01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic IT Helpdesk & AI Request Triage |
| 86.0% | 6 6 active |
| SOC Automation & Case Management | 3 executions | 6.0% | 16 16 active |
| Alert Enrichment & IOC Lookup | 0 executions | 0.0% | 34 34 active |
| EDR Containment & Endpoint Response | 0 executions | 0.0% | 5 5 active |
| Employee Onboarding & Identity Management | 0 executions | 0.0% | 8 8 active |
| Network Infrastructure Automated Patching | 0 executions | 0.0% | 4 0 active |
| IT Asset & SaaS Administration |
| 8.0% | 3 2 active |
| Vulnerability Notification | 0 executions | 0.0% | 1 1 active |
| Total | 50 executions | 100% | 77 72 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep SOC investment, fully built but not yet in production. The largest portion of the automation estate — a complete alert-to-case pipeline (Process Alert → Extract Observables → Enrich → Respond) with 50+ supporting playbooks — is fully built but shows zero executions over 12 months. This represents significant platform investment and readiness; the infrastructure is in place to handle high-volume SOC operations the moment the pipeline is activated.
Agentic AI is the only live, high-volume use case. The Microsoft Teams DM triage workflow (Incoming Message Tagged → Process Incoming DM) is the most active automation in the environment, processing 65 events in 12 months using Claude for classification and ClickUp for ticket creation. This is a genuinely differentiated, AI-native use case demonstrating that the team is comfortable with agentic automation patterns.
Broad enrichment coverage across 8+ sources. The enrichment library covers CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, and Whois. Once the SOC pipeline goes live, this enrichment depth will provide immediate, multi-source context on every observable without analyst effort.
Dual-platform EDR readiness. The environment has containment playbooks for both CrowdStrike (RTR, isolation) and Aurora/Cylance, covering both real-time response and device lockdown — giving the SOC flexibility regardless of which EDR is primary on a given endpoint.
Infrastructure automation running reliably. The four PWR-GTWY auto-update workflows are executing on schedule, demonstrating that Blink is trusted for production-level operational automation, not just security tooling.
###
Gaps & Opportunities
SOC pipeline activation is the highest-value near-term action. The Process Alert workflow and all downstream enrichment/response playbooks are at zero executions. If CrowdStrike and Okta alerts are currently being processed manually, activating this pipeline could be the single highest-ROI change available — turning the entire existing SOC automation investment into production value.
Employee onboarding has no executions despite being fully built. Both the BambooHR webhook-triggered and web-form-triggered onboarding workflows are at zero. Given the complexity of the Onboard New Employee playbook (Entra ID provisioning, Local AD creation, Snipe-IT hardware checkout, ClickUp ticketing, Teams notifications), activating this would deliver significant time savings per hire.
Vulnerability notification is a single, on-demand playbook with no executions. Intruder is connected but the workflow runs only when manually triggered. Converting this to a scheduled or webhook-triggered flow would ensure findings are distributed automatically after every scan.
No cloud security coverage. There are no automations in the CSPM, cloud config audit, or cloud asset inventory categories. If MotivHealth operates cloud workloads (AWS, Azure, GCP), this is an unaddressed area for platform expansion.
Duplicate active workflows suggest ongoing iteration. The "(Eyes emoji) Process Incoming DM copy" workflow running alongside "Process Incoming DM (Push-Pin)" suggests a version-in-progress. Consolidating these reduces operational risk from split execution counts and divergent logic.
Integration Ecosystem
| Category | Integrations in Use |
|---|---|
| EDR & Endpoint | CrowdStrike, Aurora/Cylance |
| Identity & IAM | Microsoft Entra ID (Azure AD), Okta, Local AD (WinRM) |
| Threat Intelligence | VirusTotal, URLScan, AbuseIPDB, Whois |
| Productivity & Comms | Microsoft Teams, Microsoft Outlook, Email (core) |
| Ticketing & ITSM | ClickUp |
| HR | BambooHR |
| Asset Management | Snipe-IT |
| Collaboration | Slack (enrichment), GitHub (enrichment) |
| AI | Anthropic Claude |
| Directory | Google Workspace |
| Vulnerability Scanning | Intruder |
| Web/SaaS | WordPress API |
| Case Management | Blink Case Management (native) |
A Case Management 1 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| IT Workspace | 1 | 1 | 0 | N/A |
B AI Agents 1 active | 16 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Clicky UpShot | Blink Hackathon | 16 | 0 | 1,270,392 |
| 2 | Agent Blink | IT Workspace | 0 | 0 | 0 |
| 3 | Agent Smith | vschill@motivhealth.com | 0 | 0 | 0 |
| 4 | New Agent | Blink Hackathon | 0 | 0 | 0 |
| 5 | Test Agent | chill@motivhealth.com | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Blink Hackathon | 16 |
| IT Workspace | 0 |
| vschill@motivhealth.com | 0 |
| chill@motivhealth.com | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Hello World | 0 | 0 |
| 2 | Case Management | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Onboarding | 0 | 0 |
| 2 | New employee onboarding | 0 | 0 |
| 3 | Refresh Environment Databases | 0 | 0 |
| 4 | Add User to a group in Entra | 0 | 0 |
| 5 | Self-service Demo | 0 | 0 |
D Full Use Case Analysis 8 use cases | 50 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| IT service requests captured and queued for automated AI triage | 38 | Incoming Message Tagged |
| IT requests AI-analyzed by Claude, ticketed in ClickUp, and routed to the team | 27 | Process Incoming DM (Push-Pin) + Process Incoming DM copy |
| Automated patch runs executed across network gateway nodes | 8 | PWR-GTWY-01/02/03/04 Auto-Update |
| IT asset lifecycle events synced between ClickUp and Snipe-IT | 2 | ClickUp to Snipe-IT: Asset Management Sync |
| WordPress multisite plugin compliance audits completed automatically | 1 | Wordpress API Multisite Main |
Use Case Summary
| # | Use Case | Category | Playbooks | Executions (12 mo) |
|---|---|---|---|---|
| 1 | Agentic IT Helpdesk & AI Request Triage | SOC / Other | 6 | 65 |
| 2 | SOC Automation & Case Management | SOC | 16 | 0 |
| 3 | Alert Enrichment & IOC Lookup | SOC | 34 | 0 |
| 4 | EDR Containment & Endpoint Response | SOC | 5 | 0 |
| 5 | Employee Onboarding & Identity Management | IAM | 8 | 0 |
| 6 | Network Infrastructure Automated Patching | Other | 4 | 8 |
| 7 | IT Asset & SaaS Administration | Other | 3 | 3 |
| 8 | Vulnerability Notification | Vulnerability Mgmt | 1 | 0 |
| Total | 77 | 76 |
Use Cases
1. Agentic IT Helpdesk & AI Request Triage
Description: AI-powered triage of inbound IT service requests arriving via Microsoft Teams. When a team member pins or tags a message, Blink captures it, invokes Claude to classify the request and extract key context, creates a ClickUp task, and notifies the requester — removing the manual intake step entirely.
Business Problem Solved: IT teams spend significant time manually reading, categorizing, and routing inbound requests from Teams DMs. This use case eliminates that triage overhead, ensuring every flagged message is processed consistently, logged in a tracking system, and acknowledged within minutes.
Integrations: Microsoft Teams, Anthropic Claude, ClickUp, Blink Tables
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| Incoming Message Tagged | Event (Webhook) | 38 | SOC | Agentic SOC |
| Process Incoming DM (Push-Pin) | Event (Polling) | 21 | SOC | Agentic SOC |
| (Eyes emoji) Process Incoming DM copy | Event (Polling) | 6 | SOC | Agentic SOC |
| Self-service Demo | Event (Web Form) | 0 | Other | IT helpdesk & ticket routing |
| Self-service URL | On-demand | 0 | Other | IT helpdesk & ticket routing |
| ClickUp Ticket Search | On-demand | 0 | Other | IT helpdesk & ticket routing |
2. SOC Automation & Case Management
Description: A full case management and SOAR pipeline built natively in Blink. New alerts from any source are ingested, observables are extracted, cases are deduplicated and created, enrichment is triggered in parallel, and automated response playbooks are dispatched based on alert type (phishing, malware). Utility workflows support observable relationship tracking, stale case hygiene, and recovery handling for missed alerts. A Claude-powered triage module is available for AI-assisted analyst support.
Business Problem Solved: Security teams face alert fatigue and inconsistent incident handling when alert processing is manual. This pipeline automates the full alert-to-case lifecycle — ensuring every alert is processed, deduplicated against existing cases, enriched, and routed to the appropriate response workflow within minutes of detection.
Integrations: Blink Case Management, CrowdStrike, Okta, Microsoft Outlook, Anthropic Claude, Darktrace
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| Process Alert | Event (Polling) | 0 | SOC | Case mgmt & SOAR |
| Ingest Alert Darktrace | Event | 0 | SOC | SIEM & log pipeline monitoring |
| Response Subflow - Phishing | On-demand (Subflow) | 0 | SOC | Phishing detection & response |
| Response Subflow - Malware | On-demand (Subflow) | 0 | SOC | Case mgmt & SOAR |
| Subflow - Response - Main Router | On-demand (Subflow) | 0 | SOC | Case mgmt & SOAR |
| Subflow - Missing Alert Template Notification | On-demand (Subflow) | 0 | SOC | Case mgmt & SOAR |
| Claude Alert Triage | On-demand | 0 | SOC | Agentic SOC |
| Utility - Close Stale Cases | On-demand | 0 | SOC | Case mgmt & SOAR |
| Utility - Find Similar Cases Based on Observables | On-demand | 0 | SOC | Case mgmt & SOAR |
| Table Action - Validate Observables Extraction Template | On-demand | 0 | SOC | Case mgmt & SOAR |
| Recovery - Handle Unprocessed Alerts | On-demand | 0 | SOC | Case mgmt & SOAR |
| Recovery - Enrich Non-Enriched Observables | On-demand | 0 | SOC | Case mgmt & SOAR |
| Error Handling - Send Error Notification Email | On-demand (Utility) | 0 | SOC | Case mgmt & SOAR |
| Simulate Crowdstrike Alert | On-demand | 0 | SOC | Case mgmt & SOAR |
| Simulate Multiple Alerts from Different Sources | On-demand | 0 | SOC | Case mgmt & SOAR |
| USE WITH CARE - Reset Case Management Environment | On-demand (Admin) | 0 | SOC | Case mgmt & SOAR |
3. Alert Enrichment & IOC Lookup
Description: A comprehensive library of enrichment playbooks that look up observables — IP addresses, domains, URLs, file hashes, usernames, and email addresses — across 8+ threat intelligence and identity sources, storing structured results back into the case management system. Observable relationship utilities support linking and querying connections between alerts and observables.
Business Problem Solved: Manual IOC lookup across multiple tools is time-consuming and inconsistent. This enrichment layer automatically queries multiple data sources for every observable in a case, giving analysts a complete threat picture within seconds of alert creation, without leaving the case management interface.
Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, Whois, Blink Case Management
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| Subflow - Enrich Observables - Main Router | On-demand (Subflow) | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | On-demand (Subflow) | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Update Enrichment | On-demand (Utility) | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Set Or Update Observable Relation | On-demand (Utility) | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - List Alert Observable Relations | On-demand (Utility) | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - List Observable Alert Relations | On-demand (Utility) | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Delete Observable Relation | On-demand (Utility) | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username - Github | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Github | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Okta Search for User Activity | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Okta | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | On-demand | 0 | SOC | Phishing detection & response |
| Secure URL Screenshot Capture | On-demand | 0 | SOC | Phishing detection & response |
| Get End of Life Date for a Product | On-demand | 0 | Vulnerability Mgmt | CVE lookup & remediation |
4. EDR Containment & Endpoint Response
Description: Playbooks for containing compromised or lost endpoints via CrowdStrike and Aurora (Cylance), including remote triage commands, host isolation, device lock/wipe workflows, and coordinated lost/stolen laptop response that spans identity revocation, asset tracking, and management approval.
Business Problem Solved: When an endpoint is compromised or a device is lost, response time is critical. These playbooks enable instant isolation and containment actions from Blink, removing the need for analysts to manually navigate multiple EDR consoles, and ensure that lost/stolen device incidents are handled with a consistent, documented, multi-step response.
Integrations: CrowdStrike (RTR & Host Actions), Aurora/Cylance, Microsoft Entra ID, Snipe-IT, ClickUp, Microsoft Teams
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| CrowdStrike RTR to a Batch of Hosts | On-demand | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | On-demand | 0 | SOC | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | On-demand | 0 | SOC | EDR containment & response |
| Aurora Lockdown Device | On-demand | 0 | SOC | EDR containment & response |
| Lost/Stolen Laptop | On-demand | 0 | SOC | EDR containment & response |
5. Employee Onboarding & Identity Management
Description: End-to-end employee lifecycle automation covering new hire provisioning and access management. The onboarding workflows span BambooHR-triggered and web-form-triggered flows, provisioning accounts in both cloud (Microsoft Entra ID) and on-premises (Local AD) environments, assigning security groups by department, checking out hardware in Snipe-IT, and notifying stakeholders via Teams and email. Supporting workflows handle access group management and disable offboarded accounts in Local AD.
Business Problem Solved: Manual employee onboarding involves coordinating across HR systems, Active Directory, IT asset management, and multiple communications channels — creating delays and risk of missed steps. These workflows codify the entire checklist into a repeatable, auditable process that executes within minutes of a new hire trigger.
Integrations: BambooHR (webhook), Microsoft Entra ID (Azure AD), Local AD (WinRM), Snipe-IT, ClickUp, Microsoft Teams, Email
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| Onboarding | Event (Webhook — BambooHR) | 0 | IAM | Employee onboarding |
| Onboard New Employee | Event (Web Form) | 0 | IAM | Employee onboarding |
| Create user in Local AD | On-demand (Subflow) | 0 | IAM | Employee onboarding |
| Disable User in Local AD | On-demand | 0 | IAM | Employee offboarding |
| Add New User to Entra Group | Event (Web Form) | 0 | IAM | Access review & group mgmt |
| Get All Security Groups | On-demand | 0 | IAM | Access review & group mgmt |
| Refresh Environment Databases | Event (Web Form) | 0 | IAM | Identity lifecycle automation |
| ScratchPad - Entra Group Management | On-demand | 0 | IAM | Access review & group mgmt |
6. Network Infrastructure Automated Patching
Description: Scheduled workflows that run automated Windows Update commands over WinRM on four named network gateway servers (PWR-GTWY-01 through 04), verifying patch status and conditionally taking action after each run. All four execute on the same monthly schedule.
Business Problem Solved: Manually patching network infrastructure devices requires scheduling maintenance windows and manual SSH/RDP access. These workflows automate patch execution and verification on a fixed schedule, reducing operational burden and ensuring gateways stay current without analyst involvement.
Integrations: WinRM (Windows Remote Management)
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| PWR-GTWY-01 Auto-Update | Scheduled (Monthly) | 2 | Other | IT/OT & network infra monitoring |
| PWR-GTWY-02 Auto-Update | Scheduled (Monthly) | 2 | Other | IT/OT & network infra monitoring |
| PWR-GTWY-03 Auto-Update | Scheduled (Monthly) | 2 | Other | IT/OT & network infra monitoring |
| PWR-GTWY-04 Auto-Update | Scheduled (Monthly) | 2 | Other | IT/OT & network infra monitoring |
7. IT Asset & SaaS Administration
Description: Automations that keep IT asset data and SaaS platforms in sync. The ClickUp-to-Snipe-IT sync updates asset statuses in the hardware tracking system whenever a ClickUp ticket is updated. The WordPress workflows audit plugins across a multisite installation on a weekly schedule, and allow on-demand plugin inspection by IT staff via a Teams-based interactive selector.
Business Problem Solved: Keeping asset inventory and SaaS platform state synchronized across tools manually is error-prone and time-consuming. These automations ensure asset lifecycle changes in the ticketing system are reflected in hardware inventory in real time, and that WordPress plugin hygiene is audited regularly without manual effort.
Integrations: ClickUp, Snipe-IT, WordPress API, Microsoft Teams
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| ClickUp to Snipe-IT: Asset Management Sync | Event (ClickUp Webhook) | 2 | Other | SaaS / IT administration |
| Wordpress API Multisite Main | Scheduled (Weekly) | 1 | Other | SaaS / IT administration |
| WP Plugins | On-demand | 0 | Other | SaaS / IT administration |
8. Vulnerability Notification
Description: Fetches vulnerability data from the Intruder scanning platform, formats it into a summary report, and sends a notification email to designated recipients.
Business Problem Solved: Security teams need to distribute vulnerability scan results to stakeholders without requiring manual export and formatting. This automation ensures findings are pushed to the right people immediately after a scan, reducing time-to-awareness for newly discovered exposures.
Integrations: Intruder, SendGrid, Microsoft Outlook
| Playbook | Type | Executions | Category | Subcategory |
|---|---|---|---|---|
| Intruder Notification | On-demand | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
Key Observations
Strengths
Deep SOC investment, fully built but not yet in production. The largest portion of the automation estate — a complete alert-to-case pipeline (Process Alert → Extract Observables → Enrich → Respond) with 50+ supporting playbooks — is fully built but shows zero executions over 12 months. This represents significant platform investment and readiness; the infrastructure is in place to handle high-volume SOC operations the moment the pipeline is activated.
Agentic AI is the only live, high-volume use case. The Microsoft Teams DM triage workflow (Incoming Message Tagged → Process Incoming DM) is the most active automation in the environment, processing 65 events in 12 months using Claude for classification and ClickUp for ticket creation. This is a genuinely differentiated, AI-native use case demonstrating that the team is comfortable with agentic automation patterns.
Broad enrichment coverage across 8+ sources. The enrichment library covers CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, and Whois. Once the SOC pipeline goes live, this enrichment depth will provide immediate, multi-source context on every observable without analyst effort.
Dual-platform EDR readiness. The environment has containment playbooks for both CrowdStrike (RTR, isolation) and Aurora/Cylance, covering both real-time response and device lockdown — giving the SOC flexibility regardless of which EDR is primary on a given endpoint.
Infrastructure automation running reliably. The four PWR-GTWY auto-update workflows are executing on schedule, demonstrating that Blink is trusted for production-level operational automation, not just security tooling.
Gaps & Opportunities
SOC pipeline activation is the highest-value near-term action. The Process Alert workflow and all downstream enrichment/response playbooks are at zero executions. If CrowdStrike and Okta alerts are currently being processed manually, activating this pipeline could be the single highest-ROI change available — turning the entire existing SOC automation investment into production value.
Employee onboarding has no executions despite being fully built. Both the BambooHR webhook-triggered and web-form-triggered onboarding workflows are at zero. Given the complexity of the Onboard New Employee playbook (Entra ID provisioning, Local AD creation, Snipe-IT hardware checkout, ClickUp ticketing, Teams notifications), activating this would deliver significant time savings per hire.
Vulnerability notification is a single, on-demand playbook with no executions. Intruder is connected but the workflow runs only when manually triggered. Converting this to a scheduled or webhook-triggered flow would ensure findings are distributed automatically after every scan.
No cloud security coverage. There are no automations in the CSPM, cloud config audit, or cloud asset inventory categories. If MotivHealth operates cloud workloads (AWS, Azure, GCP), this is an unaddressed area for platform expansion.
Duplicate active workflows suggest ongoing iteration. The "(Eyes emoji) Process Incoming DM copy" workflow running alongside "Process Incoming DM (Push-Pin)" suggests a version-in-progress. Consolidating these reduces operational risk from split execution counts and divergent logic.
Integration Ecosystem
| Category | Integrations in Use |
|---|---|
| EDR & Endpoint | CrowdStrike, Aurora/Cylance |
| Identity & IAM | Microsoft Entra ID (Azure AD), Okta, Local AD (WinRM) |
| Threat Intelligence | VirusTotal, URLScan, AbuseIPDB, Whois |
| Productivity & Comms | Microsoft Teams, Microsoft Outlook, Email (core) |
| Ticketing & ITSM | ClickUp |
| HR | BambooHR |
| Asset Management | Snipe-IT |
| Collaboration | Slack (enrichment), GitHub (enrichment) |
| AI | Anthropic Claude |
| Directory | Google Workspace |
| Vulnerability Scanning | Intruder |
| Web/SaaS | WordPress API |
| Case Management | Blink Case Management (native) |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.