01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Use Case 1 — Multi-Platform IOC Blocking & Remediation |
| 0.0% | 7 7 active |
| Use Case 2 — ServiceNow-Driven IOC Request Fulfillment |
| 0.0% | 3 3 active |
| Use Case 3 — Alert Enrichment & IOC Investigation | 0 executions | 0.0% | 5 3 active |
| Use Case 4 — SIEM Case Ingestion & Triage | 0 executions | 0.0% | 1 0 active |
| Total | 0 executions | 100% | 16 13 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- Multi-platform containment is live and operational. The IOC blocking stack across Palo Alto, Zscaler, and O365 is the most mature and actively used capability, with 27 total blocking/unblocking executions in the last 12 months. The Palo Alto integration is the most exercised (13 block + 4 commit + 2 unblock = 19 actions).
- ServiceNow integration bridges ITSM and enforcement. The SCTASK workflows close the
gap between ticketing and execution — requests submitted in ServiceNow are fulfilled automatically without a human relaying the action to the security tool. This is a high-value automation that removes a class of manual handoffs entirely.
- Broad enforcement coverage. Three distinct enforcement points are automated: network perimeter (Palo Alto NGFW), internet/web proxy (Zscaler ZIA), and cloud/SaaS access (Microsoft O365). This provides defense-in-depth containment from a single orchestration layer.
Gaps & Opportunities
- Alert enrichment workflows have zero executions. The IP, domain, and hash enrichment flows (including both Main v2.0 workflows) show no activity. These are built and ready — the gap is likely in trigger wiring (they appear to be on-demand only, with no event trigger). Connecting them to the NGSIEM Cases ingestion flow or a CrowdStrike alert trigger would unlock automated enrichment on every incoming alert.
- NGSIEM Cases workflow is inactive. The CrowdStrike webhook trigger for SIEM case ingestion has 0 executions. If the CrowdStrike–Blink webhook is not yet configured, that is the single highest-leverage setup action: it would feed all downstream enrichment and potentially the containment flows automatically.
- No automated detection-to-containment pipeline. Today, blocking and enrichment are operated separately and largely on-demand. Connecting NGSIEM Cases → enrichment subflows → conditional block actions would create a closed-loop detection-to-containment pipeline without analyst involvement for high-confidence indicators.
- Unblock flows underutilized relative to block flows. With 13 Palo Alto blocks but only 2 unblocks, there may be accumulation of stale block entries. Automated block expiry or periodic review automation could help prevent over-blocking and reduce false-positive impact.
Integration Ecosystem
| Platform | Usage |
|---|---|
| Palo Alto PAN-OS | Active — block, unblock, commit |
| Zscaler Internet Access (ZIA) | Active — block, unblock, activate |
| Microsoft O365 | Active — IPv4 block/unblock |
| CrowdStrike Falcon | Built, inactive — alert details API + webhook trigger |
| ServiceNow | Active — SCTASK/RITM table reads, ticket updates |
| Email (Blink core) | Built, inactive — enrichment result delivery |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | 12312 | 0 | 0 |
| 2 | NGSIEM Use Cases | 0 | 0 |
| 3 | Dashboard - Containment | 0 | 0 |
| 4 | Test Dashboard - Containment | 0 | 0 |
| 5 | IPV4 IOC Blocking - RITM - PA | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 4 use cases | 0 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| IP addresses blocked in Palo Alto Firewall | 13 | Block in Palo Alto Firewall - IP Netmask |
| Network perimeter IOC blocking requests fulfilled (ServiceNow) | 4 | SCTASK Network Perimeter - IP |
| IPs/domains blocked in Zscaler Internet Access | 4 | Block in Zscaler Internet Access - IPs and Domains |
| Zscaler IOC blocking requests fulfilled (ServiceNow) | 4 | SCTASK - ZIA |
| IPs blocked in Microsoft O365 | 4 | Block in O365 - IPv4 Address |
| O365 IOC blocking requests fulfilled (ServiceNow) | 4 | SCTASK - O365 |
| IP addresses unblocked in Palo Alto Firewall | 2 | Unblock in Palo Alto Firewall |
| IPs/domains unblocked in Zscaler Internet Access | 2 | Unblock in Zscaler Internet Access (ZIA) - IPs and Domains/URL |
| IPs unblocked in Microsoft O365 | 2 | Unblock in O365 - IPv4 Address |
Use Case Summary
| Use Case | Category | Playbook Count | Active Playbooks |
|---|---|---|---|
| Multi-Platform IOC Blocking & Remediation | SOC | 7 | 6 |
| ServiceNow-Driven IOC Request Fulfillment | SOC | 3 | 3 |
| Alert Enrichment & IOC Investigation | SOC | 5 | 0 |
| SIEM Case Ingestion & Triage | SOC | 1 | 0 |
| Total | 16 | 9 |
Use Cases
Use Case 1 — Multi-Platform IOC Blocking & Remediation
Description: Automated enforcement of IP, domain, and URL block/unblock actions across Palo Alto Firewall, Zscaler Internet Access (ZIA), and Microsoft O365 Conditional Access. When a threat indicator needs to be contained or an earlier block needs reversal, Blink executes the full action — including configuration commits — without requiring a network engineer to log into each platform.
Business problem solved: Network perimeter containment is a time-sensitive operation. Manual blocking across three separate platforms (NGFW, internet proxy, cloud access) requires multiple logins, command expertise, and coordination. This use case reduces mean time to contain (MTTC) for IP/domain-based threats from hours to seconds.
Category: SOC
Subcategories: EDR containment & response, Threat intel ingest & curation
Integrations: Palo Alto PAN-OS, Zscaler Internet Access (ZIA), Microsoft O365
| Playbook | Executions (12mo) | Role |
|---|---|---|
| Block in Palo Alto Firewall - IP Netmask | 13 | Adds IP/netmask to Palo Alto block list |
| Unblock in Palo Alto Firewall | 2 | Removes IP from Palo Alto block list and commits |
| Commit Configurations Palo Alto FW | 4 | Commits pending Palo Alto configuration changes |
| Block in Zscaler Internet Access - IPs and Domains | 4 | Blocks IPs and domains in ZIA with activation |
| Unblock in Zscaler Internet Access (ZIA) - IPs and Domains/URL | 2 | Removes IPs/domains/URLs from ZIA block list |
| Block in O365 - IPv4 Address | 4 | Adds IPv4 addresses to O365 block policy |
| Unblock in O365 - IPv4 Address | 2 | Removes IPv4 addresses from O365 block policy |
Use Case 2 — ServiceNow-Driven IOC Request Fulfillment
Description: End-to-end automation of ServiceNow Service Catalog Task (SCTASK) IOC blocking requests. When a security team member or approver submits a blocking request through ServiceNow, Blink handles the full workflow: parsing the RITM/SCTASK data, routing to the appropriate enforcement platform, executing the block action, and updating the ticket with status and approver notifications via email.
Business problem solved: Blocking requests that travel through ITSM workflows traditionally stall on manual handoffs between the ticketing system and the enforcement tool. This use case eliminates that gap — the SCTASK triggers Blink, which fulfills the request and closes the loop back in ServiceNow automatically, reducing fulfillment time and audit trail gaps.
Category: SOC
Subcategories: Case mgmt & SOAR, Threat intel ingest & curation
Integrations: ServiceNow (HTTP/Tables API), Palo Alto PAN-OS, Zscaler Internet Access, Microsoft O365
| Playbook | Executions (12mo) | Role |
|---|---|---|
| SCTASK Network Perimeter - IP | 4 | Handles ServiceNow SCTASK for Palo Alto IP blocking |
| SCTASK - ZIA | 4 | Handles ServiceNow SCTASK for Zscaler IOC blocking |
| SCTASK - O365 | 4 | Handles ServiceNow SCTASK for O365 IOC blocking |
Use Case 3 — Alert Enrichment & IOC Investigation
Description: On-demand enrichment of threat indicators (IPs, domains, file hashes) surfaced from CrowdStrike alerts. Each enrichment workflow retrieves alert context from CrowdStrike Falcon, queries threat intelligence sources, classifies the indicator (private/organizational/external), evaluates threat confidence, and returns a structured enrichment output. Domain and IP workflows also check against internal allowlists to reduce false positives.
Business problem solved: SOC analysts spend significant time pivoting between alert tools and threat intelligence platforms to understand whether an indicator is genuinely malicious. These workflows automate that investigation loop, delivering enriched context alongside the alert so analysts can make faster, better-informed decisions.
Category: SOC
Subcategories: Alert enrichment / IOC lookup, Agentic SOC
Integrations: CrowdStrike Falcon, ServiceNow (HTTP/Tables API for IP cache), Email (Blink core)
| Playbook | Executions (12mo) | Role |
|---|---|---|
| Main - IP Enrichment v2.0 | 0 | Top-level IP enrichment: classifies IPs, runs enrichment subflow, emails results |
| Main - Domain Enrichment v2.0 | 0 | Top-level domain enrichment: checks org allowlist, runs enrichment, emails results |
| Subflow - IP Enrichment | 0 | Enriches a single IP; evaluates threat confidence; called by Main |
| Subflow - Domain Enrichment | 0 | Enriches a single domain; called by Main |
| Subflow - Hash Enrichment | 0 | Enriches a SHA-256 file hash; called by Main |
Use Case 4 — SIEM Case Ingestion & Triage
Description: Event-driven ingestion of CrowdStrike NGSIEM detection cases via webhook. When CrowdStrike fires a case event, the workflow extracts the alert ID, retrieves full alert details from the Falcon API, and applies conditional logic to triage and route the case.
Business problem solved: SIEM-generated cases require immediate intake and qualification before they can be acted on. This webhook-driven flow eliminates manual alert pickup from the SIEM console, ensuring every case enters the response pipeline automatically.
Category: SOC
Subcategories: SIEM & log pipeline monitoring, Case mgmt & SOAR
Integrations: CrowdStrike Falcon (webhook + API)
| Playbook | Executions (12mo) | Role |
|---|---|---|
| NGSIEM Cases | 0 | Ingests CrowdStrike NGSIEM case events and triages |
Key Observations
Strengths
- Multi-platform containment is live and operational. The IOC blocking stack across Palo Alto, Zscaler, and O365 is the most mature and actively used capability, with 27 total blocking/unblocking executions in the last 12 months. The Palo Alto integration is the most exercised (13 block + 4 commit + 2 unblock = 19 actions).
- ServiceNow integration bridges ITSM and enforcement. The SCTASK workflows close the gap between ticketing and execution — requests submitted in ServiceNow are fulfilled automatically without a human relaying the action to the security tool. This is a high-value automation that removes a class of manual handoffs entirely.
- Broad enforcement coverage. Three distinct enforcement points are automated: network perimeter (Palo Alto NGFW), internet/web proxy (Zscaler ZIA), and cloud/SaaS access (Microsoft O365). This provides defense-in-depth containment from a single orchestration layer.
Gaps & Opportunities
- Alert enrichment workflows have zero executions. The IP, domain, and hash enrichment flows (including both Main v2.0 workflows) show no activity. These are built and ready — the gap is likely in trigger wiring (they appear to be on-demand only, with no event trigger). Connecting them to the NGSIEM Cases ingestion flow or a CrowdStrike alert trigger would unlock automated enrichment on every incoming alert.
- NGSIEM Cases workflow is inactive. The CrowdStrike webhook trigger for SIEM case ingestion has 0 executions. If the CrowdStrike–Blink webhook is not yet configured, that is the single highest-leverage setup action: it would feed all downstream enrichment and potentially the containment flows automatically.
- No automated detection-to-containment pipeline. Today, blocking and enrichment are operated separately and largely on-demand. Connecting NGSIEM Cases → enrichment subflows → conditional block actions would create a closed-loop detection-to-containment pipeline without analyst involvement for high-confidence indicators.
- Unblock flows underutilized relative to block flows. With 13 Palo Alto blocks but only 2 unblocks, there may be accumulation of stale block entries. Automated block expiry or periodic review automation could help prevent over-blocking and reduce false-positive impact.
Integration Ecosystem
| Platform | Usage |
|---|---|
| Palo Alto PAN-OS | Active — block, unblock, commit |
| Zscaler Internet Access (ZIA) | Active — block, unblock, activate |
| Microsoft O365 | Active — IPv4 block/unblock |
| CrowdStrike Falcon | Built, inactive — alert details API + webhook trigger |
| ServiceNow | Active — SCTASK/RITM table reads, ticket updates |
| Email (Blink core) | Built, inactive — enrichment result delivery |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Project-red-phoenix-prod | zscaler-oneapi | prd_zscaler_oneapi_connection | 2026-08-17 |