ONE AGENT. ONE PLATFORM. ONE CONTROL.

ERA Response (SOAR)Response automation

Closes the "detected → responded" loop: ready-made playbooks for host isolation, IP blocking, service desk ticket creation, and a log of all actions. No separate SOAR vendor required — runs in the same perimeter as XDR.

Purpose

Eliminate manual copy-paste of commands between consoles during an incident. The analyst launches a playbook — the platform executes agreed steps and records the outcome.

Key capabilities

  • Playbooks: host isolation, IP block, ticket creation.
  • Response action log for audit.
  • Connectors: isolation script, ITSM webhook, NGFW integration (e.g. Palo Alto).
  • Launch from a case or via API — within RBAC policies.

Who it's for

SOC teams needing built-in SOAR without a separate XSOAR license. Typical upsell to Core + AI.

Licensing

Separate ERA Response license.