Tracecat
Open-source SOAR for AI-native security teams — agents, cases, and workflows with human approval gates
0Visit Tracecat
tracecat.comAbout Tracecat
Tracecat is an open-source SOAR — security orchestration, automation, and response — rebuilt for teams that want to run security agents alongside traditional workflows. The pitch is leverage: turn analysts into builders and builders into architects so a team of three can do the work of thirty, replacing the static, brittle playbooks of legacy SOAR with custom agents you own. The platform is organized around agents, cases, and workflows, with a skills registry and MCP inventory so agents reach tools like Wiz and CrowdStrike Falcon through MCP connections rather than bespoke integrations. A representative flow from the site: a Wiz cloud finding fires, a SOC analyst agent pulls associated assets and CloudTrail context, correlates with EDR telemetry from Falcon, opens a case, and proposes containment — then waits for a human to approve before isolating the host and revoking session tokens. Human approval gates are first-class rather than an afterthought. The open-source tier is free forever and genuinely usable: unlimited workflows and cases, Tracecat MCP for prompt-to-automation, prebuilt integrations, lookup tables, SSO and audit trails included, and deployment via Docker or AWS Fargate. Enterprise adds advanced agents and cases, RBAC and SCIM, agent guardrails, git-native version control, a Kubernetes Helm chart, a forward-deployed security engineer, and 24/7 support.
Does ChatGPT recommend your AI tool?
If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.
Key Features
Tracecat Pros & Cons
✅ Pros
- +The free tier includes SSO and audit trails, which competitors gate
- +MCP-native, so new tool integrations are not bespoke work
- +Approval gates keep destructive actions under human control
⚠️ Cons
- −Enterprise pricing is fully custom with no starting figure
- −Self-hosting a SOAR is real operational work
Tags
Is Tracecat your tool?
This is the page buyers and AI assistants read when they look up Tracecat. Claim your listing for $19 one-time — no subscription, nothing to cancel — and get a Featured badge, top placement in your category, and a permanent dofollow backlink. Prefer it ongoing? Monthly is one click away on the next page.
Complete Your Security Stack
Other security tools in our catalog:
1Password
Try FreeSecrets and credential manager
Keep API keys and .env secrets out of your repo
Gamma
Try FreeAI presentation builder
Turn ideas into polished decks instantly
AdCreative.ai
Try FreeAI-powered ad creatives
Generate marketing visuals in seconds
💰 Affiliate disclosure: We may earn a commission if you sign up through these links at no extra cost to you.
Stay updated on AI Security & Testing tools — join our weekly newsletter
One concise email with fresh launches, trending picks, and featured standouts.
Alternatives to Tracecat
View all Tracecat alternatives →More AI Security & Testing tools
Trestle
Local secret scanner with an MCP server so coding agents check their own output
Axtary
Payload-bound authorization for AI agents — human approval is cryptographically tied to the exact action, so a changed payload is denied
Lineation
Security control plane for AI agents — zero-trust agent identity, LLM and MCP gateways, policy-as-code, and prompt-injection defense
Vibe App Scanner
Attack-grade security scanning for AI-built apps with agent-ready fixes over MCP and weekly monitoring, first scan free, from $19/mo
VibeDoctor
149+ automated security, performance, and quality checks plus ongoing monitoring for AI-built apps
Sneaky Peek AI
Everyday AI utilities and calculators, free to try with Pro for higher limits.
Agent connectivity: not yet verified