Tracecat | Security engineering teams and MSSPs that want to build, version, self-host, and own their agents, workflows, and cases. | The AGPL core runs AI and agent actions inside workflows. Enterprise adds a reusable agent builder. Preset agents bundle reusable skills with tools, tables, resources, and MCP servers. They run across workflows, cases, and chat. | Customizable cases and custom fields ship in the AGPL core. Reusable agents inside cases, human approvals, case triggers, tasks, metrics, and customer-owned Git sync require Enterprise. | Enterprise syncs workflows and workspaces to customer-owned GitHub, GitLab, and Bitbucket repositories. The AGPL core includes a separate custom Python registry. | AGPL self-hosting on Docker or Fargate. Air-gapped deployments available. Enterprise adds Kubernetes Helm deployment. |
|---|
Torq | Enterprise SOCs that want a hosted AI SOC platform, accept a vendor-operated control plane, and need self-hosted runners for private execution. | Multi-agent investigation, case handling, and response built inside Torq. | Native case management for investigation through remediation. | Visual and agentic building inside Torq. No verified customer-owned Git model. | Vendor-operated control plane. Self-hosted Step Runners on Docker, Kubernetes, or Podman for private execution. No full self-hosted control plane verified. |
|---|
BlinkOps | Teams that want a no-code agent builder, workflows, and cases from one hosted vendor, with runners for private networks. | No-code agent builder, reusable and custom micro-agents, Analyst Copilot, and approval gates. | Native case management with tables and dashboards. | No-code builder. No verified customer-owned Git model. | Vendor-operated control plane. Cloud or self-hosted runners in Docker or Kubernetes. |
|---|
Swimlane | Enterprise SOCs standardized on low-code playbooks that want on-premises deployment from a commercial vendor. | Hero AI companion, an AI Agent Builder for tailoring expert agents, and AI SOC workflows, all inside Turbine. | Integrated security case management. | Low-code components versioned through Git integration. Logic stays in Swimlane's format. | Cloud or on-premises. |
|---|
Cortex XSOAR | Large SOCs already standardized on Palo Alto Networks that want the content pack library and the AgentiX upgrade path. | System and custom agents through Cortex AgentiX, positioned as the next generation of XSOAR. | Integrated incident management. | Python and JavaScript automations. Remote Git content repositories on supported setups. | Cloud or on-premises. |
|---|
Google Security Operations (Chronicle SOAR) | Enterprises already on Google Security Operations or Google Cloud that want SIEM, threat intelligence, cases, and response automation from one Google-managed platform. | Gemini assistance and a Google-provided Triage and Investigation Agent. The agent has fixed built-in tools, reads only SIEM-ingested alerts rather than SOAR connector alerts, and carries documented throughput limits. A managed remote MCP server and a pre-GA Detection Engineering Agent for external clients extend access. There is no reusable BYO agent builder or skills registry. | Native case management with alert grouping, queues, tasks, collaboration, and audit history. Case-level playbooks are pre-GA and not available to every customer in every region. | Visual playbooks and reusable blocks, plus a Python IDE for custom integrations. Google documents built-in versioning, export, and rollback. No customer-owned Git sync appears in the reviewed materials. | Google-managed cloud control plane. Remote Agents execute integrations, connectors, and jobs near private systems. No customer-hosted control plane is documented. |
|---|
Splunk SOAR | Splunk Enterprise Security customers that want orchestration and cases from the vendor they already run. | No standalone agent builder. AI through the broader Splunk security platform. | Integrated case management. | Visual Playbook Editor, Python playbooks, and Git repositories. | Cloud, on-premises, or hybrid. |
|---|
D3 Security | Enterprises that want vendor-defined autonomy controls and on-premises or air-gapped deployment from a proprietary platform. | Vendor-defined autonomy modes and governed response on a deterministic SOAR engine. | Unified case management with one audit trail. | Proprietary playbook format. No verified customer-owned Git model. | Cloud, on-premises, hybrid, sovereign, and air-gapped. Native multi-tenancy. |
|---|
DFIR IRIS | Teams that want a free, self-hosted case and evidence system and already run automation elsewhere. | None. The documentation shows no AI or agent features. | Cases with assets, IOCs, timeline, evidence, notes, tasks, and alerts. Real-time war rooms for collaboration. | LGPL v3 source. Python modules extend the core through pipeline and processor hooks. REST API and a Python client. | Self-hosted on Docker Compose. Helm and Kustomize starting points for Kubernetes. |
|---|
Shuffle | Teams that need free visual SOAR and accept maintaining a pre-agent platform themselves. | AI Agent action added in 2025. Agents call Shuffle apps as MCP tools with action approvals. Approvals do not yet notify in real time. Agent-built workflows are still marked coming soon. | No native case management. Case actions create and update tickets in third-party tools. Shuffle Security with incident management is a separate roadmap item. | AGPL v3 backend with MIT apps, workflows, and App SDK. Apps come from OpenAPI specs or Python. Workflows back up to GitHub. No two-way sync from repositories you own. | Self-hosted on Docker Compose. Docker Swarm or Kubernetes for scaled runtime locations. Shuffle Cloud SaaS and a hybrid mode. |
|---|
n8n | Teams automating across departments where security is one workload among many and cases live in another tool. | AI agent and model nodes inside general-purpose workflows. | No native security case management. Cases live in another tool. | Source control on qualifying commercial plans. | Self-hosted or n8n Cloud. |
|---|