Best Enterprise Incident Response Software

How Many Incident Response Software Products Does G2 Track?

Total Products under this Category: 108

Category Stats (Sep 2026)

  • Average Rating: 4.47/5 (↓0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: CybaOps (+0.97%) - Among all products in this category, CybaOps recorded the largest rating increase compared to last month

Last updated: September 29, 2026

How Does G2 Rank Incident Response Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 108+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Incident Response Software

G2 Grid® for Incident Response Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Tines Stories, ServiceNow Security Operations, Microsoft Sentinel, KnowBe4 PhishER/PhishER Plus, IBM QRadar SIEM, Palo Alto Cortex XSIAM, and Splunk Enterprise Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/incident-response/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=tines-stories&focus%5B%5D=servicenow-security-operations&focus%5B%5D=microsoft-sentinel&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=ibm-ibm-qradar-siem&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=splunk-enterprise-security&segment=enterprise)

CrowdStrike Falcon Endpoint Protection Platform

Organizations today face a serious challenge: managing numerous security vendors and tools while confronting an ever-evolving threat landscape. Sophisticated adversaries are becoming smarter, faster, and more evasive, launching complex attacks that can strike in minutes or even seconds. Traditional security approaches struggle to keep pace, leaving businesses vulnerable. The CrowdStrike Falcon Platform addresses this by offering a unified, cloud-native solution. It consolidates previously siloed security solutions and incorporates third-party data into a single platform with one efficient and resource-conscious agent, leveraging advanced AI and real-time threat intelligence. This approach simplifies security operations, speeds analyst decision making, and enhances protection to stop the breach, allowing organizations to reduce risk with less complexity and lower costs. CrowdStrike's Falcon Platform includes: - Endpoint Security: Secure the endpoint, stop the breach - Identify Protection: Identity is the front line, defend it - Next-Gen SIEM: The future of SIEM, today - Data Protection: Real-time data protection from endpoint to cloud - Exposure Management: Understand risk to stop breaches - Charlotte AI: Powering the next evolution of the SOC

Average Rating: 4.7/5.0

Total Reviews: 545

How Do G2 Users Rate CrowdStrike Falcon Endpoint Protection Platform?

  • Threat Intelligence: 9.5/10 (Category avg: 8.9/10)
  • Quality of Support: 9.0/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind CrowdStrike Falcon Endpoint Protection Platform?

  • Seller: CrowdStrike
  • Company Website:
  • Year Founded: 2011
  • HQ Location: Sunnyvale, CA
  • Twitter: @CrowdStrike
    110,809 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    21,058 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Analyst, Security Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 46% Large, 40% Medium

What Do G2 Reviewers Say About CrowdStrike Falcon Endpoint Protection Platform?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the lightweight performance and powerful threat detection of CrowdStrike Falcon, enhancing security without slowing down systems.
  • Users commend the effective threat detection capabilities of CrowdStrike Falcon, ensuring robust security without system slowdowns.
  • Users appreciate the ease of use of CrowdStrike Falcon, benefiting from its lightweight impact and efficient incident management.
  • Users appreciate the advanced real-time threat protection of CrowdStrike Falcon, ensuring efficient security without system performance issues.
  • Users praise the exceptional threat detection of CrowdStrike Falcon, noting its effectiveness against both known and unknown threats.
Cons
  • Users find the cost prohibitive for smaller organizations, especially with additional modules increasing overall expenses.
  • Users find the complexity of the user interface and additional costs challenging, complicating their overall experience.
  • Users face a steep learning curve with CrowdStrike’s query language, making transitions from other platforms challenging.
  • Users find the limited features challenging, especially concerning cost and technical accessibility for smaller businesses.
  • Users find that pricing can be a barrier for smaller organizations, complicating access to advanced features.

What Are Recent G2 Reviews of CrowdStrike Falcon Endpoint Protection Platform?

What Are G2 Users Discussing About CrowdStrike Falcon Endpoint Protection Platform?

Tines Stories

Tines is the intelligent workflow platform trusted by the world's most advanced organizations. Companies like Coinbase, Databricks, Mars, Reddit, and SAP use Tines to power their most important workflows. With Tines, they’ve built a secure, flexible foundation to operationalize AI agents and intelligent workflows, unlocking productivity, moving faster, and future-proofing how work gets done.

Average Rating: 4.7/5.0

Total Reviews: 424

How Do G2 Users Rate Tines Stories?

  • Threat Intelligence: 8.8/10 (Category avg: 8.9/10)
  • Quality of Support: 9.5/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.7/10 (Category avg: 8.5/10)
  • Incident Logs: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind Tines Stories?

  • Seller: Tines
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Dublin, IE
  • LinkedIn® Page: www.linkedin.com
    619 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 38% Medium, 35% Large

What Do G2 Reviewers Say About Tines Stories?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Tines, enabling seamless automation without any coding knowledge.
  • Users highlight the flexibility and ease of automation with Tines, making integration and workflow creation seamless.
  • Users commend Tines for its exceptional customer support, appreciating the team's responsiveness and proactive assistance.
  • Users highlight Tines for its ease of use and rapid implementation, significantly boosting team efficiency and automation capabilities.
  • Users value Tines for its time-saving automation capabilities, allowing teams to focus on more strategic activities efficiently.
Cons
  • Users note a steep learning curve with Tines, especially for newcomers to automation and orchestration tools.
  • Users find Tines lacking in missing features that can hinder initial onboarding and expectations for functionality.
  • Users note a lack of features in Tines, pointing out missing options and inconsistencies in functionality.
  • Users find the complexity of advanced features in Tines overwhelming, especially for teams lacking a clear strategy.
  • Users find Tines has a difficult learning curve, particularly for newcomers to automation and orchestration tools.

What Are Recent G2 Reviews of Tines Stories?

What Are G2 Users Discussing About Tines Stories?

ServiceNow Security Operations

ServiceNow Security Operations is a sophisticated software solution designed to enhance threat and vulnerability management as well as incident response for organizations. By leveraging artificial intelligence, this platform empowers security teams to operate more efficiently and effectively, allowing for streamlined collaboration across IT, security, and risk management departments. The primary goal of ServiceNow Security Operations is to simplify complex security processes while minimizing risks associated with cybersecurity threats. Targeted at security teams within organizations of various sizes, ServiceNow Security Operations addresses the need for a cohesive approach to managing security incidents and vulnerabilities. It is particularly beneficial for organizations that utilize multiple security tools, as it integrates security and vulnerability data from these existing systems. This integration enables teams to respond to threats more rapidly by automating critical workflows and processes, thus reducing the manual effort traditionally required in incident response. The platform is suitable for both small businesses and large enterprises, making it a versatile choice for organizations looking to enhance their cybersecurity measures. Key features of ServiceNow Security Operations include intelligent workflows that automate routine tasks, allowing security professionals to focus on more strategic initiatives. The platform’s AI-driven capabilities facilitate the automatic correlation of threat intelligence from diverse sources, such as the MITRE ATT&CK framework. This feature enhances situational awareness and enables teams to prioritize threats effectively based on real-time data. Additionally, the ability to take action within other security or IT management tools from a centralized console streamlines operations, ensuring that teams can respond to incidents without unnecessary delays. This centralized approach not only improves efficiency but also fosters better communication among different departments involved in security management. Moreover, the use of digital security workflows and orchestration significantly accelerates tasks such as analysis, prioritization, and remediation. By automating these processes, organizations can improve their response times and enhance their overall cybersecurity posture. The integration of AI-driven automation within the ServiceNow AI Platform® further strengthens the platform's capabilities, enabling organizations to drive cyber resilience and reduce their exposure to potential threats. This proactive approach to cybersecurity ensures that organizations are not only reacting to incidents but are also prepared to prevent them. ServiceNow Security Operations stands out in the cybersecurity landscape by offering a comprehensive solution that addresses the complexities of modern cybersecurity challenges. By automating and simplifying threat and vulnerability management, it empowers security teams to respond more effectively, thereby enhancing the overall security framework of an organization. This makes it an essential tool for any organization looking to bolster its defenses against the ever-evolving landscape of cyber threats.

Average Rating: 4.3/5.0

Total Reviews: 81

How Do G2 Users Rate ServiceNow Security Operations?

  • Threat Intelligence: 8.9/10 (Category avg: 8.9/10)
  • Quality of Support: 8.4/10 (Category avg: 8.8/10)
  • Incident Case Management: 9.1/10 (Category avg: 8.5/10)
  • Incident Logs: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind ServiceNow Security Operations?

  • Seller: ServiceNow
  • Company Website:
  • Year Founded: 2004
  • HQ Location: Santa Clara, CA
  • Twitter: @servicenow
    55,548 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    35,078 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 55% Large, 19% Medium

What Do G2 Reviewers Say About ServiceNow Security Operations?

AI-generated summary from verified user reviews

Pros
  • Users value the remarkable integration capabilities of ServiceNow Security Operations, facilitating seamless management of security incidents.
  • Users value the seamless integration with third-party tools in ServiceNow Security Operations, enhancing productivity and workflow efficiency.
  • Users praise the seamless integration capabilities of ServiceNow Security Operations, enhancing efficiency and productivity in incident management.
  • Users appreciate the ease of use of ServiceNow Security Operations, facilitating efficient management of security incidents.
  • Users appreciate the end-to-end management of incidents in ServiceNow Security Operations, enhancing efficiency and integration.
Cons
  • Users find the difficult setup of ServiceNow Security Operations to be a significant barrier to effective implementation.
  • Users face integration issues with ServiceNow Security Operations, citing difficulties in setup and limited direct integrations.
  • Users feel the licensing issues with ServiceNow Security Operations limit playbook options, impacting remediation and increasing costs.
  • Users struggle with the complexity of building playbooks in ServiceNow Security Operations, highlighting a need for simplification.
  • Users face difficult customization when building playbooks in ServiceNow Security Operations, hindering their effectiveness and efficiency.

What Are Recent G2 Reviews of ServiceNow Security Operations?

What Are G2 Users Discussing About ServiceNow Security Operations?

Microsoft Sentinel

Microsoft Sentinel lets you see and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can: - Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds - Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft - Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft -Respond to incidents rapidly with built-in orchestration and automation of common tasks

Average Rating: 4.4/5.0

Total Reviews: 275

How Do G2 Users Rate Microsoft Sentinel?

  • Quality of Support: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Microsoft Sentinel?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Who Uses This: Security Analyst, Senior Software Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 42% Large, 31% Medium

What Do G2 Reviewers Say About Microsoft Sentinel?

AI-generated summary from verified user reviews

Pros
  • Users value the advanced threat detection of Microsoft Sentinel, enhancing security and proactive threat management.
  • Users value the easy integrations of Microsoft Sentinel, facilitating quick setup and streamlined security processes.
  • Users value the seamless integration of Microsoft Sentinel with various third-party and Microsoft products, enhancing functionality and management.
  • Users commend the ease of use of Microsoft Sentinel, facilitating quick integration and a user-friendly experience.
Cons
  • Users express concern over the high costs of Microsoft Sentinel, especially as data ingestion increases.
  • Users face integration issues with Microsoft Sentinel, especially when connecting to legacy systems and third-party tools.
  • Users find the complexity of Microsoft Sentinel challenging, requiring extensive training and effort for effective use.

What Are Recent G2 Reviews of Microsoft Sentinel?

What Are G2 Users Discussing About Microsoft Sentinel?

KnowBe4 PhishER/PhishER Plus

KnowBe4 PhishER Plus delivers automated incident response to eliminate SOC noise and remediate malicious emails across your organization simultaneously. It leverages AI to categorize reported messages across email and Microsoft Teams, automatically responding to reporters, flagging high-risk messages, and removing threats across all mailboxes. SOC teams can even flip malicious messages into training simulations to see who would have fallen victim. Customers report saving upwards of 99% of triage time, highly praising the platform's intuitive, user-friendly interface that transforms overwhelming manual workflows into fast, consistent actions. This layer of defense reviews threats slipping past other security layers, offering a single pane of glass view with leading third-party integrations like CrowdStrike, Webroot, and VirusTotal. PhishER Plus turns manual email triaging into a proactive, automated security posture.

Average Rating: 4.5/5.0

Total Reviews: 571

How Do G2 Users Rate KnowBe4 PhishER/PhishER Plus?

  • Threat Intelligence: 8.5/10 (Category avg: 8.9/10)
  • Quality of Support: 9.2/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.9/10 (Category avg: 8.5/10)
  • Incident Logs: 8.4/10 (Category avg: 8.8/10)

Who Is the Company Behind KnowBe4 PhishER/PhishER Plus?

  • Seller: KnowBe4, Inc.
  • Company Website:
  • Year Founded: 2010
  • HQ Location: Clearwater, FL
  • Twitter: @KnowBe4
    16,161 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,642 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: IT Manager, Director of IT
  • Top Industries: Financial Services, Primary/Secondary Education
  • Company Size: 75% Medium, 13% Large

What Do G2 Reviewers Say About KnowBe4 PhishER/PhishER Plus?

AI-generated summary from verified user reviews

Pros
  • Users value the effective phishing tests and automation features of KnowBe4 PhishER, enhancing their security posture.
  • Users appreciate the email threat scoring feature of KnowBe4 PhishER, enabling proactive responses to potential threats.
  • Users value the automation capabilities of KnowBe4 PhishER, enhancing efficiency in identifying and managing phishing threats.
  • Users find KnowBe4 PhishER/PhishER Plus remarkably easy to use, enhancing efficiency in triaging and reporting spam emails.
  • Users appreciate the streamlined threat detection of KnowBe4 PhishER, making phishing email management effortless and efficient.
Cons
  • Users report issues with clean emails landing in the Junk Email folder, leading to troubleshooting difficulties and uncertainty.
  • Users experience frequent false positives, complicating automation and necessitating time-consuming manual reviews for accuracy.
  • Users experience ineffective email security with PhishER, as it fails to correctly filter phishing emails into the inbox.
  • Users find the learning curve intimidating for setup, requiring additional assistance for effective use of PhishER/PhishER Plus.
  • Users find the inefficient automation of PhishER frustrating, as it often misses campaigns and requires manual intervention.

What Are Recent G2 Reviews of KnowBe4 PhishER/PhishER Plus?

What Are G2 Users Discussing About KnowBe4 PhishER/PhishER Plus?

IBM QRadar SIEM

Outsmart threats with an end-to-end award-winning security suite; proven to prevent, endure and recover from both known & unknown IT hazards faced by SoCs in the modern-day.

Average Rating: 4.4/5.0

Total Reviews: 284

How Do G2 Users Rate IBM QRadar SIEM?

  • Threat Intelligence: 8.4/10 (Category avg: 8.9/10)
  • Quality of Support: 8.3/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind IBM QRadar SIEM?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Who Uses This: Security Engineer, SOC Analyst
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 53% Large, 29% Medium

What Do G2 Reviewers Say About IBM QRadar SIEM?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of IBM QRadar SIEM, facilitating effective threat management and investigation.
  • Users appreciate the flexible integration capabilities of IBM QRadar SIEM, enhancing log management across diverse sources.
  • Users value the advanced threat detection and centralized log management features of IBM QRadar SIEM for enhanced security.
  • Users appreciate the easy integrations of IBM QRadar SIEM, enhancing its functionality with various platforms seamlessly.
  • Users appreciate the user-friendly interface of IBM QRadar SIEM, making it accessible for both tech and non-tech users.
Cons
  • Users find the UX improvements lacking, struggling with limited features and an unfriendly interface in QRadar SIEM.
  • Users find IBM QRadar SIEM expensive, particularly small and mid-sized companies struggling with the overall cost.
  • Users find the high cost of IBM QRadar SIEM challenging, particularly for smaller organizations needing comprehensive support.
  • Users face dashboard issues with IBM QRadar SIEM, lacking customization, usability, and integration for optimal performance.
  • Users find the time-consuming nature of QRadar SIEM frustrating, especially with complicated queries and log fetching delays.

What Are Recent G2 Reviews of IBM QRadar SIEM?

Sumo Logic

Sumo Logic, Inc. unifies and analyzes enterprise data, translating it into actionable insights through one AI-powered cloud-native log analytics platform. This single source of truth enables Dev, Sec and Ops teams to simplify complexity, collaborate efficiently and accelerate data-driven decisions that drive business value. Customers around the world rely on the Sumo Logic SaaS Log Analytics Platform for trusted insights to ensure application reliability, secure and protect against modern security threats, and gain insights into their cloud infrastructures. For more information, visit: SUMOLOGIC.COM

Average Rating: 4.3/5.0

Total Reviews: 405

How Do G2 Users Rate Sumo Logic?

  • Threat Intelligence: 7.7/10 (Category avg: 8.9/10)
  • Quality of Support: 8.5/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.1/10 (Category avg: 8.5/10)
  • Incident Logs: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Sumo Logic?

  • Seller: Sumo Logic
  • Company Website:
  • Year Founded: 2010
  • HQ Location: Redwood City, CA
  • Twitter: @SumoLogic
    6,542 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    824 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 48% Medium, 38% Large

What Do G2 Reviewers Say About Sumo Logic?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use in Sumo Logic, citing its simple query language and intuitive configurations.
  • Users value the ease of searching and configuring logs with Sumo Logic, enhancing their monitoring and tracing efficiency.
  • Users appreciate the Comprehensive Continuous Intelligence feature of Sumo Logic for transforming data into actionable insights quickly.
  • Users value the powerful visual insights and efficient log management capabilities of Sumo Logic for fast resolution.
  • Users value the real-time monitoring capabilities of Sumo Logic, enjoying swift insights and effective data management.
Cons
  • Users find Sumo Logic expensive, prompting concerns about whether its value justifies the high pricing.
  • Users find the difficult learning curve of Sumo Logic challenging, requiring significant time to become proficient.
  • Users face a steep learning curve with Sumo Logic, requiring significant time to master its features and query language.
  • Users face a steep learning curve with Sumo Logic, requiring significant time to master complex features and queries.
  • Users experience slow performance with Sumo Logic, facing delays in alerting and a cumbersome user interface.

What Are Recent G2 Reviews of Sumo Logic?

What Are G2 Users Discussing About Sumo Logic?

Splunk Enterprise Security

Splunk Enterprise Security (ES) is a data-centric, modern security information and event management (SIEM) solution that delivers data-driven insights for full breadth visibility into your security posture so you can protect your business and mitigate risk at scale. With unparalleled search and reporting, advanced analytics, integrated intelligence, and prepackaged security content, Splunk ES accelerates threat detection and investigation, letting you determine the scope of high-priority threats to your environment so you can quickly take action. Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Our extensive ecosystem of Splunk, partner, and community-built integrations as well as flexible deployment options ensure your technology investments are working in tandem with Splunk ES whilst meeting you wherever you are on your cloud, multi-cloud, or hybrid journey.

Average Rating: 4.3/5.0

Total Reviews: 224

How Do G2 Users Rate Splunk Enterprise Security?

  • Threat Intelligence: 9.0/10 (Category avg: 8.9/10)
  • Quality of Support: 8.6/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.5/10 (Category avg: 8.5/10)
  • Incident Logs: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Splunk Enterprise Security?

  • Seller: Cisco
  • Year Founded: 1984
  • HQ Location: San Jose, CA
  • Twitter: @Cisco
    720,366 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    95,294 employees on LinkedIn®
  • Ownership: NASDAQ:CSCO

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 59% Large, 30% Medium

What Do G2 Reviewers Say About Splunk Enterprise Security?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Splunk Enterprise Security, enhancing their monitoring and log management experience.
  • Users appreciate the easy integrations of Splunk Enterprise Security, enabling seamless connection with various platforms and systems.
  • Users highlight the impressive threat detection capabilities of Splunk Enterprise Security, enhancing security focus and reducing false alarms.
  • Users value the effective features of Splunk Enterprise Security, enhancing security analysis with comprehensive logs and insights.
  • Users appreciate the user-friendly interface of Splunk Enterprise Security, enabling efficient monitoring and attractive dashboards.
Cons
  • Users find the high costs associated with data ingestion to be a significant drawback of Splunk Enterprise Security.
  • Users find the initial implementation complex, needing expert resources and time to onboard Splunk Enterprise Security effectively.
  • Users find the complex implementation of Splunk Enterprise Security challenging, requiring extensive expertise and resources.
  • Users find the complex setup of Splunk Enterprise Security time-consuming and challenging, impacting initial deployment effectiveness.
  • Users find the difficult learning curve of Splunk Enterprise Security challenging, especially for those new to data analysis.

What Are Recent G2 Reviews of Splunk Enterprise Security?

What Are G2 Users Discussing About Splunk Enterprise Security?

Palo Alto Cortex XSIAM

Product Description: Palo Alto Networks' Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.

Average Rating: 4.5/5.0

Total Reviews: 96

How Do G2 Users Rate Palo Alto Cortex XSIAM?

  • Threat Intelligence: 8.9/10 (Category avg: 8.9/10)
  • Quality of Support: 8.5/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.5/10 (Category avg: 8.5/10)
  • Incident Logs: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Palo Alto Cortex XSIAM?

  • Seller: Palo Alto Networks
  • Company Website:
  • Year Founded: 2005
  • HQ Location: Santa Clara, CA
  • Twitter: @PaloAltoNtwks
    128,951 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,492 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 40% Large, 36% Medium

What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

AI-generated summary from verified user reviews

Pros
  • Users value the best-in-class log management of Palo Alto Cortex XSIAM, benefiting from its effective alerting and integration features.
  • Users find the user-friendly dashboard of Palo Alto Cortex XSIAM essential for monitoring and understanding alerts effectively.
  • Users value the real-time monitoring capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency.
  • Users value the simple and user-friendly interface of Palo Alto Cortex XSIAM, making monitoring effortless.
  • Users value the good dashboard creation tools in Palo Alto Cortex XSIAM, enhancing ease of use and implementation.
Cons
  • Users note that Palo Alto Cortex XSIAM requires significant resources, impacting implementation time and increasing infrastructure costs.
  • Users find the complexity of implementation for Palo Alto Cortex XSIAM to be time-consuming and resource-intensive.
  • Users find the cost of Palo Alto Cortex XSIAM to be high, especially for smaller businesses.
  • Users face dashboard issues with XSIAM, finding it difficult to monitor assets and navigate the interface.
  • Users face difficult setup issues with Palo Alto Cortex XSIAM, requiring expertise and extensive time for initial implementation.

What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

Tanium

Trusted by 40% of the Fortune 100, 8 of the top 10 U.S. Banks, and all 6 branches of the U.S. Armed Forces. Tanium is the platform the world's most security-conscious organizations trust. The Tanium Autonomous IT Platform unifies endpoint management and security on a single, unified platform. Driven by real-time intelligence and generative, agentic, and predictive AI, Tanium ensures every insight and automation is based on accurate, trustworthy data so IT operations and security teams can act faster, stay resilient, and drive better business outcomes with confidence. Built on Tanium’s patented Linear Chain Architecture, teams can deploy trusted automation progressively, then execute actions safely at speed and scale - without scans or manual workflows. Continuous visibility across IT, mobile, OT, and cloud environments helps organizations accelerate decision agility, save costs through integrated automation, and strengthen resilience with closed-loop security.

Average Rating: 4.5/5.0

Total Reviews: 84

How Do G2 Users Rate Tanium?

  • Threat Intelligence: 8.8/10 (Category avg: 8.9/10)
  • Quality of Support: 8.8/10 (Category avg: 8.8/10)
  • Incident Case Management: 9.2/10 (Category avg: 8.5/10)
  • Incident Logs: 7.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Tanium?

  • Seller: Tanium
  • Company Website:
  • Year Founded: 2007
  • HQ Location: Emeryville, CA
  • Twitter: @Tanium
    7,243 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,318 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Hospital & Health Care
  • Company Size: 48% Large, 32% Medium

What Do G2 Reviewers Say About Tanium?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Tanium, enabling efficient device management and real-time endpoint visibility.
  • Users value the real-time visibility and comprehensive endpoint management features of Tanium for enhanced security and efficiency.
  • Users commend the reliability of Tanium for effective endpoint management and real-time visibility across assets.
  • Users value the strong security capabilities of Tanium, enhancing their endpoint security management significantly.
  • Users commend the real-time visibility provided by Tanium, enhancing their ability to manage endpoints effectively.
Cons
  • Users find the learning curve steep with Tanium, requiring significant time to become proficient in its features.
  • Users find Tanium's complexity challenging, especially those new to cybersecurity aiming for hands-on experience.
  • Users report limited features in Tanium, including outdated vulnerability databases and troublesome troubleshooting processes.
  • Users experience insufficient information during onboarding, making the initial use of Tanium challenging and time-consuming.
  • Users note that Tanium has a steep learning curve and lacks clear onboarding resources, making initial use overwhelming.

What Are Recent G2 Reviews of Tanium?

Rapid7 Next-Gen SIEM

Rapid7 InsightIDR is a SaaS SIEM for modern threat detection and response. InsightIDR enables security analysts to work more efficiently and effectively, by unifying diverse data sources, providing early and reliable out of the box detections, and delivering rich visual investigations and automation to expedite response. With a lightweight cloud deployment and intuitive UI and onboarding experience, InsightIDR customers recognize an accelerated return on their investment and start seeing valuable insights from Day 1. With InsightIDR, teams can advance their threat detection and response program without adding headcount.

Average Rating: 4.4/5.0

Total Reviews: 68

How Do G2 Users Rate Rapid7 Next-Gen SIEM?

  • Threat Intelligence: 9.2/10 (Category avg: 8.9/10)
  • Quality of Support: 8.9/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.7/10 (Category avg: 8.5/10)
  • Incident Logs: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Rapid7 Next-Gen SIEM?

  • Seller: Rapid7
  • Year Founded: 2000
  • HQ Location: Boston, MA
  • Twitter: @rapid7
    124,405 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    8,746 employees on LinkedIn®
  • Ownership: NASDAQ:RPD

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 67% Medium, 31% Large

What Do G2 Reviewers Say About Rapid7 Next-Gen SIEM?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Rapid7 Next-Gen SIEM unparalleled, with simple implementation and clear alerts.
  • Users appreciate the easy integrations of Rapid7 Next-Gen SIEM, benefiting from pre-built connections with numerous third-party tools.
  • Users appreciate the pre-built integrations of Rapid7 Next-Gen SIEM, making it easy to connect with various third-party tools.
  • Users appreciate the seamless integration of UEBA and deception tools for efficient threat detection across the network.
  • Users value the excellent visibility provided by Rapid7 Next-Gen SIEM, enabling easy log searches and clear alerts.
Cons
  • Users find the limited features of Rapid7 Next-Gen SIEM restrict overall functionality and alert setup capabilities.
  • Users find the alerting issues cumbersome, particularly when trying to create and set up pattern-based alerts.
  • Users find the limited alert management capabilities frustrating, complicating the creation of effective and timely alerts.
  • Users find the difficult customization in Rapid7 Next-Gen SIEM limits their ability to create effective alerts.
  • Users find the difficult setup of Rapid7 Next-Gen SIEM hinders effective alert creation and pattern configurations.

What Are Recent G2 Reviews of Rapid7 Next-Gen SIEM?

What Are G2 Users Discussing About Rapid7 Next-Gen SIEM?

Cynet

Cynet is the unified, AI-powered cybersecurity platform that delivers robust and comprehensive protection for security teams while maximizing operational efficiency for managed service providers (MSPs). This platform consolidates a wide array of security capabilities into a single, user-friendly interface, ensuring that organizations can effectively safeguard their digital assets without the complexity often associated with multi-solution environments. Cynet’s platform simplifies security management by integrating various functionalities, such as endpoint protection, threat detection, and incident response, into one cohesive system. This integration not only streamlines operations but also allows organizations to allocate their resources more effectively, ultimately enhancing their overall security posture. One of the standout features of Cynet’s platform is its remarkable performance in the MITRE ATT&CK Evaluations. Cynet delivered 100% visibility and 100% analytic coverage without requiring any configuration changes three years in a row. This capability ensures that organizations can monitor their environments comprehensively and respond to threats with precision. The platform’s built-in analytics and reporting tools provide actionable insights, enabling users to make informed decisions about their cybersecurity strategies. Additionally, Cynet offers 24/7 expert support, which is crucial for organizations that may not have in-house cybersecurity expertise. This round-the-clock assistance ensures that users can quickly address any security incidents or concerns, minimizing potential downtime and damage. The combination of advanced technology and dedicated support positions Cynet as a valuable partner for SMEs and service providers looking to enhance their cybersecurity measures. In summary, Cynet’s unified, AI-powered cybersecurity platform stands out in the crowded cybersecurity market by offering a unified solution tailored to the needs of MSPs. Its comprehensive features, exceptional performance in industry evaluations, and continuous expert support make it a compelling choice for organizations seeking to bolster their cybersecurity defenses while maintaining operational efficiency.

Average Rating: 4.7/5.0

Total Reviews: 218

How Do G2 Users Rate Cynet?

  • Threat Intelligence: 9.2/10 (Category avg: 8.9/10)
  • Quality of Support: 9.3/10 (Category avg: 8.8/10)
  • Incident Case Management: 9.0/10 (Category avg: 8.5/10)
  • Incident Logs: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Cynet?

  • Seller: Cynet
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Boston, MA
  • LinkedIn® Page: www.linkedin.com
    335 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: SOC Analyst, Technical Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 58% Medium, 30% Small

What Do G2 Reviewers Say About Cynet?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Cynet, appreciating its straightforward yet comprehensive functionalities for effective protection.
  • Users value the unified platform of Cynet, which offers effective security through streamlined endpoint protection and detection.
  • Users praise Cynet for its effective threat detection and seamless monitoring, enhancing overall cybersecurity effortlessly.
  • Users commend Cynet for its exceptional customer support, ensuring a smooth and efficient deployment experience.
  • Users praise Cynet for its flawless threat monitoring and detection, enhancing overall cybersecurity effectiveness effortlessly.
Cons
  • Users find limited customization options in reporting and dashboards, affecting their ability to present necessary data.
  • Users note a lack of customization in reports, wishing for more options to tailor data presentation.
  • Users find the reporting features lacking, with requests for better customization and visualization tools.
  • Users find feature limitations in Cynet, with a desire for more customization options and broader integrations.
  • Users note limited features, such as basic reporting and few third-party integrations, impacting customization and deeper controls.

What Are Recent G2 Reviews of Cynet?

What Are G2 Users Discussing About Cynet?

Proofpoint Threat Response Auto-Pull

Proofpoint Threat Response Auto-Pull (TRAP) enables messaging and security administrators the ability to automatically retract threats delivered to employee inboxes and emails that turn malicious after delivery to quarantine. It is also a powerful solution to retract messages sent in error as well as inappropriate, malicious, or emails containing compliance violations and also follows forwarded mail and distribution lists and creates an auditable activity trail. With Proofpoint Threat Response Auto-Pull, you can protect your people, data, and brand from today’s threats by: • Automatically pulling malicious or unwanted messages from an end-users inbox. • Enriching each message by checking every domain and IP address against premium intelligence feeds. • Including built-in reporting, showing stats like: Email quarantine success or failures, email retraction read status, targeting by active directory attribute • Reducing the remediation time needed from hours to minutes.

Average Rating: 4.5/5.0

Total Reviews: 24

How Do G2 Users Rate Proofpoint Threat Response Auto-Pull?

  • Threat Intelligence: 8.3/10 (Category avg: 8.9/10)
  • Quality of Support: 8.9/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.4/10 (Category avg: 8.5/10)
  • Incident Logs: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind Proofpoint Threat Response Auto-Pull?

  • Seller: Proofpoint
  • Year Founded: 2002
  • HQ Location: Sunnyvale, CA
  • Twitter: @proofpoint
    31,157 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,261 employees on LinkedIn®
  • Ownership: NASDAQ: PFPT

Who Uses This Product?

  • Company Size: 63% Large, 33% Medium

What Are Recent G2 Reviews of Proofpoint Threat Response Auto-Pull?

What Are G2 Users Discussing About Proofpoint Threat Response Auto-Pull?

IBM QRadar SOAR

IBM QRadar® SOAR is designed to help your security team respond to cyberthreats with confidence, automate with intelligence and collaborate with consistency. It guides your team in resolving incidents by codifying established incident response processes into dynamic playbooks. The open and agnostic platform helps accelerate and orchestrate their response by automating actions with intelligence and integrating with other security tools. IBM QRadar SOAR is available on AWS Marketplace.

Average Rating: 4.0/5.0

Total Reviews: 25

How Do G2 Users Rate IBM QRadar SOAR?

  • Threat Intelligence: 7.2/10 (Category avg: 8.9/10)
  • Quality of Support: 7.9/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.7/10 (Category avg: 8.5/10)
  • Incident Logs: 7.5/10 (Category avg: 8.8/10)

Who Is the Company Behind IBM QRadar SOAR?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 72% Large, 21% Medium

What Do G2 Reviewers Say About IBM QRadar SOAR?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of IBM QRadar SOAR, appreciating its intuitive interface and seamless integration options.
  • Users value the automation capabilities of IBM QRadar SOAR, which significantly streamline security operations and reduce manual work.
  • Users value the seamless integrations with various tools, enhancing efficiency in security operations and workflows.
  • Users value the seamless integration capabilities of IBM QRadar SOAR, enhancing their security and workflow efficiency.
  • Users value the quick and effective customer support from IBM, enhancing their experience with QRadar SOAR.
Cons
  • Users face integration issues with IBM QRadar SOAR, experiencing difficulties in connecting applications and managing sophisticated transformations.
  • Users find the initial complexity of IBM QRadar SOAR challenging, making it hard to adapt to its features.
  • Users find the limited integration of IBM QRadar SOAR restrictive, hindering sophisticated implementations and transformations.
  • Users find that IBM QRadar SOAR has significant system limitations that hinder complex transformations and integration tasks.
  • Users often face bug issues with workflows, experiencing errors and occasional lagging that disrupts their productivity.

What Are Recent G2 Reviews of IBM QRadar SOAR?

Torq AI SOC Platform

Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Working alongside your SecOps staff, the Torq platform integrates with your security stack to facilitate containment and remediation workflows.

Average Rating: 4.8/5.0

Total Reviews: 151

How Do G2 Users Rate Torq AI SOC Platform?

  • Threat Intelligence: 8.9/10 (Category avg: 8.9/10)
  • Quality of Support: 9.6/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.9/10 (Category avg: 8.5/10)
  • Incident Logs: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Torq AI SOC Platform?

  • Seller: torq
  • Company Website:
  • Year Founded: 2020
  • HQ Location: New York, US
  • Twitter: @torq_io
    1,944 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    470 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 49% Medium, 30% Small

What Do G2 Reviewers Say About Torq AI SOC Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the ease of use of Torq AI SOC Platform, making it accessible for all skill levels.
  • Users value the efficiency of automated security workflows in Torq, enhancing both speed and effectiveness in threat management.
  • Users value the automation capabilities of Torq AI SOC Platform, enhancing efficiency and streamlining security workflows effectively.
  • Users appreciate the no-code automation capabilities of Torq, streamlining workflows and enhancing overall operational efficiency.
  • Users value the real-time threat detection of Torq AI SOC Platform, enhancing efficiency in responding to security incidents.
Cons
  • Users face a difficult learning curve with Torq AI SOC Platform, requiring significant training and support for effective use.
  • Users face a significant learning curve with Torq AI SOC Platform, requiring time and proper training for effective use.
  • Users note the missing features in Torq AI SOC Platform, especially regarding playbooks and incident management capabilities.
  • Users note that improvement is needed in grouping findings, vendor integration, and overall flexibility for better experience.
  • Users face poor interface design in Torq, including unresponsive buttons and a challenging debugging process.

What Are Recent G2 Reviews of Torq AI SOC Platform?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated