Security orchestration, automation and response: tools that receive alerts from a SIEM and other sources and react to them automatically using workflows known as playbooks. Microsoft Sentinel offers SOAR as well as SIEM.
Also called security orchestration, automation and response.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SOAR in context, with comparison tables and the common traps.
Terms in this definition
- SIEM
A platform that gathers and correlates security logs to detect threats and raise alerts. In Azure the cloud SIEM is Microsoft Sentinel, which runs on a Log Analytics workspace.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.