GlossarySOC and monitoring

SOAR

Short answer

SOAR (Security Orchestration, Automation and Response) is technology that connects security tools and automates repetitive investigation and response tasks through playbooks, so that a security team can handle more alerts, faster and in a consistent way.

What it automates

A playbook is a predefined sequence of steps for a type of alert. For a suspected phishing email, a SOAR can extract the links and attachments, check them against threat intelligence sources, search for the same message in other mailboxes, delete it and open a ticket, all in seconds. For a compromised account, it can disable the user, revoke active sessions and notify the analyst.

SOAR and SIEM

A SIEM collects data and raises alerts. A SOAR acts on those alerts. Many modern platforms combine both, and XDR products often include automated response for their own tools.

Limits

Automation is only as good as the playbooks behind it. Poorly designed rules can disable the wrong account or flood teams with tickets. Most organisations automate enrichment and low risk actions first, and keep a person deciding on actions with business impact.

Why it matters

Automation shortens the time to respond, which limits the damage of an attack, and frees analysts for real investigation. It is one of the reasons a SOC or MDR provider can cover many companies efficiently. Automated, documented actions also support the incident response evidence auditors ask for.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub