Blink Security Automation — Confidential

hub — Customer Success Report

Generated 2026-08-30 | hub-value-report.md
2026-08-30Report Date
423Total Playbooks
83Unique Workflows (12m)
43,668,827Actions Automated (12m)
$11,231,694Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

423
Total playbooks built
all non-deleted workflows
148
Active playbooks
currently enabled
83
Unique workflows executed (12m)
distinct workflows that ran
43,668,827
Actions automated (12m)
completed action steps
242,604.6h
Hours saved (12m)
@ 20s per action
$11,231,694
Money saved (12m)
@ $100K avg salary
1
New active workflows (last 30d)
recently created & enabled
33,065
Total cases managed
30,376 opened in last 12m
9h 58m
MTTR — mean time to resolve
closed cases, last 12m
3
Active AI agents
of 9 total
16
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 11,485 security alerts processed and auto-triaged through the SOAR pipeline without manual intervention - 10,775 case overviews auto-built with full IOC enrichment context for analyst review - 10,621 automated response actions executed across active security cases - 9,849 case comments bidirectionally synchronized between Blink and the CSS external ticketing system - 6,666 Microsoft Defender for Cloud Apps alerts automatically ingested into the SOAR platform - 3,855 Intune device compliance alerts monitored and reported - 3,681 phishing emails triaged end-to-end with automated analysis and case creation - 3,676 email bodies analyzed for malicious headers, URLs, attachments, and sender domains - 2,999 phishing case status updates with analyst notifications pushed automatically - 1,135 user passwords reset via automated Entra identity response - 1,125 active user sessions revoked in response to confirmed incidents - 1,122 MFA credentials reset for suspicious or compromised accounts - 1,086 Nigeria-origin logins investigated with full sign-in log retrieval and context - 976 suspicious geolocation logins automatically verified and remediated via password reset workflow - 190 Microsoft Defender XDR incidents ingested into the case management platform - 52 impossible travel events fully investigated with sign-in history and travel tracker cross-check - 5 Microsoft Defender incident case enrichments auto-generated with structured HTML summaries

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC — Automated Alert Triage & Response
  • 11,485Security alerts processed & auto-triaged through the SOC pipeline
  • 10,775Case overviews auto-built with enriched IOC context
  • 10,621Automated response actions executed on active cases
50.6%
22
22 active
Phishing Detection & Response
  • 3,681Phishing emails triaged end-to-end
  • 3,676Phishing emails analyzed (header, URL, attachment, sender domain)
  • 2,999Phishing case updates with analyst notifications
0.0%
10
8 active
Identity Threat Response
  • 1,135User passwords reset via automated identity response
  • 1,125Active user sessions revoked during incident response
  • 1,122MFA credentials reset for compromised or suspicious accounts
3.0%
8
8 active
Case Mgmt & SOAR — CSS Ticketing Integration
  • 9,849Case comments synced bidirectionally with CSS ticketing
  • 1,075CSS external tickets ingested and parsed into Blink
  • 415CSS ticket status changes processed and synced to Blink
13.2%
11
11 active
EDR Containment & Response0 executions
0.0%
2
2 active
Alert Enrichment / IOC Lookup0 executions
0.0%
9
9 active
Cloud Asset Coverage & Inventory
  • 6,666Microsoft Defender for Cloud Apps alerts ingested into SOAR
  • 3,855Intune device compliance alerts monitored & reported
22.3%
2
2 active
Threat Intel Ingest & Curation — GreyMatter DRP
  • 32Digital risk protection (DRP) alerts polled from GreyMatter
0.0%
3
1 active
Security Metrics & Reporting85 executions
0.1%
4
4 active
Agentic SOC — AI Agent Capabilities0 executions
0.0%
6
6 active
Microsoft Defender XDR Ingestion
  • 190Microsoft Defender XDR incidents ingested
  • 5Microsoft Defender incident case enrichments auto-generated
1.6%
5
5 active
Total55,287 executions100%
82
78 active

Use Case Growth Over Time

303 unique playbooks  |  11 operational use cases  |  60,786 total executions (12m)  |  2024-08 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment / IOC Lookup
CrowdStrike URLScan VirusTotal AbuseIPDB Okta
Identity Threat Response
Microsoft Entra ID Email Microsoft Outlook
Phishing Detection & Response
Microsoft Outlook Mimecast Any Run Email
Case Mgmt & SOAR — CSS Ticketing Integration
Email
Agentic SOC — Automated Alert Triage & Response
ServiceNow Microsoft Excel Microsoft Entra ID Microsoft Teams
Cloud Asset Coverage & Inventory
Microsoft Graph Email
EDR Containment & Response
Microsoft Entra ID SentinelOne Zscaler Internet Access Mimecast Email
Threat Intel Ingest & Curation — GreyMatter DRP
Microsoft Entra ID Email
Security Metrics & Reporting
Microsoft Graph Email Jira
Agentic SOC — AI Agent Capabilities
Email Agents Joe Sandbox
Microsoft Defender XDR Ingestion
Microsoft Defender XDR Microsoft Defender for Endpoint

04Key Observations

✓  Strengths

Strengths

High-volume, fully automated SOC pipeline. The alert triage and response pipeline (Process Alert v9 → Utility - Overview Builder → Subflow 4 - Response) executed over 32,000 times in 12 months. This represents a substantial volume of alerts that were processed, enriched, and responded to without analyst involvement at the triage layer.

Identity threat response at scale. The three core identity response actions — password reset (1,135), session revocation (1,125), and MFA reset (1,122) — ran with near-identical frequency, indicating they are called together as an atomic containment action. Over 3,300 account-level containment actions were completed in 12 months.

Risk-gated password reset orchestration. A parent workflow now evaluates every "Nigeria+ logins" geolocation alert (976 executions in the reporting window), checks the user's last password-reset timestamp via Entra ID, and only triggers a fresh reset if one hasn't occurred in the past two days — avoiding redundant resets while still containing genuinely new suspicious logins automatically.

Bidirectional SOAR-ticketing integration. The CSS integration is one of the more sophisticated deployments, with nearly 10,000 comment sync events and a fully mapped bidirectional status lifecycle. This keeps incident visibility consistent across the security operations team and the broader business stakeholders who use CSS.

Phishing coverage is broad and deep. Three phishing-related playbooks collectively ran over 10,000 times (3,681 triage + 3,676 analysis + 2,999 case updates), and the email analyzer includes header inspection, URL reputation, attachment hash, sender domain WHOIS, and SPF/DKIM data — a comprehensive automated analysis chain.

Emerging agentic capability. The agent workspace with Joe Sandbox, ARIN, and URL screenshot abilities represents an early-stage but architecturally significant investment. The presence of a Builder Copilot that programmatically creates new Blink workflows signals intent to use AI to accelerate automation expansion.

###

△  Gaps & Growth Opportunities

Gaps

EDR containment playbooks have zero executions. The full SentinelOne response library (isolate, scan, block hash, cancel isolation) and the Malicious Click orchestrator show 0 executions over 12 months. This indicates these containment actions are not yet integrated into the automated pipeline — they likely remain as on-demand analyst tools rather than automated response paths.

Enrichment library underutilized in production. The IOC enrichment subflows (VirusTotal hash, IP, URL; URLScan; AbuseIPDB; CrowdStrike; Okta) collectively have near-zero executions, suggesting enrichment is occurring through a different mechanism (possibly inline within the main pipeline) or is not yet activated. Activating automated enrichment could significantly increase case context quality.

Several playbooks remain in TEST/development state. Multiple playbooks with "Test" in their name (Test GreyMatter Exposed Creds, Test Cases Closed Report for Jira, Test Populate/Send GreyMatter Reports) are running in production. Graduating these to production-named workflows would improve operational clarity and signal readiness for scaling.

No formal vulnerability management workflows. There are no playbooks covering vulnerability scan ingestion, CVE lookup, Vuln lifecycle ticketing, or patch management. For an organization of this scale, automating the vulnerability-to-ticket pipeline represents an untapped efficiency opportunity.

A parallel "SOC" workspace is duplicating production playbooks at low volume. A second workspace now hosts near-identical copies of CSS ticketing subflows, the Entra password-reset-and-notify subflow, and the Defender case enrichment workflow — all with 0-1 executions versus their established production counterparts. This looks like an in-progress migration or workspace consolidation; worth confirming with the team whether the original or the new workspace is the intended long-term home before both are maintained indefinitely.

ServiceNow IR ingestion (SNow - IR Case Ingestion) has zero executions. The ServiceNow integration for ingesting IR incidents was built but has not run, suggesting the ServiceNow-to-Blink incident pipeline is not yet in active use.

Integration Ecosystem

The following integrations are actively connected and used in production workflows:

  • Identity & Directory: Microsoft Entra ID (Active Directory), Okta
  • Email Security: Microsoft Outlook / Exchange Online, Mimecast
  • EDR / Endpoint: SentinelOne, Microsoft Intune
  • Cloud Security: Microsoft Defender for Cloud Apps, Microsoft Defender XDR, Microsoft Graph
  • Threat Intelligence: VirusTotal, URLScan, AbuseIPDB
  • Sandbox Analysis: Any.run, Joe Sandbox (agent ability, not in production)
  • Network Security: Zscaler ZIA
  • ITSM / Ticketing: ServiceNow, Jira (via email)
  • Digital Risk Protection: GreyMatter (HTTP API)
  • Productivity: Microsoft Excel, Google Docs
  • SOAR Platform: Blink Case Management (native)

The integration surface is deep in the Microsoft ecosystem (Entra, Defender, Intune, Outlook, Teams, Graph, Excel) reflecting a Microsoft-centric enterprise architecture. The presence of both CrowdStrike and SentinelOne enrichment/response playbooks suggests a possible EDR platform transition or dual-vendor deployment.

Appendices
A Case Management 30,376 cases (12m) | MTTR 9h 58m

Case Management

Total Cases (all-time)
33,065
30,376 opened in last 12m
Cases Opened (30d)
331
293 closed in last 30d
Cases Closed (12m)
30,328
of 30,376 opened
MTTR
9h 58m
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
SOC 32,978 30,372 30,327 9h 57m
CM V9 Migration Temp 80 0 0 N/A
SOC - Development 3 3 1 19d 21h
mason@blinkops.com 2 0 0 N/A
Ori Blink 1 0 0 N/A
susan.paskey@hubinternational.com 1 1 0 N/A
B AI Agents 3 active | 16 tasks (12m)

AI Agents

Active Agents
3
of 9 total
Tasks Executed (12m)
16
0 in last 30d
Data Usage (12m)
492,748
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 BlinkOps Ability Builder andrew.black@blinkops.com 12 0 315,467
2 HUB International - Brand Reporter Agent andrew.black@blinkops.com 3 0 134,830
3 Incident Investigator andrew.black@blinkops.com 1 0 42,451
4 Agent Blink Ori Blink 0 0 0
5 Agent Blink SOC - Development 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
andrew.black@blinkops.com16
Ori Blink0
SOC - Development0
SOC0
CM V9 Migration Temp0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
7
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Get Location PW Reset 00
2 MTTx 00
3 Ed Dash 00
4 Case Management 00
5 azam_test_dashboard 00

Webforms

Forms
6
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Malicious Click Form 00
2 Remediation Form 00
3 test 00
4 dddd 00
5 Manual Compromised User - Access Management 00
D Full Use Case Analysis 11 use cases | 60,786 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts processed & auto-triaged through the SOC pipeline 11,485 Process Alert v9
Case overviews auto-built with enriched IOC context 10,775 Utility - Overview Builder
Automated response actions executed on active cases 10,621 Subflow 4 - Response
Case comments synced bidirectionally with CSS ticketing 9,849 Send new case comment to CSS
Microsoft Defender for Cloud Apps alerts ingested into SOAR 6,666 Microsoft Defender for Cloud Apps Alert Ingestion
Intune device compliance alerts monitored & reported 3,855 Intune Enrolled Device Alerts
Phishing emails triaged end-to-end 3,681 Phishing Email Triage
Phishing emails analyzed (header, URL, attachment, sender domain) 3,676 Email Analyzer 2.0
Phishing case updates with analyst notifications 2,999 Case Updates
User passwords reset via automated identity response 1,135 HUB Secops - Reset Password Entra
CSS external tickets ingested and parsed into Blink 1,075 CSS_Event_Ingestion
Active user sessions revoked during incident response 1,125 HUB Secops - Revoke user active sessions
MFA credentials reset for compromised or suspicious accounts 1,122 HUB Secops - Reset MFA
Nigeria-origin logins investigated with sign-in log retrieval 1,086 Automated Subflow - Nigeria Get Sign in logs
Suspicious geolocation logins verified & password reset triggered 976 Parent - Unusual Geolocation - Password Reset
CSS ticket status changes processed and synced to Blink 415 Subflow - Process CSS Ticket Status Change
Microsoft Defender XDR incidents ingested 190 Microsoft Defender Incident Ingestion
CSS comments ingested and mapped to Blink cases 174 Subflow - Process New CSS Comment
Impossible travel events with sign-in log deep-dive 52 Automated Subflow - Impossible Travel Get Sign in logs
Impossible travel events verified against travel tracker 52 Automated Subflow - Impossible Travel Check Approval
Compromised user accounts fully remediated on demand 18 Remediate User On Demand
Digital risk protection (DRP) alerts polled from GreyMatter 32 Test GreyMatter Exposed Creds
Microsoft Defender incident case enrichments auto-generated 5 Defender Case Enrichments
In the last 12 months, Blink automated: - 11,485 security alerts processed and auto-triaged through the SOAR pipeline without manual intervention - 10,775 case overviews auto-built with full IOC enrichment context for analyst review - 10,621 automated response actions executed across active security cases - 9,849 case comments bidirectionally synchronized between Blink and the CSS external ticketing system - 6,666 Microsoft Defender for Cloud Apps alerts automatically ingested into the SOAR platform - 3,855 Intune device compliance alerts monitored and reported - 3,681 phishing emails triaged end-to-end with automated analysis and case creation - 3,676 email bodies analyzed for malicious headers, URLs, attachments, and sender domains - 2,999 phishing case status updates with analyst notifications pushed automatically - 1,135 user passwords reset via automated Entra identity response - 1,125 active user sessions revoked in response to confirmed incidents - 1,122 MFA credentials reset for suspicious or compromised accounts - 1,086 Nigeria-origin logins investigated with full sign-in log retrieval and context - 976 suspicious geolocation logins automatically verified and remediated via password reset workflow - 190 Microsoft Defender XDR incidents ingested into the case management platform - 52 impossible travel events fully investigated with sign-in history and travel tracker cross-check - 5 Microsoft Defender incident case enrichments auto-generated with structured HTML summaries

Use Case Summary

Use Case Category Playbooks Active Playbooks Total Executions
Agentic SOC — Automated Alert Triage & Response SOC 23 6 45,546
Phishing Detection & Response SOC 11 5 14,031
Identity Threat Response SOC 10 6 5,396
Case Mgmt & SOAR — CSS Ticketing Integration SOC 11 6 11,705
EDR Containment & Response SOC 7 0 0
Alert Enrichment / IOC Lookup SOC 9 1 7
Cloud Asset Coverage & Inventory Cloud Security 2 2 6,856
Threat Intel Ingest & Curation SOC 3 2 42
Security Metrics & Reporting GRC 4 2 46
Agentic SOC — AI Agent Capabilities SOC 6 0 0
Microsoft Defender XDR Ingestion SOC 5 4 197
Other / Infrastructure & Dev Other 11 2 11

Use Cases

1. Agentic SOC — Automated Alert Triage & Response

Description: End-to-end alert processing pipeline that ingests raw security alerts, extracts and deduplicates observables, creates or links Blink cases, enriches indicators, executes type-specific response logic (phishing, malware, impossible travel, Nigeria logins), and auto-builds a structured case overview for the analyst. This is the primary SOC automation backbone, running continuously.

Business problem: High-volume alert queues overwhelm SOC analysts with repetitive triage, enrichment, and initial response steps. This automation eliminates that manual burden by handling every incoming alert from ingestion through initial response without analyst involvement.

Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR, Alert enrichment / IOC lookup

Playbook Executions Link
Process Alert v9 11,485 Link
Utility - Overview Builder 10,775 Link
Subflow 4 - Response 10,621 Link
Automated Subflow - Nigeria Get Sign in logs 1,086 Link
Automated Subflow - Impossible Travel Get Sign in logs 52 Link
Automated Subflow - Impossible Travel Check Approval 52 Link
Subflow 1 - Extract Observables 0 Link
Subflow 2 - Create Case 0 Link
Subflow 2.1 - Get Deduplication Rule 0 Link
Subflow 2.2 - Check for Case Deduplicates 0 Link
Subflow 2.3 - Link Alert to Existing Case 0 Link
Subflow 3 - Enrich Observable 0 Link
Subflow - Malware 0 Link
Subflow - Missing Alert Template Notification 0 Link
Subflow - Update Enrichment Data 0 Link
Automated Subflow - Impossible Travel Manager Verification 0 Link
Automated Subflow - Nigeria Logins Manager Verification 0 Link
Automated Subflow - Add IP Info 5 Link
Utility - Find Similar Cases 0 Link
Utility - Close Stale Cases 0 Link
Utility - Auto Close Pending Cases 40 Link
Recovery - Enrich non-enriched observables 0 Link
Subflow - Update Enrichment Data 0 Link

Integrations: Blink Case Management, Microsoft Entra ID (sign-in logs), ServiceNow, Microsoft Excel (travel tracker)

2. Phishing Detection & Response

Description: Monitors a dedicated phishing submission mailbox, retrieves and parses full email content (EML), analyzes headers, URLs, attachments, and sender domain reputation, creates a case, and sends analyst notifications with enriched context. Supports both automated ingestion via Outlook polling and analyst-triggered workflows for manual phishing reports.

Business problem: Phishing reports from employees arrive continuously and require time-consuming manual analysis of email headers, link reputation, and attachment hashes. This automation converts every user submission into an analyzed, enriched, and triaged security case within minutes.

Category: SOC | Subcategories: Phishing detection & response, Alert enrichment / IOC lookup

Playbook Executions Link
Phishing Email Triage 3,681 Link
Email Analyzer 2.0 3,676 Link
Case Updates 2,999 Link
Subflow - Phishing 0 Link
Mimecast Search and Purge USE WITH CAUTION 0 Link
Mimecast Purge URL Messages 0 Link
Mimecast Threat Remediation Incidents 0 Link
Any.Run EML Upload 0 Link
HUB Secops - Mimecast External sender Block 0 Link
HUB - List Email inbox rules 0 Link
Search Email Subjects for all Users 0 Link

Integrations: Microsoft Outlook / Exchange Online, Mimecast, VirusTotal, URLScan, Any.run, AbuseIPDB, Blink Case Management

3. Identity Threat Response

Description: Automated containment workflow triggered when a user account is identified as compromised or suspicious. Resets the Entra ID password, revokes all active sessions, resets MFA credentials, gathers sign-in and audit logs, and notifies the user's manager. Supports both automated case-driven invocation and on-demand analyst-triggered execution.

Business problem: Responding to compromised account alerts requires coordinated actions across identity systems that are error-prone and slow when performed manually. This automation ensures consistent, rapid containment — password reset, session revocation, and MFA reset — within seconds of detection.

Category: SOC | Subcategories: Identity threat response, Alert enrichment / IOC lookup

Playbook Executions Link
HUB Secops - Reset Password Entra 1,135 Link
HUB Secops - Revoke user active sessions 1,125 Link
HUB Secops - Reset MFA 1,122 Link
Remediate User On Demand 18 Link
Adhoc Compromised User Workflow 0 Link
HUB PROD - Bulk Compromised user playbook 0 Link
Copy of Bulk Compromised user playbook 15 Link
Subflow - Entra Reset User PW on Next Login and Notify 0 Link
Subflow - Entra Reset User PW on Next Login and Notify (SOC) 0 Link
Parent - Unusual Geolocation - Password Reset (SOC) 976 Link

Integrations: Microsoft Entra ID (Active Directory), Microsoft Outlook / Exchange Online, Blink Case Management

4. Case Mgmt & SOAR — CSS Ticketing Integration

Description: Bidirectional integration between the Blink SOAR case management platform and an external CSS (Customer Support/Security) ticketing system. Ingests new CSS tickets as Blink alerts, maps status changes in both directions, syncs comments between platforms, and sends closure events back to CSS when Blink resolves a case. Maintains a tracking table of unprocessed case data.

Business problem: Security incidents managed in Blink must stay in sync with the enterprise ticketing system used by operations and management. Without automation, analysts manually copy updates between systems, creating lag and inconsistency. This integration eliminates dual-entry and ensures real-time bidirectional status and comment sync.

Category: SOC | Subcategories: Case mgmt & SOAR, Agentic SOC

Playbook Executions Link
Send new case comment to CSS 9,849 Link
CSS_Event_Ingestion 1,075 Link
Subflow - Process CSS Ticket Status Change 415 Link
Subflow - Process New CSS Comment 174 Link
Send Blink Closure Event to CSS 97 Link
Subflow - CSS Observable Linking 97 Link
Subflow - Process New CSS Ticket 98 Link
Subflow - CSS Observable Linking (SOC) 0 Link
Subflow - Process CSS Ticket Status Change (SOC) 0 Link
Subflow - Process New CSS Ticket (SOC) 0 Link
Subflow - Process New CSS Comment (SOC) 0 Link

Integrations: Blink Case Management, Custom webhook (CSS ticketing), Microsoft Exchange Online (email notifications)

5. EDR Containment & Response

Description: On-demand and case-driven EDR response actions against SentinelOne-managed endpoints. Covers the full containment cycle: initiate a scan, isolate an endpoint, block a file hash, cancel isolation, and search for endpoints associated with a compromised user account.

Business problem: EDR containment steps must be executed quickly and repeatably when a threat is confirmed on an endpoint. Manual execution via EDR console is slow and introduces human error. These playbooks allow the SOC to trigger endpoint isolation, scanning, and hash blocking from within the SOAR workflow.

Category: SOC | Subcategories: EDR containment & response

Playbook Executions Link
HUB PROD - Initiate Scan 0 Link
HUB PROD - Isolate Machine 0 Link
HUB PROD - Block Hash - SentinelOne 0 Link
HUB PROD - Cancel Isolation 0 Link
Search for and scan endpoints 0 Link
Hub SecOps - Malicious Click 0 Link
SecOps - Malicious Click 0 Link

Integrations: SentinelOne, Microsoft Entra ID, Mimecast, Zscaler ZIA

6. Alert Enrichment / IOC Lookup

Description: Library of enrichment subflows that look up individual observables (IP addresses, URLs, file hashes, usernames) against threat intelligence sources and write results back to the Blink case observable record. Designed to be called by the main alert processing pipeline or on demand by analysts.

Business problem: IOC context from threat intel platforms (VirusTotal, URLScan, AbuseIPDB) is essential for triage decisions but requires API integrations and data normalization. This enrichment library allows a single observable lookup to query multiple sources and return a normalized verdict automatically.

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation

Playbook Executions Link
Enrich - URL - VT 2 Link
Enrich - Hash - VT 0 Link
Enrich - IP - VT 0 Link
Enrich - IP - IPDB 0 Link
Enrich - URL - URLScan 0 Link
Enrich - Agent ID - Crowdstrike 0 Link
Enrich - Username or Email - Okta 0 Link
Hash Check - Virustottal 0 Link
Utility - Update all enrichments 0 Link

Integrations: VirusTotal, URLScan, AbuseIPDB, CrowdStrike, Okta

7. Cloud Asset Coverage & Inventory

Description: Continuous monitoring of cloud-connected assets. Polls Microsoft Intune every 15 minutes to surface enrolled devices that have compliance or hygiene issues, and ingests Microsoft Defender for Cloud Apps alerts on a 1-minute polling cycle to capture SaaS anomalies and policy violations.

Business problem: Cloud asset visibility gaps — unenrolled devices and SaaS policy violations — are among the top sources of undetected lateral movement risk. These playbooks provide continuous, automated coverage monitoring without requiring analyst polling of separate consoles.

Category: Cloud Security | Subcategories: Cloud asset coverage & inventory, Cloud access & SaaS policy mgmt

Playbook Executions Link
Intune Enrolled Device Alerts 3,855 Link
Microsoft Defender for Cloud Apps Alert Ingestion 6,666 Link

Integrations: Microsoft Intune, Microsoft Defender for Cloud Apps, Microsoft Graph API

8. Threat Intel Ingest & Curation — GreyMatter DRP

Description: Scheduled ingestion from GreyMatter's digital risk protection (DRP) platform. Polls daily for new exposed credentials alerts, weekly to populate a structured report with DRP findings (impersonating domains, exposed ports, expiring certificates), and weekly to distribute the formatted report to stakeholders.

Business problem: Digital risk alerts from DRP platforms require regular review to identify brand impersonation, credential leakage, and exposed infrastructure. Manual report compilation is time-consuming and irregular. These playbooks automate both the collection and distribution on a defined schedule.

Category: SOC | Subcategories: Threat intel ingest & curation, Security metrics & reporting

Playbook Executions Link
Test GreyMatter Exposed Creds 32 Link
Test Populate GreyMatter Reports 5 Link
Test Send Weekly GreyMatter Reports 5 Link

Integrations: GreyMatter DRP (HTTP API), Blink Tables, Email (SMTP)

9. Security Metrics & Reporting

Description: Scheduled reporting playbooks that calculate and distribute operational metrics. One workflow computes weekly meeting/collaboration time from Jira data, and another compiles and emails a daily report of closed case data from the tracking table.

Business problem: SOC managers need regular visibility into team workload, case throughput, and operational efficiency metrics without manually querying multiple systems. These scheduled reports deliver structured summaries directly to stakeholders.

Category: GRC | Subcategories: Security metrics & reporting

Playbook Executions Link
Test Cases Closed Report for Jira 40 Link
Gather Unprocessed Close Case Data 40 Link
Calculate Meeting Time for Jira 6 Link
Subflow - Gather Case Assignee Date/Time Add to table (SOC) 0 Link

Integrations: Blink Tables, Blink Case Management, Jira (via SMTP email), Email (SMTP)

10. Agentic SOC — AI Agent Capabilities

Description: An emerging agentic capability layer with purpose-built agent abilities for sandbox analysis (Joe Sandbox), URL screenshot capture, ASN/IP intelligence lookup, and HTML email composition. Includes an agent orchestrator workspace with a brand reporting agent and a builder copilot for generating new Blink workflows programmatically.

Business problem: Complex, multi-step SOC investigations require judgment-driven orchestration that goes beyond fixed playbooks. This agent capability layer enables autonomous investigation paths — dynamically selecting and calling enrichment tools, composing reports, and even generating new automation — reducing analyst dwell time on complex incidents.

Category: SOC | Subcategories: Agentic SOC, Alert enrichment / IOC lookup

Playbook Executions Link
Agent Ability: Joe Sandbox Triage 0 Link
Agent Ability: Get Screenshot of URL 0 Link
Agent Ability: Lookup ASN Information via ARIN 0 Link
Agent Ability: Send HTML Email 0 Link
Ability: Builder Copilot Create Workflows 0 Link
Agent Tests 0 Link

Integrations: Joe Sandbox, ARIN WHOIS, Blink Agent SDK, Blink API

11. Microsoft Defender XDR Ingestion

Description: Hourly scheduled ingestion of Microsoft Defender XDR incidents into the Blink case management platform, with a companion manual ingestion playbook for ad-hoc pulls and a subflow that updates Blink case metadata from XDR incident attributes.

Business problem: Microsoft Defender XDR generates incidents across endpoint, identity, and email that need to flow into the centralized SOAR platform for unified case management and response tracking.

Category: SOC | Subcategories: Case mgmt & SOAR, Alert enrichment / IOC lookup

Playbook Executions Link
Microsoft Defender Incident Ingestion 190 Link
Defender Ingestion 2 Link
Subflow - Defender XDR 0 Link
Defender Case Enrichments 4 Link
Defender Case Enrichments (SOC) 1 Link

Integrations: Microsoft Defender XDR, Blink Case Management

Key Observations

Strengths

High-volume, fully automated SOC pipeline. The alert triage and response pipeline (Process Alert v9 → Utility - Overview Builder → Subflow 4 - Response) executed over 32,000 times in 12 months. This represents a substantial volume of alerts that were processed, enriched, and responded to without analyst involvement at the triage layer.

Identity threat response at scale. The three core identity response actions — password reset (1,135), session revocation (1,125), and MFA reset (1,122) — ran with near-identical frequency, indicating they are called together as an atomic containment action. Over 3,300 account-level containment actions were completed in 12 months.

Risk-gated password reset orchestration. A parent workflow now evaluates every "Nigeria+ logins" geolocation alert (976 executions in the reporting window), checks the user's last password-reset timestamp via Entra ID, and only triggers a fresh reset if one hasn't occurred in the past two days — avoiding redundant resets while still containing genuinely new suspicious logins automatically.

Bidirectional SOAR-ticketing integration. The CSS integration is one of the more sophisticated deployments, with nearly 10,000 comment sync events and a fully mapped bidirectional status lifecycle. This keeps incident visibility consistent across the security operations team and the broader business stakeholders who use CSS.

Phishing coverage is broad and deep. Three phishing-related playbooks collectively ran over 10,000 times (3,681 triage + 3,676 analysis + 2,999 case updates), and the email analyzer includes header inspection, URL reputation, attachment hash, sender domain WHOIS, and SPF/DKIM data — a comprehensive automated analysis chain.

Emerging agentic capability. The agent workspace with Joe Sandbox, ARIN, and URL screenshot abilities represents an early-stage but architecturally significant investment. The presence of a Builder Copilot that programmatically creates new Blink workflows signals intent to use AI to accelerate automation expansion.

Gaps

EDR containment playbooks have zero executions. The full SentinelOne response library (isolate, scan, block hash, cancel isolation) and the Malicious Click orchestrator show 0 executions over 12 months. This indicates these containment actions are not yet integrated into the automated pipeline — they likely remain as on-demand analyst tools rather than automated response paths.

Enrichment library underutilized in production. The IOC enrichment subflows (VirusTotal hash, IP, URL; URLScan; AbuseIPDB; CrowdStrike; Okta) collectively have near-zero executions, suggesting enrichment is occurring through a different mechanism (possibly inline within the main pipeline) or is not yet activated. Activating automated enrichment could significantly increase case context quality.

Several playbooks remain in TEST/development state. Multiple playbooks with "Test" in their name (Test GreyMatter Exposed Creds, Test Cases Closed Report for Jira, Test Populate/Send GreyMatter Reports) are running in production. Graduating these to production-named workflows would improve operational clarity and signal readiness for scaling.

No formal vulnerability management workflows. There are no playbooks covering vulnerability scan ingestion, CVE lookup, Vuln lifecycle ticketing, or patch management. For an organization of this scale, automating the vulnerability-to-ticket pipeline represents an untapped efficiency opportunity.

A parallel "SOC" workspace is duplicating production playbooks at low volume. A second workspace now hosts near-identical copies of CSS ticketing subflows, the Entra password-reset-and-notify subflow, and the Defender case enrichment workflow — all with 0-1 executions versus their established production counterparts. This looks like an in-progress migration or workspace consolidation; worth confirming with the team whether the original or the new workspace is the intended long-term home before both are maintained indefinitely.

ServiceNow IR ingestion (SNow - IR Case Ingestion) has zero executions. The ServiceNow integration for ingesting IR incidents was built but has not run, suggesting the ServiceNow-to-Blink incident pipeline is not yet in active use.

Integration Ecosystem

The following integrations are actively connected and used in production workflows:

  • Identity & Directory: Microsoft Entra ID (Active Directory), Okta
  • Email Security: Microsoft Outlook / Exchange Online, Mimecast
  • EDR / Endpoint: SentinelOne, Microsoft Intune
  • Cloud Security: Microsoft Defender for Cloud Apps, Microsoft Defender XDR, Microsoft Graph
  • Threat Intelligence: VirusTotal, URLScan, AbuseIPDB
  • Sandbox Analysis: Any.run, Joe Sandbox (agent ability, not in production)
  • Network Security: Zscaler ZIA
  • ITSM / Ticketing: ServiceNow, Jira (via email)
  • Digital Risk Protection: GreyMatter (HTTP API)
  • Productivity: Microsoft Excel, Google Docs
  • SOAR Platform: Blink Case Management (native)

The integration surface is deep in the Microsoft ecosystem (Entra, Defender, Intune, Outlook, Teams, Graph, Excel) reflecting a Microsoft-centric enterprise architecture. The presence of both CrowdStrike and SentinelOne enrichment/response playbooks suggests a possible EDR platform transition or dual-vendor deployment.

E New Integrations (detail) 4 added in last 30d

New Integrations Added - Last 30 Days

4 new connections
TenantIntegrationConnection NameAdded
hub microsoft-outlook hubs_microsoft_outlook_connection_exchange_online 2026-08-26
hub azure-log-analytics hub_azure_log_analytics_connection 2026-08-26
hub azure hub_prod_azure 2026-08-26
hub active-directory hub_prod_entra 2026-08-26