Automate. Orchestrate. Measure.
IncMan SOAR is the pioneering Security Orchestration, Automation & Response platform to automate, orchestrate and measure CSIRTs and SOCs.
Named as a finalist by
WHAT WE DO
DFLabs IncMan Security Orchestration, Automation and Response platform enables you to automate, orchestrate and measure security operations and incident response processes and tasks.
Minimize resolution time by 90%
Maximize analyst efficiency by 80%
Increase handled incidents by 300%
Supervised Active Intelligence TM driven by Machine Learning
DFLabs R3 Rapid Response Runbooks fully automate the triage, investigation and containment of incidents using conditional actions and 99+ included automation actions that allow workflows to execute a variety of data enrichment, notification, containment and custom actions based on complex, stateful and logical decision making.
Our patent-pending Automated Responder Knowledge (ARK) module applies machine learning to historical responses to threats, and recommends relevant playbooks and paths of action to manage and mitigate them.
Cyber Incidents under Control TM
DFLabs IncMan drives intelligence-driven command and control of your security operations. Orchestrate the full incident response and investigation life cycle for your SOC and CSIRT. Empower security analysts, forensic investigators and incident responders to respond to, track, predict and visualise cyber security incidents. Enable security managers and CISO’s to manage and measure operational performance and cyber risk.
Apply linear or conditional playbooks that support complex, stateful and conditional logical decision making combining manual and automated actions, with 100+ included playbook templates.
Aggregate, correlate and analyze data from hundreds of leading 3rd party security and threat intelligence sources with 45+ certified bidirectional connectors and a restful API for custom integrations.
Maintain and transfer expertise with machine-learning driven Automated Responder Knowledge (ARK). Manage incidents across stakeholders collaboratively and securely.
Full Incident Phase Management
Measure, benchmark and optimise Security Operations and Incident Response activities and performance with 140+ KPI’s and reports. Role-based dashboards and customizable widgets produce real-time situational awareness of the state of your security operations and risk exposure. Measure every individual phase of the IR workflow. Visualise and analyse threats.
DFLabs Research Resources
Insights, Best Practices and News
Webinar: Leverage Your SIEM Solution Utilizing SOAR Technology
Join this webinar to see how DFLabs SOAR and LogPoint SIEM work seamlessly together fusing intelligence to improve the overall effectiveness and operational performance of your existing security program.
SANS 2018 SOC Survey Report “The Definition of SOC-cess”
The SANS 2018 SOC Survey sponsored by DFLabs provides an all-round perspective of what SOCs look like within today’s organizations across the globe.
Whitepaper: How To Leverage Your Existing SIEM Tool With SOAR Technology - A DFLabs and LogPoint Use Case
Learn about the benefits of combining SIEM and SOAR technology and how to integrate LogPoint SIEM and DFLabs SOAR in order to get the best of both worlds.
Whitepaper: Security Orchestration, Automation and Response (SOAR) Technology
A SOAR solution acts force multiplier for security analysts. Discover how a SOAR platform can help your security operations overcome the increasing volume of alerts.
IncMan supports hundreds of 3rd party security technologies via QIC, API, CEF, Syslog, and Email with a constantly growing list of certified bidirectional integrations.