档案库 · 开发与企业工具 · 产品决策 · 2024–2026
Tracecat 押注廉价开源 SOAR 可击败 Splunk 10 万美元的套件;3.8k 星
安全自动化始于单虚拟机 SOAR 替代品,现走向代理化;2024 年 Show HN 获 264 分,2026 年达 3.8k 星。
Tracecat
做的是什么生意
Tracecat is an open-source security automation platform for teams and AI agents: analysts build alert-response automations (investigate, contact victims, escalate, log evidence) with low-code workflows, case management and 100+ connectors, deployable as managed cloud or self-hosted.
起因
The founders were data engineers who kept hearing security friends complain about being priced out of SOAR — Splunk SOAR runs to roughly $100,000/year — while analysts face about 100 alerts a day at roughly 30 minutes each, so alerts get dropped and breaches trace back to week-old tickets. Tracecat began as a bare-bones alpha: webhook-triggered event workflows, REST API integrations, JSONPath parsing, conditional blocks, Tantivy log storage and a Jira-like case table, showcased on 2024-03-25 as 'an open source automation platform for security alerts.'
经过
The Show HN thread became a positioning debate: the founders defended an open-core business model, arguing they could out-iterate incumbents on UX, especially for AI features; commenters warned that free software is not a business model and Tracecat would need to paywall features. The product then moved up the stack: by the 2026-09-04 crawl the README describes 'the agentic security automation platform' with prompt-to-automations driven from Claude Code, Codex and OpenCode via MCP, code-native Python sync, sandboxed execution with nsjail, durable workflows on Temporal, and an Enterprise Edition under AGPL-3.0 with paid EE licensing and managed Cloud (US/EU) or self-hosting options.
结果
Still running as an open-core company: the 2026-09-04 crawl shows 3.8k stars, 411 forks, 5,736 commits, a paid Tracecat Enterprise tier and managed Cloud plus self-hosted deployment options. The material carries no funding, revenue, shutdown or acquisition data.
背景
Tracecat 是开源安全自动化平台,起初是商业 SOAR 的廉价替代品:团队通过工作流将 webhook、集成和条件逻辑串联起来,用于调查警报、联系受害者、升级事件和记录证据,并附带案例管理。
押注在于经济和架构:大多数安全团队被每年约 10 万美元的 Splunk SOAR 等平台拒之门外,因此运行在单虚拟机或笔记本上的更简单引擎——SQLite 加 Python 3.12 asyncio 事件处理器,配合 Tantivy 日志存储——能为其他人实现警报响应自动化。后来,押注扩展到代理式自动化:提示词可直接转化为端到端自动化,而非拖拽式剧本。
发展轨迹从 2024 年 3 月 25 日 Show HN 的简易 Apache-2.0 alpha(264 分、65 条评论)开始,其间创始人捍卫开放式核心,反对“免费软件不是商业模式”的警告,最终到 2026 年的产品自我描述为“代理式安全自动化平台”:通过 MCP 由 Claude Code、Codex 和 OpenCode 驱动,提示词转自动化、代码原生 Python、nsjail 沙箱、基于 Temporal 的持久化,以及 AGPL-3.0 企业版和付费许可。
截至 2026 年 9 月 4 日抓取,TracecatHQ/tracecat 显示 3.8k 星、411 分支和 5,736 次提交,提供托管云(美国/欧盟)和自托管选项,以及开源核心;资料中未见融资、营收或退出数字。
这件事要成立,得有什么
- 可验证的关注度:2024 年 3 月 25 日 Show HN 获 264 分和 65 条评论,仓库在 2026 年 9 月 4 日抓取时达 3.8k 星、411 分支和 5,736 次提交。
- 押注明确且可测试:价格和操作复杂度使 SOAR 对大多数团队遥不可及,因此单虚拟机开源引擎正击中 Splunk 10 万美元 Kubernetes 级套件的软肋。
- 帖子中实时讨论了商业模式——开放核心对永久免费——而 2026 年 AGPL 加企业许可表明公司选择了哪个答案。
- 故事有可验证的轨迹:从 alpha 发布到更名后的代理平台,都在同一仓库和 HN 帖子中有据可查。
可借鉴之处
先攻击现有厂商的价格和操作复杂度,再谈功能:单虚拟机 SOAR 让 Kubernetes 级 10 万美元的套件显得荒谬,开源代码本身就是卖点。
后续进展
截至 2026 年 9 月 5 日,Tracecat 以开放核心公司运营:2026 年 9 月 4 日抓取 TracecatHQ/tracecat 显示 3.8k 星、411 分支和 5,736 次提交,README 将平台定位为“代理式安全自动化”,提供通过 MCP 的提示词到自动化、100+ 连接器、nsjail 沙箱、基于 Temporal 的持久工作流,以及 AGPL-3.0 下的付费企业版,以托管云(美国/欧盟)或自托管加支持形式出售。资料中未披露融资、营收、关闭或收购信息,因此商业上的押注无法从这些来源验证。
资料来源
- TracecatHQ/tracecat — Open-source security automation platform (3.8k stars at 2026-09-04 crawl)
- Show HN: Tracecat – Open-source security alert automation / SOAR alternative
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡