✍️Writing & Content24🎨Image Generation32🎬Video & Animation65🎵Audio & Music49💬Chatbots & Assistants37💻Coding & Development165📈Marketing & SEO52Productivity142🎯Design & UI/UX53📊Data & Analytics37📚Education & Research24💼Business & Finance50🏥Healthcare & Wellness18🔍Search & Knowledge14🤖AI Agent Infrastructure33🛡️AI Security & Testing3🧊3D & Spatial14🔎SEO Tools5🏡Real Estate4🗃️Data Extraction3🧠ADHD & Focus Tools9
Listed in AI Security & Testing with 3 other toolsPart of 969+ curated AI tools on AISO
Tracecat logo

Tracecat

Open-source SOAR for AI-native security teams — agents, cases, and workflows with human approval gates

0
freemiumOpen source tier is free forever, self-hosted, with unlimited workflows and cases, prebuilt integrations, SSO and audit trails, and Docker or AWS Fargate deployment. Enterprise is custom-priced and adds advanced agents, RBAC/SCIM, guardrails, a Kubernetes Helm chart, a forward-deployed security engineer, and 24/7 support.View full pricing →

Visit Tracecat

https://tracecat.com

About Tracecat

Tracecat is an open-source SOAR — security orchestration, automation, and response — rebuilt for teams that want to run security agents alongside traditional workflows. The pitch is leverage: turn analysts into builders and builders into architects so a team of three can do the work of thirty, replacing the static, brittle playbooks of legacy SOAR with custom agents you own. The platform is organized around agents, cases, and workflows, with a skills registry and MCP inventory so agents reach tools like Wiz and CrowdStrike Falcon through MCP connections rather than bespoke integrations. A representative flow from the site: a Wiz cloud finding fires, a SOC analyst agent pulls associated assets and CloudTrail context, correlates with EDR telemetry from Falcon, opens a case, and proposes containment — then waits for a human to approve before isolating the host and revoking session tokens. Human approval gates are first-class rather than an afterthought. The open-source tier is free forever and genuinely usable: unlimited workflows and cases, Tracecat MCP for prompt-to-automation, prebuilt integrations, lookup tables, SSO and audit trails included, and deployment via Docker or AWS Fargate. Enterprise adds advanced agents and cases, RBAC and SCIM, agent guardrails, git-native version control, a Kubernetes Helm chart, a forward-deployed security engineer, and 24/7 support.

Key Features

Agents, cases, and workflows in one open-source platform
MCP connections to tools like Wiz and CrowdStrike Falcon
Human approval gates before containment actions execute
Prompt-to-automation via Tracecat MCP
Free self-hosted tier with SSO and audit trails included
Docker, AWS Fargate, or Kubernetes Helm deployment

Tracecat Pros & Cons

Pros

  • +The free tier includes SSO and audit trails, which competitors gate
  • +MCP-native, so new tool integrations are not bespoke work
  • +Approval gates keep destructive actions under human control

⚠️ Cons

  • Enterprise pricing is fully custom with no starting figure
  • Self-hosting a SOAR is real operational work

Tags

soarsecurity automationopen sourcemcpsocincident response
🏷️

Is this your tool?

Claim your listing to get a Featured badge, edit your description, and stand out from competitors. All plans include a permanent dofollow backlink to your site.

Claim Now →

ChatGPT already recommends Tracecat. Does it recommend yours?

If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

Stay updated on AI Security & Testing tools — join our weekly newsletter

One concise email with fresh launches, trending picks, and featured standouts.

Alternatives to Tracecat

View all Tracecat alternatives →

Agent connectivity: not yet verified