01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| EDR Alert Processing & Automated Triage |
| 100.0% | 5 4 active |
| IOC Lookup & Threat Enrichment | 0 executions | 0.0% | 4 4 active |
| Phishing & Email Security Response | 1 executions | 0.0% | 3 3 active |
| Security Incident Investigation | 0 executions | 0.0% | 3 3 active |
| Endpoint Containment | 0 executions | 0.0% | 2 2 active |
| Network Security Policy Automation | 0 executions | 0.0% | 1 0 active |
| SIEM & Infrastructure Monitoring | 0 executions | 0.0% | 2 2 active |
| DevOps & Utility | 0 executions | 0.0% | 2 1 active |
| Total | 42,779 executions | 100% | 22 19 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- High-volume EDR automation is delivering real value. Two playbooks — CS EDR and Defender For Endpoint — together processed over 20,600 events in 12 months. This is among the clearest proof points of automation ROI in the portfolio: the same analyst workflow executing thousands of times without human intervention.
- Broad security stack coverage. Nexus has connected or attempted to connect a wide range of enterprise security tools: CrowdStrike, Microsoft Defender, Palo Alto PAN-OS, VirusTotal, Hybrid Analysis, Trellix ETP, Alert Logic, Check Point Harmony, AbuseIPDB, and Zendesk. This integration breadth reflects a mature, multi-vendor security environment and positions Nexus to expand automation across all these platforms.
- Tiered investigation architecture. The confidence-tier subflows (low / medium / high) indicate architectural intent: Nexus is building a structured, policy-driven triage model rather than ad hoc response scripts. This is a strong foundation for Agentic SOC patterns.
- Policy-aware containment. The non-containment allowlist check in the Containment playbooks shows operational maturity — Nexus has encoded business context into automated response logic, reducing the risk of disruptive false-positive containment actions.
###
Gaps & Opportunities
- 27 of 29 playbooks have zero executions. The active automation footprint is limited to two workflows. Most playbooks appear to be in testing, development, or abandoned states. Activating even a subset of the investigation and enrichment workflows could multiply the automation impact significantly.
- Duplicate and fragmented workspaces. The Containment playbook exists across two separate workspaces, and multiple CrowdStrike workflows exist in different workspaces with overlapping logic. Consolidating the workspace architecture would reduce maintenance overhead and make it easier to scale active workflows.
- Investigation workflows are built but not running. Windows Account Lockout, Malware Investigation, and Service Brute Force playbooks are fully scoped — inputs are defined and logic is structured — but show zero executions. These are prime candidates for activation, particularly given the active EDR alert volume these incident types likely generate.
- Phishing response pipeline is incomplete. Trellix and Alert Logic workflows exist but are inactive. With an active email security connection and a structured Email Investigation subflow already built, completing the trigger-to-response loop would directly support a measurable phishing response KPI.
- No IAM or GRC automation present. The current portfolio is entirely SOC and infrastructure focused. Common adjacent use cases — employee onboarding/offboarding, access reviews, and vulnerability management ticketing — are not represented and represent natural expansion opportunities.
Integration Ecosystem
| Integration | Use Cases | Status |
|---|---|---|
| CrowdStrike | EDR triage, alert enrichment | Active |
| Microsoft Defender for Endpoints | EDR triage, alert filtering | Active |
| VirusTotal | IOC enrichment, URL scanning | Configured |
| Hybrid Analysis | IOC enrichment, URL scanning | Configured |
| Palo Alto Networks (PAN-OS) | Firewall rule management | Inactive |
| Trellix ETP | Email security response | Inactive |
| Alert Logic | SIEM monitoring, phishing alerts | Inactive |
| Check Point Harmony | Network block enforcement | Inactive |
| Google Workspace / Gmail | Email trigger for phishing flows | Inactive |
| Zendesk | Incident ticket linkage | Inactive |
| Jenkins | CI/CD log forwarding | Inactive |
| Discord | DevOps notifications | Inactive |
A Case Management 0 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| acatienza@nexustech.com.ph | 2 | 0 | 0 | N/A |
| Nexus Orion Workspace | 1 | 0 | 0 | N/A |
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink | acatienza@nexustech.com.ph | 0 | 0 | 0 |
| 2 | Agent Blink | lcaquino@nexustech.com.ph | 0 | 0 | 0 |
| 3 | Agent Blink | Nexus Orion Workspace | 0 | 0 | 0 |
| 4 | Agent Blink | nbmolejon@nexustech.com.ph | 0 | 0 | 0 |
| 5 | Agent Blink | jsgalleno@nexustech.com.ph | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| acatienza@nexustech.com.ph | 0 |
| lcaquino@nexustech.com.ph | 0 |
| Nexus Orion Workspace | 0 |
| nbmolejon@nexustech.com.ph | 0 |
| jsgalleno@nexustech.com.ph | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | whitelisted URL | 0 | 0 |
| 2 | Sub-Tenant Reporting | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 8 use cases | 42,779 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| CrowdStrike endpoint alerts auto-triaged & enriched with threat intelligence | 9,108 | CS EDR |
| Microsoft Defender endpoint alerts processed and filtered automatically | 11,533 | Defender For Endpoint |
| Total security events handled without manual intervention | 20,641 |
Use Case Summary
| # | Use Case | Category | Playbooks | Active | Executions (12mo) |
|---|---|---|---|---|---|
| 1 | EDR Alert Processing & Automated Triage | SOC | 5 | 2 | 20,641 |
| 2 | IOC Lookup & Threat Enrichment | SOC | 4 | 0 | 0 |
| 3 | Phishing & Email Security Response | SOC | 4 | 0 | 0 |
| 4 | Security Incident Investigation | SOC | 7 | 0 | 0 |
| 5 | Endpoint Containment | SOC | 2 | 0 | 0 |
| 6 | Network Security Policy Automation | Cloud Security | 2 | 0 | 0 |
| 7 | SIEM & Infrastructure Monitoring | SOC | 2 | 0 | 0 |
| 8 | DevOps & Utility | Other | 3 | 0 | 0 |
| Total | 29 | 2 | 20,641 |
Use Cases
1. EDR Alert Processing & Automated Triage
Description: Nexus's highest-volume automation area. Blink ingests alerts from CrowdStrike and Microsoft Defender for Endpoint in real time, automatically retrieves detection details and IOC data, enriches findings with external threat intelligence (VirusTotal), and delivers analyst-ready summaries — eliminating manual triage for more than 20,000 events per year.
Business problem solved: SOC analysts were manually pulling detection context from two separate EDR platforms and cross-referencing external threat feeds. Blink closes that loop automatically, reducing mean time to triage and freeing analyst capacity for true escalations.
Integrations: CrowdStrike, Microsoft Defender for Endpoints, VirusTotal, Email (Blink core)
Taxonomy: SOC → EDR containment & response, Alert enrichment / IOC lookup
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| CS EDR | 9,108 | ea7783ed |
| Defender For Endpoint | 11,533 | e1e09e33 |
| MS Defender EDR | 0 | 8d251fff |
| CrowdStrike | 0 | 786030e5 |
| New Automation | 0 | d8223cd4 |
2. IOC Lookup & Threat Enrichment
Description: A suite of on-demand playbooks that automate indicator-of-compromise lookups against VirusTotal and Hybrid Analysis. Analysts can submit a URL for scanning, check an existing scan's status, or trigger a combined multi-source lookup that queries both threat intel platforms and delivers a consolidated email report.
Business problem solved: Manual IOC lookups across multiple threat intelligence platforms are slow and inconsistent. These playbooks standardize the enrichment workflow and return structured results to the analyst inbox.
Integrations: VirusTotal, Hybrid Analysis, Email (Blink core)
Taxonomy: SOC → Alert enrichment / IOC lookup, Threat intel ingest & curation
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| URL Lookup | 0 | 018f7fba |
| Scan URL with VirusTotal and Send Results via Email | 0 | c16e7522 |
| Scan URL with Hybrid Analysis and Send Results via Email | 0 | 801d55c1 |
| Check Scan Status with Hybrid Analysis and Send Results via Email | 0 | 6753e763 |
3. Phishing & Email Security Response
Description: Automated workflows that monitor for malicious email alerts from Trellix Email Security and Alert Logic. On detection, the playbooks retrieve alert details, identify related delivered emails (including by SMTP sender), loop over affected recipients, and send coordinated response notifications. Includes a dedicated email-investigation subflow used as a reusable component.
Business problem solved: Responding to malicious email campaigns requires correlating alerts across email security platforms, identifying all exposed recipients, and notifying stakeholders — a multi-step process that Blink collapses into a single automated response.
Integrations: Trellix ETP, Alert Logic, Google Workspace / Gmail, Email (Blink core), Check Point Harmony
Taxonomy: SOC → Phishing detection & response, Alert enrichment / IOC lookup
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| Trellix Alert Workflow 2 | 0 | 536622ae |
| Trellix Test | 0 | e5364b7f |
| On Alert Logic Alert | 0 | 2b82ff02 |
| Subflow — Email Investigation | 0 | bc461470 |
4. Security Incident Investigation
Description: A structured set of investigation playbooks covering the most common SOC incident types: account lockouts, malware detections, and service brute-force attacks. Each playbook pulls incident context, sets enrichment variables, and routes response via conditional logic. Three confidence-tier subflows (low / medium / high) implement a tiered triage model — evaluating Tor/VPN/proxy signals and non-containment list membership before escalating or blocking. A block-sequence subflow integrates Check Point Harmony for automated network enforcement.
Business problem solved: Incident investigation workflows are frequently ad hoc, inconsistent, and undocumented. This use case formalizes a repeatable response playbook for the most common incident types, ensuring every analyst follows the same enrichment and decision logic.
Integrations: Check Point Harmony, AbuseIPDB (implied via subflow inputs), Zendesk, Microsoft Active Directory (implied), HTTP/custom APIs
Taxonomy: SOC → Case mgmt & SOAR, EDR containment & response, Alert enrichment / IOC lookup
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| Windows Account Lockout Investigation | 0 | 463a5fc6 |
| Malware Generic Investigation | 0 | cca586ae |
| Service Brute Force Investigation | 0 | 174e2d22 |
| Subflow — Investigate Low Confidence | 0 | f9e618fa |
| Subflow — Investigate Medium Confidence | 0 | 739a5696 |
| Subflow — Investigate High Confidence | 0 | 1a0612ff |
| Subflow — Block Sequence | 0 | 4933dcd5 |
5. Endpoint Containment
Description: On-demand containment playbooks that query a non-containment allowlist before isolating a host, ensuring safe and policy-aware endpoint isolation decisions. A duplicate of the workflow exists across two separate workspaces, indicating multi-team rollout or workspace segmentation.
Business problem solved: Uncontrolled endpoint containment can disrupt legitimate business operations. These playbooks enforce a policy check — blocking containment for allowlisted hosts — before taking action, reducing the risk of erroneous isolation.
Integrations: Blink HTTP Tables (non-containment list lookup)
Taxonomy: SOC → EDR containment & response
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| Containment | 0 | f4e02c15 |
| Containment (Nexus Orion Workspace) | 0 | 935ba91d |
6. Network Security Policy Automation
Description: On-demand automation for creating security rules on Palo Alto firewalls and delivering results by email. Parameterized with full rule inputs (source, destination, application, service, zone, VSYS), enabling repeatable, auditable firewall policy changes without direct console access.
Business problem solved: Firewall rule creation is error-prone when done manually. These playbooks standardize the request-to-creation process and deliver a confirmation trail to the requesting engineer, improving both accuracy and audit readiness.
Integrations: Palo Alto Networks (PAN-OS), Email (Blink core)
Taxonomy: Cloud Security → Config audit & remediation
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| Create Security Rule with Palo Alto Firewall and Send Results via Email | 0 | 1efd2e2a |
| Create Security Rule with Palo Alto Firewall and Send Results via Email (Personalized) | 0 | 1564e5ef |
7. SIEM & Infrastructure Monitoring
Description: Scheduled monitoring of Alert Logic service status, with conditional alerting on state changes. Includes a simulation playbook for testing Alert Logic list-append behavior. Together these represent Nexus's tooling for verifying the health of their SIEM pipeline.
Business problem solved: Undetected SIEM outages create coverage gaps that go unnoticed until an incident. Scheduled Blink monitoring closes that loop with automated health checks and alerts.
Integrations: Alert Logic, HTTP
Taxonomy: SOC → SIEM & log pipeline monitoring
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| AlertLogic Status Monitoring | 0 | 7233e02b |
| Alert Logic Append to List Simulation | 0 | 64280393 |
8. DevOps & Utility
Description: Supporting workflows not tied to security operations. Includes a Jenkins build log forwarder to Discord for CI/CD visibility, a getting-started Hello World template, and an untitled test automation. These are infrastructure or exploratory in nature.
Business problem solved: Build log visibility in a developer communication channel reduces the friction of tracking CI/CD pipeline status without leaving Slack/Discord.
Integrations: Jenkins, Discord, Email (Blink core)
Taxonomy: Other → DevOps & release automation
| Playbook | Executions (12mo) | Workflow ID |
|---|---|---|
| Send Jenkins Build Logs to Discord | 0 | 612f35b5 |
| Getting Started — Hello World | 0 | 28c22706 |
| New Automation 1 | 0 | 238256b9 |
Key Observations
Strengths
- High-volume EDR automation is delivering real value. Two playbooks — CS EDR and Defender For Endpoint — together processed over 20,600 events in 12 months. This is among the clearest proof points of automation ROI in the portfolio: the same analyst workflow executing thousands of times without human intervention.
- Broad security stack coverage. Nexus has connected or attempted to connect a wide range of enterprise security tools: CrowdStrike, Microsoft Defender, Palo Alto PAN-OS, VirusTotal, Hybrid Analysis, Trellix ETP, Alert Logic, Check Point Harmony, AbuseIPDB, and Zendesk. This integration breadth reflects a mature, multi-vendor security environment and positions Nexus to expand automation across all these platforms.
- Tiered investigation architecture. The confidence-tier subflows (low / medium / high) indicate architectural intent: Nexus is building a structured, policy-driven triage model rather than ad hoc response scripts. This is a strong foundation for Agentic SOC patterns.
- Policy-aware containment. The non-containment allowlist check in the Containment playbooks shows operational maturity — Nexus has encoded business context into automated response logic, reducing the risk of disruptive false-positive containment actions.
Gaps & Opportunities
- 27 of 29 playbooks have zero executions. The active automation footprint is limited to two workflows. Most playbooks appear to be in testing, development, or abandoned states. Activating even a subset of the investigation and enrichment workflows could multiply the automation impact significantly.
- Duplicate and fragmented workspaces. The Containment playbook exists across two separate workspaces, and multiple CrowdStrike workflows exist in different workspaces with overlapping logic. Consolidating the workspace architecture would reduce maintenance overhead and make it easier to scale active workflows.
- Investigation workflows are built but not running. Windows Account Lockout, Malware Investigation, and Service Brute Force playbooks are fully scoped — inputs are defined and logic is structured — but show zero executions. These are prime candidates for activation, particularly given the active EDR alert volume these incident types likely generate.
- Phishing response pipeline is incomplete. Trellix and Alert Logic workflows exist but are inactive. With an active email security connection and a structured Email Investigation subflow already built, completing the trigger-to-response loop would directly support a measurable phishing response KPI.
- No IAM or GRC automation present. The current portfolio is entirely SOC and infrastructure focused. Common adjacent use cases — employee onboarding/offboarding, access reviews, and vulnerability management ticketing — are not represented and represent natural expansion opportunities.
Integration Ecosystem
| Integration | Use Cases | Status |
|---|---|---|
| CrowdStrike | EDR triage, alert enrichment | Active |
| Microsoft Defender for Endpoints | EDR triage, alert filtering | Active |
| VirusTotal | IOC enrichment, URL scanning | Configured |
| Hybrid Analysis | IOC enrichment, URL scanning | Configured |
| Palo Alto Networks (PAN-OS) | Firewall rule management | Inactive |
| Trellix ETP | Email security response | Inactive |
| Alert Logic | SIEM monitoring, phishing alerts | Inactive |
| Check Point Harmony | Network block enforcement | Inactive |
| Google Workspace / Gmail | Email trigger for phishing flows | Inactive |
| Zendesk | Incident ticket linkage | Inactive |
| Jenkins | CI/CD log forwarding | Inactive |
| Discord | DevOps notifications | Inactive |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.