Tracecat is a scalable, self-hostable platform for automating security workflows and playbooks without limits.

Overview:

Tracecat is an open source security automation platform designed for technical teams and AI agents. It enables users to build end-to-end automations using agents, workflows, cases, and lookup tables. The platform is code-native, allowing custom Python scripts to be synced from a Git repository and turned into agent tools and workflow steps. It supports self-hosting via Docker, Kubernetes, or AWS Fargate and uses sandboxed execution with nsjail for running untrusted code securely. Tracecat is built for teams that need to automate security operations with a focus on reliability and scale.

Core Features:

  • Prompt-to-automations: Build end-to-end automations using agents, workflows, cases, and tables from an agent harness (e.g., Claude code, Codex, OpenCode).

  • Code-native: Sync custom Python scripts from a Git repository into Tracecat to use as agent tools and workflow steps.

  • All-in-one: Combines agents, workflows, lookup tables, and case management in one platform for automating work.

  • Sandboxed execution: Runs untrusted code and agents within nsjail sandboxes or pid runtimes for security.

  • Durable workflows: Supports complex control flow (if-conditions, loops) with durable execution via Temporal.

  • Integrations: Offers over 100 pre-built connectors to enterprise tools via HTTP, SMTP, gRPC, OAuth, and more.

Use Cases:

  • Security automation teams: Build automated playbooks for incident response, alert triage, and case resolution using agents and workflows.

  • AI agent developers: Integrate custom agents with MCP servers and agent harnesses (e.g., Claude code, Codex) to automate security tasks.

  • Self-hosters: Deploy the platform on Docker, Kubernetes, or AWS Fargate for full control over data and execution environment.

  • Technical teams needing case management: Track, automate, and resolve work items with agents and workflows, including human-in-the-loop approval for sensitive actions.

Why It Matters:

Tracecat provides an open source, self-hosted alternative for security automation that emphasizes agent-driven workflows and code-native extensibility. It offers sandboxed execution for untrusted code, durable workflow execution via Temporal, and supports over 100 pre-built integrations. The platform’s all-in-one design combines agents, workflows, case management, and lookup tables, reducing the need for multiple tools. Its code-native approach allows teams to directly use custom Python scripts from Git repositories, making it adaptable to existing development workflows.

CondividiXLinkedInReddit

Strumenti correlati

Statistiche progetto

Stelle

3,564

Fork

352

Licenza

AGPL-3.0

Metadati

Alternativa a
Jira