# w5teams/w5

Security Orchestration, Automation and Response (SOAR) Platform. 安全编排与自动化响应平台，无需编写代码的安全自动化，使用 SOAR 可以让团队工作更加高效

Repository: https://github.com/w5teams/w5
Canonical: https://ross.abutalabs.com/products/w5
Homepage: https://w5.io
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: soar, hacking, w5, w5soar, tools, hack, security, security-tools, security-automation, hacker, python3, automation, python-script, security-audit, devops, shuffle, walkoff
Last push: 2024-06-24T02:31:31+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2107, "days_push": 801, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1548, forks 247 (observed 2026-08-28T04:05:01.908414+00:00)

## What it is
W5 is an open-source, low-code Security Orchestration, Automation and Response (SOAR) platform built in Python with a visual playbook editor. It lets teams wrap systems and tools as APPs and orchestrate them into automated workflows triggered by various triggers, for security operations, DevOps, and automated penetration testing.

## Use cases
- automate security alert triage and response without writing code
- build visual security orchestration playbooks
- automate asset scanning and inventory ingestion
- respond to server alerts with automated remediation
- check threat intelligence for suspicious sources
- automate server maintenance across Linux and Windows
- orchestrate DevOps deployment workflows visually

## When to choose
- you need a self-hosted SOAR platform with a low-code visual workflow editor
- your team wants automation without heavy coding, including non-developers
- you want to wrap internal tools as reusable apps and chain them into playbooks
- you need security operations automation like alert response and threat detection pipelines

## When to avoid
- you need a mature enterprise SOAR with large vendor ecosystems and compliance certifications
- you require a fully code-first automation engine rather than visual playbooks
- you need active rapid development - the project appears to be in maintenance with infrequent releases
- GPL-3.0 licensing is incompatible with your closed-source derivative plans

## Facets
- artifact type: application
- maturity: maintenance
- function: workflow-automation, security, plugin-system, self-hosted, developer-tools
- domain: security, self-hosted, developer-tools
- platform: python, self-hosted
- tags: soar, low-code, security-orchestration, playbook, incident-response, security-automation, automation, devops, web-server, linux, docker

## Member repositories
- w5teams/w5 (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:01.908414+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:30:27.137150+00:00, confidence not recorded.
  - readme: https://github.com/w5teams/w5 (fetched 2026-08-28T04:05:01.908414+00:00, sha 87e9fd5430b5)
  - homepage: https://w5.io (fetched 2026-08-29T11:31:21.779689+00:00, sha 86186505508c)
  - site_page: https://w5.io/help/other/about.html (fetched 2026-08-29T11:31:21.790072+00:00, sha ac06b03bf1ae)
  - site_page: https://w5.io/help/other/faq.html (fetched 2026-08-29T11:31:21.788497+00:00, sha f809974b2626)
- Data as of 2026-08-30T08:39:29.467469+00:00.
