01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Agentic SOC Platform |
| 0.7% | 22 22 active |
| Alert Enrichment & IOC Investigation | 1 executions | 0.0% | 29 29 active |
| EDR Containment & Remote Response | 0 executions | 0.0% | 3 3 active |
| Phishing Detection & Response |
| 1.3% | 3 3 active |
| Ransomware Intelligence & Victim Alerting |
| 10.7% | 3 3 active |
| Threat Intelligence & Attack Surface Monitoring |
| 14.9% | 6 5 active |
| Assessment Services Coordination |
| 4.7% | 9 9 active |
| Security Assessment Report Generation |
| 0.0% | 4 3 active |
| Credential Leak Intelligence |
| 0.3% | 1 1 active |
| Total | 751 executions | 100% | 80 78 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Deep SOAR investment with a purpose-built case management platform. SCCIC has built a fully custom, Blink-native case management system — complete with observable tracking, deduplication, enrichment routing, response subflows, and recovery automation. The platform architecture (22 interconnected playbooks) reflects a mature, production-grade SOAR deployment, not a collection of isolated scripts.
Multi-source enrichment depth. The enrichment library spans nine platforms — CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, and Slack. This breadth means that virtually every observable type encountered in an alert can be automatically enriched without analyst intervention.
Agentic SOC capabilities. Two AI agents are deployed in production: one for phishing email analysis and one (Truskey Jr) for generating case reports and timelines. The Build Case Report and Timeline playbook — already used 8 times — represents a genuine shift toward AI-assisted incident documentation, a leading-edge capability in government SOC environments.
Ransomware monitoring with real operational impact. The ransomware extortion monitoring pipeline (217 scans, 15 victim alerts delivered) is a high-value, continuous operation that would be impractical to replicate manually. Running every 4 hours around the clock, it ensures no South Carolina victim goes unreported.
Structured services delivery at scale. The assessment services coordination use case (M365, Vulnerability Scanning, AD Audit, Threat Intelligence) runs on scheduled cadences tied directly to SharePoint as the system of record. The daily CLO and org list database synchronizations (36 + 7 runs) ensure the entire downstream automation ecosystem stays accurate without human upkeep.
Plextrac report generation at scale. 77 assessment reports generated automatically across Plextrac represents significant analyst time saved on a typically high-effort task. With 73 executions on a single playbook, report generation is clearly a high-frequency operation.
###
Gaps & Opportunities
SOAR pipeline not yet running in production. The core Process Alert event playbook shows 0 executions, meaning the full alert-to-case automation pipeline has been built and tested (via the simulator playbooks) but has not yet processed live production alerts. Once activated, this platform has the potential to automate hundreds of alert triage cycles per month.
Enrichment playbooks at zero executions. All 28 enrichment playbooks show 0 executions — consistent with the SOAR pipeline not yet processing live alerts. As the alert pipeline comes online, enrichment volume will increase proportionally. The library is ready; the trigger is the missing piece.
EDR containment capabilities built but dormant. CrowdStrike endpoint isolation and RTR capabilities are built and integrated but have not been invoked. These are high-value response actions that could significantly reduce mean time to contain once the SOAR pipeline is live.
Phishing email analysis web form at zero executions. The web-form-based phishing submission workflow (workspace 7c9e1f21) is configured and ready but has not received any submissions. Analyst awareness and adoption may be a driver to address.
Duplicate playbooks suggest iterative development. Several playbooks exist in duplicate across workspaces (two Message Trace Analysis playbooks, two AD Assessment Reports variants, one copy). Consolidating these would reduce maintenance surface and ensure consistent execution.
CyberDefenders and Bad VPS Templates at zero. These scheduled playbooks are configured but show no execution history — they may be paused, awaiting data sources, or in early development.
Integration Ecosystem
| Platform | Role |
|---|---|
| CrowdStrike | EDR — alert enrichment, endpoint containment, RTR, hash investigation |
| VirusTotal | IOC enrichment — hashes, IPs, URLs |
| URLScan | URL analysis and screenshot capture |
| AbuseIPDB | IP reputation enrichment |
| Okta | Identity enrichment, user activity lookup |
| Microsoft Entra ID | Identity enrichment, risky user detection |
| Google Workspace | Identity enrichment |
| Slack | User lookup by email |
| GitHub | User information lookup |
| Recorded Future | Domain watchlist management, validated C2 indicator list sync to EDL manager |
| Shodan | External attack surface / hostname intelligence |
| SharePoint (SLED SC) | System of record for service requests and CLO data |
| Plextrac | Security assessment report generation and delivery |
| ransomware.live | Ransomware extortion victim monitoring |
| Censys ASM | Asset inventory and attack surface seeding |
| Blink Case Management | Native SOAR / case management platform |
| Blink AI Agents | Email analysis, report and timeline generation |
A Case Management 5 cases (12m) | MTTR 54d 1h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Case Management Playground | 6 | 5 | 2 | 54d 1h |
B AI Agents 4 active | 1,664 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | South Carolina Finder | rjcummings@sled.sc.gov | 919 | 0 | 87,289,285 |
| 2 | South Carolina Finder | Shared Workspace | 707 | 180 | 46,925,353 |
| 3 | IP Attribution Agent | Shared Workspace | 30 | 0 | 3,825,456 |
| 4 | Truskey Jr | Case Management Playground | 8 | 0 | 648,378 |
| 5 | Agent Blink | vincent.sheahan@blinkops.com | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| rjcummings@sled.sc.gov | 919 |
| Shared Workspace | 737 |
| Case Management Playground | 8 |
| vincent.sheahan@blinkops.com | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Tom | 0 | 0 |
| 2 | email response | 0 | 0 |
| 3 | SLED Automation Pipeline Overview | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Hello! | 0 | 0 |
| 2 | Suspicious Email submission form | 0 | 0 |
| 3 | Threat Intelligence Onboarding | 0 | 0 |
| 4 | Threat Intelligence Onboarding | 0 | 0 |
D Full Use Case Analysis 9 use cases | 2,305 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Ransomware extortion site scans completed | 217 | Ransomware Extortion site postings |
| Security assessment reports generated | 73 | New Workflow 1 |
| CLO contact database synchronizations | 36 | CLO Database Updater |
| Parked domain tracking scans completed | 35 | Parked Domain Tracker |
| Validated C2 indicator lists synced to EDL manager | 23 | Recorded Future Pull Validated C2 List |
| Phishing sites submitted for takedown | 18 | Phishing Takedown |
| Ransomware victim alerts delivered to SC organizations | 15 | Ransomware Victim Alert email |
| Incident case reports & AI timelines generated | 8 | Build Case Report and Timeline |
| Threat intelligence domain watchlists updated | 8 | Recorded Future Domain Watchlist Updater |
| Org list database synchronizations | 7 | Org List Database Updater |
| M365 assessment requests processed & routed | 6 | 365 Assessments |
| Parked domains added to tracking database | 6 | Add Parked Domain |
| Vulnerability scanning service requests coordinated | 5 | Vulnerability Scanning |
| AD audit service requests coordinated | 5 | AD Audit |
| Threat intelligence service requests coordinated | 5 | Threat Intelligence |
| Phishing message traces analyzed for impact | 5 | Message Trace Analysis |
| Leaked credential batches parsed & sorted | 4 | Leaked Credential Sorting |
| AD assessment reports created & delivered | 4 | AD Assessment Reports + Active Directory Assessment Reports |
| Ransomware incident task workflows activated | 1 | Add Tasks to Ransomware Incident |
Use Case Summary
| Use Case | Category | Subcategory | Playbooks |
|---|---|---|---|
| Agentic SOC Platform | SOC | Case mgmt & SOAR, Agentic SOC | 22 |
| Alert Enrichment & IOC Investigation | SOC | Alert enrichment / IOC lookup | 29 |
| EDR Containment & Remote Response | SOC | EDR containment & response | 3 |
| Phishing Detection & Response | SOC | Phishing detection & response | 4 |
| Ransomware Intelligence & Victim Alerting | SOC | Threat intel ingest & curation | 3 |
| Threat Intelligence & Attack Surface Monitoring | SOC | Threat intel ingest & curation, Threat hunting & detection | 6 |
| Assessment Services Coordination | GRC | Compliance questionnaire, Security metrics & reporting | 11 |
| Security Assessment Report Generation | GRC | Security metrics & reporting | 5 |
| Credential Leak Intelligence | GRC | DLP triage & exposure resp | 1 |
Total playbooks: 84
Use Cases
1. Agentic SOC Platform
Category: SOC | Subcategories: Case mgmt & SOAR, Agentic SOC
Description: A fully automated SOC case management pipeline that ingests alerts from external tools (CrowdStrike, Proofpoint, Okta), deduplicates and enriches them, creates or appends to cases, triggers playbook-based response by alert type, and generates AI-assisted incident reports with full timelines. Includes recovery automation for unprocessed alerts and observable backfill.
Business problem solved: SOC analysts spend hours manually triaging, correlating, and documenting alerts. This platform automates alert-to-case lifecycle management end-to-end — from first ingest through enrichment, response routing, and post-incident reporting — compressing analyst time and accelerating mean time to respond.
Integrations: Blink Case Management, CrowdStrike, Microsoft Outlook, AI Agents (Truskey Jr | Build Reports and Timelines)
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| Process Alert | Event | 0 | ↗ |
| Add Tasks to Ransomware Incident | Event | 1 | ↗ |
| Build Case Report and Timeline | On-demand | 8 | ↗ |
| Subflow - Response - Main Router | Subflow | 0 | ↗ |
| Response Subflow - Phishing | Subflow | 0 | ↗ |
| Response Subflow - Malware | Subflow | 0 | ↗ |
| Subflow - Missing Alert Template Notification | Subflow | 0 | ↗ |
| Subflow - Update Enrichment Data | Subflow | 0 | ↗ |
| Recovery - Handle Unprocessed Alerts | On-demand | 0 | ↗ |
| Recovery - Enrich Non-Enriched Observables | On-demand | 0 | ↗ |
| Utility - Close Stale Cases | On-demand | 0 | ↗ |
| Utility - Find Similar Cases Based on Observables | On-demand | 0 | ↗ |
| Utility - Set Or Update Observable Relation | On-demand | 0 | ↗ |
| Utility - Update Enrichment | On-demand | 0 | ↗ |
| Utility - List Observable Alert Relations | On-demand | 0 | ↗ |
| Utility - Delete Observable Relation | On-demand | 0 | ↗ |
| Utility - List Alert Observable Relations | On-demand | 0 | ↗ |
| Table Action - Validate Observables Extraction Template | On-demand | 0 | ↗ |
| Error Handling - Send Error Notification Email | On-demand | 0 | ↗ |
| Simulate Crowdstrike Alert | On-demand | 0 | ↗ |
| Simulate Multiple Alerts from Different Sources | On-demand | 0 | ↗ |
| USE WITH CARE - Reset Case Management Environment | On-demand | 0 | ↗ |
2. Alert Enrichment & IOC Investigation
Category: SOC | Subcategories: Alert enrichment / IOC lookup
Description: A comprehensive, multi-source enrichment library that automatically investigates indicators of compromise — IPs, file hashes, URLs, domains, usernames, and email addresses — across nine integrated security platforms. The enrichment router dispatches each observable type to the appropriate tool and writes verdicts back into the case management system.
Business problem solved: Manual IOC lookups across multiple tools consume significant analyst time and introduce inconsistency. This library gives analysts instant, structured enrichment on every observable — automatically, at scale, during every alert triage cycle.
Integrations: CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Google Workspace, Microsoft Entra ID, GitHub, Slack, Whois, IPInfo
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| Subflow - Enrich Observables - Main Router | Subflow | 0 | ↗ |
| Enrich - Agent ID - Crowdstrike | On-demand | 0 | ↗ |
| Enrich - URL - URLScan | On-demand | 0 | ↗ |
| Enrich - URL - VT | On-demand | 0 | ↗ |
| Enrich - Hash - VT | On-demand | 0 | ↗ |
| Enrich - Hash - Crowdstrike | On-demand | 0 | ↗ |
| Enrich - IP - IPDB | On-demand | 0 | ↗ |
| Enrich - IP - VT | On-demand | 0 | ↗ |
| Enrich - IP or Domain - Whois | On-demand | 0 | ↗ |
| Enrich - Username or Email - Okta | On-demand | 0 | ↗ |
| Enrich - Username or Email - Google Workspace | On-demand | 0 | ↗ |
| Enrich - Username or Email - Microsoft Entra ID | On-demand | 0 | ↗ |
| Enrich - Email Address - Slack | On-demand | 0 | ↗ |
| Enrich - Username - Github | On-demand | 0 | ↗ |
| Enrich IP or Domain Using Whois | On-demand | 0 | ↗ |
| Get User Information Using Google Workspace | On-demand | 0 | ↗ |
| Get User Information Using Github | On-demand | 0 | ↗ |
| Get User Information Using Microsoft Entra ID | On-demand | 0 | ↗ |
| Get User Information Using Okta | On-demand | 0 | ↗ |
| Get User Information on Email Address Using Slack | On-demand | 0 | ↗ |
| Get Hash Info Using Crowdstrike | On-demand | 0 | ↗ |
| Get Hash Info Using VirusTotal | On-demand | 0 | ↗ |
| IP rep lookup | On-demand | 0 | ↗ |
| Okta Search for User Activity | On-demand | 0 | ↗ |
| Secure URL Screenshot Capture | On-demand | 0 | ↗ |
| Analyze URL with URLScan | On-demand | 0 | ↗ |
| Run Dig Command | On-demand | 0 | ↗ |
| Get End of Life Date for a Product | On-demand | 0 | ↗ |
| GTI/VT Enterprise | On-demand | 0 | ↗ |
3. EDR Containment & Remote Response
Category: SOC | Subcategories: EDR containment & response
Description: Enables analysts to isolate compromised endpoints and execute remote commands via CrowdStrike's Real-Time Response (RTR) capability — both on individual hosts and in bulk across a fleet. Designed to be invoked as part of the malware response subflow or manually during active incident response.
Business problem solved: Containing a compromised host requires coordinating multiple manual steps across tools. These playbooks make containment a single-click operation from within the SOAR platform, reducing time-to-containment from minutes to seconds.
Integrations: CrowdStrike
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| Manage Endpoint Quarantine Status in Crowdstrike | On-demand | 0 | ↗ |
| CrowdStrike RTR to a Single Host | On-demand | 0 | ↗ |
| CrowdStrike RTR to a Batch of Hosts | On-demand | 0 | ↗ |
4. Phishing Detection & Response
Category: SOC | Subcategories: Phishing detection & response
Description: End-to-end phishing handling — from analyst-submitted email analysis through a web form, to message trace investigation for downstream recipient exposure, to formal phishing takedown submission. Includes an AI agent for parsing email content and extracting observables.
Business problem solved: Phishing incidents require analysts to manually parse emails, identify affected recipients, trace message delivery, and coordinate takedown requests. This use case automates each step — from first submission through stakeholder notification and site takedown — reducing analyst work and accelerating remediation.
Integrations: Microsoft Outlook, AI Agents (email agent), Blink Web Forms
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| Phishing email analysis | Event (Web Form) | 0 | ↗ |
| Message Trace Analysis | On-demand | 5 | ↗ |
| Message Trace Analysis (copy) | On-demand | 0 | ↗ |
| Phishing Takedown | On-demand | 18 | ↗ |
5. Ransomware Intelligence & Victim Alerting
Category: SOC | Subcategories: Threat intel ingest & curation
Description: Automated monitoring of public ransomware extortion leak sites (via ransomware.live) on a 4-hour cadence. An AI agent scans victim lists for South Carolina organizations and triggers automated email alerts to SCCIC stakeholders when SC victims are identified. Complements this with VPS threat actor infrastructure tracking.
Business problem solved: Manually monitoring ransomware extortion sites for relevant victims is time-consuming and unreliable. This use case ensures no SC victim posting goes undetected — 24/7, without analyst involvement — and delivers structured, actionable alerts automatically.
Integrations: ransomware.live API, AI Agents (South Carolina Finder), Blink Tables, Email
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| Ransomware Extortion site postings | Scheduled (every 4h) | 217 | ↗ |
| Ransomware Victim Alert email | Event (new table record) | 15 | ↗ |
| Bad VPS Templates | Scheduled | 0 | ↗ |
6. Threat Intelligence & Attack Surface Monitoring
Category: SOC | Subcategories: Threat intel ingest & curation, Threat hunting & detection
Description: Proactive threat intelligence operations: keeping Recorded Future domain watchlists in sync with the live Cyber Liaison Officer (CLO) database, querying Shodan for IPs associated with known-bad hostnames, checking IP reputation via AbuseIPDB, pulling and validating Recorded Future's C2 server list to feed the EDL manager, and tracking parked domains for ongoing monitoring. Ensures threat intelligence tooling reflects the current SC government organizational footprint.
Business problem solved: Threat intelligence is only as useful as its coverage — if monitored domains fall out of sync with the actual organizational roster, alerts are missed. This use case automates the maintenance of watchlists and performs continuous external exposure scanning.
Integrations: Recorded Future, Shodan, AbuseIPDB, Blink Tables, HTTP/EDL Manager
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| Recorded Future Domain Watchlist Updater | Scheduled (daily) | 8 | ↗ |
| Shodan Bad Hostnames Query | On-demand | 0 | ↗ |
| SCCIC IP Abuse Checker | Scheduled | 0 | ↗ |
| Recorded Future Pull Validated C2 List | Scheduled (daily) | 23 | ↗ |
| Parked Domain Tracker | Scheduled (daily) | 35 | ↗ |
| Add Parked Domain | On-demand | 6 | ↗ |
7. Assessment Services Coordination
Category: GRC | Subcategories: Compliance questionnaire, Security metrics & reporting
Description: Automates the intake, routing, and follow-up lifecycle for SCCIC's portfolio of cyber services offered to South Carolina government organizations — including M365 Assessments, Vulnerability Scanning, Active Directory Audits, Threat Intelligence services, and CyberDefenders training. Pulls service requests from SharePoint, identifies the relevant Cyber Liaison Officer (CLO) contacts, sends notifications, and updates records automatically. Maintains synchronized CLO and organization databases from SharePoint as the system of record.
Business problem solved: Managing dozens of service requests across multiple government agencies requires constant manual tracking, email coordination, and record-keeping. This use case automates the full request-to-notification workflow — ensuring no service requests fall through the cracks and CLO databases remain current without manual effort.
Integrations: SharePoint (SLED), Blink Tables, Email
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| 365 Assessments | Scheduled (weekly, Thu) | 6 | ↗ |
| Vulnerability Scanning | Scheduled (weekly, Wed) | 5 | ↗ |
| AD Audit | Scheduled (weekly, Tue) | 5 | ↗ |
| Threat Intelligence | Scheduled (weekly, Mon) | 5 | ↗ |
| CyberDefenders | Scheduled | 0 | ↗ |
| CLO Database Updater | Scheduled (daily) | 36 | ↗ |
| Org List Database Updater | Scheduled (daily) | 7 | ↗ |
| Censys Inventory Adder | On-demand | 0 | ↗ |
| Upload File Contents to Blink Table | On-demand | 0 | ↗ |
| Censys Saved Queries | On-demand | 0 | ↗ |
| Alert Katie when Organization is Unresponsive | On-demand | 0 | ↗ |
8. Security Assessment Report Generation
Category: GRC | Subcategories: Security metrics & reporting
Description: Automates the generation and delivery of structured security assessment reports in Plextrac — SCCIC's reporting platform. Given a client name, findings list, and report date, the automation locates the client in Plextrac, creates a new report, populates it with relevant writeups from the library, and emails the completed report to the recipient. Supports Active Directory assessments and general security assessments.
Business problem solved: Producing formatted assessment reports in a client-facing platform is time-intensive and error-prone when done manually. These playbooks allow SCCIC analysts to generate professional, consistent Plextrac reports with a single trigger — dramatically accelerating report delivery to SC government agencies.
Integrations: Plextrac, Email
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| New Workflow 1 | On-demand | 73 | ↗ |
| AD Assessment Reports | On-demand | 2 | ↗ |
| Active Directory Assessment Reports | On-demand | 2 | ↗ |
| AD Assessment Reports copy | On-demand | 0 | ↗ |
| New Workflow (draft) | On-demand | 0 | ↗ |
9. Credential Leak Intelligence
Category: GRC | Subcategories: DLP triage & exposure resp
Description: Parses and structures raw leaked credential data — including unstructured or semi-structured credential dumps — extracting, deduplicating, and sorting the credentials into a normalized format for analyst review and downstream response.
Business problem solved: Leaked credential dumps arrive in inconsistent, often raw formats that are difficult to act on without preprocessing. This playbook turns raw leak data into a structured, actionable list — accelerating the analyst's ability to identify affected accounts and initiate password resets or account lockdowns.
Integrations: Python processing
Playbooks:
| Playbook | Type | Executions | Link |
|---|---|---|---|
| Leaked Credential Sorting | On-demand | 4 | ↗ |
Key Observations
Strengths
Deep SOAR investment with a purpose-built case management platform. SCCIC has built a fully custom, Blink-native case management system — complete with observable tracking, deduplication, enrichment routing, response subflows, and recovery automation. The platform architecture (22 interconnected playbooks) reflects a mature, production-grade SOAR deployment, not a collection of isolated scripts.
Multi-source enrichment depth. The enrichment library spans nine platforms — CrowdStrike, VirusTotal, URLScan, AbuseIPDB, Okta, Microsoft Entra ID, Google Workspace, GitHub, and Slack. This breadth means that virtually every observable type encountered in an alert can be automatically enriched without analyst intervention.
Agentic SOC capabilities. Two AI agents are deployed in production: one for phishing email analysis and one (Truskey Jr) for generating case reports and timelines. The Build Case Report and Timeline playbook — already used 8 times — represents a genuine shift toward AI-assisted incident documentation, a leading-edge capability in government SOC environments.
Ransomware monitoring with real operational impact. The ransomware extortion monitoring pipeline (217 scans, 15 victim alerts delivered) is a high-value, continuous operation that would be impractical to replicate manually. Running every 4 hours around the clock, it ensures no South Carolina victim goes unreported.
Structured services delivery at scale. The assessment services coordination use case (M365, Vulnerability Scanning, AD Audit, Threat Intelligence) runs on scheduled cadences tied directly to SharePoint as the system of record. The daily CLO and org list database synchronizations (36 + 7 runs) ensure the entire downstream automation ecosystem stays accurate without human upkeep.
Plextrac report generation at scale. 77 assessment reports generated automatically across Plextrac represents significant analyst time saved on a typically high-effort task. With 73 executions on a single playbook, report generation is clearly a high-frequency operation.
Gaps & Opportunities
SOAR pipeline not yet running in production. The core Process Alert event playbook shows 0 executions, meaning the full alert-to-case automation pipeline has been built and tested (via the simulator playbooks) but has not yet processed live production alerts. Once activated, this platform has the potential to automate hundreds of alert triage cycles per month.
Enrichment playbooks at zero executions. All 28 enrichment playbooks show 0 executions — consistent with the SOAR pipeline not yet processing live alerts. As the alert pipeline comes online, enrichment volume will increase proportionally. The library is ready; the trigger is the missing piece.
EDR containment capabilities built but dormant. CrowdStrike endpoint isolation and RTR capabilities are built and integrated but have not been invoked. These are high-value response actions that could significantly reduce mean time to contain once the SOAR pipeline is live.
Phishing email analysis web form at zero executions. The web-form-based phishing submission workflow (workspace 7c9e1f21) is configured and ready but has not received any submissions. Analyst awareness and adoption may be a driver to address.
Duplicate playbooks suggest iterative development. Several playbooks exist in duplicate across workspaces (two Message Trace Analysis playbooks, two AD Assessment Reports variants, one copy). Consolidating these would reduce maintenance surface and ensure consistent execution.
CyberDefenders and Bad VPS Templates at zero. These scheduled playbooks are configured but show no execution history — they may be paused, awaiting data sources, or in early development.
Integration Ecosystem
| Platform | Role |
|---|---|
| CrowdStrike | EDR — alert enrichment, endpoint containment, RTR, hash investigation |
| VirusTotal | IOC enrichment — hashes, IPs, URLs |
| URLScan | URL analysis and screenshot capture |
| AbuseIPDB | IP reputation enrichment |
| Okta | Identity enrichment, user activity lookup |
| Microsoft Entra ID | Identity enrichment, risky user detection |
| Google Workspace | Identity enrichment |
| Slack | User lookup by email |
| GitHub | User information lookup |
| Recorded Future | Domain watchlist management, validated C2 indicator list sync to EDL manager |
| Shodan | External attack surface / hostname intelligence |
| SharePoint (SLED SC) | System of record for service requests and CLO data |
| Plextrac | Security assessment report generation and delivery |
| ransomware.live | Ransomware extortion victim monitoring |
| Censys ASM | Asset inventory and attack surface seeding |
| Blink Case Management | Native SOAR / case management platform |
| Blink AI Agents | Email analysis, report and timeline generation |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| sccic | apikey-auth | google_threat_intelligence_vt_enterprise | 2026-08-25 |