Palo Alto Networks / SOAR / automation software
Cortex XSOAR is standalone security orchestration software with playbooks, a war room, marketplace content, and case management. Cortex XSIAM is a separate converged operations platform that embeds SIEM, XDR, and SOAR, including playbooks, Quick Actions, and automation rules.
Explore Cortex XSOAR and XSIAM ↗Cisco / SOAR / automation software
Splunk SOAR is licensed orchestration software, offered in cloud and on-premises forms, that automates playbooks and case management. Cisco owns Splunk. This profile is the software playbook plane, not a Cisco managed detection and response service.
Explore Splunk SOAR ↗Google / SOAR / automation software
Google Security Operations SOAR connects alerts, cases and response playbooks within Google’s security operations platform. Integrations and custom actions let analysts gather context and coordinate supported response steps, while the operating team remains responsible for permissions, workflow design and approvals.
Explore Google Security Operations SOAR ↗Tines / SOAR / automation software
Tines is a practitioner-oriented workflow platform used as security automation without a classic SOAR label. Analysts can build drag-and-drop or natural-language workflows with an audit trail, case templates, and vendor-agnostic APIs.
Explore Tines ↗Torq / SOAR / automation software
Torq sells workflow automation often marketed as AI SOC or hyperautomation. Documented building blocks include HyperAgents, a Socrates orchestrator, natural-language workflow building, and case handling. Outcome statistics on vendor pages are advertised, not independently tested here.
Explore Torq ↗Swimlane / SOAR / automation software
Swimlane Turbine is a pure-play automation platform that claims SOC plus governance, risk, and vulnerability workflow uses. It offers a low-code canvas, case management, API connectors, and agentic routing of simple versus complex alerts.
Explore Turbine ↗Fortinet / SOAR / automation software
FortiSOAR is Fortinet's fabric-adjacent security orchestration product with SaaS and self-managed options. It documents playbooks, case management, expert agents, API and MCP connections, and multi-tenancy aimed at managed service providers. OT-oriented packs are advertised.
Explore FortiSOAR ↗Rapid7 / SOAR / automation software
Rapid7 Automation, documented under the InsightConnect name, provides security workflows that connect tools, enrich alerts and coordinate response. Analysts can combine plugins and human decision steps to make a repeatable process while retaining responsibility for its permissions and operation.
Explore Rapid7 Automation ↗CrowdStrike / Managed detection and response
Falcon Complete is CrowdStrike's native-platform managed detection and response service. Provider analysts detect, investigate, and, when contracted, remediate using Falcon telemetry across endpoint, identity, cloud, SaaS, and optional third-party sources through Next-Gen SIEM.
Explore Falcon Complete ↗Microsoft / Managed detection and response
Defender Experts MDR is Microsoft-staffed managed detection and response that augments a customer security operations center. It was renamed from Defender Experts for XDR. Neither plan is an incident-response engagement, and Plan 2 is not managed SIEM.
Explore Defender Experts MDR ↗Sophos / Managed detection and response
Sophos MDR is a staffed managed detection and response service with around-the-clock monitoring, hunting, containment, flexible response modes, and third-party telemetry options. Secureworks is not a second vendor; Sophos closed that acquisition.
Explore Sophos MDR ↗Arctic Wolf / Managed detection and response
Aurora MDR is Arctic Wolf's concierge managed detection and response service. It advertises around-the-clock detect, respond, and remediate guidance, a Concierge Experience, and open XDR integrations. Cylance is an acquired endpoint product, not a peer MDR company.
Explore Aurora MDR ↗Expel / Managed detection and response
Expel MDR is a vendor-agnostic staffed service that investigates threats on the customer's existing endpoint, identity, and cloud tools. A workbench, around-the-clock SOC, and AI-assisted investigation (Ruxie) are advertised. Auto-remediation needs pre-authorization after analyst validation.
Explore Expel MDR ↗Zscaler / Managed detection and response
Zscaler MDR provides staffed investigation of supported endpoint, cloud and identity threats. Its portal, automation and validation capabilities help customer teams understand provider findings and test the service. The Red Canary lineage is relevant when identifying current documentation and service entitlements.
Explore Zscaler MDR ↗eSentire / Managed detection and response
eSentire MDR is a multi-signal staffed service packaged as Atlas Essentials, Advanced, and Complete. It advertises around-the-clock hunt, investigate, and respond across endpoint, network, log, cloud, and identity packages, with Microsoft-ecosystem MXDR listed in Azure Marketplace.
Explore eSentire MDR ↗Huntress / Managed detection and response
Huntress offers managed endpoint, identity and log-monitoring services supported by a staffed security operations center. Its portfolio is relevant to IT teams and managed service providers evaluating which operational responsibilities to delegate and which product layers they actually need.
Explore Huntress ↗Rapid7 / Managed detection and response
Rapid7 MDR combines a staffed security operations center, an advisor, hunting and exposure-informed investigations. The service works with customer teams under an agreed scope, so learners should distinguish provider investigation and response duties from the separate Rapid7 Automation software.
Explore Rapid7 MDR ↗SentinelOne / Managed detection and response
Wayfinder MDR is SentinelOne's current platform-linked managed detection and response service. It advertises continuous detection, investigation, response, and hunting using SentinelOne and Google threat intelligence, with Essentials and Elite service levels. Older Vigilance and Singularity MDR materials are lineage, not the current order form.
Explore Wayfinder MDR ↗