Automation that works
QRadar SOAR uses playbooks to automate key tasks
Playbooks automate key tasks and increase analyst productivity by providing a consistent user experience for all your analysts. Customers like TalkTalk see cases resolve 8 times faster with SOAR playbooks. With QRadar SOAR, hundreds of prebuilt integrations are leveraged to easily automate the steps to investigate and resolve a case.
QRadar SOAR key feature details
Playbook Designer to create, edit and customize playbooks
Users can create detailed tasks and workflow elements from a single location and quickly process and transform threat/enrichment data without code to accelerate response times. It allows for faster decision-making, with predefined, configurable blocks that present data to a case and have built-in “getting started” experiences and in-context help.
Install and deploy integrations quickly with AppHost
With an extensive orchestration and automation ecosystem formed by more than 160 IBM validated, third-party supported and community applications published via the IBM® App Exchange, IBM Security QRadar SOAR enables numerous integrations with other security tools. AppHost, IBM Security QRadar SOAR's new integration server, makes the installation and configuration of applications quick and simple with a step-by-step installation process that allows for editable settings and configurations.
Visualize and understand relationships across incidents
Leverage the artifact visualization graph to better see and understand the relationship between incidents and the details associated with each incident, which may help uncover a broader campaign or an advanced persistent threat (APT). Information about related closed or open incidents is also displayed in hover and timeline view in IBM Security QRadar SOAR.
Respond with agility and intelligence with dynamic playbooks
IBM Security QRadar SOAR’s playbooks are dynamic and additive, which means that they adapt and change with an incident as the known facts evolve during an incident investigation. This dynamism is critical to your security operations center (SOC) analysts because it amplifies your team’s ability to respond to incidents by providing it with a recommended course of action and giving it the agility to pivot as required by changing events.
Inform strategic business decisions by tracking key metrics
Track metrics and KPIs for incidents and users, including mean time to detect (MTTD) and mean time to respond (MTTR), through IBM Security QRadar SOAR's comprehensive dashboards and reporting capabilities. Based on your results and analysis, you may choose to run simulations to train new employees, test new workflows and incident response plans, or practice different cyber-threat scenarios.
Make complex processes simple with visual workflows
Workflows codify your organization's incident response processes and allow you to leverage automation to eliminate repetitive tasks, orchestration to integrate with other security tools, and human intelligence to make decisions. The visual workflow editor enables your team to design and build complex workflows with a business process management notation (BPMN) engine that requires no special programming or coding skills. Playbooks consist of a single or multiple discrete workflows.
Integrate privacy use cases with the QRadar SOAR platform
Keep up with the ever-increasing challenges to address complex privacy breach reporting requirements and meet compliance standards with IBM Security QRadar SOAR with Privacy. The Global Privacy Regulations Knowledgebase, at the heart of the solution, tracks over 170 global regulations, including GDPR, PIPEDA, HIPAA, CCPA, and all 50 stated breach notification rules, and provides your team with guidance through the breach notification process.
Product specifications
Technical specifications
IBM Security QRadar SOAR requires Red Hat Enterprise Linux 7.4 to 7.7 or better.
Software requirements
IBM Security QRadar SOAR web access requires the latest versions of Firefox, Chrome, Edge and Safari to log in.
Hardware requirements
IBM Security QRadar SOAR requires a server with 4 CPU cores, 16 GB of memory, and a minimum of 100 GB of disk space.
Deployment options
Flexible deployment options include on premises, in IaaS or as SaaS.
IBM Security QRadar SOAR on Cloud
IBM Security QRadar SOAR on Cloud supports your cloud-centric strategy, allowing you to scale and deploy quickly without compromising security, privacy or risk levels. It meets the following industry and global compliance standards:
- ISO 27001, 27017, 27018
- Operating in IBM Cloud SOC2 Type 2 (SSAE 16)

How customers use it
Incident enrichment

Incident enrichment
Problem
Collecting information to add context to an alert and determine its severity can be time-consuming since it requires analysts to search across other tools.
Solution
Through its powerful orchestration capabilities, IBM Security QRadar SOAR integrates with numerous security tools. This enables automatic incident enrichment, which reduces investigation time and allows analysts to focus on analysis and response.
Automated phishing response

Automated phishing response
Problem
Phishing attacks, which can do significant harm to an organization, are on the rise. For this reason, security teams are seeing a higher volume of alerts related to possible phishing attacks.
Solution
IBM Security QRadar SOAR allows your security team to build and implement phishing playbooks, guided incident response plans that align with your organization's standard operation procedures, to resolve phishing incidents efficiently and effectively.
Vulnerability management
Vulnerability management
Problem
Vulnerabilities present different risk levels depending on how easy it is to exploit them; hence security teams need to work closely with IT to identify and patch critical vulnerabilities fast.
Solution
Bridge the gap and improve collaboration between security and IT teams with IBM Security QRadar SOAR, which integrates with Red Hat Ansible to automate and accelerate remediation, as well as ticketing systems to track and manage tasks across teams.
Meet compliance requirements
Meet compliance requirements
Problem
Keeping up with evolving data breach reporting requirements and regulations is challenging, as well as generating quick, comprehensive reports for authorities during audits.
Solution
IBM Security QRadar SOAR is the only SOAR platform that integrates privacy use cases. With a global library of over 170 regulations, it guides your team through the breach notification process and generates detailed, audit-ready reports.
You may also be interested in
IBM Cloud Pak® for Security
Integrate security tools to gain insights into threats across hybrid, multicloud environments.
IBM Security® X-Force® Incident Response and Intelligence Services
Proactively manage your security threats with the expertise, skills and people of IBM Security Services.
IBM Security® QRadar SIEM
Get intelligent security analytics for insights into your most critical threats.
IBM X-Force® Exchange
Speed your security investigations with actionable threat intelligence that integrates with your security tools.
IBM® Guardium® Data Protection
Safeguard sensitive data using automated discovery, classification, monitoring and cognitive analytics.