Tracecat
Open source SOAR platform with workflow automation, cases, and AI-assisted playbook building.
Technical Architecture & Overview
Tracecat is an open source security automation platform combining workflow orchestration, case management, and tables in one self-hostable deployment. It integrates with SIEMs, EDRs, and ticketing through a growing connector set, and its AI features generate workflow scaffolding from natural language descriptions. The project markets itself as an open alternative to Tines and Splunk SOAR.
Targeted Technical Use Cases
Teams that want SOAR automation without enterprise licensing, using code-reviewable workflows.
Evaluation & Trade-offs
Core Strengths
- +Self-hosted with a fast-moving development pace.
- +Workflows, cases, and enrichment in one tool.
- +AI-assisted authoring shortens playbook work.
Trade-Offs & Limitations
- -Younger platform with a smaller integration library.
- -AGPL licensing needs review for some deployments.
Defensive Security Application
Automating alert triage, enrichment, and response actions across security tooling.
Frequently Asked Questions
What is Tracecat?→
Tracecat is an open source security automation platform combining workflow orchestration, case management, and tables in one self-hostable deployment. It integrates with SIEMs, EDRs, and ticketing through a growing connector set, and its AI features generate workflow scaffolding from natural language descriptions. The project markets itself as an open alternative to Tines and Splunk SOAR.
What is Tracecat used for?→
Teams that want SOAR automation without enterprise licensing, using code-reviewable workflows.
What are the strengths of Tracecat?→
- +Self-hosted with a fast-moving development pace.
- +Workflows, cases, and enrichment in one tool.
- +AI-assisted authoring shortens playbook work.
What are the limitations of Tracecat?→
- +Younger platform with a smaller integration library.
- +AGPL licensing needs review for some deployments.
How is Tracecat used defensively?→
Automating alert triage, enrichment, and response actions across security tooling.