License & Deployment Mix: 15 tools – 5 OSS, 5 SaaS. (OSS and SaaS counts can overlap when an open-source tool also offers a vendor-hosted edition.)

Overview

SOAR (Security Orchestration, Automation, and Response) platforms automate and coordinate the incident response lifecycle. When a security alert fires – from SIEM, EDR, email security, IDS/IPS, or any detection tool – a SOAR platform executes predefined playbooks to triage, investigate, contain, and remediate the threat with minimal human intervention.

SOAR platforms provide:

  • Playbook automation – codified incident response procedures (SOPs) that execute automatically when triggered by an alert; if/then logic, parallel tasks, human approval gates, and loops
  • Orchestration – connect to dozens or hundreds of security and IT tools via API integrations; a single playbook might query the SIEM, enrich an IP in a threat intelligence platform, block the IP on the firewall, disable the user in the IdP, and create a ticket – all automatically
  • Case management – track incidents from detection through resolution; assign analysts, attach evidence, record timelines, and generate post-incident reports
  • Threat intelligence integration – enrich alerts with IOC (indicator of compromise) data from threat feeds (MISP, VirusTotal, AbuseIPDB, OTX, STIX/TAXII sources)
  • Alert triage and deduplication – correlate and deduplicate alerts from multiple sources; auto-close known false positives; escalate only true positives to analysts
  • Metrics and reporting – mean time to detect (MTTD), mean time to respond (MTTR), playbook execution counts, analyst workload, and SLA compliance dashboards

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison


Deployment Model

ToolSelf-HostedSaaSLicense
ShuffleYesYesApache 2.0
TheHiveYesYesProprietary (freemium)
CortexYesNoAGPL-3.0
DFIR-IRISYesNoLGPL-3.0
GRRYesNoApache 2.0
Splunk SOARYesYesProprietary
Sentinel SOARNoYesProprietary
QRadar SOARYesYesProprietary
Chronicle SOARNoYesProprietary
TinesNoYesProprietary*
TorqNoYesProprietary
SwimlaneYesYesProprietary
Cortex XSOARYesYesProprietary
FortiSOARYesNoProprietary
ServiceNow SecOpsNoYesProprietary

* = community edition available


Core Capabilities

ToolPlaybook BuilderCase MgmtTI EnrichmentMulti-Tenant
ShuffleVisual (drag-drop)BasicYes (MISP, VT)Yes
TheHiveNo (use Cortex)Yes (full)Yes (Cortex)Yes
CortexNo (analyzers)No (TheHive)Yes (native)No
DFIR-IRISNoYes (DFIR)Yes (modules)Yes
Splunk SOARVisual + PythonYesYes (100+)Yes
Sentinel SOARLogic AppsYesYes (native)Yes
QRadar SOARVisual + PythonYesYesYes
Chronicle SOARVisual + PythonYesYes (native)Yes
TinesVisual (no-code)BasicYes (any API)Yes
TorqVisual (no-code)BasicYes (any API)Yes
SwimlaneVisual (low-code)YesYesYes
Cortex XSOARVisual + YAMLYesYes (700+)Yes
FortiSOARVisual + JinjaYesYesYes
ServiceNow SecOpsFlow DesignerYesYesYes

Integration Count

ToolPre-Built IntegrationsCustom Integration
Shuffle1,000+ (OpenAPI-based)OpenAPI spec import
Cortex XSOAR700+Python SDK
Splunk SOAR350+Python apps
Tines300+HTTP actions (any API)
TheHive + Cortex150+ analyzersPython analyzers
Sentinel SOAR200+ (Logic Apps)Azure Functions
Swimlane200+Python plugins
FortiSOAR300+Python connectors

Detection-Stack Integration

ToolWazuhSuricataOpenSearchAuthentikTicketing
ShuffleYes (API)Yes (via SIEM)Yes (API)Yes (API)Yes (API)
TheHiveYes (webhook)Yes (alerts)Yes (search)SAMLYes (API)
Splunk SOARYesYesYesSAMLYes
Cortex XSOARYesYesYesSAMLYes
TinesYes (API)Yes (webhook)Yes (API)OIDCYes (API)

SSO / Authentik Integration

ToolOIDCSAMLSCIMNotes
ShuffleNoNoNoAPI key auth; forward-auth via Traefik
TheHiveYesYesNoOIDC/SAML SSO; Authentik as IdP
Splunk SOARNoYesNoSAML SSO
Cortex XSOARNoYesYesSAML SSO + SCIM
TinesYesYesYesOIDC/SAML + SCIM
SwimlaneNoYesNoSAML SSO
FortiSOARNoYesNoSAML SSO
ServiceNow SecOpsYesYesYesFull SSO + SCIM
Sentinel SOARYesYesYesEntra ID native

Tools

15 tools.

Cortex

Cortex is an open-source observable analysis and active response engine developed by StrangeBee as the companion tool to TheHive.

License: AGPL-3.0-only (OSS) · Kind: web · Deploy: native, docker · SSO: none

Website · Source

DFIR-IRIS

DFIR-IRIS is an open-source incident response platform built by Airbus CyberSecurity, focused on collaborative digital forensics and incident response investigations.

License: LGPL-3.0-or-later (OSS) · Kind: web · Deploy: native, docker · SSO: OIDC

Website · Source

Fortinet FortiSOAR

Fortinet FortiSOAR (originally CyberSponse, acquired by Fortinet in 2019) is an enterprise SOAR platform integrated into the Fortinet Security Fabric.

License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none

Website

Google Chronicle SOAR (Siemplify)

Google Chronicle SOAR (originally Siemplify, acquired by Google in January 2022) is a cloud- native SOAR platform integrated into Google Security Operations (formerly Chronicle).

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

GRR Rapid Response

GRR Rapid Response is an open-source incident response framework developed by Google, focused on remote live forensics at enterprise scale.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native · SSO: none

Website · Source

IBM QRadar SOAR (Resilient)

IBM QRadar SOAR (formerly IBM Resilient) is an enterprise incident response and SOAR platform that provides structured case management, dynamic playbooks, and integration with the broader IBM security portfolio.

License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none

Website

Microsoft Sentinel SOAR

Microsoft Sentinel SOAR is the automation and orchestration capability built into Microsoft Sentinel, Microsoft’s cloud-native SIEM/SOAR platform running on Azure.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Palo Alto Cortex XSOAR

Palo Alto Cortex XSOAR (formerly Demisto, acquired by Palo Alto Networks in 2019) is one of the leading commercial SOAR platforms, recognized as a Gartner Magic Quadrant leader in security orchestration.

License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none

Website

ServiceNow Security Operations

ServiceNow Security Operations (SecOps) is a SOAR module built on the ServiceNow Now Platform that bridges security operations with IT service management.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Shuffle

Shuffle is an open-source security orchestration, automation, and response (SOAR) platform designed to make security automation accessible.

License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker · SSO: none

Website · Source

Splunk SOAR (Phantom)

Splunk SOAR (formerly Phantom) is an enterprise SOAR platform that provides security orchestration, automation, and response tightly integrated with the Splunk ecosystem.

License: Proprietary (proprietary) · Kind: web · Deploy: native, appliance · SSO: none

Website

Swimlane

Swimlane is a low-code security automation and SOAR platform that provides visual playbook building, case management, and extensive integration capabilities for security operations teams.

License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, k8s · SSO: none

Website

TheHive

TheHive is a SOC incident-response case-management platform. TheHive 5 is proprietary freemium (ex-AGPL); the companion Cortex engine stays AGPL-3.0.

License: Proprietary (proprietary) · Kind: web · Deploy: native, docker, saas · SSO: none

Website · Source

Tines

Tines is a no-code security automation platform designed to enable security teams to build sophisticated workflows without programming knowledge.

License: Proprietary (proprietary) · Kind: web · Deploy: native, saas · SSO: none

Website

Torq

Torq is a SaaS-based security hyperautomation platform designed for enterprise security teams and MSSPs.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

ResorsIT Tools Catalog Search