Blink Security Automation — Confidential

healthfirst — Customer Success Report

Generated 2026-08-30 | healthfirst-value-report.md
2026-08-30Report Date
488Total Playbooks
105Unique Workflows (12m)
2,232,887Actions Automated (12m)
$574,302Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

488
Total playbooks built
all non-deleted workflows
230
Active playbooks
currently enabled
105
Unique workflows executed (12m)
distinct workflows that ran
2,232,887
Actions automated (12m)
completed action steps
12,404.9h
Hours saved (12m)
@ 20s per action
$574,302
Money saved (12m)
@ $100K avg salary
2
New active workflows (last 30d)
recently created & enabled
741
Total cases managed
740 opened in last 12m
15d 7h
MTTR — mean time to resolve
closed cases, last 12m
3
Active AI agents
of 7 total
87
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated:

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Email Threat Ingestion & Response
  • 11,564Email attachment threat alerts ingested & processed
  • 11,564Email attachment alerts scanned for threat hunting
  • 52Mimecast phishing/malware cases responded to
14.1%
3
3 active
SOC Case Management & SOAR
  • 3,855Bi-directional ServiceNow case sync events handled
  • 1,160Security alerts processed end-to-end
  • 470Case comment events processed and synchronized
10.5%
20
20 active
AI/Cloud Security Alert Ingestion & Response (Noma & Wiz)
  • 2,428AI/ML security alerts ingested from Noma
53.9%
3
3 active
Alert Enrichment & IOC Lookup
  • 714IOC reputation checks executed against CrowdStrike
1.2%
25
25 active
Network Access Policy Enforcement (Forescout)
  • 535Wireless policy violations ingested (CCO environment)
  • 440Wireless policy violations ingested (LTC environment)
  • 111Wireless policy violations responded to (CCO)
2.2%
5
5 active
EDR Ingestion & Response (CrowdStrike)
  • 75CrowdStrike EDR alerts triaged and responded to
  • 56CrowdStrike endpoint response actions executed
  • 36Metasploit scanning detections responded to
0.0%
8
8 active
Deception Technology Monitoring (Canary)
  • 482Canary deception sensor disconnections detected & alerted
0.7%
4
4 active
PCI & Data Access Alert Response (Varonis)
  • 103Varonis PCI data access alerts responded to
  • 40Varonis PCI alerts ingested for analysis
0.2%
3
3 active
Threat Intelligence Curation
  • 174Threat intelligence records curated
0.2%
1
1 active
SOC Enrichment — Identity & Endpoint Context
  • 78Employee records synced to SOC cases from Workday
0.1%
7
7 active
Endpoint Inventory & Hygiene (Intune / CrowdStrike)
  • 25Endpoint records reconciled across Intune and CrowdStrike
0.1%
4
4 active
Agentic Risky User Detection & Response0 executions
0.0%
12
12 active
Fraud Detection Capabilities (Abilities Library)0 executions
0.0%
3
3 active
Privileged Access & Vault Visibility (CyberArk)0 executions
0.0%
2
2 active
HR Data Integration (Workday)79 executions
0.1%
5
4 active
Automation Governance & Workflow Metadata Tracking2 executions
0.0%
1
1 active
Total68,241 executions100%
106
105 active

Use Case Growth Over Time

377 unique playbooks  |  16 operational use cases  |  81,828 total executions (12m)  |  2024-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
CrowdStrike URLScan VirusTotal AbuseIPDB Okta IPinfo Microsoft Entra ID Email Slack IP API MISP Mimecast GreyNoise Censys Shodan Whois
HR Data Integration (Workday)
Workday Microsoft Outlook
EDR Ingestion & Response (CrowdStrike)
CrowdStrike Email Active Directory On-Prem
SOC Enrichment — Identity & Endpoint Context
Microsoft Entra ID Microsoft Graph Forescout Netskope CTE CrowdStrike
SOC Case Management & SOAR
ServiceNow Microsoft Teams
Email Threat Ingestion & Response
Mimecast ServiceNow
Privileged Access & Vault Visibility (CyberArk)
CyberArk Email CyberArk - Privilege Cloud
Threat Intelligence Curation
MISP RSS Email
Endpoint Inventory & Hygiene (Intune / CrowdStrike)
Microsoft Intune CrowdStrike
PCI & Data Access Alert Response (Varonis)
ServiceNow
Network Access Policy Enforcement (Forescout)
Forescout ServiceNow Microsoft Outlook
Deception Technology Monitoring (Canary)
Thinkst Canary
Fraud Detection Capabilities (Abilities Library)
Workday
Agentic Risky User Detection & Response
Agents Microsoft Graph ServiceNow CrowdStrike Varonis Living Security
AI/Cloud Security Alert Ingestion & Response (Noma & Wiz)
ServiceNow Wiz

04Key Observations

✓  Strengths

Strengths

1. High-volume, production-grade SOC automation. The Mimecast attachment alert pipeline alone accounts for 23,128 executions — the single highest-volume automation in the deployment. Running on a 5-minute schedule across both a primary ingest and a parallel threat-hunting ingest, this demonstrates mature, production-grade email security automation covering the most prevalent threat vector (phishing/malicious attachments) in healthcare environments.

2. Deeply integrated ServiceNow bidirectional sync. The ServiceNow case mirroring and state synchronization cluster (7 active playbooks, 5,346 combined executions) represents a mature, production case management integration. Coverage spans incident (INC) and issue (IS) state updates, field-level change tracking, case owner assignment, and error handling. This depth of integration reduces analyst double-entry and maintains audit trails required for HIPAA incident response documentation.

3. Multi-environment network policy enforcement. The Forescout wireless policy violation pipeline operates across two distinct environments (CCO and LTC), with combined ingestion of 975 violation events and 111 automated response actions. For a healthcare payer with distributed facilities, this demonstrates cross-environment security consistency at scale.

4. Agentic SOC capability in development. The presence of an Agentic workspace with five risky-user ability modules (covering CrowdStrike, Varonis, ServiceNow, Entra, and Living Security), a table-join aggregation playbook, and an impossible travel detection workflow indicates Healthfirst is building toward multi-source, AI-driven insider risk detection. This positions the SOC for more sophisticated detection patterns than traditional rule-based SOAR allows.

5. Noma AI security integration. With 2,428 executions, the Noma alert ingestion pipeline is active and producing case volume. This is noteworthy as relatively few organizations have operationalized AI security posture management tooling into their SOC workflows. It indicates awareness and early action on an emerging threat category particularly relevant to healthcare AI adoption. Dedicated Wiz issue tracking and response subflows have also been introduced, extending cloud security posture coverage beyond AI-specific alerting to broader cloud misconfiguration findings.

6. Workday HR enrichment linked to security cases. 78 Workday worker records were automatically linked to open security cases during the period, with 30 additional SOC enrichment runs pulling Workday data. Connecting HR data to security investigations is a differentiating SOC capability that supports insider threat and credential compromise investigations.

7. Emerging automation governance capability. A new scheduled workflow (SOC - Workflow Metadata Tracking) reconciles tracked workflow metadata against the Blink platform API daily. This represents an early step toward addressing the workspace sprawl and duplicate-playbook governance

△  Gaps & Growth Opportunities

gap identified below.

Gaps & Opportunities

1. Large enrichment library with near-zero execution volume. The enrichment library contains over 20 playbooks (hash lookups via CrowdStrike and VT, IP enrichment via IPDB/VT, URL enrichment via URLScan/VT, user lookups via Okta/Entra/Google Workspace/Slack/GitHub) with 0 executions recorded. These playbooks appear to be provisioned but not yet integrated into the active alert processing pipeline. Connecting the "Subflow - Enrich Observables - Main Router" (644 executions) to these individual enrichment modules would activate automated enrichment at scale.

2. Response subflows inactive. "Response Subflow - Phishing" and "Response Subflow - Malware" both show 0 executions, despite the Mimecast ingestion pipeline being highly active. The "Subflow - Response - Main Router" also shows 0 executions. This suggests the alert ingestion pipeline is not yet fully connected to automated response actions. Closing this loop would convert ingest volume into automated response throughput.

3. CrowdStrike RTR capabilities unused. Real-time response playbooks for single and batch host actions in CrowdStrike show 0 executions. These represent significant containment automation potential for endpoint threats — the capability infrastructure is built, but it is not yet being triggered from active response workflows.

4. Identity and access management automation is limited. Despite Okta, Microsoft Entra ID, and Active Directory integrations being present, no IAM lifecycle automation (onboarding, offboarding, access review, password reset) shows meaningful execution volume. The Reset AD Password playbook has 0 executions, Okta-based workflows are inactive, and general group management tooling is largely absent (a new CyberArk Safe Creation workflow does provision AD admin/user/lister groups tied to PAM safes, but no broader onboarding/offboarding lifecycle automation exists). For a healthcare organization with HIPAA access control requirements, this represents a high-value automation gap.

5. Fraud detection library not yet operationalized. LexisNexis, Telesign, and MinFraud ability playbooks have 0 executions. While built and presumably tested, they have not been integrated into active fraud detection or member onboarding workflows. Given Healthfirst's exposure to healthcare fraud, activating these integrations into operational workflows would provide measurable GRC value.

6. GRC / Compliance reporting automation absent. No playbooks for automated compliance reporting, evidence collection, or regulatory questionnaire support are deployed. Given HIPAA, PCI DSS, and state insurance regulatory obligations, there is a clear opportunity to extend Blink's automation into the compliance operations domain.

7. Duplicate playbook names across workspaces. Multiple playbooks (e.g., "Enrich - Agent ID - Crowdstrike", "Enrich - URL - URLScan", "SOC - Case Management - ServiceNow Error Handling", "Utility - Get Random Case Owner") appear under different workspace IDs with identical names. This pattern across 11 workspaces suggests workspace sprawl or a multi-tenant architecture that may benefit from consolidation or governance review to prevent configuration drift.

Integration Ecosystem

The following integrations are currently deployed and active within the Healthfirst Blink environment:

Integration Category Usage Status
Mimecast Email security Active — high volume
ServiceNow ITSM / case management Active — high volume
CrowdStrike Falcon EDR / threat intelligence Active
Noma AI security posture Active
Forescout Network access control Active
Canary Deception technology Active
Varonis Data access analytics Active
Workday HR data / identity Active
Microsoft Intune MDM / endpoint inventory Active
Living Security Security awareness / risk scoring Active (minimal)
ActiveOps WorkIQ Workforce analytics Active
Microsoft Entra ID / Azure AD Identity directory Provisioned, minimal usage
Okta Identity / SSO Provisioned, not active
VirusTotal Threat intelligence Provisioned, not active
URLScan URL threat intelligence Provisioned, not active
IPDB IP threat intelligence Provisioned, not active
Whois Domain intelligence Provisioned, not active
GitHub Developer identity Provisioned, not active
Google Workspace Identity / collaboration Provisioned, not active
Slack Identity / notification Provisioned, not active
CyberArk PAM / privileged access Provisioned, not active
LexisNexis Identity verification / fraud Provisioned, not active
Telesign Phone risk scoring Provisioned, not active
MaxMind MinFraud Transaction fraud scoring Provisioned, not active
MISP Threat intelligence platform Provisioned, not active
NetSkope CASB / DLP Active (response playbook)
Wiz Cloud security posture management Active (minimal)
Microsoft Teams Notification / collaboration Active (minimal)
Appendices
A Case Management 740 cases (12m) | MTTR 15d 7h

Case Management

Total Cases (all-time)
741
740 opened in last 12m
Cases Opened (30d)
126
56 closed in last 30d
Cases Closed (12m)
642
of 740 opened
MTTR
15d 7h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
SOC 739 739 642 15d 7h
Case Management Playground 2 1 0 N/A
B AI Agents 3 active | 87 tasks (12m)

AI Agents

Active Agents
3
of 7 total
Tasks Executed (12m)
87
0 in last 30d
Data Usage (12m)
5,829,671
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Risky User Analysis AgentsDemo 80 0 5,420,604
2 Impossible Travel Agent Case Management Playground 5 0 270,015
3 The Registration Integrity Agent AgentsDemo 2 0 139,052
4 Agent Blink Case Management Playground 0 0 0
5 Agent Blink SOC 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
AgentsDemo82
Case Management Playground5
SOC0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
8
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Case Management Dashboard 00
2 Privacy Open PCI Tickets 00
3 Privacy PCI Tickets 00
4 Open ServiceNow Tickets 00
5 RiskyUsers Overview 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 16 use cases | 81,828 executions (12m)

Business KPIs

Metric Count Playbook
Email attachment threat alerts ingested & processed 11,564 Ingest - Mimecast - Get Attachment Alerts
Email attachment alerts scanned for threat hunting 11,564 Ingest - Mimecast - Get Attachment Alerts for Threat Hunting
Bi-directional ServiceNow case sync events handled 3,855 ServiceNow Mirroring - Test
AI/ML security alerts ingested from Noma 2,428 SOC - Ingest - Noma Alerts
Security alerts processed end-to-end 1,160 Process Alert
IOC reputation checks executed against CrowdStrike 714 CrowdStrike Falcon IOC Reputation Check
Wireless policy violations ingested (CCO environment) 535 CCO - Ingest - Forescout Wireless Policy Violations
Canary deception sensor disconnections detected & alerted 482 SOC - Scheduled - Canary Disconnection Monitoring
Case comment events processed and synchronized 470 New Comment Added to Case
Wireless policy violations ingested (LTC environment) 440 LTC - Ingest - Forescout Wireless Policy Violations
Cases automatically created from active alerts 165 SOC - Case Management - Case Creation with Alerts
Wireless policy violations responded to (CCO) 111 CCO - Response - Forescout Wireless Policy Violation
Varonis PCI data access alerts responded to 103 SOC - Response - Varonis PCI Alert
CrowdStrike EDR alerts triaged and responded to 75 Ingest - CrowdStrike Webhook
Mimecast phishing/malware cases responded to 52 Response - Mimecast Cases
NetSkope unauthorized webmail incidents handled 68 SOC - Response - NetSkope Webmail
CrowdStrike endpoint response actions executed 56 SOC - Response - CrowdStrike Falcon
Threat intelligence records curated 174 Threat intel
Varonis PCI alerts ingested for analysis 40 SOC - Ingest - Varonis PCI Alert
Metasploit scanning detections responded to 36 SOC - Response - Metasploit Scanning
Employee records synced to SOC cases from Workday 78 Workday Worker Link to Case
Endpoint records reconciled across Intune and CrowdStrike 25 Device Reconciliation Intune or CrowdStrike
In the last 12 months, Blink automated: - 23,128 email attachment threats ingested and queued for analyst review or automated response — spanning both real-time triage and proactive threat hunting pipelines - 2,428 AI/cloud security alerts from Noma automatically ingested and converted to actionable SOC cases - 1,160 security alerts processed end-to-end through the normalized alert processing pipeline - 975 network policy violations detected and responded to across CCO and LTC environments via Forescout integration - 714 IOC reputation lookups executed automatically against CrowdStrike Falcon Intelligence with zero analyst intervention - 482 Canary deception sensor health-check events automatically detected and escalated - 174 threat intelligence records curated and operationalized - 103 Varonis PCI data-access anomalies responded to, supporting HIPAA and PCI compliance obligations - 78 Workday employee records automatically linked to open security cases, enriching analyst context - 56 CrowdStrike endpoint response actions executed to contain or investigate active threats

Use Case Summary

# Use Case Category Playbooks Active Playbooks Total Executions
1 Email Threat Ingestion & Response SOC — Phishing detection & response 5 4 23,180
2 SOC Case Management & SOAR SOC — Case mgmt & SOAR 20 17 6,895
3 AI/Cloud Security Alert Ingestion & Response (Noma & Wiz) Cloud Security — CSPM ingest & triage 3 2 2,433
4 Alert Enrichment & IOC Lookup SOC — Alert enrichment / IOC lookup 25 5 1,432
5 Network Access Policy Enforcement (Forescout) Other — IT/OT & network infra monitoring 5 5 1,117
6 EDR Ingestion & Response (CrowdStrike) SOC — EDR containment & response 9 6 917
7 Deception Technology Monitoring (Canary) SOC — Alert enrichment / IOC lookup 3 2 510
8 PCI & Data Access Alert Response (Varonis) GRC — PCI & regulatory monitoring 3 3 148
9 Threat Intelligence Curation SOC — Threat intel ingest & curation 2 1 174
10 SOC Enrichment — Identity & Endpoint Context SOC — Alert enrichment / IOC lookup 7 4 175
11 Endpoint Inventory & Hygiene (Intune/CrowdStrike) Other — Endpoint hygiene & MDM ops 4 4 107
12 Agentic Risky User Detection & Response SOC — Agentic SOC / Identity threat response 12 7 8
13 Fraud Detection Capabilities (Abilities Library) GRC — AML / KYC compliance 3 0 0
14 Privileged Access & Vault Visibility (CyberArk) IAM — Privileged account mgmt 2 0 0
15 HR Data Integration (Workday) Other — IT helpdesk & ticket routing 5 3 118
16 Automation Governance & Workflow Metadata Tracking GRC — Security metrics & reporting 1 1 2

Use Cases

1. Email Threat Ingestion & Response

Description: Automated pipeline for continuously ingesting Mimecast attachment protection logs, creating structured alerts, and executing response workflows for confirmed phishing and malware cases. Runs on a 5-minute polling schedule to minimize dwell time between email threat detection and analyst action.

Business Problem Solved: Manual review of Mimecast attachment protection logs is time-intensive and creates lag between email detonation events and analyst engagement. This automation closes that gap by creating normalized alerts and routing cases through a standardized response workflow.

Category: SOC — Phishing detection & response

Integrations: Mimecast, Blink Case Management

Playbook Executions Taxonomy
Ingest - Mimecast - Get Attachment Alerts 11,564 SOC — Phishing detection & response
Ingest - Mimecast - Get Attachment Alerts for Threat Hunting 11,564 SOC — Threat hunting & detection
Response - Mimecast Cases 52 SOC — Phishing detection & response
Ingest - Mimecast - Get URL for Threat Hunting 0 SOC — Threat hunting & detection
IT Security Program - Get Mimecast Release Requests 0 SOC — Phishing detection & response

2. SOC Case Management & SOAR

Description: Comprehensive bi-directional case management integration between Blink and ServiceNow, covering case creation, state synchronization, comment mirroring, case owner assignment, and error handling. Forms the operational backbone of the Healthfirst SOC workflow.

Business Problem Solved: SOC analysts require a single source of truth across Blink's native case management and ServiceNow INC/IS ticket workflows. Without automation, state changes, comments, and ticket assignments require manual double-entry across systems, increasing error rates and degrading response times.

Category: SOC — Case mgmt & SOAR

Integrations: Blink Case Management, ServiceNow

Playbook Executions Taxonomy
ServiceNow Mirroring - Test 3,855 SOC — Case mgmt & SOAR
SOC - Case Management - Get ServiceNow Connection and Table 1,015 SOC — Case mgmt & SOAR
Subflow - Response - Alerts Router 1,090 SOC — Case mgmt & SOAR
Process Alert 1,160 SOC — Case mgmt & SOAR
New Comment Added to Case 470 SOC — Case mgmt & SOAR
SOC - Case Management - Get Case with Retry 326 SOC — Case mgmt & SOAR
Case Manager Updated 287 SOC — Case mgmt & SOAR
SOC - Case Management - INC State Updated 186 SOC — Case mgmt & SOAR
SOC - Case Management - ServiceNow Error Handling 181 SOC — Case mgmt & SOAR
Utility - Get Random Case Owner 181 SOC — Case mgmt & SOAR
SOC - Case Management - Case Creation with Alerts 165 SOC — Case mgmt & SOAR
SOC - Case Management - IS State Updated 60 SOC — Case mgmt & SOAR
SOC - Case Management - ServiceNow Number Field Change 45 SOC — Case mgmt & SOAR
SOC - Case Management - ServiceNow System ID Field Change 42 SOC — Case mgmt & SOAR
SOC - Case Management - Case Creation with No Alerts 12 SOC — Case mgmt & SOAR
Subflow - Response - No Alerts Router 12 SOC — Case mgmt & SOAR
Update Blink Case with ServiceNow Changes 0 SOC — Case mgmt & SOAR
Utility - Close Stale Cases 0 SOC — Case mgmt & SOAR
USE WITH CARE - Reset Case Management Environment 0 SOC — Case mgmt & SOAR
Teams 11 SOC — Case mgmt & SOAR

3. AI/Cloud Security Alert Ingestion & Response (Noma & Wiz)

Description: Automated ingestion of alerts from Noma, an AI/ML security posture platform that monitors AI applications and data pipelines for misconfigurations and anomalous usage, alongside dedicated tracking and response subflows for Wiz cloud security findings. Ingested alerts are converted to normalized Blink cases for analyst triage, and Wiz issues are routed through their own response and tracking logic.

Business Problem Solved: As Healthfirst expands its AI and data platform footprint, visibility into AI-specific risk vectors (model misuse, data exfiltration via AI APIs, shadow AI) requires a dedicated ingestion path. Noma provides that signal; this automation ensures it reaches the SOC promptly. Wiz surfaces cloud misconfiguration and posture findings that also require structured, consistent tracking; dedicated subflows ensure these issues are logged and actioned alongside AI security alerts.

Category: Cloud Security — CSPM ingest & triage

Integrations: Noma, Wiz, ServiceNow, Blink Case Management

Playbook Executions Taxonomy
SOC - Ingest - Noma Alerts 2,428 Cloud Security — CSPM ingest & triage
SOC - Response - Wiz Issue 5 Cloud Security — CSPM ingest & triage
IT Security Program - Track Wiz Issue Subflow 0 Cloud Security — CSPM ingest & triage

4. Alert Enrichment & IOC Lookup

Description: Modular library of enrichment subflows and standalone lookups covering IP addresses, file hashes, URLs, domains, email addresses, and usernames. Integrations span CrowdStrike Falcon Intelligence, VirusTotal, URLScan, Whois, Okta, Microsoft Entra ID, Google Workspace, Slack, and GitHub.

Business Problem Solved: Analysts investigating alerts require corroborating context across multiple threat intelligence and identity sources. Without automation, enrichment is manual, inconsistent, and time-consuming. These playbooks standardize enrichment, reduce analyst toil, and accelerate triage.

Category: SOC — Alert enrichment / IOC lookup

Integrations: CrowdStrike Falcon, VirusTotal, URLScan, Whois/IPDB, Okta, Microsoft Entra ID, Google Workspace, Slack, GitHub, Blink Case Management

Playbook Executions Taxonomy
CrowdStrike Falcon IOC Reputation Check 714 SOC — Alert enrichment / IOC lookup
Subflow - Enrich Observables - Main Router 644 SOC — Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification 69 SOC — Case mgmt & SOAR
Indicator Enrichment 0 SOC — Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike 0 SOC — Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike 0 SOC — Alert enrichment / IOC lookup
Enrich - Hash - VT 0 SOC — Alert enrichment / IOC lookup
Enrich - IP - IPDB 0 SOC — Alert enrichment / IOC lookup
Enrich - IP - VT 0 SOC — Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 0 SOC — Alert enrichment / IOC lookup
Enrich - URL - URLScan 0 SOC — Alert enrichment / IOC lookup
Enrich - URL - VT 0 SOC — Alert enrichment / IOC lookup
Enrich - Username - Github 0 SOC — Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace 0 SOC — Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID 0 SOC — Alert enrichment / IOC lookup
Enrich - Username or Email - Okta 0 SOC — Alert enrichment / IOC lookup
Enrich - Email Address - Slack 0 SOC — Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 0 SOC — Alert enrichment / IOC lookup
IOC Reputation Check - CrowdStrike Intel 0 SOC — Alert enrichment / IOC lookup
Main IOC Reputation Check - CrowdStrike Intel 0 SOC — Alert enrichment / IOC lookup
Domain Enrichment 0 SOC — Alert enrichment / IOC lookup
Email Enrichment 0 SOC — Alert enrichment / IOC lookup
File Enrichment 0 SOC — Alert enrichment / IOC lookup
URL Enrichment 0 SOC — Alert enrichment / IOC lookup
SOC - Utility - Get Observables from Case 0 SOC — Alert enrichment / IOC lookup

5. Network Access Policy Enforcement (Forescout)

Description: Automated ingestion of wireless policy violations from Forescout across two distinct environments (CCO and LTC), with automated remediation workflows that evaluate violations, issue notifications, and generate compliance reports. Runs on a scheduled polling model to ensure continuous enforcement.

Business Problem Solved: Unauthorized wireless device connections represent a significant attack surface in healthcare environments subject to HIPAA and PCI requirements. Manual review of Forescout violation logs creates compliance gaps. This use case automates detection-to-notification cycles and maintains an audit trail.

Category: Other — IT/OT & network infra monitoring; GRC — PCI & regulatory monitoring

Integrations: Forescout, Blink Case Management, Notification/Email

Playbook Executions Taxonomy
CCO - Ingest - Forescout Wireless Policy Violations 535 Other — IT/OT & network infra monitoring
LTC - Ingest - Forescout Wireless Policy Violations 440 Other — IT/OT & network infra monitoring
CCO - Response - Forescout Wireless Policy Violation 111 Other — IT/OT & network infra monitoring
CCO - Subflow - Send Policy Violation Notification 30 Other — IT/OT & network infra monitoring
LTC - Response - Wireless Policy Violation Report 1 Other — IT/OT & network infra monitoring

6. EDR Ingestion & Response (CrowdStrike)

Description: Full pipeline from CrowdStrike Falcon webhook alert ingestion through enrichment to response actions including endpoint investigation and real-time response (RTR) operations. Also covers detection of exploit activity, Metasploit scanning events, and outbound anomalous traffic.

Business Problem Solved: CrowdStrike generates high-volume endpoint telemetry. Without automation, analysts must manually pivot from Falcon alerts to investigation steps. This use case automates the ingest-enrich-respond chain, reducing mean time to respond (MTTR) for endpoint threats.

Category: SOC — EDR containment & response

Integrations: CrowdStrike Falcon, Blink Case Management, ServiceNow

Playbook Executions Taxonomy
Ingest - CrowdStrike Webhook 75 SOC — EDR containment & response
SOC - Response - CrowdStrike Falcon 56 SOC — EDR containment & response
SOC - Response - Metasploit Scanning 36 SOC — EDR containment & response
Schedual pro active huntin 40 SOC — Threat hunting & detection
Crowdstrike Exploit 0 SOC — EDR containment & response
CrowdStrike RTR to a Single Host 0 SOC — EDR containment & response
CrowdStrike RTR to a Batch of Hosts 0 SOC — EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike 0 SOC — EDR containment & response
SOC - Response - Remote Access to Internet 0 SOC — EDR containment & response

7. Deception Technology Monitoring (Canary)

Description: Continuous monitoring of Canary deception tokens and sensors, including scheduled health-check polling for disconnected sensors and event-driven webhook ingestion when Canary tokens are triggered. Automated response allows for IP whitelisting after analyst review.

Business Problem Solved: Deception technology is only effective if sensors are operational and alerts are actioned promptly. Manual monitoring of Canary infrastructure creates gaps where sensors can go dark unnoticed. Automated disconnection detection and alert routing ensures deception coverage is continuously validated.

Category: SOC — Alert enrichment / IOC lookup; SOC — EDR containment & response

Integrations: Canary, Blink Case Management

Playbook Executions Taxonomy
SOC - Scheduled - Canary Disconnection Monitoring 482 SOC — Alert enrichment / IOC lookup
SOC - Ingest - Canary Webhook 28 SOC — Alert enrichment / IOC lookup
SOC - Action - Canary Whitelist IP 0 SOC — EDR containment & response
SOC - Response - Canary Incident 0 SOC — EDR containment & response

8. PCI & Data Access Alert Response (Varonis)

Description: Automated ingestion and response for Varonis Data Activity Classification (DAC) alerts related to PCI data access anomalies. Ingestion playbook captures new Varonis alerts; response playbook executes the documented PCI violation response procedure.

Business Problem Solved: As a healthcare payer, Healthfirst handles both PHI and payment card data subject to HIPAA and PCI DSS requirements. Varonis provides behavioral analytics on data access; automating the alert-to-response cycle ensures that suspected PCI data exposure events are consistently and promptly investigated.

Category: GRC — PCI & regulatory monitoring; GRC — DLP triage & exposure resp

Integrations: Varonis, Blink Case Management, ServiceNow

Playbook Executions Taxonomy
SOC - Ingest - Varonis PCI Alert 40 GRC — PCI & regulatory monitoring
SOC - Response - Varonis PCI Alert 103 GRC — PCI & regulatory monitoring
On New Alert - Varonis DAC 5 GRC — DLP triage & exposure resp

9. Threat Intelligence Curation

Description: Scheduled threat intelligence ingestion and curation workflow, alongside a proactive threat hunting schedule. The threat intel playbook handles structured indicator ingestion; the scheduled hunting playbook executes proactive searches based on current intelligence.

Business Problem Solved: Static threat intelligence without operational integration provides limited SOC value. These playbooks operationalize threat intel by scheduling regular ingestion and driving proactive hunting runs, ensuring indicators remain current and hunts are executed consistently.

Category: SOC — Threat intel ingest & curation; SOC — Threat hunting & detection

Integrations: Threat intelligence platform (MISP-compatible), CrowdStrike, Blink Case Management

Playbook Executions Taxonomy
Threat intel 174 SOC — Threat intel ingest & curation
MISP-Test 0 SOC — Threat intel ingest & curation

10. SOC Enrichment — Identity & Endpoint Context

Description: Dedicated enrichment playbooks that augment open SOC cases with identity context from Workday HR data and endpoint context from CrowdStrike Falcon. Identity linkage to cases improves analyst context significantly for insider threat and privileged access investigations.

Business Problem Solved: Correlating security events to the full identity and HR profile of an employee (their role, manager, recent activity, PTO status) is essential for insider threat investigations and credential compromise triage. Pulling this context manually from Workday is time-consuming; these playbooks automate the linkage.

Category: SOC — Alert enrichment / IOC lookup; IAM — Identity sync & directory mgmt

Integrations: Workday, CrowdStrike Falcon, Microsoft Entra ID, Okta, Blink Case Management

Playbook Executions Taxonomy
Workday Worker Link to Case 78 SOC — Alert enrichment / IOC lookup
SOC - Enrichment - Add Workday Worker Records 30 SOC — Alert enrichment / IOC lookup
SOC - Enrichment - Get Falcon Device by IP 1 SOC — Alert enrichment / IOC lookup
Healthfirst - Username - Entra Enrichment 0 SOC — Alert enrichment / IOC lookup
Azure AD Account Enrichment 0 SOC — Alert enrichment / IOC lookup
User/Host Enrichment 0 SOC — Alert enrichment / IOC lookup
Netscope CTE Enrichment 0 SOC — Alert enrichment / IOC lookup

11. Endpoint Inventory & Hygiene (Intune / CrowdStrike)

Description: Scheduled synchronization and reconciliation of endpoint inventory data between Microsoft Intune and CrowdStrike Falcon. Includes daily device record syncs, device additions, and cross-platform reconciliation to identify managed device gaps.

Business Problem Solved: Healthcare organizations must maintain comprehensive asset inventories for HIPAA risk assessments and vulnerability management programs. Discrepancies between MDM (Intune) and EDR (CrowdStrike) coverage indicate unmanaged endpoints. Automated reconciliation surfaces these gaps without requiring manual spreadsheet comparisons.

Category: Other — Endpoint hygiene & MDM ops; Vulnerability Mgmt — Cloud asset coverage & inventory

Integrations: Microsoft Intune, CrowdStrike Falcon

Playbook Executions Taxonomy
InTune Get Devices 40 Other — Endpoint hygiene & MDM ops
Add Device Records 36 Other — Endpoint hygiene & MDM ops
Device Reconciliation Intune or CrowdStrike 25 Other — Endpoint hygiene & MDM ops
Update Crowdstrike Devices 6 Other — Endpoint hygiene & MDM ops

12. Agentic Risky User Detection & Response

Description: Agentic workflows that aggregate risky user signals from multiple sources — CrowdStrike, Varonis, ServiceNow, Microsoft Entra ID, and Living Security — into a unified risk table. Ability playbooks serve as callable intelligence modules for per-source risky user lookups. Agentic impossible travel detection is in the pipeline.

Business Problem Solved: Insider risk and compromised credential scenarios require correlating behavioral anomalies across multiple data sources before a confident determination can be made. The agentic pattern allows for adaptive, multi-step investigation logic without requiring a fixed playbook sequence.

Category: SOC — Agentic SOC; SOC — Identity threat response; GRC — RBAC review & access mgmt

Integrations: CrowdStrike Falcon, Varonis, ServiceNow, Microsoft Entra ID, Living Security, Okta

Playbook Executions Taxonomy
Entra Get Risky User - Ability 1 SOC — Agentic SOC; SOC — Identity threat response
Get Servicenow Risky User - Ability 1 SOC — Agentic SOC; SOC — Identity threat response
Get Crowdstrike Risky User - Ability 1 SOC — Agentic SOC; SOC — EDR containment & response
Get Varonis Risky User - Ability 1 SOC — Agentic SOC; GRC — DLP triage & exposure resp
Living Security Get Risky User - Ability 1 SOC — Agentic SOC; SOC — Identity threat response
AGENTIC All risky Users - Table Join 0 SOC — Agentic SOC
1. Agentic Impossible Travel Workflow 0 SOC — Agentic SOC; SOC — Identity threat response
Crowdstrike Risky User - Table Fill 0 SOC — Identity threat response
Entra Risky User - Table Fill 0 SOC — Identity threat response
Varonis Risky User - Table Fill 0 GRC — DLP triage & exposure resp
Living Security Risky User - Table Fill 0 SOC — Identity threat response
Servicenow Risky User - Table Fill 0 SOC — Identity threat response

13. Fraud Detection Capabilities (Abilities Library)

Description: A library of callable fraud detection abilities covering LexisNexis identity verification, Telesign phone risk scoring, and MaxMind MinFraud transaction risk scoring. These are on-demand ability modules intended to be embedded within broader investigation or onboarding workflows.

Business Problem Solved: As a health insurance organization, Healthfirst is exposed to healthcare fraud risk including member identity fraud and provider fraud. Having pre-built, callable fraud check abilities enables rapid assembly of fraud detection workflows without rebuilding integration logic.

Category: GRC — AML / KYC compliance; GRC — Financial & fraud operations

Integrations: LexisNexis, Telesign, MaxMind MinFraud

Playbook Executions Taxonomy
LexisNexis - Fraud Check - Ability 0 GRC — AML / KYC compliance
Telesign Fraud Check - Ability 0 GRC — AML / KYC compliance
MinFraud - Ability 0 GRC — AML / KYC compliance

14. Privileged Access & Vault Visibility (CyberArk)

Description: Playbooks for enumerating CyberArk PAM safes and reporting contents via email, providing periodic visibility into privileged account inventory and vault structure, plus an on-demand safe provisioning workflow that creates new CyberArk Privilege Cloud safes, establishes the corresponding on-premises AD admin/user/lister groups, and assigns tiered safe permissions.

Business Problem Solved: Privileged account sprawl is a persistent IAM risk. Periodic reporting of CyberArk safe contents allows security teams to identify orphaned accounts, validate vault hygiene, and support access certification programs. Manual safe provisioning — coordinating safe creation, AD group setup, and permission assignment across separate systems — introduces delay and inconsistency; the safe creation workflow standardizes this sequence into a single on-demand automation.

Category: IAM — Privileged account mgmt

Integrations: CyberArk, On-Prem Active Directory

Playbook Executions Taxonomy
List Safes with CyberArk and Send Results via Email 0 IAM — Privileged account mgmt
CyberArk Safe Creation_AuthorUnknown 0 IAM — Privileged account mgmt

15. HR Data Integration (Workday)

Description: Scheduled synchronization of active Workday worker records to support SOC enrichment and case context. Includes daily RaaS report pulls, PTO status checks, and a worker data sync that keeps Blink tables current with HR data. The ActiveOps WorkIQ integration provides workforce analytics data alongside security telemetry.

Business Problem Solved: Security investigations involving employees require current HR context: active employment status, role, manager, and leave status. Stale or absent HR data leads to unnecessary escalations or missed insider threat indicators. Automated Workday sync ensures SOC enrichment data reflects current employment records.

Category: Other — IT helpdesk & ticket routing; IAM — Identity sync & directory mgmt

Integrations: Workday, ActiveOps WorkIQ

Playbook Executions Taxonomy
Workday Worker Data RaaS Sync - Daily 40 IAM — Identity sync & directory mgmt
ActiveOps - WorkIQ - Get Timeline Events Export 27 Other — IT helpdesk & ticket routing
Workday - Get Active Workers Raas Report 0 IAM — Identity sync & directory mgmt
Workday PTO Check 0 IAM — Identity sync & directory mgmt
Workday Workers Enrichment 0 IAM — Identity sync & directory mgmt

16. Automation Governance & Workflow Metadata Tracking

Description: Scheduled daily job that pulls workflow metadata from a tracking table, queries the Blink platform API for the current state of tracked workflows, and loops through results to reconcile the automation inventory.

Business Problem Solved: With automation deployed across 11+ workspaces, maintaining visibility into which workflows exist, their status, and metadata drift requires a dedicated tracking mechanism. This playbook automates daily reconciliation of the workflow inventory, supporting governance and reducing the risk of untracked or duplicate automations.

Category: GRC — Security metrics & reporting

Integrations: Blink Platform API, Blink Tables

Playbook Executions Taxonomy
SOC - Workflow Metadata Tracking 2 GRC — Security metrics & reporting

Key Observations

Strengths

1. High-volume, production-grade SOC automation. The Mimecast attachment alert pipeline alone accounts for 23,128 executions — the single highest-volume automation in the deployment. Running on a 5-minute schedule across both a primary ingest and a parallel threat-hunting ingest, this demonstrates mature, production-grade email security automation covering the most prevalent threat vector (phishing/malicious attachments) in healthcare environments.

2. Deeply integrated ServiceNow bidirectional sync. The ServiceNow case mirroring and state synchronization cluster (7 active playbooks, 5,346 combined executions) represents a mature, production case management integration. Coverage spans incident (INC) and issue (IS) state updates, field-level change tracking, case owner assignment, and error handling. This depth of integration reduces analyst double-entry and maintains audit trails required for HIPAA incident response documentation.

3. Multi-environment network policy enforcement. The Forescout wireless policy violation pipeline operates across two distinct environments (CCO and LTC), with combined ingestion of 975 violation events and 111 automated response actions. For a healthcare payer with distributed facilities, this demonstrates cross-environment security consistency at scale.

4. Agentic SOC capability in development. The presence of an Agentic workspace with five risky-user ability modules (covering CrowdStrike, Varonis, ServiceNow, Entra, and Living Security), a table-join aggregation playbook, and an impossible travel detection workflow indicates Healthfirst is building toward multi-source, AI-driven insider risk detection. This positions the SOC for more sophisticated detection patterns than traditional rule-based SOAR allows.

5. Noma AI security integration. With 2,428 executions, the Noma alert ingestion pipeline is active and producing case volume. This is noteworthy as relatively few organizations have operationalized AI security posture management tooling into their SOC workflows. It indicates awareness and early action on an emerging threat category particularly relevant to healthcare AI adoption. Dedicated Wiz issue tracking and response subflows have also been introduced, extending cloud security posture coverage beyond AI-specific alerting to broader cloud misconfiguration findings.

6. Workday HR enrichment linked to security cases. 78 Workday worker records were automatically linked to open security cases during the period, with 30 additional SOC enrichment runs pulling Workday data. Connecting HR data to security investigations is a differentiating SOC capability that supports insider threat and credential compromise investigations.

7. Emerging automation governance capability. A new scheduled workflow (SOC - Workflow Metadata Tracking) reconciles tracked workflow metadata against the Blink platform API daily. This represents an early step toward addressing the workspace sprawl and duplicate-playbook governance gap identified below.

Gaps & Opportunities

1. Large enrichment library with near-zero execution volume. The enrichment library contains over 20 playbooks (hash lookups via CrowdStrike and VT, IP enrichment via IPDB/VT, URL enrichment via URLScan/VT, user lookups via Okta/Entra/Google Workspace/Slack/GitHub) with 0 executions recorded. These playbooks appear to be provisioned but not yet integrated into the active alert processing pipeline. Connecting the "Subflow - Enrich Observables - Main Router" (644 executions) to these individual enrichment modules would activate automated enrichment at scale.

2. Response subflows inactive. "Response Subflow - Phishing" and "Response Subflow - Malware" both show 0 executions, despite the Mimecast ingestion pipeline being highly active. The "Subflow - Response - Main Router" also shows 0 executions. This suggests the alert ingestion pipeline is not yet fully connected to automated response actions. Closing this loop would convert ingest volume into automated response throughput.

3. CrowdStrike RTR capabilities unused. Real-time response playbooks for single and batch host actions in CrowdStrike show 0 executions. These represent significant containment automation potential for endpoint threats — the capability infrastructure is built, but it is not yet being triggered from active response workflows.

4. Identity and access management automation is limited. Despite Okta, Microsoft Entra ID, and Active Directory integrations being present, no IAM lifecycle automation (onboarding, offboarding, access review, password reset) shows meaningful execution volume. The Reset AD Password playbook has 0 executions, Okta-based workflows are inactive, and general group management tooling is largely absent (a new CyberArk Safe Creation workflow does provision AD admin/user/lister groups tied to PAM safes, but no broader onboarding/offboarding lifecycle automation exists). For a healthcare organization with HIPAA access control requirements, this represents a high-value automation gap.

5. Fraud detection library not yet operationalized. LexisNexis, Telesign, and MinFraud ability playbooks have 0 executions. While built and presumably tested, they have not been integrated into active fraud detection or member onboarding workflows. Given Healthfirst's exposure to healthcare fraud, activating these integrations into operational workflows would provide measurable GRC value.

6. GRC / Compliance reporting automation absent. No playbooks for automated compliance reporting, evidence collection, or regulatory questionnaire support are deployed. Given HIPAA, PCI DSS, and state insurance regulatory obligations, there is a clear opportunity to extend Blink's automation into the compliance operations domain.

7. Duplicate playbook names across workspaces. Multiple playbooks (e.g., "Enrich - Agent ID - Crowdstrike", "Enrich - URL - URLScan", "SOC - Case Management - ServiceNow Error Handling", "Utility - Get Random Case Owner") appear under different workspace IDs with identical names. This pattern across 11 workspaces suggests workspace sprawl or a multi-tenant architecture that may benefit from consolidation or governance review to prevent configuration drift.

Integration Ecosystem

The following integrations are currently deployed and active within the Healthfirst Blink environment:

Integration Category Usage Status
Mimecast Email security Active — high volume
ServiceNow ITSM / case management Active — high volume
CrowdStrike Falcon EDR / threat intelligence Active
Noma AI security posture Active
Forescout Network access control Active
Canary Deception technology Active
Varonis Data access analytics Active
Workday HR data / identity Active
Microsoft Intune MDM / endpoint inventory Active
Living Security Security awareness / risk scoring Active (minimal)
ActiveOps WorkIQ Workforce analytics Active
Microsoft Entra ID / Azure AD Identity directory Provisioned, minimal usage
Okta Identity / SSO Provisioned, not active
VirusTotal Threat intelligence Provisioned, not active
URLScan URL threat intelligence Provisioned, not active
IPDB IP threat intelligence Provisioned, not active
Whois Domain intelligence Provisioned, not active
GitHub Developer identity Provisioned, not active
Google Workspace Identity / collaboration Provisioned, not active
Slack Identity / notification Provisioned, not active
CyberArk PAM / privileged access Provisioned, not active
LexisNexis Identity verification / fraud Provisioned, not active
Telesign Phone risk scoring Provisioned, not active
MaxMind MinFraud Transaction fraud scoring Provisioned, not active
MISP Threat intelligence platform Provisioned, not active
NetSkope CASB / DLP Active (response playbook)
Wiz Cloud security posture management Active (minimal)
Microsoft Teams Notification / collaboration Active (minimal)
E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
healthfirst blink blinkops_api_connection 2026-08-26
healthfirst forescout forescout_aws 2026-08-05