Intezer Adds Native Response Automation with Integrated SOAR
Intezer introduces integrated response automation capabilities within its platform, eliminating the need for external SOAR solutions.
Intezer Launches Workflows for Automated Response
Intezer has launched Workflows, a built-in automation and response tool that allows security teams to design and implement custom response procedures directly within the Intezer platform. This innovation integrates response mechanisms into the same environment where threat alerts are analyzed and evaluated, enabling organizations to automate follow-up actions without relying on separate Security Orchestration, Automation, and Response (SOAR) systems.
Addressing the Gap in Response Processes
While security teams can rapidly investigate alerts, response processes frequently occur in isolated systems. Once a determination is made, teams often depend on standalone SOAR platforms, custom integrations, or manual procedures to resolve alerts, inform analysts, isolate affected systems, update tickets, or perform other remediation tasks. Workflows bridges this gap by embedding customizable response automation directly into the Intezer AI SOC, allowing actions to execute immediately with the full investigation context available.
“As adversaries leverage AI to scale their attacks, security operations must operate at machine-level efficiency,” stated Itai Tevet, CEO of Intezer. “Combining deep forensic analysis with tailored automated response enables teams to accelerate remediation and close the loop more effectively. Workflows integrates response into the same environment where investigations occur, allowing organizations to expand AI-driven security operations across the entire SOC lifecycle.”
Insights from the Intezer AI SOC Report 2026
The Intezer AI SOC Report 2026 revealed that nearly 1% of actual incidents originated from alerts categorized as the lowest severity level. For an enterprise generating 450,000 alerts annually, this equates to approximately 54 genuine threats per year, or about one per week, that might remain unaddressed. The report underscores the importance of comprehensive alert coverage. SOAR solutions that operate on limited alert visibility and shallow analysis inherit similar limitations. By conducting forensic-level analysis on every alert, Intezer can detect low-severity threats and initiate response actions once a conclusion is reached.
Core Features of Intezer Workflows
Integrated Response Logic Within the AI SOC
Teams can develop response workflows directly in Intezer without requiring a separate SOAR system. Workflows can resolve alerts, isolate endpoints, update tickets, notify analysts, and trigger other actions across the security infrastructure based on investigation outcomes, eliminating the need for additional APIs or polling.
Natural-Language Workflow Creation
Users can specify desired actions using plain language through Intezer’s MCP, then review, refine, test, and deploy the generated workflow within the platform.
Investigation Context in Response Operations
Workflows utilizes the evidence, data, and organizational context collected during the investigation. Actions are documented in the relevant alert or case, with each execution logged for audit and troubleshooting purposes.
Benefits for Managed Security Service Providers (MSSPs)
For managed security service providers (MSSPs), Intezer Workflows can automate client communications and tenant-specific routing that would otherwise require manual intervention.
