Tracecat
Open source AI-native SOAR for security automation
Best open-source SOAR for teams that prefer AI agent-based automation over static playbooks. Recent MCP and skills updates lower the barrier, but it still demands development investment. Not a plug-and-play replacement for traditional SOAR.
Verified 17d ago · liveness 95/100 · cite: rightaichoice.com/tools/tracecat
- Security teams wanting custom AI agents for automation
- Startups and mid-size companies seeking open-source SOAR
- Teams with engineering talent who prefer self-hosted security automation
- Cloud-native security operations needing flexible integration via MCP servers
- Teams needing plug-and-play SOAR with pre-built playbooks
- Organizations without in-house development resources for agent building
- Teams that prefer vendor-supported closed-source solutions with SLAs
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip Tracecat if you need a plug-and-play SOAR with pre-built playbooks and no custom development work.
You must bring your own LLM API keys (e.g., OpenAI, Anthropic), adding variable cost.
Tracecat's Open Source tier is free forever with unlimited workflows and cases, making it extremely cost-effective for startups. The Enterprise tier is custom-priced, likely higher than n8n's Team plan ($50/mo) but cheaper than Tines ($15K+/yr). Best for teams who can self-host.
In short
Tracecat — Open source AI-native SOAR for security automation. Best for Security teams wanting custom AI agents for automation, Startups and mid-size companies seeking open-source SOAR, Teams with engineering talent who prefer self-hosted security automation. Free to use.
What's new in Tracecat
Checked 17 days agoAcross the latest 8 updates: 5 feature updates and 3 launches.
Tracecat automation skill for coding agents
Open source skill lets agents build Tracecat automations: author YAML, design tables, validate definitions, debug executions.
Enterprise edition MCP servers now have their own page
MCP catalog gets dedicated page; new tool picker organizes integrations by capability; chat sessions can carry own tools.
Agent Skills (Enterprise edition)
Agents can load reusable skills for alert enrichment, escalation, and tool use. New skills studio to build and manage them.
Case Metrics, Dropdowns & Closure Requirements (Enterprise edition)
Dropdowns, fields, metrics in case rows; closure requirements; long-text and URL field types; bulk actions for commenting and dropdowns.
Hosted MCP Servers (Open source)
MCP servers now run on Tracecat's infrastructure; Jira first hosted integration secured with OAuth 2.1; more servers coming.
Chat for Workflows, Tables & Agents (Enterprise edition)
Chat panel from cases now available on workflows, tables, agents; each conversation is a full agent session with real tools.
Tracecat MCP (Open source)
Tracecat runs as an MCP server; connect Claude, Codex, or any MCP client to workspace for workflows, cases, tables.
Managed Cloud (Cloud)
Tracecat Cloud is live: multi-tenant service with organizations, workspaces; rebuilt execution engine with Temporal orchestration.
Viability Score
How likely is Tracecat to still be operational in 12 months? Based on 4 signals — momentum (how recently it shipped), wrapper dependency, revenue model, and web presence.
Last calculated: July 2026
How we score →Key Features
- Build custom AI agents for security tasks
- Human-in-the-loop approvals on sensitive actions
- Replayable workflow runs with full audit logs
- Hosted MCP servers for 100+ tool integrations
- Draft workflows from natural language via Tracecat MCP
- Limitless control flow: loops, conditions, subflows
- Cloud alert enrichment and triage agents
- Endpoint isolation and containment agents
- OAuth app review and vulnerability response agents
- Case management with agent-assisted summaries and metrics
- Agent skills studio for reusable instructions
- Closure requirements and dropdowns in cases
- Self-host in your VPC or on-premises
- Deploy on Tracecat Cloud (managed multi-tenant)
- Open source audit logs of every tool call
About Tracecat
Tracecat is an open-source security automation platform that lets you replace static playbooks with custom AI agents. It handles phishing triage, cloud alert enrichment, endpoint isolation, OAuth app review, and vulnerability response. Core features include human-in-the-loop approvals, replayable workflow runs with full audit logs, and over 100 tool integrations via hosted MCP servers. You can self-host in your VPC or use Tracecat Cloud (managed multi-tenant). Recent additions include an agent skills studio, case metrics, and the Tracecat MCP server, which lets coding assistants like Claude and Codex manage automations from natural language prompts. Unlike proprietary SOAR platforms, Tracecat gives you full control over data and automations with open-source auditability.
Behind the Verdict
Tracecat is a compelling option if you're building a security automation practice from scratch or migrating off a legacy SOAR. Its agent-first mindset lets you define playbooks in natural language and reuse skills across workflows. The hosted MCP servers with 100+ integrations dramatically reduce the integration coding burden. However, this isn't a tool you hand to a junior analyst and walk away. Building custom agents still requires understanding how to prompt, chain tool calls, and handle edge cases. Teams without a security engineer who can script will find the ramp steep. Compared to Tines or Splunk SOAR, Tracecat offers more flexibility and transparency (open-source AGPL, full audit logs), but less out-of-the-box playbook content. The managed cloud option lowers deployment friction, but for production use you'll likely want the Enterprise plan for RBAC and support. In practice, we'd recommend it for startups and mid-size teams that have one or two automation-savvy engineers who can own the agent library. Larger teams may prefer the guardrails and SLAs of a commercial SOAR.
Researching Tracecat? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas Tracecat actually fits — and what changes day-one when you adopt it.
Phishing email triage via Gmail
Outcome: Automatically parse headers, detonate links, pull Falcon telemetry, quarantine endpoints, and revoke Okta sessions -- all with human approval gates.
Wiz cloud finding enrichment
Outcome: Correlate Wiz alerts with CloudTrail and CrowdStrike Falcon telemetry, then propose containment actions for approval.
OAuth grant review automation
Outcome: Schedule weekly scans of OAuth grants across Google Workspace and Entra ID, revoke risky permissions, and notify app owners.
Use Cases
- Triage Wiz cloud findings by correlating with CloudTrail and EDR, then propose containment actions.
- Isolate compromised endpoints via CrowdStrike Falcon after an alert, with human approval.
- Automate OAuth grant review across Google Workspace and Entra ID, revoking risky permissions.
- Correlate npm package vulnerability alerts with GitHub advisories and rotate affected tokens.
- Scheduled weekly scans of OAuth grants using the OAuth grant review agent (May 2026).
Models Under the Hood
as of 2026-07-14
Limitations
- Open-source tier is self-managed (Docker/AWS Fargate) and lacks advanced agents, skills registry, RBAC, and SCIM.
- Enterprise features like AI-powered dashboards are still 'coming soon.' Hosted MCP servers are available in open source.
as of 2026-06-26
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published Tracecat tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
Open Source
$0/mo
Ideal for
Solo security engineers or small teams willing to self-host and build custom agents with no budget for commercial SOAR.
What this tier adds
Free entry point with unlimited workflows and cases; includes Tracecat MCP but no advanced agents or skills registry.
Enterprise
Custom
Ideal for
Mid-to-large security teams that need advanced agents, RBAC, SCIM, dedicated support, and managed cloud deployment.
What this tier adds
Adds advanced agents, agent guardrails, skills registry, MCP inventory, RBAC/SCIM, and a dedicated security engineer.
Where the pricing makes sense
The company stage and team size where Tracecat's pricing actually pencils out — and where peers do it cheaper.
Tracecat's Open Source tier is free forever with unlimited workflows and cases, making it extremely cost-effective for startups. The Enterprise tier is custom-priced, likely higher than n8n's Team plan ($50/mo) but cheaper than Tines ($15K+/yr). Best for teams who can self-host.
Setup time & first value
How long it actually takes to get something useful out of Tracecat — broken out by persona, not the marketing-page minute.
Self-hosted: 1-2 hours with Docker or AWS Fargate. Tracecat Cloud: instant provisioning. Building a first agent takes a few hours for a team familiar with workflows. MCP hookups require configuring OAuth 2.1 for hosted servers (e.g., Jira).
Switching to or from Tracecat
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From Tines: Export playbooks as YAML and adapt to Tracecat workflow DSL (manual).
- →From Splunk SOAR: Rebuild playbooks as agents using Tracecat's agent builder.
- →From n8n: Rewrite general-purpose workflows for security-specific agent logic.
- ↗To Tines: Rebuild agent logic as no-code playbooks (manual).
- ↗To n8n: Export workflow definitions and adapt to n8n nodes (manual).
- ↗To Splunk SOAR: Export run logs and rebuild playbooks in Splunk SOAR format.
Integrations
Resources & Guides
Tutorials & Learning
Official links
Popular in Security & Privacy
Push Security
Browser security platform for AI-era attacks and AI tool control.
Sublime Security
AI email security platform that stops BEC with transparent, agentic detection.
Frequently Asked Questions
Best-of guides
Used Tracecat? Help shape our editorial sentiment research.
![[ALPHA] Basics - Your first workflow with Tracecat](https://img.youtube.com/vi/Qt4jVqzZQOs/mqdefault.jpg)
![[ALPHA] Basics - Use AI to automate phishing email investigations](https://img.youtube.com/vi/xl2qxce8Xw8/mqdefault.jpg)
![[ALPHA] Basics - Create the classic VirusTotal enrichment SOAR playbook](https://img.youtube.com/vi/q-2vwDNj2TE/mqdefault.jpg)