Blink Security Automation — Confidential

GreenDot — Customer Success Report

Generated 2026-09-10 | greendot-value-report.md
2026-09-10Report Date
294Total Playbooks
46Unique Workflows (12m)
42,969Actions Automated (12m)
$11,052Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

294
Total playbooks built
all non-deleted workflows
175
Active playbooks
currently enabled
46
Unique workflows executed (12m)
distinct workflows that ran
42,969
Actions automated (12m)
completed action steps
238.7h
Hours saved (12m)
@ 20s per action
$11,052
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
275
Total cases managed
275 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
10
Active AI agents
of 25 total
1,103
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 1,098 security alerts auto-ingested from Splunk into the SOC platform - 840 threat observables enriched automatically across IPs, users, hashes, and URLs - 336 autonomous AI-driven triage decisions executed without analyst intervention - 227 security incidents investigated end-to-end through the Agentic SOC pipeline - 359 user identity records queried automatically to support active investigations

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC — AI-Driven Investigation
  • 489VIP user context lookups by AI agents
  • 336AI-driven triage decisions executed
  • 227Alerts processed end-to-end through Agentic SOC
75.0%
22
22 active
SIEM Alert Ingestion & Pipeline0 executions
0.0%
5
5 active
Alert Enrichment & IOC Lookup
  • 840Threat observables automatically enriched
  • 359User identity records enriched via Microsoft Entra ID
  • 214Enrichment records written back to case management
0.0%
35
35 active
Phishing Detection & Response
  • 81Phishing investigation triage sessions
0.0%
4
4 active
EDR Containment & Malware Response0 executions
0.0%
7
7 active
Identity Threat Response0 executions
0.0%
8
8 active
Threat Intel & Ad-Hoc Investigation0 executions
0.0%
14
12 active
DLP & Cloud App Security Monitoring
  • 15MCAS user activity queries during investigations
0.0%
2
2 active
Endpoint Visibility & Hygiene0 executions
0.0%
6
6 active
Case Management Platform & Utilities0 executions
0.0%
15
15 active
Total3 executions100%
118
116 active

Use Case Growth Over Time

219 unique playbooks  |  10 operational use cases  |  4 total executions (12m)  |  2026-04 to 2026-06
Toggle:
Toggle:

03Integration Ecosystem

Threat Intel & Ad-Hoc Investigation
Recorded Future Email VirusTotal Splunk CrowdStrike Agents Glean Jira Slack Confluence Recorded Future Triage Cloud
Phishing Detection & Response
Microsoft Outlook Agents Splunk Microsoft Graph
Alert Enrichment & IOC Lookup
CrowdStrike Okta Google Workspace Microsoft Entra ID AbuseIPDB VirusTotal URLScan Recorded Future GitHub Slack Agents Check Point Harmony
Case Management Platform & Utilities
Email
EDR Containment & Malware Response
CrowdStrike Microsoft Defender For Endpoints Email
Identity Threat Response
Microsoft Entra ID Email Microsoft Defender XDR
Endpoint Visibility & Hygiene
Microsoft Intune Email Trend Vision One
Agentic SOC — AI-Driven Investigation
Agents
SIEM Alert Ingestion & Pipeline
Splunk Microsoft Defender XDR
DLP & Cloud App Security Monitoring
Microsoft Defender For Cloud Apps

04Key Observations

✓  Strengths

Strengths

1. Fully operational Agentic SOC pipeline. The active workspace (75205226) runs a mature, production-grade Agentic SOC that ingests Splunk alerts, extracts observables, enriches them, and routes each alert through AI-driven expert agents for triage. With 1,098 alerts ingested and 227 processed end-to-end, this is a live, high-value automation — not a proof of concept.

2. Purpose-built AI agent architecture. The deployment goes beyond rule-based automation: the Decision Layer, Expert Agents (phishing, malware, identity), and 14+ Agent Ability playbooks form a genuine AI SOC analyst backed by real data (VIP users table, org assets, historical cases). The 489 VIP user lookups and 184 observable enrichment queries from agents show active use during live investigations.

3. Deep Microsoft stack coverage. Microsoft Entra ID, Defender for Endpoints, Defender XDR, Defender for Cloud Apps, Intune, and Azure Monitor are all wired in — reflecting the customer's Microsoft-centric environment. Identity enrichment is the most active enrichment source (359 executions), confirming Entra ID is central to investigation workflows.

4. Rich enrichment framework. The observable enrichment library covers every major IOC type (IP, URL, hash, username/email, domain, agent ID) across 7+ intelligence sources. While most enrichers currently show 0 executions, the routing infrastructure is live and firing 840 times — suggesting enrichments are succeeding silently or most alerts currently carry only user-type observables.

5. Splunk as the primary alert source. Three distinct Splunk saved searches are actively feeding the pipeline (SOC 54, SOC 95, SOC 270), accounting for all 1,098 ingested alerts. This is a well-structured, multi-rule Splunk integration.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

1. Enrichment sources other than Entra ID are not firing. VirusTotal, AbuseIPDB, CrowdStrike, URLScan, and Okta enrichers all show 0 executions despite being deployed. This likely means either (a) observable extraction templates are not yet configured for hash/IP/URL types in current alert templates, or (b) the Splunk alerts feeding the pipeline primarily generate user-type observables. Enabling additional observable types would multiply the depth of automated context.

2. Phishing and malware response playbooks are built but disconnected. The phishing response subflow, the Splunk phishing ingest playbooks, and the MDE isolation/AV scan workflows all show 0 executions. These represent ready-built automation that could immediately extend coverage if connected to live alert sources.

3. Threat intel tools are underutilized. Recorded Future is deployed (domain search, malware search, Triage Cloud, and an IP enricher with 1 execution), but the ad-hoc threat hunting workspace (17db3b15) shows no production usage. The agentic Splunk Threat Hunter and SIEM Hunt Bot are built but idle — an opportunity to activate agentic threat hunting as a force multiplier.

4. Identity response is read-only. Workflows for disabling accounts, revoking sessions, and isolating endpoints exist but have 0 executions. The Agentic SOC pipeline currently stops at investigation — activating automated containment actions would reduce MTTR for confirmed identity and endpoint threats.

5. Spycloud BIN list export is empty. Given the customer's financial services profile, the Spycloud integration for payment card fraud monitoring is a notable capability that has not yet been built out. This is a gap worth prioritizing given the regulatory and fraud risk context.

Integration Ecosystem

Integration Category Usage
Splunk SIEM Active — 1,098 alerts ingested
Microsoft Entra ID Identity Active — 359 enrichments
Microsoft Defender for Cloud Apps (MCAS) CASB / DLP Active — 15 queries
Blink Case Management SOAR Active — core platform
CrowdStrike Falcon EDR / Threat Intel Built, idle in production
VirusTotal Threat Intel Built, idle
Recorded Future Threat Intel Built, 1 execution
AbuseIPDB Threat Intel Built, idle
URLScan Threat Intel Built, idle
Microsoft Defender for Endpoints EDR Built, idle
Microsoft Defender XDR XDR Built, idle
Microsoft Intune MDM Built, idle
Okta Identity Built, idle
Trend Vision One EDR Built, idle
Slack Communication / Identity Built, idle
GitHub Developer Identity Built, idle
Google Workspace Identity Built, idle
Azure Monitor Cloud Logs Built, idle
Glean Enterprise Search Built, idle
Confluence Documentation Built, idle
Spycloud Fraud / Credential Intel Skeleton only
Appendices
A Case Management 275 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
275
275 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 275 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
SOC AI 269 269 0 N/A
Case Management 6 6 0 N/A
B AI Agents 10 active | 1,103 tasks (12m)

AI Agents

Active Agents
10
of 25 total
Tasks Executed (12m)
1,103
0 in last 30d
Data Usage (12m)
88,343,115
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink - Decision Maker SOC AI 538 0 39,736,985
2 Micro Agent - Historical Case Check SOC AI 273 0 12,976,218
3 SOC Agent - Phishing Agent SOC AI 107 0 14,386,360
4 SOC Agent - Core Investigator Agent SOC AI 97 0 12,104,319
5 MCAS DLP Investigation Agent SOC AI 37 0 3,879,366
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
SOC AI1,099
POV Use Cases4
Case Management0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
2
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Workflow Summary 00
2 SOC AI Overview 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 10 use cases | 4 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-ingested from Splunk 1,098 Splunk SOC 270 Alert Ingest (654) · Splunk Alerts Ingest - SOC 95 (387) · Splunk SOC 54 Alert Ingest (57)
Threat observables automatically enriched 840 Subflow - Enrich Observables - Main Router
AI-driven triage decisions executed 336 Agentic SOC - Decision Layer
Alerts processed end-to-end through Agentic SOC 227 Process Alert
User identity records enriched via Microsoft Entra ID 359 Enrich - Username or Email - Microsoft Entra ID
Enrichment records written back to case management 214 Subflow - Update Enrichment Data
VIP user context lookups by AI agents 489 Agent Ability - Get VIP Users
Phishing investigation triage sessions 81 Agent Ability - Get Phishing Questions
Asset context lookups by AI agents 153 Agent Ability - Get Org Assets
MCAS user activity queries during investigations 15 Agent Ability - Get User activity MCAS
In the last 12 months, Blink automated: - 1,098 security alerts auto-ingested from Splunk into the SOC platform - 840 threat observables enriched automatically across IPs, users, hashes, and URLs - 336 autonomous AI-driven triage decisions executed without analyst intervention - 227 security incidents investigated end-to-end through the Agentic SOC pipeline - 359 user identity records queried automatically to support active investigations

Use Case Summary

# Use Case Category Subcategories Playbooks
1 Agentic SOC — AI-Driven Investigation SOC Agentic SOC, Case mgmt & SOAR 24
2 SIEM Alert Ingestion & Pipeline SOC SIEM & log pipeline monitoring, Case mgmt & SOAR 7
3 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 55
4 Phishing Detection & Response SOC Phishing detection & response 4
5 EDR Containment & Malware Response SOC EDR containment & response 9
6 Identity Threat Response SOC Identity threat response 8
7 Threat Intel & Ad-Hoc Investigation SOC Threat intel ingest & curation 14
8 DLP & Cloud App Security Monitoring GRC DLP triage & exposure resp 2
9 Endpoint Visibility & Hygiene Other Endpoint hygiene & MDM ops 6
10 Case Management Platform & Utilities SOC Case mgmt & SOAR 30

Use Cases

1. Agentic SOC — AI-Driven Investigation

Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR

Description: An AI-driven SOC pipeline where each incoming alert is investigated by a coordinated set of specialized agents — phishing analyst, malware analyst, identity analyst — that gather context, query historical cases, look up VIP users, and produce a triage decision (close, escalate, or request analyst input).

Business Problem: Security alerts arrive faster than analysts can manually triage. This pipeline autonomously works each alert from extraction through enrichment, AI investigation, and response routing, reducing mean time to triage and preventing alert backlog.

Integrations: Blink Case Management, Microsoft Entra ID, CrowdStrike, Okta, VirusTotal, Slack, Splunk

Playbook Executions Category Subcategories
Process Alert 227 SOC Agentic SOC, Case mgmt & SOAR
Agentic SOC - Decision Layer 336 SOC Agentic SOC
Agentic SOC - Expert Agents 168 SOC Agentic SOC
Subflow - Agentic SOC - Main - AI Investigation 168 SOC Agentic SOC
Subflow - Response - Main Router 168 SOC Agentic SOC, Case mgmt & SOAR
Agentic SOC - Close Case — SOC Agentic SOC, Case mgmt & SOAR
Agent Ability - Historical Case Checks 168 SOC Agentic SOC
Agent Ability - Get Case Observable's Enrichment 184 SOC Agentic SOC, Alert enrichment / IOC lookup
Agent Ability - Get VIP Users 489 SOC Agentic SOC, Identity threat response
Agent Ability - Get Org Assets 153 SOC Agentic SOC
Agent Ability - Get Core Agent Questions 58 SOC Agentic SOC
Agent Ability - Get Malware Questions 14 SOC Agentic SOC, EDR containment & response
Agent Ability - Get Phishing Questions 81 SOC Agentic SOC, Phishing detection & response
Agent Ability - Get Closing Questions — SOC Agentic SOC
Agent Ability - Recommendation for case — SOC Agentic SOC
Agent Ability - Get Alert — SOC Agentic SOC, Case mgmt & SOAR
Agent Ability - Get Case — SOC Agentic SOC, Case mgmt & SOAR
Agent Ability - Get Cases and Alerts Bulk — SOC Agentic SOC, Case mgmt & SOAR
Agent Ability - Get Case Types From Case Management Settings — SOC Agentic SOC
Agent Ability - Get Observable Reputations From Case Management Settings — SOC Agentic SOC, Alert enrichment / IOC lookup
Agent Ability - Get Observable Types From Case Management Settings — SOC Agentic SOC
Agent Ability - Get Observable Relation Types From Case Management Settings — SOC Agentic SOC
Agent Ability - Get Vendor Logo List — SOC Agentic SOC
Utility - Refresh investigation — SOC Agentic SOC, Case mgmt & SOAR
Note: A legacy version of this pipeline also exists in workspace 9da53177 (Process Alert, Subflow - Response - Main Router) with 0 executions — superseded by the active workspace above.

2. SIEM Alert Ingestion & Pipeline

Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR

Description: Webhook-based ingestion of Splunk search alerts into the Blink case management platform. Three distinct Splunk saved search IDs (SOC 270, SOC 95, SOC 54) each fire on separate alert categories, normalize the payload, and create structured alerts for downstream Agentic SOC processing.

Business Problem: Alert ingestion from Splunk is manual-prone without automation — analysts must context-switch between SIEM and case management. This pipeline provides continuous, normalized alert flow directly from Splunk into the investigation queue.

Integrations: Splunk, Blink Case Management, Microsoft Defender XDR (XDR username normalization)

Playbook Executions Category Subcategories
Splunk SOC 270 Alert Ingest 654 SOC SIEM & log pipeline monitoring, Case mgmt & SOAR
Splunk Alerts Ingest - SOC 95 387 SOC SIEM & log pipeline monitoring, Case mgmt & SOAR
Splunk SOC 54 Alert Ingest 57 SOC SIEM & log pipeline monitoring, Case mgmt & SOAR
Subflow - Splunk Ingestion with Raw Events 57 SOC SIEM & log pipeline monitoring
XDR Username to UPN 57 SOC SIEM & log pipeline monitoring, Identity threat response
Splunk Ingest - Splunk Ms Phishing Alert (Custom) — SOC SIEM & log pipeline monitoring, Phishing detection & response
Splunk Ingest - Splunk Ms Phishing Alert (General) — SOC SIEM & log pipeline monitoring, Phishing detection & response

3. Alert Enrichment & IOC Lookup

Category: SOC | Subcategories: Alert enrichment / IOC lookup

Description: A comprehensive observable enrichment framework that automatically queries multiple threat intel and identity sources for every new IOC (IP, URL, hash, username, email, domain) extracted from incoming alerts. A main routing subflow dispatches to source-specific enrichers and writes results back to the case management record.

Business Problem: Manual IOC lookups across CrowdStrike, VirusTotal, Okta, Entra ID, and other tools consume significant analyst time per alert. This framework runs all enrichments in parallel automatically, giving analysts pre-populated context when they open a case.

Integrations: Microsoft Entra ID, Okta, CrowdStrike, VirusTotal, AbuseIPDB, URLScan, Recorded Future, GitHub, Google Workspace, Slack, Whois/Dig, Blink Case Management

Active Workspace (75205226)

Playbook Executions Category Subcategories
Subflow - Enrich Observables - Main Router 840 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 214 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID 359 SOC Alert enrichment / IOC lookup, Identity threat response
Get User Information Using Microsoft Entra ID 359 SOC Alert enrichment / IOC lookup, Identity threat response
Enrich - IP - RecordedFuture 1 SOC Alert enrichment / IOC lookup, Threat intel ingest & curation
SubFlow - Context Enrichment — SOC Alert enrichment / IOC lookup
Enrich - IP - VT — SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB — SOC Alert enrichment / IOC lookup
Enrich - URL - VT — SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan — SOC Alert enrichment / IOC lookup
Enrich - Hash - VT — SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike — SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois — SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta — SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace — SOC Alert enrichment / IOC lookup
Enrich - Email Address - Slack — SOC Alert enrichment / IOC lookup
Enrich - Username - Github — SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike — SOC Alert enrichment / IOC lookup
Enrich - Crowdstrike Threatgraph Enrichment — SOC Alert enrichment / IOC lookup
Enrich - Check If Observable inside Organization — SOC Alert enrichment / IOC lookup
Get User Information Using Google Workspace — SOC Alert enrichment / IOC lookup
Get User Information Using Okta — SOC Alert enrichment / IOC lookup
Get User Information Using Github — SOC Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack — SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal — SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike — SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois — SOC Alert enrichment / IOC lookup
Run Dig Command — SOC Alert enrichment / IOC lookup
Analyze URL with URLScan — SOC Alert enrichment / IOC lookup
Okta Search for User Activity — SOC Alert enrichment / IOC lookup
Secure URL Screenshot Capture — SOC Alert enrichment / IOC lookup, Phishing detection & response
Get End of Life Date for a Product — SOC Alert enrichment / IOC lookup
Agent Ability - Query Observables by Content — SOC Alert enrichment / IOC lookup
Query Observable — SOC Alert enrichment / IOC lookup
Get Observables by Case ID — SOC Alert enrichment / IOC lookup

4. Phishing Detection & Response

Category: SOC | Subcategories: Phishing detection & response, SIEM & log pipeline monitoring

Description: Detection and triage of phishing alerts sourced from Splunk (via Microsoft 365/Defender data) and from user-reported emails. The response subflow uses an AI Phishing Triage Analyst agent, retrieves the original email headers, and checks for KnowBe4 simulation markers before escalating or remediating.

Business Problem: Phishing is a high-volume alert category that requires consistent investigation steps across every case. Automation ensures no alert is skipped and simulation emails are automatically filtered from true investigations.

Integrations: Splunk, Microsoft Outlook, Microsoft Graph, Blink Case Management, KnowBe4

Playbook Executions Category Subcategories
Agent Ability - Get Phishing Questions 81 SOC Phishing detection & response, Agentic SOC
Response Subflow - Phishing — SOC Phishing detection & response
Splunk Ingest - Splunk Ms Phishing Alert (Custom) — SOC Phishing detection & response, SIEM & log pipeline monitoring
Splunk Ingest - Splunk Ms Phishing Alert (General) — SOC Phishing detection & response, SIEM & log pipeline monitoring

5. EDR Containment & Malware Response

Category: SOC | Subcategories: EDR containment & response

Description: Automated endpoint isolation and malware response using CrowdStrike Falcon and Microsoft Defender for Endpoints. Covers device quarantine/unquarantine, Remote Terminal Response (RTR) command execution on single or batch hosts, antivirus scan initiation, and endpoint isolation via MDE.

Business Problem: Containing a compromised endpoint requires immediate, consistent action across tools. Manual isolation steps are time-critical; automation eliminates the delay between detection and containment.

Integrations: CrowdStrike Falcon, Microsoft Defender for Endpoints, Blink Case Management

Playbook Executions Category Subcategories
Agent Ability - Get Malware Questions 14 SOC EDR containment & response, Agentic SOC
Manage Endpoint Quarantine Status in Crowdstrike — SOC EDR containment & response
CrowdStrike RTR to a Single Host — SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts — SOC EDR containment & response
Isolate Endpoint in MDE — SOC EDR containment & response
Initiate AV Scan using MDE — SOC EDR containment & response
Response Subflow - Malware — SOC EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike — SOC EDR containment & response
CrowdStrike RTR to a Single Host — SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts — SOC EDR containment & response

6. Identity Threat Response

Category: SOC | Subcategories: Identity threat response

Description: Automated response to identity-based threats including risky user detection, account disablement across on-premises Active Directory and Microsoft Entra ID, session revocation, user membership analysis, and Defender XDR alert investigation. Covers the full identity containment workflow from detection to remediation.

Business Problem: Identity compromise is the leading attack vector; delayed account disablement directly extends attacker dwell time. Automation ensures consistent, immediate response across both cloud and on-premises directory services simultaneously.

Integrations: Microsoft Entra ID, Microsoft Defender XDR, On-premises Active Directory

Playbook Executions Category Subcategories
Disable an account in on-prem AD as well as EntraID and revoke Sessions — SOC Identity threat response
Get Risky User with Microsoft Entra ID and Send Results via Email copy — SOC Identity threat response
List Risky Users with Microsoft Entra ID and Send Results via Email copy — SOC Identity threat response
List User Membership with Microsoft Entra ID and Send Results via Email copy — SOC Identity threat response
Get User Details with Microsoft Entra ID and Send Results via Email copy — SOC Identity threat response
List Alerts with Microsoft Defender XDR and Send Results via Email copy — SOC Identity threat response
Microsoft Defender XDR Custom Action and Send Results via Email copy — SOC Identity threat response
Defender User Lookup — SOC Identity threat response

7. Threat Intel & Ad-Hoc Investigation

Category: SOC | Subcategories: Threat intel ingest & curation

Description: On-demand and ad-hoc threat intelligence workflows for analyst-initiated lookups across Recorded Future, VirusTotal, Splunk, and CrowdStrike. Includes an agentic threat hunting bot (SIEM Hunt Bot and AdHOC threat hunt bot) that can run Splunk queries autonomously and publish reports to Confluence.

Business Problem: Analysts need rapid, repeatable access to threat intelligence during investigations. These playbooks expose complex multi-tool lookups as single-click operations and enable an AI agent to autonomously hunt for IOCs across the SIEM.

Integrations: Recorded Future, Recorded Future Triage Cloud, VirusTotal, Splunk, CrowdStrike, Glean, Confluence, Spycloud

Playbook Executions Category Subcategories
Agent Ability - Splunk Threat Hunter — SOC Threat intel ingest & curation
Agent Ability - Run Splunk Search — SOC Threat intel ingest & curation
Agent Ability - Get Splunk Schema — SOC Threat intel ingest & curation
Search Domain with Recorded Future and Send Results via Email — SOC Threat intel ingest & curation
Search Malware with Recorded Future and Send Results via Email — SOC Threat intel ingest & curation
Submit Sample with Recorded Future Triage Cloud and Send Results via Email — SOC Threat intel ingest & curation
Create Search Job with Splunk and Send Results via Email — SOC Threat intel ingest & curation
VirusTotal IP ADHOC — SOC Threat intel ingest & curation
Splunk Login ADHOC — SOC Threat intel ingest & curation
Crowdstrike EDR ADHOC — SOC Threat intel ingest & curation
Call Searching bot — SOC Threat intel ingest & curation, Agentic SOC
Call ADHOC hunt bot — SOC Threat intel ingest & curation, Agentic SOC
Saved Query — SOC Threat intel ingest & curation
Exporting Bin List from Spycloud — GRC AML / KYC compliance

8. DLP & Cloud App Security Monitoring

Category: GRC | Subcategories: DLP triage & exposure resp

Description: Agent-accessible abilities to query Microsoft Defender for Cloud Apps (MCAS) for user activity and DLP policy details during active investigations. These playbooks extend the Agentic SOC's capabilities to include cloud app behavior context when investigating potential data exposure or insider threat scenarios.

Business Problem: DLP alerts in isolation lack user behavior context. These playbooks enable AI agents to automatically pull MCAS activity timelines and policy details, enriching investigations with cloud app behavior without requiring analyst intervention.

Integrations: Microsoft Defender for Cloud Apps (MCAS)

Playbook Executions Category Subcategories
Agent Ability - Get User activity MCAS 15 GRC DLP triage & exposure resp
Agent Ability - Get MCAS DLP Policy 15 GRC DLP triage & exposure resp

9. Endpoint Visibility & Hygiene

Category: Other | Subcategories: Endpoint hygiene & MDM ops

Description: On-demand endpoint lookup and management across Microsoft Intune and Trend Vision One. Enables security analysts to query device health, compliance state, and encryption status by device name or ID, run malware scans, and list endpoint inventory.

Business Problem: Endpoint hygiene investigations require pulling device data from multiple MDM and EDR platforms. These playbooks surface device compliance, encryption, and management state on demand without analyst access to each tool console.

Integrations: Microsoft Intune, Trend Vision One

Playbook Executions Category Subcategories
Get Managed Device with Microsoft Intune and Send Results via Email — Other Endpoint hygiene & MDM ops
Get Managed Device with Microsoft Intune using device name, Send Results via Email — Other Endpoint hygiene & MDM ops
Run Malware Scan on Endpoint with Trend Vision One and Send Results via Email — Other Endpoint hygiene & MDM ops
List Endpoints with Trend Vision One and Send Results via Email — Other Endpoint hygiene & MDM ops
Get Endpoint with Trend Vision One and Send Results via Email — Other Endpoint hygiene & MDM ops
Query an endpoint by full endpoint name in TrendOne and have the results displayed and emailed — Other Endpoint hygiene & MDM ops

10. Case Management Platform & Utilities

Category: SOC | Subcategories: Case mgmt & SOAR

Description: Supporting infrastructure for the Blink Case Management platform — observable relation management, stale case cleanup, error handling, alert template validation, and recovery workflows for unprocessed alerts or un-enriched observables. These playbooks maintain the integrity and operational health of the SOC platform.

Business Problem: SOAR platforms accumulate stale cases, missing enrichments, and unprocessed alerts without active maintenance. This utility layer ensures data quality, enables re-processing of failed items, and provides consistent error notification to the SOC team.

Active Workspace (75205226)

Playbook Executions Category Subcategories
Comment On Case — SOC Case mgmt & SOAR
Utility - Add Observable Extraction Rule — SOC Case mgmt & SOAR
Utility - Set Or Update Observable Relation — SOC Case mgmt & SOAR
Utility - Delete Observable Relation — SOC Case mgmt & SOAR
Utility - List Observable Alert Relations — SOC Case mgmt & SOAR
Utility - List Alert Observable Relations — SOC Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables — SOC Case mgmt & SOAR
Utility - Close Stale Cases — SOC Case mgmt & SOAR
Utility - Update Enrichment — SOC Case mgmt & SOAR
Table Action - Validate Observables Extraction Template — SOC Case mgmt & SOAR
Subflow - Missing Alert Template Notification — SOC Case mgmt & SOAR
Error Handling - Send Error Notification Email — SOC Case mgmt & SOAR
Recovery - Enrich Non-Enriched Observables — SOC Case mgmt & SOAR, Alert enrichment / IOC lookup
Recovery - Handle Unprocessed Alerts — SOC Case mgmt & SOAR
Recovery - Handle Unprocessed Alert — SOC Case mgmt & SOAR

Key Observations

Strengths

1. Fully operational Agentic SOC pipeline. The active workspace (75205226) runs a mature, production-grade Agentic SOC that ingests Splunk alerts, extracts observables, enriches them, and routes each alert through AI-driven expert agents for triage. With 1,098 alerts ingested and 227 processed end-to-end, this is a live, high-value automation — not a proof of concept.

2. Purpose-built AI agent architecture. The deployment goes beyond rule-based automation: the Decision Layer, Expert Agents (phishing, malware, identity), and 14+ Agent Ability playbooks form a genuine AI SOC analyst backed by real data (VIP users table, org assets, historical cases). The 489 VIP user lookups and 184 observable enrichment queries from agents show active use during live investigations.

3. Deep Microsoft stack coverage. Microsoft Entra ID, Defender for Endpoints, Defender XDR, Defender for Cloud Apps, Intune, and Azure Monitor are all wired in — reflecting the customer's Microsoft-centric environment. Identity enrichment is the most active enrichment source (359 executions), confirming Entra ID is central to investigation workflows.

4. Rich enrichment framework. The observable enrichment library covers every major IOC type (IP, URL, hash, username/email, domain, agent ID) across 7+ intelligence sources. While most enrichers currently show 0 executions, the routing infrastructure is live and firing 840 times — suggesting enrichments are succeeding silently or most alerts currently carry only user-type observables.

5. Splunk as the primary alert source. Three distinct Splunk saved searches are actively feeding the pipeline (SOC 54, SOC 95, SOC 270), accounting for all 1,098 ingested alerts. This is a well-structured, multi-rule Splunk integration.

Gaps & Opportunities

1. Enrichment sources other than Entra ID are not firing. VirusTotal, AbuseIPDB, CrowdStrike, URLScan, and Okta enrichers all show 0 executions despite being deployed. This likely means either (a) observable extraction templates are not yet configured for hash/IP/URL types in current alert templates, or (b) the Splunk alerts feeding the pipeline primarily generate user-type observables. Enabling additional observable types would multiply the depth of automated context.

2. Phishing and malware response playbooks are built but disconnected. The phishing response subflow, the Splunk phishing ingest playbooks, and the MDE isolation/AV scan workflows all show 0 executions. These represent ready-built automation that could immediately extend coverage if connected to live alert sources.

3. Threat intel tools are underutilized. Recorded Future is deployed (domain search, malware search, Triage Cloud, and an IP enricher with 1 execution), but the ad-hoc threat hunting workspace (17db3b15) shows no production usage. The agentic Splunk Threat Hunter and SIEM Hunt Bot are built but idle — an opportunity to activate agentic threat hunting as a force multiplier.

4. Identity response is read-only. Workflows for disabling accounts, revoking sessions, and isolating endpoints exist but have 0 executions. The Agentic SOC pipeline currently stops at investigation — activating automated containment actions would reduce MTTR for confirmed identity and endpoint threats.

5. Spycloud BIN list export is empty. Given the customer's financial services profile, the Spycloud integration for payment card fraud monitoring is a notable capability that has not yet been built out. This is a gap worth prioritizing given the regulatory and fraud risk context.

Integration Ecosystem

Integration Category Usage
Splunk SIEM Active — 1,098 alerts ingested
Microsoft Entra ID Identity Active — 359 enrichments
Microsoft Defender for Cloud Apps (MCAS) CASB / DLP Active — 15 queries
Blink Case Management SOAR Active — core platform
CrowdStrike Falcon EDR / Threat Intel Built, idle in production
VirusTotal Threat Intel Built, idle
Recorded Future Threat Intel Built, 1 execution
AbuseIPDB Threat Intel Built, idle
URLScan Threat Intel Built, idle
Microsoft Defender for Endpoints EDR Built, idle
Microsoft Defender XDR XDR Built, idle
Microsoft Intune MDM Built, idle
Okta Identity Built, idle
Trend Vision One EDR Built, idle
Slack Communication / Identity Built, idle
GitHub Developer Identity Built, idle
Google Workspace Identity Built, idle
Azure Monitor Cloud Logs Built, idle
Glean Enterprise Search Built, idle
Confluence Documentation Built, idle
Spycloud Fraud / Credential Intel Skeleton only
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.