Blink Security Automation — Confidential

PreSales — Customer Success Report

Generated 2026-08-30 | presales-value-report.md
2026-08-30Report Date
352Total Playbooks
37Unique Workflows (12m)
3,641Actions Automated (12m)
$936Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

352
Total playbooks built
all non-deleted workflows
134
Active playbooks
currently enabled
37
Unique workflows executed (12m)
distinct workflows that ran
3,641
Actions automated (12m)
completed action steps
20.2h
Hours saved (12m)
@ 20s per action
$936
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
1
Total cases managed
1 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
3
Active AI agents
of 8 total
58
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 3 security alerts auto-triaged through an AI-powered case management and enrichment pipeline - 4 cloud security events ingested and normalized from Azure Monitor and Wiz - 1 lateral movement threat detection retrieved and surfaced from Vectra RUX - 2 analyst workflow interactions automated via Slack - 16 internal IP address inventory refreshes automated for network asset tracking

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
UC1 — NGSIEM Alert Enrichment Pipeline0 executions
0.0%
13
11 active
UC2 — Case Management & Automated SOC Response
  • 3Security alerts auto-triaged through case management pipeline
  • 3Cloud security events ingested and normalized from Azure Monitor
  • 1Cloud security findings ingested and normalized from Wiz
20.0%
61
57 active
UC3 — Agentic Detection Engineering & Threat Intel
  • 1Lateral movement threat detections retrieved from Vectra
  • 1Detection engineering requests processed via Slack
  • 1Analyst Slack interactions automated
0.0%
9
9 active
UC4 — Multi-Platform IAM State & Access Inventory0 executions
0.0%
11
11 active
UC5 — Cloud & Infrastructure Compliance Auditing0 executions
0.0%
7
7 active
UC6 — IT Helpdesk & Access Provisioning
  • 16Internal IP address inventory list refreshed for network asset tracking
80.0%
8
8 active
UC7 — Demo, Test & Utility Workflows0 executions
0.0%
15
13 active
Total20 executions100%
124
116 active

Use Case Growth Over Time

297 unique playbooks  |  7 operational use cases  |  20 total executions (12m)  |  2023-12 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

UC6 — IT Helpdesk & Access Provisioning
SSH Microsoft Defender For Endpoints Any Run Microsoft Teams Microsoft Outlook Email Microsoft Entra ID Active Directory On-Prem
UC7 — Demo, Test & Utility Workflows
CrowdStrike Web Form Email VirusTotal Recorded Future Okta Slack ServiceNow SharePoint GitHub AWS Google Sheets
UC4 — Multi-Platform IAM State & Access Inventory
Microsoft Entra ID Email GitHub Slack Datadog Wiz Google Workspace Salesforce HubSpot
UC1 — NGSIEM Alert Enrichment Pipeline
VirusTotal AbuseIPDB CrowdStrike Email Hybrid Analysis Slack
UC5 — Cloud & Infrastructure Compliance Auditing
AWS Email String Utilities SSH
UC2 — Case Management & Automated SOC Response
CrowdStrike Email VirusTotal Hybrid Analysis AbuseIPDB Microsoft Outlook Okta Google Workspace Microsoft Entra ID URLScan GitHub Slack
UC3 — Agentic Detection Engineering & Threat Intel
CrowdStrike Agents Slack

04Key Observations

✓  Strengths

Strengths

Mature SOAR foundation. UC2 is the most architecturally complete use case in the environment — a production-grade case management platform spanning 6 ingest connectors, 14 enrichment providers, response routing for phishing and malware, case deduplication, observable relation management, stale case recovery, and simulation tooling. This is a comprehensive demonstration of Blink's SOAR depth.

Broadest IAM coverage of any PreSales asset. UC4 spans 10 identity and SaaS platforms (Azure, GitHub, Slack, DataDog, Wiz, Google Workspace, Salesforce, Hubspot, Okta, Active Directory) in a single normalized inventory pipeline. This directly addresses the SaaS access visibility

△  Gaps & Growth Opportunities

gap that surfaces in almost every enterprise prospect conversation.

Agentic SOC differentiation. UC3 showcases two named AI agents (Athena — CTI Analyst, Hermes — Detection Technical Writer) embedded in a live Slack-driven detection engineering workflow. With 3 executions recorded, this is the most-used non-case-management use case, signaling strong prospect interest in agentic capabilities.

Multi-OS compliance coverage. UC5 covers CIS AWS, RHEL, Ubuntu, and Windows Server from a single toolset — a strong response to mixed-infrastructure compliance questions.

Broad integration ecosystem. 20+ integrations demonstrated across CrowdStrike, Microsoft (Entra ID, Outlook, Teams, Defender, Azure), Google Workspace, AWS, Okta, Slack, GitHub, Wiz, VirusTotal, AbuseIPDB, URLScan, Vectra, Salesforce, Hubspot, DataDog, and SSH/WinRM infrastructure.

Gaps

Limited production usage, concentrated in one utility. 26 total executions across 133 playbooks — 16 of them from a single internal IP address list maintenance utility (UC6) rather than the SOC/IAM demo flows. Excluding that utility, prospect-facing demo execution volume remains thin (10 executions), so the PreSales team should track which specific SOC/IAM playbooks are demonstrated most, as this remains the primary signal of prospect interest.

High enrichment pipeline duplication. UC1 contains 6+ versioned copies of IP/Hash/Domain enrichment subflows (variants, (1) suffixes, Copy suffixes) across two workspaces. This dilutes the demo narrative and makes workspace navigation confusing for prospects. Consolidation into a single canonical pipeline per IOC type is recommended.

No Vulnerability Management use cases. With CrowdStrike, Wiz, and AWS all connected, there is no vuln scanning ingestion, prioritization/ticketing, or CVE lookup workflow. This is a significant gap relative to what prospects typically evaluate alongside SOAR.

Limited GRC automation depth. UC5 covers compliance checklists well but there is nothing for vendor risk/TPRM, DSAR/privacy, RBAC review workflows, or security metrics reporting — subcategories that appear in most GRC-focused deals.

SIEM/log pipeline gaps beyond CrowdStrike. Despite SSH and WinRM infrastructure tooling, there are no Splunk, Elastic, or generic SIEM ingestion or log pipeline automation workflows. Prospects with existing SIEM investments need these bridges.

Integration Ecosystem

Category Integrations
EDR / SIEM CrowdStrike Falcon, Vectra RUX
Identity Microsoft Entra ID, Okta, Google Workspace, Active Directory
SaaS / DevTools GitHub, Slack, Salesforce, Hubspot, DataDog, Wiz, SharePoint
Cloud AWS (IAM, EC2, CloudTrail), Azure Monitor
Threat Intel VirusTotal, AbuseIPDB, URLScan
Communication Email (Blink native), Microsoft Outlook, Microsoft Teams
Infrastructure SSH (Linux), WinRM (Windows Server)
AI Agents Athena (CTI Analyst), Hermes (Detection Writer)
Appendices
A Case Management 1 cases (12m) | MTTR N/A

Case Management

Total Cases (all-time)
1
1 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
0
of 1 opened
MTTR
N/A
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management V9 1 1 0 N/A
B AI Agents 3 active | 58 tasks (12m)

AI Agents

Active Agents
3
of 8 total
Tasks Executed (12m)
58
0 in last 30d
Data Usage (12m)
3,576,322
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Hermes NexDevOps 45 0 3,381,035
2 Athena NexDevOps 11 0 170,121
3 Iris NexDevOps 2 0 25,166
4 Agent Blink Demo Workspace 0 0 0
5 Agent Blink NexDevOps 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
NexDevOps58
Demo Workspace0
Case Management V90
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
1
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 test 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 7 use cases | 20 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-triaged through case management pipeline 3 Process Alert
Cloud security events ingested and normalized from Azure Monitor 3 EXAMPLE Ingest - Azure
Cloud security findings ingested and normalized from Wiz 1 EXAMPLE Ingest - Wiz
Lateral movement threat detections retrieved from Vectra 1 Vectra - Get Lateral Detections
Detection engineering requests processed via Slack 1 Process Detection Request on Slack mention
Analyst Slack interactions automated 1 Slack - Respond to Message
Internal IP address inventory list refreshed for network asset tracking 16 Update Internal IP address list
In the last 12 months, Blink automated: - 3 security alerts auto-triaged through an AI-powered case management and enrichment pipeline - 4 cloud security events ingested and normalized from Azure Monitor and Wiz - 1 lateral movement threat detection retrieved and surfaced from Vectra RUX - 2 analyst workflow interactions automated via Slack - 16 internal IP address inventory refreshes automated for network asset tracking

*Note: This is a PreSales demonstration environment. Execution counts reflect controlled demo usage rather than production workload.*

Use Case Summary

# Use Case Category Playbooks Executions (12mo)
1 NGSIEM Alert Enrichment Pipeline SOC 19 0
2 Case Management & Automated SOC Response SOC 62 7
3 Agentic Detection Engineering & Threat Intel SOC 9 3
4 Multi-Platform IAM State & Access Inventory IAM 11 0
5 Cloud & Infrastructure Compliance Auditing Cloud Security / GRC 7 0
6 IT Helpdesk & Access Provisioning Other 10 16
7 Demo, Test & Utility Workflows Other 15 0
Total 133 26

Use Cases

UC1 — NGSIEM Alert Enrichment Pipeline

Description: Automated enrichment pipeline for CrowdStrike NGSIEM detections. Ingests alerts via webhook, extracts IPs, domains, and file hashes, performs multi-source threat intelligence lookups, and routes enriched findings via email.

Business problem solved: NGSIEM detections arrive with raw IOCs requiring analyst lookups across VirusTotal, AbuseIPDB, and CrowdStrike indicators. This pipeline automates triage end-to-end — from alert receipt through enrichment and analyst notification.

Integrations: CrowdStrike Falcon, VirusTotal, AbuseIPDB

Category: SOC | Subcategories: Alert enrichment / IOC lookup, SIEM & log pipeline monitoring

Playbook Executions Link
NGSIEM Incident 0 Open
NGSIEM Incident (1) 0 Open
NGSIEM Cases 0 Open
Main - IP Lookup and Enrichment 0 Open
Subflow - IP Lookup 0 Open
Main - IP Enrichment 0 Open
Main - Hash Enrichment 0 Open
Main - Domain Enrichment 0 Open
Subflow - IP Enrichment 0 Open
Subflow - Hash Enrichment 0 Open
Subflow - Domain Enrichment 0 Open
Subflow - Hash Enrichment (1) 0 Open
Subflow - IP Enrichment (1) 0 Open
Subflow - Domain Enrichment (1) 0 Open
Main - Hash Enrichment (1) 0 Open
Main - Domain Enrichment (1) 0 Open
GET Host Information from CS via IP Address 0 Open
VirusTotal and AbuseIPDB Lookup 0 Open
Subflow - IP Enrichment Copy 0 Open

UC2 — Case Management & Automated SOC Response

Description: Full-featured, AI-assisted case management platform built on Blink. Automates multi-source alert ingestion (6 sources), observable extraction, deduplication, IOC enrichment across 8 enrichment providers, case creation, response routing (phishing, malware), and analyst notifications.

Business problem solved: SOC teams spend the majority of analyst time manually triaging, deduplicating, and enriching alerts across fragmented tools. This platform replaces that manual pipeline with automated flow from raw alert to enriched case with routed response — covering 6 ingestion sources.

Integrations: CrowdStrike Falcon, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, VirusTotal, AbuseIPDB, URLScan, Wiz, Azure Monitor, AWS CloudTrail, Microsoft Defender for Cloud Apps, Microsoft Outlook

Category: SOC | Subcategories: Case mgmt & SOAR, Alert enrichment / IOC lookup, EDR containment & response, Phishing detection & response

Playbook Executions Link
Process Alert 3 Open
EXAMPLE Ingest - Azure 3 Open
EXAMPLE Ingest - Wiz 1 Open
EXAMPLE Ingest - CrowdStrike 0 Open
EXAMPLE Ingest - CrowdStrike Falcon LogScale 0 Open
EXAMPLE Ingest - Microsoft Defender For Cloud Apps 0 Open
EXAMPLE Ingest - AWS CloudTrail 0 Open
Response Subflow - Phishing 0 Open
Response Subflow - Malware 0 Open
Subflow - Response - Main Router 0 Open
Enrich - Agent ID - Crowdstrike 0 Open
Enrich - Username or Email - Okta 0 Open
Enrich - Username or Email - Google Workspace 0 Open
Enrich - Username or Email - Microsoft Entra ID 0 Open
Enrich - Username - Github 0 Open
Enrich - Email Address - Slack 0 Open
Enrich - IP - IPDB 0 Open
Enrich - IP - VT 0 Open
Enrich IP or Domain Using Whois 0 Open
Enrich - IP or Domain - Whois 0 Open
Enrich - URL - VT 0 Open
Enrich - URL - URLScan 0 Open
Enrich - Hash - VT 0 Open
Enrich - Hash - Crowdstrike 0 Open
Get User Information Using Google Workspace 0 Open
Get User Information Using Microsoft Entra ID 0 Open
Get User Information Using Github 0 Open
Get User Information Using Okta 0 Open
Get User Information on Email Address Using Slack 0 Open
Get Hash Info Using VirusTotal 0 Open
Get Hash Info Using Crowdstrike 0 Open
Okta Search for User Activity 0 Open
Manage Endpoint Quarantine Status in Crowdstrike 0 Open
CrowdStrike RTR to a Single Host 0 Open
CrowdStrike RTR to a Batch of Hosts 0 Open
Analyze URL with URLScan 0 Open
Secure URL Screenshot Capture 0 Open
Get End of Life Date for a Product 0 Open
Run Dig Command 0 Open
Subflow - Enrich Observables - Main Router 0 Open
Subflow - Update Enrichment Data 0 Open
Subflow - Missing Alert Template Notification 0 Open
Utility - Update Enrichment 0 Open
Utility - Close Stale Cases 0 Open
Utility - Delete Observable Relation 0 Open
Utility - Set Or Update Observable Relation 0 Open
Utility - List Observable Alert Relations 0 Open
Utility - List Alert Observable Relations 0 Open
Utility - Find Similar Cases Based on Observables 0 Open
Table Action - Validate Observables Extraction Template 0 Open
Error Handling - Send Error Notification Email 0 Open
Recovery - Enrich Non-Enriched Observables 0 Open
Recovery - Handle Unprocessed Alerts 0 Open
Simulate Multiple Alerts from Different Sources 0 Open
Simulate Crowdstrike Alert 0 Open
USE WITH CARE - Reset Case Management Environment 0 Open
Subflow - IP Enrichment Copy 0 Open
Subflow - Hash Enrichment 0 Open
Subflow - Domain Enrichment 0 Open
Main - Domain Enrichment 0 Open
Main - IP Enrichment 0 Open
Main - Hash Enrichment 0 Open

UC3 — Agentic Detection Engineering & Threat Intel

Description: AI-agent-powered detection engineering workflow. Uses named agents (Athena, a Cyber Threat Intelligence Analyst, and Hermes, a Detection Technical Writer) to process detection requests from Slack, retrieve adversary intel from CrowdStrike, generate detection rules, and retrieve lateral movement detections from Vectra.

Business problem solved: Detection engineering is bottlenecked by the time analysts spend researching threat actors, writing rule syntax, and routing requests through manual channels. This use case automates the full detection request lifecycle via Slack mention, from intake through AI-generated rule output and stakeholder notification.

Integrations: CrowdStrike Falcon (intel), Vectra RUX, Slack, Blink AI Agents (Athena — CTI Analyst, Hermes — Detection Writer)

Category: SOC | Subcategories: Agentic SOC, Threat intel ingest & curation

Playbook Executions Link
Process Detection Request on Slack mention 1 Open
Slack - Respond to Message 1 Open
Vectra - Get Lateral Detections 1 Open
Detection Request Form 0 Open
Create Detection Rule 0 Open
Adversaries Intel Reports 0 Open
Post Threat Intel Report to Slack 0 Open
Monitor Channel Mentions 0 Open
Process Interactivity Event 0 Open

UC4 — Multi-Platform IAM State & Access Inventory

Description: Automated ingestion of user permissions, roles, groups, and license data from 10 identity and SaaS platforms into a centralized Blink table, plus detection of deactivated and inactive accounts in Active Directory.

Business problem solved: Access review and SaaS governance programs require a unified view of who has access to what across the entire tool stack. This use case automates the data collection phase — pulling permissions from 10 platforms into one place for review, audit, or downstream RBAC analysis.

Integrations: Microsoft Entra ID, GitHub, Slack, DataDog, Wiz, Google Workspace, Salesforce, Hubspot, Active Directory

Category: IAM | Subcategories: Access review & group mgmt, Identity sync & directory mgmt, RBAC review & access mgmt

Playbook Executions Link
IAM State - Insert Azure License 0 Open
IAM State - Insert Azure User Permissions 0 Open
IAM State - Insert Azure User Group 0 Open
IAM State - Insert Github User Permissions 0 Open
IAM State - Insert Slack User Permissions 0 Open
IAM State - Insert DataDog User Permissions 0 Open
IAM State - Insert Wiz User Permissions 0 Open
IAM State - Insert Google Workspace User Permissions 0 Open
IAM State - Insert SalesForce User Permissions 0 Open
IAM State - Insert Hubspot User Permissions 0 Open
Get Deactivated and Inactive Accounts 0 Open

UC5 — Cloud & Infrastructure Compliance Auditing

Description: Automated compliance checklists and CIS benchmark reporting for AWS cloud and Linux/Windows server infrastructure. Executes checks via native AWS APIs, SSH, and WinRM, and delivers results via email.

Business problem solved: Compliance teams run periodic manual checks against CIS benchmarks and internal policy baselines — SSH-ing into servers, running AWS CLI commands, and compiling results by hand. This use case automates the full data collection and reporting cycle.

Integrations: AWS (IAM, EC2), SSH (RHEL, Ubuntu), WinRM (Windows Server)

Category: Cloud Security / GRC | Subcategories: Config audit & remediation, DevSecOps compliance, RBAC review & access mgmt

Playbook Executions Link
CIS V1.5.0 Compliance Report for AWS 0 Open
AWS Checklist 0 Open
Ensure IAM Users Access Keys are Rotated Every 90 Days or Less in AWS 0 Open
ACCESS KEYSW 0 Open
RHEL-based Linux GRC Checklist 0 Open
Windows Server GRC Checklist 0 Open
Ubuntu-based Linux GRC Checklist 0 Open

UC6 — IT Helpdesk & Access Provisioning

Description: Self-service and event-driven IT automation covering secure remote access (SRA) requests, temporary user provisioning, IP blocking with approval gates, password expiry notifications, DNS record management, and firewall port management.

Business problem solved: High-volume, repetitive IT requests — access provisioning, firewall changes, DNS updates, password warnings — consume IT team bandwidth and often involve manual email chains for approvals. This use case automates the intake, approval, and execution cycle.

Integrations: Microsoft Entra ID, Microsoft Outlook, Microsoft Teams, Microsoft Defender, Nessus, Active Directory, SSH (Linux), WinRM (Windows), Email

Category: Other | Subcategories: IT helpdesk & ticket routing, JIT & temporary access, IT/OT & network infra monitoring, Password & credential lifecycle

Playbook Executions Link
SRA - self-service 0 Open
SRA - Event-based 0 Open
HR/IT - Create a Temporary User with Microsoft Entra ID 0 Open
Approval (SRA) 0 Open
Block IP Address 0 Open
Approval (IP Block) 0 Open
Password Expiry Notification 0 Open
Add DNS Record 0 Open
Open Port on Linux Machines (CentOS) 0 Open
Update Internal IP address list 16 Open

UC7 — Demo, Test & Utility Workflows

Description: Ad-hoc demonstrations, test scaffolding, and utility workflows used during PreSales engagements or internal development. Includes data pipeline demos (CSV-to-table, SharePoint upload, Terraform provisioning), event-driven demos (Slack bot, Windows attack simulation), and blank/skeleton workflows.

Category: Other | Subcategories: DevOps & release automation, SaaS / IT administration

Playbook Executions Link
Color Game 0 Open
Perform containment 0 Open
CTF Registration Form 0 Open
Windows Attack 0 Open
CSV File to Table 0 Open
Slack Bot 0 Open
SharedPoint Integration 0 Open
AWS - TF Auto Provision of Resources 0 Open
GWS 0 Open
Hello World 0 Open
David Publish Test 0 Open
Test for publish 0 Open
Subflow Example 0 Open
Subflow Example 0 Open
New Workflow 1 0 Open

Key Observations

Strengths

Mature SOAR foundation. UC2 is the most architecturally complete use case in the environment — a production-grade case management platform spanning 6 ingest connectors, 14 enrichment providers, response routing for phishing and malware, case deduplication, observable relation management, stale case recovery, and simulation tooling. This is a comprehensive demonstration of Blink's SOAR depth.

Broadest IAM coverage of any PreSales asset. UC4 spans 10 identity and SaaS platforms (Azure, GitHub, Slack, DataDog, Wiz, Google Workspace, Salesforce, Hubspot, Okta, Active Directory) in a single normalized inventory pipeline. This directly addresses the SaaS access visibility gap that surfaces in almost every enterprise prospect conversation.

Agentic SOC differentiation. UC3 showcases two named AI agents (Athena — CTI Analyst, Hermes — Detection Technical Writer) embedded in a live Slack-driven detection engineering workflow. With 3 executions recorded, this is the most-used non-case-management use case, signaling strong prospect interest in agentic capabilities.

Multi-OS compliance coverage. UC5 covers CIS AWS, RHEL, Ubuntu, and Windows Server from a single toolset — a strong response to mixed-infrastructure compliance questions.

Broad integration ecosystem. 20+ integrations demonstrated across CrowdStrike, Microsoft (Entra ID, Outlook, Teams, Defender, Azure), Google Workspace, AWS, Okta, Slack, GitHub, Wiz, VirusTotal, AbuseIPDB, URLScan, Vectra, Salesforce, Hubspot, DataDog, and SSH/WinRM infrastructure.

Gaps

Limited production usage, concentrated in one utility. 26 total executions across 133 playbooks — 16 of them from a single internal IP address list maintenance utility (UC6) rather than the SOC/IAM demo flows. Excluding that utility, prospect-facing demo execution volume remains thin (10 executions), so the PreSales team should track which specific SOC/IAM playbooks are demonstrated most, as this remains the primary signal of prospect interest.

High enrichment pipeline duplication. UC1 contains 6+ versioned copies of IP/Hash/Domain enrichment subflows (variants, (1) suffixes, Copy suffixes) across two workspaces. This dilutes the demo narrative and makes workspace navigation confusing for prospects. Consolidation into a single canonical pipeline per IOC type is recommended.

No Vulnerability Management use cases. With CrowdStrike, Wiz, and AWS all connected, there is no vuln scanning ingestion, prioritization/ticketing, or CVE lookup workflow. This is a significant gap relative to what prospects typically evaluate alongside SOAR.

Limited GRC automation depth. UC5 covers compliance checklists well but there is nothing for vendor risk/TPRM, DSAR/privacy, RBAC review workflows, or security metrics reporting — subcategories that appear in most GRC-focused deals.

SIEM/log pipeline gaps beyond CrowdStrike. Despite SSH and WinRM infrastructure tooling, there are no Splunk, Elastic, or generic SIEM ingestion or log pipeline automation workflows. Prospects with existing SIEM investments need these bridges.

Integration Ecosystem

Category Integrations
EDR / SIEM CrowdStrike Falcon, Vectra RUX
Identity Microsoft Entra ID, Okta, Google Workspace, Active Directory
SaaS / DevTools GitHub, Slack, Salesforce, Hubspot, DataDog, Wiz, SharePoint
Cloud AWS (IAM, EC2, CloudTrail), Azure Monitor
Threat Intel VirusTotal, AbuseIPDB, URLScan
Communication Email (Blink native), Microsoft Outlook, Microsoft Teams
Infrastructure SSH (Linux), WinRM (Windows Server)
AI Agents Athena (CTI Analyst), Hermes (Detection Writer)
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
PreSales zscaler-oneapi dev_zscaler_oneapi_connection 2026-08-18