01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Alert Enrichment — IP, Domain & Hash | 0 executions | 0.0% | 5 5 active |
| CrowdStrike NGSIEM Case Intake | 0 executions | 0.0% | 1 1 active |
| Total | 0 executions | 100% | 6 6 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Modular enrichment architecture. The separation of Main orchestrators from enrichment Subflows (IP / Domain / Hash) is a strong design pattern. Subflows can be reused across multiple alert types and triggers without duplication, and the architecture scales cleanly as more indicator types are added.
- Organizational context awareness. The IP and Domain enrichment mains query Blink Tables for organization-owned assets before querying external threat intelligence. This avoids false positives on internally routed IPs and org-controlled domains — a production-quality refinement that reflects real-world operational maturity.
- CrowdStrike-native integration. Both the NGSIEM Cases intake and the enrichment subflows call
crowdstrike.GetAlertDetails, meaning alert context is fetched directly from the authoritative source rather than relying on potentially truncated webhook payloads. - Confidence scoring logic. The IP Enrichment subflow includes a Python step explicitly named "Evaluate threat confidence," indicating the automation produces a risk score rather than raw data — directly supporting analyst decision-making.
###
Gaps
- Zero production executions. All 6 workflows show 0 executions in the last 12 months. The automation layer is built and configured but has not yet been activated in a live alert pipeline. The value of this investment is currently unrealized.
- No active trigger on enrichment mains. Both
Main - IP Enrichment v2.0andMain - Domain Enrichment v2.0areon_demandwith no event trigger wired. They are designed to be called from a parent workflow (e.g., NGSIEM Cases) but that connection has not been made — the NGSIEM Cases workflow routes through conditions but does not visibly invoke the enrichment mains. - No alert closure or ticketing step. The pipeline enriches and scores indicators but there is no visible step that creates a ticket, updates a case status, or closes an alert. Adding a case-update action (e.g., back to CrowdStrike or a ITSM tool) would complete the loop and enable full automation of the triage cycle.
- Hash enrichment not connected.
Subflow - Hash Enrichmentexists but no top-levelMain - Hash Enrichmentorchestrator is present. Hash-based indicators would need a main flow to be operationalized. - Email as sole output. The Domain Enrichment main sends results via Blink email. For a SOC use case, enrichment output is better delivered into the case management system (CrowdStrike case comments, a SIEM annotation, or a Slack/Teams alert) to keep the analyst in a single pane.
Integration Ecosystem
| Integration | Usage |
|---|---|
| CrowdStrike | Alert detail retrieval (GetAlertDetails), webhook event source (NGSIEM) |
| Blink HTTP Tables | Organizational IP and domain allow-lists |
| Blink Email (core.emailV2) | Enrichment result delivery |
| Python (core.python / core.pythonV2) | Alert ID extraction, IP classification, threat confidence scoring, data formatting |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 2 use cases | 0 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| — | — | No playbooks recorded executions in the last 12 months |
Use Case Summary
| Use Case | Category | Subcategory | Playbook Count | Executions (12 mo) |
|---|---|---|---|---|
| Alert Enrichment — IP, Domain & Hash | SOC | Alert enrichment / IOC lookup | 5 | 0 |
| CrowdStrike NGSIEM Case Intake | SOC | Case mgmt & SOAR, SIEM & log pipeline monitoring | 1 | 0 |
Total: 6 playbooks across 2 use cases.
Use Cases
1. Alert Enrichment — IP, Domain & Hash
Description: A layered enrichment pipeline that classifies and investigates indicators of compromise — IP addresses, domains, and file hashes — surfaced by CrowdStrike alerts. The architecture separates orchestration (Main playbooks) from enrichment logic (Subflows), enabling reuse across different alert types.
Business problem solved: Analysts spend significant time manually looking up whether an IP, domain, or file hash is malicious. This use case automates that investigation, classifies indicators as internal/external/organizational, queries threat intelligence, and delivers a formatted enrichment summary — removing manual lookup work from the alert triage loop.
Integrations observed: CrowdStrike (alert detail retrieval), Blink HTTP Tables (organizational IP/domain allow-lists), Blink Email (enrichment delivery), Python (IP classification logic, threat confidence scoring).
| Playbook | Role | Executions (12 mo) |
|---|---|---|
| Main - IP Enrichment v2.0 | Top-level orchestrator for IP indicator enrichment; classifies IPs as private, org-owned, or external before enriching | 0 |
| Main - Domain Enrichment v2.0 | Top-level orchestrator for domain indicator enrichment; checks org domain list then sends enrichment email | 0 |
| Subflow - IP Enrichment | Enrichment subflow invoked by Main; queries threat intel, scores confidence, formats output | 0 |
| Subflow - Domain Enrichment | Enrichment subflow for domain indicators | 0 |
| Subflow - Hash Enrichment | Enrichment subflow for SHA-256 file hash indicators | 0 |
Taxonomy: SOC › Alert enrichment / IOC lookup
2. CrowdStrike NGSIEM Case Intake
Description: An event-driven workflow that ingests CrowdStrike NGSIEM alerts via webhook, extracts the alert ID, retrieves full alert details, and routes the case through conditional logic for triage or downstream action.
Business problem solved: Security cases generated in CrowdStrike NGSIEM need to be captured, normalized, and acted upon quickly. This workflow provides the intake layer — ensuring that every inbound CrowdStrike case is received, enriched with alert detail, and evaluated against triage conditions without manual intervention.
Integrations observed: CrowdStrike (webhook trigger, GetAlertDetails), Python (alert ID extraction), conditional branching logic.
| Playbook | Role | Executions (12 mo) |
|---|---|---|
| NGSIEM Cases | Event-driven intake for CrowdStrike NGSIEM alerts; extracts, retrieves, and conditionally routes cases | 0 |
Taxonomy: SOC › Case mgmt & SOAR, SIEM & log pipeline monitoring
Key Observations
Strengths
- Modular enrichment architecture. The separation of Main orchestrators from enrichment Subflows (IP / Domain / Hash) is a strong design pattern. Subflows can be reused across multiple alert types and triggers without duplication, and the architecture scales cleanly as more indicator types are added.
- Organizational context awareness. The IP and Domain enrichment mains query Blink Tables for organization-owned assets before querying external threat intelligence. This avoids false positives on internally routed IPs and org-controlled domains — a production-quality refinement that reflects real-world operational maturity.
- CrowdStrike-native integration. Both the NGSIEM Cases intake and the enrichment subflows call
crowdstrike.GetAlertDetails, meaning alert context is fetched directly from the authoritative source rather than relying on potentially truncated webhook payloads. - Confidence scoring logic. The IP Enrichment subflow includes a Python step explicitly named "Evaluate threat confidence," indicating the automation produces a risk score rather than raw data — directly supporting analyst decision-making.
Gaps
- Zero production executions. All 6 workflows show 0 executions in the last 12 months. The automation layer is built and configured but has not yet been activated in a live alert pipeline. The value of this investment is currently unrealized.
- No active trigger on enrichment mains. Both
Main - IP Enrichment v2.0andMain - Domain Enrichment v2.0areon_demandwith no event trigger wired. They are designed to be called from a parent workflow (e.g., NGSIEM Cases) but that connection has not been made — the NGSIEM Cases workflow routes through conditions but does not visibly invoke the enrichment mains. - No alert closure or ticketing step. The pipeline enriches and scores indicators but there is no visible step that creates a ticket, updates a case status, or closes an alert. Adding a case-update action (e.g., back to CrowdStrike or a ITSM tool) would complete the loop and enable full automation of the triage cycle.
- Hash enrichment not connected.
Subflow - Hash Enrichmentexists but no top-levelMain - Hash Enrichmentorchestrator is present. Hash-based indicators would need a main flow to be operationalized. - Email as sole output. The Domain Enrichment main sends results via Blink email. For a SOC use case, enrichment output is better delivered into the case management system (CrowdStrike case comments, a SIEM annotation, or a Slack/Teams alert) to keep the analyst in a single pane.
Integration Ecosystem
| Integration | Usage |
|---|---|
| CrowdStrike | Alert detail retrieval (GetAlertDetails), webhook event source (NGSIEM) |
| Blink HTTP Tables | Organizational IP and domain allow-lists |
| Blink Email (core.emailV2) | Enrichment result delivery |
| Python (core.python / core.pythonV2) | Alert ID extraction, IP classification, threat confidence scoring, data formatting |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.