Research Paper · Cybersecurity & Threat Intelligence

Streamlining Security: An In-Depth Analysis of SOAR Implementations

Shivam Baikerikar University of Guelph, Canada sbaikeri@uoguelph.ca
Ripunjoy Buddha University of Guelph, Canada rbuddha@uoguelph.ca
Fatemeh Khodaparast University of Guelph, Canada khodapaf@uoguelph.ca
Abstract This research examines Security Orchestration, Automation, and Response (SOAR) as an approach to managing cybersecurity incidents, and its integration within modern security operations. Human analysts increasingly struggle with alert volume, alert fatigue, threat complexity, time pressure, tool overload, and limited resources — challenges that SOAR platforms are designed to address by automating and orchestrating incident response. Drawing on academic literature, industry reports, and case studies, the paper provides a comprehensive overview of how SOAR streamlines processes, reduces response times, and strengthens organizational cybersecurity posture, while outlining its capabilities and current limitations.
Index Terms — SOAR, SIEM, SOC, incident response, security automation, orchestration, threat intelligence

I. Introduction

Organizations today face a massive challenge in managing the growing number of security alerts. The capabilities of human security analysts are being pushed to their limits by the increasing complexity of cyberattacks. Security Operation Centers (SOCs) are responsible for protecting sensitive data and digital assets within an organization. However, they frequently receive an excessive amount of alerts from different security tools. The resulting alert fatigue, inefficiency, and potential gaps in incident response have raised critical concerns in the cybersecurity domain. Security Orchestration, Automation, and Response, or SOAR, has become an effective strategy to address these issues [1].

Cybersecurity incidents and breaches can lead to severe outcomes, including financial losses and harm to reputation. As a result, businesses have made big investments in security solutions like firewalls, intrusion detection systems (IDS), antivirus software, and other threat intelligence tools. These tools generate a constant stream of alerts, indicating potential security incidents. Although the goal of using these technologies is to improve security, security professionals may become alert fatigued and respond to incidents too slowly or not at all due to the high frequency of alerts [2].

Human security analysts have a tough job going through security alerts one by one to figure out if they're real and how serious they are. Doing this manually takes a lot of time, can have mistakes, and uses up a lot of resources. As cyber threats get smarter, there's a growing need for a better system to manage these alerts quickly and effectively.

Dealing with too many alerts and managing them manually is a big problem for organizations. Businesses are looking for smart solutions to boost their cybersecurity posture, and that's where SOAR technology comes in. It helps by automating tasks, sorting alerts, and providing more information on incidents, making human security analysts better at spotting and dealing with security threats. This research project is all about understanding how SOAR technology has evolved, its benefits, and how it changes the job of human analysts in today's security operations — particularly how SOAR tools can help solve the problem of handling too many alerts.

II. Terminologies

III. Literature Survey

This literature survey examines how organizations currently respond to incidents, the integration of security tools, real-world case studies of successful implementations, and the importance of user experience in shaping effective cybersecurity practices.

Twenty-four participants evaluated six commercial SOAR products in one study, with investigative work totaling more than 200 hours. The findings highlight that streamlining the process of gathering and correlating data is crucial to improving cybersecurity posture; switching between multiple tools for data collection is time-consuming, distracting, and often delays reaction to issues [3]. Centralizing data from various sources onto a single platform was found to reduce context switching and increase efficiency, though it may also affect ticketing accuracy.

Due to the gap between OT and IT, digitizing SCADA systems presents security challenges, with critical sectors often relying on outdated tools. Researchers propose SOAR platforms — leveraging machine learning and AI — as an ideal solution for resolving security flaws and performance interruptions, helping protect smart grid SCADA systems from emerging threats [4].

Other work provides a detailed implementation strategy for deploying SIEM solutions, emphasizing that corporations need a clear goal (reporting, compliance, or threat management) for a SIEM deployment to succeed. The same deliberate approach is recommended when deploying SOAR solutions [5].

A recent survey found that roughly three-quarters of surveyed firms are testing AI/ML for cybersecurity, underscoring the crucial role of ML and AI in developing SOAR systems that automate threat detection and response and support both offensive and defensive SOC capabilities [1].

Additional proposed systems integrate honeypots (e.g., T-Pot), Suricata for network threat detection, ELK for log parsing and visualization, and Spiderfoot for threat intelligence gathering, combined with an AI agent that determines true versus false positives and generates supporting reports and playbooks [6][7]. For Distributed Energy Resource (DER) systems, a technique called SOAR4DER combines cyber and physical data via a BITW device to detect and respond to attacks — including man-in-the-middle assaults, brute-force logins, malicious Modbus commands, and denial-of-service attacks — within seconds [8].

A Palo Alto Networks survey of North American security professionals found that many incident response teams remain small, as shown below, leaving them exposed to high stress and full responsibility for handling security incidents [1].

28%
1–3
28%
4–5
23%
6–10
12%
11–25
8%
26+
Fig. 1. Count of team members handling incident response, by response rate.

IV. Existing System

A. Where does SOAR fit in?

In a typical SOC workflow, numerous tools generate huge quantities of logs, processed through a SIEM system. In a large organization these logs originate from sources like Active Directory, firewalls, endpoints, antivirus, web access firewalls, DNS/DHCP servers, web servers, IPS/IDS, routers, switches, and email servers. Correlation rules in the SIEM trigger roughly 80–120 alerts per day. Security analysts then analyze these alerts, and confirmed incidents are escalated to incident handlers for response.

Typical SOC Workflow
Thousands of Log Sources
Millions of Logs
Processed in SIEM
Runs 100s of Correlation Rules
Triggers Few 100 Alerts
Analysis by Security Analysts
Incident Response Handlers
Typical SOC Workflow with SOAR
Thousands of Log Sources
Millions of Logs
Processed in SIEM
Runs 100s of Correlation Rules
Triggers Few 100 Alerts
SOAR
Analysis + Response (streamlined)
Fig. 2. SOC workflow, without and with SOAR handling the bulk of alert processing.

In the SOC workflow with SOAR, the process remains largely the same, but SOAR handles the bulk of the workload. Analysis by security analysts and response by handlers are still essential, but the technology streamlines and automates many tasks. While the number of required security analysts may decrease, human involvement remains crucial [1]. SOAR's role begins with processing alerts and concludes with executing incident response actions — enhancing efficiency and reducing the workload on human analysts.

V. Current Scenario of Threat Feed Management

In threat management, a significant 50% of analysts still handle threat feeds manually, while the other half use various tools (Fig. 3). The risk associated with manual handling is high given the nature of modern threats: small teams may face overload, leading to mishandled alerts. False positives waste time and resources, while false negatives can result in security breaches. Automating this critical workflow is essential to improving efficiency and reducing errors.

50%
Manual
19%
ThreatConnect
11%
MISP
7%
Anomali
7%
ThreatQuotient
7%
Others
Fig. 3. Threat feed management approaches by response rate.

VI. What Can Be Automated?

A. Assignment of alerts to analyst

Alert assignment in a SOC can be significantly streamlined through automation. SOC teams typically operate with just one or two analysts per shift, often using a round-robin approach. Machine learning can replace this rotational model by analyzing historical data — assigning new alerts to the analyst who previously handled a related host or incident, acknowledging potential connections between incidents and optimizing analyst expertise.

B. Information gathering

This phase focuses on extracting key details from triggered alerts — for a malware alert, this includes host name, IP address, the affected user, the malware's name, and the action taken by antivirus software (deletion, quarantine, cleaning). Automating this extraction ensures all important details are gathered consistently, creating a solid base for further analysis.

C. Enrichment of information

Enrichment gathers additional context beyond what's in the original log or alert — connecting to Active Directory for a user's department, role, manager, and location; to vulnerability assessment reports for machine health; and to threat intelligence services for the reputation of IPs, URLs, and files. Automating enrichment produces a more comprehensive, targeted analysis.

D. Analysis

Automatable analysis tasks include retrieving a file from an end-user machine and submitting it to a sandbox, checking an IP's historical communication within the network (informed by earlier reputation findings), and reviewing whether other users received email from the same phishing sender by comparing subject lines and sender details.

E. User interaction

Automation extends to user communication — acknowledging a reported suspicious email, then following up with the analysis outcome. It also covers seeking approval from higher-ups, such as sending a manager a request with "Yes/No" options to delete identified phishing emails, streamlining the permission-seeking process while keeping a human in the loop for the final decision.

F. Respond

Automated response actions include generating tickets for tracking, triggering vulnerability or antivirus scans on suspect systems, and blocking malicious applications, IPs, or URLs on the firewall or web gateway — eliminating the need to manually raise tickets or wait on administrators to update policies.

G. Enhancement / lessons learned

Automation supports continuous improvement: automatically adding a newly detected malware hash to the local threat intelligence database, and checking for its presence across the network. It also extends to organizational awareness — for example, automatically alerting the organization when a new targeted phishing technique tied to a recent company event is identified.

74%
Phishing
56%
Malware
53%
Endpoint Security
40%
Network Security
17%
IAM
16%
VPN
16%
SIEM
14%
Cloud Service Provider
12%
Threat Intel Feed
1%
Others
Fig. 5. Types of alerts security teams face, by response rate.

VII. SOAR Playbook Use-Cases

According to the data above, the top three incidents security teams face are phishing alerts (74%), malware alerts (56%), and endpoint security alerts (53%). Network security incidents stand at 40%. The remaining 15–17% consist of anomalous logins, VPN issues, SIEM alerts, and cloud service provider alerts. Addressing these primary threats is crucial for protecting an organization against security breaches.

A. Detonating a URL using VirusTotal

The playbook starts with an incident created in the SOAR platform representing a security event that needs investigation. Relevant information — such as the suspicious URL to detonate — is gathered and stored in the incident context for use throughout the playbook. A VirusTotal integration enriches the incident with the URL's reputation, associated domains, IPs, and other indicators of compromise. Conditional logic based on the reputation score determines whether to proceed with detonation — executing the URL in a controlled environment to observe its behavior. Results are monitored and retrieved from the VirusTotal API, and a report is generated. Depending on findings, response actions may include blocking the URL, isolating affected systems, or notifying stakeholders before the incident is closed.

B. Malware investigation and response

This playbook is triggered by a malware alert and starts an SLA timer to ensure timely response. It assesses whether an analyst needs assignment, then sets tags based on the incoming alert. Once the expected SIEM alert arrives, the playbook retrieves detailed incident data and marks the SIEM state as processed to avoid redundant work. Analysts select an investigation tool — Microsoft Defender for Endpoint, CrowdStrike Falcon, or Palo Alto XDR — to extract and analyze investigation details. Sub-playbooks then carry out malware remediation and hunt for detonation activity elsewhere in the company.

C. Phishing

A phishing playbook begins with an instant notification to the management chain, followed by a thorough initial inspection of the reported email — checking for malicious URLs, attachments, suspicious sender names or addresses, and hostname legitimacy. If the email is not phishing, the case closes as a false positive. If confirmed, severity is assessed and analysts are assigned for a deeper Investigation Step 2: extracting URLs and hostnames, fetching linked files, and running malicious hash inspections. Investigation Step 3 checks whether the incident is part of a broader campaign. In the response phase, actions can include notifying the internal PR team (if a campaign), blocking the email on the server, updating spam filters, informing the email security vendor, removing the email from inboxes, blackholing the phishing domain, blocking the download URL, and reporting malware samples to antivirus systems.

Table I — Resolution percentages for different types of alerts, by time to resolution
Type of Alert30–60 min1–4 hrs5–8 hrs1–2 days2+ days
Phishing40%29%15%5%2%
Malware21%42%15%8%2%
Endpoint21%42%15%8%2%
Cloud Service Provider16%35%21%7%2%
Remote Access / VPN25%31%17%12%1%
The paper title functions as the primary text head, since all subsequent material relates back to it; second-level heads (uppercase Roman numerals) are used for major sections, and sub-heads are introduced only where a section has two or more sub-topics.
Acknowledgment. The authors thank their collaborators and institution for supporting this research into SOAR implementations and their role in modern security operations.

References

  1. J. Kinyua and L. Awuah, "AI/ML in security orchestration, automation and response: Future research directions," Intelligent Automation & Soft Computing, vol. 28, no. 2, 2021.
  2. V.-G. Bilali, D. Kosyvas, T. Theodoropoulos, E. Ouzounoglou, L. Karagiannidis, and A. Amditis, "Iris advanced threat intelligence orchestrator — a way to manage cybersecurity challenges of IoT ecosystems in smart cities," in Global IoT Summit. Springer, 2022, pp. 315–325.
  3. R. A. Bridges, A. E. Rice, S. Oesch, J. A. Nichols, C. Watson, K. Spakes, S. Norem, M. Huettel, B. Jewell, B. Weber et al., "Testing SOAR tools in use," Computers & Security, vol. 129, p. 103201, 2023.
  4. A. W. Mir and R. K. Ramachandran, "Implementation of security orchestration, automation and response (SOAR) in smart grid-based SCADA systems," in Sixth International Conference on Intelligent Computing and Applications: Proceedings of ICICA 2020. Springer, 2021, pp. 157–169.
  5. M. Rosenberg, B. Schneider, C. Scherb, and P. M. Asprion, "An adaptable approach for successful SIEM adoption in companies," arXiv preprint arXiv:2308.01065, 2023.
  6. R. Vast, S. Sawant, A. Thorbole, and V. Badgujar, "Artificial intelligence based security orchestration, automation and response system," in 2021 6th International Conference for Convergence in Technology (I2CT). IEEE, 2021, pp. 1–5.
  7. U. Bartwal, S. Mukhopadhyay, R. Negi, and S. Shukla, "Security orchestration, automation, and response engine for deployment of behavioural honeypots," in 2022 IEEE Conference on Dependable and Secure Computing (DSC). IEEE, 2022, pp. 1–8.
  8. J. Johnson, C. B. Jones, A. Chavez, and S. Hossain-McKenzie, "SOAR4DER: security orchestration, automation, and response for distributed energy resources," in Power Systems Cybersecurity: Methods, Concepts, and Best Practices. Springer, 2023, pp. 387–411.
  9. D. Lalos, "Analysis on security orchestration automation and response (SOAR) platforms for security operation centers," Ph.D. dissertation, University of Piraeus (Greece), 2022.
  10. K. Fysarakis, A. Lekidis, V. Mavroeidis, K. Lampropoulos, G. Lyberopoulos, I. G.-M. Vidal, J. C. T. i Casals, E. R. Luna, A. A. M. Sancho, A. Mavrelos et al., "Phoeni2X — a European cyber resilience framework with artificial-intelligence-assisted orchestration, automation & response capabilities for business continuity and recovery, incident response, and information exchange," in 2023 IEEE International Conference on Cyber Security and Resilience (CSR). IEEE, 2023, pp. 538–545.