Blink Security Automation — Confidential

westernalliancebank — Customer Success Report

Generated 2026-08-31 | westernalliancebank-value-report.md
2026-08-31Report Date
310Total Playbooks
134Unique Workflows (12m)
56,250Actions Automated (12m)
$14,468Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

310
Total playbooks built
all non-deleted workflows
238
Active playbooks
currently enabled
134
Unique workflows executed (12m)
distinct workflows that ran
56,250
Actions automated (12m)
completed action steps
312.5h
Hours saved (12m)
@ 20s per action
$14,468
Money saved (12m)
@ $100K avg salary
9
New active workflows (last 30d)
recently created & enabled
42
Total cases managed
42 opened in last 12m
1d
MTTR — mean time to resolve
closed cases, last 12m
13
Active AI agents
of 35 total
487
AI agent tasks executed (12m)
334 in last 30d
In the last 12 months, Blink automated: - 34,560 phishing alerts auto-ingested and triaged across Google Workspace and Microsoft Defender XDR - 11,520 endpoint alerts auto-ingested from Microsoft Defender for Endpoint - 3,210 security alerts polled from the Microsoft Graph Security API on a 5-minute cycle - 147 security alerts fully processed through the end-to-end automated SOC response pipeline - 40 Abnormal Security email threat scan batches executed - 408 observables enriched via the automated enrichment router - 45 case observable enrichment lookups served to analysts and AI agents - 263 org asset lookups served through automated queries - 36 response actions routed through the automated response engine - 53 VIP user lookups served to analysts and AI agents - 36 org technology stack lookups served to analysts and AI agents - 21 missing alert template notifications handled automatically - 9 AI investigations processed through the Agentic SOC pipeline - 9 investigation guideline lookups served to the Agentic SOC pipeline

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Phishing Detection & Response
  • 11,520Phishing alerts auto-ingested from Google Workspace (reclassification)
  • 11,520User-reported phishing alerts auto-ingested from Google Workspace
  • 11,520Phishing alerts auto-ingested from Microsoft Defender XDR
12.0%
20
20 active
Agentic SOC — AI Investigation Engine
  • 9AI investigations processed through the Agentic SOC pipeline
  • 9Investigation guideline lookups served to the Agentic SOC pipeline
0.1%
9
9 active
Case Management & SOAR Platform
  • 147Security alerts fully processed through the automated SOC pipeline
  • 36Response actions routed through the automated response engine
  • 21Missing alert template notifications handled
0.6%
12
12 active
Alert Enrichment & IOC Lookup
  • 408Observables enriched via automated enrichment router
  • 45Case observable enrichment lookups served to analysts and AI agents
0.8%
46
46 active
EDR Containment & Response
  • 11,520Endpoint alerts auto-ingested from Microsoft Defender for Endpoint
21.3%
16
16 active
Identity Threat Response0 executions
0.0%
3
3 active
Cloud Exposure Review & Remediation0 executions
0.0%
2
2 active
SOC Reporting & Command Intelligence
  • 263Org asset lookups served to analysts and AI agents
  • 53VIP user lookups served to analysts and AI agents
  • 36Org technology stack lookups served to analysts and AI agents
0.7%
8
8 active
Employee Onboarding0 executions
0.0%
0
0 active
Vulnerability Scanning & Reporting0 executions
0.0%
1
1 active
Platform Administration & DevOps Automation0 executions
0.0%
3
3 active
Total19,126 executions100%
120
120 active

Use Case Growth Over Time

199 unique playbooks  |  10 operational use cases  |  54,026 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Alert Enrichment & IOC Lookup
VirusTotal Okta Google Workspace Microsoft Entra ID AbuseIPDB URLScan CrowdStrike Slack GitHub
EDR Containment & Response
CrowdStrike Microsoft Defender For Endpoints Elasticsearch Recorded Future
Case Management & SOAR Platform
Email SentinelOne Agents
Phishing Detection & Response
Abnormal URLScan Whois Recorded Future Proofpoint TAP Proofpoint Threat Response Auto Pull Microsoft Defender XDR Exchange Online Elasticsearch Microsoft Outlook Agents Microsoft Teams Cortex XDR Microsoft Graph DNS Dumpster Falcon Surface VirusTotal
Identity Threat Response
Microsoft Entra ID CrowdStrike Microsoft Defender XDR Elasticsearch
Cloud Exposure Review & Remediation
Microsoft Defender For Cloud Recorded Future Elasticsearch
Vulnerability Scanning & Reporting
Shodan
Platform Administration & DevOps Automation
Microsoft Teams

04Key Observations

✓  Strengths

Strengths

1. Phishing is the primary production workload. Five ingestion playbooks are running at scale — Google Workspace (reclassification + user-reported), Microsoft Defender XDR, Abnormal Security, and a Microsoft Graph Security API poller running on a 5-minute cycle — collectively ingesting over 49,000 alerts per year. This is a mature, multi-source phishing pipeline covering every major email security tool in the WAB stack, now including a second, independently deployed Microsoft Graph-based alert poller.

2. Deep Agentic SOC investment. Western Alliance Bank has built a full agentic investigation layer: a Decision Layer, Expert Agents, and a Close Case flow, all wired into a rich library of 47 enrichment abilities. The architecture is production-ready and represents one of the more complete Agentic SOC deployments — early production usage has begun (9 AI investigations processed via the main investigation flow, backed by new case-sanitization and truncation utilities), though volume remains well below the pipeline's full capacity.

3. Broad integration ecosystem. The playbook library spans 20+ distinct security tools: CrowdStrike Falcon (EDR, RTR, Identity Protection, Falcon Surface), Microsoft Defender for Endpoint/XDR/Cloud, Microsoft Graph Security API, Google Workspace, Okta, Proofpoint TAP/TRAP, Abnormal, Recorded Future, VirusTotal, Elasticsearch, URLScan, AbuseIPDB, WHOIS, DNS Dumpster, Slack, GitHub, SentinelOne, Shodan, and ServiceNow. This breadth positions Blink as the connective tissue across WAB's entire security stack.

4. WAB-native self-service and copilot layer. The WAB-branded self-service flows (phishing campaign investigation, endpoint malware containment drill, identity lateral movement response, cloud risk remediation) and the WAB SOC Copilot abilities represent a purpose-built, bank-specific automation layer — a strong signal of deep product adoption and customization.

5. Analyst approval gating throughout. Destructive actions (endpoint isolation, email quarantine, session revocation) are consistently gated behind approval_decision inputs, reflecting a security-appropriate human-in-the-loop design for a regulated financial institution.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

1. Agentic SOC and enrichment library are still mostly unexercised. The Agentic SOC pipeline has begun processing cases in production (9 AI investigations recorded), but the bulk of the 47-playbook enrichment library, identity and cloud response flows, and the employee onboarding suite still show no executions in the trailing 12 months. Fully enabling and routing production alerts through the Agentic SOC pipeline would multiply measurable automation value.

2. Process Alert volume (147) is low relative to ingestion volume (46,080+). The four ingestion playbooks are running at full scale, but only 147 alerts have been processed through the end-to-end pipeline. This gap suggests the Process Alert workflow is either connected to a different alert source than the four ingestion playbooks, or is underutilized relative to potential.

3. SentinelOne and Okta ingestion connectors are dormant. Both the SentinelOne webhook ingest and the Okta webhook ingest show 0 executions, while WAB has Okta deployed (used in enrichment playbooks). Activating these would expand log coverage without additional development work.

4. Employee onboarding not yet in production. The IAM onboarding workspace has 0 executions. With Okta already integrated and the provisioning logic built, activating the HR webhook trigger would deliver measurable time-to-access reduction for new hires.

5. Cloud security coverage is thin. Three playbooks cover cloud exposure and remediation, all with 0 executions and no ingestion trigger for cloud-native alert sources. Given WAB's Azure footprint (Microsoft Defender for Cloud is connected), adding scheduled or event-triggered cloud alert ingestion would expand the use case without significant new build effort.

6. Duplicate agent abilities. Agent_Ability_Enrich_domain and Agent_Ability_Enrich_domain copy are identical. Consolidating these would reduce maintenance overhead.

7. A second, separately deployed alert-polling pipeline has emerged. The Microsoft Graph Security Alert Poller Workflow, its lookback-time subflow, and the Microsoft Defender for Office 365 / Check SM list processing steps live in a distinct workspace from the primary SOC pipeline, yet are already running at high volume (3,210 executions). Consolidating this into the main workspace would reduce duplicated maintenance and give a single pane of glass over phishing ingestion.

8. Vulnerability scanning is a single, isolated, unexercised playbook. The new Shodan-based vulnerability search-and-summarize workflow has 0 executions and no scheduled trigger or ticketing integration. Wiring it to a recurring schedule and a downstream ticket/case creation step would turn it into a repeatable vulnerability management workflow rather than a one-off utility.

Integration Ecosystem Summary

Category Tools
EDR / Endpoint CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne
Email Security Google Workspace / Gmail, Microsoft Defender XDR, Microsoft Graph Security API, Proofpoint TAP/TRAP, Abnormal Security, Cofense/Outlook
Identity Microsoft Entra ID, Okta, CrowdStrike Identity Protection
Cloud Security Microsoft Defender for Cloud, Azure Monitor, AWS CloudTrail
Threat Intelligence VirusTotal, Recorded Future, CrowdStrike ThreatGraph, AbuseIPDB, DNS Dumpster
Vulnerability Management Shodan
SIEM / Logging Elasticsearch
URL / Domain URLScan, WHOIS
Collaboration Slack, Microsoft Teams
ITSM ServiceNow
Developer GitHub
Case Management Blink native (case management, tables, agents)
Appendices
A Case Management 42 cases (12m) | MTTR 1d

Case Management

Total Cases (all-time)
42
42 opened in last 12m
Cases Opened (30d)
10
3 closed in last 30d
Cases Closed (12m)
22
of 42 opened
MTTR
1d
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Agentic SOC 32 32 19 1d 4h
Agentic SOC - Development 10 10 3 4m
B AI Agents 13 active | 487 tasks (12m)

AI Agents

Active Agents
13
of 35 total
Tasks Executed (12m)
487
334 in last 30d
Data Usage (12m)
29,447,343
15,158,323 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 Micro Agent - Context Enrichment Agentic SOC - Development 271 271 9,409,781
2 Agent Blink - Decision Maker Agentic SOC 67 0 6,106,446
3 Micro Agent - Response Recommendation Agentic SOC - Development 36 36 3,023,169
4 Micro Agent - Historical Case Check Agentic SOC 33 0 1,095,084
5 SOC Analyst Agentic SOC - Development 18 18 1,483,773
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Agentic SOC - Development334
Agentic SOC139
Building14
CD Development Workspace0
jeffery.brown@blinkops.com0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
5
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 Test 00
2 Agentic SOC 00
3 TEST - Threat Intel Dashboard 00
4 WAB PM Tracker Metrics 00
5 WAB - Kanban Board 00

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 10 use cases | 54,026 executions (12m)

Business KPIs

Metric Count Playbook
Phishing alerts auto-ingested from Google Workspace (reclassification) 11,520 Google Workspace Alert Center — Phishing reclassification Alert
User-reported phishing alerts auto-ingested from Google Workspace 11,520 Google Workspace Alert Center — User reported phishing Alert
Phishing alerts auto-ingested from Microsoft Defender XDR 11,520 Defender XDR — Phishing Alerts
Endpoint alerts auto-ingested from Microsoft Defender for Endpoint 11,520 Microsoft Defender for endpoint ingestion
Security alerts polled from Microsoft Graph Security API (5-min cycle) 3,210 Microsoft Graph Security Alert Poller Workflow
Security alerts fully processed through the automated SOC pipeline 147 Process Alert
Abnormal Security email threat scan batches executed 40 Abnormal Ingest
Observables enriched via automated enrichment router 408 Subflow - Enrich Observables - Main Router
Case observable enrichment lookups served to analysts and AI agents 45 Agent Ability - Get Case Observable's Enrichment
Org asset lookups served to analysts and AI agents 263 Agent Ability - Get Org Assets
Response actions routed through the automated response engine 36 Subflow - Response - Main Router
VIP user lookups served to analysts and AI agents 53 Agent Ability - Get VIP Users
Org technology stack lookups served to analysts and AI agents 36 Agent Ability - Get Org Technological Stack
Missing alert template notifications handled 21 Subflow - Missing Alert Template Notification
AI investigations processed through the Agentic SOC pipeline 9 Subflow - Agentic SOC - Main - AI Investigation
Investigation guideline lookups served to the Agentic SOC pipeline 9 Agent Ability - Get Investigation Guidelines
In the last 12 months, Blink automated: - 34,560 phishing alerts auto-ingested and triaged across Google Workspace and Microsoft Defender XDR - 11,520 endpoint alerts auto-ingested from Microsoft Defender for Endpoint - 3,210 security alerts polled from the Microsoft Graph Security API on a 5-minute cycle - 147 security alerts fully processed through the end-to-end automated SOC response pipeline - 40 Abnormal Security email threat scan batches executed - 408 observables enriched via the automated enrichment router - 45 case observable enrichment lookups served to analysts and AI agents - 263 org asset lookups served through automated queries - 36 response actions routed through the automated response engine - 53 VIP user lookups served to analysts and AI agents - 36 org technology stack lookups served to analysts and AI agents - 21 missing alert template notifications handled automatically - 9 AI investigations processed through the Agentic SOC pipeline - 9 investigation guideline lookups served to the Agentic SOC pipeline

Use Case Summary

# Use Case Category Subcategories Playbook Count
1 Phishing Detection & Response SOC Phishing detection & response, SIEM & log pipeline monitoring 35
2 Agentic SOC — AI Investigation Engine SOC Agentic SOC, Case mgmt & SOAR 16
3 Case Management & SOAR Platform SOC Case mgmt & SOAR, SIEM & log pipeline monitoring 28
4 Alert Enrichment & IOC Lookup SOC Alert enrichment / IOC lookup, Threat intel ingest & curation 93
5 EDR Containment & Response SOC EDR containment & response, Alert enrichment / IOC lookup 25
6 Identity Threat Response SOC Identity threat response 5
7 Cloud Exposure Review & Remediation Cloud Security CSPM ingest & triage, Config audit & remediation 3
8 SOC Reporting & Command Intelligence GRC Security metrics & reporting 16
9 Employee Onboarding IAM Employee onboarding, Identity lifecycle automation 4
10 Vulnerability Scanning & Reporting Vulnerability Mgmt Vuln scanning ingest & report, Threat hunting & detection 1
11 Platform Administration & DevOps Automation Other SaaS / IT administration, DevOps & release automation 3

Use Cases

1. Phishing Detection & Response

Description: End-to-end phishing coverage from multi-source alert ingestion through AI-powered triage, IOC capture, analyst-assisted containment, and evidence archival. Purpose-built around Western Alliance Bank's email security stack.

Business problem: Phishing is the dominant initial access vector in financial services. Analyst capacity cannot match alert volume across Google Workspace, Microsoft Defender XDR, Proofpoint, Abnormal, and Cofense simultaneously. Blink unifies ingestion, automates triage, and gates containment actions behind analyst approval.

Key integrations: Google Workspace / Gmail, Microsoft Defender XDR, Microsoft Graph / Exchange Online, Proofpoint TAP/TRAP, Abnormal Security, Cofense/Outlook, VirusTotal, URLScan, Recorded Future, WHOIS, Elasticsearch, Blink Case Management

Category: SOC | Subcategories: Phishing detection & response, SIEM & log pipeline monitoring, Alert enrichment / IOC lookup

Playbook Executions (12 mo) Type
Google Workspace Alert Center — Phishing reclassification Alert 11,520 Ingest / Event
Google Workspace Alert Center — User reported phishing Alert 11,520 Ingest / Event
Defender XDR — Phishing Alerts 11,520 Ingest / Event
Abnormal Ingest 40 Ingest / Scheduled
Defender O365 Phishing Alerts — Hourly 0 Ingest / Scheduled
Outlook Phishing 0 Investigation / Event
WAB Self Service — Phishing Campaign Investigation 0 Self-Service
Analyze Suspicious Email 0 Agent Ability
Check Proofpoint Message 0 Agent Ability
Check O365 Defender Message 0 Agent Ability
Capture URL and Domain Evidence 0 Agent Ability
Save Phishing Evidence 0 Agent Ability
Quarantine Email 0 Agent Ability
Read Phishing Campaign Intel 0 Agent Ability
WAB Ability — Email Containment and User Response 0 Agent Ability
WAB SOC — Proofpoint Message Lookup 0 SOC Copilot Ability
WAB SOC — O365 Defender Message Lookup 0 SOC Copilot Ability
WAB SOC — Quarantine Email With Approval 0 SOC Copilot Ability
WAB SOC — URL Screenshot And Reputation 0 SOC Copilot Ability
WAB SOC — Recorded Future Domain Lookup 0 SOC Copilot Ability
WAB SOC — Elastic Hunt Around Indicator 0 SOC Copilot Ability
Get Email Attachments — Ability 0 Agent Ability
Agent_Ability_Get_Outlook_Email 0 Agent Ability
Agent_Ability_Enrich_URL 0 Agent Ability
Agent_Ability_Send_Email 0 Agent Ability
Agent_Ability_Search_Sentinel 0 Agent Ability
Agent_Ability_Enrich_domain 0 Agent Ability
Agent_Ability_Enrich_domain copy 0 Agent Ability
Agent Ability — Get Phishing Questions 0 Agent Ability
Agent Ability — Get Malware Questions 0 Agent Ability
Microsoft Graph Security Alert Poller Workflow 3,210 Ingest / Scheduled
Get lookback time 3,210 Utility
Microsoft Defender for Office 365 0 Processing
Check SM list 0 Enrichment
Pull SM List 1 Ingest / Scheduled

2. Agentic SOC — AI Investigation Engine

Description: A fully autonomous AI-driven investigation layer that receives cases, runs specialized expert agents, produces close/escalate recommendations, and executes closure or escalation actions — without waiting for analyst input on routine alerts.

Business problem: SOC analysts are bottlenecked by high alert volume and repetitive investigation steps. The Agentic SOC shifts routine triage to AI, freeing analysts for complex, high-judgment work and reducing mean-time-to-respond on lower-severity alerts.

Key integrations: Blink Case Management, Blink AI Agents / Micro Agents, all enrichment and response subflows as agent abilities

Category: SOC | Subcategories: Agentic SOC, Case mgmt & SOAR

Playbook Executions (12 mo) Type
Agentic SOC — Decision Layer 0 Core Engine
Agentic SOC — Expert Agents 0 Core Engine
Agentic SOC — Close Case 0 Core Engine
Subflow — Agentic SOC — Main — AI Investigation 0 Orchestration
Utility — Refresh Investigation 0 Utility
Agent Ability — Recommendation for Case 0 Agent Ability
Agent Ability — Historical Case Checks 0 Agent Ability
Load cases predictions from conclusions 0 Utility
Subflow - Agentic SOC - Main - AI Investigation 9 Orchestration
Utility - Sanitize Case From Prior Investigation 9 Utility
Utility - Truncate Case & Alert 9 Utility
Agent Ability - Get Investigation Guidelines 9 Agent Ability
Utility - Refresh investigation 0 Utility
Refresh investigations on case dataset 0 Utility
Load cases taggings from csv 0 Evaluation
Main Evaluation - Evaluate On Cases dataset 0 Evaluation

3. Case Management & SOAR Platform

Description: The core SOAR backbone: ingesting alerts from any source, deduplicating into cases, extracting observables, routing enrichment and response subflows, managing recovery for missed or stale events, and providing the foundational query/comment/update operations that all other use cases depend on.

Business problem: A financial institution handling alerts from a dozen security tools needs a single, auditable system of record for every alert and case. Blink Case Management provides that backbone, with built-in deduplication, observable extraction, and recovery logic to ensure no alert goes unprocessed.

Key integrations: Blink Case Management, SentinelOne, Okta, Microsoft Defender for Endpoint, AWS CloudTrail, Azure Monitor, CrowdStrike, Sumo Logic

Category: SOC | Subcategories: Case mgmt & SOAR, SIEM & log pipeline monitoring

Playbook Executions (12 mo) Type
Process Alert 147 Core Pipeline
Subflow — Response — Main Router 0 Orchestration
Recovery — Handle Unprocessed Alerts 0 Recovery
Recovery — Handle Unprocessed Alert 0 Recovery
Recovery — Enrich Non-Enriched Observables 0 Recovery
Utility — Close Stale Cases 0 Utility
Subflow — Missing Alert Template Notification 0 Utility
Table Action — Validate Observables Extraction Template 0 Utility
Case Management Query 0 Utility
Comment On Case 0 Utility
Get Observables by Case ID 0 Utility
Error Handling — Send Error Notification Email 0 Utility
Sentinelone ingestion 0 Ingest / Event
Ingest — Okta (Webhook) 0 Ingest / Event
WAB — Mock Sumo Alert Ingestion 0 Ingest / On-Demand
EXAMPLE Ingest — AWS CloudTrail 0 Ingest / Example
EXAMPLE Ingest — CrowdStrike 0 Ingest / Example
EXAMPLE Ingest — Azure 0 Ingest / Example
Create ServiceNow Ticket 0 Utility
Agent Ability — Get Closing Questions 0 Agent Ability
Table Action - Validate Observables Extraction Template 0 Utility
Error Handling - Send Error Notification Email 0 Utility
Subflow - Response - Main Router 36 Orchestration
Get Observables by Case ID 0 Utility
Utility - Close Stale Cases 0 Utility
Subflow - Missing Alert Template Notification 21 Utility
Recovery - Enrich Non-Enriched Observables 0 Recovery
Comment On Case 0 Utility

4. Alert Enrichment & IOC Lookup

Description: A deep library of enrichment subflows covering every observable type — IP, domain, URL, file hash, username, email address, and agent ID — across VirusTotal, CrowdStrike, Okta, Microsoft Entra ID, Google Workspace, Slack, GitHub, AbuseIPDB, URLScan, WHOIS, and CrowdStrike ThreatGraph. Includes observable relationship management and similarity scoring between cases.

Business problem: Analysts and agentic workflows need instant, normalized context on any indicator without switching tools. This library provides a single callable interface for every enrichment source WAB has licensed, invocable by both the Agentic SOC and human analysts via the copilot.

Key integrations: VirusTotal, CrowdStrike (EDR + ThreatGraph + Falcon Surface), AbuseIPDB, URLScan, WHOIS, Recorded Future, Okta, Microsoft Entra ID (Active Directory), Google Workspace, Slack, GitHub, DNS Dumpster, Blink Case Management

Category: SOC | Subcategories: Alert enrichment / IOC lookup, Threat intel ingest & curation

Playbook Executions (12 mo) Observable Type
Subflow — Enrich Observables — Main Router 0 Router
SubFlow — Context Enrichment 0 Router
Subflow — Update Enrichment Data 0 Router
Utility — Update Enrichment 0 Utility
Enrich — URL — VT 0 URL
Enrich — URL — URLScan 0 URL
Enrich — IP — VT 0 IP
Enrich — IP — IPDB 0 IP
Enrich — IP or Domain — Whois 0 IP / Domain
Enrich IP or Domain Using Whois 0 IP / Domain
Enrich — Hash — VT 0 Hash
Enrich — Hash — Crowdstrike 0 Hash
Enrich — Username or Email — Okta 0 Username / Email
Enrich — Username or Email — Google Workspace 0 Username / Email
Enrich — Username or Email — Microsoft Entra ID 0 Username / Email
Enrich — Username — Github 0 Username
Enrich — Email Address — Slack 0 Email
Enrich — Agent ID — Crowdstrike 0 Agent ID
Enrich — Crowdstrike Threatgraph Enrichment 0 Threat Graph
Enrich — Check If Observable inside Organization 0 Context
Get Hash Info Using VirusTotal 0 Hash
Get Hash Info Using Crowdstrike 0 Hash
Get User Information Using Okta 0 User
Get User Information Using Google Workspace 0 User
Get User Information Using Microsoft Entra ID 0 User
Get User Information Using Github 0 User
Get User Information on Email Address Using Slack 0 User
Okta Search for User Activity 0 User Activity
Run Dig Command 0 DNS
Analyze URL with URLScan 0 URL
Secure URL Screenshot Capture 0 URL
Get End of Life Date for a Product 0 Product
Query Observable 0 Observable
Utility — Find Similar Cases Based on Observables 0 Case
Utility — List Alert Observable Relations 0 Observable
Utility — List Observable Alert Relations 0 Observable
Utility — Set Or Update Observable Relation 0 Observable
Utility — Delete Observable Relation 0 Observable
Utility — Add Observable Extraction Rule 0 Observable
Agent Ability — Get Alert 0 Agent Ability
Agent Ability — Get Case 0 Agent Ability
Agent Ability — Get Case Observable's Enrichment 0 Agent Ability
Agent Ability — Get Cases and Alerts Bulk 0 Agent Ability
Agent Ability — Query Observables by Content 0 Agent Ability
Agent Ability — Get Observable Reputations 0 Agent Ability
Agent Ability — Get Observable Relation Types 0 Agent Ability
Agent Ability — Get Observable Types 0 Agent Ability
Agent Ability - Get Alert 0 Agent Ability
Analyze URL with URLScan 0 URL
Utility - Find Similar Cases Based on Observables 0 Case
Query Observable 0 Observable
Subflow - Update Enrichment Data 0 Router
Enrich - Username or Email - Okta 0 Username / Email
Get User Information Using Google Workspace 0 User
Enrich - Username or Email - Google Workspace 0 Username / Email
Get User Information Using Microsoft Entra ID 0 User
Enrich - Username or Email - Microsoft Entra ID 0 Username / Email
Enrich - IP - IPDB 0 IP
Enrich - IP - VT 0 IP
Enrich IP or Domain Using Whois 0 IP / Domain
Subflow - Enrich Observables - Main Router 408 Router
Enrich - IP or Domain - Whois 0 IP / Domain
Enrich - URL - VT 0 URL
Enrich - URL - URLScan 0 URL
Enrich - Hash - VT 0 Hash
Secure URL Screenshot Capture 0 URL
Get User Information on Email Address Using Slack 0 User
Agent Ability - Query Observables by Content 0 Agent Ability
Get Hash Info Using VirusTotal 0 Hash
Utility - Add Observable Extraction Rule 0 Observable
Agent Ability - Get Observable Relation Types From Case Management Settings 0 Agent Ability
Enrich - Hash - Crowdstrike 0 Hash
Utility - List Observable Alert Relations 0 Observable
Get User Information Using Github 0 User
Enrich - Username - Github 0 Username
Enrich - Crowdstrike Threatgraph Enrichment 0 Threat Graph
Agent Ability - Get Observable Types From Case Management Settings 0 Agent Ability
Agent Ability - Get Observable Reputations From Case Management Settings 0 Agent Ability
Utility - Set Or Update Observable Relation 0 Observable
Utility - List Alert Observable Relations 0 Observable
Enrich - Check If Observable inside Organization 0 Context
Enrich - Email Address - Slack 0 Email
Enrich - Router Default Case 0 Router
Get Hash Info Using Crowdstrike 0 Hash
Okta Search for User Activity 0 User Activity
Get User Information Using Okta 0 User
Agent Ability - Get Case Observable's Enrichment 45 Agent Ability
Utility - Delete Observable Relation 0 Observable
Get End of Life Date for a Product 0 Product
Enrich - Agent ID - Crowdstrike 0 Agent ID
Run Dig Command 0 DNS
Utility - Update Enrichment 0 Utility
Agent Ability - Get Case 0 Agent Ability

5. EDR Containment & Response

Description: Endpoint investigation and containment across CrowdStrike Falcon and Microsoft Defender for Endpoint. Covers alert ingestion, host and file context gathering, advanced Elasticsearch hunting, and approval-gated isolation actions. Includes purpose-built WAB self-service and analyst-copilot flows for malware containment drills.

Business problem: When a workstation at a financial institution is suspected of compromise, analysts need host context, process telemetry, file hash intelligence, and a safe containment path — all in minutes. Blink orchestrates multi-tool evidence gathering and gates destructive actions (isolation, quarantine) behind explicit analyst approval.

Key integrations: CrowdStrike Falcon (EDR, RTR, identity protection, Falcon Surface), Microsoft Defender for Endpoint, Elasticsearch, Recorded Future, Blink Case Management

Category: SOC | Subcategories: EDR containment & response, Alert enrichment / IOC lookup

Playbook Executions (12 mo) Type
Microsoft Defender for endpoint ingestion 11,520 Ingest / Event
WAB Self Service — Endpoint Malware Containment Drill 0 Self-Service
WAB Self Service — Analyze Suspicious File 0 Self-Service
WAB Ability — Endpoint Evidence Collection 0 Agent Ability
WAB Ability — Endpoint Containment Response 0 Agent Ability
WAB SOC — CrowdStrike Host Context 0 SOC Copilot Ability
WAB SOC — Isolate CrowdStrike Host With Approval 0 SOC Copilot Ability
CrowdStrike RTR to a Single Host 0 Response
CrowdStrike RTR to a Batch of Hosts 0 Response
Manage Endpoint Quarantine Status in Crowdstrike 0 Response
Get CrowdStrike Host Context 0 Investigation
Get Defender Endpoint Context 0 Investigation
Analyze Suspicious File 0 Investigation
Check CrowdStrike File Hash 0 Investigation
Check Defender File Evidence 0 Investigation
Save File Analysis Evidence 0 Evidence
Search Elastic Around Host 0 Threat Hunting
Search Elastic Around File 0 Threat Hunting
Search Elastic Around Observable 0 Threat Hunting
Search Elastic Around User 0 Threat Hunting
Prepare Endpoint Containment 0 Response
Isolate Endpoint 0 Response
CrowdStrike RTR to a Batch of Hosts 0 Response
Manage Endpoint Quarantine Status in Crowdstrike 0 Response
CrowdStrike RTR to a Single Host 0 Response

6. Identity Threat Response

Description: Investigation and response for identity-based threats including lateral movement, Entra ID risk scoring, CrowdStrike Identity Protection lookups, Elasticsearch identity hunting, and approval-gated session revocation.

Business problem: Lateral movement and compromised credentials are high-priority threats for a financial institution. Blink provides a structured investigation path that correlates Microsoft Entra risk scores, CrowdStrike Identity Protection signals, and Elasticsearch timeline data before surfacing an analyst-approved remediation action.

Key integrations: Microsoft Entra ID (Active Directory), CrowdStrike Identity Protection, Microsoft Defender for Endpoint, Elasticsearch, Blink Case Management

Category: SOC | Subcategories: Identity threat response

Playbook Executions (12 mo) Type
WAB Self Service — Identity Lateral Movement Response 0 Self-Service
WAB SOC — Entra And Azure Identity Risk Review 0 SOC Copilot Ability
Get Entra User Risk 0 Investigation
Review Azure Identity Anomaly 0 Investigation
Revoke User Sessions 0 Response

7. Cloud Exposure Review & Remediation

Description: Cloud security alert correlation and remediation packaging — correlating Microsoft Defender for Cloud alerts with Recorded Future external exposure context and Elasticsearch activity logs, then producing a structured remediation package for the asset owner.

Business problem: Cloud misconfigurations and externally exposed resources require rapid triage across multiple signals. Blink aggregates cloud security alerts, external threat intelligence, and log data into a single remediation package that can be routed to business owners without analyst manual effort.

Key integrations: Microsoft Defender for Cloud, Recorded Future, Elasticsearch, Blink Tables

Category: Cloud Security | Subcategories: CSPM ingest & triage, Config audit & remediation

Playbook Executions (12 mo) Type
WAB Self Service — Cloud Risk Remediation Package 0 Self-Service
Review Cloud Exposure 0 Investigation
Create Cloud Remediation Package 0 Response

8. SOC Reporting & Command Intelligence

Description: Real-time SOC command metrics, risk register reads, response evidence ledger queries, executive briefings, and asset/technology stack lookups that give the Agentic SOC and human analysts situational awareness at case time.

Business problem: Security leadership at a regulated financial institution needs continuous visibility into SOC performance and risk posture without waiting for manual reporting cycles. Blink provides on-demand and agent-invocable access to the command center, risk register, and evidence ledger.

Key integrations: Blink Tables, Blink Case Management

Category: GRC | Subcategories: Security metrics & reporting

Playbook Executions (12 mo) Type
Read SOC Command Metrics 0 Reporting
Read Recent Response Evidence 0 Reporting
Read Risk Register 0 Reporting
Save Executive Briefing 0 Reporting
Agent Ability — Get Org Technological Stack 0 Agent Ability
Agent Ability — Get Org Assets 0 Agent Ability
Agent Ability — Get VIP Users 0 Agent Ability
Agent Ability — Get Vendor Logo List 0 Agent Ability
Agent Ability — Get Core Agent Questions 0 Agent Ability
Agent Ability — Get Closing Questions 0 Agent Ability
Agent Ability — Get Case Types From Case Management Settings 0 Agent Ability
Agent Ability — Get Malware Questions 0 Agent Ability
Agent Ability - Get Org Assets 263 Agent Ability
Agent Ability - Get Vendor Logo List 0 Agent Ability
Agent Ability - Get VIP Users 53 Agent Ability
Agent Ability - Get Org Technological Stack 36 Agent Ability

9. Employee Onboarding

Description: Automated new-employee provisioning in Okta triggered by HR system webhooks, covering user creation, credential generation, and onboarding flow orchestration.

Business problem: Manual provisioning creates lag between a hire's start date and their day-one access, and increases the risk of configuration errors. Blink automates Okta account creation and onboarding steps from the moment an HR record is created.

Key integrations: Okta, HR webhook (custom webhook trigger)

Category: IAM | Subcategories: Employee onboarding, Identity lifecycle automation

Playbook Executions (12 mo) Type
1. Employee Onboarding — Ignition 0 Provisioning
2. Employee Onboarding — Lift Off 0 Provisioning
2. Employee Onboarding — Orbit 0 Event-Triggered
Employee Onboarding Orbit — Trigger 0 Utility

10. Vulnerability Scanning & Reporting

Description: On-demand Shodan-based vulnerability scanning that searches for exposed, vulnerable assets and summarizes the top findings for review.

Business problem: Security teams need a fast way to surface externally visible vulnerable assets without manually querying Shodan and sifting through raw results. Blink automates the search, extraction, and formatting of the highest-priority findings into a readable summary.

Key integrations: Shodan

Category: Vulnerability Mgmt | Subcategories: Vuln scanning ingest & report, Threat hunting & detection

Playbook Executions (12 mo) Type
SUCCESS HALLELUJAH 0 On-Demand

11. Platform Administration & DevOps Automation

Description: Platform-level administrative automations for data onboarding and workflow release management — generic CSV-to-Blink-Table import utilities (including an auto-create-table variant) and a Teams-approval-gated pipeline for promoting workflows and agent packs from a dev workspace to production.

Business problem: As the Blink footprint grows, teams need standardized, low-code ways to bulk-load reference data into Blink Tables and to safely promote workflow changes from dev to production without manual, unaudited copy/paste. Blink provides reusable import utilities and an approval-gated promotion pipeline — with optional destination-workspace backup — so platform changes stay consistent, auditable, and reversible.

Key integrations: Blink Tables, Microsoft Teams, Blink Platform (workspace/workflow promotion)

Category: Other | Subcategories: SaaS / IT administration, DevOps & release automation

Playbook Executions (12 mo) Type
Generic CSV To Blink Table 0 Utility
Generic CSV to Blink Table Import (Auto-Create Table) 0 Utility
Promote Dev to Prod (Teams Approval) 0 Release Mgmt

Key Observations

Strengths

1. Phishing is the primary production workload. Five ingestion playbooks are running at scale — Google Workspace (reclassification + user-reported), Microsoft Defender XDR, Abnormal Security, and a Microsoft Graph Security API poller running on a 5-minute cycle — collectively ingesting over 49,000 alerts per year. This is a mature, multi-source phishing pipeline covering every major email security tool in the WAB stack, now including a second, independently deployed Microsoft Graph-based alert poller.

2. Deep Agentic SOC investment. Western Alliance Bank has built a full agentic investigation layer: a Decision Layer, Expert Agents, and a Close Case flow, all wired into a rich library of 47 enrichment abilities. The architecture is production-ready and represents one of the more complete Agentic SOC deployments — early production usage has begun (9 AI investigations processed via the main investigation flow, backed by new case-sanitization and truncation utilities), though volume remains well below the pipeline's full capacity.

3. Broad integration ecosystem. The playbook library spans 20+ distinct security tools: CrowdStrike Falcon (EDR, RTR, Identity Protection, Falcon Surface), Microsoft Defender for Endpoint/XDR/Cloud, Microsoft Graph Security API, Google Workspace, Okta, Proofpoint TAP/TRAP, Abnormal, Recorded Future, VirusTotal, Elasticsearch, URLScan, AbuseIPDB, WHOIS, DNS Dumpster, Slack, GitHub, SentinelOne, Shodan, and ServiceNow. This breadth positions Blink as the connective tissue across WAB's entire security stack.

4. WAB-native self-service and copilot layer. The WAB-branded self-service flows (phishing campaign investigation, endpoint malware containment drill, identity lateral movement response, cloud risk remediation) and the WAB SOC Copilot abilities represent a purpose-built, bank-specific automation layer — a strong signal of deep product adoption and customization.

5. Analyst approval gating throughout. Destructive actions (endpoint isolation, email quarantine, session revocation) are consistently gated behind approval_decision inputs, reflecting a security-appropriate human-in-the-loop design for a regulated financial institution.

Gaps & Opportunities

1. Agentic SOC and enrichment library are still mostly unexercised. The Agentic SOC pipeline has begun processing cases in production (9 AI investigations recorded), but the bulk of the 47-playbook enrichment library, identity and cloud response flows, and the employee onboarding suite still show no executions in the trailing 12 months. Fully enabling and routing production alerts through the Agentic SOC pipeline would multiply measurable automation value.

2. Process Alert volume (147) is low relative to ingestion volume (46,080+). The four ingestion playbooks are running at full scale, but only 147 alerts have been processed through the end-to-end pipeline. This gap suggests the Process Alert workflow is either connected to a different alert source than the four ingestion playbooks, or is underutilized relative to potential.

3. SentinelOne and Okta ingestion connectors are dormant. Both the SentinelOne webhook ingest and the Okta webhook ingest show 0 executions, while WAB has Okta deployed (used in enrichment playbooks). Activating these would expand log coverage without additional development work.

4. Employee onboarding not yet in production. The IAM onboarding workspace has 0 executions. With Okta already integrated and the provisioning logic built, activating the HR webhook trigger would deliver measurable time-to-access reduction for new hires.

5. Cloud security coverage is thin. Three playbooks cover cloud exposure and remediation, all with 0 executions and no ingestion trigger for cloud-native alert sources. Given WAB's Azure footprint (Microsoft Defender for Cloud is connected), adding scheduled or event-triggered cloud alert ingestion would expand the use case without significant new build effort.

6. Duplicate agent abilities. Agent_Ability_Enrich_domain and Agent_Ability_Enrich_domain copy are identical. Consolidating these would reduce maintenance overhead.

7. A second, separately deployed alert-polling pipeline has emerged. The Microsoft Graph Security Alert Poller Workflow, its lookback-time subflow, and the Microsoft Defender for Office 365 / Check SM list processing steps live in a distinct workspace from the primary SOC pipeline, yet are already running at high volume (3,210 executions). Consolidating this into the main workspace would reduce duplicated maintenance and give a single pane of glass over phishing ingestion.

8. Vulnerability scanning is a single, isolated, unexercised playbook. The new Shodan-based vulnerability search-and-summarize workflow has 0 executions and no scheduled trigger or ticketing integration. Wiring it to a recurring schedule and a downstream ticket/case creation step would turn it into a repeatable vulnerability management workflow rather than a one-off utility.

Integration Ecosystem Summary

Category Tools
EDR / Endpoint CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne
Email Security Google Workspace / Gmail, Microsoft Defender XDR, Microsoft Graph Security API, Proofpoint TAP/TRAP, Abnormal Security, Cofense/Outlook
Identity Microsoft Entra ID, Okta, CrowdStrike Identity Protection
Cloud Security Microsoft Defender for Cloud, Azure Monitor, AWS CloudTrail
Threat Intelligence VirusTotal, Recorded Future, CrowdStrike ThreatGraph, AbuseIPDB, DNS Dumpster
Vulnerability Management Shodan
SIEM / Logging Elasticsearch
URL / Domain URLScan, WHOIS
Collaboration Slack, Microsoft Teams
ITSM ServiceNow
Developer GitHub
Case Management Blink native (case management, tables, agents)
E New Integrations (detail) 7 added in last 30d

New Integrations Added - Last 30 Days

7 new connections
TenantIntegrationConnection NameAdded
westernalliancebank servicenow servicenow_connection 2026-08-21
westernalliancebank elasticsearch elasticsearch_connection 2026-08-18
westernalliancebank microsoft-graph microsoft_graph_migration_connection 2026-08-12
westernalliancebank crowdstrike crowdstrike_dev_connection 2026-08-12
westernalliancebank recorded-future recorded_future_connection 2026-08-11
westernalliancebank crowdstrike crowdstrike_connection 2026-08-11
westernalliancebank microsoft-graph microsoft_graph_connection_security 2026-08-11