License & Deployment Mix: 15 tools – 5 OSS, 5 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)
Overview
SOAR (Security Orchestration, Automation, and Response) platforms automate and coordinate the incident response lifecycle. When a security alert fires – from SIEM, EDR, email security, IDS/IPS, or any detection tool – a SOAR platform executes predefined playbooks to triage, investigate, contain, and remediate the threat with minimal human intervention.
SOAR platforms provide:
- Playbook automation – codified incident response procedures (SOPs) that execute automatically when triggered by an alert; if/then logic, parallel tasks, human approval gates, and loops
- Orchestration – connect to dozens or hundreds of security and IT tools via API integrations; a single playbook might query the SIEM, enrich an IP in a threat intelligence platform, block the IP on the firewall, disable the user in the IdP, and create a ticket – all automatically
- Case management – track incidents from detection through resolution; assign analysts, attach evidence, record timelines, and generate post-incident reports
- Threat intelligence integration – enrich alerts with IOC (indicator of compromise) data from threat feeds (MISP, VirusTotal, AbuseIPDB, OTX, STIX/TAXII sources)
- Alert triage and deduplication – correlate and deduplicate alerts from multiple sources; auto-close known false positives; escalate only true positives to analysts
- Metrics and reporting – mean time to detect (MTTD), mean time to respond (MTTR), playbook execution counts, analyst workload, and SLA compliance dashboards
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Deployment Model
| Tool | Self-Hosted | SaaS | License |
|---|---|---|---|
| Shuffle | Yes | Yes | Apache 2.0 |
| TheHive | Yes | Yes | Proprietary (freemium) |
| Cortex | Yes | No | AGPL-3.0 |
| DFIR-IRIS | Yes | No | LGPL-3.0 |
| GRR | Yes | No | Apache 2.0 |
| Splunk SOAR | Yes | Yes | Proprietary |
| Sentinel SOAR | No | Yes | Proprietary |
| QRadar SOAR | Yes | Yes | Proprietary |
| Chronicle SOAR | No | Yes | Proprietary |
| Tines | No | Yes | Proprietary* |
| Torq | No | Yes | Proprietary |
| Swimlane | Yes | Yes | Proprietary |
| Cortex XSOAR | Yes | Yes | Proprietary |
| FortiSOAR | Yes | No | Proprietary |
| ServiceNow SecOps | No | Yes | Proprietary |
* = community edition available
Core Capabilities
| Tool | Playbook Builder | Case Mgmt | TI Enrichment | Multi-Tenant |
|---|---|---|---|---|
| Shuffle | Visual (drag-drop) | Basic | Yes (MISP, VT) | Yes |
| TheHive | No (use Cortex) | Yes (full) | Yes (Cortex) | Yes |
| Cortex | No (analyzers) | No (TheHive) | Yes (native) | No |
| DFIR-IRIS | No | Yes (DFIR) | Yes (modules) | Yes |
| Splunk SOAR | Visual + Python | Yes | Yes (100+) | Yes |
| Sentinel SOAR | Logic Apps | Yes | Yes (native) | Yes |
| QRadar SOAR | Visual + Python | Yes | Yes | Yes |
| Chronicle SOAR | Visual + Python | Yes | Yes (native) | Yes |
| Tines | Visual (no-code) | Basic | Yes (any API) | Yes |
| Torq | Visual (no-code) | Basic | Yes (any API) | Yes |
| Swimlane | Visual (low-code) | Yes | Yes | Yes |
| Cortex XSOAR | Visual + YAML | Yes | Yes (700+) | Yes |
| FortiSOAR | Visual + Jinja | Yes | Yes | Yes |
| ServiceNow SecOps | Flow Designer | Yes | Yes | Yes |
Integration Count
| Tool | Pre-Built Integrations | Custom Integration |
|---|---|---|
| Shuffle | 1,000+ (OpenAPI-based) | OpenAPI spec import |
| Cortex XSOAR | 700+ | Python SDK |
| Splunk SOAR | 350+ | Python apps |
| Tines | 300+ | HTTP actions (any API) |
| TheHive + Cortex | 150+ analyzers | Python analyzers |
| Sentinel SOAR | 200+ (Logic Apps) | Azure Functions |
| Swimlane | 200+ | Python plugins |
| FortiSOAR | 300+ | Python connectors |
Detection-Stack Integration
| Tool | Wazuh | Suricata | OpenSearch | Authentik | Ticketing |
|---|---|---|---|---|---|
| Shuffle | Yes (API) | Yes (via SIEM) | Yes (API) | Yes (API) | Yes (API) |
| TheHive | Yes (webhook) | Yes (alerts) | Yes (search) | SAML | Yes (API) |
| Splunk SOAR | Yes | Yes | Yes | SAML | Yes |
| Cortex XSOAR | Yes | Yes | Yes | SAML | Yes |
| Tines | Yes (API) | Yes (webhook) | Yes (API) | OIDC | Yes (API) |
SSO / Authentik Integration
| Tool | OIDC | SAML | SCIM | Notes |
|---|---|---|---|---|
| Shuffle | No | No | No | API key auth; forward-auth via Traefik |
| TheHive | Yes | Yes | No | OIDC/SAML SSO; Authentik as IdP |
| Splunk SOAR | No | Yes | No | SAML SSO |
| Cortex XSOAR | No | Yes | Yes | SAML SSO + SCIM |
| Tines | Yes | Yes | Yes | OIDC/SAML + SCIM |
| Swimlane | No | Yes | No | SAML SSO |
| FortiSOAR | No | Yes | No | SAML SSO |
| ServiceNow SecOps | Yes | Yes | Yes | Full SSO + SCIM |
| Sentinel SOAR | Yes | Yes | Yes | Entra ID native |
Tools
15 tools.
Cortex
Cortex is an open-source observable analysis and active response engine developed by StrangeBee as the companion tool to TheHive.
License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: none
DFIR-IRIS
DFIR-IRIS is an open-source incident response platform built by Airbus CyberSecurity, focused on collaborative digital forensics and incident response investigations.
License: LGPL-3.0-or-later (OSS) · Kind: web · Deploy: native, docker · SSO: OIDC
Fortinet FortiSOAR
Fortinet FortiSOAR (originally CyberSponse, acquired by Fortinet in 2019) is an enterprise SOAR platform integrated into the Fortinet Security Fabric.
License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none
Google Chronicle SOAR (Siemplify)
Google Chronicle SOAR (originally Siemplify, acquired by Google in January 2022) is a cloud- native SOAR platform integrated into Google Security Operations (formerly Chronicle).
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
GRR Rapid Response
GRR Rapid Response is an open-source incident response framework developed by Google, focused on remote live forensics at enterprise scale.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none
IBM QRadar SOAR (Resilient)
IBM QRadar SOAR (formerly IBM Resilient) is an enterprise incident response and SOAR platform that provides structured case management, dynamic playbooks, and integration with the broader IBM security portfolio.
License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none
Microsoft Sentinel SOAR
Microsoft Sentinel SOAR is the automation and orchestration capability built into Microsoft Sentinel, Microsoft’s cloud-native SIEM/SOAR platform running on Azure.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Palo Alto Cortex XSOAR
Palo Alto Cortex XSOAR (formerly Demisto, acquired by Palo Alto Networks in 2019) is one of the leading commercial SOAR platforms, recognized as a Gartner Magic Quadrant leader in security orchestration.
License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none
ServiceNow Security Operations
ServiceNow Security Operations (SecOps) is a SOAR module built on the ServiceNow Now Platform that bridges security operations with IT service management.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Shuffle
Shuffle is an open-source security orchestration, automation, and response (SOAR) platform designed to make security automation accessible.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker · SSO: none
Splunk SOAR (Phantom)
Splunk SOAR (formerly Phantom) is an enterprise SOAR platform that provides security orchestration, automation, and response tightly integrated with the Splunk ecosystem.
License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none
Swimlane
Swimlane is a low-code security automation and SOAR platform that provides visual playbook building, case management, and extensive integration capabilities for security operations teams.
License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, k8s · SSO: none
TheHive
TheHive is a SOC incident-response case-management platform. TheHive 5 is proprietary freemium (ex-AGPL); the companion Cortex engine stays AGPL-3.0.
License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, saas · SSO: none
Tines
Tines is a no-code security automation platform designed to enable security teams to build sophisticated workflows without programming knowledge.
License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none
Torq
Torq is a SaaS-based security hyperautomation platform designed for enterprise security teams and MSSPs.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none