01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Fraud Alert System (FAS) Case Intake, Decisioning & Closure |
| 21.7% | 28 28 active |
| DevOps, Release & Data Pipeline Automation |
| 19.3% | 29 27 active |
| Customer Support Case Synchronization |
| 9.9% | 14 14 active |
| SIEM Alert Ingestion & SOC Case Management | 27,928 executions | 8.2% | 94 94 active |
| Interac & E-Transfer Fraud Operations |
| 7.9% | 27 27 active |
| SOC & IT Platform Utilities | 20,414 executions | 6.0% | 32 31 active |
| Identity Threat & Anomalous Login Response |
| 5.9% | 59 59 active |
| AML / KYC Compliance & Identity Verification |
| 5.8% | 21 21 active |
| Alert & Observable Enrichment (IOC Lookups) | 19,193 executions | 5.6% | 38 38 active |
| Malware & EDR Threat Detection |
| 2.8% | 33 33 active |
| Real-Time Transaction Risk & Velocity Monitoring | 8,133 executions | 2.4% | 24 24 active |
| Card & Payment Network Fraud (Stripe / BNPL) |
| 0.8% | 8 8 active |
| Privileged & Just-In-Time Access Management | 2,603 executions | 0.8% | 18 17 active |
| Vulnerable Customer Protection (Elder & Scam-Victim Safeguards) | 2,207 executions | 0.6% | 8 8 active |
| Account Takeover & Registration Abuse Detection | 2,028 executions | 0.6% | 26 26 active |
| Dispute, Indemnity, Insolvency & Write-Off Operations | 1,721 executions | 0.5% | 19 19 active |
| Sardine Fraud-Engine Rule & Merchant Block Management | 1,214 executions | 0.4% | 8 8 active |
| Cloud Access & Firewall Configuration Management | 1,144 executions | 0.3% | 6 6 active |
| Customer Registry & Account Data Maintenance | 960 executions | 0.3% | 8 8 active |
| Cloud Security Posture — AWS Config & CloudTrail Audit | 388 executions | 0.1% | 56 56 active |
| Privacy, Access-Request & Regulatory Reporting | 334 executions | 0.1% | 13 13 active |
| Pre-Authorized Payment & Bill-Pay Fraud Controls | 328 executions | 0.1% | 10 10 active |
| Employee Offboarding Automation | 92 executions | 0.0% | 20 19 active |
| Third-Party Fraud Intelligence & Case Utilities | 91 executions | 0.0% | 4 4 active |
| Employee Onboarding & Directory Provisioning | 61 executions | 0.0% | 8 7 active |
| Endpoint & Device Inventory Hygiene | 15 executions | 0.0% | 4 4 active |
| Access Review & Credential Hygiene | 11 executions | 0.0% | 12 12 active |
| Threat Hunting & Critical Vulnerability Detection | 0 executions | 0.0% | 3 3 active |
| Threat Intelligence Ingestion & Curation | 0 executions | 0.0% | 11 11 active |
| Total | 342,469 executions | 100% | 641 635 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Gap: Vulnerability Management is the thinnest category (4 playbooks, threat hunting and Log4Shell detection only) — there's no evidence of a systematic vuln-scanning-ingest-to-ticket pipeline, which is a natural next area for expansion.
- Integration ecosystem. The program integrates with 45 distinct external systems. The most-used are: Blink Case Management, Slack, AWS, Splunk, Jira, Google Sheets, JumpCloud, Google Workspace, GitHub, AbuseIPDB, VirusTotal, Kustomer, CrowdStrike, Cloudflare, Gmail. Slack, Jira, and AWS anchor the majority of workflows as the primary notification, case-tracking, and infrastructure surfaces.
A Case Management 25,894 cases (12m) | MTTR 6h 38m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Security | 19,466 | 9,804 | 9,777 | 6h 38m |
| Case Management | 16,090 | 16,090 | 2 | 3m |
| Risk | 6 | 0 | 0 | N/A |
| ely@blinkops.com | 3 | 0 | 0 | N/A |
B AI Agents 8 active | 1,868 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | LePookie I | Security | 1,653 | 585 | 214,233,301 |
| 2 | Drama King | Security | 132 | 24 | 2,762,507 |
| 3 | Pouglas | Security | 48 | 0 | 23,576,006 |
| 4 | Formathan | Security | 11 | 0 | 240,227 |
| 5 | Weborah | Security | 10 | 0 | 7,726,355 |
| Workspace | Tasks (12m) |
|---|---|
| Security | 1,866 |
| cameron@blinkops.com | 2 |
| sam.kang@koho.ca | 0 |
| ely@blinkops.com | 0 |
| Case Management | 0 |
C Self-Service & Webforms 0 app runs | 15 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | auto close vs human close | 0 | 0 |
| 2 | test | 0 | 0 |
| 3 | Case MTTR Performance | 0 | 0 |
| 4 | KOHO Custom Use Cases x count | 0 | 0 |
| 5 | test | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | PAP Messages | 15 | 12 |
| 2 | Information Request Intake Guide | 0 | 0 |
| 3 | Emailage Email Drop off | 0 | 0 |
| 4 | Page Security via Incident.io | 0 | 0 |
| 5 | JIRA Automation Triggers | 0 | 0 |
D Full Use Case Analysis 29 use cases | 342,545 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Engineering rollouts tracked and broadcast across Slack & GitHub | 55,146 | Rollout Notification blue |
| Fraud alerts intaken and routed to investigators via Jira | 30,008 | FAS Intake Flow - JIRA |
| Identity-fraud support tickets automatically cross-linked for investigators | 22,197 | Automatic Ticket Linking - ID Fraud |
| Interac e-Transfer fraud alerts ingested and logged for investigation | 19,595 | Interac Inbound FAS Trigger (Production) |
| Customer support comments synced from Kustomer into fraud/ops Jira tickets | 12,867 | Kustomer to IDF - Comments |
| Non-VPN SSO/AWS login anomalies auto-investigated | 9,629 | KOHO-UC-2025.03.31 / KOHO-UC-2025.04.03 - SSO / AWS Login with Non-ZScaler IP |
| Endpoint (EDR) security alerts opened as SOC cases for analyst triage | 9,071 | KOHO-UC-2026.5.27_EDR Alert Detected |
| Known-fraudulent identity documents detected and blocked at onboarding | 5,756 | Onfido Known Fraud Document |
| Duplicate-credit-file identity verification checks completed | 5,756 | Trulioo Duplicate Credit File AUV |
| Resolved fraud cases closed out and stakeholders notified | 5,470 | FAS Offboard flow |
| Fraud-risk signups automatically filed for investigator review | 3,840 | FAR Signups to JIRA |
| Interac fund-recovery requests initiated for misdirected/fraudulent transfers | 2,934 | Interac Recovery Request |
| Accounts automatically suspended on Stripe fraud-warning signals | 1,920 | Stripe Early Fraud Warning Suspensions |
| Non-resident accounts locked to enforce regulatory residency rules | 1,100 | Non-Resident Lock Script |
Use Case Summary
| # | Use Case | Category | Playbooks | 12-mo Executions |
|---|---|---|---|---|
| 1 | Fraud Alert System (FAS) Case Intake, Decisioning & Closure | Other | 28 | 74,194 |
| 2 | DevOps, Release & Data Pipeline Automation | Other | 31 | 65,975 |
| 3 | Customer Support Case Synchronization | Other | 14 | 33,942 |
| 4 | SIEM Alert Ingestion & SOC Case Management | SOC | 120 | 27,930 |
| 5 | Interac & E-Transfer Fraud Operations | Other | 27 | 27,084 |
| 6 | SOC & IT Platform Utilities | Other | 32 | 20,414 |
| 7 | Identity Threat & Anomalous Login Response | SOC | 88 | 20,366 |
| 8 | AML / KYC Compliance & Identity Verification | GRC | 21 | 19,885 |
| 9 | Alert & Observable Enrichment (IOC Lookups) | SOC | 58 | 19,193 |
| 10 | Malware & EDR Threat Detection | SOC | 49 | 9,473 |
| 11 | Real-Time Transaction Risk & Velocity Monitoring | Other | 24 | 8,133 |
| 12 | Card & Payment Network Fraud (Stripe / BNPL) | Other | 8 | 2,685 |
| 13 | Privileged & Just-In-Time Access Management | IAM | 19 | 2,603 |
| 14 | Vulnerable Customer Protection (Elder & Scam-Victim Safeguards) | Other | 8 | 2,207 |
| 15 | Account Takeover & Registration Abuse Detection | Other | 30 | 2,028 |
| 16 | Dispute, Indemnity, Insolvency & Write-Off Operations | Other | 19 | 1,721 |
| 17 | Sardine Fraud-Engine Rule & Merchant Block Management | Other | 8 | 1,214 |
| 18 | Cloud Access & Firewall Configuration Management | Cloud Security | 7 | 1,144 |
| 19 | Customer Registry & Account Data Maintenance | Other | 8 | 960 |
| 20 | Cloud Security Posture — AWS Config & CloudTrail Audit | Cloud Security | 81 | 388 |
| 21 | Privacy, Access-Request & Regulatory Reporting | GRC | 15 | 374 |
| 22 | Pre-Authorized Payment & Bill-Pay Fraud Controls | Other | 10 | 328 |
| 23 | Employee Offboarding Automation | IAM | 22 | 92 |
| 24 | Third-Party Fraud Intelligence & Case Utilities | Other | 4 | 91 |
| 25 | Employee Onboarding & Directory Provisioning | IAM | 8 | 61 |
| 26 | Endpoint & Device Inventory Hygiene | Other | 4 | 15 |
| 27 | Access Review & Credential Hygiene | IAM | 12 | 11 |
| 28 | Threat Hunting & Critical Vulnerability Detection | Vulnerability Mgmt | 4 | 0 |
| 29 | Threat Intelligence Ingestion & Curation | SOC | 13 | 0 |
Use Cases
1. Fraud Alert System (FAS) Case Intake, Decisioning & Closure
Category: Other
Subcategories: Financial & fraud operations
Description:
Ingests fraud alerts from internal risk systems into Jira, applies rules-based decisioning, and manages each case through to closure and stakeholder notification.
Business problem solved:
Without automation, fraud analysts would have to manually create, triage, and close a high volume of fraud alert tickets, slowing response to active fraud and letting cases go stale.
Integrations: Jira · AWS · Google Sheets · Gmail · Kustomer · Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| FAS Intake Flow - JIRA | 30,008 | Ingests new fraud alerts into Jira as structured tickets, forming the intake point for the fraud investigation queue. |
| Automatic Ticket Linking - ID Fraud | 22,197 | Automatically links related Jira tickets for identity-fraud cases so investigators see the full picture without manual cross-referencing. |
| FAS Offboard flow | 5,470 | Closes out resolved fraud alert cases in Jira, notifying stakeholders by email and Slack once the investigation is complete. |
| FAR Signups to JIRA | 3,840 | Automatically files newly flagged fraud-risk signups as Jira tickets, ensuring the fraud review team investigates high-risk new accounts promptly. |
| FAS Decision Tree | 3,839 | Applies rules-based decision logic to incoming fraud alert tickets in Jira to automatically route or prioritize them for investigator action. |
| FAS AUV | 2,935 | Runs automated user verification checks against fraud alert records to validate account details before cases are escalated for review. |
| AUV Greater than or equal 2 thirdp senders new account | 1,920 | Flags new accounts receiving e-transfers from two or more distinct third-party senders, a common fraud indicator. |
| AUV Alerts to JIRA | 960 | Converts unusual account-velocity (AUV) fraud alerts into Jira tickets for investigator follow-up. |
| Closure Email send | 960 | Sends a closure notification email to the customer once their fraud or dispute case has been resolved. |
| FAS Lock Workflow | 758 | Automatically locks customer accounts identified by the Fraud Alert System pending investigation, limiting further fraud exposure. |
| Automatic Ticket Linking - IPO | 644 | Automatically links related Jira tickets for a specific fraud/ops case type to streamline investigation follow-up. |
| EFW Alerts to Jira | 535 | Converts electronic funds withdrawal (EFW) fraud alerts into Jira tickets for investigator follow-up. |
| Fraud Care - AUV | 47 | Pulls fraud case details from Jira and logs them to a shared tracker to support the Fraud Care team's automated user verification checks. |
| AML FAS UAR Update | 40 | Automatically updates AML-related tickets in Jira with the latest user activity report data. |
| FAR Transaction Alerts to JIRA | 40 | Converts real-time transaction fraud alerts into Jira tickets, giving the fraud operations team a structured queue for investigation. |
| AML FAS UAR Update (Manual) | 1 | Manually triggered version that updates AML-related tickets in Jira with the latest user activity report data. |
| Bulk Delete | 0 | Performs bulk deletion of stale fraud-case records or tickets to keep the tracking system clean. |
| Bulk Link Close | 0 | Bulk-closes linked Jira tickets once a related fraud case has been resolved, reducing manual ticket cleanup. |
| Bulk Link Close - Web Form | 0 | Provides a web form so analysts can trigger bulk closure of linked fraud-case tickets on demand. |
| FAS Bulk Close (Closed Accounts) | 0 | Bulk-closes outstanding fraud alert tickets for accounts that have already been closed, keeping the fraud queue focused on active risk. |
| FAS Bulk Close (Reported +100 Days) | 0 | Bulk-closes stale fraud alert tickets that have remained open for more than 100 days, keeping the fraud case backlog manageable. |
| FAS Decision Tree - Manual run | 0 | Provides an on-demand, manually triggered run of the fraud alert decision-tree logic to reprocess or re-route Jira fraud tickets as needed. |
| FAS UAR Check | 0 | Runs a periodic verification check on fraud alert Jira tickets to confirm user account data is accurate before cases are closed. |
| Forward to Fraud Care (FAS) | 0 | Creates and links a Jira ticket to route a case to the Fraud Care team, ensuring flagged issues reach the right fraud investigators. |
| Fraud Care - FAS | 0 | Pulls Fraud Alert System ticket details from Jira to support the Fraud Care team's case handling and reporting. |
| Generate Alert Summary - Web Form | 0 | Generates a plain-language summary of a fraud alert case from Jira through an interactive web form, speeding up investigator review. |
| Generate FAS Summary | 0 | Compiles a summary report of Fraud Alert System tickets from Jira to give leadership visibility into fraud case volume and status. |
| Get Kustomer Convo (Cases) | 0 | Retrieves customer support conversation transcripts tied to fraud case Jira tickets and logs them to a shared tracker for investigator reference. |
2. DevOps, Release & Data Pipeline Automation
Category: Other
Subcategories: DevOps & release automation
Description:
Automates rollout notifications, CI/CD pipeline health checks, and dbt/Redshift data pipeline operations for engineering and data teams.
Business problem solved:
Keeps engineering informed of deployment status in real time and keeps the data warehouse pipeline reliable without manual monitoring.
Integrations: AWS · GitHub · Slack · Blink Case Management · Google Sheets · LaunchDarkly · Terraform Cloud · incident.io
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Rollout Notification blue | 55,146 | Notifies relevant Slack channels and tracks deployment status during blue/green production rollouts, keeping engineering teams informed in real time. |
| Check for long-running CI jobs | 3,841 | Monitors CI pipeline jobs for abnormally long runtimes, helping engineering catch stuck or inefficient builds. |
| Make repository_dispatch call to actions repo | 3,026 | Triggers a downstream GitHub Actions pipeline in another repository to kick off automated build or deployment steps. |
| rollout abort prod | 1,582 | Aborts an in-progress production feature rollout, halting further deployment when an issue is detected. |
| Ping slack user upon failure | 1,263 | Notifies the responsible engineer on Slack when a Terraform Cloud run fails, speeding up infrastructure issue resolution. |
| dbt CI Job Run Metadata Logger | 993 | Logs metadata from each dbt CI job run to track data pipeline reliability and build history. |
| Get Batch Incremental Lineage dbt Prod Data Project | 40 | Pulls incremental data-pipeline lineage information from the production dbt project to help engineering monitor data-model dependencies. |
| Get Model Runtimes dbt Prod Data Project | 40 | Collects model execution runtime metrics from the production dbt data project to help engineering monitor data pipeline performance. |
| rollout abort sandbox | 35 | Aborts an in-progress sandbox/staging feature rollout to stop deployment before issues reach production. |
| guardians-help to match PD rotation massage | 6 | Syncs the current on-call rotation from the incident management system into the Slack notification group, keeping incident paging up to date. |
| dbt Run Failure Retry - CI Master job | 2 | Automatically retries failed dbt CI pipeline runs to reduce manual pipeline babysitting. |
| Send a message to Moe if there are new DB PR | 1 | Notifies an engineer via Slack whenever a new database change pull request is opened, speeding up review turnaround. |
| DBT Info AGENT | 0 | Uses an AI agent to answer questions about dbt data models and pipeline configuration on demand. |
| DBT get encryptions | 0 | Retrieves encryption configuration details from the dbt data pipeline to verify data warehouse security settings. |
| Data - Cancel PID for blink_outliers_user | 0 | Cancels stuck or long-running database queries for the outlier-monitoring process to keep the data warehouse healthy. |
| Data - Create Table In Redshift | 0 | Automates creation of new tables in the Redshift data warehouse to support analytics and reporting pipelines. |
| Data - Delete From Table | 0 | Automates deletion of records from a Redshift data warehouse table as part of scheduled data maintenance. |
| Data - Write Google Sheet to Redshift | 0 | Syncs data from a Google Sheet into the Redshift data warehouse to keep analytics tables current. |
| KOHO-UC-2024.6.3 successful_login_analysis_redshift_query | 0 | Pulls raw login event data from the company's AWS data warehouse to feed the successful-login anomaly detection pipeline. |
| KOHO-UC-2025.5.30 successful_login_analysis_redshift_query | 0 | Pulls raw login event data from the company's AWS data warehouse to feed the successful-login anomaly detection pipeline. |
| Launch Darkly FF Control | 0 | Lets engineers check and control LaunchDarkly feature-flag status directly from Slack, streamlining safe feature rollouts. |
| Production - Redshift fingerprint query Subflow | 0 | Internal subflow that queries the Redshift data warehouse for device and session fingerprint data to enrich security investigations. |
| Redshift Connection Quickstart | 0 | Template workflow validating connectivity to the Redshift data warehouse for other automations to build on. |
| Response CM V9 - KOHO-UC-2024.6.3 successful_login_analysis_redshift_query | 0 | Pulls raw login event data from the AWS Redshift data warehouse to feed the successful-login anomaly analysis workflow. |
| Response CM V9 - KOHO-UC-2024.6.3 successful_login_analysis_redshift_query | 0 | Pulls raw login event data from the AWS Redshift data warehouse to feed the successful-login anomaly analysis workflow. |
| Response CM V9 - KOHO-UC-2025.5.30 successful_login_analysis_redshift_query | 0 | Pulls raw login event data from the AWS Redshift data warehouse to feed the successful-login anomaly analysis workflow. |
| Response CM V9 - KOHO-UC-2025.5.30 successful_login_analysis_redshift_query | 0 | Pulls raw login event data from the AWS Redshift data warehouse to feed the successful-login anomaly analysis workflow. |
| Risk - Create Table In Redshift | 0 | Provisions a data table in the AWS Redshift warehouse to support the fraud/risk team's analytics pipeline. |
| Risk - Write csv Rows to Redshift | 0 | Loads CSV data into the AWS Redshift warehouse to feed the fraud/risk team's reporting and analytics pipeline. |
| Run Git Sizer Report on Repository | 0 | Generates a repository size and health report to help engineering manage source code repository bloat and performance. |
| dbt Run Failure Retry - Main Prod job | 0 | Automatically retries failed dbt production pipeline runs to minimize data pipeline downtime. |
3. Customer Support Case Synchronization
Category: Other
Subcategories: IT helpdesk & ticket routing
Description:
Keeps customer support cases in sync across Kustomer, Jira, and Intercom, creating linked tickets and mirroring comments in both directions so support and fraud/ops teams share one source of truth.
Business problem solved:
Support agents and back-office investigators work in different tools; without sync, case context gets lost and customers get inconsistent updates.
Integrations: Jira · Kustomer · Google Docs · Intercom · Linear
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Kustomer to IDF - Comments | 12,867 | Syncs comments between Kustomer support cases and their linked IDF Jira tickets so both teams stay up to date. |
| JIRA IDF to Kustomer - Comments | 10,665 | Syncs internal case comments into the customer support platform so support agents stay updated without switching tools. |
| L2 Message Sync: Jira to Kustomer | 4,556 | Syncs Jira ticket updates back into Kustomer as customer-facing messages, keeping support agents in the loop. |
| Kustomer to IPO - Case Creation | 1,329 | Automatically creates and updates a Jira ticket in the IPO queue whenever a new customer support case is opened in Kustomer. |
| Kustomer to IDF - Case Creation | 1,243 | Automatically creates a Jira ticket in the IDF queue whenever a new customer support case is opened in Kustomer. |
| Auto-create fax requests in JIRA | 961 | Automatically creates Jira tickets for incoming fax requests so operations can process them without manual entry. |
| Intercom - Alert on Engagement Spike | 960 | Monitors customer support conversation volume in Intercom and alerts the team when engagement unexpectedly spikes. |
| Kustomer to FDTR - Case Creation | 803 | Automatically creates a Jira ticket in the FDTR queue whenever a new customer support case is opened in Kustomer. |
| Create L2 Issues in Linear from Webhook | 409 | Automatically creates Level-2 support issues in Linear from incoming webhook events to route escalated tickets to engineering. |
| Kustomer to IDF - Internal Case Creation | 148 | Creates an internal follow-up case when a Kustomer support conversation requires additional internal handling. |
| Intercom Parser | 1 | Parses incoming Intercom customer conversation data into structured fields for downstream support automation. |
| Get Kustomer Convo (US Referrals) | 0 | Pulls customer support conversations related to the US referral program into a shared document to support program tracking and reporting. |
| Jira to Kustomer | 0 | Pulls ticket details from Jira and forwards them into the customer support platform so agents have unified case context. |
| L2HD Kustomer Webhook | 0 | Receives incoming webhook events from Kustomer to trigger downstream Level-2 help desk processing. |
4. SIEM Alert Ingestion & SOC Case Management
Category: SOC
Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR
Description:
Ingests Splunk-correlated security alerts (web-attack signatures, embargoed-country connections, health checks) into Blink Case Management and runs the SOC's on-call paging, escalation, and case-hygiene operations.
Business problem solved:
A security team can't manually watch every SIEM alert stream and on-call rotation; this keeps the case queue populated, triaged, and routed to the right on-call responder around the clock.
Integrations: Blink Case Management · Splunk · Slack · AbuseIPDB · Cloudflare · PagerDuty · incident.io · Jira · AWS · GitHub · Google Sheets · Notion
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Subflow_Get Case Manager Email | 10,292 | Looks up the on-call case manager's email via incident.io so security escalations reach the right person automatically. |
| Subflow_Convert payload to table | 9,671 | Reformats a raw alert payload into a structured table, making incoming security data easier to process and display in cases. |
| Subflow - Update Enrichment Data | 2,506 | Writes enrichment results, such as reputation and geolocation, back onto the relevant case observable so analysts see full context. |
| Add Emoji Reaction to SOC Case Creation Notification | 1,121 | Adds an emoji acknowledgment reaction when a new SOC case is created so analysts can signal they've seen it. |
| My Glorious King | 745 | Core orchestration engine that repeatedly updates SOC case records as an investigation progresses through its lifecycle. |
| Notify SOC of Case Creation | 590 | Notifies the SOC team when a new security case is created, including a direct link for immediate triage. |
| Process Alert | 519 | Core SOC pipeline that deduplicates incoming alerts and extracts indicators of compromise before routing them to case investigation. |
| Subflow - Response - Main Router | 514 | Acts as the central decision point that routes a security case to the correct automated response playbook based on its type. |
| Receive Feedback on LePookie | 426 | Captures analyst feedback on the LePookie security assistant's responses via Slack to improve the AI agent over time. |
| Subflow_Run Splunk Query | 424 | Runs a Splunk search and retrieves the results, giving other automations and analysts fast access to log data. |
| V9 Response - Splunk ES Alert Processing | 151 | Processes incoming Splunk Enterprise Security alerts and routes them into the automated case response pipeline for triage. |
| Splunk Enterprise SIEM Case Ingestion | 102 | Ingests Splunk Enterprise SIEM alerts and automatically opens enriched security cases, cutting manual triage time for the SOC team. |
| AWS GuardDuty alerts from Splunk | 85 | Ingests AWS GuardDuty threat findings routed through Splunk and automatically opens a SOC case for investigation. |
| SECURE-1125 | 84 | Sends a Slack alert tied to a specific tracked security case, keeping the response team notified in real time. |
| Subflow_Convert Country Code to Country Name | 77 | Translates a raw country code into a readable country name so case details are easier for analysts to interpret. |
| Generic Workflow - Receive Splunk Alerts | 62 | Provides the standard intake path for Splunk security alerts, automatically opening a case in the SOC case-management system for triage. |
| KOHO-UC-2024.5.10 - GitHub Download Activity | 62 | Investigates unusual GitHub download activity by checking the source IP's reputation and opening a case for analyst review. |
| Koho CM V9 - Generic Workflow - Receive Splunk Alerts | 62 | Provides the generic intake pipeline that receives alerts from Splunk and automatically opens a corresponding case for SOC analyst triage. |
| Koho CM V9 - KOHO-UC-2024.5.10 - GitHub Download Activity | 62 | Raises a security alert when unusual GitHub download activity is detected, flagging possible source-code exfiltration for review. |
| Central Page out on Critical case creation | 52 | Automatically pages the on-call responder and alerts Slack when a critical security case is created, ensuring fast response. |
| Daily Security Team Status | 40 | Compiles a daily status summary of open security cases and Jira issues for the security team's operational visibility. |
| KOHO-UC-2024.8.21 Identity_Logs_Analysis | 40 | Extracts and loads identity and authentication log data into an analytics table to feed downstream login-threat detections. |
| PagerDuty - find 24H SLA breach | 40 | Scans PagerDuty incidents to identify ones breaching a 24-hour SLA and triggers a follow-up notification. |
| Splunk Cline Data | 40 | Pulls a scheduled data set from Splunk and loads it into Google Sheets for security reporting and analysis. |
| Response V9 - KOHO-UC-2026.06.24.2_Index Health Check | 33 | Periodically verifies that key SOC log indexes are receiving expected data volumes, alerting the team if log ingestion falls silent. |
| KOHO-UC-2025.1.22_1Password Vault Deletion | 26 | Enriches the source IP behind a 1Password vault deletion event with reputation data to help analysts assess the risk. |
| Koho CM V9 - KOHO-UC-2025.1.22_1Password Vault Deletion | 26 | Enriches the source IP behind a 1Password vault deletion event with reputation data to help analysts assess the risk. |
| Response CM V9 - Generic Workflow - Receive Splunk Alerts | 24 | Central intake workflow that receives Splunk security alerts and routes them into the case management system for triage. |
| Blink CS - Dedup for SQL injection | 6 | Deduplicates SQL-injection alert cases in case management to prevent duplicate investigations of the same attack. |
| KOHO-UC-2024.7.1 | 6 | Runs a scheduled check against Cloudflare edge-network data to monitor for anomalies in company web traffic. |
| SecOps Case Review QA Workflow | 5 | Runs a periodic quality-review pass over closed security cases to confirm analyst work meets SecOps quality standards. |
| VIP List Creation | 5 | Maintains an up-to-date VIP list used by SOC detection rules so high-priority accounts get appropriate alert handling. |
| KOHO-UC-2024.12.13_1Password Export Action | 4 | Investigates a 1Password vault export event by pulling related Splunk logs and checking IP reputation before opening a case. |
| Koho CM V9 - KOHO-UC-2024.12.13 - 1Password Export Action | 4 | Alerts when vault data is exported from 1Password, a sensitive action that could indicate credential exfiltration if unauthorized. |
| Subflow_Get Email from AWS ARN | 4 | Resolves an AWS identity ARN referenced in an alert into a human email address, helping analysts identify who triggered it. |
| KOHO-UC-2024.10.23.8_Potential Successful SQL Injection Attempt Observed | 3 | Opens a case when web application logs show a potentially successful SQL injection attempt against company systems. |
| Koho CM V9 - KOHO-UC-2024.10.23.8 - Potential Successful SQL Injection Attempt Observed | 3 | Alerts when a SQL injection attack against an application appears to have succeeded, requiring urgent investigation of possible data compromise. |
| Response CM V9 - KOHO-UC-2024.10.23.8_Potential Successful SQL Injection Attempt Observed | 3 | Opens and tracks a case when a web application firewall flags a potentially successful SQL injection attempt, ensuring analyst follow-up. |
| Process Alert | 2 | Core SOC pipeline that deduplicates incoming alerts and extracts indicators of compromise before routing them to case investigation. |
| Subflow - Missing Alert Template Notification | 2 | Alerts the SOC team when an incoming alert doesn't match any known template, preventing gaps in automated case handling. |
| Unlink Cases | 2 | Removes an incorrect link between a security case and its associated Jira ticket, keeping case records accurate. |
| Unlink Cases Web Form | 2 | Provides analysts a simple web form to trigger unlinking a case from its Jira ticket without needing engineering help. |
| WIP - Scott - Dynamically Updating GD Cases | 2 | An in-development workflow for dynamically keeping security case records updated as new information arrives. |
| ESCU - AWS Multi-Factor Authentication Disabled - Rule | 1 | Runs a security detection rule that flags when multi-factor authentication is disabled on an AWS account, prompting immediate security review. |
| Cloudflare Rate Limit Exceeded | 0 | Triages Cloudflare rate-limit threshold breaches as potential abuse or DDoS activity and routes them into the SOC alert pipeline. |
| General BlinkOps Case Creation Workflow | 0 | Provides a shared, reusable step that creates a structured case in the security case-management system whenever an alert needs formal tracking. |
| KOHO-UC-2024.10.24.4_Possible Directory Traversal Attempt | 0 | Opens a case when web logs show a possible directory traversal attack attempt against company systems. |
| KOHO-UC-2024.10.24.6_Imminent Threat Deny | 0 | Opens a case whenever the network perimeter blocks a connection flagged as an imminent, high-confidence threat. |
| KOHO-UC-2024.10.25.2_WAF Alerts of Interest | 0 | Opens a case for high-interest web application firewall alerts so they get analyst attention. |
| KOHO-UC-2024.2.1 | 0 | Enriches an open security case with IOC and Cloudflare network data, automatically documenting findings in the case timeline. |
| KOHO-UC-2024.5.1 | 0 | Sends a Slack notification as part of an early iteration of the security automation program. |
| KOHO-UC-2025.04.21_Health Check | 0 | Runs a scheduled health check on the login-detection data pipeline, alerting the team if data ingestion stalls. |
| Koho CM V9 - KOHO-UC-2024.10.21.8 - AWS EC2 Flow Log Deletion | 0 | Flags deletion of AWS EC2 network flow logs, which could indicate an attempt to hide network-based attacker activity. |
| Koho CM V9 - KOHO-UC-2024.10.21.8 - AWS EC2 Flow Log Deletion | 0 | Flags deletion of AWS EC2 network flow logs, which could indicate an attempt to hide network-based attacker activity. |
| Koho CM V9 - KOHO-UC-2024.10.22.1 - Allowed Connection to known US Embargo Country | 0 | Flags network connections permitted to or from countries under US embargo, supporting sanctions-compliance and security monitoring. |
| Koho CM V9 - KOHO-UC-2024.10.22.1 - Allowed Connection to known US Embargo Country | 0 | Flags network connections permitted to or from countries under US embargo, supporting sanctions-compliance and security monitoring. |
| Koho CM V9 - KOHO-UC-2024.10.23.8 - Potential Successful SQL Injection Attempt Observed | 0 | Alerts when a SQL injection attack against an application appears to have succeeded, requiring urgent investigation of possible data compromise. |
| Koho CM V9 - KOHO-UC-2024.10.24.3 - Log4jShell Detection | 0 | Detects exploitation attempts of the Log4Shell vulnerability so the SOC can respond before attackers gain a foothold. |
| Koho CM V9 - KOHO-UC-2024.10.24.3 - Log4jShell Detection | 0 | Detects exploitation attempts of the Log4Shell vulnerability so the SOC can respond before attackers gain a foothold. |
| Koho CM V9 - KOHO-UC-2024.10.24.4 - Possible Directory Traversal Attempt | 0 | Flags directory traversal attack attempts against applications, which could allow attackers to access restricted files. |
| Koho CM V9 - KOHO-UC-2024.10.24.4 - Possible Directory Traversal Attempt | 0 | Flags directory traversal attack attempts against applications, which could allow attackers to access restricted files. |
| Koho CM V9 - KOHO-UC-2024.10.24.6 - Imminent Threat Deny | 0 | Notifies the SOC when a known imminent threat indicator is automatically blocked, confirming protective controls are working as intended. |
| Koho CM V9 - KOHO-UC-2024.10.24.6 - Imminent Threat Deny | 0 | Notifies the SOC when a known imminent threat indicator is automatically blocked, confirming protective controls are working as intended. |
| Koho CM V9 - KOHO-UC-2024.10.25.2 - WAF Alerts of Interest | 0 | Surfaces high-priority web application firewall alerts for analyst review, filtering signal from routine WAF noise. |
| Koho CM V9 - KOHO-UC-2024.10.25.2 - WAF Alerts of Interest | 0 | Surfaces high-priority web application firewall alerts for analyst review, filtering signal from routine WAF noise. |
| Koho CM V9 - KOHO-UC-2024.12.13 - 1Password Export Action | 0 | Alerts when vault data is exported from 1Password, a sensitive action that could indicate credential exfiltration if unauthorized. |
| Koho CM V9 - KOHO-UC-2025.04.21_Health Check | 0 | Runs a scheduled health check on the login-detection data pipeline, alerting the team if data ingestion stalls. |
| Koho CM V9 - KOHO-UC-2025.1.22_1Password Vault Deletion | 0 | Enriches the source IP behind a 1Password vault deletion event with reputation data to help analysts assess the risk. |
| Notify Start of Security Office Hours | 0 | Signals the start of the security team's on-call office hours to align case handling and staffing expectations. |
| Notify on SLA breach | 0 | Checks open case and incident records for SLA breaches and triggers a notification before response deadlines are missed. |
| Page Security On-Call via Incident.io | 0 | Pages the on-call security engineer through Incident.io when a security incident requires immediate attention. |
| PagerDuty - Main Automation | 0 | Creates a PagerDuty incident to escalate a security alert to the on-call responder. |
| PagerDuty On-Call Schedule | 0 | Retrieves the current PagerDuty on-call schedule so security alerts are routed to the right responder. |
| Queen of Threats | 0 | AI agent that researches emerging threats and automatically documents findings and recommendations in Notion for the SOC team. |
| Receive PagerDuty Updates | 0 | Ingests incident status updates from PagerDuty to keep security case records synchronized. |
| Recovery - Handle Unprocessed Alerts | 0 | Safety-net workflow that detects alerts stuck unprocessed in the case system and resubmits them for handling. |
| Response - Cloudflare Rate Limit Exceeded | 0 | Automated SOC playbook that investigates and closes out alerts triggered when a Cloudflare rate limit is exceeded. |
| Response - KOHO-UC-2024.5.10 - GitHub Download Activity | 0 | Investigates suspicious bulk GitHub download activity by checking the source IP's reputation and updating the related security case. |
| Response - KOHO-UC-2025.04.21_Health Check | 0 | Periodic health check that verifies the SOC detection and response pipeline components are functioning correctly. |
| Response CM V9 - KOHO-UC-2024.10.22.1_Allowed Connection to known US Embargo Country | 0 | Flags an allowed network connection to a country under U.S. trade embargo and routes the case to an analyst via Slack for confirmation. |
| Response CM V9 - KOHO-UC-2024.10.22.1_Allowed Connection to known US Embargo Country | 0 | Flags an allowed network connection to a country under U.S. trade embargo and routes the case to an analyst via Slack for confirmation. |
| Response CM V9 - KOHO-UC-2024.10.23.8_Potential Successful SQL Injection Attempt Observed | 0 | Opens and tracks a case when a web application firewall flags a potentially successful SQL injection attempt, ensuring analyst follow-up. |
| Response CM V9 - KOHO-UC-2024.10.24.4_Possible Directory Traversal Attempt | 0 | Opens a case when a directory traversal attack attempt is detected against a web application, enabling prompt analyst triage. |
| Response CM V9 - KOHO-UC-2024.10.24.4_Possible Directory Traversal Attempt | 0 | Opens a case when a directory traversal attack attempt is detected against a web application, enabling prompt analyst triage. |
| Response CM V9 - KOHO-UC-2024.10.24.6_Imminent Threat Deny | 0 | Notifies the SOC when network traffic matching an imminent-threat indicator feed is automatically blocked, logging a case for tracking. |
| Response CM V9 - KOHO-UC-2024.10.24.6_Imminent Threat Deny | 0 | Notifies the SOC when network traffic matching an imminent-threat indicator feed is automatically blocked, logging a case for tracking. |
| Response CM V9 - KOHO-UC-2024.10.25.2_WAF Alerts of Interest | 0 | Triages notable web application firewall alerts by opening a case and notifying the SOC via Slack for manual review. |
| Response CM V9 - KOHO-UC-2024.10.25.2_WAF Alerts of Interest | 0 | Triages notable web application firewall alerts by opening a case and notifying the SOC via Slack for manual review. |
| Response Subflow - Convert payload to table | 0 | Internal helper automation that reformats raw alert data into a structured table for use by other SOC case-management playbooks. |
| Response Subflow - Convert payload to table | 0 | Internal helper automation that reformats raw alert data into a structured table for use by other SOC case-management playbooks. |
| Response Subflow - Get Case Manager Email | 0 | Looks up the on-call case manager's contact details via PagerDuty so SOC playbooks can route notifications and assignments correctly. |
| Response Subflow - Send Slack Notification | 0 | Internal helper automation that standardizes how SOC case notifications are sent to Slack across multiple response playbooks. |
| Response Subflow - Send Slack Notification | 0 | Internal helper automation that standardizes how SOC case notifications are sent to Slack across multiple response playbooks. |
| Response V9 - KOHO-UC-2025.04.21_Health Check | 0 | Runs a periodic health check on the SOC detection pipeline to confirm that alerts and log data are flowing correctly. |
| SECURE-1130 | 0 | Sends a Slack notification for a tracked security case to ensure the right team is alerted as it progresses. |
| Secure URL Screenshot Capture | 0 | Safely captures a screenshot of a suspicious URL so analysts can visually assess a phishing or malicious site without opening it. |
| Security Webhooks | 0 | Provides a central webhook intake point for external security tools to feed alerts into the SOC pipeline. |
| Simulate Multiple Alerts from Different Sources | 0 | Generates synthetic alerts from multiple simulated sources to test how the SOC platform ingests and correlates security cases. |
| Subflow - Missing Alert Template Notification | 0 | Alerts the SOC team when an incoming alert doesn't match any known template, preventing gaps in automated case handling. |
| Subflow - Response - Main Router | 0 | Acts as the central decision point that routes a security case to the correct automated response playbook based on its type. |
| Subflow - Update Enrichment Data | 0 | Writes enrichment results, such as reputation and geolocation, back onto the relevant case observable so analysts see full context. |
| Subflow_Check AWS account ID | 0 | Looks up whether an AWS account ID referenced in an alert belongs to the company, adding that context as a case comment. |
| Subflow_Check AWS account ID | 0 | Looks up whether an AWS account ID referenced in an alert belongs to the company, adding that context as a case comment. |
| Subflow_Convert Country Code to Country Name | 0 | Translates a raw country code into a readable country name so case details are easier for analysts to interpret. |
| Subflow_Convert Epoch Time to EST and PST | 0 | Converts raw timestamp data into Eastern and Pacific time so case timelines are easy for analysts to read. |
| Subflow_Convert Epoch Time to EST and PST | 0 | Converts raw timestamp data into Eastern and Pacific time so case timelines are easy for analysts to read. |
| Subflow_Convert from Epoch time to EST | 0 | Converts a raw timestamp into Eastern time so case records display readable, localized event times. |
| Subflow_Convert from Epoch time to PST | 0 | Converts a raw timestamp into Pacific time so case records display readable, localized event times. |
| Subflow_Convert payload to table | 0 | Reformats a raw alert payload into a structured table, making incoming security data easier to process and display in cases. |
| Subflow_Determine PagerDuty Action | 0 | Decides what PagerDuty action a case should trigger, such as paging, resolving, or escalating, based on its severity and status. |
| Subflow_Get Case Manager Email | 0 | Looks up the on-call case manager's email via incident.io so security escalations reach the right person automatically. |
| Subflow_Splunk Query - With File for Large Queries | 0 | Runs large Splunk searches and retrieves results via file export, supporting investigations that return too much data for a normal query. |
| Subflow_Splunk Query Direct | 0 | Runs a direct Splunk search and returns the results for use in downstream SOC automations and case enrichment. |
| Subflow_Splunk Query Direct with head | 0 | Runs a direct Splunk search limited to top results, giving analysts a quick preview of relevant log data. |
| USE WITH CARE - Reset Case Management Environment | 0 | Provides a controlled way to wipe test data from the case management environment, used cautiously for environment resets. |
| Unblock IP in Cloudflare past wait | 0 | Automatically lifts a previously blocked IP in Cloudflare once its containment wait period has elapsed, restoring access without manual follow-up. |
| Unblock IP in Cloudflare past wait | 0 | Automatically lifts a previously blocked IP in Cloudflare once its containment wait period has elapsed, restoring access without manual follow-up. |
| Update Pager Duty | 0 | Updates PagerDuty and notifies the team in Slack as a security case's status changes, keeping on-call responders informed. |
| Utility - Close Stale Cases | 0 | Automatically closes security cases that have sat inactive past a defined threshold, keeping the case queue clean for analysts. |
| temp production endpoint abuse detection | 0 | Flags abnormal usage of a production API endpoint and alerts the security team in Slack for a closer look. |
5. Interac & E-Transfer Fraud Operations
Category: Other
Subcategories: Financial & fraud operations
Description:
Detects, triages, and recovers funds from fraudulent or misdirected Interac e-Transfer activity, including autodeposit abuse and multi-sender money-transfer fraud.
Business problem solved:
E-Transfer fraud (autodeposit hijacking, flow-through laundering, multi-sender abuse) moves money in real time; Koho needs automated detection and recovery workflows to limit losses before funds are gone.
Integrations: AWS · Jira · Google Sheets · Gmail · Google Workspace
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Interac Inbound FAS Trigger (Production) | 19,595 | Ingests inbound Interac fraud-alert signals in real time and logs them to a shared tracking sheet for the fraud operations team. |
| Interac Recovery Request | 2,934 | Initiates a recovery request for funds sent through a fraudulent or misdirected Interac e-transfer. |
| FAS - No UserRef Update Script | 1,920 | Scans open fraud alert tickets in Jira for missing user reference data and updates them, keeping fraud case records complete for investigators. |
| Interac - Flagged autodeposits Gmail scraper | 960 | Scans inbox emails for flagged Interac e-transfer autodeposit notifications to catch suspicious money-movement activity early. |
| Recovery Request - Reattempt | 960 | Automatically reattempts failed fund-recovery requests tracked in Jira, reducing manual follow-up for the recoveries team. |
| No Userref Email lookup | 240 | Looks up customer email details for e-Transfers that are missing a user reference so the ops team can reconcile the payment. |
| Portal e-transfers No UserRef copy | 167 | Identifies e-Transfer payments received through the customer portal that are missing a user reference, for manual reconciliation. |
| E-transfer Flowthrough reach out | 90 | Coordinates outreach to customers involved in suspicious e-transfer 'flow-through' activity, a common money-mule pattern. |
| 24HR ET Velocity | 40 | Tracks Interac e-transfer velocity over a 24-hour period to identify suspicious money-movement patterns. |
| Etransfer Flowthrough Velocity | 40 | Tracks how quickly incoming e-Transfer funds move back out of accounts, flagging high-velocity flow-through patterns typical of money-mule fraud. |
| IMT Multi-Sender | 40 | Detects Interac Money Transfers received from an unusually high number of distinct senders into one account, a common money-mule fraud pattern. |
| K2K Sender Velocity Report | 40 | Generates a velocity report on Koho-to-Koho money transfers to flag senders showing suspicious transaction patterns. |
| Add to IMT Blocklist | 22 | Adds identified bad actors to an international money-transfer blocklist sourced from a shared tracking sheet. |
| IMT Blocklist Web trigger | 22 | Provides a web-triggered entry point to add senders or recipients to the Interac Money Transfer blocklist, stopping known fraudulent transfers. |
| Gmail event listener | 6 | Watches a shared mailbox for new fraud-related emails and logs each message to a shared tracker so nothing is missed by the team. |
| Etransfer FI Spike Alert | 5 | Monitors incoming Interac e-Transfer volume from a specific financial institution and alerts the fraud team to unusual spikes that may signal a fraud ring. |
| Outbound E-Transfer Block | 2 | Blocks outbound e-Transfer payments flagged as high risk and logs them to a tracking sheet for the fraud team. |
| Interac Flagged Autodeposit Registration | 1 | Registers accounts flagged for suspicious Interac e-transfer autodeposits so they can be tracked for ongoing fraud monitoring. |
| Broken user ref flow | 0 | Identifies and repairs broken user reference records within the fraud data pipeline to maintain data integrity. |
| FAS No UserRef Update | 0 | Batch-updates fraud alert records that are missing a user reference, keeping the fraud case data set accurate and complete. |
| Gmail - Flagged Autodeposits | 0 | Processes emails flagging suspicious Interac e-Transfer autodeposit activity, converting the data for fraud team review. |
| Gmail -Recovery Requests | 0 | Processes incoming account or funds recovery request emails, converting the data so the fraud and support teams can action them. |
| ID Payment Requests - User ref update | 0 | Updates missing user reference data on identity-related payment request tickets in Jira, keeping fraud investigation records accurate. |
| IMT Verification Reach Out | 0 | Coordinates customer outreach through Jira to verify suspicious Interac Money Transfer activity before funds are released. |
| Interac Funds Recovered Event Handler | 0 | Processes notifications when funds from a disputed Interac e-transfer are successfully recovered, closing out the associated case. |
| JIRA User Ref fix | 0 | Corrects mismatched user references across a batch of Jira tickets to maintain accurate ownership records. |
| Jira User Ref Fix - Manual update | 0 | Applies a manual, file-driven bulk correction of incorrect user references on Jira tickets. |
6. SOC & IT Platform Utilities
Category: Other
Subcategories: SaaS / IT administration, IT/OT & network infra monitoring
Description:
Internal utility automations, including error handling and failure notifications, Jira/Slack/Notion administration, and workflow-reliability plumbing, that keep the broader automation program running smoothly.
Business problem solved:
Without shared error-handling and admin utilities, every other automation would need to reinvent failure recovery and notification logic, increasing maintenance burden.
Integrations: Slack · Jira · GitHub · Google Calendar · Notion
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Remove stuck execution from queue | 19,183 | Detects and clears stuck automation executions from the internal processing queue to keep workflows running smoothly. |
| JIRA reprioritize | 960 | Automatically reprioritizes a batch of Jira tickets based on business rules so urgent items surface first. |
| Remove from queue in case failure | 166 | Removes a failed job from the internal automation processing queue and notifies the team via Slack to prevent stuck executions. |
| Issue Type Change | 32 | Automatically updates a Jira ticket's issue type according to business rules to keep records properly categorized. |
| Issue Type Change Web form | 32 | Provides a self-service web form that lets staff trigger the Jira issue-type update automation on demand. |
| Monitoring - Error Handler | 17 | Sends an email and Slack alert whenever an automated workflow errors out, so the team can quickly investigate the failure. |
| Manual Executer | 8 | Generic manual-trigger utility that lets IT run ad hoc automation steps outside of scheduled or event-based triggers. |
| slack channels - according to user | 6 | Looks up which Slack channels a given employee belongs to, supporting internal access and communication reviews. |
| Fetch KOHO Holidays and Events | 5 | Pulls the company holiday and events calendar so downstream automations can account for business closures when scheduling work. |
| List all users - Notion | 5 | Builds and refreshes a table of all workspace users to support administrative reporting and directory syncs with Notion. |
| CHRISM - UI | 0 | Provides a Slack-driven interface to an internal system, letting users trigger predefined actions on demand. |
| Change status page and alert company | 0 | Updates the public status page and alerts the company via Slack when a service incident occurs. |
| Error Handling - Send Error Notification Email | 0 | Sends an email notification to the automation team whenever another playbook fails, ensuring automation errors are caught and fixed quickly. |
| Error Handling - Send Error Notification Email | 0 | Sends an email notification to the automation team whenever another playbook fails, ensuring automation errors are caught and fixed quickly. |
| Get End of Life Date for a Product | 0 | Looks up the end-of-life or end-of-support date for a software product to support IT asset lifecycle and patching decisions. |
| Get Your Slack Name | 0 | A simple utility that looks up and returns the requester's own Slack display name, mainly used to validate automation connectivity. |
| Github - Csv to Json | 0 | Converts a CSV file into JSON and loads it into a data table, supporting downstream automation data preparation. |
| JIRA Automation Trigger - Portal | 0 | Acts as the entry point that routes requests submitted through the self-service portal into the correct Jira automation. |
| JIRA Automation Trigger Web Form | 0 | Provides a web form entry point that triggers the appropriate downstream Jira automation based on submitted details. |
| JIRA Integration | 0 | Provides shared Jira data-conversion logic reused by other automations to keep ticket records in sync. |
| JIRA Manual Link | 0 | Manually links related Jira tickets together so agents have consolidated case history in one place. |
| JIRA bulk close | 0 | Bulk-closes a batch of matching Jira tickets to keep the issue queue clean and up to date. |
| Notify user when failure | 0 | Alerts an engineer via Slack whenever an automation execution fails, so platform issues are triaged quickly. |
| Run Dig Command | 0 | Runs an on-demand DNS lookup to help engineers troubleshoot network or domain resolution issues. |
| Send AWS cost reports via slack | 0 | Generates a scheduled AWS cloud spend report and delivers it to Slack so leadership can track infrastructure costs. |
| Send Message Upon Workflow Error | 0 | Automatically alerts the team in Slack whenever another automation fails, ensuring workflow errors don't go unnoticed. |
| Send Slack Notification | 0 | Provides a reusable building block for sending a Slack notification, used by other automations to keep teams informed. |
| Send message address | 0 | Sends a templated Slack notification containing address information as part of an internal operational process. |
| Send message letters | 0 | Sends a templated Slack notification containing letter/document information as part of an internal operational process. |
| Slack Example | 0 | A sample/reference automation demonstrating how to send a basic Slack message, used for internal testing and training. |
| copy tables | 0 | Copies data between internal Blink tables to support downstream automation and reporting needs. |
| slack message | 0 | A lightweight utility that conditionally logs a message, used as a building block within other Slack-based automations. |
7. Identity Threat & Anomalous Login Response
Category: SOC
Subcategories: Identity threat response
Description:
Detects and investigates suspicious identity activity, including impossible travel, MFA brute force, password spraying, non-VPN SSO/AWS logins, and anomalous AWS IAM account lifecycle events.
Business problem solved:
Credential-based attacks are a top intrusion vector; without automated correlation, these signals would sit unreviewed in log data instead of becoming actionable SOC cases.
Integrations: Blink Case Management · Slack · Splunk · IPWhois · AbuseIPDB · Google Workspace · Okta
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| KOHO-UC-2025.03.31 / KOHO-UC-2025.04.03 - SSO / AWS Login with Non-ZScaler IP | 9,629 | Flags SSO or AWS console logins that don't originate from the corporate VPN egress IPs as a potential account-compromise indicator. |
| Koho CM V9 - KOHO-UC-2025.03.31 / KOHO-UC-2025.04.03 - SSO / AWS Login with Non-ZScaler IP | 7,683 | Flags SSO or AWS console logins that don't originate from the corporate VPN egress IPs as a potential account-compromise indicator. |
| KOHO-UC-2024.10.16.2_Users Impossible Travel Activity | 1,287 | Cross-checks employee sign-in locations against travel records to flag logins that represent impossible or implausible travel. |
| Koho CM V9 - KOHO-UC-2024.10.16.2 - Users Impossible Travel Activity | 1,287 | Correlates login locations to flag impossible-travel logins, prompting analysts to verify whether an account has been compromised. |
| KOHO-UC-2025.9.22.1_Look-alike Domain | 344 | Opens a case when a domain impersonating the company's brand is detected, supporting early phishing and brand-abuse response. |
| Response CM V9 - KOHO-UC-2024.10.16.2_Users Impossible Travel Activity | 82 | Investigates impossible-travel login alerts, where a user logs in from geographically implausible locations in a short window. |
| Response V9 - KOHO-UC-2025.03.31 / KOHO-UC-2025.04.03 - SSO / AWS Login with Non-ZScaler IP | 27 | Detects SSO or AWS console logins that bypass the corporate secure network, flagging potential unauthorized or compromised access. |
| KOHO-UC-2024-12-11.1_Excessive Unsuccessful 1Password Logins | 5 | Investigates repeated failed 1Password logins by checking the source IP's reputation and opening a case when the pattern looks malicious. |
| Koho CM V9 - KOHO-UC-2024-12-11.1 - Excessive Unsuccessful 1Password Logins | 5 | Alerts security analysts when a 1Password account shows repeated failed login attempts, a possible sign of a credential-stuffing or brute-force attack. |
| Response CM V9 - KOHO-UC-2024-12-11.1_Excessive Unsuccessful 1Password Logins | 5 | Automated response playbook for repeated failed 1Password login attempts, a potential credential-stuffing or brute-force indicator. |
| KOHO-UC-2024.6.3 successful_login_analysis_send_to_slack | 3 | Delivers the results of the successful-login anomaly analysis to the security team's Slack channel for visibility. |
| KOHO-UC-2025.5.30 successful_login_analysis_send_to_slack | 3 | Delivers the results of the successful-login anomaly analysis to the security team's Slack channel for visibility. |
| KOHO-UC-2025.7.14.1_Internal Email Credentials Leaked | 3 | Alerts the security team when internal employee email credentials are found exposed in a data leak, prompting a forced reset. |
| KOHO-UC-2024.10.16.1_Potential MFA Brute Force - AWS | 1 | Investigates a potential AWS MFA brute-force attempt by looking up the source IP's location and opening a case for review. |
| Koho CM V9 - KOHO-UC-2024.10.16.1- Potential MFA Brute Force - AWS | 1 | Detects repeated failed multi-factor authentication attempts against AWS accounts that may indicate an active brute-force attack. |
| Response CM V9 - KOHO-UC-2024.10.16.1_Potential MFA Brute Force - AWS | 1 | Investigates suspected MFA brute-force attempts against AWS accounts, enriching the source IP and alerting the SOC via Slack. |
| Adaptive MFA Risk Assessment Toggle | 0 | Toggles adaptive multi-factor authentication risk settings and notifies security in Slack when posture changes. |
| Adaptive MFA Risk Assessment Toggle | 0 | Toggles adaptive multi-factor authentication risk settings and notifies security in Slack when posture changes. |
| Get Adaptive MFA Risk Assessment Setting | 0 | Checks whether risk-based adaptive multi-factor authentication is enabled for the identity provider, supporting investigation of a potential account-takeover attempt. |
| KOHO-UC-2024.10.16.3_Accounts Created in AWS IAM | 0 | Alerts the security team via Slack whenever a new account is created in AWS IAM, so provisioning can be verified as legitimate. |
| KOHO-UC-2024.10.16.4_Account Created Used and Deleted-LST-AWS | 0 | Flags accounts that are created, used, and deleted in rapid succession, a pattern typical of an attacker covering their tracks. |
| KOHO-UC-2024.10.16_Multiple Accounts Removed by Same User-LST-AWS | 0 | Flags when the same user removes multiple accounts in a short window, a potential sign of insider threat or compromise. |
| KOHO-UC-2024.10.21.1_Account Created Used and Deleted-LST-NIX | 0 | Flags accounts that are created, used, and deleted in rapid succession, a pattern typical of an attacker covering their tracks. |
| KOHO-UC-2024.10.23.4_Potential Internal Password Spray | 0 | Flags a burst of failed authentication attempts against internal systems consistent with an internal password-spray attack. |
| KOHO-UC-2024.10.23.5_Potential Password Spray | 0 | Flags a burst of failed authentication attempts across many accounts consistent with a password-spray attack. |
| KOHO-UC-2024.10.24.5_Account Removed from CD Critical Group-LST-AWS | 0 | Alerts when an account is removed from a critical access-control group, ensuring privileged group membership changes are reviewed. |
| KOHO-UC-2024.10.25.1_Excessive Account Lockouts | 0 | Flags an unusually high number of account lockouts, which can indicate a brute-force or password-spray attack in progress. |
| KOHO-UC-2024.6.3 KOHO_successful_login_analysis_upsert | 0 | Keeps the case management system updated with the latest successful-login analysis results so investigators have current data. |
| KOHO-UC-2024.6.3 successful_login_analysis | 0 | Runs the end-to-end successful-login anomaly analysis, correlating login data and raising an alert when suspicious patterns emerge. |
| KOHO-UC-2025.4.9.2_Foreign Login Anomaly Detection | 0 | Flags employee logins originating from unexpected foreign countries as a potential sign of account compromise. |
| KOHO-UC-2025.5.30 KOHO_successful_login_analysis_upsert | 0 | Keeps the case management system updated with the latest successful-login analysis results so investigators have current data. |
| KOHO-UC-2025.5.30 successful_login_analysis | 0 | Runs the end-to-end successful-login anomaly analysis, correlating login data and raising an alert when suspicious patterns emerge. |
| Koho CM V9 - KOHO-UC-2024-12-11.1 - Excessive Unsuccessful 1Password Logins | 0 | Alerts security analysts when a 1Password account shows repeated failed login attempts, a possible sign of a credential-stuffing or brute-force attack. |
| Koho CM V9 - KOHO-UC-2024.10.16 - Multiple Accounts Removed by Same User-LST-AWS | 0 | Flags when a single AWS user removes multiple accounts in a short window, a pattern consistent with insider misuse or compromised admin credentials. |
| Koho CM V9 - KOHO-UC-2024.10.16 - Multiple Accounts Removed by Same User-LST-AWS | 0 | Flags when a single AWS user removes multiple accounts in a short window, a pattern consistent with insider misuse or compromised admin credentials. |
| Koho CM V9 - KOHO-UC-2024.10.16.1- Potential MFA Brute Force - AWS | 0 | Detects repeated failed multi-factor authentication attempts against AWS accounts that may indicate an active brute-force attack. |
| Koho CM V9 - KOHO-UC-2024.10.16.2 - Users Impossible Travel Activity | 0 | Correlates login locations to flag impossible-travel logins, prompting analysts to verify whether an account has been compromised. |
| Koho CM V9 - KOHO-UC-2024.10.16.3 - Accounts Created in AWS IAM | 0 | Alerts the SOC whenever a new AWS IAM account is created, so analysts can confirm the account was authorized. |
| Koho CM V9 - KOHO-UC-2024.10.16.3 - Accounts Created in AWS IAM | 0 | Alerts the SOC whenever a new AWS IAM account is created, so analysts can confirm the account was authorized. |
| Koho CM V9 - KOHO-UC-2024.10.16.4 - Account Created Used and Deleted-LST-AWS | 0 | Flags the suspicious pattern of an AWS account being created, used, and deleted in quick succession, a common attacker technique to cover tracks. |
| Koho CM V9 - KOHO-UC-2024.10.16.4 - Account Created Used and Deleted-LST-AWS | 0 | Flags the suspicious pattern of an AWS account being created, used, and deleted in quick succession, a common attacker technique to cover tracks. |
| Koho CM V9 - KOHO-UC-2024.10.21.1 - Account Created Used and Deleted-LST-NIX | 0 | Flags the suspicious pattern of a Linux/Unix account being created, used, and deleted in quick succession, a common attacker technique to cover tracks. |
| Koho CM V9 - KOHO-UC-2024.10.21.1 - Account Created Used and Deleted-LST-NIX | 0 | Flags the suspicious pattern of a Linux/Unix account being created, used, and deleted in quick succession, a common attacker technique to cover tracks. |
| Koho CM V9 - KOHO-UC-2024.10.23.4 - Potential Internal Password Spray | 0 | Detects password-spray style login attempts originating from inside the corporate network, a technique used to avoid external lockout policies. |
| Koho CM V9 - KOHO-UC-2024.10.23.4 - Potential Internal Password Spray | 0 | Detects password-spray style login attempts originating from inside the corporate network, a technique used to avoid external lockout policies. |
| Koho CM V9 - KOHO-UC-2024.10.23.5 - Potential Password Spray | 0 | Detects a password-spray attack pattern, where an attacker tries common passwords across many accounts to avoid lockouts. |
| Koho CM V9 - KOHO-UC-2024.10.23.5 - Potential Password Spray | 0 | Detects a password-spray attack pattern, where an attacker tries common passwords across many accounts to avoid lockouts. |
| Koho CM V9 - KOHO-UC-2024.10.24.5 - Account Removed from CD Critical Group-LST-AWS | 0 | Alerts when a user account is removed from a critical directory security group, ensuring unauthorized privilege changes are caught quickly. |
| Koho CM V9 - KOHO-UC-2024.10.24.5 - Account Removed from CD Critical Group-LST-AWS | 0 | Alerts when a user account is removed from a critical directory security group, ensuring unauthorized privilege changes are caught quickly. |
| Koho CM V9 - KOHO-UC-2024.10.25.1 - Excessive Account Lockouts | 0 | Flags an unusual spike in account lockouts, which can indicate a brute-force attack or a widespread authentication issue. |
| Koho CM V9 - KOHO-UC-2024.10.25.1 - Excessive Account Lockouts | 0 | Flags an unusual spike in account lockouts, which can indicate a brute-force attack or a widespread authentication issue. |
| Koho CM V9 - KOHO-UC-2024.6.3 successful_login_analysis | 0 | Raises a security alert when analysis of successful employee logins uncovers a suspicious pattern worth investigating. |
| Koho CM V9 - KOHO-UC-2024.6.3 successful_login_analysis | 0 | Raises a security alert when analysis of successful employee logins uncovers a suspicious pattern worth investigating. |
| Koho CM V9 - KOHO-UC-2025.4.9.2_Foreign Login Anomaly Detection | 0 | Flags employee logins originating from unexpected foreign countries as a potential sign of account compromise. |
| Koho CM V9 - KOHO-UC-2025.5.30 successful_login_analysis | 0 | Raises a security alert when analysis of successful employee logins uncovers a suspicious pattern worth investigating. |
| Koho CM V9 - KOHO-UC-2025.5.30 successful_login_analysis | 0 | Raises a security alert when analysis of successful employee logins uncovers a suspicious pattern worth investigating. |
| Okta Search for User Activity | 0 | Pulls a user's Okta login and activity history to support an identity-related security investigation. |
| Response - KOHO-UC-2025.03.31 / KOHO-UC-2025.04.03 - SSO / AWS Login with Non-ZScaler IP | 0 | Detects SSO or AWS console logins that bypass the corporate ZScaler network path, flagging potential unauthorized access attempts. |
| Response - KOHO-UC-2025.4.9.2_Foreign Login Anomaly Detection | 0 | Investigates and updates the case record when a user logs in from an unexpected foreign country, a possible account compromise indicator. |
| Response CM V9 - KOHO-UC-2024-12-11.1_Excessive Unsuccessful 1Password Logins | 0 | Automated response playbook for repeated failed 1Password login attempts, a potential credential-stuffing or brute-force indicator. |
| Response CM V9 - KOHO-UC-2024.10.16.1_Potential MFA Brute Force - AWS | 0 | Investigates suspected MFA brute-force attempts against AWS accounts, enriching the source IP and alerting the SOC via Slack. |
| Response CM V9 - KOHO-UC-2024.10.16.2_Users Impossible Travel Activity | 0 | Investigates impossible-travel login alerts, where a user logs in from geographically implausible locations in a short window. |
| Response CM V9 - KOHO-UC-2024.10.16.3_Accounts Created in AWS IAM | 0 | Alerts the SOC when a new AWS IAM account is created outside expected change processes, a potential unauthorized access indicator. |
| Response CM V9 - KOHO-UC-2024.10.16.3_Accounts Created in AWS IAM | 0 | Alerts the SOC when a new AWS IAM account is created outside expected change processes, a potential unauthorized access indicator. |
| Response CM V9 - KOHO-UC-2024.10.16.4_Account Created Used and Deleted-LST-AWS | 0 | Flags the suspicious pattern of an AWS account being created, used, and deleted in quick succession, a sign of covering tracks. |
| Response CM V9 - KOHO-UC-2024.10.16.4_Account Created Used and Deleted-LST-AWS | 0 | Flags the suspicious pattern of an AWS account being created, used, and deleted in quick succession, a sign of covering tracks. |
| Response CM V9 - KOHO-UC-2024.10.16: Multiple Accounts Removed by Same User-LST-AWS | 0 | Detects when a single user deletes multiple AWS accounts in a short window, a potential insider threat or sabotage signal. |
| Response CM V9 - KOHO-UC-2024.10.16: Multiple Accounts Removed by Same User-LST-AWS | 0 | Detects when a single user deletes multiple AWS accounts in a short window, a potential insider threat or sabotage signal. |
| Response CM V9 - KOHO-UC-2024.10.21.1_Account Created Used and Deleted-LST-NIX | 0 | Flags the suspicious pattern of a Linux/Unix system account being created, used, and deleted quickly, a sign of covering tracks. |
| Response CM V9 - KOHO-UC-2024.10.21.1_Account Created Used and Deleted-LST-NIX | 0 | Flags the suspicious pattern of a Linux/Unix system account being created, used, and deleted quickly, a sign of covering tracks. |
| Response CM V9 - KOHO-UC-2024.10.23.4_Potential Internal Password Spray | 0 | Detects a suspected internal password-spray attack against employee accounts and opens a case for the SOC to assess compromise risk. |
| Response CM V9 - KOHO-UC-2024.10.23.4_Potential Internal Password Spray | 0 | Detects a suspected internal password-spray attack against employee accounts and opens a case for the SOC to assess compromise risk. |
| Response CM V9 - KOHO-UC-2024.10.23.5_Potential Password Spray | 0 | Detects a suspected external password-spray attack against employee accounts and opens a case for the SOC to assess compromise risk. |
| Response CM V9 - KOHO-UC-2024.10.23.5_Potential Password Spray | 0 | Detects a suspected external password-spray attack against employee accounts and opens a case for the SOC to assess compromise risk. |
| Response CM V9 - KOHO-UC-2024.10.24.5_Account Removed from CD Critical Group-LST-AWS | 0 | Detects when a user account is removed from a critical privileged access group in AWS and opens a case to confirm the change was authorized. |
| Response CM V9 - KOHO-UC-2024.10.24.5_Account Removed from CD Critical Group-LST-AWS | 0 | Detects when a user account is removed from a critical privileged access group in AWS and opens a case to confirm the change was authorized. |
| Response CM V9 - KOHO-UC-2024.10.25.1_Excessive Account Lockouts | 0 | Detects an unusual spike in account lockouts that may indicate a brute-force or password-spray attack and opens a case for investigation. |
| Response CM V9 - KOHO-UC-2024.10.25.1_Excessive Account Lockouts | 0 | Detects an unusual spike in account lockouts that may indicate a brute-force or password-spray attack and opens a case for investigation. |
| Response CM V9 - KOHO-UC-2024.6.3 successful_login_analysis | 0 | Analyzes patterns in successful employee logins to flag anomalous access for further SOC investigation. |
| Response CM V9 - KOHO-UC-2024.6.3 successful_login_analysis | 0 | Analyzes patterns in successful employee logins to flag anomalous access for further SOC investigation. |
| Response CM V9 - KOHO-UC-2024.6.3 successful_login_analysis_send_to_slack | 0 | Sends the results of the successful-login anomaly analysis to the SOC's Slack channel for visibility and follow-up. |
| Response CM V9 - KOHO-UC-2024.6.3 successful_login_analysis_send_to_slack | 0 | Sends the results of the successful-login anomaly analysis to the SOC's Slack channel for visibility and follow-up. |
| Response CM V9 - KOHO-UC-2025.5.30 successful_login_analysis | 0 | Analyzes patterns in successful employee logins to flag anomalous access for further SOC investigation. |
| Response CM V9 - KOHO-UC-2025.5.30 successful_login_analysis | 0 | Analyzes patterns in successful employee logins to flag anomalous access for further SOC investigation. |
| Response CM V9 - KOHO-UC-2025.5.30 successful_login_analysis_send_to_slack | 0 | Sends the results of the successful-login anomaly analysis to the SOC's Slack channel for visibility and follow-up. |
| Response CM V9 - KOHO-UC-2025.5.30 successful_login_analysis_send_to_slack | 0 | Sends the results of the successful-login anomaly analysis to the SOC's Slack channel for visibility and follow-up. |
| Response Subflow - KOHO-UC-2025.03.31 - SSO AWS Login with Non-ZScaler IP | 0 | Supports investigation of SSO/AWS logins originating from outside the corporate secure network, a potential sign of credential compromise. |
| Response V9 - KOHO-UC-2025.4.9.2_Foreign Login Anomaly Detection | 0 | Flags employee logins originating from unexpected foreign locations and opens a case for the SOC to assess account compromise risk. |
8. AML / KYC Compliance & Identity Verification
Category: GRC
Subcategories: AML / KYC compliance
Description:
Automates anti-money-laundering and know-your-customer checks: sanctioned-country transaction screening, FINTRAC suspicious-transaction reporting, non-resident account controls, and Onfido/Trulioo identity-document verification.
Business problem solved:
AML/KYC failures carry direct regulatory and licensing risk for a fintech; automation ensures every flagged transaction or identity mismatch is consistently screened and reported.
Integrations: AWS · Slack · Google Sheets · Jira · Blink Case Management · Cloudflare
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Onfido Known Fraud Document | 5,756 | Detects when a submitted Onfido identity document matches a known fraudulent document, blocking risky account sign-ups. |
| Trulioo Duplicate Credit File AUV | 5,756 | Flags identity verification attempts that reuse a credit file already tied to another customer, a signal of possible identity fraud. |
| Trulioo - High Risk Phone Operator AUV | 1,920 | Flags new customers whose phone number belongs to a high-risk carrier during identity verification, supporting KYC/AML screening. |
| Trulioo EC Fraud Flag AUV | 1,920 | Flags customers whose identity verification triggers a fraud indicator, supporting KYC/AML compliance screening for new accounts. |
| Non-Resident Lock Script | 1,100 | Automatically locks non-resident customer accounts to enforce regulatory residency compliance requirements. |
| Non-Resident Automation | 960 | Core automation that manages account status changes for non-resident customers as part of ongoing compliance controls. |
| Non-Resident Email | 960 | Sends compliance-related email notifications to non-resident customers regarding the status of their account. |
| Claude - Info Request Intake | 894 | Uses an AI assistant to process incoming information requests (e.g., regulatory or legal inquiries) and log them to the related Jira case. |
| FINTRAC - STR - Manual Trigger | 240 | Lets compliance staff manually trigger the Suspicious Transaction Report process required by Canada's FINTRAC anti-money-laundering regulator. |
| Non-Resident - Credit Building Withdrawals | 160 | Applies withdrawal controls on the credit-building product for non-resident customers to meet regulatory compliance requirements. |
| Apata Feedback | 40 | Processes fraud feedback signals from an identity-verification vendor to refine detection of fraudulent account applications. |
| Approved Txns in Blocked Countries - Sanctions | 40 | Flags transactions approved from sanctioned or blocked countries so compliance can review potential sanctions violations. |
| FINTRAC - STR - Not Attempted | 40 | Alerts the compliance team via Slack when a required Suspicious Transaction Report to FINTRAC was not attempted, preventing regulatory reporting gaps. |
| Onfido DOB Mismatch | 40 | Flags identity-verification cases where a customer's stated date of birth doesn't match their Onfido ID document, for compliance review. |
| Onfido Underage Users from Previous Day to Google Sheet | 40 | Compiles a daily report of customers flagged as underage by Onfido identity verification for compliance follow-up. |
| Forward To AML | 10 | Forwards a case from Jira to the anti-money-laundering (AML) team for specialist review when a transaction warrants deeper compliance scrutiny. |
| AML - Closure Slack Message | 4 | Sends a Slack notification when an AML case is closed, keeping the compliance team informed of outcomes. |
| Forward To AML - Web Form | 4 | Provides an interactive web form so staff can manually forward a case to the AML team for review, using the same underlying compliance workflow. |
| High Risk Countries Transactions Alert | 1 | Flags transactions originating from high-risk countries and alerts the compliance team via Slack, supporting anti-money-laundering monitoring obligations. |
| AML Sheet to Blink Table | 0 | Imports AML tracking data from a Google Sheet into a Blink table so it can feed other compliance automations. |
| KOHO-UC-2024.10.22.1_Allowed Connection to known US Embargo Country | 0 | Flags network connections to a country under U.S. trade embargo/sanctions, supporting sanctions compliance obligations. |
9. Alert & Observable Enrichment (IOC Lookups)
Category: SOC
Subcategories: Alert enrichment / IOC lookup
Description:
Automatically enriches SOC case observables (IPs, hashes, URLs, domains, usernames) against CrowdStrike, VirusTotal, AbuseIPDB, WHOIS, URLScan, and identity providers before analyst review.
Business problem solved:
Manual enrichment lookups are one of the biggest time sinks in SOC triage; automating them gives analysts pre-enriched context the moment a case is created.
Integrations: VirusTotal · CrowdStrike · AbuseIPDB · GitHub · Google Workspace · Microsoft Entra ID · Blink Case Management · Okta · Slack · URLScan · IPWHOIS · WHOIS Lookup · Whois · Jira · Recorded Future
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Subflow - Enrich Observables - Main Router | 15,916 | Routes case observables (IPs, domains, hashes) to the correct enrichment lookup so analysts get context automatically instead of manually. |
| Enrich - IP - IPDB | 1,370 | Checks a suspicious IP address against AbuseIPDB to enrich a SOC case with abuse reputation data. |
| Enrich - IP - IPWHOIS | 1,370 | Performs a WHOIS lookup on a suspicious IP address to enrich a SOC case with ownership and network details. |
| Subflow_LePookie Query CM Objects | 422 | Queries case management objects to support other automations that need case, alert, or observable data on demand. |
| Subflow_IP Lookup LePookie | 66 | Looks up a suspicious IP address's reputation via AbuseIPDB to give analysts fast context during investigation. |
| Recorded Future Identity Automation | 40 | Pulls identity-related threat intelligence from Recorded Future and opens a Jira ticket for the security team to investigate. |
| Subflow_Check IP on AbuseIPDB | 9 | Checks a suspicious IP address against AbuseIPDB's reputation database and logs the result on the case for analyst review. |
| Analyze URL with URLScan | 0 | Scans a suspicious URL with URLScan to help analysts assess whether it is malicious before taking action. |
| Enrich - Agent ID - Crowdstrike | 0 | Looks up a CrowdStrike agent/device ID to enrich a SOC case with endpoint details before analyst review. |
| Enrich - Agent ID - Crowdstrike | 0 | Looks up a CrowdStrike agent/device ID to enrich a SOC case with endpoint details before analyst review. |
| Enrich - Email Address - Slack | 0 | Looks up an email address's associated Slack identity to enrich a SOC case with employee context. |
| Enrich - Email Address - Slack | 0 | Looks up an email address's associated Slack identity to enrich a SOC case with employee context. |
| Enrich - Hash - Crowdstrike | 0 | Searches CrowdStrike for a file hash across all managed devices to enrich a SOC case with prevalence and detection data. |
| Enrich - Hash - Crowdstrike | 0 | Searches CrowdStrike for a file hash across all managed devices to enrich a SOC case with prevalence and detection data. |
| Enrich - Hash - VT | 0 | Looks up a file hash in VirusTotal to enrich a SOC case with malware reputation data before analyst review. |
| Enrich - Hash - VT | 0 | Looks up a file hash in VirusTotal to enrich a SOC case with malware reputation data before analyst review. |
| Enrich - IP - IPDB | 0 | Checks a suspicious IP address against AbuseIPDB to enrich a SOC case with abuse reputation data. |
| Enrich - IP - IPWHOIS | 0 | Performs a WHOIS lookup on a suspicious IP address to enrich a SOC case with ownership and network details. |
| Enrich - IP - VT | 0 | Looks up a suspicious IP address in VirusTotal to enrich a SOC case with reputation data before analyst review. |
| Enrich - IP - VT | 0 | Looks up a suspicious IP address in VirusTotal to enrich a SOC case with reputation data before analyst review. |
| Enrich - IP or Domain - Whois | 0 | Performs a WHOIS lookup on a suspicious IP address or domain to enrich a SOC case with registration details. |
| Enrich - IP or Domain - Whois | 0 | Performs a WHOIS lookup on a suspicious IP address or domain to enrich a SOC case with registration details. |
| Enrich - URL - URLScan | 0 | Submits a suspicious URL to URLScan to enrich a SOC case with visual and technical analysis before analyst review. |
| Enrich - URL - URLScan | 0 | Submits a suspicious URL to URLScan for automated analysis, giving analysts safe visibility into where a link leads before acting on a case. |
| Enrich - URL - VT | 0 | Scans a suspicious URL through VirusTotal to pull reputation and detection data, helping analysts triage phishing or malware cases faster. |
| Enrich - URL - VT | 0 | Scans a suspicious URL through VirusTotal to pull reputation and detection data, helping analysts triage phishing or malware cases faster. |
| Enrich - Username - Github | 0 | Looks up a username in GitHub to enrich a security case with account and repository ownership context. |
| Enrich - Username - Github | 0 | Looks up a username in GitHub to enrich a security case with account and repository ownership context. |
| Enrich - Username or Email - Google Workspace | 0 | Looks up a username or email in Google Workspace to pull employee identity details that enrich a security case for faster triage. |
| Enrich - Username or Email - Google Workspace | 0 | Looks up a username or email in Google Workspace to pull employee identity details that enrich a security case for faster triage. |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Looks up a username or email in Microsoft Entra ID to pull identity and account details that enrich a security case for analyst review. |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Looks up a username or email in Microsoft Entra ID to pull identity and account details that enrich a security case for analyst review. |
| Enrich - Username or Email - Okta | 0 | Looks up a username or email in Okta to pull account status and profile details that enrich a security case for analyst review. |
| Enrich - Username or Email - Okta | 0 | Looks up a username or email in Okta to pull account status and profile details that enrich a security case for analyst review. |
| Enrich IP or Domain Using Whois | 0 | Runs a WHOIS lookup on a suspicious IP address or domain to surface registration and ownership details that support case enrichment. |
| Enrich IP or Domain Using Whois | 0 | Runs a WHOIS lookup on a suspicious IP address or domain to surface registration and ownership details that support case enrichment. |
| Get Hash Info Using Crowdstrike | 0 | Looks up a file hash in CrowdStrike threat intelligence to determine whether it's a known malicious indicator, enriching a case for analyst review. |
| Get Hash Info Using VirusTotal | 0 | Looks up a file hash in VirusTotal to check for known malware detections, enriching a security case with reputation data. |
| Get User Information Using Github | 0 | Looks up a GitHub account's profile details to enrich a security case involving developer or repository activity. |
| Get User Information Using Github | 0 | Looks up a GitHub account's profile details to enrich a security case involving developer or repository activity. |
| Get User Information Using Google Workspace | 0 | Retrieves an employee's Google Workspace profile details to enrich a security case with identity and account context. |
| Get User Information Using Google Workspace | 0 | Retrieves an employee's Google Workspace profile details to enrich a security case with identity and account context. |
| Get User Information Using Microsoft Entra ID | 0 | Pulls a user's Microsoft Entra ID profile and risk status, including whether they're flagged as a risky user, to support identity threat investigations. |
| Get User Information Using Microsoft Entra ID | 0 | Pulls a user's Microsoft Entra ID profile and risk status, including whether they're flagged as a risky user, to support identity threat investigations. |
| Get User Information Using Okta | 0 | Looks up a user's Okta account details by email to enrich a security case with identity and account status information. |
| Get User Information on Email Address Using Slack | 0 | Looks up a Slack user profile by email address to enrich a security case with employee identity context. |
| Recovery - Enrich Non-Enriched Observables | 0 | Safety-net workflow that finds case observables missed by initial enrichment and reprocesses them for completeness. |
| Subflow - Enrich Observables - Main Router | 0 | Routes case observables (IPs, domains, hashes) to the correct enrichment lookup so analysts get context automatically instead of manually. |
| Utility - Delete Observable Relation | 0 | Removes an outdated relationship between case observables, keeping enrichment data accurate as investigations evolve. |
| Utility - Find Similar Cases Based on Observables | 0 | Searches for other cases sharing the same observables, such as IPs, hashes, or domains, to help analysts spot related incidents faster. |
| Utility - List Alert Observable Relations | 0 | Retrieves all observables linked to a given alert, giving analysts a full picture of related indicators in one view. |
| Utility - List Observable Alert Relations | 0 | Retrieves all alerts linked to a given observable, helping analysts see everywhere a suspicious indicator has appeared. |
| Utility - Set Or Update Observable Relation | 0 | Creates or updates the link between an alert and its observables, keeping case enrichment data accurate and current. |
| Utility - Update Enrichment | 0 | Triggers the observable enrichment router to refresh reputation and context data on a case, giving analysts up-to-date information. |
| Utility - Update Enrichment | 0 | Triggers the observable enrichment router to refresh reputation and context data on a case, giving analysts up-to-date information. |
| Web Scraping Subflow - Known Domains | 0 | Checks a suspicious domain against a known-domains reference list to quickly enrich case data during investigation. |
| Web Scraping Subflow - Unknown Domains | 0 | Scrapes a suspicious, previously-unseen domain to gather content and context for analysts investigating a case. |
| Web Scraping Subflow - Wayback Machine | 0 | Looks up a suspicious domain's historical content via the Wayback Machine to help analysts assess its legitimacy. |
10. Malware & EDR Threat Detection
Category: SOC
Subcategories: EDR containment & response
Description:
Detects malware and endpoint threats (repeated AV alerts, malware outbreaks, known hacking tools, EDR/SentinelOne alerts) and drives containment actions like CrowdStrike RTR and endpoint quarantine.
Business problem solved:
Endpoint compromises need to be contained in minutes, not hours; this automates detection-to-containment for the most common EDR/AV alert patterns.
Integrations: Blink Case Management · Splunk · Slack · CrowdStrike · VirusTotal · SentinelOne
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| KOHO-UC-2026.5.27_EDR Alert Detected | 9,071 | Opens a case for every EDR-detected alert, giving analysts a consistent starting point to triage endpoint threats. |
| KOHO-UC-2026.07.05_Endpoint Behavioural Kill Chain | 123 | Opens and manages a case for EDR alerts that match multiple stages of an attack kill chain, escalating high-confidence threats. |
| S1 Incident Status Notification | 72 | Notifies stakeholders in real time when a SentinelOne security incident's status changes, keeping response teams aligned. |
| KOHO-UC-2024.10.23.6_Repeated AV signature on Single Host | 47 | Investigates a repeated antivirus signature hit on a single host by pulling related Splunk logs and scanning the file with VirusTotal. |
| Koho CM V9 - KOHO-UC-2024.10.23.6 - Repeated AV signature on Single Host | 47 | Flags when the same antivirus signature repeatedly triggers on one device, suggesting an infection that isn't being fully remediated. |
| Response CM V9 - KOHO-UC-2024.10.23.6_Repeated AV signature on Single Host | 47 | Investigates repeated antivirus detections on a single endpoint by pulling related logs from Splunk and checking suspicious URLs against VirusTotal. |
| KOHO-UC-2024.10.25.6_Unmitigated_Alerts_Live_Detection | 11 | Opens a case for security alerts that remain unmitigated after live detection, ensuring nothing falls through the cracks. |
| Koho CM V9 - KOHO-UC-2024.10.25.6 - Unmitigated_Alerts_Live_Detection | 11 | Highlights security alerts that remain unmitigated in real time, ensuring open threats don't fall through the cracks. |
| Response CM V9 - KOHO-UC-2024.10.25.6_Unmitigated_Alerts_Live_Detection | 11 | Flags security alerts that remain unmitigated on live systems and opens a case to ensure timely SOC follow-up and remediation. |
| KOHO-UC-2024.10.25.5_Repeated_AV_Alerts_On_Single_Host | 9 | Opens a case when repeated antivirus alerts fire across hosts, indicating a possible spreading malware infection. |
| Koho CM V9 - KOHO-UC-2024.10.25.5 - Repeated_AV_Alerts_On_Single_Host | 9 | Flags repeated antivirus alerts on a single host, indicating an infection that antivirus alone hasn't fully resolved. |
| Response CM V9 - KOHO-UC-2024.10.25.5_Repeated_AV_Alerts_On_Single_Host | 9 | Detects repeated antivirus alerts on a single endpoint that may indicate a persistent infection and opens a case for SOC investigation. |
| KOHO-UC-2025.05.29_SentinelOne Health Check | 2 | Periodically verifies that the SentinelOne EDR data feed is healthy and opens a case if the integration goes silent. |
| Koho CM V9 - KOHO-UC-2025.05.29_SentinelOne Health Check | 2 | Periodically verifies that the SentinelOne EDR data feed is healthy and opens a case if the integration goes silent. |
| Response CM V9 - KOHO-UC-2025.05.29_SentinelOne Health Check | 2 | Periodically checks that the SentinelOne EDR platform is reporting data correctly, alerting the SOC if the telemetry pipeline goes silent. |
| CrowdStrike RTR to a Batch of Hosts | 0 | Runs a CrowdStrike Real Time Response script across a batch of endpoints to investigate or contain a security issue at scale. |
| CrowdStrike RTR to a Single Host | 0 | Runs a CrowdStrike Real Time Response script on a single targeted endpoint for investigation or containment. |
| KOHO-UC-2024.10.23.2_Potential Malware Outbreak | 0 | Opens a case when multiple hosts show signs consistent with a malware outbreak, so responders can contain the spread. |
| KOHO-UC-2024.10.23.7_Possible Malware Hosting Device | 0 | Opens a case when a device is flagged as a possible malware-hosting host, so it can be isolated and investigated. |
| KOHO-UC-2024.10.25.3_File_Execution_Of_Known_Hacking_Tools | 0 | Opens a case when a known hacking tool is detected executing on a company endpoint, prompting immediate investigation. |
| KOHO-UC-2024.10.25.4_Repeated_AV_Alerts_On_Multiple_Hosts | 0 | Opens a case when repeated antivirus alerts fire across hosts, indicating a possible spreading malware infection. |
| Koho CM V9 - KOHO-UC-2024.10.23.2 - Potential Malware Outbreak | 0 | Detects signs of a broader malware outbreak across the environment so the SOC can respond before it spreads further. |
| Koho CM V9 - KOHO-UC-2024.10.23.2 - Potential Malware Outbreak | 0 | Detects signs of a broader malware outbreak across the environment so the SOC can respond before it spreads further. |
| Koho CM V9 - KOHO-UC-2024.10.23.6 - Repeated AV signature on Single Host | 0 | Flags when the same antivirus signature repeatedly triggers on one device, suggesting an infection that isn't being fully remediated. |
| Koho CM V9 - KOHO-UC-2024.10.23.7 - Possible Malware Hosting Device | 0 | Flags a device that may be hosting or distributing malware, prompting the SOC to isolate and investigate it. |
| Koho CM V9 - KOHO-UC-2024.10.23.7 - Possible Malware Hosting Device | 0 | Flags a device that may be hosting or distributing malware, prompting the SOC to isolate and investigate it. |
| Koho CM V9 - KOHO-UC-2024.10.25.3 - File_Execution_Of_Known_Hacking_Tools | 0 | Detects execution of known hacking tools on an endpoint, triggering rapid SOC investigation and containment. |
| Koho CM V9 - KOHO-UC-2024.10.25.3 - File_Execution_Of_Known_Hacking_Tools | 0 | Detects execution of known hacking tools on an endpoint, triggering rapid SOC investigation and containment. |
| Koho CM V9 - KOHO-UC-2024.10.25.4 - Repeated_AV_Alerts_On_Multiple_Hosts | 0 | Flags the same antivirus alert firing across multiple hosts, a pattern that can indicate a spreading infection or coordinated attack. |
| Koho CM V9 - KOHO-UC-2024.10.25.4 - Repeated_AV_Alerts_On_Multiple_Hosts | 0 | Flags the same antivirus alert firing across multiple hosts, a pattern that can indicate a spreading infection or coordinated attack. |
| Koho CM V9 - KOHO-UC-2024.10.25.5 - Repeated_AV_Alerts_On_Single_Host | 0 | Flags repeated antivirus alerts on a single host, indicating an infection that antivirus alone hasn't fully resolved. |
| Koho CM V9 - KOHO-UC-2024.10.25.6 - Unmitigated_Alerts_Live_Detection | 0 | Highlights security alerts that remain unmitigated in real time, ensuring open threats don't fall through the cracks. |
| Koho CM V9 - KOHO-UC-2025.05.29_SentinelOne Health Check | 0 | Periodically verifies that the SentinelOne EDR data feed is healthy and opens a case if the integration goes silent. |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Quarantines or restores a compromised endpoint in CrowdStrike, letting responders contain a threat directly from the case. |
| Response CM V9 - KOHO-UC-2024.10.23.2_Potential Malware Outbreak | 0 | Detects signs of a potential malware outbreak across endpoints and opens a case to coordinate containment and team notification. |
| Response CM V9 - KOHO-UC-2024.10.23.2_Potential Malware Outbreak | 0 | Detects signs of a potential malware outbreak across endpoints and opens a case to coordinate containment and team notification. |
| Response CM V9 - KOHO-UC-2024.10.23.6_Repeated AV signature on Single Host | 0 | Investigates repeated antivirus detections on a single endpoint by pulling related logs from Splunk and checking suspicious URLs against VirusTotal. |
| Response CM V9 - KOHO-UC-2024.10.23.7_Possible Malware Hosting Device | 0 | Flags a host suspected of hosting malware and opens a case so the SOC can investigate and contain the endpoint. |
| Response CM V9 - KOHO-UC-2024.10.23.7_Possible Malware Hosting Device | 0 | Flags a host suspected of hosting malware and opens a case so the SOC can investigate and contain the endpoint. |
| Response CM V9 - KOHO-UC-2024.10.25.3_File_Execution_Of_Known_Hacking_Tools | 0 | Detects execution of known hacking tools on an endpoint and opens a case so the SOC can investigate potential compromise. |
| Response CM V9 - KOHO-UC-2024.10.25.3_File_Execution_Of_Known_Hacking_Tools | 0 | Detects execution of known hacking tools on an endpoint and opens a case so the SOC can investigate potential compromise. |
| Response CM V9 - KOHO-UC-2024.10.25.4_Repeated_AV_Alerts_On_Multiple_Hosts | 0 | Detects a pattern of repeated antivirus alerts spreading across multiple hosts, signaling a possible outbreak, and opens a case for the SOC. |
| Response CM V9 - KOHO-UC-2024.10.25.4_Repeated_AV_Alerts_On_Multiple_Hosts | 0 | Detects a pattern of repeated antivirus alerts spreading across multiple hosts, signaling a possible outbreak, and opens a case for the SOC. |
| Response CM V9 - KOHO-UC-2024.10.25.5_Repeated_AV_Alerts_On_Single_Host | 0 | Detects repeated antivirus alerts on a single endpoint that may indicate a persistent infection and opens a case for SOC investigation. |
| Response CM V9 - KOHO-UC-2024.10.25.6_Unmitigated_Alerts_Live_Detection | 0 | Flags security alerts that remain unmitigated on live systems and opens a case to ensure timely SOC follow-up and remediation. |
| Response CM V9 - KOHO-UC-2025.05.29_SentinelOne Health Check | 0 | Periodically checks that the SentinelOne EDR platform is reporting data correctly, alerting the SOC if the telemetry pipeline goes silent. |
| Response Subflow - Malware | 0 | Internal helper automation that supports malware-related SOC playbooks by pulling case data and applying shared malware-handling logic. |
| S1 Alert ingestion | 0 | Ingests security alerts from the SentinelOne EDR platform and automatically creates corresponding cases in the SOC case management system. |
| Simulate Crowdstrike Alert | 0 | Generates a synthetic CrowdStrike-style alert to test and validate the SOC's alert intake and case creation pipeline. |
11. Real-Time Transaction Risk & Velocity Monitoring
Category: Other
Subcategories: Financial & fraud operations
Description:
Continuously screens transactions, devices, and accounts against velocity thresholds and risk models (sketchy IP/device/platform, crypto anomalies, new-device/merchant checks) to catch fraud in real time.
Business problem solved:
Fraud losses compound the longer a bad transaction pattern goes undetected; this gives Koho's risk team a real-time, rules-based first line of defense before manual review is needed.
Integrations: AWS · Google Sheets
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| 24_hour_blanket_velocity | 962 | Monitors transaction velocity within a 24-hour window to catch fraud patterns that build up more gradually. |
| 1_hour_blanket_velocity | 961 | Monitors transaction velocity within a 1-hour window to catch fast-building fraud patterns for review. |
| Admin Authentication | 960 | Authenticates against Koho's internal admin systems to obtain access tokens used by downstream fraud-monitoring automations. |
| Invalid Platform | 960 | Flags transactions or logins originating from an unrecognized or unsupported platform as a fraud risk signal. |
| Known Bad Device | 960 | Checks transactions against a maintained list of known-bad devices to block fraudulent activity from previously flagged hardware. |
| dupe_close_account | 960 | Automatically closes duplicate customer accounts identified as a fraud or policy-abuse risk. |
| international_digital_goods_velocity | 960 | Flags unusually high transaction velocity on international digital-goods purchases, a common signal of card fraud. |
| Wire Monitor | 640 | Monitors outbound wire transfers in real time to flag unusual amounts or patterns that may indicate fraud. |
| Sketchy IP (realtime) SQL | 80 | Runs a real-time SQL check against transaction data to flag connections from suspicious ('sketchy') IP addresses for fraud review. |
| Sketchy Model (realtime) SQL | 80 | Runs a real-time SQL check against device data to flag suspicious device fingerprints associated with fraud. |
| Sketchy Platform (realtime) SQL | 80 | Runs a real-time SQL check against platform usage data to flag suspicious activity patterns for fraud review. |
| New Device | 68 | Flags customer accounts logging in from a newly seen device, helping the fraud team catch potential account takeover attempts. |
| New IP | 68 | Flags customer accounts transacting from a new or unrecognized IP address as an early signal of possible account takeover. |
| New Merchant | 68 | Flags transactions involving a merchant not previously seen on a customer's account, surfacing a potential fraud indicator for review. |
| Crypto Deposit Volume | 40 | Monitors cryptocurrency deposit volumes for unusual patterns that may indicate fraud or money laundering. |
| Crypto Spend 3DS Email Mismatch | 40 | Flags crypto purchase transactions where the 3D-Secure verification email doesn't match the account holder's email, a strong fraud signal. |
| High User Account Views | 40 | Alerts the fraud team when a customer account is viewed an unusually high number of times, a pattern that can indicate account-takeover reconnaissance. |
| High Value Credit | 40 | Flags unusually large credit or deposit transactions for fraud team review before funds become fully available to the customer. |
| Multi-credit alerts | 40 | Flags customer accounts receiving multiple credit transactions in a short window, a pattern often linked to fraud or money laundering. |
| Negative Balance Alerts | 40 | Flags customer accounts that have dropped into a negative balance so the risk and collections teams can follow up. |
| Self-dealing alerts | 40 | Flags potential self-dealing or conflict-of-interest transactions for review, helping the business catch improper financial activity early. |
| VIP Views Alerts | 40 | Alerts the fraud/support team whenever a VIP customer's account is accessed or viewed, adding extra oversight for high-value accounts. |
| Doc Country Volume Change Alerts | 5 | Monitors changes in transaction/document volume by country to catch emerging fraud or compliance risk patterns. |
| Country Volume Change Alerts | 1 | Alerts when transaction volume from a given country changes significantly, surfacing emerging fraud or compliance risk. |
12. Card & Payment Network Fraud (Stripe / BNPL)
Category: Other
Subcategories: Financial & fraud operations
Description:
Responds to card-network fraud signals from Stripe (Early Fraud Warnings, shared-card alerts) and manages BNPL settlement decisions and card tokenization.
Business problem solved:
Card-network fraud signals are time-sensitive and come from an external party; automated suspension keeps Koho ahead of chargebacks and network penalties.
Integrations: AWS · Jira · Stripe
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Stripe Early Fraud Warning Suspensions | 1,920 | Automatically suspends accounts flagged by Stripe's Early Fraud Warning signal, cutting off suspected fraud before losses accumulate. |
| Bread Settlement Decision Flow | 480 | Automates settlement decisioning for transactions processed through a buy-now-pay-later payment partner. |
| Tokenization | 120 | Runs the process that tokenizes sensitive payment card data in AWS, reducing exposure of raw card numbers across systems. |
| Oscilar Case Creation Manual Referrals | 67 | Creates a fraud review case for transactions manually referred by the Oscilar fraud-decisioning platform. |
| Stripe Shared Card Alert to JIRA - rework | 41 | Opens a Jira ticket when Stripe detects a card shared across multiple accounts, a common fraud indicator, for investigation. |
| Stripe EWF Alert | 40 | Alerts the fraud team when Stripe issues an Early Warning Fraud signal so suspicious payment activity gets timely review. |
| Stripe Flowthrough Alert to JIRA (Serverless) | 17 | Creates a Jira ticket whenever Stripe flags a 'flowthrough' fraud alert, ensuring suspicious payment patterns are tracked and investigated. |
| Generate Stripe Summary | 0 | Compiles a summary report of Stripe payment-related tickets from Jira to help the team track payment disputes and processing issues. |
13. Privileged & Just-In-Time Access Management
Category: IAM
Subcategories: Privileged account mgmt, JIT & temporary access
Description:
Grants and revokes time-boxed elevated access to production AWS, databases, and admin roles, and tracks privileged group membership.
Business problem solved:
Standing privileged access is a major attack surface; just-in-time grants let engineers get the access they need for a task without leaving permanent admin rights behind.
Integrations: Slack · JumpCloud · AWS · Blink Case Management · PagerDuty · incident.io
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Alert on DBA membership | 960 | Monitors directory group membership for database administrator (DBA) access to catch unauthorized privileged grants. |
| Alert on DBReader membership | 960 | Monitors directory group membership for read-only database access to catch unauthorized access grants. |
| Subflow_JumpCloud Lookup and Add to Privileged Access Users | 560 | Looks up JumpCloud group membership and adds qualifying users to the privileged access users list, keeping tracking accurate. |
| Grant Temporary Access to AWS Account Administration | 72 | Grants time-limited administrative access to an AWS account through JumpCloud, minimizing standing privileged access for cloud administration tasks. |
| Privileged Access List Creation | 40 | Builds and maintains an inventory of privileged accounts to support ongoing access governance and audits. |
| Elevate Permission to ProductionAdminRole (firefighting) | 4 | Grants temporary elevated production admin access during an active incident, with Slack notice and incident tracking for accountability. |
| PAM - re-useable sub-workflow - add trusted entities in prod | 3 | Reusable sub-workflow that temporarily grants a trusted access entity in the production AWS environment for a privileged operation. |
| PAM - re-useable sub-workflow - remove trusted entities in prod | 3 | Reusable sub-workflow that revokes a temporary trusted access entity from production once the privileged session ends. |
| Grant Temporary Access to AWS Account Readonly Permission | 1 | Grants time-limited read-only access to an AWS account through JumpCloud for troubleshooting or review needs without creating standing access. |
| Access Review - Privileged Access | 0 | Reviews who holds privileged access rights to confirm only authorized staff retain elevated permissions. |
| Grant Temporary Access to a Non-Production AWS Database | 0 | Grants time-limited access to a non-production AWS database through JumpCloud and automatically notifies the requester via Slack. |
| Grant Temporary Access to a Production AWS Database | 0 | Grants time-limited access to a production AWS database through JumpCloud, reducing standing privileged access while supporting urgent needs. |
| JC Temporary Privilege Escalation | 0 | Grants a user temporary, time-boxed elevated JumpCloud access with Slack-based approval, then automatically revokes it. |
| KOHO-UC-2024.6.21 - Mambu Admin Access Enabled for a User | 0 | Flags whenever a user is granted admin-level access within the Mambu core banking platform so sensitive privilege grants get reviewed. |
| PAM - re-useable sub-workflow - page out a service | 0 | Reusable sub-workflow that pages the on-call team when a privileged access action needs human awareness or approval. |
| Response CM V9 - KOHO-UC-2025.1.22_1Password Vault Deletion | 0 | Detects deletion of a 1Password vault holding privileged credentials and opens a case to confirm the action was authorized and assess impact. |
| Response CM V9 - KOHO-UC-2025.1.22_1Password Vault Deletion | 0 | Detects deletion of a 1Password vault holding privileged credentials and opens a case to confirm the action was authorized and assess impact. |
| Temporarily Add User to Group in Google Workspace | 0 | Grants a user temporary membership in a Google Workspace group and automatically removes it after a set time, enforcing least privilege. |
| Time-Limited Privileged AWS Access (Plan B) | 0 | Grants time-limited privileged AWS access so elevated permissions automatically expire instead of lingering indefinitely. |
14. Vulnerable Customer Protection (Elder & Scam-Victim Safeguards)
Category: Other
Subcategories: Financial & fraud operations
Description:
Identifies and protects elderly and vulnerable customers from financial abuse and scam-victim patterns, triggering outreach and protective account locks.
Business problem solved:
Elder financial abuse is a regulatory and reputational priority for fintechs; this ensures at-risk customers get proactive intervention rather than after-the-fact loss recovery.
Integrations: AWS · Jira
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| High Risk Scam Population - Elder Abuse AUV | 960 | Runs automated user verification checks on accounts flagged within the high-risk elder-abuse scam population to support victim protection efforts. |
| etransfer_elder_abuse_lock | 960 | Automatically locks accounts showing e-Transfer activity consistent with elder financial abuse, protecting vulnerable customers from scam losses. |
| Elder Abuse Outreach | 127 | Coordinates customer outreach for accounts showing signs of elder financial abuse, updating the related Jira case. |
| Crypto Spend 3DS Email Mismatch - Elder | 40 | Flags crypto purchase transactions with a 3D-Secure email mismatch specifically on accounts at elevated risk of elder financial abuse. |
| Elder Abuse Velocity Alerts to JIRA | 40 | Converts velocity-based elder-abuse fraud alerts into Jira tickets so the team can intervene quickly. |
| Etransfer_Senior_Scam_Victim | 40 | Identifies senior customers showing e-Transfer patterns consistent with scam victimization and routes them to the fraud team for follow-up and protection. |
| Senior_Daily_Cash_Loads | 40 | Monitors daily cash-load activity for senior/high-tier accounts to flag unusual funding patterns that may indicate fraud. |
| Bankruptcy/Consumer Proposal reach out | 0 | Coordinates customer outreach for accounts flagged with bankruptcy or consumer-proposal filings via the related Jira case. |
15. Account Takeover & Registration Abuse Detection
Category: Other
Subcategories: Financial & fraud operations
Description:
Detects account-takeover and mass-registration fraud patterns, including passkey abuse, look-alike email domains, registration floods, and 2SV-bypass attempts.
Business problem solved:
Fraud rings increasingly target account creation and authentication flows directly; catching these patterns early prevents downstream transaction fraud and chargebacks.
Integrations: Blink Case Management · Slack · Auth0 · AWS · Jira · Splunk · Gmail
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Identity Creations Exceed 200/hour | 960 | Alerts the fraud team when new account and identity creation volume exceeds 200 per hour, a signal of potential bot-driven signup fraud. |
| Known Faces to JIRA | 960 | Flags matches against a known-fraudster identity list and opens a ticket for investigation. |
| KOHO-UC-2025.11.06.1_Registration Flood | 35 | Detects a sudden flood of new account registrations and opens a case for the fraud team to review for bot or fraud-ring activity. |
| Koho CM V9 - KOHO-UC-2025.11.06.1 - Registration Flood | 35 | Detects a sudden flood of new account registrations and opens a case for the fraud team to review for bot or fraud-ring activity. |
| Response CM V9 - KOHO-UC-2025.11.06.1_Registration Flood | 35 | Detects abnormal spikes in new customer account registrations that may indicate a fraud ring or bot attack and routes the case for fraud team review. |
| Look Up Auth0 IDs in Bulk for Registration Floods | 3 | Bulk-resolves Auth0 identity IDs tied to a registration-flood incident so the fraud team can quickly action many accounts at once. |
| ATO Account Sanitizer | 0 | Cleans up compromised accounts after an account-takeover incident by revoking risky access and updating the case ticket. |
| Create ATO Case | 0 | Creates and updates a Jira case to track investigation and remediation of a suspected account-takeover incident. |
| Create ATO Case Trigger | 0 | Provides a web form letting analysts manually trigger creation of an account-takeover investigation case. |
| KOHO-UC-2026.04.29.1_ATO Email Lookalike Ring Detection - Fast | 0 | Detects rings of customer accounts using look-alike email domains that are indicative of coordinated account-takeover fraud. |
| KOHO-UC-2026.04.29.2_ATO Email Lookalike Ring Detection - Slow | 0 | Detects rings of customer accounts using look-alike email domains that are indicative of coordinated account-takeover fraud. |
| KOHO-UC-2026.05.2.1_Suspicious_Domain_Burst_Accounts | 0 | Detects a burst of customer account activity tied to a suspicious email domain, flagging likely coordinated fraud. |
| KOHO-UC-2026.06.03.1_Passkey Count Over Limit | 0 | Flags customer accounts that exceed the normal limit of enrolled passkeys, a possible sign of account-takeover persistence. |
| KOHO-UC-2026.06.04.1_Passkey Enrollment After Password Reset | 0 | Flags when a customer enrolls a new passkey immediately after a password reset, a pattern consistent with account-takeover fraud. |
| Koho CM V9 - KOHO-UC-2024.12.24 - User triggered AUV for 2SV bypass - excessive volume | 0 | Flags an unusually high volume of user-triggered 2-step-verification bypass requests as a possible account-takeover attempt. |
| Koho CM V9 - KOHO-UC-2024.12.24 - User triggered AUV for 2SV bypass - excessive volume | 0 | Flags an unusually high volume of user-triggered 2-step-verification bypass requests as a possible account-takeover attempt. |
| Koho CM V9 - KOHO-UC-2025.11.06.1 - Registration Flood | 0 | Detects a sudden flood of new account registrations and opens a case for the fraud team to review for bot or fraud-ring activity. |
| Koho CM V9 - KOHO-UC-2026.05.28.1_Passkey Count Over Limit | 0 | Flags customer accounts that exceed the normal limit of enrolled passkeys, a possible sign of account-takeover persistence. |
| Koho CM V9 - KOHO-UC-2026.05.28.8_Passkey Enrollment Volume Spike | 0 | Detects a spike in passkey enrollments across customer accounts that could indicate a coordinated account-takeover campaign. |
| Koho CM V9 - KOHO-UC-2026.06.03.1_Passkey Count Over Limit | 0 | Flags when a customer enrolls a new passkey immediately after a password reset, a pattern consistent with account-takeover fraud. |
| Koho CM V9 - KOHO-UC-2026.06.04.1_Passkey Enrollment After Password Reset | 0 | Flags when a customer enrolls a new passkey immediately after a password reset, a pattern consistent with account-takeover fraud. |
| Response CM V9 - KOHO-UC-2024.12.24 - User triggered AUV for 2SV bypass - excessive volume | 0 | Detects an abnormal volume of two-step verification bypass requests from a user, a signal of possible account takeover, and pages the on-call team. |
| Response CM V9 - KOHO-UC-2024.12.24 - User triggered AUV for 2SV bypass - excessive volume | 0 | Detects an abnormal volume of two-step verification bypass requests from a user, a signal of possible account takeover, and pages the on-call team. |
| Response CM V9 - KOHO-UC-2025.11.06.1_Registration Flood | 0 | Detects abnormal spikes in new customer account registrations that may indicate a fraud ring or bot attack and routes the case for fraud team review. |
| Response CM V9 - KOHO-UC-2026.05.28.1_Passkey Count Over Limit | 0 | Detects when a customer account has an abnormally high number of registered passkeys, a signal of possible account takeover, and opens a fraud case. |
| Response CM V9 - KOHO-UC-2026.05.28.8_Passkey Enrollment Volume Spike | 0 | Flags a sudden spike in passkey enrollments across customer accounts, a common account-takeover pattern, by querying Splunk and raising a fraud alert. |
| Response CM V9 - KOHO-UC-2026.06.03.1_Passkey Count Over Limit | 0 | Detects when a customer account has an abnormally high number of registered passkeys, a signal of possible account takeover, and opens a fraud case. |
| Response CM V9 - KOHO-UC-2026.06.04.1_Passkey Enrollment After Password Reset | 0 | Flags when a customer enrolls a new passkey immediately after resetting their password, a strong indicator of account takeover, and opens a fraud case. |
| Self Serve - Check Device Login Rate Limit | 0 | Lets employees self-check via Slack whether a device has hit login rate limits by querying Splunk, cutting manual SOC lookups. |
| lookalike Email Registrations | 0 | Scans new account sign-ups for lookalike email domains, a common indicator of fraud rings or mass fake-account creation. |
16. Dispute, Indemnity, Insolvency & Write-Off Operations
Category: Other
Subcategories: Financial & fraud operations
Description:
Processes customer transaction disputes, indemnity claims, insolvency filings, and account write-offs from intake through resolution.
Business problem solved:
These are high-touch, document-heavy customer recovery processes that create backlogs and inconsistent handling without a structured intake-to-resolution workflow.
Integrations: Jira · AWS · Google Sheets · Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Disputes Automation Prototype | 960 | Prototype automation to help process customer transaction disputes and chargebacks more efficiently. |
| Writeoff Value Hourly Alert | 320 | Checks account write-off values every hour and alerts the team in Slack when losses exceed expected thresholds. |
| Indemnity Intake - Claude | 191 | Uses AI to process incoming indemnity claim intake and automatically updates the corresponding Jira ticket with the results. |
| Claude - Insolvency Intake | 84 | Uses an AI assistant to capture insolvency filing details from customers and logs them to a tracking sheet and Jira case. |
| Trigger Indemnity Process - Web Form | 46 | Lets staff kick off the customer indemnity/reimbursement process from a web form, linking it to the related Jira ticket automatically. |
| Auto Write Off Daily Threshold Alert | 40 | Alerts the fraud/finance team when daily automatic write-off amounts exceed a defined threshold. |
| High Write-Off Alert | 40 | Alerts the finance and fraud teams when account write-off amounts exceed a defined threshold, prompting review of potential fraud losses. |
| InApp Dispute Volume Alert | 40 | Alerts the operations team when in-app payment dispute volume spikes, helping catch systemic issues or fraud waves early. |
| Claude - Billpay Report Intake | 0 | Uses an AI assistant to process incoming bill-pay fraud reports and update the corresponding Jira case with structured details. |
| Email - Insolvency Data Input | 0 | Processes insolvency-related information submitted by customers via email and logs it against the relevant Jira case. |
| Indemnity Debit Check | 0 | Checks open indemnity debit claims in Jira to keep the fraud recovery team's dispute queue accurate and current. |
| Indemnity Intake Guide | 0 | Guides intake of new indemnity claims by checking existing Jira tickets so requests are routed to the right queue. |
| Indemnity updated | 0 | Detects updates to an indemnity claim ticket in Jira and triggers the next step in the claims-handling process. |
| Insolvency - Existing Case | 0 | Attaches new supporting documents, submitted via a self-service web form, to an existing customer insolvency case in Jira. |
| Insolvency - Mail workflow | 0 | Processes incoming insolvency-related correspondence and links it to the relevant case in Jira for the recovery team. |
| Insolvency Data Input | 0 | Validates and logs insolvency case data into Jira to keep customer recovery records accurate and complete. |
| Insolvency Request - Data Input | 0 | Captures new insolvency request details and records them in Jira so the recovery team can act on them promptly. |
| Mail - Insolvency Data Input | 0 | Routes incoming insolvency notice emails into a Jira ticket queue so the collections/recoveries team can action them promptly. |
| Outbound Indemnities | 0 | Processes indemnity claims tied to disputed outbound transfers, supporting the fraud and dispute-resolution workflow. |
17. Sardine Fraud-Engine Rule & Merchant Block Management
Category: Other
Subcategories: Financial & fraud operations
Description:
Publishes and maintains Koho's fraud detection rule sets in the Sardine risk engine and automatically blocks merchants flagged as high-risk.
Business problem solved:
Fraud rules need to be updated faster than a manual release cycle allows to keep pace with evolving fraud patterns.
Integrations: Google Sheets · AWS · Sardine
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| KOHO Sardine Feedback | 934 | Sends fraud-outcome feedback data back to the Sardine risk platform to continuously improve the accuracy of its fraud and identity risk scoring. |
| Sardine Merchant Block Automation - KOHO Specific | 40 | Automatically blocks high-risk merchants flagged by the Sardine fraud engine to stop suspicious transactions before they complete. |
| Sardine Merchant Block Automation - Overall Exact | 40 | Automatically blocks high-risk merchants flagged by the Sardine fraud engine to stop suspicious transactions before they complete. |
| Sardine Merchant Block Automation - WS Specific | 40 | Automatically blocks high-risk merchants flagged by the Sardine fraud engine to stop suspicious transactions before they complete. |
| Sardine Rules - KOHO Lite Specific Ruleset | 40 | Publishes KOHO's lightweight fraud rule set into the Sardine engine so a lower-friction group of transactions still gets risk screening. |
| Sardine Rules - KOHO Specific Ruleset | 40 | Publishes KOHO-specific fraud detection rules into the Sardine engine to keep real-time transaction risk scoring current. |
| Sardine Rules - Overall Fraud Ruleset | 40 | Publishes the company-wide fraud rule set into Sardine to keep transaction risk scoring consistent across all products. |
| Sardine Rules - Policy Fraud Ruleset | 40 | Publishes policy-driven fraud rules into Sardine so transaction screening reflects the latest risk and compliance decisions. |
18. Cloud Access & Firewall Configuration Management
Category: Cloud Security
Subcategories: Cloud access & SaaS policy mgmt, Config audit & remediation
Description:
Manages Cloudflare firewall/malicious-IP list state, audits externally-shared Google Drive files, and runs Terraform-based cloud provisioning.
Business problem solved:
Firewall lists and shared-drive permissions drift constantly; automation keeps perimeter and SaaS-sharing controls enforced without manual upkeep.
Integrations: AWS · Slack · Cloudflare · GitHub
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Refresh CloudFlare Firewall Rule Lookup Table | 960 | Refreshes the internal lookup table of Cloudflare firewall rules so downstream security workflows use up-to-date network policy data. |
| Subflow_Terraform Autoclose | 155 | Automatically closes security cases once a related Terraform infrastructure issue has been confirmed resolved, cutting manual case cleanup. |
| Fetch AWS Trusted Developer | 29 | Maintains an up-to-date roster of AWS IAM users granted elevated 'trusted developer' access, alerting the team via Slack when the roster changes. |
| Check Externally Shared Google Drive Files | 0 | Checks for Google Drive files shared externally to catch potential data-exposure risk before it becomes an incident. |
| Reset CloudFlare Malicious IP List | 0 | Refreshes Cloudflare's malicious IP blocklist to ensure known bad actors remain blocked from customer-facing systems. |
| Subflow_Terraform Autoclose | 0 | Automatically closes security cases once a related Terraform infrastructure issue has been confirmed resolved, cutting manual case cleanup. |
| Terraform | 0 | Applies Terraform infrastructure-as-code changes from GitHub to AWS, automating consistent and auditable cloud provisioning. |
19. Customer Registry & Account Data Maintenance
Category: Other
Subcategories: Customer registry & FinOps auto
Description:
Maintains core customer record accuracy, including address and direct-deposit updates, duplicate-account handling, and account-status lookups.
Business problem solved:
Inaccurate customer records cause downstream payment failures and compliance issues; automation keeps registry data current without manual data entry.
Integrations: Slack · Datadog
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Post PTC Balance to Slack | 960 | Posts a daily program trust account balance metric to Slack so finance and ops can monitor liquidity in real time. |
| Bulk Lookup Account Status in Admin | 0 | Looks up account status for a batch of customer accounts in the admin system and reports results via Slack. |
| Save Re-onboarding | 0 | Automates a check of the customer re-onboarding flow for KOHO's Save product, helping confirm the process works as expected. |
| address update | 0 | Automates processing of a customer's address-update request in the core customer registry system. |
| address update copy | 0 | A duplicate/secondary variant of the customer address-update workflow, likely for testing or an alternate path. |
| direct deposit update | 0 | Automates processing of a customer's direct-deposit banking information update in the customer registry system. |
| expenses | 0 | Automates routing and validation logic for internal expense submissions, reducing manual finance-team processing effort. |
| jira duplicate account | 0 | Identifies duplicate customer accounts and logs them to a tracking table so the operations team can reconcile them. |
20. Cloud Security Posture — AWS Config & CloudTrail Audit
Category: Cloud Security
Subcategories: CSPM ingest & triage
Description:
Continuously audits AWS for configuration drift and tampering: S3 bucket/ACL changes, WAF and CloudTrail log deletions, root-account and AssumeRoot activity, and unapproved EC2 launches.
Business problem solved:
Cloud misconfigurations and log-tampering are how breaches go undetected; this gives the security team a real-time trip-wire on AWS control-plane changes instead of relying on periodic manual audits.
Integrations: Blink Case Management · Slack · Splunk · AWS
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| KOHO-UC-2025.11.27.01_Non-active AWS Region Changes Detected | 89 | Alerts on cloud infrastructure changes made in AWS regions the company doesn't normally operate in, a sign of possible compromise. |
| Koho CM V9 - KOHO-UC-2025.11.27.01_Non-active AWS Region Changes Detected | 89 | Alerts on cloud infrastructure changes made in AWS regions the company doesn't normally operate in, a sign of possible compromise. |
| KOHO-UC-2024.10.24.2_Bucket Created-LST-AWS | 48 | Detects S3 bucket creation, deletion, or ACL changes so unauthorized or risky storage changes are caught quickly. |
| Koho CM V9 - KOHO-UC-2024.10.24.2 - Bucket Created-LST-AWS | 48 | Alerts when a new AWS storage bucket is created, giving the SOC visibility into new cloud resources that may need security review. |
| Response CM V9 - KOHO-UC-2024.10.24.2_Bucket Created-LST-AWS | 47 | Detects creation of a new AWS S3 bucket outside the normal change process and opens a case to verify it is authorized and properly configured. |
| Fetch AWS IAM User and Email | 29 | Synchronizes AWS IAM user identities with employee email addresses into a shared registry, giving teams visibility into who owns each cloud account. |
| KOHO-UC-2024.10.21.2_S3 Bucket ACL Modification-LST-AWS | 5 | Detects S3 bucket creation, deletion, or ACL changes so unauthorized or risky storage changes are caught quickly. |
| Koho CM V9 - KOHO-UC-2024.10.21.2 - S3 Bucket ACL Modification-LST-AWS | 5 | Alerts when access permissions on an AWS S3 storage bucket are changed, helping catch accidental or malicious exposure of sensitive data. |
| Response CM V9 - KOHO-UC-2024.10.21.2_S3 Bucket ACL Modification-LST-AWS | 5 | Detects unauthorized modifications to AWS S3 bucket access permissions and opens a case with a Slack alert for the security team to review. |
| KOHO-UC-2026.5.27.1_Detect AssumeRoot Invocations | 3 | Alerts whenever the sensitive AWS AssumeRoot privilege is invoked or used in a session, so unexpected root-level activity gets reviewed. |
| Koho CM V9 - KOHO-UC-2026.5.27.1_Detect AssumeRoot Invocations | 3 | Alerts whenever the sensitive AWS AssumeRoot privilege is invoked or used in a session, so unexpected root-level activity gets reviewed. |
| Response CM V9 - KOHO-UC-2026.5.27.1_Detect AssumeRoot Invocations | 3 | Monitors invocations of AWS's temporary root-access ('AssumeRoot') privilege escalation feature and opens a case to verify appropriate use. |
| KOHO-UC-2024.10.24.1_Bucket Deleted-LST-AWS | 2 | Detects S3 bucket creation, deletion, or ACL changes so unauthorized or risky storage changes are caught quickly. |
| KOHO-UC-2026.5.27.2_Detect AssumeRoot Session Actions | 2 | Alerts whenever the sensitive AWS AssumeRoot privilege is invoked or used in a session, so unexpected root-level activity gets reviewed. |
| Koho CM V9 - KOHO-UC-2024.10.24.1 - Bucket Deleted-LST-AWS | 2 | Alerts when an AWS storage bucket is deleted, helping confirm the action was authorized and not a sign of malicious activity or data loss. |
| Koho CM V9 - KOHO-UC-2026.5.27.2_Detect AssumeRoot Session Actions | 2 | Alerts whenever the sensitive AWS AssumeRoot privilege is invoked or used in a session, so unexpected root-level activity gets reviewed. |
| Response CM V9 - KOHO-UC-2024.10.24.1_Bucket Deleted-LST-AWS | 2 | Detects deletion of an AWS S3 bucket and opens a case to confirm it was authorized, guarding against data loss or cover-up of malicious activity. |
| Response CM V9 - KOHO-UC-2026.5.27.2_Detect AssumeRoot Session Actions | 2 | Monitors actions taken during AWS AssumeRoot privileged sessions and opens a case to verify the elevated access was used appropriately. |
| Response V9 - KOHO-UC-2025.11.27.01_Non-active AWS Region Changes Detected | 2 | Detects AWS activity occurring in regions the company doesn't normally use, a common indicator of compromised cloud credentials, and opens a case. |
| Alert on AWS Root Usage | 0 | Detects use of the highly privileged AWS root account and opens a case to ensure appropriate scrutiny. |
| CMPU Audit | 0 | Runs a scheduled audit of AWS resources to verify configuration compliance and catch drift. |
| Detect Large AWS EC2 Instances and Send Report on Slack | 0 | Identifies unusually large AWS EC2 instances and reports them to Slack, helping catch cost or governance outliers. |
| KOHO-UC-2024.03.10.1_S3 Account-Level Block Public Access Disabled | 0 | Alerts when account-level S3 Block Public Access protection is disabled, a critical cloud data-exposure risk. |
| KOHO-UC-2024.10.21.3_AWS WAF Access Control List Deletion | 0 | Alerts when an AWS WAF access control list is deleted, which could disable protection against web attacks. |
| KOHO-UC-2024.10.21.4_AWS WAF Rule or Rule Group Deletion | 0 | Alerts when an AWS WAF rule or rule group is deleted, which could weaken protection against web attacks. |
| KOHO-UC-2024.10.21.5_AWS CloudWatch Log Group Deletion | 0 | Alerts when a CloudWatch log group is deleted, a common technique attackers use to cover their tracks. |
| KOHO-UC-2024.10.21.6_AWS CloudTrail Log Updated | 0 | Alerts when AWS CloudTrail logging configuration is modified, since tampering with audit logs can hide malicious activity. |
| KOHO-UC-2024.10.21.7_AWS CloudTrail Log Suspended | 0 | Alerts when AWS CloudTrail logging is suspended, since this can be used to hide malicious activity from audit logs. |
| KOHO-UC-2024.10.21.8_AWS EC2 Flow Log Deletion | 0 | Alerts when an AWS EC2 VPC flow log is deleted, which removes network traffic visibility used to detect attacks. |
| KOHO-UC-2024.10.23.1_ AWS CloudTrail Log Deleted | 0 | Alerts when an AWS CloudTrail log is deleted outright, a strong signal of an attacker covering their tracks. |
| KOHO-UC-2024.10.23.3_AWS Root Account | 0 | Alerts on activity performed using the AWS root account, since root usage bypasses normal least-privilege controls. |
| KOHO-UC-2024.12.29_Sucessful Bucket Deletion | 0 | Opens a case whenever an S3 bucket is successfully deleted so the change can be verified as authorized. |
| KOHO-UC-2026.03.15.2_ Detect high-volume of new EC2 instances | 0 | Detects an unusually high volume of new EC2 instance launches, a common indicator of stolen cloud credentials being used for abuse. |
| KOHO-UC-2026.03.15.3_GPU/compute-optimized EC2 instance launches | 0 | Flags GPU or compute-optimized EC2 instance launches, which can indicate cryptomining abuse of compromised cloud credentials. |
| KOHO-UC-2026.03.15_EC2 Launch in Non-Approved AWS Region | 0 | Alerts when an EC2 instance is launched in an AWS region that hasn't been approved for company use. |
| Koho CM V9 - KOHO-UC-2024.10.21.2 - S3 Bucket ACL Modification-LST-AWS | 0 | Alerts when access permissions on an AWS S3 storage bucket are changed, helping catch accidental or malicious exposure of sensitive data. |
| Koho CM V9 - KOHO-UC-2024.10.21.3 - AWS WAF Access Control List Deletion | 0 | Notifies the SOC when an AWS web application firewall access control list is deleted, which could remove critical attack protections. |
| Koho CM V9 - KOHO-UC-2024.10.21.3 - AWS WAF Access Control List Deletion | 0 | Notifies the SOC when an AWS web application firewall access control list is deleted, which could remove critical attack protections. |
| Koho CM V9 - KOHO-UC-2024.10.21.4 - AWS WAF Rule or Rule Group Deletion | 0 | Notifies the SOC when a web application firewall rule or rule group is deleted, flagging potential weakening of perimeter defenses. |
| Koho CM V9 - KOHO-UC-2024.10.21.4 - AWS WAF Rule or Rule Group Deletion | 0 | Notifies the SOC when a web application firewall rule or rule group is deleted, flagging potential weakening of perimeter defenses. |
| Koho CM V9 - KOHO-UC-2024.10.21.5 - AWS CloudWatch Log Group Deletion | 0 | Flags deletion of an AWS CloudWatch log group, a common technique attackers use to erase evidence of their activity. |
| Koho CM V9 - KOHO-UC-2024.10.21.5 - AWS CloudWatch Log Group Deletion | 0 | Flags deletion of an AWS CloudWatch log group, a common technique attackers use to erase evidence of their activity. |
| Koho CM V9 - KOHO-UC-2024.10.21.6 - AWS CloudTrail Log Updated | 0 | Detects changes to AWS CloudTrail audit logging configuration that could indicate an attempt to reduce visibility into account activity. |
| Koho CM V9 - KOHO-UC-2024.10.21.6 - AWS CloudTrail Log Updated | 0 | Detects changes to AWS CloudTrail audit logging configuration that could indicate an attempt to reduce visibility into account activity. |
| Koho CM V9 - KOHO-UC-2024.10.21.7 - AWS CloudTrail Log Suspended | 0 | Alerts immediately if AWS CloudTrail audit logging is suspended, since this would blind the organization to further account activity. |
| Koho CM V9 - KOHO-UC-2024.10.21.7 - AWS CloudTrail Log Suspended | 0 | Alerts immediately if AWS CloudTrail audit logging is suspended, since this would blind the organization to further account activity. |
| Koho CM V9 - KOHO-UC-2024.10.23.1 - AWS CloudTrail Log Deleted | 0 | Alerts when AWS CloudTrail audit logs are deleted outright, a high-severity indicator of an attacker covering their tracks. |
| Koho CM V9 - KOHO-UC-2024.10.23.1 - AWS CloudTrail Log Deleted | 0 | Alerts when AWS CloudTrail audit logs are deleted outright, a high-severity indicator of an attacker covering their tracks. |
| Koho CM V9 - KOHO-UC-2024.10.23.3 - AWS Root Account | 0 | Alerts whenever the highly privileged AWS root account is used, since root activity is rare and carries elevated risk if compromised. |
| Koho CM V9 - KOHO-UC-2024.10.23.3 - AWS Root Account | 0 | Alerts whenever the highly privileged AWS root account is used, since root activity is rare and carries elevated risk if compromised. |
| Koho CM V9 - KOHO-UC-2024.10.24.1 - Bucket Deleted-LST-AWS | 0 | Alerts when an AWS storage bucket is deleted, helping confirm the action was authorized and not a sign of malicious activity or data loss. |
| Koho CM V9 - KOHO-UC-2024.10.24.2 - Bucket Created-LST-AWS | 0 | Alerts when a new AWS storage bucket is created, giving the SOC visibility into new cloud resources that may need security review. |
| Koho CM V9 - KOHO-UC-2026.03.15.2_ Detect high-volume of new EC2 instances | 0 | Detects an unusually high volume of new EC2 instance launches, a common indicator of stolen cloud credentials being used for abuse. |
| Koho CM V9 - KOHO-UC-2026.03.15.3_GPU/compute-optimized EC2 instance launches | 0 | Flags GPU or compute-optimized EC2 instance launches, which can indicate cryptomining abuse of compromised cloud credentials. |
| Koho CM V9 - KOHO-UC-2026.03.15_EC2 Launch in Non-Approved AWS Region | 0 | Alerts when an EC2 instance is launched in an AWS region that hasn't been approved for company use. |
| Koho CM V9 - KOHO-UC-2026.5.27.1_Detect AssumeRoot Invocations | 0 | Alerts whenever the sensitive AWS AssumeRoot privilege is invoked or used in a session, so unexpected root-level activity gets reviewed. |
| Koho CM V9 - KOHO-UC-2026.5.27.2_Detect AssumeRoot Session Actions | 0 | Alerts whenever the sensitive AWS AssumeRoot privilege is invoked or used in a session, so unexpected root-level activity gets reviewed. |
| Response CM V9 - KOHO-UC-2024.10.21.2_S3 Bucket ACL Modification-LST-AWS | 0 | Alerts the SOC when an S3 bucket's access control list is modified, helping catch unauthorized changes to cloud storage permissions. |
| Response CM V9 - KOHO-UC-2024.10.21.3_AWS WAF Access Control List Deletion | 0 | Detects deletion of an AWS Web Application Firewall access control list and opens a case to confirm it wasn't unauthorized tampering. |
| Response CM V9 - KOHO-UC-2024.10.21.3_AWS WAF Access Control List Deletion | 0 | Detects deletion of an AWS Web Application Firewall access control list and opens a case to confirm it wasn't unauthorized tampering. |
| Response CM V9 - KOHO-UC-2024.10.21.4_AWS WAF Rule or Rule Group Deletion | 0 | Detects deletion of AWS WAF rules or rule groups that could weaken web application defenses and opens a case for review. |
| Response CM V9 - KOHO-UC-2024.10.21.4_AWS WAF Rule or Rule Group Deletion | 0 | Detects deletion of AWS WAF rules or rule groups that could weaken web application defenses and opens a case for review. |
| Response CM V9 - KOHO-UC-2024.10.21.5_AWS CloudWatch Log Group Deletion | 0 | Detects deletion of AWS CloudWatch log groups that could indicate an attempt to erase audit trails and opens a case for investigation. |
| Response CM V9 - KOHO-UC-2024.10.21.5_AWS CloudWatch Log Group Deletion | 0 | Detects deletion of AWS CloudWatch log groups that could indicate an attempt to erase audit trails and opens a case for investigation. |
| Response CM V9 - KOHO-UC-2024.10.21.6_AWS CloudTrail Log Updated | 0 | Detects changes to AWS CloudTrail logging configuration, a common attacker technique to reduce visibility, and opens a case for review. |
| Response CM V9 - KOHO-UC-2024.10.21.6_AWS CloudTrail Log Updated | 0 | Detects changes to AWS CloudTrail logging configuration, a common attacker technique to reduce visibility, and opens a case for review. |
| Response CM V9 - KOHO-UC-2024.10.21.7_AWS CloudTrail Log Suspended | 0 | Detects suspension of AWS CloudTrail logging, which could mask malicious activity, and raises a case for the security team. |
| Response CM V9 - KOHO-UC-2024.10.21.7_AWS CloudTrail Log Suspended | 0 | Detects suspension of AWS CloudTrail logging, which could mask malicious activity, and raises a case for the security team. |
| Response CM V9 - KOHO-UC-2024.10.21.8_AWS EC2 Flow Log Deletion | 0 | Detects deletion of AWS VPC flow logs that could hide network traffic from investigators and opens a case for review. |
| Response CM V9 - KOHO-UC-2024.10.21.8_AWS EC2 Flow Log Deletion | 0 | Detects deletion of AWS VPC flow logs that could hide network traffic from investigators and opens a case for review. |
| Response CM V9 - KOHO-UC-2024.10.23.1_ AWS CloudTrail Log Deleted | 0 | Detects deletion of AWS CloudTrail audit logs, a high-risk anti-forensic action, and opens a case for urgent investigation. |
| Response CM V9 - KOHO-UC-2024.10.23.1_ AWS CloudTrail Log Deleted | 0 | Detects deletion of AWS CloudTrail audit logs, a high-risk anti-forensic action, and opens a case for urgent investigation. |
| Response CM V9 - KOHO-UC-2024.10.23.3_AWS Root Account | 0 | Detects usage of the highly privileged AWS root account, a critical security control violation, and opens a case for immediate review. |
| Response CM V9 - KOHO-UC-2024.10.23.3_AWS Root Account | 0 | Detects usage of the highly privileged AWS root account, a critical security control violation, and opens a case for immediate review. |
| Response CM V9 - KOHO-UC-2024.10.24.1_Bucket Deleted-LST-AWS | 0 | Detects deletion of an AWS S3 bucket and opens a case to confirm it was authorized, guarding against data loss or cover-up of malicious activity. |
| Response CM V9 - KOHO-UC-2024.10.24.2_Bucket Created-LST-AWS | 0 | Detects creation of a new AWS S3 bucket outside the normal change process and opens a case to verify it is authorized and properly configured. |
| Response CM V9 - KOHO-UC-2026.5.27.1_Detect AssumeRoot Invocations | 0 | Monitors invocations of AWS's temporary root-access ('AssumeRoot') privilege escalation feature and opens a case to verify appropriate use. |
| Response CM V9 - KOHO-UC-2026.5.27.2_Detect AssumeRoot Session Actions | 0 | Monitors actions taken during AWS AssumeRoot privileged sessions and opens a case to verify the elevated access was used appropriately. |
| Response V9 - KOHO-UC-2026.03.15.2_ Detect high-volume of new EC2 instances | 0 | Detects an unusually high volume of new AWS EC2 instances being launched, a possible sign of cryptomining abuse or compromised credentials, and opens a case. |
| Response V9 - KOHO-UC-2026.03.15.3_GPU/compute-optimized EC2 instance launches | 0 | Flags launches of GPU or compute-optimized EC2 instances, commonly abused for cryptomining after account compromise, and opens a case for review. |
| Response V9 - KOHO-UC-2026.03.15_EC2 Launch in Non-Approved AWS Region | 0 | Detects EC2 instances launched in AWS regions outside the company's approved list and opens a case to verify legitimacy. |
21. Privacy, Access-Request & Regulatory Reporting
Category: GRC
Subcategories: DSAR & privacy automation, RBAC review & access mgmt, Security metrics & reporting
Description:
Handles legal production orders and user-access-request (UAR) intake, RBAC/manager access reporting, DLP exposure alerts, and security/AI-usage metrics reporting.
Business problem solved:
Legal and regulatory requests carry firm deadlines and audit exposure; automation ensures consistent intake and reporting instead of relying on ad hoc manual tracking.
Integrations: Slack · Splunk · Blink Case Management · Jira · AWS · BambooHR · JumpCloud · basic-auth · blink
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Blink audit log extraction to S3 | 160 | Exports Blink platform audit logs to S3 on a schedule to support long-term retention and compliance audits. |
| Response V9 - KOHO-UC-2024.5.10 - GitHub Download Activity | 62 | Detects unusual bulk download activity from company GitHub repositories that could indicate source code exfiltration and opens a case for investigation. |
| Non Resident Address Alert | 40 | Flags customer accounts with a non-resident address and sends a report to the compliance team via Slack for review. |
| Populate Manager Report Table of Active Employees - BambooHR | 40 | Syncs the active employee directory from BambooHR into a reporting table used to support manager and access-review reporting. |
| Populate Manager Report Table of Active Employees - BambooHR | 40 | Syncs the active employee directory from BambooHR into a reporting table used to support manager and access-review reporting. |
| PO UAR Webhook | 12 | Receives webhook triggers to process user access review requests tied to Jira production-order tickets. |
| Production Order - UAR Prompt | 6 | Prompts reviewers via Jira to complete a user access review tied to a production change order ticket. |
| Publish staging-ai-coding-assistant Usage Report to Slack | 5 | Publishes a usage report for the staging AI coding assistant to Slack, supporting governance oversight of AI tool adoption. |
| Publish tooling-ai-coding-assistant Usage Report to Slack | 5 | Publishes a usage report for the tooling AI coding assistant environment to Slack for AI governance tracking. |
| Response CM V9 - KOHO-UC-2024.12.13_1Password Export Action | 4 | Detects when a user performs a bulk export from the 1Password vault and opens a case to assess potential large-scale credential exposure. |
| BugBounty Report Statistics | 0 | Pulls statistics from the bug bounty program to track vulnerability submission volume for security leadership. |
| Generate UAR Prompt - Production Order | 0 | Generates a structured prompt for handling a legal production order request for customer data, helping compliance respond within regulatory timelines. |
| Information Request Intake Guide | 0 | Captures incoming customer or legal information requests through a web form and opens a tracked Jira ticket for timely compliance response. |
| Response CM V9 - KOHO-UC-2024.12.13_1Password Export Action | 0 | Detects when a user performs a bulk export from the 1Password vault and opens a case to assess potential large-scale credential exposure. |
| Revoke Access to Gated AI Coding Assistant | 0 | Revokes a user's access to a gated internal AI coding assistant to enforce the company's AI usage governance policy. |
22. Pre-Authorized Payment & Bill-Pay Fraud Controls
Category: Other
Subcategories: Financial & fraud operations
Description:
Screens and blocks pre-authorized debit/credit (PAC/PAD) transactions and bill-pay loads for payee-name mismatches and merchant-level fraud.
Business problem solved:
Pre-authorized payment fraud (payee mismatches, compromised merchants) can drain accounts through a channel customers don't actively monitor; automated screening catches it before settlement.
Integrations: AWS · Jira
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Fraud Care - PAPs Messages Webform | 193 | Captures pre-authorized payment related customer messages through a web form and routes them into the fraud operations pipeline. |
| Bill Pay - Tangerine Loads | 40 | Monitors bill-payment 'load' transactions routed through a banking partner for potentially fraudulent activity. |
| Bill Pay Loads | 40 | Monitors bill-payment loading transactions for anomalies that may indicate fraud. |
| PAC Override Upload (Self-Serve) | 28 | Self-serve tool letting the risk team upload override decisions for flagged pre-authorized transaction name mismatches. |
| PACs - Name Mismatch. Auto-run | 22 | Automatically screens pre-authorized transactions for payee name mismatches to catch potential fraud or processing errors. |
| PAC Name Mismatch Override Bulk Upload - Web Form | 3 | Provides a web form for the risk team to bulk-upload manual overrides for pre-authorized transactions flagged with payee name mismatches. |
| PAD Merchant Block Limit Update | 2 | Updates the transaction limit thresholds used to automatically block risky pre-authorized debit merchants. |
| Bill Pay Fraud Guide | 0 | Guides fraud analysts through investigating and resolving suspicious bill-payment transactions via a linked Jira ticket. |
| PAD Merchant Block | 0 | Blocks specific merchants from initiating pre-authorized debit transactions after fraud or dispute signals are detected. |
| PAP Manual Name Mismatch Msg | 0 | Sends manual notifications for pre-authorized payment transactions flagged with a payee name mismatch. |
23. Employee Offboarding Automation
Category: IAM
Subcategories: Employee offboarding
Description:
Deprovisions departing employees across Slack, Google Workspace, GitHub, JumpCloud, Microsoft 365, Datadog, LaunchDarkly, and Adobe in a single coordinated flow.
Business problem solved:
Manual offboarding across a dozen SaaS tools is slow and error-prone, leaving orphaned access that's a common source of insider risk and audit findings.
Integrations: Slack · Google Workspace · JumpCloud · AWS · Active Directory · Datadog · GitHub · LaunchDarkly · Notion · Splunk
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Offboard Multiple BPO Users | 28 | Processes offboarding for a batch of outsourced (BPO) contractor users and reports status to Slack. |
| Manual Offboarding | 8 | Manually triggered fallback that lets IT run the employee offboarding process on demand when the standard trigger doesn't fire. |
| Offboard - Github | 8 | Removes a departing employee from the company's GitHub organization and notifies IT once complete. |
| Offboard - Google Workspace | 8 | Revokes a departing employee's Google Workspace license, transfers their Drive files, and sets up email forwarding. |
| Offboard - Jumpcloud | 8 | Removes a departing employee's group memberships and access in JumpCloud as part of offboarding. |
| Offboard - Slack | 8 | Removes a departing employee's Slack access, looking up their account before deactivation. |
| Offboard - microsoft 365 | 8 | Deletes a departing employee's Microsoft 365/Active Directory account and removes their assigned licenses. |
| Offboard LaunchDarkly | 8 | Removes a departing employee's access to LaunchDarkly as part of the offboarding checklist. |
| Offboard Multiple BPO | 4 | Batch-offboards multiple outsourced (BPO) contractor accounts and notifies the team via Slack once complete. |
| Offboard - Datadog | 2 | Removes a departing employee's Datadog account access as part of the standard IT offboarding process. |
| Receive Offboard Request from IT | 2 | Captures incoming employee offboarding requests from IT and logs them to kick off the deprovisioning process. |
| Deactivate in Slack | 0 | Looks up a departing employee's Slack account and prompts a confirmation step before deactivating their access. |
| Offboard - adobe cloud | 0 | Revokes a departing employee's Adobe Creative Cloud access as part of the standard offboarding checklist. |
| Offboard multiples BPO users in JIRA Customer | 0 | Offboards multiple outsourced contractor (BPO) users triggered from a Jira customer ticket, notifying the team via Slack. |
| Offboarding Monitoring | 0 | Cross-checks Splunk activity logs against completed offboarding tasks and logs findings in Notion to catch missed deprovisioning steps. |
| Revoke All Users from AWS firefighterGroup | 0 | Automatically revokes temporary 'firefighter' break-glass privileged access in AWS once the elevated access window ends, reducing standing privilege risk. |
| Subflow_One-Click Deactivate Account - With Web Form | 0 | Gives IT/security a one-click web form to instantly deactivate a departing employee's account, speeding up offboarding. |
| Subflow_One-Click Deactivate Accounts | 0 | Disables a departing employee's Google Workspace and JumpCloud accounts in one step, reducing offboarding risk and manual work. |
| Subflow_One-Click Deactivate Accounts | 0 | Disables a departing employee's Google Workspace and JumpCloud accounts in one step, reducing offboarding risk and manual work. |
| Subflow_One-Click Reactivate Account | 0 | Restores a previously deactivated employee's Google Workspace and JumpCloud access in one step when access needs to be reinstated. |
| Subflow_One-Click Reactivate Account | 0 | Restores a previously deactivated employee's Google Workspace and JumpCloud access in one step when access needs to be reinstated. |
| Subflow_One-Click Reactivate Account - With Web Form | 0 | Gives IT/security a one-click web form to quickly reactivate an employee account that was previously deactivated. |
24. Third-Party Fraud Intelligence & Case Utilities
Category: Other
Subcategories: Financial & fraud operations
Description:
Pulls supplementary fraud-intelligence signals (Emailage, Flinks) and supports fraud-case data cleanup for identity-fraud investigations.
Business problem solved:
Fraud investigators need enrichment data from multiple vendors consolidated in one place rather than checking each tool manually.
Integrations: AWS · Google Sheets · Flinks
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Flinks Fails from Previous Day to Google Sheets | 40 | Compiles the prior day's failed bank-account verification attempts into a shared spreadsheet so the operations team can follow up with affected customers. |
| Fraud Tester Merchants | 40 | Identifies merchants being used to test stolen card or account details and logs them to a shared tracker so the fraud team can block them proactively. |
| Emailage Email Upload | 11 | Uploads email risk-scoring data from a fraud-intelligence vendor to support fraud detection and case review. |
| ID Fraud Script Runner | 0 | Runs identity-fraud detection scripts against flagged accounts to support the fraud team's investigation of suspected fake or stolen identities. |
25. Employee Onboarding & Directory Provisioning
Category: IAM
Subcategories: Employee onboarding
Description:
Provisions new-hire accounts across Google Workspace, JumpCloud, and Gmail, including bulk onboarding for BPO/contractor teams.
Business problem solved:
Manual account provisioning delays new-hire productivity and creates inconsistent access setups across teams.
Integrations: Slack · Google Workspace · JumpCloud
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| JumpCloud User Population | 40 | Refreshes the internal user roster from the identity provider to keep employee identity data current for other automations. |
| Onboard Multiple BPO | 13 | Provisions a batch of outsourced (BPO) contractor accounts in JumpCloud and reports progress to Slack. |
| Create Gmail and JC with Prod | 8 | Provisions a new employee's Gmail and JumpCloud accounts together in production, streamlining IT onboarding. |
| Create Gmail User | 0 | Creates a new employee's Gmail account as part of onboarding, with confirmation posted to Slack. |
| Create Gmail User With JumpCloud | 0 | Creates a new employee's Gmail and JumpCloud accounts together to complete IT account provisioning during onboarding. |
| Google Workspace Onboarding - FTE | 0 | Adds a new full-time employee to the correct Google Workspace groups on their start date and notifies the team in Slack once complete. |
| JumpCloud Custom Action and Send Results via Slack | 0 | Runs a custom JumpCloud administrative action and posts the results to Slack for team visibility. |
| Onboarding | 0 | Logs a new hire's details into a tracking table to kick off the employee onboarding process. |
26. Endpoint & Device Inventory Hygiene
Category: Other
Subcategories: Endpoint hygiene & MDM ops
Description:
Audits device-naming conventions, cross-references JumpCloud/SentinelOne/Zscaler device inventories, and keeps WorkWize hardware inventory current.
Business problem solved:
Inconsistent device inventory across MDM/EDR tools creates blind spots for both IT asset management and security coverage.
Integrations: Blink Case Management
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| JumpCloud / S1 / ZCC DeviceName Comparisson | 5 | Cross-checks device naming consistency across identity, EDR, and network security tools to catch unmanaged or misconfigured endpoints. |
| WorkWize Metadata Update | 5 | Keeps employee device and equipment metadata in the WorkWize asset management platform accurate and up to date. |
| WorkWize Weekly Inventory Report | 5 | Generates a weekly report of company equipment inventory from WorkWize to support IT asset tracking. |
| Device Naming Convention Audit | 0 | Audits managed devices to ensure their names follow the corporate naming convention, supporting endpoint inventory hygiene. |
27. Access Review & Credential Hygiene
Category: IAM
Subcategories: Access review & group mgmt, Password & credential lifecycle
Description:
Runs periodic access reviews, MFA compliance checks, and credential/2SV hygiene tasks across JumpCloud, Google Workspace, and 1Password.
Business problem solved:
Access sprawl and MFA gaps are common audit findings; scheduled automated reviews catch drift between formal access-review cycles.
Integrations: JumpCloud · Slack · Google Workspace · 1Password
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Check My JumpCloud User Groups | 6 | Lets an employee self-check which JumpCloud security groups they belong to, with results delivered via Slack. |
| Weekly Google MFA Check | 2 | Runs a weekly audit of Google Workspace users to identify anyone without multi-factor authentication enabled. |
| Weekly JumpCloud MFA Check | 2 | Runs a weekly audit of JumpCloud users to identify anyone without multi-factor authentication enabled. |
| Turn Adaptive MFA back ON | 1 | Automatically re-enables adaptive multi-factor authentication after a temporary exception window closes, preventing controls from staying disabled. |
| 1Password Invite User | 0 | Provisions a new user account in 1Password so employees can securely store and share credentials. |
| 1password Invite | 0 | Emails new employees an invitation to set up their 1Password credential vault account during onboarding. |
| Access Review - Consistency Validation | 0 | Cross-checks user access records for consistency as part of periodic access certification reviews. |
| Access Review - User Inventory | 0 | Pulls a full inventory of user accounts from Google Workspace to support access review and certification. |
| Create BPOs Gmail In Bulk | 0 | Bulk-creates Gmail accounts for outsourced (BPO) staff as part of onboarding, with status posted to Slack. |
| Grant Access to Gated AI Coding Assistant | 0 | Adds an employee to the JumpCloud group that grants access to a restricted AI coding assistant, notifying the team in Slack of the change. |
| RBAC subworkflow - Add user to Jumpcloud user group | 0 | Reusable subworkflow that adds an employee to the correct JumpCloud group to grant role-based access. |
| Subflow - Enroll user in 2SV | 0 | Automatically enrolls a user in two-step verification, strengthening account security without requiring manual IT setup. |
28. Threat Hunting & Critical Vulnerability Detection
Category: Vulnerability Mgmt
Subcategories: Threat hunting & detection
Description:
Runs proactive AI-assisted threat hunts and detects exploitation attempts of critical vulnerabilities such as Log4Shell.
Business problem solved:
Critical CVEs get weaponized within days of disclosure; automated detection closes the gap before a manual hunt would even begin.
Integrations: Blink Case Management · Confluence · Slack
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| AGENT - Threat Hunt | 0 | Runs an AI agent to proactively threat-hunt across the environment and publishes findings to a documentation page. |
| KOHO-UC-2024.10.24.3_Log4jShell Detection | 0 | Detects potential exploitation attempts of the Log4Shell vulnerability against company systems so they can be investigated immediately. |
| Response CM V9 - KOHO-UC-2024.10.24.3_Log4jShell Detection | 0 | Detects active exploitation attempts of the Log4Shell vulnerability in the environment and opens a case for urgent investigation. |
| Response CM V9 - KOHO-UC-2024.10.24.3_Log4jShell Detection | 0 | Detects active exploitation attempts of the Log4Shell vulnerability in the environment and opens a case for urgent investigation. |
29. Threat Intelligence Ingestion & Curation
Category: SOC
Subcategories: Threat intel ingest & curation
Description:
Ingests and curates external threat-intelligence signals, including nation-state IOC feeds, botnet alerts, and domain-registry monitoring, to keep detection content current.
Business problem solved:
Detection rules go stale without a continuous feed of new indicators; this keeps the SOC's IOC library current against emerging threats.
Integrations: Blink Case Management · Slack · Splunk · GitHub · Microsoft Outlook · Notion
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Domain Registry Monitor | 0 | Monitors newly registered domains that could be used for phishing or brand impersonation, logging findings for the security team. |
| Incoming Botnet Alert | 0 | Automatically opens a SOC case whenever a botnet-related security alert fires, ensuring timely analyst triage and response. |
| Irregular Domains - burst | 0 | Flags a sudden burst of connections to irregular or newly observed domains, a pattern often linked to malware command-and-control traffic. |
| KOHO-UC-2024.10.23.9_Threat Feed Malware L2R - GTIC IP | 0 | Opens a case when internal telemetry matches a known malicious IP from the threat-intel feed, prompting investigation. |
| KOHO-UC-2025-11-25 - North Korean IOCs | 0 | Checks observed activity against a curated list of North Korea-linked threat indicators to flag potential nation-state risk. |
| Koho CM V9 - KOHO-UC-2024.10.23.9 - Threat Feed Malware L2R - GTIC IP | 0 | Matches internal traffic against a curated threat-intelligence feed of known malware IP addresses to catch outbound communication to malicious infrastructure. |
| Koho CM V9 - KOHO-UC-2024.10.23.9 - Threat Feed Malware L2R - GTIC IP | 0 | Matches internal traffic against a curated threat-intelligence feed of known malware IP addresses to catch outbound communication to malicious infrastructure. |
| Koho CM V9 - KOHO-UC-2025-11-25 - North Korean IOCs | 0 | Checks observed activity against a curated list of North Korea-linked threat indicators to flag potential nation-state risk. |
| Response CM V9 - KOHO-UC-2024.10.23.9_Threat Feed Malware L2R - GTIC IP | 0 | Correlates internal traffic against a curated threat-intel feed of known malicious IPs and opens a case when a malware communication match is found. |
| Response CM V9 - KOHO-UC-2024.10.23.9_Threat Feed Malware L2R - GTIC IP | 0 | Correlates internal traffic against a curated threat-intel feed of known malicious IPs and opens a case when a malware communication match is found. |
| Response Subflow - Phishing | 0 | Retrieves the reported email message from the corporate mailbox to support the SOC's phishing investigation and response process. |
| Response V9 - KOHO-UC-2025-11-25 - North Korean IOCs | 0 | Matches network activity against known North Korean threat-actor indicators of compromise and opens a case when a match is found. |
| Subflow - KOHO-UC-2025-11-25 - North Korean IOCs | 0 | Checks incoming case data against a curated list of known North Korean threat-actor indicators to flag matches for the SOC. |
Key Observations
- Scale. 772 active business playbooks executed 342,511 times in the last 12 months, spanning fraud operations, a full SIEM-fed SOC pipeline, cloud security, IAM, GRC, and engineering/data automation. An additional 199 workflows in the raw export (onboarding tutorial templates, dev/test scaffolds, and unbuilt placeholders — all with zero executions) were excluded as they carry no business function.
- Fraud & risk operations is the largest single program. 255 playbooks tagged "Other" (240,991 executions) are dominated by real-time transaction risk scoring, the Fraud Alert System (FAS) case pipeline, Interac/e-Transfer fraud recovery, account-takeover detection, and vulnerable-customer protection — reflecting Koho's core exposure as a consumer fintech.
- A mature, SIEM-fed Agentic SOC is in production. 328 SOC playbooks (76,962 executions) implement a full detection-to-response lifecycle: Splunk correlation rules feed Blink Case Management, cases are auto-enriched against CrowdStrike/VirusTotal/AbuseIPDB/WHOIS, and dedicated response playbooks handle identity threats, malware/EDR containment, and threat-intel curation. Many detection rules are deployed in duplicate across two case-management workspaces, suggesting an active migration or blue/green rollout of the SOC case-management platform ("CM V9") worth consolidating once the migration completes.
- Cloud security is concentrated on AWS control-plane integrity. 88 playbooks (1,532 executions) watch for CloudTrail tampering, S3/WAF/ACL changes, and unapproved EC2 launches — high-value detective controls, though low execution counts suggest these are (appropriately) rare-event trip-wires rather than high-volume pipelines.
- IAM and GRC automation cover the full identity and compliance lifecycle — onboarding, offboarding, privileged/JIT access, access reviews, AML/KYC screening (Onfido, Trulioo, FINTRAC), and privacy/regulatory reporting — reducing manual, audit-sensitive work across 97 playbooks.
- Gap: Vulnerability Management is the thinnest category (4 playbooks, threat hunting and Log4Shell detection only) — there's no evidence of a systematic vuln-scanning-ingest-to-ticket pipeline, which is a natural next area for expansion.
- Integration ecosystem. The program integrates with 45 distinct external systems. The most-used are: Blink Case Management, Slack, AWS, Splunk, Jira, Google Sheets, JumpCloud, Google Workspace, GitHub, AbuseIPDB, VirusTotal, Kustomer, CrowdStrike, Cloudflare, Gmail. Slack, Jira, and AWS anchor the majority of workflows as the primary notification, case-tracking, and infrastructure surfaces.
E New Integrations (detail) 3 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Koho | slack | thomas_slack_connection | 2026-08-27 |
| Koho | slack | my_slack_connection_1 | 2026-07-31 |
| Koho | slack | it_slack_admin_connection | 2026-07-31 |