Blink Security Automation — Confidential

Project-red-phoenix-prod — Customer Success Report

Generated 2026-08-30 | project-red-phoenix-prod-value-report.md
2026-08-30Report Date
83Total Playbooks
24Unique Workflows (12m)
95,689Actions Automated (12m)
$24,611Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

83
Total playbooks built
all non-deleted workflows
19
Active playbooks
currently enabled
24
Unique workflows executed (12m)
distinct workflows that ran
95,689
Actions automated (12m)
completed action steps
531.6h
Hours saved (12m)
@ 20s per action
$24,611
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 13 IP addresses blocked in Palo Alto Firewall without manual CLI intervention - 12 ServiceNow SCTASK IOC blocking requests fulfilled automatically across Palo Alto, Zscaler, and O365 - 10 IPs and domains blocked across Zscaler Internet Access and Microsoft O365 - 6 IOC unblock actions executed across all three enforcement platforms

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1 — Multi-Platform IOC Blocking & Remediation
  • 13IP addresses blocked in Palo Alto Firewall
  • 4IPs/domains blocked in Zscaler Internet Access
  • 4IPs blocked in Microsoft O365
0.0%
7
7 active
Use Case 2 — ServiceNow-Driven IOC Request Fulfillment
  • 4Network perimeter IOC blocking requests fulfilled (ServiceNow)
  • 4Zscaler IOC blocking requests fulfilled (ServiceNow)
  • 4O365 IOC blocking requests fulfilled (ServiceNow)
0.0%
3
3 active
Use Case 3 — Alert Enrichment & IOC Investigation0 executions
0.0%
5
3 active
Use Case 4 — SIEM Case Ingestion & Triage0 executions
0.0%
1
0 active
Total0 executions100%
16
13 active

Use Case Growth Over Time

46 unique playbooks  |  4 operational use cases  |  0 total executions (12m)  |  2025-05 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Use Case 3 — Alert Enrichment & IOC Investigation
CrowdStrike VirusTotal Email Hybrid Analysis AbuseIPDB
Use Case 1 — Multi-Platform IOC Blocking & Remediation
Palo Alto Firewall Zscaler Internet Access Exchange Online
Use Case 2 — ServiceNow-Driven IOC Request Fulfillment
ServiceNow Email Web Form
Use Case 4 — SIEM Case Ingestion & Triage
CrowdStrike Email

04Key Observations

✓  Strengths

Strengths

  • Multi-platform containment is live and operational. The IOC blocking stack across Palo Alto, Zscaler, and O365 is the most mature and actively used capability, with 27 total blocking/unblocking executions in the last 12 months. The Palo Alto integration is the most exercised (13 block + 4 commit + 2 unblock = 19 actions).
  • ServiceNow integration bridges ITSM and enforcement. The SCTASK workflows close the
△  Gaps & Growth Opportunities

gap between ticketing and execution — requests submitted in ServiceNow are fulfilled automatically without a human relaying the action to the security tool. This is a high-value automation that removes a class of manual handoffs entirely.

  • Broad enforcement coverage. Three distinct enforcement points are automated: network perimeter (Palo Alto NGFW), internet/web proxy (Zscaler ZIA), and cloud/SaaS access (Microsoft O365). This provides defense-in-depth containment from a single orchestration layer.

Gaps & Opportunities

  • Alert enrichment workflows have zero executions. The IP, domain, and hash enrichment flows (including both Main v2.0 workflows) show no activity. These are built and ready — the gap is likely in trigger wiring (they appear to be on-demand only, with no event trigger). Connecting them to the NGSIEM Cases ingestion flow or a CrowdStrike alert trigger would unlock automated enrichment on every incoming alert.
  • NGSIEM Cases workflow is inactive. The CrowdStrike webhook trigger for SIEM case ingestion has 0 executions. If the CrowdStrike–Blink webhook is not yet configured, that is the single highest-leverage setup action: it would feed all downstream enrichment and potentially the containment flows automatically.
  • No automated detection-to-containment pipeline. Today, blocking and enrichment are operated separately and largely on-demand. Connecting NGSIEM Cases → enrichment subflows → conditional block actions would create a closed-loop detection-to-containment pipeline without analyst involvement for high-confidence indicators.
  • Unblock flows underutilized relative to block flows. With 13 Palo Alto blocks but only 2 unblocks, there may be accumulation of stale block entries. Automated block expiry or periodic review automation could help prevent over-blocking and reduce false-positive impact.

Integration Ecosystem

Platform Usage
Palo Alto PAN-OS Active — block, unblock, commit
Zscaler Internet Access (ZIA) Active — block, unblock, activate
Microsoft O365 Active — IPv4 block/unblock
CrowdStrike Falcon Built, inactive — alert details API + webhook trigger
ServiceNow Active — SCTASK/RITM table reads, ticket updates
Email (Blink core) Built, inactive — enrichment result delivery
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
8
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 12312 00
2 NGSIEM Use Cases 00
3 Dashboard - Containment 00
4 Test Dashboard - Containment 00
5 IPV4 IOC Blocking - RITM - PA 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 4 use cases | 0 executions (12m)

Business KPIs

Metric Count Playbook
IP addresses blocked in Palo Alto Firewall 13 Block in Palo Alto Firewall - IP Netmask
Network perimeter IOC blocking requests fulfilled (ServiceNow) 4 SCTASK Network Perimeter - IP
IPs/domains blocked in Zscaler Internet Access 4 Block in Zscaler Internet Access - IPs and Domains
Zscaler IOC blocking requests fulfilled (ServiceNow) 4 SCTASK - ZIA
IPs blocked in Microsoft O365 4 Block in O365 - IPv4 Address
O365 IOC blocking requests fulfilled (ServiceNow) 4 SCTASK - O365
IP addresses unblocked in Palo Alto Firewall 2 Unblock in Palo Alto Firewall
IPs/domains unblocked in Zscaler Internet Access 2 Unblock in Zscaler Internet Access (ZIA) - IPs and Domains/URL
IPs unblocked in Microsoft O365 2 Unblock in O365 - IPv4 Address
In the last 12 months, Blink automated: - 13 IP addresses blocked in Palo Alto Firewall without manual CLI intervention - 12 ServiceNow SCTASK IOC blocking requests fulfilled automatically across Palo Alto, Zscaler, and O365 - 10 IPs and domains blocked across Zscaler Internet Access and Microsoft O365 - 6 IOC unblock actions executed across all three enforcement platforms

Use Case Summary

Use Case Category Playbook Count Active Playbooks
Multi-Platform IOC Blocking & Remediation SOC 7 6
ServiceNow-Driven IOC Request Fulfillment SOC 3 3
Alert Enrichment & IOC Investigation SOC 5 0
SIEM Case Ingestion & Triage SOC 1 0
Total 16 9
Note: 3 additional subflow/utility playbooks (Subflow Update - Block in Palo Alto FW, Subflow Update - Block in ZIA, Subflow Update - Block in O365) support the above use cases and are excluded from the use case counts.

Use Cases

Use Case 1 — Multi-Platform IOC Blocking & Remediation

Description: Automated enforcement of IP, domain, and URL block/unblock actions across Palo Alto Firewall, Zscaler Internet Access (ZIA), and Microsoft O365 Conditional Access. When a threat indicator needs to be contained or an earlier block needs reversal, Blink executes the full action — including configuration commits — without requiring a network engineer to log into each platform.

Business problem solved: Network perimeter containment is a time-sensitive operation. Manual blocking across three separate platforms (NGFW, internet proxy, cloud access) requires multiple logins, command expertise, and coordination. This use case reduces mean time to contain (MTTC) for IP/domain-based threats from hours to seconds.

Category: SOC

Subcategories: EDR containment & response, Threat intel ingest & curation

Integrations: Palo Alto PAN-OS, Zscaler Internet Access (ZIA), Microsoft O365

Playbook Executions (12mo) Role
Block in Palo Alto Firewall - IP Netmask 13 Adds IP/netmask to Palo Alto block list
Unblock in Palo Alto Firewall 2 Removes IP from Palo Alto block list and commits
Commit Configurations Palo Alto FW 4 Commits pending Palo Alto configuration changes
Block in Zscaler Internet Access - IPs and Domains 4 Blocks IPs and domains in ZIA with activation
Unblock in Zscaler Internet Access (ZIA) - IPs and Domains/URL 2 Removes IPs/domains/URLs from ZIA block list
Block in O365 - IPv4 Address 4 Adds IPv4 addresses to O365 block policy
Unblock in O365 - IPv4 Address 2 Removes IPv4 addresses from O365 block policy

Use Case 2 — ServiceNow-Driven IOC Request Fulfillment

Description: End-to-end automation of ServiceNow Service Catalog Task (SCTASK) IOC blocking requests. When a security team member or approver submits a blocking request through ServiceNow, Blink handles the full workflow: parsing the RITM/SCTASK data, routing to the appropriate enforcement platform, executing the block action, and updating the ticket with status and approver notifications via email.

Business problem solved: Blocking requests that travel through ITSM workflows traditionally stall on manual handoffs between the ticketing system and the enforcement tool. This use case eliminates that gap — the SCTASK triggers Blink, which fulfills the request and closes the loop back in ServiceNow automatically, reducing fulfillment time and audit trail gaps.

Category: SOC

Subcategories: Case mgmt & SOAR, Threat intel ingest & curation

Integrations: ServiceNow (HTTP/Tables API), Palo Alto PAN-OS, Zscaler Internet Access, Microsoft O365

Playbook Executions (12mo) Role
SCTASK Network Perimeter - IP 4 Handles ServiceNow SCTASK for Palo Alto IP blocking
SCTASK - ZIA 4 Handles ServiceNow SCTASK for Zscaler IOC blocking
SCTASK - O365 4 Handles ServiceNow SCTASK for O365 IOC blocking

Use Case 3 — Alert Enrichment & IOC Investigation

Description: On-demand enrichment of threat indicators (IPs, domains, file hashes) surfaced from CrowdStrike alerts. Each enrichment workflow retrieves alert context from CrowdStrike Falcon, queries threat intelligence sources, classifies the indicator (private/organizational/external), evaluates threat confidence, and returns a structured enrichment output. Domain and IP workflows also check against internal allowlists to reduce false positives.

Business problem solved: SOC analysts spend significant time pivoting between alert tools and threat intelligence platforms to understand whether an indicator is genuinely malicious. These workflows automate that investigation loop, delivering enriched context alongside the alert so analysts can make faster, better-informed decisions.

Category: SOC

Subcategories: Alert enrichment / IOC lookup, Agentic SOC

Integrations: CrowdStrike Falcon, ServiceNow (HTTP/Tables API for IP cache), Email (Blink core)

Playbook Executions (12mo) Role
Main - IP Enrichment v2.0 0 Top-level IP enrichment: classifies IPs, runs enrichment subflow, emails results
Main - Domain Enrichment v2.0 0 Top-level domain enrichment: checks org allowlist, runs enrichment, emails results
Subflow - IP Enrichment 0 Enriches a single IP; evaluates threat confidence; called by Main
Subflow - Domain Enrichment 0 Enriches a single domain; called by Main
Subflow - Hash Enrichment 0 Enriches a SHA-256 file hash; called by Main

Use Case 4 — SIEM Case Ingestion & Triage

Description: Event-driven ingestion of CrowdStrike NGSIEM detection cases via webhook. When CrowdStrike fires a case event, the workflow extracts the alert ID, retrieves full alert details from the Falcon API, and applies conditional logic to triage and route the case.

Business problem solved: SIEM-generated cases require immediate intake and qualification before they can be acted on. This webhook-driven flow eliminates manual alert pickup from the SIEM console, ensuring every case enters the response pipeline automatically.

Category: SOC

Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR

Integrations: CrowdStrike Falcon (webhook + API)

Playbook Executions (12mo) Role
NGSIEM Cases 0 Ingests CrowdStrike NGSIEM case events and triages

Key Observations

Strengths

  • Multi-platform containment is live and operational. The IOC blocking stack across Palo Alto, Zscaler, and O365 is the most mature and actively used capability, with 27 total blocking/unblocking executions in the last 12 months. The Palo Alto integration is the most exercised (13 block + 4 commit + 2 unblock = 19 actions).
  • ServiceNow integration bridges ITSM and enforcement. The SCTASK workflows close the gap between ticketing and execution — requests submitted in ServiceNow are fulfilled automatically without a human relaying the action to the security tool. This is a high-value automation that removes a class of manual handoffs entirely.
  • Broad enforcement coverage. Three distinct enforcement points are automated: network perimeter (Palo Alto NGFW), internet/web proxy (Zscaler ZIA), and cloud/SaaS access (Microsoft O365). This provides defense-in-depth containment from a single orchestration layer.

Gaps & Opportunities

  • Alert enrichment workflows have zero executions. The IP, domain, and hash enrichment flows (including both Main v2.0 workflows) show no activity. These are built and ready — the gap is likely in trigger wiring (they appear to be on-demand only, with no event trigger). Connecting them to the NGSIEM Cases ingestion flow or a CrowdStrike alert trigger would unlock automated enrichment on every incoming alert.
  • NGSIEM Cases workflow is inactive. The CrowdStrike webhook trigger for SIEM case ingestion has 0 executions. If the CrowdStrike–Blink webhook is not yet configured, that is the single highest-leverage setup action: it would feed all downstream enrichment and potentially the containment flows automatically.
  • No automated detection-to-containment pipeline. Today, blocking and enrichment are operated separately and largely on-demand. Connecting NGSIEM Cases → enrichment subflows → conditional block actions would create a closed-loop detection-to-containment pipeline without analyst involvement for high-confidence indicators.
  • Unblock flows underutilized relative to block flows. With 13 Palo Alto blocks but only 2 unblocks, there may be accumulation of stale block entries. Automated block expiry or periodic review automation could help prevent over-blocking and reduce false-positive impact.

Integration Ecosystem

Platform Usage
Palo Alto PAN-OS Active — block, unblock, commit
Zscaler Internet Access (ZIA) Active — block, unblock, activate
Microsoft O365 Active — IPv4 block/unblock
CrowdStrike Falcon Built, inactive — alert details API + webhook trigger
ServiceNow Active — SCTASK/RITM table reads, ticket updates
Email (Blink core) Built, inactive — enrichment result delivery
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Project-red-phoenix-prod zscaler-oneapi prd_zscaler_oneapi_connection 2026-08-17