{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/soar","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/soar/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/soar/"},"term":{"en":"SOAR","da":"SOAR"},"aka":{"en":["security orchestration","automation and response"],"da":["security orchestration","automation and response"]},"domain":["security"],"cluster":"security-operations","status":"current","era":2017,"summary":{"en":"A platform that ties a security team's tools together and runs the routine steps of handling an alarm by itself.","da":"En platform, der binder sikkerhedsteamets værktøjer sammen og selv udfører de faste trin i håndteringen af en alarm."},"body":{"formal":{"en":"Software that receives alarms, mostly from a SIEM, and runs stored step-by-step plans across other tools, such as looking up an address in threat intelligence, locking an account or isolating a laptop, while keeping one case record for the analysts.","da":"Software, der modtager alarmer, oftest fra en SIEM, og kører gemte trin-for-trin-forløb på tværs af andre værktøjer, fx slår en adresse op i threat intelligence, spærrer en konto eller isolerer en bærbar, mens den fører én samlet sag for analytikerne."},"plain":{"en":"Like a kitchen where the prep cook does all the chopping and measuring from the recipe, so the chef only has to make the real decisions.","da":"Som et køkken, hvor kokkeassistenten klarer alt forarbejdet efter opskriften, så kokken kun skal træffe de egentlige beslutninger."},"inPractice":{"en":"When a clerk at a municipality reports a phishing email, SOAR pulls out the links, checks them against known bad sites, deletes the same email from every inbox and hands the analyst a finished summary.","da":"Når en sagsbehandler i en kommune melder en phishing-mail, trækker SOAR linkene ud, tjekker dem mod kendte skadelige sider, sletter den samme mail fra alle indbakker og giver analytikeren et færdigt sammendrag."},"whyItMatters":{"en":"Teams get far more alarms than people can handle by hand; taking the routine steps off their hands answers attacks in minutes instead of hours.","da":"Teams får langt flere alarmer, end mennesker kan klare i hånden; når de faste trin klares automatisk, besvares angreb på minutter i stedet for timer."}},"deepDive":{"en":"The term SOAR was popularised by Gartner around 2017 to describe the convergence of three earlier product categories: security orchestration and automation, security incident response platforms (case management) and threat-intelligence platforms. A SOAR platform has four core components: integrations (connectors wrapping the APIs of SIEM, EDR, email, identity, firewall, ticketing and threat-intelligence tools), playbooks (workflows of actions, conditions, loops and human approval steps, usually built in a visual editor or as code), a case management layer that records artefacts, tasks, evidence and timelines, and metrics reporting. Well-known products include Splunk SOAR (formerly Phantom), Palo Alto Networks Cortex XSOAR (formerly Demisto), and Microsoft Sentinel's automation rules and Logic Apps playbooks; newer tools such as Tines market themselves as general security automation platforms.\n\nA typical playbook for a reported phishing email parses the message, extracts observables (sender, URLs, attachments, hashes), queries reputation services and sandbox detonation, searches the mail platform for other recipients, and branches: benign verdicts are closed with a reply to the reporter, while malicious verdicts trigger purging of the message from all mailboxes, blocking of indicators and, after analyst approval, containment such as disabling the account or isolating the endpoint. OASIS's CACAO Security Playbooks specification (version 2.0, 2023) defines a vendor-neutral JSON format for describing and exchanging such playbooks, though adoption in commercial products is still limited.\n\nThe design principle that matters most is graduated automation. Enrichment and deduplication are safe to automate fully; reversible containment (quarantining a file, forcing a password reset) can often be automated for high-confidence detections; disruptive or irreversible actions (disabling an executive's account, isolating a production server, blocking a cloud provider's IP range) should require a human decision. Automating actions on top of noisy detections scales false positives into outages, so playbook quality is bounded by detection quality.\n\nSOAR introduces its own risks. The platform stores API credentials with broad privileges across the security stack, making it a high-value target that needs strict access control, secrets management, change control on playbooks and audit logging of its own actions. Playbooks decay silently when connected APIs change, so they need testing like code. SOAR differs from a SIEM, which collects and correlates events to raise alerts, whereas SOAR acts on those alerts; the categories are converging as SIEM and XDR platforms build in automation, and AI assistants are increasingly used for enrichment and summarisation within these workflows, which calls for the same approval gates as any other automated action.","da":"Betegnelsen SOAR blev gjort udbredt af Gartner omkring 2017 for at beskrive sammensmeltningen af tre tidligere produktkategorier: security orchestration and automation, platforme til hændelseshåndtering (sagsstyring) og platforme til threat intelligence. En SOAR-platform har fire kernekomponenter: integrationer (connectors, der pakker API'erne til SIEM, EDR, mail, identitet, firewall, ticketsystemer og threat intelligence-værktøjer ind), playbooks (arbejdsgange af handlinger, betingelser, løkker og menneskelige godkendelsestrin, som regel bygget i en visuel editor eller som kode), et lag til sagsstyring, der registrerer artefakter, opgaver, beviser og tidslinjer, samt rapportering af nøgletal. Kendte produkter er Splunk SOAR (tidligere Phantom), Palo Alto Networks Cortex XSOAR (tidligere Demisto) og Microsoft Sentinels automation rules og Logic Apps-playbooks; nyere værktøjer som Tines markedsfører sig som generelle platforme til sikkerhedsautomatisering.\n\nEn typisk playbook for en indberettet phishing-mail parser beskeden, trækker observationer ud (afsender, URL'er, vedhæftninger, hashes), spørger omdømmetjenester og sandbox-detonering, søger i mailplatformen efter andre modtagere og forgrener sig: godartede vurderinger lukkes med et svar til indberetteren, mens ondsindede vurderinger udløser fjernelse af mailen fra alle postkasser, blokering af indikatorer og, efter godkendelse fra en analytiker, inddæmning som at spærre kontoen eller isolere endpointet. OASIS' specifikation CACAO Security Playbooks (version 2.0, 2023) definerer et leverandørneutralt JSON-format til at beskrive og udveksle sådanne playbooks, men udbredelsen i kommercielle produkter er stadig begrænset.\n\nDet vigtigste designprincip er graduering af automatiseringen. Berigelse og deduplikering kan trygt automatiseres fuldt ud; reversibel inddæmning (karantæne af en fil, tvungen nulstilling af en adgangskode) kan ofte automatiseres ved detektioner med høj konfidens; forstyrrende eller irreversible handlinger (spærring af en direktørs konto, isolering af en produktionsserver, blokering af en cloududbyders IP-interval) bør kræve en menneskelig beslutning. Automatiserede handlinger oven på støjende detektioner skalerer falske positiver op til nedbrud, så kvaliteten af en playbook er begrænset af kvaliteten af detektionen.\n\nSOAR medfører sine egne risici. Platformen gemmer API-nøgler med brede rettigheder på tværs af hele sikkerhedsstakken og er derfor et mål af høj værdi, der kræver streng adgangskontrol, håndtering af hemmeligheder, ændringsstyring af playbooks og auditlogning af platformens egne handlinger. Playbooks forfalder i stilhed, når de tilkoblede API'er ændrer sig, så de skal testes som kode. SOAR adskiller sig fra en SIEM, der indsamler og korrelerer hændelser for at rejse alarmer, mens SOAR handler på de alarmer; kategorierne smelter sammen, efterhånden som SIEM- og XDR-platforme bygger automatisering ind, og AI-assistenter bruges i stigende grad til berigelse og opsummering i disse arbejdsgange, hvilket kræver de samme godkendelsestrin som enhver anden automatiseret handling."},"edges":[{"type":"requires","to":"security/siem","confidence":"high","strength":"normal"},{"type":"requires","to":"security/alert-triage","confidence":"high","strength":"normal"},{"type":"kind-of","to":"security/control","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/soc","why":{"en":"The SOC's analysts use SOAR to handle routine alarms automatically and spend their time on the hard cases.","da":"SOC'ens analytikere bruger SOAR til at håndtere rutinealarmer automatisk og bruge deres tid på de svære sager."},"confidence":"high","strength":"primary"}],"depth":3,"sources":[{"title":"Wikipedia - Security orchestration, automation and response","url":"https://en.wikipedia.org/wiki/Security_orchestration,_automation_and_response","tier":"reference"},{"title":"NIST SP 800-61 Rev. 3 - Incident Response Recommendations and Considerations for Cybersecurity Risk Management","url":"https://doi.org/10.6028/NIST.SP.800-61r3","tier":"standard","publisher":"NIST"}],"draft":true}