01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| IOC Enrichment & Automated Ticket Management | 1,695 executions | 10.6% | 12 12 active |
| Threat Intelligence Feed Management |
| 2.0% | 2 2 active |
| SIEM Threshold Monitoring | 262 executions | 1.6% | 3 3 active |
| Identity Threat Response — High-Risk Travel |
| 0.2% | 1 1 active |
| Phishing Detection & Response | 0 executions | 0.0% | 2 2 active |
| Credential Exposure Monitoring |
| 0.0% | 1 1 active |
| CI/CD Security Scanning & Alert Routing |
| 1.7% | 2 2 active |
| Third Party Risk Management (TPRM) |
| 1.4% | 6 0 active |
| Data Privacy, Legal Hold & Compliance Reporting |
| 70.3% | 4 4 active |
| Identity Directory Sync & BYOD Management |
| 0.4% | 5 3 active |
| Employee Offboarding Automation |
| 0.2% | 1 1 active |
| Inactive User & Access Hygiene Reporting | 12 executions | 0.1% | 2 1 active |
| MFA Security & Duo Management |
| 0.2% | 2 2 active |
| Entra Credential Lifecycle Management | 6 executions | 0.0% | 1 1 active |
| Endpoint Security, MDM & Network Access |
| 1.3% | 19 19 active |
| IT Platform Operations & Monitoring |
| 1.8% | 9 9 active |
| Total | 14,749 executions | 100% | 72 63 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature IOC Enrichment Engine: The most-executed automation is the IOC enrichment framework — 930 IP cache lookups in 12 months indicates a high-volume, production-grade deployment. The layered architecture (extraction → deduplication → caching → enrichment → ticket update) reflects significant engineering investment and operational maturity. Shared subflows reused across JIRA, PagerDuty, and Splunk pipelines is a strong design pattern.
Broad Security Stack Coverage: The automation stack spans Splunk, Microsoft Defender for Endpoints, Microsoft XDR, Wiz, Okta, Entra ID, Zscaler, Duo, VirusTotal, HaveIBeenPwned, Ransomware.live, PagerDuty, and JIRA. The breadth of integration coverage across SOC, IAM, endpoint, and cloud security signals a mature, multi-stakeholder automation program.
Compliance Automation Depth: The GRC use cases are unusually well-developed. The ServiceNow → AuditBoard → questionnaire → risk creation pipeline represents a fully automated TPRM lifecycle. The Purview legal hold, Workday offboarding, and BigID labeling automations demonstrate regulatory-grade compliance investment — particularly relevant for a life sciences company.
DevSecOps Coverage: 337 Wiz CI/CD scan events automatically triaged and routed in 12 months places this program ahead of most peers in operationalizing DevSecOps alerting without manual security review queues.
Platform Self-Management: Automating Blink's own workflow backups, error handling, and platform health checks reflects a mature team that treats their SOAR platform as production infrastructure — not just a tool.
Expanding Analyst Self-Service Toolkit: A growing set of on-demand lookup tools (IP reputation, VirusTotal IOC checks, Entra user lookups, Defender file retrieval, Intune device lookups) saw 176 combined executions, indicating analysts are increasingly using Blink as a manual investigation aid alongside the fully automated pipelines.
###
Gaps & Opportunities
Phishing Response Gap: The phishing detection workflow (0 executions) is built and deployed but not receiving Outlook webhook events. Activating this would extend automated IOC enrichment to user-reported phishing at no additional development cost, adding another high-volume enrichment channel.
Browser Extension Visibility: Six browser extension inventory workflows exist across multiple development iterations but have never been executed. Given the active Intune and Defender investment, activating extension auditing would close a meaningful endpoint hygiene gap — particularly relevant for detecting unauthorized AI tools or data exfiltration browser extensions.
AI Governance Gap: An "Update AI Usage Data" workflow using Reco AI exists but has never been executed. With OpenAI already integrated in the Zscaler checker and AI tool usage a growing compliance concern in life sciences, activating AI governance monitoring would be a natural next step.
Duo Unenrolled Users: The Duo unenrolled user reporting workflow (0 executions) exists but has not been activated. Given the active Duo bypass monitoring, pairing it with enrollment gap reporting would provide complete MFA coverage.
Wiz Secrets Posture: "Get Secrets from Wiz" (0 executions) could complement the active CI/CD scanning pipeline with periodic full secrets posture reviews rather than only event-driven coverage.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| SIEM / Logging | Splunk |
| Ticketing / Case Mgmt | JIRA (Cloud), PagerDuty, ServiceNow |
| EDR / XDR | Microsoft Defender for Endpoints, Microsoft XDR Defender |
| Cloud Security | Wiz |
| Network Security | Zscaler (ZIA, Client Connector / OneAPI) |
| Browser Security | SquareX |
| Identity | Microsoft Entra ID, Okta, Duo |
| Compliance / GRC | AuditBoard, Microsoft Purview (via MS Graph) |
| DLP / Data | BigID |
| Threat Intel | VirusTotal (via IOC subflows), IPInfo, HaveIBeenPwned, Ransomware.live |
| Communication | Microsoft Outlook, Microsoft Teams, Email |
| HR / Offboarding | Workday (via HTTP) |
| Source Control | GitHub |
| AI | OpenAI (GPT), Reco AI |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 1 active | 92 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Ticket Enhancer Agent | DevCyberSecurity | 92 | 57 | 5,113,785 |
| Workspace | Tasks (12m) |
|---|---|
| DevCyberSecurity | 92 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Ori Test | 0 | 0 |
| 2 | Browser Extensions | 0 | 0 |
| 3 | Defender/Entra/Intune/Zscaler Dashboard | 0 | 0 |
| 4 | test | 0 | 0 |
| 5 | BlinkOps Classes | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Training Web Form - Print a nice message! | 0 | 0 |
D Full Use Case Analysis 16 use cases | 16,048 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-enriched with IOC intelligence and ticket updates driven | 785 | JIRA - Lookup all IOCs and Update Ticket with Formatting (+694), Pager Duty - Lookup all IOCs and Update Ticket (+45), Ingest Splunk Alerts via Webhook and create JIRA ticket (+46) |
| CI/CD security scan findings triaged and routed to stakeholders | 337 | Get CI/CD Scan and alert parties - Events |
| Threat intel feed updates pushed to Splunk and Microsoft Defender | 241 | Update IOCs in Splunk and Defender |
| Token expiration events automatically detected and teams notified | 199 | Token Refresh Alerting |
| Ad hoc SOC investigations supported via on-demand IOC, user, and file lookups | 166 | Lookup User in Entra (+112), Look up IP in IPInfo (+30), Lookup IOC in VirusTotal (+23), Defender Getfile by Hostname and Path (+1) |
| SIEM threshold breach events monitored and tracked through resolution | 140 | Check for Splunk Beyond Threshold - New Records Trigger (+49), Check for Splunk Beyond Threshold - Updated Records Trigger (+91) |
| Vendor questionnaire status check-ins automated | 96 | Update Questionnaire Status |
| Elevated endpoint privilege management events detected and teams notified | 84 | Elevated Endpoint Privilege Management Notification |
| Third-party vendor risk assessments initiated end-to-end | 59 | Assessment Service Request Trigger - Prod |
| Departing employees automatically placed under legal hold in Microsoft Purview | 41 | Push Departing Users to Purview |
| Duo MFA bypass events automatically investigated | 41 | Duo Bypass Lookup |
| Legal hold and eDiscovery compliance reports generated | 40 | Generate and Email MBrewer a report on new Mailboxes & SharePoint Sites(New) |
| Entra security groups automatically assigned to applications based on naming convention | 30 | Auto Assign Entra Groups to App Based On Group Name |
| High-risk travel security alerts automatically processed and routed | 29 | Process new High Risk Travel emails |
| Endpoint security dashboard data automated refreshes | 29 | Update Data for Defender/Intune/Zscaler Dashboard |
| Press release MNPI monitoring runs executed | 29 | Update Press Releases V2 |
| Unassigned Windows device alerts sent to IT support leadership | 29 | Send Email to IT Support Leadership of Unassigned Windows Devices in Intune every weekday morning at 9am |
| Ransomware threat actor targeting checks | 28 | Daily Ransomware.live First Party Monitor |
| Vendor risks automatically created in AuditBoard | 21 | Create AuditBoard Risk |
| On-demand device lookups performed against Intune for investigations | 10 | Look up Device in Intune |
| Credential breach checks executed against HaveIBeenPwned | 6 | Check HaveIBeenPwnd Report for Neurocrine Emails |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks | Active |
|---|---|---|---|---|---|
| 1 | IOC Enrichment & Automated Ticket Management | SOC | Alert enrichment / IOC lookup, Case mgmt & SOAR | 13 | 13 |
| 2 | Threat Intelligence Feed Management | SOC | Threat intel ingest & curation | 3 | 2 |
| 3 | SIEM Threshold Monitoring | SOC | SIEM & log pipeline monitoring | 3 | 3 |
| 4 | Identity Threat Response — High-Risk Travel | SOC | Identity threat response | 1 | 1 |
| 5 | Phishing Detection & Response | SOC | Phishing detection & response | 2 | 0 |
| 6 | Credential Exposure Monitoring | SOC | Identity threat response, Threat intel ingest & curation | 1 | 1 |
| 7 | CI/CD Security Scanning & Alert Routing | Cloud Security | CSPM ingest & triage, DevSecOps compliance | 3 | 1 |
| 8 | Third Party Risk Management (TPRM) | GRC | Vendor risk & TPRM, Compliance questionnaire | 12 | 10 |
| 9 | Data Privacy, Legal Hold & Compliance Reporting | GRC | DLP triage & exposure resp, DSAR & privacy automation, Security metrics & reporting | 7 | 5 |
| 10 | Identity Directory Sync & BYOD Management | IAM | Identity sync & directory mgmt, Access review & group mgmt | 5 | 4 |
| 11 | Employee Offboarding Automation | IAM | Employee offboarding | 1 | 1 |
| 12 | Inactive User & Access Hygiene Reporting | IAM | Access review & group mgmt | 2 | 1 |
| 13 | MFA Security & Duo Management | IAM | Identity lifecycle automation, Privileged account mgmt | 2 | 1 |
| 14 | Entra Credential Lifecycle Management | IAM | Password & credential lifecycle | 1 | 1 |
| 15 | Endpoint Security, MDM & Network Access | Other | Endpoint hygiene & MDM ops | 20 | 9 |
| 16 | IT Platform Operations & Monitoring | Other | DevOps & release automation, SaaS / IT administration | 9 | 6 |
| Total | 86 | 59 |
Use Cases
1. IOC Enrichment & Automated Ticket Management
Category: SOC
Subcategories: Alert enrichment / IOC lookup, Case mgmt & SOAR
Description: Neurocrine's primary SOC automation enriches incoming security events from JIRA, PagerDuty, and Splunk with IOC intelligence — IP reputation (with caching), URL scanning, file hash lookups, and user country resolution via Entra ID — and writes findings back to the originating ticket. A shared extraction engine filters false positives and normalizes IOC formats before delegating to specialized subflows, enabling a single automated investigation framework across multiple ticketing platforms. A complementary suite of on-demand tools lets analysts manually look up IP reputation, IOC verdicts, and user identity during ad hoc investigations, and retrieve files directly from Defender-managed endpoints by hostname and path.
Business problem solved: Manual IOC triage is one of the most repetitive analyst tasks in a SOC. Every alert containing IPs, URLs, or hashes requires looking up each indicator against threat intel databases and adding context to the ticket. This automation runs that process end-to-end — no analyst involvement required for the enrichment phase. The on-demand lookup tools extend the same enrichment coverage to manual investigations that fall outside the automated ticket pipelines.
Key integrations: Splunk, JIRA, PagerDuty, VirusTotal, IPInfo, Microsoft Entra ID, Microsoft Defender for Endpoints, Blink Tables (IP cache)
| Playbook | Executions (12m) | Type |
|---|---|---|
| JIRA - Lookup all IOCs and Update Ticket with Formatting | 694 | Top-level (event) |
| Pager Duty - Lookup all IOCs and Update Ticket | 45 | Top-level (event) |
| Ingest Splunk Alerts via Webhook and create JIRA ticket | 46 | Top-level (event) |
| Extract - Filter and Enhance IP, Url, User, Hash IOCs | 454 | Subflow |
| IP Lookup Table Check Subflow | 930 | Subflow |
| IP lookup with caching subflow | 233 | Subflow |
| URL lookup subflow | 149 | Subflow |
| Hash lookup subflow | 112 | Subflow |
| Lookup user Country in Entra | 9 | Subflow |
| Lookup User in Entra | 112 | Top-level (on-demand) |
| Look up IP in IPInfo | 30 | Top-level (on-demand) |
| Lookup IOC in VirusTotal | 23 | Top-level (on-demand) |
| Defender Getfile by Hostname and Path | 1 | Top-level (on-demand) |
2. Threat Intelligence Feed Management
Category: SOC
Subcategories: Threat intel ingest & curation
Description: Automated ingestion and distribution of external threat intelligence into the security stack. A scheduled workflow pulls STIX 2.1 IOC feeds every four hours and propagates them to both Splunk and Microsoft Defender, keeping detection surfaces current without manual curation. A twice-daily ransomware monitoring workflow checks Ransomware.live for mentions of Neurocrine and key third-party partners.
Business problem solved: Keeping SIEM and EDR IOC blocklists current is operationally demanding and often delayed without automation. The ransomware monitoring provides proactive first-party and supply-chain threat awareness against active threat actors.
Key integrations: Splunk, Microsoft Defender for Endpoints, Ransomware.live API
| Playbook | Executions (12m) | Type |
|---|---|---|
| Update IOCs in Splunk and Defender | 241 | Top-level (scheduled) |
| Daily Ransomware.live First Party Monitor | 28 | Top-level (scheduled) |
| New Workflow (Ransomware Monitoring Prototype) | 0 | Top-level (on-demand) |
3. SIEM Threshold Monitoring
Category: SOC
Subcategories: SIEM & log pipeline monitoring
Description: Event-driven monitoring of a Splunk "beyond threshold" alerting table. When new records are inserted or existing records are updated in the monitoring table, Blink automatically dispatches a Splunk re-query to verify the threshold condition is still met, creating a closed-loop triage workflow that continues retrying on a configurable delay until the condition resolves.
Business problem solved: Prevents analysts from manually polling Splunk for threshold-based alerts. Triggered by table changes, this automation reduces mean time to verify threshold violations and ensures nothing sits unaddressed.
Key integrations: Splunk, Blink Tables
| Playbook | Executions (12m) | Type |
|---|---|---|
| Check for Splunk Beyond Threshold - New Records Trigger | 49 | Top-level (event) |
| Check for Splunk Beyond Threshold - Updated Records Trigger | 91 | Top-level (event) |
| Check for Splunk Beyond Threshold v2 | 137 | Subflow |
4. Identity Threat Response — High-Risk Travel
Category: SOC
Subcategories: Identity threat response
Description: A weekday-scheduled automation processes incoming security alerts around employee travel to high-risk regions. Uses a global variable as a cursor to consume new alerts incrementally and avoid reprocessing, providing continuous visibility into potential identity risk from travel to sensitive geographies.
Business problem solved: Ensures high-risk travel alerts are consistently reviewed and never pile up unread, reducing the window for undetected account compromise or insider threat risk arising from employee travel.
Key integrations: Email/Outlook, Blink global variables
| Playbook | Executions (12m) | Type |
|---|---|---|
| Process new High Risk Travel emails | 29 | Top-level (scheduled) |
5. Phishing Detection & Response
Category: SOC
Subcategories: Phishing detection & response
Description: A Microsoft Outlook webhook subscription feeds user-reported phishing emails into an automated analysis workflow that extracts URLs from the email body HTML and routes them through inspection. A companion workflow manages the Outlook subscription lifecycle — listing, deleting expired subscriptions, and recreating them — to ensure the webhook remains active. Currently built and deployed but not yet receiving events.
Business problem solved: Reduces the manual burden of analyzing user-reported phishing emails, enabling faster triage of suspicious links at scale without requiring analyst involvement for initial inspection.
Key integrations: Microsoft Outlook, Microsoft Graph, Blink platform API
| Playbook | Executions (12m) | Type |
|---|---|---|
| Phishing Email | 0 | Top-level (event) |
| Phishing Email - Create Subscription | 0 | Top-level (on-demand) |
6. Credential Exposure Monitoring
Category: SOC
Subcategories: Identity threat response, Threat intel ingest & curation
Description: A weekly workflow queries HaveIBeenPwned for new breach events involving corporate email domains since the last run. Uses a global variable as a cursor to avoid re-processing historical breaches, ensuring only new exposure events trigger notifications.
Business problem solved: Gives the security team early warning when corporate credentials appear in external breach data, enabling faster password resets and compromise investigation before attackers can operationalize stolen credentials.
Key integrations: HaveIBeenPwned API, Blink global variables
| Playbook | Executions (12m) | Type |
|---|---|---|
| Check HaveIBeenPwnd Report for Neurocrine Emails | 6 | Top-level (scheduled) |
7. CI/CD Security Scanning & Alert Routing
Category: Cloud Security
Subcategories: CSPM ingest & triage, DevSecOps compliance
Description: An event-driven pipeline ingests Wiz CI/CD security scan webhooks and categorizes findings by type (IaC, SAST, secrets, data vulnerabilities), then routes email notifications to the relevant engineering and security stakeholders per finding category. A secondary workflow can query Wiz for secrets findings on demand.
Business problem solved: Brings security visibility into the CI/CD pipeline without requiring developers to manually check a security portal. 337 automated scan-result routings in 12 months represents continuous DevSecOps coverage for every scan event generated.
Key integrations: Wiz, Microsoft Outlook, HTTP
| Playbook | Executions (12m) | Type |
|---|---|---|
| Get CI/CD Scan and alert parties - Events | 337 | Top-level (event) |
| Get Secrets from Wiz | 0 | Top-level (on-demand) |
| wiz-Blink-3 | 0 | Top-level (event) |
8. Third Party Risk Management (TPRM)
Category: GRC
Subcategories: Vendor risk & TPRM, Compliance questionnaire
Description: End-to-end automation of the third-party vendor risk assessment lifecycle. When a ServiceNow service request triggers an assessment, Blink sanitizes the input, looks up the vendor in AuditBoard, creates or updates the vendor record with business owner context, evaluates whether a questionnaire is required, and initiates it automatically. A three-times-daily status-polling workflow monitors all open questionnaires and updates their statuses. A separate risk-creation workflow translates questionnaire responses (including AI-specific risk categorization) into AuditBoard risks, with manual override capabilities via on-demand workflows.
Business problem solved: Eliminates manual handoffs between the GRC team, ServiceNow, and AuditBoard. The full assessment lifecycle from intake to risk creation runs autonomously, ensuring consistent vendor risk coverage with no process gaps.
Key integrations: ServiceNow, AuditBoard, Microsoft Outlook, Blink Tables
| Playbook | Executions (12m) | Type |
|---|---|---|
| Assessment Service Request Trigger - Prod | 37 | Top-level (event) |
| Third Party Risk Management (TPRM) - Prod | 37 | Subflow |
| Update Questionnaire Status | 87 | Top-level (scheduled) |
| Create AuditBoard Risk | 16 | Subflow |
| Manually create risks given vendor name | 2 | Top-level (on-demand) |
| manually create questionaire | 1 | Top-level (on-demand) |
| CSV Input - Create Vendor Risks | 0 | Top-level (on-demand) |
| Assessment Service Request Trigger - Prod | 22 | Top-level (event) |
| Update Questionnaire Status | 9 | Top-level (scheduled) |
| Create AuditBoard Risk | 5 | Subflow |
| Manually create risks given vendor name | 4 | Top-level (on-demand) |
| manually create questionaire | 0 | Top-level (on-demand) |
9. Data Privacy, Legal Hold & Compliance Reporting
Category: GRC
Subcategories: DLP triage & exposure resp, DSAR & privacy automation, Security metrics & reporting
Description: A suite of automations covering Microsoft Purview eDiscovery and legal hold reporting, BigID data labeling compliance metrics, and Splunk-based MNPI monitoring for press releases. The Purview legal hold workflow generates weekly reports on mailbox and SharePoint site coverage across active cases and highest-priority holds. BigID workflows track document labeling progress across four data repositories (NBIFiler, OneDrive, SharePoint, Box) and record metrics weekly. Press release monitoring pushes an updated corpus to Splunk daily to support insider threat and MNPI detection use cases.
Business problem solved: Manual Purview legal hold audits are time-consuming and error-prone. Automating these checks ensures legal and compliance teams have current coverage data. Data labeling tracking provides measurable progress metrics for the DLP program.
Key integrations: Microsoft Purview (via MS Graph), BigID, Splunk
| Playbook | Executions (12m) | Type |
|---|---|---|
| Generate and Email MBrewer a report on new Mailboxes & SharePoint Sites(New) | 40 | Top-level (scheduled) |
| Update Purview via MS Graph | 242 | Subflow/utility |
| BigID Label Report (workspace A) | 2 | Top-level (scheduled) |
| BigID Label Report (workspace B) | 2 | Top-level (scheduled) |
| Update Press Releases V2 | 29 | Top-level (scheduled) |
| Update Press Releases | 0 | Top-level (on-demand) |
| BigID ACI Search | 0 | Top-level (on-demand) |
10. Identity Directory Sync & BYOD Management
Category: IAM
Subcategories: Identity sync & directory mgmt, Access review & group mgmt
Description: Maintains synchronized user lookup tables sourced from Microsoft Entra ID (daily) and Okta (weekly), providing a fast-query user repository that powers IOC enrichment lookups and access reporting across the platform. A weekly BYOD workflow syncs the BYOD device enrollment group, cross-references the user lookup table to identify enrollment gaps, and pushes the results to Splunk for dashboard visibility. A daily workflow (with an on-demand variant) automatically assigns Entra security groups to applications based on group naming convention, removing a manual provisioning step from access management.
Business problem solved: Many workflows need to quickly look up user attributes (country, manager, status) without making real-time API calls to identity providers. These scheduled sync workflows maintain a local cache that accelerates IOC investigation and supports access compliance reporting.
Key integrations: Microsoft Entra ID, Okta, Splunk, Blink Tables
| Playbook | Executions (12m) | Type |
|---|---|---|
| Populate User Lookup Table Daily V2 | 31 | Top-level (scheduled) |
| Populate Okta User Lookup Table Weekly | 6 | Top-level (scheduled) |
| Update BYOD Users | 6 | Top-level (scheduled) |
| Auto Assign Entra Groups to App Based On Group Name | 30 | Top-level (scheduled) |
| SCK's Auto Assign Entra Groups to App Based on Group Name | 0 | Top-level (on-demand) |
11. Employee Offboarding Automation
Category: IAM
Subcategories: Employee offboarding
Description: A daily workflow pulls the departing employee report from Workday and automatically updates Microsoft Purview with departure records to ensure legal hold and eDiscovery coverage is maintained throughout the notice period and post-departure window.
Business problem solved: Ensures no departing employee falls through the cracks for legal hold compliance. Manual Purview updates are error-prone and often delayed, creating compliance and litigation risk. Daily automation provides consistent, auditable coverage.
Key integrations: Workday (via HTTP/basic-auth), Microsoft Purview (via Blink subflow)
| Playbook | Executions (12m) | Type |
|---|---|---|
| Push Departing Users to Purview | 41 | Top-level (scheduled) |
12. Inactive User & Access Hygiene Reporting
Category: IAM
Subcategories: Access review & group mgmt
Description: A scheduled monthly report (second Tuesday of each month) segments inactive users across three populations — US employees with EmployeeIDs, non-US employees, and service accounts — and emails a consolidated CSV report per segment. Identifies accounts inactive beyond 90 days by comparing last-login epoch times against the user lookup table.
Business problem solved: Inactive accounts represent a persistent attack surface. Automated reporting gives the IAM team regular visibility to perform hygiene reviews without running manual Entra queries.
Key integrations: Blink Tables (user_lookup), Email
| Playbook | Executions (12m) | Type |
|---|---|---|
| Inactive User Report v2 (SCK) | 15 | Top-level (scheduled) |
| Inactive User Report | 0 | Top-level (on-demand) |
13. MFA Security & Duo Management
Category: IAM
Subcategories: Identity lifecycle automation, Privileged account mgmt
Description: A daily automation queries Duo for all users with active bypass codes, then cross-references recent authentication events in Splunk to surface anomalous usage patterns, delivering a daily bypass digest to the security team. A companion workflow identifies and emails a list of unenrolled Duo users for enrollment follow-up.
Business problem solved: Duo bypass codes are a temporary MFA bypass that, if left unchecked, become standing privileged-access mechanisms. Daily automated monitoring ensures bypass exposure windows are visible and acted on promptly.
Key integrations: Duo (via HTTP), Splunk
| Playbook | Executions (12m) | Type |
|---|---|---|
| Duo Bypass Lookup | 41 | Top-level (scheduled) |
| Duo Email Unenerolled Users | 0 | Top-level (on-demand) |
14. Entra Credential Lifecycle Management
Category: IAM
Subcategories: Password & credential lifecycle
Description: A weekly workflow scans all Microsoft Entra ID application registrations for secrets and certificates approaching expiration, generates a CSV report, and emails it to security contacts. Runs on a fixed weekly schedule to provide consistent advance warning before any credential expires.
Business problem solved: Expired application secrets in Entra ID cause service outages and can create security gaps if not rotated on schedule. Automated weekly monitoring eliminates manual checks across potentially hundreds of app registrations.
Key integrations: Microsoft Entra ID, Email
| Playbook | Executions (12m) | Type |
|---|---|---|
| Microsoft Entra Secret Expiration | 6 | Top-level (scheduled) |
15. Endpoint Security, MDM & Network Access
Category: Other
Subcategories: Endpoint hygiene & MDM ops
Description: A comprehensive set of automations for endpoint visibility and network security management. Scheduled workflows merge device records from Microsoft Defender for Endpoints, Intune, and Zscaler into a unified dashboard dataset pushed to Splunk. A daily Defender AV change report surfaces hosts with non-healthy antivirus status. Zscaler tooling provides OTP generation for help-desk scenarios, a weekly disabled-reason audit with OpenAI scoring to prioritize outreach, and blocked-country management. Browser extension inventory workflows (multiple development iterations) provide on-demand visibility into installed extensions with permission data across the device fleet. A weekday-morning workflow emails IT support leadership a list of unassigned Windows devices in Intune, and an on-demand workflow consolidates machine records from Defender, Intune, and Entra to surface devices older than 30 days. On-demand lookup tools support quick Intune device checks, a scheduled workflow notifies teams of elevated endpoint privilege management events, and a webhook-driven workflow handles SquareX browser security exception requests.
Business problem solved: Maintaining up-to-date visibility across three distinct endpoint and network security tools without automation requires constant manual data exports. The dashboard automation provides fresh posture data daily, and the AV change report catches Defender health degradations before they become incidents. Proactive unassigned-device and privilege-elevation notifications close visibility gaps before they become support or security incidents.
Key integrations: Microsoft Defender for Endpoints, Microsoft XDR Defender, Microsoft Intune, Zscaler (ZIA, Client Connector/OneAPI), Microsoft Graph, Splunk, OpenAI, Microsoft Teams, SquareX
16. IT Platform Operations & Monitoring
Category: Other
Subcategories: DevOps & release automation, SaaS / IT administration
Description: Infrastructure automation supporting the Blink platform itself and general IT operations. Backup workflows automatically commit published workflow configurations to GitHub daily for version control and disaster recovery. A webhook-driven error handler captures and routes workflow failures. Token refresh alerting notifies security teams of authentication token events received via webhook. Mailbox usage reporting delivers a weekly top-20 mailbox capacity analysis. QR code generation automates a recurring operational task on demand. A platform health check workflow identifies published-but-abandoned workflow drafts.
Business problem solved: Keeps the SOAR platform healthy, auditable, and recoverable. Source-controlled workflow backups ensure no automation logic is lost. Error handling prevents silent failures. Token alerting provides lightweight integration health monitoring.
Key integrations: GitHub, Microsoft Entra ID, Microsoft Graph, Microsoft Outlook, Email, Blink platform API
| Playbook | Executions (12m) | Type |
|---|---|---|
| Token Refresh Alerting | 199 | Top-level (event) |
| Backup Published Workflows | 44 | Top-level (scheduled) |
| Backup file to GitHub | 110 | Subflow/utility |
| Workflow Error Handler | 53 | Top-level (event) |
| Mailbox Usage Report | 6 | Top-level (scheduled) |
| Generate and Email QR Codes | 15 | Top-level (on-demand) |
| Look for Unpublished Workflows | 0 | Top-level (on-demand) |
| Push IP Subnets to Defender | 0 | Top-level (on-demand) |
| Test for getting a response via email | 0 | Top-level (on-demand) |
Key Observations
Strengths
Mature IOC Enrichment Engine: The most-executed automation is the IOC enrichment framework — 930 IP cache lookups in 12 months indicates a high-volume, production-grade deployment. The layered architecture (extraction → deduplication → caching → enrichment → ticket update) reflects significant engineering investment and operational maturity. Shared subflows reused across JIRA, PagerDuty, and Splunk pipelines is a strong design pattern.
Broad Security Stack Coverage: The automation stack spans Splunk, Microsoft Defender for Endpoints, Microsoft XDR, Wiz, Okta, Entra ID, Zscaler, Duo, VirusTotal, HaveIBeenPwned, Ransomware.live, PagerDuty, and JIRA. The breadth of integration coverage across SOC, IAM, endpoint, and cloud security signals a mature, multi-stakeholder automation program.
Compliance Automation Depth: The GRC use cases are unusually well-developed. The ServiceNow → AuditBoard → questionnaire → risk creation pipeline represents a fully automated TPRM lifecycle. The Purview legal hold, Workday offboarding, and BigID labeling automations demonstrate regulatory-grade compliance investment — particularly relevant for a life sciences company.
DevSecOps Coverage: 337 Wiz CI/CD scan events automatically triaged and routed in 12 months places this program ahead of most peers in operationalizing DevSecOps alerting without manual security review queues.
Platform Self-Management: Automating Blink's own workflow backups, error handling, and platform health checks reflects a mature team that treats their SOAR platform as production infrastructure — not just a tool.
Expanding Analyst Self-Service Toolkit: A growing set of on-demand lookup tools (IP reputation, VirusTotal IOC checks, Entra user lookups, Defender file retrieval, Intune device lookups) saw 176 combined executions, indicating analysts are increasingly using Blink as a manual investigation aid alongside the fully automated pipelines.
Gaps & Opportunities
Phishing Response Gap: The phishing detection workflow (0 executions) is built and deployed but not receiving Outlook webhook events. Activating this would extend automated IOC enrichment to user-reported phishing at no additional development cost, adding another high-volume enrichment channel.
Browser Extension Visibility: Six browser extension inventory workflows exist across multiple development iterations but have never been executed. Given the active Intune and Defender investment, activating extension auditing would close a meaningful endpoint hygiene gap — particularly relevant for detecting unauthorized AI tools or data exfiltration browser extensions.
AI Governance Gap: An "Update AI Usage Data" workflow using Reco AI exists but has never been executed. With OpenAI already integrated in the Zscaler checker and AI tool usage a growing compliance concern in life sciences, activating AI governance monitoring would be a natural next step.
Duo Unenrolled Users: The Duo unenrolled user reporting workflow (0 executions) exists but has not been activated. Given the active Duo bypass monitoring, pairing it with enrollment gap reporting would provide complete MFA coverage.
Wiz Secrets Posture: "Get Secrets from Wiz" (0 executions) could complement the active CI/CD scanning pipeline with periodic full secrets posture reviews rather than only event-driven coverage.
Integration Ecosystem
| Domain | Integrations |
|---|---|
| SIEM / Logging | Splunk |
| Ticketing / Case Mgmt | JIRA (Cloud), PagerDuty, ServiceNow |
| EDR / XDR | Microsoft Defender for Endpoints, Microsoft XDR Defender |
| Cloud Security | Wiz |
| Network Security | Zscaler (ZIA, Client Connector / OneAPI) |
| Browser Security | SquareX |
| Identity | Microsoft Entra ID, Okta, Duo |
| Compliance / GRC | AuditBoard, Microsoft Purview (via MS Graph) |
| DLP / Data | BigID |
| Threat Intel | VirusTotal (via IOC subflows), IPInfo, HaveIBeenPwned, Ransomware.live |
| Communication | Microsoft Outlook, Microsoft Teams, Email |
| HR / Offboarding | Workday (via HTTP) |
| Source Control | GitHub |
| AI | OpenAI (GPT), Reco AI |
E New Integrations (detail) 3 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| neurocrine | bearer-token | zscaler_zero_trust_browser_api_key | 2026-08-14 |
| neurocrine | openai | grc_openai | 2026-08-10 |
| neurocrine | microsoft-graph | microsoft_graph_entra_id_permissions | 2026-07-31 |