Automate security workflows and playbooks using a low code builder with integrated AI agents and case management.

Tracecat is an open-source, self-hosted web application designed for security automation and orchestration. It provides a platform for security teams to build automated playbooks and manage cases using a combination of AI agents and low-code workflows. The software is deployed as a server application via Docker, AWS Fargate, or Kubernetes Helm, allowing teams to maintain control over their security infrastructure.
Users can create end-to-end automations by integrating custom Python scripts from Git repositories or by using a visual builder. The platform manages the entire lifecycle of security incidents, from initial detection and data lookup to resolution and case tracking. It is designed for security operations centers and teams requiring a centralized hub for security orchestration, automation, and response, enabling the transition from manual tasks to automated agentic workflows.
The backend is built with Python, FastAPI, and Pydantic, while the frontend uses Next.js and TypeScript. It utilizes Temporal for durable workflow execution and PostgreSQL for data storage, ensuring that long-running security processes are reliable and scalable. The architecture allows for the conversion of custom Python scripts into agent tools and workflow steps through a custom registry, which allows security engineers to extend the platform with their own proprietary logic.
Tracecat is an agentic security automation platform that bridges the gap between manual case management and autonomous AI-driven security operations.
A network-wide DNS sinkhole that blocks unwanted content for all devices on a local network.
Blocks malicious IP addresses by detecting failed login attempts from event viewers and log files.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.