01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Automated Alert Triage & IOC Enrichment |
| 27.1% | 6 4 active |
| Network IOC Blocking & Perimeter Enforcement |
| 72.9% | 6 6 active |
| Total | 85 executions | 100% | 12 10 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- High-volume alert automation is live and running. The NGSIEM Cases pipeline processed 460 CrowdStrike alerts over 12 months with automatic IP enrichment on every case — this is a fully operational tier-1 triage bypass.
- Domain enrichment is active and covers a meaningful subset. 110 domain enrichments ran, suggesting domain-bearing alerts are a significant portion of the alert mix (~24% of total alerts).
- Firewall response is codified and auditable. The Palo Alto blocking stack (request → block → commit) is in place with an explicit IOC blocking request flow that captures reason and ticket number, meeting audit and change-management requirements.
- Production workspace is clearly separated. All active executions run in workspace
4573c11f(NGSIEM, IP enrichment, domain enrichment) with a clean separation from the secondary workspace0b00076c(firewall management, inactive duplicates), indicating deliberate workspace hygiene.
###
Gaps & Opportunities
- Hash enrichment has never run. The Subflow - Hash Enrichment playbook exists but has 0 executions. If CrowdStrike alerts surface file hash (SHA-256) indicators, this enrichment path is currently dormant — enabling it would close a gap in the IOC enrichment coverage.
- Domain enrichment subflow appears unused. Despite Main - Domain Enrichment running 110 times, the Subflow - Domain Enrichment in the production workspace has 0 executions. This may indicate the main flow handles enrichment inline without delegating to the subflow, or the subflow was replaced and can be retired.
- Inactive workspace duplicates add maintenance risk. Workspace
0b00076cholds non-executing copies of NGSIEM Cases, Main - IP Enrichment v2.0, and Main - Domain Enrichment v2.0. If not intentionally kept as staging, they should be archived to prevent confusion during future updates. - IOC blocking volume is low relative to alert volume. Only 8 IPs were blocked across 460 triaged alerts (~1.7%). This is plausible if enrichment is doing its job and most alerts are resolved without containment — but it's worth confirming that the block workflows are being surfaced to analysts in the alert output.
- No case management or ticketing integration visible. The enrichment pipeline sends email but does not appear to create tickets in a SIEM or ITSM platform (e.g., ServiceNow, Jira, Splunk). Adding a bi-directional case sync would close the loop between Blink automation and the broader SOC workflow.
Integration Ecosystem
| Integration | Purpose | Use Case |
|---|---|---|
| CrowdStrike Falcon / NGSIEM | Webhook event source, alert detail retrieval | Alert triage |
| Palo Alto PAN-OS | Firewall address group management, configuration commit | IOC blocking |
| Blink Tables (HTTP) | Public IP/domain allowlists, enrichment result cache | IP & domain enrichment |
| Blink Core Python | Threat confidence scoring, IP classification, data formatting | Both use cases |
| Blink Email (core.emailV2) | Analyst notification with enrichment results | Domain enrichment |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | test | 0 | 0 |
| 2 | IPv4 IOC Blocking in PAN | 0 | 0 |
| 3 | Test | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 2 use cases | 85 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-triaged from CrowdStrike NGSIEM | 460 | NGSIEM Cases |
| Domains automatically enriched in response to alerts | 110 | Main - Domain Enrichment v2.0 |
| IPs blocked at the network perimeter (Palo Alto) | 8 | Block in Palo Alto Firewall - IP Netmask |
| IOC blocking requests processed end-to-end | 2 | IOC Blocking Request - IPv4 Address |
| IPs unblocked from network perimeter | 2 | Unblock in Palo Alto Firewall |
| IPv4 masterlist records updated in Blink Table | 8 | Update IPv4 Masterlist in Blink Table |
Use Case Summary
| Use Case | Category | Subcategories | Total Playbooks | Active Playbooks |
|---|---|---|---|---|
| Automated Alert Triage & IOC Enrichment | SOC | Agentic SOC, Alert enrichment / IOC lookup, Case mgmt & SOAR | 9 | 4 |
| Network IOC Blocking & Perimeter Enforcement | SOC | EDR containment & response | 6 | 5 |
Use Cases
1. Automated Alert Triage & IOC Enrichment
Description: Ingests CrowdStrike NGSIEM webhook events and automatically enriches the threat indicators (IPs, domains, file hashes) found in each alert. Enrichment results are classified, scored for threat confidence, and surfaced to analysts — reducing the volume of alerts requiring manual investigation.
Business problem: The SOC receives a high volume of CrowdStrike NGSIEM alerts. Manually looking up every IP, domain, or hash indicator is slow and inconsistent. This use case automates the enrichment pipeline end-to-end, from webhook ingestion through indicator classification, so analysts receive a pre-assessed alert rather than raw telemetry.
Integrations: CrowdStrike Falcon / NGSIEM (webhook trigger, alert detail retrieval), Blink Tables (public IP/domain allowlists, enrichment cache), Blink Core Python (threat confidence scoring, data formatting), Email (analyst notification)
| Playbook | Role | Executions (12 mo.) | Link |
|---|---|---|---|
| NGSIEM Cases | Main event trigger — receives CrowdStrike webhook, extracts alert ID, routes to enrichment flows | 460 | Link |
| Main - IP Enrichment v2.0 | Top-level IP enrichment pipeline — classifies IPs (private / org / external), runs enrichment subflow, caches results | 460 | Link |
| Main - Domain Enrichment v2.0 | Top-level domain enrichment pipeline — checks org-owned domains, iterates enrichment subflows, sends analyst email | 110 | Link |
| Subflow - IP Enrichment | Executes third-party IP lookups, evaluates threat confidence, formats enrichment output | 31 | Link |
| Subflow - Domain Enrichment | Executes third-party domain lookups, formats enrichment output | 0 | Link |
| Subflow - Hash Enrichment | Executes hash/SHA-256 lookups for file indicators | 0 | Link |
| NGSIEM Cases *(inactive workspace)* | Duplicate pipeline in secondary workspace — not currently active | 0 | Link |
| Main - IP Enrichment v2.0 *(inactive workspace)* | Duplicate in secondary workspace — not currently active | 0 | Link |
| Main - Domain Enrichment v2.0 *(inactive workspace)* | Duplicate in secondary workspace — not currently active | 0 | Link |
2. Network IOC Blocking & Perimeter Enforcement
Description: Provides a structured, auditable workflow for blocking and unblocking malicious IP addresses in the Palo Alto Firewall. Covers both reactive blocking triggered by an IOC request and proactive configuration commit management to ensure changes take effect.
Business problem: Blocking a malicious IP in a firewall is error-prone when done manually — wrong subnet masks, missed commits, no audit trail. This use case ensures every block/unblock action goes through a consistent, documented process that includes validation, firewall commit, and status confirmation.
Integrations: Palo Alto Networks PAN-OS (ExecuteAPICommand for address group management and commit), Blink Core Python (data cleaning, input normalization)
| Playbook | Role | Executions (12 mo.) | Link |
|---|---|---|---|
| Block in Palo Alto Firewall - IP Netmask | Adds an IP/netmask to the Palo Alto address group and tracks result | 8 | Link |
| IOC Blocking Request - IPv4 Address | On-demand entry point for analyst-initiated IPv4 blocking with reason and ticket tracking | 2 | Link |
| Unblock in Palo Alto Firewall | Removes addresses from the Palo Alto block group, commits, and reports reverted IOCs | 2 | Link |
| Commit Configurations Palo Alto FW | Commits pending firewall configuration changes and returns commit status | 2 | Link |
| On-Demand Commit Configuration | Analyst-initiated commit with documented reason; calls the commit subflow | 0 | Link |
| Update IPv4 Masterlist in Blink Table | On-demand ingestion of a CSV of IPv4 addresses to update the master blocklist record in Blink Tables, with error handling and email notification | 8 | Link |
Key Observations
Strengths
- High-volume alert automation is live and running. The NGSIEM Cases pipeline processed 460 CrowdStrike alerts over 12 months with automatic IP enrichment on every case — this is a fully operational tier-1 triage bypass.
- Domain enrichment is active and covers a meaningful subset. 110 domain enrichments ran, suggesting domain-bearing alerts are a significant portion of the alert mix (~24% of total alerts).
- Firewall response is codified and auditable. The Palo Alto blocking stack (request → block → commit) is in place with an explicit IOC blocking request flow that captures reason and ticket number, meeting audit and change-management requirements.
- Production workspace is clearly separated. All active executions run in workspace
4573c11f(NGSIEM, IP enrichment, domain enrichment) with a clean separation from the secondary workspace0b00076c(firewall management, inactive duplicates), indicating deliberate workspace hygiene.
Gaps & Opportunities
- Hash enrichment has never run. The Subflow - Hash Enrichment playbook exists but has 0 executions. If CrowdStrike alerts surface file hash (SHA-256) indicators, this enrichment path is currently dormant — enabling it would close a gap in the IOC enrichment coverage.
- Domain enrichment subflow appears unused. Despite Main - Domain Enrichment running 110 times, the Subflow - Domain Enrichment in the production workspace has 0 executions. This may indicate the main flow handles enrichment inline without delegating to the subflow, or the subflow was replaced and can be retired.
- Inactive workspace duplicates add maintenance risk. Workspace
0b00076cholds non-executing copies of NGSIEM Cases, Main - IP Enrichment v2.0, and Main - Domain Enrichment v2.0. If not intentionally kept as staging, they should be archived to prevent confusion during future updates. - IOC blocking volume is low relative to alert volume. Only 8 IPs were blocked across 460 triaged alerts (~1.7%). This is plausible if enrichment is doing its job and most alerts are resolved without containment — but it's worth confirming that the block workflows are being surfaced to analysts in the alert output.
- No case management or ticketing integration visible. The enrichment pipeline sends email but does not appear to create tickets in a SIEM or ITSM platform (e.g., ServiceNow, Jira, Splunk). Adding a bi-directional case sync would close the loop between Blink automation and the broader SOC workflow.
Integration Ecosystem
| Integration | Purpose | Use Case |
|---|---|---|
| CrowdStrike Falcon / NGSIEM | Webhook event source, alert detail retrieval | Alert triage |
| Palo Alto PAN-OS | Firewall address group management, configuration commit | IOC blocking |
| Blink Tables (HTTP) | Public IP/domain allowlists, enrichment result cache | IP & domain enrichment |
| Blink Core Python | Threat confidence scoring, IP classification, data formatting | Both use cases |
| Blink Email (core.emailV2) | Analyst notification with enrichment results | Domain enrichment |
Taxonomy Classification
| Playbook | Category | Subcategories |
|---|---|---|
| NGSIEM Cases | SOC | Agentic SOC, Case mgmt & SOAR |
| Main - IP Enrichment v2.0 | SOC | Alert enrichment / IOC lookup, Agentic SOC |
| Main - Domain Enrichment v2.0 | SOC | Alert enrichment / IOC lookup, Agentic SOC |
| Subflow - IP Enrichment | SOC | Alert enrichment / IOC lookup |
| Subflow - Domain Enrichment | SOC | Alert enrichment / IOC lookup |
| Subflow - Hash Enrichment | SOC | Alert enrichment / IOC lookup |
| Block in Palo Alto Firewall - IP Netmask | SOC | EDR containment & response |
| IOC Blocking Request - IPv4 Address | SOC | EDR containment & response, Alert enrichment / IOC lookup |
| Unblock in Palo Alto Firewall | SOC | EDR containment & response |
| Commit Configurations Palo Alto FW | SOC | EDR containment & response |
| On-Demand Commit Configuration | SOC | EDR containment & response |
| Update IPv4 Masterlist in Blink Table | SOC | EDR containment & response |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.