Ayati One — Managed Cyber Security
Ayati One response policy · Shuffle playbooks

Automated Incident Response (SOAR)

Predefined actions fire the instant an incident is detected — containment at machine speed, with human judgement kept where it belongs.

Overview

Security orchestration, automation and response — SOAR — exists because the gap between detection and containment is where damage happens. Ransomware does not wait for an analyst to finish reading the alert. If a high-severity detection can be contained in seconds instead of the forty minutes it takes to notice, triage and act, the blast radius is a different order of magnitude.

Ayati One implements this as policy rather than as a scripting project. You set the severity threshold at which automatic containment applies; from that point a qualifying detection is contained at the moment it is raised, and the containment is stamped on the incident record so the response time is measured, not estimated. The shipped default engages at high severity and above, and it can be tuned or switched off entirely.

The automation is deliberately bounded. Every automated action is reversible from the console, is written to the same audit log as human actions, and stops well short of anything that would require judgement. The AI triage layer summarises and recommends — it has no ability to execute. Automation handles the mechanical and the urgent; analysts handle the decisions.

Ayati One automated response flow: a detection passes a severity policy gate and triggers playbook actions including host isolation, containment marking, alert grouping, suppression, notification and ticketing, bounded by reversibility and audit guardrails

What's included

SOAR Automation capabilities

  • Automatic containment on detection

    A configurable policy contains qualifying incidents at the moment of detection and records the containment time on the case. Mean time to respond stops being a function of who happened to be watching the console.

  • One-click host isolation

    An endpoint can be quarantined at the network layer — automatically by policy, or manually from the console — while the agent's own management channel is deliberately preserved. The machine is cut off from everything except the platform investigating it, so isolation does not cost you visibility.

  • Reversible by design

    Isolation is released from the console in one action. Automated response you cannot cleanly undo is automated response nobody switches on, so every action is built to be reversed.

  • Alert grouping

    Repeat alerts from the same rule collapse into a single case carrying a count. A misconfiguration that fires eight hundred times produces one case with a number attached, not eight hundred queue entries burying the detection that mattered.

  • Suppression of known-good activity

    Tuning rules silence the false positives specific to your environment — the backup agent that looks like exfiltration, the admin script that looks like living-off-the-land. Suppressed alerts are still counted and auditable rather than deleted, so tuning stays honest and reviewable.

  • Playbook-driven notification

    The right people are told through the channel they actually watch: in-portal notification, email through your central SMTP account, Microsoft Teams, Slack, or a webhook into a system of your own.

  • Automated ticket creation

    Qualifying incidents raise a ServiceNow or Jira ticket automatically where that integration is enabled, keeping the security queue and the IT queue in step without an analyst rekeying anything.

  • Fleet-wide response actions

    Response work that has to reach many machines — a compliance sweep, a hardening re-check, an agent update — is queued across the estate and deferred for offline endpoints, draining automatically as they reconnect. Nothing is silently skipped because a laptop was shut.

  • Defensive-only automation library

    The playbook and skill content behind AI-assisted response is filtered to defensive material by design. The platform will help you contain, investigate and recover; it is not a tool for producing offensive tradecraft.

  • Every action attributed

    Automated actions are written to the same append-only activity log as human ones, distinguishable as automated. When someone asks why a production host dropped off the network at 04:12, the answer is in the case, with the rule that caused it.

The rest of the platform

Scope SOAR Automation against your environment

A 30-minute conversation with our engineers is usually enough to map your requirement to a concrete plan and honest estimate.