Blink Security Automation — Confidential

snyk — Customer Success Report

Generated 2026-08-31 | snyk-value-report.md
2026-08-31Report Date
529Total Playbooks
99Unique Workflows (12m)
1,032,834Actions Automated (12m)
$265,647Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

529
Total playbooks built
all non-deleted workflows
192
Active playbooks
currently enabled
99
Unique workflows executed (12m)
distinct workflows that ran
1,032,834
Actions automated (12m)
completed action steps
5,738.0h
Hours saved (12m)
@ 20s per action
$265,647
Money saved (12m)
@ $100K avg salary
47
New active workflows (last 30d)
recently created & enabled
4,817
Total cases managed
4,707 opened in last 12m
1m
MTTR — mean time to resolve
closed cases, last 12m
10
Active AI agents
of 23 total
539
AI agent tasks executed (12m)
528 in last 30d
In the last 12 months, Blink automated: - 310 security alerts auto-processed end-to-end through the SOC platform - 320 Expel analyst closures synced back to Panther automatically - 298 Panther SIEM alerts ingested and queued for automated response - 47 Panther SIEM alerts routed through the automated paging pipeline - 960 email security events synced from the Panther SIEM pipeline hourly - 28 security digest messages posted to Slack automatically - 261 vendor security reviews automatically triggered from the procurement platform - 51 security review tasks completed for vendor/procurement requests - 44 AI-driven vendor review skill runs executed via a Claude SDK agent - 129 AI-driven security investigations completed end-to-end via the Agentic SOC AI Investigation subflow - 249 investigation guideline lookups served to the AI SOC agent - 193 VIP user status checks performed during automated investigations - 130 case-linked observable enrichment lookups served to the AI SOC agent - 160 audit log ingestion runs across Terraform, Blink, FireHydrant & GitGuardian pipelines - 40 Salesforce network CIDR ranges synced to S3 - 40 cloud security (Orca) notification batches triaged daily - 40 CrowdStrike endpoints automatically tagged with ITAM data - 40 insider threat watchlists refreshed from Okta - 40 Zscaler device status reports synced and delivered to the security team - 6 IT asset inventory databases rebuilt from CrowdStrike & Jira

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC & Automated Alert Response
  • 960Email security events synced from the Panther SIEM pipeline hourly
  • 320Expel analyst closures synced back to Panther automatically
  • 310Security alerts auto-processed end-to-end through SOC platform
42.4%
51
48 active
Alert Enrichment & IOC Lookup
  • 130Case-linked observable enrichment lookups served to the AI SOC agent
1.6%
38
35 active
EDR Containment & Response0 executions
0.0%
3
3 active
Identity Threat Response & User Containment
  • 40Okta user directory records synced for identity lookups
  • 40Insider threat watchlists refreshed from Okta
  • 40Insider threat datasets synced to data lake
2.2%
23
23 active
SIEM & Audit Log Ingestion
  • 40Terraform audit log batches archived to S3
  • 40Blink platform audit log batches archived to S3
  • 40FireHydrant incident log batches archived to S3
2.3%
6
5 active
Cloud Security & Network Posture
  • 40Cloud security (Orca) notification batches triaged
  • 40Orca usage health checks run
  • 40Salesforce network CIDR ranges synced to S3
2.1%
9
7 active
IT Asset Management (ITAM)
  • 40CrowdStrike endpoints tagged with ITAM data
  • 40Devices with broken MDM enrollment identified via automated sweep
  • 6IT asset inventory databases rebuilt from CrowdStrike & Jira
1.6%
8
7 active
Endpoint & Device Management0 executions
0.0%
7
7 active
Vulnerability Management0 executions
0.0%
1
1 active
Security Operations Support & Tooling0 executions
0.0%
4
2 active
Vendor Risk & Security Review Automation
  • 261Vendor security reviews automatically triggered from the procurement platform
  • 51Security review tasks completed for vendor/procurement requests
  • 44AI-driven vendor review skill runs executed via Claude SDK agent
4.4%
3
3 active
Threat Intelligence Digest Distribution
  • 28Security digest messages posted to Slack automatically
0.3%
1
1 active
Total4,600 executions100%
154
142 active

Use Case Growth Over Time

433 unique playbooks  |  12 operational use cases  |  8,075 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Google Workspace GitHub Microsoft Entra ID Slack Extraction Utilities String Utilities
Agentic SOC & Automated Alert Response
Microsoft Outlook Email Google Docs Google Drive Google Sheets Slack Gmail Google Workspace Okta Panther Expel FireHydrant Jira Gemini Snowflake Agents LiteLLM
Security Operations Support & Tooling
Panther Intezer CrowdStrike AWS Microsoft Intune Slack Google Workspace Email Okta Jira Web Form FireHydrant Google Sheets Snowflake Jamf
Cloud Security & Network Posture
Orca Security Slack Google Sheets Gemini Snowflake AWS Zscaler Internet Access Jamf
SIEM & Audit Log Ingestion
AWS FireHydrant Slack
Identity Threat Response & User Containment
Oort CrowdStrike Panther Gemini Google Sheets Google Drive Okta AWS Snowflake Google Workspace Google Admin Console Jamf Slack Salesforce
IT Asset Management (ITAM)
AWS CrowdStrike Jamf Snowflake Slack Google Admin Console
EDR Containment & Response
CrowdStrike
Endpoint & Device Management
Jamf Slack Google Sheets JumpCloud Microsoft Intune CrowdStrike
Vulnerability Management
CrowdStrike Email
Vendor Risk & Security Review Automation
Google Drive Jira Slack
Threat Intelligence Digest Distribution
Slack

04Key Observations

✓  Strengths

Strengths

Mature end-to-end Agentic SOC. The Process Alert → Enrich → Respond pipeline is fully operational with 310 alerts processed, 381 enrichment routes fired, and 320 Expel closures synced — this is a production-grade, lights-out SOC workflow running at scale.

AI investigation agent is fully instrumented and running at scale. The Agentic SOC AI Investigation subflow completed 129 end-to-end investigations, backed by supporting agent abilities — 249 investigation guideline lookups, 193 VIP user checks, 149 org asset lookups, and 130 case-observable enrichment lookups — showing the AI agent is actively reasoning over case context during real investigations, not just running a fixed script.

Comprehensive enrichment coverage. 29 dedicated enrichment playbooks span 8+ threat intel and identity sources (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack). The architecture correctly separates observable enrichment from case response routing, making the library reusable across alert types.

Robust data lake pipeline. Four security tooling sources (Terraform, FireHydrant, GitGuardian, Blink) feed daily into AWS S3 with consistent archiving patterns — 160 ingestion runs in 12 months. This indicates a mature log management strategy beyond just SIEM forwarding.

Strong ITAM foundation. The Build ITAM Database + CrowdStrike tag sync combination runs weekly and daily respectively, producing a continuously refreshed device inventory that underpins both the insider threat monitoring and the on-demand cscheck workflow.

Insider threat monitoring pipeline is active. Okta-based watchlist refreshes running 40 times in 12 months demonstrate a proactive approach to insider risk, not just reactive alerting.

Compromised user containment is architecture-complete. The full multi-tool containment suite (Okta, Google Workspace, Slack, Salesforce, JAMF) with Slack-based human approval is built and ready — a significant security capability that few organizations automate end-to-end.

Vendor risk intake is now automated end-to-end. The Tropic-triggered security review pipeline has processed 261 procurement requests and driven 51 review workflows to completion via Jira in its first period live — extending Blink's footprint from pure SOC/IAM into GRC vendor risk management.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

Enrichment subflows show 0 executions despite the enrichment router running 381 times. The individual enrichment playbooks (Enrich - IP - VT, Enrich - Hash - VT, etc.) all report 0 executions — worth validating that observable types are correctly mapped in the enrichment router and that playbook-level execution tracking is working as expected. If enrichments are running but not registering, this represents a reporting gap.

EDR containment is built but unused. CrowdStrike isolation and RTR playbooks have 0 executions. Given the active SOC pipeline, this likely means actual containment-triggering incidents haven't fired, or analysts are executing containment outside of Blink. Connecting these playbooks to the Response Subflow - Malware handler would close the loop.

Phishing response subflow has 0 executions. Despite the phishing response handler existing (including KnowBe4 campaign detection logic), it has never run. If phishing alerts are flowing through Panther, it's worth verifying the alert template mapping routes them correctly to this subflow.

Compromised user containment hasn't been exercised. The full containment suite (across two workspace variants) shows 0 executions. This is likely by design — these are break-glass workflows — but confirming the Slack approval flow works end-to-end via a tabletop exercise would de-risk the capability.

Vulnerability management coverage is minimal. With CrowdStrike vuln data available and a Snowflake connection in place, there's a clear opportunity to expand into automated vuln prioritization, Jira ticket creation, and SLA tracking — none of which exist today.

Multiple workspace variants for key workflows. Compromised User Containment, JAMF lock, and session revocation playbooks exist in 2-3 workspace copies each (workspaces 48453b3b, afa8215c, 178fdce3). Consolidating to a single production workspace would reduce maintenance overhead and ambiguity about which version is authoritative.

Integration Ecosystem

Category Integrations
SIEM / Threat Detection Panther, Expel
Endpoint / EDR CrowdStrike, JAMF, JumpCloud, Microsoft Intune
Threat Intel VirusTotal, AbuseIPDB, URLScan
Identity & Access Okta, Google Workspace, Google Admin Console, Microsoft Entra ID
Cloud Security Orca Security
Network Security Zscaler
Secrets Detection GitGuardian
Collaboration & Comms Slack, Microsoft Outlook
Productivity Google Sheets, Google Docs, Google Drive
ITSM / Incident Mgmt Jira, FireHydrant
Cloud Infrastructure AWS (S3, Secrets Manager, Glue), Terraform Cloud/HCP
Data Warehouse Snowflake
Code / DevOps GitHub
Enterprise Apps Salesforce
Procurement / Vendor Risk Tropic
Platform Native Blink Case Management, Blink Tables, Blink Web Forms, Blink Audit Logs
Appendices
A Case Management 4,707 cases (12m) | MTTR 1m

Case Management

Total Cases (all-time)
4,817
4,707 opened in last 12m
Cases Opened (30d)
293
54 closed in last 30d
Cases Closed (12m)
54
of 4,707 opened
MTTR
1m
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Snyk SecOps Dev 4,623 4,578 0 N/A
AI SOC 129 129 54 1m
POVWorkspace 65 0 0 N/A
B AI Agents 10 active | 539 tasks (12m)

AI Agents

Active Agents
10
of 23 total
Tasks Executed (12m)
539
528 in last 30d
Data Usage (12m)
40,630,870
40,538,765 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 SOC Analyst AI SOC 258 258 15,066,971
2 Micro Agent - Historical Case Check AI SOC 141 141 6,230,766
3 SOC Agent - Data Protection Agent AI SOC 63 63 9,874,682
4 SOC Agent - Identity Agent AI SOC 30 30 4,448,524
5 SOC Agent - Developer Platform Agent AI SOC 18 18 2,382,964
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
AI SOC528
Snyk SecOps Dev11
Connections0
POVWorkspace0
Snyk SecOps Prod0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
4
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Mobile MDM Devices 00
2 Alert Analysis 00
3 example 00
4 Laptop Status 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Onboarding Form 00
D Full Use Case Analysis 12 use cases | 8,075 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts auto-processed end-to-end through SOC platform 310 Process Alert
Expel analyst closures synced back to Panther automatically 320 Panther - Expel Closure
Panther SIEM alerts ingested & queued for automated response 298 Panther Alert Ingestion
Panther SIEM alerts routed through automated paging pipeline 47 Panther Alert Paging Pipeline
Email security events synced from the Panther SIEM pipeline hourly 960 emails
Security digest messages posted to Slack automatically 28 Slack Webhook for security digest
Vendor security reviews automatically triggered from the procurement platform 261 Tropic automation - automatically start - PROD
Security review tasks completed for vendor/procurement requests 51 Tropic - Security Review Automation
AI-driven vendor review skill runs executed via Claude SDK agent 44 Tropic run Claude SDK flow
Daily SOC metrics reports delivered to on-call team 40 Alerts Stats Reminder
Geofencing sign-in threats investigated & adjudicated via Slack 2 GeoFencig Automation
Cloud security (Orca) notification batches triaged 40 Orca - Check Notifications
Orca usage health checks run 40 Monitor Orca Usage
Terraform audit log batches archived to S3 40 Terraform Log Ingest
Blink platform audit log batches archived to S3 40 BlinkOps Audit Logs ingest
FireHydrant incident log batches archived to S3 40 FireHydrant Log Ingest
GitGuardian audit log batches archived to S3 40 GitGuardian Log Ingestion
GitGuardian secret-detection alerts auto-forwarded to Panther SIEM 3 GitGuardian alerts to Panther
AWS Glue pipeline health checks run 40 Monitor AWS Glue Jobs
Okta user directory records synced for identity lookups 40 Sync Okta Data to Blinkops Table
Insider threat watchlists refreshed from Okta 40 Insider Threat Monitoring List
Insider threat datasets synced to data lake 40 Insider Threat Monitoring S3 Upload
CrowdStrike endpoints tagged with ITAM data 40 Crowdstrike - Sync ITAM tags
Devices with broken MDM enrollment identified via automated sweep 40 Find Devices with Broken MDM
MDM enrollment gaps identified via automated device sweep 2 Get devices not in MDM
Zscaler device status reports synced & delivered to security team 40 Zscaler - Snowflake Tables Sync + slack message
Zscaler enrollment follow-up reminders sent to pending users 3 Automated Zscaler Follow Up
IT asset inventory databases rebuilt from CrowdStrike & Jira 6 Build ITAM Database
IT asset records uploaded to data lake 6 ITAM S3 Upload
Admin user enrichment reports generated from Snowflake 6 Snyk_Admin_User_Enrichment
Zscaler CIDR ranges synced to S3 6 Zscalertwo CIDR ranges sync
Salesforce network CIDR ranges synced to S3 40 Salesforce CIDR ranges sync
On-demand device status audits across JAMF, CrowdStrike & Snowflake 7 New cscheck workflow - jamf, crowdstrike, itam, etc
GitHub username datasets synced to data lake 1 Github Usernames table sync
AI-driven security investigations completed end-to-end by the agentic SOC 129 Subflow - Agentic SOC - Main - AI Investigation
Investigation guideline lookups served to the AI SOC agent 249 Agent Ability - Get Investigation Guidelines
VIP user status checks performed during automated investigations 193 Agent Ability - Get VIP Users
Organizational asset lookups performed by the AI SOC agent 149 Agent Ability - Get Org Assets
Case-linked observable enrichment lookups served to the AI SOC agent 130 Agent Ability - Get Case Observable's Enrichment
Non-enriched observables recovered and processed via automated sweep 1 Recovery - Enrich Non-Enriched Observables
In the last 12 months, Blink automated: - 310 security alerts auto-processed end-to-end through the SOC platform - 320 Expel analyst closures synced back to Panther automatically - 298 Panther SIEM alerts ingested and queued for automated response - 47 Panther SIEM alerts routed through the automated paging pipeline - 960 email security events synced from the Panther SIEM pipeline hourly - 28 security digest messages posted to Slack automatically - 261 vendor security reviews automatically triggered from the procurement platform - 51 security review tasks completed for vendor/procurement requests - 44 AI-driven vendor review skill runs executed via a Claude SDK agent - 129 AI-driven security investigations completed end-to-end via the Agentic SOC AI Investigation subflow - 249 investigation guideline lookups served to the AI SOC agent - 193 VIP user status checks performed during automated investigations - 130 case-linked observable enrichment lookups served to the AI SOC agent - 160 audit log ingestion runs across Terraform, Blink, FireHydrant & GitGuardian pipelines - 40 Salesforce network CIDR ranges synced to S3 - 40 cloud security (Orca) notification batches triaged daily - 40 CrowdStrike endpoints automatically tagged with ITAM data - 40 insider threat watchlists refreshed from Okta - 40 Zscaler device status reports synced and delivered to the security team - 6 IT asset inventory databases rebuilt from CrowdStrike & Jira

Use Case Summary

# Use Case Category Subcategories Playbooks With Executions
1 Agentic SOC & Automated Alert Response SOC Agentic SOC, Case mgmt & SOAR 61 20
2 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup 43 1
3 EDR Containment & Response SOC EDR containment & response 3 0
4 Identity Threat Response & User Containment SOC / IAM Identity threat response, Password & credential lifecycle 31 4
5 SIEM & Audit Log Ingestion SOC SIEM & log pipeline monitoring 6 6
6 Cloud Security & Network Posture Cloud Security CSPM ingest & triage, Cloud provisioning & IaC automation 9 7
7 IT Asset Management (ITAM) Other Endpoint hygiene & MDM ops, SaaS / IT administration 8 7
8 Endpoint & Device Management Other Endpoint hygiene & MDM ops 8 0
9 Vulnerability Management Vulnerability Mgmt Vuln scanning ingest & report 1 0
10 Security Operations Support & Tooling Other IT helpdesk & ticket routing, Financial & fraud operations 4 0
11 Vendor Risk & Security Review Automation GRC Vendor risk & TPRM 3 3
12 Threat Intelligence Digest Distribution SOC Threat intel ingest & curation 1 1
Total 178 49

Use Cases

1. Agentic SOC & Automated Alert Response

Description: Fully automated security operations center pipeline — ingests alerts from Panther via webhook, extracts and deduplicates observables, orchestrates enrichment, routes to response playbooks based on alert type, and syncs closed cases back to the SIEM. Includes AI-assisted backlog analysis and daily ops metrics reporting.

Business Problem: Analyst capacity is the binding constraint in any SOC. This platform eliminates manual alert triage, deduplication, and initial enrichment — freeing analysts for high-judgment decisions while ensuring consistent handling of every alert at machine speed.

Category: SOC

Subcategories: Agentic SOC, Case mgmt & SOAR

Integrations: Panther, Microsoft Outlook, Slack, Jira, CrowdStrike, Gemini, Google Docs, Google Sheets, Blink Case Management

Playbook Executions (12mo) Automation Type
Process Alert 310 Event (polling)
Panther Alert Ingestion 298 Event (webhook)
Panther - Expel Closure 320 Scheduled
Alerts Stats Reminder 40 Scheduled
GeoFencig Automation 2 Event (polling)
timezone to location 0 On-demand (utility)
emails 960 Scheduled (hourly)
Subflow - Enrich Observables - Main Router 381 On-demand (subflow)
Subflow - Response - Main Router 310 On-demand (subflow)
Response Subflow - Phishing 0 On-demand (subflow)
Response Subflow - Malware 0 On-demand (subflow)
Subflow - Missing Alert Template Notification 0 On-demand (subflow)
Table Action - Validate Observables Extraction Template 0 On-demand
Recovery - Handle Unprocessed Alerts 0 On-demand
Recovery - Enrich Non-Enriched Observables 0 On-demand
SCRT Project AI Backlog Cleaner 0 On-demand
Automated SCRT Reminder 0 Event (webhook)
Utility - Set Or Update Observable Relation 0 On-demand (utility)
Utility - Close Stale Cases 0 On-demand (utility)
Utility - Delete Observable Relation 0 On-demand (utility)
Utility - List Observable Alert Relations 0 On-demand (utility)
Utility - List Alert Observable Relations 0 On-demand (utility)
Creating Google Doc 0 On-demand (utility)
Add JSON to Google Sheet 0 On-demand (utility)
Error Handling - Send Error Notification Email 0 On-demand (utility)
JSON Payload Anonymizer 0 On-demand (utility)
Simulate Crowdstrike Alert 0 On-demand (testing)
Simulate Crowdstrike Alert 0 On-demand (testing)
Simulate Multiple Alerts from Different Sources 0 On-demand (testing)
USE WITH CARE - Reset Case Management Environment 0 On-demand (testing)
Agentic Panther Daily Analysis 0 On-demand
New Workflow 16 0 On-demand (testing)
Agent Ability - Get Alert 0 On-demand
Agent Ability - Get Vendor Logo List 0 On-demand
Load cases taggings from csv 0 On-demand
Load cases predictions from conclusions 0 On-demand
Main Evaluation - Evaluate On Cases dataset 0 On-demand
Agent Ability - Get VIP Users 193 On-demand
Agent Ability - Get Org Technological Stack 3 On-demand
Error Handling - Send Error Notification Email 0 On-demand (utility)
Utility - Sanitize Case From Prior Investigation 129 On-demand (utility)
Utility - Truncate Case & Alert 129 On-demand (utility)
Agent Ability - Get Org Assets 149 On-demand
Subflow - Agentic SOC - Main - AI Investigation 129 On-demand (subflow)
Subflow - Response - Main Router 129 On-demand (subflow)
Recovery - Handle Unprocessed Alert 1 On-demand
Utility - Refresh investigation 0 On-demand (utility)
Refresh investigations on case dataset 0 On-demand
Agent Ability - Get Investigation Guidelines 249 On-demand
Table Action - Validate Observables Extraction Template 0 On-demand
Utility - List Observable Alert Relations 0 On-demand (utility)
Agent Ability - Get Case 0 On-demand
Utility - Set Or Update Observable Relation 0 On-demand (utility)
Utility - Close Stale Cases 0 On-demand (utility)
Utility - Delete Observable Relation 0 On-demand (utility)
Recovery - Enrich Non-Enriched Observables 1 On-demand
Utility - List Alert Observable Relations 0 On-demand (utility)
Comment On Case 0 On-demand
Subflow - Missing Alert Template Notification 3 On-demand (subflow)
Utility - Add Observable Extraction Rule 0 On-demand (utility)
Panther Alert Paging Pipeline 47 Event (webhook)

2. Alert Enrichment & IOC Lookup

Description: A comprehensive library of enrichment playbooks covering every major observable type — IPs, domains, hashes, URLs, usernames, and email addresses — queried across threat intel platforms and enterprise identity sources. All playbooks feed context back into the Blink case management platform via the Subflow - Update Enrichment Data pipeline.

Business Problem: Manual IOC lookup across 8+ tools is a time-consuming, error-prone step that slows analyst response. This library standardizes enrichment into reusable building blocks that run automatically when the Process Alert flow triggers observable extraction.

Category: SOC

Subcategories: Alert enrichment / IOC lookup

Integrations: VirusTotal, URLScan, AbuseIPDB, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Whois, Blink Case Management, Blink Tables

Playbook Executions (12mo) Automation Type
Subflow - Update Enrichment Data 0 On-demand (subflow)
Utility - Update Enrichment 0 On-demand (utility)
Utility - Find Similar Cases Based on Observables 0 On-demand (utility)
Enrich - Agent ID - Crowdstrike 0 On-demand
Enrich - URL - URLScan 0 On-demand
Enrich - Hash - VT 0 On-demand
Enrich - IP - IPDB 0 On-demand
Enrich - Username or Email - Okta 0 On-demand
Enrich - IP - VT 0 On-demand
Enrich - URL - VT 0 On-demand
Enrich - Hash - Crowdstrike 0 On-demand
Enrich - IP or Domain - Whois 0 On-demand
Enrich - Username or Email - Google Workspace 0 On-demand
Enrich - Username or Email - Microsoft Entra ID 0 On-demand
Enrich - Username - Github 0 On-demand
Enrich - Email Address - Slack 0 On-demand
Enrich IP or Domain Using Whois 0 On-demand
Analyze URL with URLScan 0 On-demand
Secure URL Screenshot Capture 0 On-demand
Run Dig Command 0 On-demand
Get User Information Using Google Workspace 0 On-demand
Get User Information Using Github 0 On-demand
Get User Information Using Microsoft Entra ID 0 On-demand
Get User Information on Email Address Using Slack 0 On-demand
Get Hash Info Using Crowdstrike 0 On-demand
Get Hash Info Using VirusTotal 0 On-demand
Get User Information Using Okta 0 On-demand
Okta Search for User Activity 0 On-demand
Get End of Life Date for a Product 0 On-demand
Query Observable 0 On-demand
Agent Ability - Get Observable Types From Case Management Settings 0 On-demand
Agent Ability - Get Observable Relation Types From Case Management Settings 0 On-demand
Secure URL Screenshot Capture 0 On-demand
Enrich - Router Default Case 0 On-demand
Utility - Find Similar Cases Based on Observables 0 On-demand (utility)
Agent Ability - Get Observable Reputations From Case Management Settings 0 On-demand
Get End of Life Date for a Product 0 On-demand
Get Observables by Case ID 0 On-demand
Agent Ability - Query Observables by Content 0 On-demand
Utility - Update Enrichment 0 On-demand (utility)
Run Dig Command 0 On-demand
Agent Ability - Get Case Observable's Enrichment 130 On-demand
Enrich - Check If Observable inside Organization 0 On-demand

3. EDR Containment & Response

Description: On-demand playbooks to isolate compromised endpoints and execute remote response actions via CrowdStrike Real-Time Response (RTR) — targeting either a single host or a batch of devices simultaneously.

Business Problem: When a malware or intrusion alert fires, minutes matter. This suite enables analysts to quarantine a device or run forensic commands directly from the SOC workflow without switching tools or manually identifying the host.

Category: SOC

Subcategories: EDR containment & response

Integrations: CrowdStrike

Playbook Executions (12mo) Automation Type
Manage Endpoint Quarantine Status in Crowdstrike 0 On-demand
CrowdStrike RTR to a Single Host 0 On-demand
CrowdStrike RTR to a Batch of Hosts 0 On-demand

4. Identity Threat Response & User Containment

Description: End-to-end orchestration for responding to compromised or risky user accounts. Includes human-in-the-loop Slack approval workflows that allow analysts to select containment actions (revoke sessions, lock device, reset password) across Okta, Google Workspace, Slack, Salesforce, and JAMF — all triggered from a single entry point. Also covers proactive insider threat monitoring, risky user sweeps, and admin user enrichment via Panther/Snowflake.

Business Problem: Containing a compromised account requires coordinated action across 5+ enterprise tools. Without automation, an analyst manually revokes sessions across each system sequentially, often taking 30+ minutes. This suite reduces mean time to contain (MTTC) to under two minutes while maintaining an auditable approval trail.

Category: SOC / IAM

Subcategories: Identity threat response, Password & credential lifecycle, Identity lifecycle automation

Integrations: Okta, Google Workspace, Google Admin Console, Slack, Salesforce, JAMF, Panther, Snowflake, Blink Tables

Playbook Executions (12mo) Automation Type
Insider Threat Monitoring List 40 Scheduled
Insider Threat Monitoring S3 Upload 40 Scheduled
Snyk_Admin_User_Enrichment 6 Scheduled
Compromised User Containment 0 On-demand
Compromised User Containment - Main 0 On-demand (subflow)
Compromised User Containment - Execute Actions 0 On-demand (subflow)
JAMF - Lock User Computer 0 On-demand (subflow)
Google Workspace - Clear User Sessions 0 On-demand (subflow)
OKTA - Reset User Sessions 0 On-demand (subflow)
Slack - Revoke User Sessions 0 On-demand (subflow)
Salesforce - Revoke User Sessions 0 On-demand (subflow)
Compromised User Containment 0 On-demand
Compromised User Containment - Main 0 On-demand (subflow)
Compromised User Containment - Execute Actions 0 On-demand (subflow)
Google Workspace - Clear User Sessions 0 On-demand (subflow)
Google Workspace - Clear User Tokens/Sessions 0 On-demand
OKTA - Reset User Sessions 0 On-demand (subflow)
Slack - Revoke User Sessions 0 On-demand (subflow)
Reset User Password with Okta 0 On-demand
Reset User Password on Google Workspace 0 On-demand
Risky User Sweep 0 On-demand
Risky User - Panther Sweep 0 On-demand
Risky user intake self service 0 On-demand
WIP - JAMF - Lock User Computer 0 On-demand
WIP - Salesforce - Revoke User Sessions 0 On-demand
Sync Okta Data to Blinkops Table 40 Scheduled (daily)
OKTA - Reset User Sessions AND Suspend User 0 On-demand
Un-suspend Okta User 0 On-demand
Google workspace - revoke tokens 0 On-demand
Slack - Revoke User Sessions 0 On-demand (subflow)
Salesforce - Freeze Account 0 On-demand
Change OUs for List of Users 0 On-demand

5. SIEM & Audit Log Ingestion

Description: Scheduled daily pipelines that pull audit logs from five security tooling sources and archive them to AWS S3, feeding a centralized data lake for correlation and compliance. Covers Terraform HCP, FireHydrant incident management, GitGuardian secrets detection, and the Blink platform itself, with AWS Glue pipeline health monitoring.

Business Problem: Maintaining continuous, tamper-evident audit trails across security tooling is required for compliance and forensic readiness. Manual log pulls are unreliable and error-prone. These pipelines ensure each source is archived daily without analyst involvement.

Category: SOC

Subcategories: SIEM & log pipeline monitoring

Integrations: Terraform HCP, FireHydrant, GitGuardian, Blink (audit logs), AWS S3, AWS Glue, Panther

Playbook Executions (12mo) Automation Type
Terraform Log Ingest 40 Scheduled (daily)
BlinkOps Audit Logs ingest 40 Scheduled (daily)
FireHydrant Log Ingest 40 Scheduled (daily)
GitGuardian Log Ingestion 40 Scheduled (daily)
Monitor AWS Glue Jobs 40 Scheduled (daily)
GitGuardian alerts to Panther 3 Event (webhook)

6. Cloud Security & Network Posture

Description: Monitors Orca Security cloud posture notifications daily, tracks Zscaler device enrollment and CIDR ranges, and automates Terraform Cloud plan activation via webhook. Includes Zscaler-to-Snowflake data sync with Slack notification, device statistics calculation, and bulk user communication for Zscaler onboarding campaigns.

Business Problem: Cloud security posture and network access policy drift are hard to detect manually at scale. This suite surfaces Orca findings daily, keeps Zscaler device data synchronized with the data warehouse, and ensures Terraform-managed network changes activate automatically.

Category: Cloud Security

Subcategories: CSPM ingest & triage, Cloud provisioning & IaC automation, Cloud asset coverage & inventory

Integrations: Orca Security, Zscaler, AWS S3, Snowflake, Slack, JAMF, Terraform Cloud, Google Sheets, Salesforce

Playbook Executions (12mo) Automation Type
Orca - Check Notifications 40 Scheduled (daily)
Monitor Orca Usage 40 Scheduled (daily)
Zscaler - Snowflake Tables Sync + slack message 40 Scheduled (daily)
Automated Zscaler Follow Up 3 Scheduled (twice weekly)
Zscalertwo CIDR ranges sync 6 Scheduled (daily)
Salesforce CIDR ranges sync 40 Scheduled (daily)
Zscaler Terraform Activator 0 Event (webhook)
Zscaler Jamf Workflow 0 On-demand
Slack Bulk Message 0 On-demand

7. IT Asset Management (ITAM)

Description: Automated asset inventory management pipeline that pulls data from CrowdStrike, JAMF, and Jira weekly to build a comprehensive user-device database, uploads it to S3, and keeps CrowdStrike device tags synchronized with ITAM classifications. Includes on-demand cross-system device status checks and GitHub username synchronization for identity correlation.

Business Problem: Asset inventory is foundational for vulnerability management, offboarding, and compliance — but manually aggregating it from multiple systems is a weekly burden. This suite keeps the ITAM database current without manual effort and allows on-demand lookups across all asset data sources in a single query.

Category: Other

Subcategories: Endpoint hygiene & MDM ops, SaaS / IT administration

Integrations: CrowdStrike, JAMF, Jira (via AWS Secrets Manager), Snowflake, AWS S3, Slack, GitHub, Google Admin Console, Blink Tables

Playbook Executions (12mo) Automation Type
Crowdstrike - Sync ITAM tags 40 Scheduled (daily)
Build ITAM Database 6 Scheduled (weekly)
ITAM S3 Upload 6 Scheduled (weekly)
New cscheck workflow - jamf, crowdstrike, itam, etc 7 On-demand
Github Usernames table sync 1 Scheduled (daily)
Find Devices with Broken MDM 40 Scheduled (daily)
Get devices not in MDM 2 Scheduled (weekly)
create comprehensive dashboard 0 On-demand

8. Endpoint & Device Management

Description: A suite of device wipe and lock playbooks spanning JAMF, JumpCloud, and Microsoft Intune — executable by serial number or user email. Includes post-action verification to confirm wipe commands completed successfully, with results logged to Google Sheets for audit trail.

Business Problem: Lost or offboarded employee devices require rapid remote wipe to prevent data exfiltration. This suite provides a consistent, cross-MDM interface to initiate and verify device wipes without requiring direct MDM console access.

Category: Other

Subcategories: Endpoint hygiene & MDM ops

Integrations: JAMF, JumpCloud, Microsoft Intune, Google Sheets, Blink Tables

Playbook Executions (12mo) Automation Type
Jamf Wipe Device 0 On-demand
SERIAL - JAMF - Wipe User Computer 0 On-demand
JumpCloud - Wipe/Lock device by Serial Number 0 On-demand
Intune - Wipe Device 0 On-demand
Jamf - successful wipe check 0 On-demand
Get Jamf Devices in Certain Group 0 On-demand
WIP - JAMF - Wipe User Computer 0 On-demand
Crowdstrike Reboot Pending Macs 0 On-demand

9. Vulnerability Management

Description: On-demand vulnerability report generation using CrowdStrike's vuln dataset, with results delivered directly to stakeholders via email.

Business Problem: Vulnerability status reports requested by engineering teams or leadership typically require manual CrowdStrike console navigation and export. This playbook automates the retrieval and delivery in a single step.

Category: Vulnerability Mgmt

Subcategories: Vuln scanning ingest & report

Integrations: CrowdStrike, Blink email

Playbook Executions (12mo) Automation Type
List Vulnerabilities with CrowdStrike and Send Results via Email 0 On-demand

10. Security Operations Support & Tooling

Description: Miscellaneous operational tooling supporting the security team — including on-call pay calculation from FireHydrant schedule data, a self-service Okta group provisioning web form, and a GitHub username testing workflow.

Category: Other

Subcategories: IT helpdesk & ticket routing, Financial & fraud operations

Integrations: FireHydrant, Okta, Slack, Google Sheets, Blink Web Forms

Playbook Executions (12mo) Automation Type
On-Call Pay Calculator 0 On-demand
Web Form 0 Event (web form)
testing 0 On-demand
New Workflow 0 On-demand

11. Vendor Risk & Security Review Automation

Description: Captures new procurement requests from Tropic (spend/vendor management platform) via webhook and drives them through a security review process — assigning Jira tasks to the security team and tracking review status to completion.

Business Problem: Every new vendor or procurement request requires a security review before purchase, but manually triaging each incoming request creates delays and inconsistent documentation. This automation intakes every request from Tropic and orchestrates the review through Jira, giving the security team a consistent, auditable process.

Category: GRC

Subcategories: Vendor risk & TPRM

Integrations: Tropic, Jira, Blink Tables, Google Drive

Playbook Executions (12mo) Automation Type
Tropic automation - automatically start - PROD 261 Event (webhook)
Tropic - Security Review Automation 51 On-demand
Tropic run Claude SDK flow 44 On-demand

12. Threat Intelligence Digest Distribution

Description: Webhook-triggered pipeline that receives curated security/RSS content and posts it as a threaded digest message in Slack, keeping the security team informed of external threat intelligence and industry news without manual curation.

Business Problem: Staying current on emerging threats and industry security news requires manually checking multiple external feeds. This automation delivers a consolidated digest directly into the team's existing Slack workspace, removing the need for analysts to monitor sources individually.

Category: SOC

Subcategories: Threat intel ingest & curation

Integrations: Slack

Playbook Executions (12mo) Automation Type
Slack Webhook for security digest 28 Event (webhook)

Key Observations

Strengths

Mature end-to-end Agentic SOC. The Process Alert → Enrich → Respond pipeline is fully operational with 310 alerts processed, 381 enrichment routes fired, and 320 Expel closures synced — this is a production-grade, lights-out SOC workflow running at scale.

AI investigation agent is fully instrumented and running at scale. The Agentic SOC AI Investigation subflow completed 129 end-to-end investigations, backed by supporting agent abilities — 249 investigation guideline lookups, 193 VIP user checks, 149 org asset lookups, and 130 case-observable enrichment lookups — showing the AI agent is actively reasoning over case context during real investigations, not just running a fixed script.

Comprehensive enrichment coverage. 29 dedicated enrichment playbooks span 8+ threat intel and identity sources (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack). The architecture correctly separates observable enrichment from case response routing, making the library reusable across alert types.

Robust data lake pipeline. Four security tooling sources (Terraform, FireHydrant, GitGuardian, Blink) feed daily into AWS S3 with consistent archiving patterns — 160 ingestion runs in 12 months. This indicates a mature log management strategy beyond just SIEM forwarding.

Strong ITAM foundation. The Build ITAM Database + CrowdStrike tag sync combination runs weekly and daily respectively, producing a continuously refreshed device inventory that underpins both the insider threat monitoring and the on-demand cscheck workflow.

Insider threat monitoring pipeline is active. Okta-based watchlist refreshes running 40 times in 12 months demonstrate a proactive approach to insider risk, not just reactive alerting.

Compromised user containment is architecture-complete. The full multi-tool containment suite (Okta, Google Workspace, Slack, Salesforce, JAMF) with Slack-based human approval is built and ready — a significant security capability that few organizations automate end-to-end.

Vendor risk intake is now automated end-to-end. The Tropic-triggered security review pipeline has processed 261 procurement requests and driven 51 review workflows to completion via Jira in its first period live — extending Blink's footprint from pure SOC/IAM into GRC vendor risk management.

Gaps & Opportunities

Enrichment subflows show 0 executions despite the enrichment router running 381 times. The individual enrichment playbooks (Enrich - IP - VT, Enrich - Hash - VT, etc.) all report 0 executions — worth validating that observable types are correctly mapped in the enrichment router and that playbook-level execution tracking is working as expected. If enrichments are running but not registering, this represents a reporting gap.

EDR containment is built but unused. CrowdStrike isolation and RTR playbooks have 0 executions. Given the active SOC pipeline, this likely means actual containment-triggering incidents haven't fired, or analysts are executing containment outside of Blink. Connecting these playbooks to the Response Subflow - Malware handler would close the loop.

Phishing response subflow has 0 executions. Despite the phishing response handler existing (including KnowBe4 campaign detection logic), it has never run. If phishing alerts are flowing through Panther, it's worth verifying the alert template mapping routes them correctly to this subflow.

Compromised user containment hasn't been exercised. The full containment suite (across two workspace variants) shows 0 executions. This is likely by design — these are break-glass workflows — but confirming the Slack approval flow works end-to-end via a tabletop exercise would de-risk the capability.

Vulnerability management coverage is minimal. With CrowdStrike vuln data available and a Snowflake connection in place, there's a clear opportunity to expand into automated vuln prioritization, Jira ticket creation, and SLA tracking — none of which exist today.

Multiple workspace variants for key workflows. Compromised User Containment, JAMF lock, and session revocation playbooks exist in 2-3 workspace copies each (workspaces 48453b3b, afa8215c, 178fdce3). Consolidating to a single production workspace would reduce maintenance overhead and ambiguity about which version is authoritative.

Integration Ecosystem

Category Integrations
SIEM / Threat Detection Panther, Expel
Endpoint / EDR CrowdStrike, JAMF, JumpCloud, Microsoft Intune
Threat Intel VirusTotal, AbuseIPDB, URLScan
Identity & Access Okta, Google Workspace, Google Admin Console, Microsoft Entra ID
Cloud Security Orca Security
Network Security Zscaler
Secrets Detection GitGuardian
Collaboration & Comms Slack, Microsoft Outlook
Productivity Google Sheets, Google Docs, Google Drive
ITSM / Incident Mgmt Jira, FireHydrant
Cloud Infrastructure AWS (S3, Secrets Manager, Glue), Terraform Cloud/HCP
Data Warehouse Snowflake
Code / DevOps GitHub
Enterprise Apps Salesforce
Procurement / Vendor Risk Tropic
Platform Native Blink Case Management, Blink Tables, Blink Web Forms, Blink Audit Logs
E New Integrations (detail) 2 added in last 30d

New Integrations Added - Last 30 Days

2 new connections
TenantIntegrationConnection NameAdded
snyk apikey-auth gitguardian_logs 2026-08-27
snyk okta okta_dev_connection 2026-08-11