01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC Alert Intake, Deduplication & Response Orchestration |
| 2.6% | 45 44 active |
| Automated Alert Enrichment & IOC Lookup |
| 0.2% | 30 30 active |
| Threat Intelligence Ingestion & Brand/Domain Monitoring | 0 executions | 0.0% | 10 10 active |
| Identity Threat Detection & Response |
| 0.7% | 75 75 active |
| Phishing Detection & Response | 0 executions | 0.0% | 12 12 active |
| DLP Triage & Data Exposure Response | 0 executions | 0.0% | 14 14 active |
| EDR Containment & Endpoint Response |
| 0.0% | 20 20 active |
| SOC Metrics, Dashboards & Log Pipeline Monitoring | 177 executions | 0.7% | 17 17 active |
| AD/Azure AD Group Membership & Access Automation |
| 88.3% | 37 34 active |
| Password & Credential Self-Service |
| 1.5% | 11 9 active |
| Employee Onboarding, Offboarding & Account Lifecycle |
| 5.7% | 24 23 active |
| Privileged & Service Account Management | 30 executions | 0.1% | 8 8 active |
| Endpoint & Device Hygiene (MDM Ops) | 0 executions | 0.0% | 5 2 active |
| Security Control Validation & Threat Hunting | 0 executions | 0.0% | 4 4 active |
| IT/OT & Network Infrastructure Monitoring | 0 executions | 0.0% | 3 3 active |
| Platform Administration, Testing & Migration Utilities | 0 executions | 0.0% | 16 13 active |
| Total | 24,393 executions | 100% | 331 318 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- A mature, centralized SOC response architecture. Rather than maintaining bespoke logic per alert source, Mr. Cooper has converged on a two-layer design: a broad intake layer of per-source alert playbooks feeding a single orchestration engine (*Alert Process v9*) that deduplicates cases, enriches observables through one shared subflow (*Subflow 3 - Enrich Observable*), and routes response actions through one shared decision engine (*Subflow 4 - Response*). This means new alert sources can be onboarded without duplicating enrichment or response logic, and it explains why many individual alert-type playbooks show zero executions in the trailing 12 months — they have been superseded by the unified router rather than abandoned.
- IAM is the highest-volume, highest-maturity automation domain. AD/Azure AD group membership management, employee offboarding (Workday-triggered), guest-account cleanup, and self-service password/MFA resets are fully automated end-to-end. These are the highest-frequency identity requests in any large enterprise, and removing them from help-desk queues is the single largest efficiency win visible in this environment.
- Consistent, reusable enrichment layer. A common set of enrichment playbooks (VirusTotal, URLScan.io, AbuseIPDB, Whois, CrowdStrike, Okta, LDAP) feed the shared enrichment subflow, ensuring every case gets the same quality of contextual data regardless of which system raised the original alert.
- Broad integration footprint. Automation spans SIEM (Splunk), EDR (CrowdStrike), identity (Active Directory, Microsoft Graph/Azure AD, Okta), PAM (CyberArk), network security (Zscaler), endpoint management (Absolute), phishing defense (Proofpoint TRAP), messaging/on-call (Slack, PagerDuty), and AI agent-based triage — indicating Blink operates as the central automation layer across the security and IT stack rather than a point solution.
Gaps & opportunities
- A large share of cataloged playbooks recorded zero executions in the last 12 months. Entire use cases — Threat Intelligence Ingestion, Phishing Detection & Response, DLP Triage, Endpoint & Device Hygiene, Security Control Validation & Threat Hunting, and IT/OT & Network Infrastructure Monitoring — show no recorded runs in the period. This may reflect event-driven playbooks with no qualifying events, environments awaiting trigger configuration, or genuinely stale/deprecated workflows; it's worth a workspace-by-workspace review to confirm which of these are dormant-by-design versus candidates for cleanup.
- Duplication across workspaces inflates the raw playbook count. The same tenant spans 12 workspaces (evident from repeated names like "Falcon," "Open Port Detected," "Executive WLP Check," and explicit "copy" suffixes), consistent with dev/test/prod segregation. This is normal, but it means the 387-playbook total overstates unique automation logic — the real footprint is closer to the 331 distinct playbook names — and periodic pruning of stale test/duplicate copies (e.g., *New Workflow 1*, *New Workflow 2*, *swap-test*, *Getting Started - Hello World*) would tighten the catalog.
- Raw execution volume is concentrated in a few high-fan-out subflows, not distinct business actions. Shared utility subflows like *Sub - Group Membership*, *Special Characters LDAP Parse*, and *Convert LDAP to Json* are invoked in loops by many parent playbooks, so their execution counts (in the thousands) reflect internal processing steps rather than completed business events. The KPI table intentionally reports counts from the top-level, business-facing playbooks instead, to keep the metrics meaningful to a non-technical audience.
Integration ecosystem
Active Directory · Microsoft Graph / Azure AD · Okta · CyberArk · CrowdStrike · Splunk · VirusTotal · URLScan.io · AbuseIPDB · IPWhois · Zscaler · Absolute · Proofpoint TRAP · Palo Alto Cortex XSOAR · PagerDuty · Slack · Microsoft Outlook · Microsoft Defender for Cloud Apps · AI Agents
A Case Management 53,003 cases (12m) | MTTR 1h 21m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| IR Team | 75,174 | 50,951 | 50,947 | 1h 21m |
| Temp Workspace | 2,052 | 2,052 | 0 | N/A |
B AI Agents 4 active | 72 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | DLP Email Review | IR Team | 28 | 0 | 968,796 |
| 2 | PhishGPT - Blink | IR Team | 22 | 0 | 1,589,706 |
| 3 | IP Enrichment Agent | IR Team | 21 | 0 | 987,231 |
| 4 | Hash Summary Agent | IR Team | 1 | 0 | 86,477 |
| 5 | Agent Blink | SecOps | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| IR Team | 72 |
| SecOps | 0 |
| shiran@blinkops.com | 0 |
| karin@blinkops.com | 0 |
| Temp Workspace | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | for cases? maybe | 0 | 0 |
| 2 | KRIs - Monthly | 0 | 0 |
| 3 | Human Involvement | 0 | 0 |
| 4 | Pager_Dashboard | 0 | 0 |
| 5 | MRC_Usage | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | header | 0 | 0 |
| 2 | MRC User Password Reset | 0 | 0 |
D Full Use Case Analysis 16 use cases | 24,393 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| AD/Azure AD group membership additions processed | 1,518 | MRC SecAdmin - Add Account to AD Group Only |
| Terminated-employee records synced from Workday to trigger offboarding | 960 | Pull Terminated Users |
| New hires auto-provisioned into required AD groups via LSAMS | 454 | Adding LSAMS User to AD Group |
| External/guest accounts stripped of all Azure AD group access | 408 | MRC SecAdmin - Remove All Azure Groups from External Account |
| External guest accounts disabled and fully deprovisioned in Azure AD | 370 | MRC SecAdmin - Disable External Guest Account in Azure AD and Remove from all Groups |
| Bulk AD/Azure AD group membership changes processed via CSV upload | 339 | MRC SecAdmin - Add/Remove To Group (CSV) |
| Self-service MFA resets completed for end users | 294 | User MFA Reset |
| Threat observables auto-enriched with threat intelligence | 248 | Subflow 3 - Enrich Observable |
| User accounts fully stripped of AD group access (offboarding/cleanup) | 167 | MRC SecAdmin - Remove Users from All Groups |
| Security alerts ingested, deduplicated & routed for automated response | 149 | Alert Process v9 |
| SOC cases auto-responded to based on alert type | 145 | Subflow 4 - Response |
| AD password-change-failure alerts opened as investigable cases | 120 | SOAR_AD_PasswordChangeFailure |
| Azure AD group membership changes processed for individual users | 92 | MRC SecAdmin - Add or Remove User from Azure AD Group Only |
| User identities enriched via LDAP lookup during investigations | 55 | Enrich Utility - Email or Username or DisplayName - LDAP |
| Self-service/help-desk password resets completed | 36 | MRC Service Desk - Account Reset Password |
| Admin (ADM) accounts provisioned | 29 | MRC SecAdmin - Create ADM Account |
| Service-account password-change alerts opened as cases | 27 | SOAR-Service Account password changed |
| Malicious/blocked URLs updated on the web proxy block list | 7 | Seceng - Add or Remove URLs from Zscaler Block |
| Compromised user sessions revoked in Azure AD | 5 | Revoke Azure Session |
Use Case Summary
| # | Use Case | Category | Playbooks | Executions (12mo) |
|---|---|---|---|---|
| 1 | Agentic SOC Alert Intake, Deduplication & Response Orchestration | SOC | 59 | 641 |
| 2 | Automated Alert Enrichment & IOC Lookup | SOC | 38 | 55 |
| 3 | Threat Intelligence Ingestion & Brand/Domain Monitoring | SOC | 12 | 0 |
| 4 | Identity Threat Detection & Response | SOC | 91 | 180 |
| 5 | Phishing Detection & Response | SOC | 12 | 0 |
| 6 | DLP Triage & Data Exposure Response | GRC | 14 | 0 |
| 7 | EDR Containment & Endpoint Response | SOC | 23 | 7 |
| 8 | SOC Metrics, Dashboards & Log Pipeline Monitoring | SOC | 22 | 177 |
| 9 | AD/Azure AD Group Membership & Access Automation | IAM | 41 | 21,545 |
| 10 | Password & Credential Self-Service | IAM | 11 | 368 |
| 11 | Employee Onboarding, Offboarding & Account Lifecycle | IAM | 25 | 1,395 |
| 12 | Privileged & Service Account Management | IAM | 8 | 30 |
| 13 | Endpoint & Device Hygiene (MDM Ops) | Other | 5 | 0 |
| 14 | Security Control Validation & Threat Hunting | Vulnerability Mgmt | 5 | 0 |
| 15 | IT/OT & Network Infrastructure Monitoring | Other | 5 | 0 |
| 16 | Platform Administration, Testing & Migration Utilities | Other | 16 | 0 |
Use Cases
1. Agentic SOC Alert Intake, Deduplication & Response Orchestration
Category: SOC
Subcategories: Agentic SOC, Case mgmt & SOAR
Description:
A single agentic engine ingests every new security alert, deduplicates it against open cases, enriches it with context, and routes it to the correct automated or analyst-assisted response path.
Business problem solved:
Analysts were manually triaging every alert one by one, re-investigating duplicate alerts, and losing time on case bookkeeping instead of real threats.
Integrations: Case Management · Case Management (System) · HTTP/Webhook · Microsoft Outlook · Palo Alto Cortex XSOAR · Utility
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Subflow 3 - Enrich Observable | 248 | Enriches every extracted observable on a case with threat intelligence before it reaches an analyst. |
| Alert Process v9 | 149 | Polls the case management system for new alerts every minute, extracts observables, deduplicates against open cases, enriches, and routes to the response subflow — the core intake engine for the whole SOC. |
| Subflow 4 - Response | 145 | Central response router: inspects the alert type on a processed case and branches into the correct automated remediation (DLP quarantine, attachment defense, click-permitted, IDP alerts, etc.). |
| Payload Formatter | 55 | Supports the agentic SOC case-management pipeline (Payload Formatter). |
| sub - Send SMS | 36 | Supports the agentic SOC case-management pipeline (sub - Send SMS). |
| Convert to List | 7 | Supports the agentic SOC case-management pipeline (Convert to List). |
| Process Alert | 1 | Supports the agentic SOC case-management pipeline (Process Alert). |
| Subflow 1 - Extract Observables | 0 | Parses the raw alert payload against its template to extract IOCs and entities for enrichment. |
| Subflow 2.1 - Get Deduplication Rule | 0 | Looks up the configured deduplication rule for the alert's product/title. |
| Subflow 2.2 - Check for Case Deduplicates | 0 | Checks an incoming alert against open cases to prevent duplicate case creation. |
| Subflow 2.3 - Link Alert to Existing Case | 0 | Links a duplicate alert to its existing open case instead of opening a new one. |
| Subflow 2 - Create Case | 0 | Creates a new case in the case management system for a non-duplicate alert. |
| Subflow - Missing Alert Template Notification | 0 | Supports the agentic SOC case-management pipeline (Subflow - Missing Alert Template Notification). |
| Subflow - Update Enrichment Data | 0 | Supports the agentic SOC case-management pipeline (Subflow - Update Enrichment Data). |
| Utility - Update Enrichment | 0 | Supports the agentic SOC case-management pipeline (Utility - Update Enrichment). |
| Utility - Close Stale Cases | 0 | Supports the agentic SOC case-management pipeline (Utility - Close Stale Cases). |
| Utility - Find Similar Cases | 0 | Supports the agentic SOC case-management pipeline (Utility - Find Similar Cases). |
| Utility - Update all enrichments | 0 | Supports the agentic SOC case-management pipeline (Utility - Update all enrichments). |
| Recovery - Enrich non-enriched observables | 0 | Supports the agentic SOC case-management pipeline (Recovery - Enrich non-enriched observables). |
| Recovery - Handle Unprocessed Alerts | 0 | Supports the agentic SOC case-management pipeline (Recovery - Handle Unprocessed Alerts). |
| Utility - Weekend Escalation Check | 0 | Supports the agentic SOC case-management pipeline (Utility - Weekend Escalation Check). |
| Auto Assign a Case | 0 | Supports the agentic SOC case-management pipeline (Auto Assign a Case). |
| Utility - Random Case Audit Tag | 0 | Supports the agentic SOC case-management pipeline (Utility - Random Case Audit Tag). |
| list timeline events issue | 0 | Supports the agentic SOC case-management pipeline (list timeline events issue). |
| Utility - Create Observables - Deduplication Handling | 0 | Supports the agentic SOC case-management pipeline (Utility - Create Observables - Deduplication Handling). |
| Subflow - Update Enrichment Data | 0 | Supports the agentic SOC case-management pipeline (Subflow - Update Enrichment Data). |
| Subflow 2.3 - Link Alert to Existing Case | 0 | Links a duplicate alert to its existing open case instead of opening a new one. |
| Subflow 2.2 - Check for Case Deduplicates | 0 | Checks an incoming alert against open cases to prevent duplicate case creation. |
| Subflow 2.1 - Get Deduplication Rule | 0 | Looks up the configured deduplication rule for the alert's product/title. |
| Subflow 1 - Extract Observables | 0 | Parses the raw alert payload against its template to extract IOCs and entities for enrichment. |
| Subflow 4 - Response | 0 | Central response router: inspects the alert type on a processed case and branches into the correct automated remediation (DLP quarantine, attachment defense, click-permitted, IDP alerts, etc.). |
| Utility - Overview Builder | 0 | Supports the agentic SOC case-management pipeline (Utility - Overview Builder). |
| Subflow 3 - Enrich Observable | 0 | Enriches every extracted observable on a case with threat intelligence before it reaches an analyst. |
| Subflow 2 - Create Case | 0 | Creates a new case in the case management system for a non-duplicate alert. |
| Subflow - Missing Alert Template Notification | 0 | Supports the agentic SOC case-management pipeline (Subflow - Missing Alert Template Notification). |
| Auto Assign | 0 | Supports the agentic SOC case-management pipeline (Auto Assign). |
| Random Case Audit | 0 | Supports the agentic SOC case-management pipeline (Random Case Audit). |
| Case Priority Escalation | 0 | Supports the agentic SOC case-management pipeline (Case Priority Escalation). |
| Rushmore EndpointBasecamp Alert Whitelist | 0 | Supports the agentic SOC case-management pipeline (Rushmore EndpointBasecamp Alert Whitelist). |
| Weekend Escalation Check | 0 | Supports the agentic SOC case-management pipeline (Weekend Escalation Check). |
| Pagerduty - Create Incident | 0 | Supports the agentic SOC case-management pipeline (Pagerduty - Create Incident). |
| Pagerduty - Create Incident | 0 | Supports the agentic SOC case-management pipeline (Pagerduty - Create Incident). |
| Weekend Escalation Check | 0 | Supports the agentic SOC case-management pipeline (Weekend Escalation Check). |
| Catchall Playbook | 0 | Supports the agentic SOC case-management pipeline (Catchall Playbook). |
| Case Priority Escalation | 0 | Supports the agentic SOC case-management pipeline (Case Priority Escalation). |
| Pagerduty - Create Incident | 0 | Supports the agentic SOC case-management pipeline (Pagerduty - Create Incident). |
| Sub - Esclate Case | 0 | Supports the agentic SOC case-management pipeline (Sub - Esclate Case). |
| sub - Send SMS IR | 0 | Supports the agentic SOC case-management pipeline (sub - Send SMS IR). |
| Send Mail | 0 | Supports the agentic SOC case-management pipeline (Send Mail). |
| Sub - Send SMS | 0 | Supports the agentic SOC case-management pipeline (Sub - Send SMS). |
| Sub - Send SMS | 0 | Supports the agentic SOC case-management pipeline (Sub - Send SMS). |
| Subflow - Update Enrichment Data copy copy | 0 | Supports the agentic SOC case-management pipeline (Subflow - Update Enrichment Data copy copy). |
| Payload Formatter copy | 0 | Supports the agentic SOC case-management pipeline (Payload Formatter copy). |
| Get Observables | 0 | Supports the agentic SOC case-management pipeline (Get Observables). |
| Screenshot to base64 | 0 | Supports the agentic SOC case-management pipeline (Screenshot to base64). |
| RKT Escalations | 0 | Supports the agentic SOC case-management pipeline (RKT Escalations). |
| Utility - Python Output To JSON | 0 | Supports the agentic SOC case-management pipeline (Utility - Python Output To JSON). |
| RKT - Create XSOAR Case | 0 | Supports the agentic SOC case-management pipeline (RKT - Create XSOAR Case). |
| Torq Redirect | 0 | Supports the agentic SOC case-management pipeline (Torq Redirect). |
2. Automated Alert Enrichment & IOC Lookup
Category: SOC
Subcategories: Alert enrichment / IOC lookup
Description:
A library of on-demand lookups automatically enriches observables (IPs, URLs, hashes, domains, users, hosts) with reputation and context data from threat intel and identity/EDR sources.
Business problem solved:
Analysts previously had to manually pivot across VirusTotal, AbuseIPDB, Whois, CrowdStrike, Okta and LDAP consoles for every single indicator in an alert.
Integrations: AI Agents · AbuseIPDB · CrowdStrike · HTTP/Webhook · Okta · URLScan.io · VirusTotal
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Enrich Utility - Email or Username or DisplayName - LDAP | 55 | Looks up Email or Username or DisplayName data via an LDAP directory lookup to enrich an observable during case investigation. |
| Enrich - Agent ID - Crowdstrike | 0 | Looks up Agent ID data via CrowdStrike to enrich an observable during case investigation. |
| Enrich - URL - URLScan | 0 | Looks up URL data via URLScan.io to enrich an observable during case investigation. |
| Enrich - Hash - VT | 0 | Looks up Hash data via VirusTotal to enrich an observable during case investigation. |
| Enrich - IP - IPDB | 0 | Looks up IP data via AbuseIPDB to enrich an observable during case investigation. |
| Enrich - IP - VT | 0 | Looks up IP data via VirusTotal to enrich an observable during case investigation. |
| Enrich - URL - VT | 0 | Looks up URL data via VirusTotal to enrich an observable during case investigation. |
| Enrich - IP - VT | 0 | Looks up IP data via VirusTotal to enrich an observable during case investigation. |
| Enrich - IP - IPDB | 0 | Looks up IP data via AbuseIPDB to enrich an observable during case investigation. |
| Enrich - Username or Email - Okta | 0 | Looks up Username or Email data via Okta to enrich an observable during case investigation. |
| Enrich - Agent ID - Crowdstrike | 0 | Looks up Agent ID data via CrowdStrike to enrich an observable during case investigation. |
| Enrich - Hash - VT | 0 | Looks up Hash data via VirusTotal to enrich an observable during case investigation. |
| Enrich - URL - URLScan | 0 | Looks up URL data via URLScan.io to enrich an observable during case investigation. |
| Enrich - URL - VT | 0 | Looks up URL data via VirusTotal to enrich an observable during case investigation. |
| CrowdStrike IOC search | 0 | Searches CrowdStrike telemetry for a given indicator of compromise. |
| is IP bad | 0 | Checks whether an IP address is known-malicious. |
| Enrich Observable - Email, Username, or DisplayName - LDAP | 0 | Looks up Email, Username, or DisplayName data via an LDAP directory lookup to enrich an observable during case investigation. |
| Enrich - Get Host Name Information - Crowdstrike | 0 | Looks up Get Host Name Information data via CrowdStrike to enrich an observable during case investigation. |
| Enrich - Get Hosts by IOC or Processes By Host - Crowdstrike | 0 | Looks up Get Hosts by IOC or Processes By Host data via CrowdStrike to enrich an observable during case investigation. |
| Enrich - Domain - VT | 0 | Looks up Domain data via VirusTotal to enrich an observable during case investigation. |
| Enrich Observables - All Types - VT | 0 | On-demand enrichment lookup (Enrich Observables - All Types - VT) used during case investigation. |
| Enrich Utility - IP/URL - Whois | 0 | Looks up IP/URL data via Whois to enrich an observable during case investigation. |
| Enrich Utility - Hash - VT | 0 | Looks up Hash data via VirusTotal to enrich an observable during case investigation. |
| Enrich Utility - URL\Domain - Whois | 0 | Looks up URL\Domain data via Whois to enrich an observable during case investigation. |
| Enrich Utility - IP - Whois | 0 | Looks up IP data via Whois to enrich an observable during case investigation. |
| Enrich - IP - Whois | 0 | Looks up IP data via Whois to enrich an observable during case investigation. |
| Enrich - Domain - Whois | 0 | Looks up Domain data via Whois to enrich an observable during case investigation. |
| IR - MRC Site Check | 0 | Checks the status of an MRC-owned site during investigation. |
| Create IOC In Crowdstrike | 0 | Publishes a confirmed indicator of compromise into CrowdStrike for detection. |
| IR - Check if URL is Blocked | 0 | Checks whether a URL is already blocked at the web proxy. |
| Validate URL | 0 | Validates that a URL observable is well-formed before further analysis. |
| Enrich Utility - URL\Domain - Whois | 0 | Looks up URL\Domain data via Whois to enrich an observable during case investigation. |
| Validate URL | 0 | Validates that a URL observable is well-formed before further analysis. |
| Python Get DNS Records | 0 | Resolves DNS records for a domain observable. |
| Agent - Run Whois Command | 0 | AI-agent-driven Whois lookup for a domain/IP observable. |
| Get Geolocation of an IPV4 Address | 0 | Resolves the geolocation of an IP address for enrichment. |
| IP Enrichment Agent Workflow- Will | 0 | AI agent that enriches an IP observable end-to-end across multiple sources. |
| Agent - Scan IP Address in IPDB | 0 | AI-agent-driven AbuseIPDB reputation check for an IP observable. |
3. Threat Intelligence Ingestion & Brand/Domain Monitoring
Category: SOC
Subcategories: Threat intel ingest & curation
Description:
Ingests curated threat intelligence feeds (Recorded Future and internal brand-monitoring sources) and opens cases for identity exposure, domain abuse, and typosquatting targeting the Mr. Cooper brand.
Business problem solved:
External threats against the company's brand and domains (typosquatting, leaked credentials, domain abuse) need continuous monitoring that no analyst can do manually at scale.
Integrations: Case Management · Case Management (System) · HTTP/Webhook · Slack · Splunk · Templates
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| RF - Classic Alerts | 0 | Ingests and cases the 'RF - Classic Alerts' threat-intelligence alert. |
| RF - Identity Exposure | 0 | Ingests and cases the 'RF - Identity Exposure' threat-intelligence alert. |
| MrC Threat Intel | 0 | Ingests and cases the 'MrC Threat Intel' threat-intelligence alert. |
| Typosquat MRC Domain | 0 | Ingests and cases the 'Typosquat MRC Domain' threat-intelligence alert. |
| Recorded Future | 0 | Ingests and cases the 'Recorded Future' threat-intelligence alert. |
| RF Domain Alert | 0 | Ingests and cases the 'RF Domain Alert' threat-intelligence alert. |
| RF - Identity Exposure | 0 | Ingests and cases the 'RF - Identity Exposure' threat-intelligence alert. |
| RF - Playbook Alerts | 0 | Ingests and cases the 'RF - Playbook Alerts' threat-intelligence alert. |
| Domain Abuse | 0 | Ingests and cases the 'Domain Abuse' threat-intelligence alert. |
| RF Domain Workflow | 0 | Ingests and cases the 'RF Domain Workflow' threat-intelligence alert. |
| RF Domain Workflow | 0 | Ingests and cases the 'RF Domain Workflow' threat-intelligence alert. |
| RF Identity Workflow- Will | 0 | Ingests and cases the 'RF Identity Workflow- Will' threat-intelligence alert. |
4. Identity Threat Detection & Response
Category: SOC
Subcategories: Identity threat response
Description:
The largest single detection catalog in the environment: dozens of playbooks ingest identity and access anomalies (impossible travel, brute force, risky sign-ins, privilege changes, password policy violations) from Splunk, Azure AD, Okta and CrowdStrike, case them automatically, and take remediation actions such as revoking sessions or releasing cleared users.
Business problem solved:
Identity-based attacks (compromised credentials, privilege abuse, anomalous logins) are the highest-volume threat vector and require 24/7 automated detection and consistent, fast response.
Integrations: AbuseIPDB · Active Directory · Case Management · Case Management (System) · CrowdStrike · HTTP/Webhook · IPWhois · Microsoft Defender for Cloud Apps · Microsoft Graph / Azure AD · Microsoft Outlook · Splunk · Utility · VirusTotal
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| SOAR_AD_PasswordChangeFailure | 120 | Ingests an AD password-change-failure detection via webhook and opens a case. |
| SOAR-Service Account password changed | 27 | Ingests a service-account password-change detection and opens a case for review. |
| P2-workflow_SOAR-Service Account password changed | 27 | On-demand/manual re-run path for service-account password-change case creation. |
| Revoke Azure Session | 5 | Revokes the active Azure AD session(s) for a compromised or suspicious account. |
| IR-Lookup user contractor or employee | 1 | Looks up whether a user under investigation is an employee or contractor. |
| User Risk v2 | 0 | Ingests and cases the 'User Risk v2' identity/access security alert for investigation and automated response. |
| O365 | 0 | Ingests and cases the 'O365' identity/access security alert for investigation and automated response. |
| ADM Account in Wrong OU | 0 | Ingests and cases the 'ADM Account in Wrong OU' identity/access security alert for investigation and automated response. |
| MRC - Download Outside US or India | 0 | Ingests and cases the 'MRC - Download Outside US or India' identity/access security alert for investigation and automated response. |
| PIM role activated | 0 | Ingests and cases the 'PIM role activated' identity/access security alert for investigation and automated response. |
| Suspicious activity - WhatsApp | 0 | Ingests and cases the 'Suspicious activity - WhatsApp' identity/access security alert for investigation and automated response. |
| Kerberos Pre-Auth Not Required Set | 0 | Ingests and cases the 'Kerberos Pre-Auth Not Required Set' identity/access security alert for investigation and automated response. |
| Identity verification denied | 0 | Ingests and cases the 'Identity verification denied' identity/access security alert for investigation and automated response. |
| Unauthorized Machine Access v2 | 0 | Ingests and cases the 'Unauthorized Machine Access v2' identity/access security alert for investigation and automated response. |
| IDP-session-alert | 0 | Ingests and cases the 'IDP-session-alert' identity/access security alert for investigation and automated response. |
| IT User Check | 0 | Ingests and cases the 'IT User Check' identity/access security alert for investigation and automated response. |
| Unfamiliar sign-in properties | 0 | Ingests and cases the 'Unfamiliar sign-in properties' identity/access security alert for investigation and automated response. |
| Break Glass account logon | 0 | Ingests and cases the 'Break Glass account logon' identity/access security alert for investigation and automated response. |
| authenticated from 2 countries | 0 | Ingests and cases the 'authenticated from 2 countries' identity/access security alert for investigation and automated response. |
| MRC - INFREQUENT COUNTRIES | 0 | Ingests and cases the 'MRC - INFREQUENT COUNTRIES' identity/access security alert for investigation and automated response. |
| Risky User to IS_Group3 | 0 | Ingests and cases the 'Risky User to IS_Group3' identity/access security alert for investigation and automated response. |
| Password Not Required Set | 0 | Ingests and cases the 'Password Not Required Set' identity/access security alert for investigation and automated response. |
| MRC - Impossible travel | 0 | Ingests and cases the 'MRC - Impossible travel' identity/access security alert for investigation and automated response. |
| MRC Abnormal Zscaler Host | 0 | Ingests and cases the 'MRC Abnormal Zscaler Host' identity/access security alert for investigation and automated response. |
| Password Brute Force - Web or Cloud Based | 0 | Ingests and cases the 'Password Brute Force - Web or Cloud Based' identity/access security alert for investigation and automated response. |
| Password Never Expires Set | 0 | Ingests and cases the 'Password Never Expires Set' identity/access security alert for investigation and automated response. |
| AD Account Creation | 0 | Ingests and cases the 'AD Account Creation' identity/access security alert for investigation and automated response. |
| Risky Sign-in | 0 | Ingests and cases the 'Risky Sign-in' identity/access security alert for investigation and automated response. |
| CrowdStrike BruteForce AD | 0 | Ingests and cases the 'CrowdStrike BruteForce AD' identity/access security alert for investigation and automated response. |
| Unconstrained Delegation Set on Account | 0 | Ingests and cases the 'Unconstrained Delegation Set on Account' identity/access security alert for investigation and automated response. |
| ObserveIT | 0 | Ingests and cases the 'ObserveIT' identity/access security alert for investigation and automated response. |
| MRC - High Risk Tokens | 0 | Ingests and cases the 'MRC - High Risk Tokens' identity/access security alert for investigation and automated response. |
| Password Change Failure | 0 | Ingests and cases the 'Password Change Failure' identity/access security alert for investigation and automated response. |
| Add to IS_Group3 | 0 | Ingests and cases the 'Add to IS_Group3' identity/access security alert for investigation and automated response. |
| Unauthorized Local Admin | 0 | Ingests and cases the 'Unauthorized Local Admin' identity/access security alert for investigation and automated response. |
| Password Changed Notification | 0 | Ingests and cases the 'Password Changed Notification' identity/access security alert for investigation and automated response. |
| PIM Role Granted | 0 | Ingests and cases the 'PIM Role Granted' identity/access security alert for investigation and automated response. |
| Service Account password change | 0 | Ingests and cases the 'Service Account password change' identity/access security alert for investigation and automated response. |
| Risky User Removal | 0 | Ingests and cases the 'Risky User Removal' identity/access security alert for investigation and automated response. |
| TRYING TO STOP OBSERVEIT | 0 | Ingests and cases the 'TRYING TO STOP OBSERVEIT' identity/access security alert for investigation and automated response. |
| Risky User Removal | 0 | Ingests and cases the 'Risky User Removal' identity/access security alert for investigation and automated response. |
| Service Account password change | 0 | Ingests and cases the 'Service Account password change' identity/access security alert for investigation and automated response. |
| PIM Role Granted | 0 | Ingests and cases the 'PIM Role Granted' identity/access security alert for investigation and automated response. |
| Add to IS_Group3 | 0 | Ingests and cases the 'Add to IS_Group3' identity/access security alert for investigation and automated response. |
| Unauthorized Local Admin | 0 | Ingests and cases the 'Unauthorized Local Admin' identity/access security alert for investigation and automated response. |
| Password Changed Notification | 0 | Ingests and cases the 'Password Changed Notification' identity/access security alert for investigation and automated response. |
| TRYING TO STOP OBSERVEIT | 0 | Ingests and cases the 'TRYING TO STOP OBSERVEIT' identity/access security alert for investigation and automated response. |
| TRYING TO STOP OBSERVEIT | 0 | Ingests and cases the 'TRYING TO STOP OBSERVEIT' identity/access security alert for investigation and automated response. |
| Unauthorized Local Admin | 0 | Ingests and cases the 'Unauthorized Local Admin' identity/access security alert for investigation and automated response. |
| Service Account password change | 0 | Ingests and cases the 'Service Account password change' identity/access security alert for investigation and automated response. |
| Risky User Removal | 0 | Ingests and cases the 'Risky User Removal' identity/access security alert for investigation and automated response. |
| PIM Role Granted | 0 | Ingests and cases the 'PIM Role Granted' identity/access security alert for investigation and automated response. |
| User Risk v2 | 0 | Ingests and cases the 'User Risk v2' identity/access security alert for investigation and automated response. |
| O365 | 0 | Ingests and cases the 'O365' identity/access security alert for investigation and automated response. |
| Quick Add Risky users | 0 | Ingests and cases the 'Quick Add Risky users' identity/access security alert for investigation and automated response. |
| O365 - Unfamiliar sign-in properties | 0 | Ingests and cases the 'O365 - Unfamiliar sign-in properties' identity/access security alert for investigation and automated response. |
| Pim role activated | 0 | Ingests and cases the 'Pim role activated' identity/access security alert for investigation and automated response. |
| Non-admin added to Admin group | 0 | Ingests and cases the 'Non-admin added to Admin group' identity/access security alert for investigation and automated response. |
| IT User Check | 0 | Ingests and cases the 'IT User Check' identity/access security alert for investigation and automated response. |
| O365 - MRC - Download Outside US or India | 0 | Ingests and cases the 'O365 - MRC - Download Outside US or India' identity/access security alert for investigation and automated response. |
| SOAR-BreakGlass account used | 0 | Ingests and cases the 'SOAR-BreakGlass account used' identity/access security alert for investigation and automated response. |
| SOAR-Admin in wrong OU | 0 | Ingests and cases the 'SOAR-Admin in wrong OU' identity/access security alert for investigation and automated response. |
| Subflow-SOAR_AD_AccountCreated | 0 | Ingests and cases the 'Subflow-SOAR_AD_AccountCreated' identity/access security alert for investigation and automated response. |
| sub_flow_SOAR_AD_KerberosPreAuthNotRequired | 0 | Ingests and cases the 'sub_flow_SOAR_AD_KerberosPreAuthNotRequired' identity/access security alert for investigation and automated response. |
| P2_workflow_SOAR_MFADeclined | 0 | Ingests and cases the 'P2_workflow_SOAR_MFADeclined' identity/access security alert for investigation and automated response. |
| P2_Workflow_SOAR_AD_PasswordNotRequired | 0 | Ingests and cases the 'P2_Workflow_SOAR_AD_PasswordNotRequired' identity/access security alert for investigation and automated response. |
| SOAR_AD_SuspiciousPrivAcctPWChange | 0 | Ingests and cases the 'SOAR_AD_SuspiciousPrivAcctPWChange' identity/access security alert for investigation and automated response. |
| P2-SOAR_AD_SuspiciousPrivAcctPWChange | 0 | Ingests and cases the 'P2-SOAR_AD_SuspiciousPrivAcctPWChange' identity/access security alert for investigation and automated response. |
| Add To Risky User Group | 0 | Ingests and cases the 'Add To Risky User Group' identity/access security alert for investigation and automated response. |
| SOAR_AD_PasswordChangeFailure | 0 | Ingests an AD password-change-failure detection via webhook and opens a case. |
| Splunk - Risky User Release | 0 | Ingests and cases the 'Splunk - Risky User Release' identity/access security alert for investigation and automated response. |
| Automated Risky User Release | 0 | Ingests and cases the 'Automated Risky User Release' identity/access security alert for investigation and automated response. |
| SOAR - User reported Suspicious MFA | 0 | Ingests and cases the 'SOAR - User reported Suspicious MFA' identity/access security alert for investigation and automated response. |
| p2-SOAR - User reported Suspicious MFA | 0 | Ingests and cases the 'p2-SOAR - User reported Suspicious MFA' identity/access security alert for investigation and automated response. |
| O365 - Creation of forwarding/redirect rule | 0 | Ingests and cases the 'O365 - Creation of forwarding/redirect rule ' identity/access security alert for investigation and automated response. |
| O365 - eDiscovery search started or exported | 0 | Ingests and cases the 'O365 - eDiscovery search started or exported' identity/access security alert for investigation and automated response. |
| Proofpoint add to Risky users | 0 | Ingests and cases the 'Proofpoint add to Risky users' identity/access security alert for investigation and automated response. |
| P2_IDP - Unusual login to an endpoint | 0 | Ingests and cases the 'P2_IDP - Unusual login to an endpoint' identity/access security alert for investigation and automated response. |
| O365 - Logon activity from a potentially harmful application | 0 | Ingests and cases the 'O365 - Logon activity from a potentially harmful application' identity/access security alert for investigation and automated response. |
| CrackShack Webhook | 0 | Ingests and cases the 'CrackShack Webhook' identity/access security alert for investigation and automated response. |
| Intern PWNED Pass Policy DRAFT | 0 | Ingests and cases the 'Intern PWNED Pass Policy DRAFT' identity/access security alert for investigation and automated response. |
| Intern Remove Pwned USers | 0 | Ingests and cases the 'Intern Remove Pwned USers' identity/access security alert for investigation and automated response. |
| IDP PW Brute Force attack (web-based) | 0 | Ingests and cases the 'IDP PW Brute Force attack (web-based)' identity/access security alert for investigation and automated response. |
| IDP - Suspicious web-based activity (ML) | 0 | Ingests and cases the 'IDP - Suspicious web-based activity (ML)' identity/access security alert for investigation and automated response. |
| P2_IDP - Suspicious web-based activity (ML) | 0 | Ingests and cases the 'P2_IDP - Suspicious web-based activity (ML)' identity/access security alert for investigation and automated response. |
| IDP - Identity verification denied | 0 | Ingests and cases the 'IDP - Identity verification denied' identity/access security alert for investigation and automated response. |
| IDP PW Brute Force Attack (Active Directory) | 0 | Ingests and cases the 'IDP PW Brute Force Attack (Active Directory)' identity/access security alert for investigation and automated response. |
| IDP - Access from multiple locations concurrently workflow | 0 | Ingests and cases the 'IDP - Access from multiple locations concurrently workflow' identity/access security alert for investigation and automated response. |
| Splunk -user removed from Adminstrator group | 0 | Ingests and cases the 'Splunk -user removed from Adminstrator group' identity/access security alert for investigation and automated response. |
| Splunk - Watched Users Add | 0 | Ingests and cases the 'Splunk - Watched Users Add' identity/access security alert for investigation and automated response. |
| IDP - Suspicious Login | 0 | Ingests and cases the 'IDP - Suspicious Login' identity/access security alert for investigation and automated response. |
5. Phishing Detection & Response
Category: SOC
Subcategories: Phishing detection & response
Description:
Automates the intake and handling of reported and detected phishing/malicious email activity, integrating with Proofpoint, PhishAlarm and an internal PhishGPT triage assistant.
Business problem solved:
Phishing is the most common intrusion vector and manual review of every reported email does not scale with employee reporting volume.
Integrations: AI Agents · Case Management · Case Management (System) · CrowdStrike · HTTP/Webhook · Microsoft Outlook · Proofpoint TRAP · Splunk
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Subflow - Phishing | 0 | Handles the 'Subflow - Phishing' step of phishing report/detection triage. |
| TAP Attachment Defense | 0 | Handles the 'TAP Attachment Defense' step of phishing report/detection triage. |
| PhishAlarm Manual Review | 0 | Handles the 'PhishAlarm Manual Review' step of phishing report/detection triage. |
| Email Release | 0 | Handles the 'Email Release' step of phishing report/detection triage. |
| IR - Ask PhishGPT | 0 | Handles the 'IR - Ask PhishGPT' step of phishing report/detection triage. |
| ClickPermitted Playbook | 0 | Handles the 'ClickPermitted Playbook' step of phishing report/detection triage. |
| AttachmentDefense | 0 | Handles the 'AttachmentDefense' step of phishing report/detection triage. |
| P2-PhishAlarm | 0 | Handles the 'P2-PhishAlarm' step of phishing report/detection triage. |
| PhishGPT Webhook | 0 | Handles the 'PhishGPT Webhook' step of phishing report/detection triage. |
| Push To PhishGPT | 0 | Handles the 'Push To PhishGPT' step of phishing report/detection triage. |
| David - Abnormal Threat Email | 0 | Handles the 'David - Abnormal Threat Email' step of phishing report/detection triage. |
| PhishGPT Agent Test | 0 | Handles the 'PhishGPT Agent Test' step of phishing report/detection triage. |
6. DLP Triage & Data Exposure Response
Category: GRC
Subcategories: DLP triage & exposure resp
Description:
Ingests data-loss-prevention alerts (large file transfers, quarantines, sensitive document printing, Varonis data-security alerts) and automates triage, release and reporting.
Business problem solved:
Sensitive data exposure events must be triaged and, where legitimate, released quickly without waiting on a human queue.
Integrations: AI Agents · Case Management · Case Management (System) · Microsoft Outlook · Splunk · Utility
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Personal Email Lookup | 0 | Ingests and triages the 'Personal Email Lookup' data-loss-prevention alert. |
| MRC - PRINTING SENSITIVE DOCUMENTS | 0 | Ingests and triages the 'MRC - PRINTING SENSITIVE DOCUMENTS' data-loss-prevention alert. |
| DLP 25MB Alert | 0 | Ingests and triages the 'DLP 25MB Alert' data-loss-prevention alert. |
| DLP Quarantine Alert | 0 | Ingests and triages the 'DLP Quarantine Alert' data-loss-prevention alert. |
| DLP Quarantine Response | 0 | Ingests and triages the 'DLP Quarantine Response' data-loss-prevention alert. |
| Splunk DLP Enumeration | 0 | Ingests and triages the 'Splunk DLP Enumeration' data-loss-prevention alert. |
| DLP Release - Self Service | 0 | Ingests and triages the 'DLP Release - Self Service' data-loss-prevention alert. |
| Varonis Alert | 0 | Ingests and triages the 'Varonis Alert' data-loss-prevention alert. |
| Update Personal Email Address into Splunk Lookup Table | 0 | Ingests and triages the 'Update Personal Email Address into Splunk Lookup Table' data-loss-prevention alert. |
| DLP Bot - kai | 0 | Ingests and triages the 'DLP Bot - kai' data-loss-prevention alert. |
| DLPBot - Slack | 0 | Ingests and triages the 'DLPBot - Slack' data-loss-prevention alert. |
| DLP Email Review (Orchestrator) | 0 | Ingests and triages the 'DLP Email Review (Orchestrator)' data-loss-prevention alert. |
| Create DLP Sample Alert | 0 | Ingests and triages the 'Create DLP Sample Alert' data-loss-prevention alert. |
| DLP Sample Alert | 0 | Ingests and triages the 'DLP Sample Alert' data-loss-prevention alert. |
7. EDR Containment & Endpoint Response
Category: SOC
Subcategories: EDR containment & response
Description:
Automates endpoint detection and response actions on top of CrowdStrike Falcon and related tooling: host containment, IOC blocking, local admin removal, and malware/persistence alert handling.
Business problem solved:
Compromised endpoints need to be contained within minutes, not the hours it takes to reach an on-call analyst.
Integrations: Case Management · Case Management (System) · CrowdStrike · PagerDuty · Splunk · String Utils · Zscaler
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Seceng - Add or Remove URLs from Zscaler Block | 7 | Adds or removes URLs from the Zscaler web-proxy block list. |
| Subflow - Malware | 0 | Executes the 'Subflow - Malware' endpoint detection/containment action. |
| CPL Detection T1218_002 | 0 | Executes the 'CPL Detection T1218_002' endpoint detection/containment action. |
| Suspicious activity - Custom IOA | 0 | Executes the 'Suspicious activity - Custom IOA' endpoint detection/containment action. |
| NGAV | 0 | Executes the 'NGAV' endpoint detection/containment action. |
| Falcon | 0 | Executes the 'Falcon' endpoint detection/containment action. |
| Host Riskv2 | 0 | Executes the 'Host Riskv2' endpoint detection/containment action. |
| Risky Host Removal | 0 | Executes the 'Risky Host Removal' endpoint detection/containment action. |
| Risky Host Removal | 0 | Executes the 'Risky Host Removal' endpoint detection/containment action. |
| Risky Host Removal | 0 | Executes the 'Risky Host Removal' endpoint detection/containment action. |
| Falcon | 0 | Executes the 'Falcon' endpoint detection/containment action. |
| Response - Detect/Block IOCs on all Host Groups - Crowdstrike | 0 | Executes the 'Response - Detect/Block IOCs on all Host Groups - Crowdstrike' endpoint detection/containment action. |
| Falcon Custom IOA | 0 | Executes the 'Falcon Custom IOA' endpoint detection/containment action. |
| IR - Add To Zscaler Group | 0 | Executes the 'IR - Add To Zscaler Group' endpoint detection/containment action. |
| Kill User | 0 | Executes the 'Kill User' endpoint detection/containment action. |
| IR - Add OR Remove local Admin | 0 | Executes the 'IR - Add OR Remove local Admin' endpoint detection/containment action. |
| IR - Host Containment | 0 | Executes the 'IR - Host Containment' endpoint detection/containment action. |
| IR - Multiple Host Containment | 0 | Executes the 'IR - Multiple Host Containment' endpoint detection/containment action. |
| SOARBY - Host Containment | 0 | Executes the 'SOARBY - Host Containment ' endpoint detection/containment action. |
| SOARBY - Lift Host contaiment | 0 | Executes the 'SOARBY - Lift Host contaiment ' endpoint detection/containment action. |
| P2-Overwatch High enrichment | 0 | Executes the 'P2-Overwatch High enrichment' endpoint detection/containment action. |
| P2-BitsAdmin Job Persistence Alert | 0 | Executes the 'P2-BitsAdmin Job Persistence Alert' endpoint detection/containment action. |
| P2-KVM_Spoof | 0 | Executes the 'P2-KVM_Spoof' endpoint detection/containment action. |
8. SOC Metrics, Dashboards & Log Pipeline Monitoring
Category: SOC
Subcategories: SIEM & log pipeline monitoring
Description:
Scheduled jobs that refresh SOC dashboards, executive watchlists and lookup tables, and generate recurring security metrics reporting from Splunk and case management data.
Business problem solved:
Leadership and analysts need continuously fresh dashboards and metrics without manual report generation each day/week.
Integrations: Case Management · Case Management (System) · HTTP/Webhook · Microsoft Outlook · Splunk
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Sched - Top 5 Hosts | 40 | Scheduled/utility job supporting SOC reporting: Sched - Top 5 Hosts. |
| Update CF Domain Table | 40 | Scheduled/utility job supporting SOC reporting: Update CF Domain Table. |
| Sched - Top 5 UserName | 40 | Scheduled/utility job supporting SOC reporting: Sched - Top 5 UserName. |
| Exec WLP Daily Refresh | 40 | Scheduled/utility job supporting SOC reporting: Exec WLP Daily Refresh. |
| Account failure and lockout locations | 6 | Scheduled/utility job supporting SOC reporting: Account failure and lockout locations. |
| Weekly IR Dashboard Metrics | 5 | Generates the weekly incident-response metrics dashboard. |
| IR - Get User Details | 5 | Looks up identity/account details for a user under investigation. |
| SecAdmin - Get User Details | 1 | Looks up account details for a Security Admin request. |
| Executive WLP Check | 0 | Scheduled/utility job supporting SOC reporting: Executive WLP Check. |
| Executive WLP Check | 0 | Scheduled/utility job supporting SOC reporting: Executive WLP Check. |
| Update Network Ranges | 0 | Scheduled/utility job supporting SOC reporting: Update Network Ranges. |
| Update Executive Watchlist | 0 | Scheduled/utility job supporting SOC reporting: Update Executive Watchlist. |
| Update Network Ranges | 0 | Scheduled/utility job supporting SOC reporting: Update Network Ranges. |
| Update Executive Watchlist | 0 | Scheduled/utility job supporting SOC reporting: Update Executive Watchlist. |
| Update Executive Watchlist | 0 | Scheduled/utility job supporting SOC reporting: Update Executive Watchlist. |
| Update Network Ranges | 0 | Scheduled/utility job supporting SOC reporting: Update Network Ranges. |
| SOARBY - WLP Term | 0 | Scheduled/utility job supporting SOC reporting: SOARBY - WLP Term. |
| Executive WLP Check copy | 0 | Scheduled/utility job supporting SOC reporting: Executive WLP Check copy. |
| IR - HPC Info | 0 | Scheduled/utility job supporting SOC reporting: IR - HPC Info. |
| Search for Customer Email | 0 | Scheduled/utility job supporting SOC reporting: Search for Customer Email. |
| Search Azure Logins- Last 24hrs | 0 | Scheduled/utility job supporting SOC reporting: Search Azure Logins- Last 24hrs. |
| exec_user_pager_alert | 0 | Scheduled/utility job supporting SOC reporting: exec_user_pager_alert. |
9. AD/Azure AD Group Membership & Access Automation
Category: IAM
Subcategories: Access review & group mgmt, Identity sync & directory mgmt, JIT & temporary access
Description:
The highest-volume automation in the environment: adds, removes and audits Active Directory and Azure AD group memberships on request, via CSV bulk upload, or via time-based/scheduled rules, with dedicated subflows that normalize and deduplicate LDAP data.
Business problem solved:
Group membership requests (grant, remove, bulk CSV changes, external-guest cleanup) were manual help-desk work; every request also had to be parsed from inconsistent LDAP output before it could be actioned.
Integrations: Active Directory · Extraction Utility · HTTP/Webhook · Microsoft Graph / Azure AD · Microsoft Outlook · Utility
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Sub - Group Membership | 6,453 | Core subflow that adds or removes a user from an AD/Azure AD group, called by every group-management playbook. |
| Special Characters LDAP Parse | 6,453 | Sanitizes group names containing special characters before LDAP lookups. |
| Convert LDAP to Json | 3,612 | Converts raw LDAP query output into structured JSON for downstream processing. |
| MRC SecAdmin - Add Account to AD Group Only | 1,518 | Adds one or more accounts to a specified AD group from a Security Admin ticket request. |
| HPC Schedule Run | 960 | Hourly scheduled job that processes queued high-privilege/time-based group membership changes. |
| RKT HPC Schedule Run | 960 | Hourly scheduled job (Rocket brand) that processes queued high-privilege/time-based group membership changes. |
| Adding LSAMS User to AD Group | 454 | Adds a user to the required AD group automatically when LSAMS raises a provisioning webhook, then emails confirmation. |
| MRC SecAdmin - Remove All Azure Groups from External Account | 408 | Strips every Azure AD group assignment from an external/guest account. |
| MRC SecAdmin - Add/Remove To Group (CSV) | 339 | Bulk adds/removes group membership for a list of users submitted via CSV upload. |
| MRC SecAdmin - Remove Users from All Groups | 167 | Strips a user account of all AD group memberships in one run. |
| MRC SecAdmin - Add or Remove User from Azure AD Group Only | 92 | Adds or removes a single user from a specified Azure AD group. |
| MRC SecAdmin - Remove Account from a AD Group Only | 59 | Removes a specified account from an AD group. |
| MRC Messaging - Add User to AD Group | 45 | Adds a Messaging-team-requested user to an AD group. |
| MRC SecAdmin - Create/Delete Groups | 18 | Creates or deletes an AD/Azure AD group on request. |
| Convert LDAP to Json | 5 | Converts raw LDAP query output into structured JSON for downstream processing. |
| MRC SecAdmin - Azure Group Bulk Creation | 2 | Bulk-creates multiple Azure AD groups from a submitted list. |
| LDAP integration | 0 | AD/Azure AD group-membership operation: LDAP integration. |
| LDAP - add or remove user to group | 0 | AD/Azure AD group-membership operation: LDAP - add or remove user to group. |
| Sub - Move OUs | 0 | AD/Azure AD group-membership operation: Sub - Move OUs. |
| Sub - Static Group List Add | 0 | AD/Azure AD group-membership operation: Sub - Static Group List Add. |
| Sub - Static Group List Remove | 0 | AD/Azure AD group-membership operation: Sub - Static Group List Remove. |
| IR- Add or Remove user from AD group | 0 | AD/Azure AD group-membership operation: IR- Add or Remove user from AD group. |
| LDAP - add or remove user to group copy | 0 | AD/Azure AD group-membership operation: LDAP - add or remove user to group copy. |
| Sub - Static Group List Add | 0 | AD/Azure AD group-membership operation: Sub - Static Group List Add. |
| Sub - Static Group List Remove | 0 | AD/Azure AD group-membership operation: Sub - Static Group List Remove. |
| Sub - Move OUs | 0 | AD/Azure AD group-membership operation: Sub - Move OUs. |
| MRC SecAdmin - Add or Remove from a AD group | 0 | AD/Azure AD group-membership operation: MRC SecAdmin - Add or Remove from a AD group. |
| sub - modify accouts | 0 | AD/Azure AD group-membership operation: sub - modify accouts. |
| MRC SecAdmin - Modify Group | 0 | AD/Azure AD group-membership operation: MRC SecAdmin - Modify Group. |
| Add Or Remove to AD Group | 0 | AD/Azure AD group-membership operation: Add Or Remove to AD Group. |
| Get Ad Groups | 0 | AD/Azure AD group-membership operation: Get Ad Groups. |
| MRC ITAM - Add or Remove Account from a AD Group | 0 | AD/Azure AD group-membership operation: MRC ITAM - Add or Remove Account from a AD Group. |
| Time Based Group Membership | 0 | AD/Azure AD group-membership operation: Time Based Group Membership. |
| MRC SecAdmin - Get AD Group Memberships for a User | 0 | AD/Azure AD group-membership operation: MRC SecAdmin - Get AD Group Memberships for a User. |
| MRC SecAdmin - Create Azure AD Group | 0 | AD/Azure AD group-membership operation: MRC SecAdmin - Create Azure AD Group. |
| Convert LDAP to Json copy | 0 | AD/Azure AD group-membership operation: Convert LDAP to Json copy. |
| Parse Groups Names | 0 | AD/Azure AD group-membership operation: Parse Groups Names. |
| Special Characters LDAP Parse copy | 0 | AD/Azure AD group-membership operation: Special Characters LDAP Parse copy. |
| Sub - Group Membership copy | 0 | AD/Azure AD group-membership operation: Sub - Group Membership copy. |
| Remove Nested Group | 0 | AD/Azure AD group-membership operation: Remove Nested Group. |
| Add one group to another | 0 | AD/Azure AD group-membership operation: Add one group to another. |
10. Password & Credential Self-Service
Category: IAM
Subcategories: Password & credential lifecycle
Description:
Self-service and help-desk-triggered flows for MFA resets, password resets, account unlocks and password-policy reporting across Azure AD and legacy AD.
Business problem solved:
Password/MFA resets are the single highest-volume help-desk request and needed to be resolved in seconds rather than routed to a technician.
Integrations: Microsoft Graph / Azure AD · Microsoft Outlook · Utility
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| User MFA Reset | 294 | Self-service MFA reset for a user's Microsoft account via Graph API. |
| MRC Service Desk - Account Reset Password | 36 | Password/credential lifecycle operation: MRC Service Desk - Account Reset Password. |
| Get MFA Method Details | 21 | Looks up a user's registered MFA methods in Azure AD. |
| SecAdmin - Send Password | 11 | Sends a newly issued or reset password to the requesting user securely. |
| MRC Desktop Tech - Account Reset Password | 3 | Desktop-support-triggered password reset for a user account. |
| MRC Service Desk - Account Unlock | 2 | Service-desk-triggered account unlock. |
| IR - Account Reset Password | 1 | Incident-response-triggered password reset for a compromised account. |
| LDAP - reset user password | 0 | Password/credential lifecycle operation: LDAP - reset user password. |
| MRC Desktop Tech - Account Unlock | 0 | Password/credential lifecycle operation: MRC Desktop Tech - Account Unlock. |
| Password Dynamic Policy Report | 0 | Password/credential lifecycle operation: Password Dynamic Policy Report. |
| Password Dynamic Policy Report - Kai Copy | 0 | Password/credential lifecycle operation: Password Dynamic Policy Report - Kai Copy. |
11. Employee Onboarding, Offboarding & Account Lifecycle
Category: IAM
Subcategories: Employee onboarding, Employee offboarding, Full employee lifecycle
Description:
Syncs employee terminations from Workday and drives the full offboarding chain (disable, deprovision, purge, remove MFA) as well as new-account provisioning and attribute updates such as expiration dates and Encompass IDs.
Business problem solved:
Terminated employees must lose access immediately for compliance and security, and new-hire account setup needs to be consistent and fast.
Integrations: Active Directory · Case Management · Case Management (System) · Extraction Utility · HTTP/Webhook · Microsoft Graph / Azure AD · Splunk · String Utils · Templates · Utility
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Pull Terminated Users | 960 | Hourly sync that pulls newly terminated employees from Workday to trigger offboarding. |
| MRC SecAdmin - Disable External Guest Account in Azure AD and Remove from all Groups | 370 | Disables an external guest account in Azure AD, revokes its session, and removes it from all groups in one run. |
| MRC SecAdmin - Create ADM Account | 29 | Employee lifecycle operation: MRC SecAdmin - Create ADM Account. |
| MRC SecAdmin - Create CADM Account in Azure AD | 16 | Provisions a new CADM (cloud admin) account in Azure AD. |
| MRC SecAdmin - Extend the Account Expiration Date of User Account | 9 | Extends the expiration date on a user account. |
| MRC SecAdmin - Disable AD Account only | 6 | Employee lifecycle operation: MRC SecAdmin - Disable AD Account only. |
| MRC SecAdmin - Add or Remove Home Folder from user account | 3 | Adds or removes a network home folder assignment on a user account. |
| MRC SecAdmin - Deprovision CADM Account in Azure AD | 2 | Deprovisions a CADM account in Azure AD at end of use. |
| Workday Termination Alert | 0 | Employee lifecycle operation: Workday Termination Alert. |
| Unreturned Laptop Detection by Terminated Employee | 0 | Employee lifecycle operation: Unreturned Laptop Detection by Terminated Employee. |
| Unreturned Laptop Detection by Terminated Employee | 0 | Employee lifecycle operation: Unreturned Laptop Detection by Terminated Employee. |
| Workday Termination Alert - Ingest | 0 | Employee lifecycle operation: Workday Termination Alert - Ingest. |
| Workday Termination Alert | 0 | Employee lifecycle operation: Workday Termination Alert. |
| LDAP - disable an account | 0 | Employee lifecycle operation: LDAP - disable an account. |
| IR - Disable User(s) | 0 | Employee lifecycle operation: IR - Disable User(s). |
| Disable Account | 0 | Employee lifecycle operation: Disable Account. |
| Enable account | 0 | Employee lifecycle operation: Enable account. |
| MRC SecAdmin - Modify Account | 0 | Employee lifecycle operation: MRC SecAdmin - Modify Account. |
| MRC SecAdmin - Add Encompass ID to AD User Account | 0 | Employee lifecycle operation: MRC SecAdmin - Add Encompass ID to AD User Account. |
| IR - Disable CADM Account in Azure AD | 0 | Employee lifecycle operation: IR - Disable CADM Account in Azure AD. |
| MRC Messaging - Add Fax Number to User Account | 0 | Employee lifecycle operation: MRC Messaging - Add Fax Number to User Account. |
| IR - Purge User from Environment | 0 | Employee lifecycle operation: IR - Purge User from Environment. |
| Purge User Sublfow - Verify Accounts | 0 | Employee lifecycle operation: Purge User Sublfow - Verify Accounts. |
| Purge User - Subflow Remove MFA Methods | 0 | Employee lifecycle operation: Purge User - Subflow Remove MFA Methods. |
| IR - Disable AD Account only | 0 | Employee lifecycle operation: IR - Disable AD Account only. |
12. Privileged & Service Account Management
Category: IAM
Subcategories: Privileged account mgmt
Description:
Manages the lifecycle of service (SVC) and admin accounts: creation, password rotation, decommissioning, interactive-login restrictions and emergency lockdown.
Business problem solved:
Service and privileged accounts carry outsized risk if mismanaged and require tightly controlled, auditable lifecycle operations.
Integrations: CyberArk · Templates
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| MRC SecAdmin - Change SVC Password | 18 | Rotates the password for a service account. |
| MRC SecAdmin - Create SVC Account | 12 | Provisions a new service account. |
| MRC SecAdmin - SVC Account Modify Interactive Login | 0 | Privileged/service-account lifecycle operation: MRC SecAdmin - SVC Account Modify Interactive Login. |
| Decom SVC Accounts | 0 | Privileged/service-account lifecycle operation: Decom SVC Accounts. |
| IR - Bulk Decom SVC Accounts | 0 | Privileged/service-account lifecycle operation: IR - Bulk Decom SVC Accounts. |
| swap-test | 0 | Privileged/service-account lifecycle operation: swap-test. |
| IR - Lock Down SVC Account | 0 | Privileged/service-account lifecycle operation: IR - Lock Down SVC Account. |
| MRC SecAdmin - Deprovisioning Service Account Only | 0 | Privileged/service-account lifecycle operation: MRC SecAdmin - Deprovisioning Service Account Only. |
13. Endpoint & Device Hygiene (MDM Ops)
Category: Other
Subcategories: Endpoint hygiene & MDM ops
Description:
Desktop-support-triggered device object management in Active Directory (moving, deleting and regrouping computer objects and printers) plus remote wipe/unenroll for lost or donated hardware.
Business problem solved:
IT technicians needed a fast, consistent way to manage device objects and remotely retire hardware without manual AD console work.
Integrations: Absolute · CrowdStrike
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| MRC Desktop Tech - Add or Remove Computer From Group | 0 | Endpoint/device object management: MRC Desktop Tech - Add or Remove Computer From Group. |
| MRC Desktop Tech - Delete Computer Object | 0 | Endpoint/device object management: MRC Desktop Tech - Delete Computer Object. |
| MRC Desktop Tech - Move Computer to New OU | 0 | Endpoint/device object management: MRC Desktop Tech - Move Computer to New OU. |
| MRC Desktop Tech - Delete Printer | 0 | Endpoint/device object management: MRC Desktop Tech - Delete Printer. |
| Absolute Freeze, Wipe and Unenroll For Donated Laptop | 0 | Endpoint/device object management: Absolute Freeze, Wipe and Unenroll For Donated Laptop. |
14. Security Control Validation & Threat Hunting
Category: Vulnerability Mgmt
Subcategories: Threat hunting & detection
Description:
Runs breach-and-attack-simulation checks (SafeBreach) and pentest/attacker-methodology detections to continuously validate that security controls actually catch known attack techniques.
Business problem solved:
Security tooling needs to be continuously validated against real attacker techniques rather than assumed to be working.
Integrations: Extraction Utility · HTTP/Webhook
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| SafeBreach Suppression | 0 | Security control validation check: SafeBreach Suppression. |
| SafeBreach Suppression | 0 | Security control validation check: SafeBreach Suppression. |
| SafeBreach Check - CS Connector | 0 | Security control validation check: SafeBreach Check - CS Connector. |
| CS - Detection attacker_methodology | 0 | Security control validation check: CS - Detection attacker_methodology. |
| Rocket Pentest Check | 0 | Security control validation check: Rocket Pentest Check. |
15. IT/OT & Network Infrastructure Monitoring
Category: Other
Subcategories: IT/OT & network infra monitoring
Description:
Lightweight monitoring for network/infrastructure conditions such as open ports and wifi access-point geolocation.
Business problem solved:
Unexpected network exposure (open ports, rogue wifi) needs to be flagged automatically rather than discovered during an incident.
Integrations: Case Management (System)
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Open Port Detected | 0 | Network/infrastructure monitoring check: Open Port Detected. |
| Open Port Detected | 0 | Network/infrastructure monitoring check: Open Port Detected. |
| Open Port Detected | 0 | Network/infrastructure monitoring check: Open Port Detected. |
| P2- WhatsApp site Accessible | 0 | Network/infrastructure monitoring check: P2- WhatsApp site Accessible. |
| Wifi SSID GeoLocate | 0 | Network/infrastructure monitoring check: Wifi SSID GeoLocate. |
16. Platform Administration, Testing & Migration Utilities
Category: Other
Subcategories: SaaS / IT administration
Description:
Internal utilities used to test, migrate and maintain the Blink workspace itself: alert simulators, environment resets, settings migration between workspaces, and workflow execution reporting.
Business problem solved:
Standing up, testing and migrating the automation platform safely requires its own tooling separate from production security workflows.
Integrations: Case Management · Case Management (System) · Utility
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| USE WITH CARE - Reset Environment | 0 | Internal platform administration/testing utility: USE WITH CARE - Reset Environment. |
| Simulate Crowdstrike Alert | 0 | Internal platform administration/testing utility: Simulate Crowdstrike Alert. |
| Simulate multiple alerts form different sources | 0 | Internal platform administration/testing utility: Simulate multiple alerts form different sources. |
| Getting Started - Hello World | 0 | Internal platform administration/testing utility: Getting Started - Hello World. |
| Test SailPoint URL | 0 | Internal platform administration/testing utility: Test SailPoint URL. |
| New Workflow 1 | 0 | Internal platform administration/testing utility: New Workflow 1. |
| sharepoint cleanup webhooks | 0 | Internal platform administration/testing utility: sharepoint cleanup webhooks. |
| Subflow - Create Historical Alerts | 0 | Internal platform administration/testing utility: Subflow - Create Historical Alerts. |
| Main - Replay Historical Alerts from Prod WS | 0 | Internal platform administration/testing utility: Main - Replay Historical Alerts from Prod WS. |
| Migrate Settings to v9 - From Remote WS | 0 | Internal platform administration/testing utility: Migrate Settings to v9 - From Remote WS. |
| Delete CM Records(BEWARE) | 0 | Internal platform administration/testing utility: Delete CM Records(BEWARE). |
| Report Comparing Prod and Testing Differences | 0 | Internal platform administration/testing utility: Report Comparing Prod and Testing Differences . |
| Pager test | 0 | Internal platform administration/testing utility: Pager test. |
| kai azure blob removal | 0 | Internal platform administration/testing utility: kai azure blob removal. |
| Execution Report On WorkFlow | 0 | Internal platform administration/testing utility: Execution Report On WorkFlow. |
| New Workflow 2 | 0 | Internal platform administration/testing utility: New Workflow 2. |
Key Observations
Strengths
- A mature, centralized SOC response architecture. Rather than maintaining bespoke logic per alert source, Mr. Cooper has converged on a two-layer design: a broad intake layer of per-source alert playbooks feeding a single orchestration engine (*Alert Process v9*) that deduplicates cases, enriches observables through one shared subflow (*Subflow 3 - Enrich Observable*), and routes response actions through one shared decision engine (*Subflow 4 - Response*). This means new alert sources can be onboarded without duplicating enrichment or response logic, and it explains why many individual alert-type playbooks show zero executions in the trailing 12 months — they have been superseded by the unified router rather than abandoned.
- IAM is the highest-volume, highest-maturity automation domain. AD/Azure AD group membership management, employee offboarding (Workday-triggered), guest-account cleanup, and self-service password/MFA resets are fully automated end-to-end. These are the highest-frequency identity requests in any large enterprise, and removing them from help-desk queues is the single largest efficiency win visible in this environment.
- Consistent, reusable enrichment layer. A common set of enrichment playbooks (VirusTotal, URLScan.io, AbuseIPDB, Whois, CrowdStrike, Okta, LDAP) feed the shared enrichment subflow, ensuring every case gets the same quality of contextual data regardless of which system raised the original alert.
- Broad integration footprint. Automation spans SIEM (Splunk), EDR (CrowdStrike), identity (Active Directory, Microsoft Graph/Azure AD, Okta), PAM (CyberArk), network security (Zscaler), endpoint management (Absolute), phishing defense (Proofpoint TRAP), messaging/on-call (Slack, PagerDuty), and AI agent-based triage — indicating Blink operates as the central automation layer across the security and IT stack rather than a point solution.
Gaps & opportunities
- A large share of cataloged playbooks recorded zero executions in the last 12 months. Entire use cases — Threat Intelligence Ingestion, Phishing Detection & Response, DLP Triage, Endpoint & Device Hygiene, Security Control Validation & Threat Hunting, and IT/OT & Network Infrastructure Monitoring — show no recorded runs in the period. This may reflect event-driven playbooks with no qualifying events, environments awaiting trigger configuration, or genuinely stale/deprecated workflows; it's worth a workspace-by-workspace review to confirm which of these are dormant-by-design versus candidates for cleanup.
- Duplication across workspaces inflates the raw playbook count. The same tenant spans 12 workspaces (evident from repeated names like "Falcon," "Open Port Detected," "Executive WLP Check," and explicit "copy" suffixes), consistent with dev/test/prod segregation. This is normal, but it means the 387-playbook total overstates unique automation logic — the real footprint is closer to the 331 distinct playbook names — and periodic pruning of stale test/duplicate copies (e.g., *New Workflow 1*, *New Workflow 2*, *swap-test*, *Getting Started - Hello World*) would tighten the catalog.
- Raw execution volume is concentrated in a few high-fan-out subflows, not distinct business actions. Shared utility subflows like *Sub - Group Membership*, *Special Characters LDAP Parse*, and *Convert LDAP to Json* are invoked in loops by many parent playbooks, so their execution counts (in the thousands) reflect internal processing steps rather than completed business events. The KPI table intentionally reports counts from the top-level, business-facing playbooks instead, to keep the metrics meaningful to a non-technical audience.
Integration ecosystem
Active Directory · Microsoft Graph / Azure AD · Okta · CyberArk · CrowdStrike · Splunk · VirusTotal · URLScan.io · AbuseIPDB · IPWhois · Zscaler · Absolute · Proofpoint TRAP · Palo Alto Cortex XSOAR · PagerDuty · Slack · Microsoft Outlook · Microsoft Defender for Cloud Apps · AI Agents
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Mr_Cooper | blink | automated_report | 2026-08-03 |