Best Incident Response Software - Page 2

How Many Incident Response Software Products Does G2 Track?

Total Products under this Category: 109

Category Stats (Sep 2026)

  • Average Rating: 4.48/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: ReliaQuest GreyMatter (+1.61%) - Among all products in this category, ReliaQuest GreyMatter recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Incident Response Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,500+ Authentic Reviews
  • 109+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Incident Response Software

G2 Grid® for Incident Response Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, KnowBe4 PhishER/PhishER Plus, Torq AI SOC Platform, Tines Stories, SentinelOne Singularity Endpoint, Cynet, Palo Alto Cortex XSIAM, and Microsoft Sentinel.

Underlying data: [Grid® JSON](https://www.g2.com/categories/incident-response/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=tines-stories&focus%5B%5D=sentinelone-singularity-endpoint&focus%5B%5D=cynet&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=microsoft-sentinel)

Barracuda Incident Response

No email defense technology can protect against increasingly advanced email threats 100 percent of the time. Some advanced social engineering attacks like business email compromise will reach users’ mailboxes. And when they do, you need to respond quickly and accurately to minimize the scope and severity of damage. Barracuda Incident Response lets you respond to threats quickly and effectively, by automating investigative workflows and enabling direct removal of malicious emails

Average Rating: 4.5/5.0

Total Reviews: 16

How Do G2 Users Rate Barracuda Incident Response?

  • Threat Intelligence: 8.8/10 (Category avg: 8.9/10)
  • Quality of Support: 9.4/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.5/10 (Category avg: 8.5/10)
  • Incident Logs: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Barracuda Incident Response?

  • Seller: Barracuda
  • Year Founded: 2002
  • HQ Location: Campbell, CA
  • Twitter: @Barracuda
    15,239 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,327 employees on LinkedIn®
  • Ownership: Private

Who Uses This Product?

  • Company Size: 50% Medium, 25% Large

What Do G2 Reviewers Say About Barracuda Incident Response?

AI-generated summary from verified user reviews

Pros
  • Users value the instant threat removal capability of Barracuda Incident Response, enhancing email security effectively.
  • Users appreciate the email search and removal functionality in Barracuda Incident Response, enhancing data control easily.
  • Users value the instant threat removal capability of Barracuda Incident Response, preventing potential larger security issues.
  • Users value the comprehensive incident response capabilities of Barracuda, enhancing their cybersecurity protection effectively.
  • Users find Barracuda Incident Response to be an incredible tool for effective remediation and investigation in cybersecurity.
Cons
  • Users wish for blocking future emails across all gateway levels, as current limitations impact email management effectiveness.

What Are Recent G2 Reviews of Barracuda Incident Response?

What Are G2 Users Discussing About Barracuda Incident Response?

UnderDefense MAXI

UnderDefense is an Agentic AI SOC & Compliance Automation platform trusted by 200+ enterprises in the US and EU. It works on top of the security stack you already own — no rip-and-replace, no added headcount — so your team spends its time on decisions, not triage. ◆ 10+ years of operations with zero ransomware incidents ◆ 250+ integrations across any SIEM, EDR, or cloud stack ◆ 24/7 IR team available whenever you need urgent support WHAT WE OFFER AGENTIC AI SOC UnderDefense Agentic AI SOC works on top of your existing security stack, turning every security team into a machine-speed defense unit without tool replacement or headcount expansion. It takes over the investigative routine that pulls your team away from strategic decisions: enrichment, correlation, triage. ▸ Investigation at Machine Speed: Agentic AI SOC accesses tools, enriches data, and performs deep cross-environment investigations at machine speed. It correlates, triages, and forms conclusions, offloading all repetitive work from your team. ▸ 2 Minutes Per Alert: Complete SIEM queries, threat intel checks, and cross-system correlations in 2 minutes. Every step fully observable and auditable. ▸ Human at Every Decision Point: The platform verifies suspicious activity with end-users via Slack or Teams, then routes containment decisions to your team or our 24/7 IR experts. COMPLIANCE AUTOMATION Stop chasing spreadsheets. UnderDefense MAXI Compliance AI automatically collects continuous evidence across ISO 27001, SOC 2, PCI DSS, GDPR, and HIPAA, and publishes your live posture through a shareable Trust Center link. ▸ 40% audit-ready in the first 40 minutes ▸ 2X faster time-to-compliance vs. traditional audit ▸ 24/7 continuous monitoring — posture always current, not point-in-time WHY WE ARE BETTER ✓ No rip-and-replace: Works with your current SIEM (Splunk, Sentinel, Chronicle, QRadar, Elastic), EDR, and cloud tools. Logs stay in your data lake. ✓ True Multi-Environment Coverage: Comprehensive visibility across on-premises, cloud (AWS, GCP, Azure), SaaS, network, identity, and OT/SCADA environments. ✓ The Only Agentic AI SOC with on-prem deployment: Full AI SOC inside your own infrastructure. No telemetry leaving your environment. Air-gapped available. ✓ Right-Sized for Any Enterprise: Detection engineering and support tailored to your organization, not a one-size-fits-all template. Start your free trial at underdefense.com

Average Rating: 4.9/5.0

Total Reviews: 40

How Do G2 Users Rate UnderDefense MAXI?

  • Threat Intelligence: 9.7/10 (Category avg: 8.9/10)
  • Quality of Support: 9.9/10 (Category avg: 8.9/10)
  • Incident Case Management: 9.3/10 (Category avg: 8.5/10)
  • Incident Logs: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind UnderDefense MAXI?

  • Seller: UnderDefense
  • Year Founded: 2017
  • HQ Location: New York, NY
  • Twitter: @underdefense
    153 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    133 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Information Technology and Services, Marketing and Advertising
  • Company Size: 57% Medium, 33% Small

What Do G2 Reviewers Say About UnderDefense MAXI?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the visibility provided by UnderDefense MAXI, allowing them to focus on relevant security alerts effectively.
  • Users commend UnderDefense MAXI for its outstanding customer support, ensuring rapid responses and clear guidance throughout their cybersecurity needs.
  • Users appreciate the expert cybersecurity support from UnderDefense MAXI, enhancing their security posture and alert management.
  • Users commend the accuracy of information provided by UnderDefense MAXI, enhancing their security management and decision-making.
  • Users value the exceptional issue resolution by UnderDefense, enhancing security management with quick and effective solutions.
Cons
  • Users desire more automation in UnderDefense MAXI, seeking greater control over the dashboard and updates.
  • Users desire more control over the dashboard and automated updates for a better experience with UnderDefense MAXI.
  • Users note the limited integration requiring extra setup time, which can be a hurdle for new users.
  • Users note the setup difficulty requiring time and effort to properly integrate tools before full functionality can be enjoyed.

What Are Recent G2 Reviews of UnderDefense MAXI?

IBM Concert platform

IBM Concert® is an agentic IT Ops platform that creates an adaptable, unified operational layer across your environment. It connects signals, generates shared context, and coordinates action across teams and tools, so your entire system operates as one. With cross-domain intelligence, Concert helps you reduce risk, maintain business continuity, improve performance, and optimize cost across the stack. Powered by agentic AI, it surfaces what matters, prioritizes business impact, and orchestrates action through governed workflows. 

Average Rating: 4.2/5.0

Total Reviews: 27

How Do G2 Users Rate IBM Concert platform?

  • Quality of Support: 7.3/10 (Category avg: 8.9/10)

Who Is the Company Behind IBM Concert platform?

  • Seller: IBM
  • Company Website:
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 41% Small, 37% Medium

What Do G2 Reviewers Say About IBM Concert platform?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of IBM Concert, which simplifies project management and enhances team communication effectively.
  • Users value the end-to-end visibility and actionable insights of IBM Concert, enhancing focus and collaboration in their workflows.
  • Users value the automation capabilities of IBM Concert, enhancing efficiency and collaboration while minimizing manual efforts.
  • Users find the easy setup of IBM Concert smooth, enhancing productivity by integrating multiple tools into one platform.
  • Users value IBM Concert for its effective problem-solving capabilities, offering clear insights and speeding up incident resolution.
Cons
  • Users find the learning difficulty of IBM Concert challenging, often requiring time and better onboarding support.
  • Users find the initial setup complex, with a steep learning curve that challenges new users to get acquainted.
  • Users feel the learning curve is steep, making it challenging to grasp all features of IBM Concert quickly.
  • Users face integration issues with IBM Concert, noting the need for smoother connections and improved onboarding support.
  • Users express a need for limited customization options in IBM Concert, which hinder adaptability for diverse team requirements.

What Are Recent G2 Reviews of IBM Concert platform?

Pondurance

Pondurance is the only provider of risk-based MDR services specifically engineered to eliminate breach risks. As a full-service provider of DFIR, MDR, and cybersecurity advisory and compliance services, Pondurance protects midmarket organizations from data breach risks before, during, and after its occurrence. Organizations entrusted with consumer protected health information (PHI) and personally identifiable information (PII) rely on Pondurance to provide a unified platform and trusted U.S.-based SOC service.

Average Rating: 4.7/5.0

Total Reviews: 18

How Do G2 Users Rate Pondurance?

  • Threat Intelligence: 9.5/10 (Category avg: 8.9/10)
  • Quality of Support: 9.8/10 (Category avg: 8.9/10)
  • Incident Case Management: 9.0/10 (Category avg: 8.5/10)
  • Incident Logs: 9.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Pondurance?

  • Seller: Pondurance
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Indianapolis, US
  • LinkedIn® Page: www.linkedin.com
    105 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Hospital & Health Care
  • Company Size: 61% Medium, 28% Large

What Do G2 Reviewers Say About Pondurance?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the rapid response times of Pondurance, enhancing their ability to address security issues effectively.
  • Users value the proactive cybersecurity approach of Pondurance, enhancing their overall security posture with exceptional support.
  • Users value the continuous monitoring of Pondurance, ensuring reliable protection and high-quality support throughout their experience.
  • Users value Pondurance's proactive customer support, ensuring robust security and prompt responsiveness to issues.
  • Users value the real-time monitoring for prompt issue resolution, enhancing system reliability and peace of mind.
Cons
  • Users report occasional deployment issues, though they are infrequent and typically minor, not a major concern.

What Are Recent G2 Reviews of Pondurance?

Wazuh

Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh, with over 30 million downloads per year, has one of the largest open-source security communities in the world. Wazuh helps organizations of all sizes protect their data assets against security threats. Learn more about the project at wazuh.com

Average Rating: 4.5/5.0

Total Reviews: 70

How Do G2 Users Rate Wazuh?

  • Threat Intelligence: 8.7/10 (Category avg: 8.9/10)
  • Quality of Support: 8.4/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.9/10 (Category avg: 8.5/10)
  • Incident Logs: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Wazuh?

  • Seller: Wazuh Inc.
  • Year Founded: 2015
  • HQ Location: Campbell, US
  • Twitter: @wazuh
    8,026 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    270 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: SOC Analyst
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 47% Small, 40% Medium

What Do G2 Reviewers Say About Wazuh?

AI-generated summary from verified user reviews

Pros
  • Users value the user-friendly design of Wazuh, making it simple to implement and manage security tasks effectively.
  • Users value Wazuh for its affordability, benefiting from enterprise-level security without high licensing costs.
  • Users value the real-time threat detection and control offered by Wazuh for robust cybersecurity across their infrastructure.
  • Users value the easy management of Wazuh, simplifying their experience and streamlining operations effectively.
  • Users find the easy setup of Wazuh beneficial, enabling quick deployment and configuration for endpoint monitoring.
Cons
  • Users find the complex interface challenging, with a steep learning curve and time-consuming configurations for new users.
  • Users find Wazuh to have a steep learning curve and convoluted setup, making it challenging for new users.
  • Users face significant challenges with complex implementation of Wazuh, making setup and management difficult.
  • Users face a difficult learning curve with Wazuh, particularly during setup and configuration, hindering initial use.
  • Users face a difficult setup with Wazuh, often struggling with the steep learning curve and time-consuming configurations.

What Are Recent G2 Reviews of Wazuh?

What Are G2 Users Discussing About Wazuh?

SpinOne

SpinOne is an AI-powered SaaS data protection platform that combines automated backup and recovery, Data Leak and Loss Prevention (DLP), SaaS Security Posture Management (SSPM), ransomware protection, and continuous security monitoring to protect business-critical data across Google Workspace, Microsoft 365, Salesforce, and Slack. Recognized by Gartner in the Market Guide for SaaS Security Posture Management, SpinOne helps organizations secure, protect, recover, and govern SaaS data across their most critical cloud applications. Unlike traditional backup solutions or standalone security tools, SpinOne unifies SaaS backup, data recovery, Data Leak and Loss Prevention (DLP), SaaS Security Posture Management (SSPM), ransomware protection, and automated security controls in a single platform. Organizations use SpinOne to prevent data loss, reduce cyber risk, strengthen compliance, and improve business continuity. SpinOne provides automated Google Workspace backup and recovery for Gmail, Google Drive, Shared Drives, Calendar, Contacts, and Google Sites. IT teams can restore individual files, emails, folders, users, or complete accounts with point-in-time recovery to minimize downtime caused by accidental deletion, ransomware, insider threats, malicious applications, or operational errors. SpinOne also provides Microsoft 365 backup and recovery for Exchange Online, OneDrive, SharePoint, and Microsoft Teams. Across SaaS applications, SpinOne helps organizations maintain secure, recoverable, and compliant business data. Beyond backup and recovery, SpinOne protects SaaS environments with AI-powered Data Leak and Loss Prevention (DLP), helping organizations identify sensitive information, prevent unauthorized data exposure, reduce data leakage risks, and enforce security policies. SpinOne SaaS Security Posture Management (SSPM) continuously monitors SaaS environments, identifies security risks, detects misconfigurations, and helps automate remediation. Key capabilities include: Google Workspace backup and recovery Microsoft 365 backup and recovery SaaS backup and data protection Data Leak Prevention (DLP) Data Loss Prevention (DLP) SaaS Security Posture Management (SSPM) Ransomware detection and recovery Point-in-time recovery and granular restore Continuous SaaS security monitoring Sensitive data protection Compliance and audit readiness Business continuity and disaster recovery SpinOne has been recognized by Cyber Defense Magazine through multiple Global InfoSec Awards, including recognition for Secure SaaS Backup, Ransomware Protection for SaaS Data, SaaS/Cloud Security, Browser Security, and Data Security Posture Management categories. SpinOne helps organizations protect SaaS data throughout its lifecycle—from preventing data leaks and security risks to backing up critical information, detecting ransomware, and rapidly recovering after cyber incidents. Organizations choose SpinOne as a unified SaaS data protection platform to secure, back up, recover, and govern critical data across Google Workspace, Microsoft 365, Salesforce, and Slack.

Average Rating: 4.8/5.0

Total Reviews: 127

G2 Deal: Get $ 500 off SpinOne with this exclusive G2 deal!

SpinOne is an all-in-one, SaaS security platform that protects SaaS data for mission-critical SaaS applications. Start a 15-day free trial of SpinOne. When you're ready to purchase, add the promo code "SPINLOVER" to claim $ 500 off your first year of a main subscription purchase of SpinOne.

Price: $500 Off

View this exclusive G2 deal

How Do G2 Users Rate SpinOne?

  • Threat Intelligence: 9.2/10 (Category avg: 8.9/10)
  • Quality of Support: 9.6/10 (Category avg: 8.9/10)
  • Incident Case Management: 9.3/10 (Category avg: 8.5/10)
  • Incident Logs: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind SpinOne?

  • Seller: SpinAI
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Palo Alto, California
  • Twitter: @spintechinc
    766 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    91 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, IT Director
  • Top Industries: Marketing and Advertising, Non-Profit Organization Management
  • Company Size: 51% Medium, 40% Small

What Do G2 Reviewers Say About SpinOne?

AI-generated summary from verified user reviews

Pros
  • Users highlight the exceptional customer support from SpinOne, providing tailored solutions and easy integration for peace of mind.
  • Users appreciate the ease of use of SpinOne, highlighting seamless integration and straightforward setup for peace of mind.
  • Users value the ease of use and reliable backups of SpinOne, ensuring peace of mind with data protection.
  • Users value the reliability of SpinOne for secure and intuitive backup of their Google Workspace data.
  • Users value SpinOne's reliable backup features that ensure data security and easy management, enhancing peace of mind.
Cons
  • Users report backup issues with limited management features, large backup delays, and a frustrating interface performance.
  • Users experience poor interface design in SpinOne, which complicates navigation and affects task efficiency.
  • Users find the cost prohibitive for large organizations, limiting accessibility and backup options for smaller entities.
  • Users find the pricing issues of SpinOne challenging, particularly for small organizations and archived users.
  • Users face unclear guidance due to limited resources and a complex manual process, complicating their experience with SpinOne.

What Are Recent G2 Reviews of SpinOne?

What Are G2 Users Discussing About SpinOne?

ReliaQuest GreyMatter

ReliaQuest’s agentic AI security operations platform, GreyMatter, allows security teams to detect threats at the source, contain them in under 5 minutes, and eliminate Tier 1 and Tier 2 work for faster investigation and response. GreyMatter orchestrates 6 agentic AI personas with 200+ agent skills and 400+ AI tools to exponentially scale security operations and help organizations predict what's next.

Average Rating: 4.6/5.0

Total Reviews: 19

How Do G2 Users Rate ReliaQuest GreyMatter?

  • Threat Intelligence: 8.6/10 (Category avg: 8.9/10)
  • Quality of Support: 9.0/10 (Category avg: 8.9/10)
  • Incident Case Management: 9.5/10 (Category avg: 8.5/10)
  • Incident Logs: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind ReliaQuest GreyMatter?

  • Seller: ReliaQuest
  • Company Website:
  • Year Founded: 2007
  • HQ Location: Tampa, Florida, United States
  • Twitter: @ReliaQuest
    2,577 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,106 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Consumer Services
  • Company Size: 37% Medium, 26% Small

What Do G2 Reviewers Say About ReliaQuest GreyMatter?

AI-generated summary from verified user reviews

Pros
  • Users value the exceptional visibility and integration capabilities of ReliaQuest GreyMatter, enhancing security operations across environments.
  • Users value the centralized management of ReliaQuest GreyMatter, enhancing visibility and streamlining security operations effectively.
  • Users highlight the exceptional customer support of ReliaQuest GreyMatter, enhancing satisfaction and streamlining security operations.
  • Users praise the ease of use of ReliaQuest GreyMatter, highlighting its straightforward setup and seamless integrations.
  • Users highlight the seamless integration with existing tools, streamlining security operations and enhancing overall efficiency.
Cons
  • Users note UX improvement needs in ReliaQuest GreyMatter, citing alert delays, slow report loading, and clunky Android app experience.
  • Users find the complexity of configurations in ReliaQuest GreyMatter can hinder usability and require significant fine-tuning.
  • Users experience an inefficient alert system with delays, duplicates, and slow report loading, affecting overall usability.
  • Users find the learning curve steep for advanced workflows, though documentation and support help eventually.
  • Users find login issues with the ReliaQuest GreyMatter app, particularly on Android, making the sign-in process frustrating.

What Are Recent G2 Reviews of ReliaQuest GreyMatter?

Blumira Automated Detection & Response

Blumira is an integrated security operations platform built for growing teams and the partners supporting them to gain complete visibility into their environment, identify and address risk faster, and deliver advanced security and compliance. The platform includes: - Managed Detections for automated threat hunting to identify attacks early - AI Investigation with 98.5% accurate, human-in-the-loop triage validated against real cases - Rapid Response with automation and 1-click actions to contain and block threats immediately - One Year of Data Retention with unlimited log ingestion to satisfy compliance requirements - Advanced Reporting and dashboards for forensics and easy investigation - Endpoint & Identity Protection (EDR/ITDR) for real-time remediation across devices and users - 24/7 Security Operations support for critical priority issues

Average Rating: 4.6/5.0

Total Reviews: 122

How Do G2 Users Rate Blumira Automated Detection & Response?

  • Threat Intelligence: 9.1/10 (Category avg: 8.9/10)
  • Quality of Support: 9.5/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.9/10 (Category avg: 8.5/10)
  • Incident Logs: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Blumira Automated Detection & Response?

  • Seller: Blumira
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Ann Arbor, Michigan
  • Twitter: @blumira
    1 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    55 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: IT Manager
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Medium, 36% Small

What Do G2 Reviewers Say About Blumira Automated Detection & Response?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the easy setup of Blumira Automated Detection & Response, enabling quick integration and efficient use.
  • Users appreciate the responsive customer support of Blumira, finding it reliable and personal for their IT needs.
  • Users praise the setup ease of Blumira, appreciating its quick integration and automated alert features.
  • Users appreciate the reliable real-time alerting of Blumira, valuing its clarity and ease of use for all techs.
  • Users value the reliable real-time alerting of Blumira, appreciating its ease of use and helpful implementation.
Cons
  • Users find limited customization with detection filters, relying on support for creating necessary custom detections.
  • Users express concern over false positives that can disrupt business functions and lead to frustration with repeated alerts.
  • Users find Blumira's pricing expensive, citing inflexible models and insufficient features in lower tiers.
  • Users express frustration over false positives that waste time and complicate the overall experience with Blumira.
  • Users express concern over insufficient information, desiring better data accessibility and clearer deployment status.

What Are Recent G2 Reviews of Blumira Automated Detection & Response?

What Are G2 Users Discussing About Blumira Automated Detection & Response?

Darktrace / NETWORK

Darktrace / NETWORK™ is the industry’s most advanced Network Detection and Response (NDR) solution. It learns what normal behavior is for your entire modern network, using Self-Learning AI to detect and autonomously contain any activity that could cause business disruption including known, novel and insider threats. - Sophisticated agentic AI to automate triage and investigation at speed and scale - Recognized as a Leader in the 2025 Gartner® Magic Quadrant™ for NDR - Over 10,000 customers globally

Average Rating: 4.5/5.0

Total Reviews: 44

How Do G2 Users Rate Darktrace / NETWORK?

  • Threat Intelligence: 8.6/10 (Category avg: 8.9/10)
  • Quality of Support: 9.2/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.7/10 (Category avg: 8.5/10)
  • Incident Logs: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Darktrace / NETWORK?

  • Seller: Darktrace
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Cambridgeshire, England
  • Twitter: @Darktrace
    18,177 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,597 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 60% Medium, 32% Large

What Do G2 Reviewers Say About Darktrace / NETWORK?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the excellent monitoring capabilities of Darktrace, offering impressive visibility and efficient network analysis.
  • Users appreciate the self-learning AI technology of Darktrace/Network, effectively adapting to threats without extensive configuration.
  • Users commend Darktrace's rapid threat detection, ensuring robust security with minimal manual intervention for maximum efficiency.
  • Users commend the responsive customer support of Darktrace/Network, enhancing learning and facilitating efficient troubleshooting.
  • Users highlight the autonomous AI-driven cybersecurity of Darktrace, which effectively detects and responds to threats in real time.
Cons
  • Users report a significant learning curve with Darktrace as the AI generates numerous alerts during initial setup.
  • Users note that the product can be expensive, particularly for smaller organizations with constrained budgets and significant training costs.
  • Users experience alert issues with Darktrace, needing extensive manual tuning to manage false positives during the learning phase.
  • Users find the complex setup of Darktrace challenging, requiring skilled teams for effective management and configuration.
  • Users experience false positives occasionally, requiring IT support to resolve issues affecting network connectivity.

What Are Recent G2 Reviews of Darktrace / NETWORK?

What Are G2 Users Discussing About Darktrace / NETWORK?

Proofpoint Threat Response Auto-Pull

Proofpoint Threat Response Auto-Pull (TRAP) enables messaging and security administrators the ability to automatically retract threats delivered to employee inboxes and emails that turn malicious after delivery to quarantine. It is also a powerful solution to retract messages sent in error as well as inappropriate, malicious, or emails containing compliance violations and also follows forwarded mail and distribution lists and creates an auditable activity trail. With Proofpoint Threat Response Auto-Pull, you can protect your people, data, and brand from today’s threats by: • Automatically pulling malicious or unwanted messages from an end-users inbox. • Enriching each message by checking every domain and IP address against premium intelligence feeds. • Including built-in reporting, showing stats like: Email quarantine success or failures, email retraction read status, targeting by active directory attribute • Reducing the remediation time needed from hours to minutes.

Average Rating: 4.5/5.0

Total Reviews: 24

How Do G2 Users Rate Proofpoint Threat Response Auto-Pull?

  • Threat Intelligence: 8.3/10 (Category avg: 8.9/10)
  • Quality of Support: 8.9/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.4/10 (Category avg: 8.5/10)
  • Incident Logs: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind Proofpoint Threat Response Auto-Pull?

  • Seller: Proofpoint
  • Year Founded: 2002
  • HQ Location: Sunnyvale, CA
  • Twitter: @proofpoint
    31,157 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,261 employees on LinkedIn®
  • Ownership: NASDAQ: PFPT

Who Uses This Product?

  • Company Size: 63% Large, 33% Medium

What Are Recent G2 Reviews of Proofpoint Threat Response Auto-Pull?

What Are G2 Users Discussing About Proofpoint Threat Response Auto-Pull?

CYREBRO

CYREBRO is an AI-native Managed Detection and Response solution, providing the core foundation and capabilities of a state-level Security Operations Center delivered through its cloud-based, interactive SOC Platform. CYREBRO rapidly detects, analyzes, investigates and responds to cyber threats, for businesses of all sizes.

Average Rating: 4.3/5.0

Total Reviews: 128

How Do G2 Users Rate CYREBRO?

  • Threat Intelligence: 8.6/10 (Category avg: 8.9/10)
  • Quality of Support: 8.3/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.0/10 (Category avg: 8.5/10)
  • Incident Logs: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind CYREBRO?

  • Seller: CYREBRO
  • Year Founded: 2013
  • HQ Location: Tel Aviv, IL
  • Twitter: @CYREBRO_IO
    307 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    81 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 64% Medium, 25% Small

What Do G2 Reviewers Say About CYREBRO?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of CYREBRO, thanks to its intuitive UI and quick access to investigations.
  • Users value the responsive and knowledgeable customer support of CYREBRO, enhancing their overall experience and satisfaction.
  • Users value the dashboard usability of CYREBRO, benefiting from easy management and seamless incident response.
  • Users value the real-time alerts and actionable insights from CYREBRO, enhancing their security response and peace of mind.
  • Users value the real-time alerts from CYREBRO that enhance response time and simplify incident management effectively.
Cons
  • Users report experiencing update issues with alert management, leading to overwhelmed users and hindered onboarding processes.
  • Users face communication issues with Cyrebro support, experiencing slow response times and vague information that complicates problem resolution.
  • Users report poor customer support with slow response times and limited availability, impacting their overall experience.
  • Users often find ineffective alerts from CYREBRO, struggling with overwhelming volume and vague details requiring further support.
  • Users report an inefficient alert system, with overwhelming notifications and redundant alerts complicating their experience.

What Are Recent G2 Reviews of CYREBRO?

What Are G2 Users Discussing About CYREBRO?

IBM QRadar SOAR

IBM QRadar® SOAR is designed to help your security team respond to cyberthreats with confidence, automate with intelligence and collaborate with consistency. It guides your team in resolving incidents by codifying established incident response processes into dynamic playbooks. The open and agnostic platform helps accelerate and orchestrate their response by automating actions with intelligence and integrating with other security tools. IBM QRadar SOAR is available on AWS Marketplace.

Average Rating: 4.0/5.0

Total Reviews: 25

How Do G2 Users Rate IBM QRadar SOAR?

  • Threat Intelligence: 7.2/10 (Category avg: 8.9/10)
  • Quality of Support: 7.9/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.7/10 (Category avg: 8.5/10)
  • Incident Logs: 7.5/10 (Category avg: 8.8/10)

Who Is the Company Behind IBM QRadar SOAR?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 72% Large, 21% Medium

What Do G2 Reviewers Say About IBM QRadar SOAR?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of IBM QRadar SOAR, appreciating its intuitive interface and seamless integration options.
  • Users value the automation capabilities of IBM QRadar SOAR, which significantly streamline security operations and reduce manual work.
  • Users value the seamless integrations with various tools, enhancing efficiency in security operations and workflows.
  • Users value the seamless integration capabilities of IBM QRadar SOAR, enhancing their security and workflow efficiency.
  • Users value the quick and effective customer support from IBM, enhancing their experience with QRadar SOAR.
Cons
  • Users face integration issues with IBM QRadar SOAR, experiencing difficulties in connecting applications and managing sophisticated transformations.
  • Users find the initial complexity of IBM QRadar SOAR challenging, making it hard to adapt to its features.
  • Users find the limited integration of IBM QRadar SOAR restrictive, hindering sophisticated implementations and transformations.
  • Users find that IBM QRadar SOAR has significant system limitations that hinder complex transformations and integration tasks.
  • Users often face bug issues with workflows, experiencing errors and occasional lagging that disrupts their productivity.

What Are Recent G2 Reviews of IBM QRadar SOAR?

Splunk SOAR (Security Orchestration, Automation and Response)

Splunk SOAR provides security orchestration, automation and response capabilities that allow security analysts to work smarter by automating repetitive tasks; respond to security incidents faster with automated detection, investigation, and response; increase productivity, efficiency and accuracy; and strengthen defenses by connecting and coordinating complex workflows across their team and tools. Splunk SOAR also supports a broad range of security operations center (SOC) functions including event and case management, integrated threat intelligence, collaboration tools and reporting.

Average Rating: 4.4/5.0

Total Reviews: 39

How Do G2 Users Rate Splunk SOAR (Security Orchestration, Automation and Response)?

  • Threat Intelligence: 8.8/10 (Category avg: 8.9/10)
  • Quality of Support: 8.8/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.0/10 (Category avg: 8.5/10)
  • Incident Logs: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Splunk SOAR (Security Orchestration, Automation and Response)?

  • Seller: Cisco
  • Year Founded: 1984
  • HQ Location: San Jose, CA
  • Twitter: @Cisco
    720,366 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    95,294 employees on LinkedIn®
  • Ownership: NASDAQ:CSCO

Who Uses This Product?

  • Top Industries: Information Technology and Services, Consulting
  • Company Size: 43% Medium, 35% Large

What Do G2 Reviewers Say About Splunk SOAR (Security Orchestration, Automation and Response)?

AI-generated summary from verified user reviews

Pros
  • Users value the end-to-end security management of Splunk SOAR, enhancing incident response and threat detection efficiency.
  • Users commend the easy threat detection and analysis capabilities, enhancing security response with flexible workflows.
  • Users appreciate the ease of use in Splunk SOAR, benefiting from a user-friendly interface and seamless integrations.
  • Users value the real-time monitoring capabilities of Splunk SOAR, enhancing threat detection and response efficiency.
  • Users appreciate the real-time threat alerts from Splunk SOAR, enhancing security response and reducing human error.
Cons
  • Users find Splunk SOAR expensive, making it difficult for normal users to afford and implement effectively.
  • Users find the software's complexity challenging to navigate, particularly for beginners needing extensive training.
  • Users find a significant lack of guidance, requiring external help to understand complex workflows and configurations.
  • Users face poor customer support, making it challenging to resolve issues quickly and efficiently.
  • Users find the complex implementation of Splunk SOAR to be time-consuming and often requiring significant resources and expertise.

What Are Recent G2 Reviews of Splunk SOAR (Security Orchestration, Automation and Response)?

What Are G2 Users Discussing About Splunk SOAR (Security Orchestration, Automation and Response)?

Intezer

Intezer automates the entire alert triage process, like an extension of your team handling Tier 1 SOC tasks for every alert at machine-speed. Intezer monitors incoming incidents from endpoint, reported phishing pipelines, or SIEM tools, then autonomously collects evidence, investigates, makes triage decisions, and escalates only the serious threats to your team for human intervention. Power your SOC with artificial intelligence that makes sure every alert is deeply analyzed (including every single artifact like files, URLs, endpoint memory, etc.), detecting malicious code in memory and other evasive threats. Fast set up and integrations with your SOC team's workflows (EDR, SOAR, SIEM, etc.) means Intezer's AI can immediately start filtering out false positives, giving you detailed analysis about every threat, and speeding up your incident response time. With Intezer: • Reduce Tier 1 escalation, sending only 4% of alerts on average to your team for immediate action. • Identify up to 97% of false positive alerts without taking any time from your analysts. • Reduce average triage time to 5 minutes or less, while giving your analysts deep context about every alert to prioritize critical treats and respond faster.

Average Rating: 4.5/5.0

Total Reviews: 187

How Do G2 Users Rate Intezer?

  • Threat Intelligence: 8.9/10 (Category avg: 8.9/10)
  • Quality of Support: 8.6/10 (Category avg: 8.9/10)
  • Incident Case Management: 7.8/10 (Category avg: 8.5/10)
  • Incident Logs: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind Intezer?

  • Seller: Intezer
  • Year Founded: 2015
  • HQ Location: New York
  • Twitter: @IntezerLabs
    10,170 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    89 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Student
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 54% Small, 23% Medium

What Do G2 Reviewers Say About Intezer?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the robust security features of Intezer, ensuring timely detection and blocking of malware.
  • Users value the effective malware detection and security features of Intezer that enhance system protection.
  • Users value Intezer for its effective malware detection and response capabilities, enhancing overall security and incident management.
  • Users value the high detection accuracy of Intezer, ensuring timely malware detection and enhanced system security.
  • Users appreciate the ease of use of Intezer, making malware detection and incident response straightforward and efficient.
Cons
  • Users feel the inability to control file visibility limits their privacy and management options in certain situations.
  • Users report complex interface issues with Intezer, making navigation challenging and less intuitive.
  • Users are concerned about limited file visibility control, which may impact their data privacy and access management.
  • Users find the difficult navigation of Intezer frustrating, with a less-than-ideal UI and small text affecting readability.
  • Users find the expensive pricing of Intezer problematic, especially with the limited free tier and some GUI issues.

What Are Recent G2 Reviews of Intezer?

What Are G2 Users Discussing About Intezer?

LogRhythm SIEM

Rapidly deploy LogRhythm SIEM, the leading self-hosted SIEM, to secure your organization with powerful detections, synchronized threat intelligence, automated workflows, and achieve faster, more accurate threat detection, investigation, and response (TDIR).

Average Rating: 4.2/5.0

Total Reviews: 137

How Do G2 Users Rate LogRhythm SIEM?

  • Threat Intelligence: 8.7/10 (Category avg: 8.9/10)
  • Quality of Support: 8.5/10 (Category avg: 8.9/10)
  • Incident Case Management: 8.7/10 (Category avg: 8.5/10)
  • Incident Logs: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind LogRhythm SIEM?

  • Seller: Exabeam
  • Year Founded: 2013
  • HQ Location: Broomfield, CO
  • Twitter: @exabeam
    5,374 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    785 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Information Security Analyst, Cyber Security Analyst
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 40% Large, 40% Medium

What Are Recent G2 Reviews of LogRhythm SIEM?

What Are G2 Users Discussing About LogRhythm SIEM?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated April 22, 2026