01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| UC1 — NGSIEM Alert Enrichment Pipeline | 0 executions | 0.0% | 13 11 active |
| UC2 — Case Management & Automated SOC Response |
| 20.0% | 61 57 active |
| UC3 — Agentic Detection Engineering & Threat Intel |
| 0.0% | 9 9 active |
| UC4 — Multi-Platform IAM State & Access Inventory | 0 executions | 0.0% | 11 11 active |
| UC5 — Cloud & Infrastructure Compliance Auditing | 0 executions | 0.0% | 7 7 active |
| UC6 — IT Helpdesk & Access Provisioning |
| 80.0% | 8 8 active |
| UC7 — Demo, Test & Utility Workflows | 0 executions | 0.0% | 15 13 active |
| Total | 20 executions | 100% | 124 116 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature SOAR foundation. UC2 is the most architecturally complete use case in the environment — a production-grade case management platform spanning 6 ingest connectors, 14 enrichment providers, response routing for phishing and malware, case deduplication, observable relation management, stale case recovery, and simulation tooling. This is a comprehensive demonstration of Blink's SOAR depth.
Broadest IAM coverage of any PreSales asset. UC4 spans 10 identity and SaaS platforms (Azure, GitHub, Slack, DataDog, Wiz, Google Workspace, Salesforce, Hubspot, Okta, Active Directory) in a single normalized inventory pipeline. This directly addresses the SaaS access visibility
gap that surfaces in almost every enterprise prospect conversation.
Agentic SOC differentiation. UC3 showcases two named AI agents (Athena — CTI Analyst, Hermes — Detection Technical Writer) embedded in a live Slack-driven detection engineering workflow. With 3 executions recorded, this is the most-used non-case-management use case, signaling strong prospect interest in agentic capabilities.
Multi-OS compliance coverage. UC5 covers CIS AWS, RHEL, Ubuntu, and Windows Server from a single toolset — a strong response to mixed-infrastructure compliance questions.
Broad integration ecosystem. 20+ integrations demonstrated across CrowdStrike, Microsoft (Entra ID, Outlook, Teams, Defender, Azure), Google Workspace, AWS, Okta, Slack, GitHub, Wiz, VirusTotal, AbuseIPDB, URLScan, Vectra, Salesforce, Hubspot, DataDog, and SSH/WinRM infrastructure.
Gaps
Limited production usage, concentrated in one utility. 26 total executions across 133 playbooks — 16 of them from a single internal IP address list maintenance utility (UC6) rather than the SOC/IAM demo flows. Excluding that utility, prospect-facing demo execution volume remains thin (10 executions), so the PreSales team should track which specific SOC/IAM playbooks are demonstrated most, as this remains the primary signal of prospect interest.
High enrichment pipeline duplication. UC1 contains 6+ versioned copies of IP/Hash/Domain enrichment subflows (variants, (1) suffixes, Copy suffixes) across two workspaces. This dilutes the demo narrative and makes workspace navigation confusing for prospects. Consolidation into a single canonical pipeline per IOC type is recommended.
No Vulnerability Management use cases. With CrowdStrike, Wiz, and AWS all connected, there is no vuln scanning ingestion, prioritization/ticketing, or CVE lookup workflow. This is a significant gap relative to what prospects typically evaluate alongside SOAR.
Limited GRC automation depth. UC5 covers compliance checklists well but there is nothing for vendor risk/TPRM, DSAR/privacy, RBAC review workflows, or security metrics reporting — subcategories that appear in most GRC-focused deals.
SIEM/log pipeline gaps beyond CrowdStrike. Despite SSH and WinRM infrastructure tooling, there are no Splunk, Elastic, or generic SIEM ingestion or log pipeline automation workflows. Prospects with existing SIEM investments need these bridges.
Integration Ecosystem
| Category | Integrations |
|---|---|
| EDR / SIEM | CrowdStrike Falcon, Vectra RUX |
| Identity | Microsoft Entra ID, Okta, Google Workspace, Active Directory |
| SaaS / DevTools | GitHub, Slack, Salesforce, Hubspot, DataDog, Wiz, SharePoint |
| Cloud | AWS (IAM, EC2, CloudTrail), Azure Monitor |
| Threat Intel | VirusTotal, AbuseIPDB, URLScan |
| Communication | Email (Blink native), Microsoft Outlook, Microsoft Teams |
| Infrastructure | SSH (Linux), WinRM (Windows Server) |
| AI Agents | Athena (CTI Analyst), Hermes (Detection Writer) |
A Case Management 1 cases (12m) | MTTR N/A
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management V9 | 1 | 1 | 0 | N/A |
B AI Agents 3 active | 58 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Hermes | NexDevOps | 45 | 0 | 3,381,035 |
| 2 | Athena | NexDevOps | 11 | 0 | 170,121 |
| 3 | Iris | NexDevOps | 2 | 0 | 25,166 |
| 4 | Agent Blink | Demo Workspace | 0 | 0 | 0 |
| 5 | Agent Blink | NexDevOps | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| NexDevOps | 58 |
| Demo Workspace | 0 |
| Case Management V9 | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | test | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 7 use cases | 20 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-triaged through case management pipeline | 3 | Process Alert |
| Cloud security events ingested and normalized from Azure Monitor | 3 | EXAMPLE Ingest - Azure |
| Cloud security findings ingested and normalized from Wiz | 1 | EXAMPLE Ingest - Wiz |
| Lateral movement threat detections retrieved from Vectra | 1 | Vectra - Get Lateral Detections |
| Detection engineering requests processed via Slack | 1 | Process Detection Request on Slack mention |
| Analyst Slack interactions automated | 1 | Slack - Respond to Message |
| Internal IP address inventory list refreshed for network asset tracking | 16 | Update Internal IP address list |
*Note: This is a PreSales demonstration environment. Execution counts reflect controlled demo usage rather than production workload.*
Use Case Summary
| # | Use Case | Category | Playbooks | Executions (12mo) |
|---|---|---|---|---|
| 1 | NGSIEM Alert Enrichment Pipeline | SOC | 19 | 0 |
| 2 | Case Management & Automated SOC Response | SOC | 62 | 7 |
| 3 | Agentic Detection Engineering & Threat Intel | SOC | 9 | 3 |
| 4 | Multi-Platform IAM State & Access Inventory | IAM | 11 | 0 |
| 5 | Cloud & Infrastructure Compliance Auditing | Cloud Security / GRC | 7 | 0 |
| 6 | IT Helpdesk & Access Provisioning | Other | 10 | 16 |
| 7 | Demo, Test & Utility Workflows | Other | 15 | 0 |
| Total | 133 | 26 |
Use Cases
UC1 — NGSIEM Alert Enrichment Pipeline
Description: Automated enrichment pipeline for CrowdStrike NGSIEM detections. Ingests alerts via webhook, extracts IPs, domains, and file hashes, performs multi-source threat intelligence lookups, and routes enriched findings via email.
Business problem solved: NGSIEM detections arrive with raw IOCs requiring analyst lookups across VirusTotal, AbuseIPDB, and CrowdStrike indicators. This pipeline automates triage end-to-end — from alert receipt through enrichment and analyst notification.
Integrations: CrowdStrike Falcon, VirusTotal, AbuseIPDB
Category: SOC | Subcategories: Alert enrichment / IOC lookup, SIEM & log pipeline monitoring
| Playbook | Executions | Link |
|---|---|---|
| NGSIEM Incident | 0 | Open |
| NGSIEM Incident (1) | 0 | Open |
| NGSIEM Cases | 0 | Open |
| Main - IP Lookup and Enrichment | 0 | Open |
| Subflow - IP Lookup | 0 | Open |
| Main - IP Enrichment | 0 | Open |
| Main - Hash Enrichment | 0 | Open |
| Main - Domain Enrichment | 0 | Open |
| Subflow - IP Enrichment | 0 | Open |
| Subflow - Hash Enrichment | 0 | Open |
| Subflow - Domain Enrichment | 0 | Open |
| Subflow - Hash Enrichment (1) | 0 | Open |
| Subflow - IP Enrichment (1) | 0 | Open |
| Subflow - Domain Enrichment (1) | 0 | Open |
| Main - Hash Enrichment (1) | 0 | Open |
| Main - Domain Enrichment (1) | 0 | Open |
| GET Host Information from CS via IP Address | 0 | Open |
| VirusTotal and AbuseIPDB Lookup | 0 | Open |
| Subflow - IP Enrichment Copy | 0 | Open |
UC2 — Case Management & Automated SOC Response
Description: Full-featured, AI-assisted case management platform built on Blink. Automates multi-source alert ingestion (6 sources), observable extraction, deduplication, IOC enrichment across 8 enrichment providers, case creation, response routing (phishing, malware), and analyst notifications.
Business problem solved: SOC teams spend the majority of analyst time manually triaging, deduplicating, and enriching alerts across fragmented tools. This platform replaces that manual pipeline with automated flow from raw alert to enriched case with routed response — covering 6 ingestion sources.
Integrations: CrowdStrike Falcon, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, VirusTotal, AbuseIPDB, URLScan, Wiz, Azure Monitor, AWS CloudTrail, Microsoft Defender for Cloud Apps, Microsoft Outlook
Category: SOC | Subcategories: Case mgmt & SOAR, Alert enrichment / IOC lookup, EDR containment & response, Phishing detection & response
| Playbook | Executions | Link |
|---|---|---|
| Process Alert | 3 | Open |
| EXAMPLE Ingest - Azure | 3 | Open |
| EXAMPLE Ingest - Wiz | 1 | Open |
| EXAMPLE Ingest - CrowdStrike | 0 | Open |
| EXAMPLE Ingest - CrowdStrike Falcon LogScale | 0 | Open |
| EXAMPLE Ingest - Microsoft Defender For Cloud Apps | 0 | Open |
| EXAMPLE Ingest - AWS CloudTrail | 0 | Open |
| Response Subflow - Phishing | 0 | Open |
| Response Subflow - Malware | 0 | Open |
| Subflow - Response - Main Router | 0 | Open |
| Enrich - Agent ID - Crowdstrike | 0 | Open |
| Enrich - Username or Email - Okta | 0 | Open |
| Enrich - Username or Email - Google Workspace | 0 | Open |
| Enrich - Username or Email - Microsoft Entra ID | 0 | Open |
| Enrich - Username - Github | 0 | Open |
| Enrich - Email Address - Slack | 0 | Open |
| Enrich - IP - IPDB | 0 | Open |
| Enrich - IP - VT | 0 | Open |
| Enrich IP or Domain Using Whois | 0 | Open |
| Enrich - IP or Domain - Whois | 0 | Open |
| Enrich - URL - VT | 0 | Open |
| Enrich - URL - URLScan | 0 | Open |
| Enrich - Hash - VT | 0 | Open |
| Enrich - Hash - Crowdstrike | 0 | Open |
| Get User Information Using Google Workspace | 0 | Open |
| Get User Information Using Microsoft Entra ID | 0 | Open |
| Get User Information Using Github | 0 | Open |
| Get User Information Using Okta | 0 | Open |
| Get User Information on Email Address Using Slack | 0 | Open |
| Get Hash Info Using VirusTotal | 0 | Open |
| Get Hash Info Using Crowdstrike | 0 | Open |
| Okta Search for User Activity | 0 | Open |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | Open |
| CrowdStrike RTR to a Single Host | 0 | Open |
| CrowdStrike RTR to a Batch of Hosts | 0 | Open |
| Analyze URL with URLScan | 0 | Open |
| Secure URL Screenshot Capture | 0 | Open |
| Get End of Life Date for a Product | 0 | Open |
| Run Dig Command | 0 | Open |
| Subflow - Enrich Observables - Main Router | 0 | Open |
| Subflow - Update Enrichment Data | 0 | Open |
| Subflow - Missing Alert Template Notification | 0 | Open |
| Utility - Update Enrichment | 0 | Open |
| Utility - Close Stale Cases | 0 | Open |
| Utility - Delete Observable Relation | 0 | Open |
| Utility - Set Or Update Observable Relation | 0 | Open |
| Utility - List Observable Alert Relations | 0 | Open |
| Utility - List Alert Observable Relations | 0 | Open |
| Utility - Find Similar Cases Based on Observables | 0 | Open |
| Table Action - Validate Observables Extraction Template | 0 | Open |
| Error Handling - Send Error Notification Email | 0 | Open |
| Recovery - Enrich Non-Enriched Observables | 0 | Open |
| Recovery - Handle Unprocessed Alerts | 0 | Open |
| Simulate Multiple Alerts from Different Sources | 0 | Open |
| Simulate Crowdstrike Alert | 0 | Open |
| USE WITH CARE - Reset Case Management Environment | 0 | Open |
| Subflow - IP Enrichment Copy | 0 | Open |
| Subflow - Hash Enrichment | 0 | Open |
| Subflow - Domain Enrichment | 0 | Open |
| Main - Domain Enrichment | 0 | Open |
| Main - IP Enrichment | 0 | Open |
| Main - Hash Enrichment | 0 | Open |
UC3 — Agentic Detection Engineering & Threat Intel
Description: AI-agent-powered detection engineering workflow. Uses named agents (Athena, a Cyber Threat Intelligence Analyst, and Hermes, a Detection Technical Writer) to process detection requests from Slack, retrieve adversary intel from CrowdStrike, generate detection rules, and retrieve lateral movement detections from Vectra.
Business problem solved: Detection engineering is bottlenecked by the time analysts spend researching threat actors, writing rule syntax, and routing requests through manual channels. This use case automates the full detection request lifecycle via Slack mention, from intake through AI-generated rule output and stakeholder notification.
Integrations: CrowdStrike Falcon (intel), Vectra RUX, Slack, Blink AI Agents (Athena — CTI Analyst, Hermes — Detection Writer)
Category: SOC | Subcategories: Agentic SOC, Threat intel ingest & curation
| Playbook | Executions | Link |
|---|---|---|
| Process Detection Request on Slack mention | 1 | Open |
| Slack - Respond to Message | 1 | Open |
| Vectra - Get Lateral Detections | 1 | Open |
| Detection Request Form | 0 | Open |
| Create Detection Rule | 0 | Open |
| Adversaries Intel Reports | 0 | Open |
| Post Threat Intel Report to Slack | 0 | Open |
| Monitor Channel Mentions | 0 | Open |
| Process Interactivity Event | 0 | Open |
UC4 — Multi-Platform IAM State & Access Inventory
Description: Automated ingestion of user permissions, roles, groups, and license data from 10 identity and SaaS platforms into a centralized Blink table, plus detection of deactivated and inactive accounts in Active Directory.
Business problem solved: Access review and SaaS governance programs require a unified view of who has access to what across the entire tool stack. This use case automates the data collection phase — pulling permissions from 10 platforms into one place for review, audit, or downstream RBAC analysis.
Integrations: Microsoft Entra ID, GitHub, Slack, DataDog, Wiz, Google Workspace, Salesforce, Hubspot, Active Directory
Category: IAM | Subcategories: Access review & group mgmt, Identity sync & directory mgmt, RBAC review & access mgmt
| Playbook | Executions | Link |
|---|---|---|
| IAM State - Insert Azure License | 0 | Open |
| IAM State - Insert Azure User Permissions | 0 | Open |
| IAM State - Insert Azure User Group | 0 | Open |
| IAM State - Insert Github User Permissions | 0 | Open |
| IAM State - Insert Slack User Permissions | 0 | Open |
| IAM State - Insert DataDog User Permissions | 0 | Open |
| IAM State - Insert Wiz User Permissions | 0 | Open |
| IAM State - Insert Google Workspace User Permissions | 0 | Open |
| IAM State - Insert SalesForce User Permissions | 0 | Open |
| IAM State - Insert Hubspot User Permissions | 0 | Open |
| Get Deactivated and Inactive Accounts | 0 | Open |
UC5 — Cloud & Infrastructure Compliance Auditing
Description: Automated compliance checklists and CIS benchmark reporting for AWS cloud and Linux/Windows server infrastructure. Executes checks via native AWS APIs, SSH, and WinRM, and delivers results via email.
Business problem solved: Compliance teams run periodic manual checks against CIS benchmarks and internal policy baselines — SSH-ing into servers, running AWS CLI commands, and compiling results by hand. This use case automates the full data collection and reporting cycle.
Integrations: AWS (IAM, EC2), SSH (RHEL, Ubuntu), WinRM (Windows Server)
Category: Cloud Security / GRC | Subcategories: Config audit & remediation, DevSecOps compliance, RBAC review & access mgmt
| Playbook | Executions | Link |
|---|---|---|
| CIS V1.5.0 Compliance Report for AWS | 0 | Open |
| AWS Checklist | 0 | Open |
| Ensure IAM Users Access Keys are Rotated Every 90 Days or Less in AWS | 0 | Open |
| ACCESS KEYSW | 0 | Open |
| RHEL-based Linux GRC Checklist | 0 | Open |
| Windows Server GRC Checklist | 0 | Open |
| Ubuntu-based Linux GRC Checklist | 0 | Open |
UC6 — IT Helpdesk & Access Provisioning
Description: Self-service and event-driven IT automation covering secure remote access (SRA) requests, temporary user provisioning, IP blocking with approval gates, password expiry notifications, DNS record management, and firewall port management.
Business problem solved: High-volume, repetitive IT requests — access provisioning, firewall changes, DNS updates, password warnings — consume IT team bandwidth and often involve manual email chains for approvals. This use case automates the intake, approval, and execution cycle.
Integrations: Microsoft Entra ID, Microsoft Outlook, Microsoft Teams, Microsoft Defender, Nessus, Active Directory, SSH (Linux), WinRM (Windows), Email
Category: Other | Subcategories: IT helpdesk & ticket routing, JIT & temporary access, IT/OT & network infra monitoring, Password & credential lifecycle
| Playbook | Executions | Link |
|---|---|---|
| SRA - self-service | 0 | Open |
| SRA - Event-based | 0 | Open |
| HR/IT - Create a Temporary User with Microsoft Entra ID | 0 | Open |
| Approval (SRA) | 0 | Open |
| Block IP Address | 0 | Open |
| Approval (IP Block) | 0 | Open |
| Password Expiry Notification | 0 | Open |
| Add DNS Record | 0 | Open |
| Open Port on Linux Machines (CentOS) | 0 | Open |
| Update Internal IP address list | 16 | Open |
UC7 — Demo, Test & Utility Workflows
Description: Ad-hoc demonstrations, test scaffolding, and utility workflows used during PreSales engagements or internal development. Includes data pipeline demos (CSV-to-table, SharePoint upload, Terraform provisioning), event-driven demos (Slack bot, Windows attack simulation), and blank/skeleton workflows.
Category: Other | Subcategories: DevOps & release automation, SaaS / IT administration
| Playbook | Executions | Link |
|---|---|---|
| Color Game | 0 | Open |
| Perform containment | 0 | Open |
| CTF Registration Form | 0 | Open |
| Windows Attack | 0 | Open |
| CSV File to Table | 0 | Open |
| Slack Bot | 0 | Open |
| SharedPoint Integration | 0 | Open |
| AWS - TF Auto Provision of Resources | 0 | Open |
| GWS | 0 | Open |
| Hello World | 0 | Open |
| David Publish Test | 0 | Open |
| Test for publish | 0 | Open |
| Subflow Example | 0 | Open |
| Subflow Example | 0 | Open |
| New Workflow 1 | 0 | Open |
Key Observations
Strengths
Mature SOAR foundation. UC2 is the most architecturally complete use case in the environment — a production-grade case management platform spanning 6 ingest connectors, 14 enrichment providers, response routing for phishing and malware, case deduplication, observable relation management, stale case recovery, and simulation tooling. This is a comprehensive demonstration of Blink's SOAR depth.
Broadest IAM coverage of any PreSales asset. UC4 spans 10 identity and SaaS platforms (Azure, GitHub, Slack, DataDog, Wiz, Google Workspace, Salesforce, Hubspot, Okta, Active Directory) in a single normalized inventory pipeline. This directly addresses the SaaS access visibility gap that surfaces in almost every enterprise prospect conversation.
Agentic SOC differentiation. UC3 showcases two named AI agents (Athena — CTI Analyst, Hermes — Detection Technical Writer) embedded in a live Slack-driven detection engineering workflow. With 3 executions recorded, this is the most-used non-case-management use case, signaling strong prospect interest in agentic capabilities.
Multi-OS compliance coverage. UC5 covers CIS AWS, RHEL, Ubuntu, and Windows Server from a single toolset — a strong response to mixed-infrastructure compliance questions.
Broad integration ecosystem. 20+ integrations demonstrated across CrowdStrike, Microsoft (Entra ID, Outlook, Teams, Defender, Azure), Google Workspace, AWS, Okta, Slack, GitHub, Wiz, VirusTotal, AbuseIPDB, URLScan, Vectra, Salesforce, Hubspot, DataDog, and SSH/WinRM infrastructure.
Gaps
Limited production usage, concentrated in one utility. 26 total executions across 133 playbooks — 16 of them from a single internal IP address list maintenance utility (UC6) rather than the SOC/IAM demo flows. Excluding that utility, prospect-facing demo execution volume remains thin (10 executions), so the PreSales team should track which specific SOC/IAM playbooks are demonstrated most, as this remains the primary signal of prospect interest.
High enrichment pipeline duplication. UC1 contains 6+ versioned copies of IP/Hash/Domain enrichment subflows (variants, (1) suffixes, Copy suffixes) across two workspaces. This dilutes the demo narrative and makes workspace navigation confusing for prospects. Consolidation into a single canonical pipeline per IOC type is recommended.
No Vulnerability Management use cases. With CrowdStrike, Wiz, and AWS all connected, there is no vuln scanning ingestion, prioritization/ticketing, or CVE lookup workflow. This is a significant gap relative to what prospects typically evaluate alongside SOAR.
Limited GRC automation depth. UC5 covers compliance checklists well but there is nothing for vendor risk/TPRM, DSAR/privacy, RBAC review workflows, or security metrics reporting — subcategories that appear in most GRC-focused deals.
SIEM/log pipeline gaps beyond CrowdStrike. Despite SSH and WinRM infrastructure tooling, there are no Splunk, Elastic, or generic SIEM ingestion or log pipeline automation workflows. Prospects with existing SIEM investments need these bridges.
Integration Ecosystem
| Category | Integrations |
|---|---|
| EDR / SIEM | CrowdStrike Falcon, Vectra RUX |
| Identity | Microsoft Entra ID, Okta, Google Workspace, Active Directory |
| SaaS / DevTools | GitHub, Slack, Salesforce, Hubspot, DataDog, Wiz, SharePoint |
| Cloud | AWS (IAM, EC2, CloudTrail), Azure Monitor |
| Threat Intel | VirusTotal, AbuseIPDB, URLScan |
| Communication | Email (Blink native), Microsoft Outlook, Microsoft Teams |
| Infrastructure | SSH (Linux), WinRM (Windows Server) |
| AI Agents | Athena (CTI Analyst), Hermes (Detection Writer) |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| PreSales | zscaler-oneapi | dev_zscaler_oneapi_connection | 2026-08-18 |