ManageEngine, a division of Zoho Corporation and a leading provider of enterprise IT management solutions, today announced a core architecture upgrade in Log360, its unified security platform, introducing native SOAR capabilities, seven new integrations with some of the industry's leading security vendors, and cross-domain orchestration capabilities that places detection, AI investigation, and automated response in a single data model. Security operations are entering the agentic automation era, albeit with infrastructure that was not built for it.
ManageEngine announces native SOAR built into Log360 unified security platform with low-code playbook builder.
Adds seven new integrations across leading EDR, identity, and threat intelligence platforms for cross-domain orchestration.
Includes CDN-delivered library of prebuilt response templates for automation on day one.
Playbooks can isolate endpoints, revoke compromised credentials, open service tickets, and enforce response actions.
Analysts extend workflows through low-code Zoho Qntrl; engineers use Python or Deluge.
Free trial available at www.mnge.it/soar.
Log360's native SOAR is engineered for shared context. A single playbook can isolate an endpoint through EDR, revoke a compromised session through IAM, enrich the incident with external threat intelligence, open a service ticket, and notify the SOC, all driven by the same alerts, detections, and behavioral signals the platform already produces.
“The next evolution in security operations is about rethinking the architecture so that AI, detection, and response share the same foundation,” said Manikandan Thangaraj, vice president of ManageEngine. “When an AI investigation agent and an orchestration engine operate over the same data model, the friction that has kept security teams reactive for years is eliminated. No API handoffs, no reconstructing context, no gap between insight and action. The best automation isn't prescriptive, it's programmable. That's what we've built into Log360.”
Expert playbooks, ready on day one: A CDN-delivered library of prebuilt response templates means automation is live on day one. When teams are ready to go deeper, analysts extend workflows through low-code platform Zoho Qntrl, while engineers take full control with Python or Deluge. The approach allows teams to build once and continuously adapt workflows to evolving environments and compliance requirements.
Automated response across the entire stack: One automated workflow can isolate endpoints, revoke compromised credentials, open service tickets, and enforce response actions across EDR platforms, network infrastructure, and business applications, eliminating manual handoffs between teams and tools.
Context-aware incident response: Playbooks enrich alerts with threat intelligence and asset context, apply conditional logic to route incidents by severity or compliance scope, and execute multi-step response sequences automatically without human intervention.
Endpoint coverage that closes the cross-domain gap: Endpoint telemetry, along with identity and cloud context, is brought into Log360's correlation and response layer to track and contain threats from a single platform.
Log360 is a unified SIEM solution with integrated DLP, CASB, and SOAR capabilities that detects, prioritizes, investigates, and responds to security threats. Vigil IQ, its TDIR module, combines threat intelligence, an Incident Workbench, ML-based anomaly detection, and rule-based attack detection to surface sophisticated attacks alongside an incident management console for remediation. Reengineered detection with a centralized console, multi-mode rule creation, and tuning insights elevates signal quality and reduces false positives. Native SOAR, with a built-in orchestration engine and extensible playbook library, automates responses across your security stack, closing the gap between detection and action.
ManageEngine is a division of Zoho Corporation and a leading provider of IT management solutions for organizations across the world. With a powerful, flexible, and AI-powered digital enterprise management platform, we help businesses get their work done from anywhere and everywhere—better, safer, and faster.