# Best Incident Response Software for Medium-Sized Businesses - Page 2

## How Many Incident Response Software Products Does G2 Track?

**Total Products under this Category:** 103

### Category Stats (Aug 2026)

- **Average Rating:** 4.48/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Palo Alto Cortex XSIAM (+0.81%) - Among all products in this category, Palo Alto Cortex XSIAM recorded the largest rating increase compared to last month

_Last updated: August 07, 2026_

## How Does G2 Rank Incident Response Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 5,300+ Authentic Reviews
- 103+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Incident Response Software
 ![G2 Grid® for Incident Response Software plotting products by satisfaction and market presence](https://www.g2.com/categories/incident-response/grids.png?focus%5B%5D=68606&focus%5B%5D=139264&focus%5B%5D=164907&focus%5B%5D=70840&focus%5B%5D=16881&focus%5B%5D=98376&focus%5B%5D=1430041&focus%5B%5D=122123)

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, KnowBe4 PhishER/PhishER Plus, Torq AI SOC Platform, Cynet, SentinelOne Singularity Endpoint, Tines, Palo Alto Cortex XSIAM, and Microsoft Sentinel.

Underlying data: [Grid® JSON](https://www.g2.com/categories/incident-response/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=cynet&focus%5B%5D=sentinelone-singularity-endpoint&focus%5B%5D=tines&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=microsoft-sentinel&segment=mid-market)

**Sponsored**

### Tanium

Trusted by 40% of the Fortune 100, 8 of the top 10 U.S. Banks, and all 6 branches of the U.S. Armed Forces. Tanium is the platform the world's most security-conscious organizations trust. The Tanium Autonomous IT Platform unifies endpoint management and security on a single, unified platform. Driven by real-time intelligence and generative, agentic, and predictive AI, Tanium ensures every insight and automation is based on accurate, trustworthy data so IT operations and security teams can act faster, stay resilient, and drive better business outcomes with confidence. Built on Tanium’s patented Linear Chain Architecture, teams can deploy trusted automation progressively, then execute actions safely at speed and scale - without scans or manual workflows. Continuous visibility across IT, mobile, OT, and cloud environments helps organizations accelerate decision agility, save costs through integrated automation, and strengthen resilience with closed-loop security.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1082&secure%5Bchosen_at%5D=2026-08-10T10%3A10%3A44Z&secure%5Bdisplayable_resource_id%5D=1082&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1082&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=14979&secure%5Bresource_id%5D=1082&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fincident-response%2Fmid-market%3Fpage%3D2%26segment%3Dmid-market&secure%5Btoken%5D=fb72158b99ff32583c9e0da7c480ae465140e7a35319fa3c99c2a615573b408d&secure%5Burl%5D=https%3A%2F%2Fwww.tanium.com%2Fsee-a-demo%2F%3Futm_source%3Dg2%26utm_source_platform%3Dg2_ads%26utm_asset%3Ddemorequest%26utm_medium%3Dreviewsite%26utm_campaign%3Drwsite-g2-lead-bofu-all-GBL-autoit-spnsr-demoreq-EN%26utm_content%3Dprospect%26utm_id%3D701PI00002WvdsUYAR%26utm_marketing_tactic%3Ddemo_request%26utm_creative_format%3Dppc&secure%5Burl_type%5D=book_demo)

### [ServiceNow Security Operations](https://www.g2.com/products/servicenow-security-operations/reviews)

ServiceNow Security Operations is a sophisticated software solution designed to enhance threat and vulnerability management as well as incident response for organizations. By leveraging artificial intelligence, this platform empowers security teams to operate more efficiently and effectively, allowing for streamlined collaboration across IT, security, and risk management departments. The primary goal of ServiceNow Security Operations is to simplify complex security processes while minimizing risks associated with cybersecurity threats. Targeted at security teams within organizations of various sizes, ServiceNow Security Operations addresses the need for a cohesive approach to managing security incidents and vulnerabilities. It is particularly beneficial for organizations that utilize multiple security tools, as it integrates security and vulnerability data from these existing systems. This integration enables teams to respond to threats more rapidly by automating critical workflows and processes, thus reducing the manual effort traditionally required in incident response. The platform is suitable for both small businesses and large enterprises, making it a versatile choice for organizations looking to enhance their cybersecurity measures. Key features of ServiceNow Security Operations include intelligent workflows that automate routine tasks, allowing security professionals to focus on more strategic initiatives. The platform’s AI-driven capabilities facilitate the automatic correlation of threat intelligence from diverse sources, such as the MITRE ATT&CK framework. This feature enhances situational awareness and enables teams to prioritize threats effectively based on real-time data. Additionally, the ability to take action within other security or IT management tools from a centralized console streamlines operations, ensuring that teams can respond to incidents without unnecessary delays. This centralized approach not only improves efficiency but also fosters better communication among different departments involved in security management. Moreover, the use of digital security workflows and orchestration significantly accelerates tasks such as analysis, prioritization, and remediation. By automating these processes, organizations can improve their response times and enhance their overall cybersecurity posture. The integration of AI-driven automation within the ServiceNow AI Platform® further strengthens the platform's capabilities, enabling organizations to drive cyber resilience and reduce their exposure to potential threats. This proactive approach to cybersecurity ensures that organizations are not only reacting to incidents but are also prepared to prevent them. ServiceNow Security Operations stands out in the cybersecurity landscape by offering a comprehensive solution that addresses the complexities of modern cybersecurity challenges. By automating and simplifying threat and vulnerability management, it empowers security teams to respond more effectively, thereby enhancing the overall security framework of an organization. This makes it an essential tool for any organization looking to bolster its defenses against the ever-evolving landscape of cyber threats.

**Average Rating:** 4.3/5.0

**Total Reviews:** 82

#### How Do G2 Users Rate ServiceNow Security Operations?

- **Threat Intelligence:** 8.9/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.5/10 (Category avg: 8.8/10)
- **Incident Case Management:** 9.1/10 (Category avg: 8.5/10)
- **Incident Logs:** 9.2/10 (Category avg: 8.8/10)

#### Who Is the Company Behind ServiceNow Security Operations?

- **Seller:** [ServiceNow](https://www.g2.com/sellers/servicenow)
- **Company Website:** www.servicenow.com
- **Year Founded:** 2004
- **HQ Location:** Santa Clara, CA
- **Twitter:** @servicenow  
55,548 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8f146dd2da6255ae21db2f89043b268912043fe250660dfee40ba3c0574bb1ba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F29352%2F&secure%5Burl_type%5D=linkedin_company_website)  
35,081 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 53% Large, 21% Medium

#### What Do G2 Reviewers Say About ServiceNow Security Operations?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **integration capabilities** of ServiceNow Security Operations, enabling seamless connections with essential third-party tools.
- Users value the **remarkable integration capabilities** of ServiceNow Security Operations, enhancing incident management and data processing efficiency.
- Users appreciate the **ease of use** of ServiceNow Security Operations, enhancing productivity with seamless integration and setup.
- Users value the **robust integration capabilities** of ServiceNow Security Operations, enhancing workflow and incident management efficiency.
- Users appreciate the **end-to-end incident management** capabilities in ServiceNow, making it a comprehensive security solution.

##### Cons

- Users find the **difficult setup** of ServiceNow Security Operations a barrier, impacting overall usability and cost-effectiveness.
- Users face **integration issues** , struggling with field mapping, initial setup, and documentation, affecting overall usability.
- Users find the **restrictive licensing issues** limiting for playbooks, impacting remediation efficiency and security operations.
- Users face **complexity in building playbooks** within ServiceNow Security Operations, finding the process challenging and costly.
- Users find **difficult customization** in ServiceNow Security Operations hinders their ability to effectively build playbooks.

#### What Are Recent G2 Reviews of ServiceNow Security Operations?

**["Centralized Incident Management with Intuitive Dashboard"](https://www.g2.com/survey_responses/servicenow-security-operations-review-13161740)**

**Rating:** 4.0/5.0 stars

_— vignesh m._

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-13161740)

**["All Security Tools in One Place with Fast, Automated Playbooks"](https://www.g2.com/survey_responses/servicenow-security-operations-review-13168876)**

**Rating:** 4.0/5.0 stars

_— Adam R._

[Read full review](https://www.g2.com/survey_responses/servicenow-security-operations-review-13168876)

#### What Are G2 Users Discussing About ServiceNow Security Operations?

- [What is ServiceNow sir?](https://www.g2.com/discussions/what-is-servicenow-sir)
- [What is service now in cyber security?](https://www.g2.com/discussions/what-is-service-now-in-cyber-security)
- [What are the typical functions of the Security Operations Center SOC analysts?](https://www.g2.com/discussions/what-are-the-typical-functions-of-the-security-operations-center-soc-analysts)
- [What can ServiceNow security operations do?](https://www.g2.com/discussions/what-can-servicenow-security-operations-do)

### [LogRhythm SIEM](https://www.g2.com/products/exabeam-logrhythm-siem/reviews)

Rapidly deploy LogRhythm SIEM, the leading self-hosted SIEM, to secure your organization with powerful detections, synchronized threat intelligence, automated workflows, and achieve faster, more accurate threat detection, investigation, and response (TDIR).

**Average Rating:** 4.2/5.0

**Total Reviews:** 137

#### How Do G2 Users Rate LogRhythm SIEM?

- **Threat Intelligence:** 8.7/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.5/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.7/10 (Category avg: 8.5/10)
- **Incident Logs:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind LogRhythm SIEM?

- **Seller:** [Exabeam](https://www.g2.com/sellers/exabeam)
- **Year Founded:** 2013
- **HQ Location:** Broomfield, CO
- **Twitter:** @exabeam  
5,374 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8269dcd878e7968524f3962a9164ef59bc027b3288cea78560785eb6feaa457e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fexabeam&secure%5Burl_type%5D=linkedin_company_website)  
793 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Information Security Analyst, Cyber Security Analyst
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 40% Large, 40% Medium

#### What Are Recent G2 Reviews of LogRhythm SIEM?

**["More than a SIEM"](https://www.g2.com/survey_responses/logrhythm-siem-review-10516628)**

**Rating:** 5.0/5.0 stars

_— Verified User in Banking_

[Read full review](https://www.g2.com/survey_responses/logrhythm-siem-review-10516628)

**["LogRhythm SIEM - Best Solution In Market"](https://www.g2.com/survey_responses/logrhythm-siem-review-11463953)**

**Rating:** 5.0/5.0 stars

_— Vishwa K._

[Read full review](https://www.g2.com/survey_responses/logrhythm-siem-review-11463953)

#### What Are G2 Users Discussing About LogRhythm SIEM?

- [What are some SIEM tools?](https://www.g2.com/discussions/what-are-some-siem-tools)
- [What does a SIEM platform do?](https://www.g2.com/discussions/what-does-a-siem-platform-do)
- [How does Siem LogRhythm work?](https://www.g2.com/discussions/how-does-siem-logrhythm-work)
- [What is LogRhythm software?](https://www.g2.com/discussions/what-is-logrhythm-software)

### [CYREBRO](https://www.g2.com/products/cyrebro/reviews)

CYREBRO is an AI-native Managed Detection and Response solution, providing the core foundation and capabilities of a state-level Security Operations Center delivered through its cloud-based, interactive SOC Platform. CYREBRO rapidly detects, analyzes, investigates and responds to cyber threats, for businesses of all sizes.

**Average Rating:** 4.3/5.0

**Total Reviews:** 128

#### How Do G2 Users Rate CYREBRO?

- **Threat Intelligence:** 8.6/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.3/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.0/10 (Category avg: 8.5/10)
- **Incident Logs:** 8.6/10 (Category avg: 8.8/10)

#### Who Is the Company Behind CYREBRO?

- **Seller:** [CYREBRO](https://www.g2.com/sellers/cyrebro)
- **Year Founded:** 2013
- **HQ Location:** Tel Aviv, IL
- **Twitter:** @CYREBRO\_IO  
307 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=008c1d696cb988c9ef52973cb326dae9be42ff651c2a7ff3831106f8d1ac58d1&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcyrebro%2F&secure%5Burl_type%5D=linkedin_company_website)  
83 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 64% Medium, 25% Small

#### What Do G2 Reviewers Say About CYREBRO?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of CYREBRO, noting its intuitive dashboard and quick response to issues.
- Users value the **responsive and knowledgeable customer support** of CYREBRO, enhancing their overall experience and confidence.
- Users find the **dashboard usability** of CYREBRO exceptional, enabling efficient management of reports and rapid incident responses.
- Users value the **real-time alerts** from CYREBRO, enhancing incident response and providing peace of mind with 24/7 monitoring.
- Users value the **real-time alerts** from CYREBRO, enhancing incident management and ensuring quick responses to threats.

##### Cons

- Users report **update issues** with alert management and integration complexities, which can hinder the user experience.
- Users experience **communication issues** with Cyrebro's support, leading to delays and vague responses that hinder effectiveness.
- Users highlight **poor customer support** , citing slow response times and insufficient assistance during critical incidents.
- Users experience **ineffective alerts** , often receiving vague or repetitive notifications that require additional support for clarity.
- Users experience an **inefficient alert system** , noting overwhelming notifications and a need for better customization options.

#### What Are Recent G2 Reviews of CYREBRO?

**["My experience with Cyrebro has been average, it hasn't been bad but not excellent either."](https://www.g2.com/survey_responses/cyrebro-review-7695729)**

**Rating:** 4.0/5.0 stars

_— felipe f._

[Read full review](https://www.g2.com/survey_responses/cyrebro-review-7695729)

**["An honest opinion on Cyrebro"](https://www.g2.com/survey_responses/cyrebro-review-11259267)**

**Rating:** 4.0/5.0 stars

_— Jayme M._

[Read full review](https://www.g2.com/survey_responses/cyrebro-review-11259267)

#### What Are G2 Users Discussing About CYREBRO?

- [What is CYREBRO used for?](https://www.g2.com/discussions/what-is-cyrebro-used-for) - 1 comment, 1 upvote

### [UnderDefense MAXI](https://www.g2.com/products/underdefense-maxi/reviews)

UnderDefense is an Agentic AI SOC & Compliance Automation platform trusted by 200+ enterprises in the US and EU. It works on top of the security stack you already own — no rip-and-replace, no added headcount — so your team spends its time on decisions, not triage. ◆ 10+ years of operations with zero ransomware incidents ◆ 250+ integrations across any SIEM, EDR, or cloud stack ◆ 24/7 IR team available whenever you need urgent support WHAT WE OFFER AGENTIC AI SOC UnderDefense Agentic AI SOC works on top of your existing security stack, turning every security team into a machine-speed defense unit without tool replacement or headcount expansion. It takes over the investigative routine that pulls your team away from strategic decisions: enrichment, correlation, triage. ▸ Investigation at Machine Speed: Agentic AI SOC accesses tools, enriches data, and performs deep cross-environment investigations at machine speed. It correlates, triages, and forms conclusions, offloading all repetitive work from your team. ▸ 2 Minutes Per Alert: Complete SIEM queries, threat intel checks, and cross-system correlations in 2 minutes. Every step fully observable and auditable. ▸ Human at Every Decision Point: The platform verifies suspicious activity with end-users via Slack or Teams, then routes containment decisions to your team or our 24/7 IR experts. COMPLIANCE AUTOMATION Stop chasing spreadsheets. UnderDefense MAXI Compliance AI automatically collects continuous evidence across ISO 27001, SOC 2, PCI DSS, GDPR, and HIPAA, and publishes your live posture through a shareable Trust Center link. ▸ 40% audit-ready in the first 40 minutes ▸ 2X faster time-to-compliance vs. traditional audit ▸ 24/7 continuous monitoring — posture always current, not point-in-time WHY WE ARE BETTER ✓ No rip-and-replace: Works with your current SIEM (Splunk, Sentinel, Chronicle, QRadar, Elastic), EDR, and cloud tools. Logs stay in your data lake. ✓ True Multi-Environment Coverage: Comprehensive visibility across on-premises, cloud (AWS, GCP, Azure), SaaS, network, identity, and OT/SCADA environments. ✓ The Only Agentic AI SOC with on-prem deployment: Full AI SOC inside your own infrastructure. No telemetry leaving your environment. Air-gapped available. ✓ Right-Sized for Any Enterprise: Detection engineering and support tailored to your organization, not a one-size-fits-all template. Start your free trial at underdefense.com

**Average Rating:** 4.9/5.0

**Total Reviews:** 32

#### How Do G2 Users Rate UnderDefense MAXI?

- **Threat Intelligence:** 9.7/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.9/10 (Category avg: 8.8/10)
- **Incident Case Management:** 9.3/10 (Category avg: 8.5/10)
- **Incident Logs:** 10.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind UnderDefense MAXI?

- **Seller:** [UnderDefense](https://www.g2.com/sellers/underdefense)
- **Year Founded:** 2017
- **HQ Location:** New York, NY
- **Twitter:** @underdefense  
153 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=58843c2b215633c7e82dc703401c6be2409820b1cf096740d3975364b89f4cdc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Funderdefense-llc&secure%5Burl_type%5D=linkedin_company_website)  
133 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Marketing and Advertising
- **Company Size:** 63% Medium, 25% Small

#### What Do G2 Reviewers Say About UnderDefense MAXI?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise the **responsive and professional customer support** of UnderDefense, enhancing their cybersecurity experience significantly.
- Users commend UnderDefense MAXI for its **exceptional responsiveness and effective cybersecurity solutions** , enhancing overall security management seamlessly.
- Users value the **accurate information provided** by UnderDefense MAXI, which enhances their ability to address security vulnerabilities effectively.
- Users commend UnderDefense MAXI for its **efficient issue resolution** , noted for quick responsiveness and insightful recommendations.
- Users highlight the **exceptional reliability** of UnderDefense MAXI, praising their responsive support and effective security solutions.

##### Cons

- Users desire **greater automation** for updates and dashboard control to enhance their experience with UnderDefense MAXI.
- Users desire **greater control** over the dashboard and automated updates for a more tailored experience with UnderDefense MAXI.
- Users note the **limited integration** requires time and effort for proper setup, which may be a consideration for new clients.
- Users note that **setup difficulty** may require significant initial time investment to ensure proper tool integration.

#### What Are Recent G2 Reviews of UnderDefense MAXI?

**["Solved the risk of developer credential exposure across dozens of client environments"](https://www.g2.com/survey_responses/underdefense-maxi-review-13198173)**

**Rating:** 5.0/5.0 stars

_— Maksym G._

[Read full review](https://www.g2.com/survey_responses/underdefense-maxi-review-13198173)

**["Reliable 24/7 coverage without extra headcount"](https://www.g2.com/survey_responses/underdefense-maxi-review-13226162)**

**Rating:** 5.0/5.0 stars

_— Bohdan P._

[Read full review](https://www.g2.com/survey_responses/underdefense-maxi-review-13226162)

### [Wazuh](https://www.g2.com/products/wazuh/reviews)

Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh, with over 30 million downloads per year, has one of the largest open-source security communities in the world. Wazuh helps organizations of all sizes protect their data assets against security threats. Learn more about the project at wazuh.com

**Average Rating:** 4.5/5.0

**Total Reviews:** 68

#### How Do G2 Users Rate Wazuh?

- **Threat Intelligence:** 8.6/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.3/10 (Category avg: 8.8/10)
- **Incident Case Management:** 7.7/10 (Category avg: 8.5/10)
- **Incident Logs:** 9.1/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Wazuh?

- **Seller:** [Wazuh Inc.](https://www.g2.com/sellers/wazuh-inc)
- **Year Founded:** 2015
- **HQ Location:** Campbell, US
- **Twitter:** @wazuh  
8,026 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a11b29b57ea9b004506afb09df3cca0a100e3a29c72c50f204a7470caa7b5674&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fwazuh%2F&secure%5Burl_type%5D=linkedin_company_website)  
276 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** SOC Analyst
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 47% Small, 40% Medium

#### What Do G2 Reviewers Say About Wazuh?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Wazuh, finding it user-friendly and ideal for small-scale companies.
- Users value Wazuh's **affordability** , enjoying top-tier security features without the burden of high licensing fees.
- Users value the **high visibility and control** provided by Wazuh for comprehensive security event management.
- Users find Wazuh's **easy management** features enhance usability, facilitating efficient operations and cost reduction.
- Users find the **easy setup** of Wazuh greatly beneficial for rolling out and managing security effectively.

##### Cons

- Users struggle with the **complex interface** , finding it challenging to navigate during setup and configuration.
- Users find Wazuh **not user-friendly** , struggling with steep learning curves and convoluted setup processes for new users.
- Users face **complicated implementation** challenges with the on-prem console, creating frustrations during setup and management.
- Users face a **steep learning curve** with Wazuh, finding initial setup and tuning time-consuming and challenging.
- Users find the **difficult setup** of Wazuh challenging, particularly due to its steep learning curve and time-consuming configurations.

#### What Are Recent G2 Reviews of Wazuh?

**["All-in-One Open-Source SIEM/XDR with Powerful Customization and Integrations"](https://www.g2.com/survey_responses/wazuh-review-13177015)**

**Rating:** 4.5/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/wazuh-review-13177015)

**["Centralized Monitoring and security Incidents Simplified"](https://www.g2.com/survey_responses/wazuh-review-12848657)**

**Rating:** 4.5/5.0 stars

_— Karsh T._

[Read full review](https://www.g2.com/survey_responses/wazuh-review-12848657)

#### What Are G2 Users Discussing About Wazuh?

- [What is Wazuh - The Open Source Security Platform used for?](https://www.g2.com/discussions/what-is-wazuh-the-open-source-security-platform-used-for) - 1 comment

### [LevelBlue USM Anywhere](https://www.g2.com/products/levelblue-usm-anywhere/reviews)

LevelBlue USM Anywhere is a cloud-based security management solution that accelerates and centralizes threat detection, incident response, and compliance management for your cloud, hybrid cloud, and on-premises environments. USM Anywhere includes purpose-built cloud sensors that natively monitor your Amazon Web Services (AWS) and Microsoft Azure cloud environments. On premises, lightweight virtual sensors run on Microsoft Hyper-V and VMware ESXi to monitor your virtual private cloud and physical IT infrastructure. With USM Anywhere, you can rapidly deploy sensors into your cloud and on-premises environments while centrally managing data collection, security analysis, and threat detection from the AlienVault Secure Cloud. Five Essential Security Capabilities in a Single SaaS Platform AlienVault USM Anywhere provides five essential security capabilities in a single SaaS solution, giving you everything you need for threat detection, incident response, and compliance management—all in a single pane of glass. With USM Anywhere, you can focus on finding and responding to threats, not managing software. An elastic, cloud-based security solution, USM Anywhere can readily scale to meet your threat detection needs as your hybrid cloud environment changes and grows. 1. Asset Discovery 2. Vulnerability Assessment 3. Intrusion Detection 4. Behavioral Monitoring 5. SIEM

**Average Rating:** 4.4/5.0

**Total Reviews:** 102

#### How Do G2 Users Rate LevelBlue USM Anywhere?

- **Threat Intelligence:** 9.2/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.6/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.3/10 (Category avg: 8.5/10)
- **Incident Logs:** 9.2/10 (Category avg: 8.8/10)

#### Who Is the Company Behind LevelBlue USM Anywhere?

- **Seller:** [LevelBlue](https://www.g2.com/sellers/levelblue-49a2e3c1-ca90-4308-b899-08973f657bae)
- **HQ Location:** Dallas, Texas, United States
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=b7c87546a6975c33488ad71b8d45d5e29fffbd81a2f727bd39487c5bbfe94466&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Flevelbluecyber%2F&secure%5Burl_type%5D=linkedin_company_website)  
782 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 62% Medium, 20% Small

#### What Are Recent G2 Reviews of LevelBlue USM Anywhere?

**["Impressive Cloud Based SIEM"](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-9698214)**

**Rating:** 4.5/5.0 stars

_— Goodness I._

[Read full review](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-9698214)

**["Comprehensive cloud security and monitoring platform"](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-11718892)**

**Rating:** 5.0/5.0 stars

_— Luis Emmanuel M._

[Read full review](https://www.g2.com/survey_responses/levelblue-usm-anywhere-review-11718892)

#### What Are G2 Users Discussing About LevelBlue USM Anywhere?

- [How has AlienVault USM supported your cybersecurity efforts, and what features do you rely on most?](https://www.g2.com/discussions/how-has-alienvault-usm-supported-your-cybersecurity-efforts-and-what-features-do-you-rely-on-most)
- [What is AlienVault USM (from AT&T Cybersecurity) used for?](https://www.g2.com/discussions/what-is-alienvault-usm-from-at-t-cybersecurity-used-for)

### [Splunk SOAR (Security Orchestration, Automation and Response)](https://www.g2.com/products/splunk-soar-security-orchestration-automation-and-response/reviews)

Splunk SOAR provides security orchestration, automation and response capabilities that allow security analysts to work smarter by automating repetitive tasks; respond to security incidents faster with automated detection, investigation, and response; increase productivity, efficiency and accuracy; and strengthen defenses by connecting and coordinating complex workflows across their team and tools. Splunk SOAR also supports a broad range of security operations center (SOC) functions including event and case management, integrated threat intelligence, collaboration tools and reporting.

**Average Rating:** 4.4/5.0

**Total Reviews:** 40

#### How Do G2 Users Rate Splunk SOAR (Security Orchestration, Automation and Response)?

- **Threat Intelligence:** 8.8/10 (Category avg: 8.9/10)
- **Quality of Support:** 8.8/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.0/10 (Category avg: 8.5/10)
- **Incident Logs:** 8.9/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Splunk SOAR (Security Orchestration, Automation and Response)?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Consulting
- **Company Size:** 41% Medium, 34% Large

#### What Do G2 Reviewers Say About Splunk SOAR (Security Orchestration, Automation and Response)?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **automation capabilities** of Splunk SOAR, enhancing security and response efficiency dramatically.
- Users value the **effective incident management** of Splunk SOAR, enhancing security response and automation in their workflows.
- Users value the **flexibility and integration** of Splunk SOAR, allowing seamless workflow orchestration for enhanced security.
- Users appreciate the **easy threat detection** capability of Splunk SOAR, enhancing security analysis and response efficiency.
- Users value the **ease of use** of Splunk SOAR, appreciating its intuitive UI and seamless integration capabilities.

##### Cons

- Users find the **high cost** of Splunk SOAR prohibitive, making it difficult for average users to afford.
- Users find the **learning curve steep** , requiring extensive knowledge and training to effectively use Splunk SOAR.
- Users find the **difficult learning curve** to be challenging, especially for beginners new to automation platforms.
- Users find the **complexity** of Splunk SOAR challenging, requiring extensive learning for effective use.
- Users find the **poor interface design** of Splunk SOAR challenging, particularly for those new to automation platforms.

#### What Are Recent G2 Reviews of Splunk SOAR (Security Orchestration, Automation and Response)?

**["Extensive SOC Automation with Splunk SOAR"](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-13157846)**

**Rating:** 4.5/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-13157846)

**["Splunk SOAR is a good software for automation"](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)**

**Rating:** 5.0/5.0 stars

_— Dheeraj T._

[Read full review](https://www.g2.com/survey_responses/splunk-soar-security-orchestration-automation-and-response-review-9922172)

#### What Are G2 Users Discussing About Splunk SOAR (Security Orchestration, Automation and Response)?

- [What is Splunk SOAR (Security Orchestration, Automation and Response) used for?](https://www.g2.com/discussions/what-is-splunk-soar-security-orchestration-automation-and-response-used-for)

### [Guardsix](https://www.g2.com/products/guardsix/reviews)

Guardsix is the sovereign security platform for lean European teams, bringing log management and audit-ready compliance to regulated industries, critical national infrastructure operators, and the Managed Security Service Providers (MSSPs) that serve them throughout Europe and beyond. Headquartered in Copenhagen, Denmark, Guardsix delivers sovereign-by-design security for organisations that carry real operational responsibility. The company employs several hundred cyber security specialists and keeps every organisation it serves in full control of their data, deployment, and operations. Guardsix provides a unified Command Centre platform combining: • Security Information and Event Management (SIEM) • Network Detection and Response (NDR) • Security Orchestration, Automation and Response (SOAR) • Fleet for enabling multi-tenant management • Governance for Healthcare internal risk compliance monitoring The platform is built to support European data sovereignty, regulatory compliance and operational control, with predictable node-based pricing and deployment options spanning on-premises, air-gapped, hybrid and cloud environments. Guardsix solutions help organisations: • Simplify audit readiness for regulations such as NIS2, DORA, and GDPR. • Support lean security teams with efficient log management and simplified workflows. • Scale security operations without increased complexity or ingestion-led pricing surprises. • Keep security data under European jurisdiction and control — where it lives, who operates it, and under whose laws. • Deploy on their own terms, on-prem and in infrastructure they control, keeping migration a real option at every renewal. • See clearly across their whole environment, with SIEM, NDR, SOAR, Fleet, and Governance in one sovereign platform rather than a stack of point tools. Guardsix maintains SOC 2 Type II attestation and designs its solutions in accordance with European data protection requirements. With a strong partner-first model, Guardsix works closely with regional MSSPs and service providers, combining sovereign-by-design security technology with European integrity and deployment flexibility.

**Average Rating:** 4.3/5.0

**Total Reviews:** 105

#### How Do G2 Users Rate Guardsix?

- **Threat Intelligence:** 8.4/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.0/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.3/10 (Category avg: 8.5/10)
- **Incident Logs:** 8.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Guardsix?

- **Seller:** [guardsix](https://www.g2.com/sellers/guardsix)
- **Company Website:** guardsix.com
- **Year Founded:** 2001
- **HQ Location:** Copenhagen, Capital Region
- **LinkedIn® Page:** [linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=92bf20089a2ec7456b77a9cafe8277355b36f5113b6cae2b0f9df3a0cfc82f20&secure%5Burl%5D=https%3A%2F%2Flinkedin.com%2Fcompany%2Fguardsix&secure%5Burl_type%5D=linkedin_company_website)  
162 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 44% Medium, 31% Small

#### What Do G2 Reviewers Say About Guardsix?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Guardsix, making administration and navigation simple and efficient.
- Users appreciate the **effortless integration and usability** of Logpoint, enhancing efficiency in managing diverse log data.
- Users appreciate the **excellent customer support** provided by Logpoint, enhancing their experience and satisfaction with the product.
- Users appreciate the **easy integrations** of Guardsix, allowing seamless compatibility with their tech ecosystem for enhanced functionality.
- Users appreciate the **efficiency** of Guardsix in managing incidents and integrating with existing tools seamlessly.

##### Cons

- Users criticize the **poor interface design** of Guardsix, finding it difficult to understand and navigate effectively.
- Users find the **poor log presentation** and overall interface slow, hindering their experience with Guardsix.
- Users find the **interface complexity** challenging, but hope for improvements in the near future.
- Users find the **confusing interface** of Guardsix difficult to navigate and slow to respond.
- Users find there is an **information deficiency** regarding appliance design and resource requirements for new devices.

#### What Are Recent G2 Reviews of Guardsix?

**["Context-Driven SIEM That Enhances Incident Response"](https://www.g2.com/survey_responses/guardsix-review-11985484)**

**Rating:** 4.5/5.0 stars

_— Simon A._

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11985484)

**["Review"](https://www.g2.com/survey_responses/guardsix-review-11378057)**

**Rating:** 4.0/5.0 stars

_— Ronny K._

[Read full review](https://www.g2.com/survey_responses/guardsix-review-11378057)

#### What Are G2 Users Discussing About Guardsix?

- [What is your experience with Logpoint for SIEM, and what do you recommend for new users?](https://www.g2.com/discussions/what-is-your-experience-with-logpoint-for-siem-and-what-do-you-recommend-for-new-users)
- [What is LogPoint used for?](https://www.g2.com/discussions/what-is-logpoint-used-for)

### [D3 Security](https://www.g2.com/products/d3-security/reviews)

D3 stands at the forefront of AI-powered security, providing real-time, autonomous SOC solutions that help organizations stay ahead of cyber threats. By merging autonomous investigation and triage with AI-guided remediation, D3 is delivering AI-powered, human-led cyber security solutions. Morpheus is D3 Security’s fully autonomous SOC solution that triages, investigates, and responds to every alert, 24/7. Morpheus covers 100% of your alerts — no exceptions — so your team never has to choose between chasing false positives or risking a breach. It triages 95% of alerts in under two minutes, integrating seamlessly with any SIEM, XDR, or security stack. Unlike traditional SOAR platforms, Morpheus doesn’t need endless playbook tuning; it can build response workflows on the fly, specific to your security stack. The result? Zero alert fatigue, fewer missed threats, and a dramatic boost in SOC efficiency, powered by a data privacy-friendly and SecOps-focused AI model.

**Average Rating:** 4.2/5.0

**Total Reviews:** 64

#### How Do G2 Users Rate D3 Security?

- **Threat Intelligence:** 9.0/10 (Category avg: 8.9/10)
- **Quality of Support:** 9.0/10 (Category avg: 8.8/10)
- **Incident Case Management:** 8.9/10 (Category avg: 8.5/10)

#### Who Is the Company Behind D3 Security?

- **Seller:** [D3 Security Management Systems](https://www.g2.com/sellers/d3-security-management-systems)
- **Year Founded:** 2012
- **HQ Location:** Vancouver, British Columbia
- **Twitter:** @D3Security  
1,118 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e5845965397adf4071b06f49eff850d4e9ab889560ddc9e82faade8524df1c6e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F342986%2F&secure%5Burl_type%5D=linkedin_company_website)  
159 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 49% Large, 41% Medium

#### What Are Recent G2 Reviews of D3 Security?

**["Next Generation SOAR Platform"](https://www.g2.com/survey_responses/d3-security-review-7793810)**

**Rating:** 4.5/5.0 stars

_— Kristian T._

[Read full review](https://www.g2.com/survey_responses/d3-security-review-7793810)

**["The best security operation platform"](https://www.g2.com/survey_responses/d3-security-review-3110773)**

**Rating:** 5.0/5.0 stars

_— George K._

[Read full review](https://www.g2.com/survey_responses/d3-security-review-3110773)

- [&lsaquo; Prev‹ Prev](/categories/incident-response/mid-market?order=g2_score#product-list)
- [1](/categories/incident-response/mid-market?order=g2_score#product-list)
- 2
- Next &rsaquo;Next ›

Spotlight Categories

[Sales Enablement Software](https://www.g2.com/categories/sales-enablement)

[Customer Communications Management Software](https://www.g2.com/categories/customer-communications-management)

[Outbound Call Tracking Software](https://www.g2.com/categories/outbound-call-tracking)

[VoIP Providers](https://www.g2.com/categories/voip)

[Managed File Transfer (MFT) Software](https://www.g2.com/categories/managed-file-transfer-mft)

Similar Categories

- [Security Information and Event Management (SIEM)](/categories/security-information-and-event-management-siem)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Breach and Attack Simulation (BAS)](/categories/breach-and-attack-simulation-bas)
- [Deception Technology](/categories/deception-technology)

- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)
- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)

- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)
- [Security Orchestration, Automation, and Response (SOAR)](/categories/security-orchestration-automation-and-response-soar)

[Browse Incident Response Themes](/categories/incident-response/themes)