Open-source SOAR for AI-native security teams — agents, workflows, and cases that security engineers own end-to-end, with an MCP catalog of security tools.
Open-source SOAR for AI-native security teams — agents, workflows, and cases that security engineers own end-to-end, with an MCP catalog of security tools.
Tracecat is an open-source SOAR (security orchestration, automation, and response) platform built for AI-native security teams. Unlike legacy SOAR products that are closed boxes of low-code playbooks, Tracecat ships as a self-hostable platform (3.5k+ GitHub stars) where teams write workflows and agents in YAML/Python, manage cases, and own the entire data plane. It includes a Workspace with Workflows, Cases, Agents, Skills, Tools, Tables, Members, Variables, and Integrations, and ships with an MCP catalog of pre-built security tools (cloud findings triage, OAuth grant revocation, endpoint isolation, etc.) that agents can call. Typical use cases include automatically triaging cloud findings from Wiz/Prowler, revoking risky OAuth grants from Google Workspace or Okta, isolating compromised endpoints, and enriching alerts with threat intel before they hit a human analyst. Tracecat is offered as a free open-source self-host and a managed Cloud/Enterprise tier — pricing for the managed plan is via Book a Demo. Best for security engineering teams that want a SOAR they can extend like software and pair with LLM agents under their own control.
Was this helpful?
Feature information is available on the official website.
View Features →Free
Contact sales
Contact sales
Ready to get started with Tracecat?
View Pricing Options →Weekly insights on the latest AI tools, features, and trends delivered to your inbox.
No reviews yet. Be the first to share your experience!
Get started with Tracecat and see if it's the right fit for your needs.
Get Started →Take our 60-second quiz to get personalized tool recommendations
Find Your Perfect AI Stack →Explore 20 ready-to-deploy AI agent templates for sales, support, dev, research, and operations.
Browse Agent Templates →