About Tracecat
Tracecat is open-source software for automating security operations, used by teams and AI agents together. It aims to give security teams everything they need to build agents and automate cyber defense in one place, from alert handling to incident response, with unlimited agents, cases, lookup tables and workflows.
Its building blocks include agents and skills built from prompts, tools and MCP, case management for tracking and resolving incidents with agent help, workflows that execute deterministic logic with resilience on Temporal, tables for storing and querying structured data, and a Tracecat MCP that turns prompts into automations from Claude Code, Codex and similar tools. The stack is Python with FastAPI and a Next.js interface.
Tracecat is licensed under AGPL-3.0 and can be self-hosted, with a managed cloud also offered by the vendor. It suits security operations, detection engineering and incident response teams that want a programmable, AI-ready alternative to proprietary SOAR tools.
Key features
- AI agents with prompts, tools and MCP
- Case management for incidents
- Workflows running on Temporal
- Tables for structured data lookups
- Tracecat MCP for prompt-driven automation
- Unlimited agents, cases and workflows
Good fit for
- →Security alert triage automation
- →Incident response case handling
- →Building SOAR-style playbooks
- Tags
- security-automation
- soar
- incident-response
- ai-agents
- case-management
- workflows
- temporal
- python
Tracecat: questions and answers
- What is Tracecat used for?
- Tracecat is a security automation platform, open source, in which security teams and AI agents build workflows, handle cases and automate incident response. It is a good fit for security alert triage automation, incident response case handling and building SOAR-style playbooks.
- Is Tracecat open source?
- Yes. Tracecat is open source under the AGPL-3.0 licence. Its source code is on GitHub at TracecatHQ/tracecat and is written mainly in Python.
- Is Tracecat free?
- Yes. Tracecat is open source, so the software itself is free to use. A managed cloud version is also available.
- Can I self-host Tracecat?
- Yes. Tracecat can be self-hosted on your own server or infrastructure.
- What is Tracecat an alternative to?
- Tracecat is an open-source alternative to Tines, Torq, Swimlane and Microsoft Sentinel. Other open-source alternatives to Tines include StackStorm and n8n.
- Is Tracecat actively maintained?
- Yes. The most recent commit to Tracecat was on 2 October 2026, and the latest release is 1.0.1, published on 18 September 2026. The project has 3.8k stars on GitHub.
Open-source alternatives to Tracecat
See all
StackStorm
Workflow Automation
StackStorm (aka "IFTTT for Ops") is event-driven automation for auto-remediation, incident
Apache-2.0vs Tines★ 6.5k
Wazuh
Security
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints a
OSSvs Splunk★ 17k
Security Onion
Security
Security Onion is a free and open platform for threat hunting, enterprise security monitor
OSSvs Splunk★ 4.9k
Graylog
Monitoring & Observability
Free and open log management
OSSvs Splunk★ 8.2k
n8n
Workflow Automation
n8n is a workflow automation platform that uniquely combines AI capabilities with business
OSSvs Zapier★ 206k
fail2ban
Security
Daemon to ban hosts that cause multiple authentication errors
OSS★ 19k
SaaS alternatives to Tracecat
See all
Tines
Workflow Automation
No-code workflow automation platform for security and IT operations teams
SaaS
Torq
Security
Security automation platform for orchestrating SOC workflows and AI-assisted response
SaaS
Swimlane
Security
Low-code security automation platform for case management and incident response
SaaS
Microsoft Sentinel
Security
Cloud-native SIEM and SOAR service from Microsoft
SaaS
Google Security Operations
Security
Cloud security operations platform with SIEM and SOAR from Google
SaaS
Exabeam
Security
SIEM and security analytics platform with behavioral detection
SaaS

