01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC & Automated Alert Response |
| 42.4% | 51 48 active |
| Alert Enrichment & IOC Lookup |
| 1.6% | 38 35 active |
| EDR Containment & Response | 0 executions | 0.0% | 3 3 active |
| Identity Threat Response & User Containment |
| 2.2% | 23 23 active |
| SIEM & Audit Log Ingestion |
| 2.3% | 6 5 active |
| Cloud Security & Network Posture |
| 2.1% | 9 7 active |
| IT Asset Management (ITAM) |
| 1.6% | 8 7 active |
| Endpoint & Device Management | 0 executions | 0.0% | 7 7 active |
| Vulnerability Management | 0 executions | 0.0% | 1 1 active |
| Security Operations Support & Tooling | 0 executions | 0.0% | 4 2 active |
| Vendor Risk & Security Review Automation |
| 4.4% | 3 3 active |
| Threat Intelligence Digest Distribution |
| 0.3% | 1 1 active |
| Total | 4,600 executions | 100% | 154 142 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature end-to-end Agentic SOC. The Process Alert → Enrich → Respond pipeline is fully operational with 310 alerts processed, 381 enrichment routes fired, and 320 Expel closures synced — this is a production-grade, lights-out SOC workflow running at scale.
AI investigation agent is fully instrumented and running at scale. The Agentic SOC AI Investigation subflow completed 129 end-to-end investigations, backed by supporting agent abilities — 249 investigation guideline lookups, 193 VIP user checks, 149 org asset lookups, and 130 case-observable enrichment lookups — showing the AI agent is actively reasoning over case context during real investigations, not just running a fixed script.
Comprehensive enrichment coverage. 29 dedicated enrichment playbooks span 8+ threat intel and identity sources (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack). The architecture correctly separates observable enrichment from case response routing, making the library reusable across alert types.
Robust data lake pipeline. Four security tooling sources (Terraform, FireHydrant, GitGuardian, Blink) feed daily into AWS S3 with consistent archiving patterns — 160 ingestion runs in 12 months. This indicates a mature log management strategy beyond just SIEM forwarding.
Strong ITAM foundation. The Build ITAM Database + CrowdStrike tag sync combination runs weekly and daily respectively, producing a continuously refreshed device inventory that underpins both the insider threat monitoring and the on-demand cscheck workflow.
Insider threat monitoring pipeline is active. Okta-based watchlist refreshes running 40 times in 12 months demonstrate a proactive approach to insider risk, not just reactive alerting.
Compromised user containment is architecture-complete. The full multi-tool containment suite (Okta, Google Workspace, Slack, Salesforce, JAMF) with Slack-based human approval is built and ready — a significant security capability that few organizations automate end-to-end.
Vendor risk intake is now automated end-to-end. The Tropic-triggered security review pipeline has processed 261 procurement requests and driven 51 review workflows to completion via Jira in its first period live — extending Blink's footprint from pure SOC/IAM into GRC vendor risk management.
###
Gaps & Opportunities
Enrichment subflows show 0 executions despite the enrichment router running 381 times. The individual enrichment playbooks (Enrich - IP - VT, Enrich - Hash - VT, etc.) all report 0 executions — worth validating that observable types are correctly mapped in the enrichment router and that playbook-level execution tracking is working as expected. If enrichments are running but not registering, this represents a reporting gap.
EDR containment is built but unused. CrowdStrike isolation and RTR playbooks have 0 executions. Given the active SOC pipeline, this likely means actual containment-triggering incidents haven't fired, or analysts are executing containment outside of Blink. Connecting these playbooks to the Response Subflow - Malware handler would close the loop.
Phishing response subflow has 0 executions. Despite the phishing response handler existing (including KnowBe4 campaign detection logic), it has never run. If phishing alerts are flowing through Panther, it's worth verifying the alert template mapping routes them correctly to this subflow.
Compromised user containment hasn't been exercised. The full containment suite (across two workspace variants) shows 0 executions. This is likely by design — these are break-glass workflows — but confirming the Slack approval flow works end-to-end via a tabletop exercise would de-risk the capability.
Vulnerability management coverage is minimal. With CrowdStrike vuln data available and a Snowflake connection in place, there's a clear opportunity to expand into automated vuln prioritization, Jira ticket creation, and SLA tracking — none of which exist today.
Multiple workspace variants for key workflows. Compromised User Containment, JAMF lock, and session revocation playbooks exist in 2-3 workspace copies each (workspaces 48453b3b, afa8215c, 178fdce3). Consolidating to a single production workspace would reduce maintenance overhead and ambiguity about which version is authoritative.
Integration Ecosystem
| Category | Integrations |
|---|---|
| SIEM / Threat Detection | Panther, Expel |
| Endpoint / EDR | CrowdStrike, JAMF, JumpCloud, Microsoft Intune |
| Threat Intel | VirusTotal, AbuseIPDB, URLScan |
| Identity & Access | Okta, Google Workspace, Google Admin Console, Microsoft Entra ID |
| Cloud Security | Orca Security |
| Network Security | Zscaler |
| Secrets Detection | GitGuardian |
| Collaboration & Comms | Slack, Microsoft Outlook |
| Productivity | Google Sheets, Google Docs, Google Drive |
| ITSM / Incident Mgmt | Jira, FireHydrant |
| Cloud Infrastructure | AWS (S3, Secrets Manager, Glue), Terraform Cloud/HCP |
| Data Warehouse | Snowflake |
| Code / DevOps | GitHub |
| Enterprise Apps | Salesforce |
| Procurement / Vendor Risk | Tropic |
| Platform Native | Blink Case Management, Blink Tables, Blink Web Forms, Blink Audit Logs |
A Case Management 4,707 cases (12m) | MTTR 1m
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Snyk SecOps Dev | 4,623 | 4,578 | 0 | N/A |
| AI SOC | 129 | 129 | 54 | 1m |
| POVWorkspace | 65 | 0 | 0 | N/A |
B AI Agents 10 active | 539 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | SOC Analyst | AI SOC | 258 | 258 | 15,066,971 |
| 2 | Micro Agent - Historical Case Check | AI SOC | 141 | 141 | 6,230,766 |
| 3 | SOC Agent - Data Protection Agent | AI SOC | 63 | 63 | 9,874,682 |
| 4 | SOC Agent - Identity Agent | AI SOC | 30 | 30 | 4,448,524 |
| 5 | SOC Agent - Developer Platform Agent | AI SOC | 18 | 18 | 2,382,964 |
| Workspace | Tasks (12m) |
|---|---|
| AI SOC | 528 |
| Snyk SecOps Dev | 11 |
| Connections | 0 |
| POVWorkspace | 0 |
| Snyk SecOps Prod | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Mobile MDM Devices | 0 | 0 |
| 2 | Alert Analysis | 0 | 0 |
| 3 | example | 0 | 0 |
| 4 | Laptop Status | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Onboarding Form | 0 | 0 |
D Full Use Case Analysis 12 use cases | 8,075 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-processed end-to-end through SOC platform | 310 | Process Alert |
| Expel analyst closures synced back to Panther automatically | 320 | Panther - Expel Closure |
| Panther SIEM alerts ingested & queued for automated response | 298 | Panther Alert Ingestion |
| Panther SIEM alerts routed through automated paging pipeline | 47 | Panther Alert Paging Pipeline |
| Email security events synced from the Panther SIEM pipeline hourly | 960 | emails |
| Security digest messages posted to Slack automatically | 28 | Slack Webhook for security digest |
| Vendor security reviews automatically triggered from the procurement platform | 261 | Tropic automation - automatically start - PROD |
| Security review tasks completed for vendor/procurement requests | 51 | Tropic - Security Review Automation |
| AI-driven vendor review skill runs executed via Claude SDK agent | 44 | Tropic run Claude SDK flow |
| Daily SOC metrics reports delivered to on-call team | 40 | Alerts Stats Reminder |
| Geofencing sign-in threats investigated & adjudicated via Slack | 2 | GeoFencig Automation |
| Cloud security (Orca) notification batches triaged | 40 | Orca - Check Notifications |
| Orca usage health checks run | 40 | Monitor Orca Usage |
| Terraform audit log batches archived to S3 | 40 | Terraform Log Ingest |
| Blink platform audit log batches archived to S3 | 40 | BlinkOps Audit Logs ingest |
| FireHydrant incident log batches archived to S3 | 40 | FireHydrant Log Ingest |
| GitGuardian audit log batches archived to S3 | 40 | GitGuardian Log Ingestion |
| GitGuardian secret-detection alerts auto-forwarded to Panther SIEM | 3 | GitGuardian alerts to Panther |
| AWS Glue pipeline health checks run | 40 | Monitor AWS Glue Jobs |
| Okta user directory records synced for identity lookups | 40 | Sync Okta Data to Blinkops Table |
| Insider threat watchlists refreshed from Okta | 40 | Insider Threat Monitoring List |
| Insider threat datasets synced to data lake | 40 | Insider Threat Monitoring S3 Upload |
| CrowdStrike endpoints tagged with ITAM data | 40 | Crowdstrike - Sync ITAM tags |
| Devices with broken MDM enrollment identified via automated sweep | 40 | Find Devices with Broken MDM |
| MDM enrollment gaps identified via automated device sweep | 2 | Get devices not in MDM |
| Zscaler device status reports synced & delivered to security team | 40 | Zscaler - Snowflake Tables Sync + slack message |
| Zscaler enrollment follow-up reminders sent to pending users | 3 | Automated Zscaler Follow Up |
| IT asset inventory databases rebuilt from CrowdStrike & Jira | 6 | Build ITAM Database |
| IT asset records uploaded to data lake | 6 | ITAM S3 Upload |
| Admin user enrichment reports generated from Snowflake | 6 | Snyk_Admin_User_Enrichment |
| Zscaler CIDR ranges synced to S3 | 6 | Zscalertwo CIDR ranges sync |
| Salesforce network CIDR ranges synced to S3 | 40 | Salesforce CIDR ranges sync |
| On-demand device status audits across JAMF, CrowdStrike & Snowflake | 7 | New cscheck workflow - jamf, crowdstrike, itam, etc |
| GitHub username datasets synced to data lake | 1 | Github Usernames table sync |
| AI-driven security investigations completed end-to-end by the agentic SOC | 129 | Subflow - Agentic SOC - Main - AI Investigation |
| Investigation guideline lookups served to the AI SOC agent | 249 | Agent Ability - Get Investigation Guidelines |
| VIP user status checks performed during automated investigations | 193 | Agent Ability - Get VIP Users |
| Organizational asset lookups performed by the AI SOC agent | 149 | Agent Ability - Get Org Assets |
| Case-linked observable enrichment lookups served to the AI SOC agent | 130 | Agent Ability - Get Case Observable's Enrichment |
| Non-enriched observables recovered and processed via automated sweep | 1 | Recovery - Enrich Non-Enriched Observables |
Use Case Summary
| # | Use Case | Category | Subcategories | Playbooks | With Executions |
|---|---|---|---|---|---|
| 1 | Agentic SOC & Automated Alert Response | SOC | Agentic SOC, Case mgmt & SOAR | 61 | 20 |
| 2 | Alert Enrichment & IOC Lookup | SOC | Alert enrichment / IOC lookup | 43 | 1 |
| 3 | EDR Containment & Response | SOC | EDR containment & response | 3 | 0 |
| 4 | Identity Threat Response & User Containment | SOC / IAM | Identity threat response, Password & credential lifecycle | 31 | 4 |
| 5 | SIEM & Audit Log Ingestion | SOC | SIEM & log pipeline monitoring | 6 | 6 |
| 6 | Cloud Security & Network Posture | Cloud Security | CSPM ingest & triage, Cloud provisioning & IaC automation | 9 | 7 |
| 7 | IT Asset Management (ITAM) | Other | Endpoint hygiene & MDM ops, SaaS / IT administration | 8 | 7 |
| 8 | Endpoint & Device Management | Other | Endpoint hygiene & MDM ops | 8 | 0 |
| 9 | Vulnerability Management | Vulnerability Mgmt | Vuln scanning ingest & report | 1 | 0 |
| 10 | Security Operations Support & Tooling | Other | IT helpdesk & ticket routing, Financial & fraud operations | 4 | 0 |
| 11 | Vendor Risk & Security Review Automation | GRC | Vendor risk & TPRM | 3 | 3 |
| 12 | Threat Intelligence Digest Distribution | SOC | Threat intel ingest & curation | 1 | 1 |
| Total | 178 | 49 |
Use Cases
1. Agentic SOC & Automated Alert Response
Description: Fully automated security operations center pipeline — ingests alerts from Panther via webhook, extracts and deduplicates observables, orchestrates enrichment, routes to response playbooks based on alert type, and syncs closed cases back to the SIEM. Includes AI-assisted backlog analysis and daily ops metrics reporting.
Business Problem: Analyst capacity is the binding constraint in any SOC. This platform eliminates manual alert triage, deduplication, and initial enrichment — freeing analysts for high-judgment decisions while ensuring consistent handling of every alert at machine speed.
Category: SOC
Subcategories: Agentic SOC, Case mgmt & SOAR
Integrations: Panther, Microsoft Outlook, Slack, Jira, CrowdStrike, Gemini, Google Docs, Google Sheets, Blink Case Management
2. Alert Enrichment & IOC Lookup
Description: A comprehensive library of enrichment playbooks covering every major observable type — IPs, domains, hashes, URLs, usernames, and email addresses — queried across threat intel platforms and enterprise identity sources. All playbooks feed context back into the Blink case management platform via the Subflow - Update Enrichment Data pipeline.
Business Problem: Manual IOC lookup across 8+ tools is a time-consuming, error-prone step that slows analyst response. This library standardizes enrichment into reusable building blocks that run automatically when the Process Alert flow triggers observable extraction.
Category: SOC
Subcategories: Alert enrichment / IOC lookup
Integrations: VirusTotal, URLScan, AbuseIPDB, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Whois, Blink Case Management, Blink Tables
3. EDR Containment & Response
Description: On-demand playbooks to isolate compromised endpoints and execute remote response actions via CrowdStrike Real-Time Response (RTR) — targeting either a single host or a batch of devices simultaneously.
Business Problem: When a malware or intrusion alert fires, minutes matter. This suite enables analysts to quarantine a device or run forensic commands directly from the SOC workflow without switching tools or manually identifying the host.
Category: SOC
Subcategories: EDR containment & response
Integrations: CrowdStrike
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | 0 | On-demand |
| CrowdStrike RTR to a Single Host | 0 | On-demand |
| CrowdStrike RTR to a Batch of Hosts | 0 | On-demand |
4. Identity Threat Response & User Containment
Description: End-to-end orchestration for responding to compromised or risky user accounts. Includes human-in-the-loop Slack approval workflows that allow analysts to select containment actions (revoke sessions, lock device, reset password) across Okta, Google Workspace, Slack, Salesforce, and JAMF — all triggered from a single entry point. Also covers proactive insider threat monitoring, risky user sweeps, and admin user enrichment via Panther/Snowflake.
Business Problem: Containing a compromised account requires coordinated action across 5+ enterprise tools. Without automation, an analyst manually revokes sessions across each system sequentially, often taking 30+ minutes. This suite reduces mean time to contain (MTTC) to under two minutes while maintaining an auditable approval trail.
Category: SOC / IAM
Subcategories: Identity threat response, Password & credential lifecycle, Identity lifecycle automation
Integrations: Okta, Google Workspace, Google Admin Console, Slack, Salesforce, JAMF, Panther, Snowflake, Blink Tables
5. SIEM & Audit Log Ingestion
Description: Scheduled daily pipelines that pull audit logs from five security tooling sources and archive them to AWS S3, feeding a centralized data lake for correlation and compliance. Covers Terraform HCP, FireHydrant incident management, GitGuardian secrets detection, and the Blink platform itself, with AWS Glue pipeline health monitoring.
Business Problem: Maintaining continuous, tamper-evident audit trails across security tooling is required for compliance and forensic readiness. Manual log pulls are unreliable and error-prone. These pipelines ensure each source is archived daily without analyst involvement.
Category: SOC
Subcategories: SIEM & log pipeline monitoring
Integrations: Terraform HCP, FireHydrant, GitGuardian, Blink (audit logs), AWS S3, AWS Glue, Panther
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| Terraform Log Ingest | 40 | Scheduled (daily) |
| BlinkOps Audit Logs ingest | 40 | Scheduled (daily) |
| FireHydrant Log Ingest | 40 | Scheduled (daily) |
| GitGuardian Log Ingestion | 40 | Scheduled (daily) |
| Monitor AWS Glue Jobs | 40 | Scheduled (daily) |
| GitGuardian alerts to Panther | 3 | Event (webhook) |
6. Cloud Security & Network Posture
Description: Monitors Orca Security cloud posture notifications daily, tracks Zscaler device enrollment and CIDR ranges, and automates Terraform Cloud plan activation via webhook. Includes Zscaler-to-Snowflake data sync with Slack notification, device statistics calculation, and bulk user communication for Zscaler onboarding campaigns.
Business Problem: Cloud security posture and network access policy drift are hard to detect manually at scale. This suite surfaces Orca findings daily, keeps Zscaler device data synchronized with the data warehouse, and ensures Terraform-managed network changes activate automatically.
Category: Cloud Security
Subcategories: CSPM ingest & triage, Cloud provisioning & IaC automation, Cloud asset coverage & inventory
Integrations: Orca Security, Zscaler, AWS S3, Snowflake, Slack, JAMF, Terraform Cloud, Google Sheets, Salesforce
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| Orca - Check Notifications | 40 | Scheduled (daily) |
| Monitor Orca Usage | 40 | Scheduled (daily) |
| Zscaler - Snowflake Tables Sync + slack message | 40 | Scheduled (daily) |
| Automated Zscaler Follow Up | 3 | Scheduled (twice weekly) |
| Zscalertwo CIDR ranges sync | 6 | Scheduled (daily) |
| Salesforce CIDR ranges sync | 40 | Scheduled (daily) |
| Zscaler Terraform Activator | 0 | Event (webhook) |
| Zscaler Jamf Workflow | 0 | On-demand |
| Slack Bulk Message | 0 | On-demand |
7. IT Asset Management (ITAM)
Description: Automated asset inventory management pipeline that pulls data from CrowdStrike, JAMF, and Jira weekly to build a comprehensive user-device database, uploads it to S3, and keeps CrowdStrike device tags synchronized with ITAM classifications. Includes on-demand cross-system device status checks and GitHub username synchronization for identity correlation.
Business Problem: Asset inventory is foundational for vulnerability management, offboarding, and compliance — but manually aggregating it from multiple systems is a weekly burden. This suite keeps the ITAM database current without manual effort and allows on-demand lookups across all asset data sources in a single query.
Category: Other
Subcategories: Endpoint hygiene & MDM ops, SaaS / IT administration
Integrations: CrowdStrike, JAMF, Jira (via AWS Secrets Manager), Snowflake, AWS S3, Slack, GitHub, Google Admin Console, Blink Tables
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| Crowdstrike - Sync ITAM tags | 40 | Scheduled (daily) |
| Build ITAM Database | 6 | Scheduled (weekly) |
| ITAM S3 Upload | 6 | Scheduled (weekly) |
| New cscheck workflow - jamf, crowdstrike, itam, etc | 7 | On-demand |
| Github Usernames table sync | 1 | Scheduled (daily) |
| Find Devices with Broken MDM | 40 | Scheduled (daily) |
| Get devices not in MDM | 2 | Scheduled (weekly) |
| create comprehensive dashboard | 0 | On-demand |
8. Endpoint & Device Management
Description: A suite of device wipe and lock playbooks spanning JAMF, JumpCloud, and Microsoft Intune — executable by serial number or user email. Includes post-action verification to confirm wipe commands completed successfully, with results logged to Google Sheets for audit trail.
Business Problem: Lost or offboarded employee devices require rapid remote wipe to prevent data exfiltration. This suite provides a consistent, cross-MDM interface to initiate and verify device wipes without requiring direct MDM console access.
Category: Other
Subcategories: Endpoint hygiene & MDM ops
Integrations: JAMF, JumpCloud, Microsoft Intune, Google Sheets, Blink Tables
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| Jamf Wipe Device | 0 | On-demand |
| SERIAL - JAMF - Wipe User Computer | 0 | On-demand |
| JumpCloud - Wipe/Lock device by Serial Number | 0 | On-demand |
| Intune - Wipe Device | 0 | On-demand |
| Jamf - successful wipe check | 0 | On-demand |
| Get Jamf Devices in Certain Group | 0 | On-demand |
| WIP - JAMF - Wipe User Computer | 0 | On-demand |
| Crowdstrike Reboot Pending Macs | 0 | On-demand |
9. Vulnerability Management
Description: On-demand vulnerability report generation using CrowdStrike's vuln dataset, with results delivered directly to stakeholders via email.
Business Problem: Vulnerability status reports requested by engineering teams or leadership typically require manual CrowdStrike console navigation and export. This playbook automates the retrieval and delivery in a single step.
Category: Vulnerability Mgmt
Subcategories: Vuln scanning ingest & report
Integrations: CrowdStrike, Blink email
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| List Vulnerabilities with CrowdStrike and Send Results via Email | 0 | On-demand |
10. Security Operations Support & Tooling
Description: Miscellaneous operational tooling supporting the security team — including on-call pay calculation from FireHydrant schedule data, a self-service Okta group provisioning web form, and a GitHub username testing workflow.
Category: Other
Subcategories: IT helpdesk & ticket routing, Financial & fraud operations
Integrations: FireHydrant, Okta, Slack, Google Sheets, Blink Web Forms
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| On-Call Pay Calculator | 0 | On-demand |
| Web Form | 0 | Event (web form) |
| testing | 0 | On-demand |
| New Workflow | 0 | On-demand |
11. Vendor Risk & Security Review Automation
Description: Captures new procurement requests from Tropic (spend/vendor management platform) via webhook and drives them through a security review process — assigning Jira tasks to the security team and tracking review status to completion.
Business Problem: Every new vendor or procurement request requires a security review before purchase, but manually triaging each incoming request creates delays and inconsistent documentation. This automation intakes every request from Tropic and orchestrates the review through Jira, giving the security team a consistent, auditable process.
Category: GRC
Subcategories: Vendor risk & TPRM
Integrations: Tropic, Jira, Blink Tables, Google Drive
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| Tropic automation - automatically start - PROD | 261 | Event (webhook) |
| Tropic - Security Review Automation | 51 | On-demand |
| Tropic run Claude SDK flow | 44 | On-demand |
12. Threat Intelligence Digest Distribution
Description: Webhook-triggered pipeline that receives curated security/RSS content and posts it as a threaded digest message in Slack, keeping the security team informed of external threat intelligence and industry news without manual curation.
Business Problem: Staying current on emerging threats and industry security news requires manually checking multiple external feeds. This automation delivers a consolidated digest directly into the team's existing Slack workspace, removing the need for analysts to monitor sources individually.
Category: SOC
Subcategories: Threat intel ingest & curation
Integrations: Slack
| Playbook | Executions (12mo) | Automation Type |
|---|---|---|
| Slack Webhook for security digest | 28 | Event (webhook) |
Key Observations
Strengths
Mature end-to-end Agentic SOC. The Process Alert → Enrich → Respond pipeline is fully operational with 310 alerts processed, 381 enrichment routes fired, and 320 Expel closures synced — this is a production-grade, lights-out SOC workflow running at scale.
AI investigation agent is fully instrumented and running at scale. The Agentic SOC AI Investigation subflow completed 129 end-to-end investigations, backed by supporting agent abilities — 249 investigation guideline lookups, 193 VIP user checks, 149 org asset lookups, and 130 case-observable enrichment lookups — showing the AI agent is actively reasoning over case context during real investigations, not just running a fixed script.
Comprehensive enrichment coverage. 29 dedicated enrichment playbooks span 8+ threat intel and identity sources (VirusTotal, AbuseIPDB, URLScan, CrowdStrike, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack). The architecture correctly separates observable enrichment from case response routing, making the library reusable across alert types.
Robust data lake pipeline. Four security tooling sources (Terraform, FireHydrant, GitGuardian, Blink) feed daily into AWS S3 with consistent archiving patterns — 160 ingestion runs in 12 months. This indicates a mature log management strategy beyond just SIEM forwarding.
Strong ITAM foundation. The Build ITAM Database + CrowdStrike tag sync combination runs weekly and daily respectively, producing a continuously refreshed device inventory that underpins both the insider threat monitoring and the on-demand cscheck workflow.
Insider threat monitoring pipeline is active. Okta-based watchlist refreshes running 40 times in 12 months demonstrate a proactive approach to insider risk, not just reactive alerting.
Compromised user containment is architecture-complete. The full multi-tool containment suite (Okta, Google Workspace, Slack, Salesforce, JAMF) with Slack-based human approval is built and ready — a significant security capability that few organizations automate end-to-end.
Vendor risk intake is now automated end-to-end. The Tropic-triggered security review pipeline has processed 261 procurement requests and driven 51 review workflows to completion via Jira in its first period live — extending Blink's footprint from pure SOC/IAM into GRC vendor risk management.
Gaps & Opportunities
Enrichment subflows show 0 executions despite the enrichment router running 381 times. The individual enrichment playbooks (Enrich - IP - VT, Enrich - Hash - VT, etc.) all report 0 executions — worth validating that observable types are correctly mapped in the enrichment router and that playbook-level execution tracking is working as expected. If enrichments are running but not registering, this represents a reporting gap.
EDR containment is built but unused. CrowdStrike isolation and RTR playbooks have 0 executions. Given the active SOC pipeline, this likely means actual containment-triggering incidents haven't fired, or analysts are executing containment outside of Blink. Connecting these playbooks to the Response Subflow - Malware handler would close the loop.
Phishing response subflow has 0 executions. Despite the phishing response handler existing (including KnowBe4 campaign detection logic), it has never run. If phishing alerts are flowing through Panther, it's worth verifying the alert template mapping routes them correctly to this subflow.
Compromised user containment hasn't been exercised. The full containment suite (across two workspace variants) shows 0 executions. This is likely by design — these are break-glass workflows — but confirming the Slack approval flow works end-to-end via a tabletop exercise would de-risk the capability.
Vulnerability management coverage is minimal. With CrowdStrike vuln data available and a Snowflake connection in place, there's a clear opportunity to expand into automated vuln prioritization, Jira ticket creation, and SLA tracking — none of which exist today.
Multiple workspace variants for key workflows. Compromised User Containment, JAMF lock, and session revocation playbooks exist in 2-3 workspace copies each (workspaces 48453b3b, afa8215c, 178fdce3). Consolidating to a single production workspace would reduce maintenance overhead and ambiguity about which version is authoritative.
Integration Ecosystem
| Category | Integrations |
|---|---|
| SIEM / Threat Detection | Panther, Expel |
| Endpoint / EDR | CrowdStrike, JAMF, JumpCloud, Microsoft Intune |
| Threat Intel | VirusTotal, AbuseIPDB, URLScan |
| Identity & Access | Okta, Google Workspace, Google Admin Console, Microsoft Entra ID |
| Cloud Security | Orca Security |
| Network Security | Zscaler |
| Secrets Detection | GitGuardian |
| Collaboration & Comms | Slack, Microsoft Outlook |
| Productivity | Google Sheets, Google Docs, Google Drive |
| ITSM / Incident Mgmt | Jira, FireHydrant |
| Cloud Infrastructure | AWS (S3, Secrets Manager, Glue), Terraform Cloud/HCP |
| Data Warehouse | Snowflake |
| Code / DevOps | GitHub |
| Enterprise Apps | Salesforce |
| Procurement / Vendor Risk | Tropic |
| Platform Native | Blink Case Management, Blink Tables, Blink Web Forms, Blink Audit Logs |
E New Integrations (detail) 2 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| snyk | apikey-auth | gitguardian_logs | 2026-08-27 |
| snyk | okta | okta_dev_connection | 2026-08-11 |