Solutions/AgentSOAR · SOAR AI

AgentSOAR: response automation driven by AI triage.

AgentSOAR is the response engine built into AgentSOC. When triage confirms a threat, AgentSOAR acts on your cloud, email, and identity providers, under your approval or policy, and records every step so it can be reverted.

Built into AgentSOCAWS · GCP · Azure · M365 · Google WorkspaceRevert on every action
Start free
AgentSOC · SOC overview
AgentSOC dashboard
Built in
No external SOAR to buy or wire up before you can take action.
Cloud, email, identity
Native actions across AWS, GCP, Azure, Hostinger, Google Workspace, and Microsoft 365.
Gated by you
Approval-based or policy-guided, depending on your plan.
Reversible
Every execution is logged with its status and can be reverted.
Explainer

What is AI SOAR?

From playbooks to decisions

Security orchestration, automation, and response (SOAR) tools run playbooks that people write in advance. They execute reliably, but someone still has to decide which playbook fits an alert, and every new case means another playbook to build and maintain.

AI SOAR adds a reasoning step before execution. AI works out whether an alert needs a response and which action fits. A deterministic engine then carries out that action the same way every time, within the limits you set.

How AgentSOAR fits into AgentSOC

AgentSOAR is a module of AgentSOC, not a separate product. Triage and correlation decide what needs a response, the response agent builds a remediation plan, and AgentSOAR executes it against your connected providers. Each execution moves through clear states (pending, running, succeeded, failed, or reverted), and the incident report picks up the result.

Cloud credentials are encrypted with AES-256-GCM and mapped to the domains they cover, so each action runs with the right account. AgentSOAR also syncs an inventory of hosts, users, and IPs from your cloud providers, so actions target real assets.

Bring the automation you already run

If your team already has workflows in Shuffle, connect your own instance and trigger them from Jutsu investigations. Connectors for Tines, Splunk SOAR, Cortex XSOAR, n8n, and Torq are on the integrations roadmap.

Actions

What AgentSOAR can do today.

Response capabilities by provider, as documented for AgentSOAR.

ActionWhat it doesProviders
Block IPBlocks traffic from a malicious IP address.AWS, GCP, Azure, Hostinger
Isolate hostCuts a compromised instance off from the network.AWS, GCP, Azure, Hostinger
Power controlChanges the power state of a cloud instance.AWS, GCP, Azure, Hostinger
Block senderStops mail from a phishing or spoofed sender.Google Workspace
Block email domainBlocks mail from an entire malicious domain.Google Workspace, Microsoft 365, AgentSOC Mail Block
Disable userSuspends a compromised account.Google Workspace, Microsoft 365

Executions are logged, and the state needed to undo an action is captured (for example, a host's original AWS security groups) so it can be reverted.

Capabilities

Everything in AgentSOAR.

Native response playbooks

Run actions across AWS, GCP, Azure, Hostinger, Google Workspace, and Microsoft 365 without an external SOAR.

Approval-based response

An analyst approves an action before it runs. Included from the Startup plan.

Policy-guided automation

Actions your policies allow run on their own. Included from the Growth plan.

Execution history and revert

Every run logged with its status. Undo an action when it's no longer needed.

Credential management

Cloud credentials encrypted with AES-256-GCM and mapped to the domains they cover.

Shuffle workflows

Trigger workflows on your own Shuffle instance from Jutsu investigations.

FAQ

Common questions.

Automate the response, and keep the undo button.

Book a demo to see AgentSOAR act on a confirmed threat, then revert it.

Start free

Subscribe to our newsletter

Get the latest security tips, product updates, and news delivered to your inbox.