01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Email Threat Detection & Response |
| 92.7% | 7 7 active |
| Alert Triage & SOAR |
| 1.3% | 9 9 active |
| Identity Threat Response |
| 0.0% | 2 2 active |
| IOC Enrichment & Observable Management | 236 executions | 0.9% | 34 34 active |
| Endpoint Management & EDR Response |
| 3.7% | 8 8 active |
| Data Exposure & DLP Response |
| 0.1% | 1 1 active |
| Zscaler Web Policy & DLP Management |
| 0.5% | 6 6 active |
| ServiceNow ITSM & On-Call Management |
| 0.5% | 7 6 active |
| Phishing Simulation & Security Awareness | 0 executions | 0.0% | 9 9 active |
| Threat Intelligence Ingest |
| 0.3% | 3 2 active |
| Case Management Utilities, Recovery & Testing | 0 executions | 0.0% | 13 13 active |
| Agentic SOC | 0 executions | 0.0% | 1 1 active |
| Platform Onboarding & Testing Utilities | 0 executions | 0.0% | 5 4 active |
| Total | 25,998 executions | 100% | 105 102 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature email threat pipeline, now with closed-loop response. The Proofpoint TAP ingestion suite remains the highest-volume automation in the environment, processing over 24,000 events in 12 months. Since the last review, the response side matured too: a rebuilt Subflow - Response Router - ProofPoint TAP now drives Zscaler URL blocking and human-in-the-loop Teams messaging directly (39 executions), replacing the earlier standalone response subflow that has since gone dormant.
Identity threat response is now live. The previous report flagged automated identity containment as a
gap. That gap is now closing: Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID has executed 7 times, giving responders a one-step password reset + session revocation action instead of manual, multi-console remediation.
New DLP/data-exposure integration (Cyera). Cyera - Mark User as Risky (23 executions) is a new capability that automatically flags identities associated with data exposure signals from Cyera's data security posture management platform — extending the automation footprint beyond email/endpoint/identity into data risk.
CrowdStrike remains the anchor EDR platform, with 960 automated server decommission checks and now two additional response subflows (alert verification and device quarantine) built to formalize CrowdStrike alert response as discrete, reusable steps.
Comprehensive enrichment library. The IOC enrichment framework covers 10+ intelligence sources with a central observable router (98 invocations) and shared enrichment update subflow, scaling cleanly as new sources are added.
Growing ServiceNow adoption. Travel request processing grew from 51 to 80 executions (+57%), and the on-call dispatcher lookup grew from 18 to 38 executions, indicating increasing reliance on these workflows for day-to-day security operations.
Gaps & Opportunities
Google Chronicle Zscaler Search has gone idle. This workflow ran 9 times in the previous reporting period and shows 0 executions now, while a related but differently-named workflow (Subflow - Response - URL Traffic Verification - Google Chronicle) picked up 7 executions. Worth confirming whether Chronicle-backed investigation moved fully to the new subflow or whether the standalone search tool was simply not needed this period.
Zscaler webhook alert volume dropped sharply (26 → 12 executions), while Zscaler Expired rules and Zscaler Rules for Dropbox, Sharefile, Gdrive both grew. Worth confirming this reflects fewer actual policy violations rather than a webhook delivery issue.
Workspace sprawl and test/demo clutter is increasing. The environment now spans 4 workspaces (up from 1), and roughly 10 of the 105 playbooks are explicitly named as tests, demos, or "copy" duplicates (SNOW TEST, testing grounds, Test Reset, Test Email Format, Simulate Crowdstrike Alert, Simulate Multiple Alerts from Different Sources, Getting Started - Hello World, Self-service Demo, Flow Completion Test, Subflow 1/2 - seconds, plus Phishing Simulation Tracking - Adam Testing Copy and its related "copy" subflows). None have executed. A cleanup pass would sharpen the signal in future reporting.
Phishing simulation tracking is still built but inactive. The Proofpoint Security Awareness Training integration has zero executions, unchanged from last period. Activating it would close the loop between email threat detection (already running at scale) and the training program.
Enrichment pipeline utilization is low relative to its breadth. Despite 98 router invocations, most individual enrichment playbooks show 0 executions; only hash/URL enrichers show single-digit activity. Confirming end-to-end wiring from alert triage into these enrichers would surface value from the existing library.
Agentic SOC is still a single pilot. Agent Get User Info has 0 executions. As Blink's agent platform matures, expanding into multi-step investigation patterns would be a natural next step given the existing enrichment and SOAR foundation.
Integration Ecosystem
| Integration | Category | Used In |
|---|---|---|
| Proofpoint TAP | Email Security | Email Threat Detection, Zscaler Policy |
| Proofpoint Security Awareness Training | Awareness | Phishing Simulation |
| CrowdStrike | EDR | Enrichment, Endpoint Response |
| VirusTotal | Threat Intel | Enrichment |
| AbuseIPDB | Threat Intel | Enrichment |
| URLScan | Threat Intel | Enrichment |
| VMRay | Threat Intel | Enrichment |
| Cyera | Data Security (DSPM/DLP) | Data Exposure & DLP Response |
| Zscaler ZIA | Web Security | Web Policy Management, Email Response |
| Google Chronicle (Cyderes) | SIEM | Zscaler Investigation, Email Response, Log Ingestion |
| ServiceNow | ITSM | Alert Escalation, Travel Requests, On-Call, Endpoint Decom |
| SharePoint | ITSM | On-Call / Dispatcher Roster |
| Microsoft Entra ID | IAM | Enrichment, PhishSim, Identity Threat Response |
| Okta | IAM | Enrichment, User Activity |
| Microsoft Teams | Collaboration | Analyst Notifications, Interactive Approvals |
| Microsoft Outlook | Phishing Response, Error Notifications | |
| Slack | Collaboration | Enrichment (User Lookup) |
| GitHub | Developer | Enrichment (User Info) |
| Google Workspace | Productivity | Enrichment (User Info) |
| RSS (HTTP) | Threat Intel | Threat Intelligence Ingest |
| Blink Case Management | SOAR (native) | Alert/Case/Observable Operations |
| Blink Agents | AI | Agentic User Investigation |
A Case Management 326 cases (12m) | MTTR 27d 19h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Shelter Workspace | 326 | 326 | 287 | 27d 19h |
B AI Agents 1 active | 4 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Agent Seth | Shelter Workspace | 4 | 0 | 135,721 |
| 2 | Agent Blink | Shelter Workspace | 0 | 0 | 0 |
| 3 | New Agent | Shelter Workspace | 0 | 0 | 0 |
| 4 | New Agent 1 | Shelter Workspace | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Shelter Workspace | 4 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Example Dashboard | 0 | 0 |
| 2 | TAP Dashboards | 0 | 0 |
| 3 | GitHub | 0 | 0 |
| 4 | Blink Test | 0 | 0 |
| 5 | RSS Feeds | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | New Employee Onboarding | 0 | 0 |
D Full Use Case Analysis 13 use cases | 25,998 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Email threat events ingested & processed (delivered messages) | 11,521 | TAP - New Delivered Message |
| Email threat events ingested & processed (permitted URL clicks) | 11,521 | TAP - New Permitted URL Click |
| Blocked URL click events detected & processed | 960 | TAP - New Blocked URL Click |
| CrowdStrike server decommission lifecycle checks executed | 960 | CrowdStrike Server Decom |
| Employee travel requests processed for security review | 80 | ServiceNow - Travel Requests |
| Security alerts auto-triaged, enriched & case-managed | 61 | Process Alert |
| Zscaler cloud app URL rules created & managed | 54 | Zscaler Rules for Dropbox, Sharefile, Gdrive |
| Data breach & threat intelligence digests compiled from external feeds | 40 | Company Breaches |
| Threat intelligence RSS feeds ingested | 40 | RSS Feed |
| Expired Zscaler URL filtering rules automatically cleaned up | 40 | Zscaler Expired rules |
| Users flagged as high-risk following data exposure signals | 23 | Cyera - Mark User as Risky |
| ITSM security escalations auto-routed from ServiceNow | 14 | ITSM Ticket Escalated to Security |
| Zscaler webhook policy alerts detected & routed | 12 | Zscaler Webhook Alerts |
| Endpoints automatically flagged & tagged as decommissioned | 11 | Tag Host as Decommissioned |
| Compromised-account containment actions executed (password reset & session revoke) | 7 | Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID |
| Chronicle threat-traffic verification searches executed | 7 | Subflow - Response - URL Traffic Verification - Google Chronicle |
Use Case Summary
| # | Use Case | Category | Active Playbooks | Total Playbooks |
|---|---|---|---|---|
| 1 | Email Threat Detection & Response | SOC | 5 | 7 |
| 2 | Alert Triage & SOAR | SOC | 4 | 9 |
| 3 | Identity Threat Response | SOC | 1 | 2 |
| 4 | IOC Enrichment & Observable Management | SOC | 7 | 34 |
| 5 | Endpoint Management & EDR Response | SOC | 2 | 8 |
| 6 | Data Exposure & DLP Response | GRC | 1 | 1 |
| 7 | Zscaler Web Policy & DLP Management | Cloud Security | 3 | 7 |
| 8 | ServiceNow ITSM & On-Call Management | Other | 3 | 6 |
| 9 | Phishing Simulation & Security Awareness | SOC | 0 | 9 |
| 10 | Threat Intelligence Ingest | SOC | 2 | 3 |
| 11 | Case Management Utilities, Recovery & Testing | SOC | 0 | 13 |
| 12 | Agentic SOC | SOC | 0 | 1 |
| 13 | Platform Onboarding & Testing Utilities | Other | 0 | 5 |
Total: 105 playbooks across 13 use cases
Use Cases
1. Email Threat Detection & Response
Category: SOC | Subcategories: Phishing detection & response, Case mgmt & SOAR
Description: Continuous automated processing of Proofpoint TAP email threat events — blocked URL clicks, permitted URL clicks, and delivered suspicious messages — with per-event alert creation, observable extraction, enrichment, and response routing. A rebuilt response router now drives Zscaler URL-blocking and human-in-the-loop Teams messaging directly from TAP alert context, replacing the earlier standalone response subflow.
Business problem: High-volume email threat telemetry from Proofpoint TAP cannot be manually triaged at scale. Automating ingestion-to-case across all three TAP event types, and closing the loop with automatic Zscaler blocking and analyst notification, ensures no threat goes unprocessed while reducing manual response steps.
Integrations: Proofpoint TAP, Zscaler ZIA, Google Chronicle, Microsoft Outlook, Microsoft Teams, Blink Case Management
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| TAP - New Delivered Message | Scheduled (every 5 min) | 11,521 | Phishing detection & response |
| TAP - New Permitted URL Click | Scheduled (every 5 min) | 11,521 | Phishing detection & response |
| TAP - New Blocked URL Click | Scheduled (hourly) | 960 | Phishing detection & response |
| Subflow - Response Router - ProofPoint TAP | On-demand subflow | 39 | Phishing detection & response |
| Subflow - Response - URL Traffic Verification - Google Chronicle | On-demand subflow | 7 | Phishing detection & response |
| Response Subflow - Proofpoint TAP | On-demand subflow | 0 | Phishing detection & response |
| Response Subflow - Phishing | On-demand subflow | 0 | Phishing detection & response |
2. Alert Triage & SOAR
Category: SOC | Subcategories: Case mgmt & SOAR
Description: End-to-end automated alert processing pipeline covering alert ingestion from case management polling and ServiceNow ITSM webhooks, observable extraction, deduplication into cases, and type-based response routing to specialized subflows. Includes Teams-based analyst notification and error handling for failed runs.
Business problem: Inconsistent manual triage leads to missed alerts, duplicate cases, and uneven analyst workloads. This pipeline standardizes alert handling from any source into a single, auditable processing flow with guaranteed routing and notification.
Integrations: Blink Case Management, ServiceNow, Microsoft Teams
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Process Alert | Event (polling, 1 min) | 61 | Case mgmt & SOAR |
| Subflow - Response - Main Router | On-demand subflow | 61 | Case mgmt & SOAR |
| Subflow - Comms to Teams | On-demand subflow | 38 | Case mgmt & SOAR |
| ITSM Ticket Escalated to Security | Event (ServiceNow webhook) | 14 | Case mgmt & SOAR |
| Response Subflow - Malware | On-demand subflow | 0 | Case mgmt & SOAR |
| Subflow - Missing Alert Template Notification | On-demand subflow | 0 | Case mgmt & SOAR |
| Error Handling - Send Error Notification Email | On-demand subflow | 0 | Case mgmt & SOAR |
| Failed State Resolution | Event (error trigger) | 0 | Case mgmt & SOAR |
| Refresh Notes - Proofpoint and ServiceNow | On-demand | 0 | Case mgmt & SOAR |
3. Identity Threat Response
Category: SOC | Subcategories: Identity threat response
Description: On-demand identity containment for Microsoft Entra ID accounts — resets a user's password and revokes all active sessions in a single call, invoked as a response action from alert-handling workflows.
Business problem: When an account is suspected of compromise (e.g., from a phishing click or anomalous sign-in), every minute an attacker retains a valid session increases exposure. This closes the identity-response gap by giving responders a one-step containment action instead of manual, multi-console remediation in Entra ID.
Integrations: Microsoft Entra ID
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID | On-demand subflow | 7 | Identity threat response |
| Test Reset | On-demand (dev/test) | 0 | Identity threat response |
4. IOC Enrichment & Observable Management
Category: SOC | Subcategories: Alert enrichment / IOC lookup, Case mgmt & SOAR
Description: A comprehensive multi-source enrichment framework that enriches observable types — IPs, URLs, hashes, usernames, email addresses — across VirusTotal, CrowdStrike, AbuseIPDB, URLScan, VMRay, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, and Whois. A central router dispatches observables to the appropriate enricher(s), with results written back to the case management platform via a shared enrichment update subflow.
Business problem: Manual enrichment across 10+ security tools consumes analyst time and introduces inconsistency. Automating observable enrichment at case creation time gives analysts pre-populated context on every alert, reducing mean time to investigate.
Integrations: VirusTotal, CrowdStrike, AbuseIPDB, URLScan, VMRay, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, Whois/Dig, Blink Case Management
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Subflow - Enrich Observables - Main Router | On-demand subflow | 98 | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | On-demand subflow | 7 | Alert enrichment / IOC lookup |
| Enrich - Hash - VirusTotal | On-demand | 3 | Alert enrichment / IOC lookup |
| Enrich - URL - VirusTotal | On-demand | 1 | Alert enrichment / IOC lookup |
| Enrich - URL - AbuseIPDB | On-demand | 1 | Alert enrichment / IOC lookup |
| Enrich - URL - Whois | On-demand | 1 | Alert enrichment / IOC lookup |
| Enrich - URL - VMRay | On-demand | 1 | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - IP - VT | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - URL - VT | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - Hash - Crowdstrike | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - IP or Domain - Whois | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Google Workspace | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Microsoft Entra ID | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - Username - Github | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich - Email Address - Slack | On-demand | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Google Workspace | On-demand | 0 | Alert enrichment / IOC lookup |
| Enrich IP or Domain Using Whois | On-demand | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Github | On-demand | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Microsoft Entra ID | On-demand | 0 | Alert enrichment / IOC lookup |
| Get User Info | On-demand | 0 | Alert enrichment / IOC lookup |
| Get User Information Using Okta | On-demand | 0 | Alert enrichment / IOC lookup |
| Get Hash Info Using Crowdstrike | On-demand | 0 | Alert enrichment / IOC lookup |
| Get Hash Info Using VirusTotal | On-demand | 0 | Alert enrichment / IOC lookup |
| Analyze URL with URLScan | On-demand | 0 | Alert enrichment / IOC lookup |
| Okta Search for User Activity | On-demand | 0 | Alert enrichment / IOC lookup |
| Get User Information on Email Address Using Slack | On-demand | 0 | Alert enrichment / IOC lookup |
| Run Dig Command | On-demand | 0 | Alert enrichment / IOC lookup |
| Secure URL Screenshot Capture | On-demand | 0 | Alert enrichment / IOC lookup |
| Get End of Life Date for a Product | On-demand | 0 | Alert enrichment / IOC lookup |
5. Endpoint Management & EDR Response
Category: SOC | Subcategories: EDR containment & response, Case mgmt & SOAR
Description: CrowdStrike-integrated endpoint response automation covering scheduled server decommission lifecycle management, real-time endpoint isolation and quarantine, RTR (Real Time Response) command execution to single hosts and host batches, device enrichment, and automated tagging of decommissioned assets. Two new subflows now handle CrowdStrike alert verification and device quarantine as discrete, callable response steps for the alert pipeline.
Business problem: Manual endpoint response to security incidents introduces dangerous delay. Automated CrowdStrike containment, RTR execution, and decommission processing reduces dwell time and ensures timely lifecycle management of retiring infrastructure.
Integrations: CrowdStrike, ServiceNow, Blink Case Management
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| CrowdStrike Server Decom | Scheduled (hourly) | 960 | EDR containment & response |
| Tag Host as Decommissioned | On-demand | 11 | EDR containment & response |
| Manage Endpoint Quarantine Status in Crowdstrike | On-demand | 0 | EDR containment & response |
| Subflow - Response - Alert Verification - Crowdstrike | On-demand subflow | 0 | EDR containment & response |
| Subflow - Response - Quarantine Device - Crowdstrike | On-demand subflow | 0 | EDR containment & response |
| CrowdStrike RTR to a Single Host | On-demand | 0 | EDR containment & response |
| CrowdStrike RTR to a Batch of Hosts | On-demand | 0 | EDR containment & response |
| Crowdstrike Device Enrichment | On-demand | 0 | EDR containment & response |
6. Data Exposure & DLP Response
Category: GRC | Subcategories: DLP triage & exposure resp
Description: Integrates with Cyera (data security posture management) to flag a user's identity as high-risk when a data exposure or sensitive-data-handling signal is detected, creating an auditable risk marker for downstream monitoring.
Business problem: Data exposure risk tied to specific identities is easy to lose track of without a systematic flagging step. Automating the "mark as risky" action ensures every Cyera-detected exposure signal produces a consistent, auditable identity risk designation rather than a one-off manual note.
Integrations: Cyera
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Cyera - Mark User as Risky | On-demand | 23 | DLP triage & exposure resp |
7. Zscaler Web Policy & DLP Management
Category: Cloud Security | Subcategories: Cloud access & SaaS policy mgmt, SIEM & log pipeline monitoring
Description: Automated management of Zscaler Internet Access web filtering policies, including scheduled expiry cleanup of stale URL rules, webhook-triggered alert processing for policy violations, and dynamic rule creation for cloud file-sharing services (Dropbox, ShareFile, Google Drive). Google Chronicle integration provides SIEM-backed investigation links for Zscaler events.
Business problem: Stale Zscaler URL rules accumulate without automation, creating policy drift and potential security gaps. Automated enforcement of cloud app access policies (especially for file-sharing services that create DLP risk) reduces data exfiltration exposure.
Integrations: Zscaler ZIA, Google Chronicle, Proofpoint TAP
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Zscaler Rules for Dropbox, Sharefile, Gdrive | On-demand | 54 | Cloud access & SaaS policy mgmt |
| Zscaler Expired rules | Scheduled (daily 7am) | 40 | Cloud access & SaaS policy mgmt |
| Zscaler Webhook Alerts | Event (webhook) | 12 | Cloud access & SaaS policy mgmt |
| Update TAP URL category and send teams message to user | On-demand | 0 | Cloud access & SaaS policy mgmt |
| Zscaler Webhook Alerts (main workspace) | Event (webhook) | 0 | Cloud access & SaaS policy mgmt |
| Google Chronicle Zscaler Search | On-demand | 0 | SIEM & log pipeline monitoring |
| Google Chronicle Link generator copy | On-demand | 0 | SIEM & log pipeline monitoring |
8. ServiceNow ITSM & On-Call Management
Category: Other | Subcategories: IT helpdesk & ticket routing
Description: Bidirectional ServiceNow integration for security operations workflow management. Covers automated processing of employee travel requests for security review and dynamic on-call schedule resolution from ServiceNow and SharePoint, plus two developer test workflows validating ServiceNow custom actions.
Business problem: Security teams need timely awareness of employee travel (for geolocation anomaly context) and a resolvable on-call chain without manually monitoring multiple systems.
Integrations: ServiceNow, SharePoint, Microsoft Entra ID
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| ServiceNow - Travel Requests | Scheduled (every 12hr) | 80 | IT helpdesk & ticket routing |
| Subflow - SharePoint - Get Dispatcher | On-demand subflow | 38 | IT helpdesk & ticket routing |
| Subflow - ServiceNow - Get On-Call | On-demand subflow | 1 | IT helpdesk & ticket routing |
| SIR Webhook | On-demand | 0 | IT helpdesk & ticket routing |
| SNOW TEST | On-demand (dev/test) | 0 | IT helpdesk & ticket routing |
| testing grounds | On-demand (dev/test) | 0 | IT helpdesk & ticket routing |
9. Phishing Simulation & Security Awareness
Category: SOC | Subcategories: Phishing sim & awareness
Description: Full Proofpoint Security Awareness Training phishing simulation tracking pipeline, including campaign result ingestion, data storage in Blink tables, and Microsoft Entra ID enrichment of user records. A webform-based onboarding flow and Teams-interactive training workflow provide self-service security awareness tooling. Currently built and staged but not yet producing executions at scale.
Business problem: Security awareness programs require automated data collection to measure campaign effectiveness and identify high-risk users who repeatedly fail simulations — informing targeted remediation and training prioritization.
Integrations: Proofpoint Security Awareness Training, Microsoft Entra ID, Microsoft Teams, ServiceNow, Blink Tables
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Phishing Simulation Tracking | On-demand | 0 | Phishing sim & awareness |
| Subflow - PhishSim Table Update | On-demand subflow | 0 | Phishing sim & awareness |
| Subflow - Entra PhishSim Enrichment | On-demand subflow | 0 | Phishing sim & awareness |
| Phishing Simulation Training | On-demand | 0 | Phishing sim & awareness |
| Training Level 1 - Workflow | On-demand | 0 | Phishing sim & awareness |
| Training - Webforms | Event (web form) | 0 | Phishing sim & awareness |
| Phishing Simulation Tracking - Adam Testing Copy | On-demand | 0 | Phishing sim & awareness |
| Subflow - Entra PhishSim Enrichment copy | On-demand subflow | 0 | Phishing sim & awareness |
| Subflow - PhishSim Table Update copy | On-demand subflow | 0 | Phishing sim & awareness |
10. Threat Intelligence Ingest
Category: SOC | Subcategories: Threat intel ingest & curation, SIEM & log pipeline monitoring
Description: Automated daily ingestion of threat intelligence and breach-monitoring content from RSS feeds — including HackerNews, Bleeping Computer, Dark Reading, Security Weekly, KrebsOnSecurity, HaveIBeenPwned, and Wired — merged and stored in a shared table for SOC consumption. Chronicle log ingestion testing supports SIEM pipeline validation for Zscaler log data via Cyderes-managed Chronicle.
Business problem: SOC teams need a continuous, automated stream of external threat and breach intelligence to stay current on emerging threats without manually monitoring multiple feeds.
Integrations: RSS (HTTP), Google Chronicle (Cyderes), Blink Tables
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| RSS Feed | Scheduled (daily 7am) | 40 | Threat intel ingest & curation |
| Company Breaches | Scheduled (daily 7am) | 40 | Threat intel ingest & curation |
| Cyderes Logs Ingestion Testing | On-demand | 0 | SIEM & log pipeline monitoring |
11. Case Management Utilities, Recovery & Testing
Category: SOC | Subcategories: Case mgmt & SOAR
Description: Supporting infrastructure for the SOAR platform including observable relation management (create, update, delete), case similarity detection, stale case closure, unprocessed alert recovery, and observable extraction template validation. Also includes alert-simulation tools used to generate synthetic CrowdStrike, ProofPoint, and Okta alerts for pipeline testing, plus a Teams message-format test.
Business problem: These utilities underpin the health and accuracy of the case management platform and let the team validate the alert pipeline with synthetic data, without representing direct analyst-facing outcomes themselves.
Integrations: Blink Case Management, Microsoft Teams
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Utility - Find Similar Cases Based on Observables | On-demand | 0 | Case mgmt & SOAR |
| Utility - List Observable Alert Relations | On-demand | 0 | Case mgmt & SOAR |
| Utility - Update Enrichment | On-demand | 0 | Case mgmt & SOAR |
| Utility - Close Stale Cases | On-demand | 0 | Case mgmt & SOAR |
| Table Action - Validate Observables Extraction Template | On-demand | 0 | Case mgmt & SOAR |
| Utility - List Alert Observable Relations | On-demand | 0 | Case mgmt & SOAR |
| Utility - Set Or Update Observable Relation | On-demand | 0 | Case mgmt & SOAR |
| Utility - Delete Observable Relation | On-demand | 0 | Case mgmt & SOAR |
| Recovery - Enrich Non-Enriched Observables | On-demand | 0 | Case mgmt & SOAR |
| Recovery - Handle Unprocessed Alerts | On-demand | 0 | Case mgmt & SOAR |
| Simulate Crowdstrike Alert | On-demand (dev/test) | 0 | Case mgmt & SOAR |
| Simulate Multiple Alerts from Different Sources | On-demand (dev/test) | 0 | Case mgmt & SOAR |
| Test Email Format | On-demand (dev/test) | 0 | Case mgmt & SOAR |
12. Agentic SOC
Category: SOC | Subcategories: Agentic SOC, Alert enrichment / IOC lookup
Description: An AI agent-powered user investigation capability that invokes a named Blink Agent to answer questions about user identities and activity. Represents early-stage deployment of agentic automation for SOC analyst augmentation.
Business problem: Complex investigation questions that span multiple data sources traditionally require significant analyst effort. Agentic automation can handle routine lookup and correlation tasks autonomously, freeing analysts for higher-order decisions.
Integrations: Blink Agents (AI)
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Agent Get User Info | On-demand | 0 | Agentic SOC |
13. Platform Onboarding & Testing Utilities
Category: Other | Subcategories: SaaS / IT administration
Description: Blink platform onboarding templates ("Hello World") and lightweight subflow-chaining/timing test workflows, spread across three separate workspaces. These validate platform mechanics (bash/python execution, subflow chaining, sleep timing) rather than delivering a security outcome.
Business problem: Not applicable — these are platform enablement and internal testing artifacts, included here for completeness of the full automation inventory rather than as a business-driven use case.
Integrations: None (native Blink platform actions only)
| Playbook | Type | Executions | Subcategory |
|---|---|---|---|
| Getting Started - Hello World | On-demand | 0 | SaaS / IT administration |
| Self-service Demo | On-demand | 0 | SaaS / IT administration |
| Flow Completion Test | On-demand | 0 | SaaS / IT administration |
| Subflow 1 - 10 seconds | On-demand subflow | 0 | SaaS / IT administration |
| Subflow 2 - 15 seconds | On-demand subflow | 0 | SaaS / IT administration |
Key Observations
Strengths
Mature email threat pipeline, now with closed-loop response. The Proofpoint TAP ingestion suite remains the highest-volume automation in the environment, processing over 24,000 events in 12 months. Since the last review, the response side matured too: a rebuilt Subflow - Response Router - ProofPoint TAP now drives Zscaler URL blocking and human-in-the-loop Teams messaging directly (39 executions), replacing the earlier standalone response subflow that has since gone dormant.
Identity threat response is now live. The previous report flagged automated identity containment as a gap. That gap is now closing: Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID has executed 7 times, giving responders a one-step password reset + session revocation action instead of manual, multi-console remediation.
New DLP/data-exposure integration (Cyera). Cyera - Mark User as Risky (23 executions) is a new capability that automatically flags identities associated with data exposure signals from Cyera's data security posture management platform — extending the automation footprint beyond email/endpoint/identity into data risk.
CrowdStrike remains the anchor EDR platform, with 960 automated server decommission checks and now two additional response subflows (alert verification and device quarantine) built to formalize CrowdStrike alert response as discrete, reusable steps.
Comprehensive enrichment library. The IOC enrichment framework covers 10+ intelligence sources with a central observable router (98 invocations) and shared enrichment update subflow, scaling cleanly as new sources are added.
Growing ServiceNow adoption. Travel request processing grew from 51 to 80 executions (+57%), and the on-call dispatcher lookup grew from 18 to 38 executions, indicating increasing reliance on these workflows for day-to-day security operations.
Gaps & Opportunities
Google Chronicle Zscaler Search has gone idle. This workflow ran 9 times in the previous reporting period and shows 0 executions now, while a related but differently-named workflow (Subflow - Response - URL Traffic Verification - Google Chronicle) picked up 7 executions. Worth confirming whether Chronicle-backed investigation moved fully to the new subflow or whether the standalone search tool was simply not needed this period.
Zscaler webhook alert volume dropped sharply (26 → 12 executions), while Zscaler Expired rules and Zscaler Rules for Dropbox, Sharefile, Gdrive both grew. Worth confirming this reflects fewer actual policy violations rather than a webhook delivery issue.
Workspace sprawl and test/demo clutter is increasing. The environment now spans 4 workspaces (up from 1), and roughly 10 of the 105 playbooks are explicitly named as tests, demos, or "copy" duplicates (SNOW TEST, testing grounds, Test Reset, Test Email Format, Simulate Crowdstrike Alert, Simulate Multiple Alerts from Different Sources, Getting Started - Hello World, Self-service Demo, Flow Completion Test, Subflow 1/2 - seconds, plus Phishing Simulation Tracking - Adam Testing Copy and its related "copy" subflows). None have executed. A cleanup pass would sharpen the signal in future reporting.
Phishing simulation tracking is still built but inactive. The Proofpoint Security Awareness Training integration has zero executions, unchanged from last period. Activating it would close the loop between email threat detection (already running at scale) and the training program.
Enrichment pipeline utilization is low relative to its breadth. Despite 98 router invocations, most individual enrichment playbooks show 0 executions; only hash/URL enrichers show single-digit activity. Confirming end-to-end wiring from alert triage into these enrichers would surface value from the existing library.
Agentic SOC is still a single pilot. Agent Get User Info has 0 executions. As Blink's agent platform matures, expanding into multi-step investigation patterns would be a natural next step given the existing enrichment and SOAR foundation.
Integration Ecosystem
| Integration | Category | Used In |
|---|---|---|
| Proofpoint TAP | Email Security | Email Threat Detection, Zscaler Policy |
| Proofpoint Security Awareness Training | Awareness | Phishing Simulation |
| CrowdStrike | EDR | Enrichment, Endpoint Response |
| VirusTotal | Threat Intel | Enrichment |
| AbuseIPDB | Threat Intel | Enrichment |
| URLScan | Threat Intel | Enrichment |
| VMRay | Threat Intel | Enrichment |
| Cyera | Data Security (DSPM/DLP) | Data Exposure & DLP Response |
| Zscaler ZIA | Web Security | Web Policy Management, Email Response |
| Google Chronicle (Cyderes) | SIEM | Zscaler Investigation, Email Response, Log Ingestion |
| ServiceNow | ITSM | Alert Escalation, Travel Requests, On-Call, Endpoint Decom |
| SharePoint | ITSM | On-Call / Dispatcher Roster |
| Microsoft Entra ID | IAM | Enrichment, PhishSim, Identity Threat Response |
| Okta | IAM | Enrichment, User Activity |
| Microsoft Teams | Collaboration | Analyst Notifications, Interactive Approvals |
| Microsoft Outlook | Phishing Response, Error Notifications | |
| Slack | Collaboration | Enrichment (User Lookup) |
| GitHub | Developer | Enrichment (User Info) |
| Google Workspace | Productivity | Enrichment (User Info) |
| RSS (HTTP) | Threat Intel | Threat Intelligence Ingest |
| Blink Case Management | SOAR (native) | Alert/Case/Observable Operations |
| Blink Agents | AI | Agentic User Investigation |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| shelter-insurance | shodan | my_shodan_connection | 2026-08-27 |