Blink Security Automation — Confidential

shelter-insurance — Customer Success Report

Generated 2026-08-31 | shelter-insurance-value-report.md
2026-08-31Report Date
185Total Playbooks
50Unique Workflows (12m)
804,990Actions Automated (12m)
$207,045Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

185
Total playbooks built
all non-deleted workflows
106
Active playbooks
currently enabled
50
Unique workflows executed (12m)
distinct workflows that ran
804,990
Actions automated (12m)
completed action steps
4,472.2h
Hours saved (12m)
@ 20s per action
$207,045
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
326
Total cases managed
326 opened in last 12m
27d 19h
MTTR — mean time to resolve
closed cases, last 12m
1
Active AI agents
of 4 total
4
AI agent tasks executed (12m)
0 in last 30d
In the last 12 months, Blink automated: - 24,002 email threat events ingested and processed from Proofpoint TAP (blocked clicks, permitted clicks, and delivered messages) - 960 CrowdStrike server decommission lifecycle reviews completed automatically - 106 Zscaler web policy actions executed — rules created, expired rules cleaned up, and webhook alerts processed - 80 employee travel requests processed for security review via ServiceNow - 80 threat intelligence and breach-monitoring digests ingested from RSS and open security sources - 61 security alerts auto-triaged, enriched, and case-managed end-to-end without analyst involvement - 23 users automatically flagged as high-risk in Cyera following data exposure signals - 14 ITSM service tickets automatically escalated to the security operations team - 14 identity containment and threat-verification actions executed (password resets, session revocations, and Chronicle traffic checks) - 11 endpoints automatically flagged and tagged as decommissioned

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Email Threat Detection & Response
  • 11,521Email threat events ingested & processed (delivered messages)
  • 11,521Email threat events ingested & processed (permitted URL clicks)
  • 960Blocked URL click events detected & processed
92.7%
7
7 active
Alert Triage & SOAR
  • 61Security alerts auto-triaged, enriched & case-managed
  • 14ITSM security escalations auto-routed from ServiceNow
1.3%
9
9 active
Identity Threat Response
  • 7Compromised-account containment actions executed (password reset & session revoke)
0.0%
2
2 active
IOC Enrichment & Observable Management236 executions
0.9%
34
34 active
Endpoint Management & EDR Response
  • 960CrowdStrike server decommission lifecycle checks executed
  • 11Endpoints automatically flagged & tagged as decommissioned
3.7%
8
8 active
Data Exposure & DLP Response
  • 23Users flagged as high-risk following data exposure signals
0.1%
1
1 active
Zscaler Web Policy & DLP Management
  • 40Expired Zscaler URL filtering rules automatically cleaned up
  • 12Zscaler webhook policy alerts detected & routed
0.5%
6
6 active
ServiceNow ITSM & On-Call Management
  • 80Employee travel requests processed for security review
0.5%
7
6 active
Phishing Simulation & Security Awareness0 executions
0.0%
9
9 active
Threat Intelligence Ingest
  • 40Data breach & threat intelligence digests compiled from external feeds
  • 40Threat intelligence RSS feeds ingested
0.3%
3
2 active
Case Management Utilities, Recovery & Testing0 executions
0.0%
13
13 active
Agentic SOC0 executions
0.0%
1
1 active
Platform Onboarding & Testing Utilities0 executions
0.0%
5
4 active
Total25,998 executions100%
105
102 active

Use Case Growth Over Time

153 unique playbooks  |  13 operational use cases  |  25,998 total executions (12m)  |  2024-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

IOC Enrichment & Observable Management
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Google Workspace GitHub Microsoft Entra ID Slack
Email Threat Detection & Response
Microsoft Outlook Proofpoint TAP Chronicle Email Microsoft Teams
Alert Triage & SOAR
Email Microsoft Teams ServiceNow
Endpoint Management & EDR Response
CrowdStrike ServiceNow
Agentic SOC
Agents
ServiceNow ITSM & On-Call Management
ServiceNow SharePoint Microsoft Entra ID Microsoft Teams Microsoft Outlook
Zscaler Web Policy & DLP Management
Zscaler Internet Access Microsoft Teams Microsoft Outlook Microsoft Entra ID Email
Phishing Simulation & Security Awareness
Proofpoint Security Awareness Training Microsoft Outlook Microsoft Entra ID Microsoft Teams ServiceNow
Identity Threat Response
Microsoft Entra ID Microsoft Teams Microsoft Outlook
Threat Intelligence Ingest
RSS Microsoft Teams
Case Management Utilities, Recovery & Testing
Microsoft Teams
Data Exposure & DLP Response
Cyera

04Key Observations

✓  Strengths

Strengths

Mature email threat pipeline, now with closed-loop response. The Proofpoint TAP ingestion suite remains the highest-volume automation in the environment, processing over 24,000 events in 12 months. Since the last review, the response side matured too: a rebuilt Subflow - Response Router - ProofPoint TAP now drives Zscaler URL blocking and human-in-the-loop Teams messaging directly (39 executions), replacing the earlier standalone response subflow that has since gone dormant.

Identity threat response is now live. The previous report flagged automated identity containment as a

△  Gaps & Growth Opportunities

gap. That gap is now closing: Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID has executed 7 times, giving responders a one-step password reset + session revocation action instead of manual, multi-console remediation.

New DLP/data-exposure integration (Cyera). Cyera - Mark User as Risky (23 executions) is a new capability that automatically flags identities associated with data exposure signals from Cyera's data security posture management platform — extending the automation footprint beyond email/endpoint/identity into data risk.

CrowdStrike remains the anchor EDR platform, with 960 automated server decommission checks and now two additional response subflows (alert verification and device quarantine) built to formalize CrowdStrike alert response as discrete, reusable steps.

Comprehensive enrichment library. The IOC enrichment framework covers 10+ intelligence sources with a central observable router (98 invocations) and shared enrichment update subflow, scaling cleanly as new sources are added.

Growing ServiceNow adoption. Travel request processing grew from 51 to 80 executions (+57%), and the on-call dispatcher lookup grew from 18 to 38 executions, indicating increasing reliance on these workflows for day-to-day security operations.

Gaps & Opportunities

Google Chronicle Zscaler Search has gone idle. This workflow ran 9 times in the previous reporting period and shows 0 executions now, while a related but differently-named workflow (Subflow - Response - URL Traffic Verification - Google Chronicle) picked up 7 executions. Worth confirming whether Chronicle-backed investigation moved fully to the new subflow or whether the standalone search tool was simply not needed this period.

Zscaler webhook alert volume dropped sharply (26 → 12 executions), while Zscaler Expired rules and Zscaler Rules for Dropbox, Sharefile, Gdrive both grew. Worth confirming this reflects fewer actual policy violations rather than a webhook delivery issue.

Workspace sprawl and test/demo clutter is increasing. The environment now spans 4 workspaces (up from 1), and roughly 10 of the 105 playbooks are explicitly named as tests, demos, or "copy" duplicates (SNOW TEST, testing grounds, Test Reset, Test Email Format, Simulate Crowdstrike Alert, Simulate Multiple Alerts from Different Sources, Getting Started - Hello World, Self-service Demo, Flow Completion Test, Subflow 1/2 - seconds, plus Phishing Simulation Tracking - Adam Testing Copy and its related "copy" subflows). None have executed. A cleanup pass would sharpen the signal in future reporting.

Phishing simulation tracking is still built but inactive. The Proofpoint Security Awareness Training integration has zero executions, unchanged from last period. Activating it would close the loop between email threat detection (already running at scale) and the training program.

Enrichment pipeline utilization is low relative to its breadth. Despite 98 router invocations, most individual enrichment playbooks show 0 executions; only hash/URL enrichers show single-digit activity. Confirming end-to-end wiring from alert triage into these enrichers would surface value from the existing library.

Agentic SOC is still a single pilot. Agent Get User Info has 0 executions. As Blink's agent platform matures, expanding into multi-step investigation patterns would be a natural next step given the existing enrichment and SOAR foundation.

Integration Ecosystem

Integration Category Used In
Proofpoint TAP Email Security Email Threat Detection, Zscaler Policy
Proofpoint Security Awareness Training Awareness Phishing Simulation
CrowdStrike EDR Enrichment, Endpoint Response
VirusTotal Threat Intel Enrichment
AbuseIPDB Threat Intel Enrichment
URLScan Threat Intel Enrichment
VMRay Threat Intel Enrichment
Cyera Data Security (DSPM/DLP) Data Exposure & DLP Response
Zscaler ZIA Web Security Web Policy Management, Email Response
Google Chronicle (Cyderes) SIEM Zscaler Investigation, Email Response, Log Ingestion
ServiceNow ITSM Alert Escalation, Travel Requests, On-Call, Endpoint Decom
SharePoint ITSM On-Call / Dispatcher Roster
Microsoft Entra ID IAM Enrichment, PhishSim, Identity Threat Response
Okta IAM Enrichment, User Activity
Microsoft Teams Collaboration Analyst Notifications, Interactive Approvals
Microsoft Outlook Email Phishing Response, Error Notifications
Slack Collaboration Enrichment (User Lookup)
GitHub Developer Enrichment (User Info)
Google Workspace Productivity Enrichment (User Info)
RSS (HTTP) Threat Intel Threat Intelligence Ingest
Blink Case Management SOAR (native) Alert/Case/Observable Operations
Blink Agents AI Agentic User Investigation
Appendices
A Case Management 326 cases (12m) | MTTR 27d 19h

Case Management

Total Cases (all-time)
326
326 opened in last 12m
Cases Opened (30d)
42
36 closed in last 30d
Cases Closed (12m)
287
of 326 opened
MTTR
27d 19h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Shelter Workspace 326 326 287 27d 19h
B AI Agents 1 active | 4 tasks (12m)

AI Agents

Active Agents
1
of 4 total
Tasks Executed (12m)
4
0 in last 30d
Data Usage (12m)
135,721
0 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Agent Seth Shelter Workspace 4 0 135,721
2 Agent Blink Shelter Workspace 0 0 0
3 New Agent Shelter Workspace 0 0 0
4 New Agent 1 Shelter Workspace 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Shelter Workspace4
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
6
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Example Dashboard 00
2 TAP Dashboards 00
3 GitHub 00
4 Blink Test 00
5 RSS Feeds 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 New Employee Onboarding 00
D Full Use Case Analysis 13 use cases | 25,998 executions (12m)

Business KPIs

Metric Count Playbook
Email threat events ingested & processed (delivered messages) 11,521 TAP - New Delivered Message
Email threat events ingested & processed (permitted URL clicks) 11,521 TAP - New Permitted URL Click
Blocked URL click events detected & processed 960 TAP - New Blocked URL Click
CrowdStrike server decommission lifecycle checks executed 960 CrowdStrike Server Decom
Employee travel requests processed for security review 80 ServiceNow - Travel Requests
Security alerts auto-triaged, enriched & case-managed 61 Process Alert
Zscaler cloud app URL rules created & managed 54 Zscaler Rules for Dropbox, Sharefile, Gdrive
Data breach & threat intelligence digests compiled from external feeds 40 Company Breaches
Threat intelligence RSS feeds ingested 40 RSS Feed
Expired Zscaler URL filtering rules automatically cleaned up 40 Zscaler Expired rules
Users flagged as high-risk following data exposure signals 23 Cyera - Mark User as Risky
ITSM security escalations auto-routed from ServiceNow 14 ITSM Ticket Escalated to Security
Zscaler webhook policy alerts detected & routed 12 Zscaler Webhook Alerts
Endpoints automatically flagged & tagged as decommissioned 11 Tag Host as Decommissioned
Compromised-account containment actions executed (password reset & session revoke) 7 Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID
Chronicle threat-traffic verification searches executed 7 Subflow - Response - URL Traffic Verification - Google Chronicle
In the last 12 months, Blink automated: - 24,002 email threat events ingested and processed from Proofpoint TAP (blocked clicks, permitted clicks, and delivered messages) - 960 CrowdStrike server decommission lifecycle reviews completed automatically - 106 Zscaler web policy actions executed — rules created, expired rules cleaned up, and webhook alerts processed - 80 employee travel requests processed for security review via ServiceNow - 80 threat intelligence and breach-monitoring digests ingested from RSS and open security sources - 61 security alerts auto-triaged, enriched, and case-managed end-to-end without analyst involvement - 23 users automatically flagged as high-risk in Cyera following data exposure signals - 14 ITSM service tickets automatically escalated to the security operations team - 14 identity containment and threat-verification actions executed (password resets, session revocations, and Chronicle traffic checks) - 11 endpoints automatically flagged and tagged as decommissioned

Use Case Summary

# Use Case Category Active Playbooks Total Playbooks
1 Email Threat Detection & Response SOC 5 7
2 Alert Triage & SOAR SOC 4 9
3 Identity Threat Response SOC 1 2
4 IOC Enrichment & Observable Management SOC 7 34
5 Endpoint Management & EDR Response SOC 2 8
6 Data Exposure & DLP Response GRC 1 1
7 Zscaler Web Policy & DLP Management Cloud Security 3 7
8 ServiceNow ITSM & On-Call Management Other 3 6
9 Phishing Simulation & Security Awareness SOC 0 9
10 Threat Intelligence Ingest SOC 2 3
11 Case Management Utilities, Recovery & Testing SOC 0 13
12 Agentic SOC SOC 0 1
13 Platform Onboarding & Testing Utilities Other 0 5

Total: 105 playbooks across 13 use cases

Use Cases

1. Email Threat Detection & Response

Category: SOC | Subcategories: Phishing detection & response, Case mgmt & SOAR

Description: Continuous automated processing of Proofpoint TAP email threat events — blocked URL clicks, permitted URL clicks, and delivered suspicious messages — with per-event alert creation, observable extraction, enrichment, and response routing. A rebuilt response router now drives Zscaler URL-blocking and human-in-the-loop Teams messaging directly from TAP alert context, replacing the earlier standalone response subflow.

Business problem: High-volume email threat telemetry from Proofpoint TAP cannot be manually triaged at scale. Automating ingestion-to-case across all three TAP event types, and closing the loop with automatic Zscaler blocking and analyst notification, ensures no threat goes unprocessed while reducing manual response steps.

Integrations: Proofpoint TAP, Zscaler ZIA, Google Chronicle, Microsoft Outlook, Microsoft Teams, Blink Case Management

Playbook Type Executions Subcategory
TAP - New Delivered Message Scheduled (every 5 min) 11,521 Phishing detection & response
TAP - New Permitted URL Click Scheduled (every 5 min) 11,521 Phishing detection & response
TAP - New Blocked URL Click Scheduled (hourly) 960 Phishing detection & response
Subflow - Response Router - ProofPoint TAP On-demand subflow 39 Phishing detection & response
Subflow - Response - URL Traffic Verification - Google Chronicle On-demand subflow 7 Phishing detection & response
Response Subflow - Proofpoint TAP On-demand subflow 0 Phishing detection & response
Response Subflow - Phishing On-demand subflow 0 Phishing detection & response

2. Alert Triage & SOAR

Category: SOC | Subcategories: Case mgmt & SOAR

Description: End-to-end automated alert processing pipeline covering alert ingestion from case management polling and ServiceNow ITSM webhooks, observable extraction, deduplication into cases, and type-based response routing to specialized subflows. Includes Teams-based analyst notification and error handling for failed runs.

Business problem: Inconsistent manual triage leads to missed alerts, duplicate cases, and uneven analyst workloads. This pipeline standardizes alert handling from any source into a single, auditable processing flow with guaranteed routing and notification.

Integrations: Blink Case Management, ServiceNow, Microsoft Teams

Playbook Type Executions Subcategory
Process Alert Event (polling, 1 min) 61 Case mgmt & SOAR
Subflow - Response - Main Router On-demand subflow 61 Case mgmt & SOAR
Subflow - Comms to Teams On-demand subflow 38 Case mgmt & SOAR
ITSM Ticket Escalated to Security Event (ServiceNow webhook) 14 Case mgmt & SOAR
Response Subflow - Malware On-demand subflow 0 Case mgmt & SOAR
Subflow - Missing Alert Template Notification On-demand subflow 0 Case mgmt & SOAR
Error Handling - Send Error Notification Email On-demand subflow 0 Case mgmt & SOAR
Failed State Resolution Event (error trigger) 0 Case mgmt & SOAR
Refresh Notes - Proofpoint and ServiceNow On-demand 0 Case mgmt & SOAR

3. Identity Threat Response

Category: SOC | Subcategories: Identity threat response

Description: On-demand identity containment for Microsoft Entra ID accounts — resets a user's password and revokes all active sessions in a single call, invoked as a response action from alert-handling workflows.

Business problem: When an account is suspected of compromise (e.g., from a phishing click or anomalous sign-in), every minute an attacker retains a valid session increases exposure. This closes the identity-response gap by giving responders a one-step containment action instead of manual, multi-console remediation in Entra ID.

Integrations: Microsoft Entra ID

Playbook Type Executions Subcategory
Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID On-demand subflow 7 Identity threat response
Test Reset On-demand (dev/test) 0 Identity threat response

4. IOC Enrichment & Observable Management

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Case mgmt & SOAR

Description: A comprehensive multi-source enrichment framework that enriches observable types — IPs, URLs, hashes, usernames, email addresses — across VirusTotal, CrowdStrike, AbuseIPDB, URLScan, VMRay, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, and Whois. A central router dispatches observables to the appropriate enricher(s), with results written back to the case management platform via a shared enrichment update subflow.

Business problem: Manual enrichment across 10+ security tools consumes analyst time and introduces inconsistency. Automating observable enrichment at case creation time gives analysts pre-populated context on every alert, reducing mean time to investigate.

Integrations: VirusTotal, CrowdStrike, AbuseIPDB, URLScan, VMRay, Okta, Microsoft Entra ID, Google Workspace, GitHub, Slack, Whois/Dig, Blink Case Management

Playbook Type Executions Subcategory
Subflow - Enrich Observables - Main Router On-demand subflow 98 Alert enrichment / IOC lookup
Subflow - Update Enrichment Data On-demand subflow 7 Alert enrichment / IOC lookup
Enrich - Hash - VirusTotal On-demand 3 Alert enrichment / IOC lookup
Enrich - URL - VirusTotal On-demand 1 Alert enrichment / IOC lookup
Enrich - URL - AbuseIPDB On-demand 1 Alert enrichment / IOC lookup
Enrich - URL - Whois On-demand 1 Alert enrichment / IOC lookup
Enrich - URL - VMRay On-demand 1 Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike On-demand 0 Alert enrichment / IOC lookup
Enrich - URL - URLScan On-demand 0 Alert enrichment / IOC lookup
Enrich - Hash - VT On-demand 0 Alert enrichment / IOC lookup
Enrich - IP - IPDB On-demand 0 Alert enrichment / IOC lookup
Enrich - Username or Email - Okta On-demand 0 Alert enrichment / IOC lookup
Enrich - IP - VT On-demand 0 Alert enrichment / IOC lookup
Enrich - URL - VT On-demand 0 Alert enrichment / IOC lookup
Enrich - Hash - Crowdstrike On-demand 0 Alert enrichment / IOC lookup
Enrich - IP or Domain - Whois On-demand 0 Alert enrichment / IOC lookup
Enrich - Username or Email - Google Workspace On-demand 0 Alert enrichment / IOC lookup
Enrich - Username or Email - Microsoft Entra ID On-demand 0 Alert enrichment / IOC lookup
Enrich - Username - Github On-demand 0 Alert enrichment / IOC lookup
Enrich - Email Address - Slack On-demand 0 Alert enrichment / IOC lookup
Get User Information Using Google Workspace On-demand 0 Alert enrichment / IOC lookup
Enrich IP or Domain Using Whois On-demand 0 Alert enrichment / IOC lookup
Get User Information Using Github On-demand 0 Alert enrichment / IOC lookup
Get User Information Using Microsoft Entra ID On-demand 0 Alert enrichment / IOC lookup
Get User Info On-demand 0 Alert enrichment / IOC lookup
Get User Information Using Okta On-demand 0 Alert enrichment / IOC lookup
Get Hash Info Using Crowdstrike On-demand 0 Alert enrichment / IOC lookup
Get Hash Info Using VirusTotal On-demand 0 Alert enrichment / IOC lookup
Analyze URL with URLScan On-demand 0 Alert enrichment / IOC lookup
Okta Search for User Activity On-demand 0 Alert enrichment / IOC lookup
Get User Information on Email Address Using Slack On-demand 0 Alert enrichment / IOC lookup
Run Dig Command On-demand 0 Alert enrichment / IOC lookup
Secure URL Screenshot Capture On-demand 0 Alert enrichment / IOC lookup
Get End of Life Date for a Product On-demand 0 Alert enrichment / IOC lookup

5. Endpoint Management & EDR Response

Category: SOC | Subcategories: EDR containment & response, Case mgmt & SOAR

Description: CrowdStrike-integrated endpoint response automation covering scheduled server decommission lifecycle management, real-time endpoint isolation and quarantine, RTR (Real Time Response) command execution to single hosts and host batches, device enrichment, and automated tagging of decommissioned assets. Two new subflows now handle CrowdStrike alert verification and device quarantine as discrete, callable response steps for the alert pipeline.

Business problem: Manual endpoint response to security incidents introduces dangerous delay. Automated CrowdStrike containment, RTR execution, and decommission processing reduces dwell time and ensures timely lifecycle management of retiring infrastructure.

Integrations: CrowdStrike, ServiceNow, Blink Case Management

Playbook Type Executions Subcategory
CrowdStrike Server Decom Scheduled (hourly) 960 EDR containment & response
Tag Host as Decommissioned On-demand 11 EDR containment & response
Manage Endpoint Quarantine Status in Crowdstrike On-demand 0 EDR containment & response
Subflow - Response - Alert Verification - Crowdstrike On-demand subflow 0 EDR containment & response
Subflow - Response - Quarantine Device - Crowdstrike On-demand subflow 0 EDR containment & response
CrowdStrike RTR to a Single Host On-demand 0 EDR containment & response
CrowdStrike RTR to a Batch of Hosts On-demand 0 EDR containment & response
Crowdstrike Device Enrichment On-demand 0 EDR containment & response

6. Data Exposure & DLP Response

Category: GRC | Subcategories: DLP triage & exposure resp

Description: Integrates with Cyera (data security posture management) to flag a user's identity as high-risk when a data exposure or sensitive-data-handling signal is detected, creating an auditable risk marker for downstream monitoring.

Business problem: Data exposure risk tied to specific identities is easy to lose track of without a systematic flagging step. Automating the "mark as risky" action ensures every Cyera-detected exposure signal produces a consistent, auditable identity risk designation rather than a one-off manual note.

Integrations: Cyera

Playbook Type Executions Subcategory
Cyera - Mark User as Risky On-demand 23 DLP triage & exposure resp

7. Zscaler Web Policy & DLP Management

Category: Cloud Security | Subcategories: Cloud access & SaaS policy mgmt, SIEM & log pipeline monitoring

Description: Automated management of Zscaler Internet Access web filtering policies, including scheduled expiry cleanup of stale URL rules, webhook-triggered alert processing for policy violations, and dynamic rule creation for cloud file-sharing services (Dropbox, ShareFile, Google Drive). Google Chronicle integration provides SIEM-backed investigation links for Zscaler events.

Business problem: Stale Zscaler URL rules accumulate without automation, creating policy drift and potential security gaps. Automated enforcement of cloud app access policies (especially for file-sharing services that create DLP risk) reduces data exfiltration exposure.

Integrations: Zscaler ZIA, Google Chronicle, Proofpoint TAP

Playbook Type Executions Subcategory
Zscaler Rules for Dropbox, Sharefile, Gdrive On-demand 54 Cloud access & SaaS policy mgmt
Zscaler Expired rules Scheduled (daily 7am) 40 Cloud access & SaaS policy mgmt
Zscaler Webhook Alerts Event (webhook) 12 Cloud access & SaaS policy mgmt
Update TAP URL category and send teams message to user On-demand 0 Cloud access & SaaS policy mgmt
Zscaler Webhook Alerts (main workspace) Event (webhook) 0 Cloud access & SaaS policy mgmt
Google Chronicle Zscaler Search On-demand 0 SIEM & log pipeline monitoring
Google Chronicle Link generator copy On-demand 0 SIEM & log pipeline monitoring

8. ServiceNow ITSM & On-Call Management

Category: Other | Subcategories: IT helpdesk & ticket routing

Description: Bidirectional ServiceNow integration for security operations workflow management. Covers automated processing of employee travel requests for security review and dynamic on-call schedule resolution from ServiceNow and SharePoint, plus two developer test workflows validating ServiceNow custom actions.

Business problem: Security teams need timely awareness of employee travel (for geolocation anomaly context) and a resolvable on-call chain without manually monitoring multiple systems.

Integrations: ServiceNow, SharePoint, Microsoft Entra ID

Playbook Type Executions Subcategory
ServiceNow - Travel Requests Scheduled (every 12hr) 80 IT helpdesk & ticket routing
Subflow - SharePoint - Get Dispatcher On-demand subflow 38 IT helpdesk & ticket routing
Subflow - ServiceNow - Get On-Call On-demand subflow 1 IT helpdesk & ticket routing
SIR Webhook On-demand 0 IT helpdesk & ticket routing
SNOW TEST On-demand (dev/test) 0 IT helpdesk & ticket routing
testing grounds On-demand (dev/test) 0 IT helpdesk & ticket routing

9. Phishing Simulation & Security Awareness

Category: SOC | Subcategories: Phishing sim & awareness

Description: Full Proofpoint Security Awareness Training phishing simulation tracking pipeline, including campaign result ingestion, data storage in Blink tables, and Microsoft Entra ID enrichment of user records. A webform-based onboarding flow and Teams-interactive training workflow provide self-service security awareness tooling. Currently built and staged but not yet producing executions at scale.

Business problem: Security awareness programs require automated data collection to measure campaign effectiveness and identify high-risk users who repeatedly fail simulations — informing targeted remediation and training prioritization.

Integrations: Proofpoint Security Awareness Training, Microsoft Entra ID, Microsoft Teams, ServiceNow, Blink Tables

Playbook Type Executions Subcategory
Phishing Simulation Tracking On-demand 0 Phishing sim & awareness
Subflow - PhishSim Table Update On-demand subflow 0 Phishing sim & awareness
Subflow - Entra PhishSim Enrichment On-demand subflow 0 Phishing sim & awareness
Phishing Simulation Training On-demand 0 Phishing sim & awareness
Training Level 1 - Workflow On-demand 0 Phishing sim & awareness
Training - Webforms Event (web form) 0 Phishing sim & awareness
Phishing Simulation Tracking - Adam Testing Copy On-demand 0 Phishing sim & awareness
Subflow - Entra PhishSim Enrichment copy On-demand subflow 0 Phishing sim & awareness
Subflow - PhishSim Table Update copy On-demand subflow 0 Phishing sim & awareness

10. Threat Intelligence Ingest

Category: SOC | Subcategories: Threat intel ingest & curation, SIEM & log pipeline monitoring

Description: Automated daily ingestion of threat intelligence and breach-monitoring content from RSS feeds — including HackerNews, Bleeping Computer, Dark Reading, Security Weekly, KrebsOnSecurity, HaveIBeenPwned, and Wired — merged and stored in a shared table for SOC consumption. Chronicle log ingestion testing supports SIEM pipeline validation for Zscaler log data via Cyderes-managed Chronicle.

Business problem: SOC teams need a continuous, automated stream of external threat and breach intelligence to stay current on emerging threats without manually monitoring multiple feeds.

Integrations: RSS (HTTP), Google Chronicle (Cyderes), Blink Tables

Playbook Type Executions Subcategory
RSS Feed Scheduled (daily 7am) 40 Threat intel ingest & curation
Company Breaches Scheduled (daily 7am) 40 Threat intel ingest & curation
Cyderes Logs Ingestion Testing On-demand 0 SIEM & log pipeline monitoring

11. Case Management Utilities, Recovery & Testing

Category: SOC | Subcategories: Case mgmt & SOAR

Description: Supporting infrastructure for the SOAR platform including observable relation management (create, update, delete), case similarity detection, stale case closure, unprocessed alert recovery, and observable extraction template validation. Also includes alert-simulation tools used to generate synthetic CrowdStrike, ProofPoint, and Okta alerts for pipeline testing, plus a Teams message-format test.

Business problem: These utilities underpin the health and accuracy of the case management platform and let the team validate the alert pipeline with synthetic data, without representing direct analyst-facing outcomes themselves.

Integrations: Blink Case Management, Microsoft Teams

Playbook Type Executions Subcategory
Utility - Find Similar Cases Based on Observables On-demand 0 Case mgmt & SOAR
Utility - List Observable Alert Relations On-demand 0 Case mgmt & SOAR
Utility - Update Enrichment On-demand 0 Case mgmt & SOAR
Utility - Close Stale Cases On-demand 0 Case mgmt & SOAR
Table Action - Validate Observables Extraction Template On-demand 0 Case mgmt & SOAR
Utility - List Alert Observable Relations On-demand 0 Case mgmt & SOAR
Utility - Set Or Update Observable Relation On-demand 0 Case mgmt & SOAR
Utility - Delete Observable Relation On-demand 0 Case mgmt & SOAR
Recovery - Enrich Non-Enriched Observables On-demand 0 Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts On-demand 0 Case mgmt & SOAR
Simulate Crowdstrike Alert On-demand (dev/test) 0 Case mgmt & SOAR
Simulate Multiple Alerts from Different Sources On-demand (dev/test) 0 Case mgmt & SOAR
Test Email Format On-demand (dev/test) 0 Case mgmt & SOAR

12. Agentic SOC

Category: SOC | Subcategories: Agentic SOC, Alert enrichment / IOC lookup

Description: An AI agent-powered user investigation capability that invokes a named Blink Agent to answer questions about user identities and activity. Represents early-stage deployment of agentic automation for SOC analyst augmentation.

Business problem: Complex investigation questions that span multiple data sources traditionally require significant analyst effort. Agentic automation can handle routine lookup and correlation tasks autonomously, freeing analysts for higher-order decisions.

Integrations: Blink Agents (AI)

Playbook Type Executions Subcategory
Agent Get User Info On-demand 0 Agentic SOC

13. Platform Onboarding & Testing Utilities

Category: Other | Subcategories: SaaS / IT administration

Description: Blink platform onboarding templates ("Hello World") and lightweight subflow-chaining/timing test workflows, spread across three separate workspaces. These validate platform mechanics (bash/python execution, subflow chaining, sleep timing) rather than delivering a security outcome.

Business problem: Not applicable — these are platform enablement and internal testing artifacts, included here for completeness of the full automation inventory rather than as a business-driven use case.

Integrations: None (native Blink platform actions only)

Playbook Type Executions Subcategory
Getting Started - Hello World On-demand 0 SaaS / IT administration
Self-service Demo On-demand 0 SaaS / IT administration
Flow Completion Test On-demand 0 SaaS / IT administration
Subflow 1 - 10 seconds On-demand subflow 0 SaaS / IT administration
Subflow 2 - 15 seconds On-demand subflow 0 SaaS / IT administration

Key Observations

Strengths

Mature email threat pipeline, now with closed-loop response. The Proofpoint TAP ingestion suite remains the highest-volume automation in the environment, processing over 24,000 events in 12 months. Since the last review, the response side matured too: a rebuilt Subflow - Response Router - ProofPoint TAP now drives Zscaler URL blocking and human-in-the-loop Teams messaging directly (39 executions), replacing the earlier standalone response subflow that has since gone dormant.

Identity threat response is now live. The previous report flagged automated identity containment as a gap. That gap is now closing: Subflow - Response - Reset User Password and Revoke Sessions - Microsoft Entra ID has executed 7 times, giving responders a one-step password reset + session revocation action instead of manual, multi-console remediation.

New DLP/data-exposure integration (Cyera). Cyera - Mark User as Risky (23 executions) is a new capability that automatically flags identities associated with data exposure signals from Cyera's data security posture management platform — extending the automation footprint beyond email/endpoint/identity into data risk.

CrowdStrike remains the anchor EDR platform, with 960 automated server decommission checks and now two additional response subflows (alert verification and device quarantine) built to formalize CrowdStrike alert response as discrete, reusable steps.

Comprehensive enrichment library. The IOC enrichment framework covers 10+ intelligence sources with a central observable router (98 invocations) and shared enrichment update subflow, scaling cleanly as new sources are added.

Growing ServiceNow adoption. Travel request processing grew from 51 to 80 executions (+57%), and the on-call dispatcher lookup grew from 18 to 38 executions, indicating increasing reliance on these workflows for day-to-day security operations.

Gaps & Opportunities

Google Chronicle Zscaler Search has gone idle. This workflow ran 9 times in the previous reporting period and shows 0 executions now, while a related but differently-named workflow (Subflow - Response - URL Traffic Verification - Google Chronicle) picked up 7 executions. Worth confirming whether Chronicle-backed investigation moved fully to the new subflow or whether the standalone search tool was simply not needed this period.

Zscaler webhook alert volume dropped sharply (26 → 12 executions), while Zscaler Expired rules and Zscaler Rules for Dropbox, Sharefile, Gdrive both grew. Worth confirming this reflects fewer actual policy violations rather than a webhook delivery issue.

Workspace sprawl and test/demo clutter is increasing. The environment now spans 4 workspaces (up from 1), and roughly 10 of the 105 playbooks are explicitly named as tests, demos, or "copy" duplicates (SNOW TEST, testing grounds, Test Reset, Test Email Format, Simulate Crowdstrike Alert, Simulate Multiple Alerts from Different Sources, Getting Started - Hello World, Self-service Demo, Flow Completion Test, Subflow 1/2 - seconds, plus Phishing Simulation Tracking - Adam Testing Copy and its related "copy" subflows). None have executed. A cleanup pass would sharpen the signal in future reporting.

Phishing simulation tracking is still built but inactive. The Proofpoint Security Awareness Training integration has zero executions, unchanged from last period. Activating it would close the loop between email threat detection (already running at scale) and the training program.

Enrichment pipeline utilization is low relative to its breadth. Despite 98 router invocations, most individual enrichment playbooks show 0 executions; only hash/URL enrichers show single-digit activity. Confirming end-to-end wiring from alert triage into these enrichers would surface value from the existing library.

Agentic SOC is still a single pilot. Agent Get User Info has 0 executions. As Blink's agent platform matures, expanding into multi-step investigation patterns would be a natural next step given the existing enrichment and SOAR foundation.

Integration Ecosystem

Integration Category Used In
Proofpoint TAP Email Security Email Threat Detection, Zscaler Policy
Proofpoint Security Awareness Training Awareness Phishing Simulation
CrowdStrike EDR Enrichment, Endpoint Response
VirusTotal Threat Intel Enrichment
AbuseIPDB Threat Intel Enrichment
URLScan Threat Intel Enrichment
VMRay Threat Intel Enrichment
Cyera Data Security (DSPM/DLP) Data Exposure & DLP Response
Zscaler ZIA Web Security Web Policy Management, Email Response
Google Chronicle (Cyderes) SIEM Zscaler Investigation, Email Response, Log Ingestion
ServiceNow ITSM Alert Escalation, Travel Requests, On-Call, Endpoint Decom
SharePoint ITSM On-Call / Dispatcher Roster
Microsoft Entra ID IAM Enrichment, PhishSim, Identity Threat Response
Okta IAM Enrichment, User Activity
Microsoft Teams Collaboration Analyst Notifications, Interactive Approvals
Microsoft Outlook Email Phishing Response, Error Notifications
Slack Collaboration Enrichment (User Lookup)
GitHub Developer Enrichment (User Info)
Google Workspace Productivity Enrichment (User Info)
RSS (HTTP) Threat Intel Threat Intelligence Ingest
Blink Case Management SOAR (native) Alert/Case/Observable Operations
Blink Agents AI Agentic User Investigation
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
shelter-insurance shodan my_shodan_connection 2026-08-27