Frame the question
Start with supplied evidence or the sources configured in your installation. Keep the asset, time window, and investigation scope explicit.
Investigate · Rehearse · Review
SOAR is a security investigation and governed-response workspace for SOC analysts, threat hunters, and IT engineers.
Connect the evidence to the question. Examine possible attack paths. Turn an operational request into a proposal you can inspect—before authorizing a change.
Already a customer? Sign in to SOAR. Documentation requires an authorized account.

From an alert to an accountable next step
Your SIEM, IDS, EDR, and vulnerability tools already collect signals. SOAR helps the people working those signals investigate what they mean and review what to do next.
Start with supplied evidence or the sources configured in your installation. Keep the asset, time window, and investigation scope explicit.
Use Chat, Live, Console, and Replay to examine observations, candidate paths, and competing hypotheses. See where evidence ends and inference begins.
Inspect a proposed query, script, or response. Check permissions, impact, recovery, and approvals. Execution and a verified outcome are separate steps.
One workspace. Different ways to investigate.
The important distinction is not how confident an answer sounds. It is whether you can inspect its inputs, challenge its reasoning, and govern the next action.
Work through an alert, ask for alternative explanations, and identify missing context. Supplied-input investigations stay distinct from connected-estate retrieval.
Watch the investigation films ↗Inspect operating signals alongside provenance and coverage. A composite count is a clue—not a conclusion that an intrusion occurred.
See Live evidence ↗Inspect inventory-derived candidate paths and event timelines. Digital-twin and modeled records help explore scenarios; source labels distinguish them from measured events.
Explore rehearsal workflows ↗Review detection-rule results and generated operational code. Patch, monitoring, and firewall drafts remain proposals until the required engineering and execution checks pass.
Inspect Console workflows ↗The product, on screen
Recorded from the authenticated application, with editorial close-ups and an AI-generated voice. Each film states its evidence context. Captions are optional; use full screen for fine detail.
10 recorded workflows
These recordings demonstrate investigation and review. Active response depends on your installation, configured adapters, approved scope, and a separately verified result.
Built around the people doing the work
Investigate an alert without losing the distinction between reported facts, hypotheses, and the evidence still needed.
Trace candidate routes, examine timelines, and turn uncertainty into a focused next evidence request.
Inspect operational drafts, identify unsafe assumptions, and review recovery before considering execution.
Ask what is known, what remains unverified, who owns the decision, and what authorizes the response.
Fit it to your environment
SOAR complements detection and enforcement tools. It does not replace endpoint protection, network controls, identity policy, or the engineers responsible for operating them.
A team with evidence to investigate, named operational owners, and a defined workflow to evaluate.
Do not choose SOAR expecting every integration to work out of the box, an AI-generated answer to prove a breach, or unrestricted autonomous changes.
Production is deployed on-site, with an air-gapped operating configuration. IT/Cyber controls offline updates or explicitly permitted outbound retrieval. Validate local models, adapters, retention and execution permissions for the selected release.
Read the deployment and operating guidance ↗Before you begin
An investigation and governed-response application with Chat, Console, Live evidence, attack-scenario review, and Replay workspaces. Begin with the supported workflows and integrations in your installation—not an assumption that every possible response is automated.
Those tools collect, detect, correlate, or assess. SOAR focuses on investigating evidence and reviewing operational next steps. Your existing systems remain sources and enforcement points where supported integrations are configured.
Execution is installation- and capability-dependent. Generated code is not permission to run it. Review the target, credentials, approval route, allowed actions, blast radius, and rollback. Confirm the result with fresh evidence after any authorized execution.
No. A candidate path describes a route to investigate. Reachability, vulnerability applicability, and observed activity require separate evidence. Modeled, illustrative, and injected records are labeled so they are not confused with measured events.
Use Open application with an authorized account. The searchable reader and PDF are available through Documentation behind the same authentication gate. Reader annotations are stored in the local browser, not on the server.
Start with one real question