01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC — Alert Triage & SOAR Orchestration |
| 12.1% | 26 25 active |
| Case Management & Slack Synchronization |
| 5.7% | 9 9 active |
| Alert Enrichment & IOC Analysis |
| 46.5% | 50 50 active |
| Phishing Detection & Email Triage |
| 0.9% | 10 10 active |
| DLP Triage & Investigation |
| 0.0% | 1 1 active |
| Endpoint Hygiene & Compliance Scanning |
| 0.2% | 8 8 active |
| Threat Intelligence Ingest & Curation |
| 0.3% | 5 5 active |
| Identity & Access Management |
| 3.3% | 5 5 active |
| Security Operations Reporting |
| 2.1% | 2 2 active |
| Security Pack & Tooling Lifecycle |
| 0.5% | 2 2 active |
| Cloud Security Posture Management (Wiz) |
| 1.8% | 3 3 active |
| Cloud Infrastructure Investigation & Remediation |
| 7.2% | 4 4 active |
| Vulnerability Management — SCA Critical Ticketing |
| 0.1% | 5 5 active |
| Agentic SOC — Interactive Case Assistant (Slack) |
| 0.2% | 7 6 active |
| Database & Network Infrastructure Health Monitoring |
| 12.0% | 3 3 active |
| Financial Order Monitoring & Account Lookup |
| 0.0% | 3 3 active |
| WAF IP Blocking & Auto-Unblock |
| 0.1% | 4 4 active |
| AI Prompt Offence Investigation (Cato) |
| 0.2% | 3 3 active |
| Holdings Data Import & OFX Generation |
| 0.1% | 2 2 active |
| Total | 30,244 executions | 100% | 152 150 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature agentic SOC pipeline. The alert triage flow — CrowdStrike and Sumo Logic ingestion → case deduplication → observable enrichment → AI summary → Slack delivery — is fully automated end-to-end. With 679 CrowdStrike detections and 442 process-alert executions over 12 months, this is the highest-volume and highest-value use case in the environment.
Slack-native SOC operations. With 1,532 incoming Slack interactions and 1,440 case-update syncs handled automatically, the team has made Slack the primary incident response interface — eliminating context-switching between the case management system and communication tools for routine operations.
AI deeply embedded across the security program. OpenAI is used not only for case summarization but also for phishing classification, DLP intent analysis, threat intel filtering, endpoint IDE investigation, case escalation briefings, and incident post-mortems. This indicates a sophisticated, AI-augmented security posture that goes well beyond basic automation.
Rich, custom enrichment library. Fifteen-plus enrichment playbooks cover every major observable type. The custom Pontera-specific enrichers (username/email via Sumo Logic, hostname via CrowdStrike) are actively running, demonstrating mature platform customization beyond out-of-the-box capabilities.
Proactive threat intelligence consumption. Automated monitoring of HaveIBeenPwned for breach data on organizational domains, combined with supply chain security RSS feeds (SocketSecurity) and community vulnerability research, provides a curated, AI-filtered intelligence stream without manual analyst monitoring.
Unique AI tooling automation. The Claude Security Pack Updater is a particularly sophisticated workflow — automating the lifecycle of an AI-powered security detection pack (release detection, config comparison, deployment, release notes) in a way that is rare among Blink customers.
Emerging agentic cloud security capability. New AI-agent tooling now enables autonomous AWS CLI execution and EC2/S3 investigation via a purpose-built "Cloud Analyst" agent — the AWS CLI tool alone has already executed 2,321 times, making it the single highest-volume automation in the environment. Combined with new Wiz-based posture alerting for exposed secrets, this marks the environment's expansion from pure SOC/EDR automation into cloud security posture management.
Multi-agent forensics network now operational. A new "Agent 2 Agent" tier lets the primary case-handling agent delegate forensics questions to vendor-specialized analyst agents — AWS, Google Workspace, Cato Networks, Sumo Logic, Okta, and Wiz — with 1,463 combined consultations in the last 12 months. Paired with a new direct-query layer (Okta log search at 2,307 executions, Cato Networks queries at 750, Wiz GraphQL queries at 580), this significantly deepens the platform's autonomous investigation depth across identity, network, and cloud domains.
New conversational Slack assistant for live investigations. A "SOC AI" tier now lets analysts ask ad-hoc questions and close cases directly from Slack (58 AI-recommended case closures, 19 ad-hoc Q&A sessions), backed by a dedicated user-communications agent for direct end-user outreach — extending the platform's AI footprint from background automation into a live, conversational analyst interface.
AI-driven case investigation now a high-volume core process. The new Main - Investigation playbook — which queries the case management system, evaluates conditions, pulls timeline events, and hands off to a "Post Investigation Triage Agent" before updating the case — has already run 324 times, and a new Sumologic WAF Alert flow adds a dedicated network forensics agent for WAF-triggered alerts (111 executions). Together these deepen the automated investigation layer introduced alongside the multi-agent forensics network.
Expansion into infrastructure health and business operations monitoring. Beyond security, Blink now automates database lock/block anomaly detection (3,839 real-time checks plus a daily summary) and proxy health scoring via Snowflake, alongside order-digest and account-lookup tooling for financial operations — signaling that the platform is being adopted as a general automation layer for the business, not solely for the SOC.
New network-layer containment capability. IP blocking and auto-unblocking in the WAF (27 combined on-demand executions plus 20 scheduled auto-unblock cycles) closes the
gap between WAF alert investigation (Sumologic WAF Alert) and actual containment action, with a scheduled job guaranteeing temporary blocks expire automatically.
Emerging AI-usage governance. A new Cato-integrated pipeline (74 combined executions) evaluates AI-app prompts flagged as policy offences via a dedicated "Cato Prompt Analyist" agent, extending the platform's oversight from network and endpoint threats into GenAI usage risk.
Financial operations digitization via AI vision. The new Holdings Import pipeline (26 combined executions) uses AI vision to extract customer holdings data from uploaded screenshots, routes it through a Slack-based human review loop, and generates ready-to-import OFX files — automating a previously manual, error-prone data-entry process.
Gaps & Opportunities
Offboarding half of IAM lifecycle still dormant. The user deactivation, Cato coverage, and Okta deprovisioning playbooks all show 0 executions. Onboarding is now active — the new HiBob-triggered onboarding and sync playbooks run 11 and 1,049 times respectively — but the offboarding and coverage-reporting side of the tooling remains built but not yet operationally active. Wiring deactivation and deprovisioning to the same HiBob trigger is the most immediately addressable gap given the existing infrastructure.
Enrichment library underutilized. The general enrichment playbooks (IP/URL/hash enrichment via VirusTotal, AbuseIPDB, URLScan) all show 0 executions. This suggests the main triage pipeline currently routes through only the Pontera-specific enrichers, with the broader threat intel lookups not yet wired into the automated flow.
EDR containment not yet activated. CrowdStrike RTR (batch and single host) and endpoint quarantine playbooks exist but show 0 executions. Connecting these to the alert triage pipeline as automated response actions — triggered on confirmed high-severity detections — would complete the containment loop without analyst involvement.
Phishing email investigation incomplete. Init Email Investigation, Investigate Email - Search, and Investigate Email - Sandbox File all have 0 executions while the ingestion playbook runs 85 times per year. The new Agent Ability - Google List Gmail Messages tool (70 executions) now provides active mailbox search for investigations, partially closing this gap — but sandbox file analysis remains unused.
Vulnerability management coverage is just beginning. The new SCA Critical Ticketing workflow (20 executions) introduces AI-triaged, ticketed remediation for software composition analysis findings — a first step into vulnerability management. Broader coverage (CVE lookup, vulnerability scanner integration, patch lifecycle automation) is still missing, and given daily endpoint compliance scanning is already in place, there is a natural expansion path into fuller vulnerability prioritization.
Integration Ecosystem
The environment spans 20+ integrated platforms: CrowdStrike, Sumo Logic, Okta, Google Workspace / Gmail, Microsoft Entra ID, Slack, OpenAI, Teramind, Mitiga, Kandji, Cato Networks, Perception Point, VirusTotal, AbuseIPDB, URLScan, GitHub, HaveIBeenPwned, Monday.com, Wiz, AWS, HiBob, Snowflake, Jira, and MySQL.
This is a broad, mature integration footprint — signaling a security team that has actively unified disparate tools under automated orchestration rather than operating them in silos. The presence of Mitiga (cloud incident response), Teramind (DLP / insider threat), and Perception Point (email security) alongside the core CrowdStrike / Sumo Logic stack indicates a layered detection approach across endpoint, cloud, and human-layer threat vectors.
A Case Management 897 cases (12m) | MTTR 2d 2h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Incident Response | 895 | 895 | 831 | 2d 2h |
| SecOps | 2 | 2 | 0 | N/A |
B AI Agents 18 active | 8,720 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | AWS Bucket Analyst | SecOps | 4,482 | 0 | 40,783,413 |
| 2 | Enrichment Agent | Incident Response | 989 | 483 | 50,413,857 |
| 3 | Sumologic Agent | Incident Response | 937 | 684 | 1,043,465,532 |
| 4 | AWS Agent | Incident Response | 542 | 249 | 136,123,655 |
| 5 | Okta Agent | Incident Response | 422 | 277 | 224,396,198 |
| Workspace | Tasks (12m) |
|---|---|
| SecOps | 4,482 |
| Incident Response | 4,146 |
| toms@pontera.com | 56 |
| Sensitive | 27 |
| guy.sheffer@pontera.com | 9 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Device Compliance | 0 | 0 |
| 2 | Case Management | 0 | 0 |
| 3 | Dashboard1 | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 19 use cases | 32,452 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| AWS CLI commands executed autonomously by AI cloud agent | 2,321 | Agent Ability - AWS CLI |
| CrowdStrike detections ingested and processed | 679 | Ingestion - Crowdstrike |
| Analyst Slack interactions handled automatically | 1,532 | Slack Subscription - Incoming |
| Case status updates synchronized to Slack | 1,440 | Slack Sync - Case Updated |
| Security alerts auto-triaged end-to-end | 460 | Process Alert |
| Multi-vendor alerts deduplicated and correlated | 305 | Check and Record Alert |
| Resolved cases closed and reflected in Sumo Logic | 240 | Sumologic Sync - Case Closed |
| New cases opened with dedicated Slack channels | 223 | Slack Sync - Case Created |
| Sumo Logic insights closed via case workflow | 188 | Sumologic Sync - Insight Closed |
| Sumo Logic insights ingested and case-correlated | 186 | Alert Ingestion - Sumologic Insights |
| Automation error reports delivered to security lead | 212 | Report to Shachar |
| Security-inbox emails automatically triaged | 85 | Ingestion - Mail to security@pontera.com |
| Email attachment investigations processed | 45 | Main - Bulk File Upload |
| Username/email observables enriched | 47 | Enrich - Username/Email - Pontera |
| Hostname observables enriched | 44 | Enrich - Hostname - Pontera |
| Google Workspace admin activities investigated by AI agent | 75 | Agent Ability - Google List Admin Activities |
| Gmail messages searched for phishing investigation | 70 | Agent Ability - Google List Gmail Messages |
| Gmail messages retrieved for phishing investigation | 102 | Agent Ability - Google Get Gmail Message |
| Device policy compliance scans executed | 30 | Scanner - Scan Dev Devices for Policy Violation |
| Data breach notifications processed | 25 | HaveIBeenPwned RSS |
| File integrity alerts auto-investigated | 25 | Incoming - File Integrity Alert |
| SCA critical vulnerabilities triaged and ticketed | 20 | SCA Critical Ticketing |
| DLP incidents investigated with AI analysis | 18 | Main - Teramind DLP Investigation |
| Supply chain security articles assessed | 15 | SocketSecurity RSS |
| Security pack version updates automated | 10 | Claude Security Pack Updater |
| Cloud incident enrichments from Mitiga | 7 | Response - Mitiga Enrichment |
| Phishing alerts fully investigated | 8 | Main - Phishing |
| Cases escalated with AI-generated briefings | 5 | Main - Escalate |
| Incident post-mortem summaries posted | 1 | Incident Post Digest |
| Okta security logs queried autonomously by AI forensics agent | 2,307 | Agent Ability - Okta Get Logs |
| Cato Networks queries executed autonomously by AI network agent | 750 | Agent Ability - Cato Query |
| Wiz cloud security graph queries executed autonomously by AI agent | 580 | Agent Ability - Wiz GraphQL Query |
| Sumo Logic forensics agent consultations during case investigations | 793 | Agent 2 Agent - Sumologic Agent |
| Okta forensics agent consultations during case investigations | 365 | Agent 2 Agent - Okta Agent |
| Alert case data synchronized to Monday.com templates | 328 | Template Processing - Main |
| Okta user identities looked up by AI agent | 318 | Agent Ability - Okta Get User By Email |
| Case enrichment data retrieved by AI agent | 306 | Agent Ability - Get Enrichments |
| AWS forensics agent consultations during case investigations | 176 | Agent 2 Agent - AWS Agent |
| Google Workspace forensics agent consultations during case investigations | 49 | Agent 2 Agent - Google Agent |
| Cato Networks forensics agent consultations during case investigations | 47 | Agent 2 Agent - Cato Agent |
| Wiz forensics agent consultations during case investigations | 33 | Agent 2 Agent - Wiz Agent |
| New alert cases ingested from IR webhook source | 7 | Alerts from IR |
| HR data sync events processed from HiBob | 1,049 | Hibob Sync |
| Alert observables enriched via SOC AI orchestrator | 332 | SOC AI - Enrich Alert Observables |
| AWS entity enrichments delivered to cases | 108 | Enrich - AWS |
| Cases closed via AI-recommended Slack workflow | 58 | SOC AI - Close Case |
| Ad-hoc AI Q&A sessions handled via Slack | 19 | SOC AI - Ask AI Question (Slack) |
| HiBob onboarding events processed automatically | 11 | Hibob Onboarding |
| Real-time database lock/block anomaly checks executed | 3,839 | Real-Time Locks / Blocks Anomaly Alerts |
| AI-triaged case investigations completed | 324 | Main - Investigation |
| WAF alerts investigated by AI network forensics agent | 111 | Sumologic WAF Alert |
| Proxy score reports delivered to Slack | 29 | Proxy Score Report |
| Daily database locking summary reports generated | 40 | DAILY LOCKING SUMMARY |
| Order digest reports delivered to Slack | 10 | Get Orders |
| Automatic-fix ticket completion notifications sent to Slack | 4 | Ticket Slack Notification |
| Malicious IPs blocked in WAF | 3 | Block IP in WAF |
| IPs unblocked from WAF | 3 | Unblock IP in WAF |
| Scheduled WAF auto-unblock cycles executed | 20 | Daily WAF Unblock |
| Blocked-IP list reports generated | 1 | List Blocked IPs |
| AI-flagged prompt offences analyzed via Cato agent | 37 | Main - Analyse AI Prompt |
| On-demand Cato AI-prompt offence investigations triggered | 21 | Analyse Cato AI Prompt |
| Cases bulk re-analyzed for AI prompt offences | 16 | On Demand - Analyse Cato AI Prompt |
| Customer holdings documents imported and converted to OFX | 14 | Holdings Import |
| Holdings import requests routed from Slack | 12 | CDI Ops Router |
Use Case Summary
| # | Use Case | Category | Subcategory | Playbooks |
|---|---|---|---|---|
| 1 | Agentic SOC — Alert Triage & SOAR Orchestration | SOC | Agentic SOC, Case mgmt & SOAR, SIEM & log pipeline monitoring | 33 |
| 2 | Case Management & Slack Synchronization | SOC | Case mgmt & SOAR, Agentic SOC | 10 |
| 3 | Alert Enrichment & IOC Analysis | SOC | Alert enrichment / IOC lookup | 77 |
| 4 | Phishing Detection & Email Triage | SOC | Phishing detection & response | 10 |
| 5 | DLP Triage & Investigation | GRC | DLP triage & exposure resp | 1 |
| 6 | Endpoint Hygiene & Compliance Scanning | Other | Endpoint hygiene & MDM ops, EDR containment & response | 11 |
| 7 | Threat Intelligence Ingest & Curation | SOC | Threat intel ingest & curation | 5 |
| 8 | Identity & Access Management | IAM | Employee onboarding, Employee offboarding, Access review & group mgmt, Identity lifecycle automation | 6 |
| 9 | Security Operations Reporting | GRC | Security metrics & reporting, Agentic SOC | 3 |
| 10 | Security Pack & Tooling Lifecycle | Other | DevOps & release automation | 2 |
| 11 | Cloud Security Posture Management (Wiz) | Cloud Security | CSPM ingest & triage | 4 |
| 12 | Cloud Infrastructure Investigation & Remediation | Cloud Security | Cloud asset coverage & inventory, Config audit & remediation | 5 |
| 13 | Vulnerability Management — SCA Critical Ticketing | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket | 5 |
| 14 | Agentic SOC — Interactive Case Assistant (Slack) | SOC | Agentic SOC, Case mgmt & SOAR | 8 |
| 15 | Database & Network Infrastructure Health Monitoring | Other | IT/OT & network infra monitoring | 3 |
| 16 | Financial Order Monitoring & Account Lookup | Other | Financial & fraud operations, Customer registry & FinOps auto | 3 |
| 17 | WAF IP Blocking & Auto-Unblock | SOC | EDR containment & response | 4 |
| 18 | AI Prompt Offence Investigation (Cato) | SOC | Alert enrichment / IOC lookup, Agentic SOC | 3 |
| 19 | Holdings Data Import & OFX Generation | Other | Customer registry & FinOps auto | 2 |
Use Cases
1. Agentic SOC — Alert Triage & SOAR Orchestration
Description: End-to-end automated alert processing pipeline that ingests detections from CrowdStrike and Sumo Logic, deduplicates and correlates events into cases, enriches all observables, applies AI-powered response routing, and delivers analyst-ready summaries — without requiring manual first-pass triage.
Business problem solved: Security teams are overwhelmed by alert volume across multiple detection sources. This use case eliminates manual triage by automating the full journey from raw alert to enriched, deduplicated, AI-summarized case ready for analyst action.
Key integrations: CrowdStrike, Sumo Logic, Blink Case Management, OpenAI, Slack, Monday.com, AWS, Google Workspace, Cato Networks, Okta, Wiz
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Process Alert | 442 | Event | SOC | Agentic SOC, Case mgmt & SOAR |
| Ingestion - Crowdstrike | 679 | Event | SOC | SIEM & log pipeline monitoring |
| Alert Ingestion - Sumologic Insights | 186 | Event | SOC | SIEM & log pipeline monitoring |
| Check and Record Alert | 305 | On-demand | SOC | Case mgmt & SOAR |
| Main - Escalate | 5 | On-demand | SOC | Agentic SOC, Case mgmt & SOAR |
| Subflow - Response - Main Router | 431 | On-demand (subflow) | SOC | Agentic SOC |
| Subflow - Enrich Observables - Main Router | 376 | On-demand (subflow) | SOC | Alert enrichment / IOC lookup |
| Subflow - Generate Summery | 438 | On-demand (subflow) | SOC | Agentic SOC |
| Subflow - Update Enrichment Data | 66 | On-demand (subflow) | SOC | Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | 14 | On-demand (subflow) | SOC | Case mgmt & SOAR |
| Recovery - Handle Unprocessed Alerts | 0 | On-demand | SOC | Case mgmt & SOAR |
| Error Handling - Send Error Notification Email | 0 | On-demand | SOC | Case mgmt & SOAR |
| SOC AI - Generate Slack Post | 1,084 | On-demand (subflow) | SOC | Agentic SOC |
| Subflow - Response - Main Router | 1 | On-demand (subflow) | SOC | Agentic SOC |
| Error Handling - Send Error Notification Email | 0 | On-demand | SOC | Case mgmt & SOAR |
| Subflow - Enrich Observables - Main Router | 1 | On-demand (subflow) | SOC | Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | 0 | On-demand (subflow) | SOC | Case mgmt & SOAR |
| Simulate Multiple Alerts from Different Sources | 0 | On-demand | SOC | Agentic SOC, Case mgmt & SOAR |
| Simulate Crowdstrike Alert | 0 | On-demand | SOC | Agentic SOC, Case mgmt & SOAR |
| Process Alert | 18 | Event | SOC | Agentic SOC, Case mgmt & SOAR |
| Recovery - Handle Unprocessed Alerts | 0 | On-demand | SOC | Case mgmt & SOAR |
| Agent 2 Agent - AWS Agent | 176 | On-demand | SOC | Agentic SOC |
| Agent 2 Agent - Google Agent | 49 | On-demand | SOC | Agentic SOC |
| Agent 2 Agent - Cato Agent | 47 | On-demand | SOC | Agentic SOC |
| Agent 2 Agent - Sumologic Agent | 793 | On-demand | SOC | Agentic SOC |
| Agent 2 Agent - Okta Agent | 365 | On-demand | SOC | Agentic SOC |
| Agent 2 Agent - Wiz Agent | 33 | On-demand | SOC | Agentic SOC |
| Alerts from IR | 7 | Event | SOC | Agentic SOC, Case mgmt & SOAR |
| Template Processing - Main | 328 | On-demand | SOC | Agentic SOC, Case mgmt & SOAR |
| Fix Templates | 0 | On-demand | SOC | Case mgmt & SOAR |
| Main - Investigation | 324 | On-demand | SOC | Agentic SOC, Case mgmt & SOAR |
| Sumologic WAF Alert | 111 | Event | SOC | Agentic SOC, Case mgmt & SOAR |
| Build Sumo Rules | 0 | On-demand | SOC | SIEM & log pipeline monitoring |
2. Case Management & Slack Synchronization
Description: Bi-directional synchronization layer between Blink case management and Slack. When a new case opens, a dedicated Slack channel is created and populated with an AI-generated briefing. As case fields evolve (status, severity, summary), Slack messages update in real time. Analyst replies in Slack feed back into the case. When cases close, Sumo Logic insights are updated accordingly.
Business problem solved: SOC analysts spend significant time context-switching between case management systems and communication tools. This use case makes Slack the single operational interface for incident response, eliminating manual status updates and keeping the entire team in sync automatically.
Key integrations: Slack, Blink Case Management, Sumo Logic, OpenAI
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Slack Subscription - Incoming | 1,532 | Event | SOC | Case mgmt & SOAR |
| Slack Sync - Case Updated | 1,440 | Event | SOC | Case mgmt & SOAR |
| Slack Sync - Case Created | 223 | On-demand | SOC | Case mgmt & SOAR, Agentic SOC |
| Sumologic Sync - Case Closed | 240 | Event | SOC | Case mgmt & SOAR, SIEM & log pipeline monitoring |
| Sumologic Sync - Insight Closed | 188 | Event | SOC | SIEM & log pipeline monitoring |
| Slack Interactivity - Main | 55 | Event | SOC | Case mgmt & SOAR |
| Utility - Close Stale Cases | 0 | On-demand | SOC | Case mgmt & SOAR |
| Utility - Close Stale Cases | 0 | On-demand | SOC | Case mgmt & SOAR |
| Find Cases to Merge | 0 | On-demand | SOC | Case mgmt & SOAR |
| USE WITH CARE - Reset Case Management Environment | 0 | On-demand | SOC | Case mgmt & SOAR |
3. Alert Enrichment & IOC Analysis
Description: Comprehensive observable enrichment library covering IPs, URLs, domains, hashes, hostnames, and user identities across multiple threat intelligence and identity sources. Custom enrichment pipelines pull context specific to the organization's environment from Sumo Logic and CrowdStrike, augmenting standard threat feeds. Utility playbooks manage the lifecycle of observable-to-alert relationships within the case management system.
Business problem solved: Manual enrichment of each observable in an alert is the most time-consuming part of triage. This library provides automated, on-demand context for every observable type — so analysts begin investigation with full context rather than spending time gathering it from disparate tools.
Key integrations: AbuseIPDB, VirusTotal, URLScan, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Sumo Logic, Mitiga, Whois, Cato Networks, AWS, Blink Case Management
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Enrich - Username/Email - Pontera | 47 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Hostname - Pontera | 44 | On-demand | SOC | Alert enrichment / IOC lookup |
| Response - Mitiga Enrichment | 7 | On-demand | SOC | Alert enrichment / IOC lookup |
| Subflow - Sumologic Cato Search | 5 | On-demand (subflow) | SOC | Alert enrichment / IOC lookup |
| Subflow - Crowdstrike Search | 4 | On-demand (subflow) | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Okta | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Github | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Okta Search for User Activity | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | 0 | On-demand | Vulnerability Mgmt | CVE lookup & remediation |
| Table Action - Validate Observables Extraction Template | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - Find Similar Cases Based on Observables | 0 | On-demand | SOC | Case mgmt & SOAR |
| Utility - Update Enrichment | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - Set Or Update Observable Relation | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - List Observable Alert Relations | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - List Alert Observable Relations | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - Delete Observable Relation | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Recovery - Enrich Non-Enriched Observables | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Tool - Query Sumo | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Google List Admin Activities | 75 | On-demand | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 0 | On-demand (subflow) | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - Update Enrichment | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Recovery - Enrich Non-Enriched Observables | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - Delete Observable Relation | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Github | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Username - Github | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | 0 | On-demand | Vulnerability Mgmt | CVE lookup & remediation |
| Analyze URL with URLScan | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Okta Search for User Activity | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information Using Okta | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - Set Or Update Observable Relation | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - List Observable Alert Relations | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - List Alert Observable Relations | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Utility - Find Similar Cases Based on Observables | 0 | On-demand | SOC | Case mgmt & SOAR |
| Table Action - Validate Observables Extraction Template | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Cato Query | 750 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Get Enrichments | 306 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Okta Get Logs | 2,307 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Okta Get User By Email | 318 | On-demand | SOC | Alert enrichment / IOC lookup |
| Enrich - AWS | 108 | On-demand | SOC | Alert enrichment / IOC lookup |
| New Workflow 2 | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Find Cato AI Session ID | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
| SOC AI - Enrich Alert Observables | 332 | On-demand | SOC | Alert enrichment / IOC lookup |
| Agent Ability - Sumologic Query | 0 | On-demand | SOC | Alert enrichment / IOC lookup |
4. Phishing Detection & Email Triage
Description: Automated phishing response pipeline covering the full investigation lifecycle: monitors the security inbox for inbound mail, uses AI to classify intent and extract indicators, queries Perception Point for known phishing campaigns by subject and sender, investigates attachments, and updates the case with a verdict and recommended action.
Business problem solved: Phishing reports from users and security-inbox emails are high-volume and require rapid first-response to contain threats. This use case eliminates manual triage of email-based threats, enabling faster analyst focus on confirmed incidents.
Key integrations: Google Workspace, Gmail, OpenAI, Slack, Blink Case Management, Perception Point
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Ingestion - Mail to security@pontera.com | 85 | Event | SOC | Phishing detection & response |
| Main - Bulk File Upload | 45 | On-demand | SOC | Phishing detection & response |
| Main - Phishing | 8 | On-demand | SOC | Phishing detection & response |
| Init Email Investigation | 0 | On-demand | SOC | Phishing detection & response |
| Investigate Email - Search | 0 | On-demand | SOC | Phishing detection & response |
| Investigate Email - Sandbox File | 0 | On-demand | SOC | Phishing detection & response |
| Agent Ability - Google List Gmail Messages | 70 | On-demand | SOC | Phishing detection & response |
| Agent Ability - Google Get Gmail Message | 102 | On-demand | SOC | Phishing detection & response |
| Response Subflow - Phishing | 0 | On-demand (subflow) | SOC | Phishing detection & response |
| Agent Ability - Analyze Drive File | 0 | On-demand | SOC | Phishing detection & response |
5. DLP Triage & Investigation
Description: Automated investigation workflow triggered by Teramind DLP alerts. Cross-references the flagged activity against Google Workspace admin logs and Sumo Logic Cato network logs, applies AI reasoning to determine intent and risk level, and delivers a structured finding to Slack and the case record.
Business problem solved: DLP alerts for data exfiltration require correlation across email, network, and endpoint data — a manual process that takes analysts hours. This workflow automates the full correlation and delivers a contextualized verdict in minutes.
Key integrations: Teramind, Google Admin Console, Sumo Logic, OpenAI, Slack, Blink Case Management
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Main - Teramind DLP Investigation | 18 | On-demand | GRC | DLP triage & exposure resp |
6. Endpoint Hygiene & Compliance Scanning
Description: Automated endpoint security posture management combining scheduled policy compliance scans (CrowdStrike + Kandji) with real-time file integrity monitoring. Device inventory and compliance state are tracked across both macOS (Kandji) and Windows (CrowdStrike) endpoints; violations trigger investigation workflows. Remote script execution via CrowdStrike RTR and endpoint quarantine capabilities enable rapid containment.
Business problem solved: Maintaining continuous endpoint compliance visibility across a mixed-device fleet is operationally intensive. This use case automates daily scans, anomaly detection, and targeted remediation — reducing drift between security policy and endpoint state.
Key integrations: CrowdStrike, Kandji, OpenAI, Blink Case Management
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Scanner - Scan Dev Devices for Policy Violation | 30 | Scheduled | Other | Endpoint hygiene & MDM ops |
| Incoming - File Integrity Alert | 25 | Event | Other | Endpoint hygiene & MDM ops |
| Kanji IDE | 2 | On-demand | Other | Endpoint hygiene & MDM ops |
| Main - Device Compliance | 0 | On-demand | Other | Endpoint hygiene & MDM ops |
| CrowdStrike RTR to a Batch of Hosts | 0 | On-demand | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | 0 | On-demand | SOC | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | On-demand | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | 0 | On-demand | SOC | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | On-demand | SOC | EDR containment & response |
| Response Subflow - Malware | 0 | On-demand (subflow) | SOC | EDR containment & response |
| CrowdStrike RTR to a Single Host | 0 | On-demand | SOC | EDR containment & response |
7. Threat Intelligence Ingest & Curation
Description: Automated threat intelligence pipeline monitoring curated RSS sources — HaveIBeenPwned for credential breach data relevant to organizational domains, SocketSecurity for supply chain security signals, and community vulnerability research. Entries are assessed by AI for applicability, and relevant findings are delivered to the security team via Slack. A GitHub code search subflow supports IOC hunting across public repositories.
Business problem solved: Security teams struggle to keep pace with the volume of threat intelligence published daily. This use case provides a filtered, AI-curated signal feed ensuring relevant threats — especially credential breaches and supply chain risks — reach the team without manual monitoring.
Key integrations: RSS, HTTP, OpenAI, Slack, HaveIBeenPwned API, GitHub
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| HaveIBeenPwned RSS | 25 | Event | SOC | Threat intel ingest & curation |
| SocketSecurity RSS | 15 | Event | SOC | Threat intel ingest & curation |
| Automated Scan Bouncer | 9 | On-demand | SOC | Threat intel ingest & curation |
| ramimac TeampPCP RSS | 2 | Event | SOC | Threat intel ingest & curation |
| Subflow - Github Code Search | 0 | On-demand (subflow) | SOC | Threat intel ingest & curation |
8. Identity & Access Management
Description: IAM lifecycle automation covering employee onboarding triggered via HiBob HR webhooks, user deactivation, Teramind monitoring license removal triggered via Okta webhooks, and compliance reporting on identity coverage gaps — users missing Cato network agent coverage and Okta accounts deprovisioned for over 90 days without cleanup.
Business problem solved: Identity hygiene — ensuring timely onboarding, timely deprovisioning, monitoring tool coverage, and stale account detection — is frequently deferred due to operational burden. This use case automates onboarding directly from the HR system alongside detection and reporting of IAM coverage gaps, reducing unauthorized access risk via orphaned accounts and delayed provisioning.
Key integrations: HiBob, Okta, Teramind, Cato Networks, Gmail, Google Workspace
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| TM License removal | 1 | Event | IAM | Employee offboarding, Identity lifecycle automation |
| Deactive User | 0 | On-demand | IAM | Employee offboarding |
| Report - Users Missing Cato | 0 | On-demand | IAM | Access review & group mgmt |
| Report - Deprovisioned Okta Users over 90 days | 0 | On-demand | IAM | Access review & group mgmt |
| Hibob Onboarding | 11 | Event | IAM | Employee onboarding |
| Hibob Sync | 1,049 | Event | IAM | Employee onboarding, Identity sync & directory mgmt |
9. Security Operations Reporting
Description: AI-powered reporting layer that monitors Blink automation health and delivers structured error reports to the security lead via Slack. A separate incident post-mortem workflow fetches relevant incident data from external sources, applies AI summarization, and posts a digestible briefing to the team.
Business problem solved: Security leads need continuous visibility into automation health and incident learnings without reading raw logs. This use case provides proactive, AI-generated summaries that keep the state of the security program immediately legible.
Key integrations: OpenAI, Slack, HTTP
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Report to Shachar | 212 | Event | GRC | Security metrics & reporting, Agentic SOC |
| Incident Post Digest | 1 | On-demand | GRC | Security metrics & reporting |
| New Workflow | 0 | Scheduled | GRC | Security metrics & reporting |
10. Security Pack & Tooling Lifecycle
Description: Automated lifecycle management for the Claude AI security pack deployed via Kandji. Monitors the GitHub repository for new releases on a daily schedule, compares configuration deltas against current Sumo Logic match lists and Kandji state, applies updates, and distributes AI-generated release notes to the appropriate Slack channel by deployment ring.
Business problem solved: Keeping AI-assisted detection packs current typically requires manual tracking of releases and error-prone configuration updates. This use case automates the full update lifecycle, ensuring the latest detections are consistently deployed without analyst involvement.
Key integrations: GitHub, Kandji, Sumo Logic, OpenAI, HTTP
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Claude Pack Update Trigger | 2 | Scheduled | Other | DevOps & release automation |
| Claude Security Pack Updater | 10 | On-demand | Other | DevOps & release automation |
11. Cloud Security Posture Management (Wiz)
Description: Real-time cloud posture monitoring via Wiz webhook events. When Wiz flags a posture issue involving exposed secrets, the workflow queries Wiz for full issue context and secret instance details, then delivers a structured alert to the security team's Slack channel.
Business problem solved: Cloud misconfigurations and exposed secrets can go unnoticed without continuous posture monitoring. This workflow streams Wiz posture findings directly into the security team's existing Slack-based response process, ensuring secret exposure issues are surfaced immediately rather than discovered during periodic reviews.
Key integrations: Wiz, Slack, OpenAI
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Wiz Posture Issue - Secret Alerting | 0 | Event | Cloud Security | CSPM ingest & triage |
| Agent Ability - Wiz GraphQL Query | 580 | On-demand | Cloud Security | CSPM ingest & triage |
| Create Ticket on Demand | 0 | On-demand | Cloud Security | CSPM ingest & triage |
| Agent Ability - Wiz GraphQL Query | 0 | On-demand | Cloud Security | CSPM ingest & triage |
12. Cloud Infrastructure Investigation & Remediation
Description: On-demand AI-agent tooling for AWS environments — enabling arbitrary AWS CLI script execution and EC2 instance inventory lookups, plus a dedicated S3 bucket security analysis subflow that runs a purpose-built "Cloud Analyst" agent and reports findings to Slack.
Business problem solved: Cloud investigations traditionally require an analyst to manually run AWS CLI commands or console queries across accounts. This capability lets an AI agent execute cloud investigation and remediation actions directly, sharply reducing the time from suspicion to answer during cloud-related security investigations — already the single highest-volume automation in the environment.
Key integrations: AWS, Slack, Sumo Logic
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Agent Ability - AWS CLI | 2,321 | On-demand | Cloud Security | Config audit & remediation |
| Agent Ability - EC2 Describe Instances | 0 | On-demand | Cloud Security | Cloud asset coverage & inventory |
| Agent Ability - AWS CLI | 0 | On-demand | Cloud Security | Config audit & remediation |
| AWS S3 bucket subflow | 0 | On-demand (subflow) | Cloud Security | Cloud asset coverage & inventory |
| Sumo Trigger - S3BucketPublicPolicyChanged | 0 | Event | Cloud Security | Config audit & remediation, Cloud asset coverage & inventory |
13. Vulnerability Management — SCA Critical Ticketing
Description: AI-powered triage of software composition analysis (SCA) findings. The workflow evaluates flagged dependency nodes for criticality using OpenAI, then loops through qualifying findings to create tracking tickets for remediation.
Business problem solved: SCA scan output is often voluminous and undifferentiated, burying critical vulnerabilities among low-priority findings. This workflow applies AI-based criticality assessment and automates ticket creation for the findings that matter most. A companion set of playbooks tracks AUTOMATIC_FIX tickets through to their linked pull requests and notifies the team in Slack once an automated fix agent completes, closing the loop from finding to remediated code.
Key integrations: OpenAI, Jira, GitHub, Slack
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| SCA Critical Ticketing | 20 | On-demand | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Fetch AUTOMATIC_FIX tickets with PR link | 0 | On-demand | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Ticket Slack Notification | 4 | Event | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Ticket Slack Notification (APD) | 0 | Event | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Fetch AUTOMATIC_FIX tickets with PR link (APD) | 0 | On-demand | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
14. Agentic SOC — Interactive Case Assistant (Slack)
Description: A conversational, Slack-embedded AI assistant that lets analysts ask ad-hoc questions during an investigation, receive AI-recommended case-closure guidance, and communicate directly with affected end users — all without leaving Slack. A dedicated "User Communications Agent" drafts and sends user-facing messages, while supporting query tooling pulls context from Sumo Logic and Snowflake on demand via Slack slash commands.
Business problem solved: Mid-investigation questions and end-user communications typically require analysts to switch tools or manually track down data. This use case embeds AI-driven Q&A, case-closure recommendations, and user outreach directly into Slack's interactive components (buttons, forms, slash commands), keeping analysts in a single interface from question to resolution.
Key integrations: Slack, OpenAI, Sumo Logic, Snowflake, Blink Case Management
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| SOC AI - Slack Interactivity | 0 | Event | SOC | Agentic SOC, Case mgmt & SOAR |
| SOC AI - Close Case | 58 | On-demand | SOC | Agentic SOC, Case mgmt & SOAR |
| SOC AI - Ask AI Question (Slack) | 19 | On-demand | SOC | Agentic SOC |
| Agent 2 Agent - User Communications | 0 | On-demand | SOC | Agentic SOC |
| New Workflow | 0 | On-demand | SOC | Agentic SOC |
| Slack Command | 1 | Event | SOC | Agentic SOC |
| New Workflow | 0 | On-demand | SOC | Agentic SOC |
| Slash Command Demo | 0 | On-demand | SOC | Agentic SOC |
15. Database & Network Infrastructure Health Monitoring
Description: Snowflake-powered operational health monitoring covering database locking behavior and proxy performance. A high-frequency real-time check flags locking/blocking anomalies as they occur, a daily job summarizes lock activity against a refreshed baseline, and a separate daily report scores proxy health — all delivered as structured Slack alerts.
Business problem solved: Database lock contention and proxy degradation can silently erode application performance until they cause an outage. This use case gives the team continuous, automated visibility into infrastructure health via near-real-time and daily Snowflake-driven checks, surfacing anomalies in Slack before they escalate.
Key integrations: Snowflake, Slack
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Real-Time Locks / Blocks Anomaly Alerts | 3,839 | Scheduled | Other | IT/OT & network infra monitoring |
| DAILY LOCKING SUMMARY | 40 | Scheduled | Other | IT/OT & network infra monitoring |
| Proxy Score Report | 29 | Scheduled | Other | IT/OT & network infra monitoring |
16. Financial Order Monitoring & Account Lookup
Description: Order-processing oversight combining a scheduled digest of recent orders with an AI-driven order analysis agent that reviews order data on demand and reports findings to Slack, backed by a direct account lookup tool against the production database.
Business problem solved: Reviewing order activity and looking up account details for investigation typically requires direct database access and manual cross-referencing. This use case automates recurring order reporting and gives the team an AI-assisted, Slack-native way to analyze order data and pull account context on demand.
Key integrations: MySQL, Slack, OpenAI
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Get Orders | 10 | Scheduled | Other | Financial & fraud operations |
| Order analysis via Slack | 0 | On-demand | Other | Financial & fraud operations |
| Account info | 0 | On-demand | Other | Customer registry & FinOps auto |
17. WAF IP Blocking & Auto-Unblock
Description: On-demand and scheduled IP blocklist management for the web application firewall, backed by a Blink table tracking currently blocked IPs. Analysts can block or unblock a specific IP on demand or list the current blocklist, while a daily scheduled job automatically expires and unblocks IPs once their block window elapses.
Business problem solved: Manually tracking which IPs are blocked in the WAF and remembering to lift temporary blocks is error-prone, leading to either lingering unnecessary blocks or missed containment. This use case gives analysts a simple on-demand block/unblock/list interface while a scheduled job guarantees blocks expire automatically.
Key integrations: AWS, Blink Tables
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Block IP in WAF | 3 | On-demand | SOC | EDR containment & response |
| Unblock IP in WAF | 3 | On-demand | SOC | EDR containment & response |
| Daily WAF Unblock | 20 | Scheduled | SOC | EDR containment & response |
| List Blocked IPs | 1 | On-demand | SOC | EDR containment & response |
18. AI Prompt Offence Investigation (Cato)
Description: Investigation pipeline for AI-app prompt policy violations ("offences") surfaced by Cato Networks. A dedicated "Cato Prompt Analyist" AI agent evaluates the flagged prompt and session, invoked either directly from the webhook-driven analysis flow or on demand — including a bulk mode that pulls existing cases and re-analyzes their AI prompt offences.
Business problem solved: As employees increasingly use AI tools, Cato's network visibility flags risky prompts (e.g., potential data exfiltration or policy violations), but assessing whether each flagged prompt is actually risky still required manual review. This use case automates that assessment with an AI agent and supports both real-time and retroactive bulk investigation.
Key integrations: Cato Networks, Blink Case Management, HTTP
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| Main - Analyse AI Prompt | 37 | Event | SOC | Alert enrichment / IOC lookup, Agentic SOC |
| Analyse Cato AI Prompt | 21 | On-demand | SOC | Alert enrichment / IOC lookup |
| On Demand - Analyse Cato AI Prompt | 16 | On-demand | SOC | Alert enrichment / IOC lookup, Case mgmt & SOAR |
19. Holdings Data Import & OFX Generation
Description: Slack-driven pipeline that converts uploaded holdings statement screenshots into structured data. A router listens for mentions in a dedicated ops channel and offers a menu of import purposes; when holdings import is selected, the uploaded image is passed to an AI vision model to extract holdings data, an analyst reviews and edits the extracted data through interactive Slack forms, and the confirmed data is compiled into an OFX file for downstream import.
Business problem solved: Manually transcribing customer holdings data from statement screenshots into a structured, importable format is slow and error-prone. This use case automates extraction with AI vision, keeps a human in the loop for verification via Slack, and outputs a ready-to-import OFX file — reducing a manual data-entry task to a guided review.
Key integrations: Slack, OpenAI
| Playbook | Executions | Type | Category | Subcategory |
|---|---|---|---|---|
| CDI Ops Router | 12 | Event | Other | Customer registry & FinOps auto |
| Holdings Import | 14 | On-demand | Other | Customer registry & FinOps auto |
Key Observations
Strengths
Mature agentic SOC pipeline. The alert triage flow — CrowdStrike and Sumo Logic ingestion → case deduplication → observable enrichment → AI summary → Slack delivery — is fully automated end-to-end. With 679 CrowdStrike detections and 442 process-alert executions over 12 months, this is the highest-volume and highest-value use case in the environment.
Slack-native SOC operations. With 1,532 incoming Slack interactions and 1,440 case-update syncs handled automatically, the team has made Slack the primary incident response interface — eliminating context-switching between the case management system and communication tools for routine operations.
AI deeply embedded across the security program. OpenAI is used not only for case summarization but also for phishing classification, DLP intent analysis, threat intel filtering, endpoint IDE investigation, case escalation briefings, and incident post-mortems. This indicates a sophisticated, AI-augmented security posture that goes well beyond basic automation.
Rich, custom enrichment library. Fifteen-plus enrichment playbooks cover every major observable type. The custom Pontera-specific enrichers (username/email via Sumo Logic, hostname via CrowdStrike) are actively running, demonstrating mature platform customization beyond out-of-the-box capabilities.
Proactive threat intelligence consumption. Automated monitoring of HaveIBeenPwned for breach data on organizational domains, combined with supply chain security RSS feeds (SocketSecurity) and community vulnerability research, provides a curated, AI-filtered intelligence stream without manual analyst monitoring.
Unique AI tooling automation. The Claude Security Pack Updater is a particularly sophisticated workflow — automating the lifecycle of an AI-powered security detection pack (release detection, config comparison, deployment, release notes) in a way that is rare among Blink customers.
Emerging agentic cloud security capability. New AI-agent tooling now enables autonomous AWS CLI execution and EC2/S3 investigation via a purpose-built "Cloud Analyst" agent — the AWS CLI tool alone has already executed 2,321 times, making it the single highest-volume automation in the environment. Combined with new Wiz-based posture alerting for exposed secrets, this marks the environment's expansion from pure SOC/EDR automation into cloud security posture management.
Multi-agent forensics network now operational. A new "Agent 2 Agent" tier lets the primary case-handling agent delegate forensics questions to vendor-specialized analyst agents — AWS, Google Workspace, Cato Networks, Sumo Logic, Okta, and Wiz — with 1,463 combined consultations in the last 12 months. Paired with a new direct-query layer (Okta log search at 2,307 executions, Cato Networks queries at 750, Wiz GraphQL queries at 580), this significantly deepens the platform's autonomous investigation depth across identity, network, and cloud domains.
New conversational Slack assistant for live investigations. A "SOC AI" tier now lets analysts ask ad-hoc questions and close cases directly from Slack (58 AI-recommended case closures, 19 ad-hoc Q&A sessions), backed by a dedicated user-communications agent for direct end-user outreach — extending the platform's AI footprint from background automation into a live, conversational analyst interface.
AI-driven case investigation now a high-volume core process. The new Main - Investigation playbook — which queries the case management system, evaluates conditions, pulls timeline events, and hands off to a "Post Investigation Triage Agent" before updating the case — has already run 324 times, and a new Sumologic WAF Alert flow adds a dedicated network forensics agent for WAF-triggered alerts (111 executions). Together these deepen the automated investigation layer introduced alongside the multi-agent forensics network.
Expansion into infrastructure health and business operations monitoring. Beyond security, Blink now automates database lock/block anomaly detection (3,839 real-time checks plus a daily summary) and proxy health scoring via Snowflake, alongside order-digest and account-lookup tooling for financial operations — signaling that the platform is being adopted as a general automation layer for the business, not solely for the SOC.
New network-layer containment capability. IP blocking and auto-unblocking in the WAF (27 combined on-demand executions plus 20 scheduled auto-unblock cycles) closes the gap between WAF alert investigation (Sumologic WAF Alert) and actual containment action, with a scheduled job guaranteeing temporary blocks expire automatically.
Emerging AI-usage governance. A new Cato-integrated pipeline (74 combined executions) evaluates AI-app prompts flagged as policy offences via a dedicated "Cato Prompt Analyist" agent, extending the platform's oversight from network and endpoint threats into GenAI usage risk.
Financial operations digitization via AI vision. The new Holdings Import pipeline (26 combined executions) uses AI vision to extract customer holdings data from uploaded screenshots, routes it through a Slack-based human review loop, and generates ready-to-import OFX files — automating a previously manual, error-prone data-entry process.
Gaps & Opportunities
Offboarding half of IAM lifecycle still dormant. The user deactivation, Cato coverage, and Okta deprovisioning playbooks all show 0 executions. Onboarding is now active — the new HiBob-triggered onboarding and sync playbooks run 11 and 1,049 times respectively — but the offboarding and coverage-reporting side of the tooling remains built but not yet operationally active. Wiring deactivation and deprovisioning to the same HiBob trigger is the most immediately addressable gap given the existing infrastructure.
Enrichment library underutilized. The general enrichment playbooks (IP/URL/hash enrichment via VirusTotal, AbuseIPDB, URLScan) all show 0 executions. This suggests the main triage pipeline currently routes through only the Pontera-specific enrichers, with the broader threat intel lookups not yet wired into the automated flow.
EDR containment not yet activated. CrowdStrike RTR (batch and single host) and endpoint quarantine playbooks exist but show 0 executions. Connecting these to the alert triage pipeline as automated response actions — triggered on confirmed high-severity detections — would complete the containment loop without analyst involvement.
Phishing email investigation incomplete. Init Email Investigation, Investigate Email - Search, and Investigate Email - Sandbox File all have 0 executions while the ingestion playbook runs 85 times per year. The new Agent Ability - Google List Gmail Messages tool (70 executions) now provides active mailbox search for investigations, partially closing this gap — but sandbox file analysis remains unused.
Vulnerability management coverage is just beginning. The new SCA Critical Ticketing workflow (20 executions) introduces AI-triaged, ticketed remediation for software composition analysis findings — a first step into vulnerability management. Broader coverage (CVE lookup, vulnerability scanner integration, patch lifecycle automation) is still missing, and given daily endpoint compliance scanning is already in place, there is a natural expansion path into fuller vulnerability prioritization.
Integration Ecosystem
The environment spans 20+ integrated platforms: CrowdStrike, Sumo Logic, Okta, Google Workspace / Gmail, Microsoft Entra ID, Slack, OpenAI, Teramind, Mitiga, Kandji, Cato Networks, Perception Point, VirusTotal, AbuseIPDB, URLScan, GitHub, HaveIBeenPwned, Monday.com, Wiz, AWS, HiBob, Snowflake, Jira, and MySQL.
This is a broad, mature integration footprint — signaling a security team that has actively unified disparate tools under automated orchestration rather than operating them in silos. The presence of Mitiga (cloud incident response), Teramind (DLP / insider threat), and Perception Point (email security) alongside the core CrowdStrike / Sumo Logic stack indicates a layered detection approach across endpoint, cloud, and human-layer threat vectors.
E New Integrations (detail) 33 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Pontera | slack | my_slack_connection | 2026-08-30 |
| Pontera | blink | my_blink_connection | 2026-08-21 |
| Pontera | github | or_s_github_connection | 2026-08-20 |
| Pontera | jira | qa_jira | 2026-08-12 |
| Pontera | jira | cli_jira | 2026-08-12 |
| Pontera | jira | ops_jira | 2026-08-11 |
| Pontera | jira | pm_jira | 2026-08-11 |
| Pontera | sumo-logic | qa_sumologic | 2026-08-11 |
| Pontera | sumo-logic | ops_sumologic | 2026-08-11 |
| Pontera | sumo-logic | pm_sumologic | 2026-08-11 |
| Pontera | sumo-logic | cli_sumologic | 2026-08-11 |
| Pontera | google-calendar | qa_google_calendar | 2026-08-11 |
| Pontera | gmail | qa_gmail | 2026-08-11 |
| Pontera | google-calendar | ops_google_calendar | 2026-08-11 |
| Pontera | gmail | ops_gmail | 2026-08-11 |
| Pontera | slack | blinkops_ops | 2026-08-11 |
| Pontera | google-drive | pm_google_drive | 2026-08-11 |
| Pontera | google-calendar | pm_google_calendar | 2026-08-11 |
| Pontera | gmail | pm_gmail | 2026-08-11 |
| Pontera | google-sheets | pm_google_sheets | 2026-08-11 |
| Pontera | google-docs | pm_google_docs | 2026-08-11 |
| Pontera | google-calendar | cli_google_calendar | 2026-08-11 |
| Pontera | gmail | cli_gmail | 2026-08-11 |
| Pontera | cato-networks | ir_sensitive_cato | 2026-08-11 |
| Pontera | jira | apd_jira | 2026-08-11 |
| Pontera | gmail | apd_gmail | 2026-08-11 |
| Pontera | google-calendar | apd_google_calendar | 2026-08-11 |
| Pontera | mysql | my_mysql_connection_1 | 2026-08-09 |
| Pontera | jira | my_jira_connection | 2026-08-05 |
| Pontera | github | my_github_connection | 2026-08-05 |
| Pontera | jira | my_jira_connection | 2026-08-04 |
| Pontera | slack | my_slack_connection | 2026-08-04 |
| Pontera | snowflake | my_snowflake_connection | 2026-08-03 |