EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2024–2026

Tracecat bets cheap open-source SOAR beats Splunk's $100k stack; 3.8k stars

Security automation born as a one-VM SOAR alternative, now agentic; 264-point Show HN in 2024, 3.8k stars by 2026.

Tracecat

The betTeams are priced out of SOAR, so an open-source engine that runs on one VM — and later turns prompts into automations — can win where Splunk SOAR charges $100k/year.Live

What the business is

Tracecat is an open-source security automation platform for teams and AI agents: analysts build alert-response automations (investigate, contact victims, escalate, log evidence) with low-code workflows, case management and 100+ connectors, deployable as managed cloud or self-hosted.

How it started

The founders were data engineers who kept hearing security friends complain about being priced out of SOAR — Splunk SOAR runs to roughly $100,000/year — while analysts face about 100 alerts a day at roughly 30 minutes each, so alerts get dropped and breaches trace back to week-old tickets. Tracecat began as a bare-bones alpha: webhook-triggered event workflows, REST API integrations, JSONPath parsing, conditional blocks, Tantivy log storage and a Jira-like case table, showcased on 2024-03-25 as 'an open source automation platform for security alerts.'

What happened

The Show HN thread became a positioning debate: the founders defended an open-core business model, arguing they could out-iterate incumbents on UX, especially for AI features; commenters warned that free software is not a business model and Tracecat would need to paywall features. The product then moved up the stack: by the 2026-09-04 crawl the README describes 'the agentic security automation platform' with prompt-to-automations driven from Claude Code, Codex and OpenCode via MCP, code-native Python sync, sandboxed execution with nsjail, durable workflows on Temporal, and an Enterprise Edition under AGPL-3.0 with paid EE licensing and managed Cloud (US/EU) or self-hosting options.

How it ended up

Still running as an open-core company: the 2026-09-04 crawl shows 3.8k stars, 411 forks, 5,736 commits, a paid Tracecat Enterprise tier and managed Cloud plus self-hosted deployment options. The material carries no funding, revenue, shutdown or acquisition data.

Background

Tracecat is an open-source security automation platform that started as a cheap alternative to commercial SOAR products: teams wire webhooks, integrations and conditional logic into workflows that investigate alerts, contact victims, escalate incidents and log evidence, with case management on top.

The bet was economic and architectural: most security teams are priced out of platforms like Splunk SOAR at roughly $100,000/year, so a simpler engine that runs on a single VM or laptop — SQLite plus a Python 3.12 asyncio event processor, with Tantivy log storage — could automate alert response for everyone else. Later the bet extended to agentic automation: prompts become end-to-end automations instead of drag-and-drop playbooks.

The arc ran from a 2024-03-25 Show HN of a bare-bones Apache-2.0 alpha (264 points, 65 comments) through a thread where the founders defended open core against warnings that free software is not a business model, to a 2026 product that describes itself as 'the agentic security automation platform': prompt-to-automations via MCP from Claude Code, Codex and OpenCode, code-native Python sync, nsjail sandboxing, Temporal durability, and an Enterprise Edition under AGPL-3.0 with paid licensing.

As of the 2026-09-04 crawl, TracecatHQ/tracecat shows 3.8k stars, 411 forks and 5,736 commits, with managed Cloud (US/EU) and self-hosted options alongside the open-source core; no funding, revenue or exit figures appear in the material.

What has to be true

  • Verifiable attention: the 2024-03-25 Show HN drew 264 points and 65 comments, and the repo reached 3.8k stars, 411 forks and 5,736 commits by the 2026-09-04 crawl.
  • The bet is sharp and testable: price and operating complexity keep SOAR out of reach for most teams, so a one-VM open-source engine attacks Splunk's $100k Kubernetes-grade stack where it is weakest.
  • The thread shows the business-model question argued in real time — open core versus free-forever — and the 2026 AGPL-plus-Enterprise licensing shows which answer the company chose.
  • The story has a verifiable arc from alpha launch to a rebranded agentic platform, all documented on the same repo and HN thread.

What can be applied

Attack the incumbent's price and operating complexity before its features: a SOAR that runs on one VM makes the Kubernetes-grade $100k stack look absurd, and open code does the selling.

Aftermath

As of 2026-09-05 Tracecat is running as an open-core company: the 2026-09-04 crawl of TracecatHQ/tracecat shows 3.8k stars, 411 forks and 5,736 commits, and the README presents the platform as 'agentic security automation' with prompt-to-automations via MCP, 100+ connectors, nsjail sandboxing, Temporal-based durable workflows, and a paid Enterprise Edition under AGPL-3.0, sold as managed Cloud (US/EU) or self-hosted with support. The material contains no funding, revenue, shutdown or acquisition disclosures, so the commercial half of the bet is not verifiable from these sources.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases