01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC — Alert Processing Pipeline |
| 49.0% | 9 9 active |
| Multi-Source Alert Ingestion |
| 8.0% | 9 9 active |
| ITSM Integration — BMC Remedy |
| 8.0% | 9 9 active |
| Phishing Detection & Response (Abnormal) |
| 3.8% | 5 5 active |
| IOC & Observable Enrichment | 15,479 executions | 14.7% | 19 16 active |
| Recorded Future Threat Intelligence |
| 4.8% | 5 5 active |
| Identity Threat Response |
| 0.2% | 7 7 active |
| EDR Containment & Host Response |
| 6.9% | 13 13 active |
| Case Management & Analyst Workflow |
| 4.0% | 12 12 active |
| Agentic Threat Hunting |
| 0.0% | 6 6 active |
| Vulnerability Ticket Management (TVM) |
| 0.1% | 3 3 active |
| Cloud Security Monitoring (Wiz) |
| 0.1% | 1 1 active |
| Cloud Asset Inventory | 194 executions | 0.2% | 4 4 active |
| DSAR & Privacy Automation |
| 0.1% | 12 12 active |
| Security Metrics & Reporting | 162 executions | 0.2% | 6 6 active |
| Platform Migration & Environment Testing | 0 executions | 0.0% | 4 4 active |
| Total | 105,463 executions | 100% | 124 121 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature agentic SOC pipeline. The Process Alert pipeline — spanning five chained subflows with 5,667 top-level executions and 7,431 observable enrichments — represents a production-grade, end-to-end automation that most organizations aspire to but few fully implement. Deduplication, case linking, enrichment, and response all happen without analyst involvement.
Broad multi-source alert coverage. Eight alert sources are integrated and actively firing: CrowdStrike (endpoint + FIM + TVM), Falcon LogScale, Varonis, Cribl, Wiz, Abnormal (shared mailbox), and BMC Remedy. This gives the SOC a single normalized queue regardless of detection origin.
ITSM bidirectionality at scale. The BMC Remedy integration handles 7,680 incident and work order syncs per year, with real-time status synchronization back from Blink. This is the kind of ITSM integration that typically requires middleware; Blink handles it natively.
Phishing automation depth. The Abnormal pipeline doesn't stop at case creation — it extracts raw email headers, attaches them as artifacts, enriches with MISP, and sends branded advisory emails to affected users (269 sent). Few customers implement all three layers.
Multi-brand architecture. The brand-aware CrowdStrike connection routing (via Crowdtrike - get relevant connection, 1,420 executions) elegantly handles the multi-tenant complexity of a holding company with four separate retail brand environments.
Nascent agentic threat hunting. The presence of the Threat Hunting Agent with three AI sub-agents (Cribl, LogScale, and ability tools) signals early investment in the next frontier. With 7 hunt reports generated, the capability is proven and ready for expanded use.
###
Gaps & Opportunities
CM Showcase workspace underutilized. Workspace 6aba2aef contains a parallel set of subflows (Subflow 1–4, enrichment stubs) with 0 executions. These are likely legacy templates or a development environment. They create confusion in the playbook inventory and should be archived or decommissioned.
Identity response volume is low relative to alert volume. With 5,667 alerts processed, only 60 identity response actions were executed. This likely reflects current human-in-the-loop approval for identity containment — an opportunity to expand automated response for confirmed high-confidence detections.
EDR containment is primarily passive. Of the CrowdStrike containment playbooks, only alert closure (681 runs) is fully automated. Network isolation, USB control, and sandbox submission are on-demand only with near-zero executions — these are configured and ready but not yet automated.
DSAR pipeline is early-stage, and build-out is outpacing adoption. With 15 DSAR orchestrations and the Relate/OneTrust fulfillment subflows at 0 executions, this use case is deployed but not yet running at scale. A second brand-specific OneTrust workspace has since been built with the same orchestration pattern plus new Amperity and LiveRamp opt-out subflows — all currently at 0 executions. The underlying complexity (multi-brand MDM, Oracle DB, CDP opt-out) is built — adoption is the remaining gap.
Threat hunting needs volume. The agent framework is technically sound, but 7 hunts in 12 months suggests awareness or workflow adoption is limiting usage. Scheduling periodic automated hunts (e.g., weekly hunting runs from a pre-approved hunt list) would multiply the value of the existing capability without additional build.
Cloud security automation is limited to ingestion. Wiz alerts are ingested (96) and metrics collected (40/month), but there are no CSPM remediation, cloud asset tagging, or misconfiguration response playbooks. This is a natural next expansion.
Integration Ecosystem
| Category | Tools |
|---|---|
| EDR / XDR | CrowdStrike Falcon (multi-tenant), CrowdStrike Falcon LogScale |
| Email Security | Abnormal Security |
| Threat Intelligence | Recorded Future, VirusTotal, MISP |
| Data Security | Varonis |
| Cloud Security | Wiz |
| SIEM / Log Pipeline | Cribl, Falcon LogScale |
| ITSM | BMC Remedy |
| Identity | OneLogin, Microsoft Entra ID, Active Directory (LDAP) |
| Privacy / GRC | OneTrust, Relate CDP, Amperity, LiveRamp |
| Asset Management | runZero, ServiceNow CMDB |
| Network / WAF | Akamai (configured) |
| Internal | Blink Case Management, Blink Web Forms, Blink Agents, Email |
A Case Management 25,584 cases (12m) | MTTR 8h 18m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Catalyst SecOps | 38,494 | 25,581 | 25,319 | 8h 18m |
| ely@blinkops.com | 15 | 3 | 1 | 31s |
| CM | 2 | 0 | 0 | N/A |
B AI Agents 4 active | 85 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent LogScale | Catalyst SecOps | 30 | 5 | 7,749,906 |
| 2 | Threat Hunting Agent | Catalyst SecOps | 21 | 1 | 4,545,598 |
| 3 | Agent Cribl | Catalyst SecOps | 20 | 3 | 6,612,239 |
| 4 | Agent After Action Report | Catalyst SecOps | 14 | 14 | 1,155,415 |
| 5 | Agent Blink | Catalyst Compliance | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Catalyst SecOps | 85 |
| Catalyst Compliance | 0 |
| Case Management Testing | 0 |
| smohan3@jcp.com | 0 |
| CM | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Monthly Metrics - Leadership | 0 | 0 |
| 2 | Cases Overview | 0 | 0 |
| 3 | Example | 0 | 0 |
| 4 | MITRE Overview | 0 | 0 |
| 5 | SecOps VSOC - Dashboard | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Create Work Order | 0 | 0 |
| 2 | question | 0 | 0 |
| 3 | addd user to to group entra | 0 | 0 |
| 4 | Catalyst TVM - Vulnerability Ticket | 0 | 0 |
D Full Use Case Analysis 16 use cases | 105,541 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts processed end-to-end (detection → case → response) | 5,667 | Process Alert |
| BMC Remedy incidents synced to Blink | 5,760 | BMC Remedy - Incident Ingestion |
| BMC Remedy work orders synced to Blink | 1,920 | BMC Remedy - Work Order Ingestion |
| Cases auto-assigned to on-call analyst via shift schedule | 2,462 | Assign to current shift |
| Cases enriched with Recorded Future threat intelligence | 2,524 | Recorded Future - Main Case Automation |
| CrowdStrike FIM events converted to security alerts | 1,856 | CrowdStrike FIM Notification |
| High/critical severity case notifications sent to SOC | 1,736 | High/Critical Alert Notification |
| CrowdStrike endpoint alerts ingested | 1,543 | Crowdstrike ingest alert JCP |
| Hashes enriched via Recorded Future | 1,487 | Recorded Future - Enrich Hash |
| LogScale alerts ingested | 1,085 | LogScale Alert Ingestion |
| Phishing email cases analyzed and investigated | 960 | Phishing Email Analysis |
| Account takeover cases triaged (Abnormal) | 960 | Abnormal- Account Takeover |
| Suspicious email activity cases triaged (Abnormal) | 960 | Abnormal- Suspicious Activity |
| Phishing cases enriched with full email header analysis | 858 | Abnormal phishing enrichment |
| IPs enriched via Recorded Future | 812 | Recorded Future - Enrich IP Address |
| CrowdStrike alerts auto-closed on case resolution | 681 | Close Relevant CrowdStrike Alert |
| Shared mailbox security emails triaged | 641 | Shared Mailbox Alert Ingestion |
| Email message headers extracted and attached to cases | 849 | Response - Extract Message Headers - Abnormal |
| Varonis data security alerts ingested | 449 | Varonis Alert Ingestion |
| Phishing advisory emails sent to affected users | 269 | Send Phishing Advisory Email |
| Shift summaries generated for SOC handoffs | 122 | Shift Summary |
| Cribl SIEM alerts ingested | 131 | Cribl Alerts Ingestion |
| BMC Remedy case status changes synchronized | 136 | BMC Remedy - Case Synchronization |
| Wiz cloud security alerts ingested | 96 | Wiz Alerts Ingestion |
| High-risk identity response actions executed | 60 | High Risk - User Response Actions |
| SLA breach notifications dispatched | 56 | SLA Breach Notification |
| DSAR privacy requests orchestrated end-to-end | 15 | Orchestrator - DSAR |
| AI-generated threat hunt reports | 7 | Threat Hunting Agent |
| Vulnerability tickets created via web form | 5 | Catalyst TVM - Vuln Ticket Creation |
Use Case Summary
| Use Case | Category | Subcategory | Total Playbooks | Active Playbooks |
|---|---|---|---|---|
| Agentic SOC — Alert Processing Pipeline | SOC | Agentic SOC, Case mgmt & SOAR | 10 | 9 |
| Multi-Source Alert Ingestion | SOC | Case mgmt & SOAR, SIEM & log pipeline monitoring | 11 | 8 |
| ITSM Integration — BMC Remedy | SOC | Case mgmt & SOAR | 9 | 8 |
| Phishing Detection & Response (Abnormal) | SOC | Phishing detection & response | 6 | 6 |
| IOC & Observable Enrichment | SOC | Alert enrichment / IOC lookup | 18 | 11 |
| Recorded Future Threat Intelligence | SOC | Threat intel ingest & curation | 5 | 5 |
| Identity Threat Response | SOC | Identity threat response | 7 | 6 |
| EDR Containment & Host Response | SOC | EDR containment & response | 13 | 6 |
| Case Management & Analyst Workflow | SOC | Case mgmt & SOAR | 13 | 11 |
| Agentic Threat Hunting | Vulnerability Mgmt | Threat hunting & detection | 6 | 6 |
| Vulnerability Ticket Management (TVM) | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket | 3 | 3 |
| Cloud Security Monitoring (Wiz) | Cloud Security | CSPM ingest & triage | 2 | 2 |
| Cloud Asset Inventory | Cloud Security | Cloud asset coverage & inventory | 4 | 3 |
| DSAR & Privacy Automation | GRC | DSAR & privacy automation | 21 | 5 |
| Security Metrics & Reporting | GRC | Security metrics & reporting | 6 | 6 |
| Platform Migration & Environment Testing | Other | SaaS / IT administration, DevOps & release automation | 4 | 0 |
Use Cases
1. Agentic SOC — Alert Processing Pipeline
Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR
Description: The core end-to-end alert automation pipeline. Every inbound alert is automatically parsed to extract observables, checked for deduplication against existing cases, promoted to a new case or linked to an existing one, enriched, and handed off to the appropriate response subflow — all without analyst intervention.
Business problem solved: Eliminates the manual alert triage cycle. Analysts receive fully formed, enriched cases rather than raw detections, reducing mean time to triage and freeing capacity for investigation.
Integrations: Blink Case Management, CrowdStrike, Recorded Future
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Process Alert | 5,667 | Event | Top-level orchestrator triggered on every new alert |
| Subflow 1 - Extract Observables | 5,691 | On-demand | Parses alert payload, extracts IPs/hashes/users/domains via Jinja templates |
| Subflow 2 - Create Case | 5,659 | On-demand | Creates a new case or skips if dedup rule matches |
| Subflow 2.1 - Get Deduplication Rule | 5,659 | On-demand | Looks up POSIX-regex dedup rules from a config table |
| Subflow 2.2 - Check for Case Deduplicates | 5,659 | On-demand | Checks for open matching cases using global variable locking |
| Subflow 2.3 - Link Alert to Existing Case | 3,149 | On-demand | Links duplicate alert to open case; escalates severity if higher |
| Subflow 3 - Enrich Observable | 7,431 | On-demand | Routes each observable to the appropriate enrichment subflow by type |
| Subflow 4 - Response | 5,620 | On-demand | Branches response by vendor (CrowdStrike, Abnormal) and severity |
| Recovery - Handle Unprocessed Alerts | 160 | Scheduled | Runs every 6 hours to catch alerts stuck mid-processing |
| Subflow - Missing Alert Template Notification | 4 | On-demand | Notifies the SOC when an alert arrives with no matching template |
2. Multi-Source Alert Ingestion
Category: SOC | Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring
Description: Normalized alert ingestion from eight security tooling sources. Each playbook receives raw detections via webhook or scheduled polling, normalizes the payload, and creates a standardized Blink alert that feeds the processing pipeline.
Business problem solved: Consolidates a fragmented detection landscape into a single case management queue with consistent alert structure, eliminating source-specific analyst workflows.
Integrations: CrowdStrike Falcon, Falcon LogScale, Varonis, Cribl, Wiz, Abnormal (shared mailbox), Akamai
| Playbook | Executions (12mo) | Type | Source |
|---|---|---|---|
| CrowdStrike FIM Notification | 1,856 | Event (webhook) | CrowdStrike File Integrity Monitoring |
| Crowdstrike ingest alert JCP | 1,543 | Event (webhook) | CrowdStrike endpoint detections |
| LogScale Alert Ingestion | 1,085 | Event (webhook) | CrowdStrike Falcon LogScale |
| Varonis Alert Ingestion | 449 | Event (webhook) | Varonis data security platform |
| Shared Mailbox Alert Ingestion | 641 | Scheduled (hourly) | Microsoft Outlook shared security mailbox |
| Cribl Alerts Ingestion | 131 | Event (webhook) | Cribl SIEM pipeline |
| Wiz Alerts Ingestion | 96 | Event (webhook) | Wiz cloud security platform |
| On Crowdstrike Webhook - TVM Reports | 45 | Event (webhook) | CrowdStrike TVM vulnerability reports |
| Shared Mailbox Case Enhancements | 7 | Event | Enriches mailbox-sourced cases with formatted card |
| Akamai Alert Ingestion | 0 | Event (webhook) | Akamai WAF/CDN — configured, not yet active |
| EXAMPLE Ingest - Crowdstrike Trigger | 0 | Event (webhook) | Reference/template playbook |
3. ITSM Integration — BMC Remedy
Category: SOC | Subcategories: Case mgmt & SOAR
Description: Bidirectional integration between BMC Remedy and Blink Case Management. Incidents and work orders are polled from Remedy and created as Blink cases; status changes in Blink are reflected back to Remedy. Analyst assignments are synced to keep both systems aligned.
Business problem solved: Eliminates dual-entry for the SecOps team who work across Blink and the enterprise ITSM system. Ensures Remedy tickets always reflect the current state of Blink cases without manual updates.
Integrations: BMC Remedy, Blink Case Management
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| BMC Remedy - Incident Ingestion | 5,760 | Scheduled (every 10 min) | Polls open SecOps incidents from Remedy |
| BMC Remedy - Work Order Ingestion | 1,920 | Scheduled (every 30 min) | Polls open SecOps work orders from Remedy |
| BMC Remedy - Case Synchronization | 136 | Event | Syncs Blink case status changes back to Remedy |
| Subflow - Update BMC Remedy Record | 141 | On-demand | Updates work log and assignment in Remedy |
| BMC Remedy - Reprocess Records | 120 | Scheduled (every 8 hrs) | Retries failed Remedy sync records |
| BMC Remedy - Populate User List | 40 | Scheduled (nightly) | Refreshes SOC user list from Remedy for assignment |
| BMC Remedy - Populate Support Groups | 40 | Scheduled (nightly) | Refreshes support group data for routing logic |
| BMC Remedy - Case Action - Add Work Log Update | 5 | On-demand | Manual action to push a work log note to Remedy |
| BMC Remedy - Create Work Order | 1 | On-demand | Creates a new Remedy work order from a Blink case |
4. Phishing Detection & Response (Abnormal)
Category: SOC | Subcategories: Phishing detection & response
Description: Full-lifecycle phishing automation powered by Abnormal Security. Covers three distinct threat categories — phishing, account takeover, and suspicious activity — with automated case creation, email header extraction, threat enrichment, and advisory email dispatch to affected users.
Business problem solved: Removes the bottleneck of manual phishing triage. Analysts receive pre-enriched phishing cases complete with original email headers, sender analysis, and a contextualized advisory already drafted for the affected user.
Integrations: Abnormal Security, Blink Case Management, Email
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Phishing Email Analysis | 960 | Scheduled (hourly) | Fetches new phishing cases from Abnormal, creates Blink alerts |
| Abnormal- Account Takeover | 960 | Scheduled (hourly) | Fetches account takeover cases from Abnormal |
| Abnormal- Suspicious Activity | 960 | Scheduled (hourly) | Fetches suspicious email activity cases from Abnormal |
| Abnormal phishing enrichment | 858 | Event | Triggered on new phishing case; adds enrichment comment |
| Response - Extract Message Headers - Abnormal | 849 | On-demand | Fetches raw email, parses headers, attaches to case as artifact |
| Send Phishing Advisory Email | 269 | On-demand | Sends a branded advisory email to the targeted user |
5. IOC & Observable Enrichment
Category: SOC | Subcategories: Alert enrichment / IOC lookup
Description: Automated enrichment of observables extracted from security alerts. Covers IPs, file hashes, URLs, domains, usernames, and devices using VirusTotal, MISP, OneLogin, CrowdStrike, and a multi-source on-demand IOC engine. User enrichment cross-references JCPenney and SPARC directories.
Business problem solved: Eliminates manual IOC lookup during investigation. Every observable attached to a case arrives pre-scored and contextualized, reducing the analyst investigation cycle from minutes to seconds.
Integrations: VirusTotal, MISP, OneLogin, CrowdStrike, Active Directory (LDAP)
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Subflow 3 - Enrich Observable | 7,431 | On-demand | Routes each observable type to the correct enrichment subflow |
| Enrichment - User | 1,257 | On-demand | Aggregates user context from JCPenney and SPARC directories |
| Query - User - JCPenney | 1,257 | On-demand | Looks up user via OneLogin, CrowdStrike, and LDAP |
| Enrich - User - Crowdstrike | 1,169 | On-demand | Retrieves user's CrowdStrike endpoint history |
| Enrich - Device - Crowdstrike | 904 | On-demand | Retrieves full device profile from CrowdStrike |
| New observable auto enrich | 937 | Event | Triggered on new observables; checks MISP and tags RHISAC-vetted IOCs |
| Query - User - SPARC | 386 | On-demand | Looks up users in the SPARC retail brand directory |
| Enrich - User - Onelogin | 166 | On-demand | Fetches OneLogin profile and 90-day event history |
| Enrichment - Hash | 187 | Event | Auto-enriches new File Hash observables via VirusTotal |
| OneLogin Detailed Enrichment | 44 | On-demand | Detailed OneLogin lookup by email or user ID |
| Enrichment - External IP | 44 | Event | Auto-enriches new External IP observables via VirusTotal |
| VT - Enrich URL | 81 | On-demand | Scans URL via VirusTotal and appends verdict to case overview |
| OnDemand IOC Enrichment | 30 | On-demand | Multi-source IOC enrichment router (IP, hash, URL) |
| On Demand Enrichment - IP | 3 | On-demand | VirusTotal IP lookup triggered manually |
| Lookup email | 4 | On-demand | LDAP lookup against JCPenney Active Directory |
| Enrich - Hash - VT | 0 | On-demand | VirusTotal hash enrichment (CM showcase workspace) |
| Enrich - IP - VT | 0 | On-demand | VirusTotal IP enrichment (CM showcase workspace) |
| Enrich - IP - IPDB | 0 | On-demand | AbuseIPDB lookup (CM showcase workspace) |
| Enrich - URL - VT | 0 | On-demand | VirusTotal URL enrichment (CM showcase workspace) |
6. Recorded Future Threat Intelligence
Category: SOC | Subcategories: Threat intel ingest & curation
Description: Deep threat intelligence enrichment for every active case using Recorded Future. Automatically scores IPs, file hashes, and domains and augments case timelines with threat actor context. Monthly risk metrics are collected for executive reporting.
Business problem solved: Provides instant threat actor attribution and risk context at case open time, reducing the research burden on analysts and enabling faster escalation decisions.
Integrations: Recorded Future
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Recorded Future - Main Case Automation | 2,524 | Event | Triggers on every new case; enriches observables with RF intel |
| Recorded Future - Enrich Hash | 1,487 | On-demand | Hash risk score, malware family, and threat actor attribution |
| Recorded Future - Enrich IP Address | 812 | On-demand | IP reputation, geolocation, and threat actor context |
| Recorded Future - Enrich Domains | 80 | On-demand | Domain risk score and threat intel context |
| Recorded Future - Enrich URLs | 3 | On-demand | URL risk analysis |
| Recorded Future - Metrics | 2 | Scheduled (monthly) | Collects RF risk scores across 12 entity types for reporting |
7. Identity Threat Response
Category: SOC | Subcategories: Identity threat response
Description: Automated response actions targeting compromised or high-risk user accounts. Supports session revocation, account sign-in blocking, and password resets across Microsoft Entra ID and OneLogin, with full audit logging of all actions taken.
Business problem solved: Reduces attacker dwell time following account compromise by executing containment actions in seconds rather than waiting for manual IT intervention.
Integrations: Microsoft Entra ID, OneLogin
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| High Risk - User Response Actions | 60 | On-demand | Orchestrator for multi-action user response; writes full audit record |
| Subflow - Revoke User Sessions - Microsoft Entra ID | 52 | On-demand | Kills all active Entra ID sessions for a user |
| Subflow - Block User Sign-ins - Microsoft Entra ID | 19 | On-demand | Disables sign-in access in Entra ID |
| Subflow - Reset User Password - Microsoft Entra ID | 18 | On-demand | Forces password reset in Entra ID |
| Subflow - Revoke User Sessions - Onelogin | 20 | On-demand | Kills all active OneLogin sessions for a user |
| Subflow - Reset User Password - Onelogin | 9 | On-demand | Forces OneLogin password reset |
| Revoke user sessions in Entra ID | 0 | On-demand | Standalone Entra ID session revoke (alternate workspace) |
8. EDR Containment & Host Response
Category: SOC | Subcategories: EDR containment & response
Description: CrowdStrike-driven host containment and response actions across all Catalyst Brands entities (JCPenney, Lucky Brands, Eddie Bauer, Brooks Brothers). Supports network isolation, USB policy enforcement, sandbox file submission, Real Time Response (RTR) command execution, and bidirectional alert closure. Uses a brand-aware connection table to route actions to the correct CrowdStrike tenant.
Business problem solved: Enables the SOC to contain endpoint threats across multiple retail brands from a single Blink case, without manually switching between brand-specific CrowdStrike consoles.
Integrations: CrowdStrike Falcon (multi-tenant)
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Close Relevant CrowdStrike Alert | 681 | Event | Auto-closes CrowdStrike alerts when Blink case is closed |
| Crowdstrike overview detailer | 3,408 | On-demand | Fetches and formats detailed CrowdStrike alert context for case overview |
| Crowdtrike - get relevant connection | 1,420 | On-demand | Resolves the correct CrowdStrike tenant connection by brand name |
| Isolate CrowdStrike | 7 | On-demand | Network-isolates hosts by brand across multi-tenant CrowdStrike |
| Isolate Crowdstrike Subflow | 7 | On-demand | Executes per-host containment action |
| CrowdStrike - Fetch User Information (Asset/IP) | 5 | On-demand | Lists devices associated with a user or IP across brands |
| Crowdstrike - Network/Isolate Host | 3 | On-demand | Network-isolates a host by brand and hostname |
| Crowdstrike - USB Block | 1 | On-demand | Blocks USB storage on specified hosts via host group policy |
| Crowdstrike - USB Allow | 0 | On-demand | Removes USB block |
| Crowdstrike - Remove Network Containment of Host | 0 | On-demand | Lifts network isolation |
| Crowdstrike - Submit file to Sandbox (On Demand) | 0 | On-demand | Submits file to CrowdStrike sandbox and attaches HTML report |
| Crowdstrike - Submit file to Sandbox (Case Management) | 0 | On-demand | Case-integrated sandbox submission |
| Utility - Execute RTR Action - CrowdStrike | 1 | On-demand | Enriches device context, validates RTR session criteria, and executes a Real Time Response action against a host |
9. Case Management & Analyst Workflow
Category: SOC | Subcategories: Case mgmt & SOAR
Description: Operational workflows supporting day-to-day analyst workflow: shift-based case assignment, SLA monitoring and breach notification, case escalation, high-severity alerting, shift summaries, multi-geo detection, and pending case reporting.
Business problem solved: Keeps the SOC running in rhythm — cases are always assigned to the right analyst for the current shift, SLAs are actively monitored, and managers receive automated visibility without pulling manual reports.
Integrations: Blink Case Management, Email, Blink Users/Groups API
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Assign to current shift | 2,462 | On-demand | Reads shift schedule table and assigns case to on-call analyst |
| High/Critical Alert Notification | 1,736 | Event | Sends email on case open when severity is High or Critical |
| SLA Breach Notification | 56 | Event | Emails SOC on SLA expiry for severity 3/4 cases |
| Shift Summary | 122 | On-demand | Generates a case summary for a specified shift window |
| Pending Case Summary | 40 | Scheduled (daily) | Emails a daily open-case status report to the SOC |
| Escalate Case - Catalyst | 7 | On-demand | Escalates a case to a higher analyst tier with email notification |
| Escalate Case to TVM | 8 | On-demand | Transfers case ownership to the TVM team with share + email |
| Shift Schedule Upload | 2 | On-demand | Parses and loads a shift schedule file into the scheduling table |
| Multi-Geo Detection | 2 | Event | Flags cases with observables from more than one country |
| notify user about a task | 5 | On-demand | Notifies an analyst of a newly assigned task via email |
| Table Action - Validate Template | 10 | On-demand | Validates Jinja alert templates against live data |
| Case Data - old Last 30Days | 2 | Scheduled (monthly) | Emails a CSV of last 30 days of case data |
| Restrict case to tier 3 | 0 | On-demand | Locks case visibility to tier-3 analysts only |
10. Agentic Threat Hunting
Category: Vulnerability Mgmt | Subcategories: Threat hunting & detection
Description: AI-powered threat hunting using Blink's native agent framework. Analysts submit natural-language hunt requests; AI agents translate them into optimized Cribl and LogScale queries, execute searches, and compile findings into a formatted HTML report. A reference table of prior hunt queries improves agent continuity.
Business problem solved: Reduces the barrier to proactive threat hunting for analysts who lack query expertise, enabling structured hunts without requiring manual SPL/YARA/logscale query authorship.
Integrations: Blink Agents, Cribl, CrowdStrike Falcon LogScale, Email
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Threat Hunting Agent | 7 | On-demand | End-to-end hunt: takes request, calls agents, returns HTML report |
| Cribl Search Query Builder Agent | 7 | On-demand | AI agent that generates optimized Cribl queries from natural language |
| Crowdstrike LogScale Query Builder Agent | 5 | On-demand | AI agent that generates optimized LogScale queries |
| Agent Ability - Run Cribl Search Query | 29 | On-demand | Executes a Cribl search job and returns results |
| Agent Ability - Run LogScale Search Query | 19 | On-demand | Executes a LogScale query and returns results |
| Agent Ability - Reference Hunt Query Table | 12 | On-demand | Retrieves prior hunt queries to inform agent context |
11. Vulnerability Ticket Management (TVM)
Category: Vulnerability Mgmt | Subcategories: Vuln lifecycle prioritize & ticket
Description: Web form-driven vulnerability ticket creation for the Catalyst TVM team, covering all four retail brands. Analysts or TVM engineers submit CVE details, affected brand, severity, and impacted asset list via a structured form; Blink creates the case with full context and routes it appropriately.
Business problem solved: Standardizes vulnerability intake across brands, replacing ad-hoc email or ticket creation with a structured, auditable workflow that feeds directly into the SecOps case queue.
Integrations: Blink Case Management, Blink Web Forms, CrowdStrike (TVM webhook)
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| On Crowdstrike Webhook - TVM Reports | 45 | Event (webhook) | Ingests CrowdStrike TVM reports as Blink alerts and cases |
| Escalate Case to TVM | 8 | On-demand | Transfers a SOC case to the TVM team with share + notification |
| Catalyst TVM - Vuln Ticket Creation | 5 | Event (web form) | Structured form for CVE submission across Lucky Brands, Eddie Bauer, Aero/Nautica, Brooks Brothers |
12. Cloud Security Monitoring (Wiz)
Category: Cloud Security | Subcategories: CSPM ingest & triage
Description: Cloud security posture management using Wiz. Alerts are ingested via webhook into the Blink alert pipeline, and daily scheduled queries collect cloud asset and risk metrics for the VSOC dashboard.
Business problem solved: Surfaces cloud security findings in the same analyst queue as endpoint and email threats, ensuring cloud risks are triaged alongside traditional security alerts.
Integrations: Wiz
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Wiz Alerts Ingestion | 96 | Event (webhook) | Ingests Wiz issues as Blink alerts via Wiz webhook |
| Wiz | 40 | Scheduled (daily) | Runs GraphQL queries against Wiz and stores metrics in dashboard tables |
13. Cloud Asset Inventory
Category: Cloud Security | Subcategories: Cloud asset coverage & inventory
Description: Bi-monthly asset inventory collection from CMDB (ServiceNow) and runZero network discovery. Assets are fetched, normalized, and written to a central inventory table used by enrichment and response workflows.
Business problem solved: Maintains an up-to-date asset registry that powers device-context enrichment during incidents, ensuring CrowdStrike device lookups and ownership queries have a reliable source of truth.
Integrations: ServiceNow CMDB, runZero
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Asset Ingestion Orchestrator | 3 | Scheduled (1st & 15th) | Chains CMDB and runZero asset fetches with sleep buffer |
| Subflow - Asset Inventory Writer | 229 | On-demand | Upserts asset records to the inventory table in bulk |
| Subflow - Get Assets - CMDB | 2 | On-demand | Paginates through CMDB and streams assets to writer |
| Subflow - Get Assets - runZero | 3 | On-demand | Paginates through runZero discovery data and streams to writer |
14. DSAR & Privacy Automation
Category: GRC | Subcategories: DSAR & privacy automation
Description: Automated orchestration of Data Subject Access Requests (DSAR) received from OneTrust across multiple retail brands. Incoming requests are ingested, users are looked up and de-identified against the MDM Oracle database, subtasks are created in OneTrust, and super-customer cases are escalated with notifications. The pipeline has been extended with a second, brand-specific OneTrust workspace running the same orchestration pattern, plus new subflows that de-identify/enrich users in the Relate customer data platform and opt users out of downstream marketing platforms (Amperity, LiveRamp).
Business problem solved: Removes manual handoffs in the DSAR fulfillment process, which spans multiple brand databases and privacy workflows. Ensures consistent, auditable handling of privacy rights requests, including opt-out propagation to downstream marketing/CDP platforms.
Integrations: OneTrust, Oracle MDM Database, Relate CDP, Amperity, LiveRamp, Email
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Orchestrator - DSAR | 15 | Event | Main DSAR pipeline; triggered on new audit records |
| OneTrust Webhook for DSAR | 2 | Event (webhook) | Receives OneTrust DSAR webhook and creates audit record |
| Populate DSAR Brand Profile Registry | 3 | Scheduled (weekly) | Refreshes brand-to-connection mapping from Blink's automation packs |
| Subflow - Enrich User - MDM | 5 | On-demand | Looks up data subject in Oracle MDM by email/name |
| Subflow - De-identify User - MDM | 2 | On-demand | Executes de-identification of user data in MDM |
| Ingest - DSAR Requests - OneTrust | 0 | On-demand | Batch ingest of DSAR requests from OneTrust API |
| Subflow - Create Subtask - OneTrust | 0 | On-demand | Creates and verifies a fulfillment subtask in OneTrust |
| Subflow - Super Customer Processing | 0 | On-demand | Escalates VIP/super-customer DSARs via email + OneTrust subtask |
| Subflow - Enrich User - Relate | 0 | On-demand | User lookup against the Relate customer data platform (UAT) |
| Subflow - De-identify User - Relate | 0 | On-demand | De-identifies a user's records in the Relate customer data platform |
| Subflow - Opt-out - Amperity | 0 | On-demand | Opts a user out of the Amperity marketing/CDP platform |
| Orchestrator - DSAR (Brand 2) | 0 | Event | Parallel DSAR orchestrator for a second brand's OneTrust workspace; polls the dsar_audit table and reconciles brand profile |
| Ingest - DSAR Requests - OneTrust (Brand 2) | 0 | On-demand | Batch ingest of DSAR requests from the second brand's OneTrust instance |
| Subflow - Create Subtask - OneTrust (Brand 2) | 0 | On-demand | Creates and retrieves a fulfillment subtask in OneTrust (UAT) |
| Subflow - Super Customer Notification | 0 | On-demand | Escalates VIP/super-customer DSARs via email and a OneTrust subtask |
| Subflow - Enrich User - Relate (Brand 2) | 0 | On-demand | User lookup against the Relate customer data platform (UAT) via generated XML query |
| Subflow - De-identify User - Relate (Brand 2) | 0 | On-demand | De-identifies a user's records in the Relate customer data platform |
| Subflow - Enrich User - MDM (Brand 2) | 0 | On-demand | User lookup in Oracle MDM via generated SQL query (UAT) |
| Subflow - De-identify User - MDM (Brand 2) | 0 | On-demand | Executes de-identification of user data in MDM |
| Subflow - Opt-out - Amperity (Brand 2) | 0 | On-demand | Opts a user out of the Amperity marketing/CDP platform |
| Subflow - Opt-out - LiveRamp | 0 | On-demand | Opts a user out of the LiveRamp identity resolution platform |
15. Security Metrics & Reporting
Category: GRC | Subcategories: Security metrics & reporting
Description: Automated collection of security operations metrics from CrowdStrike (device coverage by brand), Wiz (cloud risk), Abnormal (email threat trends), and Blink's own automation value metrics. Data is written to dashboard tables and emailed to leadership on a daily/monthly cadence.
Business problem solved: Provides continuous, automated visibility into the security posture across all brand environments without requiring manual data pulls from each tool.
Integrations: CrowdStrike, Wiz, Abnormal, Recorded Future, Blink Tables, Email
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| CrowdStrike - VSOC Metrics | 40 | Scheduled (daily) | Collects device coverage counts per brand across 6 CrowdStrike tenants |
| Blink Solutions Value Metrics | 40 | Scheduled (daily) | Tracks Blink automation execution metrics for ROI reporting |
| Wiz | 40 | Scheduled (daily) | Writes cloud security metrics to Wiz dashboard table |
| WIP - abnormal dashboards | 40 | Scheduled (daily) | Collects Abnormal attack trends, vectors, and impersonation stats |
| Abnormal - Metrics | 2 | Scheduled (monthly) | Collects monthly Abnormal attack type/strategy breakdowns |
| Recorded Future - Metrics | 2 | Scheduled (monthly) | Collects monthly RF risk scores across 12 entity types |
16. Platform Migration & Environment Testing
Category: Other | Subcategories: SaaS / IT administration, DevOps & release automation
Description: Internal utilities used to migrate Catalyst Brands' automation configuration onto a newer Blink platform version. Historical alerts are replayed from the production workspace into a test workspace to validate parity, and a Python-generated report compares configuration and behavior differences between the two environments ahead of cutover.
Business problem solved: Reduces risk during platform version migrations by validating that a new workspace reproduces production alert-processing behavior before traffic is cut over, replacing manual side-by-side comparison with an automated diff report.
Integrations: Blink Case Management, Email
| Playbook | Executions (12mo) | Type | Notes |
|---|---|---|---|
| Migrate Settings to v9 - From Remote WS | 0 | On-demand | Migrates workspace settings (e.g., dedup rules) from a remote workspace to v9; creates a tracking case and emails the result |
| Subflow - Create Historical Alerts | 0 | On-demand | Bulk-creates historical alert records in the target workspace for replay testing |
| Main - Replay Historical Alerts from Prod WS | 0 | On-demand | Replays a rolling window of production alerts into the test workspace to validate migration parity |
| Report Comparing Prod and Testing Differences | 0 | On-demand | Generates and emails a report comparing configuration/behavior differences between production and testing workspaces |
Key Observations
Strengths
Mature agentic SOC pipeline. The Process Alert pipeline — spanning five chained subflows with 5,667 top-level executions and 7,431 observable enrichments — represents a production-grade, end-to-end automation that most organizations aspire to but few fully implement. Deduplication, case linking, enrichment, and response all happen without analyst involvement.
Broad multi-source alert coverage. Eight alert sources are integrated and actively firing: CrowdStrike (endpoint + FIM + TVM), Falcon LogScale, Varonis, Cribl, Wiz, Abnormal (shared mailbox), and BMC Remedy. This gives the SOC a single normalized queue regardless of detection origin.
ITSM bidirectionality at scale. The BMC Remedy integration handles 7,680 incident and work order syncs per year, with real-time status synchronization back from Blink. This is the kind of ITSM integration that typically requires middleware; Blink handles it natively.
Phishing automation depth. The Abnormal pipeline doesn't stop at case creation — it extracts raw email headers, attaches them as artifacts, enriches with MISP, and sends branded advisory emails to affected users (269 sent). Few customers implement all three layers.
Multi-brand architecture. The brand-aware CrowdStrike connection routing (via Crowdtrike - get relevant connection, 1,420 executions) elegantly handles the multi-tenant complexity of a holding company with four separate retail brand environments.
Nascent agentic threat hunting. The presence of the Threat Hunting Agent with three AI sub-agents (Cribl, LogScale, and ability tools) signals early investment in the next frontier. With 7 hunt reports generated, the capability is proven and ready for expanded use.
Gaps & Opportunities
CM Showcase workspace underutilized. Workspace 6aba2aef contains a parallel set of subflows (Subflow 1–4, enrichment stubs) with 0 executions. These are likely legacy templates or a development environment. They create confusion in the playbook inventory and should be archived or decommissioned.
Identity response volume is low relative to alert volume. With 5,667 alerts processed, only 60 identity response actions were executed. This likely reflects current human-in-the-loop approval for identity containment — an opportunity to expand automated response for confirmed high-confidence detections.
EDR containment is primarily passive. Of the CrowdStrike containment playbooks, only alert closure (681 runs) is fully automated. Network isolation, USB control, and sandbox submission are on-demand only with near-zero executions — these are configured and ready but not yet automated.
DSAR pipeline is early-stage, and build-out is outpacing adoption. With 15 DSAR orchestrations and the Relate/OneTrust fulfillment subflows at 0 executions, this use case is deployed but not yet running at scale. A second brand-specific OneTrust workspace has since been built with the same orchestration pattern plus new Amperity and LiveRamp opt-out subflows — all currently at 0 executions. The underlying complexity (multi-brand MDM, Oracle DB, CDP opt-out) is built — adoption is the remaining gap.
Threat hunting needs volume. The agent framework is technically sound, but 7 hunts in 12 months suggests awareness or workflow adoption is limiting usage. Scheduling periodic automated hunts (e.g., weekly hunting runs from a pre-approved hunt list) would multiply the value of the existing capability without additional build.
Cloud security automation is limited to ingestion. Wiz alerts are ingested (96) and metrics collected (40/month), but there are no CSPM remediation, cloud asset tagging, or misconfiguration response playbooks. This is a natural next expansion.
Integration Ecosystem
| Category | Tools |
|---|---|
| EDR / XDR | CrowdStrike Falcon (multi-tenant), CrowdStrike Falcon LogScale |
| Email Security | Abnormal Security |
| Threat Intelligence | Recorded Future, VirusTotal, MISP |
| Data Security | Varonis |
| Cloud Security | Wiz |
| SIEM / Log Pipeline | Cribl, Falcon LogScale |
| ITSM | BMC Remedy |
| Identity | OneLogin, Microsoft Entra ID, Active Directory (LDAP) |
| Privacy / GRC | OneTrust, Relate CDP, Amperity, LiveRamp |
| Asset Management | runZero, ServiceNow CMDB |
| Network / WAF | Akamai (configured) |
| Internal | Blink Case Management, Blink Web Forms, Blink Agents, Email |
E New Integrations (detail) 5 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Catalyst Brands | ssh | liveramp_sftp | 2026-08-27 |
| Catalyst Brands | oracle_db | mdm_uat_database | 2026-08-26 |
| Catalyst Brands | onetrust | onetrust_prod | 2026-08-26 |
| Catalyst Brands | apikey-auth | fortra_http_custom_authentication_connection_cb | 2026-08-14 |
| Catalyst Brands | gmail | mock | 2026-08-13 |