Tracecat | AI-native security teams that want agents, workflows, cases, and automation-as-code. Tracecat also supports full self-hosting and any LLM provider or gateway. | The open source edition includes AI and agent actions inside workflows plus Tracecat MCP for coding assistants. Enterprise adds the agent builder, preset agents, skills, and 65+ hosted MCP servers curated and maintained by Tracecat. The same preset agent works across workflows, cases, and chat. | Case management includes custom fields, comments, and attachments. Enterprise adds tasks, linked table rows, triggers, metrics, and agent mentions. Tables provide structured storage with lookup and search. | Enterprise Git sync exports workflows, preset agents, skills, table schemas, and case configuration to customer-owned GitHub, GitLab, or Bitbucket repositories. | Managed cloud or full self-hosting with Docker or AWS Fargate. Enterprise adds Kubernetes Helm deployment. |
|---|
Torq | Enterprise SOCs that want a hosted AI SOC platform with self-hosted runners for private execution. | Multi-agent investigation, case handling, and response built inside Torq. | Native case management for investigation through remediation. | Visual and agentic building inside Torq. No verified customer-owned Git model. | Vendor-operated control plane. Self-hosted Step Runners on Docker, Kubernetes, or Podman for private execution. No customer-hosted control plane is documented. |
|---|
BlinkOps | Teams that want a no-code agent builder, workflows, and cases from one hosted vendor, with runners for private networks. | No-code agent builder, reusable and custom micro-agents, Analyst Copilot, and approval gates. | Native case management with tables and dashboards. | No-code builder. No verified customer-owned Git model. | Vendor-operated control plane. Cloud or self-hosted runners in Docker or Kubernetes. |
|---|
D3 Security | Enterprises that want vendor-defined autonomy controls and on-premises or air-gapped deployment from a proprietary platform. | Vendor-defined autonomy modes and governed response on a deterministic SOAR engine. | Unified case management with one audit trail. | Proprietary playbook format. No verified customer-owned Git model. | Cloud, on-premises, hybrid, sovereign, and air-gapped. Native multi-tenancy. |
|---|
Swimlane | Enterprise SOCs standardized on low-code playbooks that want on-premises deployment from a commercial vendor. | Hero AI companion, an agent builder for custom expert agents, and AI SOC workflows inside Turbine. | Integrated security case management. | Low-code components versioned through Git integration. Logic stays in Swimlane's format. | Cloud or on-premises. |
|---|
Cortex XSOAR | Large SOCs already standardized on Palo Alto Networks that want the content pack library and the AgentiX upgrade path. | System and custom agents through Cortex AgentiX. | Integrated incident management. | Python and JavaScript automations. Remote content repositories in Git for dev and prod setups. | Cloud or on-premises. |
|---|
Google Security Operations (Chronicle SOAR) | Enterprises already on Google Security Operations or Google Cloud that want SIEM, threat intelligence, cases, and response automation from one Google-managed platform. | Gemini assistance and a Google-provided Triage and Investigation Agent with fixed built-in tools. A managed remote MCP server and a pre-GA Detection Engineering Agent extend access. No customer-defined agent builder or skills registry. | Native case management with alert grouping, queues, tasks, collaboration, and audit history. Case-level playbooks are pre-GA and not available to every customer in every region. | Visual playbooks and reusable blocks, plus a Python IDE for custom integrations. Google documents built-in versioning, export, and rollback. No customer-owned Git sync appears in the reviewed materials. | Google-managed cloud control plane. Remote Agents execute integrations, connectors, and jobs near private systems. No customer-hosted control plane is documented. |
|---|
Splunk SOAR | Splunk Enterprise Security customers that want orchestration and cases from the vendor they already run. | No standalone agent builder. AI features come from the broader Splunk security platform. | Integrated case management. | Visual Playbook Editor, Python playbooks, and Git repositories. | Cloud, on-premises, or hybrid. |
|---|
DFIR IRIS | Teams that want a free, self-hosted case and evidence system and already run automation elsewhere. | None. The documentation shows no AI or agent features. | Cases with assets, IOCs, timeline, evidence, notes, tasks, and alerts. Real-time war rooms for collaboration. | LGPL v3 source. Python modules extend the core through pipeline and processor hooks. REST API and a Python client. | Self-hosted on Docker Compose. Helm and Kustomize starting points for Kubernetes. |
|---|
Shuffle | Teams that need free visual SOAR and accept maintaining a pre-agent platform themselves. | AI Agent action added in 2025. Agents call Shuffle apps as MCP tools with action approvals. Approvals do not yet notify in real time. Agent-built workflows are still marked coming soon. | No native case management. Case actions create and update tickets in third-party tools. Shuffle Security with incident management is a separate roadmap item. | AGPL v3 backend with MIT apps, workflows, and App SDK. Apps come from OpenAPI specs or Python. Workflows back up to GitHub. No two-way sync from repositories you own. | Self-hosted on Docker Compose. Docker Swarm or Kubernetes for scaled runtime locations. Shuffle Cloud SaaS and a hybrid mode. |
|---|
n8n | Teams automating across departments where security is one workload among many and cases live in another tool. | AI agent and model nodes inside general-purpose workflows. | No native security case management. Cases live in another tool. | Source control on qualifying commercial plans. | Self-hosted or n8n Cloud. |
|---|