01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Alert Ingestion & Source Integration |
| 9.1% | 6 6 active |
| Alert Processing & Case Deduplication |
| 12.1% | 6 6 active |
| Observable Enrichment | 0 executions | 0.0% | 30 30 active |
| Case Management & SOAR |
| 55.6% | 13 13 active |
| Incident Response Playbooks |
| 10.5% | 4 4 active |
| EDR Containment & Response | 0 executions | 0.0% | 3 3 active |
| Identity Threat Response | 110 executions | 0.3% | 1 1 active |
| Threat Intelligence Curation |
| 0.1% | 1 1 active |
| Deception Technology |
| 1.5% | 1 1 active |
| Total | 28,360 executions | 100% | 65 65 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
The agentic SOC pipeline is fully operational at production scale. Process Alert — the core orchestration engine — has processed 883 alerts end-to-end, handling observable extraction, case deduplication, enrichment routing, and downstream response actions without analyst intervention. This positions the automation program well beyond basic alert forwarding: it is executing structured, multi-step SOC workflows autonomously. Complementing this, the Thinkst Canary integration has delivered 193 total executions (180 ingestions, 13 closed-loop acknowledgements), representing one of the highest-confidence detection pipelines in the stack — every Canary alert is both actioned in case management and reconciled back to the source platform automatically.
The enrichment library is enterprise-grade in breadth. Forty-six enrichment subflows span IP reputation (VirusTotal, AbuseIPDB), domain and URL analysis (URLScan, Whois), file hash lookup (VirusTotal, CrowdStrike), and identity resolution across Microsoft Entra ID, Okta, Google Workspace, GitHub, and Slack. When Process Alert extracts an observable, the platform can query 10 distinct security data sources automatically. The H-ISAC BlueIntel integration (46 bulletins processed) adds sector-specific threat intelligence context to the operational picture, closing the loop between external threat feeds and the internal SOC workflow.
The case management layer is actively absorbing automation volume. Across the five active case management playbooks, 186 case lifecycle actions were executed — 62 analyst assignments, 41 status updates, 37 new case notifications, 25 automated closures, and 21 automated timeline comments. This represents meaningful SOC administrative overhead that has been eliminated from analyst workflows. The Generic IRP has also executed 54 times, confirming that structured incident response procedures are running against triaged cases.
Gaps and Opportunities
Three high-value response capability areas are deployed but show zero production executions: EDR containment (CrowdStrike host quarantine and RTR), identity threat response (Entra ID risky user disposition), and the phishing and malware response subflows. These represent the most operationally impactful automation available — endpoint quarantine and identity remediation are precisely the actions where automation reduces attacker dwell time most materially. Validating that the Generic IRP correctly routes to phishing and malware subflows via the Response Main Router should be a near-term priority; if the router is not selecting the correct subflow path, 54 IRP executions may be terminating at case documentation rather than executing remediation steps.
The enrichment subflows reporting zero direct executions is expected given their subflow architecture, but this creates a visibility gap: there is no straightforward way to confirm enrichment is firing correctly across the full observable type matrix (IP, URL, hash, username, domain) without instrumenting the Process Alert workflow directly. Adding lightweight execution logging or a metrics table update within the enrichment router would provide confirmation that the 46-subflow library is active against production alert volume.
Workspace B contains a near-complete mirror of the Workspace A enrichment and response subflow library — 16 enrichment playbooks plus response, error handling, and ingestion subflows — with zero executions across every playbook. If Workspace B is a staging or test environment, it should be explicitly documented as such. If it is intended as a production workspace for a distinct alert source or organizational unit, the ingestion playbooks that should be feeding it have not yet been connected. Resolving this ambiguity and either activating Workspace B's pipeline or consolidating it into Workspace A would simplify governance and eliminate the maintenance burden of keeping two parallel playbook libraries in sync.
Integration Ecosystem
The active integration footprint spans 12 or more platforms: CrowdStrike Falcon (EDR, hash enrichment, RTR), Rapid7 InsightIDR (SIEM), VirusTotal, AbuseIPDB, URLScan, Microsoft Entra ID (identity enrichment and risky user response), Microsoft Outlook (threat intel ingestion), Okta (identity enrichment), Google Workspace, GitHub, Slack, and Thinkst Canary. Four additional EXAMPLE ingest connectors — Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, and Wiz — have completed initial testing (8 combined executions) and are structurally ready to be promoted to production triggers. Activating these connectors would materially expand the alert surface covered by the automated pipeline without requiring new enrichment or response playbook development.
A Case Management 3,378 cases (12m) | MTTR 7h 56m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management | 3,378 | 3,378 | 3,244 | 7h 56m |
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Blink | DEMO: ENGINEERING | 0 | 0 | 0 |
| 2 | Agent Blink | Case Management | 0 | 0 | 0 |
| 3 | New Agent | Case Management | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| DEMO: ENGINEERING | 0 |
| Case Management | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Test-Suryakant | 0 | 0 |
| 2 | SOC HO Dashboard | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 9 use cases | 31,776 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts processed end-to-end | 883 | Process Alert |
| Deception alerts detected and ingested | 180 | Thinkst Canary Alert Ingestion |
| Rapid7 investigations ingested into case management | 139 | Rapid7 - Investigation Ingestion |
| Cases automatically assigned to analysts | 62 | Assign User to Incident UI |
| Incidents launched with structured IRP playbook | 54 | Incident Playbook - Generic IRP |
| H-ISAC threat intelligence bulletins processed | 46 | H-ISAC BlueIntel Notifications |
| Case status transitions automated | 41 | Set Status in UI |
| New case notifications dispatched | 37 | New Case Notification |
| Cases automatically closed | 25 | Set to Close in UI |
| Case timeline updates automated | 21 | Post Comment to UI |
| Deception alert response cycles closed | 13 | Canary Close/Acknowledgement |
| Cloud/SaaS alerts ingested via example connectors | 8 | Microsoft Defender For Cloud Apps, Azure, Wiz |
Use Case Summary
| Use Case | Category | Subcategory | Total Playbooks | Active Playbooks | Total Executions |
|---|---|---|---|---|---|
| Alert Ingestion & Source Integration | SOC | SIEM & log pipeline monitoring | 9 | 3 | 147 |
| Alert Processing & Case Deduplication | SOC | Agentic SOC, Case mgmt & SOAR | 7 | 3 | 1,299 |
| Observable Enrichment | SOC | Alert enrichment / IOC lookup | 46 | 0 | 0\* |
| Case Management & SOAR | SOC | Case mgmt & SOAR | 14 | 5 | 186 |
| Incident Response Playbooks | SOC | Phishing detection & response, Case mgmt & SOAR | 7 | 1 | 54 |
| EDR Containment & Response | SOC | EDR containment & response | 3 | 0 | 0 |
| Identity Threat Response | SOC | Identity threat response | 2 | 0 | 0 |
| Threat Intelligence Curation | SOC | Threat intel ingest & curation | 1 | 1 | 46 |
| Deception Technology | SOC | Agentic SOC, Case mgmt & SOAR | 2 | 2 | 193 |
\* Enrichment playbooks run as subflows invoked by Process Alert; individual execution counts are not tracked at the subflow level.
Use Cases
Alert Ingestion & Source Integration
This use case covers the intake layer of the agentic SOC pipeline, ingesting alerts and investigation events from multiple security platforms into the Blink case management environment.
Business problem solved: Security teams operating across multiple detection platforms are forced to context-switch between consoles. These playbooks normalize and centralize alert ingestion so every signal enters a single structured pipeline regardless of source.
Integrations: Rapid7 InsightIDR, Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, Wiz, CrowdStrike Falcon, custom webhook
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Rapid7 - Investigation Ingestion | Workspace A | 139 | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - Microsoft Defender For Cloud Apps | Workspace A | 3 | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - Azure | Workspace A | 3 | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - Wiz | Workspace A | 2 | SOC | SIEM & log pipeline monitoring |
| Rapid7 - Investigation Ingestion | Workspace B | 0 | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - CrowdStrike Falcon LogScale | Workspace A | 0 | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - CrowdStrike | Workspace A | 0 | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - AWS CloudTrail | Workspace A | 0 | SOC | SIEM & log pipeline monitoring |
| New Workflow (CrowdStrike + CreateAlertV4) | Workspace B | 0 | SOC | SIEM & log pipeline monitoring |
Alert Processing & Case Deduplication
The core orchestration layer of the agentic SOC pipeline — Process Alert receives normalized alerts, extracts observables, deduplicates against existing cases, and routes to enrichment and response.
Business problem solved: Without automated deduplication and orchestration, analysts manually review duplicate alerts and repeat enrichment steps for the same indicators. This pipeline eliminates redundant work by linking related alerts to existing cases and triggering enrichment only on net-new observables.
Integrations: Blink Case Management (native), CrowdStrike Falcon
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Process Alert | Workspace A | 883 | SOC | Agentic SOC, Case mgmt & SOAR |
| Subflow - Missing Alert Template Notification | Workspace A | 411 | SOC | Agentic SOC, Case mgmt & SOAR |
| Subflow - Missing Alert Template Notification | Workspace B | 5 | SOC | Agentic SOC, Case mgmt & SOAR |
| Recovery - Handle Unprocessed Alerts | Workspace A | 0 | SOC | Agentic SOC, Case mgmt & SOAR |
| Table Action - Validate Observables Extraction Template | Workspace A | 0 | SOC | Agentic SOC, Case mgmt & SOAR |
| Simulate Multiple Alerts from Different Sources | Workspace A | 0 | SOC | Agentic SOC, Case mgmt & SOAR |
| Simulate Crowdstrike Alert | Workspace A | 0 | SOC | Agentic SOC, Case mgmt & SOAR |
Observable Enrichment
This use case encompasses the full library of enrichment subflows that look up IP addresses, domains, URLs, file hashes, usernames, and email addresses across the integrated threat intelligence and identity platforms.
Business problem solved: Manual enrichment of security observables is the most time-intensive step in alert triage. These subflows eliminate analyst lookup time by automatically querying every relevant platform the moment an observable is extracted from an incoming alert.
Integrations: CrowdStrike Falcon, VirusTotal, AbuseIPDB, URLScan, Microsoft Entra ID, Okta, Google Workspace, GitHub, Slack, Bash (whois/dig)
Workspace A
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Subflow - Enrich Observables - Main Router | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Utility - Update Enrichment | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Recovery - Enrich Non-Enriched Observables | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username - Github | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Github | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Okta | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Okta Search for User Activity | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | Workspace A | 0 | SOC | Alert enrichment / IOC lookup |
Workspace B
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Subflow - Enrich Observables - Main Router | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | Workspace B | 0 | SOC | Alert enrichment / IOC lookup |
Case Management & SOAR
These playbooks manage the lifecycle of security cases — from initial notification through analyst assignment, status tracking, and automated closure — within the Blink native case management environment.
Business problem solved: Manual case lifecycle management creates delays between detection and analyst action and leaves audit trails incomplete. These playbooks ensure every case is acknowledged, assigned, and tracked to resolution without requiring analysts to perform repetitive administrative updates.
Integrations: Blink Case Management (native)
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Assign User to Incident UI | Workspace A | 62 | SOC | Case mgmt & SOAR |
| Set Status in UI | Workspace A | 41 | SOC | Case mgmt & SOAR |
| New Case Notification | Workspace A | 37 | SOC | Case mgmt & SOAR |
| Set to Close in UI | Workspace A | 25 | SOC | Case mgmt & SOAR |
| Post Comment to UI | Workspace A | 21 | SOC | Case mgmt & SOAR |
| Utility - Close Stale Cases | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Utility - Find Similar Cases Based on Observables | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Utility - Set Or Update Observable Relation | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Utility - List Observable Alert Relations | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Utility - List Alert Observable Relations | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Utility - Delete Observable Relation | Workspace A | 0 | SOC | Case mgmt & SOAR |
| USE WITH CARE - Reset Case Management Environment | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Error Handling - Send Error Notification Email | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Error Handling - Send Error Notification Email | Workspace B | 0 | SOC | Case mgmt & SOAR |
Incident Response Playbooks
Structured incident response playbooks that execute predefined remediation steps against triaged cases, with modular subflows for specific threat categories including phishing and malware.
Business problem solved: Without automated response playbooks, analyst response quality is inconsistent and dependent on individual experience. These playbooks enforce a repeatable, auditable response process for each incident category, reducing mean time to respond and ensuring no remediation steps are skipped.
Integrations: Microsoft Outlook (KnowBe4 phishing simulation check), Microsoft Entra ID, Blink Case Management
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Incident Playbook - Generic IRP | Workspace A | 54 | SOC | Case mgmt & SOAR |
| Subflow - Response - Main Router | Workspace A | 0 | SOC | Case mgmt & SOAR |
| Response Subflow - Phishing | Workspace A | 0 | SOC | Phishing detection & response |
| Response Subflow - Malware | Workspace A | 0 | SOC | EDR containment & response |
| Subflow - Response - Main Router | Workspace B | 0 | SOC | Case mgmt & SOAR |
| Response Subflow - Phishing | Workspace B | 0 | SOC | Phishing detection & response |
| Response Subflow - Malware | Workspace B | 0 | SOC | EDR containment & response |
EDR Containment & Response
CrowdStrike Falcon-based endpoint containment playbooks that allow analysts to quarantine hosts and execute real-time response commands against individual endpoints or batches of hosts.
Business problem solved: Endpoint containment during an active incident requires immediate, repeatable action with a full audit trail. These playbooks let analysts trigger quarantine and remote response actions directly from the case management interface without switching to the CrowdStrike console.
Integrations: CrowdStrike Falcon RTR
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | Workspace A | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | Workspace A | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | Workspace A | 0 | SOC | EDR containment & response |
Identity Threat Response
Playbooks that manage the lifecycle of risky user events surfaced by Microsoft Entra ID, enabling analysts to dismiss false positives or confirm a user as safe directly through the automation layer.
Business problem solved: Identity risk events in Entra ID require prompt analyst disposition to prevent alert fatigue and ensure genuine threats are escalated. These playbooks allow case-linked disposition of risky user signals without requiring direct Entra ID console access.
Integrations: Microsoft Entra ID (risky user APIs)
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Dismiss Risky User-Case | Workspace A | 0 | SOC | Identity threat response |
| Confirm User Safe-Case | Workspace A | 0 | SOC | Identity threat response |
Threat Intelligence Curation
Automated ingestion of H-ISAC BlueIntel threat intelligence bulletins, enabling the security team to receive and act on sector-specific threat intelligence without manual monitoring of external feeds.
Business problem solved: Threat intelligence feeds deliver high-value context that often goes unread due to volume and the absence of workflow integration. This playbook ensures every H-ISAC bulletin is ingested, logged, and surfaced to the appropriate team automatically.
Integrations: Microsoft Outlook (email polling)
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| H-ISAC BlueIntel Notifications | Workspace A | 46 | SOC | Threat intel ingest & curation |
Deception Technology
End-to-end automation for Thinkst Canary deception alerts — from initial webhook ingestion through case creation to closed-loop analyst acknowledgement written back to the Canary platform.
Business problem solved: Canary alerts are high-confidence indicators of adversarial activity, but without automation they require manual triaging and acknowledgement steps that delay response. This use case ensures every Canary alert is immediately logged as a case and that analyst disposition is reflected back in the Canary console automatically.
Integrations: Thinkst Canary
| Playbook | Workspace | Executions | Category | Subcategory |
|---|---|---|---|---|
| Thinkst Canary Alert Ingestion | Workspace A | 180 | SOC | Agentic SOC, Case mgmt & SOAR |
| Canary Close/Acknowledgement | Workspace A | 13 | SOC | Case mgmt & SOAR |
Key Observations
Strengths
The agentic SOC pipeline is fully operational at production scale. Process Alert — the core orchestration engine — has processed 883 alerts end-to-end, handling observable extraction, case deduplication, enrichment routing, and downstream response actions without analyst intervention. This positions the automation program well beyond basic alert forwarding: it is executing structured, multi-step SOC workflows autonomously. Complementing this, the Thinkst Canary integration has delivered 193 total executions (180 ingestions, 13 closed-loop acknowledgements), representing one of the highest-confidence detection pipelines in the stack — every Canary alert is both actioned in case management and reconciled back to the source platform automatically.
The enrichment library is enterprise-grade in breadth. Forty-six enrichment subflows span IP reputation (VirusTotal, AbuseIPDB), domain and URL analysis (URLScan, Whois), file hash lookup (VirusTotal, CrowdStrike), and identity resolution across Microsoft Entra ID, Okta, Google Workspace, GitHub, and Slack. When Process Alert extracts an observable, the platform can query 10 distinct security data sources automatically. The H-ISAC BlueIntel integration (46 bulletins processed) adds sector-specific threat intelligence context to the operational picture, closing the loop between external threat feeds and the internal SOC workflow.
The case management layer is actively absorbing automation volume. Across the five active case management playbooks, 186 case lifecycle actions were executed — 62 analyst assignments, 41 status updates, 37 new case notifications, 25 automated closures, and 21 automated timeline comments. This represents meaningful SOC administrative overhead that has been eliminated from analyst workflows. The Generic IRP has also executed 54 times, confirming that structured incident response procedures are running against triaged cases.
Gaps and Opportunities
Three high-value response capability areas are deployed but show zero production executions: EDR containment (CrowdStrike host quarantine and RTR), identity threat response (Entra ID risky user disposition), and the phishing and malware response subflows. These represent the most operationally impactful automation available — endpoint quarantine and identity remediation are precisely the actions where automation reduces attacker dwell time most materially. Validating that the Generic IRP correctly routes to phishing and malware subflows via the Response Main Router should be a near-term priority; if the router is not selecting the correct subflow path, 54 IRP executions may be terminating at case documentation rather than executing remediation steps.
The enrichment subflows reporting zero direct executions is expected given their subflow architecture, but this creates a visibility gap: there is no straightforward way to confirm enrichment is firing correctly across the full observable type matrix (IP, URL, hash, username, domain) without instrumenting the Process Alert workflow directly. Adding lightweight execution logging or a metrics table update within the enrichment router would provide confirmation that the 46-subflow library is active against production alert volume.
Workspace B contains a near-complete mirror of the Workspace A enrichment and response subflow library — 16 enrichment playbooks plus response, error handling, and ingestion subflows — with zero executions across every playbook. If Workspace B is a staging or test environment, it should be explicitly documented as such. If it is intended as a production workspace for a distinct alert source or organizational unit, the ingestion playbooks that should be feeding it have not yet been connected. Resolving this ambiguity and either activating Workspace B's pipeline or consolidating it into Workspace A would simplify governance and eliminate the maintenance burden of keeping two parallel playbook libraries in sync.
Integration Ecosystem
The active integration footprint spans 12 or more platforms: CrowdStrike Falcon (EDR, hash enrichment, RTR), Rapid7 InsightIDR (SIEM), VirusTotal, AbuseIPDB, URLScan, Microsoft Entra ID (identity enrichment and risky user response), Microsoft Outlook (threat intel ingestion), Okta (identity enrichment), Google Workspace, GitHub, Slack, and Thinkst Canary. Four additional EXAMPLE ingest connectors — Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, and Wiz — have completed initial testing (8 combined executions) and are structurally ready to be promoted to production triggers. Activating these connectors would materially expand the alert surface covered by the automated pipeline without requiring new enrichment or response playbook development.
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| O&M | blink | my_blink_connection_ach | 2026-08-06 |
| O&M | digicert | my_digicert_connection | 2026-08-04 |