Security teams are seeking faster and more efficient ways to handle incident response. They are moving beyond manual workflows or relying solely on commercial platforms by adopting open-source Security Orchestration, Automation, and Response (SOAR) solutions to enhance their operations.
Open-source SOAR platforms are gaining recognition for their flexibility, transparency, and cost-effectiveness. These tools enable organizations to customize automation workflows, integrate with a wide range of tools, and contribute to a model driven by community innovation. During my research, I noticed that finding an updated and comprehensive list of open-source SOAR options was not as straightforward as expected.
This led me to create an overview of the most relevant open-source SOAR projects available today. The focus is on their features, use cases, and what sets each apart. Whether you need a lightweight automation tool to support your security operations or a robust platform capable of handling complex workflows, this guide provides valuable insights.
Why Open-Source Matters to Me
My first hands-on experience with an open-source project was around 2012-2013. At that time, I was implementing Security Onion, Suricata, and AlienVault for an employer. This experience was foundational, teaching me the essentials of security architecture and engineering. These projects were truly eye-opening, paving the way for later work, such as developing a complete Threat Intelligence program around CRITS. Over time, I have engaged with more than 20 different open-source projects. Here’s what I’ve learned about the advantages and challenges of taking this route.
➕ Pros of Open-Source Projects:
No Licensing Fees: Open-source tools are generally available without the hefty licensing fees associated with commercial software, which can be particularly beneficial for startups and small businesses with limited budgets.
Optional Support Costs: While the base software is free, many open-source projects offer paid support services for a relatively low cost, providing an economical way to access expert assistance when needed.
Tailor-Made Solutions: Open-source software often comes with highly customisable codebases that allow users to tweak and alter the software to fit their specific operational needs or integrate with existing systems.
− Cons of Open-Source Projects:
Initial Setup Complexity: While customizable, the initial setup and integration of open-source tools can be complex without vendor support, potentially leading to higher upfront time investments.
Long-Term Maintenance Burden: As businesses grow, they might find that the open-source solution requires substantial customisation or additional coding to scale with their operations, which can divert resources from other areas.
Intermittent Updates and Support: Unlike commercial products, some open-source projects may suffer from irregular updates or be abandoned altogether, leading to potential security and functionality gaps.
Community-Dependent Reliability: The reliability of finding solutions through community forums is not guaranteed; users may face delays or lack of responses to critical issues.
Exploring Open-Source SOAR Platforms
I've done some digging to uncover several open-source SOAR projects. Without big marketing budgets or SEO strategies, these projects often rely solely on community engagement and word-of-mouth.
To aid in your exploration, I've created an infographic that lists these projects, including links and information on active support, like the most recent version release.
If you are curious to explore the processes and frameworks that can help you fully leverage a SOAR or security automation platform, check out my blogs for deeper insights and practical guidance.
Security Automation Development Lifecycle (SADLC)
www.cybersec-automation.com/p/security-automation-development-lifecycle
Integrating Detection Engineering with Automation
www.cybersec-automation.com/p/detection-engineering-automation-incident-response
Links to open-source projects
GitHub - TracecatHQ/tracecat: The open source alternative to Tines / Splunk SOAR. Build AI-assisted workflows, orchestrate alerts, and close cases fast.
The open source alternative to Tines / Splunk SOAR. Build AI-assisted workflows, orchestrate alerts, and close cases fast. - TracecatHQ/tracecat
github.com/TracecatHQ/tracecat
GitHub - Admyral-Security/admyral: Next-gen Security Hyperautomation Platform
Next-gen Security Hyperautomation Platform. Contribute to Admyral-Security/admyral development by creating an account on GitHub.
github.com/Admyral-Security/admyral?tab=readme-ov-file
SOARCA » COSSAS
Released March 19, 2024 Language Go license Apache License 2.0 SOARCA is an open and extensible security orchestrator that can ingest, validate and execute CACAOv2 security playbooks and comes with native http(s), SSH and OpenC2 capabilities to interface with external tools and data resources CONTEXT AND BACKGROUND Organisations are increasingly automating threat and incident response
cossas-project.org/portfolio/SOARCA
GitHub - SecurityBrewery/catalyst: Catalyst is an open source SOAR and ticket system that helps to automate alert handling and incident response processes
Catalyst is an open source SOAR and ticket system that helps to automate alert handling and incident response processes - SecurityBrewery/catalyst
github.com/SecurityBrewery/catalyst
GitHub - z1pti3/jimi: Jimi is an automation first no-code platform designed and developed originally for Security Orchestration and Response. Since its launch jimi has developed into a fully fledged IT automation platform which effortlessly integrates with your existing tools unlocking the potential for autonomous IT and Security operations.
Jimi is an automation first no-code platform designed and developed originally for Security Orchestration and Response. Since its launch jimi has developed into a fully fledged IT automation platfo...
github.com/z1pti3/jimi
GitHub - cookpad/deepalert: Serverless SOAR (Security Orchestration, Automation and Response) framework for automatic inspection and evaluation of security alert
Serverless SOAR (Security Orchestration, Automation and Response) framework for automatic inspection and evaluation of security alert - cookpad/deepalert
github.com/cookpad/deepalert
GitHub - swiftbird07/IRIS-SOAR: IRIS-SOAR: Modular SOAR (Security Orchestration, Automation, and Response) implementation in Python. Designed to complement DFIR-IRIS through playbook automation and seamless integrations. Easily extensible and in active development. Join us in building a tool geared towards enhancing security efficiency!
IRIS-SOAR: Modular SOAR (Security Orchestration, Automation, and Response) implementation in Python. Designed to complement DFIR-IRIS through playbook automation and seamless integrations. Easily...
github.com/swiftbird07/IRIS-SOAR
GitHub - Shuffle/Shuffle: Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing. - Shuffle/Shuffle
github.com/Shuffle/Shuffle
GitHub - nsacyber/WALKOFF: A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down. #nsacyber
A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down. #nsacyber - nsacyber/WALKOFF
github.com/nsacyber/WALKOFF
TheHive Project
Scalable, Open Source Security Incident Response Solutions designed for SOCs & CERTs to collaborate, elaborate, analyze and get their job done
thehive-project.org
StackStorm - StackStorm
StackStorm connects all your apps, services, and workflows. Why StackStorm? Get Started Open source and trusted by the enterprise Robust Automation Engine From simple if/then rules to complicated workflows, StackStorm lets you automate DevOps your way. See More Features... Integrates with your Existing Infrastructure No need to change your existing processes or workflows, StackStorm connects…
stackstorm.com
Check out our SecOps Market Landscape tracker and evaluation frameworks


