# Security Orchestration, Automation and Response (SOAR)

Technology that automates and coordinates security tasks and incident response workflows to speed up threat handling.

**Security Orchestration, Automation and Response (SOAR)** refers to technology that automates repetitive security tasks and coordinates incident response[↗](/incident-response) workflows across multiple tools, so analysts spend less time on manual, repetitive steps and more time on genuine investigation and decision-making.

A SOAR platform might automatically enrich an alert with threat intelligence[↗](/threat-intelligence), isolate an infected device from the network, and open a ticket, all within seconds of a SIEM flagging suspicious activity, actions that would otherwise take an analyst many manual steps across several tools. This dramatically shortens the time between detecting a threat and actually containing it.
