Blink Security Automation — Confidential

O&M — Customer Success Report

Generated 2026-08-30 | o&m-value-report.md
2026-08-30Report Date
151Total Playbooks
31Unique Workflows (12m)
782,530Actions Automated (12m)
$201,268Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

151
Total playbooks built
all non-deleted workflows
98
Active playbooks
currently enabled
31
Unique workflows executed (12m)
distinct workflows that ran
782,530
Actions automated (12m)
completed action steps
4,347.4h
Hours saved (12m)
@ 20s per action
$201,268
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
3,378
Total cases managed
3,378 opened in last 12m
7h 56m
MTTR — mean time to resolve
closed cases, last 12m
0
Active AI agents
of 3 total
0
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 883 security alerts processed end-to-end through the agentic SOC pipeline — from ingestion through observable extraction, enrichment, and case creation - 180 deception technology alerts ingested from Thinkst Canary, with 13 closed-loop analyst acknowledgements written back to the platform - 139 Rapid7 InsightIDR investigations ingested and routed into case management without analyst intervention - 54 structured incident response playbooks executed automatically against triaged cases - 62 cases assigned to the correct analyst queue automatically, with 37 real-time new case notifications dispatched - 46 H-ISAC BlueIntel threat intelligence bulletins ingested and processed for operational awareness - 103 case lifecycle actions automated — status transitions, closures, and timeline entries — eliminating repetitive administrative work from analyst workflows

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Alert Ingestion & Source Integration
  • 139Rapid7 investigations ingested into case management
9.1%
6
6 active
Alert Processing & Case Deduplication
  • 883Security alerts processed end-to-end
12.1%
6
6 active
Observable Enrichment0 executions
0.0%
30
30 active
Case Management & SOAR
  • 62Cases automatically assigned to analysts
  • 41Case status transitions automated
  • 37New case notifications dispatched
55.6%
13
13 active
Incident Response Playbooks
  • 54Incidents launched with structured IRP playbook
10.5%
4
4 active
EDR Containment & Response0 executions
0.0%
3
3 active
Identity Threat Response110 executions
0.3%
1
1 active
Threat Intelligence Curation
  • 46H-ISAC threat intelligence bulletins processed
0.1%
1
1 active
Deception Technology
  • 180Deception alerts detected and ingested
  • 13Deception alert response cycles closed
1.5%
1
1 active
Total28,360 executions100%
65
65 active

Use Case Growth Over Time

97 unique playbooks  |  9 operational use cases  |  31,776 total executions (12m)  |  2026-04 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Ingestion & Source Integration
CrowdStrike Rapid7 InsightIDR Microsoft Entra ID
Incident Response Playbooks
Microsoft Outlook
Observable Enrichment
CrowdStrike Okta Google Workspace Microsoft Entra ID AbuseIPDB VirusTotal URLScan GitHub Slack
Case Management & SOAR
Email Rapid7 InsightIDR CrowdStrike
Alert Processing & Case Deduplication
Email Rapid7 InsightIDR CrowdStrike
EDR Containment & Response
CrowdStrike
Identity Threat Response
Microsoft Entra ID
Threat Intelligence Curation
Microsoft Outlook
Deception Technology
Thinkst Canary

04Key Observations

✓  Strengths

Strengths

The agentic SOC pipeline is fully operational at production scale. Process Alert — the core orchestration engine — has processed 883 alerts end-to-end, handling observable extraction, case deduplication, enrichment routing, and downstream response actions without analyst intervention. This positions the automation program well beyond basic alert forwarding: it is executing structured, multi-step SOC workflows autonomously. Complementing this, the Thinkst Canary integration has delivered 193 total executions (180 ingestions, 13 closed-loop acknowledgements), representing one of the highest-confidence detection pipelines in the stack — every Canary alert is both actioned in case management and reconciled back to the source platform automatically.

The enrichment library is enterprise-grade in breadth. Forty-six enrichment subflows span IP reputation (VirusTotal, AbuseIPDB), domain and URL analysis (URLScan, Whois), file hash lookup (VirusTotal, CrowdStrike), and identity resolution across Microsoft Entra ID, Okta, Google Workspace, GitHub, and Slack. When Process Alert extracts an observable, the platform can query 10 distinct security data sources automatically. The H-ISAC BlueIntel integration (46 bulletins processed) adds sector-specific threat intelligence context to the operational picture, closing the loop between external threat feeds and the internal SOC workflow.

The case management layer is actively absorbing automation volume. Across the five active case management playbooks, 186 case lifecycle actions were executed — 62 analyst assignments, 41 status updates, 37 new case notifications, 25 automated closures, and 21 automated timeline comments. This represents meaningful SOC administrative overhead that has been eliminated from analyst workflows. The Generic IRP has also executed 54 times, confirming that structured incident response procedures are running against triaged cases.

△  Gaps & Growth Opportunities

Gaps and Opportunities

Three high-value response capability areas are deployed but show zero production executions: EDR containment (CrowdStrike host quarantine and RTR), identity threat response (Entra ID risky user disposition), and the phishing and malware response subflows. These represent the most operationally impactful automation available — endpoint quarantine and identity remediation are precisely the actions where automation reduces attacker dwell time most materially. Validating that the Generic IRP correctly routes to phishing and malware subflows via the Response Main Router should be a near-term priority; if the router is not selecting the correct subflow path, 54 IRP executions may be terminating at case documentation rather than executing remediation steps.

The enrichment subflows reporting zero direct executions is expected given their subflow architecture, but this creates a visibility gap: there is no straightforward way to confirm enrichment is firing correctly across the full observable type matrix (IP, URL, hash, username, domain) without instrumenting the Process Alert workflow directly. Adding lightweight execution logging or a metrics table update within the enrichment router would provide confirmation that the 46-subflow library is active against production alert volume.

Workspace B contains a near-complete mirror of the Workspace A enrichment and response subflow library — 16 enrichment playbooks plus response, error handling, and ingestion subflows — with zero executions across every playbook. If Workspace B is a staging or test environment, it should be explicitly documented as such. If it is intended as a production workspace for a distinct alert source or organizational unit, the ingestion playbooks that should be feeding it have not yet been connected. Resolving this ambiguity and either activating Workspace B's pipeline or consolidating it into Workspace A would simplify governance and eliminate the maintenance burden of keeping two parallel playbook libraries in sync.

Integration Ecosystem

The active integration footprint spans 12 or more platforms: CrowdStrike Falcon (EDR, hash enrichment, RTR), Rapid7 InsightIDR (SIEM), VirusTotal, AbuseIPDB, URLScan, Microsoft Entra ID (identity enrichment and risky user response), Microsoft Outlook (threat intel ingestion), Okta (identity enrichment), Google Workspace, GitHub, Slack, and Thinkst Canary. Four additional EXAMPLE ingest connectors — Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, and Wiz — have completed initial testing (8 combined executions) and are structurally ready to be promoted to production triggers. Activating these connectors would materially expand the alert surface covered by the automated pipeline without requiring new enrichment or response playbook development.

Appendices
A Case Management 3,378 cases (12m) | MTTR 7h 56m

Case Management

Total Cases (all-time)
3,378
3,378 opened in last 12m
Cases Opened (30d)
2,930
2,807 closed in last 30d
Cases Closed (12m)
3,244
of 3,378 opened
MTTR
7h 56m
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management 3,378 3,378 3,244 7h 56m
B AI Agents 0 active | 0 tasks (12m)

AI Agents

Active Agents
0
of 3 total
Tasks Executed (12m)
0
0 in last 30d
Data Usage (12m)
0
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Blink DEMO: ENGINEERING 0 0 0
2 Agent Blink Case Management 0 0 0
3 New Agent Case Management 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
DEMO: ENGINEERING0
Case Management0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
2
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Test-Suryakant 00
2 SOC HO Dashboard 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 9 use cases | 31,776 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts processed end-to-end 883 Process Alert
Deception alerts detected and ingested 180 Thinkst Canary Alert Ingestion
Rapid7 investigations ingested into case management 139 Rapid7 - Investigation Ingestion
Cases automatically assigned to analysts 62 Assign User to Incident UI
Incidents launched with structured IRP playbook 54 Incident Playbook - Generic IRP
H-ISAC threat intelligence bulletins processed 46 H-ISAC BlueIntel Notifications
Case status transitions automated 41 Set Status in UI
New case notifications dispatched 37 New Case Notification
Cases automatically closed 25 Set to Close in UI
Case timeline updates automated 21 Post Comment to UI
Deception alert response cycles closed 13 Canary Close/Acknowledgement
Cloud/SaaS alerts ingested via example connectors 8 Microsoft Defender For Cloud Apps, Azure, Wiz
In the last 12 months, Blink automated: - 883 security alerts processed end-to-end through the agentic SOC pipeline — from ingestion through observable extraction, enrichment, and case creation - 180 deception technology alerts ingested from Thinkst Canary, with 13 closed-loop analyst acknowledgements written back to the platform - 139 Rapid7 InsightIDR investigations ingested and routed into case management without analyst intervention - 54 structured incident response playbooks executed automatically against triaged cases - 62 cases assigned to the correct analyst queue automatically, with 37 real-time new case notifications dispatched - 46 H-ISAC BlueIntel threat intelligence bulletins ingested and processed for operational awareness - 103 case lifecycle actions automated — status transitions, closures, and timeline entries — eliminating repetitive administrative work from analyst workflows

Use Case Summary

Use Case Category Subcategory Total Playbooks Active Playbooks Total Executions
Alert Ingestion & Source Integration SOC SIEM & log pipeline monitoring 9 3 147
Alert Processing & Case Deduplication SOC Agentic SOC, Case mgmt & SOAR 7 3 1,299
Observable Enrichment SOC Alert enrichment / IOC lookup 46 0 0\*
Case Management & SOAR SOC Case mgmt & SOAR 14 5 186
Incident Response Playbooks SOC Phishing detection & response, Case mgmt & SOAR 7 1 54
EDR Containment & Response SOC EDR containment & response 3 0 0
Identity Threat Response SOC Identity threat response 2 0 0
Threat Intelligence Curation SOC Threat intel ingest & curation 1 1 46
Deception Technology SOC Agentic SOC, Case mgmt & SOAR 2 2 193

\* Enrichment playbooks run as subflows invoked by Process Alert; individual execution counts are not tracked at the subflow level.

Use Cases

Alert Ingestion & Source Integration

This use case covers the intake layer of the agentic SOC pipeline, ingesting alerts and investigation events from multiple security platforms into the Blink case management environment.

Business problem solved: Security teams operating across multiple detection platforms are forced to context-switch between consoles. These playbooks normalize and centralize alert ingestion so every signal enters a single structured pipeline regardless of source.

Integrations: Rapid7 InsightIDR, Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, Wiz, CrowdStrike Falcon, custom webhook

Playbook Workspace Executions Category Subcategory
Rapid7 - Investigation Ingestion Workspace A 139 SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - Microsoft Defender For Cloud Apps Workspace A 3 SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - Azure Workspace A 3 SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - Wiz Workspace A 2 SOC SIEM & log pipeline monitoring
Rapid7 - Investigation Ingestion Workspace B 0 SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - CrowdStrike Falcon LogScale Workspace A 0 SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - CrowdStrike Workspace A 0 SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - AWS CloudTrail Workspace A 0 SOC SIEM & log pipeline monitoring
New Workflow (CrowdStrike + CreateAlertV4) Workspace B 0 SOC SIEM & log pipeline monitoring

Alert Processing & Case Deduplication

The core orchestration layer of the agentic SOC pipeline — Process Alert receives normalized alerts, extracts observables, deduplicates against existing cases, and routes to enrichment and response.

Business problem solved: Without automated deduplication and orchestration, analysts manually review duplicate alerts and repeat enrichment steps for the same indicators. This pipeline eliminates redundant work by linking related alerts to existing cases and triggering enrichment only on net-new observables.

Integrations: Blink Case Management (native), CrowdStrike Falcon

Playbook Workspace Executions Category Subcategory
Process Alert Workspace A 883 SOC Agentic SOC, Case mgmt & SOAR
Subflow - Missing Alert Template Notification Workspace A 411 SOC Agentic SOC, Case mgmt & SOAR
Subflow - Missing Alert Template Notification Workspace B 5 SOC Agentic SOC, Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts Workspace A 0 SOC Agentic SOC, Case mgmt & SOAR
Table Action - Validate Observables Extraction Template Workspace A 0 SOC Agentic SOC, Case mgmt & SOAR
Simulate Multiple Alerts from Different Sources Workspace A 0 SOC Agentic SOC, Case mgmt & SOAR
Simulate Crowdstrike Alert Workspace A 0 SOC Agentic SOC, Case mgmt & SOAR

Observable Enrichment

These playbooks are invoked as subflows by Process Alert and have no independently tracked executions. Execution counts reflect the parent workflow's orchestration rather than discrete trigger events.

This use case encompasses the full library of enrichment subflows that look up IP addresses, domains, URLs, file hashes, usernames, and email addresses across the integrated threat intelligence and identity platforms.

Business problem solved: Manual enrichment of security observables is the most time-intensive step in alert triage. These subflows eliminate analyst lookup time by automatically querying every relevant platform the moment an observable is extracted from an incoming alert.

Integrations: CrowdStrike Falcon, VirusTotal, AbuseIPDB, URLScan, Microsoft Entra ID, Okta, Google Workspace, GitHub, Slack, Bash (whois/dig)

Workspace A

Playbook Workspace Executions Category Subcategory
Subflow - Enrich Observables - Main Router Workspace A 0 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data Workspace A 0 SOC Alert enrichment / IOC lookup
Utility - Update Enrichment Workspace A 0 SOC Alert enrichment / IOC lookup
Recovery - Enrich Non-Enriched Observables Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Username - Github Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Email Address - Slack Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - IP - VT Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - URL - VT Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - VT Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike Workspace A 0 SOC Alert enrichment / IOC lookup
Get User Information Using Google Workspace Workspace A 0 SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID Workspace A 0 SOC Alert enrichment / IOC lookup
Get User Information Using Github Workspace A 0 SOC Alert enrichment / IOC lookup
Get User Information Using Okta Workspace A 0 SOC Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack Workspace A 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike Workspace A 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal Workspace A 0 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois Workspace A 0 SOC Alert enrichment / IOC lookup
Okta Search for User Activity Workspace A 0 SOC Alert enrichment / IOC lookup
Run Dig Command Workspace A 0 SOC Alert enrichment / IOC lookup
Secure URL Screenshot Capture Workspace A 0 SOC Alert enrichment / IOC lookup
Analyze URL with URLScan Workspace A 0 SOC Alert enrichment / IOC lookup
Get End of Life Date for a Product Workspace A 0 SOC Alert enrichment / IOC lookup

Workspace B

Playbook Workspace Executions Category Subcategory
Subflow - Enrich Observables - Main Router Workspace B 0 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - IP - VT Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - URL - VT Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - VT Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike Workspace B 0 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois Workspace B 0 SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID Workspace B 0 SOC Alert enrichment / IOC lookup
Get User Information Using Google Workspace Workspace B 0 SOC Alert enrichment / IOC lookup

Case Management & SOAR

These playbooks manage the lifecycle of security cases — from initial notification through analyst assignment, status tracking, and automated closure — within the Blink native case management environment.

Business problem solved: Manual case lifecycle management creates delays between detection and analyst action and leaves audit trails incomplete. These playbooks ensure every case is acknowledged, assigned, and tracked to resolution without requiring analysts to perform repetitive administrative updates.

Integrations: Blink Case Management (native)

Playbook Workspace Executions Category Subcategory
Assign User to Incident UI Workspace A 62 SOC Case mgmt & SOAR
Set Status in UI Workspace A 41 SOC Case mgmt & SOAR
New Case Notification Workspace A 37 SOC Case mgmt & SOAR
Set to Close in UI Workspace A 25 SOC Case mgmt & SOAR
Post Comment to UI Workspace A 21 SOC Case mgmt & SOAR
Utility - Close Stale Cases Workspace A 0 SOC Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables Workspace A 0 SOC Case mgmt & SOAR
Utility - Set Or Update Observable Relation Workspace A 0 SOC Case mgmt & SOAR
Utility - List Observable Alert Relations Workspace A 0 SOC Case mgmt & SOAR
Utility - List Alert Observable Relations Workspace A 0 SOC Case mgmt & SOAR
Utility - Delete Observable Relation Workspace A 0 SOC Case mgmt & SOAR
USE WITH CARE - Reset Case Management Environment Workspace A 0 SOC Case mgmt & SOAR
Error Handling - Send Error Notification Email Workspace A 0 SOC Case mgmt & SOAR
Error Handling - Send Error Notification Email Workspace B 0 SOC Case mgmt & SOAR

Incident Response Playbooks

Structured incident response playbooks that execute predefined remediation steps against triaged cases, with modular subflows for specific threat categories including phishing and malware.

Business problem solved: Without automated response playbooks, analyst response quality is inconsistent and dependent on individual experience. These playbooks enforce a repeatable, auditable response process for each incident category, reducing mean time to respond and ensuring no remediation steps are skipped.

Integrations: Microsoft Outlook (KnowBe4 phishing simulation check), Microsoft Entra ID, Blink Case Management

Playbook Workspace Executions Category Subcategory
Incident Playbook - Generic IRP Workspace A 54 SOC Case mgmt & SOAR
Subflow - Response - Main Router Workspace A 0 SOC Case mgmt & SOAR
Response Subflow - Phishing Workspace A 0 SOC Phishing detection & response
Response Subflow - Malware Workspace A 0 SOC EDR containment & response
Subflow - Response - Main Router Workspace B 0 SOC Case mgmt & SOAR
Response Subflow - Phishing Workspace B 0 SOC Phishing detection & response
Response Subflow - Malware Workspace B 0 SOC EDR containment & response

EDR Containment & Response

CrowdStrike Falcon-based endpoint containment playbooks that allow analysts to quarantine hosts and execute real-time response commands against individual endpoints or batches of hosts.

Business problem solved: Endpoint containment during an active incident requires immediate, repeatable action with a full audit trail. These playbooks let analysts trigger quarantine and remote response actions directly from the case management interface without switching to the CrowdStrike console.

Integrations: CrowdStrike Falcon RTR

Playbook Workspace Executions Category Subcategory
Manage Endpoint Quarantine Status in Crowdstrike Workspace A 0 SOC EDR containment & response
CrowdStrike RTR to a Single Host Workspace A 0 SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts Workspace A 0 SOC EDR containment & response

Identity Threat Response

Playbooks that manage the lifecycle of risky user events surfaced by Microsoft Entra ID, enabling analysts to dismiss false positives or confirm a user as safe directly through the automation layer.

Business problem solved: Identity risk events in Entra ID require prompt analyst disposition to prevent alert fatigue and ensure genuine threats are escalated. These playbooks allow case-linked disposition of risky user signals without requiring direct Entra ID console access.

Integrations: Microsoft Entra ID (risky user APIs)

Playbook Workspace Executions Category Subcategory
Dismiss Risky User-Case Workspace A 0 SOC Identity threat response
Confirm User Safe-Case Workspace A 0 SOC Identity threat response

Threat Intelligence Curation

Automated ingestion of H-ISAC BlueIntel threat intelligence bulletins, enabling the security team to receive and act on sector-specific threat intelligence without manual monitoring of external feeds.

Business problem solved: Threat intelligence feeds deliver high-value context that often goes unread due to volume and the absence of workflow integration. This playbook ensures every H-ISAC bulletin is ingested, logged, and surfaced to the appropriate team automatically.

Integrations: Microsoft Outlook (email polling)

Playbook Workspace Executions Category Subcategory
H-ISAC BlueIntel Notifications Workspace A 46 SOC Threat intel ingest & curation

Deception Technology

End-to-end automation for Thinkst Canary deception alerts — from initial webhook ingestion through case creation to closed-loop analyst acknowledgement written back to the Canary platform.

Business problem solved: Canary alerts are high-confidence indicators of adversarial activity, but without automation they require manual triaging and acknowledgement steps that delay response. This use case ensures every Canary alert is immediately logged as a case and that analyst disposition is reflected back in the Canary console automatically.

Integrations: Thinkst Canary

Playbook Workspace Executions Category Subcategory
Thinkst Canary Alert Ingestion Workspace A 180 SOC Agentic SOC, Case mgmt & SOAR
Canary Close/Acknowledgement Workspace A 13 SOC Case mgmt & SOAR

Key Observations

Strengths

The agentic SOC pipeline is fully operational at production scale. Process Alert — the core orchestration engine — has processed 883 alerts end-to-end, handling observable extraction, case deduplication, enrichment routing, and downstream response actions without analyst intervention. This positions the automation program well beyond basic alert forwarding: it is executing structured, multi-step SOC workflows autonomously. Complementing this, the Thinkst Canary integration has delivered 193 total executions (180 ingestions, 13 closed-loop acknowledgements), representing one of the highest-confidence detection pipelines in the stack — every Canary alert is both actioned in case management and reconciled back to the source platform automatically.

The enrichment library is enterprise-grade in breadth. Forty-six enrichment subflows span IP reputation (VirusTotal, AbuseIPDB), domain and URL analysis (URLScan, Whois), file hash lookup (VirusTotal, CrowdStrike), and identity resolution across Microsoft Entra ID, Okta, Google Workspace, GitHub, and Slack. When Process Alert extracts an observable, the platform can query 10 distinct security data sources automatically. The H-ISAC BlueIntel integration (46 bulletins processed) adds sector-specific threat intelligence context to the operational picture, closing the loop between external threat feeds and the internal SOC workflow.

The case management layer is actively absorbing automation volume. Across the five active case management playbooks, 186 case lifecycle actions were executed — 62 analyst assignments, 41 status updates, 37 new case notifications, 25 automated closures, and 21 automated timeline comments. This represents meaningful SOC administrative overhead that has been eliminated from analyst workflows. The Generic IRP has also executed 54 times, confirming that structured incident response procedures are running against triaged cases.

Gaps and Opportunities

Three high-value response capability areas are deployed but show zero production executions: EDR containment (CrowdStrike host quarantine and RTR), identity threat response (Entra ID risky user disposition), and the phishing and malware response subflows. These represent the most operationally impactful automation available — endpoint quarantine and identity remediation are precisely the actions where automation reduces attacker dwell time most materially. Validating that the Generic IRP correctly routes to phishing and malware subflows via the Response Main Router should be a near-term priority; if the router is not selecting the correct subflow path, 54 IRP executions may be terminating at case documentation rather than executing remediation steps.

The enrichment subflows reporting zero direct executions is expected given their subflow architecture, but this creates a visibility gap: there is no straightforward way to confirm enrichment is firing correctly across the full observable type matrix (IP, URL, hash, username, domain) without instrumenting the Process Alert workflow directly. Adding lightweight execution logging or a metrics table update within the enrichment router would provide confirmation that the 46-subflow library is active against production alert volume.

Workspace B contains a near-complete mirror of the Workspace A enrichment and response subflow library — 16 enrichment playbooks plus response, error handling, and ingestion subflows — with zero executions across every playbook. If Workspace B is a staging or test environment, it should be explicitly documented as such. If it is intended as a production workspace for a distinct alert source or organizational unit, the ingestion playbooks that should be feeding it have not yet been connected. Resolving this ambiguity and either activating Workspace B's pipeline or consolidating it into Workspace A would simplify governance and eliminate the maintenance burden of keeping two parallel playbook libraries in sync.

Integration Ecosystem

The active integration footprint spans 12 or more platforms: CrowdStrike Falcon (EDR, hash enrichment, RTR), Rapid7 InsightIDR (SIEM), VirusTotal, AbuseIPDB, URLScan, Microsoft Entra ID (identity enrichment and risky user response), Microsoft Outlook (threat intel ingestion), Okta (identity enrichment), Google Workspace, GitHub, Slack, and Thinkst Canary. Four additional EXAMPLE ingest connectors — Microsoft Defender for Cloud Apps, Azure Monitor, AWS CloudTrail, and Wiz — have completed initial testing (8 combined executions) and are structurally ready to be promoted to production triggers. Activating these connectors would materially expand the alert surface covered by the automated pipeline without requiring new enrichment or response playbook development.

E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
O&M blink my_blink_connection_ach 2026-08-06
O&M digicert my_digicert_connection 2026-08-04