Skip to content

SOAR (Security Orchestration, Automation, and Response)

Definition

A platform that receives alerts from the SIEM and other sources, executes automated playbooks to enrich and triage them, and integrates with downstream tools to take containment actions or open case tickets without manual analyst intervention.

Full form
Security Orchestration, Automation, and Response
Input source
Alerts from SIEM and other tools
Core actions
Enrichment, triage, containment
Integration point
Downstream case-ticketing tools

Common questions

What does 'enrichment' mean in a SOAR workflow?+

Enrichment is the automated step where the platform pulls additional context around an alert, such as looking up an IP's reputation, checking a file hash against threat intelligence feeds, or pulling asset ownership data, so an analyst sees a fuller picture without doing each lookup manually.

Can SOAR open a case ticket without an analyst involved?+

Yes, that is one of its defined uses. A playbook can be configured to automatically create or update a ticket in a case-management system once triage criteria are met, keeping the incident record current even before a human analyst picks up the alert.

Is SOAR the same product as the SIEM it receives alerts from?+

No, they are typically separate platforms that integrate together. The SIEM's job is detection and correlation of events; SOAR's job is orchestrating the response workflow across the SIEM and other security tools once an alert has been raised.

Related terms

EDR (Endpoint Detection and Response)
An agent-based security tool deployed on individual endpoints (workstations, servers, mobile devices) that monitors process execution, file changes, network connections, and registry...
MTTD / MTTR
Mean Time to Detect and Mean Time to Respond: the two primary operational KPIs for a SOC. MTTD measures the gap between...
SIEM (Security Information and Event Management)
A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...
STIX / TAXII
Structured Threat Information eXpression (STIX) is a standardised language for describing threat intelligence objects. Trusted Automated eXchange of Intelligence Information (TAXII) is...
Threat Intelligence Platform (TIP)
A system that ingests indicator feeds from external providers and internal sources, deduplicates and scores them, and exports curated indicators of compromise...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.