Blink Security Automation — Confidential

Wix — Customer Success Report

Generated 2026-08-31 | wix-value-report.md
2026-08-31Report Date
979Total Playbooks
265Unique Workflows (12m)
23,968,111Actions Automated (12m)
$6,164,638Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

979
Total playbooks built
all non-deleted workflows
458
Active playbooks
currently enabled
265
Unique workflows executed (12m)
distinct workflows that ran
23,968,111
Actions automated (12m)
completed action steps
133,156.2h
Hours saved (12m)
@ 20s per action
$6,164,638
Money saved (12m)
@ $100K avg salary
1
New active workflows (last 30d)
recently created & enabled
64,620
Total cases managed
31,739 opened in last 12m
8d 13h
MTTR — mean time to resolve
closed cases, last 12m
7
Active AI agents
of 25 total
1,939
AI agent tasks executed (12m)
171 in last 30d
In the last 12 months, Blink automated: - 52,804 security alerts ingested from Splunk SIEM and routed for automated triage - 3,133 alerts processed end-to-end through Wix's custom SOC triage and enrichment pipeline - 1,078 EDR containment and investigation actions executed live on endpoints via CrowdStrike - 522 critical vulnerability artifacts queried and triaged from Splunk - 172 secrets scanning executions run across code repositories via TruffleHog - 141 bug bounty findings from HackerOne ingested and processed - 128 employee-reported phishing emails ingested, analyzed, and routed - 117 CVE vulnerabilities detected via Upwind and automatically routed to remediation - 103 cloud asset inventory assessments conducted by an AI agent - 98 internal data exposure alerts (Harpy) handled without analyst involvement

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
SIEM Ingestion & Alert Pipeline
  • 52,804Security alerts ingested from Splunk SIEM
  • 3,133Security alerts processed end-to-end through automated triage pipeline
15.5%
34
28 active
Alert Enrichment & Observable Intelligence20,271 executions
22.5%
42
40 active
Case Management & SOC Orchestration
  • 55SOC shift handover reports generated automatically
31.2%
108
98 active
Phishing Detection & Response
  • 128Phishing email reports ingested and analyzed from Gmail
  • 98Internal data exposure (Harpy) alerts handled without analyst involvement
  • 28Phishing incidents with full end-to-end automated response
0.2%
28
27 active
EDR Containment & Endpoint Investigation
  • 1,078EDR containment and investigation actions executed on live endpoints
0.5%
34
30 active
Secrets & Code Security
  • 172TruffleHog secrets scanning executions run across repositories
0.0%
6
6 active
Vulnerability Management
  • 522Critical vulnerability artifacts queried and triaged from Splunk
  • 141Bug bounty (HackerOne) findings ingested and processed
  • 117CVE vulnerabilities detected via Upwind and auto-routed to remediation
0.9%
10
9 active
Cloud Security & IaC Governance
  • 103Cloud asset inventory assessments conducted by AI agent
  • 29AWS GuardDuty security alerts automatically investigated
0.2%
15
14 active
Identity & Access Management
  • 62Unauthorized user creation events detected and investigated
0.2%
12
9 active
Compliance & GRC206 executions
0.2%
13
13 active
Platform Health & Automation Monitoring12,435 executions
13.8%
19
17 active
Total76,677 executions100%
321
291 active

Use Case Growth Over Time

650 unique playbooks  |  11 operational use cases  |  89,924 total executions (12m)  |  1970-01 to 2026-08
Toggle:
Toggle:

03Integration Ecosystem

Phishing Detection & Response
Slack Gmail Perception Point Microsoft Outlook Agents Web Form
Identity & Access Management
Google Workspace Duo LDAP Slack Splunk
Alert Enrichment & Observable Intelligence
Slack CrowdStrike URLScan VirusTotal AbuseIPDB Okta String Utilities Email Perception Point LDAP Extraction Utilities Splunk Whois Axonius
SIEM Ingestion & Alert Pipeline
Splunk SOAR Slack Gmail String Utilities LDAP Splunk Email CrowdStrike
Case Management & SOC Orchestration
Slack String Utilities Monday Email Duo Splunk SSH Web Form Extraction Utilities Opsgenie Google Meet Axonius LDAP VirusTotal AbuseIPDB Splunk Observability OpenAI CrowdStrike Node.js Box ServiceNow Gmail
Cloud Security & IaC Governance
Whois Splunk LDAP Slack Axonius Agents GitHub
Platform Health & Automation Monitoring
Slack Gmail LDAP String Utilities Monday Splunk IP API Agents GitHub
Compliance & GRC
String Utilities Slack MySQL Agents Google Sheets Node.js Splunk
EDR Containment & Endpoint Investigation
String Utilities Slack Node.js Splunk CrowdStrike Email
Secrets & Code Security
Splunk Slack
Vulnerability Management
Splunk Slack Gmail Agents Node.js

04Key Observations

✓  Strengths

Strengths

Mature, high-scale SIEM automation. With 52,804 Splunk ingestion events and a fully automated alert processing pipeline (Process Alert - v9), Wix has industrialized its alert handling. The pipeline covers observable extraction, enrichment, deduplication, case creation, SLA tracking, and closure — all without analyst intervention at the triage layer.

Identity-aware enrichment. The enrichment pipeline specifically flags VIP and sensitive employees across all alert types. This context-sensitive enrichment (via LDAP, Okta, and internal VIP lists) enables risk-weighted triage that most SOCs implement only as a manual step.

AI agent adoption. Wix is deploying AI agents for multiple security workflows: cloud asset inventory, phishing verdict analysis, CVE enrichment, and GuardDuty investigation. With 103 cloud inventory assessments and 21 AI-assisted phishing verdicts, Wix is an early operator of agentic security automation.

Comprehensive EDR response. The CrowdStrike integration covers the full response lifecycle: host status check, RTR command execution, file download, process termination, and session management. This automation executed 1,078 endpoint actions in 12 months — work that would otherwise require manual analyst effort.

Harpy internal exposure detection. The Harpy use case (98 active executions) monitors internal Slack and platform activity for PII and data exposure — a security domain that most organizations leave unmonitored. This reflects a mature data loss prevention posture.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

314 inactive playbooks (69% of total). A significant portion of the playbook library has not executed in 12 months. Many are duplicates across workspaces or development drafts, but a systematic review and decommission would reduce maintenance overhead and clarify the active automation footprint.

Phishing response volume is low relative to pipeline investment. While the phishing pipeline (Perception Point, Gmail, Harpy, AI agent) is technically sophisticated, only 28 phishing incidents received a full automated response. Increasing analyst adoption or lowering the confidence threshold for automated response would improve ROI on this investment.

Cloud security coverage is developing. With 139 total executions across 6 active cloud playbooks, cloud security automation is nascent relative to SOC coverage. Expanding AWS GuardDuty alert handling, adding CSPM integration, and operationalizing the cloud inventory AI agent at higher frequency would strengthen the cloud posture.

IAM automation is limited. Only 162 executions across 5 active IAM playbooks indicates that identity lifecycle events (onboarding, offboarding, access reviews) are not yet fully automated. This is a high-value expansion area, particularly given Wix's scale.

Integration Ecosystem

Integration Primary Use Case
Splunk SIEM alert ingestion, vulnerability artifact queries, Falcon data sync
CrowdStrike Falcon EDR containment, host investigation, RTR command execution
Slack SOC notifications, analyst approvals, shift handovers, war room
LDAP User/identity enrichment for alert observables
Okta Identity enrichment and access verification
VirusTotal IP, URL, and file hash threat intelligence
Jira Security ticket creation and tracking
Monday.com SOP link retrieval for case response
Perception Point Phishing email scanning and verdict
Uptycs Endpoint memory carving and forensics
Upwind CVE detection and cloud workload context
HackerOne Bug bounty finding ingestion
AbuseIPDB / URLScan / WHOIS IOC enrichment and domain analysis
Gmail / Google Workspace Phishing report ingestion, user suspension
GitHub Repository monitoring and secrets detection support
MySQL / Trino SBOM and internal data queries
ServiceNow Ticket and record search
Axonius Asset inventory enrichment
Appendices
A Case Management 31,739 cases (12m) | MTTR 8d 13h

Case Management

Total Cases (all-time)
64,620
31,739 opened in last 12m
Cases Opened (30d)
1,802
1,755 closed in last 30d
Cases Closed (12m)
30,001
of 31,739 opened
MTTR
8d 13h
Mean time to resolve (12m)
Per Workspace Breakdown
WorkspaceTotal (all-time)Opened (12m)Closed (12m)MTTR
Production 58,386 29,992 29,991 8d 13h
TRIAL II 2,511 436 10 4m
Trial 2,250 0 0 N/A
ShadowV9 1,311 1,311 0 N/A
Splunk SOAR Migration 158 0 0 N/A
CM 1 0 0 N/A
Case Management 1 0 0 N/A
karin@blinkops.com 1 0 0 N/A
davidr@blinkops.com 1 0 0 N/A
B AI Agents 7 active | 1,939 tasks (12m)

AI Agents

Active Agents
7
of 25 total
Tasks Executed (12m)
1,939
171 in last 30d
Data Usage (12m)
321,095,890
11,355,992 in last 30d
Top 5 Agents by Tasks (Last 12 Months)
#AgentWorkspaceTasks (12m)Tasks (30d)Data (12m)
1 cloud inventory agent Production 1,409 97 136,338,900
2 Blink Phishing Verdict Agent Production 272 7 136,979,477
3 WIP - Blink Email Redirection Production 142 4 10,929,035
4 CVE Analyzer Production 63 63 3,670,307
5 WIP - Blink GuardDuty Agent Production 46 0 31,802,501
Tasks by Workspace (Last 12 Months)
WorkspaceTasks (12m)
Production1,937
TRIAL II2
shachar@blinkops.com0
uri@blinkops.com0
georgea@wix.com0
C Self-Service & Webforms 0 app runs | 0 form submissions

Self-Service Applications

Apps
27
self-service applications
Runs (12 months)
0
total executions
Runs (30 days)
0
recent executions
Top 5 Apps by Runs (Last 12 Months)
#AppRuns (12m)Runs (30d)
1 KZ 00
2 test 00
3 Case Management Dashboard 00
4 test 00
5 SOC test 00

Webforms

Forms
1
active webforms
Total Submissions
0
all time
Completed
0
fully submitted
Submissions (30d)
0
recent activity
Top 5 Forms by Submissions
#FormTotalCompleted
1 Wix Shift Report 00
D Full Use Case Analysis 11 use cases | 89,924 executions (12m)

Business KPIs

Metric Count Playbook
Security alerts ingested from Splunk SIEM 52,804 Ingest Splunk
Security alerts processed end-to-end through automated triage pipeline 3,133 Process Alert - v9
EDR containment and investigation actions executed on live endpoints 1,078 CrowdStrike - Run Command on host
Critical vulnerability artifacts queried and triaged from Splunk 522 Vuln_artifact_Critical
TruffleHog secrets scanning executions run across repositories 172 Truffelhog Execution
Bug bounty (HackerOne) findings ingested and processed 141 HackerOne test
Phishing email reports ingested and analyzed from Gmail 128 Phishing Report Ingest In Gmail CPR-IR
CVE vulnerabilities detected via Upwind and auto-routed to remediation 117 CVE Upwind detection
Cloud asset inventory assessments conducted by AI agent 103 Cloud inventory workflow with Agent
Internal data exposure (Harpy) alerts handled without analyst involvement 98 Harpy Alert Handler
SQL anomaly and injection alerts investigated automatically 112 Handle SQL Syntax Errors Alert + SQL Syntax Error Detected
SOC shift handover reports generated automatically 55 Shift Handover v2
Unauthorized user creation events detected and investigated 62 User Created Manually
AWS GuardDuty security alerts automatically investigated 29 AWS GD workflow
Phishing incidents with full end-to-end automated response 28 1. Response Main - Phishing
In the last 12 months, Blink automated: - 52,804 security alerts ingested from Splunk SIEM and routed for automated triage - 3,133 alerts processed end-to-end through Wix's custom SOC triage and enrichment pipeline - 1,078 EDR containment and investigation actions executed live on endpoints via CrowdStrike - 522 critical vulnerability artifacts queried and triaged from Splunk - 172 secrets scanning executions run across code repositories via TruffleHog - 141 bug bounty findings from HackerOne ingested and processed - 128 employee-reported phishing emails ingested, analyzed, and routed - 117 CVE vulnerabilities detected via Upwind and automatically routed to remediation - 103 cloud asset inventory assessments conducted by an AI agent - 98 internal data exposure alerts (Harpy) handled without analyst involvement

Use Case Summary

# Use Case Category Total Playbooks Active (executions > 0)
1 SIEM Ingestion & Alert Pipeline SOC 49 16
2 Alert Enrichment & Observable Intelligence SOC 76 14
3 Case Management & SOC Orchestration SOC 148 45
4 Phishing Detection & Response SOC 39 12
5 EDR Containment & Endpoint Investigation SOC 48 15
6 Secrets & Code Security GRC 6 3
7 Vulnerability Management Vulnerability Mgmt 14 7
8 Cloud Security & IaC Governance Cloud Security 18 6
9 Identity & Access Management IAM 15 5
10 Compliance & GRC GRC 21 12
11 Platform Health & Automation Monitoring Other 21 6

Use Cases

1. SIEM Ingestion & Alert Pipeline

Category: SOC

Subcategories: SIEM & log pipeline monitoring

Playbooks: 49 total (16 active)

Total Executions (12mo): 70,620

Wix ingests security telemetry from Splunk and CrowdStrike Falcon into Blink's case management platform. This use case covers the full alert ingestion lifecycle: raw event capture, alert normalization, case creation, deduplication, and bidirectional SOAR mirroring. It is the highest-volume use case by execution count, processing tens of thousands of alerts per year.

Business Value: Splunk ingestion at scale eliminates manual log review and ensures every alert is captured, deduplicated, and enriched automatically. The SOAR migration layer allows Wix to transition from Splunk SOAR to Blink's native case management without disruption.

Key Integrations: crowdstrike, splunk, splunk-soar

Playbook Executions (12mo) Category Subcategory
Ingest Splunk 52,804 SOC SIEM & log pipeline monitoring
Splunk Mirroring 3,435 SOC SIEM & log pipeline monitoring
Update Rule Sentiment Table 3,395 SOC SIEM & log pipeline monitoring
Add Event Source Link 3,381 SOC SIEM & log pipeline monitoring
Process Alert - v9 3,133 SOC SIEM & log pipeline monitoring
Falcon to Splunk lookup 1,928 SOC SIEM & log pipeline monitoring
Get Splunk Alert Link 907 SOC SIEM & log pipeline monitoring
Main Workflow - Refactor 835 SOC SIEM & log pipeline monitoring
Check Duplicate Rules 414 SOC SIEM & log pipeline monitoring
CPR Arch Splunk Alerts 143 SOC SIEM & log pipeline monitoring
Splunk Assist 130 SOC SIEM & log pipeline monitoring
Ingest Crowdstrike alert 49 SOC SIEM & log pipeline monitoring
Process Alert 20 SOC SIEM & log pipeline monitoring
Process Alert - v9 19 SOC SIEM & log pipeline monitoring
Splunk Cloud connection 18 SOC SIEM & log pipeline monitoring
DataModel Generic Playbook 9 SOC SIEM & log pipeline monitoring
DataModel Generic Playbook — SOC SIEM & log pipeline monitoring
Download Splunk SOAR Case Attachment and Add Attachment in Case Management - V2 — SOC SIEM & log pipeline monitoring
Download Splunk SOAR Case Attachment and Add Attachment in Case Management - V2 — SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - Rapid7 — SOC SIEM & log pipeline monitoring
EXAMPLE Ingest - Sentinel One — SOC SIEM & log pipeline monitoring
Generate events for ingestion — SOC SIEM & log pipeline monitoring
Get Splunk Alert Link — SOC SIEM & log pipeline monitoring
Ingest Splunk for on demand helper — SOC SIEM & log pipeline monitoring
Main - Migrating Splunk SOAR to Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Main - Migrating Splunk SOAR to Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Main - Replay Historical Alerts from Prod WS — SOC SIEM & log pipeline monitoring
Main Paginated- Migrating Splunk SOAR to Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Main Paginated- Migrating Splunk SOAR to Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Main Workflow - Refactor — SOC SIEM & log pipeline monitoring
Migrate Settings to v9 From Remote WS — SOC SIEM & log pipeline monitoring
Simulate Crowdstrike Alert — SOC SIEM & log pipeline monitoring
Simulate Crowdstrike Alert — SOC SIEM & log pipeline monitoring
Simulate Crowdstrike Alert — SOC SIEM & log pipeline monitoring
splunk - blink — SOC SIEM & log pipeline monitoring
Splunk Assist — SOC SIEM & log pipeline monitoring
Splunk search - for missing alerts — SOC SIEM & log pipeline monitoring
Subflow - Create Historical Alerts — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Artifacts in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Artifacts in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Case Owner in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Case Owner in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Comments in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Comments in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Evidence and Notes in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Sync and Manage Splunk SOAR Evidence and Notes in Blink Case Management - V2 — SOC SIEM & log pipeline monitoring
Update Case Status In Case Management - V2 — SOC SIEM & log pipeline monitoring
Update Case Status In Case Management - V2 — SOC SIEM & log pipeline monitoring
v9 migration - Create Extraction Rules — SOC SIEM & log pipeline monitoring

2. Alert Enrichment & Observable Intelligence

Category: SOC

Subcategories: Alert enrichment / IOC lookup

Playbooks: 76 total (14 active)

Total Executions (12mo): 43,245

Every alert observable — IP address, URL, file hash, email, username — is automatically enriched with threat intelligence from VirusTotal, AbuseIPDB, URLScan, Okta, LDAP, Axonius, and Whois. VIP and sensitive employees are identified and flagged during enrichment, ensuring high-risk alerts receive immediate escalation.

Business Value: Automated enrichment removes a time-consuming manual step from SOC analysts, providing full context before a human ever opens a case. The identification of VIP and sensitive employees as observables enables risk-aware triage.

Key Integrations: abuselpdb, axonius, blink, crowdstrike, okta, perception-point, slack, splunk, urlscan, virus-total, whois

Playbook Executions (12mo) Category Subcategory
Enrich Observable 27,450 SOC Alert enrichment / IOC lookup
Subflow 3 - Enrich Observable 6,813 SOC Alert enrichment / IOC lookup
Enrich Observable - VIP Employees 3,380 SOC Alert enrichment / IOC lookup
Enrich Observable - Sensitive Employees 3,380 SOC Alert enrichment / IOC lookup
Enrich Utility - Email or Username or DisplayName - LDAP 992 SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data 967 SOC Alert enrichment / IOC lookup
Agent Utility - PP URL Scan 75 SOC Alert enrichment / IOC lookup
Email Enrichment - Enrich Email Screenshot 55 SOC Alert enrichment / IOC lookup
Get SensitiveUser 40 SOC Alert enrichment / IOC lookup
VIP Update on close 28 SOC Alert enrichment / IOC lookup
Agent Utility - Enrich IP Address 20 SOC Alert enrichment / IOC lookup
Agent Utility - Get HTML URLs 20 SOC Alert enrichment / IOC lookup
IOCs Enrichment 19 SOC Alert enrichment / IOC lookup
Get VIP List 6 SOC Alert enrichment / IOC lookup
Agent Utility - Get User Confirmation Template — SOC Alert enrichment / IOC lookup
Agent Utility - Query Emails — SOC Alert enrichment / IOC lookup
Artifact enrichment — SOC Alert enrichment / IOC lookup
artifact enrichments — SOC Alert enrichment / IOC lookup
Axonius lookup — SOC Alert enrichment / IOC lookup
Check for wix registered domains — SOC Alert enrichment / IOC lookup
Check for wix registered domains — SOC Alert enrichment / IOC lookup
Check_WixhostedDomains — SOC Alert enrichment / IOC lookup
DNS Workflow — SOC Alert enrichment / IOC lookup
DNS Workflow — SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike — SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike — SOC Alert enrichment / IOC lookup
Enrich - Agent ID - Crowdstrike — SOC Alert enrichment / IOC lookup
Enrich - Hash - VT — SOC Alert enrichment / IOC lookup
Enrich - Hash - VT — SOC Alert enrichment / IOC lookup
Enrich - Hash - VT — SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB — SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB — SOC Alert enrichment / IOC lookup
Enrich - IP - IPDB — SOC Alert enrichment / IOC lookup
Enrich - IP - VT — SOC Alert enrichment / IOC lookup
Enrich - IP - VT — SOC Alert enrichment / IOC lookup
Enrich - IP - VT — SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan — SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan — SOC Alert enrichment / IOC lookup
Enrich - URL - URLScan — SOC Alert enrichment / IOC lookup
Enrich - URL - VT — SOC Alert enrichment / IOC lookup
Enrich - URL - VT — SOC Alert enrichment / IOC lookup
Enrich - URL - VT — SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta — SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta — SOC Alert enrichment / IOC lookup
Enrich - Username or Email - Okta — SOC Alert enrichment / IOC lookup
Enrich Observable - Email or Username or DisplayName - LDAP — SOC Alert enrichment / IOC lookup
Enrich Observable - Sensitive Employees — SOC Alert enrichment / IOC lookup
Enrich Observable - VIP Employees — SOC Alert enrichment / IOC lookup
Enrich URL with VT — SOC Alert enrichment / IOC lookup
Enrich Utility - Email or Username or DisplayName - LDAP — SOC Alert enrichment / IOC lookup
Enrich Utility - Email or Username or DisplayName - LDAP — SOC Alert enrichment / IOC lookup
Enrich Utility - Email or Username or DisplayName - LDAP - Copy — SOC Alert enrichment / IOC lookup
Get runlogs — SOC Alert enrichment / IOC lookup
Get URL content stripped — SOC Alert enrichment / IOC lookup
Recovery - Enrich non-enriched observables — SOC Alert enrichment / IOC lookup
Recovery - Enrich non-enriched observables — SOC Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification — SOC Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification — SOC Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification — SOC Alert enrichment / IOC lookup
Subflow - Missing Alert Template Notification — SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data — SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data — SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data — SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data copy — SOC Alert enrichment / IOC lookup
Subflow - Update Enrichment Data copy — SOC Alert enrichment / IOC lookup
Subflow 1 - Extract Observables — SOC Alert enrichment / IOC lookup
Subflow 1 - Extract Observables — SOC Alert enrichment / IOC lookup
Subflow 1 - Extract Observables — SOC Alert enrichment / IOC lookup
Subflow 3 - Enrich Observable — SOC Alert enrichment / IOC lookup
Subflow 3 - Enrich Observable — SOC Alert enrichment / IOC lookup
Utility - Update all enrichments — SOC Alert enrichment / IOC lookup
Utility - Update all enrichments — SOC Alert enrichment / IOC lookup
Utility - Update Enrichment — SOC Alert enrichment / IOC lookup
Utility - Update Enrichment — SOC Alert enrichment / IOC lookup
VIP username validator — SOC Alert enrichment / IOC lookup
VT case command — SOC Alert enrichment / IOC lookup

3. Case Management & SOC Orchestration

Category: SOC

Subcategories: Agentic SOC, Case mgmt & SOAR, Security metrics & reporting

Playbooks: 148 total (45 active)

Total Executions (12mo): 42,191

Wix runs a sophisticated case management automation layer that handles the full case lifecycle: SLA enforcement, assignment routing, escalation, analyst notifications, war room coordination, Jira ticket creation, shift handovers, and automated closure. This is the largest use case by playbook count, reflecting the depth of SOC workflow automation.

Business Value: Automating SLA alerts, assignment changes, and analyst notifications reduces response latency and ensures nothing falls through the cracks. Shift handover automation eliminates manual status compilation at each SOC rotation.

Key Integrations: blink, monday, servicenow, slack, tables

Playbook Executions (12mo) Category Subcategory
Breached SLA - Status Updated 5,893 SOC Case mgmt & SOAR
Status is Waiting for answer 24h Alert 5,860 SOC Case mgmt & SOAR
Case Closed Responder 3,429 SOC Case mgmt & SOAR
Utility - Similar Cases and Deduplication 3,380 SOC Case mgmt & SOAR
Add test tag to cases in test table 3,380 SOC Case mgmt & SOAR
Get Monday SOP link 3,347 SOC Case mgmt & SOAR
Subflow 4 - Response 3,112 SOC Case mgmt & SOAR
General Response - Send New Notification in Slack 2,542 SOC Case mgmt & SOAR
Post breach assignment handler 2,522 SOC Case mgmt & SOAR
Assignment change status 2,522 SOC Case mgmt & SOAR
Jira Search Ticket Via Ero 964 SOC Case mgmt & SOAR
Get Close Details 804 SOC Case mgmt & SOAR
Status SLA Breach Responder 785 SOC Case mgmt & SOAR
Close details to soc-alert-only 579 SOC Case mgmt & SOAR
1. User Confirmation - main 561 SOC Case mgmt & SOAR
Fill Bracket Tags 382 SOC Case mgmt & SOAR
AlertPAL 335 SOC Case mgmt & SOAR
1.2.1 User Confirmation - Routing Subflow 299 SOC Case mgmt & SOAR
Slack Approval Module 244 SOC Case mgmt & SOAR
New war_room Message 203 SOC Case mgmt & SOAR
(subflow) case comment markdown 188 SOC Case mgmt & SOAR
Escalation Flow - WIP 122 SOC Case mgmt & SOAR
Slack Response Processing - WIP 98 SOC Case mgmt & SOAR
Close Case By Automation 70 SOC Case mgmt & SOAR
Shift Handover v2 55 SOC Security metrics & reporting
Generate Vendor2Analyst Table 52 SOC Security metrics & reporting
Upload Files From Slack 51 SOC Case mgmt & SOAR
Shift Handover Trigger - 16:00 41 SOC Security metrics & reporting
Shift Handover Trigger - 14:30 41 SOC Security metrics & reporting
Shift Handover Trigger - 15:30 41 SOC Security metrics & reporting
Shift Handover Trigger - 6:30 40 SOC Security metrics & reporting
Shift Handover Trigger - 23:00 40 SOC Security metrics & reporting
Shift Handover Trigger - 22:30 40 SOC Security metrics & reporting
Getting Case comments from the last day 40 SOC Case mgmt & SOAR
Agent Utility - Get Alert 21 SOC Agentic SOC
Beasy Workflow - New Case Trigger 20 SOC Case mgmt & SOAR
Agent Utility - Get Case Observables 20 SOC Agentic SOC
Beasy Workflow - Case Tag Trigger 19 SOC Case mgmt & SOAR
Slack Approval Module - WixSOC Account 16 SOC Case mgmt & SOAR
Jira Create Ticket Via Ero 14 SOC Case mgmt & SOAR
Action Review WIP 13 SOC Case mgmt & SOAR
trigger Incident from war Room 3 SOC Case mgmt & SOAR
User & Guild statistics 1 SOC Case mgmt & SOAR
Alert Statistics - Per Month 1 SOC Security metrics & reporting
Send to SOCopilot 1 SOC Case mgmt & SOAR
(testing) On new Slack message — SOC Case mgmt & SOAR
1. Main Migrated Observables Case Recovery — SOC Case mgmt & SOAR
1.2.1 User Confirmation - Routing Subflow — SOC Case mgmt & SOAR
2. Subflow - Migrated Observables Case Recovery — SOC Case mgmt & SOAR
Action Review WIP — SOC Case mgmt & SOAR
Add comment to case — SOC Case mgmt & SOAR
Battlefield — SOC Case mgmt & SOAR
Beasy Add Management — SOC Case mgmt & SOAR
Beasy Channel Rename — SOC Case mgmt & SOAR
Beasy Main Workflow — SOC Case mgmt & SOAR
Beasy Main Workflow — SOC Case mgmt & SOAR
Beasy Main Workflow - Test — SOC Case mgmt & SOAR
Beasy Questionnaire Webhook — SOC Case mgmt & SOAR
Bulk run workflow — SOC Case mgmt & SOAR
Check slack user — SOC Case mgmt & SOAR
Close Case By Automation — SOC Case mgmt & SOAR
Close Cases for Uptycs — SOC Case mgmt & SOAR
Delete CM Records(BEWARE) — SOC Case mgmt & SOAR
Escalation Flow - WIP — SOC Case mgmt & SOAR
Fill Bracket Tags — SOC Case mgmt & SOAR
Fill Bracket Tags copy — SOC Case mgmt & SOAR
Fill Bracket Tags copy — SOC Case mgmt & SOAR
Generate Vendor2Analyst Table — SOC Security metrics & reporting
Get Cases with SQL — SOC Case mgmt & SOAR
Get Close Details — SOC Case mgmt & SOAR
Get Historical Rules — SOC Case mgmt & SOAR
Get WIX singer — SOC Case mgmt & SOAR
Harpy api Via Ero — SOC Case mgmt & SOAR
Harpy api Via Ero — SOC Case mgmt & SOAR
Incident Manager Questionnaire - Web Form — SOC Case mgmt & SOAR
Jira Create Ticket Via Ero — SOC Case mgmt & SOAR
List all workflows in a workspace — SOC Case mgmt & SOAR
Long workflow execution report — SOC Case mgmt & SOAR
Main - CS Rules Alert — SOC Case mgmt & SOAR
New Workflow — SOC Case mgmt & SOAR
New Workflow — SOC Case mgmt & SOAR
New Workflow 4 — SOC Case mgmt & SOAR
New Workflow 5 — SOC Case mgmt & SOAR
No Response — SOC Case mgmt & SOAR
No Response — SOC Case mgmt & SOAR
OBS Prod Report on Duplicates — SOC Case mgmt & SOAR
On Demand General Slack — SOC Case mgmt & SOAR
Open case from form — SOC Case mgmt & SOAR
Recovery - handle alert case wise — SOC Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts — SOC Case mgmt & SOAR
Recovery - Handle Unprocessed Alerts — SOC Case mgmt & SOAR
Recovery - Refill Case Missing Searchable Filed Values — SOC Case mgmt & SOAR
Report Comparing Prod and Testing Differences — SOC Case mgmt & SOAR
Rocket - get dm — SOC Case mgmt & SOAR
Rocket - get dm — SOC Case mgmt & SOAR
Rocket - get host — SOC Case mgmt & SOAR
Rocket - get host — SOC Case mgmt & SOAR
Rocket - get node ip — SOC Case mgmt & SOAR
Rocket - get node ip — SOC Case mgmt & SOAR
Rocket - get pod — SOC Case mgmt & SOAR
Rocket - get pod — SOC Case mgmt & SOAR
Rocket - get user — SOC Case mgmt & SOAR
Rocket - get user — SOC Case mgmt & SOAR
search DM using Rocket — SOC Case mgmt & SOAR
search DM using Rocket — SOC Case mgmt & SOAR
Send Webform to User — SOC Case mgmt & SOAR
Shift Handover - Slack Block Builder — SOC Security metrics & reporting
Shift Handover Handler — SOC Security metrics & reporting
Slack Approval Module — SOC Case mgmt & SOAR
Slack Approval Module - WixSOC Account — SOC Case mgmt & SOAR
Slack Bot information getter — SOC Case mgmt & SOAR
SOD Tirgger — SOC Case mgmt & SOAR
Subflow 2 - Create Case — SOC Case mgmt & SOAR
Subflow 2 - Create Case — SOC Case mgmt & SOAR
Subflow 2 - Create Case — SOC Case mgmt & SOAR
Subflow 2.1 - Get Deduplication Rule — SOC Case mgmt & SOAR
Subflow 2.1 - Get Deduplication Rule — SOC Case mgmt & SOAR
Subflow 2.1 - Get Deduplication Rule — SOC Case mgmt & SOAR
Subflow 2.2 - Check for Case Deduplicates — SOC Case mgmt & SOAR
Subflow 2.2 - Check for Case Deduplicates — SOC Case mgmt & SOAR
Subflow 2.2 - Check for Case Deduplicates — SOC Case mgmt & SOAR
Subflow 2.3 - Link Alert to Existing Case — SOC Case mgmt & SOAR
Subflow 2.3 - Link Alert to Existing Case — SOC Case mgmt & SOAR
Subflow 2.3 - Link Alert to Existing Case — SOC Case mgmt & SOAR
Subflow 4 - Response — SOC Case mgmt & SOAR
Subflow 4 - Response - POC — SOC Case mgmt & SOAR
Subflow example — SOC Case mgmt & SOAR
test for — SOC Case mgmt & SOAR
test slack attachment — SOC Case mgmt & SOAR
Upload Attachment to Slack Bot - Web Form — SOC Case mgmt & SOAR
Upload Files From Slack — SOC Case mgmt & SOAR
USE WITH CARE - Reset Environment — SOC Case mgmt & SOAR
USE WITH CARE - Reset Environment — SOC Case mgmt & SOAR
USE WITH CARE - Reset Environment — SOC Case mgmt & SOAR
USE WITH CARE - Reset Environment — SOC Case mgmt & SOAR
user Confirmation - SecOPs — SOC Case mgmt & SOAR
user Confirmation - SecOPs — SOC Case mgmt & SOAR
User Confirmation New — SOC Case mgmt & SOAR
User Confirmation with text input — SOC Case mgmt & SOAR
Utility - Append to Case Overview Automation Update — SOC Case mgmt & SOAR
Utility - Close Stale Cases — SOC Case mgmt & SOAR
Utility - Close Stale Cases — SOC Case mgmt & SOAR
Utility - Find by Observables — SOC Case mgmt & SOAR
Utility - Find Similar Cases — SOC Case mgmt & SOAR
Utility - Overview Builder — SOC Case mgmt & SOAR
Utility - Overview Builder — SOC Case mgmt & SOAR
Utility - Overview Builder — SOC Case mgmt & SOAR
Utility - Similar Cases and Deduplication — SOC Case mgmt & SOAR

4. Phishing Detection & Response

Category: SOC

Subcategories: Phishing detection & response

Playbooks: 39 total (12 active)

Total Executions (12mo): 528

Wix automates the end-to-end phishing pipeline: email ingestion from Gmail, screenshot enrichment, AI-assisted verdict analysis via a Phishing Verdict Analyst agent, Perception Point integration, and user notification. The Harpy system detects internal PII and data exposure incidents from Slack and other channels.

Business Value: AI-assisted phishing verdict analysis accelerates the most repetitive SOC task — reviewing reported phishing emails. The Harpy integration adds coverage for internal data exposure that traditional email security tools miss.

Key Integrations: google-workspace, microsoft-outlook, perception-point, slack

Playbook Executions (12mo) Category Subcategory
Phishing Report Ingest In Gmail CPR-IR 128 SOC Phishing detection & response
Harpy Alert Handler 98 SOC Phishing detection & response
Harpy Exposed PII 98 SOC Phishing detection & response
HP Project main workflow 38 SOC Phishing detection & response
Gmail Ingested Alert Enrichment 34 SOC Phishing detection & response
1. Response Main - Phishing 28 SOC Phishing detection & response
Phishing Email Verdict 25 SOC Phishing detection & response
Create Phishing Overview 25 SOC Phishing detection & response
Agent - Phishing Verdict Analyst 21 SOC Phishing detection & response
Email Redirection Handler 15 SOC Phishing detection & response
Email Redirection Agent 15 SOC Phishing detection & response
Send Webform to User copy 3 SOC Phishing detection & response
Agent - Email Spam Detector — SOC Phishing detection & response
Agent - Phishing Verdict Analyst — SOC Phishing detection & response
Create or Update Phishing Email Overview — SOC Phishing detection & response
Create or Update Phishing Email Overview — SOC Phishing detection & response
Create or Update Phishing Email Overview-1 — SOC Phishing detection & response
Harpy Alert Handler — SOC Phishing detection & response
Harpy Alerts - Test — SOC Phishing detection & response
Harpy API UpdateAlert — SOC Phishing detection & response
Harpy API UpdateAlert — SOC Phishing detection & response
Harpy Exposed assets (test) — SOC Phishing detection & response
Harpy Exposed PII — SOC Phishing detection & response
Harpy Generic — SOC Phishing detection & response
Harpy Generic — SOC Phishing detection & response
Harpy Generic — SOC Phishing detection & response
Harpy Slack Watchman — SOC Phishing detection & response
Harpy Slack Watchman (Not IN Use) — SOC Phishing detection & response
Harpy Watchman Generic — SOC Phishing detection & response
Harpy Watchman Generic — SOC Phishing detection & response
harpy webhook close cases — SOC Phishing detection & response
HP Access Detected — SOC Phishing detection & response
Perception Point. - Emails Verdcit — SOC Phishing detection & response
Perception Point. - Emails Verdcit — SOC Phishing detection & response
Phishing Email Overview Reaction Button — SOC Phishing detection & response
Phishing Email Verdict — SOC Phishing detection & response
Subflow - Phishing — SOC Phishing detection & response
Subflow - Phishing — SOC Phishing detection & response
Testing phishing screenshot gmail extractor — SOC Phishing detection & response

5. EDR Containment & Endpoint Investigation

Category: SOC

Subcategories: EDR containment & response

Playbooks: 48 total (15 active)

Total Executions (12mo): 1,983

When an endpoint is flagged by CrowdStrike Falcon, Blink executes containment and investigation automatically: host isolation, RTR command execution, file download, memory carving via Uptycs, and macOS/Windows forensics collection. K8s workloads are monitored via Cilium for suspicious service account token access.

Business Value: Automated EDR response compresses mean time to contain (MTTC) by executing containment actions the moment an alert fires, without waiting for an analyst to log in.

Key Integrations: crowdstrike, slack

Playbook Executions (12mo) Category Subcategory
CrowdStrike - Run Command on host 1,078 SOC EDR containment & response
CS:03 Custom Rules FP 234 SOC EDR containment & response
CrowdStrike - Get Host Information 224 SOC EDR containment & response
CrowdStrike - Check Host Status 209 SOC EDR containment & response
(subflow) SRV Sign 57 SOC EDR containment & response
Download histroy files from RTR 54 SOC EDR containment & response
CS:02 get all relevant events 43 SOC EDR containment & response
Malpack 30 SOC EDR containment & response
Rocket - Check If Host Is Online 20 SOC EDR containment & response
CrowdStrike - Fetch Files 19 SOC EDR containment & response
Reg Save System and SAM 8 SOC EDR containment & response
Uptycs carving 2 SOC EDR containment & response
Rocket - Uptycs carving 2 SOC EDR containment & response
Windows Event Logs Clearing 2 SOC EDR containment & response
Initiate forensics collection macOS 1 SOC EDR containment & response
AWX-Dumping Pod — SOC EDR containment & response
Cilium test — SOC EDR containment & response
Cilium: Suspicious K8s Service Account Token Access — SOC EDR containment & response
clickfix attack using osascript and curl — SOC EDR containment & response
CrowdStrike - Check Host Status — SOC EDR containment & response
CrowdStrike - Check Host Status copy — SOC EDR containment & response
CrowdStrike - Create a batch session temp — SOC EDR containment & response
CrowdStrike - Fetch Files — SOC EDR containment & response
CrowdStrike - Get Host Information — SOC EDR containment & response
CrowdStrike - Get Host Information copy — SOC EDR containment & response
CrowdStrike - Polling Check — SOC EDR containment & response
CrowdStrike - Remove Files — SOC EDR containment & response
CrowdStrike - Run Command on host — SOC EDR containment & response
CrowdStrike Tests — SOC EDR containment & response
CS: Obfuscated Remote Script Execution via Curl and Base64 Decoding — SOC EDR containment & response
CS:01-Get Similar cases — SOC EDR containment & response
CS:01-Get Similar cases — SOC EDR containment & response
CS:02 get all relevant events — SOC EDR containment & response
CS:03 Custom Rules FP — SOC EDR containment & response
CSWinDiag Execution WIP — SOC EDR containment & response
Download histroy files from RTR — SOC EDR containment & response
Extract browser extensions — SOC EDR containment & response
Initiate forensics collection macOS — SOC EDR containment & response
MacOS Collector — SOC EDR containment & response
macos_forensics_collection — SOC EDR containment & response
Rocket - Uptycs carving — SOC EDR containment & response
Run RTR on Multiple devices by FQL filter — SOC EDR containment & response
Run RTR on Multiple devices by FQL filter — SOC EDR containment & response
Subflow - Malware — SOC EDR containment & response
Subflow - Malware — SOC EDR containment & response
Uptycs carving — SOC EDR containment & response
Uptycs integration test — SOC EDR containment & response
Windows Automatic Collection — SOC EDR containment & response

6. Secrets & Code Security

Category: GRC

Subcategories: DevSecOps compliance

Playbooks: 6 total (3 active)

Total Executions (12mo): 212

TruffleHog scans repositories for exposed secrets and credentials. When a secret is detected, Blink automatically creates a case, collects webhook callback data, and orchestrates the response workflow. GitHub repository monitoring tracks new repositories and content for security review.

Business Value: Automated secrets detection and response prevents credential exposure from becoming a breach, closing the gap between code commit and security review.

Key Integrations: splunk

Playbook Executions (12mo) Category Subcategory
Truffelhog Execution 172 GRC DevSecOps compliance
trufflehog was detected 21 GRC DevSecOps compliance
TruffleHog Execution - Webhook Callback 19 GRC DevSecOps compliance
Github check repo created — GRC DevSecOps compliance
Github query — GRC DevSecOps compliance
Truffelhog Execution - backup — GRC DevSecOps compliance

7. Vulnerability Management

Category: Vulnerability Mgmt

Subcategories: CVE lookup & remediation, Vuln lifecycle prioritize & ticket, Vuln scanning ingest & report

Playbooks: 14 total (7 active)

Total Executions (12mo): 1,019

Wix tracks vulnerability exposure across multiple dimensions: Upwind-sourced CVE detections are triaged by an AI CVE Agent, SBOM data is queried via Trino for dependency analysis, HackerOne bug bounty findings are ingested and processed, Nuclei regression scans validate security controls, and critical vulnerability artifacts are queried from Splunk.

Business Value: AI-assisted CVE triage (CVE Agent) and SBOM-based vulnerability analysis provide modern, context-aware vulnerability prioritization beyond traditional CVSS scoring.

Key Integrations: gmail, slack, splunk

Playbook Executions (12mo) Category Subcategory
Vuln_artifact_Critical 522 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
HackerOne test 141 Vulnerability Mgmt Vuln scanning ingest & report
CVE Upwind detection 117 Vulnerability Mgmt CVE lookup & remediation
CVE Agent 98 Vulnerability Mgmt CVE lookup & remediation
Query SBOM by Trino 97 Vulnerability Mgmt CVE lookup & remediation
Nuclei Regression Results 39 Vulnerability Mgmt Vuln scanning ingest & report
Root CA Certificate was added via CLI 5 Vulnerability Mgmt Vuln lifecycle prioritize & ticket
CVE Agent — Vulnerability Mgmt CVE lookup & remediation
PaloAlto non WixIP — Vulnerability Mgmt Vuln lifecycle prioritize & ticket
PaloAlto non WixIP — Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Query SBOM by Trino — Vulnerability Mgmt CVE lookup & remediation
Query SBOM by Trino v2 — Vulnerability Mgmt CVE lookup & remediation
Trino test — Vulnerability Mgmt Vuln lifecycle prioritize & ticket
Vuln_artifact_Critical — Vulnerability Mgmt Vuln lifecycle prioritize & ticket

8. Cloud Security & IaC Governance

Category: Cloud Security

Subcategories: CSPM ingest & triage, Cloud access & SaaS policy mgmt, Cloud asset coverage & inventory, Cloud provisioning & IaC automation

Playbooks: 18 total (6 active)

Total Executions (12mo): 139

AWS GuardDuty alerts are ingested and automatically investigated. An AI agent conducts cloud asset inventory assessments. Public S3 bucket exposure triggers a justification workflow, Terraform break-glass access is governed and audited, PaloAlto firewall anomalies are detected, and AWS KMS encryption anomalies are flagged.

Business Value: AI agent-driven cloud inventory assessment is a forward-looking capability that reduces the manual burden of cloud asset reviews. GuardDuty integration ensures cloud threat signals reach the SOC at machine speed.

Key Integrations: github, slack, splunk, whois

Playbook Executions (12mo) Category Subcategory
Cloud inventory workflow with Agent 103 Cloud Security Cloud asset coverage & inventory
AWS GD workflow 29 Cloud Security CSPM ingest & triage
Public S3 Bucket justification 4 Cloud Security CSPM ingest & triage
AWS: Encryption or Decryption of objects on from unknown entity with unrelated keys 1 Cloud Security CSPM ingest & triage
Terraform_live_infra_provisioning_break_the_glass 1 Cloud Security Cloud provisioning & IaC automation
Block domain on Island 1 Cloud Security Cloud access & SaaS policy mgmt
Agent - Guardduty Investigator — Cloud Security CSPM ingest & triage
AWS CLI Persistent Token Access — Cloud Security CSPM ingest & triage
AWS GD workflow — Cloud Security CSPM ingest & triage
AWS New Subnet Created in Production Account — Cloud Security Cloud provisioning & IaC automation
AWS SIR — Cloud Security CSPM ingest & triage
AWS TH Generic details — Cloud Security CSPM ingest & triage
AWS TH: IAM User Usage from Non Wix Address — Cloud Security CSPM ingest & triage
GD Flow — Cloud Security CSPM ingest & triage
GD Flow — Cloud Security CSPM ingest & triage
GuardDuty — Cloud Security CSPM ingest & triage
GuardDuty Suspicious Domain Requests — Cloud Security CSPM ingest & triage
Terraform_live_infra_provisioning_break_the_glass — Cloud Security Cloud provisioning & IaC automation

9. Identity & Access Management

Category: IAM

Subcategories: Access review & group mgmt, Employee onboarding, Identity lifecycle automation, Identity sync & directory mgmt, Password & credential lifecycle, Privileged account mgmt

Playbooks: 15 total (5 active)

Total Executions (12mo): 162

Identity events — manual user creation, Okta identity operations, Kerberos keytab access, DUO MFA anomalies, CLI-based account manipulation, and group synchronization — are detected and responded to automatically. Vault access requires user confirmation before secrets are revealed.

Business Value: Detecting manual user creation and CLI-based account changes catches identity-based attacks that bypass standard IAM provisioning workflows.

Key Integrations: google-workspace, slack, splunk

Playbook Executions (12mo) Category Subcategory
Okta 75 IAM Identity sync & directory mgmt
User Created Manually 62 IAM Employee onboarding
Mac New User was Create/Delete via CLI 13 IAM Identity lifecycle automation
Run KGB Groups Sync 6 IAM Access review & group mgmt
vault user confirmation 6 IAM Password & credential lifecycle
Azure Reset user password — IAM Password & credential lifecycle
Block IP — IAM Identity lifecycle automation
Duo MFA Validation - WIP — IAM Password & credential lifecycle
DUO Multiple Push to the same User — IAM Password & credential lifecycle
DUO Multiple Push to the same User — IAM Password & credential lifecycle
Google Workspace Suspicious User — IAM Identity sync & directory mgmt
User accessed Kerberos Keytab — IAM Privileged account mgmt
User Created Manually — IAM Employee onboarding
User DataModel query (KZ) — IAM Identity lifecycle automation
vault user confirmation — IAM Password & credential lifecycle

10. Compliance & GRC

Category: GRC

Subcategories: Compliance questionnaire, DevSecOps compliance, PCI & regulatory monitoring, Security metrics & reporting

Playbooks: 21 total (12 active)

Total Executions (12mo): 560

Wix enforces PCI compliance edge cases, monitors for SQL syntax errors that may indicate injection attempts, sends compliance questionnaire reminders via case management, and imports anomaly tracking data. The SQL monitoring pipeline uses AI gateway integration for intelligent anomaly analysis.

Business Value: AI-assisted SQL anomaly investigation (via Call AiGateway) adds intelligence to what would otherwise be a noisy, false-positive-heavy alert category.

Key Integrations: '{{steps, google-sheets, mysql, slack, splunk

Playbook Executions (12mo) Category Subcategory
PCI Edge-case Handler 134 GRC PCI & regulatory monitoring
SQL Syntax Error Detected 62 GRC DevSecOps compliance
Error logs workflow 50 GRC Security metrics & reporting
(subflow) get sql systax errors - previously investigated 50 GRC DevSecOps compliance
(subflow) SQL syntax errors from Splunk 50 GRC DevSecOps compliance
(subflow) Get Artifact Info 50 GRC Security metrics & reporting
Handle SQL Syntax Errors Alert 50 GRC DevSecOps compliance
(subflow) Call AiGateway 49 GRC Security metrics & reporting
Questionnaire_Reminder 19 GRC Compliance questionnaire
Questionnaire_Task_case_manager 19 GRC Compliance questionnaire
Questionnaire_Reminder 19 GRC Compliance questionnaire
SQL Syntax Error Detected - slack 8 GRC DevSecOps compliance
(subflow) clickhouse find SQL syntax Errors — GRC DevSecOps compliance
(subflow) clickhouse find SQL syntax Errors — GRC DevSecOps compliance
(subflow) Get Artifact Info — GRC Security metrics & reporting
(subflow) get sql systax errors - previously investigated — GRC DevSecOps compliance
(subflow) SQL syntax errors from Splunk — GRC DevSecOps compliance
manual - import sql_syntaxt_error_tracking Sheet — GRC DevSecOps compliance
manual - import sql_syntaxt_error_tracking Sheet — GRC DevSecOps compliance
PCI Edge-case Handler — GRC PCI & regulatory monitoring
SQL Syntax Error Detected — GRC DevSecOps compliance

11. Platform Health & Automation Monitoring

Category: Other

Subcategories: IT/OT & network infra monitoring, SaaS / IT administration

Playbooks: 21 total (6 active)

Total Executions (12mo): 15,787

Blink automation runners are monitored for health and performance: runner sanity checks, ingestion failure alerts, execution rate limiting alerts, and unauthorized integration approvals are all automated. This infrastructure layer ensures Wix's 400+ automation workflows remain reliable.

Business Value: Automating the monitoring of the automation platform itself creates a self-healing SOC infrastructure that alerts on its own failures before they impact alert coverage.

Key Integrations: crowdstrike, github, gmail, google-workspace, ip-api, monday, slack, splunk, uptycs

Playbook Executions (12mo) Category Subcategory
Tag automation is running limit alert 9,713 Other IT/OT & network infra monitoring
Runner Sanity Check 1,928 Other IT/OT & network infra monitoring
Periodic Runner Sanity test 1,927 Other IT/OT & network infra monitoring
Ingestion General Failure Alert 1,887 Other IT/OT & network infra monitoring
Ingestion Runner Failure Alert 191 Other IT/OT & network infra monitoring
Unapprove Integrations 141 Other IT/OT & network infra monitoring
3d workflow — Other SaaS / IT administration
Benjamin Work Flow Test — Other SaaS / IT administration
Blink Agent Playground — Other SaaS / IT administration
changed name — Other SaaS / IT administration
Clear Env — Other SaaS / IT administration
daniel-test cprlib — Other SaaS / IT administration
Getting Started - Example from Idan — Other SaaS / IT administration
Getting Started - Hello World — Other SaaS / IT administration
Getting Started - Hello World — Other SaaS / IT administration
Getting Started - Hello World — Other SaaS / IT administration
Idan test workflow for testing — Other SaaS / IT administration
Query IP — Other SaaS / IT administration
shiran test - reporting — Other SaaS / IT administration
Test runner v2 — Other IT/OT & network infra monitoring
Test workflow Test II workspace — Other SaaS / IT administration

Key Observations

Strengths

Mature, high-scale SIEM automation. With 52,804 Splunk ingestion events and a fully automated alert processing pipeline (Process Alert - v9), Wix has industrialized its alert handling. The pipeline covers observable extraction, enrichment, deduplication, case creation, SLA tracking, and closure — all without analyst intervention at the triage layer.

Identity-aware enrichment. The enrichment pipeline specifically flags VIP and sensitive employees across all alert types. This context-sensitive enrichment (via LDAP, Okta, and internal VIP lists) enables risk-weighted triage that most SOCs implement only as a manual step.

AI agent adoption. Wix is deploying AI agents for multiple security workflows: cloud asset inventory, phishing verdict analysis, CVE enrichment, and GuardDuty investigation. With 103 cloud inventory assessments and 21 AI-assisted phishing verdicts, Wix is an early operator of agentic security automation.

Comprehensive EDR response. The CrowdStrike integration covers the full response lifecycle: host status check, RTR command execution, file download, process termination, and session management. This automation executed 1,078 endpoint actions in 12 months — work that would otherwise require manual analyst effort.

Harpy internal exposure detection. The Harpy use case (98 active executions) monitors internal Slack and platform activity for PII and data exposure — a security domain that most organizations leave unmonitored. This reflects a mature data loss prevention posture.

Gaps & Opportunities

314 inactive playbooks (69% of total). A significant portion of the playbook library has not executed in 12 months. Many are duplicates across workspaces or development drafts, but a systematic review and decommission would reduce maintenance overhead and clarify the active automation footprint.

Phishing response volume is low relative to pipeline investment. While the phishing pipeline (Perception Point, Gmail, Harpy, AI agent) is technically sophisticated, only 28 phishing incidents received a full automated response. Increasing analyst adoption or lowering the confidence threshold for automated response would improve ROI on this investment.

Cloud security coverage is developing. With 139 total executions across 6 active cloud playbooks, cloud security automation is nascent relative to SOC coverage. Expanding AWS GuardDuty alert handling, adding CSPM integration, and operationalizing the cloud inventory AI agent at higher frequency would strengthen the cloud posture.

IAM automation is limited. Only 162 executions across 5 active IAM playbooks indicates that identity lifecycle events (onboarding, offboarding, access reviews) are not yet fully automated. This is a high-value expansion area, particularly given Wix's scale.

Integration Ecosystem

Integration Primary Use Case
Splunk SIEM alert ingestion, vulnerability artifact queries, Falcon data sync
CrowdStrike Falcon EDR containment, host investigation, RTR command execution
Slack SOC notifications, analyst approvals, shift handovers, war room
LDAP User/identity enrichment for alert observables
Okta Identity enrichment and access verification
VirusTotal IP, URL, and file hash threat intelligence
Jira Security ticket creation and tracking
Monday.com SOP link retrieval for case response
Perception Point Phishing email scanning and verdict
Uptycs Endpoint memory carving and forensics
Upwind CVE detection and cloud workload context
HackerOne Bug bounty finding ingestion
AbuseIPDB / URLScan / WHOIS IOC enrichment and domain analysis
Gmail / Google Workspace Phishing report ingestion, user suspension
GitHub Repository monitoring and secrets detection support
MySQL / Trino SBOM and internal data queries
ServiceNow Ticket and record search
Axonius Asset inventory enrichment
E New Integrations (detail) 1 added in last 30d

New Integrations Added - Last 30 Days

1 new connections
TenantIntegrationConnection NameAdded
Wix artemis artemis 2026-08-10