Investigate · Rehearse · Review

A signal is a starting point.
Make the next decision count.

SOAR is a security investigation and governed-response workspace for SOC analysts, threat hunters, and IT engineers.

Connect the evidence to the question. Examine possible attack paths. Turn an operational request into a proposal you can inspect—before authorizing a change.

Already a customer? Sign in to SOAR. Documentation requires an authorized account.

SOAR’s gold and ember authority-engine emblem
THE OPERATOR STAYS IN COMMANDEvidence informs.
People authorize.
01 Know the source02 Challenge the explanation03 Verify the outcome

From an alert to an accountable next step

Not another place
to accumulate alerts.

Your SIEM, IDS, EDR, and vulnerability tools already collect signals. SOAR helps the people working those signals investigate what they mean and review what to do next.

01

Frame the question

Start with supplied evidence or the sources configured in your installation. Keep the asset, time window, and investigation scope explicit.

02

Inspect the explanation

Use Chat, Live, Console, and Replay to examine observations, candidate paths, and competing hypotheses. See where evidence ends and inference begins.

03

Review the next step

Inspect a proposed query, script, or response. Check permissions, impact, recovery, and approvals. Execution and a verified outcome are separate steps.

One workspace. Different ways to investigate.

Depth for the analyst.
Control for the engineer.

The important distinction is not how confident an answer sounds. It is whether you can inspect its inputs, challenge its reasoning, and govern the next action.

CHAT

Reason inside the evidence.

Work through an alert, ask for alternative explanations, and identify missing context. Supplied-input investigations stay distinct from connected-estate retrieval.

Watch the investigation films ↗
LIVE

Read coverage, not just counters.

Inspect operating signals alongside provenance and coverage. A composite count is a clue—not a conclusion that an intrusion occurred.

See Live evidence ↗
ATTACK PATHS + REPLAY

Explore a route. Test its assumptions.

Inspect inventory-derived candidate paths and event timelines. Digital-twin and modeled records help explore scenarios; source labels distinguish them from measured events.

Explore rehearsal workflows ↗
CONSOLE

Make the proposal inspectable.

Review detection-rule results and generated operational code. Patch, monitoring, and firewall drafts remain proposals until the required engineering and execution checks pass.

Inspect Console workflows ↗

The product, on screen

Ten workflows.
About a minute each.

Recorded from the authenticated application, with editorial close-ups and an AI-generated voice. Each film states its evidence context. Captions are optional; use full screen for fine detail.

10 recorded workflows

These recordings demonstrate investigation and review. Active response depends on your installation, configured adapters, approved scope, and a separately verified result.

Built around the people doing the work

A shared view.
Distinct responsibilities.

SOC analysts

Investigate an alert without losing the distinction between reported facts, hypotheses, and the evidence still needed.

Threat hunters

Trace candidate routes, examine timelines, and turn uncertainty into a focused next evidence request.

IT engineers

Inspect operational drafts, identify unsafe assumptions, and review recovery before considering execution.

Security leaders

Ask what is known, what remains unverified, who owns the decision, and what authorizes the response.

Fit it to your environment

Keep your controls.
Add an investigation workspace.

SOAR complements detection and enforcement tools. It does not replace endpoint protection, network controls, identity policy, or the engineers responsible for operating them.

A good starting point

A team with evidence to investigate, named operational owners, and a defined workflow to evaluate.

  • Choose one alert, hunt, or operational review.
  • Confirm supported inputs and adapters for that installation.
  • Define access, retention, approvals, and recovery.
  • Validate the workflow in a controlled environment before expanding scope.

Not a shortcut around accountability

Do not choose SOAR expecting every integration to work out of the box, an AI-generated answer to prove a breach, or unrestricted autonomous changes.

Production is deployed on-site, with an air-gapped operating configuration. IT/Cyber controls offline updates or explicitly permitted outbound retrieval. Validate local models, adapters, retention and execution permissions for the selected release.

Read the deployment and operating guidance ↗

Before you begin

Questions worth asking.

What are we adopting?

An investigation and governed-response application with Chat, Console, Live evidence, attack-scenario review, and Replay workspaces. Begin with the supported workflows and integrations in your installation—not an assumption that every possible response is automated.

How is this different from a SIEM or a vulnerability manager?

Those tools collect, detect, correlate, or assess. SOAR focuses on investigating evidence and reviewing operational next steps. Your existing systems remain sources and enforcement points where supported integrations are configured.

Can SOAR change production systems?

Execution is installation- and capability-dependent. Generated code is not permission to run it. Review the target, credentials, approval route, allowed actions, blast radius, and rollback. Confirm the result with fresh evidence after any authorized execution.

Are attack paths and digital twins proof of a compromise?

No. A candidate path describes a route to investigate. Reachability, vulnerability applicability, and observed activity require separate evidence. Modeled, illustrative, and injected records are labeled so they are not confused with measured events.

How do I access the product and documentation?

Use Open application with an authorized account. The searchable reader and PDF are available through Documentation behind the same authentication gate. Reader annotations are stored in the local browser, not on the server.

Start with one real question

Start with one investigation.
Agree what success means.