — mirroring the original pipeline's full operator toolset, though these newest additions have not yet accrued executions.

VM scanner coverage expanded significantly. Beyond Defender, Rapid7, and Wiz, NIQ has added Spektion, Tanium, and SecurityScorecard as new vulnerability/software-risk data sources, each with its own ingestion, writer, and hunting playbooks already producing meaningful volume (Spektion and Tanium software hunts each running in the 200+ execution range, on par with the original three scanners).

Gaps and Opportunities

Response playbooks built but not yet executing. Several high-value response actions have 0 executions: IOC blocking (Defender for Endpoint, SentinelOne, Zscaler), device isolation (Defender, SentinelOne), and user credential reset (Entra). The approval workflow infrastructure exists and is running (693 IOC response trigger events fired). The gap suggests response is still requiring manual confirmation at a high rate, or the blocking/isolation capabilities are staged for broader rollout. Activating automated response for confirmed malicious IOCs would significantly reduce dwell time.

WF0–WF7 table-based VM pipeline has 0 executions. The older workspace (06f7470e) containing WF0–WF8 workflows shows zero execution across all workflows. All active VM pipeline execution is occurring in the newer workspace (b76c3ccc). The older workspace appears to be a superseded iteration — these playbooks could be archived to reduce maintenance overhead.

User Response Actions workflow has 0 executions. The Response - User Response Actions event-based workflow (which responds to compromised user table records) fired 0 times, while the Device Response Actions workflow fired 14. This asymmetry suggests the user response workflow may not be connected to the active case management tables.

Software CVE hunt executions appear pooled across wrapper playbooks. The Blink VM integration wrapper playbooks (Hunt - Software - SentinelOne - Blink Vulnerability Management, Hunt - Software - Wiz - Blink Vulnerability Management, Hunt - Software - Cycode - Blink Vulnerability Management) each show 1,044 executions — likely the same hunt batch running across all three sources in parallel. The underlying direct hunt playbooks (Hunt - Software - SentinelOne, Hunt - Software - Wiz at 1,044 and Hunt - Software - Cycode at 1,109) show consistent counts, confirming a live software hunt program.

ASM workspace (2a845363) has no active playbooks. The Attack Surface Management workspace contains several drafted workflows (Coverage Gap - Alert and Ticket, Ingestion Health Monitor, ASM Agent) with 0 executions. This appears to be an emerging capability being developed rather than production automation.

Integration Ecosystem Summary

Tool Category Role in Automation
Microsoft Defender XDR / MDE EDR / VM IOC hunting, device containment, vulnerability ingestion
SentinelOne EDR IOC hunting, device isolation, scan initiation, software inventory
Wiz CSPM / VM Cloud vulnerability ingestion, SBOM hunting, TI notifications
Rapid7 InsightVM Cloud VM Scanner Vulnerability ingestion (NIQ + GFK entities)
Microsoft Entra ID IAM User enrichment, device attribution, MFA revocation, batch lookups
Microsoft Intune MDM Device enrichment, offboarding device management
SailPoint IAM / HR Termination and activation event source
Zscaler ZIA / SSPM Network / SaaS IOC URL blocking, SaaS app governance
ServiceNow CMDB / ITSM CMDB asset ingestion, ticket routing
Jira Ticketing Remediation ticket creation and assignment
Azure Synapse / ADLS Data Platform Vulnerability datalake, SLA metrics, analytics
AlienVault OTX Threat Intel IOC enrichment
Cycode AppSec / VM Software CVE hunting
CISA KEV / EPSS / NVD Threat Intel Vulnerability prioritization dimensions
Microsoft Outlook Email TI notification ingestion, reporting delivery
Microsoft Teams Collaboration Response approval requests
Spektion Software Risk / VM Software CVE hunting, software risk inventory ingestion
Tanium Endpoint Mgmt / VM Software CVE hunting, software inventory ingestion
SecurityScorecard Security Ratings / VM Vulnerability and patching-cadence issue ingestion
Microsoft Graph / M365 AI Agent Governance AI agent discovery and activity ingestion for governance
Microsoft Active Directory IAM / Asset Inventory On-prem asset and identity source for inventory

1. Business KPIs — Last 12 Months

Metric Count Playbook
Observable findings automatically updated & enriched 4,154 Subflow - Update Observable Findings
Security cases auto-orchestrated through SOC pipeline 3,844 Case Orchestrator
Observables automatically triaged & enriched 3,843 Observable Orchestrator
Entra email batch lookups executed for remediation owners 3,739 Entra Email Lookup Batch
Asset inventory records written to shared inventory 3,126 Subflow - Shared Inventory Writer
Asset inventory records written via new asset ingestion pipeline 940 Subflow - Shared Inventory Writer (new asset pipeline)
Ingestion health records logged for new asset pipeline 17 Subflow - Shared Ingestion Health Writer (new asset pipeline)
Observable processing status updates 3,177 Subflow - Update Observable Processing Status
Case processing status updates 2,676 Subflow - Update Case Processing Status
Wiz threat intelligence notifications ingested 1,922 Ingest - Wiz - GraphQL TI Notification
Observable enrichment data updated 1,874 Subflow - Update Enrichment Data
Microsoft Defender vulnerability records ingested to data lake 1,348 ADLS Ingest Defender
Software CVE hunts executed across SentinelOne 1,044 Hunt - Software - SentinelOne
Software CVE hunts executed across Wiz 1,044 Hunt - Software - Wiz
Software CVE hunts executed via Cycode 1,109 Hunt - Software - Cycode
Employee offboarding workflows processed 961 Termination Event Ingestion
Security alerts fully processed through SOAR pipeline 947 Process Alert
VIP user enrichment lookups executed 971 Enrich - VIP User
Observable enrichment routed automatically 971 Subflow - Enrich Observables - Main Router
IOC response actions triggered on malicious observables 693 Response - IOC Response Actions
Hunt findings for IOCs across Microsoft Defender XDR 392 Hunt - IOC - Microsoft Defender XDR
Hunt findings for IOCs across SentinelOne 392 Hunt - IOC - SentinelOne
IOC router decisions for enrichment & hunting 1,960 Router - Enrich & Hunt Observables
Offboarding action sequences completed 460 Response Subflow - Offboarding
Intune device enrichments executed 970 Enrich - Intune Devices
Entity response data records updated 769 Subflow - Update Response Data
Employee activation events logged from SailPoint 77 Sailpoint Webhook Number 2 (Employee Activations)
Rapid7 vulnerability records ingested to data lake 127 ADLS Ingest Rapid7
CVE hunts across Blink Vulnerability Management 154 Hunt - CVE - Blink Vulnerability Management
Wiz vulnerability records ingested to data lake 354 ADLS Ingest Wiz
MFA revocation subflow executions 314 Subflow - Revoke MFA
Response approval requests sent 211 Subflow - Response - Main Router
Threat intel notifications normalized by AI agent 125 Subflow - Intelligence Normalization Agent
Zscaler 3rd-party app governance reports generated 40 Zscaler 3rd Party App Governance - Query Apps Present In Environment
Weekly threat intelligence reports delivered 5 Weekly Threat Intelligence Reporting
Software CVE hunts executed via Microsoft Defender TVM 215 Hunt - Software - Defender TVM
Software CVE hunts executed via Spektion 215 Hunt - Software - Spektion
Software CVE hunts executed via Tanium 205 Hunt - Software - Tanium
Identity isolation eligibility checks executed for active users 241 Subflow - Isolation Logic - KQL for active user
AI agent inventory records written to unified AI-agent governance datastore 375 AI Agent Chunk Writer
Wiz cloud issue records ingested & written 98 Wiz Issue Writer
Microsoft Defender vulnerability delta records ingested 93 Defender Delta Ingest
Spektion software inventory records ingested & written 65 Spektion Software Writer
Wiz wide-exposure vulnerability records ingested to data lake 55 ADLS Ingest Wiz Wide Exposure
Daily offboarding metrics computed & published 40 Compute Offboarding Metrics
Microsoft Defender vulnerability recommendations retrieved 22 Get Defender VM Reccomendations
Extension IOC hunts executed across SentinelOne 23 Hunt - Extension - SentinelOne
AI agent governance reporting dashboards refreshed 24 MS Defender AI Agent Reporting Dashboard
Wiz cloud security issues ingested 14 Wiz Issues Ingestion
Critical open-vulnerability assets tagged for prioritization 12 Critical Open Vuln Assets
ASM host lookups resolved via ServiceNow CMDB integration 4 Utility - ASM Host Lookup
In the last 12 months, Blink automated: - 7,687 security cases and observables auto-orchestrated through the SOC pipeline without analyst intervention - 6,053 IOC enrichments, hunts, and response actions executed across Microsoft Defender XDR, SentinelOne, and Wiz - 3,767 software CVE hunts performed across SentinelOne, Wiz, Cycode, Microsoft Defender TVM, Spektion, and Tanium - 1,922 Wiz threat intelligence notifications automatically ingested and processed - 1,977 vulnerability records continuously ingested from Defender, Rapid7, and Wiz into the enterprise data lake - 961 employee termination events automatically processed end-to-end - 940 VIP user enrichments and Intune device enrichments executed automatically - 417 AI agent governance actions executed — a new unified inventory, ingestion, and risk-metrics program spanning Microsoft Defender, M365 Graph, and Wiz AI-agent telemetry - 246 identity isolation eligibility checks and weekly isolation-rate calculations computed for EDR containment decisions - 940 asset inventory records processed through a newly stood-up second asset ingestion pipeline — now expanded with SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium connectors (alongside the original Spektion and Active Directory sources) plus new EOL-OS tracking and asset metrics computation

2. Use Case Summary

Use Case Category Active Playbooks Total Executions (12 mo)
SOC Case Management & Alert Triage SOC 13 ~15,000+
IOC Enrichment & Threat Hunting SOC 15 ~8,200
Threat Intelligence Ingestion & Curation SOC 11 ~2,250
Vulnerability Management Data Lake Pipeline Vulnerability Mgmt 35 ~2,650
Vulnerability Lifecycle, Prioritization & Ticketing Vulnerability Mgmt 35 ~1,450
Employee Offboarding & IAM Response IAM 8 ~1,650
Cloud Asset Coverage & Inventory Cloud Security 61 ~4,273
Identity Response Actions SOC 10 ~600
SaaS App Governance Cloud Security 2 ~40
GRC Reporting GRC 3 ~46
AI Agent Governance & Inventory Cloud Security 13 ~420

3. Use Cases

Use Case 1 — SOC Case Management & Alert Triage

Description: End-to-end automated SOC pipeline that ingests security alerts, extracts and deduplicates observables, runs enrichment, and routes cases through approval workflows. Enables a lean SOC team to handle high alert volumes with consistent, repeatable triage logic.

Business Problem Solved: Security analysts spend the majority of their time on repetitive alert processing tasks. This use case removes that burden by automatically normalizing alerts, extracting indicators, deduplicating cases, running enrichment in parallel, and escalating only when human judgment is genuinely required.

Integrations: Blink Case Management, Microsoft Teams, Blink API

Playbook Executions (12 mo) Category Subcategory
Case Orchestrator 3,844 SOC Case mgmt & SOAR
Observable Orchestrator 3,843 SOC Case mgmt & SOAR
Process Alert 947 SOC Case mgmt & SOAR
Subflow - Update Observable Findings 4,154 SOC Case mgmt & SOAR
Subflow - Update Observable Processing Status 3,177 SOC Case mgmt & SOAR
Subflow - Update Case Processing Status 2,676 SOC Case mgmt & SOAR
Subflow - Request Response Approval 14 SOC Case mgmt & SOAR
Daily Response Approval Polling 28 SOC Case mgmt & SOAR
Subflow - Response - Main Router 211 SOC Case mgmt & SOAR
Action Subflow - Router 249 SOC Case mgmt & SOAR
Process Alert (workspace 49940165) 124 SOC Case mgmt & SOAR
Error Handling - Error Notification 142 SOC Case mgmt & SOAR
Auto Close Cases from D3 11 SOC Case mgmt & SOAR

Use Case 2 — IOC Enrichment & Threat Hunting

Description: Automated enrichment and hunting pipeline for Indicators of Compromise (IOCs). When an observable is identified, Blink routes it to the appropriate enrichment sources and hunting tools, then triggers automated response if a malicious verdict is reached. Covers IPs, domains, hashes, CVEs, and software packages across multiple security products.

Business Problem Solved: Manual IOC lookup and hunting across siloed tools (Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode) is slow and inconsistent. This use case automates the full investigation chain from detection to containment decision.

Integrations: Microsoft Defender XDR, SentinelOne, AlienVault OTX, Wiz, Cycode, Zscaler ZIA, Blink Case Management

Playbook Executions (12 mo) Category Subcategory
Router - Enrich & Hunt Observables 1,960 SOC Alert enrichment / IOC lookup
IOC Response Actions 693 SOC Alert enrichment / IOC lookup
Hunt - IOC - Microsoft Defender XDR 392 SOC Alert enrichment / IOC lookup
Hunt - IOC - SentinelOne 392 SOC Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router 971 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 1,874 SOC Alert enrichment / IOC lookup
Subflow - Add Hunt Finding Record 46 SOC Alert enrichment / IOC lookup
Enrich - IOC - Alienvault OTX 46 SOC Alert enrichment / IOC lookup
Hunt - CVE - Blink Vulnerability Management 154 SOC Alert enrichment / IOC lookup
Observable Re-hunting 60 SOC Alert enrichment / IOC lookup
Hunt - SaaS - Zscaler SSPM 33 SOC Alert enrichment / IOC lookup
Subflow - Enrich User 14 SOC Alert enrichment / IOC lookup
Hunt - Extension - SentinelOne 23 SOC Alert enrichment / IOC lookup
Hunt - Software - Spektion - Blink Vulnerability Management 215 SOC Alert enrichment / IOC lookup
Hunt - Software - Tanium - Blink Vulnerability Management 201 SOC Alert enrichment / IOC lookup
Subflow - Attach Bulk Hunt Results to Existing Case 4 SOC Alert enrichment / IOC lookup
Response - IOC Response Actions - On-demand 1 SOC Alert enrichment / IOC lookup

Use Case 3 — Threat Intelligence Ingestion & Curation

Description: Automated ingestion of threat intelligence from multiple sources including CISA RSS feeds, Rapid7 advisories, Wiz GraphQL queries, shared mailbox scanning, and manual webpage ingestion. An AI agent normalizes and structures the raw intelligence into actionable case management records. Weekly reporting delivers consolidated threat landscape summaries to the security team.

Business Problem Solved: Monitoring multiple disparate threat intel feeds manually is time-intensive and inconsistent. This use case ensures no advisory is missed, normalizes heterogeneous formats, and surfaces actionable intelligence automatically to the CTSO team.

Integrations: CISA RSS, Rapid7 RSS, Wiz, Microsoft Outlook, SailPoint

Playbook Executions (12 mo) Category Subcategory
Ingest - Wiz - GraphQL TI Notification 1,922 SOC Threat intel ingest & curation
Subflow - Intelligence Normalization Agent 125 SOC Threat intel ingest & curation, Agentic SOC
Ingest - Shared Mailbox - CTSO TI Notification 12 SOC Threat intel ingest & curation
Ingest - RSS - CISA TI Notification 51 SOC Threat intel ingest & curation
Ingest - RSS - Rapid7 TI Notification 5 SOC Threat intel ingest & curation
Ingest - Manual Webpage - TI Notification 13 SOC Threat intel ingest & curation
Weekly Threat Intelligence Reporting 5 SOC Threat intel ingest & curation
TI Analyst Agent 5 SOC Agentic SOC, Threat intel ingest & curation
Response Global Variable Update 6 SOC Threat intel ingest & curation
Populate TI Products 6 SOC Threat intel ingest & curation
Ingest - Shared Mailbox - BlueVoyant SOC Trends Report 4 SOC Threat intel ingest & curation
Ingest - RSS - RSS Ingestion Validation 40 SOC Threat intel ingest & curation
Monthly Threat Intelligence Reporting 1 SOC Threat intel ingest & curation

Use Case 4 — Vulnerability Management Data Lake Pipeline

Description: Enterprise-scale vulnerability data ingestion pipeline that pulls findings from Microsoft Defender, Rapid7 InsightVM, Wiz, and ServiceNow CMDB into an Azure Data Lake Storage (ADLS) / Synapse environment. Supports daily ingestion, cursor-based pagination, data normalization to OCSF schema, KEV/EPSS/NVD dimension tables, and automated phantom purge for stale records. Enables a single source of truth for the VM program across multiple business units and scanner sources.

Business Problem Solved: NIQ runs Defender, Rapid7, and Wiz across separate business units (NIQ and GFK). Without automation, reconciling vulnerability data across scanners and feeding it into a datalake for analytics would require substantial manual engineering work. This pipeline automates the entire ingestion-normalization-enrichment-analytics chain.

Integrations: Microsoft Defender for Endpoints, Rapid7 InsightVM Cloud, Wiz, ServiceNow CMDB, Azure Data Lake Storage / Azure Synapse, CISA KEV, EPSS, NVD

Playbook Executions (12 mo) Category Subcategory
ADLS Orch Main 40 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Defender 1,348 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Rapid7 127 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Wiz 354 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest CMDB 4 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Defender 50 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch R7 120 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Wiz 33 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Wiz Resolved 4 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch CMDB 4 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Dim Builder KEV 40 Vulnerability Mgmt Vuln scanning ingest & report, CVE lookup & remediation
ADLS Dim Builder EPSS 40 Vulnerability Mgmt Vuln scanning ingest & report, CVE lookup & remediation
ADLS Dim Builder NVD 38 Vulnerability Mgmt Vuln scanning ingest & report, CVE lookup & remediation
ADLS R7 Vuln Dim Orch 40 Vulnerability Mgmt Vuln scanning ingest & report
ADLS R7 Vuln Dim Worker 127 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Wiz Inactive Asset Tombstone 30 Vulnerability Mgmt Vuln scan lifecycle automation
Wiz Resolved Rejected Backfill 56 Vulnerability Mgmt Vuln scan lifecycle automation
Wiz Phantom Orchestrator 11 Vulnerability Mgmt Vuln scan lifecycle automation
ADLS Monthly Capture 1 Vulnerability Mgmt Security metrics & reporting
Spektion Software Ingestion 21 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Wiz Tombstone Orchestrator 0 Vulnerability Mgmt Vuln scan lifecycle automation
ADLS Wiz Open Snapshot Orchestrator 28 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Wiz Open Snapshot v2 0 Vulnerability Mgmt Vuln scanning ingest & report
Spektion Software Writer 65 Vulnerability Mgmt Vuln scanning ingest & report
Get Defender VM Reccomendations 22 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Issues Ingestion 14 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Issue Writer 98 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Portfolio Metrics Ingestion 0 Vulnerability Mgmt Vuln scanning ingest & report
Wiz Top Risk Drivers 0 Vulnerability Mgmt Vuln scanning ingest & report
Security Scorecard Vuln Ingestion 0 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Ingest Wiz Wide Exposure 55 Vulnerability Mgmt Vuln scanning ingest & report
ADLS Orch Wiz Wide Exposure 31 Vulnerability Mgmt Vuln scanning ingest & report
Defender Delta Ingest 93 Vulnerability Mgmt Vuln scanning ingest & report
Defender Delta Orchestrator 21 Vulnerability Mgmt Vuln scanning ingest & report
Tanium Software Ingestion 1 Vulnerability Mgmt Vuln scanning ingest & report
Tanium Software Writer 0 Vulnerability Mgmt Vuln scanning ingest & report

Use Case 5 — Vulnerability Lifecycle: Prioritization, Ticketing & Reporting

Description: Downstream processing of vulnerability data for SLA evaluation, cross-source asset correlation, remediation candidate generation, Jira ticket assignment, and executive reporting. Includes AI-powered analyst agents for natural language querying of the vulnerability datalake and on-demand CVE search capability.

Business Problem Solved: After ingestion, vulnerability data must be correlated across multiple scanners and business units, enriched with SLA context, prioritized by CVSS/EPSS/KEV, and routed to the right ticket owners. This use case automates that entire chain, ensuring no critical finding sits unowned.

Integrations: Azure Synapse, Jira, Wiz, Rapid7 InsightVM, Microsoft Defender, Blink Case Management, AI Agents

Playbook Executions (12 mo) Category Subcategory
WF0 - VM Orchestrator 0 Vulnerability Mgmt Vuln scan lifecycle automation
WF1 - VM Source Ingestion & Normalize 0 Vulnerability Mgmt Vuln scanning ingest & report
WF2 - Severity & SLA Evaluation 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF3 - Cross-Source Asset Correlation 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF4 - Correlate & Build Remediation Candidates (ws 06f7470e) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF4 - Correlate & Build Remediation Candidates (ws b76c3ccc) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF5 - Remediation Task Assignment (ws 06f7470e) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF5 - Remediation Task Assignment (ws b76c3ccc) 1 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF6 - Dashboard Metrics Rollup 0 Vulnerability Mgmt Security metrics & reporting
WF7 - VM Reporting (ws 06f7470e) 0 Vulnerability Mgmt Security metrics & reporting
WF7 - Remediation Progress Tracking (ws b76c3ccc) 0 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
WF8 - Software Hunting 0 Vulnerability Mgmt Threat hunting & detection
WF9 VM Analyst Agent Ability 0 Vulnerability Mgmt Threat hunting & detection
VM Analyst Agent 2 Vulnerability Mgmt Agentic SOC, Threat hunting & detection
VM Operator Agent 0 Vulnerability Mgmt Agentic SOC
WF - VM Analysis 0 Vulnerability Mgmt Threat hunting & detection
WF - Software Analysis 2 Vulnerability Mgmt Threat hunting & detection
Hunt - CVE - Blink Vulnerability Management (ws b76c3ccc) 178 Vulnerability Mgmt CVE lookup & remediation
Hunt - Software - SentinelOne 1,044 Vulnerability Mgmt Threat hunting & detection
Hunt - Software - Wiz 1,044 Vulnerability Mgmt Threat hunting & detection
Hunt - Software - Cycode 1,109 Vulnerability Mgmt Threat hunting & detection
ADLS CVE Search 12 Vulnerability Mgmt CVE lookup & remediation
ADLS Report Builder 1 Vulnerability Mgmt Security metrics & reporting
ADLS Report Request 1 Vulnerability Mgmt Security metrics & reporting
ADLS SQL Builder Portal 1 Vulnerability Mgmt Threat hunting & detection
Ad Hoc Synapse Query 25 Vulnerability Mgmt Threat hunting & detection
Entra Email Lookup Orchestrator 40 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Entra Email Lookup Batch 3,739 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Entra Email Lookup Worker 44 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
VM Severity Counts 0 Vulnerability Mgmt Security metrics & reporting
Spektion HTML Report Generator 21 Vulnerability Mgmt Security metrics & reporting
VM Analyst Agent - Ability - Ask TI Analyst Agent 5 Vulnerability Mgmt Agentic SOC, Threat hunting & detection
Hunt - Software - Defender TVM 215 Vulnerability Mgmt Threat hunting & detection
Get VM Metrics Tables 0 Vulnerability Mgmt Security metrics & reporting
VM Dashboard Metrics Agent 0 Vulnerability Mgmt Agentic SOC, Security metrics & reporting
Render & Save VM Dashboard 0 Vulnerability Mgmt Security metrics & reporting
ADLS VM KPI Weekly Snapshot 5 Vulnerability Mgmt Security metrics & reporting
Hunt - Software - Spektion 215 Vulnerability Mgmt Threat hunting & detection
MDVM Recommendations Report Generator 11 Vulnerability Mgmt Security metrics & reporting
Get and summarize VM and Risk Metrics 44 Vulnerability Mgmt Agentic SOC, Security metrics & reporting
MDVM Patch and Zero-Day Digest 44 Vulnerability Mgmt Security metrics & reporting
Spektion Software Report Digest 44 Vulnerability Mgmt Security metrics & reporting
VM Metrics Digest 44 Vulnerability Mgmt Security metrics & reporting
Wiz SLA Metrics Flow 40 Vulnerability Mgmt Security metrics & reporting
Hunt - Software - Tanium 205 Vulnerability Mgmt Threat hunting & detection
Wiz External Facing Disposition 13 Vulnerability Mgmt Security metrics & reporting
Get AI Software from the Spektion Software table 22 Vulnerability Mgmt Security metrics & reporting
Ad Hoc Synapse Query copy 0 Vulnerability Mgmt Threat hunting & detection
Defender AD HOC Metrics 0 Vulnerability Mgmt Security metrics & reporting
Critical Open Vuln Assets 12 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
VM KPI Dashboard Refresh 7 Vulnerability Mgmt Security metrics & reporting
Wiz Risk Metrics Builder 0 Vulnerability Mgmt Agentic SOC, Security metrics & reporting
Rapid7 Vulnerability Instances - FTP Assets 0 Vulnerability Mgmt Vuln scanning ingest & report, Security metrics & reporting

Use Case 6 — Employee Offboarding & IAM Response

Description: Automated offboarding pipeline triggered by SailPoint termination events. Blink processes each departing employee by revoking user sessions, resetting passwords, revoking MFA methods, wiping or unenrolling devices from Intune, and closing the associated case. A scheduled workflow handles edge cases and batches unresolved offboarding events to a downstream ITSM system (D3).

Business Problem Solved: Employee offboarding is a high-risk, time-sensitive IAM process. Missing a device wipe or leaving sessions active post-termination creates significant data leakage exposure. This use case automates the full sequence and provides audit trails for compliance.

Integrations: SailPoint, Microsoft Entra ID, Microsoft Intune, SentinelOne, Blink Case Management

Playbook Executions (12 mo) Category Subcategory
Termination Event Ingestion 961 IAM Employee offboarding
Response Subflow - Offboarding 460 IAM Employee offboarding
Offboarding - Send Batched Edge Case to D3 13 IAM Employee offboarding
Sailpoint Webhook Number 2 (Employee Activations) 77 IAM Employee onboarding, Identity lifecycle automation
Offboarding User not found Email 40 IAM Employee offboarding
Subflow - Revoke MFA 314 IAM Password & credential lifecycle
Enrich - Intune Devices 970 IAM Identity lifecycle automation
Enrich - VIP User 971 IAM Identity lifecycle automation
Compute Offboarding Metrics 40 IAM Employee offboarding

Use Case 7 — Identity Threat Response (EDR Containment)

Description: Automated response actions for compromised identities and devices. Covers IOC blocking across Microsoft Defender for Endpoint and SentinelOne, user session revocation and password reset, device isolation and scan initiation, and URL blocking via Zscaler ZIA. All actions are gated through an approval workflow before execution.

Business Problem Solved: When a malicious observable is confirmed, response execution latency is critical. Manual containment across multiple tools (MDE, S1, Zscaler) introduces unacceptable delay. This use case automates the full response chain with human-in-the-loop approval where required.

Integrations: Microsoft Defender for Endpoint, SentinelOne, Microsoft Entra ID, Zscaler ZIA

Playbook Executions (12 mo) Category Subcategory
Response - IOC Response Actions 693 SOC EDR containment & response
Response - Device Response Actions 14 SOC EDR containment & response
Attribution - Device 38 SOC EDR containment & response
Attribution - User 9 SOC Identity threat response
Subflow - Enrich Device 31 SOC EDR containment & response
Response - Revoke User Sessions and Reset Password - Microsoft Entra ID 0 SOC Identity threat response
Response - Isolate Device - Microsoft Defender for Endpoints 0 SOC EDR containment & response
Response - Isolate Device - SentinelOne 0 SOC EDR containment & response
Response - Block IOC - Microsoft Defender for Endpoint 0 SOC EDR containment & response
Response - Block Hash - SentinelOne 0 SOC EDR containment & response
Response - Block URL - Zscaler ZIA 0 SOC EDR containment & response
Response - Run Device Scan - Microsoft Defender for Endpoints 0 SOC EDR containment & response
Response - Run Device Scan - SentinelOne 0 SOC EDR containment & response
Subflow - Isolation Logic - KQL for active user 241 SOC EDR containment & response
Calculate weekly isolation rate 5 SOC EDR containment & response
Subflow - Send D3 Response Action Notification 0 SOC EDR containment & response
Response - Device Response Actions - On-demand 1 SOC EDR containment & response
Response - User Response Actions - On-demand 1 SOC Identity threat response

Use Case 8 — Cloud Asset Coverage & Inventory

Description: Multi-source asset inventory aggregation pipeline that collects device and software inventory from Microsoft Defender, SentinelOne, Wiz, Rapid7, Entra ID, Intune, Zscaler, Jamf, and ServiceNow. Assets are correlated across sources and written to a shared inventory table for vulnerability correlation and coverage gap analysis.

Business Problem Solved: Without a unified asset inventory, vulnerability remediation cannot be accurately scoped. This use case continuously syncs asset records from all deployed security tools and identifies coverage gaps where EDR is missing.

Integrations: Microsoft Defender for Endpoints, SentinelOne, Wiz, Rapid7, Microsoft Entra ID, Intune, Zscaler, Jamf, ServiceNow, Spektion, Microsoft Active Directory

Playbook Executions (12 mo) Category Subcategory
Asset Ingestion Orchestrator 8 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Inventory Writer 3,126 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Defender for Endpoints 13 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - SentinelOne 5 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Wiz 3 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Ingestion Health Writer 60 Cloud Security Cloud asset coverage & inventory
Populate Product Connections Global Variable 5 Cloud Security Cloud asset coverage & inventory
Wiz Inventory Snapshot 17 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Coverage HTML Report Generator 6 Cloud Security Cloud asset coverage & inventory
User Ingestion Orchestrator 5 Cloud Security Cloud asset coverage & inventory
Subflow - Get Users - Microsoft Entra AD 5 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Inventory Cleanup 5 Cloud Security Cloud asset coverage & inventory
ServiceNow CMDB Host Lookup 7 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Reference Query Table Examples 3 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Table Schema 2 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Tables 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - ASM SQL Query 8 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent 0 Cloud Security Cloud asset coverage & inventory
Utility - Refresh Table Views 9 Cloud Security Cloud asset coverage & inventory
Utility - Tag Assets 11 Cloud Security Cloud asset coverage & inventory
Asset Ingestion Re-processing 4 Cloud Security Cloud asset coverage & inventory
Subflow - Format Connection List 8 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Post-Ingestion 5 Cloud Security Cloud asset coverage & inventory
Defender Host Lookup 2 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Active Directory 0 Cloud Security Cloud asset coverage & inventory
Query - Device - ASM 6 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Spektion 1 Cloud Security Cloud asset coverage & inventory
Subflow - Gather End of Life OS Details 1 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Metrics Computation 2 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Post-Ingestion 3 Cloud Security Cloud asset coverage & inventory
Scratchpad 0 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Ingestion Health Writer (new asset pipeline) 17 Cloud Security Cloud asset coverage & inventory
Subflow - Shared Inventory Writer (new asset pipeline) 940 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Wiz (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Active Directory (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
ServiceNow CMDB Host Lookup (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Inventory Cleanup (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Asset Coverage HTML Report Generator (new asset pipeline) 2 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Table Schema (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Asset Ingestion Orchestrator (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Format Connection List (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - SentinelOne (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Zscaler (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Entra AD (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - ServiceNow (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Microsoft Defender for Endpoint (new asset pipeline) 2 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Rapid7 InsightVM (new asset pipeline) 3 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Intune (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Jamf (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Subflow - Get Assets - Tanium (new asset pipeline) 1 Cloud Security Cloud asset coverage & inventory
Utility - Refresh Table Views (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Utility - Tag Assets (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - ASM SQL Query (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Subflow - Get Users - Microsoft Entra AD (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Query - Device - ASM (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Get ASM Tables (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
User Ingestion Orchestrator (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Defender Host Lookup (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
On Error Notification (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
ASM Analyst Agent - Ability - Reference Query Table Examples (new asset pipeline) 0 Cloud Security Cloud asset coverage & inventory
Utility - ASM Host Lookup 4 Cloud Security Cloud asset coverage & inventory

Use Case 9 — SaaS Application Governance

Description: Scheduled governance automation that queries Zscaler ZIA for third-party SaaS applications present in the environment, generates compliance views, and feeds findings into a reporting pipeline. Surfaces shadow IT and unauthorized application usage.

Business Problem Solved: Unmanaged SaaS applications represent a data leakage and compliance risk. This use case automates the detection and cataloging of all SaaS applications traversing the network perimeter.

Integrations: Zscaler ZIA, Microsoft Outlook

Playbook Executions (12 mo) Category Subcategory
Zscaler 3rd Party App Governance - Query Apps Present In Environment (scheduled) 40 Cloud Security Cloud access & SaaS policy mgmt
Zscaler 3rd Party App Governance - Query Apps Present In Environment (on-demand) 0 Cloud Security Cloud access & SaaS policy mgmt

Use Case 10 — GRC & Security Reporting

Description: Automated security metrics and executive reporting workflows including weekly threat intelligence reports and Blink automation reporting. Provides consistent, timely security status updates to stakeholders without manual report assembly.

Business Problem Solved: Preparing security metrics reports manually is error-prone and time-consuming. Automation ensures reports are generated on schedule with up-to-date data from live case management and vulnerability systems.

Integrations: Blink Case Management, Email

Playbook Executions (12 mo) Category Subcategory
Weekly Threat Intelligence Reporting 5 GRC Security metrics & reporting
Unowned Assets Report 0 GRC Security metrics & reporting
Monthly Threat Intelligence Reporting 1 GRC Security metrics & reporting

Use Case 11 — AI Agent Governance & Inventory

Description: A new automation program that discovers, correlates, and monitors AI agents deployed across the enterprise — pulling agent telemetry from Microsoft Defender (Security Copilot / M365 agent activity via Microsoft Graph) and Wiz (cloud-deployed AI agents), reconciling both sources into a unified AI-agent inventory with identity links, and computing governance/risk metrics (exposure, connected hubs, tool/MCP counts, shared-connection risk). Dashboards surface capability analytics and priority governance gaps.

Business Problem Solved: AI agents (Copilot extensions, cloud-hosted agents, MCP-connected tools) are proliferating faster than security teams can track them, creating an ungoverned identity and data-access surface. This use case builds the asset inventory and risk-scoring layer needed to bring AI agents under the same governance rigor as traditional endpoints and cloud resources.

Integrations: Microsoft Defender, Microsoft Graph (M365), Wiz, Blink Case Management

Playbook Executions (12 mo) Category Subcategory
Ingest M365 Agent Data 8 Cloud Security Cloud asset coverage & inventory
AI Agent Chunk Writer 375 Cloud Security Cloud asset coverage & inventory
MS Defender AI Agent Reporting Dashboard 24 Cloud Security Cloud asset coverage & inventory
Wiz Agent Data Writer 0 Cloud Security Cloud asset coverage & inventory
Wiz AI Agent Ingestion 4 Cloud Security Cloud asset coverage & inventory
Wiz AI Agent Metrics Dashboard 1 Cloud Security Cloud asset coverage & inventory
AI Agent Unified Inventory Builder 0 Cloud Security Cloud asset coverage & inventory
AI Agent Metric Observation Builder 1 Cloud Security Cloud asset coverage & inventory
AI Agent Unified Metrics Dashboard 1 Cloud Security Cloud asset coverage & inventory
AI Agent Unified Inventory IO Worker 1 Cloud Security Cloud asset coverage & inventory
Get Spektion AI Software from VM Workspace 1 Cloud Security Cloud asset coverage & inventory
Defender AI Agent Capability Analytics 1 Cloud Security Config audit & remediation
Defender AI Agent Component Metrics Builder 0 Cloud Security Config audit & remediation

4. Key Observations

Strengths

Deep, production-grade Vulnerability Management program. NIQ has built one of the most sophisticated VM automation programs in the Blink customer base. The ADLS pipeline ingests vulnerabilities from three scanner families (Defender, Rapid7, Wiz) across multiple business unit instances (NIQ + GFK), normalizes to OCSF, enriches with KEV/EPSS/NVD context, correlates cross-source, and drives Jira remediation ticket creation — all automated. The daily cadence of KEV, EPSS, and NVD dimension builds (38–40 executions each) and Defender/R7/Wiz ingestion runs (127–1,348 executions) demonstrates genuine production reliance.

High-volume SOC automation is operational and running. The Case Orchestrator and Observable Orchestrator together processed nearly 7,700 items in the past 12 months. The enrichment chain (Observable Router → per-tool Hunt subflows → Update Observable Findings at 4,154 executions) is clearly handling real alert volume, not just testing.

Agentic security capabilities are deployed. NIQ has production AI agents for three distinct functions: TI Analyst Agent (threat intelligence interrogation), VM Analyst Agent (natural language vulnerability datalake queries), and a VM Operator Agent with full pipeline tooling. This positions NIQ ahead of most customers in deploying agentic security workflows.

Breadth of integration ecosystem. NIQ's automation spans: Microsoft Defender XDR, SentinelOne, Wiz, Rapid7 InsightVM, Microsoft Entra ID, Microsoft Intune, Zscaler ZIA/SSPM, SailPoint, AlienVault OTX, Cycode, ServiceNow, Jira, Azure Synapse / ADLS, CISA KEV, EPSS, NVD — a mature, enterprise-scale integration footprint.

Cross-business-unit coverage. The VM pipeline explicitly handles both the NIQ and GFK entities with separate scanner connections, reflecting a post-merger integration use case where automation bridges organizational boundaries.

New: AI Agent Governance program stood up. NIQ has launched a dedicated workspace and pipeline (Use Case 11) to inventory and risk-score AI agents across Microsoft Defender/M365 and Wiz — reconciling both sources into a unified inventory, computing exposure and shared-connection risk metrics, and publishing governance dashboards. The AI Agent Chunk Writer alone processed 375 records in its first period, indicating active, ongoing discovery rather than a one-time pilot. This positions NIQ ahead of the curve on a fast-emerging AI-agent attack surface.

New: second asset ingestion pipeline stood up with EOL-OS and metrics capabilities. A new workspace mirrors the core asset-inventory subflows (shared inventory writer, ingestion health writer, cleanup, coverage reporting) and adds two new capabilities not previously present: end-of-life OS detection and asset metrics computation. It also extends source coverage with Spektion and Microsoft Active Directory connectors, and has since added parallel Get-Assets connectors for SentinelOne, Zscaler, Microsoft Entra AD, ServiceNow, Microsoft Defender for Endpoint, Rapid7 InsightVM, Intune, Jamf, and Tanium — effectively rebuilding the full source breadth of the original pipeline within the new architecture. The inventory writer alone processed 940 records, indicating active parallel rollout rather than a dormant fork. The pipeline has since gained its own user-ingestion orchestrator, ASM Analyst Agent abilities, device/host lookup subflows, and error-notification handling — mirroring the original pipeline's full operator toolset, though these newest additions have not yet accrued executions.

VM scanner coverage expanded significantly. Beyond Defender, Rapid7, and Wiz, NIQ has added Spektion, Tanium, and SecurityScorecard as new vulnerability/software-risk data sources, each with its own ingestion, writer, and hunting playbooks already producing meaningful volume (Spektion and Tanium software hunts each running in the 200+ execution range, on par with the original three scanners).

Gaps and Opportunities

Response playbooks built but not yet executing. Several high-value response actions have 0 executions: IOC blocking (Defender for Endpoint, SentinelOne, Zscaler), device isolation (Defender, SentinelOne), and user credential reset (Entra). The approval workflow infrastructure exists and is running (693 IOC response trigger events fired). The gap suggests response is still requiring manual confirmation at a high rate, or the blocking/isolation capabilities are staged for broader rollout. Activating automated response for confirmed malicious IOCs would significantly reduce dwell time.

WF0–WF7 table-based VM pipeline has 0 executions. The older workspace (06f7470e) containing WF0–WF8 workflows shows zero execution across all workflows. All active VM pipeline execution is occurring in the newer workspace (b76c3ccc). The older workspace appears to be a superseded iteration — these playbooks could be archived to reduce maintenance overhead.

User Response Actions workflow has 0 executions. The Response - User Response Actions event-based workflow (which responds to compromised user table records) fired 0 times, while the Device Response Actions workflow fired 14. This asymmetry suggests the user response workflow may not be connected to the active case management tables.

Software CVE hunt executions appear pooled across wrapper playbooks. The Blink VM integration wrapper playbooks (Hunt - Software - SentinelOne - Blink Vulnerability Management, Hunt - Software - Wiz - Blink Vulnerability Management, Hunt - Software - Cycode - Blink Vulnerability Management) each show 1,044 executions — likely the same hunt batch running across all three sources in parallel. The underlying direct hunt playbooks (Hunt - Software - SentinelOne, Hunt - Software - Wiz at 1,044 and Hunt - Software - Cycode at 1,109) show consistent counts, confirming a live software hunt program.

ASM workspace (2a845363) has no active playbooks. The Attack Surface Management workspace contains several drafted workflows (Coverage Gap - Alert and Ticket, Ingestion Health Monitor, ASM Agent) with 0 executions. This appears to be an emerging capability being developed rather than production automation.

Integration Ecosystem Summary

Tool Category Role in Automation
Microsoft Defender XDR / MDE EDR / VM IOC hunting, device containment, vulnerability ingestion
SentinelOne EDR IOC hunting, device isolation, scan initiation, software inventory
Wiz CSPM / VM Cloud vulnerability ingestion, SBOM hunting, TI notifications
Rapid7 InsightVM Cloud VM Scanner Vulnerability ingestion (NIQ + GFK entities)
Microsoft Entra ID IAM User enrichment, device attribution, MFA revocation, batch lookups
Microsoft Intune MDM Device enrichment, offboarding device management
SailPoint IAM / HR Termination and activation event source
Zscaler ZIA / SSPM Network / SaaS IOC URL blocking, SaaS app governance
ServiceNow CMDB / ITSM CMDB asset ingestion, ticket routing
Jira Ticketing Remediation ticket creation and assignment
Azure Synapse / ADLS Data Platform Vulnerability datalake, SLA metrics, analytics
AlienVault OTX Threat Intel IOC enrichment
Cycode AppSec / VM Software CVE hunting
CISA KEV / EPSS / NVD Threat Intel Vulnerability prioritization dimensions
Microsoft Outlook Email TI notification ingestion, reporting delivery
Microsoft Teams Collaboration Response approval requests
Spektion Software Risk / VM Software CVE hunting, software risk inventory ingestion
Tanium Endpoint Mgmt / VM Software CVE hunting, software inventory ingestion
SecurityScorecard Security Ratings / VM Vulnerability and patching-cadence issue ingestion
Microsoft Graph / M365 AI Agent Governance AI agent discovery and activity ingestion for governance
Microsoft Active Directory IAM / Asset Inventory On-prem asset and identity source for inventory
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
NIQ winrm winrm_connection 2026-08-11