Blink Security Automation — Confidential

Catalyst Brands — Customer Success Report

Generated 2026-08-30 | catalyst-brands-value-report.md
2026-08-30Report Date
409Total Playbooks
121Unique Workflows (12m)
8,112,346Actions Automated (12m)
$2,086,509Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

409
Total playbooks built
all non-deleted workflows
190
Active playbooks
currently enabled
121
Unique workflows executed (12m)
distinct workflows that ran
8,112,346
Actions automated (12m)
completed action steps
45,068.6h
Hours saved (12m)
@ 20s per action
$2,086,509
Money saved (12m)
@ $100K avg salary
17
New active workflows (last 30d)
recently created & enabled
38,511
Total cases managed
25,584 opened in last 12m
8h 18m
MTTR — mean time to resolve
closed cases, last 12m
4
Active AI agents
of 12 total
85
AI agent tasks executed (12m)
23 in last 30d
In the last 12 months, Blink automated: - 5,667 security alerts processed end-to-end — from raw detection to case, enrichment, and automated response without analyst intervention - 7,680 BMC Remedy incidents and work orders synced bidirectionally, eliminating manual ITSM handoffs for the SecOps team - 2,880 Abnormal-sourced email threats automatically investigated across phishing, account takeover, and suspicious activity case types - 2,524 cases enriched with Recorded Future threat intelligence, accelerating analyst triage decisions - 2,462 security cases auto-assigned to the on-call analyst based on live shift schedule - 1,736 high/critical severity alerts routed to analysts with real-time email notifications - 681 CrowdStrike endpoint alerts automatically closed in sync with case resolution - 60 high-risk identity response actions executed autonomously (session revocation, account blocks, password resets) - 15 DSAR privacy requests fully orchestrated, from OneTrust intake through user de-identification and fulfillment

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC — Alert Processing Pipeline
  • 5,667Security alerts processed end-to-end (detection → case → response)
49.0%
9
9 active
Multi-Source Alert Ingestion
  • 1,856CrowdStrike FIM events converted to security alerts
  • 1,543CrowdStrike endpoint alerts ingested
  • 1,085LogScale alerts ingested
8.0%
9
9 active
ITSM Integration — BMC Remedy
  • 5,760BMC Remedy incidents synced to Blink
  • 1,920BMC Remedy work orders synced to Blink
  • 136BMC Remedy case status changes synchronized
8.0%
9
9 active
Phishing Detection & Response (Abnormal)
  • 960Phishing email cases analyzed and investigated
  • 960Account takeover cases triaged (Abnormal)
  • 960Suspicious email activity cases triaged (Abnormal)
3.8%
5
5 active
IOC & Observable Enrichment15,479 executions
14.7%
19
16 active
Recorded Future Threat Intelligence
  • 2,524Cases enriched with Recorded Future threat intelligence
  • 1,487Hashes enriched via Recorded Future
  • 812IPs enriched via Recorded Future
4.8%
5
5 active
Identity Threat Response
  • 60High-risk identity response actions executed
0.2%
7
7 active
EDR Containment & Host Response
  • 681CrowdStrike alerts auto-closed on case resolution
6.9%
13
13 active
Case Management & Analyst Workflow
  • 2,462Cases auto-assigned to on-call analyst via shift schedule
  • 1,736High/critical severity case notifications sent to SOC
  • 122Shift summaries generated for SOC handoffs
4.0%
12
12 active
Agentic Threat Hunting
  • 7AI-generated threat hunt reports
0.0%
6
6 active
Vulnerability Ticket Management (TVM)
  • 5Vulnerability tickets created via web form
0.1%
3
3 active
Cloud Security Monitoring (Wiz)
  • 96Wiz cloud security alerts ingested
0.1%
1
1 active
Cloud Asset Inventory194 executions
0.2%
4
4 active
DSAR & Privacy Automation
  • 15DSAR privacy requests orchestrated end-to-end
0.1%
12
12 active
Security Metrics & Reporting162 executions
0.2%
6
6 active
Platform Migration & Environment Testing0 executions
0.0%
4
4 active
Total105,463 executions100%
124
121 active

Use Case Growth Over Time

302 unique playbooks  |  16 operational use cases  |  105,541 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Multi-Source Alert Ingestion
CrowdStrike
IOC & Observable Enrichment
VirusTotal CrowdStrike AbuseIPDB MISP LDAP OneLogin Microsoft Entra ID
Case Management & Analyst Workflow
Email
EDR Containment & Host Response
CrowdStrike Email
Phishing Detection & Response (Abnormal)
Abnormal
Security Metrics & Reporting
Abnormal Wiz CrowdStrike Recorded Future Dashboards Email
Identity Threat Response
Microsoft Entra ID OneLogin
Cloud Security Monitoring (Wiz)
Wiz
Vulnerability Ticket Management (TVM)
Email
Recorded Future Threat Intelligence
Recorded Future
ITSM Integration — BMC Remedy
BMC Remedy Email
Cloud Asset Inventory
runZero SMB Utilities
Agentic Threat Hunting
Agents Email Cribl Falcon LogScale
DSAR & Privacy Automation
Oracle Database OneTrust Email SMB Utilities AWS
Platform Migration & Environment Testing
Email

04Key Observations

✓  Strengths

Strengths

Mature agentic SOC pipeline. The Process Alert pipeline — spanning five chained subflows with 5,667 top-level executions and 7,431 observable enrichments — represents a production-grade, end-to-end automation that most organizations aspire to but few fully implement. Deduplication, case linking, enrichment, and response all happen without analyst involvement.

Broad multi-source alert coverage. Eight alert sources are integrated and actively firing: CrowdStrike (endpoint + FIM + TVM), Falcon LogScale, Varonis, Cribl, Wiz, Abnormal (shared mailbox), and BMC Remedy. This gives the SOC a single normalized queue regardless of detection origin.

ITSM bidirectionality at scale. The BMC Remedy integration handles 7,680 incident and work order syncs per year, with real-time status synchronization back from Blink. This is the kind of ITSM integration that typically requires middleware; Blink handles it natively.

Phishing automation depth. The Abnormal pipeline doesn't stop at case creation — it extracts raw email headers, attaches them as artifacts, enriches with MISP, and sends branded advisory emails to affected users (269 sent). Few customers implement all three layers.

Multi-brand architecture. The brand-aware CrowdStrike connection routing (via Crowdtrike - get relevant connection, 1,420 executions) elegantly handles the multi-tenant complexity of a holding company with four separate retail brand environments.

Nascent agentic threat hunting. The presence of the Threat Hunting Agent with three AI sub-agents (Cribl, LogScale, and ability tools) signals early investment in the next frontier. With 7 hunt reports generated, the capability is proven and ready for expanded use.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

CM Showcase workspace underutilized. Workspace 6aba2aef contains a parallel set of subflows (Subflow 1–4, enrichment stubs) with 0 executions. These are likely legacy templates or a development environment. They create confusion in the playbook inventory and should be archived or decommissioned.

Identity response volume is low relative to alert volume. With 5,667 alerts processed, only 60 identity response actions were executed. This likely reflects current human-in-the-loop approval for identity containment — an opportunity to expand automated response for confirmed high-confidence detections.

EDR containment is primarily passive. Of the CrowdStrike containment playbooks, only alert closure (681 runs) is fully automated. Network isolation, USB control, and sandbox submission are on-demand only with near-zero executions — these are configured and ready but not yet automated.

DSAR pipeline is early-stage, and build-out is outpacing adoption. With 15 DSAR orchestrations and the Relate/OneTrust fulfillment subflows at 0 executions, this use case is deployed but not yet running at scale. A second brand-specific OneTrust workspace has since been built with the same orchestration pattern plus new Amperity and LiveRamp opt-out subflows — all currently at 0 executions. The underlying complexity (multi-brand MDM, Oracle DB, CDP opt-out) is built — adoption is the remaining gap.

Threat hunting needs volume. The agent framework is technically sound, but 7 hunts in 12 months suggests awareness or workflow adoption is limiting usage. Scheduling periodic automated hunts (e.g., weekly hunting runs from a pre-approved hunt list) would multiply the value of the existing capability without additional build.

Cloud security automation is limited to ingestion. Wiz alerts are ingested (96) and metrics collected (40/month), but there are no CSPM remediation, cloud asset tagging, or misconfiguration response playbooks. This is a natural next expansion.

Integration Ecosystem

Category Tools
EDR / XDR CrowdStrike Falcon (multi-tenant), CrowdStrike Falcon LogScale
Email Security Abnormal Security
Threat Intelligence Recorded Future, VirusTotal, MISP
Data Security Varonis
Cloud Security Wiz
SIEM / Log Pipeline Cribl, Falcon LogScale
ITSM BMC Remedy
Identity OneLogin, Microsoft Entra ID, Active Directory (LDAP)
Privacy / GRC OneTrust, Relate CDP, Amperity, LiveRamp
Asset Management runZero, ServiceNow CMDB
Network / WAF Akamai (configured)
Internal Blink Case Management, Blink Web Forms, Blink Agents, Email
Appendices
A Case Management 25,584 cases (12m) | MTTR 8h 18m

Case Management

Total Cases (all-time)
38,511
25,584 opened in last 12m
Cases Opened (30d)
1,452
1,420 closed in last 30d
Cases Closed (12m)
25,320
of 25,584 opened
MTTR
8h 18m
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Catalyst SecOps 38,494 25,581 25,319 8h 18m
ely@blinkops.com 15 3 1 31s
CM 2 0 0 N/A
B AI Agents 4 active | 85 tasks (12m)

AI Agents

Active Agents
4
of 12 total
Tasks Executed (12m)
85
23 in last 30d
Data Usage (12m)
20,063,158
2,961,186 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent LogScale Catalyst SecOps 30 5 7,749,906
2 Threat Hunting Agent Catalyst SecOps 21 1 4,545,598
3 Agent Cribl Catalyst SecOps 20 3 6,612,239
4 Agent After Action Report Catalyst SecOps 14 14 1,155,415
5 Agent Blink Catalyst Compliance 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Catalyst SecOps85
Catalyst Compliance0
Case Management Testing0
smohan3@jcp.com0
CM0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
17
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Monthly Metrics - Leadership 00
2 Cases Overview 00
3 Example 00
4 MITRE Overview 00
5 SecOps VSOC - Dashboard 00

Webforms

Forms
4
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Create Work Order 00
2 question 00
3 addd user to to group entra 00
4 Catalyst TVM - Vulnerability Ticket 00
D Full Use Case Analysis 16 use cases | 105,541 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts processed end-to-end (detection → case → response) 5,667 Process Alert
BMC Remedy incidents synced to Blink 5,760 BMC Remedy - Incident Ingestion
BMC Remedy work orders synced to Blink 1,920 BMC Remedy - Work Order Ingestion
Cases auto-assigned to on-call analyst via shift schedule 2,462 Assign to current shift
Cases enriched with Recorded Future threat intelligence 2,524 Recorded Future - Main Case Automation
CrowdStrike FIM events converted to security alerts 1,856 CrowdStrike FIM Notification
High/critical severity case notifications sent to SOC 1,736 High/Critical Alert Notification
CrowdStrike endpoint alerts ingested 1,543 Crowdstrike ingest alert JCP
Hashes enriched via Recorded Future 1,487 Recorded Future - Enrich Hash
LogScale alerts ingested 1,085 LogScale Alert Ingestion
Phishing email cases analyzed and investigated 960 Phishing Email Analysis
Account takeover cases triaged (Abnormal) 960 Abnormal- Account Takeover
Suspicious email activity cases triaged (Abnormal) 960 Abnormal- Suspicious Activity
Phishing cases enriched with full email header analysis 858 Abnormal phishing enrichment
IPs enriched via Recorded Future 812 Recorded Future - Enrich IP Address
CrowdStrike alerts auto-closed on case resolution 681 Close Relevant CrowdStrike Alert
Shared mailbox security emails triaged 641 Shared Mailbox Alert Ingestion
Email message headers extracted and attached to cases 849 Response - Extract Message Headers - Abnormal
Varonis data security alerts ingested 449 Varonis Alert Ingestion
Phishing advisory emails sent to affected users 269 Send Phishing Advisory Email
Shift summaries generated for SOC handoffs 122 Shift Summary
Cribl SIEM alerts ingested 131 Cribl Alerts Ingestion
BMC Remedy case status changes synchronized 136 BMC Remedy - Case Synchronization
Wiz cloud security alerts ingested 96 Wiz Alerts Ingestion
High-risk identity response actions executed 60 High Risk - User Response Actions
SLA breach notifications dispatched 56 SLA Breach Notification
DSAR privacy requests orchestrated end-to-end 15 Orchestrator - DSAR
AI-generated threat hunt reports 7 Threat Hunting Agent
Vulnerability tickets created via web form 5 Catalyst TVM - Vuln Ticket Creation
In the last 12 months, Blink automated: - 5,667 security alerts processed end-to-end — from raw detection to case, enrichment, and automated response without analyst intervention - 7,680 BMC Remedy incidents and work orders synced bidirectionally, eliminating manual ITSM handoffs for the SecOps team - 2,880 Abnormal-sourced email threats automatically investigated across phishing, account takeover, and suspicious activity case types - 2,524 cases enriched with Recorded Future threat intelligence, accelerating analyst triage decisions - 2,462 security cases auto-assigned to the on-call analyst based on live shift schedule - 1,736 high/critical severity alerts routed to analysts with real-time email notifications - 681 CrowdStrike endpoint alerts automatically closed in sync with case resolution - 60 high-risk identity response actions executed autonomously (session revocation, account blocks, password resets) - 15 DSAR privacy requests fully orchestrated, from OneTrust intake through user de-identification and fulfillment

Use Case Summary

Use Case Category Subcategory Total Playbooks Active Playbooks
Agentic SOC — Alert Processing Pipeline SOC Agentic SOC, Case mgmt & SOAR 10 9
Multi-Source Alert Ingestion SOC Case mgmt & SOAR, SIEM & log pipeline monitoring 11 8
ITSM Integration — BMC Remedy SOC Case mgmt & SOAR 9 8
Phishing Detection & Response (Abnormal) SOC Phishing detection & response 6 6
IOC & Observable Enrichment SOC Alert enrichment / IOC lookup 18 11
Recorded Future Threat Intelligence SOC Threat intel ingest & curation 5 5
Identity Threat Response SOC Identity threat response 7 6
EDR Containment & Host Response SOC EDR containment & response 13 6
Case Management & Analyst Workflow SOC Case mgmt & SOAR 13 11
Agentic Threat Hunting Vulnerability Mgmt Threat hunting & detection 6 6
Vulnerability Ticket Management (TVM) Vulnerability Mgmt Vuln lifecycle prioritize & ticket 3 3
Cloud Security Monitoring (Wiz) Cloud Security CSPM ingest & triage 2 2
Cloud Asset Inventory Cloud Security Cloud asset coverage & inventory 4 3
DSAR & Privacy Automation GRC DSAR & privacy automation 21 5
Security Metrics & Reporting GRC Security metrics & reporting 6 6
Platform Migration & Environment Testing Other SaaS / IT administration, DevOps & release automation 4 0

Use Cases

1. Agentic SOC — Alert Processing Pipeline

Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR

Description: The core end-to-end alert automation pipeline. Every inbound alert is automatically parsed to extract observables, checked for deduplication against existing cases, promoted to a new case or linked to an existing one, enriched, and handed off to the appropriate response subflow — all without analyst intervention.

Business problem solved: Eliminates the manual alert triage cycle. Analysts receive fully formed, enriched cases rather than raw detections, reducing mean time to triage and freeing capacity for investigation.

Integrations: Blink Case Management, CrowdStrike, Recorded Future

Playbook Executions (12mo) Type Notes
Process Alert 5,667 Event Top-level orchestrator triggered on every new alert
Subflow 1 - Extract Observables 5,691 On-demand Parses alert payload, extracts IPs/hashes/users/domains via Jinja templates
Subflow 2 - Create Case 5,659 On-demand Creates a new case or skips if dedup rule matches
Subflow 2.1 - Get Deduplication Rule 5,659 On-demand Looks up POSIX-regex dedup rules from a config table
Subflow 2.2 - Check for Case Deduplicates 5,659 On-demand Checks for open matching cases using global variable locking
Subflow 2.3 - Link Alert to Existing Case 3,149 On-demand Links duplicate alert to open case; escalates severity if higher
Subflow 3 - Enrich Observable 7,431 On-demand Routes each observable to the appropriate enrichment subflow by type
Subflow 4 - Response 5,620 On-demand Branches response by vendor (CrowdStrike, Abnormal) and severity
Recovery - Handle Unprocessed Alerts 160 Scheduled Runs every 6 hours to catch alerts stuck mid-processing
Subflow - Missing Alert Template Notification 4 On-demand Notifies the SOC when an alert arrives with no matching template

2. Multi-Source Alert Ingestion

Category: SOC | Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring

Description: Normalized alert ingestion from eight security tooling sources. Each playbook receives raw detections via webhook or scheduled polling, normalizes the payload, and creates a standardized Blink alert that feeds the processing pipeline.

Business problem solved: Consolidates a fragmented detection landscape into a single case management queue with consistent alert structure, eliminating source-specific analyst workflows.

Integrations: CrowdStrike Falcon, Falcon LogScale, Varonis, Cribl, Wiz, Abnormal (shared mailbox), Akamai

Playbook Executions (12mo) Type Source
CrowdStrike FIM Notification 1,856 Event (webhook) CrowdStrike File Integrity Monitoring
Crowdstrike ingest alert JCP 1,543 Event (webhook) CrowdStrike endpoint detections
LogScale Alert Ingestion 1,085 Event (webhook) CrowdStrike Falcon LogScale
Varonis Alert Ingestion 449 Event (webhook) Varonis data security platform
Shared Mailbox Alert Ingestion 641 Scheduled (hourly) Microsoft Outlook shared security mailbox
Cribl Alerts Ingestion 131 Event (webhook) Cribl SIEM pipeline
Wiz Alerts Ingestion 96 Event (webhook) Wiz cloud security platform
On Crowdstrike Webhook - TVM Reports 45 Event (webhook) CrowdStrike TVM vulnerability reports
Shared Mailbox Case Enhancements 7 Event Enriches mailbox-sourced cases with formatted card
Akamai Alert Ingestion 0 Event (webhook) Akamai WAF/CDN — configured, not yet active
EXAMPLE Ingest - Crowdstrike Trigger 0 Event (webhook) Reference/template playbook

3. ITSM Integration — BMC Remedy

Category: SOC | Subcategories: Case mgmt & SOAR

Description: Bidirectional integration between BMC Remedy and Blink Case Management. Incidents and work orders are polled from Remedy and created as Blink cases; status changes in Blink are reflected back to Remedy. Analyst assignments are synced to keep both systems aligned.

Business problem solved: Eliminates dual-entry for the SecOps team who work across Blink and the enterprise ITSM system. Ensures Remedy tickets always reflect the current state of Blink cases without manual updates.

Integrations: BMC Remedy, Blink Case Management

Playbook Executions (12mo) Type Notes
BMC Remedy - Incident Ingestion 5,760 Scheduled (every 10 min) Polls open SecOps incidents from Remedy
BMC Remedy - Work Order Ingestion 1,920 Scheduled (every 30 min) Polls open SecOps work orders from Remedy
BMC Remedy - Case Synchronization 136 Event Syncs Blink case status changes back to Remedy
Subflow - Update BMC Remedy Record 141 On-demand Updates work log and assignment in Remedy
BMC Remedy - Reprocess Records 120 Scheduled (every 8 hrs) Retries failed Remedy sync records
BMC Remedy - Populate User List 40 Scheduled (nightly) Refreshes SOC user list from Remedy for assignment
BMC Remedy - Populate Support Groups 40 Scheduled (nightly) Refreshes support group data for routing logic
BMC Remedy - Case Action - Add Work Log Update 5 On-demand Manual action to push a work log note to Remedy
BMC Remedy - Create Work Order 1 On-demand Creates a new Remedy work order from a Blink case

4. Phishing Detection & Response (Abnormal)

Category: SOC | Subcategories: Phishing detection & response

Description: Full-lifecycle phishing automation powered by Abnormal Security. Covers three distinct threat categories — phishing, account takeover, and suspicious activity — with automated case creation, email header extraction, threat enrichment, and advisory email dispatch to affected users.

Business problem solved: Removes the bottleneck of manual phishing triage. Analysts receive pre-enriched phishing cases complete with original email headers, sender analysis, and a contextualized advisory already drafted for the affected user.

Integrations: Abnormal Security, Blink Case Management, Email

Playbook Executions (12mo) Type Notes
Phishing Email Analysis 960 Scheduled (hourly) Fetches new phishing cases from Abnormal, creates Blink alerts
Abnormal- Account Takeover 960 Scheduled (hourly) Fetches account takeover cases from Abnormal
Abnormal- Suspicious Activity 960 Scheduled (hourly) Fetches suspicious email activity cases from Abnormal
Abnormal phishing enrichment 858 Event Triggered on new phishing case; adds enrichment comment
Response - Extract Message Headers - Abnormal 849 On-demand Fetches raw email, parses headers, attaches to case as artifact
Send Phishing Advisory Email 269 On-demand Sends a branded advisory email to the targeted user

5. IOC & Observable Enrichment

Category: SOC | Subcategories: Alert enrichment / IOC lookup

Description: Automated enrichment of observables extracted from security alerts. Covers IPs, file hashes, URLs, domains, usernames, and devices using VirusTotal, MISP, OneLogin, CrowdStrike, and a multi-source on-demand IOC engine. User enrichment cross-references JCPenney and SPARC directories.

Business problem solved: Eliminates manual IOC lookup during investigation. Every observable attached to a case arrives pre-scored and contextualized, reducing the analyst investigation cycle from minutes to seconds.

Integrations: VirusTotal, MISP, OneLogin, CrowdStrike, Active Directory (LDAP)

Playbook Executions (12mo) Type Notes
Subflow 3 - Enrich Observable 7,431 On-demand Routes each observable type to the correct enrichment subflow
Enrichment - User 1,257 On-demand Aggregates user context from JCPenney and SPARC directories
Query - User - JCPenney 1,257 On-demand Looks up user via OneLogin, CrowdStrike, and LDAP
Enrich - User - Crowdstrike 1,169 On-demand Retrieves user's CrowdStrike endpoint history
Enrich - Device - Crowdstrike 904 On-demand Retrieves full device profile from CrowdStrike
New observable auto enrich 937 Event Triggered on new observables; checks MISP and tags RHISAC-vetted IOCs
Query - User - SPARC 386 On-demand Looks up users in the SPARC retail brand directory
Enrich - User - Onelogin 166 On-demand Fetches OneLogin profile and 90-day event history
Enrichment - Hash 187 Event Auto-enriches new File Hash observables via VirusTotal
OneLogin Detailed Enrichment 44 On-demand Detailed OneLogin lookup by email or user ID
Enrichment - External IP 44 Event Auto-enriches new External IP observables via VirusTotal
VT - Enrich URL 81 On-demand Scans URL via VirusTotal and appends verdict to case overview
OnDemand IOC Enrichment 30 On-demand Multi-source IOC enrichment router (IP, hash, URL)
On Demand Enrichment - IP 3 On-demand VirusTotal IP lookup triggered manually
Lookup email 4 On-demand LDAP lookup against JCPenney Active Directory
Enrich - Hash - VT 0 On-demand VirusTotal hash enrichment (CM showcase workspace)
Enrich - IP - VT 0 On-demand VirusTotal IP enrichment (CM showcase workspace)
Enrich - IP - IPDB 0 On-demand AbuseIPDB lookup (CM showcase workspace)
Enrich - URL - VT 0 On-demand VirusTotal URL enrichment (CM showcase workspace)

6. Recorded Future Threat Intelligence

Category: SOC | Subcategories: Threat intel ingest & curation

Description: Deep threat intelligence enrichment for every active case using Recorded Future. Automatically scores IPs, file hashes, and domains and augments case timelines with threat actor context. Monthly risk metrics are collected for executive reporting.

Business problem solved: Provides instant threat actor attribution and risk context at case open time, reducing the research burden on analysts and enabling faster escalation decisions.

Integrations: Recorded Future

Playbook Executions (12mo) Type Notes
Recorded Future - Main Case Automation 2,524 Event Triggers on every new case; enriches observables with RF intel
Recorded Future - Enrich Hash 1,487 On-demand Hash risk score, malware family, and threat actor attribution
Recorded Future - Enrich IP Address 812 On-demand IP reputation, geolocation, and threat actor context
Recorded Future - Enrich Domains 80 On-demand Domain risk score and threat intel context
Recorded Future - Enrich URLs 3 On-demand URL risk analysis
Recorded Future - Metrics 2 Scheduled (monthly) Collects RF risk scores across 12 entity types for reporting

7. Identity Threat Response

Category: SOC | Subcategories: Identity threat response

Description: Automated response actions targeting compromised or high-risk user accounts. Supports session revocation, account sign-in blocking, and password resets across Microsoft Entra ID and OneLogin, with full audit logging of all actions taken.

Business problem solved: Reduces attacker dwell time following account compromise by executing containment actions in seconds rather than waiting for manual IT intervention.

Integrations: Microsoft Entra ID, OneLogin

Playbook Executions (12mo) Type Notes
High Risk - User Response Actions 60 On-demand Orchestrator for multi-action user response; writes full audit record
Subflow - Revoke User Sessions - Microsoft Entra ID 52 On-demand Kills all active Entra ID sessions for a user
Subflow - Block User Sign-ins - Microsoft Entra ID 19 On-demand Disables sign-in access in Entra ID
Subflow - Reset User Password - Microsoft Entra ID 18 On-demand Forces password reset in Entra ID
Subflow - Revoke User Sessions - Onelogin 20 On-demand Kills all active OneLogin sessions for a user
Subflow - Reset User Password - Onelogin 9 On-demand Forces OneLogin password reset
Revoke user sessions in Entra ID 0 On-demand Standalone Entra ID session revoke (alternate workspace)

8. EDR Containment & Host Response

Category: SOC | Subcategories: EDR containment & response

Description: CrowdStrike-driven host containment and response actions across all Catalyst Brands entities (JCPenney, Lucky Brands, Eddie Bauer, Brooks Brothers). Supports network isolation, USB policy enforcement, sandbox file submission, Real Time Response (RTR) command execution, and bidirectional alert closure. Uses a brand-aware connection table to route actions to the correct CrowdStrike tenant.

Business problem solved: Enables the SOC to contain endpoint threats across multiple retail brands from a single Blink case, without manually switching between brand-specific CrowdStrike consoles.

Integrations: CrowdStrike Falcon (multi-tenant)

Playbook Executions (12mo) Type Notes
Close Relevant CrowdStrike Alert 681 Event Auto-closes CrowdStrike alerts when Blink case is closed
Crowdstrike overview detailer 3,408 On-demand Fetches and formats detailed CrowdStrike alert context for case overview
Crowdtrike - get relevant connection 1,420 On-demand Resolves the correct CrowdStrike tenant connection by brand name
Isolate CrowdStrike 7 On-demand Network-isolates hosts by brand across multi-tenant CrowdStrike
Isolate Crowdstrike Subflow 7 On-demand Executes per-host containment action
CrowdStrike - Fetch User Information (Asset/IP) 5 On-demand Lists devices associated with a user or IP across brands
Crowdstrike - Network/Isolate Host 3 On-demand Network-isolates a host by brand and hostname
Crowdstrike - USB Block 1 On-demand Blocks USB storage on specified hosts via host group policy
Crowdstrike - USB Allow 0 On-demand Removes USB block
Crowdstrike - Remove Network Containment of Host 0 On-demand Lifts network isolation
Crowdstrike - Submit file to Sandbox (On Demand) 0 On-demand Submits file to CrowdStrike sandbox and attaches HTML report
Crowdstrike - Submit file to Sandbox (Case Management) 0 On-demand Case-integrated sandbox submission
Utility - Execute RTR Action - CrowdStrike 1 On-demand Enriches device context, validates RTR session criteria, and executes a Real Time Response action against a host

9. Case Management & Analyst Workflow

Category: SOC | Subcategories: Case mgmt & SOAR

Description: Operational workflows supporting day-to-day analyst workflow: shift-based case assignment, SLA monitoring and breach notification, case escalation, high-severity alerting, shift summaries, multi-geo detection, and pending case reporting.

Business problem solved: Keeps the SOC running in rhythm — cases are always assigned to the right analyst for the current shift, SLAs are actively monitored, and managers receive automated visibility without pulling manual reports.

Integrations: Blink Case Management, Email, Blink Users/Groups API

Playbook Executions (12mo) Type Notes
Assign to current shift 2,462 On-demand Reads shift schedule table and assigns case to on-call analyst
High/Critical Alert Notification 1,736 Event Sends email on case open when severity is High or Critical
SLA Breach Notification 56 Event Emails SOC on SLA expiry for severity 3/4 cases
Shift Summary 122 On-demand Generates a case summary for a specified shift window
Pending Case Summary 40 Scheduled (daily) Emails a daily open-case status report to the SOC
Escalate Case - Catalyst 7 On-demand Escalates a case to a higher analyst tier with email notification
Escalate Case to TVM 8 On-demand Transfers case ownership to the TVM team with share + email
Shift Schedule Upload 2 On-demand Parses and loads a shift schedule file into the scheduling table
Multi-Geo Detection 2 Event Flags cases with observables from more than one country
notify user about a task 5 On-demand Notifies an analyst of a newly assigned task via email
Table Action - Validate Template 10 On-demand Validates Jinja alert templates against live data
Case Data - old Last 30Days 2 Scheduled (monthly) Emails a CSV of last 30 days of case data
Restrict case to tier 3 0 On-demand Locks case visibility to tier-3 analysts only

10. Agentic Threat Hunting

Category: Vulnerability Mgmt | Subcategories: Threat hunting & detection

Description: AI-powered threat hunting using Blink's native agent framework. Analysts submit natural-language hunt requests; AI agents translate them into optimized Cribl and LogScale queries, execute searches, and compile findings into a formatted HTML report. A reference table of prior hunt queries improves agent continuity.

Business problem solved: Reduces the barrier to proactive threat hunting for analysts who lack query expertise, enabling structured hunts without requiring manual SPL/YARA/logscale query authorship.

Integrations: Blink Agents, Cribl, CrowdStrike Falcon LogScale, Email

Playbook Executions (12mo) Type Notes
Threat Hunting Agent 7 On-demand End-to-end hunt: takes request, calls agents, returns HTML report
Cribl Search Query Builder Agent 7 On-demand AI agent that generates optimized Cribl queries from natural language
Crowdstrike LogScale Query Builder Agent 5 On-demand AI agent that generates optimized LogScale queries
Agent Ability - Run Cribl Search Query 29 On-demand Executes a Cribl search job and returns results
Agent Ability - Run LogScale Search Query 19 On-demand Executes a LogScale query and returns results
Agent Ability - Reference Hunt Query Table 12 On-demand Retrieves prior hunt queries to inform agent context

11. Vulnerability Ticket Management (TVM)

Category: Vulnerability Mgmt | Subcategories: Vuln lifecycle prioritize & ticket

Description: Web form-driven vulnerability ticket creation for the Catalyst TVM team, covering all four retail brands. Analysts or TVM engineers submit CVE details, affected brand, severity, and impacted asset list via a structured form; Blink creates the case with full context and routes it appropriately.

Business problem solved: Standardizes vulnerability intake across brands, replacing ad-hoc email or ticket creation with a structured, auditable workflow that feeds directly into the SecOps case queue.

Integrations: Blink Case Management, Blink Web Forms, CrowdStrike (TVM webhook)

Playbook Executions (12mo) Type Notes
On Crowdstrike Webhook - TVM Reports 45 Event (webhook) Ingests CrowdStrike TVM reports as Blink alerts and cases
Escalate Case to TVM 8 On-demand Transfers a SOC case to the TVM team with share + notification
Catalyst TVM - Vuln Ticket Creation 5 Event (web form) Structured form for CVE submission across Lucky Brands, Eddie Bauer, Aero/Nautica, Brooks Brothers

12. Cloud Security Monitoring (Wiz)

Category: Cloud Security | Subcategories: CSPM ingest & triage

Description: Cloud security posture management using Wiz. Alerts are ingested via webhook into the Blink alert pipeline, and daily scheduled queries collect cloud asset and risk metrics for the VSOC dashboard.

Business problem solved: Surfaces cloud security findings in the same analyst queue as endpoint and email threats, ensuring cloud risks are triaged alongside traditional security alerts.

Integrations: Wiz

Playbook Executions (12mo) Type Notes
Wiz Alerts Ingestion 96 Event (webhook) Ingests Wiz issues as Blink alerts via Wiz webhook
Wiz 40 Scheduled (daily) Runs GraphQL queries against Wiz and stores metrics in dashboard tables

13. Cloud Asset Inventory

Category: Cloud Security | Subcategories: Cloud asset coverage & inventory

Description: Bi-monthly asset inventory collection from CMDB (ServiceNow) and runZero network discovery. Assets are fetched, normalized, and written to a central inventory table used by enrichment and response workflows.

Business problem solved: Maintains an up-to-date asset registry that powers device-context enrichment during incidents, ensuring CrowdStrike device lookups and ownership queries have a reliable source of truth.

Integrations: ServiceNow CMDB, runZero

Playbook Executions (12mo) Type Notes
Asset Ingestion Orchestrator 3 Scheduled (1st & 15th) Chains CMDB and runZero asset fetches with sleep buffer
Subflow - Asset Inventory Writer 229 On-demand Upserts asset records to the inventory table in bulk
Subflow - Get Assets - CMDB 2 On-demand Paginates through CMDB and streams assets to writer
Subflow - Get Assets - runZero 3 On-demand Paginates through runZero discovery data and streams to writer

14. DSAR & Privacy Automation

Category: GRC | Subcategories: DSAR & privacy automation

Description: Automated orchestration of Data Subject Access Requests (DSAR) received from OneTrust across multiple retail brands. Incoming requests are ingested, users are looked up and de-identified against the MDM Oracle database, subtasks are created in OneTrust, and super-customer cases are escalated with notifications. The pipeline has been extended with a second, brand-specific OneTrust workspace running the same orchestration pattern, plus new subflows that de-identify/enrich users in the Relate customer data platform and opt users out of downstream marketing platforms (Amperity, LiveRamp).

Business problem solved: Removes manual handoffs in the DSAR fulfillment process, which spans multiple brand databases and privacy workflows. Ensures consistent, auditable handling of privacy rights requests, including opt-out propagation to downstream marketing/CDP platforms.

Integrations: OneTrust, Oracle MDM Database, Relate CDP, Amperity, LiveRamp, Email

Playbook Executions (12mo) Type Notes
Orchestrator - DSAR 15 Event Main DSAR pipeline; triggered on new audit records
OneTrust Webhook for DSAR 2 Event (webhook) Receives OneTrust DSAR webhook and creates audit record
Populate DSAR Brand Profile Registry 3 Scheduled (weekly) Refreshes brand-to-connection mapping from Blink's automation packs
Subflow - Enrich User - MDM 5 On-demand Looks up data subject in Oracle MDM by email/name
Subflow - De-identify User - MDM 2 On-demand Executes de-identification of user data in MDM
Ingest - DSAR Requests - OneTrust 0 On-demand Batch ingest of DSAR requests from OneTrust API
Subflow - Create Subtask - OneTrust 0 On-demand Creates and verifies a fulfillment subtask in OneTrust
Subflow - Super Customer Processing 0 On-demand Escalates VIP/super-customer DSARs via email + OneTrust subtask
Subflow - Enrich User - Relate 0 On-demand User lookup against the Relate customer data platform (UAT)
Subflow - De-identify User - Relate 0 On-demand De-identifies a user's records in the Relate customer data platform
Subflow - Opt-out - Amperity 0 On-demand Opts a user out of the Amperity marketing/CDP platform
Orchestrator - DSAR (Brand 2) 0 Event Parallel DSAR orchestrator for a second brand's OneTrust workspace; polls the dsar_audit table and reconciles brand profile
Ingest - DSAR Requests - OneTrust (Brand 2) 0 On-demand Batch ingest of DSAR requests from the second brand's OneTrust instance
Subflow - Create Subtask - OneTrust (Brand 2) 0 On-demand Creates and retrieves a fulfillment subtask in OneTrust (UAT)
Subflow - Super Customer Notification 0 On-demand Escalates VIP/super-customer DSARs via email and a OneTrust subtask
Subflow - Enrich User - Relate (Brand 2) 0 On-demand User lookup against the Relate customer data platform (UAT) via generated XML query
Subflow - De-identify User - Relate (Brand 2) 0 On-demand De-identifies a user's records in the Relate customer data platform
Subflow - Enrich User - MDM (Brand 2) 0 On-demand User lookup in Oracle MDM via generated SQL query (UAT)
Subflow - De-identify User - MDM (Brand 2) 0 On-demand Executes de-identification of user data in MDM
Subflow - Opt-out - Amperity (Brand 2) 0 On-demand Opts a user out of the Amperity marketing/CDP platform
Subflow - Opt-out - LiveRamp 0 On-demand Opts a user out of the LiveRamp identity resolution platform

15. Security Metrics & Reporting

Category: GRC | Subcategories: Security metrics & reporting

Description: Automated collection of security operations metrics from CrowdStrike (device coverage by brand), Wiz (cloud risk), Abnormal (email threat trends), and Blink's own automation value metrics. Data is written to dashboard tables and emailed to leadership on a daily/monthly cadence.

Business problem solved: Provides continuous, automated visibility into the security posture across all brand environments without requiring manual data pulls from each tool.

Integrations: CrowdStrike, Wiz, Abnormal, Recorded Future, Blink Tables, Email

Playbook Executions (12mo) Type Notes
CrowdStrike - VSOC Metrics 40 Scheduled (daily) Collects device coverage counts per brand across 6 CrowdStrike tenants
Blink Solutions Value Metrics 40 Scheduled (daily) Tracks Blink automation execution metrics for ROI reporting
Wiz 40 Scheduled (daily) Writes cloud security metrics to Wiz dashboard table
WIP - abnormal dashboards 40 Scheduled (daily) Collects Abnormal attack trends, vectors, and impersonation stats
Abnormal - Metrics 2 Scheduled (monthly) Collects monthly Abnormal attack type/strategy breakdowns
Recorded Future - Metrics 2 Scheduled (monthly) Collects monthly RF risk scores across 12 entity types

16. Platform Migration & Environment Testing

Category: Other | Subcategories: SaaS / IT administration, DevOps & release automation

Description: Internal utilities used to migrate Catalyst Brands' automation configuration onto a newer Blink platform version. Historical alerts are replayed from the production workspace into a test workspace to validate parity, and a Python-generated report compares configuration and behavior differences between the two environments ahead of cutover.

Business problem solved: Reduces risk during platform version migrations by validating that a new workspace reproduces production alert-processing behavior before traffic is cut over, replacing manual side-by-side comparison with an automated diff report.

Integrations: Blink Case Management, Email

Playbook Executions (12mo) Type Notes
Migrate Settings to v9 - From Remote WS 0 On-demand Migrates workspace settings (e.g., dedup rules) from a remote workspace to v9; creates a tracking case and emails the result
Subflow - Create Historical Alerts 0 On-demand Bulk-creates historical alert records in the target workspace for replay testing
Main - Replay Historical Alerts from Prod WS 0 On-demand Replays a rolling window of production alerts into the test workspace to validate migration parity
Report Comparing Prod and Testing Differences 0 On-demand Generates and emails a report comparing configuration/behavior differences between production and testing workspaces

Key Observations

Strengths

Mature agentic SOC pipeline. The Process Alert pipeline — spanning five chained subflows with 5,667 top-level executions and 7,431 observable enrichments — represents a production-grade, end-to-end automation that most organizations aspire to but few fully implement. Deduplication, case linking, enrichment, and response all happen without analyst involvement.

Broad multi-source alert coverage. Eight alert sources are integrated and actively firing: CrowdStrike (endpoint + FIM + TVM), Falcon LogScale, Varonis, Cribl, Wiz, Abnormal (shared mailbox), and BMC Remedy. This gives the SOC a single normalized queue regardless of detection origin.

ITSM bidirectionality at scale. The BMC Remedy integration handles 7,680 incident and work order syncs per year, with real-time status synchronization back from Blink. This is the kind of ITSM integration that typically requires middleware; Blink handles it natively.

Phishing automation depth. The Abnormal pipeline doesn't stop at case creation — it extracts raw email headers, attaches them as artifacts, enriches with MISP, and sends branded advisory emails to affected users (269 sent). Few customers implement all three layers.

Multi-brand architecture. The brand-aware CrowdStrike connection routing (via Crowdtrike - get relevant connection, 1,420 executions) elegantly handles the multi-tenant complexity of a holding company with four separate retail brand environments.

Nascent agentic threat hunting. The presence of the Threat Hunting Agent with three AI sub-agents (Cribl, LogScale, and ability tools) signals early investment in the next frontier. With 7 hunt reports generated, the capability is proven and ready for expanded use.

Gaps & Opportunities

CM Showcase workspace underutilized. Workspace 6aba2aef contains a parallel set of subflows (Subflow 1–4, enrichment stubs) with 0 executions. These are likely legacy templates or a development environment. They create confusion in the playbook inventory and should be archived or decommissioned.

Identity response volume is low relative to alert volume. With 5,667 alerts processed, only 60 identity response actions were executed. This likely reflects current human-in-the-loop approval for identity containment — an opportunity to expand automated response for confirmed high-confidence detections.

EDR containment is primarily passive. Of the CrowdStrike containment playbooks, only alert closure (681 runs) is fully automated. Network isolation, USB control, and sandbox submission are on-demand only with near-zero executions — these are configured and ready but not yet automated.

DSAR pipeline is early-stage, and build-out is outpacing adoption. With 15 DSAR orchestrations and the Relate/OneTrust fulfillment subflows at 0 executions, this use case is deployed but not yet running at scale. A second brand-specific OneTrust workspace has since been built with the same orchestration pattern plus new Amperity and LiveRamp opt-out subflows — all currently at 0 executions. The underlying complexity (multi-brand MDM, Oracle DB, CDP opt-out) is built — adoption is the remaining gap.

Threat hunting needs volume. The agent framework is technically sound, but 7 hunts in 12 months suggests awareness or workflow adoption is limiting usage. Scheduling periodic automated hunts (e.g., weekly hunting runs from a pre-approved hunt list) would multiply the value of the existing capability without additional build.

Cloud security automation is limited to ingestion. Wiz alerts are ingested (96) and metrics collected (40/month), but there are no CSPM remediation, cloud asset tagging, or misconfiguration response playbooks. This is a natural next expansion.

Integration Ecosystem

Category Tools
EDR / XDR CrowdStrike Falcon (multi-tenant), CrowdStrike Falcon LogScale
Email Security Abnormal Security
Threat Intelligence Recorded Future, VirusTotal, MISP
Data Security Varonis
Cloud Security Wiz
SIEM / Log Pipeline Cribl, Falcon LogScale
ITSM BMC Remedy
Identity OneLogin, Microsoft Entra ID, Active Directory (LDAP)
Privacy / GRC OneTrust, Relate CDP, Amperity, LiveRamp
Asset Management runZero, ServiceNow CMDB
Network / WAF Akamai (configured)
Internal Blink Case Management, Blink Web Forms, Blink Agents, Email
E New Integrations (detail) 5 added in last 30d

New Integrations Added - Last 30 Days

5 new connections
TenantIntegrationConnection NameAdded
Catalyst Brands ssh liveramp_sftp 2026-08-27
Catalyst Brands oracle_db mdm_uat_database 2026-08-26
Catalyst Brands onetrust onetrust_prod 2026-08-26
Catalyst Brands apikey-auth fortra_http_custom_authentication_connection_cb 2026-08-14
Catalyst Brands gmail mock 2026-08-13