OpenSecOps Newsletter logo

OpenSecOps Newsletter

Archives
Subscribe
October 4, 2026

OpenSecOps SOAR 4.0.0: Current Claude Models

SOAR 4.0.0 is released. It moves SOAR's AI analyses to the current generation of Claude models on Amazon Bedrock. It is a major release because the AI configuration changes: two parameters are removed and six take their place, so an existing installation needs a small configuration edit before it can deploy.

Why

SOAR uses Claude to explain each security ticket, autoremediation and incident to the team that owns the account, and to write the weekly security report. Until now it ran on Claude Sonnet 4.5, named by a hand-written inference-profile ID in the configuration. The current Opus and Sonnet models produce better security analysis, but they take a different request (adaptive thinking with a configurable effort level) and they can decline requests. Keeping up with new models should not mean editing profile IDs or code each time, so the configuration now names models and SOAR works out the rest.

Declines and the fallback

Claude Opus 5.5, Opus 5 and Sonnet 5.5 have safety classifiers that can decline a request, and Anthropic notes that benign cybersecurity work can trigger them. SOAR's analyses are exactly that: defensive explanations of findings from AWS's own security services, sent only to security staff and the account's team. The prompts now state this purpose plainly, which removed most declines in our tests, but not all.

So SOAR 4.0.0 requires a fallback model. When the primary model declines, SOAR asks the fallback once. The recommended fallback is Claude Opus 4.8, which has no such classifiers. Each time the fallback answers, SOAR publishes a message to a new SNS topic, OpenSecOpsSOARAIFallbacks, so you can see how often it happens. Subscribe to it if you want to know. Failures of any kind still go to OpenSecOpsSOARExternalCallFailures, and the ticket, incident notification or report is still sent, without the AI text.

Configuration

Six keys in apps/soar/parameters.toml, all required:

Key Recommended Meaning
AIModel anthropic.claude-opus-5-5 The model for all analyses. Claude Opus 4.6 or Sonnet 4.6 or later.
AIFallbackModel anthropic.claude-opus-4-8 Used once when the primary declines. Choose a model without classifiers. none disables it.
AIRegion us-east-1 The Bedrock Region SOAR calls.
AILocality regional regional: processing stays within the Region's geography (US, EU, Japan, Australia and so on). global: any commercial Region worldwide, at slightly lower cost.
AIEffort high How much the model thinks before answering. Opus 5.5 accepts low, medium, high, xhigh and max.
AIMaxTokens 128000 Output cap, thinking included. At most the model's limit; 128000 for both recommended models.

SOAR asks the model for adaptive thinking with an effort level. Claude Opus 4.6 and Claude Sonnet 4.6 are the earliest models that accept both; Claude Sonnet 4.5, the model SOAR used until now, does not. Effort levels vary by model: Opus 4.6 and Sonnet 4.6, for example, have no xhigh.

An EU organisation that wants inference to stay in the EU sets AIRegion to an EU Region and keeps regional. Claude Sonnet 5.5 at high is a faster alternative to Opus 5.5; keep Opus 4.8 as its fallback.

Every deploy checks the configuration: SOAR looks up each model's inference profile in your Region and calls each model once. A wrong model ID, a model without a profile in the Region, an effort level or token cap the model rejects, or a model the account cannot use stops the deploy with the reason, and the previous version keeps running.

SOAR 4.0.0 supports Claude models only. We intend to open it to more models in coming releases.

Also in this release

  • AI error handling is consistent: every AI step retries transient Bedrock errors and reports a failure once. Before, some steps caught only timeouts and some caught nothing.
  • Fresh installations of SOAR and of Foundation-control-tower-log-aggregator failed on two custom resources (one since SOAR 3.0.0 and log-aggregator 1.6.0, one since SOAR 2.4.1). This is fixed, and a custom resource that does not respond now fails the deploy after 5 minutes instead of an hour. The log-aggregator fix is in its 1.6.7 release.
  • The 1 October component releases moved urllib3 to 2.8.0 wherever it is used, fixing CVE-2026-97687, CVE-2026-97688 and CVE-2026-97689. ./init installs them along with this release; nothing else is needed.

Upgrading

  1. cd Installer && git pull, then ./init on both Foundation and SOAR.
  2. In apps/soar/parameters.toml, delete the BedrockRegion and BedrockModel lines and copy in the six AI lines from apps.example/soar/parameters.toml. Adjust the values if you want.
  3. ./deploy-all, as usual.

Without step 2, the SOAR deploy stops before changing anything, with Parameters: [AIFallbackModel, AIEffort, AIModel, AIMaxTokens, AIRegion, AILocality] must have values.

One prerequisite, which most installations already meet: Anthropic's one-time use-case form must have been submitted for the organisation (organisations already using Claude on Bedrock have done so). Each model's Marketplace subscription is created automatically on first use.

More information

  • SOAR CHANGELOG.md, v4.0.0: the complete list of changes.
  • Anthropic: Refusals and fallback.
  • AWS: cross-Region inference (regional versus global) and model access (the use-case form).
Don't miss what's next. Subscribe to OpenSecOps Newsletter:
Older → The supply-chain work is done
GitHub
www.opensecops.org
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.