Blink Security Automation — Confidential

itogether — Customer Success Report

Generated 2026-08-30 | itogether-value-report.md
2026-08-30Report Date
274Total Playbooks
38Unique Workflows (12m)
3,122Actions Automated (12m)
$803Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

274
Total playbooks built
all non-deleted workflows
143
Active playbooks
currently enabled
38
Unique workflows executed (12m)
distinct workflows that ran
3,122
Actions automated (12m)
completed action steps
17.3h
Hours saved (12m)
@ 20s per action
$803
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
5
Active AI agents
of 12 total
27
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 5 security alerts processed end-to-end through the automated SOC pipeline — observables extracted, cases created, enrichment dispatched, and response routed — without analyst involvement - 4 Microsoft Defender for Cloud Apps alerts automatically ingested and case-created - 3 Azure Monitor security events automatically routed into case management - 2 Wiz CSPM findings automatically triaged and case-created - 2 AWS CloudTrail security events automatically ingested and processed

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1: Agentic SOC — Alert Processing Pipeline70 executions
15.4%
5
5 active
Use Case 2: Multi-Source Alert Ingestion11 executions
2.4%
5
5 active
Use Case 3: Alert Enrichment Engine26 executions
5.7%
13
13 active
Use Case 4: Incident Response Automation0 executions
0.0%
2
2 active
Use Case 5: EDR Containment & Remote Response0 executions
0.0%
3
3 active
Use Case 6: Analyst Investigation Toolkit0 executions
0.0%
13
13 active
Use Case 7: Case Management Platform Utilities0 executions
0.0%
12
12 active
Total107 executions100%
53
53 active

Use Case Growth Over Time

206 unique playbooks  |  7 operational use cases  |  456 total executions (12m)  |  1970-01 to 2026-07
Toggle:
Toggle:

03Integration Ecosystem

Use Case 2: Multi-Source Alert Ingestion
CrowdStrike
Use Case 4: Incident Response Automation
Microsoft Outlook
Use Case 3: Alert Enrichment Engine
CrowdStrike Okta AbuseIPDB VirusTotal URLScan Slack
Use Case 6: Analyst Investigation Toolkit
Google Workspace Microsoft Entra ID GitHub URLScan Okta CrowdStrike Slack VirusTotal
Use Case 7: Case Management Platform Utilities
Email
Use Case 5: EDR Containment & Remote Response
CrowdStrike

04Key Observations

✓  Strengths

Strengths

Production-grade Agentic SOC architecture. The deployment follows a well-designed, layered SOAR pattern: multi-source ingestion → automated case creation with deduplication → observable enrichment fan-out → conditional response routing. The architecture separates concerns cleanly — each layer is independently maintainable and the enrichment router decouples source-specific ingest from IOC-specific enrichment logic. Recovery playbooks and structured error notification add operational resilience.

Broad and deep integration ecosystem. 12+ distinct security tool integrations are wired up and configured, including CrowdStrike (EDR, threat intel, RTR), the full Microsoft stack (Entra ID, Defender for Cloud Apps, Azure Monitor, Outlook), VirusTotal + AbuseIPDB + URLScan (threat intel), Okta + Google Workspace + GitHub (identity), and Wiz + AWS CloudTrail (cloud security). This is a strong foundation — the connections already exist and are tested.

Complete observable type coverage. The enrichment engine covers all major IOC categories — IP addresses (two sources), domains, URLs (two sources), file hashes (two sources), usernames/emails (three identity providers + Slack), and CrowdStrike endpoint agent IDs. Cross-source enrichment on the same observable type enables automated verdict confidence scoring.

Phishing simulation awareness. The phishing response subflow specifically handles KnowBe4 simulation emails by checking for X-PHISHTEST headers before triggering containment — a mature, false-positive-aware response pattern.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Platform is in early-activation phase. With 25 total executions across 12 months (16 from ingest playbooks, 9 from the core pipeline), the platform is running at POC-level volume. The architecture is production-ready — the primary gap is volume, not capability. Enabling all configured ingestion sources at production polling rates would immediately surface the full value of the enrichment and response automation.

Enrichment pipeline not yet exercised. Despite 13 enrichment subflows being fully built and connected, 0 enrichment runs have occurred. Since Process Alert did fire 5 times and called the enrichment router (8 executions), this suggests observable extraction may have yielded no enrichable IOCs in the test data, or enrichment dispatch is gated by a condition not yet met at scale. This is the highest-leverage gap to investigate.

CrowdStrike ingestion inactive. CrowdStrike is the most deeply integrated tool in the ecosystem (alert ingest, hash enrichment, agent enrichment, RTR, quarantine) but both CrowdStrike ingest playbooks show 0 executions. Activating webhook-based CrowdStrike ingest is likely the single highest-value enablement action — it would feed the pipeline with high-fidelity EDR telemetry and immediately exercise the enrichment and response automation.

Response automation not yet triggered. Both response subflows (phishing, malware) and all EDR containment playbooks show 0 executions. The routing infrastructure exists and the response router fired once — getting live phishing or malware alerts flowing through the pipeline would begin demonstrating automated MTTR reduction.

No IAM, GRC, or Cloud Security use cases beyond ingest. The deployment is entirely SOC-focused. Given that Okta, Microsoft Entra ID, and Google Workspace are already connected with active credentials, employee lifecycle automation (onboarding/offboarding/access review) is a natural adjacent expansion. Wiz and AWS CloudTrail connections similarly open the door to automated cloud posture remediation workflows.

Integration Ecosystem Summary

Integration Used In
CrowdStrike Falcon Alert ingest (×2), hash enrichment, agent ID enrichment, endpoint quarantine, RTR (single + batch), hash investigation
Microsoft Entra ID Username/email enrichment, user investigation (with risky user lookup), Defender for Cloud Apps ingest
Azure Monitor Alert ingest
Okta Username/email enrichment, user investigation, activity log search
VirusTotal IP enrichment, URL enrichment, hash enrichment, hash investigation
Wiz CSPM alert ingest
AWS CloudTrail Security event ingest
AbuseIPDB IP enrichment
URLScan URL enrichment, URL investigation
Google Workspace Username/email enrichment, user investigation
GitHub Username enrichment, user investigation
Slack Email-to-user enrichment
Microsoft Outlook Phishing email header inspection
Blink Case Management Alert, case, observable, attachment, and task APIs (core platform)
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents 5 active | 27 tasks (12m)

AI Agents

Active Agents
5
of 12 total
Tasks Executed (12m)
27
0 in last 30d
Data Usage (12m)
1,920,114
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink - Decision Maker Demo 1: AI SOC 16 0 1,152,265
2 SOC Agent - EDR Agent Demo 1: AI SOC 4 0 285,793
3 Micro Agent - Historical Case Check Demo 1: AI SOC 3 0 93,046
4 SOC Agent - Core Investigator Agent Demo 1: AI SOC 2 0 221,897
5 SOC Agent - Phishing Agent Demo 1: AI SOC 2 0 167,113
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Demo 1: AI SOC27
Case Management V90
C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 7 use cases | 456 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts processed end-to-end through automated SOC pipeline 5 Process Alert
Microsoft Defender for Cloud Apps alerts auto-ingested & case-created 4 EXAMPLE Ingest - Microsoft Defender For Cloud Apps
Azure Monitor security events auto-ingested & case-created 3 EXAMPLE Ingest - Azure
Wiz CSPM findings auto-ingested & case-created 2 EXAMPLE Ingest - Wiz
AWS CloudTrail security events auto-ingested & case-created 2 EXAMPLE Ingest - AWS CloudTrail
In the last 12 months, Blink automated: - 5 security alerts processed end-to-end through the automated SOC pipeline — observables extracted, cases created, enrichment dispatched, and response routed — without analyst involvement - 4 Microsoft Defender for Cloud Apps alerts automatically ingested and case-created - 3 Azure Monitor security events automatically routed into case management - 2 Wiz CSPM findings automatically triaged and case-created - 2 AWS CloudTrail security events automatically ingested and processed

Use Case Summary

# Use Case Category Playbooks Executions (12 mo)
1 Agentic SOC — Alert Processing Pipeline SOC 5 14
2 Multi-Source Alert Ingestion SOC 6 11
3 Alert Enrichment Engine SOC 13 0
4 Incident Response Automation SOC 2 0
5 EDR Containment & Remote Response SOC 3 0
6 Analyst Investigation Toolkit SOC 13 0
7 Case Management Platform Utilities SOC 12 0
— Draft / Development — 5 0
Total 59 25

Use Cases

Use Case 1: Agentic SOC — Alert Processing Pipeline

Description: The central automated SOC orchestration engine. When a new alert lands in the case management system, this pipeline automatically extracts observables, creates or merges into an existing case (deduplication), fans out enrichment jobs for all new observables, waits for enrichment to complete, and routes to the appropriate response subflow — without analyst involvement. Recovery playbooks handle backfill for any alerts or observables that slipped through during outages.

Business Problem Solved: Eliminates manual alert triage, observable extraction, case creation, and initial enrichment — compressing the alert-to-response timeline and removing analyst toil from all routine processing.

Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR

Playbook Executions (12 mo)
Process Alert 5
Subflow - Enrich Observables - Main Router 8
Subflow - Response - Main Router 1
Recovery - Handle Unprocessed Alerts 0
Recovery - Enrich Non-Enriched Observables 0

Key Integrations: Blink Case Management (alert, case, observable APIs), CrowdStrike, VirusTotal, AbuseIPDB, Okta, Microsoft Entra ID, Slack

Use Case 2: Multi-Source Alert Ingestion

Description: Event-driven ingestion playbooks — one per security source — that continuously poll or receive webhooks from security tools and automatically create standardized alerts in the case management system. Four of the six sources are actively running; CrowdStrike direct and LogScale ingestion are configured but not yet firing.

Business Problem Solved: Normalizes heterogeneous security telemetry from multiple platforms into a single case management view, eliminating manual aggregation and enabling consistent automated handling regardless of alert origin.

Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR, CSPM ingest & triage

Playbook Source Trigger Type Executions (12 mo)
EXAMPLE Ingest - Microsoft Defender For Cloud Apps Microsoft Defender for Cloud Apps Polling 4
EXAMPLE Ingest - Azure Azure Monitor Polling 3
EXAMPLE Ingest - Wiz Wiz Polling 2
EXAMPLE Ingest - AWS CloudTrail AWS CloudTrail Polling 2
EXAMPLE Ingest - CrowdStrike CrowdStrike Webhook 0
EXAMPLE Ingest - CrowdStrike Falcon LogScale CrowdStrike Falcon LogScale Webhook 0

Key Integrations: Wiz, Microsoft Defender for Cloud Apps, CrowdStrike, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail

Use Case 3: Alert Enrichment Engine

Description: A fleet of specialized enrichment subflows — one per observable type and data source — automatically dispatched by the enrichment router during alert processing. Each subflow enriches a specific IOC type (IP, URL, hash, username, or endpoint agent ID) using the relevant data source and writes structured results back to the observable record in case management.

Business Problem Solved: Provides instant, consistent threat context on every IOC without analyst research time. Enables the automated pipeline to make informed triage and response decisions based on enriched intel at machine speed.

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation

Playbook Observable Type Source Executions (12 mo)
Enrich - IP - VT IP VirusTotal 0
Enrich - IP - IPDB IP AbuseIPDB 0
Enrich - IP or Domain - Whois IP / Domain Whois 0
Enrich - URL - VT URL VirusTotal 0
Enrich - URL - URLScan URL URLScan 0
Enrich - Hash - VT File Hash VirusTotal 0
Enrich - Hash - Crowdstrike File Hash CrowdStrike 0
Enrich - Username or Email - Okta Username / Email Okta 0
Enrich - Username or Email - Google Workspace Username / Email Google Workspace 0
Enrich - Username or Email - Microsoft Entra ID Username / Email Microsoft Entra ID 0
Enrich - Username - Github Username GitHub 0
Enrich - Agent ID - Crowdstrike Endpoint Agent ID CrowdStrike 0
Enrich - Email Address - Slack Email Address Slack 0

Key Integrations: VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack

Use Case 4: Incident Response Automation

Description: Automated response subflows triggered after case enrichment completes. The phishing subflow validates whether a flagged email is a real attack (vs. a KnowBe4 simulation) by inspecting Microsoft Outlook headers, then applies appropriate containment. The malware subflow checks whether CrowdStrike fully or partially remediated the threat and applies conditional follow-up actions.

Business Problem Solved: Converts enriched alert context into an immediate, consistent response action — without waiting for analyst availability — reducing dwell time on confirmed threats and eliminating false-positive response on training simulations.

Category: SOC | Subcategories: Phishing detection & response, EDR containment & response, Case mgmt & SOAR

Playbook Response Type Executions (12 mo)
Response Subflow - Phishing Phishing email investigation & KnowBe4 filter 0
Response Subflow - Malware Malware remediation status check & conditional action 0

Key Integrations: Microsoft Outlook, Blink Case Management

Use Case 5: EDR Containment & Remote Response

Description: On-demand and pipeline-callable playbooks for endpoint containment (isolate / lift isolation) and remote command execution on CrowdStrike-managed endpoints. Supports both targeted single-host operations and bulk batch commands across a host group.

Business Problem Solved: Enables immediate endpoint containment during active incidents and remote forensic or remediation commands without requiring direct system access — compressing response time and limiting lateral movement risk.

Category: SOC | Subcategories: EDR containment & response

Playbook Action Executions (12 mo)
Manage Endpoint Quarantine Status in Crowdstrike Isolate / Lift Isolation 0
CrowdStrike RTR to a Single Host Remote command execution (single host) 0
CrowdStrike RTR to a Batch of Hosts Remote command execution (batch) 0

Key Integrations: CrowdStrike Falcon (RTR, Host Actions)

Use Case 6: Analyst Investigation Toolkit

Description: A library of on-demand investigative playbooks enabling analysts to quickly retrieve user identity data, file reputation, network intelligence, and endpoint state from a unified interface during active investigations. These tools use the same integration connections as the automated enrichment engine and can be called manually from the case management UI or Blink portal.

Business Problem Solved: Consolidates investigative lookups across 8+ data sources into standardized, reusable tools — reducing context-switching and eliminating inconsistent manual query patterns across the analyst team.

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation, Identity threat response

Playbook Data Type Source Executions (12 mo)
Get User Information Using Okta User identity & status Okta 0
Get User Information Using Microsoft Entra ID User identity, risk score & risky user list Microsoft Entra ID 0
Get User Information Using Google Workspace User identity Google Workspace 0
Get User Information Using Github User identity GitHub 0
Get User Information on Email Address Using Slack User-to-email mapping Slack 0
Okta Search for User Activity User activity logs (date-ranged) Okta 0
Get Hash Info Using VirusTotal File reputation VirusTotal 0
Get Hash Info Using Crowdstrike File reputation + endpoint presence CrowdStrike 0
Enrich IP or Domain Using Whois IP / domain registration data Whois 0
Analyze URL with URLScan URL reputation + visual scan URLScan 0
Secure URL Screenshot Capture URL visual inspection (safe headless capture) Internal sandbox 0
Run Dig Command DNS resolution System 0
Get End of Life Date for a Product Software EOL status endoflife.date API 0

Key Integrations: Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, VirusTotal, CrowdStrike, URLScan, Whois, DNS

Use Case 7: Case Management Platform Utilities

Description: Supporting utilities and subflows that maintain the integrity and operational health of the case management data model. Covers observable relationship lifecycle (create, update, delete, list), case hygiene (stale case closure, similar-case detection), alert template validation, and operator error notification.

Business Problem Solved: Keeps the SOAR platform data model clean and self-maintaining — automatically closing dead cases, surfacing related incidents for analyst correlation, and ensuring the team is notified when the automation encounters gaps or failures.

Category: SOC | Subcategories: Case mgmt & SOAR

Playbook Purpose Executions (12 mo)
Subflow - Update Enrichment Data Write enrichment results back to observable record 0
Utility - Update Enrichment Alias wrapper for enrichment update subflow 0
Utility - Close Stale Cases Auto-close open cases with no activity for 30+ days 0
Utility - Set Or Update Observable Relation Create or update observable-to-alert relationship 0
Utility - Delete Observable Relation Remove an observable-alert link 0
Utility - List Observable Alert Relations Enumerate all alerts linked to an observable 0
Utility - List Alert Observable Relations Enumerate all observables in an alert 0
Utility - Find Similar Cases Based on Observables Surface related cases by shared observable overlap 0
Table Action - Validate Observables Extraction Template Test observable extraction configs against real alerts 0
Subflow - Missing Alert Template Notification Notify when an inbound alert has no extraction template 0
Error Handling - Send Error Notification Email Email operators on automation failures 0
USE WITH CARE - Reset Case Management Environment Wipe all case management data (dev/testing only) 0

Key Integrations: Blink Case Management, Email (core)

Key Observations

Strengths

Production-grade Agentic SOC architecture. The deployment follows a well-designed, layered SOAR pattern: multi-source ingestion → automated case creation with deduplication → observable enrichment fan-out → conditional response routing. The architecture separates concerns cleanly — each layer is independently maintainable and the enrichment router decouples source-specific ingest from IOC-specific enrichment logic. Recovery playbooks and structured error notification add operational resilience.

Broad and deep integration ecosystem. 12+ distinct security tool integrations are wired up and configured, including CrowdStrike (EDR, threat intel, RTR), the full Microsoft stack (Entra ID, Defender for Cloud Apps, Azure Monitor, Outlook), VirusTotal + AbuseIPDB + URLScan (threat intel), Okta + Google Workspace + GitHub (identity), and Wiz + AWS CloudTrail (cloud security). This is a strong foundation — the connections already exist and are tested.

Complete observable type coverage. The enrichment engine covers all major IOC categories — IP addresses (two sources), domains, URLs (two sources), file hashes (two sources), usernames/emails (three identity providers + Slack), and CrowdStrike endpoint agent IDs. Cross-source enrichment on the same observable type enables automated verdict confidence scoring.

Phishing simulation awareness. The phishing response subflow specifically handles KnowBe4 simulation emails by checking for X-PHISHTEST headers before triggering containment — a mature, false-positive-aware response pattern.

Gaps & Opportunities

Platform is in early-activation phase. With 25 total executions across 12 months (16 from ingest playbooks, 9 from the core pipeline), the platform is running at POC-level volume. The architecture is production-ready — the primary gap is volume, not capability. Enabling all configured ingestion sources at production polling rates would immediately surface the full value of the enrichment and response automation.

Enrichment pipeline not yet exercised. Despite 13 enrichment subflows being fully built and connected, 0 enrichment runs have occurred. Since Process Alert did fire 5 times and called the enrichment router (8 executions), this suggests observable extraction may have yielded no enrichable IOCs in the test data, or enrichment dispatch is gated by a condition not yet met at scale. This is the highest-leverage gap to investigate.

CrowdStrike ingestion inactive. CrowdStrike is the most deeply integrated tool in the ecosystem (alert ingest, hash enrichment, agent enrichment, RTR, quarantine) but both CrowdStrike ingest playbooks show 0 executions. Activating webhook-based CrowdStrike ingest is likely the single highest-value enablement action — it would feed the pipeline with high-fidelity EDR telemetry and immediately exercise the enrichment and response automation.

Response automation not yet triggered. Both response subflows (phishing, malware) and all EDR containment playbooks show 0 executions. The routing infrastructure exists and the response router fired once — getting live phishing or malware alerts flowing through the pipeline would begin demonstrating automated MTTR reduction.

No IAM, GRC, or Cloud Security use cases beyond ingest. The deployment is entirely SOC-focused. Given that Okta, Microsoft Entra ID, and Google Workspace are already connected with active credentials, employee lifecycle automation (onboarding/offboarding/access review) is a natural adjacent expansion. Wiz and AWS CloudTrail connections similarly open the door to automated cloud posture remediation workflows.

Integration Ecosystem Summary

Integration Used In
CrowdStrike Falcon Alert ingest (×2), hash enrichment, agent ID enrichment, endpoint quarantine, RTR (single + batch), hash investigation
Microsoft Entra ID Username/email enrichment, user investigation (with risky user lookup), Defender for Cloud Apps ingest
Azure Monitor Alert ingest
Okta Username/email enrichment, user investigation, activity log search
VirusTotal IP enrichment, URL enrichment, hash enrichment, hash investigation
Wiz CSPM alert ingest
AWS CloudTrail Security event ingest
AbuseIPDB IP enrichment
URLScan URL enrichment, URL investigation
Google Workspace Username/email enrichment, user investigation
GitHub Username enrichment, user investigation
Slack Email-to-user enrichment
Microsoft Outlook Phishing email header inspection
Blink Case Management Alert, case, observable, attachment, and task APIs (core platform)

1. Business KPIs — Last 12 Months

Metric Count Playbook
Security alerts processed end-to-end through automated SOC pipeline 5 Process Alert
Microsoft Defender for Cloud Apps alerts auto-ingested & case-created 4 EXAMPLE Ingest - Microsoft Defender For Cloud Apps
Azure Monitor security events auto-ingested & case-created 3 EXAMPLE Ingest - Azure
Wiz CSPM findings auto-ingested & case-created 2 EXAMPLE Ingest - Wiz
AWS CloudTrail security events auto-ingested & case-created 2 EXAMPLE Ingest - AWS CloudTrail
In the last 12 months, Blink automated: - 5 security alerts processed end-to-end through the automated SOC pipeline — observables extracted, cases created, enrichment dispatched, and response routed — without analyst involvement - 4 Microsoft Defender for Cloud Apps alerts automatically ingested and case-created - 3 Azure Monitor security events automatically routed into case management - 2 Wiz CSPM findings automatically triaged and case-created - 2 AWS CloudTrail security events automatically ingested and processed

2. Use Case Summary

# Use Case Category Playbooks Executions (12 mo)
1 Agentic SOC — Alert Processing Pipeline SOC 5 14
2 Multi-Source Alert Ingestion SOC 6 11
3 Alert Enrichment Engine SOC 13 0
4 Incident Response Automation SOC 2 0
5 EDR Containment & Remote Response SOC 3 0
6 Analyst Investigation Toolkit SOC 13 0
7 Case Management Platform Utilities SOC 12 0
— Draft / Development — 5 0
Total 59 25

3. Use Cases

Use Case 1: Agentic SOC — Alert Processing Pipeline

Description: The central automated SOC orchestration engine. When a new alert lands in the case management system, this pipeline automatically extracts observables, creates or merges into an existing case (deduplication), fans out enrichment jobs for all new observables, waits for enrichment to complete, and routes to the appropriate response subflow — without analyst involvement. Recovery playbooks handle backfill for any alerts or observables that slipped through during outages.

Business Problem Solved: Eliminates manual alert triage, observable extraction, case creation, and initial enrichment — compressing the alert-to-response timeline and removing analyst toil from all routine processing.

Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR

Playbook Executions (12 mo)
Process Alert 5
Subflow - Enrich Observables - Main Router 8
Subflow - Response - Main Router 1
Recovery - Handle Unprocessed Alerts 0
Recovery - Enrich Non-Enriched Observables 0

Key Integrations: Blink Case Management (alert, case, observable APIs), CrowdStrike, VirusTotal, AbuseIPDB, Okta, Microsoft Entra ID, Slack

Use Case 2: Multi-Source Alert Ingestion

Description: Event-driven ingestion playbooks — one per security source — that continuously poll or receive webhooks from security tools and automatically create standardized alerts in the case management system. Four of the six sources are actively running; CrowdStrike direct and LogScale ingestion are configured but not yet firing.

Business Problem Solved: Normalizes heterogeneous security telemetry from multiple platforms into a single case management view, eliminating manual aggregation and enabling consistent automated handling regardless of alert origin.

Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR, CSPM ingest & triage

Playbook Source Trigger Type Executions (12 mo)
EXAMPLE Ingest - Microsoft Defender For Cloud Apps Microsoft Defender for Cloud Apps Polling 4
EXAMPLE Ingest - Azure Azure Monitor Polling 3
EXAMPLE Ingest - Wiz Wiz Polling 2
EXAMPLE Ingest - AWS CloudTrail AWS CloudTrail Polling 2
EXAMPLE Ingest - CrowdStrike CrowdStrike Webhook 0
EXAMPLE Ingest - CrowdStrike Falcon LogScale CrowdStrike Falcon LogScale Webhook 0

Key Integrations: Wiz, Microsoft Defender for Cloud Apps, CrowdStrike, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail

Use Case 3: Alert Enrichment Engine

Description: A fleet of specialized enrichment subflows — one per observable type and data source — automatically dispatched by the enrichment router during alert processing. Each subflow enriches a specific IOC type (IP, URL, hash, username, or endpoint agent ID) using the relevant data source and writes structured results back to the observable record in case management.

Business Problem Solved: Provides instant, consistent threat context on every IOC without analyst research time. Enables the automated pipeline to make informed triage and response decisions based on enriched intel at machine speed.

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation

Playbook Observable Type Source Executions (12 mo)
Enrich - IP - VT IP VirusTotal 0
Enrich - IP - IPDB IP AbuseIPDB 0
Enrich - IP or Domain - Whois IP / Domain Whois 0
Enrich - URL - VT URL VirusTotal 0
Enrich - URL - URLScan URL URLScan 0
Enrich - Hash - VT File Hash VirusTotal 0
Enrich - Hash - Crowdstrike File Hash CrowdStrike 0
Enrich - Username or Email - Okta Username / Email Okta 0
Enrich - Username or Email - Google Workspace Username / Email Google Workspace 0
Enrich - Username or Email - Microsoft Entra ID Username / Email Microsoft Entra ID 0
Enrich - Username - Github Username GitHub 0
Enrich - Agent ID - Crowdstrike Endpoint Agent ID CrowdStrike 0
Enrich - Email Address - Slack Email Address Slack 0

Key Integrations: VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack

Use Case 4: Incident Response Automation

Description: Automated response subflows triggered after case enrichment completes. The phishing subflow validates whether a flagged email is a real attack (vs. a KnowBe4 simulation) by inspecting Microsoft Outlook headers, then applies appropriate containment. The malware subflow checks whether CrowdStrike fully or partially remediated the threat and applies conditional follow-up actions.

Business Problem Solved: Converts enriched alert context into an immediate, consistent response action — without waiting for analyst availability — reducing dwell time on confirmed threats and eliminating false-positive response on training simulations.

Category: SOC | Subcategories: Phishing detection & response, EDR containment & response, Case mgmt & SOAR

Playbook Response Type Executions (12 mo)
Response Subflow - Phishing Phishing email investigation & KnowBe4 filter 0
Response Subflow - Malware Malware remediation status check & conditional action 0

Key Integrations: Microsoft Outlook, Blink Case Management

Use Case 5: EDR Containment & Remote Response

Description: On-demand and pipeline-callable playbooks for endpoint containment (isolate / lift isolation) and remote command execution on CrowdStrike-managed endpoints. Supports both targeted single-host operations and bulk batch commands across a host group.

Business Problem Solved: Enables immediate endpoint containment during active incidents and remote forensic or remediation commands without requiring direct system access — compressing response time and limiting lateral movement risk.

Category: SOC | Subcategories: EDR containment & response

Playbook Action Executions (12 mo)
Manage Endpoint Quarantine Status in Crowdstrike Isolate / Lift Isolation 0
CrowdStrike RTR to a Single Host Remote command execution (single host) 0
CrowdStrike RTR to a Batch of Hosts Remote command execution (batch) 0

Key Integrations: CrowdStrike Falcon (RTR, Host Actions)

Use Case 6: Analyst Investigation Toolkit

Description: A library of on-demand investigative playbooks enabling analysts to quickly retrieve user identity data, file reputation, network intelligence, and endpoint state from a unified interface during active investigations. These tools use the same integration connections as the automated enrichment engine and can be called manually from the case management UI or Blink portal.

Business Problem Solved: Consolidates investigative lookups across 8+ data sources into standardized, reusable tools — reducing context-switching and eliminating inconsistent manual query patterns across the analyst team.

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation, Identity threat response

Playbook Data Type Source Executions (12 mo)
Get User Information Using Okta User identity & status Okta 0
Get User Information Using Microsoft Entra ID User identity, risk score & risky user list Microsoft Entra ID 0
Get User Information Using Google Workspace User identity Google Workspace 0
Get User Information Using Github User identity GitHub 0
Get User Information on Email Address Using Slack User-to-email mapping Slack 0
Okta Search for User Activity User activity logs (date-ranged) Okta 0
Get Hash Info Using VirusTotal File reputation VirusTotal 0
Get Hash Info Using Crowdstrike File reputation + endpoint presence CrowdStrike 0
Enrich IP or Domain Using Whois IP / domain registration data Whois 0
Analyze URL with URLScan URL reputation + visual scan URLScan 0
Secure URL Screenshot Capture URL visual inspection (safe headless capture) Internal sandbox 0
Run Dig Command DNS resolution System 0
Get End of Life Date for a Product Software EOL status endoflife.date API 0

Key Integrations: Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, VirusTotal, CrowdStrike, URLScan, Whois, DNS

Use Case 7: Case Management Platform Utilities

Description: Supporting utilities and subflows that maintain the integrity and operational health of the case management data model. Covers observable relationship lifecycle (create, update, delete, list), case hygiene (stale case closure, similar-case detection), alert template validation, and operator error notification.

Business Problem Solved: Keeps the SOAR platform data model clean and self-maintaining — automatically closing dead cases, surfacing related incidents for analyst correlation, and ensuring the team is notified when the automation encounters gaps or failures.

Category: SOC | Subcategories: Case mgmt & SOAR

Playbook Purpose Executions (12 mo)
Subflow - Update Enrichment Data Write enrichment results back to observable record 0
Utility - Update Enrichment Alias wrapper for enrichment update subflow 0
Utility - Close Stale Cases Auto-close open cases with no activity for 30+ days 0
Utility - Set Or Update Observable Relation Create or update observable-to-alert relationship 0
Utility - Delete Observable Relation Remove an observable-alert link 0
Utility - List Observable Alert Relations Enumerate all alerts linked to an observable 0
Utility - List Alert Observable Relations Enumerate all observables in an alert 0
Utility - Find Similar Cases Based on Observables Surface related cases by shared observable overlap 0
Table Action - Validate Observables Extraction Template Test observable extraction configs against real alerts 0
Subflow - Missing Alert Template Notification Notify when an inbound alert has no extraction template 0
Error Handling - Send Error Notification Email Email operators on automation failures 0
USE WITH CARE - Reset Case Management Environment Wipe all case management data (dev/testing only) 0

Key Integrations: Blink Case Management, Email (core)

4. Key Observations

Strengths

Production-grade Agentic SOC architecture. The deployment follows a well-designed, layered SOAR pattern: multi-source ingestion → automated case creation with deduplication → observable enrichment fan-out → conditional response routing. The architecture separates concerns cleanly — each layer is independently maintainable and the enrichment router decouples source-specific ingest from IOC-specific enrichment logic. Recovery playbooks and structured error notification add operational resilience.

Broad and deep integration ecosystem. 12+ distinct security tool integrations are wired up and configured, including CrowdStrike (EDR, threat intel, RTR), the full Microsoft stack (Entra ID, Defender for Cloud Apps, Azure Monitor, Outlook), VirusTotal + AbuseIPDB + URLScan (threat intel), Okta + Google Workspace + GitHub (identity), and Wiz + AWS CloudTrail (cloud security). This is a strong foundation — the connections already exist and are tested.

Complete observable type coverage. The enrichment engine covers all major IOC categories — IP addresses (two sources), domains, URLs (two sources), file hashes (two sources), usernames/emails (three identity providers + Slack), and CrowdStrike endpoint agent IDs. Cross-source enrichment on the same observable type enables automated verdict confidence scoring.

Phishing simulation awareness. The phishing response subflow specifically handles KnowBe4 simulation emails by checking for X-PHISHTEST headers before triggering containment — a mature, false-positive-aware response pattern.

Gaps & Opportunities

Platform is in early-activation phase. With 25 total executions across 12 months (16 from ingest playbooks, 9 from the core pipeline), the platform is running at POC-level volume. The architecture is production-ready — the primary gap is volume, not capability. Enabling all configured ingestion sources at production polling rates would immediately surface the full value of the enrichment and response automation.

Enrichment pipeline not yet exercised. Despite 13 enrichment subflows being fully built and connected, 0 enrichment runs have occurred. Since Process Alert did fire 5 times and called the enrichment router (8 executions), this suggests observable extraction may have yielded no enrichable IOCs in the test data, or enrichment dispatch is gated by a condition not yet met at scale. This is the highest-leverage gap to investigate.

CrowdStrike ingestion inactive. CrowdStrike is the most deeply integrated tool in the ecosystem (alert ingest, hash enrichment, agent enrichment, RTR, quarantine) but both CrowdStrike ingest playbooks show 0 executions. Activating webhook-based CrowdStrike ingest is likely the single highest-value enablement action — it would feed the pipeline with high-fidelity EDR telemetry and immediately exercise the enrichment and response automation.

Response automation not yet triggered. Both response subflows (phishing, malware) and all EDR containment playbooks show 0 executions. The routing infrastructure exists and the response router fired once — getting live phishing or malware alerts flowing through the pipeline would begin demonstrating automated MTTR reduction.

No IAM, GRC, or Cloud Security use cases beyond ingest. The deployment is entirely SOC-focused. Given that Okta, Microsoft Entra ID, and Google Workspace are already connected with active credentials, employee lifecycle automation (onboarding/offboarding/access review) is a natural adjacent expansion. Wiz and AWS CloudTrail connections similarly open the door to automated cloud posture remediation workflows.

Integration Ecosystem Summary

Integration Used In
CrowdStrike Falcon Alert ingest (×2), hash enrichment, agent ID enrichment, endpoint quarantine, RTR (single + batch), hash investigation
Microsoft Entra ID Username/email enrichment, user investigation (with risky user lookup), Defender for Cloud Apps ingest
Azure Monitor Alert ingest
Okta Username/email enrichment, user investigation, activity log search
VirusTotal IP enrichment, URL enrichment, hash enrichment, hash investigation
Wiz CSPM alert ingest
AWS CloudTrail Security event ingest
AbuseIPDB IP enrichment
URLScan URL enrichment, URL investigation
Google Workspace Username/email enrichment, user investigation
GitHub Username enrichment, user investigation
Slack Email-to-user enrichment
Microsoft Outlook Phishing email header inspection
Blink Case Management Alert, case, observable, attachment, and task APIs (core platform)
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.