Glossary / Security

SOAR

Security Orchestration, Automation, and Response refers to technologies that enable organizations to automate the response to security threats, coordinating tasks across people and tools to respond faster.

Speed is Critical

The average "dwell time" (time attackers spend in a network before detection) is dropping, but the "breakout time" (time to move laterally) is now under 1 hour. SOAR allows defenders to execute containment actions in seconds, not hours.

The Three Pillars

1. Orchestration

Connecting disparate security tools (Anti-virus, Firewalls, SIEM, User Directory) through APIs. Orchestration acts as the "glue" that allows these tools to talk to each other.

2. Automation

Executing defined tasks without human intervention. These are often organized into "Playbooks".

3. Response

Managing the lifecycle of the incident. This includes case management, ticketing, and collaboration tools for analysts to track the remediation.

Example Playbook: Phishing Response

Without SOAR, analyzing a reported phishing email takes an analyst 15-30 minutes. With SOAR:

  1. Ingest: User reports email via Outlook plugin.
  2. Parse: SOAR extracts URLs, attachments, and sender IP.
  3. Enrich: URLs are checked against reputation services. Attachments are detonated in a sandbox.
  4. Decision: If malicious, SOAR deletes the email from all user inboxes across the company.
  5. Notify: SOAR emails the reporting user: "Thank you, this was malicious and has been neutralized."

Total Time: 45 seconds. Analyst Time: 0 seconds.

SOAR vs. SIEM

Function SIEM SOAR
Primary Goal Detection & Logging Response & Remediation
Input Massive volume of logs Alerts & Incidents
Human Role Reviewing alerts Building playbooks

Alterra's Expertise

Building effective SOAR capability requires more than just buying a tool; it requires deep understanding of the organization's workflows. Alterra solutions helps enterprises design custom integrations and rigorous playbooks that balance automation speed with operational safety.

Related Terms