01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Email Threat Ingestion & Response |
| 14.1% | 3 3 active |
| SOC Case Management & SOAR |
| 10.5% | 20 20 active |
| AI/Cloud Security Alert Ingestion & Response (Noma & Wiz) |
| 53.9% | 3 3 active |
| Alert Enrichment & IOC Lookup |
| 1.2% | 25 25 active |
| Network Access Policy Enforcement (Forescout) |
| 2.2% | 5 5 active |
| EDR Ingestion & Response (CrowdStrike) |
| 0.0% | 8 8 active |
| Deception Technology Monitoring (Canary) |
| 0.7% | 4 4 active |
| PCI & Data Access Alert Response (Varonis) |
| 0.2% | 3 3 active |
| Threat Intelligence Curation |
| 0.2% | 1 1 active |
| SOC Enrichment — Identity & Endpoint Context |
| 0.1% | 7 7 active |
| Endpoint Inventory & Hygiene (Intune / CrowdStrike) |
| 0.1% | 4 4 active |
| Agentic Risky User Detection & Response | 0 executions | 0.0% | 12 12 active |
| Fraud Detection Capabilities (Abilities Library) | 0 executions | 0.0% | 3 3 active |
| Privileged Access & Vault Visibility (CyberArk) | 0 executions | 0.0% | 2 2 active |
| HR Data Integration (Workday) | 79 executions | 0.1% | 5 4 active |
| Automation Governance & Workflow Metadata Tracking | 2 executions | 0.0% | 1 1 active |
| Total | 68,241 executions | 100% | 106 105 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. High-volume, production-grade SOC automation. The Mimecast attachment alert pipeline alone accounts for 23,128 executions — the single highest-volume automation in the deployment. Running on a 5-minute schedule across both a primary ingest and a parallel threat-hunting ingest, this demonstrates mature, production-grade email security automation covering the most prevalent threat vector (phishing/malicious attachments) in healthcare environments.
2. Deeply integrated ServiceNow bidirectional sync. The ServiceNow case mirroring and state synchronization cluster (7 active playbooks, 5,346 combined executions) represents a mature, production case management integration. Coverage spans incident (INC) and issue (IS) state updates, field-level change tracking, case owner assignment, and error handling. This depth of integration reduces analyst double-entry and maintains audit trails required for HIPAA incident response documentation.
3. Multi-environment network policy enforcement. The Forescout wireless policy violation pipeline operates across two distinct environments (CCO and LTC), with combined ingestion of 975 violation events and 111 automated response actions. For a healthcare payer with distributed facilities, this demonstrates cross-environment security consistency at scale.
4. Agentic SOC capability in development. The presence of an Agentic workspace with five risky-user ability modules (covering CrowdStrike, Varonis, ServiceNow, Entra, and Living Security), a table-join aggregation playbook, and an impossible travel detection workflow indicates Healthfirst is building toward multi-source, AI-driven insider risk detection. This positions the SOC for more sophisticated detection patterns than traditional rule-based SOAR allows.
5. Noma AI security integration. With 2,428 executions, the Noma alert ingestion pipeline is active and producing case volume. This is noteworthy as relatively few organizations have operationalized AI security posture management tooling into their SOC workflows. It indicates awareness and early action on an emerging threat category particularly relevant to healthcare AI adoption. Dedicated Wiz issue tracking and response subflows have also been introduced, extending cloud security posture coverage beyond AI-specific alerting to broader cloud misconfiguration findings.
6. Workday HR enrichment linked to security cases. 78 Workday worker records were automatically linked to open security cases during the period, with 30 additional SOC enrichment runs pulling Workday data. Connecting HR data to security investigations is a differentiating SOC capability that supports insider threat and credential compromise investigations.
7. Emerging automation governance capability. A new scheduled workflow (SOC - Workflow Metadata Tracking) reconciles tracked workflow metadata against the Blink platform API daily. This represents an early step toward addressing the workspace sprawl and duplicate-playbook governance
gap identified below.
Gaps & Opportunities
1. Large enrichment library with near-zero execution volume. The enrichment library contains over 20 playbooks (hash lookups via CrowdStrike and VT, IP enrichment via IPDB/VT, URL enrichment via URLScan/VT, user lookups via Okta/Entra/Google Workspace/Slack/GitHub) with 0 executions recorded. These playbooks appear to be provisioned but not yet integrated into the active alert processing pipeline. Connecting the "Subflow - Enrich Observables - Main Router" (644 executions) to these individual enrichment modules would activate automated enrichment at scale.
2. Response subflows inactive. "Response Subflow - Phishing" and "Response Subflow - Malware" both show 0 executions, despite the Mimecast ingestion pipeline being highly active. The "Subflow - Response - Main Router" also shows 0 executions. This suggests the alert ingestion pipeline is not yet fully connected to automated response actions. Closing this loop would convert ingest volume into automated response throughput.
3. CrowdStrike RTR capabilities unused. Real-time response playbooks for single and batch host actions in CrowdStrike show 0 executions. These represent significant containment automation potential for endpoint threats — the capability infrastructure is built, but it is not yet being triggered from active response workflows.
4. Identity and access management automation is limited. Despite Okta, Microsoft Entra ID, and Active Directory integrations being present, no IAM lifecycle automation (onboarding, offboarding, access review, password reset) shows meaningful execution volume. The Reset AD Password playbook has 0 executions, Okta-based workflows are inactive, and general group management tooling is largely absent (a new CyberArk Safe Creation workflow does provision AD admin/user/lister groups tied to PAM safes, but no broader onboarding/offboarding lifecycle automation exists). For a healthcare organization with HIPAA access control requirements, this represents a high-value automation gap.
5. Fraud detection library not yet operationalized. LexisNexis, Telesign, and MinFraud ability playbooks have 0 executions. While built and presumably tested, they have not been integrated into active fraud detection or member onboarding workflows. Given Healthfirst's exposure to healthcare fraud, activating these integrations into operational workflows would provide measurable GRC value.
6. GRC / Compliance reporting automation absent. No playbooks for automated compliance reporting, evidence collection, or regulatory questionnaire support are deployed. Given HIPAA, PCI DSS, and state insurance regulatory obligations, there is a clear opportunity to extend Blink's automation into the compliance operations domain.
7. Duplicate playbook names across workspaces. Multiple playbooks (e.g., "Enrich - Agent ID - Crowdstrike", "Enrich - URL - URLScan", "SOC - Case Management - ServiceNow Error Handling", "Utility - Get Random Case Owner") appear under different workspace IDs with identical names. This pattern across 11 workspaces suggests workspace sprawl or a multi-tenant architecture that may benefit from consolidation or governance review to prevent configuration drift.
Integration Ecosystem
The following integrations are currently deployed and active within the Healthfirst Blink environment:
| Integration | Category | Usage Status |
|---|---|---|
| Mimecast | Email security | Active — high volume |
| ServiceNow | ITSM / case management | Active — high volume |
| CrowdStrike Falcon | EDR / threat intelligence | Active |
| Noma | AI security posture | Active |
| Forescout | Network access control | Active |
| Canary | Deception technology | Active |
| Varonis | Data access analytics | Active |
| Workday | HR data / identity | Active |
| Microsoft Intune | MDM / endpoint inventory | Active |
| Living Security | Security awareness / risk scoring | Active (minimal) |
| ActiveOps WorkIQ | Workforce analytics | Active |
| Microsoft Entra ID / Azure AD | Identity directory | Provisioned, minimal usage |
| Okta | Identity / SSO | Provisioned, not active |
| VirusTotal | Threat intelligence | Provisioned, not active |
| URLScan | URL threat intelligence | Provisioned, not active |
| IPDB | IP threat intelligence | Provisioned, not active |
| Whois | Domain intelligence | Provisioned, not active |
| GitHub | Developer identity | Provisioned, not active |
| Google Workspace | Identity / collaboration | Provisioned, not active |
| Slack | Identity / notification | Provisioned, not active |
| CyberArk | PAM / privileged access | Provisioned, not active |
| LexisNexis | Identity verification / fraud | Provisioned, not active |
| Telesign | Phone risk scoring | Provisioned, not active |
| MaxMind MinFraud | Transaction fraud scoring | Provisioned, not active |
| MISP | Threat intelligence platform | Provisioned, not active |
| NetSkope | CASB / DLP | Active (response playbook) |
| Wiz | Cloud security posture management | Active (minimal) |
| Microsoft Teams | Notification / collaboration | Active (minimal) |
A Case Management 740 cases (12m) | MTTR 15d 7h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| SOC | 739 | 739 | 642 | 15d 7h |
| Case Management Playground | 2 | 1 | 0 | N/A |
B AI Agents 3 active | 87 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Risky User Analysis | AgentsDemo | 80 | 0 | 5,420,604 |
| 2 | Impossible Travel Agent | Case Management Playground | 5 | 0 | 270,015 |
| 3 | The Registration Integrity Agent | AgentsDemo | 2 | 0 | 139,052 |
| 4 | Agent Blink | Case Management Playground | 0 | 0 | 0 |
| 5 | Agent Blink | SOC | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| AgentsDemo | 82 |
| Case Management Playground | 5 |
| SOC | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Case Management Dashboard | 0 | 0 |
| 2 | Privacy Open PCI Tickets | 0 | 0 |
| 3 | Privacy PCI Tickets | 0 | 0 |
| 4 | Open ServiceNow Tickets | 0 | 0 |
| 5 | RiskyUsers Overview | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 16 use cases | 81,828 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Email attachment threat alerts ingested & processed | 11,564 | Ingest - Mimecast - Get Attachment Alerts |
| Email attachment alerts scanned for threat hunting | 11,564 | Ingest - Mimecast - Get Attachment Alerts for Threat Hunting |
| Bi-directional ServiceNow case sync events handled | 3,855 | ServiceNow Mirroring - Test |
| AI/ML security alerts ingested from Noma | 2,428 | SOC - Ingest - Noma Alerts |
| Security alerts processed end-to-end | 1,160 | Process Alert |
| IOC reputation checks executed against CrowdStrike | 714 | CrowdStrike Falcon IOC Reputation Check |
| Wireless policy violations ingested (CCO environment) | 535 | CCO - Ingest - Forescout Wireless Policy Violations |
| Canary deception sensor disconnections detected & alerted | 482 | SOC - Scheduled - Canary Disconnection Monitoring |
| Case comment events processed and synchronized | 470 | New Comment Added to Case |
| Wireless policy violations ingested (LTC environment) | 440 | LTC - Ingest - Forescout Wireless Policy Violations |
| Cases automatically created from active alerts | 165 | SOC - Case Management - Case Creation with Alerts |
| Wireless policy violations responded to (CCO) | 111 | CCO - Response - Forescout Wireless Policy Violation |
| Varonis PCI data access alerts responded to | 103 | SOC - Response - Varonis PCI Alert |
| CrowdStrike EDR alerts triaged and responded to | 75 | Ingest - CrowdStrike Webhook |
| Mimecast phishing/malware cases responded to | 52 | Response - Mimecast Cases |
| NetSkope unauthorized webmail incidents handled | 68 | SOC - Response - NetSkope Webmail |
| CrowdStrike endpoint response actions executed | 56 | SOC - Response - CrowdStrike Falcon |
| Threat intelligence records curated | 174 | Threat intel |
| Varonis PCI alerts ingested for analysis | 40 | SOC - Ingest - Varonis PCI Alert |
| Metasploit scanning detections responded to | 36 | SOC - Response - Metasploit Scanning |
| Employee records synced to SOC cases from Workday | 78 | Workday Worker Link to Case |
| Endpoint records reconciled across Intune and CrowdStrike | 25 | Device Reconciliation Intune or CrowdStrike |
Use Case Summary
| # | Use Case | Category | Playbooks | Active Playbooks | Total Executions |
|---|---|---|---|---|---|
| 1 | Email Threat Ingestion & Response | SOC — Phishing detection & response | 5 | 4 | 23,180 |
| 2 | SOC Case Management & SOAR | SOC — Case mgmt & SOAR | 20 | 17 | 6,895 |
| 3 | AI/Cloud Security Alert Ingestion & Response (Noma & Wiz) | Cloud Security — CSPM ingest & triage | 3 | 2 | 2,433 |
| 4 | Alert Enrichment & IOC Lookup | SOC — Alert enrichment / IOC lookup | 25 | 5 | 1,432 |
| 5 | Network Access Policy Enforcement (Forescout) | Other — IT/OT & network infra monitoring | 5 | 5 | 1,117 |
| 6 | EDR Ingestion & Response (CrowdStrike) | SOC — EDR containment & response | 9 | 6 | 917 |
| 7 | Deception Technology Monitoring (Canary) | SOC — Alert enrichment / IOC lookup | 3 | 2 | 510 |
| 8 | PCI & Data Access Alert Response (Varonis) | GRC — PCI & regulatory monitoring | 3 | 3 | 148 |
| 9 | Threat Intelligence Curation | SOC — Threat intel ingest & curation | 2 | 1 | 174 |
| 10 | SOC Enrichment — Identity & Endpoint Context | SOC — Alert enrichment / IOC lookup | 7 | 4 | 175 |
| 11 | Endpoint Inventory & Hygiene (Intune/CrowdStrike) | Other — Endpoint hygiene & MDM ops | 4 | 4 | 107 |
| 12 | Agentic Risky User Detection & Response | SOC — Agentic SOC / Identity threat response | 12 | 7 | 8 |
| 13 | Fraud Detection Capabilities (Abilities Library) | GRC — AML / KYC compliance | 3 | 0 | 0 |
| 14 | Privileged Access & Vault Visibility (CyberArk) | IAM — Privileged account mgmt | 2 | 0 | 0 |
| 15 | HR Data Integration (Workday) | Other — IT helpdesk & ticket routing | 5 | 3 | 118 |
| 16 | Automation Governance & Workflow Metadata Tracking | GRC — Security metrics & reporting | 1 | 1 | 2 |
Use Cases
1. Email Threat Ingestion & Response
Description: Automated pipeline for continuously ingesting Mimecast attachment protection logs, creating structured alerts, and executing response workflows for confirmed phishing and malware cases. Runs on a 5-minute polling schedule to minimize dwell time between email threat detection and analyst action.
Business Problem Solved: Manual review of Mimecast attachment protection logs is time-intensive and creates lag between email detonation events and analyst engagement. This automation closes that gap by creating normalized alerts and routing cases through a standardized response workflow.
Category: SOC — Phishing detection & response
Integrations: Mimecast, Blink Case Management
| Playbook | Executions | Taxonomy |
|---|---|---|
| Ingest - Mimecast - Get Attachment Alerts | 11,564 | SOC — Phishing detection & response |
| Ingest - Mimecast - Get Attachment Alerts for Threat Hunting | 11,564 | SOC — Threat hunting & detection |
| Response - Mimecast Cases | 52 | SOC — Phishing detection & response |
| Ingest - Mimecast - Get URL for Threat Hunting | 0 | SOC — Threat hunting & detection |
| IT Security Program - Get Mimecast Release Requests | 0 | SOC — Phishing detection & response |
2. SOC Case Management & SOAR
Description: Comprehensive bi-directional case management integration between Blink and ServiceNow, covering case creation, state synchronization, comment mirroring, case owner assignment, and error handling. Forms the operational backbone of the Healthfirst SOC workflow.
Business Problem Solved: SOC analysts require a single source of truth across Blink's native case management and ServiceNow INC/IS ticket workflows. Without automation, state changes, comments, and ticket assignments require manual double-entry across systems, increasing error rates and degrading response times.
Category: SOC — Case mgmt & SOAR
Integrations: Blink Case Management, ServiceNow
3. AI/Cloud Security Alert Ingestion & Response (Noma & Wiz)
Description: Automated ingestion of alerts from Noma, an AI/ML security posture platform that monitors AI applications and data pipelines for misconfigurations and anomalous usage, alongside dedicated tracking and response subflows for Wiz cloud security findings. Ingested alerts are converted to normalized Blink cases for analyst triage, and Wiz issues are routed through their own response and tracking logic.
Business Problem Solved: As Healthfirst expands its AI and data platform footprint, visibility into AI-specific risk vectors (model misuse, data exfiltration via AI APIs, shadow AI) requires a dedicated ingestion path. Noma provides that signal; this automation ensures it reaches the SOC promptly. Wiz surfaces cloud misconfiguration and posture findings that also require structured, consistent tracking; dedicated subflows ensure these issues are logged and actioned alongside AI security alerts.
Category: Cloud Security — CSPM ingest & triage
Integrations: Noma, Wiz, ServiceNow, Blink Case Management
| Playbook | Executions | Taxonomy |
|---|---|---|
| SOC - Ingest - Noma Alerts | 2,428 | Cloud Security — CSPM ingest & triage |
| SOC - Response - Wiz Issue | 5 | Cloud Security — CSPM ingest & triage |
| IT Security Program - Track Wiz Issue Subflow | 0 | Cloud Security — CSPM ingest & triage |
4. Alert Enrichment & IOC Lookup
Description: Modular library of enrichment subflows and standalone lookups covering IP addresses, file hashes, URLs, domains, email addresses, and usernames. Integrations span CrowdStrike Falcon Intelligence, VirusTotal, URLScan, Whois, Okta, Microsoft Entra ID, Google Workspace, Slack, and GitHub.
Business Problem Solved: Analysts investigating alerts require corroborating context across multiple threat intelligence and identity sources. Without automation, enrichment is manual, inconsistent, and time-consuming. These playbooks standardize enrichment, reduce analyst toil, and accelerate triage.
Category: SOC — Alert enrichment / IOC lookup
Integrations: CrowdStrike Falcon, VirusTotal, URLScan, Whois/IPDB, Okta, Microsoft Entra ID, Google Workspace, Slack, GitHub, Blink Case Management
| Playbook | Executions | Taxonomy |
|---|---|---|
| CrowdStrike Falcon IOC Reputation Check | 714 | SOC — Alert enrichment / IOC lookup |
| Subflow - Enrich Observables - Main Router | 644 | SOC — Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | 69 | SOC — Case mgmt & SOAR |
| Indicator Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Hash - VT | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - IP - VT | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - URL - VT | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Username - Github | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | 0 | SOC — Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 0 | SOC — Alert enrichment / IOC lookup |
| IOC Reputation Check - CrowdStrike Intel | 0 | SOC — Alert enrichment / IOC lookup |
| Main IOC Reputation Check - CrowdStrike Intel | 0 | SOC — Alert enrichment / IOC lookup |
| Domain Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| Email Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| File Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| URL Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| SOC - Utility - Get Observables from Case | 0 | SOC — Alert enrichment / IOC lookup |
5. Network Access Policy Enforcement (Forescout)
Description: Automated ingestion of wireless policy violations from Forescout across two distinct environments (CCO and LTC), with automated remediation workflows that evaluate violations, issue notifications, and generate compliance reports. Runs on a scheduled polling model to ensure continuous enforcement.
Business Problem Solved: Unauthorized wireless device connections represent a significant attack surface in healthcare environments subject to HIPAA and PCI requirements. Manual review of Forescout violation logs creates compliance gaps. This use case automates detection-to-notification cycles and maintains an audit trail.
Category: Other — IT/OT & network infra monitoring; GRC — PCI & regulatory monitoring
Integrations: Forescout, Blink Case Management, Notification/Email
| Playbook | Executions | Taxonomy |
|---|---|---|
| CCO - Ingest - Forescout Wireless Policy Violations | 535 | Other — IT/OT & network infra monitoring |
| LTC - Ingest - Forescout Wireless Policy Violations | 440 | Other — IT/OT & network infra monitoring |
| CCO - Response - Forescout Wireless Policy Violation | 111 | Other — IT/OT & network infra monitoring |
| CCO - Subflow - Send Policy Violation Notification | 30 | Other — IT/OT & network infra monitoring |
| LTC - Response - Wireless Policy Violation Report | 1 | Other — IT/OT & network infra monitoring |
6. EDR Ingestion & Response (CrowdStrike)
Description: Full pipeline from CrowdStrike Falcon webhook alert ingestion through enrichment to response actions including endpoint investigation and real-time response (RTR) operations. Also covers detection of exploit activity, Metasploit scanning events, and outbound anomalous traffic.
Business Problem Solved: CrowdStrike generates high-volume endpoint telemetry. Without automation, analysts must manually pivot from Falcon alerts to investigation steps. This use case automates the ingest-enrich-respond chain, reducing mean time to respond (MTTR) for endpoint threats.
Category: SOC — EDR containment & response
Integrations: CrowdStrike Falcon, Blink Case Management, ServiceNow
| Playbook | Executions | Taxonomy |
|---|---|---|
| Ingest - CrowdStrike Webhook | 75 | SOC — EDR containment & response |
| SOC - Response - CrowdStrike Falcon | 56 | SOC — EDR containment & response |
| SOC - Response - Metasploit Scanning | 36 | SOC — EDR containment & response |
| Schedual pro active huntin | 40 | SOC — Threat hunting & detection |
| Crowdstrike Exploit | 0 | SOC — EDR containment & response |
| CrowdStrike RTR to a Single Host | 0 | SOC — EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | 0 | SOC — EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | SOC — EDR containment & response |
| SOC - Response - Remote Access to Internet | 0 | SOC — EDR containment & response |
7. Deception Technology Monitoring (Canary)
Description: Continuous monitoring of Canary deception tokens and sensors, including scheduled health-check polling for disconnected sensors and event-driven webhook ingestion when Canary tokens are triggered. Automated response allows for IP whitelisting after analyst review.
Business Problem Solved: Deception technology is only effective if sensors are operational and alerts are actioned promptly. Manual monitoring of Canary infrastructure creates gaps where sensors can go dark unnoticed. Automated disconnection detection and alert routing ensures deception coverage is continuously validated.
Category: SOC — Alert enrichment / IOC lookup; SOC — EDR containment & response
Integrations: Canary, Blink Case Management
| Playbook | Executions | Taxonomy |
|---|---|---|
| SOC - Scheduled - Canary Disconnection Monitoring | 482 | SOC — Alert enrichment / IOC lookup |
| SOC - Ingest - Canary Webhook | 28 | SOC — Alert enrichment / IOC lookup |
| SOC - Action - Canary Whitelist IP | 0 | SOC — EDR containment & response |
| SOC - Response - Canary Incident | 0 | SOC — EDR containment & response |
8. PCI & Data Access Alert Response (Varonis)
Description: Automated ingestion and response for Varonis Data Activity Classification (DAC) alerts related to PCI data access anomalies. Ingestion playbook captures new Varonis alerts; response playbook executes the documented PCI violation response procedure.
Business Problem Solved: As a healthcare payer, Healthfirst handles both PHI and payment card data subject to HIPAA and PCI DSS requirements. Varonis provides behavioral analytics on data access; automating the alert-to-response cycle ensures that suspected PCI data exposure events are consistently and promptly investigated.
Category: GRC — PCI & regulatory monitoring; GRC — DLP triage & exposure resp
Integrations: Varonis, Blink Case Management, ServiceNow
| Playbook | Executions | Taxonomy |
|---|---|---|
| SOC - Ingest - Varonis PCI Alert | 40 | GRC — PCI & regulatory monitoring |
| SOC - Response - Varonis PCI Alert | 103 | GRC — PCI & regulatory monitoring |
| On New Alert - Varonis DAC | 5 | GRC — DLP triage & exposure resp |
9. Threat Intelligence Curation
Description: Scheduled threat intelligence ingestion and curation workflow, alongside a proactive threat hunting schedule. The threat intel playbook handles structured indicator ingestion; the scheduled hunting playbook executes proactive searches based on current intelligence.
Business Problem Solved: Static threat intelligence without operational integration provides limited SOC value. These playbooks operationalize threat intel by scheduling regular ingestion and driving proactive hunting runs, ensuring indicators remain current and hunts are executed consistently.
Category: SOC — Threat intel ingest & curation; SOC — Threat hunting & detection
Integrations: Threat intelligence platform (MISP-compatible), CrowdStrike, Blink Case Management
| Playbook | Executions | Taxonomy |
|---|---|---|
| Threat intel | 174 | SOC — Threat intel ingest & curation |
| MISP-Test | 0 | SOC — Threat intel ingest & curation |
10. SOC Enrichment — Identity & Endpoint Context
Description: Dedicated enrichment playbooks that augment open SOC cases with identity context from Workday HR data and endpoint context from CrowdStrike Falcon. Identity linkage to cases improves analyst context significantly for insider threat and privileged access investigations.
Business Problem Solved: Correlating security events to the full identity and HR profile of an employee (their role, manager, recent activity, PTO status) is essential for insider threat investigations and credential compromise triage. Pulling this context manually from Workday is time-consuming; these playbooks automate the linkage.
Category: SOC — Alert enrichment / IOC lookup; IAM — Identity sync & directory mgmt
Integrations: Workday, CrowdStrike Falcon, Microsoft Entra ID, Okta, Blink Case Management
| Playbook | Executions | Taxonomy |
|---|---|---|
| Workday Worker Link to Case | 78 | SOC — Alert enrichment / IOC lookup |
| SOC - Enrichment - Add Workday Worker Records | 30 | SOC — Alert enrichment / IOC lookup |
| SOC - Enrichment - Get Falcon Device by IP | 1 | SOC — Alert enrichment / IOC lookup |
| Healthfirst - Username - Entra Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| Azure AD Account Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| User/Host Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
| Netscope CTE Enrichment | 0 | SOC — Alert enrichment / IOC lookup |
11. Endpoint Inventory & Hygiene (Intune / CrowdStrike)
Description: Scheduled synchronization and reconciliation of endpoint inventory data between Microsoft Intune and CrowdStrike Falcon. Includes daily device record syncs, device additions, and cross-platform reconciliation to identify managed device gaps.
Business Problem Solved: Healthcare organizations must maintain comprehensive asset inventories for HIPAA risk assessments and vulnerability management programs. Discrepancies between MDM (Intune) and EDR (CrowdStrike) coverage indicate unmanaged endpoints. Automated reconciliation surfaces these gaps without requiring manual spreadsheet comparisons.
Category: Other — Endpoint hygiene & MDM ops; Vulnerability Mgmt — Cloud asset coverage & inventory
Integrations: Microsoft Intune, CrowdStrike Falcon
| Playbook | Executions | Taxonomy |
|---|---|---|
| InTune Get Devices | 40 | Other — Endpoint hygiene & MDM ops |
| Add Device Records | 36 | Other — Endpoint hygiene & MDM ops |
| Device Reconciliation Intune or CrowdStrike | 25 | Other — Endpoint hygiene & MDM ops |
| Update Crowdstrike Devices | 6 | Other — Endpoint hygiene & MDM ops |
12. Agentic Risky User Detection & Response
Description: Agentic workflows that aggregate risky user signals from multiple sources — CrowdStrike, Varonis, ServiceNow, Microsoft Entra ID, and Living Security — into a unified risk table. Ability playbooks serve as callable intelligence modules for per-source risky user lookups. Agentic impossible travel detection is in the pipeline.
Business Problem Solved: Insider risk and compromised credential scenarios require correlating behavioral anomalies across multiple data sources before a confident determination can be made. The agentic pattern allows for adaptive, multi-step investigation logic without requiring a fixed playbook sequence.
Category: SOC — Agentic SOC; SOC — Identity threat response; GRC — RBAC review & access mgmt
Integrations: CrowdStrike Falcon, Varonis, ServiceNow, Microsoft Entra ID, Living Security, Okta
| Playbook | Executions | Taxonomy |
|---|---|---|
| Entra Get Risky User - Ability | 1 | SOC — Agentic SOC; SOC — Identity threat response |
| Get Servicenow Risky User - Ability | 1 | SOC — Agentic SOC; SOC — Identity threat response |
| Get Crowdstrike Risky User - Ability | 1 | SOC — Agentic SOC; SOC — EDR containment & response |
| Get Varonis Risky User - Ability | 1 | SOC — Agentic SOC; GRC — DLP triage & exposure resp |
| Living Security Get Risky User - Ability | 1 | SOC — Agentic SOC; SOC — Identity threat response |
| AGENTIC All risky Users - Table Join | 0 | SOC — Agentic SOC |
| 1. Agentic Impossible Travel Workflow | 0 | SOC — Agentic SOC; SOC — Identity threat response |
| Crowdstrike Risky User - Table Fill | 0 | SOC — Identity threat response |
| Entra Risky User - Table Fill | 0 | SOC — Identity threat response |
| Varonis Risky User - Table Fill | 0 | GRC — DLP triage & exposure resp |
| Living Security Risky User - Table Fill | 0 | SOC — Identity threat response |
| Servicenow Risky User - Table Fill | 0 | SOC — Identity threat response |
13. Fraud Detection Capabilities (Abilities Library)
Description: A library of callable fraud detection abilities covering LexisNexis identity verification, Telesign phone risk scoring, and MaxMind MinFraud transaction risk scoring. These are on-demand ability modules intended to be embedded within broader investigation or onboarding workflows.
Business Problem Solved: As a health insurance organization, Healthfirst is exposed to healthcare fraud risk including member identity fraud and provider fraud. Having pre-built, callable fraud check abilities enables rapid assembly of fraud detection workflows without rebuilding integration logic.
Category: GRC — AML / KYC compliance; GRC — Financial & fraud operations
Integrations: LexisNexis, Telesign, MaxMind MinFraud
| Playbook | Executions | Taxonomy |
|---|---|---|
| LexisNexis - Fraud Check - Ability | 0 | GRC — AML / KYC compliance |
| Telesign Fraud Check - Ability | 0 | GRC — AML / KYC compliance |
| MinFraud - Ability | 0 | GRC — AML / KYC compliance |
14. Privileged Access & Vault Visibility (CyberArk)
Description: Playbooks for enumerating CyberArk PAM safes and reporting contents via email, providing periodic visibility into privileged account inventory and vault structure, plus an on-demand safe provisioning workflow that creates new CyberArk Privilege Cloud safes, establishes the corresponding on-premises AD admin/user/lister groups, and assigns tiered safe permissions.
Business Problem Solved: Privileged account sprawl is a persistent IAM risk. Periodic reporting of CyberArk safe contents allows security teams to identify orphaned accounts, validate vault hygiene, and support access certification programs. Manual safe provisioning — coordinating safe creation, AD group setup, and permission assignment across separate systems — introduces delay and inconsistency; the safe creation workflow standardizes this sequence into a single on-demand automation.
Category: IAM — Privileged account mgmt
Integrations: CyberArk, On-Prem Active Directory
| Playbook | Executions | Taxonomy |
|---|---|---|
| List Safes with CyberArk and Send Results via Email | 0 | IAM — Privileged account mgmt |
| CyberArk Safe Creation_AuthorUnknown | 0 | IAM — Privileged account mgmt |
15. HR Data Integration (Workday)
Description: Scheduled synchronization of active Workday worker records to support SOC enrichment and case context. Includes daily RaaS report pulls, PTO status checks, and a worker data sync that keeps Blink tables current with HR data. The ActiveOps WorkIQ integration provides workforce analytics data alongside security telemetry.
Business Problem Solved: Security investigations involving employees require current HR context: active employment status, role, manager, and leave status. Stale or absent HR data leads to unnecessary escalations or missed insider threat indicators. Automated Workday sync ensures SOC enrichment data reflects current employment records.
Category: Other — IT helpdesk & ticket routing; IAM — Identity sync & directory mgmt
Integrations: Workday, ActiveOps WorkIQ
| Playbook | Executions | Taxonomy |
|---|---|---|
| Workday Worker Data RaaS Sync - Daily | 40 | IAM — Identity sync & directory mgmt |
| ActiveOps - WorkIQ - Get Timeline Events Export | 27 | Other — IT helpdesk & ticket routing |
| Workday - Get Active Workers Raas Report | 0 | IAM — Identity sync & directory mgmt |
| Workday PTO Check | 0 | IAM — Identity sync & directory mgmt |
| Workday Workers Enrichment | 0 | IAM — Identity sync & directory mgmt |
16. Automation Governance & Workflow Metadata Tracking
Description: Scheduled daily job that pulls workflow metadata from a tracking table, queries the Blink platform API for the current state of tracked workflows, and loops through results to reconcile the automation inventory.
Business Problem Solved: With automation deployed across 11+ workspaces, maintaining visibility into which workflows exist, their status, and metadata drift requires a dedicated tracking mechanism. This playbook automates daily reconciliation of the workflow inventory, supporting governance and reducing the risk of untracked or duplicate automations.
Category: GRC — Security metrics & reporting
Integrations: Blink Platform API, Blink Tables
| Playbook | Executions | Taxonomy |
|---|---|---|
| SOC - Workflow Metadata Tracking | 2 | GRC — Security metrics & reporting |
Key Observations
Strengths
1. High-volume, production-grade SOC automation. The Mimecast attachment alert pipeline alone accounts for 23,128 executions — the single highest-volume automation in the deployment. Running on a 5-minute schedule across both a primary ingest and a parallel threat-hunting ingest, this demonstrates mature, production-grade email security automation covering the most prevalent threat vector (phishing/malicious attachments) in healthcare environments.
2. Deeply integrated ServiceNow bidirectional sync. The ServiceNow case mirroring and state synchronization cluster (7 active playbooks, 5,346 combined executions) represents a mature, production case management integration. Coverage spans incident (INC) and issue (IS) state updates, field-level change tracking, case owner assignment, and error handling. This depth of integration reduces analyst double-entry and maintains audit trails required for HIPAA incident response documentation.
3. Multi-environment network policy enforcement. The Forescout wireless policy violation pipeline operates across two distinct environments (CCO and LTC), with combined ingestion of 975 violation events and 111 automated response actions. For a healthcare payer with distributed facilities, this demonstrates cross-environment security consistency at scale.
4. Agentic SOC capability in development. The presence of an Agentic workspace with five risky-user ability modules (covering CrowdStrike, Varonis, ServiceNow, Entra, and Living Security), a table-join aggregation playbook, and an impossible travel detection workflow indicates Healthfirst is building toward multi-source, AI-driven insider risk detection. This positions the SOC for more sophisticated detection patterns than traditional rule-based SOAR allows.
5. Noma AI security integration. With 2,428 executions, the Noma alert ingestion pipeline is active and producing case volume. This is noteworthy as relatively few organizations have operationalized AI security posture management tooling into their SOC workflows. It indicates awareness and early action on an emerging threat category particularly relevant to healthcare AI adoption. Dedicated Wiz issue tracking and response subflows have also been introduced, extending cloud security posture coverage beyond AI-specific alerting to broader cloud misconfiguration findings.
6. Workday HR enrichment linked to security cases. 78 Workday worker records were automatically linked to open security cases during the period, with 30 additional SOC enrichment runs pulling Workday data. Connecting HR data to security investigations is a differentiating SOC capability that supports insider threat and credential compromise investigations.
7. Emerging automation governance capability. A new scheduled workflow (SOC - Workflow Metadata Tracking) reconciles tracked workflow metadata against the Blink platform API daily. This represents an early step toward addressing the workspace sprawl and duplicate-playbook governance gap identified below.
Gaps & Opportunities
1. Large enrichment library with near-zero execution volume. The enrichment library contains over 20 playbooks (hash lookups via CrowdStrike and VT, IP enrichment via IPDB/VT, URL enrichment via URLScan/VT, user lookups via Okta/Entra/Google Workspace/Slack/GitHub) with 0 executions recorded. These playbooks appear to be provisioned but not yet integrated into the active alert processing pipeline. Connecting the "Subflow - Enrich Observables - Main Router" (644 executions) to these individual enrichment modules would activate automated enrichment at scale.
2. Response subflows inactive. "Response Subflow - Phishing" and "Response Subflow - Malware" both show 0 executions, despite the Mimecast ingestion pipeline being highly active. The "Subflow - Response - Main Router" also shows 0 executions. This suggests the alert ingestion pipeline is not yet fully connected to automated response actions. Closing this loop would convert ingest volume into automated response throughput.
3. CrowdStrike RTR capabilities unused. Real-time response playbooks for single and batch host actions in CrowdStrike show 0 executions. These represent significant containment automation potential for endpoint threats — the capability infrastructure is built, but it is not yet being triggered from active response workflows.
4. Identity and access management automation is limited. Despite Okta, Microsoft Entra ID, and Active Directory integrations being present, no IAM lifecycle automation (onboarding, offboarding, access review, password reset) shows meaningful execution volume. The Reset AD Password playbook has 0 executions, Okta-based workflows are inactive, and general group management tooling is largely absent (a new CyberArk Safe Creation workflow does provision AD admin/user/lister groups tied to PAM safes, but no broader onboarding/offboarding lifecycle automation exists). For a healthcare organization with HIPAA access control requirements, this represents a high-value automation gap.
5. Fraud detection library not yet operationalized. LexisNexis, Telesign, and MinFraud ability playbooks have 0 executions. While built and presumably tested, they have not been integrated into active fraud detection or member onboarding workflows. Given Healthfirst's exposure to healthcare fraud, activating these integrations into operational workflows would provide measurable GRC value.
6. GRC / Compliance reporting automation absent. No playbooks for automated compliance reporting, evidence collection, or regulatory questionnaire support are deployed. Given HIPAA, PCI DSS, and state insurance regulatory obligations, there is a clear opportunity to extend Blink's automation into the compliance operations domain.
7. Duplicate playbook names across workspaces. Multiple playbooks (e.g., "Enrich - Agent ID - Crowdstrike", "Enrich - URL - URLScan", "SOC - Case Management - ServiceNow Error Handling", "Utility - Get Random Case Owner") appear under different workspace IDs with identical names. This pattern across 11 workspaces suggests workspace sprawl or a multi-tenant architecture that may benefit from consolidation or governance review to prevent configuration drift.
Integration Ecosystem
The following integrations are currently deployed and active within the Healthfirst Blink environment:
| Integration | Category | Usage Status |
|---|---|---|
| Mimecast | Email security | Active — high volume |
| ServiceNow | ITSM / case management | Active — high volume |
| CrowdStrike Falcon | EDR / threat intelligence | Active |
| Noma | AI security posture | Active |
| Forescout | Network access control | Active |
| Canary | Deception technology | Active |
| Varonis | Data access analytics | Active |
| Workday | HR data / identity | Active |
| Microsoft Intune | MDM / endpoint inventory | Active |
| Living Security | Security awareness / risk scoring | Active (minimal) |
| ActiveOps WorkIQ | Workforce analytics | Active |
| Microsoft Entra ID / Azure AD | Identity directory | Provisioned, minimal usage |
| Okta | Identity / SSO | Provisioned, not active |
| VirusTotal | Threat intelligence | Provisioned, not active |
| URLScan | URL threat intelligence | Provisioned, not active |
| IPDB | IP threat intelligence | Provisioned, not active |
| Whois | Domain intelligence | Provisioned, not active |
| GitHub | Developer identity | Provisioned, not active |
| Google Workspace | Identity / collaboration | Provisioned, not active |
| Slack | Identity / notification | Provisioned, not active |
| CyberArk | PAM / privileged access | Provisioned, not active |
| LexisNexis | Identity verification / fraud | Provisioned, not active |
| Telesign | Phone risk scoring | Provisioned, not active |
| MaxMind MinFraud | Transaction fraud scoring | Provisioned, not active |
| MISP | Threat intelligence platform | Provisioned, not active |
| NetSkope | CASB / DLP | Active (response playbook) |
| Wiz | Cloud security posture management | Active (minimal) |
| Microsoft Teams | Notification / collaboration | Active (minimal) |
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| healthfirst | blink | blinkops_api_connection | 2026-08-26 |
| healthfirst | forescout | forescout_aws | 2026-08-05 |