Blink Security Automation — Confidential

sccic — Customer Success Report

Generated 2026-08-31 | sccic-value-report.md
2026-08-31Report Date
169Total Playbooks
79Unique Workflows (12m)
109,525Actions Automated (12m)
$28,170Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

169
Total playbooks built
all non-deleted workflows
113
Active playbooks
currently enabled
79
Unique workflows executed (12m)
distinct workflows that ran
109,525
Actions automated (12m)
completed action steps
608.5h
Hours saved (12m)
@ 20s per action
$28,170
Money saved (12m)
@ $100K avg salary
3
New active workflows (last 30d)
recently created & enabled
6
Total cases managed
5 opened in last 12m
54d 1h
MTTR — mean time to resolve
closed cases, last 12m
4
Active AI agents
of 9 total
1,664
AI agent tasks executed (12m)
180 in last 30d
In the last 12 months, Blink automated: - 217 ransomware extortion site scans, continuously monitoring for South Carolina victim organizations - 77 security assessment reports generated and delivered via Plextrac - 35 parked domains identified and added to continuous tracking - 23 validated command-and-control (C2) indicator lists pulled from Recorded Future and synced to the network EDL manager - 21 cyber service requests (M365 assessments, vulnerability scanning, AD audits, threat intelligence) automatically processed and routed to Cyber Liaison Officers - 18 phishing sites submitted for takedown - 15 ransomware victim alerts delivered to SC stakeholder organizations - 8 incident case reports with AI-generated timelines built automatically - 8 threat intelligence domain watchlists refreshed in Recorded Future - 5 phishing message traces analyzed for organizational impact and exposure - 4 leaked credential batches automatically parsed, structured, and prioritized

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Agentic SOC Platform
  • 8Incident case reports & AI timelines generated
  • 1Ransomware incident task workflows activated
0.7%
22
22 active
Alert Enrichment & IOC Investigation1 executions
0.0%
29
29 active
EDR Containment & Remote Response0 executions
0.0%
3
3 active
Phishing Detection & Response
  • 18Phishing sites submitted for takedown
  • 5Phishing message traces analyzed for impact
1.3%
3
3 active
Ransomware Intelligence & Victim Alerting
  • 217Ransomware extortion site scans completed
  • 15Ransomware victim alerts delivered to SC organizations
10.7%
3
3 active
Threat Intelligence & Attack Surface Monitoring
  • 35Parked domain tracking scans completed
  • 23Validated C2 indicator lists synced to EDL manager
  • 8Threat intelligence domain watchlists updated
14.9%
6
5 active
Assessment Services Coordination
  • 36CLO contact database synchronizations
  • 7Org list database synchronizations
  • 6M365 assessment requests processed & routed
4.7%
9
9 active
Security Assessment Report Generation
  • 73Security assessment reports generated
  • 4AD assessment reports created & delivered
0.0%
4
3 active
Credential Leak Intelligence
  • 4Leaked credential batches parsed & sorted
0.3%
1
1 active
Total751 executions100%
80
78 active

Use Case Growth Over Time

146 unique playbooks  |  9 operational use cases  |  2,305 total executions (12m)  |  2024-09 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Investigation
CrowdStrike URLScan VirusTotal AbuseIPDB Okta Google Workspace GitHub Microsoft Entra ID Slack Extraction Utilities String Utilities IPinfo
Agentic SOC Platform
Microsoft Outlook Email Agents
EDR Containment & Remote Response
CrowdStrike
Phishing Detection & Response
Agents Recorded Future Triage Cloud Email Microsoft Outlook
Security Assessment Report Generation
Recorded Future Jira Palo Alto Firewall Microsoft Outlook Web Form Email PlexTrac
Ransomware Intelligence & Victim Alerting
Agents Email
Assessment Services Coordination
SharePoint Microsoft Outlook Email Censys ASM
Threat Intelligence & Attack Surface Monitoring
Recorded Future Email

04Key Observations

✓  Strengths

Strengths

Deep SOAR investment with a purpose-built case management platform. SCCIC has built a fully custom, Blink-native case management system — complete with observable tracking, deduplication, enrichment routing, response subflows, and recovery automation. The platform architecture (22 interconnected playbooks) reflects a mature, production-grade SOAR deployment, not a collection of isolated scripts.

Multi-source enrichment depth. The enrichment library spans nine platforms — CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, and Slack. This breadth means that virtually every observable type encountered in an alert can be automatically enriched without analyst intervention.

Agentic SOC capabilities. Two AI agents are deployed in production: one for phishing email analysis and one (Truskey Jr) for generating case reports and timelines. The Build Case Report and Timeline playbook — already used 8 times — represents a genuine shift toward AI-assisted incident documentation, a leading-edge capability in government SOC environments.

Ransomware monitoring with real operational impact. The ransomware extortion monitoring pipeline (217 scans, 15 victim alerts delivered) is a high-value, continuous operation that would be impractical to replicate manually. Running every 4 hours around the clock, it ensures no South Carolina victim goes unreported.

Structured services delivery at scale. The assessment services coordination use case (M365, Vulnerability Scanning, AD Audit, Threat Intelligence) runs on scheduled cadences tied directly to SharePoint as the system of record. The daily CLO and org list database synchronizations (36 + 7 runs) ensure the entire downstream automation ecosystem stays accurate without human upkeep.

Plextrac report generation at scale. 77 assessment reports generated automatically across Plextrac represents significant analyst time saved on a typically high-effort task. With 73 executions on a single playbook, report generation is clearly a high-frequency operation.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

SOAR pipeline not yet running in production. The core Process Alert event playbook shows 0 executions, meaning the full alert-to-case automation pipeline has been built and tested (via the simulator playbooks) but has not yet processed live production alerts. Once activated, this platform has the potential to automate hundreds of alert triage cycles per month.

Enrichment playbooks at zero executions. All 28 enrichment playbooks show 0 executions — consistent with the SOAR pipeline not yet processing live alerts. As the alert pipeline comes online, enrichment volume will increase proportionally. The library is ready; the trigger is the missing piece.

EDR containment capabilities built but dormant. CrowdStrike endpoint isolation and RTR capabilities are built and integrated but have not been invoked. These are high-value response actions that could significantly reduce mean time to contain once the SOAR pipeline is live.

Phishing email analysis web form at zero executions. The web-form-based phishing submission workflow (workspace 7c9e1f21) is configured and ready but has not received any submissions. Analyst awareness and adoption may be a driver to address.

Duplicate playbooks suggest iterative development. Several playbooks exist in duplicate across workspaces (two Message Trace Analysis playbooks, two AD Assessment Reports variants, one copy). Consolidating these would reduce maintenance surface and ensure consistent execution.

CyberDefenders and Bad VPS Templates at zero. These scheduled playbooks are configured but show no execution history — they may be paused, awaiting data sources, or in early development.

Integration Ecosystem

Platform Role
CrowdStrike EDR — alert enrichment, endpoint containment, RTR, hash investigation
VirusTotal IOC enrichment — hashes, IPs, URLs
URLScan URL analysis and screenshot capture
AbuseIPDB IP reputation enrichment
Okta Identity enrichment, user activity lookup
Microsoft Entra ID Identity enrichment, risky user detection
Google Workspace Identity enrichment
Slack User lookup by email
GitHub User information lookup
Recorded Future Domain watchlist management, validated C2 indicator list sync to EDL manager
Shodan External attack surface / hostname intelligence
SharePoint (SLED SC) System of record for service requests and CLO data
Plextrac Security assessment report generation and delivery
ransomware.live Ransomware extortion victim monitoring
Censys ASM Asset inventory and attack surface seeding
Blink Case Management Native SOAR / case management platform
Blink AI Agents Email analysis, report and timeline generation
Appendices
A Case Management 5 cases (12m) | MTTR 54d 1h

Case Management

Total Cases (all-time)
6
5 opened in last 12m
Cases Opened (30d)
0
0 closed in last 30d
Cases Closed (12m)
2
of 5 opened
MTTR
54d 1h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Case Management Playground 6 5 2 54d 1h
B AI Agents 4 active | 1,664 tasks (12m)

AI Agents

Active Agents
4
of 9 total
Tasks Executed (12m)
1,664
180 in last 30d
Data Usage (12m)
138,688,472
12,656,919 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 South Carolina Finder rjcummings@sled.sc.gov 919 0 87,289,285
2 South Carolina Finder Shared Workspace 707 180 46,925,353
3 IP Attribution Agent Shared Workspace 30 0 3,825,456
4 Truskey Jr Case Management Playground 8 0 648,378
5 Agent Blink vincent.sheahan@blinkops.com 0 0 0
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
rjcummings@sled.sc.gov919
Shared Workspace737
Case Management Playground8
vincent.sheahan@blinkops.com0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
3
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Tom 00
2 email response 00
3 SLED Automation Pipeline Overview 00

Webforms

Forms
4
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Hello! 00
2 Suspicious Email submission form 00
3 Threat Intelligence Onboarding 00
4 Threat Intelligence Onboarding 00
D Full Use Case Analysis 9 use cases | 2,305 executions (12m)

Business KPIs

Metric Count Playbook
Ransomware extortion site scans completed 217 Ransomware Extortion site postings
Security assessment reports generated 73 New Workflow 1
CLO contact database synchronizations 36 CLO Database Updater
Parked domain tracking scans completed 35 Parked Domain Tracker
Validated C2 indicator lists synced to EDL manager 23 Recorded Future Pull Validated C2 List
Phishing sites submitted for takedown 18 Phishing Takedown
Ransomware victim alerts delivered to SC organizations 15 Ransomware Victim Alert email
Incident case reports & AI timelines generated 8 Build Case Report and Timeline
Threat intelligence domain watchlists updated 8 Recorded Future Domain Watchlist Updater
Org list database synchronizations 7 Org List Database Updater
M365 assessment requests processed & routed 6 365 Assessments
Parked domains added to tracking database 6 Add Parked Domain
Vulnerability scanning service requests coordinated 5 Vulnerability Scanning
AD audit service requests coordinated 5 AD Audit
Threat intelligence service requests coordinated 5 Threat Intelligence
Phishing message traces analyzed for impact 5 Message Trace Analysis
Leaked credential batches parsed & sorted 4 Leaked Credential Sorting
AD assessment reports created & delivered 4 AD Assessment Reports + Active Directory Assessment Reports
Ransomware incident task workflows activated 1 Add Tasks to Ransomware Incident
In the last 12 months, Blink automated: - 217 ransomware extortion site scans, continuously monitoring for South Carolina victim organizations - 77 security assessment reports generated and delivered via Plextrac - 35 parked domains identified and added to continuous tracking - 23 validated command-and-control (C2) indicator lists pulled from Recorded Future and synced to the network EDL manager - 21 cyber service requests (M365 assessments, vulnerability scanning, AD audits, threat intelligence) automatically processed and routed to Cyber Liaison Officers - 18 phishing sites submitted for takedown - 15 ransomware victim alerts delivered to SC stakeholder organizations - 8 incident case reports with AI-generated timelines built automatically - 8 threat intelligence domain watchlists refreshed in Recorded Future - 5 phishing message traces analyzed for organizational impact and exposure - 4 leaked credential batches automatically parsed, structured, and prioritized

Use Case Summary

Use Case Category Subcategory Playbooks
Agentic SOC Platform SOC Case mgmt & SOAR, Agentic SOC 22
Alert Enrichment & IOC Investigation SOC Alert enrichment / IOC lookup 29
EDR Containment & Remote Response SOC EDR containment & response 3
Phishing Detection & Response SOC Phishing detection & response 4
Ransomware Intelligence & Victim Alerting SOC Threat intel ingest & curation 3
Threat Intelligence & Attack Surface Monitoring SOC Threat intel ingest & curation, Threat hunting & detection 6
Assessment Services Coordination GRC Compliance questionnaire, Security metrics & reporting 11
Security Assessment Report Generation GRC Security metrics & reporting 5
Credential Leak Intelligence GRC DLP triage & exposure resp 1

Total playbooks: 84

Use Cases

1. Agentic SOC Platform

Category: SOC | Subcategories: Case mgmt & SOAR, Agentic SOC

Description: A fully automated SOC case management pipeline that ingests alerts from external tools (CrowdStrike, Proofpoint, Okta), deduplicates and enriches them, creates or appends to cases, triggers playbook-based response by alert type, and generates AI-assisted incident reports with full timelines. Includes recovery automation for unprocessed alerts and observable backfill.

Business problem solved: SOC analysts spend hours manually triaging, correlating, and documenting alerts. This platform automates alert-to-case lifecycle management end-to-end — from first ingest through enrichment, response routing, and post-incident reporting — compressing analyst time and accelerating mean time to respond.

Integrations: Blink Case Management, CrowdStrike, Microsoft Outlook, AI Agents (Truskey Jr | Build Reports and Timelines)

Playbooks:

Playbook Type Executions Link
Process Alert Event 0 ↗
Add Tasks to Ransomware Incident Event 1 ↗
Build Case Report and Timeline On-demand 8 ↗
Subflow - Response - Main Router Subflow 0 ↗
Response Subflow - Phishing Subflow 0 ↗
Response Subflow - Malware Subflow 0 ↗
Subflow - Missing Alert Template Notification Subflow 0 ↗
Subflow - Update Enrichment Data Subflow 0 ↗
Recovery - Handle Unprocessed Alerts On-demand 0 ↗
Recovery - Enrich Non-Enriched Observables On-demand 0 ↗
Utility - Close Stale Cases On-demand 0 ↗
Utility - Find Similar Cases Based on Observables On-demand 0 ↗
Utility - Set Or Update Observable Relation On-demand 0 ↗
Utility - Update Enrichment On-demand 0 ↗
Utility - List Observable Alert Relations On-demand 0 ↗
Utility - Delete Observable Relation On-demand 0 ↗
Utility - List Alert Observable Relations On-demand 0 ↗
Table Action - Validate Observables Extraction Template On-demand 0 ↗
Error Handling - Send Error Notification Email On-demand 0 ↗
Simulate Crowdstrike Alert On-demand 0 ↗
Simulate Multiple Alerts from Different Sources On-demand 0 ↗
USE WITH CARE - Reset Case Management Environment On-demand 0 ↗

2. Alert Enrichment & IOC Investigation

Category: SOC | Subcategories: Alert enrichment / IOC lookup

Description: A comprehensive, multi-source enrichment library that automatically investigates indicators of compromise — IPs, file hashes, URLs, domains, usernames, and email addresses — across nine integrated security platforms. The enrichment router dispatches each observable type to the appropriate tool and writes verdicts back into the case management system.

Business problem solved: Manual IOC lookups across multiple tools consume significant analyst time and introduce inconsistency. This library gives analysts instant, structured enrichment on every observable — automatically, at scale, during every alert triage cycle.

Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Whois, IPInfo

Playbooks:

Playbook Type Executions Link
Subflow - Enrich Observables - Main Router Subflow 0 ↗
Enrich - Agent ID - Crowdstrike On-demand 0 ↗
Enrich - URL - URLScan On-demand 0 ↗
Enrich - URL - VT On-demand 0 ↗
Enrich - Hash - VT On-demand 0 ↗
Enrich - Hash - Crowdstrike On-demand 0 ↗
Enrich - IP - IPDB On-demand 0 ↗
Enrich - IP - VT On-demand 0 ↗
Enrich - IP or Domain - Whois On-demand 0 ↗
Enrich - Username or Email - Okta On-demand 0 ↗
Enrich - Username or Email - Google Workspace On-demand 0 ↗
Enrich - Username or Email - Microsoft Entra ID On-demand 0 ↗
Enrich - Email Address - Slack On-demand 0 ↗
Enrich - Username - Github On-demand 0 ↗
Enrich IP or Domain Using Whois On-demand 0 ↗
Get User Information Using Google Workspace On-demand 0 ↗
Get User Information Using Github On-demand 0 ↗
Get User Information Using Microsoft Entra ID On-demand 0 ↗
Get User Information Using Okta On-demand 0 ↗
Get User Information on Email Address Using Slack On-demand 0 ↗
Get Hash Info Using Crowdstrike On-demand 0 ↗
Get Hash Info Using VirusTotal On-demand 0 ↗
IP rep lookup On-demand 0 ↗
Okta Search for User Activity On-demand 0 ↗
Secure URL Screenshot Capture On-demand 0 ↗
Analyze URL with URLScan On-demand 0 ↗
Run Dig Command On-demand 0 ↗
Get End of Life Date for a Product On-demand 0 ↗
GTI/VT Enterprise On-demand 0 ↗

3. EDR Containment & Remote Response

Category: SOC | Subcategories: EDR containment & response

Description: Enables analysts to isolate compromised endpoints and execute remote commands via CrowdStrike's Real-Time Response (RTR) capability — both on individual hosts and in bulk across a fleet. Designed to be invoked as part of the malware response subflow or manually during active incident response.

Business problem solved: Containing a compromised host requires coordinating multiple manual steps across tools. These playbooks make containment a single-click operation from within the SOAR platform, reducing time-to-containment from minutes to seconds.

Integrations: CrowdStrike

Playbooks:

Playbook Type Executions Link
Manage Endpoint Quarantine Status in Crowdstrike On-demand 0 ↗
CrowdStrike RTR to a Single Host On-demand 0 ↗
CrowdStrike RTR to a Batch of Hosts On-demand 0 ↗

4. Phishing Detection & Response

Category: SOC | Subcategories: Phishing detection & response

Description: End-to-end phishing handling — from analyst-submitted email analysis through a web form, to message trace investigation for downstream recipient exposure, to formal phishing takedown submission. Includes an AI agent for parsing email content and extracting observables.

Business problem solved: Phishing incidents require analysts to manually parse emails, identify affected recipients, trace message delivery, and coordinate takedown requests. This use case automates each step — from first submission through stakeholder notification and site takedown — reducing analyst work and accelerating remediation.

Integrations: Microsoft Outlook, AI Agents (email agent), Blink Web Forms

Playbooks:

Playbook Type Executions Link
Phishing email analysis Event (Web Form) 0 ↗
Message Trace Analysis On-demand 5 ↗
Message Trace Analysis (copy) On-demand 0 ↗
Phishing Takedown On-demand 18 ↗

5. Ransomware Intelligence & Victim Alerting

Category: SOC | Subcategories: Threat intel ingest & curation

Description: Automated monitoring of public ransomware extortion leak sites (via ransomware.live) on a 4-hour cadence. An AI agent scans victim lists for South Carolina organizations and triggers automated email alerts to SCCIC stakeholders when SC victims are identified. Complements this with VPS threat actor infrastructure tracking.

Business problem solved: Manually monitoring ransomware extortion sites for relevant victims is time-consuming and unreliable. This use case ensures no SC victim posting goes undetected — 24/7, without analyst involvement — and delivers structured, actionable alerts automatically.

Integrations: ransomware.live API, AI Agents (South Carolina Finder), Blink Tables, Email

Playbooks:

Playbook Type Executions Link
Ransomware Extortion site postings Scheduled (every 4h) 217 ↗
Ransomware Victim Alert email Event (new table record) 15 ↗
Bad VPS Templates Scheduled 0 ↗

6. Threat Intelligence & Attack Surface Monitoring

Category: SOC | Subcategories: Threat intel ingest & curation, Threat hunting & detection

Description: Proactive threat intelligence operations: keeping Recorded Future domain watchlists in sync with the live Cyber Liaison Officer (CLO) database, querying Shodan for IPs associated with known-bad hostnames, checking IP reputation via AbuseIPDB, pulling and validating Recorded Future's C2 server list to feed the EDL manager, and tracking parked domains for ongoing monitoring. Ensures threat intelligence tooling reflects the current SC government organizational footprint.

Business problem solved: Threat intelligence is only as useful as its coverage — if monitored domains fall out of sync with the actual organizational roster, alerts are missed. This use case automates the maintenance of watchlists and performs continuous external exposure scanning.

Integrations: Recorded Future, Shodan, AbuseIPDB, Blink Tables, HTTP/EDL Manager

Playbooks:

Playbook Type Executions Link
Recorded Future Domain Watchlist Updater Scheduled (daily) 8 ↗
Shodan Bad Hostnames Query On-demand 0 ↗
SCCIC IP Abuse Checker Scheduled 0 ↗
Recorded Future Pull Validated C2 List Scheduled (daily) 23 ↗
Parked Domain Tracker Scheduled (daily) 35 ↗
Add Parked Domain On-demand 6 ↗

7. Assessment Services Coordination

Category: GRC | Subcategories: Compliance questionnaire, Security metrics & reporting

Description: Automates the intake, routing, and follow-up lifecycle for SCCIC's portfolio of cyber services offered to South Carolina government organizations — including M365 Assessments, Vulnerability Scanning, Active Directory Audits, Threat Intelligence services, and CyberDefenders training. Pulls service requests from SharePoint, identifies the relevant Cyber Liaison Officer (CLO) contacts, sends notifications, and updates records automatically. Maintains synchronized CLO and organization databases from SharePoint as the system of record.

Business problem solved: Managing dozens of service requests across multiple government agencies requires constant manual tracking, email coordination, and record-keeping. This use case automates the full request-to-notification workflow — ensuring no service requests fall through the cracks and CLO databases remain current without manual effort.

Integrations: SharePoint (SLED), Blink Tables, Email

Playbooks:

Playbook Type Executions Link
365 Assessments Scheduled (weekly, Thu) 6 ↗
Vulnerability Scanning Scheduled (weekly, Wed) 5 ↗
AD Audit Scheduled (weekly, Tue) 5 ↗
Threat Intelligence Scheduled (weekly, Mon) 5 ↗
CyberDefenders Scheduled 0 ↗
CLO Database Updater Scheduled (daily) 36 ↗
Org List Database Updater Scheduled (daily) 7 ↗
Censys Inventory Adder On-demand 0 ↗
Upload File Contents to Blink Table On-demand 0 ↗
Censys Saved Queries On-demand 0 ↗
Alert Katie when Organization is Unresponsive On-demand 0 ↗

8. Security Assessment Report Generation

Category: GRC | Subcategories: Security metrics & reporting

Description: Automates the generation and delivery of structured security assessment reports in Plextrac — SCCIC's reporting platform. Given a client name, findings list, and report date, the automation locates the client in Plextrac, creates a new report, populates it with relevant writeups from the library, and emails the completed report to the recipient. Supports Active Directory assessments and general security assessments.

Business problem solved: Producing formatted assessment reports in a client-facing platform is time-intensive and error-prone when done manually. These playbooks allow SCCIC analysts to generate professional, consistent Plextrac reports with a single trigger — dramatically accelerating report delivery to SC government agencies.

Integrations: Plextrac, Email

Playbooks:

Playbook Type Executions Link
New Workflow 1 On-demand 73 ↗
AD Assessment Reports On-demand 2 ↗
Active Directory Assessment Reports On-demand 2 ↗
AD Assessment Reports copy On-demand 0 ↗
New Workflow (draft) On-demand 0 ↗

9. Credential Leak Intelligence

Category: GRC | Subcategories: DLP triage & exposure resp

Description: Parses and structures raw leaked credential data — including unstructured or semi-structured credential dumps — extracting, deduplicating, and sorting the credentials into a normalized format for analyst review and downstream response.

Business problem solved: Leaked credential dumps arrive in inconsistent, often raw formats that are difficult to act on without preprocessing. This playbook turns raw leak data into a structured, actionable list — accelerating the analyst's ability to identify affected accounts and initiate password resets or account lockdowns.

Integrations: Python processing

Playbooks:

Playbook Type Executions Link
Leaked Credential Sorting On-demand 4 ↗

Key Observations

Strengths

Deep SOAR investment with a purpose-built case management platform. SCCIC has built a fully custom, Blink-native case management system — complete with observable tracking, deduplication, enrichment routing, response subflows, and recovery automation. The platform architecture (22 interconnected playbooks) reflects a mature, production-grade SOAR deployment, not a collection of isolated scripts.

Multi-source enrichment depth. The enrichment library spans nine platforms — CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, and Slack. This breadth means that virtually every observable type encountered in an alert can be automatically enriched without analyst intervention.

Agentic SOC capabilities. Two AI agents are deployed in production: one for phishing email analysis and one (Truskey Jr) for generating case reports and timelines. The Build Case Report and Timeline playbook — already used 8 times — represents a genuine shift toward AI-assisted incident documentation, a leading-edge capability in government SOC environments.

Ransomware monitoring with real operational impact. The ransomware extortion monitoring pipeline (217 scans, 15 victim alerts delivered) is a high-value, continuous operation that would be impractical to replicate manually. Running every 4 hours around the clock, it ensures no South Carolina victim goes unreported.

Structured services delivery at scale. The assessment services coordination use case (M365, Vulnerability Scanning, AD Audit, Threat Intelligence) runs on scheduled cadences tied directly to SharePoint as the system of record. The daily CLO and org list database synchronizations (36 + 7 runs) ensure the entire downstream automation ecosystem stays accurate without human upkeep.

Plextrac report generation at scale. 77 assessment reports generated automatically across Plextrac represents significant analyst time saved on a typically high-effort task. With 73 executions on a single playbook, report generation is clearly a high-frequency operation.

Gaps & Opportunities

SOAR pipeline not yet running in production. The core Process Alert event playbook shows 0 executions, meaning the full alert-to-case automation pipeline has been built and tested (via the simulator playbooks) but has not yet processed live production alerts. Once activated, this platform has the potential to automate hundreds of alert triage cycles per month.

Enrichment playbooks at zero executions. All 28 enrichment playbooks show 0 executions — consistent with the SOAR pipeline not yet processing live alerts. As the alert pipeline comes online, enrichment volume will increase proportionally. The library is ready; the trigger is the missing piece.

EDR containment capabilities built but dormant. CrowdStrike endpoint isolation and RTR capabilities are built and integrated but have not been invoked. These are high-value response actions that could significantly reduce mean time to contain once the SOAR pipeline is live.

Phishing email analysis web form at zero executions. The web-form-based phishing submission workflow (workspace 7c9e1f21) is configured and ready but has not received any submissions. Analyst awareness and adoption may be a driver to address.

Duplicate playbooks suggest iterative development. Several playbooks exist in duplicate across workspaces (two Message Trace Analysis playbooks, two AD Assessment Reports variants, one copy). Consolidating these would reduce maintenance surface and ensure consistent execution.

CyberDefenders and Bad VPS Templates at zero. These scheduled playbooks are configured but show no execution history — they may be paused, awaiting data sources, or in early development.

Integration Ecosystem

Platform Role
CrowdStrike EDR — alert enrichment, endpoint containment, RTR, hash investigation
VirusTotal IOC enrichment — hashes, IPs, URLs
URLScan URL analysis and screenshot capture
AbuseIPDB IP reputation enrichment
Okta Identity enrichment, user activity lookup
Microsoft Entra ID Identity enrichment, risky user detection
Google Workspace Identity enrichment
Slack User lookup by email
GitHub User information lookup
Recorded Future Domain watchlist management, validated C2 indicator list sync to EDL manager
Shodan External attack surface / hostname intelligence
SharePoint (SLED SC) System of record for service requests and CLO data
Plextrac Security assessment report generation and delivery
ransomware.live Ransomware extortion victim monitoring
Censys ASM Asset inventory and attack surface seeding
Blink Case Management Native SOAR / case management platform
Blink AI Agents Email analysis, report and timeline generation
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
sccic apikey-auth google_threat_intelligence_vt_enterprise 2026-08-25