Security Orchestration, Automation, and Response (SOAR) is a technology stack that integrates disparate security tools, standardizes incident response procedures into playbooks, and executes defensive actions to contain threats with machine speed. It functions as a central nervous system for a Security Operations Center (SOC), aggregating alerts from SIEMs, endpoint tools, and threat intelligence feeds to reduce manual analysis and mean time to respond (MTTR).
