01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC — AI-Driven Investigation |
| 75.0% | 22 22 active |
| SIEM Alert Ingestion & Pipeline | 0 executions | 0.0% | 5 5 active |
| Alert Enrichment & IOC Lookup |
| 0.0% | 35 35 active |
| Phishing Detection & Response |
| 0.0% | 4 4 active |
| EDR Containment & Malware Response | 0 executions | 0.0% | 7 7 active |
| Identity Threat Response | 0 executions | 0.0% | 8 8 active |
| Threat Intel & Ad-Hoc Investigation | 0 executions | 0.0% | 14 12 active |
| DLP & Cloud App Security Monitoring |
| 0.0% | 2 2 active |
| Endpoint Visibility & Hygiene | 0 executions | 0.0% | 6 6 active |
| Case Management Platform & Utilities | 0 executions | 0.0% | 15 15 active |
| Total | 3 executions | 100% | 118 116 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. Fully operational Agentic SOC pipeline. The active workspace (75205226) runs a mature, production-grade Agentic SOC that ingests Splunk alerts, extracts observables, enriches them, and routes each alert through AI-driven expert agents for triage. With 1,098 alerts ingested and 227 processed end-to-end, this is a live, high-value automation — not a proof of concept.
2. Purpose-built AI agent architecture. The deployment goes beyond rule-based automation: the Decision Layer, Expert Agents (phishing, malware, identity), and 14+ Agent Ability playbooks form a genuine AI SOC analyst backed by real data (VIP users table, org assets, historical cases). The 489 VIP user lookups and 184 observable enrichment queries from agents show active use during live investigations.
3. Deep Microsoft stack coverage. Microsoft Entra ID, Defender for Endpoints, Defender XDR, Defender for Cloud Apps, Intune, and Azure Monitor are all wired in — reflecting the customer's Microsoft-centric environment. Identity enrichment is the most active enrichment source (359 executions), confirming Entra ID is central to investigation workflows.
4. Rich enrichment framework. The observable enrichment library covers every major IOC type (IP, URL, hash, username/email, domain, agent ID) across 7+ intelligence sources. While most enrichers currently show 0 executions, the routing infrastructure is live and firing 840 times — suggesting enrichments are succeeding silently or most alerts currently carry only user-type observables.
5. Splunk as the primary alert source. Three distinct Splunk saved searches are actively feeding the pipeline (SOC 54, SOC 95, SOC 270), accounting for all 1,098 ingested alerts. This is a well-structured, multi-rule Splunk integration.
###
Gaps & Opportunities
1. Enrichment sources other than Entra ID are not firing. VirusTotal, AbuseIPDB, CrowdStrike, URLScan, and Okta enrichers all show 0 executions despite being deployed. This likely means either (a) observable extraction templates are not yet configured for hash/IP/URL types in current alert templates, or (b) the Splunk alerts feeding the pipeline primarily generate user-type observables. Enabling additional observable types would multiply the depth of automated context.
2. Phishing and malware response playbooks are built but disconnected. The phishing response subflow, the Splunk phishing ingest playbooks, and the MDE isolation/AV scan workflows all show 0 executions. These represent ready-built automation that could immediately extend coverage if connected to live alert sources.
3. Threat intel tools are underutilized. Recorded Future is deployed (domain search, malware search, Triage Cloud, and an IP enricher with 1 execution), but the ad-hoc threat hunting workspace (17db3b15) shows no production usage. The agentic Splunk Threat Hunter and SIEM Hunt Bot are built but idle — an opportunity to activate agentic threat hunting as a force multiplier.
4. Identity response is read-only. Workflows for disabling accounts, revoking sessions, and isolating endpoints exist but have 0 executions. The Agentic SOC pipeline currently stops at investigation — activating automated containment actions would reduce MTTR for confirmed identity and endpoint threats.
5. Spycloud BIN list export is empty. Given the customer's financial services profile, the Spycloud integration for payment card fraud monitoring is a notable capability that has not yet been built out. This is a gap worth prioritizing given the regulatory and fraud risk context.
Integration Ecosystem
| Integration | Category | Usage |
|---|---|---|
| Splunk | SIEM | Active — 1,098 alerts ingested |
| Microsoft Entra ID | Identity | Active — 359 enrichments |
| Microsoft Defender for Cloud Apps (MCAS) | CASB / DLP | Active — 15 queries |
| Blink Case Management | SOAR | Active — core platform |
| CrowdStrike Falcon | EDR / Threat Intel | Built, idle in production |
| VirusTotal | Threat Intel | Built, idle |
| Recorded Future | Threat Intel | Built, 1 execution |
| AbuseIPDB | Threat Intel | Built, idle |
| URLScan | Threat Intel | Built, idle |
| Microsoft Defender for Endpoints | EDR | Built, idle |
| Microsoft Defender XDR | XDR | Built, idle |
| Microsoft Intune | MDM | Built, idle |
| Okta | Identity | Built, idle |
| Trend Vision One | EDR | Built, idle |
| Slack | Communication / Identity | Built, idle |
| GitHub | Developer Identity | Built, idle |
| Google Workspace | Identity | Built, idle |
| Azure Monitor | Cloud Logs | Built, idle |
| Glean | Enterprise Search | Built, idle |
| Confluence | Documentation | Built, idle |
| Spycloud | Fraud / Credential Intel | Skeleton only |
A Case Management 275 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| SOC AI | 269 | 269 | 0 | N/A |
| Case Management | 6 | 6 | 0 | N/A |
B AI Agents 10 active | 1,103 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink - Decision Maker | SOC AI | 538 | 0 | 39,736,985 |
| 2 | Micro Agent - Historical Case Check | SOC AI | 273 | 0 | 12,976,218 |
| 3 | SOC Agent - Phishing Agent | SOC AI | 107 | 0 | 14,386,360 |
| 4 | SOC Agent - Core Investigator Agent | SOC AI | 97 | 0 | 12,104,319 |
| 5 | MCAS DLP Investigation Agent | SOC AI | 37 | 0 | 3,879,366 |
| Workspace | Tasks (12m) |
|---|---|
| SOC AI | 1,099 |
| POV Use Cases | 4 |
| Case Management | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Workflow Summary | 0 | 0 |
| 2 | SOC AI Overview | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 10 use cases | 4 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-ingested from Splunk | 1,098 | Splunk SOC 270 Alert Ingest (654) · Splunk Alerts Ingest - SOC 95 (387) · Splunk SOC 54 Alert Ingest (57) |
| Threat observables automatically enriched | 840 | Subflow - Enrich Observables - Main Router |
| AI-driven triage decisions executed | 336 | Agentic SOC - Decision Layer |
| Alerts processed end-to-end through Agentic SOC | 227 | Process Alert |
| User identity records enriched via Microsoft Entra ID | 359 | Enrich - Username or Email - Microsoft Entra ID |
| Enrichment records written back to case management | 214 | Subflow - Update Enrichment Data |
| VIP user context lookups by AI agents | 489 | Agent Ability - Get VIP Users |
| Phishing investigation triage sessions | 81 | Agent Ability - Get Phishing Questions |
| Asset context lookups by AI agents | 153 | Agent Ability - Get Org Assets |
| MCAS user activity queries during investigations | 15 | Agent Ability - Get User activity MCAS |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks |
|---|---|---|---|---|
| 1 | Agentic SOC — AI-Driven Investigation | SOC | Agentic SOC, Case mgmt & SOAR | 24 |
| 2 | SIEM Alert Ingestion & Pipeline | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR | 7 |
| 3 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 55 |
| 4 | Phishing Detection & Response | SOC | Phishing detection & response | 4 |
| 5 | EDR Containment & Malware Response | SOC | EDR containment & response | 9 |
| 6 | Identity Threat Response | SOC | Identity threat response | 8 |
| 7 | Threat Intel & Ad-Hoc Investigation | SOC | Threat intel ingest & curation | 14 |
| 8 | DLP & Cloud App Security Monitoring | GRC | DLP triage & exposure resp | 2 |
| 9 | Endpoint Visibility & Hygiene | Other | Endpoint hygiene & MDM ops | 6 |
| 10 | Case Management Platform & Utilities | SOC | Case mgmt & SOAR | 30 |
Use Cases
1. Agentic SOC — AI-Driven Investigation
Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR
Description: An AI-driven SOC pipeline where each incoming alert is investigated by a coordinated set of specialized agents — phishing analyst, malware analyst, identity analyst — that gather context, query historical cases, look up VIP users, and produce a triage decision (close, escalate, or request analyst input).
Business Problem: Security alerts arrive faster than analysts can manually triage. This pipeline autonomously works each alert from extraction through enrichment, AI investigation, and response routing, reducing mean time to triage and preventing alert backlog.
Integrations: Blink Case Management, Microsoft Entra ID, CrowdStrike, Okta, VirusTotal, Slack, Splunk
9da53177 (Process Alert, Subflow - Response - Main Router) with 0 executions — superseded by the active workspace above.2. SIEM Alert Ingestion & Pipeline
Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR
Description: Webhook-based ingestion of Splunk search alerts into the Blink case management platform. Three distinct Splunk saved search IDs (SOC 270, SOC 95, SOC 54) each fire on separate alert categories, normalize the payload, and create structured alerts for downstream Agentic SOC processing.
Business Problem: Alert ingestion from Splunk is manual-prone without automation — analysts must context-switch between SIEM and case management. This pipeline provides continuous, normalized alert flow directly from Splunk into the investigation queue.
Integrations: Splunk, Blink Case Management, Microsoft Defender XDR (XDR username normalization)
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Splunk SOC 270 Alert Ingest | 654 | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR |
| Splunk Alerts Ingest - SOC 95 | 387 | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR |
| Splunk SOC 54 Alert Ingest | 57 | SOC | SIEM & log pipeline monitoring, Case mgmt & SOAR |
| Subflow - Splunk Ingestion with Raw Events | 57 | SOC | SIEM & log pipeline monitoring |
| XDR Username to UPN | 57 | SOC | SIEM & log pipeline monitoring, Identity threat response |
| Splunk Ingest - Splunk Ms Phishing Alert (Custom) | — | SOC | SIEM & log pipeline monitoring, Phishing detection & response |
| Splunk Ingest - Splunk Ms Phishing Alert (General) | — | SOC | SIEM & log pipeline monitoring, Phishing detection & response |
3. Alert Enrichment & IOC Lookup
Category: SOC | Subcategories: Alert enrichment / IOC lookup
Description: A comprehensive observable enrichment framework that automatically queries multiple threat intel and identity sources for every new IOC (IP, URL, hash, username, email, domain) extracted from incoming alerts. A main routing subflow dispatches to source-specific enrichers and writes results back to the case management record.
Business Problem: Manual IOC lookups across CrowdStrike, VirusTotal, Okta, Entra ID, and other tools consume significant analyst time per alert. This framework runs all enrichments in parallel automatically, giving analysts pre-populated context when they open a case.
Integrations: Microsoft Entra ID, Okta, CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Recorded Future, GitHub, Google Workspace, Slack, Whois/Dig, Blink Case Management
Active Workspace (75205226)
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Subflow - Enrich Observables - Main Router | 840 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 214 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | 359 | SOC | Alert enrichment / IOC lookup, Identity threat response |
| Get User Information Using Microsoft Entra ID | 359 | SOC | Alert enrichment / IOC lookup, Identity threat response |
| Enrich - IP - RecordedFuture | 1 | SOC | Alert enrichment / IOC lookup, Threat intel ingest & curation |
| SubFlow - Context Enrichment | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Username - Github | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Crowdstrike Threatgraph Enrichment | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Check If Observable inside Organization | — | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | — | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Okta | — | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Github | — | SOC | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | — | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | — | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | — | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | — | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | — | SOC | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | — | SOC | Alert enrichment / IOC lookup |
| Okta Search for User Activity | — | SOC | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | — | SOC | Alert enrichment / IOC lookup, Phishing detection & response |
| Get End of Life Date for a Product | — | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Query Observables by Content | — | SOC | Alert enrichment / IOC lookup |
| Query Observable | — | SOC | Alert enrichment / IOC lookup |
| Get Observables by Case ID | — | SOC | Alert enrichment / IOC lookup |
9da53177 (all with 0 executions). The active workspace above is the production environment. Legacy equivalents include: Subflow - Enrich Observables - Main Router · Enrich - IP - VT · Enrich - Hash - VT · Enrich - URL - VT · Enrich - URL - URLScan · Enrich - IP - IPDB · Enrich - Username or Email - Okta · Enrich - Username or Email - Microsoft Entra ID · Enrich - Username or Email - Google Workspace · Enrich - Hash - Crowdstrike · Enrich - IP or Domain - Whois · Enrich - IP or Domain - Whois copy · Enrich - Email Address - Slack · Enrich - Username - Github · Enrich - Agent ID - Crowdstrike · Subflow - Update Enrichment Data · Get User Information Using Microsoft Entra ID · Get User Information Using Google Workspace · Get User Information Using Github · Get User Information on Email Address Using Slack · Get Hash Info Using VirusTotal · Get Hash Info Using Crowdstrike · Enrich IP or Domain Using Whois · Run Dig Command · Analyze URL with URLScan · Okta Search for User Activity · Secure URL Screenshot Capture · Get End of Life Date for a Product · Get User Activity from Azure Logs4. Phishing Detection & Response
Category: SOC | Subcategories: Phishing detection & response, SIEM & log pipeline monitoring
Description: Detection and triage of phishing alerts sourced from Splunk (via Microsoft 365/Defender data) and from user-reported emails. The response subflow uses an AI Phishing Triage Analyst agent, retrieves the original email headers, and checks for KnowBe4 simulation markers before escalating or remediating.
Business Problem: Phishing is a high-volume alert category that requires consistent investigation steps across every case. Automation ensures no alert is skipped and simulation emails are automatically filtered from true investigations.
Integrations: Splunk, Microsoft Outlook, Microsoft Graph, Blink Case Management, KnowBe4
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Agent Ability - Get Phishing Questions | 81 | SOC | Phishing detection & response, Agentic SOC |
| Response Subflow - Phishing | — | SOC | Phishing detection & response |
| Splunk Ingest - Splunk Ms Phishing Alert (Custom) | — | SOC | Phishing detection & response, SIEM & log pipeline monitoring |
| Splunk Ingest - Splunk Ms Phishing Alert (General) | — | SOC | Phishing detection & response, SIEM & log pipeline monitoring |
5. EDR Containment & Malware Response
Category: SOC | Subcategories: EDR containment & response
Description: Automated endpoint isolation and malware response using CrowdStrike Falcon and Microsoft Defender for Endpoints. Covers device quarantine/unquarantine, Remote Terminal Response (RTR) command execution on single or batch hosts, antivirus scan initiation, and endpoint isolation via MDE.
Business Problem: Containing a compromised endpoint requires immediate, consistent action across tools. Manual isolation steps are time-critical; automation eliminates the delay between detection and containment.
Integrations: CrowdStrike Falcon, Microsoft Defender for Endpoints, Blink Case Management
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Agent Ability - Get Malware Questions | 14 | SOC | EDR containment & response, Agentic SOC |
| Manage Endpoint Quarantine Status in Crowdstrike | — | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | — | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | — | SOC | EDR containment & response |
| Isolate Endpoint in MDE | — | SOC | EDR containment & response |
| Initiate AV Scan using MDE | — | SOC | EDR containment & response |
| Response Subflow - Malware | — | SOC | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | — | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | — | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | — | SOC | EDR containment & response |
6. Identity Threat Response
Category: SOC | Subcategories: Identity threat response
Description: Automated response to identity-based threats including risky user detection, account disablement across on-premises Active Directory and Microsoft Entra ID, session revocation, user membership analysis, and Defender XDR alert investigation. Covers the full identity containment workflow from detection to remediation.
Business Problem: Identity compromise is the leading attack vector; delayed account disablement directly extends attacker dwell time. Automation ensures consistent, immediate response across both cloud and on-premises directory services simultaneously.
Integrations: Microsoft Entra ID, Microsoft Defender XDR, On-premises Active Directory
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Disable an account in on-prem AD as well as EntraID and revoke Sessions | — | SOC | Identity threat response |
| Get Risky User with Microsoft Entra ID and Send Results via Email copy | — | SOC | Identity threat response |
| List Risky Users with Microsoft Entra ID and Send Results via Email copy | — | SOC | Identity threat response |
| List User Membership with Microsoft Entra ID and Send Results via Email copy | — | SOC | Identity threat response |
| Get User Details with Microsoft Entra ID and Send Results via Email copy | — | SOC | Identity threat response |
| List Alerts with Microsoft Defender XDR and Send Results via Email copy | — | SOC | Identity threat response |
| Microsoft Defender XDR Custom Action and Send Results via Email copy | — | SOC | Identity threat response |
| Defender User Lookup | — | SOC | Identity threat response |
7. Threat Intel & Ad-Hoc Investigation
Category: SOC | Subcategories: Threat intel ingest & curation
Description: On-demand and ad-hoc threat intelligence workflows for analyst-initiated lookups across Recorded Future, VirusTotal, Splunk, and CrowdStrike. Includes an agentic threat hunting bot (SIEM Hunt Bot and AdHOC threat hunt bot) that can run Splunk queries autonomously and publish reports to Confluence.
Business Problem: Analysts need rapid, repeatable access to threat intelligence during investigations. These playbooks expose complex multi-tool lookups as single-click operations and enable an AI agent to autonomously hunt for IOCs across the SIEM.
Integrations: Recorded Future, Recorded Future Triage Cloud, VirusTotal, Splunk, CrowdStrike, Glean, Confluence, Spycloud
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Agent Ability - Splunk Threat Hunter | — | SOC | Threat intel ingest & curation |
| Agent Ability - Run Splunk Search | — | SOC | Threat intel ingest & curation |
| Agent Ability - Get Splunk Schema | — | SOC | Threat intel ingest & curation |
| Search Domain with Recorded Future and Send Results via Email | — | SOC | Threat intel ingest & curation |
| Search Malware with Recorded Future and Send Results via Email | — | SOC | Threat intel ingest & curation |
| Submit Sample with Recorded Future Triage Cloud and Send Results via Email | — | SOC | Threat intel ingest & curation |
| Create Search Job with Splunk and Send Results via Email | — | SOC | Threat intel ingest & curation |
| VirusTotal IP ADHOC | — | SOC | Threat intel ingest & curation |
| Splunk Login ADHOC | — | SOC | Threat intel ingest & curation |
| Crowdstrike EDR ADHOC | — | SOC | Threat intel ingest & curation |
| Call Searching bot | — | SOC | Threat intel ingest & curation, Agentic SOC |
| Call ADHOC hunt bot | — | SOC | Threat intel ingest & curation, Agentic SOC |
| Saved Query | — | SOC | Threat intel ingest & curation |
| Exporting Bin List from Spycloud | — | GRC | AML / KYC compliance |
8. DLP & Cloud App Security Monitoring
Category: GRC | Subcategories: DLP triage & exposure resp
Description: Agent-accessible abilities to query Microsoft Defender for Cloud Apps (MCAS) for user activity and DLP policy details during active investigations. These playbooks extend the Agentic SOC's capabilities to include cloud app behavior context when investigating potential data exposure or insider threat scenarios.
Business Problem: DLP alerts in isolation lack user behavior context. These playbooks enable AI agents to automatically pull MCAS activity timelines and policy details, enriching investigations with cloud app behavior without requiring analyst intervention.
Integrations: Microsoft Defender for Cloud Apps (MCAS)
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Agent Ability - Get User activity MCAS | 15 | GRC | DLP triage & exposure resp |
| Agent Ability - Get MCAS DLP Policy | 15 | GRC | DLP triage & exposure resp |
9. Endpoint Visibility & Hygiene
Category: Other | Subcategories: Endpoint hygiene & MDM ops
Description: On-demand endpoint lookup and management across Microsoft Intune and Trend Vision One. Enables security analysts to query device health, compliance state, and encryption status by device name or ID, run malware scans, and list endpoint inventory.
Business Problem: Endpoint hygiene investigations require pulling device data from multiple MDM and EDR platforms. These playbooks surface device compliance, encryption, and management state on demand without analyst access to each tool console.
Integrations: Microsoft Intune, Trend Vision One
| Playbook | Executions | Category | Subcategories |
|---|---|---|---|
| Get Managed Device with Microsoft Intune and Send Results via Email | — | Other | Endpoint hygiene & MDM ops |
| Get Managed Device with Microsoft Intune using device name, Send Results via Email | — | Other | Endpoint hygiene & MDM ops |
| Run Malware Scan on Endpoint with Trend Vision One and Send Results via Email | — | Other | Endpoint hygiene & MDM ops |
| List Endpoints with Trend Vision One and Send Results via Email | — | Other | Endpoint hygiene & MDM ops |
| Get Endpoint with Trend Vision One and Send Results via Email | — | Other | Endpoint hygiene & MDM ops |
| Query an endpoint by full endpoint name in TrendOne and have the results displayed and emailed | — | Other | Endpoint hygiene & MDM ops |
10. Case Management Platform & Utilities
Category: SOC | Subcategories: Case mgmt & SOAR
Description: Supporting infrastructure for the Blink Case Management platform — observable relation management, stale case cleanup, error handling, alert template validation, and recovery workflows for unprocessed alerts or un-enriched observables. These playbooks maintain the integrity and operational health of the SOC platform.
Business Problem: SOAR platforms accumulate stale cases, missing enrichments, and unprocessed alerts without active maintenance. This utility layer ensures data quality, enables re-processing of failed items, and provides consistent error notification to the SOC team.
Active Workspace (75205226)
Key Observations
Strengths
1. Fully operational Agentic SOC pipeline. The active workspace (75205226) runs a mature, production-grade Agentic SOC that ingests Splunk alerts, extracts observables, enriches them, and routes each alert through AI-driven expert agents for triage. With 1,098 alerts ingested and 227 processed end-to-end, this is a live, high-value automation — not a proof of concept.
2. Purpose-built AI agent architecture. The deployment goes beyond rule-based automation: the Decision Layer, Expert Agents (phishing, malware, identity), and 14+ Agent Ability playbooks form a genuine AI SOC analyst backed by real data (VIP users table, org assets, historical cases). The 489 VIP user lookups and 184 observable enrichment queries from agents show active use during live investigations.
3. Deep Microsoft stack coverage. Microsoft Entra ID, Defender for Endpoints, Defender XDR, Defender for Cloud Apps, Intune, and Azure Monitor are all wired in — reflecting the customer's Microsoft-centric environment. Identity enrichment is the most active enrichment source (359 executions), confirming Entra ID is central to investigation workflows.
4. Rich enrichment framework. The observable enrichment library covers every major IOC type (IP, URL, hash, username/email, domain, agent ID) across 7+ intelligence sources. While most enrichers currently show 0 executions, the routing infrastructure is live and firing 840 times — suggesting enrichments are succeeding silently or most alerts currently carry only user-type observables.
5. Splunk as the primary alert source. Three distinct Splunk saved searches are actively feeding the pipeline (SOC 54, SOC 95, SOC 270), accounting for all 1,098 ingested alerts. This is a well-structured, multi-rule Splunk integration.
Gaps & Opportunities
1. Enrichment sources other than Entra ID are not firing. VirusTotal, AbuseIPDB, CrowdStrike, URLScan, and Okta enrichers all show 0 executions despite being deployed. This likely means either (a) observable extraction templates are not yet configured for hash/IP/URL types in current alert templates, or (b) the Splunk alerts feeding the pipeline primarily generate user-type observables. Enabling additional observable types would multiply the depth of automated context.
2. Phishing and malware response playbooks are built but disconnected. The phishing response subflow, the Splunk phishing ingest playbooks, and the MDE isolation/AV scan workflows all show 0 executions. These represent ready-built automation that could immediately extend coverage if connected to live alert sources.
3. Threat intel tools are underutilized. Recorded Future is deployed (domain search, malware search, Triage Cloud, and an IP enricher with 1 execution), but the ad-hoc threat hunting workspace (17db3b15) shows no production usage. The agentic Splunk Threat Hunter and SIEM Hunt Bot are built but idle — an opportunity to activate agentic threat hunting as a force multiplier.
4. Identity response is read-only. Workflows for disabling accounts, revoking sessions, and isolating endpoints exist but have 0 executions. The Agentic SOC pipeline currently stops at investigation — activating automated containment actions would reduce MTTR for confirmed identity and endpoint threats.
5. Spycloud BIN list export is empty. Given the customer's financial services profile, the Spycloud integration for payment card fraud monitoring is a notable capability that has not yet been built out. This is a gap worth prioritizing given the regulatory and fraud risk context.
Integration Ecosystem
| Integration | Category | Usage |
|---|---|---|
| Splunk | SIEM | Active — 1,098 alerts ingested |
| Microsoft Entra ID | Identity | Active — 359 enrichments |
| Microsoft Defender for Cloud Apps (MCAS) | CASB / DLP | Active — 15 queries |
| Blink Case Management | SOAR | Active — core platform |
| CrowdStrike Falcon | EDR / Threat Intel | Built, idle in production |
| VirusTotal | Threat Intel | Built, idle |
| Recorded Future | Threat Intel | Built, 1 execution |
| AbuseIPDB | Threat Intel | Built, idle |
| URLScan | Threat Intel | Built, idle |
| Microsoft Defender for Endpoints | EDR | Built, idle |
| Microsoft Defender XDR | XDR | Built, idle |
| Microsoft Intune | MDM | Built, idle |
| Okta | Identity | Built, idle |
| Trend Vision One | EDR | Built, idle |
| Slack | Communication / Identity | Built, idle |
| GitHub | Developer Identity | Built, idle |
| Google Workspace | Identity | Built, idle |
| Azure Monitor | Cloud Logs | Built, idle |
| Glean | Enterprise Search | Built, idle |
| Confluence | Documentation | Built, idle |
| Spycloud | Fraud / Credential Intel | Skeleton only |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.