These technologies are complementary.

It centralizes and analyzes events from numerous sources.

Primarily monitors endpoints and provides detection and response capabilities on these devices.

Seeks to correlate signals from multiple security domains, according to the provider's architecture.

SOAR

Automates security and response processes.

Therefore, we can have:

EDR → SIEM → SOAR

The EDR provides data.

The SIEM correlates and analyzes.

SOAR can automate certain actions.

Categories: