01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Multi-Source Alert Ingestion & Automated Case Management |
| 67.8% | 32 32 active |
| After-Hours Escalation & High-Priority Incident Response |
| 13.9% | 1 1 active |
| Threat Intelligence Enrichment — Recorded Future & Multi-Tool IOC Lookup | 0 executions | 0.0% | 13 13 active |
| Agentic SOC & SIEM Threat Hunting | 0 executions | 0.0% | 2 2 active |
| Identity Investigation & User Enrichment | 0 executions | 0.0% | 9 9 active |
| Phishing & Malware Incident Response | 0 executions | 0.0% | 2 2 active |
| EDR Containment & Endpoint Security Checks | 0 executions | 0.0% | 5 5 active |
| Platform Error Handling & Reliability |
| 1.5% | 3 3 active |
| Business Operations Data Ingestion |
| 0.1% | 2 2 active |
| Total | 6,437 executions | 100% | 69 69 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
1. Production-grade SOC automation at scale.
The core alert ingestion pipeline is active and operating at volume — 1,480 alerts triaged, 1,365 cases created, and 944 AI-enriched summaries generated over 12 months. This is a mature, battle-tested SOAR deployment covering multiple alert sources within a unified case model.
2. Multi-source alert unification.
Four distinct detection sources (Splunk, SentinelOne, Red Canary, Thinkst Canary) are normalised into a single case management model, giving analysts a unified operational view and eliminating source-specific tooling for triage.
3. Zero-
gap after-hours coverage.
974 high-priority, after-hours cases were automatically escalated to PagerDuty — eliminating manual SLA monitoring outside business hours and ensuring critical incidents receive immediate on-call response regardless of time zone.
4. Agentic SOC capabilities deployed.
AI agent-based threat hunting workflows (Splunk Bot, IOC Search Bot) are deployed in a dedicated workspace and ready for programmatic threat investigation. These workflows represent a forward investment in Agentic SOC and are not yet generating execution volume — an expansion opportunity.
5. Robust reliability infrastructure.
313 combined error notifications across two error-handling workflows demonstrate an active reliability layer that surfaces automation failures in real time, preventing silent gaps in case coverage.
Gaps & Opportunities
1. Enrichment pipeline deployed but inactive.
Despite a comprehensive enrichment library spanning Recorded Future, VirusTotal, CrowdStrike, and URLScan (Use Cases 3 and 7), none of these workflows ran in the last 12 months. The enrichment router (Subflow - Enrich Observables - Main Router) also shows zero executions, suggesting the enrichment layer is built but not yet wired into the active alert processing pipeline. Activating this would deliver automatic IOC context on every observable for every case.
2. Identity enrichment dormant.
Nine identity investigation workflows spanning Okta, Entra ID, Google Workspace, GitHub, and Slack have zero executions. Connecting these to the case creation flow would give analysts immediate multi-provider identity context per incident without any additional effort.
3. Phishing and malware response subflows not triggered.
Both Response Subflow - Phishing and Response Subflow - Malware have zero executions. The phishing subflow includes KnowBe4 simulation detection logic, which is a sophisticated capability. These playbooks are built but appear not yet connected to the active response router.
4. EDR containment capabilities built but untriggered.
CrowdStrike RTR workflows for single and batch host isolation, and the quarantine management workflow, are deployed with zero executions. Making these available as manual-trigger actions in analyst case views would immediately accelerate containment response time.
5. Duplicate enrichment playbook.
Enrich - Hash - RF copy appears to be a duplicate of Enrichment - Recorded Future. Consolidating these would reduce maintenance overhead and remove ambiguity about which workflow is canonical.
6. Fragmented workspace structure.
Playbooks are spread across five distinct workspaces. The secondary workspaces (Splunk/agentic, S1 checks, high-value users) are entirely inactive. Evaluating whether these should be consolidated into the main workspace or formalised as separate functional domains would improve governance.
Integration Ecosystem
The deployment spans 16 distinct integrations across 7 categories:
| Integration | Category | Active in Production |
|---|---|---|
| Splunk | SIEM | Yes |
| SentinelOne | EDR | Yes |
| Jira | Ticketing | Yes |
| PagerDuty | Escalation | Yes |
| Red Canary | MDR | Yes |
| Thinkst Canary | Deception | Yes |
| CrowdStrike | EDR / Threat Intel | No |
| Recorded Future | Threat Intel | No |
| VirusTotal | Threat Intel | No |
| URLScan | Threat Intel | No |
| Okta | IAM | No |
| Microsoft Entra ID | IAM | No |
| Google Workspace | IAM | No |
| GitHub | Developer Tools | No |
| Slack | Collaboration | No |
| Microsoft Outlook | No |
A Case Management 3,322 cases (12m) | MTTR 1h 56m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management | 3,322 | 3,322 | 2 | 1h 56m |
B AI Agents 4 active | 37 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Splunk Searching Agent | Agent Playground | 21 | 0 | 0 |
| 2 | IOC Search Bot (Parent) | Agent Playground | 9 | 0 | 280,131 |
| 3 | NEW Splunk Bot | Agent Playground | 4 | 0 | 0 |
| 4 | NEW2 Splunk Bot | Agent Playground | 3 | 0 | 53,848 |
| 5 | Agent Blink | Data Collection & Report Generation | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Agent Playground | 37 |
| Data Collection & Report Generation | 0 |
| Case Management | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Test | 0 | 0 |
| 2 | Case Management Dashboard | 0 | 0 |
| 3 | Threat Detection Retrospective | 0 | 0 |
| 4 | Splunk Generated Detections | 0 | 0 |
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 9 use cases | 7,715 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-triaged through SOC pipeline | 1,480 | Process Alert |
| Cases auto-created from Splunk detections | 1,050 | Splunk Case Creation |
| After-hours high-priority incidents escalated to on-call | 974 | High-priority & Non-working Hour Pagerduty Escalation |
| Cases enriched with AI-generated summary and threat context | 944 | Case Creation - Summary & Enrichment |
| Splunk alerts ingested and parsed automatically | 869 | Ingest Data from Splunk |
| SentinelOne endpoint threats auto-ingested | 633 | Ingest SentinelOne Alerts |
| SentinelOne cases automatically created | 271 | SentinelOne Case Creation |
| Workflow errors detected and notified to engineering | 197 | Workflow Error Handling |
| SACDEV Jira tickets auto-ingested and triaged | 114 | Ingest SACDEV Tickets |
| Error notifications dispatched to engineering team | 116 | Error Handling - Send Error Notification Email |
| Splunk health alerts ingested and routed automatically | 123 | Ingest healthAlerts from Splunk |
| Automation errors captured and escalated via structured BlinOps workflow | 118 | Error Handling - Generate BlinOps Error Notification copy |
| Cases auto-created from Splunk health alerts | 98 | Splunk healthAlert Case Creation |
| Missing alert template gaps flagged | 73 | Subflow - Missing Alert Template Notification |
| Observable values extracted from cases | 58 | Extract observable values |
| Red Canary alerts auto-ingested | 42 | Red Canary Alerts |
| Red Canary cases auto-created | 41 | Red Canary Case Creation |
| Scheduled Splunk detection scans executed | 40 | Get Splunk Detections |
| SaaS application data synced from Zylo for reporting | 11 | Ingest Zylo Data |
| Thinkst Canary alerts auto-processed | 5 | Thinkst Canary Notifications |
| Thinkst Canary cases auto-created | 3 | Thinkst Canary Case Creation |
| Security Alert Center (production) Jira tickets auto-ingested | 2 | Ingest SAC tickets |
| SACDEV case updates synced back to Jira | 1 | Update SACDEV Tickets |
Use Case Summary
| # | Use Case | Category | Subcategories | Total Playbooks | Active Playbooks |
|---|---|---|---|---|---|
| 1 | Multi-Source Alert Ingestion & Automated Case Management | SOC | Case mgmt & SOAR, SIEM & log pipeline monitoring | 36 | 18 |
| 2 | After-Hours Escalation & High-Priority Incident Response | SOC | Case mgmt & SOAR | 1 | 1 |
| 3 | Threat Intelligence Enrichment — Recorded Future & Multi-Tool IOC Lookup | SOC | Alert enrichment / IOC lookup, Threat intel ingest & curation | 14 | 0 |
| 4 | Agentic SOC & SIEM Threat Hunting | SOC | Agentic SOC, SIEM & log pipeline monitoring | 2 | 0 |
| 5 | Identity Investigation & User Enrichment | SOC | Identity threat response, Alert enrichment / IOC lookup | 9 | 0 |
| 6 | Phishing & Malware Incident Response | SOC | Phishing detection & response, EDR containment & response | 2 | 0 |
| 7 | EDR Containment & Endpoint Security Checks | SOC | EDR containment & response | 5 | 0 |
| 8 | Platform Error Handling & Reliability | Other | DevOps & release automation | 5 | 3 |
| 9 | Business Operations Data Ingestion | Other | SaaS / IT administration, IT helpdesk & ticket routing | 2 | 1 |
76 playbooks across 9 use cases — 23 active (30%)
Use Cases
1. Multi-Source Alert Ingestion & Automated Case Management
Description: A comprehensive SOAR platform that ingests security alerts from Splunk, SentinelOne, Red Canary, Thinkst Canary, and Jira SACDEV, then automatically creates, deduplicates, and enriches cases. Every new alert flows through a central processing engine that extracts observables, generates AI summaries, and writes structured case records.
Business Problem: Security teams managing multiple EDR, SIEM, and MDR tools face alert overload and inconsistent triage. This use case eliminates manual alert-to-case conversion, ensuring every alert is captured, deduplicated, and contextualised before reaching an analyst.
Integrations: Splunk, SentinelOne, Red Canary, Thinkst Canary, Jira, Blink Case Management
2. After-Hours Escalation & High-Priority Incident Response
Description: Monitors newly opened cases on a 5-minute polling interval and automatically evaluates whether the case is high-priority and opened outside business hours (Friday 20:00 – Monday 08:00 EST). Qualifying cases are immediately escalated to on-call staff via PagerDuty.
Business Problem: Gaps in after-hours coverage create unacceptable response lag for critical security incidents. This automation eliminates blind spots by ensuring every high-priority case opened during non-working hours pages the on-call analyst within minutes.
Integrations: PagerDuty, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| High-priority & Non-working Hour Pagerduty Escalation | 974 | SOC | Case mgmt & SOAR |
3. Threat Intelligence Enrichment — Recorded Future & Multi-Tool IOC Lookup
Description: A full-spectrum observable enrichment library that queries Recorded Future's SOAR API for IP and hash risk scores and verdicts, cross-references hashes against VirusTotal and CrowdStrike, analyzes URLs via URLScan (with screenshot capture), resolves domains via Whois and DNS, and checks product end-of-life status. All enrichment results write back to observable records in the case management system.
Business Problem: Manual threat intel lookups are slow and inconsistent. These workflows ensure every observable extracted from a case — IP, hash, domain, URL — is automatically enriched with risk scores, verdicts, and contextual data before an analyst engages.
Integrations: Recorded Future, VirusTotal, CrowdStrike, URLScan, Whois, Bash/DNS
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Enrichment - Recorded Future | 0 | SOC | Alert enrichment / IOC lookup, Threat intel ingest & curation |
| Enrich - IP - RF | 0 | SOC | Alert enrichment / IOC lookup, Threat intel ingest & curation |
| Enrich - Hash - RF copy | 0 | SOC | Alert enrichment / IOC lookup, Threat intel ingest & curation |
| Subflow - Update Enrichment Data | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | 0 | SOC | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | 0 | SOC | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | 0 | SOC | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | 0 | SOC | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | 0 | SOC | Alert enrichment / IOC lookup |
| Run Dig Command | 0 | SOC | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | 0 | SOC | Alert enrichment / IOC lookup |
| Run Splunk Search | 0 | SOC | SIEM & log pipeline monitoring |
| Ingest VPN IP data | 0 | SOC | Threat intel ingest & curation |
| Malware/Kasm list ingestion | 0 | SOC | Threat intel ingest & curation |
4. Agentic SOC & SIEM Threat Hunting
Description: AI agent-powered workflows that enable programmatic Splunk queries and IOC-based threat hunting. The Splunk Bot agent runs structured SIEM investigations, and the IOC Search Bot performs indicator lookups across the environment — both returning analyst-ready findings.
Business Problem: Threat hunting traditionally requires senior analyst expertise with SIEM query languages. These agentic workflows democratise structured threat hunting by allowing IOC searches and SIEM queries to be executed programmatically and on demand.
Integrations: Splunk, Blink AI Agents
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Splunk Agent Workflow | 0 | SOC | Agentic SOC, SIEM & log pipeline monitoring |
| IOC Search (Bots) | 0 | SOC | Agentic SOC, Alert enrichment / IOC lookup |
5. Identity Investigation & User Enrichment
Description: Provides analyst-ready user profiles by querying identity providers during investigations — covering Okta (user details and activity logs), Google Workspace, Microsoft Entra ID (including risky user signals), GitHub, and Slack. A dedicated workflow also tracks high-value users by correlating Jira EIP and PSIB ticket holders against Splunk activity data.
Business Problem: Identity context is essential for assessing blast radius and attacker dwell time. Without automation, analysts manually query multiple IAM systems per incident. These workflows consolidate multi-provider identity data into a single enrichment step.
Integrations: Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Jira, Splunk
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Enrich - Username or Email - Okta | 0 | SOC | Identity threat response, Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | 0 | SOC | Identity threat response, Alert enrichment / IOC lookup |
| Get User Information Using Okta | 0 | SOC | Identity threat response |
| Get User Information Using Google Workspace | 0 | SOC | Identity threat response |
| Get User Information Using Microsoft Entra ID | 0 | SOC | Identity threat response |
| Get User Information Using Github | 0 | SOC | Identity threat response |
| Get User Information on Email Address Using Slack | 0 | SOC | Identity threat response |
| Okta Search for User Activity | 0 | SOC | Identity threat response |
| High-Value users | 0 | SOC | Identity threat response |
6. Phishing & Malware Incident Response
Description: Dedicated response subflows for phishing email triage — including detection of KnowBe4 simulation campaigns to suppress false positives — and malware containment with remediation status evaluation. Both feed into the central response router.
Business Problem: Phishing and malware are the highest-volume, highest-risk incident types. These response playbooks enforce consistent handling at every stage, including simulation filtering, without requiring analyst judgment on routine cases.
Integrations: Microsoft Outlook, KnowBe4, Blink Case Management
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Response Subflow - Phishing | 0 | SOC | Phishing detection & response |
| Response Subflow - Malware | 0 | SOC | EDR containment & response |
7. EDR Containment & Endpoint Security Checks
Description: Enables rapid remote containment using CrowdStrike Real-Time Response (RTR) for both single hosts and batch operations, supports host isolation and lift-isolation actions, and runs Recorded Future-backed risk assessments against SentinelOne's blocklist and exemption list to validate their integrity against live threat intelligence.
Business Problem: Rapid endpoint isolation is a time-critical response action during active incidents. These workflows allow analysts to contain compromised hosts in seconds and proactively validate that SentinelOne exclusion and block configurations are not harbouring known-bad indicators.
Integrations: CrowdStrike, SentinelOne, Recorded Future
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| CrowdStrike RTR to a Single Host | 0 | SOC | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | 0 | SOC | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | SOC | EDR containment & response |
| S1 Blocklist Check | 0 | SOC | EDR containment & response, Threat intel ingest & curation |
| S1 Exemption List Check | 0 | SOC | EDR containment & response, Threat intel ingest & curation |
8. Platform Error Handling & Reliability
Description: Cross-platform error handling workflows that capture failures from any running automation via Blink's error event system and dispatch structured notification emails to the engineering team with error details, workflow stage, and execution URL for immediate debugging.
Business Problem: Silent automation failures erode trust and create undetected security gaps. These workflows act as a reliability net, ensuring every failure is surfaced and actioned in real time rather than discovered when an analyst notices a case was never created.
Integrations: Blink Email, Blink Event System
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Workflow Error Handling | 197 | Other | DevOps & release automation |
| Error Handling - Generate BlinOps Error Notification copy | 118 | Other | DevOps & release automation |
| Error Handling - Send Error Notification Email | 116 | Other | DevOps & release automation |
| Notification Failflow | 0 | Other | DevOps & release automation |
| Random Fact | 0 | Other | DevOps & release automation |
9. Business Operations Data Ingestion
Description: Ingests non-security operational data — SaaS application usage and spend metadata from Zylo and employee travel requests from Jira — for centralized reporting and tracking outside the core security pipeline.
Business Problem: Business operations data (SaaS spend visibility, travel request tracking) lived in disparate source systems without a consistent ingestion path. These workflows automate the pull of that data into shared reporting stores.
Integrations: Zylo, Splunk, Jira
| Playbook | Executions (12 mo) | Category | Subcategories |
|---|---|---|---|
| Ingest Zylo Data | 11 | Other | SaaS / IT administration |
| Jira - ingest Travel Requests | 0 | Other | IT helpdesk & ticket routing |
Key Observations
Strengths
1. Production-grade SOC automation at scale.
The core alert ingestion pipeline is active and operating at volume — 1,480 alerts triaged, 1,365 cases created, and 944 AI-enriched summaries generated over 12 months. This is a mature, battle-tested SOAR deployment covering multiple alert sources within a unified case model.
2. Multi-source alert unification.
Four distinct detection sources (Splunk, SentinelOne, Red Canary, Thinkst Canary) are normalised into a single case management model, giving analysts a unified operational view and eliminating source-specific tooling for triage.
3. Zero-gap after-hours coverage.
974 high-priority, after-hours cases were automatically escalated to PagerDuty — eliminating manual SLA monitoring outside business hours and ensuring critical incidents receive immediate on-call response regardless of time zone.
4. Agentic SOC capabilities deployed.
AI agent-based threat hunting workflows (Splunk Bot, IOC Search Bot) are deployed in a dedicated workspace and ready for programmatic threat investigation. These workflows represent a forward investment in Agentic SOC and are not yet generating execution volume — an expansion opportunity.
5. Robust reliability infrastructure.
313 combined error notifications across two error-handling workflows demonstrate an active reliability layer that surfaces automation failures in real time, preventing silent gaps in case coverage.
Gaps & Opportunities
1. Enrichment pipeline deployed but inactive.
Despite a comprehensive enrichment library spanning Recorded Future, VirusTotal, CrowdStrike, and URLScan (Use Cases 3 and 7), none of these workflows ran in the last 12 months. The enrichment router (Subflow - Enrich Observables - Main Router) also shows zero executions, suggesting the enrichment layer is built but not yet wired into the active alert processing pipeline. Activating this would deliver automatic IOC context on every observable for every case.
2. Identity enrichment dormant.
Nine identity investigation workflows spanning Okta, Entra ID, Google Workspace, GitHub, and Slack have zero executions. Connecting these to the case creation flow would give analysts immediate multi-provider identity context per incident without any additional effort.
3. Phishing and malware response subflows not triggered.
Both Response Subflow - Phishing and Response Subflow - Malware have zero executions. The phishing subflow includes KnowBe4 simulation detection logic, which is a sophisticated capability. These playbooks are built but appear not yet connected to the active response router.
4. EDR containment capabilities built but untriggered.
CrowdStrike RTR workflows for single and batch host isolation, and the quarantine management workflow, are deployed with zero executions. Making these available as manual-trigger actions in analyst case views would immediately accelerate containment response time.
5. Duplicate enrichment playbook.
Enrich - Hash - RF copy appears to be a duplicate of Enrichment - Recorded Future. Consolidating these would reduce maintenance overhead and remove ambiguity about which workflow is canonical.
6. Fragmented workspace structure.
Playbooks are spread across five distinct workspaces. The secondary workspaces (Splunk/agentic, S1 checks, high-value users) are entirely inactive. Evaluating whether these should be consolidated into the main workspace or formalised as separate functional domains would improve governance.
Integration Ecosystem
The deployment spans 16 distinct integrations across 7 categories:
| Integration | Category | Active in Production |
|---|---|---|
| Splunk | SIEM | Yes |
| SentinelOne | EDR | Yes |
| Jira | Ticketing | Yes |
| PagerDuty | Escalation | Yes |
| Red Canary | MDR | Yes |
| Thinkst Canary | Deception | Yes |
| CrowdStrike | EDR / Threat Intel | No |
| Recorded Future | Threat Intel | No |
| VirusTotal | Threat Intel | No |
| URLScan | Threat Intel | No |
| Okta | IAM | No |
| Microsoft Entra ID | IAM | No |
| Google Workspace | IAM | No |
| GitHub | Developer Tools | No |
| Slack | Collaboration | No |
| Microsoft Outlook | No |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.