01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC — Automated Alert Triage & Response |
| 50.6% | 22 22 active |
| Phishing Detection & Response |
| 0.0% | 10 8 active |
| Identity Threat Response |
| 3.0% | 8 8 active |
| Case Mgmt & SOAR — CSS Ticketing Integration |
| 13.2% | 11 11 active |
| EDR Containment & Response | 0 executions | 0.0% | 2 2 active |
| Alert Enrichment / IOC Lookup | 0 executions | 0.0% | 9 9 active |
| Cloud Asset Coverage & Inventory |
| 22.3% | 2 2 active |
| Threat Intel Ingest & Curation — GreyMatter DRP |
| 0.0% | 3 1 active |
| Security Metrics & Reporting | 85 executions | 0.1% | 4 4 active |
| Agentic SOC — AI Agent Capabilities | 0 executions | 0.0% | 6 6 active |
| Microsoft Defender XDR Ingestion |
| 1.6% | 5 5 active |
| Total | 55,287 executions | 100% | 82 78 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
High-volume, fully automated SOC pipeline. The alert triage and response pipeline (Process Alert v9 → Utility - Overview Builder → Subflow 4 - Response) executed over 32,000 times in 12 months. This represents a substantial volume of alerts that were processed, enriched, and responded to without analyst involvement at the triage layer.
Identity threat response at scale. The three core identity response actions — password reset (1,135), session revocation (1,125), and MFA reset (1,122) — ran with near-identical frequency, indicating they are called together as an atomic containment action. Over 3,300 account-level containment actions were completed in 12 months.
Risk-gated password reset orchestration. A parent workflow now evaluates every "Nigeria+ logins" geolocation alert (976 executions in the reporting window), checks the user's last password-reset timestamp via Entra ID, and only triggers a fresh reset if one hasn't occurred in the past two days — avoiding redundant resets while still containing genuinely new suspicious logins automatically.
Bidirectional SOAR-ticketing integration. The CSS integration is one of the more sophisticated deployments, with nearly 10,000 comment sync events and a fully mapped bidirectional status lifecycle. This keeps incident visibility consistent across the security operations team and the broader business stakeholders who use CSS.
Phishing coverage is broad and deep. Three phishing-related playbooks collectively ran over 10,000 times (3,681 triage + 3,676 analysis + 2,999 case updates), and the email analyzer includes header inspection, URL reputation, attachment hash, sender domain WHOIS, and SPF/DKIM data — a comprehensive automated analysis chain.
Emerging agentic capability. The agent workspace with Joe Sandbox, ARIN, and URL screenshot abilities represents an early-stage but architecturally significant investment. The presence of a Builder Copilot that programmatically creates new Blink workflows signals intent to use AI to accelerate automation expansion.
###
Gaps
EDR containment playbooks have zero executions. The full SentinelOne response library (isolate, scan, block hash, cancel isolation) and the Malicious Click orchestrator show 0 executions over 12 months. This indicates these containment actions are not yet integrated into the automated pipeline — they likely remain as on-demand analyst tools rather than automated response paths.
Enrichment library underutilized in production. The IOC enrichment subflows (VirusTotal hash, IP, URL; URLScan; AbuseIPDB; CrowdStrike; Okta) collectively have near-zero executions, suggesting enrichment is occurring through a different mechanism (possibly inline within the main pipeline) or is not yet activated. Activating automated enrichment could significantly increase case context quality.
Several playbooks remain in TEST/development state. Multiple playbooks with "Test" in their name (Test GreyMatter Exposed Creds, Test Cases Closed Report for Jira, Test Populate/Send GreyMatter Reports) are running in production. Graduating these to production-named workflows would improve operational clarity and signal readiness for scaling.
No formal vulnerability management workflows. There are no playbooks covering vulnerability scan ingestion, CVE lookup, Vuln lifecycle ticketing, or patch management. For an organization of this scale, automating the vulnerability-to-ticket pipeline represents an untapped efficiency opportunity.
A parallel "SOC" workspace is duplicating production playbooks at low volume. A second workspace now hosts near-identical copies of CSS ticketing subflows, the Entra password-reset-and-notify subflow, and the Defender case enrichment workflow — all with 0-1 executions versus their established production counterparts. This looks like an in-progress migration or workspace consolidation; worth confirming with the team whether the original or the new workspace is the intended long-term home before both are maintained indefinitely.
ServiceNow IR ingestion (SNow - IR Case Ingestion) has zero executions. The ServiceNow integration for ingesting IR incidents was built but has not run, suggesting the ServiceNow-to-Blink incident pipeline is not yet in active use.
Integration Ecosystem
The following integrations are actively connected and used in production workflows:
- Identity & Directory: Microsoft Entra ID (Active Directory), Okta
- Email Security: Microsoft Outlook / Exchange Online, Mimecast
- EDR / Endpoint: SentinelOne, Microsoft Intune
- Cloud Security: Microsoft Defender for Cloud Apps, Microsoft Defender XDR, Microsoft Graph
- Threat Intelligence: VirusTotal, URLScan, AbuseIPDB
- Sandbox Analysis: Any.run, Joe Sandbox (agent ability, not in production)
- Network Security: Zscaler ZIA
- ITSM / Ticketing: ServiceNow, Jira (via email)
- Digital Risk Protection: GreyMatter (HTTP API)
- Productivity: Microsoft Excel, Google Docs
- SOAR Platform: Blink Case Management (native)
The integration surface is deep in the Microsoft ecosystem (Entra, Defender, Intune, Outlook, Teams, Graph, Excel) reflecting a Microsoft-centric enterprise architecture. The presence of both CrowdStrike and SentinelOne enrichment/response playbooks suggests a possible EDR platform transition or dual-vendor deployment.
A Case Management 30,376 cases (12m) | MTTR 9h 58m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| SOC | 32,978 | 30,372 | 30,327 | 9h 57m |
| CM V9 Migration Temp | 80 | 0 | 0 | N/A |
| SOC - Development | 3 | 3 | 1 | 19d 21h |
| mason@blinkops.com | 2 | 0 | 0 | N/A |
| Ori Blink | 1 | 0 | 0 | N/A |
| susan.paskey@hubinternational.com | 1 | 1 | 0 | N/A |
B AI Agents 3 active | 16 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | BlinkOps Ability Builder | andrew.black@blinkops.com | 12 | 0 | 315,467 |
| 2 | HUB International - Brand Reporter Agent | andrew.black@blinkops.com | 3 | 0 | 134,830 |
| 3 | Incident Investigator | andrew.black@blinkops.com | 1 | 0 | 42,451 |
| 4 | Agent Blink | Ori Blink | 0 | 0 | 0 |
| 5 | Agent Blink | SOC - Development | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| andrew.black@blinkops.com | 16 |
| Ori Blink | 0 |
| SOC - Development | 0 |
| SOC | 0 |
| CM V9 Migration Temp | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Get Location PW Reset | 0 | 0 |
| 2 | MTTx | 0 | 0 |
| 3 | Ed Dash | 0 | 0 |
| 4 | Case Management | 0 | 0 |
| 5 | azam_test_dashboard | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Malicious Click Form | 0 | 0 |
| 2 | Remediation Form | 0 | 0 |
| 3 | test | 0 | 0 |
| 4 | dddd | 0 | 0 |
| 5 | Manual Compromised User - Access Management | 0 | 0 |
D Full Use Case Analysis 11 use cases | 60,786 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts processed & auto-triaged through the SOC pipeline | 11,485 | Process Alert v9 |
| Case overviews auto-built with enriched IOC context | 10,775 | Utility - Overview Builder |
| Automated response actions executed on active cases | 10,621 | Subflow 4 - Response |
| Case comments synced bidirectionally with CSS ticketing | 9,849 | Send new case comment to CSS |
| Microsoft Defender for Cloud Apps alerts ingested into SOAR | 6,666 | Microsoft Defender for Cloud Apps Alert Ingestion |
| Intune device compliance alerts monitored & reported | 3,855 | Intune Enrolled Device Alerts |
| Phishing emails triaged end-to-end | 3,681 | Phishing Email Triage |
| Phishing emails analyzed (header, URL, attachment, sender domain) | 3,676 | Email Analyzer 2.0 |
| Phishing case updates with analyst notifications | 2,999 | Case Updates |
| User passwords reset via automated identity response | 1,135 | HUB Secops - Reset Password Entra |
| CSS external tickets ingested and parsed into Blink | 1,075 | CSS_Event_Ingestion |
| Active user sessions revoked during incident response | 1,125 | HUB Secops - Revoke user active sessions |
| MFA credentials reset for compromised or suspicious accounts | 1,122 | HUB Secops - Reset MFA |
| Nigeria-origin logins investigated with sign-in log retrieval | 1,086 | Automated Subflow - Nigeria Get Sign in logs |
| Suspicious geolocation logins verified & password reset triggered | 976 | Parent - Unusual Geolocation - Password Reset |
| CSS ticket status changes processed and synced to Blink | 415 | Subflow - Process CSS Ticket Status Change |
| Microsoft Defender XDR incidents ingested | 190 | Microsoft Defender Incident Ingestion |
| CSS comments ingested and mapped to Blink cases | 174 | Subflow - Process New CSS Comment |
| Impossible travel events with sign-in log deep-dive | 52 | Automated Subflow - Impossible Travel Get Sign in logs |
| Impossible travel events verified against travel tracker | 52 | Automated Subflow - Impossible Travel Check Approval |
| Compromised user accounts fully remediated on demand | 18 | Remediate User On Demand |
| Digital risk protection (DRP) alerts polled from GreyMatter | 32 | Test GreyMatter Exposed Creds |
| Microsoft Defender incident case enrichments auto-generated | 5 | Defender Case Enrichments |
Use Case Summary
| Use Case | Category | Playbooks | Active Playbooks | Total Executions |
|---|---|---|---|---|
| Agentic SOC — Automated Alert Triage & Response | SOC | 23 | 6 | 45,546 |
| Phishing Detection & Response | SOC | 11 | 5 | 14,031 |
| Identity Threat Response | SOC | 10 | 6 | 5,396 |
| Case Mgmt & SOAR — CSS Ticketing Integration | SOC | 11 | 6 | 11,705 |
| EDR Containment & Response | SOC | 7 | 0 | 0 |
| Alert Enrichment / IOC Lookup | SOC | 9 | 1 | 7 |
| Cloud Asset Coverage & Inventory | Cloud Security | 2 | 2 | 6,856 |
| Threat Intel Ingest & Curation | SOC | 3 | 2 | 42 |
| Security Metrics & Reporting | GRC | 4 | 2 | 46 |
| Agentic SOC — AI Agent Capabilities | SOC | 6 | 0 | 0 |
| Microsoft Defender XDR Ingestion | SOC | 5 | 4 | 197 |
| Other / Infrastructure & Dev | Other | 11 | 2 | 11 |
Use Cases
1. Agentic SOC — Automated Alert Triage & Response
Description: End-to-end alert processing pipeline that ingests raw security alerts, extracts and deduplicates observables, creates or links Blink cases, enriches indicators, executes type-specific response logic (phishing, malware, impossible travel, Nigeria logins), and auto-builds a structured case overview for the analyst. This is the primary SOC automation backbone, running continuously.
Business problem: High-volume alert queues overwhelm SOC analysts with repetitive triage, enrichment, and initial response steps. This automation eliminates that manual burden by handling every incoming alert from ingestion through initial response without analyst involvement.
Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR, Alert enrichment / IOC lookup
| Playbook | Executions | Link |
|---|---|---|
| Process Alert v9 | 11,485 | Link |
| Utility - Overview Builder | 10,775 | Link |
| Subflow 4 - Response | 10,621 | Link |
| Automated Subflow - Nigeria Get Sign in logs | 1,086 | Link |
| Automated Subflow - Impossible Travel Get Sign in logs | 52 | Link |
| Automated Subflow - Impossible Travel Check Approval | 52 | Link |
| Subflow 1 - Extract Observables | 0 | Link |
| Subflow 2 - Create Case | 0 | Link |
| Subflow 2.1 - Get Deduplication Rule | 0 | Link |
| Subflow 2.2 - Check for Case Deduplicates | 0 | Link |
| Subflow 2.3 - Link Alert to Existing Case | 0 | Link |
| Subflow 3 - Enrich Observable | 0 | Link |
| Subflow - Malware | 0 | Link |
| Subflow - Missing Alert Template Notification | 0 | Link |
| Subflow - Update Enrichment Data | 0 | Link |
| Automated Subflow - Impossible Travel Manager Verification | 0 | Link |
| Automated Subflow - Nigeria Logins Manager Verification | 0 | Link |
| Automated Subflow - Add IP Info | 5 | Link |
| Utility - Find Similar Cases | 0 | Link |
| Utility - Close Stale Cases | 0 | Link |
| Utility - Auto Close Pending Cases | 40 | Link |
| Recovery - Enrich non-enriched observables | 0 | Link |
| Subflow - Update Enrichment Data | 0 | Link |
Integrations: Blink Case Management, Microsoft Entra ID (sign-in logs), ServiceNow, Microsoft Excel (travel tracker)
2. Phishing Detection & Response
Description: Monitors a dedicated phishing submission mailbox, retrieves and parses full email content (EML), analyzes headers, URLs, attachments, and sender domain reputation, creates a case, and sends analyst notifications with enriched context. Supports both automated ingestion via Outlook polling and analyst-triggered workflows for manual phishing reports.
Business problem: Phishing reports from employees arrive continuously and require time-consuming manual analysis of email headers, link reputation, and attachment hashes. This automation converts every user submission into an analyzed, enriched, and triaged security case within minutes.
Category: SOC | Subcategories: Phishing detection & response, Alert enrichment / IOC lookup
| Playbook | Executions | Link |
|---|---|---|
| Phishing Email Triage | 3,681 | Link |
| Email Analyzer 2.0 | 3,676 | Link |
| Case Updates | 2,999 | Link |
| Subflow - Phishing | 0 | Link |
| Mimecast Search and Purge USE WITH CAUTION | 0 | Link |
| Mimecast Purge URL Messages | 0 | Link |
| Mimecast Threat Remediation Incidents | 0 | Link |
| Any.Run EML Upload | 0 | Link |
| HUB Secops - Mimecast External sender Block | 0 | Link |
| HUB - List Email inbox rules | 0 | Link |
| Search Email Subjects for all Users | 0 | Link |
Integrations: Microsoft Outlook / Exchange Online, Mimecast, VirusTotal, URLScan, Any.run, AbuseIPDB, Blink Case Management
3. Identity Threat Response
Description: Automated containment workflow triggered when a user account is identified as compromised or suspicious. Resets the Entra ID password, revokes all active sessions, resets MFA credentials, gathers sign-in and audit logs, and notifies the user's manager. Supports both automated case-driven invocation and on-demand analyst-triggered execution.
Business problem: Responding to compromised account alerts requires coordinated actions across identity systems that are error-prone and slow when performed manually. This automation ensures consistent, rapid containment — password reset, session revocation, and MFA reset — within seconds of detection.
Category: SOC | Subcategories: Identity threat response, Alert enrichment / IOC lookup
| Playbook | Executions | Link |
|---|---|---|
| HUB Secops - Reset Password Entra | 1,135 | Link |
| HUB Secops - Revoke user active sessions | 1,125 | Link |
| HUB Secops - Reset MFA | 1,122 | Link |
| Remediate User On Demand | 18 | Link |
| Adhoc Compromised User Workflow | 0 | Link |
| HUB PROD - Bulk Compromised user playbook | 0 | Link |
| Copy of Bulk Compromised user playbook | 15 | Link |
| Subflow - Entra Reset User PW on Next Login and Notify | 0 | Link |
| Subflow - Entra Reset User PW on Next Login and Notify (SOC) | 0 | Link |
| Parent - Unusual Geolocation - Password Reset (SOC) | 976 | Link |
Integrations: Microsoft Entra ID (Active Directory), Microsoft Outlook / Exchange Online, Blink Case Management
4. Case Mgmt & SOAR — CSS Ticketing Integration
Description: Bidirectional integration between the Blink SOAR case management platform and an external CSS (Customer Support/Security) ticketing system. Ingests new CSS tickets as Blink alerts, maps status changes in both directions, syncs comments between platforms, and sends closure events back to CSS when Blink resolves a case. Maintains a tracking table of unprocessed case data.
Business problem: Security incidents managed in Blink must stay in sync with the enterprise ticketing system used by operations and management. Without automation, analysts manually copy updates between systems, creating lag and inconsistency. This integration eliminates dual-entry and ensures real-time bidirectional status and comment sync.
Category: SOC | Subcategories: Case mgmt & SOAR, Agentic SOC
| Playbook | Executions | Link |
|---|---|---|
| Send new case comment to CSS | 9,849 | Link |
| CSS_Event_Ingestion | 1,075 | Link |
| Subflow - Process CSS Ticket Status Change | 415 | Link |
| Subflow - Process New CSS Comment | 174 | Link |
| Send Blink Closure Event to CSS | 97 | Link |
| Subflow - CSS Observable Linking | 97 | Link |
| Subflow - Process New CSS Ticket | 98 | Link |
| Subflow - CSS Observable Linking (SOC) | 0 | Link |
| Subflow - Process CSS Ticket Status Change (SOC) | 0 | Link |
| Subflow - Process New CSS Ticket (SOC) | 0 | Link |
| Subflow - Process New CSS Comment (SOC) | 0 | Link |
Integrations: Blink Case Management, Custom webhook (CSS ticketing), Microsoft Exchange Online (email notifications)
5. EDR Containment & Response
Description: On-demand and case-driven EDR response actions against SentinelOne-managed endpoints. Covers the full containment cycle: initiate a scan, isolate an endpoint, block a file hash, cancel isolation, and search for endpoints associated with a compromised user account.
Business problem: EDR containment steps must be executed quickly and repeatably when a threat is confirmed on an endpoint. Manual execution via EDR console is slow and introduces human error. These playbooks allow the SOC to trigger endpoint isolation, scanning, and hash blocking from within the SOAR workflow.
Category: SOC | Subcategories: EDR containment & response
| Playbook | Executions | Link |
|---|---|---|
| HUB PROD - Initiate Scan | 0 | Link |
| HUB PROD - Isolate Machine | 0 | Link |
| HUB PROD - Block Hash - SentinelOne | 0 | Link |
| HUB PROD - Cancel Isolation | 0 | Link |
| Search for and scan endpoints | 0 | Link |
| Hub SecOps - Malicious Click | 0 | Link |
| SecOps - Malicious Click | 0 | Link |
Integrations: SentinelOne, Microsoft Entra ID, Mimecast, Zscaler ZIA
6. Alert Enrichment / IOC Lookup
Description: Library of enrichment subflows that look up individual observables (IP addresses, URLs, file hashes, usernames) against threat intelligence sources and write results back to the Blink case observable record. Designed to be called by the main alert processing pipeline or on demand by analysts.
Business problem: IOC context from threat intel platforms (VirusTotal, URLScan, AbuseIPDB) is essential for triage decisions but requires API integrations and data normalization. This enrichment library allows a single observable lookup to query multiple sources and return a normalized verdict automatically.
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation
| Playbook | Executions | Link |
|---|---|---|
| Enrich - URL - VT | 2 | Link |
| Enrich - Hash - VT | 0 | Link |
| Enrich - IP - VT | 0 | Link |
| Enrich - IP - IPDB | 0 | Link |
| Enrich - URL - URLScan | 0 | Link |
| Enrich - Agent ID - Crowdstrike | 0 | Link |
| Enrich - Username or Email - Okta | 0 | Link |
| Hash Check - Virustottal | 0 | Link |
| Utility - Update all enrichments | 0 | Link |
Integrations: VirusTotal, URLScan, AbuseIPDB, CrowdStrike, Okta
7. Cloud Asset Coverage & Inventory
Description: Continuous monitoring of cloud-connected assets. Polls Microsoft Intune every 15 minutes to surface enrolled devices that have compliance or hygiene issues, and ingests Microsoft Defender for Cloud Apps alerts on a 1-minute polling cycle to capture SaaS anomalies and policy violations.
Business problem: Cloud asset visibility gaps — unenrolled devices and SaaS policy violations — are among the top sources of undetected lateral movement risk. These playbooks provide continuous, automated coverage monitoring without requiring analyst polling of separate consoles.
Category: Cloud Security | Subcategories: Cloud asset coverage & inventory, Cloud access & SaaS policy mgmt
| Playbook | Executions | Link |
|---|---|---|
| Intune Enrolled Device Alerts | 3,855 | Link |
| Microsoft Defender for Cloud Apps Alert Ingestion | 6,666 | Link |
Integrations: Microsoft Intune, Microsoft Defender for Cloud Apps, Microsoft Graph API
8. Threat Intel Ingest & Curation — GreyMatter DRP
Description: Scheduled ingestion from GreyMatter's digital risk protection (DRP) platform. Polls daily for new exposed credentials alerts, weekly to populate a structured report with DRP findings (impersonating domains, exposed ports, expiring certificates), and weekly to distribute the formatted report to stakeholders.
Business problem: Digital risk alerts from DRP platforms require regular review to identify brand impersonation, credential leakage, and exposed infrastructure. Manual report compilation is time-consuming and irregular. These playbooks automate both the collection and distribution on a defined schedule.
Category: SOC | Subcategories: Threat intel ingest & curation, Security metrics & reporting
| Playbook | Executions | Link |
|---|---|---|
| Test GreyMatter Exposed Creds | 32 | Link |
| Test Populate GreyMatter Reports | 5 | Link |
| Test Send Weekly GreyMatter Reports | 5 | Link |
Integrations: GreyMatter DRP (HTTP API), Blink Tables, Email (SMTP)
9. Security Metrics & Reporting
Description: Scheduled reporting playbooks that calculate and distribute operational metrics. One workflow computes weekly meeting/collaboration time from Jira data, and another compiles and emails a daily report of closed case data from the tracking table.
Business problem: SOC managers need regular visibility into team workload, case throughput, and operational efficiency metrics without manually querying multiple systems. These scheduled reports deliver structured summaries directly to stakeholders.
Category: GRC | Subcategories: Security metrics & reporting
| Playbook | Executions | Link |
|---|---|---|
| Test Cases Closed Report for Jira | 40 | Link |
| Gather Unprocessed Close Case Data | 40 | Link |
| Calculate Meeting Time for Jira | 6 | Link |
| Subflow - Gather Case Assignee Date/Time Add to table (SOC) | 0 | Link |
Integrations: Blink Tables, Blink Case Management, Jira (via SMTP email), Email (SMTP)
10. Agentic SOC — AI Agent Capabilities
Description: An emerging agentic capability layer with purpose-built agent abilities for sandbox analysis (Joe Sandbox), URL screenshot capture, ASN/IP intelligence lookup, and HTML email composition. Includes an agent orchestrator workspace with a brand reporting agent and a builder copilot for generating new Blink workflows programmatically.
Business problem: Complex, multi-step SOC investigations require judgment-driven orchestration that goes beyond fixed playbooks. This agent capability layer enables autonomous investigation paths — dynamically selecting and calling enrichment tools, composing reports, and even generating new automation — reducing analyst dwell time on complex incidents.
Category: SOC | Subcategories: Agentic SOC, Alert enrichment / IOC lookup
| Playbook | Executions | Link |
|---|---|---|
| Agent Ability: Joe Sandbox Triage | 0 | Link |
| Agent Ability: Get Screenshot of URL | 0 | Link |
| Agent Ability: Lookup ASN Information via ARIN | 0 | Link |
| Agent Ability: Send HTML Email | 0 | Link |
| Ability: Builder Copilot Create Workflows | 0 | Link |
| Agent Tests | 0 | Link |
Integrations: Joe Sandbox, ARIN WHOIS, Blink Agent SDK, Blink API
11. Microsoft Defender XDR Ingestion
Description: Hourly scheduled ingestion of Microsoft Defender XDR incidents into the Blink case management platform, with a companion manual ingestion playbook for ad-hoc pulls and a subflow that updates Blink case metadata from XDR incident attributes.
Business problem: Microsoft Defender XDR generates incidents across endpoint, identity, and email that need to flow into the centralized SOAR platform for unified case management and response tracking.
Category: SOC | Subcategories: Case mgmt & SOAR, Alert enrichment / IOC lookup
| Playbook | Executions | Link |
|---|---|---|
| Microsoft Defender Incident Ingestion | 190 | Link |
| Defender Ingestion | 2 | Link |
| Subflow - Defender XDR | 0 | Link |
| Defender Case Enrichments | 4 | Link |
| Defender Case Enrichments (SOC) | 1 | Link |
Integrations: Microsoft Defender XDR, Blink Case Management
Key Observations
Strengths
High-volume, fully automated SOC pipeline. The alert triage and response pipeline (Process Alert v9 → Utility - Overview Builder → Subflow 4 - Response) executed over 32,000 times in 12 months. This represents a substantial volume of alerts that were processed, enriched, and responded to without analyst involvement at the triage layer.
Identity threat response at scale. The three core identity response actions — password reset (1,135), session revocation (1,125), and MFA reset (1,122) — ran with near-identical frequency, indicating they are called together as an atomic containment action. Over 3,300 account-level containment actions were completed in 12 months.
Risk-gated password reset orchestration. A parent workflow now evaluates every "Nigeria+ logins" geolocation alert (976 executions in the reporting window), checks the user's last password-reset timestamp via Entra ID, and only triggers a fresh reset if one hasn't occurred in the past two days — avoiding redundant resets while still containing genuinely new suspicious logins automatically.
Bidirectional SOAR-ticketing integration. The CSS integration is one of the more sophisticated deployments, with nearly 10,000 comment sync events and a fully mapped bidirectional status lifecycle. This keeps incident visibility consistent across the security operations team and the broader business stakeholders who use CSS.
Phishing coverage is broad and deep. Three phishing-related playbooks collectively ran over 10,000 times (3,681 triage + 3,676 analysis + 2,999 case updates), and the email analyzer includes header inspection, URL reputation, attachment hash, sender domain WHOIS, and SPF/DKIM data — a comprehensive automated analysis chain.
Emerging agentic capability. The agent workspace with Joe Sandbox, ARIN, and URL screenshot abilities represents an early-stage but architecturally significant investment. The presence of a Builder Copilot that programmatically creates new Blink workflows signals intent to use AI to accelerate automation expansion.
Gaps
EDR containment playbooks have zero executions. The full SentinelOne response library (isolate, scan, block hash, cancel isolation) and the Malicious Click orchestrator show 0 executions over 12 months. This indicates these containment actions are not yet integrated into the automated pipeline — they likely remain as on-demand analyst tools rather than automated response paths.
Enrichment library underutilized in production. The IOC enrichment subflows (VirusTotal hash, IP, URL; URLScan; AbuseIPDB; CrowdStrike; Okta) collectively have near-zero executions, suggesting enrichment is occurring through a different mechanism (possibly inline within the main pipeline) or is not yet activated. Activating automated enrichment could significantly increase case context quality.
Several playbooks remain in TEST/development state. Multiple playbooks with "Test" in their name (Test GreyMatter Exposed Creds, Test Cases Closed Report for Jira, Test Populate/Send GreyMatter Reports) are running in production. Graduating these to production-named workflows would improve operational clarity and signal readiness for scaling.
No formal vulnerability management workflows. There are no playbooks covering vulnerability scan ingestion, CVE lookup, Vuln lifecycle ticketing, or patch management. For an organization of this scale, automating the vulnerability-to-ticket pipeline represents an untapped efficiency opportunity.
A parallel "SOC" workspace is duplicating production playbooks at low volume. A second workspace now hosts near-identical copies of CSS ticketing subflows, the Entra password-reset-and-notify subflow, and the Defender case enrichment workflow — all with 0-1 executions versus their established production counterparts. This looks like an in-progress migration or workspace consolidation; worth confirming with the team whether the original or the new workspace is the intended long-term home before both are maintained indefinitely.
ServiceNow IR ingestion (SNow - IR Case Ingestion) has zero executions. The ServiceNow integration for ingesting IR incidents was built but has not run, suggesting the ServiceNow-to-Blink incident pipeline is not yet in active use.
Integration Ecosystem
The following integrations are actively connected and used in production workflows:
- Identity & Directory: Microsoft Entra ID (Active Directory), Okta
- Email Security: Microsoft Outlook / Exchange Online, Mimecast
- EDR / Endpoint: SentinelOne, Microsoft Intune
- Cloud Security: Microsoft Defender for Cloud Apps, Microsoft Defender XDR, Microsoft Graph
- Threat Intelligence: VirusTotal, URLScan, AbuseIPDB
- Sandbox Analysis: Any.run, Joe Sandbox (agent ability, not in production)
- Network Security: Zscaler ZIA
- ITSM / Ticketing: ServiceNow, Jira (via email)
- Digital Risk Protection: GreyMatter (HTTP API)
- Productivity: Microsoft Excel, Google Docs
- SOAR Platform: Blink Case Management (native)
The integration surface is deep in the Microsoft ecosystem (Entra, Defender, Intune, Outlook, Teams, Graph, Excel) reflecting a Microsoft-centric enterprise architecture. The presence of both CrowdStrike and SentinelOne enrichment/response playbooks suggests a possible EDR platform transition or dual-vendor deployment.
E New Integrations (detail) 4 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| hub | microsoft-outlook | hubs_microsoft_outlook_connection_exchange_online | 2026-08-26 |
| hub | azure-log-analytics | hub_azure_log_analytics_connection | 2026-08-26 |
| hub | azure | hub_prod_azure | 2026-08-26 |
| hub | active-directory | hub_prod_entra | 2026-08-26 |