01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Automated Incident Ticketing |
| 99.5% | 2 2 active |
| Malware EDR Investigation |
| 0.5% | 5 5 active |
| Total | 8,801 executions | 100% | 7 7 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- High-volume incident ticketing at scale: The ILC client ticketing automation alone processed 3,815 incidents in 12 months — demonstrating the MSSP's ability to handle enterprise-scale alert volume for managed clients without linear analyst headcount growth.
- Dual-workspace architecture: Nexus Orion MSSP operates a dedicated production SOC workspace and a separate dev/UAT workspace, indicating a mature deployment practice with proper staging and promotion controls.
- Integrated malware investigation pipeline: The malware EDR investigation use case spans CrowdStrike, VirusTotal, Hybrid Analysis, and Zendesk in a single automated workflow — covering the full detection-to-verdict-to-ticket lifecycle.
###
Gaps & Opportunities
- Low utilization of dev-workspace playbooks: Five of eight playbooks have zero executions and all reside in the dev/UAT workspace. The production version of
PRD - Malware Generic Investigation EDRin the dev workspace has never run, suggesting it may be a staging copy that was superseded by the Orion SOC workspace version. These should either be promoted or retired to reduce maintenance surface. - No active threat intel tooling:
VT File Hash Search and CSV OutputandHA Hash Search with Output Checksare standalone helper playbooks with zero executions. If these are subflows consumed by the malware investigation workflow, they should be confirmed as such; if they are standalone, activating them for on-demand analyst use could increase threat intel coverage. - Single active use case category: All active automation falls within SOC / Case mgmt & SOAR and EDR response. There is no coverage yet for vulnerability management, IAM, or GRC — areas where MSSP clients commonly have automation needs and where Blink can expand the engagement.
- No phishing or identity threat coverage: Given the MSSP context and CrowdStrike-centric environment, phishing detection and identity threat response workflows (e.g., auto-isolating compromised accounts) are natural next use cases to build out.
Integration Ecosystem
| Integration | Role | Active Workflows |
|---|---|---|
| CrowdStrike | Webhook event trigger for incident intake | 2 |
| VirusTotal | File hash threat intel enrichment | 0 (defined, not active) |
| Hybrid Analysis | File hash sandbox verdict | 0 (defined, not active) |
| Zendesk | Ticket creation and case management | 1 (implied via inputs) |
A Case Management 0 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Orion SOC Workspace | 1 | 0 | 0 | N/A |
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink | Orion SOC Workspace | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Orion SOC Workspace | 0 |
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 2 use cases | 8,801 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Client CrowdStrike incidents automatically ticketed (ILC) | 3,815 | PRD - ILC - Ticketing |
| CrowdStrike security incidents auto-ticketed (SOC) | 42 | PRD - Ticketing |
| Malware EDR detections auto-investigated | 42 | PRD - Malware Generic Investigation EDR (Orion SOC Workspace) |
Use Case Summary
| Use Case | Category | Subcategory | Total Playbooks | Active Playbooks | Executions (12mo) |
|---|---|---|---|---|---|
| Automated Incident Ticketing | SOC | Case mgmt & SOAR | 3 | 2 | 3,857 |
| Malware EDR Investigation | SOC | EDR containment & response, Alert enrichment / IOC lookup | 5 | 1 | 42 |
Use Cases
1. Automated Incident Ticketing
Description: Listens for CrowdStrike webhook events and automatically creates service tickets for incoming security incidents. Supports both the primary SOC environment and the ILC managed-client environment, enabling the MSSP to scale incident intake across tenants without manual triage overhead.
Business problem solved: MSSP analysts were spending significant time manually logging CrowdStrike detections into the ticketing system. This automation converts every webhook-triggered event into a structured ticket instantly, ensuring nothing is missed and SLA timers start immediately.
Category: SOC
Subcategory: Case mgmt & SOAR
Integrations: CrowdStrike (webhook trigger)
| Playbook | Workspace | Executions (12mo) | Status |
|---|---|---|---|
| PRD - Ticketing | Orion SOC | 42 | Active |
| PRD - ILC - Ticketing | Orion SOC | 3,815 | Active |
| PRD - ILC - Ticketing | Dev/UAT | 0 | Inactive |
2. Malware EDR Investigation
Description: Provides automated malware investigation for CrowdStrike EDR detections. Takes a detection ID and file hash as inputs, runs the hash against VirusTotal and Hybrid Analysis for threat intelligence enrichment, and produces a consolidated investigation summary linked to a Zendesk ticket.
Business problem solved: Malware triage requires analysts to manually pivot across multiple threat intel platforms (VirusTotal, Hybrid Analysis) for every file hash. This use case automates the full investigation chain — from EDR detection to enriched verdict — freeing analysts to focus on response decisions rather than data collection.
Category: SOC
Subcategory: EDR containment & response, Alert enrichment / IOC lookup
Integrations: CrowdStrike (EDR), VirusTotal, Hybrid Analysis, Zendesk
| Playbook | Workspace | Executions (12mo) | Status |
|---|---|---|---|
| PRD - Malware Generic Investigation EDR (Orion SOC Workspace) | Orion SOC | 42 | Active |
| PRD - Malware Generic Investigation EDR | Dev/UAT | 0 | Inactive |
| UAT - Malware Generic Investigation EDR | Dev/UAT | 0 | UAT |
| VT File Hash Search and CSV Output | Dev/UAT | 0 | Inactive |
| HA Hash Search with Output Checks | Dev/UAT | 0 | Inactive |
Key Observations
Strengths
- High-volume incident ticketing at scale: The ILC client ticketing automation alone processed 3,815 incidents in 12 months — demonstrating the MSSP's ability to handle enterprise-scale alert volume for managed clients without linear analyst headcount growth.
- Dual-workspace architecture: Nexus Orion MSSP operates a dedicated production SOC workspace and a separate dev/UAT workspace, indicating a mature deployment practice with proper staging and promotion controls.
- Integrated malware investigation pipeline: The malware EDR investigation use case spans CrowdStrike, VirusTotal, Hybrid Analysis, and Zendesk in a single automated workflow — covering the full detection-to-verdict-to-ticket lifecycle.
Gaps & Opportunities
- Low utilization of dev-workspace playbooks: Five of eight playbooks have zero executions and all reside in the dev/UAT workspace. The production version of
PRD - Malware Generic Investigation EDRin the dev workspace has never run, suggesting it may be a staging copy that was superseded by the Orion SOC workspace version. These should either be promoted or retired to reduce maintenance surface. - No active threat intel tooling:
VT File Hash Search and CSV OutputandHA Hash Search with Output Checksare standalone helper playbooks with zero executions. If these are subflows consumed by the malware investigation workflow, they should be confirmed as such; if they are standalone, activating them for on-demand analyst use could increase threat intel coverage. - Single active use case category: All active automation falls within SOC / Case mgmt & SOAR and EDR response. There is no coverage yet for vulnerability management, IAM, or GRC — areas where MSSP clients commonly have automation needs and where Blink can expand the engagement.
- No phishing or identity threat coverage: Given the MSSP context and CrowdStrike-centric environment, phishing detection and identity threat response workflows (e.g., auto-isolating compromised accounts) are natural next use cases to build out.
Integration Ecosystem
| Integration | Role | Active Workflows |
|---|---|---|
| CrowdStrike | Webhook event trigger for incident intake | 2 |
| VirusTotal | File hash threat intel enrichment | 0 (defined, not active) |
| Hybrid Analysis | File hash sandbox verdict | 0 (defined, not active) |
| Zendesk | Ticket creation and case management | 1 (implied via inputs) |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.