Native module actions
Isolate host (EDR), block IP (NDR), purge mail (MX) — no external auth.
Supervised playbooks. Traceable. Reversible. Explained.
Response Automation runs supervised playbooks across every Protoxol module — isolate a host, revoke a token, pull a phishing mail from inboxes, open a ticket. Every action requires (or is auto-approved by) an analyst, every action is reversible where possible, every action is logged and exported to your audit trail. No standalone SOAR — automation lives where the signals are.
Isolate host (EDR), block IP (NDR), purge mail (MX) — no external auth.
Per-playbook approval requirements. Auto-approve safe actions, require human for risky ones.
Every action logs the undo step. Un-isolate, un-revoke, un-block.
Who, what, when, why, approved-by. Exported to SIEM and ticket system.
REST and webhook actions. Connect to ITSM, IdP, firewalls, custom tools.
Revoke sessions, force password reset, kill OAuth grants, isolate endpoints — one playbook.
Pull malicious mail from all inboxes, block sender domain, alert clicked users, audit.
Isolate host, collect memory image, block C2 IPs, ticket creation, all automated.
| Action library | 150+ pre-built actions |
| Languages | YAML playbooks + Python escape hatch |
| Approval model | Per-action, per-team, per-tier |
| Audit retention | 10 years exportable to S3 |
Standalone SOAR was a 2018 idea. By the time you connect your fifteen tools, the integrations have rotted. Modern SOAR lives inside the platform that produces the signals. Protoxol SOAR is supervised automation with audit baked in.
| Vendor | Strength | Tradeoff |
|---|---|---|
| Palo Alto Cortex XSOAR | Mature playbook library. Strong ecosystem. | Heavy implementation. Drift over time. |
| Splunk SOAR (Phantom) | Deep Splunk integration. Visual flows. | Locked to Splunk ingest. Visual flow drift. |
| Tines | Modern UX. No-code workflow appeal. | Standalone — every integration is external. |
Lives where the signals are — no integration tax.
Analyst-approved. Auditable. Reversible.
Native actions for every Protoxol module.
Thirty minutes. Your environment. The modules that fit. No slideware.