Skip to main content

Cloud-delivered Incident ResponderIncident Responder Documentation

Incident Responder

Incident Responder automates your repetitive and manual tasks using actions and playbooks so you quickly investigate and respond to incidents.

Exabeam Incident Responder is a security orchestration, automation, and response (SOAR) solution that features playbooks and a visual editor. With Incident Responder, your SOC works more productively, makes less mistakes, and quickly resolves security incidents.

If you're an overburdened analyst, integrated services and automated workflows help you avoid repetitive tasks, like looking up the reputation of an IP address, and switching between security tools.

If you're a SOC manager, Incident Responder helps you deal with a shortage of talent. You create and maintain playbooks using a simple drag-and-drop editor, no coding experience required. You can even use playbook templates to teach junior analysts about your organization's best practices for common scenarios, like phishing and malware.

If you have a legacy license, Incident Responder requires a separate license from Advanced Analytics. If you have a Fusion license or Exabeam Security Operations Portfolio license, you can run all Incident Responder turnkey playbooks. To edit any playbook, create and run custom playbooks, and integrate third-party services, you must have a separate Incident Responder add-on. To learn more, contact your Exabeam representative or open a case on the Exabeam Community.