SOAR
Security Orchestration, Automation and Response — automating security operations.
Term
description · examples · notesSecurity Orchestration, Automation and Response — automating security operations.
Description
Integrates SIEM, EDR, firewall, and ticketing systems into one platform.
Automates alert triage, data enrichment, and initial response.
Playbooks define standard procedures for each incident type.
Reduces mean time to respond (MTTR) and offloads SOC analysts from repetitive tasks.
What people often say
- SOAR does not replace analysts — it automates routine tasks so they handle complex ones.
- Effectiveness depends on playbook quality, not the platform itself.
Covers / does not cover
Covers
- Automated triage and response
- Integration of multiple security tools
- Standardized incident playbooks
Does not cover
- Threat detection (that is SIEM/EDR)
- Attack prevention
- Forensic analysis of complex incidents
Mentioned in the news
Threats
reduces 3Threats it reduces. Select one to open its page.
Techniques
neutralizes 4Techniques it neutralizes. Select one to open its page.