Operations

Playbooks & SOARNew

Define, store, and execute security response playbooks with full SOAR automation — quarantine endpoints, disable AD accounts, revoke MS365 sessions, and block IPs at the firewall automatically without human approval.

Playbooks & SOAR

Automated response, orchestration, and remediation

What it does

Key capabilities

Playbook Builder

Create structured response playbooks with step-by-step procedures, decision trees, and fully automated remediation actions.

SOAR Automation

Automatically quarantine endpoints via SentinelOne, Defender, or CrowdStrike — no human approval required for speed-critical responses.

Identity Response

Disable AD accounts and revoke Microsoft 365 sessions instantly via MS Graph API when credential compromise is detected.

Network Containment

Push IP blocks to your firewall automatically when malicious infrastructure is detected — integrated with Firewall Manager accounts.

Execution Tracking

Real-time tracking of playbook execution progress with a full audit trail for post-incident review.

Compliance Evidence

Playbook execution records provide documented incident response evidence for ISO 27001 and regulatory audits.

Highlights

Why Playbooks & SOAR?

  • SOAR-grade automation — quarantine, disable, block, revoke
  • SentinelOne, Defender, CrowdStrike endpoint isolation supported
  • MS Graph integration for AD and MS365 session response
  • Full execution audit trail for compliance evidence
  • Reduces MTTR from hours to seconds on critical incidents
Included in OneView

Playbooks & SOAR is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

Playbooks can automatically quarantine endpoints via SentinelOne, Microsoft Defender, or CrowdStrike isolation APIs; disable Active Directory user accounts via LDAP; revoke all active Microsoft 365 sessions via the MS Graph API; and push IP block rules to your connected firewall through the Firewall Manager integration — all without human approval.

Yes. Playbooks integrate with the Event Manager so specific event patterns — a confirmed malware detection, a ransomware indicator, a critical UBA anomaly — can trigger a defined Playbook automatically. The playbook executes in seconds, reducing mean time to contain from hours to near-instant for well-defined threat scenarios.

You define which actions require human approval and which execute automatically. High-confidence, reversible actions like network quarantine can be fully automated. Actions with broader impact — like disabling a service account or blocking an IP range — can be configured to pause and require analyst confirmation before executing.

ISO 27001 Annex A.5.26 requires incident response procedures to be implemented and their application recorded. Every Playbook execution generates an immutable audit record — which playbook ran, which actions were taken, timestamps, and the analyst or trigger that initiated it — providing the incident response evidence trail that auditors require.

See Playbooks & SOAR in action

Request a personalised demo and we'll show you exactly how Playbooks & SOAR works within your environment.