Blink Security Automation — Confidential

Pontera — Customer Success Report

Generated 2026-08-30 | pontera-value-report.md
2026-08-30Report Date
273Total Playbooks
111Unique Workflows (12m)
202,264Actions Automated (12m)
$52,023Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

273
Total playbooks built
all non-deleted workflows
199
Active playbooks
currently enabled
111
Unique workflows executed (12m)
distinct workflows that ran
202,264
Actions automated (12m)
completed action steps
1,123.7h
Hours saved (12m)
@ 20s per action
$52,023
Money saved (12m)
@ $100K avg salary
16
New active workflows (last 30d)
recently created & enabled
897
Total cases managed
897 opened in last 12m
2d 2h
MTTR — mean time to resolve
closed cases, last 12m
18
Active AI agents
of 43 total
8,720
AI agent tasks executed (12m)
2,672 in last 30d
In the last 12 months, Blink automated: - 2,321 AWS CLI commands executed autonomously by an AI cloud investigation agent - 679 CrowdStrike detections ingested and correlated into cases - 460 security alerts auto-triaged end-to-end without analyst intervention - 1,532 analyst Slack interactions processed and routed automatically - 1,440 case status updates synchronized to Slack war-room channels - 305 multi-vendor alerts deduplicated and correlated across detection sources - 240 resolved cases closed and reflected back in Sumo Logic - 85 security-inbox emails automatically triaged and classified - 30 endpoint device policy compliance scans executed - 25 data breach notifications processed from threat intelligence feeds - 20 SCA critical vulnerabilities triaged and ticketed automatically - 18 DLP incidents investigated with AI-powered behavioral analysis - 2,307 Okta security log queries executed autonomously by an AI forensics agent - 750 Cato Networks queries executed autonomously by an AI network agent - 1,049 HR onboarding/sync events processed automatically from HiBob - 332 alert observables enriched via the new SOC AI orchestrator - 3,839 real-time database lock/block anomaly checks executed - 324 AI-triaged case investigations completed end-to-end - 111 WAF alerts investigated automatically by an AI network forensics agent - 37 AI-flagged prompts analyzed for policy violations via a dedicated Cato AI agent - 20 scheduled WAF auto-unblock cycles executed to lift expired IP blocks - 14 customer holdings documents automatically imported and converted to OFX format

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC — Alert Triage & SOAR Orchestration
  • 793Sumo Logic forensics agent consultations during case investigations
  • 679CrowdStrike detections ingested and processed
  • 460Security alerts auto-triaged end-to-end
12.1%
26
25 active
Case Management & Slack Synchronization
  • 1,532Analyst Slack interactions handled automatically
  • 1,440Case status updates synchronized to Slack
  • 240Resolved cases closed and reflected in Sumo Logic
5.7%
9
9 active
Alert Enrichment & IOC Analysis
  • 2,307Okta security logs queried autonomously by AI forensics agent
  • 750Cato Networks queries executed autonomously by AI network agent
  • 332Alert observables enriched via SOC AI orchestrator
46.5%
50
50 active
Phishing Detection & Email Triage
  • 102Gmail messages retrieved for phishing investigation
  • 85Security-inbox emails automatically triaged
  • 70Gmail messages searched for phishing investigation
0.9%
10
10 active
DLP Triage & Investigation
  • 18DLP incidents investigated with AI analysis
0.0%
1
1 active
Endpoint Hygiene & Compliance Scanning
  • 30Device policy compliance scans executed
  • 25File integrity alerts auto-investigated
0.2%
8
8 active
Threat Intelligence Ingest & Curation
  • 25Data breach notifications processed
  • 15Supply chain security articles assessed
0.3%
5
5 active
Identity & Access Management
  • 1,049HR data sync events processed from HiBob
  • 11HiBob onboarding events processed automatically
3.3%
5
5 active
Security Operations Reporting
  • 212Automation error reports delivered to security lead
  • 1Incident post-mortem summaries posted
2.1%
2
2 active
Security Pack & Tooling Lifecycle
  • 10Security pack version updates automated
0.5%
2
2 active
Cloud Security Posture Management (Wiz)
  • 580Wiz cloud security graph queries executed autonomously by AI agent
1.8%
3
3 active
Cloud Infrastructure Investigation & Remediation
  • 2,321AWS CLI commands executed autonomously by AI cloud agent
7.2%
4
4 active
Vulnerability Management — SCA Critical Ticketing
  • 20SCA critical vulnerabilities triaged and ticketed
  • 4Automatic-fix ticket completion notifications sent to Slack
0.1%
5
5 active
Agentic SOC — Interactive Case Assistant (Slack)
  • 58Cases closed via AI-recommended Slack workflow
  • 19Ad-hoc AI Q&A sessions handled via Slack
0.2%
7
6 active
Database & Network Infrastructure Health Monitoring
  • 3,839Real-time database lock/block anomaly checks executed
  • 40Daily database locking summary reports generated
  • 29Proxy score reports delivered to Slack
12.0%
3
3 active
Financial Order Monitoring & Account Lookup
  • 10Order digest reports delivered to Slack
0.0%
3
3 active
WAF IP Blocking & Auto-Unblock
  • 20Scheduled WAF auto-unblock cycles executed
  • 3Malicious IPs blocked in WAF
  • 3IPs unblocked from WAF
0.1%
4
4 active
AI Prompt Offence Investigation (Cato)
  • 37AI-flagged prompt offences analyzed via Cato agent
  • 21On-demand Cato AI-prompt offence investigations triggered
  • 16Cases bulk re-analyzed for AI prompt offences
0.2%
3
3 active
Holdings Data Import & OFX Generation
  • 14Customer holdings documents imported and converted to OFX
  • 12Holdings import requests routed from Slack
0.1%
2
2 active
Total30,244 executions100%
152
150 active

Use Case Growth Over Time

194 unique playbooks  |  19 operational use cases  |  32,452 total executions (12m)  |  2026-03 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Phishing Detection & Email Triage
Microsoft Outlook Sumo Logic Gmail OpenAI Slack Google Admin Console Any Run Perception Point Google Drive
Alert Enrichment & IOC Analysis
Agents CrowdStrike Okta Google Workspace Microsoft Entra ID VirusTotal GitHub URLScan Slack Google Admin Console Kandji Cato Networks Sumo Logic Mitiga OpenAI AbuseIPDB Snowflake Jira Google Sheets
Agentic SOC — Alert Triage & SOAR Orchestration
Email Slack Agents Monday Confluence Jira Sumo Logic
Endpoint Hygiene & Compliance Scanning
CrowdStrike Kandji Slack OpenAI
DLP Triage & Investigation
Google Admin Console Sumo Logic OpenAI Slack
Case Management & Slack Synchronization
Slack OpenAI Sumo Logic Web Form
Agentic SOC — Interactive Case Assistant (Slack)
Email CrowdStrike Okta Sumo Logic OpenAI Snowflake Slack Web Form Agents Jira AWS
Threat Intelligence Ingest & Curation
Okta Slack Google Admin Console OpenAI GitHub
Security Operations Reporting
OpenAI Slack
Identity & Access Management
Okta Cato Networks Email Gmail
Security Pack & Tooling Lifecycle
Kandji GitHub Sumo Logic OpenAI Slack
Vulnerability Management — SCA Critical Ticketing
OpenAI Google Admin Console Jira HiBob Slack GitHub
Cloud Infrastructure Investigation & Remediation
AWS Agents Slack
Cloud Security Posture Management (Wiz)
Wiz Slack OpenAI Google Admin Console Jira HiBob GitHub
Database & Network Infrastructure Health Monitoring
Snowflake Slack
Financial Order Monitoring & Account Lookup
Agents Slack MySQL
WAF IP Blocking & Auto-Unblock
AWS Slack
AI Prompt Offence Investigation (Cato)
Cato Networks Agents Slack
Holdings Data Import & OFX Generation
Slack OpenAI

04Key Observations

✓  Strengths

Strengths

Mature agentic SOC pipeline. The alert triage flow — CrowdStrike and Sumo Logic ingestion → case deduplication → observable enrichment → AI summary → Slack delivery — is fully automated end-to-end. With 679 CrowdStrike detections and 442 process-alert executions over 12 months, this is the highest-volume and highest-value use case in the environment.

Slack-native SOC operations. With 1,532 incoming Slack interactions and 1,440 case-update syncs handled automatically, the team has made Slack the primary incident response interface — eliminating context-switching between the case management system and communication tools for routine operations.

AI deeply embedded across the security program. OpenAI is used not only for case summarization but also for phishing classification, DLP intent analysis, threat intel filtering, endpoint IDE investigation, case escalation briefings, and incident post-mortems. This indicates a sophisticated, AI-augmented security posture that goes well beyond basic automation.

Rich, custom enrichment library. Fifteen-plus enrichment playbooks cover every major observable type. The custom Pontera-specific enrichers (username/email via Sumo Logic, hostname via CrowdStrike) are actively running, demonstrating mature platform customization beyond out-of-the-box capabilities.

Proactive threat intelligence consumption. Automated monitoring of HaveIBeenPwned for breach data on organizational domains, combined with supply chain security RSS feeds (SocketSecurity) and community vulnerability research, provides a curated, AI-filtered intelligence stream without manual analyst monitoring.

Unique AI tooling automation. The Claude Security Pack Updater is a particularly sophisticated workflow — automating the lifecycle of an AI-powered security detection pack (release detection, config comparison, deployment, release notes) in a way that is rare among Blink customers.

Emerging agentic cloud security capability. New AI-agent tooling now enables autonomous AWS CLI execution and EC2/S3 investigation via a purpose-built "Cloud Analyst" agent — the AWS CLI tool alone has already executed 2,321 times, making it the single highest-volume automation in the environment. Combined with new Wiz-based posture alerting for exposed secrets, this marks the environment's expansion from pure SOC/EDR automation into cloud security posture management.

Multi-agent forensics network now operational. A new "Agent 2 Agent" tier lets the primary case-handling agent delegate forensics questions to vendor-specialized analyst agents — AWS, Google Workspace, Cato Networks, Sumo Logic, Okta, and Wiz — with 1,463 combined consultations in the last 12 months. Paired with a new direct-query layer (Okta log search at 2,307 executions, Cato Networks queries at 750, Wiz GraphQL queries at 580), this significantly deepens the platform's autonomous investigation depth across identity, network, and cloud domains.

New conversational Slack assistant for live investigations. A "SOC AI" tier now lets analysts ask ad-hoc questions and close cases directly from Slack (58 AI-recommended case closures, 19 ad-hoc Q&A sessions), backed by a dedicated user-communications agent for direct end-user outreach — extending the platform's AI footprint from background automation into a live, conversational analyst interface.

AI-driven case investigation now a high-volume core process. The new Main - Investigation playbook — which queries the case management system, evaluates conditions, pulls timeline events, and hands off to a "Post Investigation Triage Agent" before updating the case — has already run 324 times, and a new Sumologic WAF Alert flow adds a dedicated network forensics agent for WAF-triggered alerts (111 executions). Together these deepen the automated investigation layer introduced alongside the multi-agent forensics network.

Expansion into infrastructure health and business operations monitoring. Beyond security, Blink now automates database lock/block anomaly detection (3,839 real-time checks plus a daily summary) and proxy health scoring via Snowflake, alongside order-digest and account-lookup tooling for financial operations — signaling that the platform is being adopted as a general automation layer for the business, not solely for the SOC.

New network-layer containment capability. IP blocking and auto-unblocking in the WAF (27 combined on-demand executions plus 20 scheduled auto-unblock cycles) closes the

△  Gaps & Growth Opportunities

gap between WAF alert investigation (Sumologic WAF Alert) and actual containment action, with a scheduled job guaranteeing temporary blocks expire automatically.

Emerging AI-usage governance. A new Cato-integrated pipeline (74 combined executions) evaluates AI-app prompts flagged as policy offences via a dedicated "Cato Prompt Analyist" agent, extending the platform's oversight from network and endpoint threats into GenAI usage risk.

Financial operations digitization via AI vision. The new Holdings Import pipeline (26 combined executions) uses AI vision to extract customer holdings data from uploaded screenshots, routes it through a Slack-based human review loop, and generates ready-to-import OFX files — automating a previously manual, error-prone data-entry process.

Gaps & Opportunities

Offboarding half of IAM lifecycle still dormant. The user deactivation, Cato coverage, and Okta deprovisioning playbooks all show 0 executions. Onboarding is now active — the new HiBob-triggered onboarding and sync playbooks run 11 and 1,049 times respectively — but the offboarding and coverage-reporting side of the tooling remains built but not yet operationally active. Wiring deactivation and deprovisioning to the same HiBob trigger is the most immediately addressable gap given the existing infrastructure.

Enrichment library underutilized. The general enrichment playbooks (IP/URL/hash enrichment via VirusTotal, AbuseIPDB, URLScan) all show 0 executions. This suggests the main triage pipeline currently routes through only the Pontera-specific enrichers, with the broader threat intel lookups not yet wired into the automated flow.

EDR containment not yet activated. CrowdStrike RTR (batch and single host) and endpoint quarantine playbooks exist but show 0 executions. Connecting these to the alert triage pipeline as automated response actions — triggered on confirmed high-severity detections — would complete the containment loop without analyst involvement.

Phishing email investigation incomplete. Init Email Investigation, Investigate Email - Search, and Investigate Email - Sandbox File all have 0 executions while the ingestion playbook runs 85 times per year. The new Agent Ability - Google List Gmail Messages tool (70 executions) now provides active mailbox search for investigations, partially closing this gap — but sandbox file analysis remains unused.

Vulnerability management coverage is just beginning. The new SCA Critical Ticketing workflow (20 executions) introduces AI-triaged, ticketed remediation for software composition analysis findings — a first step into vulnerability management. Broader coverage (CVE lookup, vulnerability scanner integration, patch lifecycle automation) is still missing, and given daily endpoint compliance scanning is already in place, there is a natural expansion path into fuller vulnerability prioritization.

Integration Ecosystem

The environment spans 20+ integrated platforms: CrowdStrike, Sumo Logic, Okta, Google Workspace / Gmail, Microsoft Entra ID, Slack, OpenAI, Teramind, Mitiga, Kandji, Cato Networks, Perception Point, VirusTotal, AbuseIPDB, URLScan, GitHub, HaveIBeenPwned, Monday.com, Wiz, AWS, HiBob, Snowflake, Jira, and MySQL.

This is a broad, mature integration footprint — signaling a security team that has actively unified disparate tools under automated orchestration rather than operating them in silos. The presence of Mitiga (cloud incident response), Teramind (DLP / insider threat), and Perception Point (email security) alongside the core CrowdStrike / Sumo Logic stack indicates a layered detection approach across endpoint, cloud, and human-layer threat vectors.

Appendices
A Case Management 897 cases (12m) | MTTR 2d 2h

Case Management

Total Cases (all-time)
897
897 opened in last 12m
Cases Opened (30d)
194
130 closed in last 30d
Cases Closed (12m)
831
of 897 opened
MTTR
2d 2h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Incident Response 895 895 831 2d 2h
SecOps 2 2 0 N/A
B AI Agents 18 active | 8,720 tasks (12m)

AI Agents

Active Agents
18
of 43 total
Tasks Executed (12m)
8,720
2,672 in last 30d
Data Usage (12m)
1,989,038,057
1,414,164,607 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 AWS Bucket Analyst SecOps 4,482 0 40,783,413
2 Enrichment Agent Incident Response 989 483 50,413,857
3 Sumologic Agent Incident Response 937 684 1,043,465,532
4 AWS Agent Incident Response 542 249 136,123,655
5 Okta Agent Incident Response 422 277 224,396,198
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
SecOps4,482
Incident Response4,146
toms@pontera.com56
Sensitive27
guy.sheffer@pontera.com9
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
3
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Device Compliance 00
2 Case Management 00
3 Dashboard1 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 19 use cases | 32,452 executions (12m)

Business KPIs

Metric Count Playbook
AWS CLI commands executed autonomously by AI cloud agent 2,321 Agent Ability - AWS CLI
CrowdStrike detections ingested and processed 679 Ingestion - Crowdstrike
Analyst Slack interactions handled automatically 1,532 Slack Subscription - Incoming
Case status updates synchronized to Slack 1,440 Slack Sync - Case Updated
Security alerts auto-triaged end-to-end 460 Process Alert
Multi-vendor alerts deduplicated and correlated 305 Check and Record Alert
Resolved cases closed and reflected in Sumo Logic 240 Sumologic Sync - Case Closed
New cases opened with dedicated Slack channels 223 Slack Sync - Case Created
Sumo Logic insights closed via case workflow 188 Sumologic Sync - Insight Closed
Sumo Logic insights ingested and case-correlated 186 Alert Ingestion - Sumologic Insights
Automation error reports delivered to security lead 212 Report to Shachar
Security-inbox emails automatically triaged 85 Ingestion - Mail to security@pontera.com
Email attachment investigations processed 45 Main - Bulk File Upload
Username/email observables enriched 47 Enrich - Username/Email - Pontera
Hostname observables enriched 44 Enrich - Hostname - Pontera
Google Workspace admin activities investigated by AI agent 75 Agent Ability - Google List Admin Activities
Gmail messages searched for phishing investigation 70 Agent Ability - Google List Gmail Messages
Gmail messages retrieved for phishing investigation 102 Agent Ability - Google Get Gmail Message
Device policy compliance scans executed 30 Scanner - Scan Dev Devices for Policy Violation
Data breach notifications processed 25 HaveIBeenPwned RSS
File integrity alerts auto-investigated 25 Incoming - File Integrity Alert
SCA critical vulnerabilities triaged and ticketed 20 SCA Critical Ticketing
DLP incidents investigated with AI analysis 18 Main - Teramind DLP Investigation
Supply chain security articles assessed 15 SocketSecurity RSS
Security pack version updates automated 10 Claude Security Pack Updater
Cloud incident enrichments from Mitiga 7 Response - Mitiga Enrichment
Phishing alerts fully investigated 8 Main - Phishing
Cases escalated with AI-generated briefings 5 Main - Escalate
Incident post-mortem summaries posted 1 Incident Post Digest
Okta security logs queried autonomously by AI forensics agent 2,307 Agent Ability - Okta Get Logs
Cato Networks queries executed autonomously by AI network agent 750 Agent Ability - Cato Query
Wiz cloud security graph queries executed autonomously by AI agent 580 Agent Ability - Wiz GraphQL Query
Sumo Logic forensics agent consultations during case investigations 793 Agent 2 Agent - Sumologic Agent
Okta forensics agent consultations during case investigations 365 Agent 2 Agent - Okta Agent
Alert case data synchronized to Monday.com templates 328 Template Processing - Main
Okta user identities looked up by AI agent 318 Agent Ability - Okta Get User By Email
Case enrichment data retrieved by AI agent 306 Agent Ability - Get Enrichments
AWS forensics agent consultations during case investigations 176 Agent 2 Agent - AWS Agent
Google Workspace forensics agent consultations during case investigations 49 Agent 2 Agent - Google Agent
Cato Networks forensics agent consultations during case investigations 47 Agent 2 Agent - Cato Agent
Wiz forensics agent consultations during case investigations 33 Agent 2 Agent - Wiz Agent
New alert cases ingested from IR webhook source 7 Alerts from IR
HR data sync events processed from HiBob 1,049 Hibob Sync
Alert observables enriched via SOC AI orchestrator 332 SOC AI - Enrich Alert Observables
AWS entity enrichments delivered to cases 108 Enrich - AWS
Cases closed via AI-recommended Slack workflow 58 SOC AI - Close Case
Ad-hoc AI Q&A sessions handled via Slack 19 SOC AI - Ask AI Question (Slack)
HiBob onboarding events processed automatically 11 Hibob Onboarding
Real-time database lock/block anomaly checks executed 3,839 Real-Time Locks / Blocks Anomaly Alerts
AI-triaged case investigations completed 324 Main - Investigation
WAF alerts investigated by AI network forensics agent 111 Sumologic WAF Alert
Proxy score reports delivered to Slack 29 Proxy Score Report
Daily database locking summary reports generated 40 DAILY LOCKING SUMMARY
Order digest reports delivered to Slack 10 Get Orders
Automatic-fix ticket completion notifications sent to Slack 4 Ticket Slack Notification
Malicious IPs blocked in WAF 3 Block IP in WAF
IPs unblocked from WAF 3 Unblock IP in WAF
Scheduled WAF auto-unblock cycles executed 20 Daily WAF Unblock
Blocked-IP list reports generated 1 List Blocked IPs
AI-flagged prompt offences analyzed via Cato agent 37 Main - Analyse AI Prompt
On-demand Cato AI-prompt offence investigations triggered 21 Analyse Cato AI Prompt
Cases bulk re-analyzed for AI prompt offences 16 On Demand - Analyse Cato AI Prompt
Customer holdings documents imported and converted to OFX 14 Holdings Import
Holdings import requests routed from Slack 12 CDI Ops Router
In the last 12 months, Blink automated: - 2,321 AWS CLI commands executed autonomously by an AI cloud investigation agent - 679 CrowdStrike detections ingested and correlated into cases - 460 security alerts auto-triaged end-to-end without analyst intervention - 1,532 analyst Slack interactions processed and routed automatically - 1,440 case status updates synchronized to Slack war-room channels - 305 multi-vendor alerts deduplicated and correlated across detection sources - 240 resolved cases closed and reflected back in Sumo Logic - 85 security-inbox emails automatically triaged and classified - 30 endpoint device policy compliance scans executed - 25 data breach notifications processed from threat intelligence feeds - 20 SCA critical vulnerabilities triaged and ticketed automatically - 18 DLP incidents investigated with AI-powered behavioral analysis - 2,307 Okta security log queries executed autonomously by an AI forensics agent - 750 Cato Networks queries executed autonomously by an AI network agent - 1,049 HR onboarding/sync events processed automatically from HiBob - 332 alert observables enriched via the new SOC AI orchestrator - 3,839 real-time database lock/block anomaly checks executed - 324 AI-triaged case investigations completed end-to-end - 111 WAF alerts investigated automatically by an AI network forensics agent - 37 AI-flagged prompts analyzed for policy violations via a dedicated Cato AI agent - 20 scheduled WAF auto-unblock cycles executed to lift expired IP blocks - 14 customer holdings documents automatically imported and converted to OFX format

Use Case Summary

# Use Case Category Subcategory Playbooks
1 Agentic SOC — Alert Triage & SOAR Orchestration SOC Agentic SOC, Case mgmt & SOAR, SIEM & log pipeline monitoring 33
2 Case Management & Slack Synchronization SOC Case mgmt & SOAR, Agentic SOC 10
3 Alert Enrichment & IOC Analysis SOC Alert enrichment / IOC lookup 77
4 Phishing Detection & Email Triage SOC Phishing detection & response 10
5 DLP Triage & Investigation GRC DLP triage & exposure resp 1
6 Endpoint Hygiene & Compliance Scanning Other Endpoint hygiene & MDM ops, EDR containment & response 11
7 Threat Intelligence Ingest & Curation SOC Threat intel ingest & curation 5
8 Identity & Access Management IAM Employee onboarding, Employee offboarding, Access review & group mgmt, Identity lifecycle automation 6
9 Security Operations Reporting GRC Security metrics & reporting, Agentic SOC 3
10 Security Pack & Tooling Lifecycle Other DevOps & release automation 2
11 Cloud Security Posture Management (Wiz) Cloud Security CSPM ingest & triage 4
12 Cloud Infrastructure Investigation & Remediation Cloud Security Cloud asset coverage & inventory, Config audit & remediation 5
13 Vulnerability Management — SCA Critical Ticketing Vulnerability Mgmt Vuln lifecycle prioritize & ticket 5
14 Agentic SOC — Interactive Case Assistant (Slack) SOC Agentic SOC, Case mgmt & SOAR 8
15 Database & Network Infrastructure Health Monitoring Other IT/OT & network infra monitoring 3
16 Financial Order Monitoring & Account Lookup Other Financial & fraud operations, Customer registry & FinOps auto 3
17 WAF IP Blocking & Auto-Unblock SOC EDR containment & response 4
18 AI Prompt Offence Investigation (Cato) SOC Alert enrichment / IOC lookup, Agentic SOC 3
19 Holdings Data Import & OFX Generation Other Customer registry & FinOps auto 2

Use Cases

1. Agentic SOC — Alert Triage & SOAR Orchestration

Description: End-to-end automated alert processing pipeline that ingests detections from CrowdStrike and Sumo Logic, deduplicates and correlates events into cases, enriches all observables, applies AI-powered response routing, and delivers analyst-ready summaries — without requiring manual first-pass triage.

Business problem solved: Security teams are overwhelmed by alert volume across multiple detection sources. This use case eliminates manual triage by automating the full journey from raw alert to enriched, deduplicated, AI-summarized case ready for analyst action.

Key integrations: CrowdStrike, Sumo Logic, Blink Case Management, OpenAI, Slack, Monday.com, AWS, Google Workspace, Cato Networks, Okta, Wiz

Playbook Executions Type Category Subcategory
Process Alert 442 Event SOC Agentic SOC, Case mgmt & SOAR
Ingestion - Crowdstrike 679 Event SOC SIEM & log pipeline monitoring
Alert Ingestion - Sumologic Insights 186 Event SOC SIEM & log pipeline monitoring
Check and Record Alert 305 On-demand SOC Case mgmt & SOAR
Main - Escalate 5 On-demand SOC Agentic SOC, Case mgmt & SOAR
Subflow - Response - Main Router 431 On-demand (subflow) SOC Agentic SOC
Subflow - Enrich Observables - Main Router 376 On-demand (subflow) SOC Alert enrichment / IOC lookup
Subflow - Generate Summery 438 On-demand (subflow) SOC Agentic SOC
Subflow - Update Enrichment Data 66 On-demand (subflow) SOC Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification 14 On-demand (subflow) SOC Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts 0 On-demand SOC Case mgmt & SOAR
Error Handling - Send Error Notification Email 0 On-demand SOC Case mgmt & SOAR
SOC AI - Generate Slack Post 1,084 On-demand (subflow) SOC Agentic SOC
Subflow - Response - Main Router 1 On-demand (subflow) SOC Agentic SOC
Error Handling - Send Error Notification Email 0 On-demand SOC Case mgmt & SOAR
Subflow - Enrich Observables - Main Router 1 On-demand (subflow) SOC Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification 0 On-demand (subflow) SOC Case mgmt & SOAR
Simulate Multiple Alerts from Different Sources 0 On-demand SOC Agentic SOC, Case mgmt & SOAR
Simulate Crowdstrike Alert 0 On-demand SOC Agentic SOC, Case mgmt & SOAR
Process Alert 18 Event SOC Agentic SOC, Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts 0 On-demand SOC Case mgmt & SOAR
Agent 2 Agent - AWS Agent 176 On-demand SOC Agentic SOC
Agent 2 Agent - Google Agent 49 On-demand SOC Agentic SOC
Agent 2 Agent - Cato Agent 47 On-demand SOC Agentic SOC
Agent 2 Agent - Sumologic Agent 793 On-demand SOC Agentic SOC
Agent 2 Agent - Okta Agent 365 On-demand SOC Agentic SOC
Agent 2 Agent - Wiz Agent 33 On-demand SOC Agentic SOC
Alerts from IR 7 Event SOC Agentic SOC, Case mgmt & SOAR
Template Processing - Main 328 On-demand SOC Agentic SOC, Case mgmt & SOAR
Fix Templates 0 On-demand SOC Case mgmt & SOAR
Main - Investigation 324 On-demand SOC Agentic SOC, Case mgmt & SOAR
Sumologic WAF Alert 111 Event SOC Agentic SOC, Case mgmt & SOAR
Build Sumo Rules 0 On-demand SOC SIEM & log pipeline monitoring

2. Case Management & Slack Synchronization

Description: Bi-directional synchronization layer between Blink case management and Slack. When a new case opens, a dedicated Slack channel is created and populated with an AI-generated briefing. As case fields evolve (status, severity, summary), Slack messages update in real time. Analyst replies in Slack feed back into the case. When cases close, Sumo Logic insights are updated accordingly.

Business problem solved: SOC analysts spend significant time context-switching between case management systems and communication tools. This use case makes Slack the single operational interface for incident response, eliminating manual status updates and keeping the entire team in sync automatically.

Key integrations: Slack, Blink Case Management, Sumo Logic, OpenAI

Playbook Executions Type Category Subcategory
Slack Subscription - Incoming 1,532 Event SOC Case mgmt & SOAR
Slack Sync - Case Updated 1,440 Event SOC Case mgmt & SOAR
Slack Sync - Case Created 223 On-demand SOC Case mgmt & SOAR, Agentic SOC
Sumologic Sync - Case Closed 240 Event SOC Case mgmt & SOAR, SIEM & log pipeline monitoring
Sumologic Sync - Insight Closed 188 Event SOC SIEM & log pipeline monitoring
Slack Interactivity - Main 55 Event SOC Case mgmt & SOAR
Utility - Close Stale Cases 0 On-demand SOC Case mgmt & SOAR
Utility - Close Stale Cases 0 On-demand SOC Case mgmt & SOAR
Find Cases to Merge 0 On-demand SOC Case mgmt & SOAR
USE WITH CARE - Reset Case Management Environment 0 On-demand SOC Case mgmt & SOAR

3. Alert Enrichment & IOC Analysis

Description: Comprehensive observable enrichment library covering IPs, URLs, domains, hashes, hostnames, and user identities across multiple threat intelligence and identity sources. Custom enrichment pipelines pull context specific to the organization's environment from Sumo Logic and CrowdStrike, augmenting standard threat feeds. Utility playbooks manage the lifecycle of observable-to-alert relationships within the case management system.

Business problem solved: Manual enrichment of each observable in an alert is the most time-consuming part of triage. This library provides automated, on-demand context for every observable type — so analysts begin investigation with full context rather than spending time gathering it from disparate tools.

Key integrations: AbuseIPDB, VirusTotal, URLScan, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Sumo Logic, Mitiga, Whois, Cato Networks, AWS, Blink Case Management

Playbook Executions Type Category Subcategory
Enrich - Username/Email - Pontera 47 On-demand SOC Alert enrichment / IOC lookup
Enrich - Hostname - Pontera 44 On-demand SOC Alert enrichment / IOC lookup
Response - Mitiga Enrichment 7 On-demand SOC Alert enrichment / IOC lookup
Subflow - Sumologic Cato Search 5 On-demand (subflow) SOC Alert enrichment / IOC lookup
Subflow - Crowdstrike Search 4 On-demand (subflow) SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - IP - VT 0 On-demand SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - URL - VT 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan 0 On-demand SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike 0 On-demand SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Okta 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Google Workspace 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Github 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack 0 On-demand SOC Alert enrichment / IOC lookup
Okta Search for User Activity 0 On-demand SOC Alert enrichment / IOC lookup
Secure URL Screenshot Capture 0 On-demand SOC Alert enrichment / IOC lookup
Analyze URL with URLScan 0 On-demand SOC Alert enrichment / IOC lookup
Run Dig Command 0 On-demand SOC Alert enrichment / IOC lookup
Get End of Life Date for a Product 0 On-demand Vulnerability Mgmt CVE lookup & remediation
Table Action - Validate Observables Extraction Template 0 On-demand SOC Alert enrichment / IOC lookup
Utility - Find Similar Cases Based on Observables 0 On-demand SOC Case mgmt & SOAR
Utility - Update Enrichment 0 On-demand SOC Alert enrichment / IOC lookup
Utility - Set Or Update Observable Relation 0 On-demand SOC Alert enrichment / IOC lookup
Utility - List Observable Alert Relations 0 On-demand SOC Alert enrichment / IOC lookup
Utility - List Alert Observable Relations 0 On-demand SOC Alert enrichment / IOC lookup
Utility - Delete Observable Relation 0 On-demand SOC Alert enrichment / IOC lookup
Recovery - Enrich Non-Enriched Observables 0 On-demand SOC Alert enrichment / IOC lookup
Agent Tool - Query Sumo 0 On-demand SOC Alert enrichment / IOC lookup
Agent Ability - Google List Admin Activities 75 On-demand SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 0 On-demand (subflow) SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Google Workspace 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - IP - VT 0 On-demand SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - URL - VT 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - Hash - VT 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike 0 On-demand SOC Alert enrichment / IOC lookup
Utility - Update Enrichment 0 On-demand SOC Alert enrichment / IOC lookup
Recovery - Enrich Non-Enriched Observables 0 On-demand SOC Alert enrichment / IOC lookup
Utility - Delete Observable Relation 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Github 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - Username - Github 0 On-demand SOC Alert enrichment / IOC lookup
Secure URL Screenshot Capture 0 On-demand SOC Alert enrichment / IOC lookup
Get End of Life Date for a Product 0 On-demand Vulnerability Mgmt CVE lookup & remediation
Analyze URL with URLScan 0 On-demand SOC Alert enrichment / IOC lookup
Okta Search for User Activity 0 On-demand SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information Using Okta 0 On-demand SOC Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack 0 On-demand SOC Alert enrichment / IOC lookup
Utility - Set Or Update Observable Relation 0 On-demand SOC Alert enrichment / IOC lookup
Utility - List Observable Alert Relations 0 On-demand SOC Alert enrichment / IOC lookup
Utility - List Alert Observable Relations 0 On-demand SOC Alert enrichment / IOC lookup
Utility - Find Similar Cases Based on Observables 0 On-demand SOC Case mgmt & SOAR
Table Action - Validate Observables Extraction Template 0 On-demand SOC Alert enrichment / IOC lookup
Run Dig Command 0 On-demand SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal 0 On-demand SOC Alert enrichment / IOC lookup
Enrich - Email Address - Slack 0 On-demand SOC Alert enrichment / IOC lookup
Agent Ability - Cato Query 750 On-demand SOC Alert enrichment / IOC lookup
Agent Ability - Get Enrichments 306 On-demand SOC Alert enrichment / IOC lookup
Agent Ability - Okta Get Logs 2,307 On-demand SOC Alert enrichment / IOC lookup
Agent Ability - Okta Get User By Email 318 On-demand SOC Alert enrichment / IOC lookup
Enrich - AWS 108 On-demand SOC Alert enrichment / IOC lookup
New Workflow 2 0 On-demand SOC Alert enrichment / IOC lookup
Agent Ability - Find Cato AI Session ID 0 On-demand SOC Alert enrichment / IOC lookup
SOC AI - Enrich Alert Observables 332 On-demand SOC Alert enrichment / IOC lookup
Agent Ability - Sumologic Query 0 On-demand SOC Alert enrichment / IOC lookup

4. Phishing Detection & Email Triage

Description: Automated phishing response pipeline covering the full investigation lifecycle: monitors the security inbox for inbound mail, uses AI to classify intent and extract indicators, queries Perception Point for known phishing campaigns by subject and sender, investigates attachments, and updates the case with a verdict and recommended action.

Business problem solved: Phishing reports from users and security-inbox emails are high-volume and require rapid first-response to contain threats. This use case eliminates manual triage of email-based threats, enabling faster analyst focus on confirmed incidents.

Key integrations: Google Workspace, Gmail, OpenAI, Slack, Blink Case Management, Perception Point

Playbook Executions Type Category Subcategory
Ingestion - Mail to security@pontera.com 85 Event SOC Phishing detection & response
Main - Bulk File Upload 45 On-demand SOC Phishing detection & response
Main - Phishing 8 On-demand SOC Phishing detection & response
Init Email Investigation 0 On-demand SOC Phishing detection & response
Investigate Email - Search 0 On-demand SOC Phishing detection & response
Investigate Email - Sandbox File 0 On-demand SOC Phishing detection & response
Agent Ability - Google List Gmail Messages 70 On-demand SOC Phishing detection & response
Agent Ability - Google Get Gmail Message 102 On-demand SOC Phishing detection & response
Response Subflow - Phishing 0 On-demand (subflow) SOC Phishing detection & response
Agent Ability - Analyze Drive File 0 On-demand SOC Phishing detection & response

5. DLP Triage & Investigation

Description: Automated investigation workflow triggered by Teramind DLP alerts. Cross-references the flagged activity against Google Workspace admin logs and Sumo Logic Cato network logs, applies AI reasoning to determine intent and risk level, and delivers a structured finding to Slack and the case record.

Business problem solved: DLP alerts for data exfiltration require correlation across email, network, and endpoint data — a manual process that takes analysts hours. This workflow automates the full correlation and delivers a contextualized verdict in minutes.

Key integrations: Teramind, Google Admin Console, Sumo Logic, OpenAI, Slack, Blink Case Management

Playbook Executions Type Category Subcategory
Main - Teramind DLP Investigation 18 On-demand GRC DLP triage & exposure resp

6. Endpoint Hygiene & Compliance Scanning

Description: Automated endpoint security posture management combining scheduled policy compliance scans (CrowdStrike + Kandji) with real-time file integrity monitoring. Device inventory and compliance state are tracked across both macOS (Kandji) and Windows (CrowdStrike) endpoints; violations trigger investigation workflows. Remote script execution via CrowdStrike RTR and endpoint quarantine capabilities enable rapid containment.

Business problem solved: Maintaining continuous endpoint compliance visibility across a mixed-device fleet is operationally intensive. This use case automates daily scans, anomaly detection, and targeted remediation — reducing drift between security policy and endpoint state.

Key integrations: CrowdStrike, Kandji, OpenAI, Blink Case Management

Playbook Executions Type Category Subcategory
Scanner - Scan Dev Devices for Policy Violation 30 Scheduled Other Endpoint hygiene & MDM ops
Incoming - File Integrity Alert 25 Event Other Endpoint hygiene & MDM ops
Kanji IDE 2 On-demand Other Endpoint hygiene & MDM ops
Main - Device Compliance 0 On-demand Other Endpoint hygiene & MDM ops
CrowdStrike RTR to a Batch of Hosts 0 On-demand SOC EDR containment & response
CrowdStrike RTR to a Single Host 0 On-demand SOC EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike 0 On-demand SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts 0 On-demand SOC EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike 0 On-demand SOC EDR containment & response
Response Subflow - Malware 0 On-demand (subflow) SOC EDR containment & response
CrowdStrike RTR to a Single Host 0 On-demand SOC EDR containment & response

7. Threat Intelligence Ingest & Curation

Description: Automated threat intelligence pipeline monitoring curated RSS sources — HaveIBeenPwned for credential breach data relevant to organizational domains, SocketSecurity for supply chain security signals, and community vulnerability research. Entries are assessed by AI for applicability, and relevant findings are delivered to the security team via Slack. A GitHub code search subflow supports IOC hunting across public repositories.

Business problem solved: Security teams struggle to keep pace with the volume of threat intelligence published daily. This use case provides a filtered, AI-curated signal feed ensuring relevant threats — especially credential breaches and supply chain risks — reach the team without manual monitoring.

Key integrations: RSS, HTTP, OpenAI, Slack, HaveIBeenPwned API, GitHub

Playbook Executions Type Category Subcategory
HaveIBeenPwned RSS 25 Event SOC Threat intel ingest & curation
SocketSecurity RSS 15 Event SOC Threat intel ingest & curation
Automated Scan Bouncer 9 On-demand SOC Threat intel ingest & curation
ramimac TeampPCP RSS 2 Event SOC Threat intel ingest & curation
Subflow - Github Code Search 0 On-demand (subflow) SOC Threat intel ingest & curation

8. Identity & Access Management

Description: IAM lifecycle automation covering employee onboarding triggered via HiBob HR webhooks, user deactivation, Teramind monitoring license removal triggered via Okta webhooks, and compliance reporting on identity coverage gaps — users missing Cato network agent coverage and Okta accounts deprovisioned for over 90 days without cleanup.

Business problem solved: Identity hygiene — ensuring timely onboarding, timely deprovisioning, monitoring tool coverage, and stale account detection — is frequently deferred due to operational burden. This use case automates onboarding directly from the HR system alongside detection and reporting of IAM coverage gaps, reducing unauthorized access risk via orphaned accounts and delayed provisioning.

Key integrations: HiBob, Okta, Teramind, Cato Networks, Gmail, Google Workspace

Playbook Executions Type Category Subcategory
TM License removal 1 Event IAM Employee offboarding, Identity lifecycle automation
Deactive User 0 On-demand IAM Employee offboarding
Report - Users Missing Cato 0 On-demand IAM Access review & group mgmt
Report - Deprovisioned Okta Users over 90 days 0 On-demand IAM Access review & group mgmt
Hibob Onboarding 11 Event IAM Employee onboarding
Hibob Sync 1,049 Event IAM Employee onboarding, Identity sync & directory mgmt

9. Security Operations Reporting

Description: AI-powered reporting layer that monitors Blink automation health and delivers structured error reports to the security lead via Slack. A separate incident post-mortem workflow fetches relevant incident data from external sources, applies AI summarization, and posts a digestible briefing to the team.

Business problem solved: Security leads need continuous visibility into automation health and incident learnings without reading raw logs. This use case provides proactive, AI-generated summaries that keep the state of the security program immediately legible.

Key integrations: OpenAI, Slack, HTTP

Playbook Executions Type Category Subcategory
Report to Shachar 212 Event GRC Security metrics & reporting, Agentic SOC
Incident Post Digest 1 On-demand GRC Security metrics & reporting
New Workflow 0 Scheduled GRC Security metrics & reporting

10. Security Pack & Tooling Lifecycle

Description: Automated lifecycle management for the Claude AI security pack deployed via Kandji. Monitors the GitHub repository for new releases on a daily schedule, compares configuration deltas against current Sumo Logic match lists and Kandji state, applies updates, and distributes AI-generated release notes to the appropriate Slack channel by deployment ring.

Business problem solved: Keeping AI-assisted detection packs current typically requires manual tracking of releases and error-prone configuration updates. This use case automates the full update lifecycle, ensuring the latest detections are consistently deployed without analyst involvement.

Key integrations: GitHub, Kandji, Sumo Logic, OpenAI, HTTP

Playbook Executions Type Category Subcategory
Claude Pack Update Trigger 2 Scheduled Other DevOps & release automation
Claude Security Pack Updater 10 On-demand Other DevOps & release automation

11. Cloud Security Posture Management (Wiz)

Description: Real-time cloud posture monitoring via Wiz webhook events. When Wiz flags a posture issue involving exposed secrets, the workflow queries Wiz for full issue context and secret instance details, then delivers a structured alert to the security team's Slack channel.

Business problem solved: Cloud misconfigurations and exposed secrets can go unnoticed without continuous posture monitoring. This workflow streams Wiz posture findings directly into the security team's existing Slack-based response process, ensuring secret exposure issues are surfaced immediately rather than discovered during periodic reviews.

Key integrations: Wiz, Slack, OpenAI

Playbook Executions Type Category Subcategory
Wiz Posture Issue - Secret Alerting 0 Event Cloud Security CSPM ingest & triage
Agent Ability - Wiz GraphQL Query 580 On-demand Cloud Security CSPM ingest & triage
Create Ticket on Demand 0 On-demand Cloud Security CSPM ingest & triage
Agent Ability - Wiz GraphQL Query 0 On-demand Cloud Security CSPM ingest & triage

12. Cloud Infrastructure Investigation & Remediation

Description: On-demand AI-agent tooling for AWS environments — enabling arbitrary AWS CLI script execution and EC2 instance inventory lookups, plus a dedicated S3 bucket security analysis subflow that runs a purpose-built "Cloud Analyst" agent and reports findings to Slack.

Business problem solved: Cloud investigations traditionally require an analyst to manually run AWS CLI commands or console queries across accounts. This capability lets an AI agent execute cloud investigation and remediation actions directly, sharply reducing the time from suspicion to answer during cloud-related security investigations — already the single highest-volume automation in the environment.

Key integrations: AWS, Slack, Sumo Logic

Playbook Executions Type Category Subcategory
Agent Ability - AWS CLI 2,321 On-demand Cloud Security Config audit & remediation
Agent Ability - EC2 Describe Instances 0 On-demand Cloud Security Cloud asset coverage & inventory
Agent Ability - AWS CLI 0 On-demand Cloud Security Config audit & remediation
AWS S3 bucket subflow 0 On-demand (subflow) Cloud Security Cloud asset coverage & inventory
Sumo Trigger - S3BucketPublicPolicyChanged 0 Event Cloud Security Config audit & remediation, Cloud asset coverage & inventory

13. Vulnerability Management — SCA Critical Ticketing

Description: AI-powered triage of software composition analysis (SCA) findings. The workflow evaluates flagged dependency nodes for criticality using OpenAI, then loops through qualifying findings to create tracking tickets for remediation.

Business problem solved: SCA scan output is often voluminous and undifferentiated, burying critical vulnerabilities among low-priority findings. This workflow applies AI-based criticality assessment and automates ticket creation for the findings that matter most. A companion set of playbooks tracks AUTOMATIC_FIX tickets through to their linked pull requests and notifies the team in Slack once an automated fix agent completes, closing the loop from finding to remediated code.

Key integrations: OpenAI, Jira, GitHub, Slack

Playbook Executions Type Category Subcategory
SCA Critical Ticketing 20 On-demand Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Fetch AUTOMATIC_FIX tickets with PR link 0 On-demand Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Ticket Slack Notification 4 Event Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Ticket Slack Notification (APD) 0 Event Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Fetch AUTOMATIC_FIX tickets with PR link (APD) 0 On-demand Vulnerability Mgmt Vuln lifecycle prioritize & ticket

14. Agentic SOC — Interactive Case Assistant (Slack)

Description: A conversational, Slack-embedded AI assistant that lets analysts ask ad-hoc questions during an investigation, receive AI-recommended case-closure guidance, and communicate directly with affected end users — all without leaving Slack. A dedicated "User Communications Agent" drafts and sends user-facing messages, while supporting query tooling pulls context from Sumo Logic and Snowflake on demand via Slack slash commands.

Business problem solved: Mid-investigation questions and end-user communications typically require analysts to switch tools or manually track down data. This use case embeds AI-driven Q&A, case-closure recommendations, and user outreach directly into Slack's interactive components (buttons, forms, slash commands), keeping analysts in a single interface from question to resolution.

Key integrations: Slack, OpenAI, Sumo Logic, Snowflake, Blink Case Management

Playbook Executions Type Category Subcategory
SOC AI - Slack Interactivity 0 Event SOC Agentic SOC, Case mgmt & SOAR
SOC AI - Close Case 58 On-demand SOC Agentic SOC, Case mgmt & SOAR
SOC AI - Ask AI Question (Slack) 19 On-demand SOC Agentic SOC
Agent 2 Agent - User Communications 0 On-demand SOC Agentic SOC
New Workflow 0 On-demand SOC Agentic SOC
Slack Command 1 Event SOC Agentic SOC
New Workflow 0 On-demand SOC Agentic SOC
Slash Command Demo 0 On-demand SOC Agentic SOC

15. Database & Network Infrastructure Health Monitoring

Description: Snowflake-powered operational health monitoring covering database locking behavior and proxy performance. A high-frequency real-time check flags locking/blocking anomalies as they occur, a daily job summarizes lock activity against a refreshed baseline, and a separate daily report scores proxy health — all delivered as structured Slack alerts.

Business problem solved: Database lock contention and proxy degradation can silently erode application performance until they cause an outage. This use case gives the team continuous, automated visibility into infrastructure health via near-real-time and daily Snowflake-driven checks, surfacing anomalies in Slack before they escalate.

Key integrations: Snowflake, Slack

Playbook Executions Type Category Subcategory
Real-Time Locks / Blocks Anomaly Alerts 3,839 Scheduled Other IT/OT & network infra monitoring
DAILY LOCKING SUMMARY 40 Scheduled Other IT/OT & network infra monitoring
Proxy Score Report 29 Scheduled Other IT/OT & network infra monitoring

16. Financial Order Monitoring & Account Lookup

Description: Order-processing oversight combining a scheduled digest of recent orders with an AI-driven order analysis agent that reviews order data on demand and reports findings to Slack, backed by a direct account lookup tool against the production database.

Business problem solved: Reviewing order activity and looking up account details for investigation typically requires direct database access and manual cross-referencing. This use case automates recurring order reporting and gives the team an AI-assisted, Slack-native way to analyze order data and pull account context on demand.

Key integrations: MySQL, Slack, OpenAI

Playbook Executions Type Category Subcategory
Get Orders 10 Scheduled Other Financial & fraud operations
Order analysis via Slack 0 On-demand Other Financial & fraud operations
Account info 0 On-demand Other Customer registry & FinOps auto

17. WAF IP Blocking & Auto-Unblock

Description: On-demand and scheduled IP blocklist management for the web application firewall, backed by a Blink table tracking currently blocked IPs. Analysts can block or unblock a specific IP on demand or list the current blocklist, while a daily scheduled job automatically expires and unblocks IPs once their block window elapses.

Business problem solved: Manually tracking which IPs are blocked in the WAF and remembering to lift temporary blocks is error-prone, leading to either lingering unnecessary blocks or missed containment. This use case gives analysts a simple on-demand block/unblock/list interface while a scheduled job guarantees blocks expire automatically.

Key integrations: AWS, Blink Tables

Playbook Executions Type Category Subcategory
Block IP in WAF 3 On-demand SOC EDR containment & response
Unblock IP in WAF 3 On-demand SOC EDR containment & response
Daily WAF Unblock 20 Scheduled SOC EDR containment & response
List Blocked IPs 1 On-demand SOC EDR containment & response

18. AI Prompt Offence Investigation (Cato)

Description: Investigation pipeline for AI-app prompt policy violations ("offences") surfaced by Cato Networks. A dedicated "Cato Prompt Analyist" AI agent evaluates the flagged prompt and session, invoked either directly from the webhook-driven analysis flow or on demand — including a bulk mode that pulls existing cases and re-analyzes their AI prompt offences.

Business problem solved: As employees increasingly use AI tools, Cato's network visibility flags risky prompts (e.g., potential data exfiltration or policy violations), but assessing whether each flagged prompt is actually risky still required manual review. This use case automates that assessment with an AI agent and supports both real-time and retroactive bulk investigation.

Key integrations: Cato Networks, Blink Case Management, HTTP

Playbook Executions Type Category Subcategory
Main - Analyse AI Prompt 37 Event SOC Alert enrichment / IOC lookup, Agentic SOC
Analyse Cato AI Prompt 21 On-demand SOC Alert enrichment / IOC lookup
On Demand - Analyse Cato AI Prompt 16 On-demand SOC Alert enrichment / IOC lookup, Case mgmt & SOAR

19. Holdings Data Import & OFX Generation

Description: Slack-driven pipeline that converts uploaded holdings statement screenshots into structured data. A router listens for mentions in a dedicated ops channel and offers a menu of import purposes; when holdings import is selected, the uploaded image is passed to an AI vision model to extract holdings data, an analyst reviews and edits the extracted data through interactive Slack forms, and the confirmed data is compiled into an OFX file for downstream import.

Business problem solved: Manually transcribing customer holdings data from statement screenshots into a structured, importable format is slow and error-prone. This use case automates extraction with AI vision, keeps a human in the loop for verification via Slack, and outputs a ready-to-import OFX file — reducing a manual data-entry task to a guided review.

Key integrations: Slack, OpenAI

Playbook Executions Type Category Subcategory
CDI Ops Router 12 Event Other Customer registry & FinOps auto
Holdings Import 14 On-demand Other Customer registry & FinOps auto

Key Observations

Strengths

Mature agentic SOC pipeline. The alert triage flow — CrowdStrike and Sumo Logic ingestion → case deduplication → observable enrichment → AI summary → Slack delivery — is fully automated end-to-end. With 679 CrowdStrike detections and 442 process-alert executions over 12 months, this is the highest-volume and highest-value use case in the environment.

Slack-native SOC operations. With 1,532 incoming Slack interactions and 1,440 case-update syncs handled automatically, the team has made Slack the primary incident response interface — eliminating context-switching between the case management system and communication tools for routine operations.

AI deeply embedded across the security program. OpenAI is used not only for case summarization but also for phishing classification, DLP intent analysis, threat intel filtering, endpoint IDE investigation, case escalation briefings, and incident post-mortems. This indicates a sophisticated, AI-augmented security posture that goes well beyond basic automation.

Rich, custom enrichment library. Fifteen-plus enrichment playbooks cover every major observable type. The custom Pontera-specific enrichers (username/email via Sumo Logic, hostname via CrowdStrike) are actively running, demonstrating mature platform customization beyond out-of-the-box capabilities.

Proactive threat intelligence consumption. Automated monitoring of HaveIBeenPwned for breach data on organizational domains, combined with supply chain security RSS feeds (SocketSecurity) and community vulnerability research, provides a curated, AI-filtered intelligence stream without manual analyst monitoring.

Unique AI tooling automation. The Claude Security Pack Updater is a particularly sophisticated workflow — automating the lifecycle of an AI-powered security detection pack (release detection, config comparison, deployment, release notes) in a way that is rare among Blink customers.

Emerging agentic cloud security capability. New AI-agent tooling now enables autonomous AWS CLI execution and EC2/S3 investigation via a purpose-built "Cloud Analyst" agent — the AWS CLI tool alone has already executed 2,321 times, making it the single highest-volume automation in the environment. Combined with new Wiz-based posture alerting for exposed secrets, this marks the environment's expansion from pure SOC/EDR automation into cloud security posture management.

Multi-agent forensics network now operational. A new "Agent 2 Agent" tier lets the primary case-handling agent delegate forensics questions to vendor-specialized analyst agents — AWS, Google Workspace, Cato Networks, Sumo Logic, Okta, and Wiz — with 1,463 combined consultations in the last 12 months. Paired with a new direct-query layer (Okta log search at 2,307 executions, Cato Networks queries at 750, Wiz GraphQL queries at 580), this significantly deepens the platform's autonomous investigation depth across identity, network, and cloud domains.

New conversational Slack assistant for live investigations. A "SOC AI" tier now lets analysts ask ad-hoc questions and close cases directly from Slack (58 AI-recommended case closures, 19 ad-hoc Q&A sessions), backed by a dedicated user-communications agent for direct end-user outreach — extending the platform's AI footprint from background automation into a live, conversational analyst interface.

AI-driven case investigation now a high-volume core process. The new Main - Investigation playbook — which queries the case management system, evaluates conditions, pulls timeline events, and hands off to a "Post Investigation Triage Agent" before updating the case — has already run 324 times, and a new Sumologic WAF Alert flow adds a dedicated network forensics agent for WAF-triggered alerts (111 executions). Together these deepen the automated investigation layer introduced alongside the multi-agent forensics network.

Expansion into infrastructure health and business operations monitoring. Beyond security, Blink now automates database lock/block anomaly detection (3,839 real-time checks plus a daily summary) and proxy health scoring via Snowflake, alongside order-digest and account-lookup tooling for financial operations — signaling that the platform is being adopted as a general automation layer for the business, not solely for the SOC.

New network-layer containment capability. IP blocking and auto-unblocking in the WAF (27 combined on-demand executions plus 20 scheduled auto-unblock cycles) closes the gap between WAF alert investigation (Sumologic WAF Alert) and actual containment action, with a scheduled job guaranteeing temporary blocks expire automatically.

Emerging AI-usage governance. A new Cato-integrated pipeline (74 combined executions) evaluates AI-app prompts flagged as policy offences via a dedicated "Cato Prompt Analyist" agent, extending the platform's oversight from network and endpoint threats into GenAI usage risk.

Financial operations digitization via AI vision. The new Holdings Import pipeline (26 combined executions) uses AI vision to extract customer holdings data from uploaded screenshots, routes it through a Slack-based human review loop, and generates ready-to-import OFX files — automating a previously manual, error-prone data-entry process.

Gaps & Opportunities

Offboarding half of IAM lifecycle still dormant. The user deactivation, Cato coverage, and Okta deprovisioning playbooks all show 0 executions. Onboarding is now active — the new HiBob-triggered onboarding and sync playbooks run 11 and 1,049 times respectively — but the offboarding and coverage-reporting side of the tooling remains built but not yet operationally active. Wiring deactivation and deprovisioning to the same HiBob trigger is the most immediately addressable gap given the existing infrastructure.

Enrichment library underutilized. The general enrichment playbooks (IP/URL/hash enrichment via VirusTotal, AbuseIPDB, URLScan) all show 0 executions. This suggests the main triage pipeline currently routes through only the Pontera-specific enrichers, with the broader threat intel lookups not yet wired into the automated flow.

EDR containment not yet activated. CrowdStrike RTR (batch and single host) and endpoint quarantine playbooks exist but show 0 executions. Connecting these to the alert triage pipeline as automated response actions — triggered on confirmed high-severity detections — would complete the containment loop without analyst involvement.

Phishing email investigation incomplete. Init Email Investigation, Investigate Email - Search, and Investigate Email - Sandbox File all have 0 executions while the ingestion playbook runs 85 times per year. The new Agent Ability - Google List Gmail Messages tool (70 executions) now provides active mailbox search for investigations, partially closing this gap — but sandbox file analysis remains unused.

Vulnerability management coverage is just beginning. The new SCA Critical Ticketing workflow (20 executions) introduces AI-triaged, ticketed remediation for software composition analysis findings — a first step into vulnerability management. Broader coverage (CVE lookup, vulnerability scanner integration, patch lifecycle automation) is still missing, and given daily endpoint compliance scanning is already in place, there is a natural expansion path into fuller vulnerability prioritization.

Integration Ecosystem

The environment spans 20+ integrated platforms: CrowdStrike, Sumo Logic, Okta, Google Workspace / Gmail, Microsoft Entra ID, Slack, OpenAI, Teramind, Mitiga, Kandji, Cato Networks, Perception Point, VirusTotal, AbuseIPDB, URLScan, GitHub, HaveIBeenPwned, Monday.com, Wiz, AWS, HiBob, Snowflake, Jira, and MySQL.

This is a broad, mature integration footprint — signaling a security team that has actively unified disparate tools under automated orchestration rather than operating them in silos. The presence of Mitiga (cloud incident response), Teramind (DLP / insider threat), and Perception Point (email security) alongside the core CrowdStrike / Sumo Logic stack indicates a layered detection approach across endpoint, cloud, and human-layer threat vectors.

E New Integrations (detail) 33 added in last 30d

New Integrations Added - Last 30 Days

33 new connections
TenantIntegrationConnection NameAdded
Pontera slack my_slack_connection 2026-08-30
Pontera blink my_blink_connection 2026-08-21
Pontera github or_s_github_connection 2026-08-20
Pontera jira qa_jira 2026-08-12
Pontera jira cli_jira 2026-08-12
Pontera jira ops_jira 2026-08-11
Pontera jira pm_jira 2026-08-11
Pontera sumo-logic qa_sumologic 2026-08-11
Pontera sumo-logic ops_sumologic 2026-08-11
Pontera sumo-logic pm_sumologic 2026-08-11
Pontera sumo-logic cli_sumologic 2026-08-11
Pontera google-calendar qa_google_calendar 2026-08-11
Pontera gmail qa_gmail 2026-08-11
Pontera google-calendar ops_google_calendar 2026-08-11
Pontera gmail ops_gmail 2026-08-11
Pontera slack blinkops_ops 2026-08-11
Pontera google-drive pm_google_drive 2026-08-11
Pontera google-calendar pm_google_calendar 2026-08-11
Pontera gmail pm_gmail 2026-08-11
Pontera google-sheets pm_google_sheets 2026-08-11
Pontera google-docs pm_google_docs 2026-08-11
Pontera google-calendar cli_google_calendar 2026-08-11
Pontera gmail cli_gmail 2026-08-11
Pontera cato-networks ir_sensitive_cato 2026-08-11
Pontera jira apd_jira 2026-08-11
Pontera gmail apd_gmail 2026-08-11
Pontera google-calendar apd_google_calendar 2026-08-11
Pontera mysql my_mysql_connection_1 2026-08-09
Pontera jira my_jira_connection 2026-08-05
Pontera github my_github_connection 2026-08-05
Pontera jira my_jira_connection 2026-08-04
Pontera slack my_slack_connection 2026-08-04
Pontera snowflake my_snowflake_connection 2026-08-03