SOAR
What is SOAR?
SOARA platform that automates and orchestrates SOC workflows by chaining detections, enrichments and response actions into playbooks executed across security tools.
Gartner coined Security Orchestration, Automation and Response (SOAR) in 2017 to name a converging class of tools that merged security orchestration and automation, security incident-response platforms (SIRP), and threat-intelligence platforms (TIP). SOAR sits alongside the SIEM and EDR/XDR to operationalize response: it uses connectors and REST APIs to query threat intelligence, IAM, endpoint, network and ticketing systems, then runs codified playbooks that triage alerts, enrich indicators, contain hosts, disable accounts and document the case.
The value is measurable. By automating repeatable steps — sandbox detonation, reputation lookups, host isolation — SOAR slashes mean time to respond (MTTR) and enforces consistent process, while human approval gates guard high-risk actions such as account lockout or firewall changes. Well-designed playbooks are idempotent and log every step for audit. Common platforms include Splunk SOAR (formerly Phantom), Palo Alto Cortex XSOAR (formerly Demisto), Microsoft Sentinel automation rules, Swimlane and Tines. Since ~2024 Gartner has folded standalone SOAR into broader SecOps and "hyperautomation" categories, but the playbook-driven pattern remains the backbone of scalable detection-and-response programs.
flowchart TD
A[Alert from SIEM or EDR] --> B[SOAR ingests and dedupes]
B --> C[Playbook enriches: TI, WHOIS, sandbox]
C --> D{Malicious?}
D -->|No| E[Close as false positive]
D -->|Yes| F{High-risk action?}
F -->|No| G[Auto-contain: isolate host, block IOC]
F -->|Yes| H[Analyst approval gate]
H --> G
G --> I[Log case and update ticket]● Examples
- 01
A phishing-triage playbook that detonates URLs in a sandbox, queries VirusTotal and quarantines the email.
- 02
An XSOAR playbook that isolates a host in EDR and resets the user's password when ransomware behaviour is detected.
● Frequently asked questions
What is SOAR?
A platform that automates and orchestrates SOC workflows by chaining detections, enrichments and response actions into playbooks executed across security tools. It belongs to the Defense & Operations category of cybersecurity.
What does SOAR mean?
A platform that automates and orchestrates SOC workflows by chaining detections, enrichments and response actions into playbooks executed across security tools.
How do you defend against SOAR?
Defences for SOAR typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for SOAR?
Common alternative names include: Security Orchestration, Automation and Response.