Tracecat is a scalable, self-hostable platform for automating security workflows and playbooks without limits.

Overview:

Tracecat is an open source security automation platform designed for technical teams and AI agents. It enables users to build end-to-end automations using agents, workflows, cases, and lookup tables. The platform is code-native, allowing custom Python scripts to be synced from a Git repository and turned into agent tools and workflow steps. It supports self-hosting via Docker, Kubernetes, or AWS Fargate and uses sandboxed execution with nsjail for running untrusted code securely. Tracecat is built for teams that need to automate security operations with a focus on reliability and scale.

Core Features:

  • Prompt-to-automations: Build end-to-end automations using agents, workflows, cases, and tables from an agent harness (e.g., Claude code, Codex, OpenCode).

  • Code-native: Sync custom Python scripts from a Git repository into Tracecat to use as agent tools and workflow steps.

  • All-in-one: Combines agents, workflows, lookup tables, and case management in one platform for automating work.

  • Sandboxed execution: Runs untrusted code and agents within nsjail sandboxes or pid runtimes for security.

  • Durable workflows: Supports complex control flow (if-conditions, loops) with durable execution via Temporal.

  • Integrations: Offers over 100 pre-built connectors to enterprise tools via HTTP, SMTP, gRPC, OAuth, and more.

Use Cases:

  • Security automation teams: Build automated playbooks for incident response, alert triage, and case resolution using agents and workflows.

  • AI agent developers: Integrate custom agents with MCP servers and agent harnesses (e.g., Claude code, Codex) to automate security tasks.

  • Self-hosters: Deploy the platform on Docker, Kubernetes, or AWS Fargate for full control over data and execution environment.

  • Technical teams needing case management: Track, automate, and resolve work items with agents and workflows, including human-in-the-loop approval for sensitive actions.

Why It Matters:

Tracecat provides an open source, self-hosted alternative for security automation that emphasizes agent-driven workflows and code-native extensibility. It offers sandboxed execution for untrusted code, durable workflow execution via Temporal, and supports over 100 pre-built integrations. The platform’s all-in-one design combines agents, workflows, case management, and lookup tables, reducing the need for multiple tools. Its code-native approach allows teams to directly use custom Python scripts from Git repositories, making it adaptable to existing development workflows.

TeilenXLinkedInReddit

Ähnliche Tools

Projektstatistiken

Sterne

3,564

Forks

352

Lizenz

AGPL-3.0

Metadaten

Alternative zu
Jira