Blink Security Automation — Confidential

recordedfuture — Customer Success Report

Generated 2026-08-30 | recordedfuture-value-report.md
2026-08-30Report Date
106Total Playbooks
34Unique Workflows (12m)
281,602Actions Automated (12m)
$72,428Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

106
Total playbooks built
all non-deleted workflows
73
Active playbooks
currently enabled
34
Unique workflows executed (12m)
distinct workflows that ran
281,602
Actions automated (12m)
completed action steps
1,564.5h
Hours saved (12m)
@ 20s per action
$72,428
Money saved (12m)
@ $100K avg salary
5
New active workflows (last 30d)
recently created & enabled
3,322
Total cases managed
3,322 opened in last 12m
1h 56m
MTTR — mean time to resolve
closed cases, last 12m
4
Active AI agents
of 8 total
37
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 1,480 security alerts automatically triaged and routed through the SOC pipeline - 1,463 security cases auto-created across Splunk, SentinelOne, Red Canary, and Thinkst Canary sources - 974 after-hours, high-priority incidents automatically escalated to on-call staff via PagerDuty - 944 cases enriched with AI-generated summaries, reducing analyst ramp-up time per investigation - 633 SentinelOne endpoint threats detected and automatically processed into the SOC workflow - 123 Splunk health alerts ingested and automatically routed for triage - 118 automation failures captured and escalated to engineering via a structured BlinOps error workflow - 114 Jira SACDEV tickets ingested and triaged end-to-end without manual intervention

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Multi-Source Alert Ingestion & Automated Case Management
  • 1,480Security alerts auto-triaged through SOC pipeline
  • 1,050Cases auto-created from Splunk detections
  • 944Cases enriched with AI-generated summary and threat context
67.8%
32
32 active
After-Hours Escalation & High-Priority Incident Response
  • 974After-hours high-priority incidents escalated to on-call
13.9%
1
1 active
Threat Intelligence Enrichment — Recorded Future & Multi-Tool IOC Lookup0 executions
0.0%
13
13 active
Agentic SOC & SIEM Threat Hunting0 executions
0.0%
2
2 active
Identity Investigation & User Enrichment0 executions
0.0%
9
9 active
Phishing & Malware Incident Response0 executions
0.0%
2
2 active
EDR Containment & Endpoint Security Checks0 executions
0.0%
5
5 active
Platform Error Handling & Reliability
  • 197Workflow errors detected and notified to engineering
  • 118Automation errors captured and escalated via structured BlinOps workflow
  • 116Error notifications dispatched to engineering team
1.5%
3
3 active
Business Operations Data Ingestion
  • 11SaaS application data synced from Zylo for reporting
0.1%
2
2 active
Total6,437 executions100%
69
69 active

Use Case Growth Over Time

93 unique playbooks  |  9 operational use cases  |  7,715 total executions (12m)  |  2024-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Identity Investigation & User Enrichment
Okta Google Workspace GitHub Microsoft Entra ID Slack Jira Splunk Google Sheets
Multi-Source Alert Ingestion & Automated Case Management
SentinelOne Jira Recorded Future Email Splunk
Phishing & Malware Incident Response
Microsoft Outlook
Threat Intelligence Enrichment — Recorded Future & Multi-Tool IOC Lookup
CrowdStrike URLScan VirusTotal Recorded Future Splunk Google Sheets
EDR Containment & Endpoint Security Checks
CrowdStrike SentinelOne Recorded Future Email
Agentic SOC & SIEM Threat Hunting
Agents
Platform Error Handling & Reliability
Email Jira
Business Operations Data Ingestion
Jira

04Key Observations

✓  Strengths

Strengths

1. Production-grade SOC automation at scale.

The core alert ingestion pipeline is active and operating at volume — 1,480 alerts triaged, 1,365 cases created, and 944 AI-enriched summaries generated over 12 months. This is a mature, battle-tested SOAR deployment covering multiple alert sources within a unified case model.

2. Multi-source alert unification.

Four distinct detection sources (Splunk, SentinelOne, Red Canary, Thinkst Canary) are normalised into a single case management model, giving analysts a unified operational view and eliminating source-specific tooling for triage.

3. Zero-

△  Gaps & Growth Opportunities

gap after-hours coverage.

974 high-priority, after-hours cases were automatically escalated to PagerDuty — eliminating manual SLA monitoring outside business hours and ensuring critical incidents receive immediate on-call response regardless of time zone.

4. Agentic SOC capabilities deployed.

AI agent-based threat hunting workflows (Splunk Bot, IOC Search Bot) are deployed in a dedicated workspace and ready for programmatic threat investigation. These workflows represent a forward investment in Agentic SOC and are not yet generating execution volume — an expansion opportunity.

5. Robust reliability infrastructure.

313 combined error notifications across two error-handling workflows demonstrate an active reliability layer that surfaces automation failures in real time, preventing silent gaps in case coverage.

Gaps & Opportunities

1. Enrichment pipeline deployed but inactive.

Despite a comprehensive enrichment library spanning Recorded Future, VirusTotal, CrowdStrike, and URLScan (Use Cases 3 and 7), none of these workflows ran in the last 12 months. The enrichment router (Subflow - Enrich Observables - Main Router) also shows zero executions, suggesting the enrichment layer is built but not yet wired into the active alert processing pipeline. Activating this would deliver automatic IOC context on every observable for every case.

2. Identity enrichment dormant.

Nine identity investigation workflows spanning Okta, Entra ID, Google Workspace, GitHub, and Slack have zero executions. Connecting these to the case creation flow would give analysts immediate multi-provider identity context per incident without any additional effort.

3. Phishing and malware response subflows not triggered.

Both Response Subflow - Phishing and Response Subflow - Malware have zero executions. The phishing subflow includes KnowBe4 simulation detection logic, which is a sophisticated capability. These playbooks are built but appear not yet connected to the active response router.

4. EDR containment capabilities built but untriggered.

CrowdStrike RTR workflows for single and batch host isolation, and the quarantine management workflow, are deployed with zero executions. Making these available as manual-trigger actions in analyst case views would immediately accelerate containment response time.

5. Duplicate enrichment playbook.

Enrich - Hash - RF copy appears to be a duplicate of Enrichment - Recorded Future. Consolidating these would reduce maintenance overhead and remove ambiguity about which workflow is canonical.

6. Fragmented workspace structure.

Playbooks are spread across five distinct workspaces. The secondary workspaces (Splunk/agentic, S1 checks, high-value users) are entirely inactive. Evaluating whether these should be consolidated into the main workspace or formalised as separate functional domains would improve governance.

Integration Ecosystem

The deployment spans 16 distinct integrations across 7 categories:

Integration Category Active in Production
Splunk SIEM Yes
SentinelOne EDR Yes
Jira Ticketing Yes
PagerDuty Escalation Yes
Red Canary MDR Yes
Thinkst Canary Deception Yes
CrowdStrike EDR / Threat Intel No
Recorded Future Threat Intel No
VirusTotal Threat Intel No
URLScan Threat Intel No
Okta IAM No
Microsoft Entra ID IAM No
Google Workspace IAM No
GitHub Developer Tools No
Slack Collaboration No
Microsoft Outlook Email No
Appendices
A Case Management 3,322 cases (12m) | MTTR 1h 56m

Case Management

Total Cases (all-time)
3,322
3,322 opened in last 12m
Cases Opened (30d)
714
0 closed in last 30d
Cases Closed (12m)
2
of 3,322 opened
MTTR
1h 56m
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management 3,322 3,322 2 1h 56m
B AI Agents 4 active | 37 tasks (12m)

AI Agents

Active Agents
4
of 8 total
Tasks Executed (12m)
37
0 in last 30d
Data Usage (12m)
333,979
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Splunk Searching Agent Agent Playground 21 0 0
2 IOC Search Bot (Parent) Agent Playground 9 0 280,131
3 NEW Splunk Bot Agent Playground 4 0 0
4 NEW2 Splunk Bot Agent Playground 3 0 53,848
5 Agent Blink Data Collection & Report Generation 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Agent Playground37
Data Collection & Report Generation0
Case Management0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
4
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Test 00
2 Case Management Dashboard 00
3 Threat Detection Retrospective 00
4 Splunk Generated Detections 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 9 use cases | 7,715 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-triaged through SOC pipeline 1,480 Process Alert
Cases auto-created from Splunk detections 1,050 Splunk Case Creation
After-hours high-priority incidents escalated to on-call 974 High-priority & Non-working Hour Pagerduty Escalation
Cases enriched with AI-generated summary and threat context 944 Case Creation - Summary & Enrichment
Splunk alerts ingested and parsed automatically 869 Ingest Data from Splunk
SentinelOne endpoint threats auto-ingested 633 Ingest SentinelOne Alerts
SentinelOne cases automatically created 271 SentinelOne Case Creation
Workflow errors detected and notified to engineering 197 Workflow Error Handling
SACDEV Jira tickets auto-ingested and triaged 114 Ingest SACDEV Tickets
Error notifications dispatched to engineering team 116 Error Handling - Send Error Notification Email
Splunk health alerts ingested and routed automatically 123 Ingest healthAlerts from Splunk
Automation errors captured and escalated via structured BlinOps workflow 118 Error Handling - Generate BlinOps Error Notification copy
Cases auto-created from Splunk health alerts 98 Splunk healthAlert Case Creation
Missing alert template gaps flagged 73 Subflow - Missing Alert Template Notification
Observable values extracted from cases 58 Extract observable values
Red Canary alerts auto-ingested 42 Red Canary Alerts
Red Canary cases auto-created 41 Red Canary Case Creation
Scheduled Splunk detection scans executed 40 Get Splunk Detections
SaaS application data synced from Zylo for reporting 11 Ingest Zylo Data
Thinkst Canary alerts auto-processed 5 Thinkst Canary Notifications
Thinkst Canary cases auto-created 3 Thinkst Canary Case Creation
Security Alert Center (production) Jira tickets auto-ingested 2 Ingest SAC tickets
SACDEV case updates synced back to Jira 1 Update SACDEV Tickets
In the last 12 months, Blink automated: - 1,480 security alerts automatically triaged and routed through the SOC pipeline - 1,463 security cases auto-created across Splunk, SentinelOne, Red Canary, and Thinkst Canary sources - 974 after-hours, high-priority incidents automatically escalated to on-call staff via PagerDuty - 944 cases enriched with AI-generated summaries, reducing analyst ramp-up time per investigation - 633 SentinelOne endpoint threats detected and automatically processed into the SOC workflow - 123 Splunk health alerts ingested and automatically routed for triage - 118 automation failures captured and escalated to engineering via a structured BlinOps error workflow - 114 Jira SACDEV tickets ingested and triaged end-to-end without manual intervention

Use Case Summary

# Use Case Category Subcategories Total Playbooks Active Playbooks
1 Multi-Source Alert Ingestion & Automated Case Management SOC Case mgmt & SOAR, SIEM & log pipeline monitoring 36 18
2 After-Hours Escalation & High-Priority Incident Response SOC Case mgmt & SOAR 1 1
3 Threat Intelligence Enrichment — Recorded Future & Multi-Tool IOC Lookup SOC Alert enrichment / IOC lookup, Threat intel ingest & curation 14 0
4 Agentic SOC & SIEM Threat Hunting SOC Agentic SOC, SIEM & log pipeline monitoring 2 0
5 Identity Investigation & User Enrichment SOC Identity threat response, Alert enrichment / IOC lookup 9 0
6 Phishing & Malware Incident Response SOC Phishing detection & response, EDR containment & response 2 0
7 EDR Containment & Endpoint Security Checks SOC EDR containment & response 5 0
8 Platform Error Handling & Reliability Other DevOps & release automation 5 3
9 Business Operations Data Ingestion Other SaaS / IT administration, IT helpdesk & ticket routing 2 1

76 playbooks across 9 use cases — 23 active (30%)

Use Cases

1. Multi-Source Alert Ingestion & Automated Case Management

Description: A comprehensive SOAR platform that ingests security alerts from Splunk, SentinelOne, Red Canary, Thinkst Canary, and Jira SACDEV, then automatically creates, deduplicates, and enriches cases. Every new alert flows through a central processing engine that extracts observables, generates AI summaries, and writes structured case records.

Business Problem: Security teams managing multiple EDR, SIEM, and MDR tools face alert overload and inconsistent triage. This use case eliminates manual alert-to-case conversion, ensuring every alert is captured, deduplicated, and contextualised before reaching an analyst.

Integrations: Splunk, SentinelOne, Red Canary, Thinkst Canary, Jira, Blink Case Management

Playbook Executions (12 mo) Category Subcategories
Process Alert 1,480 SOC Case mgmt & SOAR
Splunk Case Creation 1,050 SOC Case mgmt & SOAR, SIEM & log pipeline monitoring
Case Creation - Summary & Enrichment 944 SOC Case mgmt & SOAR
Ingest Data from Splunk 869 SOC SIEM & log pipeline monitoring
Ingest SentinelOne Alerts 633 SOC Case mgmt & SOAR
SentinelOne Case Creation 271 SOC Case mgmt & SOAR
Ingest healthAlerts from Splunk 123 SOC SIEM & log pipeline monitoring
Ingest SACDEV Tickets 114 SOC Case mgmt & SOAR
Splunk healthAlert Case Creation 98 SOC Case mgmt & SOAR
Subflow - Missing Alert Template Notification 73 SOC Case mgmt & SOAR
Extract observable values 58 SOC Case mgmt & SOAR
Red Canary Alerts 42 SOC Case mgmt & SOAR
Red Canary Case Creation 41 SOC Case mgmt & SOAR
Get Splunk Detections 40 SOC SIEM & log pipeline monitoring
Thinkst Canary Notifications 5 SOC Case mgmt & SOAR
Thinkst Canary Case Creation 3 SOC Case mgmt & SOAR
Ingest SAC tickets 2 SOC Case mgmt & SOAR
Update SACDEV Tickets 1 SOC Case mgmt & SOAR
Subflow - Response - Main Router 0 SOC Case mgmt & SOAR
Subflow - Enrich Observables - Main Router 0 SOC Alert enrichment / IOC lookup
Recovery - Handle Unprocessed Alerts 0 SOC Case mgmt & SOAR
Recovery - Enrich Non-Enriched Observables 0 SOC Alert enrichment / IOC lookup
Table Action - Validate Observables Extraction Template 0 SOC Case mgmt & SOAR
Utility - Find Similar Cases Based on Observables 0 SOC Case mgmt & SOAR
Utility - Close Stale Cases 0 SOC Case mgmt & SOAR
Utility - List Alert Observable Relations 0 SOC Case mgmt & SOAR
Utility - List Observable Alert Relations 0 SOC Case mgmt & SOAR
Utility - Update Enrichment 0 SOC Alert enrichment / IOC lookup
Utility - Delete Observable Relation 0 SOC Case mgmt & SOAR
Utility - Set Or Update Observable Relation 0 SOC Case mgmt & SOAR
Simulate Multiple Alerts from Different Sources 0 SOC Case mgmt & SOAR
Simulate Crowdstrike Alert 0 SOC Case mgmt & SOAR
SAC Sandbox 0 SOC Case mgmt & SOAR
USE WITH CARE - Reset Case Management Environment 0 SOC Case mgmt & SOAR
Ingest Recorded Future Alerts (From Swimlane) 0 SOC Case mgmt & SOAR
Ingest SecOps Request and parse 0 SOC Case mgmt & SOAR

2. After-Hours Escalation & High-Priority Incident Response

Description: Monitors newly opened cases on a 5-minute polling interval and automatically evaluates whether the case is high-priority and opened outside business hours (Friday 20:00 – Monday 08:00 EST). Qualifying cases are immediately escalated to on-call staff via PagerDuty.

Business Problem: Gaps in after-hours coverage create unacceptable response lag for critical security incidents. This automation eliminates blind spots by ensuring every high-priority case opened during non-working hours pages the on-call analyst within minutes.

Integrations: PagerDuty, Blink Case Management

Playbook Executions (12 mo) Category Subcategories
High-priority & Non-working Hour Pagerduty Escalation 974 SOC Case mgmt & SOAR

3. Threat Intelligence Enrichment — Recorded Future & Multi-Tool IOC Lookup

Description: A full-spectrum observable enrichment library that queries Recorded Future's SOAR API for IP and hash risk scores and verdicts, cross-references hashes against VirusTotal and CrowdStrike, analyzes URLs via URLScan (with screenshot capture), resolves domains via Whois and DNS, and checks product end-of-life status. All enrichment results write back to observable records in the case management system.

Business Problem: Manual threat intel lookups are slow and inconsistent. These workflows ensure every observable extracted from a case — IP, hash, domain, URL — is automatically enriched with risk scores, verdicts, and contextual data before an analyst engages.

Integrations: Recorded Future, VirusTotal, CrowdStrike, URLScan, Whois, Bash/DNS

Playbook Executions (12 mo) Category Subcategories
Enrichment - Recorded Future 0 SOC Alert enrichment / IOC lookup, Threat intel ingest & curation
Enrich - IP - RF 0 SOC Alert enrichment / IOC lookup, Threat intel ingest & curation
Enrich - Hash - RF copy 0 SOC Alert enrichment / IOC lookup, Threat intel ingest & curation
Subflow - Update Enrichment Data 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal 0 SOC Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike 0 SOC Alert enrichment / IOC lookup
Analyze URL with URLScan 0 SOC Alert enrichment / IOC lookup
Secure URL Screenshot Capture 0 SOC Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois 0 SOC Alert enrichment / IOC lookup
Run Dig Command 0 SOC Alert enrichment / IOC lookup
Get End of Life Date for a Product 0 SOC Alert enrichment / IOC lookup
Run Splunk Search 0 SOC SIEM & log pipeline monitoring
Ingest VPN IP data 0 SOC Threat intel ingest & curation
Malware/Kasm list ingestion 0 SOC Threat intel ingest & curation

4. Agentic SOC & SIEM Threat Hunting

Description: AI agent-powered workflows that enable programmatic Splunk queries and IOC-based threat hunting. The Splunk Bot agent runs structured SIEM investigations, and the IOC Search Bot performs indicator lookups across the environment — both returning analyst-ready findings.

Business Problem: Threat hunting traditionally requires senior analyst expertise with SIEM query languages. These agentic workflows democratise structured threat hunting by allowing IOC searches and SIEM queries to be executed programmatically and on demand.

Integrations: Splunk, Blink AI Agents

Playbook Executions (12 mo) Category Subcategories
Splunk Agent Workflow 0 SOC Agentic SOC, SIEM & log pipeline monitoring
IOC Search (Bots) 0 SOC Agentic SOC, Alert enrichment / IOC lookup

5. Identity Investigation & User Enrichment

Description: Provides analyst-ready user profiles by querying identity providers during investigations — covering Okta (user details and activity logs), Google Workspace, Microsoft Entra ID (including risky user signals), GitHub, and Slack. A dedicated workflow also tracks high-value users by correlating Jira EIP and PSIB ticket holders against Splunk activity data.

Business Problem: Identity context is essential for assessing blast radius and attacker dwell time. Without automation, analysts manually query multiple IAM systems per incident. These workflows consolidate multi-provider identity data into a single enrichment step.

Integrations: Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Jira, Splunk

Playbook Executions (12 mo) Category Subcategories
Enrich - Username or Email - Okta 0 SOC Identity threat response, Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace 0 SOC Identity threat response, Alert enrichment / IOC lookup
Get User Information Using Okta 0 SOC Identity threat response
Get User Information Using Google Workspace 0 SOC Identity threat response
Get User Information Using Microsoft Entra ID 0 SOC Identity threat response
Get User Information Using Github 0 SOC Identity threat response
Get User Information on Email Address Using Slack 0 SOC Identity threat response
Okta Search for User Activity 0 SOC Identity threat response
High-Value users 0 SOC Identity threat response

6. Phishing & Malware Incident Response

Description: Dedicated response subflows for phishing email triage — including detection of KnowBe4 simulation campaigns to suppress false positives — and malware containment with remediation status evaluation. Both feed into the central response router.

Business Problem: Phishing and malware are the highest-volume, highest-risk incident types. These response playbooks enforce consistent handling at every stage, including simulation filtering, without requiring analyst judgment on routine cases.

Integrations: Microsoft Outlook, KnowBe4, Blink Case Management

Playbook Executions (12 mo) Category Subcategories
Response Subflow - Phishing 0 SOC Phishing detection & response
Response Subflow - Malware 0 SOC EDR containment & response

7. EDR Containment & Endpoint Security Checks

Description: Enables rapid remote containment using CrowdStrike Real-Time Response (RTR) for both single hosts and batch operations, supports host isolation and lift-isolation actions, and runs Recorded Future-backed risk assessments against SentinelOne's blocklist and exemption list to validate their integrity against live threat intelligence.

Business Problem: Rapid endpoint isolation is a time-critical response action during active incidents. These workflows allow analysts to contain compromised hosts in seconds and proactively validate that SentinelOne exclusion and block configurations are not harbouring known-bad indicators.

Integrations: CrowdStrike, SentinelOne, Recorded Future

Playbook Executions (12 mo) Category Subcategories
CrowdStrike RTR to a Single Host 0 SOC EDR containment & response
CrowdStrike RTR to a Batch of Hosts 0 SOC EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike 0 SOC EDR containment & response
S1 Blocklist Check 0 SOC EDR containment & response, Threat intel ingest & curation
S1 Exemption List Check 0 SOC EDR containment & response, Threat intel ingest & curation

8. Platform Error Handling & Reliability

Description: Cross-platform error handling workflows that capture failures from any running automation via Blink's error event system and dispatch structured notification emails to the engineering team with error details, workflow stage, and execution URL for immediate debugging.

Business Problem: Silent automation failures erode trust and create undetected security gaps. These workflows act as a reliability net, ensuring every failure is surfaced and actioned in real time rather than discovered when an analyst notices a case was never created.

Integrations: Blink Email, Blink Event System

Playbook Executions (12 mo) Category Subcategories
Workflow Error Handling 197 Other DevOps & release automation
Error Handling - Generate BlinOps Error Notification copy 118 Other DevOps & release automation
Error Handling - Send Error Notification Email 116 Other DevOps & release automation
Notification Failflow 0 Other DevOps & release automation
Random Fact 0 Other DevOps & release automation

9. Business Operations Data Ingestion

Description: Ingests non-security operational data — SaaS application usage and spend metadata from Zylo and employee travel requests from Jira — for centralized reporting and tracking outside the core security pipeline.

Business Problem: Business operations data (SaaS spend visibility, travel request tracking) lived in disparate source systems without a consistent ingestion path. These workflows automate the pull of that data into shared reporting stores.

Integrations: Zylo, Splunk, Jira

Playbook Executions (12 mo) Category Subcategories
Ingest Zylo Data 11 Other SaaS / IT administration
Jira - ingest Travel Requests 0 Other IT helpdesk & ticket routing

Key Observations

Strengths

1. Production-grade SOC automation at scale.

The core alert ingestion pipeline is active and operating at volume — 1,480 alerts triaged, 1,365 cases created, and 944 AI-enriched summaries generated over 12 months. This is a mature, battle-tested SOAR deployment covering multiple alert sources within a unified case model.

2. Multi-source alert unification.

Four distinct detection sources (Splunk, SentinelOne, Red Canary, Thinkst Canary) are normalised into a single case management model, giving analysts a unified operational view and eliminating source-specific tooling for triage.

3. Zero-gap after-hours coverage.

974 high-priority, after-hours cases were automatically escalated to PagerDuty — eliminating manual SLA monitoring outside business hours and ensuring critical incidents receive immediate on-call response regardless of time zone.

4. Agentic SOC capabilities deployed.

AI agent-based threat hunting workflows (Splunk Bot, IOC Search Bot) are deployed in a dedicated workspace and ready for programmatic threat investigation. These workflows represent a forward investment in Agentic SOC and are not yet generating execution volume — an expansion opportunity.

5. Robust reliability infrastructure.

313 combined error notifications across two error-handling workflows demonstrate an active reliability layer that surfaces automation failures in real time, preventing silent gaps in case coverage.

Gaps & Opportunities

1. Enrichment pipeline deployed but inactive.

Despite a comprehensive enrichment library spanning Recorded Future, VirusTotal, CrowdStrike, and URLScan (Use Cases 3 and 7), none of these workflows ran in the last 12 months. The enrichment router (Subflow - Enrich Observables - Main Router) also shows zero executions, suggesting the enrichment layer is built but not yet wired into the active alert processing pipeline. Activating this would deliver automatic IOC context on every observable for every case.

2. Identity enrichment dormant.

Nine identity investigation workflows spanning Okta, Entra ID, Google Workspace, GitHub, and Slack have zero executions. Connecting these to the case creation flow would give analysts immediate multi-provider identity context per incident without any additional effort.

3. Phishing and malware response subflows not triggered.

Both Response Subflow - Phishing and Response Subflow - Malware have zero executions. The phishing subflow includes KnowBe4 simulation detection logic, which is a sophisticated capability. These playbooks are built but appear not yet connected to the active response router.

4. EDR containment capabilities built but untriggered.

CrowdStrike RTR workflows for single and batch host isolation, and the quarantine management workflow, are deployed with zero executions. Making these available as manual-trigger actions in analyst case views would immediately accelerate containment response time.

5. Duplicate enrichment playbook.

Enrich - Hash - RF copy appears to be a duplicate of Enrichment - Recorded Future. Consolidating these would reduce maintenance overhead and remove ambiguity about which workflow is canonical.

6. Fragmented workspace structure.

Playbooks are spread across five distinct workspaces. The secondary workspaces (Splunk/agentic, S1 checks, high-value users) are entirely inactive. Evaluating whether these should be consolidated into the main workspace or formalised as separate functional domains would improve governance.

Integration Ecosystem

The deployment spans 16 distinct integrations across 7 categories:

Integration Category Active in Production
Splunk SIEM Yes
SentinelOne EDR Yes
Jira Ticketing Yes
PagerDuty Escalation Yes
Red Canary MDR Yes
Thinkst Canary Deception Yes
CrowdStrike EDR / Threat Intel No
Recorded Future Threat Intel No
VirusTotal Threat Intel No
URLScan Threat Intel No
Okta IAM No
Microsoft Entra ID IAM No
Google Workspace IAM No
GitHub Developer Tools No
Slack Collaboration No
Microsoft Outlook Email No
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.