{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://atlas.maintz.dev/)"},"id":"security/soar","url":{"en":"https://atlas.maintz.dev/en/terms/security/soar/","da":"https://atlas.maintz.dev/da/terms/security/soar/"},"term":{"en":"SOAR","da":"SOAR"},"aka":{"en":["security orchestration","automation and response"],"da":["security orchestration","automation and response"]},"domain":["security"],"cluster":"security-operations","status":"current","era":2017,"summary":{"en":"A platform that ties a security team's tools together and runs the routine steps of handling an alarm by itself.","da":"En platform, der binder sikkerhedsteamets værktøjer sammen og selv udfører de faste trin i håndteringen af en alarm."},"body":{"formal":{"en":"Software that receives alarms, mostly from a SIEM, and runs stored step-by-step plans across other tools, such as looking up an address in threat intelligence, locking an account or isolating a laptop, while keeping one case record for the analysts.","da":"Software, der modtager alarmer, oftest fra en SIEM, og kører gemte trin-for-trin-forløb på tværs af andre værktøjer, fx slår en adresse op i threat intelligence, spærrer en konto eller isolerer en bærbar, mens den fører én samlet sag for analytikerne."},"plain":{"en":"Like a kitchen where the prep cook does all the chopping and measuring from the recipe, so the chef only has to make the real decisions.","da":"Som et køkken, hvor kokkeassistenten klarer alt forarbejdet efter opskriften, så kokken kun skal træffe de egentlige beslutninger."},"inPractice":{"en":"When a clerk at a municipality reports a phishing email, SOAR pulls out the links, checks them against known bad sites, deletes the same email from every inbox and hands the analyst a finished summary.","da":"Når en sagsbehandler i en kommune melder en phishing-mail, trækker SOAR linkene ud, tjekker dem mod kendte skadelige sider, sletter den samme mail fra alle indbakker og giver analytikeren et færdigt sammendrag."},"whyItMatters":{"en":"Teams get far more alarms than people can handle by hand; taking the routine steps off their hands answers attacks in minutes instead of hours.","da":"Teams får langt flere alarmer, end mennesker kan klare i hånden; når de faste trin klares automatisk, besvares angreb på minutter i stedet for timer."}},"deepDive":{"en":"The term SOAR was popularised by Gartner around 2017 to describe the convergence of three earlier product categories: security orchestration and automation, security incident response platforms (case management) and threat-intelligence platforms. A SOAR platform has four core components: integrations (connectors wrapping the APIs of SIEM, EDR, email, identity, firewall, ticketing and threat-intelligence tools), playbooks (workflows of actions, conditions, loops and human approval steps, usually built in a visual editor or as code), a case management layer that records artefacts, tasks, evidence and timelines, and metrics reporting. Well-known products include Splunk SOAR (formerly Phantom), Palo Alto Networks Cortex XSOAR (formerly Demisto), and Microsoft Sentinel's automation rules and Logic Apps playbooks; newer tools such as Tines market themselves as general security automation platforms.\n\nA typical playbook for a reported phishing email parses the message, extracts observables (sender, URLs, attachments, hashes), queries reputation services and sandbox detonation, searches the mail platform for other recipients, and branches: benign verdicts are closed with a reply to the reporter, while malicious verdicts trigger purging of the message from all mailboxes, blocking of indicators and, after analyst approval, containment such as disabling the account or isolating the endpoint. OASIS's CACAO Security Playbooks specification (version 2.0, 2023) defines a vendor-neutral JSON format for describing and exchanging such playbooks, though adoption in commercial products is still limited.\n\nThe design principle that matters most is graduated automation. Enrichment and deduplication are safe to automate fully; reversible containment (quarantining a file, forcing a password reset) can often be automated for high-confidence detections; disruptive or irreversible actions (disabling an executive's account, isolating a production server, blocking a cloud provider's IP range) should require a human decision. Automating actions on top of noisy detections scales false positives into outages, so playbook quality is bounded by detection quality.\n\nSOAR introduces its own risks. The platform stores API credentials with broad privileges across the security stack, making it a high-value target that needs strict access control, secrets management, change control on playbooks and audit logging of its own actions. Playbooks decay silently when connected APIs change, so they need testing like code. SOAR differs from a SIEM, which collects and correlates events to raise alerts, whereas SOAR acts on those alerts; the categories are converging as SIEM and XDR platforms build in automation, and AI assistants are increasingly used for enrichment and summarisation within these workflows, which calls for the same approval gates as any other automated action.","da":"Betegnelsen SOAR blev gjort udbredt af Gartner omkring 2017 for at beskrive sammensmeltningen af tre tidligere produktkategorier: security orchestration and automation, platforme til hændelseshåndtering (sagsstyring) og platforme til threat intelligence. En SOAR-platform har fire kernekomponenter: integrationer (connectors, der pakker API'erne til SIEM, EDR, mail, identitet, firewall, ticketsystemer og threat intelligence-værktøjer ind), playbooks (arbejdsgange af handlinger, betingelser, løkker og menneskelige godkendelsestrin, som regel bygget i en visuel editor eller som kode), et lag til sagsstyring, der registrerer artefakter, opgaver, beviser og tidslinjer, samt rapportering af nøgletal. Kendte produkter er Splunk SOAR (tidligere Phantom), Palo Alto Networks Cortex XSOAR (tidligere Demisto) og Microsoft Sentinels automation rules og Logic Apps-playbooks; nyere værktøjer som Tines markedsfører sig som generelle platforme til sikkerhedsautomatisering.\n\nEn typisk playbook for en indberettet phishing-mail parser beskeden, trækker observationer ud (afsender, URL'er, vedhæftninger, hashes), spørger omdømmetjenester og sandbox-detonering, søger i mailplatformen efter andre modtagere og forgrener sig: godartede vurderinger lukkes med et svar til indberetteren, mens ondsindede vurderinger udløser fjernelse af mailen fra alle postkasser, blokering af indikatorer og, efter godkendelse fra en analytiker, inddæmning som at spærre kontoen eller isolere endpointet. OASIS' specifikation CACAO Security Playbooks (version 2.0, 2023) definerer et leverandørneutralt JSON-format til at beskrive og udveksle sådanne playbooks, men udbredelsen i kommercielle produkter er stadig begrænset.\n\nDet vigtigste designprincip er graduering af automatiseringen. Berigelse og deduplikering kan trygt automatiseres fuldt ud; reversibel inddæmning (karantæne af en fil, tvungen nulstilling af en adgangskode) kan ofte automatiseres ved detektioner med høj konfidens; forstyrrende eller irreversible handlinger (spærring af en direktørs konto, isolering af en produktionsserver, blokering af en cloududbyders IP-interval) bør kræve en menneskelig beslutning. Automatiserede handlinger oven på støjende detektioner skalerer falske positiver op til nedbrud, så kvaliteten af en playbook er begrænset af kvaliteten af detektionen.\n\nSOAR medfører sine egne risici. Platformen gemmer API-nøgler med brede rettigheder på tværs af hele sikkerhedsstakken og er derfor et mål af høj værdi, der kræver streng adgangskontrol, håndtering af hemmeligheder, ændringsstyring af playbooks og auditlogning af platformens egne handlinger. Playbooks forfalder i stilhed, når de tilkoblede API'er ændrer sig, så de skal testes som kode. SOAR adskiller sig fra en SIEM, der indsamler og korrelerer hændelser for at rejse alarmer, mens SOAR handler på de alarmer; kategorierne smelter sammen, efterhånden som SIEM- og XDR-platforme bygger automatisering ind, og AI-assistenter bruges i stigende grad til berigelse og opsummering i disse arbejdsgange, hvilket kræver de samme godkendelsestrin som enhver anden automatiseret handling."},"howTo":{"steps":{"en":["Pick the handful of alert types that take the most analyst time and follow the same steps every time, such as reported phishing emails, and write those steps down as they are done by hand today.","Sort each step by risk - enrichment and deduplication can run fully automatically, reversible containment such as quarantining a file can run on high-confidence detections, and disruptive actions such as isolating a server or disabling an executive's account need a human approval step.","Connect the tools the playbook needs, such as SIEM, EDR, email, identity and ticketing, using service accounts with only the rights each action requires, and store their API keys in a secrets vault.","Build the first playbook, run it in a mode that only suggests actions, and compare its verdicts with the analysts' before letting it act.","Keep playbooks under version control with an owner, review changes before they go live, and test them again whenever a connected tool or API changes.","Restrict who can edit playbooks and administer the platform, and send the platform's own audit log to the SIEM.","Measure time saved, time to respond and wrong automatic actions every month, and only expand automation where the underlying detections are reliable."],"da":["Vælg de få alarmtyper, der tager mest analytikertid og altid følger de samme trin, fx indberettede phishing-mails, og skriv trinnene ned, som de udføres i hånden i dag.","Sortér hvert trin efter risiko - berigelse og deduplikering kan køre helt automatisk, reversibel inddæmning som karantæne af en fil kan køre ved detektioner med høj konfidens, og forstyrrende handlinger som at isolere en server eller spærre en direktørs konto kræver et menneskeligt godkendelsestrin.","Tilslut de værktøjer, playbooken skal bruge, fx SIEM, EDR, mail, identitet og ticketsystem, med servicekonti, der kun har de rettigheder, hver handling kræver, og gem deres API-nøgler i en secrets manager.","Byg den første playbook, lad den køre i en tilstand, hvor den kun foreslår handlinger, og sammenlign dens vurderinger med analytikernes, før den får lov at handle.","Hold playbooks under versionsstyring med en ejer, gennemgå ændringer, før de går i drift, og test dem igen, hver gang et tilkoblet værktøj eller API ændrer sig.","Begræns, hvem der kan redigere playbooks og administrere platformen, og send platformens egen auditlog til SIEM'en.","Mål sparet tid, tid til reaktion og forkerte automatiske handlinger hver måned, og udvid kun automatiseringen, hvor de underliggende detektioner er pålidelige."]},"pitfalls":{"en":["Automating actions on top of noisy detections, so false positives turn into outages.","Giving the platform broad administrator rights across every tool, which makes it a prize target for attackers.","Letting playbooks break silently when a connected API changes, so nobody notices that the automation stopped working."],"da":["At automatisere handlinger oven på støjende detektioner, så falske positiver bliver til nedbrud.","At give platformen brede administratorrettigheder i alle værktøjer, hvilket gør den til et attraktivt mål for angribere.","At lade playbooks gå i stykker i stilhed, når et tilkoblet API ændrer sig, så ingen opdager, at automatiseringen er holdt op med at virke."]},"guides":[{"title":"Guidance for SIEM and SOAR Implementation","url":"https://www.cisa.gov/resources-tools/resources/guidance-siem-and-soar-implementation","publisher":"CISA","tier":"official-doc"},{"title":"Automation in Microsoft Sentinel","url":"https://learn.microsoft.com/en-us/azure/sentinel/automation/automation","publisher":"Microsoft","tier":"official-doc"},{"title":"CACAO Security Playbooks Version 2.0","url":"https://docs.oasis-open.org/cacao/security-playbooks/v2.0/security-playbooks-v2.0.html","publisher":"OASIS","tier":"standard"}]},"edges":[{"type":"requires","to":"security/siem","confidence":"high","strength":"normal"},{"type":"requires","to":"security/alert-triage","confidence":"high","strength":"normal"},{"type":"kind-of","to":"security/control","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/soc","why":{"en":"The SOC's analysts use SOAR to handle routine alarms automatically and spend their time on the hard cases.","da":"SOC'ens analytikere bruger SOAR til at håndtere rutinealarmer automatisk og bruge deres tid på de svære sager."},"confidence":"high","strength":"primary"}],"depth":3,"sources":[{"title":"Wikipedia - Security orchestration, automation and response","url":"https://en.wikipedia.org/wiki/Security_orchestration,_automation_and_response","tier":"reference"},{"title":"NIST SP 800-61 Rev. 3 - Incident Response Recommendations and Considerations for Cybersecurity Risk Management","url":"https://doi.org/10.6028/NIST.SP.800-61r3","tier":"standard","publisher":"NIST"}],"draft":true}