Tracecat

Tracecat

Open source SOAR for AI-native security teams to build agents, not static playbooks.

87/100Safe BetFree planFreemium

Tracecat is the most viable open-source SOAR for teams ready to build custom AI agents, and recent additions like Agent Skills, hosted MCP servers, and the MCP catalog have made agent-building more approachable. But it's not a drop-in replacement for traditional SOAR—plan to invest engineering time and embrace an agent-centric workflow. For plug-and-play with pre-built playbooks and vendor support, consider Tines or Splunk Phantom.

Verified 3h ago · liveness 87/100 · cite: rightaichoice.com/tools/tracecat

Best for
  • Security teams wanting custom AI agents for automation rather than static playbooks
  • Startups and mid-size companies seeking an open-source SOAR they can self-host and own
  • Teams with engineering talent who can write Python and work with MCP and Git for version control
  • Cloud-native security operations needing flexible integrations across SIEM, EDR, MDM, and IdP via MCP
Not ideal for
  • Teams needing plug-and-play SOAR with pre-built playbooks and minimal setup
  • Organizations lacking in-house development resources to build and tune agents
  • Teams that prefer vendor-supported closed-source solutions with SLAs and hands-on support
Visit Website

IntermediateFor a technical team, you can have Tracecat running and connected to your first integrations within a few hours: Deploy via Docker or AWS Fargate, add MCP servers, and build a simple agent in a day. Enterprise onboarding with a forward deployed engineer takes about 3 weeks to production.Web · API · CLIAPI available3.1k viewsVerified 3h ago
Pricing
Free plan
FreemiumFree tier2 plans4 hidden costs
Learning curve
Intermediate
For a technical team, you can have Tracecat running and connected to your first integrations within a few hours: Deploy via Docker or AWS Fargate, add MCP servers, and build a simple agent in a day. Enterprise onboarding with a forward deployed engineer takes about 3 weeks to production.
Runs on
WebAPICLI
API available · 15 integrations
Who it's for
Security engineer at a mid-size startupSOC analyst in an enterpriseSecurity architect evaluating open-source SOAR
Live sentiment
Is Tracecat actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip Tracecat if you need a plug-and-play SOAR with pre-built playbooks and no engineering effort, or if you demand vendor-supported SLAs without building your own agents.

The 30-second take
Biggest gripe

The open-source tier is free but self-managed; you'll pay for your own infrastructure, engineering time to maintain it, and you miss advanced agents, skills registry, RBAC, and SCIM.

Price reality

Tracecat's open-source tier is free forever with unlimited workflows, workspaces, and cases, making it a low-cost entry for technical teams. Tines and Splunk Phantom are typically more expensive and less flexible; n8n is cheaper but not security-focused.

In short

Tracecat — Open source SOAR for AI-native security teams to build agents, not static playbooks. Best for Security teams wanting custom AI agents for automation rather than static playbooks, Startups and mid-size companies seeking an open-source SOAR they can self-host and own, Teams with engineering talent who can write Python and work with MCP and Git for version control. Free to use.

What's new in Tracecat

Checked 11 days ago

Across the latest 5 updates: 4 feature updates and 1 changelog entry.

Viability Score

87/100
Safe Bet

How well maintained and how widely used is Tracecat? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
90
Traction
not measured
Site health
95
User sentiment
not measured
What the vendor publishes
80

Last calculated: September 2026

How we score →

Key Features

  • Custom AI security agents for phishing triage, cloud alerts, endpoint isolation, OAuth review
  • Human-in-the-loop approvals on sensitive actions with audit logging
  • Replayable workflow runs with full audit logs of prompts, tool calls, and decisions
  • Hosted MCP servers for 65+ pre-built integrations with OAuth 2.1 and sandboxing
  • Tracecat MCP for prompt-to-automation with Claude, Codex, Cursor, Microsoft Copilot
  • Automation Skill (open source) for coding agents to author and debug automations over MCP
  • Agent Skills Studio (Enterprise) to package reusable team procedures
  • MCP catalog page with tool picker to assign integrations to agents (Enterprise)
  • Case management with custom fields, dropdowns, metrics, closure requirements, and bulk actions
  • Limitless control flow: loops, conditions, parallel subflows, and Python/Bash/Ansible scripts
  • Git-native version control for automations (Enterprise)
  • Custom Python actions with pinned dependencies
  • Self-host in VPC, on-prem, or deploy with Docker or AWS Fargate
  • Tracecat Cloud managed multi-tenant or self-hosted enterprise
  • Webhooks and schedule triggers for automations

About Tracecat

FreemiumIntermediateAPI availableWeb · API · CLI

Tracecat is an open-source security orchestration, automation, and response (SOAR) platform built for AI-native security teams. Instead of assembling static, no-code playbooks, you define custom agents that triage phishing, enrich cloud alerts, isolate endpoints, review OAuth apps, and respond to vulnerabilities. The platform pairs human-in-the-loop approvals on sensitive actions with replayable workflow runs and full audit logs, so every prompt, tool call, and decision is recorded for compliance and review. A defining feature is hosted MCP servers that connect agents to 65+ pre-built integrations without writing integration code, while the Enterprise edition adds a dedicated MCP catalog page, tool pickers, and the ability to run servers on Tracecat's infrastructure (or your own). Tracecat MCP lets you draft workflows, cases, and agent skills directly from natural language using Claude Code, Codex, Cursor, or Microsoft Copilot—turning your coding agent into a security automation builder. The recently added Automation Skill extends this to authoring and debugging automations through MCP, making it easier to manage automations without leaving your IDE. Enterprise case management is agent-friendly: you can add custom fields, dropdowns, case metrics, and closure requirements, while bulk actions and a case copilot help analysts move faster. For teams with engineering talent, Tracecat offers Git-native version control, custom Python actions with pinned dependencies, and deployment flexibility—self-host in your VPC, on-prem, or use Tracecat Cloud. The open-source tier is free forever, includes SSO and audit trails, and imposes no limits on workflows, workspaces, or cases. Tracecat is not a drop-in replacement for legacy SOAR tools like Splunk Phantom or Palo Alto XSOAR. It expects you to build and tune your own agents, invest in engineering, and embrace an agent-first, MCP-centric mindset. For security teams ready to own their automation stack and move beyond static

Behind the Verdict

If you're tired of wrestling with rigid SOAR playbooks that break every time your environment shifts, Tracecat's agent-first approach is a breath of fresh air. Instead of dragging nodes on a canvas, you describe what you want—triage this phishing email, isolate the endpoint, revoke the OAuth grant—and an agent figures out the steps. The human-in-the-loop approvals give you a safety net, and the audit logs keep everything above board. We'd reach for this when you have security engineers who can write Python and are comfortable with MCP. Tracecat rewards that investment with a platform that adapts to your workflows, not the other way around. Where it bites: this is not a no-code tool for junior analysts. There's a learning curve, and if you're expecting pre-built playbooks that work out of the box, you'll be disappointed. The open-source tier is powerful, but advanced features—agent guardrails, skills registry, MCP catalog page, RBAC—are gated behind Enterprise. And while the integration list is growing, you'll rely on MCP servers for many connections, which means you need to understand how MCP works. If your team isn't comfortable with agents or MCP, you'll spend more time fighting the platform than using it. Compared to Tines, which offers a polished no-code story with a slick interface and pre-built templates, Tracecat is the opposite: open-source, self-hosted, and code-first. Tines is better for teams that want speed to value without writing code. Tracecat is better for teams that want total control, data ownership, and the ability to build automations that their engineers truly own. Splunk Phantom and Palo Alto XSOAR are the legacy heavyweights, but they come with licensing costs and vendor lock-in. Tracecat lets you break free, but only if you're ready to take on

Researching Tracecat? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas Tracecat actually fits — and what changes day-one when you adopt it.

Security engineer at a mid-size startup

You want to automate phishing triage: parse emails, detonate links, check Falcon telemetry, and quarantine endpoints.

Outcome: Build a phishing triage agent using instructions and MCP servers; human approval gates on quarantine actions, with audit logs for every tool call.

SOC analyst in an enterprise

You need to review OAuth grants across Google Workspace and Entra ID, flagging high-risk scopes.

Outcome: Scheduled agent scans grants, flags high-risk scopes, and stages revocations for human approval, reducing manual review time.

Security architect evaluating open-source SOAR

You want to replace a legacy SOAR with a self-hosted, agent-first platform.

Outcome: Deploy open-source Tracecat via Docker, connect your EDR and SIEM via MCP, and start building agents within a day.

Use Cases

  • Triage Wiz cloud findings by correlating with CloudTrail and EDR, then propose containment actions.
  • Isolate compromised endpoints via CrowdStrike Falcon after an alert, with human approval.
  • Automate OAuth grant review across Google Workspace and Entra ID, revoking risky permissions.
  • Correlate npm package vulnerability alerts with GitHub advisories and rotate affected tokens.
  • Scheduled weekly scans of OAuth grants using the OAuth grant review agent (May 2026).

Models Under the Hood

Opus 4.5

as of 2026-08-31

Limitations

  • Open-source tier is self-managed (Docker/AWS Fargate) and lacks advanced agents, skills registry, RBAC, and SCIM.
  • Enterprise features like AI-powered dashboards are still 'coming soon.' Hosted MCP servers and Tracecat Automation Skill are available in open source, but some advanced capabilities are Enterprise-only.

as of 2026-08-28

Verification history

We have re-verified Tracecat 15 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  2. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  3. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  4. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  6. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it

Showing the 6 most recent of 15 verification passes.

Free to cite with attribution — this page re-verifies continuously.

12-month cost

Project the real annual outlay, including the implied monthly cost when only an annual tier is published.

Annual total
Free
Over 12 months
Effective monthly
Free
Billed monthly

Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.

Plans compared

For each published Tracecat tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.

Open Source

$0/mo

Ideal for

Technical security teams that want a free, self-hosted SOAR and are comfortable managing their own infrastructure and building agents.

What this tier adds

Free forever entry point with unlimited workflows, workspaces, and cases; includes Tracecat MCP, prebuilt integrations, lookup tables, Docker/AWS Fargate deployment, SSO, and audit trails.

Enterprise

Custom

Ideal for

Growing security teams that need managed cloud (US/EU) or self-hosted deployment with advanced agents, skills registry, RBAC, SCIM, and dedicated support.

What this tier adds

Adds advanced agents, agent guardrails, skills registry, MCP inventory, advanced cases (triggers, metrics), Git-native version control, Kubernetes Helm chart, RBAC/SCIM, 24/7 support, and a forward deployed security engineer.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • The open-source tier is free but self-managed; you'll pay for your own infrastructure, engineering time to maintain it, and you miss advanced agents, skills registry, RBAC, and SCIM.
  • Enterprise pricing is custom and scales with usage, deployment model, and support needs, so costs can grow unpredictably as you add agents and integrations.
  • Hosted MCP servers in the open-source tier have fewer connectors than Enterprise; you may need to self-host connectors or pay for Enterprise for the full catalog.
  • Some features like AI-powered dashboards are marked 'coming soon'—you might pay for Enterprise expecting them and have to wait.

Where the pricing makes sense

The company stage and team size where Tracecat's pricing actually pencils out — and where peers do it cheaper.

Tracecat's open-source tier is free forever with unlimited workflows, workspaces, and cases, making it a low-cost entry for technical teams. Tines and Splunk Phantom are typically more expensive and less flexible; n8n is cheaper but not security-focused.

Setup time & first value

How long it actually takes to get something useful out of Tracecat — broken out by persona, not the marketing-page minute.

For a technical team, you can have Tracecat running and connected to your first integrations within a few hours: Deploy via Docker or AWS Fargate, add MCP servers, and build a simple agent in a day. Enterprise onboarding with a forward deployed engineer takes about 3 weeks to production.

Switching to or from Tracecat

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • From Legacy SOAR (e.g., Splunk Phantom): Export your playbook logic as documentation, then recreate the steps as agent instructions in Tracecat, using MCP integrations to connect to your existing tools.
Migrating out
  • To Tines: Export your workflows as JSON/YAML and adapt them to Tines' no-code templates, noting that you'll lose agent-based flexibility.

Integrations

JiraWizCrowdStrike FalconGmailOktaVirusTotalURLScanSlackSplunkElasticMicrosoft Defender XDRGitHubClaudeCursorMicrosoft Copilot

Resources & Guides

Tutorials & Learning

YouTube returned 6 videos for “Tracecat”, and we withheld 6: 6 could not be judged, because “Tracecat” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about Tracecat.

Popular in Threat Detection & SOC

Push Security

Push Security

Browser-native security that blocks AI-driven phishing and secures AI app usage in the browser.

FreemiumTry
Sublime Security

Sublime Security

Agentic email security for enterprise BEC and targeted phishing

Contact SalesTry
ExtraHop

ExtraHop

ExtraHop RevealX NDR platform delivers real-time network detection and response for the agentic SOC.

Contact SalesTry

Frequently Asked Questions

Used Tracecat? Help shape our editorial sentiment research.