Closes the "detected → responded" loop: ready-made playbooks for host isolation, IP blocking, service desk ticket creation, and a log of all actions. No separate SOAR vendor required — runs in the same perimeter as XDR.
Eliminate manual copy-paste of commands between consoles during an incident. The analyst launches a playbook — the platform executes agreed steps and records the outcome.
SOC teams needing built-in SOAR without a separate XSOAR license. Typical upsell to Core + AI.
Separate ERA Response license.