Ross ROSS = Recommend OSS · open-source software intelligence for agents

TracecatHQ/tracecat

Open-source security automation platform for teams and AI agents observed · 2026-08-28

github.com/TracecatHQ/tracecat · homepage · Python · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

87/100

  • Activity 99
  • Release rhythm 85
  • Longevity 65
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 1
  • age_days: 918
  • days_rel: 23
  • days_push: 7
  • n_releases_24m: 266

Full methodology

Adoption not part of the score

3780 stars · 407 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Tracecat is an open-source, AI-native security automation (SOAR) platform that combines low-code workflows, tool-calling agents, case management, and MCP server integrations. It runs on Temporal for durable execution, sandboxes untrusted code with nsjail, and can be self-hosted via Docker, AWS Fargate, or Kubernetes.

Use cases

  • automate security alert triage and incident response
  • build AI agents that call security tools like CrowdStrike and Wiz
  • replace legacy SOAR with an open-source alternative
  • turn prompts into automations from Claude Code or Codex via MCP
  • manage security cases with human-in-the-loop approvals
  • orchestrate phishing triage and endpoint isolation workflows

When to choose

  • your security team wants agentic automation with durable, sandboxed workflows
  • you need self-hosted SOAR with case management and 100+ integrations
  • you want coding agents to build and run automations via MCP

When to avoid

  • you need a lightweight cron-style scheduler without security focus
  • you require a permissive license - Tracecat is AGPL-3.0
  • you want a fully managed turnkey product without self-hosting or enterprise plans

Facets

application · maturity active

workflow-automation agent-framework mcp chatbot webhook scheduling security self-hosted api-framework security large-language-models developer-tools self-hosted self-hosted python cloud soar security-automation case-management temporal low-code incident-response agentic-automation automation ai-agents docker kubernetes web-server

9 sources

Member repositories

RepositoryRoleHealth v2
TracecatHQ/tracecatmain87

For agents

markdown · JSON · MCP: product_card(name="TracecatHQ/tracecat")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem