SECAI Core · phase 14 of 15

Security orchestration, automation, and response

A class of security tools that facilitates incident response, threat hunting, and security configuration by orchestrating automated runbooks and delivering data enrichment.

The Explain card

Plain English
SOAR tools run automated runbooks across your security stack, enrich alerts with extra context and coordinate response steps, speeding up incident response, threat hunting and configuration changes.
Example
When the LLM gateway flags a user for repeated jailbreak attempts, the SOAR platform automatically pulls their recent logins, checks threat intelligence for the source IP, suspends the API key and opens a ticket for the analyst.
Why it matters
AI abuse generates alerts faster than humans can triage. SOAR turns playbooks into code so routine cases are handled in seconds and analysts keep the hard ones.
Hook
The autopilot for the SOC: humans set the route, the machine flies the checklist.

Where it sits in the deck

Phase 14: Incident Response, Evaluation, and Knowledge Bases

When detection fires, teams need structured response plans, scoring frameworks, and curated knowledge bases to triage, measure, and learn from AI security events.