SOARCA Logo

SOARCA

0
Free
Visit Website

SOARCA is an open-source Security Orchestration, Automation and Response (SOAR) tool that automates threat and incident response workflows using CACAO security playbooks. It supports standardized formats and technologies, including CACAOv2 and OpenC2, and allows for extensibility and customization. It can ingest, validate, and execute CACAOv2 security playbooks via a JSON API and has native capabilities for http(s), SSH, and OpenC2 interfaces. Additionally, it has an MQTT interface for adding custom integrations. The tool is designed for research and innovation purposes, allowing SOC, CERT, and CTI professionals to experiment with playbook-driven security automation.

FEATURES

ALTERNATIVES

Tool to bypass endpoint solutions blocking known 'malicious' signed applications by obtaining valid signed files with different hashes.

An investigative analytics platform that uses machine learning to fuse and analyze data from multiple sources, enabling security organizations to extract insights and identify patterns for threat prevention and complex investigations.

A collaborative and open-source incident response platform for sharing observables among analysts.

Dispatch helps manage security incidents by integrating with existing tools and automating incident response tasks.

A remediation orchestration platform that consolidates security alerts, automates triage, and streamlines the remediation process across hybrid environments.

A module-based AWS response tool for incident response in AWS environments.

CrowdStrike Falcon Orchestrator is a Windows-based application for workflow automation and security response.

Workflows for Shuffle automation tool with structured categories and customization options.

PINNED