<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Orchestration on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/orchestration/</link><description>Recent content in Orchestration on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/orchestration/index.xml" rel="self" type="application/rss+xml"/><item><title>SOAR (Security Orchestration, Automation and Response)</title><link>https://lesitedefrancois.be/en/security/soar/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/soar/</guid><description>&lt;p&gt;&lt;strong&gt;SOAR (Security Orchestration, Automation and Response)&lt;/strong&gt; is the actuation complement to a &lt;strong&gt;SIEM&lt;/strong&gt;: where the SIEM detects and alerts, SOAR responds and acts. It receives alerts — primarily from the SIEM, but also directly from EDR platforms, vulnerability scanners, cloud security posture tools, and CNI/container security platforms — and executes structured response &lt;strong&gt;playbooks&lt;/strong&gt;: predefined, branching workflows that enrich the alert with additional context from connected systems, make automated or human-gated decisions based on that context, and issue remediation actions across the organisation&amp;rsquo;s security tooling. The three pillars of SOAR are &lt;strong&gt;orchestration&lt;/strong&gt; (connecting disparate security tools into a unified, API-driven workflow so they exchange data and coordinate actions without human clipboard-copying), &lt;strong&gt;automation&lt;/strong&gt; (executing repeatable investigation and containment steps at machine speed, consistently and without analyst fatigue), and &lt;strong&gt;case management&lt;/strong&gt; (tracking the full lifecycle of a security incident — detection, triage, investigation, containment, eradication, recovery, and post-incident review — in a structured, auditable record). Leading platforms include Splunk SOAR (formerly Phantom), IBM QRadar SOAR (formerly Resilient), Palo Alto XSOAR (formerly Demisto), Microsoft Sentinel with Playbooks (Logic Apps), and open-source options such as TheHive with Cortex.&lt;/p&gt;</description></item></channel></rss>