Open source security automation platform
Automate security alerts, your way.
Tracecat is an open source Tines / Splunk SOAR alternative. Build AI-assisted workflows, orchestrate alerts, and close cases fast.
A security automation platform built for builders.
Experiment For Free
Deploy Tracecat on your own infrastructure or use Tracecat Cloud with no maintenance overhead.
Apache-2.0 Licensed
Open vision, open community, open development. Have your say in the future of security automation.
No-Code First. Code As Well.
Build automations fast with no-code. Customize without vendor lock-in using Python.
New Feature
Turn security alerts into solvable cases
Click-and-drag workflow builder
Automate SecOps using pre-built actions (API calls, webhooks, data transforms, AI tasks, and more) combined into workflows. No code required.
Built-in case management system
Open cases direct from workflows. Track and manage security incidents all-in-one platform.
More features
Unlimited workflows for everyone
Create unlimited workflows
Build as many workflows as you need. Trigger workflows in response to alerts or schedule workflows to run as cron jobs. Automate and integrate without limit.
Collaboration and tenants (coming soon)
Edit workflows and manage cases as a team. Use tenants to isolate sensitive data and credentials between users.
12 comments
0 files
Monitor alert trends
Automated alert SLO tracking (e.g. number of alerts processed / number of cases resolved).
Integrations that matter
10+ must have integrations for every SecOps team. Can't find the integration you need? Build your own using Tracecat's Python SDK and share it with the open source community!
Open Source AI Case Management
An AI that learns from past incidents
Use specialized AI models to label, summarize, and enrich alerts. Contextualize alerts with internal evidence and external threat intel. All open source. No black box.
Find cases using semantic search
MITRE ATT&CK labels
Whitelist / blacklist identities
Categorize related cases
MITRE D3FEND suggestions
Upload evidence and threat intel
Pricing & Plans
Cheaper than a missed true positive
Cloud Hosted
Support on Discord / Slack
Cancel Anytime