01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1: Agentic SOC — Alert Processing Pipeline | 70 executions | 15.4% | 5 5 active |
| Use Case 2: Multi-Source Alert Ingestion | 11 executions | 2.4% | 5 5 active |
| Use Case 3: Alert Enrichment Engine | 26 executions | 5.7% | 13 13 active |
| Use Case 4: Incident Response Automation | 0 executions | 0.0% | 2 2 active |
| Use Case 5: EDR Containment & Remote Response | 0 executions | 0.0% | 3 3 active |
| Use Case 6: Analyst Investigation Toolkit | 0 executions | 0.0% | 13 13 active |
| Use Case 7: Case Management Platform Utilities | 0 executions | 0.0% | 12 12 active |
| Total | 107 executions | 100% | 53 53 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Production-grade Agentic SOC architecture. The deployment follows a well-designed, layered SOAR pattern: multi-source ingestion → automated case creation with deduplication → observable enrichment fan-out → conditional response routing. The architecture separates concerns cleanly — each layer is independently maintainable and the enrichment router decouples source-specific ingest from IOC-specific enrichment logic. Recovery playbooks and structured error notification add operational resilience.
Broad and deep integration ecosystem. 12+ distinct security tool integrations are wired up and configured, including CrowdStrike (EDR, threat intel, RTR), the full Microsoft stack (Entra ID, Defender for Cloud Apps, Azure Monitor, Outlook), VirusTotal + AbuseIPDB + URLScan (threat intel), Okta + Google Workspace + GitHub (identity), and Wiz + AWS CloudTrail (cloud security). This is a strong foundation — the connections already exist and are tested.
Complete observable type coverage. The enrichment engine covers all major IOC categories — IP addresses (two sources), domains, URLs (two sources), file hashes (two sources), usernames/emails (three identity providers + Slack), and CrowdStrike endpoint agent IDs. Cross-source enrichment on the same observable type enables automated verdict confidence scoring.
Phishing simulation awareness. The phishing response subflow specifically handles KnowBe4 simulation emails by checking for X-PHISHTEST headers before triggering containment — a mature, false-positive-aware response pattern.
###
Gaps & Opportunities
Platform is in early-activation phase. With 25 total executions across 12 months (16 from ingest playbooks, 9 from the core pipeline), the platform is running at POC-level volume. The architecture is production-ready — the primary gap is volume, not capability. Enabling all configured ingestion sources at production polling rates would immediately surface the full value of the enrichment and response automation.
Enrichment pipeline not yet exercised. Despite 13 enrichment subflows being fully built and connected, 0 enrichment runs have occurred. Since Process Alert did fire 5 times and called the enrichment router (8 executions), this suggests observable extraction may have yielded no enrichable IOCs in the test data, or enrichment dispatch is gated by a condition not yet met at scale. This is the highest-leverage gap to investigate.
CrowdStrike ingestion inactive. CrowdStrike is the most deeply integrated tool in the ecosystem (alert ingest, hash enrichment, agent enrichment, RTR, quarantine) but both CrowdStrike ingest playbooks show 0 executions. Activating webhook-based CrowdStrike ingest is likely the single highest-value enablement action — it would feed the pipeline with high-fidelity EDR telemetry and immediately exercise the enrichment and response automation.
Response automation not yet triggered. Both response subflows (phishing, malware) and all EDR containment playbooks show 0 executions. The routing infrastructure exists and the response router fired once — getting live phishing or malware alerts flowing through the pipeline would begin demonstrating automated MTTR reduction.
No IAM, GRC, or Cloud Security use cases beyond ingest. The deployment is entirely SOC-focused. Given that Okta, Microsoft Entra ID, and Google Workspace are already connected with active credentials, employee lifecycle automation (onboarding/offboarding/access review) is a natural adjacent expansion. Wiz and AWS CloudTrail connections similarly open the door to automated cloud posture remediation workflows.
Integration Ecosystem Summary
| Integration | Used In |
|---|---|
| CrowdStrike Falcon | Alert ingest (×2), hash enrichment, agent ID enrichment, endpoint quarantine, RTR (single + batch), hash investigation |
| Microsoft Entra ID | Username/email enrichment, user investigation (with risky user lookup), Defender for Cloud Apps ingest |
| Azure Monitor | Alert ingest |
| Okta | Username/email enrichment, user investigation, activity log search |
| VirusTotal | IP enrichment, URL enrichment, hash enrichment, hash investigation |
| Wiz | CSPM alert ingest |
| AWS CloudTrail | Security event ingest |
| AbuseIPDB | IP enrichment |
| URLScan | URL enrichment, URL investigation |
| Google Workspace | Username/email enrichment, user investigation |
| GitHub | Username enrichment, user investigation |
| Slack | Email-to-user enrichment |
| Microsoft Outlook | Phishing email header inspection |
| Blink Case Management | Alert, case, observable, attachment, and task APIs (core platform) |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 5 active | 27 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink - Decision Maker | Demo 1: AI SOC | 16 | 0 | 1,152,265 |
| 2 | SOC Agent - EDR Agent | Demo 1: AI SOC | 4 | 0 | 285,793 |
| 3 | Micro Agent - Historical Case Check | Demo 1: AI SOC | 3 | 0 | 93,046 |
| 4 | SOC Agent - Core Investigator Agent | Demo 1: AI SOC | 2 | 0 | 221,897 |
| 5 | SOC Agent - Phishing Agent | Demo 1: AI SOC | 2 | 0 | 167,113 |
| Workspace | Tasks (12m) |
|---|---|
| Demo 1: AI SOC | 27 |
| Case Management V9 | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 7 use cases | 456 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts processed end-to-end through automated SOC pipeline | 5 | Process Alert |
| Microsoft Defender for Cloud Apps alerts auto-ingested & case-created | 4 | EXAMPLE Ingest - Microsoft Defender For Cloud Apps |
| Azure Monitor security events auto-ingested & case-created | 3 | EXAMPLE Ingest - Azure |
| Wiz CSPM findings auto-ingested & case-created | 2 | EXAMPLE Ingest - Wiz |
| AWS CloudTrail security events auto-ingested & case-created | 2 | EXAMPLE Ingest - AWS CloudTrail |
Use Case Summary
| # | Use Case | Category | Playbooks | Executions (12 mo) |
|---|---|---|---|---|
| 1 | Agentic SOC — Alert Processing Pipeline | SOC | 5 | 14 |
| 2 | Multi-Source Alert Ingestion | SOC | 6 | 11 |
| 3 | Alert Enrichment Engine | SOC | 13 | 0 |
| 4 | Incident Response Automation | SOC | 2 | 0 |
| 5 | EDR Containment & Remote Response | SOC | 3 | 0 |
| 6 | Analyst Investigation Toolkit | SOC | 13 | 0 |
| 7 | Case Management Platform Utilities | SOC | 12 | 0 |
| — | Draft / Development | — | 5 | 0 |
| Total | 59 | 25 |
Use Cases
Use Case 1: Agentic SOC — Alert Processing Pipeline
Description: The central automated SOC orchestration engine. When a new alert lands in the case management system, this pipeline automatically extracts observables, creates or merges into an existing case (deduplication), fans out enrichment jobs for all new observables, waits for enrichment to complete, and routes to the appropriate response subflow — without analyst involvement. Recovery playbooks handle backfill for any alerts or observables that slipped through during outages.
Business Problem Solved: Eliminates manual alert triage, observable extraction, case creation, and initial enrichment — compressing the alert-to-response timeline and removing analyst toil from all routine processing.
Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR
| Playbook | Executions (12 mo) |
|---|---|
| Process Alert | 5 |
| Subflow - Enrich Observables - Main Router | 8 |
| Subflow - Response - Main Router | 1 |
| Recovery - Handle Unprocessed Alerts | 0 |
| Recovery - Enrich Non-Enriched Observables | 0 |
Key Integrations: Blink Case Management (alert, case, observable APIs), CrowdStrike, VirusTotal, AbuseIPDB, Okta, Microsoft Entra ID, Slack
Use Case 2: Multi-Source Alert Ingestion
Description: Event-driven ingestion playbooks — one per security source — that continuously poll or receive webhooks from security tools and automatically create standardized alerts in the case management system. Four of the six sources are actively running; CrowdStrike direct and LogScale ingestion are configured but not yet firing.
Business Problem Solved: Normalizes heterogeneous security telemetry from multiple platforms into a single case management view, eliminating manual aggregation and enabling consistent automated handling regardless of alert origin.
Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR, CSPM ingest & triage
| Playbook | Source | Trigger Type | Executions (12 mo) |
|---|---|---|---|
| EXAMPLE Ingest - Microsoft Defender For Cloud Apps | Microsoft Defender for Cloud Apps | Polling | 4 |
| EXAMPLE Ingest - Azure | Azure Monitor | Polling | 3 |
| EXAMPLE Ingest - Wiz | Wiz | Polling | 2 |
| EXAMPLE Ingest - AWS CloudTrail | AWS CloudTrail | Polling | 2 |
| EXAMPLE Ingest - CrowdStrike | CrowdStrike | Webhook | 0 |
| EXAMPLE Ingest - CrowdStrike Falcon LogScale | CrowdStrike Falcon LogScale | Webhook | 0 |
Key Integrations: Wiz, Microsoft Defender for Cloud Apps, CrowdStrike, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail
Use Case 3: Alert Enrichment Engine
Description: A fleet of specialized enrichment subflows — one per observable type and data source — automatically dispatched by the enrichment router during alert processing. Each subflow enriches a specific IOC type (IP, URL, hash, username, or endpoint agent ID) using the relevant data source and writes structured results back to the observable record in case management.
Business Problem Solved: Provides instant, consistent threat context on every IOC without analyst research time. Enables the automated pipeline to make informed triage and response decisions based on enriched intel at machine speed.
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation
| Playbook | Observable Type | Source | Executions (12 mo) |
|---|---|---|---|
| Enrich - IP - VT | IP | VirusTotal | 0 |
| Enrich - IP - IPDB | IP | AbuseIPDB | 0 |
| Enrich - IP or Domain - Whois | IP / Domain | Whois | 0 |
| Enrich - URL - VT | URL | VirusTotal | 0 |
| Enrich - URL - URLScan | URL | URLScan | 0 |
| Enrich - Hash - VT | File Hash | VirusTotal | 0 |
| Enrich - Hash - Crowdstrike | File Hash | CrowdStrike | 0 |
| Enrich - Username or Email - Okta | Username / Email | Okta | 0 |
| Enrich - Username or Email - Google Workspace | Username / Email | Google Workspace | 0 |
| Enrich - Username or Email - Microsoft Entra ID | Username / Email | Microsoft Entra ID | 0 |
| Enrich - Username - Github | Username | GitHub | 0 |
| Enrich - Agent ID - Crowdstrike | Endpoint Agent ID | CrowdStrike | 0 |
| Enrich - Email Address - Slack | Email Address | Slack | 0 |
Key Integrations: VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack
Use Case 4: Incident Response Automation
Description: Automated response subflows triggered after case enrichment completes. The phishing subflow validates whether a flagged email is a real attack (vs. a KnowBe4 simulation) by inspecting Microsoft Outlook headers, then applies appropriate containment. The malware subflow checks whether CrowdStrike fully or partially remediated the threat and applies conditional follow-up actions.
Business Problem Solved: Converts enriched alert context into an immediate, consistent response action — without waiting for analyst availability — reducing dwell time on confirmed threats and eliminating false-positive response on training simulations.
Category: SOC | Subcategories: Phishing detection & response, EDR containment & response, Case mgmt & SOAR
| Playbook | Response Type | Executions (12 mo) |
|---|---|---|
| Response Subflow - Phishing | Phishing email investigation & KnowBe4 filter | 0 |
| Response Subflow - Malware | Malware remediation status check & conditional action | 0 |
Key Integrations: Microsoft Outlook, Blink Case Management
Use Case 5: EDR Containment & Remote Response
Description: On-demand and pipeline-callable playbooks for endpoint containment (isolate / lift isolation) and remote command execution on CrowdStrike-managed endpoints. Supports both targeted single-host operations and bulk batch commands across a host group.
Business Problem Solved: Enables immediate endpoint containment during active incidents and remote forensic or remediation commands without requiring direct system access — compressing response time and limiting lateral movement risk.
Category: SOC | Subcategories: EDR containment & response
| Playbook | Action | Executions (12 mo) |
|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | Isolate / Lift Isolation | 0 |
| CrowdStrike RTR to a Single Host | Remote command execution (single host) | 0 |
| CrowdStrike RTR to a Batch of Hosts | Remote command execution (batch) | 0 |
Key Integrations: CrowdStrike Falcon (RTR, Host Actions)
Use Case 6: Analyst Investigation Toolkit
Description: A library of on-demand investigative playbooks enabling analysts to quickly retrieve user identity data, file reputation, network intelligence, and endpoint state from a unified interface during active investigations. These tools use the same integration connections as the automated enrichment engine and can be called manually from the case management UI or Blink portal.
Business Problem Solved: Consolidates investigative lookups across 8+ data sources into standardized, reusable tools — reducing context-switching and eliminating inconsistent manual query patterns across the analyst team.
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation, Identity threat response
| Playbook | Data Type | Source | Executions (12 mo) |
|---|---|---|---|
| Get User Information Using Okta | User identity & status | Okta | 0 |
| Get User Information Using Microsoft Entra ID | User identity, risk score & risky user list | Microsoft Entra ID | 0 |
| Get User Information Using Google Workspace | User identity | Google Workspace | 0 |
| Get User Information Using Github | User identity | GitHub | 0 |
| Get User Information on Email Address Using Slack | User-to-email mapping | Slack | 0 |
| Okta Search for User Activity | User activity logs (date-ranged) | Okta | 0 |
| Get Hash Info Using VirusTotal | File reputation | VirusTotal | 0 |
| Get Hash Info Using Crowdstrike | File reputation + endpoint presence | CrowdStrike | 0 |
| Enrich IP or Domain Using Whois | IP / domain registration data | Whois | 0 |
| Analyze URL with URLScan | URL reputation + visual scan | URLScan | 0 |
| Secure URL Screenshot Capture | URL visual inspection (safe headless capture) | Internal sandbox | 0 |
| Run Dig Command | DNS resolution | System | 0 |
| Get End of Life Date for a Product | Software EOL status | endoflife.date API | 0 |
Key Integrations: Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, VirusTotal, CrowdStrike, URLScan, Whois, DNS
Use Case 7: Case Management Platform Utilities
Description: Supporting utilities and subflows that maintain the integrity and operational health of the case management data model. Covers observable relationship lifecycle (create, update, delete, list), case hygiene (stale case closure, similar-case detection), alert template validation, and operator error notification.
Business Problem Solved: Keeps the SOAR platform data model clean and self-maintaining — automatically closing dead cases, surfacing related incidents for analyst correlation, and ensuring the team is notified when the automation encounters gaps or failures.
Category: SOC | Subcategories: Case mgmt & SOAR
| Playbook | Purpose | Executions (12 mo) |
|---|---|---|
| Subflow - Update Enrichment Data | Write enrichment results back to observable record | 0 |
| Utility - Update Enrichment | Alias wrapper for enrichment update subflow | 0 |
| Utility - Close Stale Cases | Auto-close open cases with no activity for 30+ days | 0 |
| Utility - Set Or Update Observable Relation | Create or update observable-to-alert relationship | 0 |
| Utility - Delete Observable Relation | Remove an observable-alert link | 0 |
| Utility - List Observable Alert Relations | Enumerate all alerts linked to an observable | 0 |
| Utility - List Alert Observable Relations | Enumerate all observables in an alert | 0 |
| Utility - Find Similar Cases Based on Observables | Surface related cases by shared observable overlap | 0 |
| Table Action - Validate Observables Extraction Template | Test observable extraction configs against real alerts | 0 |
| Subflow - Missing Alert Template Notification | Notify when an inbound alert has no extraction template | 0 |
| Error Handling - Send Error Notification Email | Email operators on automation failures | 0 |
| USE WITH CARE - Reset Case Management Environment | Wipe all case management data (dev/testing only) | 0 |
Key Integrations: Blink Case Management, Email (core)
Key Observations
Strengths
Production-grade Agentic SOC architecture. The deployment follows a well-designed, layered SOAR pattern: multi-source ingestion → automated case creation with deduplication → observable enrichment fan-out → conditional response routing. The architecture separates concerns cleanly — each layer is independently maintainable and the enrichment router decouples source-specific ingest from IOC-specific enrichment logic. Recovery playbooks and structured error notification add operational resilience.
Broad and deep integration ecosystem. 12+ distinct security tool integrations are wired up and configured, including CrowdStrike (EDR, threat intel, RTR), the full Microsoft stack (Entra ID, Defender for Cloud Apps, Azure Monitor, Outlook), VirusTotal + AbuseIPDB + URLScan (threat intel), Okta + Google Workspace + GitHub (identity), and Wiz + AWS CloudTrail (cloud security). This is a strong foundation — the connections already exist and are tested.
Complete observable type coverage. The enrichment engine covers all major IOC categories — IP addresses (two sources), domains, URLs (two sources), file hashes (two sources), usernames/emails (three identity providers + Slack), and CrowdStrike endpoint agent IDs. Cross-source enrichment on the same observable type enables automated verdict confidence scoring.
Phishing simulation awareness. The phishing response subflow specifically handles KnowBe4 simulation emails by checking for X-PHISHTEST headers before triggering containment — a mature, false-positive-aware response pattern.
Gaps & Opportunities
Platform is in early-activation phase. With 25 total executions across 12 months (16 from ingest playbooks, 9 from the core pipeline), the platform is running at POC-level volume. The architecture is production-ready — the primary gap is volume, not capability. Enabling all configured ingestion sources at production polling rates would immediately surface the full value of the enrichment and response automation.
Enrichment pipeline not yet exercised. Despite 13 enrichment subflows being fully built and connected, 0 enrichment runs have occurred. Since Process Alert did fire 5 times and called the enrichment router (8 executions), this suggests observable extraction may have yielded no enrichable IOCs in the test data, or enrichment dispatch is gated by a condition not yet met at scale. This is the highest-leverage gap to investigate.
CrowdStrike ingestion inactive. CrowdStrike is the most deeply integrated tool in the ecosystem (alert ingest, hash enrichment, agent enrichment, RTR, quarantine) but both CrowdStrike ingest playbooks show 0 executions. Activating webhook-based CrowdStrike ingest is likely the single highest-value enablement action — it would feed the pipeline with high-fidelity EDR telemetry and immediately exercise the enrichment and response automation.
Response automation not yet triggered. Both response subflows (phishing, malware) and all EDR containment playbooks show 0 executions. The routing infrastructure exists and the response router fired once — getting live phishing or malware alerts flowing through the pipeline would begin demonstrating automated MTTR reduction.
No IAM, GRC, or Cloud Security use cases beyond ingest. The deployment is entirely SOC-focused. Given that Okta, Microsoft Entra ID, and Google Workspace are already connected with active credentials, employee lifecycle automation (onboarding/offboarding/access review) is a natural adjacent expansion. Wiz and AWS CloudTrail connections similarly open the door to automated cloud posture remediation workflows.
Integration Ecosystem Summary
| Integration | Used In |
|---|---|
| CrowdStrike Falcon | Alert ingest (×2), hash enrichment, agent ID enrichment, endpoint quarantine, RTR (single + batch), hash investigation |
| Microsoft Entra ID | Username/email enrichment, user investigation (with risky user lookup), Defender for Cloud Apps ingest |
| Azure Monitor | Alert ingest |
| Okta | Username/email enrichment, user investigation, activity log search |
| VirusTotal | IP enrichment, URL enrichment, hash enrichment, hash investigation |
| Wiz | CSPM alert ingest |
| AWS CloudTrail | Security event ingest |
| AbuseIPDB | IP enrichment |
| URLScan | URL enrichment, URL investigation |
| Google Workspace | Username/email enrichment, user investigation |
| GitHub | Username enrichment, user investigation |
| Slack | Email-to-user enrichment |
| Microsoft Outlook | Phishing email header inspection |
| Blink Case Management | Alert, case, observable, attachment, and task APIs (core platform) |
1. Business KPIs — Last 12 Months
| Metric | Count | Playbook |
|---|---|---|
| Security alerts processed end-to-end through automated SOC pipeline | 5 | Process Alert |
| Microsoft Defender for Cloud Apps alerts auto-ingested & case-created | 4 | EXAMPLE Ingest - Microsoft Defender For Cloud Apps |
| Azure Monitor security events auto-ingested & case-created | 3 | EXAMPLE Ingest - Azure |
| Wiz CSPM findings auto-ingested & case-created | 2 | EXAMPLE Ingest - Wiz |
| AWS CloudTrail security events auto-ingested & case-created | 2 | EXAMPLE Ingest - AWS CloudTrail |
2. Use Case Summary
| # | Use Case | Category | Playbooks | Executions (12 mo) |
|---|---|---|---|---|
| 1 | Agentic SOC — Alert Processing Pipeline | SOC | 5 | 14 |
| 2 | Multi-Source Alert Ingestion | SOC | 6 | 11 |
| 3 | Alert Enrichment Engine | SOC | 13 | 0 |
| 4 | Incident Response Automation | SOC | 2 | 0 |
| 5 | EDR Containment & Remote Response | SOC | 3 | 0 |
| 6 | Analyst Investigation Toolkit | SOC | 13 | 0 |
| 7 | Case Management Platform Utilities | SOC | 12 | 0 |
| — | Draft / Development | — | 5 | 0 |
| Total | 59 | 25 |
3. Use Cases
Use Case 1: Agentic SOC — Alert Processing Pipeline
Description: The central automated SOC orchestration engine. When a new alert lands in the case management system, this pipeline automatically extracts observables, creates or merges into an existing case (deduplication), fans out enrichment jobs for all new observables, waits for enrichment to complete, and routes to the appropriate response subflow — without analyst involvement. Recovery playbooks handle backfill for any alerts or observables that slipped through during outages.
Business Problem Solved: Eliminates manual alert triage, observable extraction, case creation, and initial enrichment — compressing the alert-to-response timeline and removing analyst toil from all routine processing.
Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR
| Playbook | Executions (12 mo) |
|---|---|
| Process Alert | 5 |
| Subflow - Enrich Observables - Main Router | 8 |
| Subflow - Response - Main Router | 1 |
| Recovery - Handle Unprocessed Alerts | 0 |
| Recovery - Enrich Non-Enriched Observables | 0 |
Key Integrations: Blink Case Management (alert, case, observable APIs), CrowdStrike, VirusTotal, AbuseIPDB, Okta, Microsoft Entra ID, Slack
Use Case 2: Multi-Source Alert Ingestion
Description: Event-driven ingestion playbooks — one per security source — that continuously poll or receive webhooks from security tools and automatically create standardized alerts in the case management system. Four of the six sources are actively running; CrowdStrike direct and LogScale ingestion are configured but not yet firing.
Business Problem Solved: Normalizes heterogeneous security telemetry from multiple platforms into a single case management view, eliminating manual aggregation and enabling consistent automated handling regardless of alert origin.
Category: SOC | Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR, CSPM ingest & triage
| Playbook | Source | Trigger Type | Executions (12 mo) |
|---|---|---|---|
| EXAMPLE Ingest - Microsoft Defender For Cloud Apps | Microsoft Defender for Cloud Apps | Polling | 4 |
| EXAMPLE Ingest - Azure | Azure Monitor | Polling | 3 |
| EXAMPLE Ingest - Wiz | Wiz | Polling | 2 |
| EXAMPLE Ingest - AWS CloudTrail | AWS CloudTrail | Polling | 2 |
| EXAMPLE Ingest - CrowdStrike | CrowdStrike | Webhook | 0 |
| EXAMPLE Ingest - CrowdStrike Falcon LogScale | CrowdStrike Falcon LogScale | Webhook | 0 |
Key Integrations: Wiz, Microsoft Defender for Cloud Apps, CrowdStrike, CrowdStrike Falcon LogScale, Azure Monitor, AWS CloudTrail
Use Case 3: Alert Enrichment Engine
Description: A fleet of specialized enrichment subflows — one per observable type and data source — automatically dispatched by the enrichment router during alert processing. Each subflow enriches a specific IOC type (IP, URL, hash, username, or endpoint agent ID) using the relevant data source and writes structured results back to the observable record in case management.
Business Problem Solved: Provides instant, consistent threat context on every IOC without analyst research time. Enables the automated pipeline to make informed triage and response decisions based on enriched intel at machine speed.
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation
| Playbook | Observable Type | Source | Executions (12 mo) |
|---|---|---|---|
| Enrich - IP - VT | IP | VirusTotal | 0 |
| Enrich - IP - IPDB | IP | AbuseIPDB | 0 |
| Enrich - IP or Domain - Whois | IP / Domain | Whois | 0 |
| Enrich - URL - VT | URL | VirusTotal | 0 |
| Enrich - URL - URLScan | URL | URLScan | 0 |
| Enrich - Hash - VT | File Hash | VirusTotal | 0 |
| Enrich - Hash - Crowdstrike | File Hash | CrowdStrike | 0 |
| Enrich - Username or Email - Okta | Username / Email | Okta | 0 |
| Enrich - Username or Email - Google Workspace | Username / Email | Google Workspace | 0 |
| Enrich - Username or Email - Microsoft Entra ID | Username / Email | Microsoft Entra ID | 0 |
| Enrich - Username - Github | Username | GitHub | 0 |
| Enrich - Agent ID - Crowdstrike | Endpoint Agent ID | CrowdStrike | 0 |
| Enrich - Email Address - Slack | Email Address | Slack | 0 |
Key Integrations: VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack
Use Case 4: Incident Response Automation
Description: Automated response subflows triggered after case enrichment completes. The phishing subflow validates whether a flagged email is a real attack (vs. a KnowBe4 simulation) by inspecting Microsoft Outlook headers, then applies appropriate containment. The malware subflow checks whether CrowdStrike fully or partially remediated the threat and applies conditional follow-up actions.
Business Problem Solved: Converts enriched alert context into an immediate, consistent response action — without waiting for analyst availability — reducing dwell time on confirmed threats and eliminating false-positive response on training simulations.
Category: SOC | Subcategories: Phishing detection & response, EDR containment & response, Case mgmt & SOAR
| Playbook | Response Type | Executions (12 mo) |
|---|---|---|
| Response Subflow - Phishing | Phishing email investigation & KnowBe4 filter | 0 |
| Response Subflow - Malware | Malware remediation status check & conditional action | 0 |
Key Integrations: Microsoft Outlook, Blink Case Management
Use Case 5: EDR Containment & Remote Response
Description: On-demand and pipeline-callable playbooks for endpoint containment (isolate / lift isolation) and remote command execution on CrowdStrike-managed endpoints. Supports both targeted single-host operations and bulk batch commands across a host group.
Business Problem Solved: Enables immediate endpoint containment during active incidents and remote forensic or remediation commands without requiring direct system access — compressing response time and limiting lateral movement risk.
Category: SOC | Subcategories: EDR containment & response
| Playbook | Action | Executions (12 mo) |
|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | Isolate / Lift Isolation | 0 |
| CrowdStrike RTR to a Single Host | Remote command execution (single host) | 0 |
| CrowdStrike RTR to a Batch of Hosts | Remote command execution (batch) | 0 |
Key Integrations: CrowdStrike Falcon (RTR, Host Actions)
Use Case 6: Analyst Investigation Toolkit
Description: A library of on-demand investigative playbooks enabling analysts to quickly retrieve user identity data, file reputation, network intelligence, and endpoint state from a unified interface during active investigations. These tools use the same integration connections as the automated enrichment engine and can be called manually from the case management UI or Blink portal.
Business Problem Solved: Consolidates investigative lookups across 8+ data sources into standardized, reusable tools — reducing context-switching and eliminating inconsistent manual query patterns across the analyst team.
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation, Identity threat response
| Playbook | Data Type | Source | Executions (12 mo) |
|---|---|---|---|
| Get User Information Using Okta | User identity & status | Okta | 0 |
| Get User Information Using Microsoft Entra ID | User identity, risk score & risky user list | Microsoft Entra ID | 0 |
| Get User Information Using Google Workspace | User identity | Google Workspace | 0 |
| Get User Information Using Github | User identity | GitHub | 0 |
| Get User Information on Email Address Using Slack | User-to-email mapping | Slack | 0 |
| Okta Search for User Activity | User activity logs (date-ranged) | Okta | 0 |
| Get Hash Info Using VirusTotal | File reputation | VirusTotal | 0 |
| Get Hash Info Using Crowdstrike | File reputation + endpoint presence | CrowdStrike | 0 |
| Enrich IP or Domain Using Whois | IP / domain registration data | Whois | 0 |
| Analyze URL with URLScan | URL reputation + visual scan | URLScan | 0 |
| Secure URL Screenshot Capture | URL visual inspection (safe headless capture) | Internal sandbox | 0 |
| Run Dig Command | DNS resolution | System | 0 |
| Get End of Life Date for a Product | Software EOL status | endoflife.date API | 0 |
Key Integrations: Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, VirusTotal, CrowdStrike, URLScan, Whois, DNS
Use Case 7: Case Management Platform Utilities
Description: Supporting utilities and subflows that maintain the integrity and operational health of the case management data model. Covers observable relationship lifecycle (create, update, delete, list), case hygiene (stale case closure, similar-case detection), alert template validation, and operator error notification.
Business Problem Solved: Keeps the SOAR platform data model clean and self-maintaining — automatically closing dead cases, surfacing related incidents for analyst correlation, and ensuring the team is notified when the automation encounters gaps or failures.
Category: SOC | Subcategories: Case mgmt & SOAR
| Playbook | Purpose | Executions (12 mo) |
|---|---|---|
| Subflow - Update Enrichment Data | Write enrichment results back to observable record | 0 |
| Utility - Update Enrichment | Alias wrapper for enrichment update subflow | 0 |
| Utility - Close Stale Cases | Auto-close open cases with no activity for 30+ days | 0 |
| Utility - Set Or Update Observable Relation | Create or update observable-to-alert relationship | 0 |
| Utility - Delete Observable Relation | Remove an observable-alert link | 0 |
| Utility - List Observable Alert Relations | Enumerate all alerts linked to an observable | 0 |
| Utility - List Alert Observable Relations | Enumerate all observables in an alert | 0 |
| Utility - Find Similar Cases Based on Observables | Surface related cases by shared observable overlap | 0 |
| Table Action - Validate Observables Extraction Template | Test observable extraction configs against real alerts | 0 |
| Subflow - Missing Alert Template Notification | Notify when an inbound alert has no extraction template | 0 |
| Error Handling - Send Error Notification Email | Email operators on automation failures | 0 |
| USE WITH CARE - Reset Case Management Environment | Wipe all case management data (dev/testing only) | 0 |
Key Integrations: Blink Case Management, Email (core)
4. Key Observations
Strengths
Production-grade Agentic SOC architecture. The deployment follows a well-designed, layered SOAR pattern: multi-source ingestion → automated case creation with deduplication → observable enrichment fan-out → conditional response routing. The architecture separates concerns cleanly — each layer is independently maintainable and the enrichment router decouples source-specific ingest from IOC-specific enrichment logic. Recovery playbooks and structured error notification add operational resilience.
Broad and deep integration ecosystem. 12+ distinct security tool integrations are wired up and configured, including CrowdStrike (EDR, threat intel, RTR), the full Microsoft stack (Entra ID, Defender for Cloud Apps, Azure Monitor, Outlook), VirusTotal + AbuseIPDB + URLScan (threat intel), Okta + Google Workspace + GitHub (identity), and Wiz + AWS CloudTrail (cloud security). This is a strong foundation — the connections already exist and are tested.
Complete observable type coverage. The enrichment engine covers all major IOC categories — IP addresses (two sources), domains, URLs (two sources), file hashes (two sources), usernames/emails (three identity providers + Slack), and CrowdStrike endpoint agent IDs. Cross-source enrichment on the same observable type enables automated verdict confidence scoring.
Phishing simulation awareness. The phishing response subflow specifically handles KnowBe4 simulation emails by checking for X-PHISHTEST headers before triggering containment — a mature, false-positive-aware response pattern.
Gaps & Opportunities
Platform is in early-activation phase. With 25 total executions across 12 months (16 from ingest playbooks, 9 from the core pipeline), the platform is running at POC-level volume. The architecture is production-ready — the primary gap is volume, not capability. Enabling all configured ingestion sources at production polling rates would immediately surface the full value of the enrichment and response automation.
Enrichment pipeline not yet exercised. Despite 13 enrichment subflows being fully built and connected, 0 enrichment runs have occurred. Since Process Alert did fire 5 times and called the enrichment router (8 executions), this suggests observable extraction may have yielded no enrichable IOCs in the test data, or enrichment dispatch is gated by a condition not yet met at scale. This is the highest-leverage gap to investigate.
CrowdStrike ingestion inactive. CrowdStrike is the most deeply integrated tool in the ecosystem (alert ingest, hash enrichment, agent enrichment, RTR, quarantine) but both CrowdStrike ingest playbooks show 0 executions. Activating webhook-based CrowdStrike ingest is likely the single highest-value enablement action — it would feed the pipeline with high-fidelity EDR telemetry and immediately exercise the enrichment and response automation.
Response automation not yet triggered. Both response subflows (phishing, malware) and all EDR containment playbooks show 0 executions. The routing infrastructure exists and the response router fired once — getting live phishing or malware alerts flowing through the pipeline would begin demonstrating automated MTTR reduction.
No IAM, GRC, or Cloud Security use cases beyond ingest. The deployment is entirely SOC-focused. Given that Okta, Microsoft Entra ID, and Google Workspace are already connected with active credentials, employee lifecycle automation (onboarding/offboarding/access review) is a natural adjacent expansion. Wiz and AWS CloudTrail connections similarly open the door to automated cloud posture remediation workflows.
Integration Ecosystem Summary
| Integration | Used In |
|---|---|
| CrowdStrike Falcon | Alert ingest (×2), hash enrichment, agent ID enrichment, endpoint quarantine, RTR (single + batch), hash investigation |
| Microsoft Entra ID | Username/email enrichment, user investigation (with risky user lookup), Defender for Cloud Apps ingest |
| Azure Monitor | Alert ingest |
| Okta | Username/email enrichment, user investigation, activity log search |
| VirusTotal | IP enrichment, URL enrichment, hash enrichment, hash investigation |
| Wiz | CSPM alert ingest |
| AWS CloudTrail | Security event ingest |
| AbuseIPDB | IP enrichment |
| URLScan | URL enrichment, URL investigation |
| Google Workspace | Username/email enrichment, user investigation |
| GitHub | Username enrichment, user investigation |
| Slack | Email-to-user enrichment |
| Microsoft Outlook | Phishing email header inspection |
| Blink Case Management | Alert, case, observable, attachment, and task APIs (core platform) |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.