

September 25, 2025
GigaOm Radar for SecOps Automation v1
Andrew Green
1. Executive Summary
SecOps automation is an umbrella category describing tools used by teams in the security operations center to triage, investigate, and respond to threats with minimal human effort. It is perhaps the best recipient of LLM-based automation, which has manifested in dozens of new AI-native solutions entering the market.
This report is the natural evolution of our four previous iterations on security orchestration, automation and response (SOAR). It includes most capabilities and vendors described in the previous SOAR reports, while also describing a separate set of AI-native capabilities under the Emerging Features section. It aims to provide a comprehensive view of all the standalone tools that automate the triage, investigation, and response processes in a security operations center.
The difference between the SOAR-like approach and the newer LLM-native tools can be described as follows:
Deterministic-first automation, which is commonly implemented by low-code/no-code workflows and scripts or, less ordinarily, robotic process automation (RPA). These follow a pre-defined logical flow, which entails a human operator describing the logic.
Non-deterministic automation, which is typically (perhaps exclusively for this report) accomplished by LLM or DSLM. It is worth noting that LLMs are considered fully deterministic systems by authoritative figures in the AI space. However, we simply label them as non-deterministic considering that a model can produce different responses when given the same prompt more than once. Vendors generally architect LLMs into AI agents, which are responsible for select parts of the SecOps processes.
Almost all vendors featured in the report are implementing LLM-based automation in one way or another. Some of the hybrid approaches include:
Design-time LLMs, meaning the AI is used to write deterministic automation such as scripts and playbooks.
Deterministic wrappers, for which LLMs are part of deterministic workflows.
AI agent writing, whereby the tool allows customers to write their own AI agents rather than using the pre-architected ones provided by the vendor.
This is our first year evaluating the SecOps automation space in the context of our Key Criteria and Radar reports.
This GigaOm Radar report examines 19 of the top SecOps automation solutions and compares offerings against the capabilities (table stakes, key features, and emerging features) and nonfunctional requirements (business criteria) outlined in the companion Key Criteria report. Together, these reports provide an overview of the market, identify leading SecOps automation offerings, and help decision-makers evaluate these solutions so they can make a more informed investment decision.
GIGAOM KEY CRITERIA AND RADAR REPORTS
The GigaOm Key Criteria report provides a detailed decision framework for IT and executive leadership assessing enterprise technologies. Each report defines relevant functional and nonfunctional aspects of solutions in a sector. The Key Criteria report informs the GigaOm Radar report, which provides a forward-looking assessment of vendor solutions in the sector.
2. Market Categories and Deployment Types
To help prospective customers find the best fit for their use case and business requirements, we assess how well SecOps automation solutions are designed to serve specific target markets and deployment models (Table 1).
For this report, we recognize the following market segments:
Small-to-medium business (SMB): Solutions in this category meet the needs of organizations ranging from small businesses to medium-sized companies. For this segment, organizations may prefer a less expensive solution with prepackaged content and easy workflow designers. Newer small enterprises may also rely heavily on cloud-based infrastructure, services, and apps and favor cloud-based SecOps automation solutions.
Large enterprise: Large enterprises will require high-performance SecOps automation solutions with the throughput and storage capacity to ingest huge volumes of data. Solutions may feature AI capabilities that can understand security analyst profiles and automatically assign analysts to appropriate cases. Flexibility in deployment, scalability, and integration with existing infrastructure are key differentiators.
Regulated industries: These typically include verticals such as finance, healthcare, and government, for which vendors need to adhere to strict rules and regulations as well as support on-premises deployments.
Managed security service provider (MSSP): MSSPs will require multitenant architectures, flexibility, and scalability. They may also favor solutions with predictable pricing models.
In addition, we recognize the following deployment models:
Virtual appliance: This refers to the solution being provided as a virtual machine or container image.
Software only: This model offers customers an installation file they can install and run on their preferred operating system and hardware.
Public cloud image: This approach enables customers to purchase the solutions for a public cloud provider’s marketplace and then run it in the respective cloud environment.
Software as a service (SaaS): The vendor hosts the solution on the customer’s behalf and provides a web-based interface so users can interact with the application.
Table 1. Vendor Positioning: Target Market and Deployment Model
Table 1 components are evaluated in a binary yes/no manner and do not factor into a vendor’s designation as a Leader, Challenger, or Entrant on the Radar chart (Figure 1).
“Target market” reflects which use cases each solution is recommended for, not simply whether that group can use it. For example, if an SMB could use a solution but doing so would be cost-prohibitive, that solution would be rated “no” for SMBs.
3. Decision Criteria Comparison
All solutions included in this Radar report meet the following table stakes—capabilities widely adopted and well implemented in the sector:
Security data ingestion
Third-party tool orchestration
Reporting, dashboards, and customizable interfaces
Standalone solution
Integrations
Tables 2, 3, and 4 summarize how each vendor in this research performs in the areas we consider differentiating and critical in this sector. The objective is to give the reader a snapshot of the technical capabilities of available solutions, define the perimeter of the relevant market space, and gauge the potential impact on the business.
Key features differentiate solutions, highlighting the primary criteria to be considered when evaluating a SecOps automation solution.
Emerging features show how well each vendor implements capabilities that are not yet mainstream but are expected to become more widespread and compelling within the next 12 to 18 months.
Business criteria provide insight into the nonfunctional requirements that factor into a purchase decision and determine a solution’s impact on an organization.
These decision criteria are summarized below. More detailed descriptions can be found in the corresponding report, “GigaOm Key Criteria for Evaluating SecOps Automation Solutions.”
Key Features
Integrations and orchestration: This key feature evaluates the tool’s portfolio of pre-configured integrations with third-party tooling, methods of defining new integrations, and the on-going maintenance of these integrations.
Contextual risk-based scoring: The current standard for risk scoring is based on frameworks such as the common vulnerability scoring system (CVSS), which helps assess the level of risk associated with a given vulnerability. Contextual risk-based scoring systems produce a similar type of scoring but also tie it into the context of the customer’s IT environment.
SIEM and SDL integration: SecOps automation tools can leverage long-term security data storage products such as security information and event management (SIEM) and security data lakes (SDL) for investigation, enrichment, correlation, and threat hunting.
Case management and collaboration: As single-pane-of-glass solutions, SecOps automation tools enable analysts to manage tickets and collaborate with team members with minimal friction. These functions can be acquired through integration with third-party systems in which the SecOps automation tool updates the customer’s existing case management tool.
DevSecOps and detection-as-code: This refers to a tool’s ability to manage and configure various aspects of a solution using code repositories, version control, and automated deployment processes.
Zero-day response: While zero-day threats are inherently unknown, SecOps automation tools can take proactive and preventive measures upon detection of suspicious behaviors and provide playbooks for isolating and containing affected entities.
Correlations and evolving threats: The ability to correlate incoming alerts can help place threats, alarms, or incidents within a wider context with respect to the affected IT systems or other existing threats. By analyzing events across a timeline and identifying the affected devices and the relationships among them, a correlation engine can be a very powerful tool that helps analysts identify the source of the threat and neutralize it completely.
Validation and red teaming: As an umbrella platform that coordinates multiple tools, a SecOps automation solution can be leveraged to automate the testing of security controls to help determine whether threats can be detected and to see how the playbooks fare against them.
Table 2. Key Features Comparison
Emerging Features
LLM modularity: This feature evaluates how SecOps automation tools enable customers to deploy and configure the LLMs used for investigation and response.
LLM monitoring and evaluations: LLM monitoring refers to the visibility over LLM performance and response times, and logging of their actions. Evaluations involve measuring the model’s response accuracy and ensuring responses are relevant and grounded in data.
Design-time LLM: LLMs can naturally be used to generate content, which means that they provide administrators and analysts with a natural language interface to write playbooks, detection rules, scripts, data transformations, and integrations with third-party tools.
LLM investigation and response copilots: These features offer analysts a natural language interface through which to conduct investigation and response actions. Typically, copilots are exposed through a chatbox, pop-up, separate window, or within the case management system.
LLM investigation and response agents: Agents are self-determining LLMs that upon a prompt or trigger can carry out investigation and response actions. SecOps automation tools offer agents either as pre-packaged and pre-configured agents that are ready-made for specific use cases, or they offer the building blocks for analysts to build and run their own agents.
Guardrails: Guardrails involve controlling the LLM outputs to ensure that they are accurate, relevant, and correctly formatted.
Non-LLM AI features: While LLMs are powerful tools for SecOps, traditional ML techniques such as statistical analysis and deep learning can also be used in conjunction with AI agents and copilots.
Pre-LLM data layer: Before sending security data into the LLM for summarization, correlation, or processing, the SecOps automation tools can employ a semantic layer that addresses inconsistency issues across various data sources, performing actions such as normalization, correlation, deduplication, sanitization, parsing, contextualization, and enrichment.
Table 3. Emerging Features Comparison
Business Criteria
Support: To help customers in adopting and running the solution at the scale they need, vendors should offer comprehensive technical documentation and support services, such as training and certification programs, technical documentation, onboarding programs, drop-in support teams, and various support channels, such as live chat, Slack, and phone.
Scalability: Scalability determines how many events a SecOps automation tool can process and how it can deal with an increasing number of events in a non-disruptive way. It also looks at the solution’s ability to cater to very large enterprises in terms of multitenancy, multi-region deployment, data processing, and sovereignty.
Cost and licensing: This criterion evaluates the way a solution is licensed and priced to support customers in managing their SecOps automation solution costs in a transparent and predictable way. The licensing model can be based on any of the following: per-seat, per-flow, or per-integration pricing, pay-as-you-go and pay-as-you-grow mechanisms, free tiers, and additional modules.
Ecosystem: This business criterion evaluates a SecOps automation vendor’s partner ecosystem, which includes alliances with third-party managed services providers, channels to market, and third-party professional services providers.
Manageability: This criterion evaluates how administrators and end-users interact with the solution, with specific focus on the work required for initial setup and ongoing configuration. SecOps automation tools specifically depend on being easy to manage due to the large numbers of integrations they must manage.
Table 4. Business Criteria Comparison
4. GigaOm Radar
The GigaOm Radar plots vendor solutions across a series of concentric rings with those set closer to the center judged to be of higher overall value. The chart characterizes each vendor on two axes—balancing Maturity versus Innovation and Feature Play versus Platform Play—while providing an arrowhead that projects each solution’s evolution over the coming 12 to 18 months.
Figure 1. GigaOm Radar for SecOps Automation
As you can see in Figure 1, the vendors are fairly equally distributed across three quadrants. The Platform Play hemisphere holds vendors that come from a low-code/no-code automation background. While most vendors are implementing AI capabilities, the ones in the Innovation/Platform Play quadrant are the ones with considerable investments and roadmap for LLM-based automation. Vendors in the Innovation/Feature Play quadrant are LLM-native solutions that have implemented AI at the core of their product instead of using deterministic automation.
Most vendors positioned in the Platform Play half have also been featured in the previous GigaOm Radar reports for SOAR. However, all vendors in the Innovation/Feature Play quadrant are new to GigaOm reports for security operations.
The Maturity/Platform Play quadrant is the only one with Forward Movers, which are products with fewer product releases and developments in the past 12 months, while Outperformers are distributed around the quadrants.
In reviewing solutions, it’s important to keep in mind that there are no universal “best” or “worst” offerings; every solution has aspects that might make it a better or worse fit for specific customer requirements. Prospective customers should consider their current and future needs when comparing solutions and vendor roadmaps.
INSIDE THE GIGAOM RADAR
To create the GigaOm Radar graphic, key features, emerging features, and business criteria are scored and weighted. Key features and business criteria receive the highest weighting and have the most impact on vendor positioning on the Radar graphic. Emerging features receive a lower weighting and have a lower impact on vendor positioning on the Radar graphic. The resulting chart is a forward-looking perspective on all the vendors in this report, based on their products’ technical capabilities and roadmaps.
Note that the Radar is technology-focused, and business considerations such as vendor market share, customer share, spend, recency or longevity in the market, and so on are not considered in our evaluations. As such, these factors do not impact scoring and positioning on the Radar graphic.
For more information, please visit our Methodology.
5. Solution Insights
BlinkOps: Blink
Solution Overview
BlinkOps is a workflow automation platform provider that leverages GenAI for building, collaborating, and scaling security and related tasks. By using the Blink platform’s AI workflow builder, Copilot, all security practitioners, regardless of skill level or team, can automate any task or workflow using natural language prompts and can put their time to use on strategic projects rather than managing low-priority alerts and tasks.
Blink Copilot works hand in hand with the workflow builder, guiding users from creating an initial workflow framework to customizing specific workflow steps. The builder just needs to write in plain text what they want to do and Copilot does the rest.
Workflows are based on playbooks, which can include nested workflows. Users have access to both no-code and pro-code tools, creating workflows from simple prompts or adding Python steps for customizable code.
BlinkOps is positioned as a Leader and Fast Mover in the Innovation/Platform Play quadrant of the SecOps automation Radar report.
Strengths
BlinkOps scored well on a number of decision criteria, including:
Design-time LLM: LLMs can be used for defining automation logic by generating and refining automation workflows through natural language inputs from users. These are then translated into actionable automation steps. Analysts can also use LLMs for transformation and normalization, as well as writing automation scripts.
Case management and collaboration: The solution’s native case management features can deduplicate, correlate, and enrich alerts automatically using built-in response workflows. All the incoming incident events are correlated via the case management system into a single incident that represents an attack. This includes tagging each incident with MITRE ATT&CK data to allow for easy correlation and division of incidents. The AI case summary tool continuously updates the case summary with a timeline of the attack and its progress.
Zero-day response: The platform offers prebuilt workflows that can scan for new zero-day attacks and, once one is published, prompt an AI model to create a mitigation workflow. Upon review, it turns into a production workflow, thereby significantly reducing the organization’s reaction time to zero-day attacks.
Opportunities
BlinkOps has room for improvement in a few decision criteria, including:
Contextual risk-based scoring: The solution can calculate security risks for incoming incidents based on many data sources such as CMDB, identity tools, cloud security, data security, and other security tools, but are tied to the workflow run and not available as they are not stored as persistent risk attributes.
DevSecOps and detection-as-code: While automations, actions and custom agents can be exported as YAML for versioning in Git repositories, the vendor could further develop features such as natively offering detection-as-code and support for YARA and SIGMA rules.
SIEM and SDL integration: While the platform can connect to SDLs and SIEM to query real-time data, or deduplicate other ongoing incidents, it could improve by offering native long-term storage capabilities.
Purchase Considerations
BlinkOps’ pricing structure has two components. The Enterprise Platform grants customers unlimited access to all Blink modules and features with no limit on the number of users, workflows, or integrations.
Tiered action packages are priced based on expected actions executed by the platform. The action packages can be consumed either via a monthly subscription or through an annual license. The monthly model is ideal for customers who are interested in a “pay as you grow” model without committing to an annual spend or volume, while the annual model gives predictability and simplicity in terms of billing and budget.
Use Cases
The Blink platform supports a wide range of use cases, including incident response, security case management, threat hunting, threat intelligence, phishing response, vulnerability management, data loss prevention, shadow IT discovery, governance, risk and compliance (GRC), service discovery, and identity and access management (IAM).
D3 Security: Morpheus ASOC
Solution Overview
Established in 2002 as an incident and case management platform, D3 Security formally released its SecOps automation offering in 2016. This was a natural development as its initial platform began supporting increasing customer-demanded use cases in the security operation centers. Since then, D3 Security has focused on LLM-based automation features, now branded as the Morpheus ASOC product.
D3 Security’s solution operates at the event level. An event is any automated ingestion from any tool that produces telemetry data such as email, EDR, threat intelligence, and SIEM. Upon ingesting an event, the solution normalizes data into JSON and performs enrichment and correlation with artifacts such as IP addresses, file hashes, usernames, and URLs. Single or multiple events can then be consolidated into an incident and assigned to analysts. This approach lowers the solution’s dependency on SIEM tools. Rather than being dependent on SIEM alerts, the solution can ingest event data straight from the source and perform data enrichment natively.
D3 Security is positioned as a Challenger and Fast Mover in the Maturity/Platform Play quadrant of the SecOps automation Radar report.
Strengths
D3 Security scored well on a number of decision criteria, including:
Correlations and evolving threats: The solution’s artifact behavior function offers a detailed, visual display of affected artifacts for each event. This feature is enhanced with a “system fields” feature, which can perform checks on risky artifacts without running any playbooks to retrieve a risk score from a third-party system. The platform can correlate across different events and even across other security platforms for a single representation of a security event.
Validation and red teaming: The platform can create simulations of common incidents easily and intuitively to test how playbooks perform and assess their outcomes. The simulator has three built-out workflows and generates different events and incidents that can either be escalated or run through the automation workflows.
Case management and collaboration: The solution can automatically open and populate cases with incident data. It stores incident details and generates reports to surface information such as type of threats, affected assets, how many incidents resolved by automation, and false positives. It also enables non-security employees to collaborate on security incidents.
Opportunities
D3 Security has room for improvement in a few decision criteria, including:
DevSecOps and detection-as-code: The platform can be improved by supporting detection-as-code YARA and SIGMA rules.
Integrations and orchestration: While D3 Security has a comprehensive portfolio of out-of-the-box integrations, the vendor can further improve via integrations with management features, such as API version control, guided integrations for new tools, and build-time integration validation and normalization.
Contextual risk-based scoring: The tool can calculate scores using CVSS and can pull information from sources such as ITSM and CMDB. However, it could be improved by taking into account the absence of information as indicators of zero-day, by considering device-specific information such as exposure to public internet and session-specifics such as SSH tunnels, or by recalculating risk scores as new information about the threat surfaces.
Purchase Considerations
D3 Morpheus ASOC charges a base software fee and then an additional fee per active user. Each named user license also comes with two read-only licenses, which are intended for collaboration or for MSSP clients to share with their customers. All features are available to all users for the same price, and the cost remains consistent regardless of resources used, number of tenants, ingested data, or any other resource-based metrics.
Use Cases
D3 Morpheus ASOC helps security operations teams deal with large volumes of alerts by reducing the amount of time spent by analysts on each one. It accomplishes this by deduplicating and correlating incoming alerts on ingestion, and automating data enrichment, containment, and recovery during the incident response process.
Dropzone AI: Dropzone AI SOC Analyst
Solution Overview
Dropzone Al offers a pre-trained Al SOC analyst that autonomously handles Tier 1 alert triage and investigation for every alert. Using generative AI, it replicates the investigative process and techniques of expert analysts, augmenting SOCs with unlimited cognitive automation to handle time-consuming and tedious SecOps tasks.
Dropzone AI uses a multi-agent system to replicate the work of expert Tier 1 SOC analysts. It uses pre-trained LLMs to carry out scoped planning, tool use, and reasoning tasks as required for the alert investigation type. The multi-agent system follows the industry-standard Obtain Information, Strategize, Collect Evidence, Analyze, Report (OSCAR) forensics methodology to ensure thorough examination of various alert types. In addition to LLM-based investigation, customers can automate workflow actions using scripting.
Dropzone AI is positioned as a Challenger and Fast Mover in the Innovation/Feature Play quadrant of the GigaOm Radar for SecOps automation report.
Strengths
Dropzone AI scored well on a number of decision criteria, including:
Zero-day response: The solution can identify threats even if there is no signature available. It works with tools such as Hybrid sandbox to detonate malware, CAPA for malware analysis, and Wireshark for network packet analysis; and uses safe-browsing methods to safely inspect suspected phishing web pages and tools to analyze suspected phishing attachments such as PDFs. Keep in mind, however, that it is not a detection platform, meaning there is a dependency on an existing alert system.
Correlations and evolving threats: The tool stores semantic relationships between entities in a vector database that is unique to each customer. This context memory feature allows the system to retrieve unique environmental context during investigations. For example, the AI SOC analyst remembers if it saw certain behavior by a device or user, or saw a previous investigation that involved the same IP address. The solution notes these correlations in its investigation.
LLM modularity: The solution includes a proprietary chain of thought reasoning engine and context memory that functions as a RAG system. The system can add items that it learns during investigations and also allows users to add items directly using natural language. Customers can also have the tool crawl their ticketing systems to learn facts and add items to context memory.
Opportunities
Dropzone AI has room for improvement in a few decision criteria, including:
Integrations and orchestration: While the platform offers integrations with major IT solutions, its overall portfolio is limited compared to other vendors in the space. It could also further expand its integrations management to allow customers to write their own integrations either using code or via no-code interfaces, offering API version control, and build-time validation and normalization of integrations.
Contextual risk-based scoring: The tool can calculate scores using CVSS and can pull information from sources such as ITSM and CMDB, but it would benefit by taking into account the absence of information as indicators of zero-day, considering device-specific information such as exposure to the public internet and session-specifics such as SSH tunnels, and by recalculating risk scores as new information about the threat surfaces.
SIEM and SDL integration: While the solution can query security tools directly to gather logs and other information, it can further improve by calibrating the SIEM tool’s alert-generation system such as suppressing alerts associated with a known-safe IP address. It could also identify and remove duplicate alerts by comparing key attributes such as source, timestamp, severity, frequency, and event type, ensuring that a single, consolidated alert represents each incident.
Purchase Considerations
The solution is priced by consumption, with year-long subscriptions based on a pre-determined number of alerts. Pricing is publicly available on Dropzone AI’s website. Note that Dropzone has also released COACH, a free Chromium web browser extension that helps junior analysts learn investigative skills.
Use Cases
Dropzone AI can support use cases such as Tier 1 alert triage and investigation across various alert types, including cloud, endpoint, identity, network (NDR/firewall), phishing email, and insider threat alerts. It depends on existing alerting mechanisms such as SIEM and on existing case management products.
Exaforce: Exaforce Agentic SOC
Solution Overview
Exaforce is an Agentic AI platform that is focused on increasing the productivity of the SOC team. The Exaforce solution is a unified platform consisting of Exabots—AI agents that simulate human-grade reasoning for investigating alerts-and the Advanced Data Exploration Platform. The latter is a data analysis platform that ingests, analyzes, and contextualizes logs, config, code, identity, and threat feeds.
Both of these capabilities are powered by a multi-model AI engine that is purpose-built for security operations. The engine uses a combination of AI techniques: deep learning/ML and knowledge graphs for semantic data and behavioral models, and LLM for knowledge models.
Exaforce is positioned as a Leader and Outperformer in the Innovation/Feature Play quadrant of the GigaOm Radar for SecOps automation Radar report.
Strengths
Exaforce scored well on a number of decision criteria, including:
Zero-day response: The multi-model AI engine is tuned to detect zero-day and/or novel attacks using a pipeline of three models: a semantic data model, which is mostly built using algorithmic techniques that rely heavily on knowledge graphs and embeddings; a behavioral model, which consists of multi-dimensional co-occurrence matrixes, isolation forests, decision trees, and the bag of words technique with deep learning; and a knowledge model, which uses LLMs that are highly tuned using the reasoning engine for consistent and deterministic output.
Correlations and evolving threats: The tool has a built-in threat correlation engine that looks at threat data over multiple days and groups findings based on identity, resource, actions, and location. These are then evaluated by the behavioral and knowledge model to determine whether these are coordinated attacks. The agentic system regularly re-evaluates these findings even if they were individually marked as false positives, to ascertain if they are part of an attack chain. The platform displays relationships between entities through visual graphs and leverages this graph for impact analysis on threats and risks.
Pre-LLM data layer: Exaforce performs extensive pre-processing through its multi-stage data pipeline in which the Semantic Data Model is the first step in the pre-processing phase before the LLM. For Exaforce, security data consists of logs, alerts, configuration, identity, code, files/folders, and threat feeds.
Opportunities
Exaforce has room for improvement in a few decision criteria, including:
Integrations and orchestration: While the solution offers integrations with major IT solutions, its overall portfolio is limited compared to other vendors in the space. It could also further expand its integrations management to allow customers to write their own integrations either using code or via no-code interfaces, offering API version control, and build-time validation and normalization of integrations.
DevSecOps and detection as code: The platform allows customers to programmatically interact with the tool via APIs, but it does not offer code-based automation to be managed via version control. Moreover, threat detection is done through the solution’s multi-modal system rather than by using detection-as-code.
Validation and red teaming: While the vendor performs red teaming tests internally for its detection and investigation capabilities, it does not expose these features to customers.
Purchase Considerations
The solution is sold as a SaaS subscription service. It has three tiers. The base tier includes one Exabot Triage agent and Exabot Investigate, and is limited to 3-month data retention. The premium tier includes the base package and the Exabot Detect agent. The enterprise tier includes the previous tiers as well as a managed detection and response service with 24/7 coverage delivered by Exaforce SOC.
Use Cases
Exaforce’s solution is suitable for managing and investigating alerts generated by third-party tools such as SIEM and Exaforce detections, ingesting data directly from the source, performing time-series and behavioral analysis, and providing automated response capabilities.
Fortinet: FortiSOAR
Solution Overview
Fortinet entered the SecOps automation market in 2019 after acquiring CyberSponse, which has been rebranded and integrated in the wider portfolio as FortiSOAR. FortiSOAR supports all deployment models described in the report, including as a physical appliance or virtual appliance, hosted in the cloud on dedicated or shared infrastructure, or as SaaS.
FortiSOAR provides a series of automated tools to track and manage the performance and resources associated with on-premises installations. Its recommendation engine is powered by AI/ML to help analysts understand and uncover insights about similar threats seen in the recent past and to recommend playbooks to execute based on past investigation patterns.
FortiSOAR can pull information from more than 120 threat intelligence providers, including FortiGuard, Fortinet’s proprietary threat intelligence platform. Leveraging its native integration with FortiGuard, FortiSOAR delivers enhanced threat intelligence management support and offers unrestricted lookup of indicator reputations, threat categories, and threat encyclopedia access. The ability to import indicators from CSV/STIX files and export indicators in STIX format enables ingestion of structured and unstructured feeds.
Fortinet is positioned as a Challenger and Forward Mover in the Maturity/Platform Play quadrant of the SecOps automation Radar report.
Strengths
Fortinet scored well on a number of decision criteria, including:
Validation and red teaming: The platform allows playbooks to enter simulation mode, in which analysts can input mock data without impacting production systems. This enables them to test whether their defined workflows work optimally and as intended.
Correlations and evolving threats: The solution can integrate with other Fortinet Security Fabric solutions, such as FortiAI, which uses deep neural networks to learn about new threats on its own and helps organizations to adapt threat protection to new attacks instantaneously. FortiAI comes pre-trained with more than six million malware features that can identify threats to IT and operational technology (OT) and classify them into malware categories.
Case management and collaboration: The tool can suggest or auto-assign the most suitable analyst based on profile, past investigations, alert types, and other factors. It also prioritizes and ranks the alerts based on the auto-enrichment and initial investigation performed by the system and re-assesses and assigns the status and severity based on investigation results.
Opportunities
Fortinet has room for improvement in a few decision criteria, including:
DevSecOps and detection-as-code: The solution currently offers only an integration with GitHub for creating and managing repositories.
Integrations and orchestration: While the platform has a comprehensive portfolio of out-of-the-box integrations, it could further improve via integrations management features, such as API version control, guided integrations for new tools, and build-time integration validation and normalization.
SIEM and SDL integration: Although FortiSOAR supports third-party SIEM and SDL integrations, it could be improved by providing feature parity across those and its native FortiSIEM integration. It could also offer direct data ingestion and native long-term storage capabilities.
Fortinet is designated a Forward Mover due to a slow rate of delivery in the last year with a correspondingly low release cadence.
Purchase Considerations
FortiSOAR can be consumed in a variety of ways. FortiSOAR Enterprise starts at a base price that includes two users and scales per unique user seat. FortiSOAR Multi-Tenant also starts with two included users plus per unique user seat, with no additional cost to add shared tenants to the system.
FortiSOAR Dedicated Tenant Node pricing starts with a base fee and includes one user license, which is typically useful for customers served by an MSSP that requires a dedicated FortiSOAR node on-premises. FortiSOAR Regional SOC Node is also licensed from a base price plus the number of unique users. FortiSOAR Threat Intel Management Service is included for free with all FortiSOAR versions.
Use Cases
FortiSOAR can be used for a range of use cases, which include security incident management, response and optimization for remediation and prevention actions across multiple-vendor security solutions, OT security with asset and vulnerability management, threat response playbooks, and full OT ecosystem integration and vulnerability management.
Imperum: Imperum SecOps Platform
Solution Overview
Imperum is an AI-powered SecOps platform built to automate, accelerate, and simplify threat detection, investigation, and response (TDIR). It combines advanced threat detection, AI-driven investigation, automated response, and forensic analysis, delivering end-to-end security operations through a single tool platform.
Imperium built its product using proprietary domain-specific large language models (DSLLMs), purpose-built for cybersecurity operations operating on-premises or in air-gapped environments. These models understand the context, behavior, and language of tools in the tech stack and threat actor arena, and are used to automatically investigate every integrated system; perform zero-touch forensics with real-time, passive artifact collection across Windows, Linux, and macOS; and build and execute custom forensic workflows without code.
Imperum is positioned as a Leader and Outperformer in the Innovation/Platform Play quadrant of the GigaOm Radar for SecOps automation report.
Strengths
Imperum scored well on a number of decision criteria, including:
Case management and collaboration: The solution supports automatic case creation and enrichment upon triggering of detection rules, with alerts correlated across sources and auto-populating each case with timeline of events, affected assets, users, systems, risk score, CVEs, threat classification, and more. Cases can be shared with non-security teams and a real-time war room can be used for multi-user collaboration. A differentiating mobile case management feature allows analysts to manage cases from a mobile device.
Zero-day response: The tool is built to identify, respond to, and contain unknown threats before signatures exist, using behavior-driven AI, sandbox integration, and multi-tenant intelligence sharing. It combines proactive defense, forensic-level visibility, and autonomous orchestration. Threats detected in one customer environment can be immediately scanned across other tenants using shared tactics, techniques, and procedures (TTPs), IOCs, and behavioral fingerprints. Behavioral deviation analysis via DSLLMs allows early recognition of zero-days without relying on known signatures.
Validation and red teaming: The platform includes a built-in validation engine that can automatically test playbooks, agents, scripts, and prompts against pre-defined scenarios. It can also simulate alerts, log entries, and behavioral patterns to validate detection and response logic and perform dry-runs or safe-mode executions of playbooks to check for errors, missing variables, and broken integrations.
Imperum is classified as an Outperformer because of its extensive development pipeline across the key and emerging features described in the report.
Opportunities
Imperum has room for improvement in a few decision criteria, including:
SIEM and SDL integration: While Imperum has deep integrations with SIEM tools and SDLs, the vendor does not currently offer long-term data storage capabilities natively. This capability is on the vendor’s roadmap.
DevSecOps and detection as code: While Imperum supports detection rules as flat YAML and JSON filters to be managed like code, the vendor is currently working on developing features such as code repositories and version control, CI/CD integrations, collaboration, and code reviews.
Purchase Considerations
Customers can choose from three tiers—premier, advanced, and basic—each offering a predefined set of core capabilities (users, ingest, detection, automation, forensics, case management, mobile, SOC wall, and so forth). Each tier includes a base number of users (5 for premier, 3 for advanced, 1 for basic). Additional users can be purchased per seat. Add-ons include additional detect agent packs, additional forensics agent packs, the mobile module, the SOC wall display module, and AI-driven capabilities.
Use Cases
Imperum can be used for writing deterministic automation, writing, managing and investigating alerts generated by third party tools such as SIEM, alerting based on raw data, and automated incident response.
Intezer: Intezer Autonomous SOC
Solution Overview
Intezer Autonomous SOC is an AI-powered security solution that emulates the decision-making process of human SOC analysts to automatically monitor, investigate, and respond to alerts. It continuously investigates alerts, filters out false positives, and autonomously responds to incidents across endpoint, identity, network, phishing, and cloud security solutions.
The solution combines advanced AI techniques, deterministic forensics, and a built-in toolkit to dismiss false positives, auto-remediate routine threats, and expose real attacks. It is fully AI agent-based, requiring no scripting or workflow building. Customers only need to connect their alert sources via API keys and then fine-tune results by providing feedback in the first week or two.
Intezer is positioned as a Challenger and Fast Mover Innovation/Feature Play quadrant of the GigaOm Radar for SecOps automation report.
Strengths
Intezer scored well on a number of decision criteria, including:
Contextual risk-based scoring: The solution determines risk based on user, device, or workload identity context (for example, a director's device poses a higher risk than an entry-level employee's), behavior deviation from the baseline, and suspicious user or workload behaviors like abnormal file downloads or unexpected connection requests. While it currently doesn't consider a resource's public internet exposure, these risk scores influence the verdict and action, leading to prioritized alerts, faster investigations, and the escalation of important incidents (creating tickets) with various priorities like false positive, audited, follow up recommended, escalated (generic), and escalated (urgent).
SIEM and SDL integration: The platform integrates with SIEM and SDLs by ingesting and investigating all alerts, correlating them with information and logs based on time, device, user, and artifacts. It filters false positives by collecting and analyzing evidence, then correlating it to make a decision. Duplicate alerts are removed and combined by aggregating entities, and the tool learns from analyst feedback on false positives. While it doesn't directly suppress SIEM alarms, it indirectly does so by not creating tickets for unescalated alerts.
Zero-day response: The solution offers robust zero-day response capabilities. It can immediately scan for detected threats across various customer environments and takes proactive containment steps upon detecting suspicious behavior, such as disabling user accounts or isolating machines. The tool provides content for isolation and containment, and can perform forensics on endpoints via the EDR API. It also collects and analyzes binaries, URLs, and documents in a sandbox environment, using multiple technologies for analysis. While a full sweep for sandbox-collected indicators isn't currently available, it's on the roadmap. Furthermore, the company produces playbooks for novel attacks using automated endpoint forensics and memory analysis to catch stealthy malicious code. It also boasts an in-house threat research unit with proprietary intelligence feeds and a software genetic database to discover new attacks and create appropriate response workflows.
Opportunities
Intezer has room for improvement in a few decision criteria, including:
Integrations and orchestration: While the platform offers integrations with major IT solutions, its overall portfolio is limited compared to other vendors in the space. It could also expand its integrations management to allow customers to write their own integrations either using code or via no-code interfaces, and by offering API version control and build-time validation and normalization of integrations.
Case management and collaboration: The solution does not currently offer native case management features, instead integrating with customers’ existing third-party ticketing systems.
Correlations and evolving threats: While the tool can visually and interactively display dependency maps that show relationships among assets and critical information for each affected artifact, it does not analyze security incidents across a timeline or display metrics that include an attack surface size comparison with peers.
Purchase Considerations
Intezer offers tiered pricing models based on the number of endpoints connected to the solution, rather than per alert or agent count. Customers then choose a package based on desired alert sources, such as endpoint, email phishing, cloud, or network. The starter package covers either EDR or Phishing Abuse Inbox, the advanced package includes both, and the complete package offers all data sources.
Use Cases
Intezer can be used for managing and investigating alerts generated by third party tools such as SIEM, alerting and investigating based on data produced at source, and automating incident response actions.
Mindflow
Solution Overview
Mindflow is an automation platform that allows users to automate security processes. It enables them to build deterministic flows by creating business logic for collecting, enriching, and executing actions. Leveraging the recent advancements in AI, Mindflow implemented AI agents to help operators retrieve data, conduct analysis, and trigger actions in natural language across the full stack of services.
Built using a security-oriented language-action model (LAM), Mindflow’s text-to-action engine is capable of translating written instructions into playbooks. Mindflow agents can build complex automation playbooks just by describing how they should work. The LAM brings together several different technologies such as multi-LLM support, semantic retrieval-augmented generation (RAG) for vendor documentation, and AI explainability.
The agent is configured by the user to ingest data sets that are transmitted to the LLM, which then defines the actions to be taken. These reported actions are configured by the LLM before being sent by the agent to the orchestration and automation engine, which applies the necessary authentication method before sending and receiving the request. This response is then passed to the LLM, which continues its work as needed by analyzing the result and then renewing the interaction cycle under the agent's control.
Mindflow earned a top score for manageability as one of its distinguishing features is its ability to enrich its integration library by automatically ingesting the documentation accompanying the APIs provided by vendors and integrating it into its unified internal language to facilitate the configuration of API calls.
Mindflow is positioned as a Leader and Fast Mover in the Innovation/Platform Play quadrant of the SecOps automation Radar report.
Strengths
Mindflow scored well on a number of decision criteria, including:
Zero-day response: The solution provides customizable playbooks that can be tailored to address zero-day or novel attacks. Users can leverage in-house threat intelligence and proprietary research to develop specific workflows and response strategies for new and emerging threats. The company has dedicated in-house threat research units that continuously monitor and analyze emerging threats.
Event ingestion and filtering: The solution can ingest events directly from the tools generating them, bypassing the need to rely solely on SIEM systems. This is achieved through the use of webhooks, with a unique webhook address attached to a workflow upon its creation. Users can redirect events from various tools directly to these workflows, enabling immediate processing and analysis.
Validation and red teaming: The tool supports running automated tests on security controls to ensure that playbooks function as intended. Users can leverage both preproduction and production environments for thorough testing. The capability to copy and paste older payloads or rerun previous executions on updated playbooks ensures that any modifications are validated effectively. The platform allows for the creation of preproduction environments or sandboxes. This feature is essential for red teaming activities in which simulations of attack scenarios can be performed in a controlled setting, ensuring no disruption to the live environment.
Opportunities
Mindflow has room for improvement in a few decision criteria, including:
Case management and collaboration: While the solution has extensive native case management features, these are based on LLM chat rather than the traditional case-based or ticket-based approach. For the latter, customers must integrate the product with their existing ticket or case management system.
SIEM and SDL integration: The platform can integrate with both SIEM tools and SDLs for threat hunting, enrichment, and correlations. This metric could be improved by offering native long-term storage capabilities.
Correlations and evolving threats: While the solution offers good capabilities in this area, including breakdowns of incidents across timelines, it does not currently provide visualization maps that show dependencies between affected assets.
Purchase Considerations
Mindflow is sold as a single solution with a tiered service model, various add-ons, premium services, and flexible licensing options. Licensing is structured around three packages: basic, fusion, and enterprise. Each package includes unlimited integrations, flow templates, and up to 100 steps per flow. A community edition is planned for release in 2025, including base features automation and AI chat. There’s also an on-demand freemium model. For MSSPs, the vendor offers flexible pay-as-you-go models.
Use Cases
Mindflow’s solution can support a wide range of use cases, including vulnerability management; incident response and threat hunting; just-in-time access to sensitive environments; login events monitoring; and creating, scoping, and deploying policies for mobile device management.
Palo Alto Networks: Cortex XSOAR*
Solution Overview
Palo Alto Networks entered the SecOps automation space when it acquired Demisto in 2019. By integrating Demisto’s automation and orchestration into its Cortex threat prevention and response capabilities, the company produced a powerful AI-enabled tool to support overburdened SOC analysts. Cortex XSOAR can be deployed as a physical server, a virtual appliance, or a cloud-hosted solution.
Palo Alto Networks is positioned as a Challenger and Forward Mover in the Maturity/Platform Play quadrant of the SecOps automation Radar report.
Strengths
Palo Alto Networks scored well on a number of decision criteria, including:
Validation and red teaming: The platform leverages Cymulate and SafeBreach Hacker’s capabilities within a templated playbook and performs validation by automatically launching thousands of benign attacks against existing networks, endpoints, and cloud infrastructure. Results are displayed through SafeBreach Insights and present identified risks and vulnerabilities. These insights can enrich context around alerts and automate policy changes across the wider environment.
Case management and collaboration: The solution learns from real-life analyst interactions and past investigations to suggest analyst case assignments, playbook enhancements, and investigation next steps. It can make incident owner recommendations depending on analyst profiles, suggesting three suitable analysts for each incident. Moreover, its War Room has an ML feature that analyzes all closed incidents, specifically looking at manual actions performed by analysts to suggest the top three who can provide relevant assistance for a particular incident.
DevSecOps and detection as code: The platform has a DevSecOps content pack that contains multiple integrations and playbooks to help shift security left, which consists of integrations with IDEs, code repository providers, CI/CD orchestrators, code compilers, and SAST/DAST/IAST tools.
Opportunities
Palo Alto Networks has room for improvement in a few decision criteria, including:
Contextual risk-based scoring: The tool can calculate scores using CVSS and can pull information from sources such as ITSM and CMDB, but could be improved by taking into consideration the absence of information as indicators of zero-day, by taking device-specific information such as exposure to public internet and session-specifics such as SSH tunnels into account, and by recalculating risk scores as new information about the threat surfaces.
SIEM and SDL integration: While the solution can work with third-party SIEMs and SDLs, it could provide feature parity between them and the integration with XSIAM. It could also offer direct data ingestion and native long-term storage capabilities.
Case management and collaboration: Although the solution has good case management features, it could improve on this by using data stored in the case management engine for knowledge sharing among analysts, assist with onboarding new team members, and serve as global context for LLM agents or copilots.
Palo Alto Networks is designated a Forward Mover because the product’s latest releases bring user experience improvements but it has not released any major features over the past year.
Purchase Considerations
Cortex XSOAR has multiple licensing options, including starter, enterprise, and MSSP. The enterprise plan is charged yearly and includes four users and unlimited integrations, threat feeds, automations/playbooks, reports/reporting, and access to new OOTB automation packs via its marketplace. Palo Alto Networks Unit42 threat intel feed is also included.
Cortex XSOAR Starter includes two users and unlimited integrations, unlimited automations/playbooks, five active threat feeds, unlimited reports/reporting, and unlimited access to new OOTB automation packs via the marketplace. Palo Alto Networks Unit42 threat intel feed is also included, and additional user seats are priced individually per year.
The MSSP offering is based on the number of users and threat intelligence feeds are priced individually from the SOAR product.
Use Cases
Cortex XSOAR can support multiple use cases, including security data analytics such as fetching, creating, and managing incidents from SIEM, authentication and authorization, case and incident management, data enrichment and threat intelligence, IAM, and endpoint security.
Prophet Security: Prophet AI SOC Platform
Solution Overview
Prophet Security's AI SOC Platform is powered by an agentic AI SOC analyst to autonomously triage, investigate, and respond to security alerts by emulating the actions of a human analyst. The Prophet AI SOC Platform operates through a structured five-phase process: Plan, Investigate, Respond, Adapt, and Report.
Prophet AI summarizes incoming alerts, extracts key artifacts, accurately classifies them, and dynamically constructs a comprehensive investigation plan. It dynamically generates an investigation plan to retrieve, correlate, and analyze contextual information from data sources such as SIEM systems and security data lakes. Upon completing its investigation, Prophet AI assigns a severity level based on its findings and prioritizes critical alerts, ensuring that the most urgent threats are addressed first. The Adapt phase allows Prophet AI to continuously learn from every piece of feedback provided by analysts. In addition, Prophet AI provides SOC managers with a real-time, intuitive dashboard that offers a clear view of impactful SOC metrics.
Prophet Security is positioned as a Challenger and Fast Mover Innovation/Feature Play quadrant of the GigaOm Radar for SecOps automation report.
Strengths
Prophet Security scored well on a number of decision criteria, including:
Contextual risk-based scoring: The solution can determine risk based on user, device, or workload and identity context. For example, it considers a higher risk score if an affected end-user device belongs to a director rather than an entry-level employee, by leveraging identity context and assessing critical and less critical assets. The solution calculates severity based on alert and contextual information. Once an alert is sent into the tool, it gathers additional data and previous alerts and activity for the affected users and devices, putting in context the investigated activity and identifying anomalies in authentication behavior, data access, and other points.
SIEM and SDL integration: Upon ingestion, the platform summarizes incoming alerts, extracts key artifacts, classifies them, and dynamically constructs an investigation plan. It removes duplicate alerts and combines multiple related alerts into a single event. The tool can learn the characteristics of incidents marked by analysts as false positives. The Adapt feature allows it to continuously learn from analyst feedback and, optionally, pre-existing playbooks to adapt to the customer's specific environment. Security data is used for contextualization and correlation by automatically stitching together related activities and logs from multiple data sources, including SIEMs and data lake.
Correlations and evolving threats: The solution builds and provides a timeline view for all alerts investigated. Its Dig Deeper capabilities allow security analysts to ask additional ad hoc questions in natural language about a single investigation or across multiple investigations. This functionality supports flexible and in-depth exploration of security events, implying an ability to drill down into the details of affected entities such as users, hosts, IPs, applications, and other artifacts.
Opportunities
Prophet Security has room for improvement in a few decision criteria, including:
Integrations and orchestration: While the platform offers integrations with major IT solutions and supports integrations via generic webhooks, its overall portfolio is limited compared to other vendors in the space. It could expand its integrations management to allow customers to write their own integrations either using code or via no-code interfaces, and by offering API version control and build-time validation and normalization of integrations.
Zero-day response: While the tool is able to investigate suspicious and anomalous behavior-based alerts, and provides custom detections, the solution has a high dependency on alerts being triggered by third-party tools.
Purchase Considerations
Prophet Security licensing is based on the number of alerts investigated per year. This represents a usage-based licensing model that aligns pricing directly with the value delivered to the customer. Prophet AI can also be acquired with an additional layer of human oversight for investigations. In this model, all inconclusive or true positives are reviewed by Prophet Security’s analysts within well-defined SLAs. All investigations are subject to Prophet's rigorous quality control process.
Use Cases
Prophet can manage and investigate alerts generated by third-party tools such as SIEM, supports custom detections, and provides automated incident response.
Radiant Security: Adaptive AI SOC Platform
Solution Overview
Radiant Security is an adaptive AI SOC platform that automates alert triage and investigation across all alert types and security use cases, evolving its triage and correlation logic dynamically based on new threats, changes in the customer environment, and analyst feedback. It ingests data from a wide range of sources, including security alerts, raw telemetry, asset and identity systems, and unstructured context such as internal knowledge bases, to determine whether each alert is benign or potentially malicious.
Radiant Security’s AI agents perform automated investigations on every alert, dynamically identifying the relevant context, querying internal and external sources, and escalating only the alerts that represent real threats. For previously unseen or unfamiliar alerts, Radiant Security leverages a dedicated AI research agent that autonomously analyzes the new threat, gathers intelligence, and dynamically develops a tailored triage approach. Each escalated incident includes clear, explainable reasoning and response recommendations that can be executed in one click or fully automated based on analyst preferences.
The product is delivered as a SaaS solution, with an optional on-premise agent available to support hybrid environments. This allows Radiant Security to connect securely to cloud, SaaS, and on-premises detection tools, log repositories, and infrastructure assets.
Radiant Security is positioned as a Challenger and Outperformer in the Innovation/Feature Play quadrant of the GigaOm Radar for SecOps automation report.
Strengths
Radiant Security scored well on a number of decision criteria, including:
SIEM and SDL integration: The solution offers integrated SIEM SDL capabilities through its built-in security data lake, which provides scalable and cost-efficient storage with fast querying for investigations and compliance. This integrated log management can enhance existing SIEM deployments by offering additional data retention and performance without increasing cost or complexity.
Correlations and evolving threats: The platform automatically correlates alerts and telemetry across time, data sources, and entities to construct high-fidelity incident narratives, eliminating the need for manual playbooks, correlation rules, or detection tuning. It performs entity-aware correlation across users, hosts, IPs, cloud identities, workloads, assets, and IOCs. Radiant Security queries telemetry and alert history across long-, mid-, and short-term timeframes to establish baselines and detect deviations in user or system behavior; groups related alerts and suspicious actions into coherent incident narratives; and determines what happened immediately before or after an alert.
Validation and red teaming: The tool combines simulated attacks in controlled lab environments with live red team operations conducted directly in customer production environments. In the lab, curated attack scenarios are executed to validate the efficacy of triage and incident construction, ensuring the platform effectively prioritizes and categorizes security events. During red team exercises in customer environments, it processes real alerts.
Radiant Security is classified as an Outperformer given its extensive development pipeline across the key and emerging features described in the report.
Opportunities
Radiant Security has room for improvement in a few decision criteria, including:
Integrations and orchestration: While the platform offers integrations with major IT and security solutions, its overall portfolio is limited compared to other vendors in the space. It could expand its integrations management to allow customers to write their own integrations either using code or via no-code interfaces, and by offering API version control and build-time validation and normalization of integrations.
Contextual risk-based scoring: The tool can calculate scores using CVSS and can pull information from sources such as ITSM and CMDB. It could be improved by taking into consideration the absence of information as indicators of zero-day attacks, taking device-specific information such as exposure to public internet and session-specific information such as SSH tunnels into account, and by recalculating risk scores as new information about the threat surfaces.
Case management and collaboration: The solution’s native case management features act as an integrated SOC workflow tool rather than a full standalone case management system. It can improve this feature by offering capabilities such as war rooms, breaking down incidents into step-by-step actions for threat hunting, and using incident data as global context for LLMs.
Purchase Considerations
Radiant Security is offered as a single, unified platform that includes three tightly integrated components: triage, response, and log management. These components are not sold separately and are designed to work seamlessly together through a common interface, enabling full-spectrum SOC automation. The log management feature is optional.
Use Cases
Radiant Security is suitable to process third-party alerts, automate threat hunting and perform incident response. It helps security operations teams deal with large volumes of alerts by reducing the amount of time spent by analysts on each one.
Simbian: Simbian Security Accelerator
Solution Overview
Simbian’s Security Accelerator is a set of autonomous AI agents that work together as a team. These agents share knowledge through the Context Lake, providing a collaborative multi-agent framework in a single console UI.
The AI SOC Agent is an autonomously operating agent designed to enhance security operations by reducing MTTR, reducing human analyst alert fatigue, and demonstrating ROI in minutes. It supplements an L1 human analysis by autonomously triaging, investigating, and responding to alerts. The AI Threat Hunt agent uses both structured and unstructured frameworks to provide actionable intelligence by interpreting reports. The AI CTEM Agent continuously assesses and contains exposure within the customer’s environment.
All of the agents leverage Simbian’s proprietary Context Lake, which fingerprints each organization with its specific assets, their relationships, and their transactions and activities enabling more informed decisions.
Simbian is positioned as a Challenger and Fast Mover in the Innovation/Feature Play quadrant of the GigaOm Radar for SecOps automation report.
Strengths
Simbian scored well on a number of decision criteria, including:
Contextual risk-based scoring: The solution calculates risk scores based on extensive contextual information by leveraging integrations with a wide range of tools and data sources. The AI agents are purpose-built to investigate and respond, including prioritizing vulnerabilities, by leveraging data and context from the customer’s environment. ContextLake helps contextualize the most relevant information from both internal and external data sources and incorporates documented and tribal knowledge, including knowledge from analysts, notes from cases, and so forth. This capability allows the platform's AI agents to connect all the dots in an environment.
SIEM and SDL integration: The solution enriches raw alerts with details such as user identity, asset criticality, business impact, and threat intelligence. By correlating these enriched data points, Simbian’s agents autonomously investigate, correlate, and respond to threats.
Correlations and evolving threats: The platform offers multiple graph views, such as the AI Agent view, Investigation View, and Entity view. It uses MITRE mappings of existing detections. The CTEM agent can leverage existing data from ASM and EM tools for context and prioritization.
Opportunities
Simbian has room for improvement in a few decision criteria, including:
Integrations and orchestration: While the tool offers integrations with major IT solutions, its overall portfolio is limited compared to other vendors in the space. It could expand its integration management by offering API version control and build-time validation and normalization of integrations.
Case management and collaboration: While the tool supports native case management features and integrations with third party tools, it does not currently offer features such as war rooms, non-security case collaboration, or automatic human analyst assignment.
DevSecOps and detection-as-code: While the tool can be deployed and managed via CI/CD integrations, the solution’s no-code automation approach means that analysts cannot interact with its functions via APIs or via CI/CD and code repository tools. YARA and SIGMA rules are used in the backend to generate hypotheses, but these capabilities are not currently exposed to customers.
Purchase Considerations
Simbian’s pricing and licensing models are based on either the number of seats or the numbers of alerts processed. Volume and longer commitment discounts are available.
Use Cases
Simbian helps security operations teams deal with large volumes of SIEM-generated alerts by deduplicating and correlating incoming alerts on ingestion. It can automate investigation and response activities.
SIRP
Solution Overview
SIRP offers an enterprise-grade SecOps automation solution that enables organizations to run end-to-end security operations. SIRP runs an in-house expert team of consultants and automation engineers to deliver professional services for integrations and playbooks. It correlates asset value, the severity of alerts, vulnerabilities, and threat intelligence via the use of analytics to calculate a realistic security score.
SIRP is a single product that can be deployed in the cloud as well as on-premises. On-cloud SIRP is hosted in customer-preferred regions, and on-premises SIRP is shipped as a VM appliance.
SIRP’s AI agents can automate data enrichment dynamically by orchestrating workflows within playbooks and executing them whenever a new incident is ingested or created. Including predefined steps, AI agents determine the best enrichment path based on the incident’s context. They leverage both open-source and commercial reputation engines to automatically enrich artifacts such as IPs, hashes, and URLs.
SIRP is positioned as a Challenger and Fast Mover in the Maturity/Platform Play quadrant of the SecOps automation Radar report.
Strengths
SIRP scored well on a number of decision criteria, including:
Case management and collaboration: The tool has native case management features that support collaboration with external teams for the resolution of incidents, vulnerabilities, or threat intelligence. There are reports available for each container as well as collective reports that can be scheduled and generated from the reports module. Members from other teams can log in to the platform, access the container where they are tagged, and share status. Alerts are automatically assigned by an AI agent to analysts based on both the history of who handled similar alerts and availability.
Contextual risk-based scoring: The platform has its own scoring engine called SIRP security score (S3), which calculates a score based on asset values. These asset values in turn can be ingested from third-party tools or can be defined within SIRP, which can determine the risk based on the given factors.
Correlations and evolving threats: The solution uses tree charts to correlate similar incidents, based on the same artifacts of the incidents. It creates a timeline for any action performed for a particular incident and offers a MITRE dashboard to lay out different TTP patterns.
Opportunities
SIRP has room for improvement in a few decision criteria, including:
SIEM and SDL integrations: While the platform can integrate with both SIEMs and SDLs, it does not remove duplicate alarms, learn the characteristics of false positives to self-tune, ingest logs directly from source, or provide native long-term storage.
Integrations and orchestration: Although the solution offers integrations with major IT solutions, its overall portfolio is limited compared to other vendors in the space. It should expand its integrations management to allow customers to write their own integrations either using code or via no-code interfaces, and offer API version control and build-time validation and normalization of integrations.
Validation and red teaming: While the solution can define playbooks that can interact with third-party red teaming services, it does not offer these capabilities natively.
Purchase Considerations
SIRP offers a yearly licensing model based on the number of tenants and users. It has a partner onboarding program in place, and every customer is assigned a dedicated success manager who ensures proper deployment, integrations, playbooks delivery, and other support. It also offers training and certification programs on request. For users looking to self-serve, comprehensive technical documentation is available.
Use Cases
SIRP supports a variety of use cases, including automated malware response, endpoint isolation and quarantine, phishing response, VPN connection from blacklist countries, and excessive outbound connections. The company has a marketplace of playbooks from which customers can choose and deploy the one needed to automate their use case.
Splunk (Cisco): SOAR
Solution Overview
Splunk SOAR unifies security infrastructure orchestration, playbook automation, and case management across teams, tools, and processes. It enables the orchestration of security workflows and the automation of repetitive tasks and incident response. Splunk SOAR is delivered as a SaaS solution hosted and managed by Splunk and is also available as a customer-managed deployment.
Splunk SOAR can ingest security events from Splunk Cloud, firewalls, or other security products, triaging, analyzing, and tracking events in a unified interface.
Splunk SOAR playbooks can leverage Splunk Threat Intelligence Management (TIM) to enhance phishing triage flows by ingesting user-reported suspicious emails and extracting observables and enriching them with open source or commercial intelligence feeds and internal historical data. Splunk TIM then calculates a normalized score for each indicator and applies a priority score to each email for automated or manual response within Splunk SOAR.
Splunk SOAR playbooks can be simplified by calling Splunk Threat Intelligence Management for indicator enrichment from the customer’s intelligence sources. Instead of building a playbook that aggregates intelligence from all sources separately, the Splunk TIM builds an aggregated priority score that can be used to automate actions.
Users can send observables from Splunk SOAR to Splunk Threat Intelligence Management to whitelist, and it will automatically remove them from the SIEM tool. By managing all intelligence sources and preparing data in a single platform, Splunk Threat Intelligence Management increases the fidelity and usability of Splunk SOAR automated playbooks.
Splunk is positioned as an Entrant and Forward Mover in the Maturity/Platform Play quadrant of the SecOps automation Radar report.
Strengths
Splunk scored well on a number of decision criteria, including:
Contextual risk-based scoring: The solution can prioritize scoring using premium intelligence sources as well as open source feeds. Each of those sources calculates scores for events and indicators in their own way. Splunk Threat Intelligence Management aggregates, normalizes, and prioritizes intelligence across all subscribed sources by applying an indicator priority score. All of this results in a high score for threat enrichment.
Case management and collaboration: The solution has a guidance tab showing recommended users, playbooks, and actions that can be used to resolve an event. The recommendations are based on a variety of factors, such as previous playbooks or actions run on a container, event, or case with the same label. The solution can determine who expert users are by looking at their activity history to find out if they have taken action on containers, events, or cases with the same label. For example, a user that has frequently changed the state of all containers with the matching label would be considered an expert, but would be considered less of an expert if the pace of these changes diminishes as time goes on.
Integrations and orchestration: The tool has a comprehensive portfolio of integrations with over 300 third-party tools. Its capabilities can also be leveraged by Splunk Enterprise Security for a seamlessly integrated unified workflow experience.
Opportunities
Splunk has room for improvement in a few decision criteria, including:
Validation and red teaming: The solution offers some native workflow debugging features, but does not provide and provision preproduction environments or sandboxes, or create dummy incidents that can test new or updated playbooks, or leverage third-party red-teaming services that test environments from the outside and provide reports.
SIEM and SDL integration: The tool has extensive integrations with Splunk Enterprise Security but does not currently integrate with third-party SDLs. It could also improve integration feature parity with other third-party SIEM tools.
DevSecOps and detection as code: The solution can be improved through integrations with code repository systems, exposing functions via APIs, integrating with CI/CD tools to manage platform configurations, and support for detection-as-code according to YARA and SIGMA rules.
Splunk is designated a Forward Mover due to a slow rate of delivery in the last year with a correspondingly low release cadence.
Purchase Considerations
Splunk SOAR licensing is seat-based, counting named users rather than concurrent users, and is not tied to data volume or storage blocks. Customers can purchase additional seats to expand capacity as needed.
Use Cases
Splunk SOAR is suitable for large enterprises and organizations working in regulated industries. Those who deploy Splunk SOAR can automate security activities such as threat hunting, case and event management, vulnerability management, and incident response. Customers can also use Splunk Threat Intelligence Management to intake prepared and normalized intelligence from internal and external sources.
StrikeReady: Command Center
Solution Overview
StrikeReady’s Command Center is a purpose-built SecOps automation tool designed to optimize, centralize, and accelerate a company’s threat response. StrikeReady provides a no-code platform with over 300 out-of-the-box integrations, focusing on ready-made playbooks for most common response use cases. StrikeReady provides a managed cloud platform for security operations and SOC management to triage alerts, run incident response, operationalize and manage threat intelligence feeds, and guide ad-hoc investigations.
StrikeReady is consumed as SaaS, hosted in GCP, Azure, or Oracle with optional on-premises software for privacy, compliance, and connectivity as required.
StrikeReady is positioned as a Leader and Fast Mover in the Innovation/Platform Play quadrant of the SecOps automation Radar report.
Strengths
StrikeReady scored well on a number of decision criteria, including:
Correlations and evolving threats: The tool aggregates similar alerts automatically added to incidents, such as alerts from the same host and to the same IP/domain. It generates timelines of all incidents as alerts are triggered and as triage happens. It can also generate topological graphs or dependency maps that show affected assets with drill-down abilities. It uses time-bound telemetry such as DNS logs from before and after an endpoint alert, pulling in proxy logs around an incident and understanding what emails a user just received before a click event was recorded.
SIEM and SDL integrations: The platform can integrate with third-party SDLs to perform automated hunting based on indicators from threat intelligence reports. It can provide on-demand federated search and can use SIEM data to generate timelines for additional context around alerts.
Zero-day response: The solution can help respond to zero-day incidents via an environment for examining suspicious content in both manual and automated sandboxes, and the indicators can be fed throughout the product circularly. The tool can ingest quarantined files from an endpoint or URLs from an email provider and perform sandbox analysis.
StrikeReady earned an Outperformer status due to its high rate of delivery in the last year, and strong roadmap for the coming year.
Opportunities
StrikeReady has room for improvement in a few decision criteria, including:
DevSecOps and detection as code: The solution can improve through native version control systems, offering detection-as-code, and supporting code-based automation via code reviews.
LLM modularity: While the tool has been implementing LLMs since 2019 and hosts them within its own infrastructure, customers can’t bring their own models, choose where the models run, or configure LLM parameters such as the context window.
Purchase Considerations
The solution is priced and sized based on the number of users and number of integrations. StrikeReady offers pay-as-you-grow models through which customers often start with a small package and grow as they add more integrations. At the moment, the solution does not offer a freemium model or multiple license tiers.
Use Cases
StrikeReady can cater to a variety of use cases, including case management for security operations, alert enrichment, false positive discovery, and dark web alerting and monitoring. The solution's multitenant SOC platform is suitable for managed detection and response (MDR) and MSSPs.
Swimlane: Turbine
Solution Overview
Swimlane Turbine is a security automation platform that can be deployed in the cloud, on-premises, and in air-gapped environments. It acts as the system of record for all security operations through its case management, dashboard, and reporting features.
Swimlane’s latest developments include:
Hero AI, Swimlane’s collection of generative and agentic AI innovations built on a proprietary LLM for private and secure use of generative AI in any security workflow or use case.
Turbine Canvas, a low-code playbook building studio.
Swimlane Marketplace, the industry's first full-stack marketplace offering complete end-to-end solutions, thousands of playbooks, automated actions, connectors and more.
Autonomous integrations for infinite API connections and an ecosystem-agnostic integration network.
Business intelligence applications, which include highly composable dashboards, scheduled reporting, and robust case management applications that help SOC, vulnerability and compliance teams customize and establish their own system or record for any use case.
Active Sensing Fabric, which uses webhooks and remote agents to enable ingesting, enriching, and correlating data from broader and hard-to-reach integration sources.
Swimlane is positioned as a Leader and Outperformer in the Maturity/Platform Play quadrant of the SecOps automation Radar report.
Strengths
Swimlane scored well on a number of decision criteria, including:
Case management and collaboration: The platform offers built-in features that are tightly integrated with playbooks and workflows. The Turbine Collaboration Extension integrates the platform with common communication channels within an organization so security teams can collaborate across organizational entities. This includes common ticketing systems, chat, email, and file sharing applications such as Jira, Slack, Google Workspace, and Microsoft 365 that allow analysts managing security activities to collaborate, communicate, and disseminate information to teams outside the SOC.
Correlations and evolving threats: The solution can search through closed or resolved incidents and suggest recommendations based on past steps to close that incident. It can also create a post-incident review, lessons-learned playbook, and workflow with notifications for specific analysts. It can automatically assign cases to analysts based on capabilities, specialty areas, existing capacity or workload, or even holiday schedules. As long as users are well defined and the appropriate productivity suite integrations are in place, the assignment of alerts, events, cases, tasks, and other activities can be automatic.
SIEM and SDL integrations: The platform correlates alerts, cases, and incidents across all integrated tools in the ecosystem, serving as the system of record for security. It uses preprocessing and inline enrichment to execute thousands of concurrent automations. Each organization's unique business logic and processes help inform the way Turbine applies custom data filtering, preprocessing, deduplication, and inline enrichment to improve the analyst experience.
Swimlane is considered an Outperformer due to its high rate of releases and delivery over the last year, such as Hero AI, Turbine Canvas, and Active Sensing Fabric and its strong roadmap for the coming year.
Opportunities
Swimline has room for improvement in a few decision criteria, including:
Zero-day response: The platform could be improved by offering isolation proxies and native sandboxes, as well as in-house threat research teams to investigate never-before-seen threats and to help with response activities.
DevSecOps and detection as code: While the solution offers versioning of playbooks, supports SIGMA and YARA rules, and provides integrations with CI/CD systems, it does not currently support detection-as-code and managing automation as code alongside version control code reviews. It could improve through integrations with code repository systems by integrating with external CI/CD tools to manage platform configurations, and by supporting detection-as-code according to YARA and SIGMA rules.
Validation and red teaming: While the solution can define red teaming playbooks that can interact with third-party red teaming services, the solution does not offer these capabilities natively.
Purchase Considerations
Swimlane offers a four-tier licensing model based on actions automated per day. All value-based tiers include access to the full-Turbine platform, including designated levels of AI prompts and support. Additional automation, AI prompts, and data retention capacity can be added to any tier. The tier model includes basic support for the first two tiers and premium support for upper tiers. Customers have the option to upgrade to premium support, and to add on technical account management (TAM) services for additional customization support. As an alternative model, customers also have the option to invest in Turbine on a per-user basis.
Use Cases
Swimlane Turbine offers prebuilt curated automation solutions for phishing, SIEM, EDR, and XDR alert triage, case and incident management, vulnerability response management, and compliance audit readiness through Swimlane Marketplace. Customers can use components and automation tools, also available in Marketplace, and Turbine Canvas to build a wide range of use cases, such as insider threat detection and response, secure employee on/off-boarding, fraud investigation and response, anti-cheat investigation, physical security, and others.
Tines
Solution Overview
Tines is an automation tool built for security teams to automate and orchestrate their daily activities. Tines’ underlying philosophy is that all workflows can be defined using only eight actions: send email, event transformation, HTTP request, receive email, trigger, webhook, send to story, and AI agent. Tines is available as a SaaS solution, with self-hosted options also available.
Tines Workflow Platform is built upon three pillars: Build, Run, and Monitor. In the tool, the build and execution environments are the same, which means users' most important workflows are ready to run. The solution’s robust monitoring features give visibility into workflow performance and create transparency on their output and impact.
In Tines, threat intelligence can be stored in records, which provide a way of storing indicators or feeds for an unlimited length of time. This means that instead of calling threat intelligence feeds in real time, analysts can query data that is already stored in Tines. Rather than normalizing feeds with a global schema, Tines gives customers the ability to create custom schema for their threat intelligence feeds using only fields that are relevant to their business. Customers can filter out details they may not use, such as original source or recording vendor.
Tines is positioned as a Leader and Fast Mover in the Innovation/Platform Play quadrant of the SecOps automation Radar report.
Strengths
Tines scored well on a number of decision criteria, including:
Case management capabilities: The platform enables analysts to document and collaborate on incidents and has advanced functionalities, including auto-assigning analysts based on a variety of factors such as profiles and current workload, as well as assigning cases based on their nature, such as malware, zero-day, or compromised C-suite devices. The case management capabilities also span across non-security teams, including business units such as HR, legal, and finance.
SIEM and SDL integrations: The solution can tune the alert generation systems at the source, such as suppressing known false positives generated by SIEM or filtering out specific indicators of compromise such as an IP address from an otherwise functional alarm. In instances where alert generation systems stop producing alerts, Tines can be used to pick up on the lack of alerts and draw attention to potential failures of upstream tools.
Contextual risk based scoring: Tines uses standards such as CVSS and CVE and can also act as a CMDB, enabling analysts to query information directly in Tines. Workflows can be used to perform a scan across a customer’s cloud assets and store all those cloud assets in a record table, including information such as uptime, IP address, operating system, known vulnerabilities, and patch status. With the event transformation action, weightings can be formulaically changed to produce scores with respect to the current environment.
Opportunities
Tines has room for improvement in a few decision criteria, including:
Correlations and evolving threats: The solution can analyze events across a timeline and identify the affected devices and the relationships among them, but it’s missing some advanced visualization features, such as natively generating interactive topological maps of affected entities to aid in threat hunting.
Pre-LLM data layer: Though Tines has an inherent ability to define deterministic logic prior to an LLM, it does not offer any preconfigured LLM-friendly actions for processing data, such as time-series analysis or explicit log schema definition.
Purchase Considerations
Tines offers a flexible licensing model tailored to various user needs. The platform provides an always-free community edition for basic use, enabling teams to start building and automating workflows without initial costs. For more advanced features and enterprise-grade capabilities, Tines offers paid plans. These plans are tiered and based on the scale of usage, number of users, and required features, providing scalable solutions for different organizational needs.
Use Cases
Tines can deliver on a range of security and non-security use cases. For SecOps automation-specific use cases, Tines can help automate incident response, vulnerability management, case management, and threat hunting. Tines’s workflow definition flexibility also enables a wide range of non-security use cases, which positions Tines to be deployed as an all-purpose automation tool rather than just a security-specific tool.
Torq
Solution Overview
Torq is an enterprise-grade security automation solution for no-code, low-code, and pro-code automations. It offers a rich template library addressing automation for various pillars of a cybersecurity program, such as SecOps, threat intelligence, threat hunting, cloud security, application security, IAM, device management, and GRC.
Torq is hosted on IaaS services such as GCP and AWS, and it has points of presence in various regions. Torq’s automation data plane can be separated from a control plane and can be self-hosted in any bare metal or virtualized private network.
Torq offers autonomous operations features for both the workflow design process and the workflow runtime for processing security events. Design-time capabilities consist of assistive development of automated processes, such as summarization for successful collaboration, improvement, and development co-pilots. Runtime capabilities consist of data enrichment and data-driven suggestions for assigning specific teams or analysts based on their profile, ownership, and history, and to recommend investigative steps to help understand the issue and containment actions that can help stop the negative effect and allow remediation as part of a process to resolve the issues completely.
Torq is positioned as a Leader and Fast Mover in the Innovation/Platform Play quadrant of the SecOps automation Radar report.
Strengths
Torq scored well on a number of decision criteria, including:
Case management and collaboration: The platform earned a top score in this area with a built-in case management system developed in-house and integrated with the solution’s event-driven architecture and security automation capabilities. It also offers out-of-the-box bidirectional integrations with leading case management systems such as ServiceNow, Jira, and Zendesk, and with communication platforms like Slack, Microsoft Teams, and Cisco Webex. It supports in-the-platform virtual war rooms as a part of its case management, and its multi-workspace architecture and granular role-based access controls (RBAC) can involve multiple teams across organizational disciplines: security, IT, engineering, business lines, and HR.
SIEM and SDL integrations: The solution can collapse multiple signals based on asset, asset-owning team, asset type and location, asset-event-time-frame combination, enriched asset properties, and more. False positive filtering can be configured according to a set of deterministic rules processing the events using risk scores or analysis from external systems. The tool can also integrate with ML and anomaly detection systems and reintroduce their response to recalibrate filtering processes.
Red teaming and validation: The tool enables users to test workflows on sample events with expected outcomes. All changes to workflows are tracked, and with each version, there is a clear (available via UI or API) list of changes made. Separate development and staging environments are available for testing and “responsible deployment” of workflows.
Opportunities
Torq has room for improvement in a few decision criteria, including:
Zero-day response: While the platform offers comprehensive zero-day response capabilities, including the collection of binaries, URLs, and documents and can scan them in a sandbox environment to identify TTPs, it does not currently have in-house threat research teams to investigate never-before-seen threats and help with response activities.
Non-LLM AI features: The solution’s AI focus centers on agentic AI capabilities built on an LLM foundation. The tool does not offer native capabilities for statistical analysis or deep learning, though it does provide some of these functionalities via integrations with specialized third-parties.
Correlations and evolving threats: The platform has extensive capabilities in this area, including visual and interactive displays of affected assets. However, it does not natively offer direct peer benchmarking to see how information gathered from threats seen in one environment can be used to secure other environments.
Purchase Considerations
Torq Hyperautomation licensing models are structured around the platform tier, number of workspaces, and product add-ons. Platform tier licensing is based on the number of employees, which determines the volume of security events to be automated. This ensures that the platform can handle security events with proper urgency and efficiency.
Each workspace is licensed based on the number of workflows and access to platform features. Workspaces can be upgraded with additional workflows and features as needed. Customers can purchase additional features and services as add-ons to their existing licenses. This includes extra workflows, advanced insights, and case management capabilities.
Use Cases
Torq can deliver on a wide range of automation and response use cases, which includes IAM, threat hunting, and cloud security posture management.
6. Analyst’s Outlook
SecOps automation is undergoing one of the most transformative changes in the industry. This category can heavily benefit from developments around generative AI. However, there is still a considerable gap between deterministic workflow-based automation and non-deterministic LLM-based automation. The first is predictable and safe for enterprises to deploy across their organization, though it involves extensive manual work in defining and maintaining the automation workflows. The latter removes much of the setup and maintenance friction, but it is still an immature solution and inherently volatile. Currently, the best middle ground is the wrapping of non-deterministic LLMs in deterministic workflows.
The most important decision factor in today’s SecOps automation market is the product’s architecture. LLM-first solutions do not have to retrofit AI in their product and may be able to unlock automation results that were previously unavailable. However, edge cases in longer-term real world deployments must be considered and evaluated to understand how these products are able to evolve and adapt. Workflow-based toolings can offer the benefits from both worlds and may be a better choice for the near future.
7. About Andrew Green
Andrew Green is an enterprise IT writer and practitioner with an engineering and product management background at a tier 1 telco. He is the co-founder of Precism.co, where he produces technical content for enterprise IT and has worked with numerous reputable brands in the technology space. Andrew enjoys analyzing and synthesizing information to make sense of today's technology landscape, and his research covers networking and security.
8. About GigaOm
GigaOm provides technical, operational, and business advice for IT’s strategic digital enterprise and business initiatives. Enterprise business leaders, CIOs, and technology organizations partner with GigaOm for practical, actionable, strategic, and visionary advice for modernizing and transforming their business. GigaOm’s advice empowers enterprises to successfully compete in an increasingly complicated business atmosphere that requires a solid understanding of constantly changing customer demands.
GigaOm works directly with enterprises both inside and outside of the IT organization to apply proven research and methodologies designed to avoid pitfalls and roadblocks while balancing risk and innovation. Research methodologies include but are not limited to adoption and benchmarking surveys, use cases, interviews, ROI/TCO, market landscapes, strategic trends, and technical benchmarks. Our analysts possess 20+ years of experience advising a spectrum of clients from early adopters to mainstream enterprises.
GigaOm’s perspective is that of the unbiased enterprise practitioner. Through this perspective, GigaOm connects with engaged and loyal subscribers on a deep and meaningful level.
9. Copyright
© Knowingly, Inc. 2025 "GigaOm Radar for SecOps Automation" is a trademark of Knowingly, Inc. For permission to reproduce this report, please contact sales@gigaom.com.