01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| SIEM Ingestion & Alert Pipeline |
| 15.5% | 34 28 active |
| Alert Enrichment & Observable Intelligence | 20,271 executions | 22.5% | 42 40 active |
| Case Management & SOC Orchestration |
| 31.2% | 108 98 active |
| Phishing Detection & Response |
| 0.2% | 28 27 active |
| EDR Containment & Endpoint Investigation |
| 0.5% | 34 30 active |
| Secrets & Code Security |
| 0.0% | 6 6 active |
| Vulnerability Management |
| 0.9% | 10 9 active |
| Cloud Security & IaC Governance |
| 0.2% | 15 14 active |
| Identity & Access Management |
| 0.2% | 12 9 active |
| Compliance & GRC | 206 executions | 0.2% | 13 13 active |
| Platform Health & Automation Monitoring | 12,435 executions | 13.8% | 19 17 active |
| Total | 76,677 executions | 100% | 321 291 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Mature, high-scale SIEM automation. With 52,804 Splunk ingestion events and a fully automated alert processing pipeline (Process Alert - v9), Wix has industrialized its alert handling. The pipeline covers observable extraction, enrichment, deduplication, case creation, SLA tracking, and closure — all without analyst intervention at the triage layer.
Identity-aware enrichment. The enrichment pipeline specifically flags VIP and sensitive employees across all alert types. This context-sensitive enrichment (via LDAP, Okta, and internal VIP lists) enables risk-weighted triage that most SOCs implement only as a manual step.
AI agent adoption. Wix is deploying AI agents for multiple security workflows: cloud asset inventory, phishing verdict analysis, CVE enrichment, and GuardDuty investigation. With 103 cloud inventory assessments and 21 AI-assisted phishing verdicts, Wix is an early operator of agentic security automation.
Comprehensive EDR response. The CrowdStrike integration covers the full response lifecycle: host status check, RTR command execution, file download, process termination, and session management. This automation executed 1,078 endpoint actions in 12 months — work that would otherwise require manual analyst effort.
Harpy internal exposure detection. The Harpy use case (98 active executions) monitors internal Slack and platform activity for PII and data exposure — a security domain that most organizations leave unmonitored. This reflects a mature data loss prevention posture.
###
Gaps & Opportunities
314 inactive playbooks (69% of total). A significant portion of the playbook library has not executed in 12 months. Many are duplicates across workspaces or development drafts, but a systematic review and decommission would reduce maintenance overhead and clarify the active automation footprint.
Phishing response volume is low relative to pipeline investment. While the phishing pipeline (Perception Point, Gmail, Harpy, AI agent) is technically sophisticated, only 28 phishing incidents received a full automated response. Increasing analyst adoption or lowering the confidence threshold for automated response would improve ROI on this investment.
Cloud security coverage is developing. With 139 total executions across 6 active cloud playbooks, cloud security automation is nascent relative to SOC coverage. Expanding AWS GuardDuty alert handling, adding CSPM integration, and operationalizing the cloud inventory AI agent at higher frequency would strengthen the cloud posture.
IAM automation is limited. Only 162 executions across 5 active IAM playbooks indicates that identity lifecycle events (onboarding, offboarding, access reviews) are not yet fully automated. This is a high-value expansion area, particularly given Wix's scale.
Integration Ecosystem
| Integration | Primary Use Case |
|---|---|
| Splunk | SIEM alert ingestion, vulnerability artifact queries, Falcon data sync |
| CrowdStrike Falcon | EDR containment, host investigation, RTR command execution |
| Slack | SOC notifications, analyst approvals, shift handovers, war room |
| LDAP | User/identity enrichment for alert observables |
| Okta | Identity enrichment and access verification |
| VirusTotal | IP, URL, and file hash threat intelligence |
| Jira | Security ticket creation and tracking |
| Monday.com | SOP link retrieval for case response |
| Perception Point | Phishing email scanning and verdict |
| Uptycs | Endpoint memory carving and forensics |
| Upwind | CVE detection and cloud workload context |
| HackerOne | Bug bounty finding ingestion |
| AbuseIPDB / URLScan / WHOIS | IOC enrichment and domain analysis |
| Gmail / Google Workspace | Phishing report ingestion, user suspension |
| GitHub | Repository monitoring and secrets detection support |
| MySQL / Trino | SBOM and internal data queries |
| ServiceNow | Ticket and record search |
| Axonius | Asset inventory enrichment |
A Case Management 31,739 cases (12m) | MTTR 8d 13h
Case Management
| Workspace | Total (all-time) | Opened (12m) | Closed (12m) | MTTR |
|---|---|---|---|---|
| Production | 58,386 | 29,992 | 29,991 | 8d 13h |
| TRIAL II | 2,511 | 436 | 10 | 4m |
| Trial | 2,250 | 0 | 0 | N/A |
| ShadowV9 | 1,311 | 1,311 | 0 | N/A |
| Splunk SOAR Migration | 158 | 0 | 0 | N/A |
| CM | 1 | 0 | 0 | N/A |
| Case Management | 1 | 0 | 0 | N/A |
| karin@blinkops.com | 1 | 0 | 0 | N/A |
| davidr@blinkops.com | 1 | 0 | 0 | N/A |
B AI Agents 7 active | 1,939 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | cloud inventory agent | Production | 1,409 | 97 | 136,338,900 |
| 2 | Blink Phishing Verdict Agent | Production | 272 | 7 | 136,979,477 |
| 3 | WIP - Blink Email Redirection | Production | 142 | 4 | 10,929,035 |
| 4 | CVE Analyzer | Production | 63 | 63 | 3,670,307 |
| 5 | WIP - Blink GuardDuty Agent | Production | 46 | 0 | 31,802,501 |
| Workspace | Tasks (12m) |
|---|---|
| Production | 1,937 |
| TRIAL II | 2 |
| shachar@blinkops.com | 0 |
| uri@blinkops.com | 0 |
| georgea@wix.com | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | KZ | 0 | 0 |
| 2 | test | 0 | 0 |
| 3 | Case Management Dashboard | 0 | 0 |
| 4 | test | 0 | 0 |
| 5 | SOC test | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | Wix Shift Report | 0 | 0 |
D Full Use Case Analysis 11 use cases | 89,924 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts ingested from Splunk SIEM | 52,804 | Ingest Splunk |
| Security alerts processed end-to-end through automated triage pipeline | 3,133 | Process Alert - v9 |
| EDR containment and investigation actions executed on live endpoints | 1,078 | CrowdStrike - Run Command on host |
| Critical vulnerability artifacts queried and triaged from Splunk | 522 | Vuln_artifact_Critical |
| TruffleHog secrets scanning executions run across repositories | 172 | Truffelhog Execution |
| Bug bounty (HackerOne) findings ingested and processed | 141 | HackerOne test |
| Phishing email reports ingested and analyzed from Gmail | 128 | Phishing Report Ingest In Gmail CPR-IR |
| CVE vulnerabilities detected via Upwind and auto-routed to remediation | 117 | CVE Upwind detection |
| Cloud asset inventory assessments conducted by AI agent | 103 | Cloud inventory workflow with Agent |
| Internal data exposure (Harpy) alerts handled without analyst involvement | 98 | Harpy Alert Handler |
| SQL anomaly and injection alerts investigated automatically | 112 | Handle SQL Syntax Errors Alert + SQL Syntax Error Detected |
| SOC shift handover reports generated automatically | 55 | Shift Handover v2 |
| Unauthorized user creation events detected and investigated | 62 | User Created Manually |
| AWS GuardDuty security alerts automatically investigated | 29 | AWS GD workflow |
| Phishing incidents with full end-to-end automated response | 28 | 1. Response Main - Phishing |
Use Case Summary
| # | Use Case | Category | Total Playbooks | Active (executions > 0) |
|---|---|---|---|---|
| 1 | SIEM Ingestion & Alert Pipeline | SOC | 49 | 16 |
| 2 | Alert Enrichment & Observable Intelligence | SOC | 76 | 14 |
| 3 | Case Management & SOC Orchestration | SOC | 148 | 45 |
| 4 | Phishing Detection & Response | SOC | 39 | 12 |
| 5 | EDR Containment & Endpoint Investigation | SOC | 48 | 15 |
| 6 | Secrets & Code Security | GRC | 6 | 3 |
| 7 | Vulnerability Management | Vulnerability Mgmt | 14 | 7 |
| 8 | Cloud Security & IaC Governance | Cloud Security | 18 | 6 |
| 9 | Identity & Access Management | IAM | 15 | 5 |
| 10 | Compliance & GRC | GRC | 21 | 12 |
| 11 | Platform Health & Automation Monitoring | Other | 21 | 6 |
Use Cases
1. SIEM Ingestion & Alert Pipeline
Category: SOC
Subcategories: SIEM & log pipeline monitoring
Playbooks: 49 total (16 active)
Total Executions (12mo): 70,620
Wix ingests security telemetry from Splunk and CrowdStrike Falcon into Blink's case management platform. This use case covers the full alert ingestion lifecycle: raw event capture, alert normalization, case creation, deduplication, and bidirectional SOAR mirroring. It is the highest-volume use case by execution count, processing tens of thousands of alerts per year.
Business Value: Splunk ingestion at scale eliminates manual log review and ensures every alert is captured, deduplicated, and enriched automatically. The SOAR migration layer allows Wix to transition from Splunk SOAR to Blink's native case management without disruption.
Key Integrations: crowdstrike, splunk, splunk-soar
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Ingest Splunk | 52,804 | SOC | SIEM & log pipeline monitoring |
| Splunk Mirroring | 3,435 | SOC | SIEM & log pipeline monitoring |
| Update Rule Sentiment Table | 3,395 | SOC | SIEM & log pipeline monitoring |
| Add Event Source Link | 3,381 | SOC | SIEM & log pipeline monitoring |
| Process Alert - v9 | 3,133 | SOC | SIEM & log pipeline monitoring |
| Falcon to Splunk lookup | 1,928 | SOC | SIEM & log pipeline monitoring |
| Get Splunk Alert Link | 907 | SOC | SIEM & log pipeline monitoring |
| Main Workflow - Refactor | 835 | SOC | SIEM & log pipeline monitoring |
| Check Duplicate Rules | 414 | SOC | SIEM & log pipeline monitoring |
| CPR Arch Splunk Alerts | 143 | SOC | SIEM & log pipeline monitoring |
| Splunk Assist | 130 | SOC | SIEM & log pipeline monitoring |
| Ingest Crowdstrike alert | 49 | SOC | SIEM & log pipeline monitoring |
| Process Alert | 20 | SOC | SIEM & log pipeline monitoring |
| Process Alert - v9 | 19 | SOC | SIEM & log pipeline monitoring |
| Splunk Cloud connection | 18 | SOC | SIEM & log pipeline monitoring |
| DataModel Generic Playbook | 9 | SOC | SIEM & log pipeline monitoring |
| DataModel Generic Playbook | — | SOC | SIEM & log pipeline monitoring |
| Download Splunk SOAR Case Attachment and Add Attachment in Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Download Splunk SOAR Case Attachment and Add Attachment in Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - Rapid7 | — | SOC | SIEM & log pipeline monitoring |
| EXAMPLE Ingest - Sentinel One | — | SOC | SIEM & log pipeline monitoring |
| Generate events for ingestion | — | SOC | SIEM & log pipeline monitoring |
| Get Splunk Alert Link | — | SOC | SIEM & log pipeline monitoring |
| Ingest Splunk for on demand helper | — | SOC | SIEM & log pipeline monitoring |
| Main - Migrating Splunk SOAR to Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Main - Migrating Splunk SOAR to Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Main - Replay Historical Alerts from Prod WS | — | SOC | SIEM & log pipeline monitoring |
| Main Paginated- Migrating Splunk SOAR to Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Main Paginated- Migrating Splunk SOAR to Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Main Workflow - Refactor | — | SOC | SIEM & log pipeline monitoring |
| Migrate Settings to v9 From Remote WS | — | SOC | SIEM & log pipeline monitoring |
| Simulate Crowdstrike Alert | — | SOC | SIEM & log pipeline monitoring |
| Simulate Crowdstrike Alert | — | SOC | SIEM & log pipeline monitoring |
| Simulate Crowdstrike Alert | — | SOC | SIEM & log pipeline monitoring |
| splunk - blink | — | SOC | SIEM & log pipeline monitoring |
| Splunk Assist | — | SOC | SIEM & log pipeline monitoring |
| Splunk search - for missing alerts | — | SOC | SIEM & log pipeline monitoring |
| Subflow - Create Historical Alerts | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Artifacts in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Artifacts in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Case Owner in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Case Owner in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Comments in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Comments in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Evidence and Notes in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Sync and Manage Splunk SOAR Evidence and Notes in Blink Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Update Case Status In Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| Update Case Status In Case Management - V2 | — | SOC | SIEM & log pipeline monitoring |
| v9 migration - Create Extraction Rules | — | SOC | SIEM & log pipeline monitoring |
2. Alert Enrichment & Observable Intelligence
Category: SOC
Subcategories: Alert enrichment / IOC lookup
Playbooks: 76 total (14 active)
Total Executions (12mo): 43,245
Every alert observable — IP address, URL, file hash, email, username — is automatically enriched with threat intelligence from VirusTotal, AbuseIPDB, URLScan, Okta, LDAP, Axonius, and Whois. VIP and sensitive employees are identified and flagged during enrichment, ensuring high-risk alerts receive immediate escalation.
Business Value: Automated enrichment removes a time-consuming manual step from SOC analysts, providing full context before a human ever opens a case. The identification of VIP and sensitive employees as observables enables risk-aware triage.
Key Integrations: abuselpdb, axonius, blink, crowdstrike, okta, perception-point, slack, splunk, urlscan, virus-total, whois
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Enrich Observable | 27,450 | SOC | Alert enrichment / IOC lookup |
| Subflow 3 - Enrich Observable | 6,813 | SOC | Alert enrichment / IOC lookup |
| Enrich Observable - VIP Employees | 3,380 | SOC | Alert enrichment / IOC lookup |
| Enrich Observable - Sensitive Employees | 3,380 | SOC | Alert enrichment / IOC lookup |
| Enrich Utility - Email or Username or DisplayName - LDAP | 992 | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | 967 | SOC | Alert enrichment / IOC lookup |
| Agent Utility - PP URL Scan | 75 | SOC | Alert enrichment / IOC lookup |
| Email Enrichment - Enrich Email Screenshot | 55 | SOC | Alert enrichment / IOC lookup |
| Get SensitiveUser | 40 | SOC | Alert enrichment / IOC lookup |
| VIP Update on close | 28 | SOC | Alert enrichment / IOC lookup |
| Agent Utility - Enrich IP Address | 20 | SOC | Alert enrichment / IOC lookup |
| Agent Utility - Get HTML URLs | 20 | SOC | Alert enrichment / IOC lookup |
| IOCs Enrichment | 19 | SOC | Alert enrichment / IOC lookup |
| Get VIP List | 6 | SOC | Alert enrichment / IOC lookup |
| Agent Utility - Get User Confirmation Template | — | SOC | Alert enrichment / IOC lookup |
| Agent Utility - Query Emails | — | SOC | Alert enrichment / IOC lookup |
| Artifact enrichment | — | SOC | Alert enrichment / IOC lookup |
| artifact enrichments | — | SOC | Alert enrichment / IOC lookup |
| Axonius lookup | — | SOC | Alert enrichment / IOC lookup |
| Check for wix registered domains | — | SOC | Alert enrichment / IOC lookup |
| Check for wix registered domains | — | SOC | Alert enrichment / IOC lookup |
| Check_WixhostedDomains | — | SOC | Alert enrichment / IOC lookup |
| DNS Workflow | — | SOC | Alert enrichment / IOC lookup |
| DNS Workflow | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Agent ID - Crowdstrike | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Hash - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - IPDB | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - IP - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - URLScan | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - URL - VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | — | SOC | Alert enrichment / IOC lookup |
| Enrich - Username or Email - Okta | — | SOC | Alert enrichment / IOC lookup |
| Enrich Observable - Email or Username or DisplayName - LDAP | — | SOC | Alert enrichment / IOC lookup |
| Enrich Observable - Sensitive Employees | — | SOC | Alert enrichment / IOC lookup |
| Enrich Observable - VIP Employees | — | SOC | Alert enrichment / IOC lookup |
| Enrich URL with VT | — | SOC | Alert enrichment / IOC lookup |
| Enrich Utility - Email or Username or DisplayName - LDAP | — | SOC | Alert enrichment / IOC lookup |
| Enrich Utility - Email or Username or DisplayName - LDAP | — | SOC | Alert enrichment / IOC lookup |
| Enrich Utility - Email or Username or DisplayName - LDAP - Copy | — | SOC | Alert enrichment / IOC lookup |
| Get runlogs | — | SOC | Alert enrichment / IOC lookup |
| Get URL content stripped | — | SOC | Alert enrichment / IOC lookup |
| Recovery - Enrich non-enriched observables | — | SOC | Alert enrichment / IOC lookup |
| Recovery - Enrich non-enriched observables | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Missing Alert Template Notification | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data copy | — | SOC | Alert enrichment / IOC lookup |
| Subflow - Update Enrichment Data copy | — | SOC | Alert enrichment / IOC lookup |
| Subflow 1 - Extract Observables | — | SOC | Alert enrichment / IOC lookup |
| Subflow 1 - Extract Observables | — | SOC | Alert enrichment / IOC lookup |
| Subflow 1 - Extract Observables | — | SOC | Alert enrichment / IOC lookup |
| Subflow 3 - Enrich Observable | — | SOC | Alert enrichment / IOC lookup |
| Subflow 3 - Enrich Observable | — | SOC | Alert enrichment / IOC lookup |
| Utility - Update all enrichments | — | SOC | Alert enrichment / IOC lookup |
| Utility - Update all enrichments | — | SOC | Alert enrichment / IOC lookup |
| Utility - Update Enrichment | — | SOC | Alert enrichment / IOC lookup |
| Utility - Update Enrichment | — | SOC | Alert enrichment / IOC lookup |
| VIP username validator | — | SOC | Alert enrichment / IOC lookup |
| VT case command | — | SOC | Alert enrichment / IOC lookup |
3. Case Management & SOC Orchestration
Category: SOC
Subcategories: Agentic SOC, Case mgmt & SOAR, Security metrics & reporting
Playbooks: 148 total (45 active)
Total Executions (12mo): 42,191
Wix runs a sophisticated case management automation layer that handles the full case lifecycle: SLA enforcement, assignment routing, escalation, analyst notifications, war room coordination, Jira ticket creation, shift handovers, and automated closure. This is the largest use case by playbook count, reflecting the depth of SOC workflow automation.
Business Value: Automating SLA alerts, assignment changes, and analyst notifications reduces response latency and ensures nothing falls through the cracks. Shift handover automation eliminates manual status compilation at each SOC rotation.
Key Integrations: blink, monday, servicenow, slack, tables
4. Phishing Detection & Response
Category: SOC
Subcategories: Phishing detection & response
Playbooks: 39 total (12 active)
Total Executions (12mo): 528
Wix automates the end-to-end phishing pipeline: email ingestion from Gmail, screenshot enrichment, AI-assisted verdict analysis via a Phishing Verdict Analyst agent, Perception Point integration, and user notification. The Harpy system detects internal PII and data exposure incidents from Slack and other channels.
Business Value: AI-assisted phishing verdict analysis accelerates the most repetitive SOC task — reviewing reported phishing emails. The Harpy integration adds coverage for internal data exposure that traditional email security tools miss.
Key Integrations: google-workspace, microsoft-outlook, perception-point, slack
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Phishing Report Ingest In Gmail CPR-IR | 128 | SOC | Phishing detection & response |
| Harpy Alert Handler | 98 | SOC | Phishing detection & response |
| Harpy Exposed PII | 98 | SOC | Phishing detection & response |
| HP Project main workflow | 38 | SOC | Phishing detection & response |
| Gmail Ingested Alert Enrichment | 34 | SOC | Phishing detection & response |
| 1. Response Main - Phishing | 28 | SOC | Phishing detection & response |
| Phishing Email Verdict | 25 | SOC | Phishing detection & response |
| Create Phishing Overview | 25 | SOC | Phishing detection & response |
| Agent - Phishing Verdict Analyst | 21 | SOC | Phishing detection & response |
| Email Redirection Handler | 15 | SOC | Phishing detection & response |
| Email Redirection Agent | 15 | SOC | Phishing detection & response |
| Send Webform to User copy | 3 | SOC | Phishing detection & response |
| Agent - Email Spam Detector | — | SOC | Phishing detection & response |
| Agent - Phishing Verdict Analyst | — | SOC | Phishing detection & response |
| Create or Update Phishing Email Overview | — | SOC | Phishing detection & response |
| Create or Update Phishing Email Overview | — | SOC | Phishing detection & response |
| Create or Update Phishing Email Overview-1 | — | SOC | Phishing detection & response |
| Harpy Alert Handler | — | SOC | Phishing detection & response |
| Harpy Alerts - Test | — | SOC | Phishing detection & response |
| Harpy API UpdateAlert | — | SOC | Phishing detection & response |
| Harpy API UpdateAlert | — | SOC | Phishing detection & response |
| Harpy Exposed assets (test) | — | SOC | Phishing detection & response |
| Harpy Exposed PII | — | SOC | Phishing detection & response |
| Harpy Generic | — | SOC | Phishing detection & response |
| Harpy Generic | — | SOC | Phishing detection & response |
| Harpy Generic | — | SOC | Phishing detection & response |
| Harpy Slack Watchman | — | SOC | Phishing detection & response |
| Harpy Slack Watchman (Not IN Use) | — | SOC | Phishing detection & response |
| Harpy Watchman Generic | — | SOC | Phishing detection & response |
| Harpy Watchman Generic | — | SOC | Phishing detection & response |
| harpy webhook close cases | — | SOC | Phishing detection & response |
| HP Access Detected | — | SOC | Phishing detection & response |
| Perception Point. - Emails Verdcit | — | SOC | Phishing detection & response |
| Perception Point. - Emails Verdcit | — | SOC | Phishing detection & response |
| Phishing Email Overview Reaction Button | — | SOC | Phishing detection & response |
| Phishing Email Verdict | — | SOC | Phishing detection & response |
| Subflow - Phishing | — | SOC | Phishing detection & response |
| Subflow - Phishing | — | SOC | Phishing detection & response |
| Testing phishing screenshot gmail extractor | — | SOC | Phishing detection & response |
5. EDR Containment & Endpoint Investigation
Category: SOC
Subcategories: EDR containment & response
Playbooks: 48 total (15 active)
Total Executions (12mo): 1,983
When an endpoint is flagged by CrowdStrike Falcon, Blink executes containment and investigation automatically: host isolation, RTR command execution, file download, memory carving via Uptycs, and macOS/Windows forensics collection. K8s workloads are monitored via Cilium for suspicious service account token access.
Business Value: Automated EDR response compresses mean time to contain (MTTC) by executing containment actions the moment an alert fires, without waiting for an analyst to log in.
Key Integrations: crowdstrike, slack
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| CrowdStrike - Run Command on host | 1,078 | SOC | EDR containment & response |
| CS:03 Custom Rules FP | 234 | SOC | EDR containment & response |
| CrowdStrike - Get Host Information | 224 | SOC | EDR containment & response |
| CrowdStrike - Check Host Status | 209 | SOC | EDR containment & response |
| (subflow) SRV Sign | 57 | SOC | EDR containment & response |
| Download histroy files from RTR | 54 | SOC | EDR containment & response |
| CS:02 get all relevant events | 43 | SOC | EDR containment & response |
| Malpack | 30 | SOC | EDR containment & response |
| Rocket - Check If Host Is Online | 20 | SOC | EDR containment & response |
| CrowdStrike - Fetch Files | 19 | SOC | EDR containment & response |
| Reg Save System and SAM | 8 | SOC | EDR containment & response |
| Uptycs carving | 2 | SOC | EDR containment & response |
| Rocket - Uptycs carving | 2 | SOC | EDR containment & response |
| Windows Event Logs Clearing | 2 | SOC | EDR containment & response |
| Initiate forensics collection macOS | 1 | SOC | EDR containment & response |
| AWX-Dumping Pod | — | SOC | EDR containment & response |
| Cilium test | — | SOC | EDR containment & response |
| Cilium: Suspicious K8s Service Account Token Access | — | SOC | EDR containment & response |
| clickfix attack using osascript and curl | — | SOC | EDR containment & response |
| CrowdStrike - Check Host Status | — | SOC | EDR containment & response |
| CrowdStrike - Check Host Status copy | — | SOC | EDR containment & response |
| CrowdStrike - Create a batch session temp | — | SOC | EDR containment & response |
| CrowdStrike - Fetch Files | — | SOC | EDR containment & response |
| CrowdStrike - Get Host Information | — | SOC | EDR containment & response |
| CrowdStrike - Get Host Information copy | — | SOC | EDR containment & response |
| CrowdStrike - Polling Check | — | SOC | EDR containment & response |
| CrowdStrike - Remove Files | — | SOC | EDR containment & response |
| CrowdStrike - Run Command on host | — | SOC | EDR containment & response |
| CrowdStrike Tests | — | SOC | EDR containment & response |
| CS: Obfuscated Remote Script Execution via Curl and Base64 Decoding | — | SOC | EDR containment & response |
| CS:01-Get Similar cases | — | SOC | EDR containment & response |
| CS:01-Get Similar cases | — | SOC | EDR containment & response |
| CS:02 get all relevant events | — | SOC | EDR containment & response |
| CS:03 Custom Rules FP | — | SOC | EDR containment & response |
| CSWinDiag Execution WIP | — | SOC | EDR containment & response |
| Download histroy files from RTR | — | SOC | EDR containment & response |
| Extract browser extensions | — | SOC | EDR containment & response |
| Initiate forensics collection macOS | — | SOC | EDR containment & response |
| MacOS Collector | — | SOC | EDR containment & response |
| macos_forensics_collection | — | SOC | EDR containment & response |
| Rocket - Uptycs carving | — | SOC | EDR containment & response |
| Run RTR on Multiple devices by FQL filter | — | SOC | EDR containment & response |
| Run RTR on Multiple devices by FQL filter | — | SOC | EDR containment & response |
| Subflow - Malware | — | SOC | EDR containment & response |
| Subflow - Malware | — | SOC | EDR containment & response |
| Uptycs carving | — | SOC | EDR containment & response |
| Uptycs integration test | — | SOC | EDR containment & response |
| Windows Automatic Collection | — | SOC | EDR containment & response |
6. Secrets & Code Security
Category: GRC
Subcategories: DevSecOps compliance
Playbooks: 6 total (3 active)
Total Executions (12mo): 212
TruffleHog scans repositories for exposed secrets and credentials. When a secret is detected, Blink automatically creates a case, collects webhook callback data, and orchestrates the response workflow. GitHub repository monitoring tracks new repositories and content for security review.
Business Value: Automated secrets detection and response prevents credential exposure from becoming a breach, closing the gap between code commit and security review.
Key Integrations: splunk
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Truffelhog Execution | 172 | GRC | DevSecOps compliance |
| trufflehog was detected | 21 | GRC | DevSecOps compliance |
| TruffleHog Execution - Webhook Callback | 19 | GRC | DevSecOps compliance |
| Github check repo created | — | GRC | DevSecOps compliance |
| Github query | — | GRC | DevSecOps compliance |
| Truffelhog Execution - backup | — | GRC | DevSecOps compliance |
7. Vulnerability Management
Category: Vulnerability Mgmt
Subcategories: CVE lookup & remediation, Vuln lifecycle prioritize & ticket, Vuln scanning ingest & report
Playbooks: 14 total (7 active)
Total Executions (12mo): 1,019
Wix tracks vulnerability exposure across multiple dimensions: Upwind-sourced CVE detections are triaged by an AI CVE Agent, SBOM data is queried via Trino for dependency analysis, HackerOne bug bounty findings are ingested and processed, Nuclei regression scans validate security controls, and critical vulnerability artifacts are queried from Splunk.
Business Value: AI-assisted CVE triage (CVE Agent) and SBOM-based vulnerability analysis provide modern, context-aware vulnerability prioritization beyond traditional CVSS scoring.
Key Integrations: gmail, slack, splunk
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Vuln_artifact_Critical | 522 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| HackerOne test | 141 | Vulnerability Mgmt | Vuln scanning ingest & report |
| CVE Upwind detection | 117 | Vulnerability Mgmt | CVE lookup & remediation |
| CVE Agent | 98 | Vulnerability Mgmt | CVE lookup & remediation |
| Query SBOM by Trino | 97 | Vulnerability Mgmt | CVE lookup & remediation |
| Nuclei Regression Results | 39 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Root CA Certificate was added via CLI | 5 | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| CVE Agent | — | Vulnerability Mgmt | CVE lookup & remediation |
| PaloAlto non WixIP | — | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| PaloAlto non WixIP | — | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Query SBOM by Trino | — | Vulnerability Mgmt | CVE lookup & remediation |
| Query SBOM by Trino v2 | — | Vulnerability Mgmt | CVE lookup & remediation |
| Trino test | — | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
| Vuln_artifact_Critical | — | Vulnerability Mgmt | Vuln lifecycle prioritize & ticket |
8. Cloud Security & IaC Governance
Category: Cloud Security
Subcategories: CSPM ingest & triage, Cloud access & SaaS policy mgmt, Cloud asset coverage & inventory, Cloud provisioning & IaC automation
Playbooks: 18 total (6 active)
Total Executions (12mo): 139
AWS GuardDuty alerts are ingested and automatically investigated. An AI agent conducts cloud asset inventory assessments. Public S3 bucket exposure triggers a justification workflow, Terraform break-glass access is governed and audited, PaloAlto firewall anomalies are detected, and AWS KMS encryption anomalies are flagged.
Business Value: AI agent-driven cloud inventory assessment is a forward-looking capability that reduces the manual burden of cloud asset reviews. GuardDuty integration ensures cloud threat signals reach the SOC at machine speed.
Key Integrations: github, slack, splunk, whois
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Cloud inventory workflow with Agent | 103 | Cloud Security | Cloud asset coverage & inventory |
| AWS GD workflow | 29 | Cloud Security | CSPM ingest & triage |
| Public S3 Bucket justification | 4 | Cloud Security | CSPM ingest & triage |
| AWS: Encryption or Decryption of objects on from unknown entity with unrelated keys | 1 | Cloud Security | CSPM ingest & triage |
| Terraform_live_infra_provisioning_break_the_glass | 1 | Cloud Security | Cloud provisioning & IaC automation |
| Block domain on Island | 1 | Cloud Security | Cloud access & SaaS policy mgmt |
| Agent - Guardduty Investigator | — | Cloud Security | CSPM ingest & triage |
| AWS CLI Persistent Token Access | — | Cloud Security | CSPM ingest & triage |
| AWS GD workflow | — | Cloud Security | CSPM ingest & triage |
| AWS New Subnet Created in Production Account | — | Cloud Security | Cloud provisioning & IaC automation |
| AWS SIR | — | Cloud Security | CSPM ingest & triage |
| AWS TH Generic details | — | Cloud Security | CSPM ingest & triage |
| AWS TH: IAM User Usage from Non Wix Address | — | Cloud Security | CSPM ingest & triage |
| GD Flow | — | Cloud Security | CSPM ingest & triage |
| GD Flow | — | Cloud Security | CSPM ingest & triage |
| GuardDuty | — | Cloud Security | CSPM ingest & triage |
| GuardDuty Suspicious Domain Requests | — | Cloud Security | CSPM ingest & triage |
| Terraform_live_infra_provisioning_break_the_glass | — | Cloud Security | Cloud provisioning & IaC automation |
9. Identity & Access Management
Category: IAM
Subcategories: Access review & group mgmt, Employee onboarding, Identity lifecycle automation, Identity sync & directory mgmt, Password & credential lifecycle, Privileged account mgmt
Playbooks: 15 total (5 active)
Total Executions (12mo): 162
Identity events — manual user creation, Okta identity operations, Kerberos keytab access, DUO MFA anomalies, CLI-based account manipulation, and group synchronization — are detected and responded to automatically. Vault access requires user confirmation before secrets are revealed.
Business Value: Detecting manual user creation and CLI-based account changes catches identity-based attacks that bypass standard IAM provisioning workflows.
Key Integrations: google-workspace, slack, splunk
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Okta | 75 | IAM | Identity sync & directory mgmt |
| User Created Manually | 62 | IAM | Employee onboarding |
| Mac New User was Create/Delete via CLI | 13 | IAM | Identity lifecycle automation |
| Run KGB Groups Sync | 6 | IAM | Access review & group mgmt |
| vault user confirmation | 6 | IAM | Password & credential lifecycle |
| Azure Reset user password | — | IAM | Password & credential lifecycle |
| Block IP | — | IAM | Identity lifecycle automation |
| Duo MFA Validation - WIP | — | IAM | Password & credential lifecycle |
| DUO Multiple Push to the same User | — | IAM | Password & credential lifecycle |
| DUO Multiple Push to the same User | — | IAM | Password & credential lifecycle |
| Google Workspace Suspicious User | — | IAM | Identity sync & directory mgmt |
| User accessed Kerberos Keytab | — | IAM | Privileged account mgmt |
| User Created Manually | — | IAM | Employee onboarding |
| User DataModel query (KZ) | — | IAM | Identity lifecycle automation |
| vault user confirmation | — | IAM | Password & credential lifecycle |
10. Compliance & GRC
Category: GRC
Subcategories: Compliance questionnaire, DevSecOps compliance, PCI & regulatory monitoring, Security metrics & reporting
Playbooks: 21 total (12 active)
Total Executions (12mo): 560
Wix enforces PCI compliance edge cases, monitors for SQL syntax errors that may indicate injection attempts, sends compliance questionnaire reminders via case management, and imports anomaly tracking data. The SQL monitoring pipeline uses AI gateway integration for intelligent anomaly analysis.
Business Value: AI-assisted SQL anomaly investigation (via Call AiGateway) adds intelligence to what would otherwise be a noisy, false-positive-heavy alert category.
Key Integrations: '{{steps, google-sheets, mysql, slack, splunk
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| PCI Edge-case Handler | 134 | GRC | PCI & regulatory monitoring |
| SQL Syntax Error Detected | 62 | GRC | DevSecOps compliance |
| Error logs workflow | 50 | GRC | Security metrics & reporting |
| (subflow) get sql systax errors - previously investigated | 50 | GRC | DevSecOps compliance |
| (subflow) SQL syntax errors from Splunk | 50 | GRC | DevSecOps compliance |
| (subflow) Get Artifact Info | 50 | GRC | Security metrics & reporting |
| Handle SQL Syntax Errors Alert | 50 | GRC | DevSecOps compliance |
| (subflow) Call AiGateway | 49 | GRC | Security metrics & reporting |
| Questionnaire_Reminder | 19 | GRC | Compliance questionnaire |
| Questionnaire_Task_case_manager | 19 | GRC | Compliance questionnaire |
| Questionnaire_Reminder | 19 | GRC | Compliance questionnaire |
| SQL Syntax Error Detected - slack | 8 | GRC | DevSecOps compliance |
| (subflow) clickhouse find SQL syntax Errors | — | GRC | DevSecOps compliance |
| (subflow) clickhouse find SQL syntax Errors | — | GRC | DevSecOps compliance |
| (subflow) Get Artifact Info | — | GRC | Security metrics & reporting |
| (subflow) get sql systax errors - previously investigated | — | GRC | DevSecOps compliance |
| (subflow) SQL syntax errors from Splunk | — | GRC | DevSecOps compliance |
| manual - import sql_syntaxt_error_tracking Sheet | — | GRC | DevSecOps compliance |
| manual - import sql_syntaxt_error_tracking Sheet | — | GRC | DevSecOps compliance |
| PCI Edge-case Handler | — | GRC | PCI & regulatory monitoring |
| SQL Syntax Error Detected | — | GRC | DevSecOps compliance |
11. Platform Health & Automation Monitoring
Category: Other
Subcategories: IT/OT & network infra monitoring, SaaS / IT administration
Playbooks: 21 total (6 active)
Total Executions (12mo): 15,787
Blink automation runners are monitored for health and performance: runner sanity checks, ingestion failure alerts, execution rate limiting alerts, and unauthorized integration approvals are all automated. This infrastructure layer ensures Wix's 400+ automation workflows remain reliable.
Business Value: Automating the monitoring of the automation platform itself creates a self-healing SOC infrastructure that alerts on its own failures before they impact alert coverage.
Key Integrations: crowdstrike, github, gmail, google-workspace, ip-api, monday, slack, splunk, uptycs
| Playbook | Executions (12mo) | Category | Subcategory |
|---|---|---|---|
| Tag automation is running limit alert | 9,713 | Other | IT/OT & network infra monitoring |
| Runner Sanity Check | 1,928 | Other | IT/OT & network infra monitoring |
| Periodic Runner Sanity test | 1,927 | Other | IT/OT & network infra monitoring |
| Ingestion General Failure Alert | 1,887 | Other | IT/OT & network infra monitoring |
| Ingestion Runner Failure Alert | 191 | Other | IT/OT & network infra monitoring |
| Unapprove Integrations | 141 | Other | IT/OT & network infra monitoring |
| 3d workflow | — | Other | SaaS / IT administration |
| Benjamin Work Flow Test | — | Other | SaaS / IT administration |
| Blink Agent Playground | — | Other | SaaS / IT administration |
| changed name | — | Other | SaaS / IT administration |
| Clear Env | — | Other | SaaS / IT administration |
| daniel-test cprlib | — | Other | SaaS / IT administration |
| Getting Started - Example from Idan | — | Other | SaaS / IT administration |
| Getting Started - Hello World | — | Other | SaaS / IT administration |
| Getting Started - Hello World | — | Other | SaaS / IT administration |
| Getting Started - Hello World | — | Other | SaaS / IT administration |
| Idan test workflow for testing | — | Other | SaaS / IT administration |
| Query IP | — | Other | SaaS / IT administration |
| shiran test - reporting | — | Other | SaaS / IT administration |
| Test runner v2 | — | Other | IT/OT & network infra monitoring |
| Test workflow Test II workspace | — | Other | SaaS / IT administration |
Key Observations
Strengths
Mature, high-scale SIEM automation. With 52,804 Splunk ingestion events and a fully automated alert processing pipeline (Process Alert - v9), Wix has industrialized its alert handling. The pipeline covers observable extraction, enrichment, deduplication, case creation, SLA tracking, and closure — all without analyst intervention at the triage layer.
Identity-aware enrichment. The enrichment pipeline specifically flags VIP and sensitive employees across all alert types. This context-sensitive enrichment (via LDAP, Okta, and internal VIP lists) enables risk-weighted triage that most SOCs implement only as a manual step.
AI agent adoption. Wix is deploying AI agents for multiple security workflows: cloud asset inventory, phishing verdict analysis, CVE enrichment, and GuardDuty investigation. With 103 cloud inventory assessments and 21 AI-assisted phishing verdicts, Wix is an early operator of agentic security automation.
Comprehensive EDR response. The CrowdStrike integration covers the full response lifecycle: host status check, RTR command execution, file download, process termination, and session management. This automation executed 1,078 endpoint actions in 12 months — work that would otherwise require manual analyst effort.
Harpy internal exposure detection. The Harpy use case (98 active executions) monitors internal Slack and platform activity for PII and data exposure — a security domain that most organizations leave unmonitored. This reflects a mature data loss prevention posture.
Gaps & Opportunities
314 inactive playbooks (69% of total). A significant portion of the playbook library has not executed in 12 months. Many are duplicates across workspaces or development drafts, but a systematic review and decommission would reduce maintenance overhead and clarify the active automation footprint.
Phishing response volume is low relative to pipeline investment. While the phishing pipeline (Perception Point, Gmail, Harpy, AI agent) is technically sophisticated, only 28 phishing incidents received a full automated response. Increasing analyst adoption or lowering the confidence threshold for automated response would improve ROI on this investment.
Cloud security coverage is developing. With 139 total executions across 6 active cloud playbooks, cloud security automation is nascent relative to SOC coverage. Expanding AWS GuardDuty alert handling, adding CSPM integration, and operationalizing the cloud inventory AI agent at higher frequency would strengthen the cloud posture.
IAM automation is limited. Only 162 executions across 5 active IAM playbooks indicates that identity lifecycle events (onboarding, offboarding, access reviews) are not yet fully automated. This is a high-value expansion area, particularly given Wix's scale.
Integration Ecosystem
| Integration | Primary Use Case |
|---|---|
| Splunk | SIEM alert ingestion, vulnerability artifact queries, Falcon data sync |
| CrowdStrike Falcon | EDR containment, host investigation, RTR command execution |
| Slack | SOC notifications, analyst approvals, shift handovers, war room |
| LDAP | User/identity enrichment for alert observables |
| Okta | Identity enrichment and access verification |
| VirusTotal | IP, URL, and file hash threat intelligence |
| Jira | Security ticket creation and tracking |
| Monday.com | SOP link retrieval for case response |
| Perception Point | Phishing email scanning and verdict |
| Uptycs | Endpoint memory carving and forensics |
| Upwind | CVE detection and cloud workload context |
| HackerOne | Bug bounty finding ingestion |
| AbuseIPDB / URLScan / WHOIS | IOC enrichment and domain analysis |
| Gmail / Google Workspace | Phishing report ingestion, user suspension |
| GitHub | Repository monitoring and secrets detection support |
| MySQL / Trino | SBOM and internal data queries |
| ServiceNow | Ticket and record search |
| Axonius | Asset inventory enrichment |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Wix | artemis | artemis | 2026-08-10 |