Blink Security Automation — Confidential

Project-falcon — Customer Success Report

Generated 2026-08-30 | project-falcon-value-report.md
2026-08-30Report Date
65Total Playbooks
15Unique Workflows (12m)
396,184Actions Automated (12m)
$101,899Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

65
Total playbooks built
all non-deleted workflows
12
Active playbooks
currently enabled
15
Unique workflows executed (12m)
distinct workflows that ran
396,184
Actions automated (12m)
completed action steps
2,201.0h
Hours saved (12m)
@ 20s per action
$101,899
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 460 CrowdStrike NGSIEM security alerts triaged and enriched without manual analyst triage - 110 domains automatically assessed for threat indicators in response to active alerts - 8 malicious IPv4 addresses blocked at the network perimeter via Palo Alto Firewall - 2 IOC blocking requests processed end-to-end with full audit trail - 2 network perimeter unblock actions executed on request - 8 master IPv4 blocklist records updated in Blink Table for audit tracking

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Automated Alert Triage & IOC Enrichment
  • 460Security alerts auto-triaged from CrowdStrike NGSIEM
  • 110Domains automatically enriched in response to alerts
27.1%
6
4 active
Network IOC Blocking & Perimeter Enforcement
  • 8IPs blocked at the network perimeter (Palo Alto)
  • 8IPv4 masterlist records updated in Blink Table
  • 2IOC blocking requests processed end-to-end
72.9%
6
6 active
Total85 executions100%
12
10 active

Use Case Growth Over Time

35 unique playbooks  |  2 operational use cases  |  85 total executions (12m)  |  2025-04 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Automated Alert Triage & IOC Enrichment
CrowdStrike AbuseIPDB VirusTotal Email Hybrid Analysis
Network IOC Blocking & Perimeter Enforcement
Email Web Form Palo Alto Firewall

04Key Observations

✓  Strengths

Strengths

  • High-volume alert automation is live and running. The NGSIEM Cases pipeline processed 460 CrowdStrike alerts over 12 months with automatic IP enrichment on every case — this is a fully operational tier-1 triage bypass.
  • Domain enrichment is active and covers a meaningful subset. 110 domain enrichments ran, suggesting domain-bearing alerts are a significant portion of the alert mix (~24% of total alerts).
  • Firewall response is codified and auditable. The Palo Alto blocking stack (request → block → commit) is in place with an explicit IOC blocking request flow that captures reason and ticket number, meeting audit and change-management requirements.
  • Production workspace is clearly separated. All active executions run in workspace 4573c11f (NGSIEM, IP enrichment, domain enrichment) with a clean separation from the secondary workspace 0b00076c (firewall management, inactive duplicates), indicating deliberate workspace hygiene.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • Hash enrichment has never run. The Subflow - Hash Enrichment playbook exists but has 0 executions. If CrowdStrike alerts surface file hash (SHA-256) indicators, this enrichment path is currently dormant — enabling it would close a gap in the IOC enrichment coverage.
  • Domain enrichment subflow appears unused. Despite Main - Domain Enrichment running 110 times, the Subflow - Domain Enrichment in the production workspace has 0 executions. This may indicate the main flow handles enrichment inline without delegating to the subflow, or the subflow was replaced and can be retired.
  • Inactive workspace duplicates add maintenance risk. Workspace 0b00076c holds non-executing copies of NGSIEM Cases, Main - IP Enrichment v2.0, and Main - Domain Enrichment v2.0. If not intentionally kept as staging, they should be archived to prevent confusion during future updates.
  • IOC blocking volume is low relative to alert volume. Only 8 IPs were blocked across 460 triaged alerts (~1.7%). This is plausible if enrichment is doing its job and most alerts are resolved without containment — but it's worth confirming that the block workflows are being surfaced to analysts in the alert output.
  • No case management or ticketing integration visible. The enrichment pipeline sends email but does not appear to create tickets in a SIEM or ITSM platform (e.g., ServiceNow, Jira, Splunk). Adding a bi-directional case sync would close the loop between Blink automation and the broader SOC workflow.

Integration Ecosystem

Integration Purpose Use Case
CrowdStrike Falcon / NGSIEM Webhook event source, alert detail retrieval Alert triage
Palo Alto PAN-OS Firewall address group management, configuration commit IOC blocking
Blink Tables (HTTP) Public IP/domain allowlists, enrichment result cache IP & domain enrichment
Blink Core Python Threat confidence scoring, IP classification, data formatting Both use cases
Blink Email (core.emailV2) Analyst notification with enrichment results Domain enrichment
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
3
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 test 00
2 IPv4 IOC Blocking in PAN 00
3 Test 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 2 use cases | 85 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-triaged from CrowdStrike NGSIEM 460 NGSIEM Cases
Domains automatically enriched in response to alerts 110 Main - Domain Enrichment v2.0
IPs blocked at the network perimeter (Palo Alto) 8 Block in Palo Alto Firewall - IP Netmask
IOC blocking requests processed end-to-end 2 IOC Blocking Request - IPv4 Address
IPs unblocked from network perimeter 2 Unblock in Palo Alto Firewall
IPv4 masterlist records updated in Blink Table 8 Update IPv4 Masterlist in Blink Table
In the last 12 months, Blink automated: - 460 CrowdStrike NGSIEM security alerts triaged and enriched without manual analyst triage - 110 domains automatically assessed for threat indicators in response to active alerts - 8 malicious IPv4 addresses blocked at the network perimeter via Palo Alto Firewall - 2 IOC blocking requests processed end-to-end with full audit trail - 2 network perimeter unblock actions executed on request - 8 master IPv4 blocklist records updated in Blink Table for audit tracking

Use Case Summary

Use Case Category Subcategories Total Playbooks Active Playbooks
Automated Alert Triage & IOC Enrichment SOC Agentic SOC, Alert enrichment / IOC lookup, Case mgmt & SOAR 9 4
Network IOC Blocking & Perimeter Enforcement SOC EDR containment & response 6 5

Use Cases

1. Automated Alert Triage & IOC Enrichment

Description: Ingests CrowdStrike NGSIEM webhook events and automatically enriches the threat indicators (IPs, domains, file hashes) found in each alert. Enrichment results are classified, scored for threat confidence, and surfaced to analysts — reducing the volume of alerts requiring manual investigation.

Business problem: The SOC receives a high volume of CrowdStrike NGSIEM alerts. Manually looking up every IP, domain, or hash indicator is slow and inconsistent. This use case automates the enrichment pipeline end-to-end, from webhook ingestion through indicator classification, so analysts receive a pre-assessed alert rather than raw telemetry.

Integrations: CrowdStrike Falcon / NGSIEM (webhook trigger, alert detail retrieval), Blink Tables (public IP/domain allowlists, enrichment cache), Blink Core Python (threat confidence scoring, data formatting), Email (analyst notification)

Playbook Role Executions (12 mo.) Link
NGSIEM Cases Main event trigger — receives CrowdStrike webhook, extracts alert ID, routes to enrichment flows 460 Link
Main - IP Enrichment v2.0 Top-level IP enrichment pipeline — classifies IPs (private / org / external), runs enrichment subflow, caches results 460 Link
Main - Domain Enrichment v2.0 Top-level domain enrichment pipeline — checks org-owned domains, iterates enrichment subflows, sends analyst email 110 Link
Subflow - IP Enrichment Executes third-party IP lookups, evaluates threat confidence, formats enrichment output 31 Link
Subflow - Domain Enrichment Executes third-party domain lookups, formats enrichment output 0 Link
Subflow - Hash Enrichment Executes hash/SHA-256 lookups for file indicators 0 Link
NGSIEM Cases *(inactive workspace)* Duplicate pipeline in secondary workspace — not currently active 0 Link
Main - IP Enrichment v2.0 *(inactive workspace)* Duplicate in secondary workspace — not currently active 0 Link
Main - Domain Enrichment v2.0 *(inactive workspace)* Duplicate in secondary workspace — not currently active 0 Link

2. Network IOC Blocking & Perimeter Enforcement

Description: Provides a structured, auditable workflow for blocking and unblocking malicious IP addresses in the Palo Alto Firewall. Covers both reactive blocking triggered by an IOC request and proactive configuration commit management to ensure changes take effect.

Business problem: Blocking a malicious IP in a firewall is error-prone when done manually — wrong subnet masks, missed commits, no audit trail. This use case ensures every block/unblock action goes through a consistent, documented process that includes validation, firewall commit, and status confirmation.

Integrations: Palo Alto Networks PAN-OS (ExecuteAPICommand for address group management and commit), Blink Core Python (data cleaning, input normalization)

Playbook Role Executions (12 mo.) Link
Block in Palo Alto Firewall - IP Netmask Adds an IP/netmask to the Palo Alto address group and tracks result 8 Link
IOC Blocking Request - IPv4 Address On-demand entry point for analyst-initiated IPv4 blocking with reason and ticket tracking 2 Link
Unblock in Palo Alto Firewall Removes addresses from the Palo Alto block group, commits, and reports reverted IOCs 2 Link
Commit Configurations Palo Alto FW Commits pending firewall configuration changes and returns commit status 2 Link
On-Demand Commit Configuration Analyst-initiated commit with documented reason; calls the commit subflow 0 Link
Update IPv4 Masterlist in Blink Table On-demand ingestion of a CSV of IPv4 addresses to update the master blocklist record in Blink Tables, with error handling and email notification 8 Link

Key Observations

Strengths

  • High-volume alert automation is live and running. The NGSIEM Cases pipeline processed 460 CrowdStrike alerts over 12 months with automatic IP enrichment on every case — this is a fully operational tier-1 triage bypass.
  • Domain enrichment is active and covers a meaningful subset. 110 domain enrichments ran, suggesting domain-bearing alerts are a significant portion of the alert mix (~24% of total alerts).
  • Firewall response is codified and auditable. The Palo Alto blocking stack (request → block → commit) is in place with an explicit IOC blocking request flow that captures reason and ticket number, meeting audit and change-management requirements.
  • Production workspace is clearly separated. All active executions run in workspace 4573c11f (NGSIEM, IP enrichment, domain enrichment) with a clean separation from the secondary workspace 0b00076c (firewall management, inactive duplicates), indicating deliberate workspace hygiene.

Gaps & Opportunities

  • Hash enrichment has never run. The Subflow - Hash Enrichment playbook exists but has 0 executions. If CrowdStrike alerts surface file hash (SHA-256) indicators, this enrichment path is currently dormant — enabling it would close a gap in the IOC enrichment coverage.
  • Domain enrichment subflow appears unused. Despite Main - Domain Enrichment running 110 times, the Subflow - Domain Enrichment in the production workspace has 0 executions. This may indicate the main flow handles enrichment inline without delegating to the subflow, or the subflow was replaced and can be retired.
  • Inactive workspace duplicates add maintenance risk. Workspace 0b00076c holds non-executing copies of NGSIEM Cases, Main - IP Enrichment v2.0, and Main - Domain Enrichment v2.0. If not intentionally kept as staging, they should be archived to prevent confusion during future updates.
  • IOC blocking volume is low relative to alert volume. Only 8 IPs were blocked across 460 triaged alerts (~1.7%). This is plausible if enrichment is doing its job and most alerts are resolved without containment — but it's worth confirming that the block workflows are being surfaced to analysts in the alert output.
  • No case management or ticketing integration visible. The enrichment pipeline sends email but does not appear to create tickets in a SIEM or ITSM platform (e.g., ServiceNow, Jira, Splunk). Adding a bi-directional case sync would close the loop between Blink automation and the broader SOC workflow.

Integration Ecosystem

Integration Purpose Use Case
CrowdStrike Falcon / NGSIEM Webhook event source, alert detail retrieval Alert triage
Palo Alto PAN-OS Firewall address group management, configuration commit IOC blocking
Blink Tables (HTTP) Public IP/domain allowlists, enrichment result cache IP & domain enrichment
Blink Core Python Threat confidence scoring, IP classification, data formatting Both use cases
Blink Email (core.emailV2) Analyst notification with enrichment results Domain enrichment

Taxonomy Classification

Playbook Category Subcategories
NGSIEM Cases SOC Agentic SOC, Case mgmt & SOAR
Main - IP Enrichment v2.0 SOC Alert enrichment / IOC lookup, Agentic SOC
Main - Domain Enrichment v2.0 SOC Alert enrichment / IOC lookup, Agentic SOC
Subflow - IP Enrichment SOC Alert enrichment / IOC lookup
Subflow - Domain Enrichment SOC Alert enrichment / IOC lookup
Subflow - Hash Enrichment SOC Alert enrichment / IOC lookup
Block in Palo Alto Firewall - IP Netmask SOC EDR containment & response
IOC Blocking Request - IPv4 Address SOC EDR containment & response, Alert enrichment / IOC lookup
Unblock in Palo Alto Firewall SOC EDR containment & response
Commit Configurations Palo Alto FW SOC EDR containment & response
On-Demand Commit Configuration SOC EDR containment & response
Update IPv4 Masterlist in Blink Table SOC EDR containment & response
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.